cfg80211: configuration for WoWLAN over TCP
[deliverable/linux.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
2a0e047e 22#include <net/inet_connection_sock.h>
55682965
JB
23#include "core.h"
24#include "nl80211.h"
b2e1b302 25#include "reg.h"
e35e4d28 26#include "rdev-ops.h"
55682965 27
5fb628e9
JM
28static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
29 struct genl_info *info,
30 struct cfg80211_crypto_settings *settings,
31 int cipher_limit);
32
4c476991
JB
33static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
34 struct genl_info *info);
35static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
36 struct genl_info *info);
37
55682965
JB
38/* the netlink family */
39static struct genl_family nl80211_fam = {
40 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
41 .name = "nl80211", /* have users key off the name instead */
42 .hdrsize = 0, /* no private header */
43 .version = 1, /* no particular meaning now */
44 .maxattr = NL80211_ATTR_MAX,
463d0183 45 .netnsok = true,
4c476991
JB
46 .pre_doit = nl80211_pre_doit,
47 .post_doit = nl80211_post_doit,
55682965
JB
48};
49
89a54e48
JB
50/* returns ERR_PTR values */
51static struct wireless_dev *
52__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 53{
89a54e48
JB
54 struct cfg80211_registered_device *rdev;
55 struct wireless_dev *result = NULL;
56 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
57 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
58 u64 wdev_id;
59 int wiphy_idx = -1;
60 int ifidx = -1;
55682965 61
89a54e48 62 assert_cfg80211_lock();
55682965 63
89a54e48
JB
64 if (!have_ifidx && !have_wdev_id)
65 return ERR_PTR(-EINVAL);
55682965 66
89a54e48
JB
67 if (have_ifidx)
68 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
69 if (have_wdev_id) {
70 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
71 wiphy_idx = wdev_id >> 32;
55682965
JB
72 }
73
89a54e48
JB
74 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
75 struct wireless_dev *wdev;
76
77 if (wiphy_net(&rdev->wiphy) != netns)
78 continue;
79
80 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
81 continue;
82
83 mutex_lock(&rdev->devlist_mtx);
84 list_for_each_entry(wdev, &rdev->wdev_list, list) {
85 if (have_ifidx && wdev->netdev &&
86 wdev->netdev->ifindex == ifidx) {
87 result = wdev;
88 break;
89 }
90 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
91 result = wdev;
92 break;
93 }
94 }
95 mutex_unlock(&rdev->devlist_mtx);
96
97 if (result)
98 break;
99 }
100
101 if (result)
102 return result;
103 return ERR_PTR(-ENODEV);
55682965
JB
104}
105
a9455408 106static struct cfg80211_registered_device *
878d9ec7 107__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 108{
7fee4778
JB
109 struct cfg80211_registered_device *rdev = NULL, *tmp;
110 struct net_device *netdev;
a9455408
JB
111
112 assert_cfg80211_lock();
113
878d9ec7 114 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
115 !attrs[NL80211_ATTR_IFINDEX] &&
116 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
117 return ERR_PTR(-EINVAL);
118
878d9ec7 119 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 120 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 121 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 122
89a54e48
JB
123 if (attrs[NL80211_ATTR_WDEV]) {
124 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
125 struct wireless_dev *wdev;
126 bool found = false;
127
128 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
129 if (tmp) {
130 /* make sure wdev exists */
131 mutex_lock(&tmp->devlist_mtx);
132 list_for_each_entry(wdev, &tmp->wdev_list, list) {
133 if (wdev->identifier != (u32)wdev_id)
134 continue;
135 found = true;
136 break;
137 }
138 mutex_unlock(&tmp->devlist_mtx);
139
140 if (!found)
141 tmp = NULL;
142
143 if (rdev && tmp != rdev)
144 return ERR_PTR(-EINVAL);
145 rdev = tmp;
146 }
147 }
148
878d9ec7
JB
149 if (attrs[NL80211_ATTR_IFINDEX]) {
150 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 151 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
152 if (netdev) {
153 if (netdev->ieee80211_ptr)
154 tmp = wiphy_to_dev(
155 netdev->ieee80211_ptr->wiphy);
156 else
157 tmp = NULL;
158
159 dev_put(netdev);
160
161 /* not wireless device -- return error */
162 if (!tmp)
163 return ERR_PTR(-EINVAL);
164
165 /* mismatch -- return error */
166 if (rdev && tmp != rdev)
167 return ERR_PTR(-EINVAL);
168
169 rdev = tmp;
a9455408 170 }
a9455408 171 }
a9455408 172
4f7eff10
JB
173 if (!rdev)
174 return ERR_PTR(-ENODEV);
a9455408 175
4f7eff10
JB
176 if (netns != wiphy_net(&rdev->wiphy))
177 return ERR_PTR(-ENODEV);
178
179 return rdev;
a9455408
JB
180}
181
182/*
183 * This function returns a pointer to the driver
184 * that the genl_info item that is passed refers to.
185 * If successful, it returns non-NULL and also locks
186 * the driver's mutex!
187 *
188 * This means that you need to call cfg80211_unlock_rdev()
189 * before being allowed to acquire &cfg80211_mutex!
190 *
191 * This is necessary because we need to lock the global
192 * mutex to get an item off the list safely, and then
193 * we lock the rdev mutex so it doesn't go away under us.
194 *
195 * We don't want to keep cfg80211_mutex locked
196 * for all the time in order to allow requests on
197 * other interfaces to go through at the same time.
198 *
199 * The result of this can be a PTR_ERR and hence must
200 * be checked with IS_ERR() for errors.
201 */
202static struct cfg80211_registered_device *
4f7eff10 203cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408
JB
204{
205 struct cfg80211_registered_device *rdev;
206
207 mutex_lock(&cfg80211_mutex);
878d9ec7 208 rdev = __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
209
210 /* if it is not an error we grab the lock on
211 * it to assure it won't be going away while
212 * we operate on it */
213 if (!IS_ERR(rdev))
214 mutex_lock(&rdev->mtx);
215
216 mutex_unlock(&cfg80211_mutex);
217
218 return rdev;
219}
220
55682965 221/* policy for the attributes */
b54452b0 222static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
223 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
224 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 225 .len = 20-1 },
31888487 226 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 227
72bdcf34 228 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 229 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
230 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
231 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
232 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
233
b9a5f8ca
JM
234 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
235 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
236 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
237 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 238 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
239
240 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
241 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
242 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 243
e007b857
EP
244 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
245 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 246
b9454e83 247 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
248 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
249 .len = WLAN_MAX_KEY_LEN },
250 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
251 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
252 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 253 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 254 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
255
256 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
257 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
258 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
259 .len = IEEE80211_MAX_DATA_LEN },
260 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
261 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
262 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
263 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
264 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
265 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
266 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 267 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 268 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 269 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 270 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 271 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 272 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 273
b2e1b302
LR
274 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
275 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
276
9f1ba906
JM
277 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
278 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
279 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
280 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
281 .len = NL80211_MAX_SUPP_RATES },
50b12f59 282 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 283
24bdd9f4 284 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 285 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 286
6c739419 287 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
288
289 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
290 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
291 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
292 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
293 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
294
295 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
296 .len = IEEE80211_MAX_SSID_LEN },
297 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
298 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 299 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 300 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 301 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
302 [NL80211_ATTR_STA_FLAGS2] = {
303 .len = sizeof(struct nl80211_sta_flag_update),
304 },
3f77316c 305 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
306 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
307 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
308 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
309 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
310 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 311 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 312 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
313 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
314 .len = WLAN_PMKID_LEN },
9588bbd5
JM
315 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
316 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 317 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
318 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
319 .len = IEEE80211_MAX_DATA_LEN },
320 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 321 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 322 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 323 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 324 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
325 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
326 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 327 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
328 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
329 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 330 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 331 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 332 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 333 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 334 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 335 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 336 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 337 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 338 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
339 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
340 .len = IEEE80211_MAX_DATA_LEN },
341 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
342 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 343 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 344 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 345 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
346 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
347 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
348 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
349 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
350 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 351 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
352 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
353 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 354 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
355 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
356 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
357 .len = NL80211_HT_CAPABILITY_LEN
358 },
1d9d9213 359 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 360 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 361 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 362 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 363 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
e39e5b5e 364 [NL80211_ATTR_SAE_DATA] = { .type = NLA_BINARY, },
f461be3e 365 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 366 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
367 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
368 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
77765eaf
VT
369 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
370 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
55682965
JB
371};
372
e31b8213 373/* policy for the key attributes */
b54452b0 374static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 375 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
376 [NL80211_KEY_IDX] = { .type = NLA_U8 },
377 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 378 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
379 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
380 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 381 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
382 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
383};
384
385/* policy for the key default flags */
386static const struct nla_policy
387nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
388 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
389 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
390};
391
ff1b6e69
JB
392/* policy for WoWLAN attributes */
393static const struct nla_policy
394nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
395 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
396 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
397 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
398 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
399 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
400 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
401 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
402 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e
JB
403 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
404};
405
406static const struct nla_policy
407nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
408 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
409 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
410 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
411 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
412 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
413 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
414 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
415 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
416 },
417 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
418 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
419 },
420 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
421 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
422 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69
JB
423};
424
e5497d76
JB
425/* policy for GTK rekey offload attributes */
426static const struct nla_policy
427nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
428 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
429 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
430 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
431};
432
a1f1c21c
LC
433static const struct nla_policy
434nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 435 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 436 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 437 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
438};
439
a043897a
HS
440/* ifidx get helper */
441static int nl80211_get_ifidx(struct netlink_callback *cb)
442{
443 int res;
444
445 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
446 nl80211_fam.attrbuf, nl80211_fam.maxattr,
447 nl80211_policy);
448 if (res)
449 return res;
450
451 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
452 return -EINVAL;
453
454 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
455 if (!res)
456 return -EINVAL;
457 return res;
458}
459
67748893
JB
460static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
461 struct netlink_callback *cb,
462 struct cfg80211_registered_device **rdev,
463 struct net_device **dev)
464{
465 int ifidx = cb->args[0];
466 int err;
467
468 if (!ifidx)
469 ifidx = nl80211_get_ifidx(cb);
470 if (ifidx < 0)
471 return ifidx;
472
473 cb->args[0] = ifidx;
474
475 rtnl_lock();
476
477 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
478 if (!*dev) {
479 err = -ENODEV;
480 goto out_rtnl;
481 }
482
483 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
484 if (IS_ERR(*rdev)) {
485 err = PTR_ERR(*rdev);
67748893
JB
486 goto out_rtnl;
487 }
488
489 return 0;
490 out_rtnl:
491 rtnl_unlock();
492 return err;
493}
494
495static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
496{
497 cfg80211_unlock_rdev(rdev);
498 rtnl_unlock();
499}
500
f4a11bb0
JB
501/* IE validation */
502static bool is_valid_ie_attr(const struct nlattr *attr)
503{
504 const u8 *pos;
505 int len;
506
507 if (!attr)
508 return true;
509
510 pos = nla_data(attr);
511 len = nla_len(attr);
512
513 while (len) {
514 u8 elemlen;
515
516 if (len < 2)
517 return false;
518 len -= 2;
519
520 elemlen = pos[1];
521 if (elemlen > len)
522 return false;
523
524 len -= elemlen;
525 pos += 2 + elemlen;
526 }
527
528 return true;
529}
530
55682965 531/* message building helper */
15e47304 532static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
533 int flags, u8 cmd)
534{
535 /* since there is no private header just add the generic one */
15e47304 536 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
537}
538
5dab3b8a
LR
539static int nl80211_msg_put_channel(struct sk_buff *msg,
540 struct ieee80211_channel *chan)
541{
9360ffd1
DM
542 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
543 chan->center_freq))
544 goto nla_put_failure;
5dab3b8a 545
9360ffd1
DM
546 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
547 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
548 goto nla_put_failure;
549 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
550 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
551 goto nla_put_failure;
552 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
553 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
554 goto nla_put_failure;
555 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
556 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
557 goto nla_put_failure;
5dab3b8a 558
9360ffd1
DM
559 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
560 DBM_TO_MBM(chan->max_power)))
561 goto nla_put_failure;
5dab3b8a
LR
562
563 return 0;
564
565 nla_put_failure:
566 return -ENOBUFS;
567}
568
55682965
JB
569/* netlink command implementations */
570
b9454e83
JB
571struct key_parse {
572 struct key_params p;
573 int idx;
e31b8213 574 int type;
b9454e83 575 bool def, defmgmt;
dbd2fd65 576 bool def_uni, def_multi;
b9454e83
JB
577};
578
579static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
580{
581 struct nlattr *tb[NL80211_KEY_MAX + 1];
582 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
583 nl80211_key_policy);
584 if (err)
585 return err;
586
587 k->def = !!tb[NL80211_KEY_DEFAULT];
588 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
589
dbd2fd65
JB
590 if (k->def) {
591 k->def_uni = true;
592 k->def_multi = true;
593 }
594 if (k->defmgmt)
595 k->def_multi = true;
596
b9454e83
JB
597 if (tb[NL80211_KEY_IDX])
598 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
599
600 if (tb[NL80211_KEY_DATA]) {
601 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
602 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
603 }
604
605 if (tb[NL80211_KEY_SEQ]) {
606 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
607 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
608 }
609
610 if (tb[NL80211_KEY_CIPHER])
611 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
612
e31b8213
JB
613 if (tb[NL80211_KEY_TYPE]) {
614 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
615 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
616 return -EINVAL;
617 }
618
dbd2fd65
JB
619 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
620 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
621 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
622 tb[NL80211_KEY_DEFAULT_TYPES],
623 nl80211_key_default_policy);
dbd2fd65
JB
624 if (err)
625 return err;
626
627 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
628 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
629 }
630
b9454e83
JB
631 return 0;
632}
633
634static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
635{
636 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
637 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
638 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
639 }
640
641 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
642 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
643 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
644 }
645
646 if (info->attrs[NL80211_ATTR_KEY_IDX])
647 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
648
649 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
650 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
651
652 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
653 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
654
dbd2fd65
JB
655 if (k->def) {
656 k->def_uni = true;
657 k->def_multi = true;
658 }
659 if (k->defmgmt)
660 k->def_multi = true;
661
e31b8213
JB
662 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
663 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
664 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
665 return -EINVAL;
666 }
667
dbd2fd65
JB
668 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
669 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
670 int err = nla_parse_nested(
671 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
672 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
673 nl80211_key_default_policy);
674 if (err)
675 return err;
676
677 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
678 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
679 }
680
b9454e83
JB
681 return 0;
682}
683
684static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
685{
686 int err;
687
688 memset(k, 0, sizeof(*k));
689 k->idx = -1;
e31b8213 690 k->type = -1;
b9454e83
JB
691
692 if (info->attrs[NL80211_ATTR_KEY])
693 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
694 else
695 err = nl80211_parse_key_old(info, k);
696
697 if (err)
698 return err;
699
700 if (k->def && k->defmgmt)
701 return -EINVAL;
702
dbd2fd65
JB
703 if (k->defmgmt) {
704 if (k->def_uni || !k->def_multi)
705 return -EINVAL;
706 }
707
b9454e83
JB
708 if (k->idx != -1) {
709 if (k->defmgmt) {
710 if (k->idx < 4 || k->idx > 5)
711 return -EINVAL;
712 } else if (k->def) {
713 if (k->idx < 0 || k->idx > 3)
714 return -EINVAL;
715 } else {
716 if (k->idx < 0 || k->idx > 5)
717 return -EINVAL;
718 }
719 }
720
721 return 0;
722}
723
fffd0934
JB
724static struct cfg80211_cached_keys *
725nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
de7044ee 726 struct nlattr *keys, bool *no_ht)
fffd0934
JB
727{
728 struct key_parse parse;
729 struct nlattr *key;
730 struct cfg80211_cached_keys *result;
731 int rem, err, def = 0;
732
733 result = kzalloc(sizeof(*result), GFP_KERNEL);
734 if (!result)
735 return ERR_PTR(-ENOMEM);
736
737 result->def = -1;
738 result->defmgmt = -1;
739
740 nla_for_each_nested(key, keys, rem) {
741 memset(&parse, 0, sizeof(parse));
742 parse.idx = -1;
743
744 err = nl80211_parse_key_new(key, &parse);
745 if (err)
746 goto error;
747 err = -EINVAL;
748 if (!parse.p.key)
749 goto error;
750 if (parse.idx < 0 || parse.idx > 4)
751 goto error;
752 if (parse.def) {
753 if (def)
754 goto error;
755 def = 1;
756 result->def = parse.idx;
dbd2fd65
JB
757 if (!parse.def_uni || !parse.def_multi)
758 goto error;
fffd0934
JB
759 } else if (parse.defmgmt)
760 goto error;
761 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 762 parse.idx, false, NULL);
fffd0934
JB
763 if (err)
764 goto error;
765 result->params[parse.idx].cipher = parse.p.cipher;
766 result->params[parse.idx].key_len = parse.p.key_len;
767 result->params[parse.idx].key = result->data[parse.idx];
768 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee
SM
769
770 if (parse.p.cipher == WLAN_CIPHER_SUITE_WEP40 ||
771 parse.p.cipher == WLAN_CIPHER_SUITE_WEP104) {
772 if (no_ht)
773 *no_ht = true;
774 }
fffd0934
JB
775 }
776
777 return result;
778 error:
779 kfree(result);
780 return ERR_PTR(err);
781}
782
783static int nl80211_key_allowed(struct wireless_dev *wdev)
784{
785 ASSERT_WDEV_LOCK(wdev);
786
fffd0934
JB
787 switch (wdev->iftype) {
788 case NL80211_IFTYPE_AP:
789 case NL80211_IFTYPE_AP_VLAN:
074ac8df 790 case NL80211_IFTYPE_P2P_GO:
ff973af7 791 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
792 break;
793 case NL80211_IFTYPE_ADHOC:
794 if (!wdev->current_bss)
795 return -ENOLINK;
796 break;
797 case NL80211_IFTYPE_STATION:
074ac8df 798 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
799 if (wdev->sme_state != CFG80211_SME_CONNECTED)
800 return -ENOLINK;
801 break;
802 default:
803 return -EINVAL;
804 }
805
806 return 0;
807}
808
7527a782
JB
809static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
810{
811 struct nlattr *nl_modes = nla_nest_start(msg, attr);
812 int i;
813
814 if (!nl_modes)
815 goto nla_put_failure;
816
817 i = 0;
818 while (ifmodes) {
9360ffd1
DM
819 if ((ifmodes & 1) && nla_put_flag(msg, i))
820 goto nla_put_failure;
7527a782
JB
821 ifmodes >>= 1;
822 i++;
823 }
824
825 nla_nest_end(msg, nl_modes);
826 return 0;
827
828nla_put_failure:
829 return -ENOBUFS;
830}
831
832static int nl80211_put_iface_combinations(struct wiphy *wiphy,
833 struct sk_buff *msg)
834{
835 struct nlattr *nl_combis;
836 int i, j;
837
838 nl_combis = nla_nest_start(msg,
839 NL80211_ATTR_INTERFACE_COMBINATIONS);
840 if (!nl_combis)
841 goto nla_put_failure;
842
843 for (i = 0; i < wiphy->n_iface_combinations; i++) {
844 const struct ieee80211_iface_combination *c;
845 struct nlattr *nl_combi, *nl_limits;
846
847 c = &wiphy->iface_combinations[i];
848
849 nl_combi = nla_nest_start(msg, i + 1);
850 if (!nl_combi)
851 goto nla_put_failure;
852
853 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
854 if (!nl_limits)
855 goto nla_put_failure;
856
857 for (j = 0; j < c->n_limits; j++) {
858 struct nlattr *nl_limit;
859
860 nl_limit = nla_nest_start(msg, j + 1);
861 if (!nl_limit)
862 goto nla_put_failure;
9360ffd1
DM
863 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
864 c->limits[j].max))
865 goto nla_put_failure;
7527a782
JB
866 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
867 c->limits[j].types))
868 goto nla_put_failure;
869 nla_nest_end(msg, nl_limit);
870 }
871
872 nla_nest_end(msg, nl_limits);
873
9360ffd1
DM
874 if (c->beacon_int_infra_match &&
875 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
876 goto nla_put_failure;
877 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
878 c->num_different_channels) ||
879 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
880 c->max_interfaces))
881 goto nla_put_failure;
11c4a075
SW
882 if (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
883 c->radar_detect_widths))
884 goto nla_put_failure;
7527a782
JB
885
886 nla_nest_end(msg, nl_combi);
887 }
888
889 nla_nest_end(msg, nl_combis);
890
891 return 0;
892nla_put_failure:
893 return -ENOBUFS;
894}
895
2a0e047e
JB
896#ifdef CONFIG_PM
897static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
898 struct sk_buff *msg)
899{
900 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan.tcp;
901 struct nlattr *nl_tcp;
902
903 if (!tcp)
904 return 0;
905
906 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
907 if (!nl_tcp)
908 return -ENOBUFS;
909
910 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
911 tcp->data_payload_max))
912 return -ENOBUFS;
913
914 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
915 tcp->data_payload_max))
916 return -ENOBUFS;
917
918 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
919 return -ENOBUFS;
920
921 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
922 sizeof(*tcp->tok), tcp->tok))
923 return -ENOBUFS;
924
925 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
926 tcp->data_interval_max))
927 return -ENOBUFS;
928
929 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
930 tcp->wake_payload_max))
931 return -ENOBUFS;
932
933 nla_nest_end(msg, nl_tcp);
934 return 0;
935}
936#endif
937
15e47304 938static int nl80211_send_wiphy(struct sk_buff *msg, u32 portid, u32 seq, int flags,
55682965
JB
939 struct cfg80211_registered_device *dev)
940{
941 void *hdr;
ee688b00
JB
942 struct nlattr *nl_bands, *nl_band;
943 struct nlattr *nl_freqs, *nl_freq;
944 struct nlattr *nl_rates, *nl_rate;
8fdc621d 945 struct nlattr *nl_cmds;
ee688b00
JB
946 enum ieee80211_band band;
947 struct ieee80211_channel *chan;
948 struct ieee80211_rate *rate;
949 int i;
2e161f78
JB
950 const struct ieee80211_txrx_stypes *mgmt_stypes =
951 dev->wiphy.mgmt_stypes;
55682965 952
15e47304 953 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_WIPHY);
55682965
JB
954 if (!hdr)
955 return -1;
956
9360ffd1
DM
957 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
958 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
959 nla_put_u32(msg, NL80211_ATTR_GENERATION,
960 cfg80211_rdev_list_generation) ||
961 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
962 dev->wiphy.retry_short) ||
963 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
964 dev->wiphy.retry_long) ||
965 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
966 dev->wiphy.frag_threshold) ||
967 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
968 dev->wiphy.rts_threshold) ||
969 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
970 dev->wiphy.coverage_class) ||
971 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
972 dev->wiphy.max_scan_ssids) ||
973 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
974 dev->wiphy.max_sched_scan_ssids) ||
975 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
976 dev->wiphy.max_scan_ie_len) ||
977 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
978 dev->wiphy.max_sched_scan_ie_len) ||
979 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
980 dev->wiphy.max_match_sets))
981 goto nla_put_failure;
982
983 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
984 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
985 goto nla_put_failure;
986 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
987 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
988 goto nla_put_failure;
989 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
990 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
991 goto nla_put_failure;
992 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
993 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
994 goto nla_put_failure;
995 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
996 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
997 goto nla_put_failure;
998 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
999 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
1000 goto nla_put_failure;
1001
1002 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1003 sizeof(u32) * dev->wiphy.n_cipher_suites,
1004 dev->wiphy.cipher_suites))
1005 goto nla_put_failure;
1006
1007 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1008 dev->wiphy.max_num_pmkids))
1009 goto nla_put_failure;
1010
1011 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
1012 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
1013 goto nla_put_failure;
1014
1015 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1016 dev->wiphy.available_antennas_tx) ||
1017 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1018 dev->wiphy.available_antennas_rx))
1019 goto nla_put_failure;
1020
1021 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
1022 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1023 dev->wiphy.probe_resp_offload))
1024 goto nla_put_failure;
87bbbe22 1025
7f531e03
BR
1026 if ((dev->wiphy.available_antennas_tx ||
1027 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
1028 u32 tx_ant = 0, rx_ant = 0;
1029 int res;
e35e4d28 1030 res = rdev_get_antenna(dev, &tx_ant, &rx_ant);
afe0cbf8 1031 if (!res) {
9360ffd1
DM
1032 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
1033 tx_ant) ||
1034 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
1035 rx_ant))
1036 goto nla_put_failure;
afe0cbf8
BR
1037 }
1038 }
1039
7527a782
JB
1040 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1041 dev->wiphy.interface_modes))
f59ac048
LR
1042 goto nla_put_failure;
1043
ee688b00
JB
1044 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1045 if (!nl_bands)
1046 goto nla_put_failure;
1047
1048 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
1049 if (!dev->wiphy.bands[band])
1050 continue;
1051
1052 nl_band = nla_nest_start(msg, band);
1053 if (!nl_band)
1054 goto nla_put_failure;
1055
d51626df 1056 /* add HT info */
9360ffd1
DM
1057 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
1058 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1059 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
1060 &dev->wiphy.bands[band]->ht_cap.mcs) ||
1061 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1062 dev->wiphy.bands[band]->ht_cap.cap) ||
1063 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1064 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
1065 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1066 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
1067 goto nla_put_failure;
d51626df 1068
bf0c111e
MP
1069 /* add VHT info */
1070 if (dev->wiphy.bands[band]->vht_cap.vht_supported &&
1071 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1072 sizeof(dev->wiphy.bands[band]->vht_cap.vht_mcs),
1073 &dev->wiphy.bands[band]->vht_cap.vht_mcs) ||
1074 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1075 dev->wiphy.bands[band]->vht_cap.cap)))
1076 goto nla_put_failure;
1077
ee688b00
JB
1078 /* add frequencies */
1079 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
1080 if (!nl_freqs)
1081 goto nla_put_failure;
1082
1083 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
1084 nl_freq = nla_nest_start(msg, i);
1085 if (!nl_freq)
1086 goto nla_put_failure;
1087
1088 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
1089
1090 if (nl80211_msg_put_channel(msg, chan))
1091 goto nla_put_failure;
e2f367f2 1092
ee688b00
JB
1093 nla_nest_end(msg, nl_freq);
1094 }
1095
1096 nla_nest_end(msg, nl_freqs);
1097
1098 /* add bitrates */
1099 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1100 if (!nl_rates)
1101 goto nla_put_failure;
1102
1103 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
1104 nl_rate = nla_nest_start(msg, i);
1105 if (!nl_rate)
1106 goto nla_put_failure;
1107
1108 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
1109 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1110 rate->bitrate))
1111 goto nla_put_failure;
1112 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1113 nla_put_flag(msg,
1114 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1115 goto nla_put_failure;
ee688b00
JB
1116
1117 nla_nest_end(msg, nl_rate);
1118 }
1119
1120 nla_nest_end(msg, nl_rates);
1121
1122 nla_nest_end(msg, nl_band);
1123 }
1124 nla_nest_end(msg, nl_bands);
1125
8fdc621d
JB
1126 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1127 if (!nl_cmds)
1128 goto nla_put_failure;
1129
1130 i = 0;
1131#define CMD(op, n) \
1132 do { \
1133 if (dev->ops->op) { \
1134 i++; \
9360ffd1
DM
1135 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1136 goto nla_put_failure; \
8fdc621d
JB
1137 } \
1138 } while (0)
1139
1140 CMD(add_virtual_intf, NEW_INTERFACE);
1141 CMD(change_virtual_intf, SET_INTERFACE);
1142 CMD(add_key, NEW_KEY);
8860020e 1143 CMD(start_ap, START_AP);
8fdc621d
JB
1144 CMD(add_station, NEW_STATION);
1145 CMD(add_mpath, NEW_MPATH);
24bdd9f4 1146 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 1147 CMD(change_bss, SET_BSS);
636a5d36
JM
1148 CMD(auth, AUTHENTICATE);
1149 CMD(assoc, ASSOCIATE);
1150 CMD(deauth, DEAUTHENTICATE);
1151 CMD(disassoc, DISASSOCIATE);
04a773ad 1152 CMD(join_ibss, JOIN_IBSS);
29cbe68c 1153 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
1154 CMD(set_pmksa, SET_PMKSA);
1155 CMD(del_pmksa, DEL_PMKSA);
1156 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
1157 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1158 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 1159 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 1160 CMD(mgmt_tx, FRAME);
f7ca38df 1161 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 1162 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 1163 i++;
9360ffd1
DM
1164 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1165 goto nla_put_failure;
463d0183 1166 }
e8c9bd5b 1167 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 1168 dev->ops->join_mesh) {
aa430da4
JB
1169 i++;
1170 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1171 goto nla_put_failure;
1172 }
e8347eba 1173 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
1174 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1175 CMD(tdls_mgmt, TDLS_MGMT);
1176 CMD(tdls_oper, TDLS_OPER);
1177 }
807f8a8c
LC
1178 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1179 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 1180 CMD(probe_client, PROBE_CLIENT);
1d9d9213 1181 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
1182 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1183 i++;
9360ffd1
DM
1184 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1185 goto nla_put_failure;
5e760230 1186 }
98104fde 1187 CMD(start_p2p_device, START_P2P_DEVICE);
f4e583c8 1188 CMD(set_mcast_rate, SET_MCAST_RATE);
8fdc621d 1189
4745fc09
KV
1190#ifdef CONFIG_NL80211_TESTMODE
1191 CMD(testmode_cmd, TESTMODE);
1192#endif
1193
8fdc621d 1194#undef CMD
b23aa676 1195
6829c878 1196 if (dev->ops->connect || dev->ops->auth) {
b23aa676 1197 i++;
9360ffd1
DM
1198 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1199 goto nla_put_failure;
b23aa676
SO
1200 }
1201
6829c878 1202 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 1203 i++;
9360ffd1
DM
1204 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1205 goto nla_put_failure;
b23aa676
SO
1206 }
1207
8fdc621d
JB
1208 nla_nest_end(msg, nl_cmds);
1209
7c4ef712 1210 if (dev->ops->remain_on_channel &&
9360ffd1
DM
1211 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1212 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1213 dev->wiphy.max_remain_on_channel_duration))
1214 goto nla_put_failure;
a293911d 1215
9360ffd1
DM
1216 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1217 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1218 goto nla_put_failure;
f7ca38df 1219
2e161f78
JB
1220 if (mgmt_stypes) {
1221 u16 stypes;
1222 struct nlattr *nl_ftypes, *nl_ifs;
1223 enum nl80211_iftype ift;
1224
1225 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1226 if (!nl_ifs)
1227 goto nla_put_failure;
1228
1229 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1230 nl_ftypes = nla_nest_start(msg, ift);
1231 if (!nl_ftypes)
1232 goto nla_put_failure;
1233 i = 0;
1234 stypes = mgmt_stypes[ift].tx;
1235 while (stypes) {
9360ffd1
DM
1236 if ((stypes & 1) &&
1237 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1238 (i << 4) | IEEE80211_FTYPE_MGMT))
1239 goto nla_put_failure;
2e161f78
JB
1240 stypes >>= 1;
1241 i++;
1242 }
1243 nla_nest_end(msg, nl_ftypes);
1244 }
1245
74b70a4e
JB
1246 nla_nest_end(msg, nl_ifs);
1247
2e161f78
JB
1248 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1249 if (!nl_ifs)
1250 goto nla_put_failure;
1251
1252 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1253 nl_ftypes = nla_nest_start(msg, ift);
1254 if (!nl_ftypes)
1255 goto nla_put_failure;
1256 i = 0;
1257 stypes = mgmt_stypes[ift].rx;
1258 while (stypes) {
9360ffd1
DM
1259 if ((stypes & 1) &&
1260 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1261 (i << 4) | IEEE80211_FTYPE_MGMT))
1262 goto nla_put_failure;
2e161f78
JB
1263 stypes >>= 1;
1264 i++;
1265 }
1266 nla_nest_end(msg, nl_ftypes);
1267 }
1268 nla_nest_end(msg, nl_ifs);
1269 }
1270
dfb89c56 1271#ifdef CONFIG_PM
ff1b6e69
JB
1272 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1273 struct nlattr *nl_wowlan;
1274
1275 nl_wowlan = nla_nest_start(msg,
1276 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1277 if (!nl_wowlan)
1278 goto nla_put_failure;
1279
9360ffd1
DM
1280 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1281 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1282 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1283 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1284 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1285 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1286 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1287 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1288 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1289 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1290 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1291 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1292 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1293 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1294 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1295 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1296 goto nla_put_failure;
ff1b6e69
JB
1297 if (dev->wiphy.wowlan.n_patterns) {
1298 struct nl80211_wowlan_pattern_support pat = {
1299 .max_patterns = dev->wiphy.wowlan.n_patterns,
1300 .min_pattern_len =
1301 dev->wiphy.wowlan.pattern_min_len,
1302 .max_pattern_len =
1303 dev->wiphy.wowlan.pattern_max_len,
bb92d199
AK
1304 .max_pkt_offset =
1305 dev->wiphy.wowlan.max_pkt_offset,
ff1b6e69 1306 };
9360ffd1
DM
1307 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1308 sizeof(pat), &pat))
1309 goto nla_put_failure;
ff1b6e69
JB
1310 }
1311
2a0e047e
JB
1312 if (nl80211_send_wowlan_tcp_caps(dev, msg))
1313 goto nla_put_failure;
1314
ff1b6e69
JB
1315 nla_nest_end(msg, nl_wowlan);
1316 }
dfb89c56 1317#endif
ff1b6e69 1318
7527a782
JB
1319 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1320 dev->wiphy.software_iftypes))
1321 goto nla_put_failure;
1322
1323 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1324 goto nla_put_failure;
1325
9360ffd1
DM
1326 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1327 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1328 dev->wiphy.ap_sme_capa))
1329 goto nla_put_failure;
562a7480 1330
9360ffd1
DM
1331 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1332 dev->wiphy.features))
1333 goto nla_put_failure;
1f074bd8 1334
9360ffd1
DM
1335 if (dev->wiphy.ht_capa_mod_mask &&
1336 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1337 sizeof(*dev->wiphy.ht_capa_mod_mask),
1338 dev->wiphy.ht_capa_mod_mask))
1339 goto nla_put_failure;
7e7c8926 1340
77765eaf
VT
1341 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1342 dev->wiphy.max_acl_mac_addrs &&
1343 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1344 dev->wiphy.max_acl_mac_addrs))
1345 goto nla_put_failure;
1346
55682965
JB
1347 return genlmsg_end(msg, hdr);
1348
1349 nla_put_failure:
bc3ed28c
TG
1350 genlmsg_cancel(msg, hdr);
1351 return -EMSGSIZE;
55682965
JB
1352}
1353
1354static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1355{
1356 int idx = 0;
1357 int start = cb->args[0];
1358 struct cfg80211_registered_device *dev;
1359
a1794390 1360 mutex_lock(&cfg80211_mutex);
79c97e97 1361 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1362 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1363 continue;
b4637271 1364 if (++idx <= start)
55682965 1365 continue;
15e47304 1366 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).portid,
55682965 1367 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1368 dev) < 0) {
1369 idx--;
55682965 1370 break;
b4637271 1371 }
55682965 1372 }
a1794390 1373 mutex_unlock(&cfg80211_mutex);
55682965
JB
1374
1375 cb->args[0] = idx;
1376
1377 return skb->len;
1378}
1379
1380static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1381{
1382 struct sk_buff *msg;
4c476991 1383 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1384
fd2120ca 1385 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1386 if (!msg)
4c476991 1387 return -ENOMEM;
55682965 1388
15e47304 1389 if (nl80211_send_wiphy(msg, info->snd_portid, info->snd_seq, 0, dev) < 0) {
4c476991
JB
1390 nlmsg_free(msg);
1391 return -ENOBUFS;
1392 }
55682965 1393
134e6375 1394 return genlmsg_reply(msg, info);
55682965
JB
1395}
1396
31888487
JM
1397static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1398 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1399 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1400 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1401 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1402 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1403};
1404
1405static int parse_txq_params(struct nlattr *tb[],
1406 struct ieee80211_txq_params *txq_params)
1407{
a3304b0a 1408 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1409 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1410 !tb[NL80211_TXQ_ATTR_AIFS])
1411 return -EINVAL;
1412
a3304b0a 1413 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1414 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1415 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1416 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1417 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1418
a3304b0a
JB
1419 if (txq_params->ac >= NL80211_NUM_ACS)
1420 return -EINVAL;
1421
31888487
JM
1422 return 0;
1423}
1424
f444de05
JB
1425static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1426{
1427 /*
cc1d2806
JB
1428 * You can only set the channel explicitly for WDS interfaces,
1429 * all others have their channel managed via their respective
1430 * "establish a connection" command (connect, join, ...)
1431 *
1432 * For AP/GO and mesh mode, the channel can be set with the
1433 * channel userspace API, but is only stored and passed to the
1434 * low-level driver when the AP starts or the mesh is joined.
1435 * This is for backward compatibility, userspace can also give
1436 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1437 *
1438 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1439 * whatever else is going on, so they have their own special
1440 * operation to set the monitor channel if possible.
f444de05
JB
1441 */
1442 return !wdev ||
1443 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1444 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1445 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1446 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1447}
1448
683b6d3b
JB
1449static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
1450 struct genl_info *info,
1451 struct cfg80211_chan_def *chandef)
1452{
dbeca2ea 1453 u32 control_freq;
683b6d3b
JB
1454
1455 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1456 return -EINVAL;
1457
1458 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1459
1460 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
1461 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
1462 chandef->center_freq1 = control_freq;
1463 chandef->center_freq2 = 0;
683b6d3b
JB
1464
1465 /* Primary channel not allowed */
1466 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
1467 return -EINVAL;
1468
3d9d1d66
JB
1469 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1470 enum nl80211_channel_type chantype;
1471
1472 chantype = nla_get_u32(
1473 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1474
1475 switch (chantype) {
1476 case NL80211_CHAN_NO_HT:
1477 case NL80211_CHAN_HT20:
1478 case NL80211_CHAN_HT40PLUS:
1479 case NL80211_CHAN_HT40MINUS:
1480 cfg80211_chandef_create(chandef, chandef->chan,
1481 chantype);
1482 break;
1483 default:
1484 return -EINVAL;
1485 }
1486 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
1487 chandef->width =
1488 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
1489 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
1490 chandef->center_freq1 =
1491 nla_get_u32(
1492 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
1493 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
1494 chandef->center_freq2 =
1495 nla_get_u32(
1496 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
1497 }
1498
9f5e8f6e 1499 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
1500 return -EINVAL;
1501
9f5e8f6e
JB
1502 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
1503 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
1504 return -EINVAL;
1505
683b6d3b
JB
1506 return 0;
1507}
1508
f444de05
JB
1509static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1510 struct wireless_dev *wdev,
1511 struct genl_info *info)
1512{
683b6d3b 1513 struct cfg80211_chan_def chandef;
f444de05 1514 int result;
e8c9bd5b
JB
1515 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1516
1517 if (wdev)
1518 iftype = wdev->iftype;
f444de05 1519
f444de05
JB
1520 if (!nl80211_can_set_dev_channel(wdev))
1521 return -EOPNOTSUPP;
1522
683b6d3b
JB
1523 result = nl80211_parse_chandef(rdev, info, &chandef);
1524 if (result)
1525 return result;
f444de05
JB
1526
1527 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1528 switch (iftype) {
aa430da4
JB
1529 case NL80211_IFTYPE_AP:
1530 case NL80211_IFTYPE_P2P_GO:
1531 if (wdev->beacon_interval) {
1532 result = -EBUSY;
1533 break;
1534 }
683b6d3b 1535 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &chandef)) {
aa430da4
JB
1536 result = -EINVAL;
1537 break;
1538 }
683b6d3b 1539 wdev->preset_chandef = chandef;
aa430da4
JB
1540 result = 0;
1541 break;
cc1d2806 1542 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 1543 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 1544 break;
e8c9bd5b 1545 case NL80211_IFTYPE_MONITOR:
683b6d3b 1546 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 1547 break;
aa430da4 1548 default:
e8c9bd5b 1549 result = -EINVAL;
f444de05
JB
1550 }
1551 mutex_unlock(&rdev->devlist_mtx);
1552
1553 return result;
1554}
1555
1556static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1557{
4c476991
JB
1558 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1559 struct net_device *netdev = info->user_ptr[1];
f444de05 1560
4c476991 1561 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1562}
1563
e8347eba
BJ
1564static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1565{
43b19952
JB
1566 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1567 struct net_device *dev = info->user_ptr[1];
1568 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1569 const u8 *bssid;
e8347eba
BJ
1570
1571 if (!info->attrs[NL80211_ATTR_MAC])
1572 return -EINVAL;
1573
43b19952
JB
1574 if (netif_running(dev))
1575 return -EBUSY;
e8347eba 1576
43b19952
JB
1577 if (!rdev->ops->set_wds_peer)
1578 return -EOPNOTSUPP;
e8347eba 1579
43b19952
JB
1580 if (wdev->iftype != NL80211_IFTYPE_WDS)
1581 return -EOPNOTSUPP;
e8347eba
BJ
1582
1583 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 1584 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
1585}
1586
1587
55682965
JB
1588static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1589{
1590 struct cfg80211_registered_device *rdev;
f444de05
JB
1591 struct net_device *netdev = NULL;
1592 struct wireless_dev *wdev;
a1e567c8 1593 int result = 0, rem_txq_params = 0;
31888487 1594 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1595 u32 changed;
1596 u8 retry_short = 0, retry_long = 0;
1597 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1598 u8 coverage_class = 0;
55682965 1599
f444de05
JB
1600 /*
1601 * Try to find the wiphy and netdev. Normally this
1602 * function shouldn't need the netdev, but this is
1603 * done for backward compatibility -- previously
1604 * setting the channel was done per wiphy, but now
1605 * it is per netdev. Previous userland like hostapd
1606 * also passed a netdev to set_wiphy, so that it is
1607 * possible to let that go to the right netdev!
1608 */
4bbf4d56
JB
1609 mutex_lock(&cfg80211_mutex);
1610
f444de05
JB
1611 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1612 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1613
1614 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1615 if (netdev && netdev->ieee80211_ptr) {
1616 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1617 mutex_lock(&rdev->mtx);
1618 } else
1619 netdev = NULL;
4bbf4d56
JB
1620 }
1621
f444de05 1622 if (!netdev) {
878d9ec7
JB
1623 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1624 info->attrs);
f444de05
JB
1625 if (IS_ERR(rdev)) {
1626 mutex_unlock(&cfg80211_mutex);
4c476991 1627 return PTR_ERR(rdev);
f444de05
JB
1628 }
1629 wdev = NULL;
1630 netdev = NULL;
1631 result = 0;
1632
1633 mutex_lock(&rdev->mtx);
71fe96bf 1634 } else
f444de05 1635 wdev = netdev->ieee80211_ptr;
f444de05
JB
1636
1637 /*
1638 * end workaround code, by now the rdev is available
1639 * and locked, and wdev may or may not be NULL.
1640 */
4bbf4d56
JB
1641
1642 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1643 result = cfg80211_dev_rename(
1644 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1645
1646 mutex_unlock(&cfg80211_mutex);
1647
1648 if (result)
1649 goto bad_res;
31888487
JM
1650
1651 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1652 struct ieee80211_txq_params txq_params;
1653 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1654
1655 if (!rdev->ops->set_txq_params) {
1656 result = -EOPNOTSUPP;
1657 goto bad_res;
1658 }
1659
f70f01c2
EP
1660 if (!netdev) {
1661 result = -EINVAL;
1662 goto bad_res;
1663 }
1664
133a3ff2
JB
1665 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1666 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1667 result = -EINVAL;
1668 goto bad_res;
1669 }
1670
2b5f8b0b
JB
1671 if (!netif_running(netdev)) {
1672 result = -ENETDOWN;
1673 goto bad_res;
1674 }
1675
31888487
JM
1676 nla_for_each_nested(nl_txq_params,
1677 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1678 rem_txq_params) {
1679 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1680 nla_data(nl_txq_params),
1681 nla_len(nl_txq_params),
1682 txq_params_policy);
1683 result = parse_txq_params(tb, &txq_params);
1684 if (result)
1685 goto bad_res;
1686
e35e4d28
HG
1687 result = rdev_set_txq_params(rdev, netdev,
1688 &txq_params);
31888487
JM
1689 if (result)
1690 goto bad_res;
1691 }
1692 }
55682965 1693
72bdcf34 1694 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
71fe96bf
JB
1695 result = __nl80211_set_channel(rdev,
1696 nl80211_can_set_dev_channel(wdev) ? wdev : NULL,
1697 info);
72bdcf34
JM
1698 if (result)
1699 goto bad_res;
1700 }
1701
98d2ff8b 1702 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 1703 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
1704 enum nl80211_tx_power_setting type;
1705 int idx, mbm = 0;
1706
c8442118
JB
1707 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
1708 txp_wdev = NULL;
1709
98d2ff8b 1710 if (!rdev->ops->set_tx_power) {
60ea385f 1711 result = -EOPNOTSUPP;
98d2ff8b
JO
1712 goto bad_res;
1713 }
1714
1715 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1716 type = nla_get_u32(info->attrs[idx]);
1717
1718 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1719 (type != NL80211_TX_POWER_AUTOMATIC)) {
1720 result = -EINVAL;
1721 goto bad_res;
1722 }
1723
1724 if (type != NL80211_TX_POWER_AUTOMATIC) {
1725 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1726 mbm = nla_get_u32(info->attrs[idx]);
1727 }
1728
c8442118 1729 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b
JO
1730 if (result)
1731 goto bad_res;
1732 }
1733
afe0cbf8
BR
1734 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1735 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1736 u32 tx_ant, rx_ant;
7f531e03
BR
1737 if ((!rdev->wiphy.available_antennas_tx &&
1738 !rdev->wiphy.available_antennas_rx) ||
1739 !rdev->ops->set_antenna) {
afe0cbf8
BR
1740 result = -EOPNOTSUPP;
1741 goto bad_res;
1742 }
1743
1744 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1745 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1746
a7ffac95 1747 /* reject antenna configurations which don't match the
7f531e03
BR
1748 * available antenna masks, except for the "all" mask */
1749 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1750 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1751 result = -EINVAL;
1752 goto bad_res;
1753 }
1754
7f531e03
BR
1755 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1756 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1757
e35e4d28 1758 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8
BR
1759 if (result)
1760 goto bad_res;
1761 }
1762
b9a5f8ca
JM
1763 changed = 0;
1764
1765 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1766 retry_short = nla_get_u8(
1767 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1768 if (retry_short == 0) {
1769 result = -EINVAL;
1770 goto bad_res;
1771 }
1772 changed |= WIPHY_PARAM_RETRY_SHORT;
1773 }
1774
1775 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1776 retry_long = nla_get_u8(
1777 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1778 if (retry_long == 0) {
1779 result = -EINVAL;
1780 goto bad_res;
1781 }
1782 changed |= WIPHY_PARAM_RETRY_LONG;
1783 }
1784
1785 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1786 frag_threshold = nla_get_u32(
1787 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1788 if (frag_threshold < 256) {
1789 result = -EINVAL;
1790 goto bad_res;
1791 }
1792 if (frag_threshold != (u32) -1) {
1793 /*
1794 * Fragments (apart from the last one) are required to
1795 * have even length. Make the fragmentation code
1796 * simpler by stripping LSB should someone try to use
1797 * odd threshold value.
1798 */
1799 frag_threshold &= ~0x1;
1800 }
1801 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1802 }
1803
1804 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1805 rts_threshold = nla_get_u32(
1806 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1807 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1808 }
1809
81077e82
LT
1810 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1811 coverage_class = nla_get_u8(
1812 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1813 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1814 }
1815
b9a5f8ca
JM
1816 if (changed) {
1817 u8 old_retry_short, old_retry_long;
1818 u32 old_frag_threshold, old_rts_threshold;
81077e82 1819 u8 old_coverage_class;
b9a5f8ca
JM
1820
1821 if (!rdev->ops->set_wiphy_params) {
1822 result = -EOPNOTSUPP;
1823 goto bad_res;
1824 }
1825
1826 old_retry_short = rdev->wiphy.retry_short;
1827 old_retry_long = rdev->wiphy.retry_long;
1828 old_frag_threshold = rdev->wiphy.frag_threshold;
1829 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1830 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1831
1832 if (changed & WIPHY_PARAM_RETRY_SHORT)
1833 rdev->wiphy.retry_short = retry_short;
1834 if (changed & WIPHY_PARAM_RETRY_LONG)
1835 rdev->wiphy.retry_long = retry_long;
1836 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1837 rdev->wiphy.frag_threshold = frag_threshold;
1838 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1839 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1840 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1841 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 1842
e35e4d28 1843 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
1844 if (result) {
1845 rdev->wiphy.retry_short = old_retry_short;
1846 rdev->wiphy.retry_long = old_retry_long;
1847 rdev->wiphy.frag_threshold = old_frag_threshold;
1848 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1849 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1850 }
1851 }
72bdcf34 1852
306d6112 1853 bad_res:
4bbf4d56 1854 mutex_unlock(&rdev->mtx);
f444de05
JB
1855 if (netdev)
1856 dev_put(netdev);
55682965
JB
1857 return result;
1858}
1859
71bbc994
JB
1860static inline u64 wdev_id(struct wireless_dev *wdev)
1861{
1862 return (u64)wdev->identifier |
1863 ((u64)wiphy_to_dev(wdev->wiphy)->wiphy_idx << 32);
1864}
55682965 1865
683b6d3b
JB
1866static int nl80211_send_chandef(struct sk_buff *msg,
1867 struct cfg80211_chan_def *chandef)
1868{
9f5e8f6e 1869 WARN_ON(!cfg80211_chandef_valid(chandef));
3d9d1d66 1870
683b6d3b
JB
1871 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1872 chandef->chan->center_freq))
1873 return -ENOBUFS;
3d9d1d66
JB
1874 switch (chandef->width) {
1875 case NL80211_CHAN_WIDTH_20_NOHT:
1876 case NL80211_CHAN_WIDTH_20:
1877 case NL80211_CHAN_WIDTH_40:
1878 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1879 cfg80211_get_chandef_type(chandef)))
1880 return -ENOBUFS;
1881 break;
1882 default:
1883 break;
1884 }
1885 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
1886 return -ENOBUFS;
1887 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
1888 return -ENOBUFS;
1889 if (chandef->center_freq2 &&
1890 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
1891 return -ENOBUFS;
1892 return 0;
1893}
1894
15e47304 1895static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 1896 struct cfg80211_registered_device *rdev,
72fb2abc 1897 struct wireless_dev *wdev)
55682965 1898{
72fb2abc 1899 struct net_device *dev = wdev->netdev;
55682965
JB
1900 void *hdr;
1901
15e47304 1902 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_INTERFACE);
55682965
JB
1903 if (!hdr)
1904 return -1;
1905
72fb2abc
JB
1906 if (dev &&
1907 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 1908 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
1909 goto nla_put_failure;
1910
1911 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1912 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
71bbc994 1913 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
98104fde 1914 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
1915 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1916 rdev->devlist_generation ^
1917 (cfg80211_rdev_list_generation << 2)))
1918 goto nla_put_failure;
f5ea9120 1919
5b7ccaf3 1920 if (rdev->ops->get_channel) {
683b6d3b
JB
1921 int ret;
1922 struct cfg80211_chan_def chandef;
1923
1924 ret = rdev_get_channel(rdev, wdev, &chandef);
1925 if (ret == 0) {
1926 if (nl80211_send_chandef(msg, &chandef))
1927 goto nla_put_failure;
1928 }
d91df0e3
PF
1929 }
1930
b84e7a05
AQ
1931 if (wdev->ssid_len) {
1932 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
1933 goto nla_put_failure;
1934 }
1935
55682965
JB
1936 return genlmsg_end(msg, hdr);
1937
1938 nla_put_failure:
bc3ed28c
TG
1939 genlmsg_cancel(msg, hdr);
1940 return -EMSGSIZE;
55682965
JB
1941}
1942
1943static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1944{
1945 int wp_idx = 0;
1946 int if_idx = 0;
1947 int wp_start = cb->args[0];
1948 int if_start = cb->args[1];
f5ea9120 1949 struct cfg80211_registered_device *rdev;
55682965
JB
1950 struct wireless_dev *wdev;
1951
a1794390 1952 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1953 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1954 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1955 continue;
bba95fef
JB
1956 if (wp_idx < wp_start) {
1957 wp_idx++;
55682965 1958 continue;
bba95fef 1959 }
55682965
JB
1960 if_idx = 0;
1961
f5ea9120 1962 mutex_lock(&rdev->devlist_mtx);
89a54e48 1963 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
1964 if (if_idx < if_start) {
1965 if_idx++;
55682965 1966 continue;
bba95fef 1967 }
15e47304 1968 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 1969 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 1970 rdev, wdev) < 0) {
f5ea9120 1971 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1972 goto out;
1973 }
1974 if_idx++;
55682965 1975 }
f5ea9120 1976 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1977
1978 wp_idx++;
55682965 1979 }
bba95fef 1980 out:
a1794390 1981 mutex_unlock(&cfg80211_mutex);
55682965
JB
1982
1983 cb->args[0] = wp_idx;
1984 cb->args[1] = if_idx;
1985
1986 return skb->len;
1987}
1988
1989static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1990{
1991 struct sk_buff *msg;
4c476991 1992 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 1993 struct wireless_dev *wdev = info->user_ptr[1];
55682965 1994
fd2120ca 1995 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1996 if (!msg)
4c476991 1997 return -ENOMEM;
55682965 1998
15e47304 1999 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
72fb2abc 2000 dev, wdev) < 0) {
4c476991
JB
2001 nlmsg_free(msg);
2002 return -ENOBUFS;
2003 }
55682965 2004
134e6375 2005 return genlmsg_reply(msg, info);
55682965
JB
2006}
2007
66f7ac50
MW
2008static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2009 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2010 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2011 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2012 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2013 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
2014};
2015
2016static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2017{
2018 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2019 int flag;
2020
2021 *mntrflags = 0;
2022
2023 if (!nla)
2024 return -EINVAL;
2025
2026 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
2027 nla, mntr_flags_policy))
2028 return -EINVAL;
2029
2030 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2031 if (flags[flag])
2032 *mntrflags |= (1<<flag);
2033
2034 return 0;
2035}
2036
9bc383de 2037static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2038 struct net_device *netdev, u8 use_4addr,
2039 enum nl80211_iftype iftype)
9bc383de 2040{
ad4bb6f8 2041 if (!use_4addr) {
f350a0a8 2042 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2043 return -EBUSY;
9bc383de 2044 return 0;
ad4bb6f8 2045 }
9bc383de
JB
2046
2047 switch (iftype) {
2048 case NL80211_IFTYPE_AP_VLAN:
2049 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2050 return 0;
2051 break;
2052 case NL80211_IFTYPE_STATION:
2053 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2054 return 0;
2055 break;
2056 default:
2057 break;
2058 }
2059
2060 return -EOPNOTSUPP;
2061}
2062
55682965
JB
2063static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2064{
4c476991 2065 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2066 struct vif_params params;
e36d56b6 2067 int err;
04a773ad 2068 enum nl80211_iftype otype, ntype;
4c476991 2069 struct net_device *dev = info->user_ptr[1];
92ffe055 2070 u32 _flags, *flags = NULL;
ac7f9cfa 2071 bool change = false;
55682965 2072
2ec600d6
LCC
2073 memset(&params, 0, sizeof(params));
2074
04a773ad 2075 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2076
723b038d 2077 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2078 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2079 if (otype != ntype)
ac7f9cfa 2080 change = true;
4c476991
JB
2081 if (ntype > NL80211_IFTYPE_MAX)
2082 return -EINVAL;
723b038d
JB
2083 }
2084
92ffe055 2085 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2086 struct wireless_dev *wdev = dev->ieee80211_ptr;
2087
4c476991
JB
2088 if (ntype != NL80211_IFTYPE_MESH_POINT)
2089 return -EINVAL;
29cbe68c
JB
2090 if (netif_running(dev))
2091 return -EBUSY;
2092
2093 wdev_lock(wdev);
2094 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2095 IEEE80211_MAX_MESH_ID_LEN);
2096 wdev->mesh_id_up_len =
2097 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2098 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2099 wdev->mesh_id_up_len);
2100 wdev_unlock(wdev);
2ec600d6
LCC
2101 }
2102
8b787643
FF
2103 if (info->attrs[NL80211_ATTR_4ADDR]) {
2104 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2105 change = true;
ad4bb6f8 2106 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2107 if (err)
4c476991 2108 return err;
8b787643
FF
2109 } else {
2110 params.use_4addr = -1;
2111 }
2112
92ffe055 2113 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
2114 if (ntype != NL80211_IFTYPE_MONITOR)
2115 return -EINVAL;
92ffe055
JB
2116 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2117 &_flags);
ac7f9cfa 2118 if (err)
4c476991 2119 return err;
ac7f9cfa
JB
2120
2121 flags = &_flags;
2122 change = true;
92ffe055 2123 }
3b85875a 2124
ac7f9cfa 2125 if (change)
3d54d255 2126 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
2127 else
2128 err = 0;
60719ffd 2129
9bc383de
JB
2130 if (!err && params.use_4addr != -1)
2131 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2132
55682965
JB
2133 return err;
2134}
2135
2136static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2137{
4c476991 2138 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2139 struct vif_params params;
84efbb84 2140 struct wireless_dev *wdev;
1c90f9d4 2141 struct sk_buff *msg;
55682965
JB
2142 int err;
2143 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 2144 u32 flags;
55682965 2145
2ec600d6
LCC
2146 memset(&params, 0, sizeof(params));
2147
55682965
JB
2148 if (!info->attrs[NL80211_ATTR_IFNAME])
2149 return -EINVAL;
2150
2151 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2152 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2153 if (type > NL80211_IFTYPE_MAX)
2154 return -EINVAL;
2155 }
2156
79c97e97 2157 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2158 !(rdev->wiphy.interface_modes & (1 << type)))
2159 return -EOPNOTSUPP;
55682965 2160
1c18f145
AS
2161 if (type == NL80211_IFTYPE_P2P_DEVICE && info->attrs[NL80211_ATTR_MAC]) {
2162 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2163 ETH_ALEN);
2164 if (!is_valid_ether_addr(params.macaddr))
2165 return -EADDRNOTAVAIL;
2166 }
2167
9bc383de 2168 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2169 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2170 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2171 if (err)
4c476991 2172 return err;
9bc383de 2173 }
8b787643 2174
1c90f9d4
JB
2175 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2176 if (!msg)
2177 return -ENOMEM;
2178
66f7ac50
MW
2179 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
2180 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2181 &flags);
e35e4d28
HG
2182 wdev = rdev_add_virtual_intf(rdev,
2183 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2184 type, err ? NULL : &flags, &params);
1c90f9d4
JB
2185 if (IS_ERR(wdev)) {
2186 nlmsg_free(msg);
84efbb84 2187 return PTR_ERR(wdev);
1c90f9d4 2188 }
2ec600d6 2189
98104fde
JB
2190 switch (type) {
2191 case NL80211_IFTYPE_MESH_POINT:
2192 if (!info->attrs[NL80211_ATTR_MESH_ID])
2193 break;
29cbe68c
JB
2194 wdev_lock(wdev);
2195 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2196 IEEE80211_MAX_MESH_ID_LEN);
2197 wdev->mesh_id_up_len =
2198 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2199 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2200 wdev->mesh_id_up_len);
2201 wdev_unlock(wdev);
98104fde
JB
2202 break;
2203 case NL80211_IFTYPE_P2P_DEVICE:
2204 /*
2205 * P2P Device doesn't have a netdev, so doesn't go
2206 * through the netdev notifier and must be added here
2207 */
2208 mutex_init(&wdev->mtx);
2209 INIT_LIST_HEAD(&wdev->event_list);
2210 spin_lock_init(&wdev->event_lock);
2211 INIT_LIST_HEAD(&wdev->mgmt_registrations);
2212 spin_lock_init(&wdev->mgmt_registrations_lock);
2213
2214 mutex_lock(&rdev->devlist_mtx);
2215 wdev->identifier = ++rdev->wdev_id;
2216 list_add_rcu(&wdev->list, &rdev->wdev_list);
2217 rdev->devlist_generation++;
2218 mutex_unlock(&rdev->devlist_mtx);
2219 break;
2220 default:
2221 break;
29cbe68c
JB
2222 }
2223
15e47304 2224 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
1c90f9d4
JB
2225 rdev, wdev) < 0) {
2226 nlmsg_free(msg);
2227 return -ENOBUFS;
2228 }
2229
2230 return genlmsg_reply(msg, info);
55682965
JB
2231}
2232
2233static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2234{
4c476991 2235 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 2236 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2237
4c476991
JB
2238 if (!rdev->ops->del_virtual_intf)
2239 return -EOPNOTSUPP;
55682965 2240
84efbb84
JB
2241 /*
2242 * If we remove a wireless device without a netdev then clear
2243 * user_ptr[1] so that nl80211_post_doit won't dereference it
2244 * to check if it needs to do dev_put(). Otherwise it crashes
2245 * since the wdev has been freed, unlike with a netdev where
2246 * we need the dev_put() for the netdev to really be freed.
2247 */
2248 if (!wdev->netdev)
2249 info->user_ptr[1] = NULL;
2250
e35e4d28 2251 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
2252}
2253
1d9d9213
SW
2254static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2255{
2256 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2257 struct net_device *dev = info->user_ptr[1];
2258 u16 noack_map;
2259
2260 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2261 return -EINVAL;
2262
2263 if (!rdev->ops->set_noack_map)
2264 return -EOPNOTSUPP;
2265
2266 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2267
e35e4d28 2268 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
2269}
2270
41ade00f
JB
2271struct get_key_cookie {
2272 struct sk_buff *msg;
2273 int error;
b9454e83 2274 int idx;
41ade00f
JB
2275};
2276
2277static void get_key_callback(void *c, struct key_params *params)
2278{
b9454e83 2279 struct nlattr *key;
41ade00f
JB
2280 struct get_key_cookie *cookie = c;
2281
9360ffd1
DM
2282 if ((params->key &&
2283 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2284 params->key_len, params->key)) ||
2285 (params->seq &&
2286 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2287 params->seq_len, params->seq)) ||
2288 (params->cipher &&
2289 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2290 params->cipher)))
2291 goto nla_put_failure;
41ade00f 2292
b9454e83
JB
2293 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2294 if (!key)
2295 goto nla_put_failure;
2296
9360ffd1
DM
2297 if ((params->key &&
2298 nla_put(cookie->msg, NL80211_KEY_DATA,
2299 params->key_len, params->key)) ||
2300 (params->seq &&
2301 nla_put(cookie->msg, NL80211_KEY_SEQ,
2302 params->seq_len, params->seq)) ||
2303 (params->cipher &&
2304 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2305 params->cipher)))
2306 goto nla_put_failure;
b9454e83 2307
9360ffd1
DM
2308 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2309 goto nla_put_failure;
b9454e83
JB
2310
2311 nla_nest_end(cookie->msg, key);
2312
41ade00f
JB
2313 return;
2314 nla_put_failure:
2315 cookie->error = 1;
2316}
2317
2318static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2319{
4c476991 2320 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2321 int err;
4c476991 2322 struct net_device *dev = info->user_ptr[1];
41ade00f 2323 u8 key_idx = 0;
e31b8213
JB
2324 const u8 *mac_addr = NULL;
2325 bool pairwise;
41ade00f
JB
2326 struct get_key_cookie cookie = {
2327 .error = 0,
2328 };
2329 void *hdr;
2330 struct sk_buff *msg;
2331
2332 if (info->attrs[NL80211_ATTR_KEY_IDX])
2333 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2334
3cfcf6ac 2335 if (key_idx > 5)
41ade00f
JB
2336 return -EINVAL;
2337
2338 if (info->attrs[NL80211_ATTR_MAC])
2339 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2340
e31b8213
JB
2341 pairwise = !!mac_addr;
2342 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2343 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2344 if (kt >= NUM_NL80211_KEYTYPES)
2345 return -EINVAL;
2346 if (kt != NL80211_KEYTYPE_GROUP &&
2347 kt != NL80211_KEYTYPE_PAIRWISE)
2348 return -EINVAL;
2349 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2350 }
2351
4c476991
JB
2352 if (!rdev->ops->get_key)
2353 return -EOPNOTSUPP;
41ade00f 2354
fd2120ca 2355 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2356 if (!msg)
2357 return -ENOMEM;
41ade00f 2358
15e47304 2359 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 2360 NL80211_CMD_NEW_KEY);
4c476991
JB
2361 if (IS_ERR(hdr))
2362 return PTR_ERR(hdr);
41ade00f
JB
2363
2364 cookie.msg = msg;
b9454e83 2365 cookie.idx = key_idx;
41ade00f 2366
9360ffd1
DM
2367 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2368 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2369 goto nla_put_failure;
2370 if (mac_addr &&
2371 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2372 goto nla_put_failure;
41ade00f 2373
e31b8213
JB
2374 if (pairwise && mac_addr &&
2375 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2376 return -ENOENT;
2377
e35e4d28
HG
2378 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
2379 get_key_callback);
41ade00f
JB
2380
2381 if (err)
6c95e2a2 2382 goto free_msg;
41ade00f
JB
2383
2384 if (cookie.error)
2385 goto nla_put_failure;
2386
2387 genlmsg_end(msg, hdr);
4c476991 2388 return genlmsg_reply(msg, info);
41ade00f
JB
2389
2390 nla_put_failure:
2391 err = -ENOBUFS;
6c95e2a2 2392 free_msg:
41ade00f 2393 nlmsg_free(msg);
41ade00f
JB
2394 return err;
2395}
2396
2397static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2398{
4c476991 2399 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2400 struct key_parse key;
41ade00f 2401 int err;
4c476991 2402 struct net_device *dev = info->user_ptr[1];
41ade00f 2403
b9454e83
JB
2404 err = nl80211_parse_key(info, &key);
2405 if (err)
2406 return err;
41ade00f 2407
b9454e83 2408 if (key.idx < 0)
41ade00f
JB
2409 return -EINVAL;
2410
b9454e83
JB
2411 /* only support setting default key */
2412 if (!key.def && !key.defmgmt)
41ade00f
JB
2413 return -EINVAL;
2414
dbd2fd65 2415 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2416
dbd2fd65
JB
2417 if (key.def) {
2418 if (!rdev->ops->set_default_key) {
2419 err = -EOPNOTSUPP;
2420 goto out;
2421 }
41ade00f 2422
dbd2fd65
JB
2423 err = nl80211_key_allowed(dev->ieee80211_ptr);
2424 if (err)
2425 goto out;
2426
e35e4d28 2427 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
2428 key.def_uni, key.def_multi);
2429
2430 if (err)
2431 goto out;
fffd0934 2432
3d23e349 2433#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2434 dev->ieee80211_ptr->wext.default_key = key.idx;
2435#endif
2436 } else {
2437 if (key.def_uni || !key.def_multi) {
2438 err = -EINVAL;
2439 goto out;
2440 }
2441
2442 if (!rdev->ops->set_default_mgmt_key) {
2443 err = -EOPNOTSUPP;
2444 goto out;
2445 }
2446
2447 err = nl80211_key_allowed(dev->ieee80211_ptr);
2448 if (err)
2449 goto out;
2450
e35e4d28 2451 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
2452 if (err)
2453 goto out;
2454
2455#ifdef CONFIG_CFG80211_WEXT
2456 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2457#endif
dbd2fd65
JB
2458 }
2459
2460 out:
fffd0934 2461 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2462
41ade00f
JB
2463 return err;
2464}
2465
2466static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2467{
4c476991 2468 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2469 int err;
4c476991 2470 struct net_device *dev = info->user_ptr[1];
b9454e83 2471 struct key_parse key;
e31b8213 2472 const u8 *mac_addr = NULL;
41ade00f 2473
b9454e83
JB
2474 err = nl80211_parse_key(info, &key);
2475 if (err)
2476 return err;
41ade00f 2477
b9454e83 2478 if (!key.p.key)
41ade00f
JB
2479 return -EINVAL;
2480
41ade00f
JB
2481 if (info->attrs[NL80211_ATTR_MAC])
2482 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2483
e31b8213
JB
2484 if (key.type == -1) {
2485 if (mac_addr)
2486 key.type = NL80211_KEYTYPE_PAIRWISE;
2487 else
2488 key.type = NL80211_KEYTYPE_GROUP;
2489 }
2490
2491 /* for now */
2492 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2493 key.type != NL80211_KEYTYPE_GROUP)
2494 return -EINVAL;
2495
4c476991
JB
2496 if (!rdev->ops->add_key)
2497 return -EOPNOTSUPP;
25e47c18 2498
e31b8213
JB
2499 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2500 key.type == NL80211_KEYTYPE_PAIRWISE,
2501 mac_addr))
4c476991 2502 return -EINVAL;
41ade00f 2503
fffd0934
JB
2504 wdev_lock(dev->ieee80211_ptr);
2505 err = nl80211_key_allowed(dev->ieee80211_ptr);
2506 if (!err)
e35e4d28
HG
2507 err = rdev_add_key(rdev, dev, key.idx,
2508 key.type == NL80211_KEYTYPE_PAIRWISE,
2509 mac_addr, &key.p);
fffd0934 2510 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2511
41ade00f
JB
2512 return err;
2513}
2514
2515static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2516{
4c476991 2517 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2518 int err;
4c476991 2519 struct net_device *dev = info->user_ptr[1];
41ade00f 2520 u8 *mac_addr = NULL;
b9454e83 2521 struct key_parse key;
41ade00f 2522
b9454e83
JB
2523 err = nl80211_parse_key(info, &key);
2524 if (err)
2525 return err;
41ade00f
JB
2526
2527 if (info->attrs[NL80211_ATTR_MAC])
2528 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2529
e31b8213
JB
2530 if (key.type == -1) {
2531 if (mac_addr)
2532 key.type = NL80211_KEYTYPE_PAIRWISE;
2533 else
2534 key.type = NL80211_KEYTYPE_GROUP;
2535 }
2536
2537 /* for now */
2538 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2539 key.type != NL80211_KEYTYPE_GROUP)
2540 return -EINVAL;
2541
4c476991
JB
2542 if (!rdev->ops->del_key)
2543 return -EOPNOTSUPP;
41ade00f 2544
fffd0934
JB
2545 wdev_lock(dev->ieee80211_ptr);
2546 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2547
2548 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2549 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2550 err = -ENOENT;
2551
fffd0934 2552 if (!err)
e35e4d28
HG
2553 err = rdev_del_key(rdev, dev, key.idx,
2554 key.type == NL80211_KEYTYPE_PAIRWISE,
2555 mac_addr);
41ade00f 2556
3d23e349 2557#ifdef CONFIG_CFG80211_WEXT
08645126 2558 if (!err) {
b9454e83 2559 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2560 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2561 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2562 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2563 }
2564#endif
fffd0934 2565 wdev_unlock(dev->ieee80211_ptr);
08645126 2566
41ade00f
JB
2567 return err;
2568}
2569
77765eaf
VT
2570/* This function returns an error or the number of nested attributes */
2571static int validate_acl_mac_addrs(struct nlattr *nl_attr)
2572{
2573 struct nlattr *attr;
2574 int n_entries = 0, tmp;
2575
2576 nla_for_each_nested(attr, nl_attr, tmp) {
2577 if (nla_len(attr) != ETH_ALEN)
2578 return -EINVAL;
2579
2580 n_entries++;
2581 }
2582
2583 return n_entries;
2584}
2585
2586/*
2587 * This function parses ACL information and allocates memory for ACL data.
2588 * On successful return, the calling function is responsible to free the
2589 * ACL buffer returned by this function.
2590 */
2591static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
2592 struct genl_info *info)
2593{
2594 enum nl80211_acl_policy acl_policy;
2595 struct nlattr *attr;
2596 struct cfg80211_acl_data *acl;
2597 int i = 0, n_entries, tmp;
2598
2599 if (!wiphy->max_acl_mac_addrs)
2600 return ERR_PTR(-EOPNOTSUPP);
2601
2602 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
2603 return ERR_PTR(-EINVAL);
2604
2605 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
2606 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
2607 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
2608 return ERR_PTR(-EINVAL);
2609
2610 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
2611 return ERR_PTR(-EINVAL);
2612
2613 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
2614 if (n_entries < 0)
2615 return ERR_PTR(n_entries);
2616
2617 if (n_entries > wiphy->max_acl_mac_addrs)
2618 return ERR_PTR(-ENOTSUPP);
2619
2620 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
2621 GFP_KERNEL);
2622 if (!acl)
2623 return ERR_PTR(-ENOMEM);
2624
2625 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
2626 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
2627 i++;
2628 }
2629
2630 acl->n_acl_entries = n_entries;
2631 acl->acl_policy = acl_policy;
2632
2633 return acl;
2634}
2635
2636static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
2637{
2638 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2639 struct net_device *dev = info->user_ptr[1];
2640 struct cfg80211_acl_data *acl;
2641 int err;
2642
2643 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2644 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2645 return -EOPNOTSUPP;
2646
2647 if (!dev->ieee80211_ptr->beacon_interval)
2648 return -EINVAL;
2649
2650 acl = parse_acl_data(&rdev->wiphy, info);
2651 if (IS_ERR(acl))
2652 return PTR_ERR(acl);
2653
2654 err = rdev_set_mac_acl(rdev, dev, acl);
2655
2656 kfree(acl);
2657
2658 return err;
2659}
2660
8860020e
JB
2661static int nl80211_parse_beacon(struct genl_info *info,
2662 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2663{
8860020e 2664 bool haveinfo = false;
ed1b6cc7 2665
9946ecfb
JM
2666 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2667 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2668 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2669 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2670 return -EINVAL;
2671
8860020e 2672 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2673
ed1b6cc7 2674 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2675 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2676 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2677 if (!bcn->head_len)
2678 return -EINVAL;
2679 haveinfo = true;
ed1b6cc7
JB
2680 }
2681
2682 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2683 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2684 bcn->tail_len =
ed1b6cc7 2685 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2686 haveinfo = true;
ed1b6cc7
JB
2687 }
2688
4c476991
JB
2689 if (!haveinfo)
2690 return -EINVAL;
3b85875a 2691
9946ecfb 2692 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2693 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2694 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2695 }
2696
2697 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2698 bcn->proberesp_ies =
9946ecfb 2699 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2700 bcn->proberesp_ies_len =
9946ecfb
JM
2701 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2702 }
2703
2704 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2705 bcn->assocresp_ies =
9946ecfb 2706 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2707 bcn->assocresp_ies_len =
9946ecfb
JM
2708 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2709 }
2710
00f740e1 2711 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2712 bcn->probe_resp =
00f740e1 2713 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2714 bcn->probe_resp_len =
00f740e1
AN
2715 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2716 }
2717
8860020e
JB
2718 return 0;
2719}
2720
46c1dd0c
FF
2721static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2722 struct cfg80211_ap_settings *params)
2723{
2724 struct wireless_dev *wdev;
2725 bool ret = false;
2726
2727 mutex_lock(&rdev->devlist_mtx);
2728
89a54e48 2729 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2730 if (wdev->iftype != NL80211_IFTYPE_AP &&
2731 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2732 continue;
2733
683b6d3b 2734 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
2735 continue;
2736
683b6d3b 2737 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
2738 ret = true;
2739 break;
2740 }
2741
2742 mutex_unlock(&rdev->devlist_mtx);
2743
2744 return ret;
2745}
2746
e39e5b5e
JM
2747static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
2748 enum nl80211_auth_type auth_type,
2749 enum nl80211_commands cmd)
2750{
2751 if (auth_type > NL80211_AUTHTYPE_MAX)
2752 return false;
2753
2754 switch (cmd) {
2755 case NL80211_CMD_AUTHENTICATE:
2756 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
2757 auth_type == NL80211_AUTHTYPE_SAE)
2758 return false;
2759 return true;
2760 case NL80211_CMD_CONNECT:
2761 case NL80211_CMD_START_AP:
2762 /* SAE not supported yet */
2763 if (auth_type == NL80211_AUTHTYPE_SAE)
2764 return false;
2765 return true;
2766 default:
2767 return false;
2768 }
2769}
2770
8860020e
JB
2771static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2772{
2773 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2774 struct net_device *dev = info->user_ptr[1];
2775 struct wireless_dev *wdev = dev->ieee80211_ptr;
2776 struct cfg80211_ap_settings params;
2777 int err;
2778
2779 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2780 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2781 return -EOPNOTSUPP;
2782
2783 if (!rdev->ops->start_ap)
2784 return -EOPNOTSUPP;
2785
2786 if (wdev->beacon_interval)
2787 return -EALREADY;
2788
2789 memset(&params, 0, sizeof(params));
2790
2791 /* these are required for START_AP */
2792 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2793 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2794 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2795 return -EINVAL;
2796
2797 err = nl80211_parse_beacon(info, &params.beacon);
2798 if (err)
2799 return err;
2800
2801 params.beacon_interval =
2802 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2803 params.dtim_period =
2804 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2805
2806 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2807 if (err)
2808 return err;
2809
2810 /*
2811 * In theory, some of these attributes should be required here
2812 * but since they were not used when the command was originally
2813 * added, keep them optional for old user space programs to let
2814 * them continue to work with drivers that do not need the
2815 * additional information -- drivers must check!
2816 */
2817 if (info->attrs[NL80211_ATTR_SSID]) {
2818 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2819 params.ssid_len =
2820 nla_len(info->attrs[NL80211_ATTR_SSID]);
2821 if (params.ssid_len == 0 ||
2822 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2823 return -EINVAL;
2824 }
2825
2826 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2827 params.hidden_ssid = nla_get_u32(
2828 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2829 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2830 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2831 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2832 return -EINVAL;
2833 }
2834
2835 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2836
2837 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2838 params.auth_type = nla_get_u32(
2839 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
2840 if (!nl80211_valid_auth_type(rdev, params.auth_type,
2841 NL80211_CMD_START_AP))
8860020e
JB
2842 return -EINVAL;
2843 } else
2844 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2845
2846 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2847 NL80211_MAX_NR_CIPHER_SUITES);
2848 if (err)
2849 return err;
2850
1b658f11
VT
2851 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2852 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2853 return -EOPNOTSUPP;
2854 params.inactivity_timeout = nla_get_u16(
2855 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2856 }
2857
53cabad7
JB
2858 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
2859 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2860 return -EINVAL;
2861 params.p2p_ctwindow =
2862 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
2863 if (params.p2p_ctwindow > 127)
2864 return -EINVAL;
2865 if (params.p2p_ctwindow != 0 &&
2866 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
2867 return -EINVAL;
2868 }
2869
2870 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
2871 u8 tmp;
2872
2873 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2874 return -EINVAL;
2875 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
2876 if (tmp > 1)
2877 return -EINVAL;
2878 params.p2p_opp_ps = tmp;
2879 if (params.p2p_opp_ps != 0 &&
2880 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
2881 return -EINVAL;
2882 }
2883
aa430da4 2884 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
2885 err = nl80211_parse_chandef(rdev, info, &params.chandef);
2886 if (err)
2887 return err;
2888 } else if (wdev->preset_chandef.chan) {
2889 params.chandef = wdev->preset_chandef;
46c1dd0c 2890 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
2891 return -EINVAL;
2892
683b6d3b 2893 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &params.chandef))
aa430da4
JB
2894 return -EINVAL;
2895
e4e32459 2896 mutex_lock(&rdev->devlist_mtx);
683b6d3b 2897 err = cfg80211_can_use_chan(rdev, wdev, params.chandef.chan,
e4e32459
MK
2898 CHAN_MODE_SHARED);
2899 mutex_unlock(&rdev->devlist_mtx);
2900
2901 if (err)
2902 return err;
2903
77765eaf
VT
2904 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
2905 params.acl = parse_acl_data(&rdev->wiphy, info);
2906 if (IS_ERR(params.acl))
2907 return PTR_ERR(params.acl);
2908 }
2909
e35e4d28 2910 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 2911 if (!err) {
683b6d3b 2912 wdev->preset_chandef = params.chandef;
8860020e 2913 wdev->beacon_interval = params.beacon_interval;
683b6d3b 2914 wdev->channel = params.chandef.chan;
06e191e2
AQ
2915 wdev->ssid_len = params.ssid_len;
2916 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 2917 }
77765eaf
VT
2918
2919 kfree(params.acl);
2920
56d1893d 2921 return err;
ed1b6cc7
JB
2922}
2923
8860020e
JB
2924static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2925{
2926 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2927 struct net_device *dev = info->user_ptr[1];
2928 struct wireless_dev *wdev = dev->ieee80211_ptr;
2929 struct cfg80211_beacon_data params;
2930 int err;
2931
2932 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2933 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2934 return -EOPNOTSUPP;
2935
2936 if (!rdev->ops->change_beacon)
2937 return -EOPNOTSUPP;
2938
2939 if (!wdev->beacon_interval)
2940 return -EINVAL;
2941
2942 err = nl80211_parse_beacon(info, &params);
2943 if (err)
2944 return err;
2945
e35e4d28 2946 return rdev_change_beacon(rdev, dev, &params);
8860020e
JB
2947}
2948
2949static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2950{
4c476991
JB
2951 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2952 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 2953
60771780 2954 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
2955}
2956
5727ef1b
JB
2957static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2958 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2959 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2960 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2961 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2962 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2963 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2964};
2965
eccb8e8f 2966static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2967 enum nl80211_iftype iftype,
eccb8e8f 2968 struct station_parameters *params)
5727ef1b
JB
2969{
2970 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2971 struct nlattr *nla;
5727ef1b
JB
2972 int flag;
2973
eccb8e8f
JB
2974 /*
2975 * Try parsing the new attribute first so userspace
2976 * can specify both for older kernels.
2977 */
2978 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2979 if (nla) {
2980 struct nl80211_sta_flag_update *sta_flags;
2981
2982 sta_flags = nla_data(nla);
2983 params->sta_flags_mask = sta_flags->mask;
2984 params->sta_flags_set = sta_flags->set;
2985 if ((params->sta_flags_mask |
2986 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2987 return -EINVAL;
2988 return 0;
2989 }
2990
2991 /* if present, parse the old attribute */
5727ef1b 2992
eccb8e8f 2993 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2994 if (!nla)
2995 return 0;
2996
2997 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2998 nla, sta_flags_policy))
2999 return -EINVAL;
3000
bdd3ae3d
JB
3001 /*
3002 * Only allow certain flags for interface types so that
3003 * other attributes are silently ignored. Remember that
3004 * this is backward compatibility code with old userspace
3005 * and shouldn't be hit in other cases anyway.
3006 */
3007 switch (iftype) {
3008 case NL80211_IFTYPE_AP:
3009 case NL80211_IFTYPE_AP_VLAN:
3010 case NL80211_IFTYPE_P2P_GO:
3011 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3012 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3013 BIT(NL80211_STA_FLAG_WME) |
3014 BIT(NL80211_STA_FLAG_MFP);
3015 break;
3016 case NL80211_IFTYPE_P2P_CLIENT:
3017 case NL80211_IFTYPE_STATION:
3018 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
3019 BIT(NL80211_STA_FLAG_TDLS_PEER);
3020 break;
3021 case NL80211_IFTYPE_MESH_POINT:
3022 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3023 BIT(NL80211_STA_FLAG_MFP) |
3024 BIT(NL80211_STA_FLAG_AUTHORIZED);
3025 default:
3026 return -EINVAL;
3027 }
5727ef1b 3028
3383b5a6
JB
3029 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
3030 if (flags[flag]) {
eccb8e8f 3031 params->sta_flags_set |= (1<<flag);
5727ef1b 3032
3383b5a6
JB
3033 /* no longer support new API additions in old API */
3034 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
3035 return -EINVAL;
3036 }
3037 }
3038
5727ef1b
JB
3039 return 0;
3040}
3041
c8dcfd8a
FF
3042static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
3043 int attr)
3044{
3045 struct nlattr *rate;
8eb41c8d
VK
3046 u32 bitrate;
3047 u16 bitrate_compat;
c8dcfd8a
FF
3048
3049 rate = nla_nest_start(msg, attr);
3050 if (!rate)
db9c64cf 3051 return false;
c8dcfd8a
FF
3052
3053 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
3054 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
3055 /* report 16-bit bitrate only if we can */
3056 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
3057 if (bitrate > 0 &&
3058 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
3059 return false;
3060 if (bitrate_compat > 0 &&
3061 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
3062 return false;
3063
3064 if (info->flags & RATE_INFO_FLAGS_MCS) {
3065 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
3066 return false;
3067 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3068 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3069 return false;
3070 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3071 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3072 return false;
3073 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
3074 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
3075 return false;
3076 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
3077 return false;
3078 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH &&
3079 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH))
3080 return false;
3081 if (info->flags & RATE_INFO_FLAGS_80_MHZ_WIDTH &&
3082 nla_put_flag(msg, NL80211_RATE_INFO_80_MHZ_WIDTH))
3083 return false;
3084 if (info->flags & RATE_INFO_FLAGS_80P80_MHZ_WIDTH &&
3085 nla_put_flag(msg, NL80211_RATE_INFO_80P80_MHZ_WIDTH))
3086 return false;
3087 if (info->flags & RATE_INFO_FLAGS_160_MHZ_WIDTH &&
3088 nla_put_flag(msg, NL80211_RATE_INFO_160_MHZ_WIDTH))
3089 return false;
3090 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
3091 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
3092 return false;
3093 }
c8dcfd8a
FF
3094
3095 nla_nest_end(msg, rate);
3096 return true;
c8dcfd8a
FF
3097}
3098
15e47304 3099static int nl80211_send_station(struct sk_buff *msg, u32 portid, u32 seq,
66266b3a
JL
3100 int flags,
3101 struct cfg80211_registered_device *rdev,
3102 struct net_device *dev,
98b62183 3103 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
3104{
3105 void *hdr;
f4263c98 3106 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 3107
15e47304 3108 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
fd5b74dc
JB
3109 if (!hdr)
3110 return -1;
3111
9360ffd1
DM
3112 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3113 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
3114 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
3115 goto nla_put_failure;
f5ea9120 3116
2ec600d6
LCC
3117 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
3118 if (!sinfoattr)
fd5b74dc 3119 goto nla_put_failure;
9360ffd1
DM
3120 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
3121 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
3122 sinfo->connected_time))
3123 goto nla_put_failure;
3124 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
3125 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
3126 sinfo->inactive_time))
3127 goto nla_put_failure;
42745e03
VK
3128 if ((sinfo->filled & (STATION_INFO_RX_BYTES |
3129 STATION_INFO_RX_BYTES64)) &&
9360ffd1 3130 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 3131 (u32)sinfo->rx_bytes))
9360ffd1 3132 goto nla_put_failure;
42745e03
VK
3133 if ((sinfo->filled & (STATION_INFO_TX_BYTES |
3134 NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 3135 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
3136 (u32)sinfo->tx_bytes))
3137 goto nla_put_failure;
3138 if ((sinfo->filled & STATION_INFO_RX_BYTES64) &&
3139 nla_put_u64(msg, NL80211_STA_INFO_RX_BYTES64,
3140 sinfo->rx_bytes))
3141 goto nla_put_failure;
3142 if ((sinfo->filled & STATION_INFO_TX_BYTES64) &&
3143 nla_put_u64(msg, NL80211_STA_INFO_TX_BYTES64,
9360ffd1
DM
3144 sinfo->tx_bytes))
3145 goto nla_put_failure;
3146 if ((sinfo->filled & STATION_INFO_LLID) &&
3147 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
3148 goto nla_put_failure;
3149 if ((sinfo->filled & STATION_INFO_PLID) &&
3150 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
3151 goto nla_put_failure;
3152 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
3153 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
3154 sinfo->plink_state))
3155 goto nla_put_failure;
66266b3a
JL
3156 switch (rdev->wiphy.signal_type) {
3157 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
3158 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
3159 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
3160 sinfo->signal))
3161 goto nla_put_failure;
3162 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
3163 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
3164 sinfo->signal_avg))
3165 goto nla_put_failure;
66266b3a
JL
3166 break;
3167 default:
3168 break;
3169 }
420e7fab 3170 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
3171 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
3172 NL80211_STA_INFO_TX_BITRATE))
3173 goto nla_put_failure;
3174 }
3175 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
3176 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
3177 NL80211_STA_INFO_RX_BITRATE))
420e7fab 3178 goto nla_put_failure;
420e7fab 3179 }
9360ffd1
DM
3180 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
3181 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
3182 sinfo->rx_packets))
3183 goto nla_put_failure;
3184 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
3185 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
3186 sinfo->tx_packets))
3187 goto nla_put_failure;
3188 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
3189 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
3190 sinfo->tx_retries))
3191 goto nla_put_failure;
3192 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
3193 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
3194 sinfo->tx_failed))
3195 goto nla_put_failure;
3196 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
3197 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
3198 sinfo->beacon_loss_count))
3199 goto nla_put_failure;
3b1c5a53
MP
3200 if ((sinfo->filled & STATION_INFO_LOCAL_PM) &&
3201 nla_put_u32(msg, NL80211_STA_INFO_LOCAL_PM,
3202 sinfo->local_pm))
3203 goto nla_put_failure;
3204 if ((sinfo->filled & STATION_INFO_PEER_PM) &&
3205 nla_put_u32(msg, NL80211_STA_INFO_PEER_PM,
3206 sinfo->peer_pm))
3207 goto nla_put_failure;
3208 if ((sinfo->filled & STATION_INFO_NONPEER_PM) &&
3209 nla_put_u32(msg, NL80211_STA_INFO_NONPEER_PM,
3210 sinfo->nonpeer_pm))
3211 goto nla_put_failure;
f4263c98
PS
3212 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
3213 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
3214 if (!bss_param)
3215 goto nla_put_failure;
3216
9360ffd1
DM
3217 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
3218 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
3219 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
3220 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
3221 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
3222 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
3223 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
3224 sinfo->bss_param.dtim_period) ||
3225 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
3226 sinfo->bss_param.beacon_interval))
3227 goto nla_put_failure;
f4263c98
PS
3228
3229 nla_nest_end(msg, bss_param);
3230 }
9360ffd1
DM
3231 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
3232 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
3233 sizeof(struct nl80211_sta_flag_update),
3234 &sinfo->sta_flags))
3235 goto nla_put_failure;
7eab0f64
JL
3236 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
3237 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
3238 sinfo->t_offset))
3239 goto nla_put_failure;
2ec600d6 3240 nla_nest_end(msg, sinfoattr);
fd5b74dc 3241
9360ffd1
DM
3242 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
3243 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
3244 sinfo->assoc_req_ies))
3245 goto nla_put_failure;
50d3dfb7 3246
fd5b74dc
JB
3247 return genlmsg_end(msg, hdr);
3248
3249 nla_put_failure:
bc3ed28c
TG
3250 genlmsg_cancel(msg, hdr);
3251 return -EMSGSIZE;
fd5b74dc
JB
3252}
3253
2ec600d6 3254static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 3255 struct netlink_callback *cb)
2ec600d6 3256{
2ec600d6
LCC
3257 struct station_info sinfo;
3258 struct cfg80211_registered_device *dev;
bba95fef 3259 struct net_device *netdev;
2ec600d6 3260 u8 mac_addr[ETH_ALEN];
bba95fef 3261 int sta_idx = cb->args[1];
2ec600d6 3262 int err;
2ec600d6 3263
67748893
JB
3264 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3265 if (err)
3266 return err;
bba95fef
JB
3267
3268 if (!dev->ops->dump_station) {
eec60b03 3269 err = -EOPNOTSUPP;
bba95fef
JB
3270 goto out_err;
3271 }
3272
bba95fef 3273 while (1) {
f612cedf 3274 memset(&sinfo, 0, sizeof(sinfo));
e35e4d28
HG
3275 err = rdev_dump_station(dev, netdev, sta_idx,
3276 mac_addr, &sinfo);
bba95fef
JB
3277 if (err == -ENOENT)
3278 break;
3279 if (err)
3b85875a 3280 goto out_err;
bba95fef
JB
3281
3282 if (nl80211_send_station(skb,
15e47304 3283 NETLINK_CB(cb->skb).portid,
bba95fef 3284 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 3285 dev, netdev, mac_addr,
bba95fef
JB
3286 &sinfo) < 0)
3287 goto out;
3288
3289 sta_idx++;
3290 }
3291
3292
3293 out:
3294 cb->args[1] = sta_idx;
3295 err = skb->len;
bba95fef 3296 out_err:
67748893 3297 nl80211_finish_netdev_dump(dev);
bba95fef
JB
3298
3299 return err;
2ec600d6 3300}
fd5b74dc 3301
5727ef1b
JB
3302static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
3303{
4c476991
JB
3304 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3305 struct net_device *dev = info->user_ptr[1];
2ec600d6 3306 struct station_info sinfo;
fd5b74dc
JB
3307 struct sk_buff *msg;
3308 u8 *mac_addr = NULL;
4c476991 3309 int err;
fd5b74dc 3310
2ec600d6 3311 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
3312
3313 if (!info->attrs[NL80211_ATTR_MAC])
3314 return -EINVAL;
3315
3316 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3317
4c476991
JB
3318 if (!rdev->ops->get_station)
3319 return -EOPNOTSUPP;
3b85875a 3320
e35e4d28 3321 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 3322 if (err)
4c476991 3323 return err;
2ec600d6 3324
fd2120ca 3325 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 3326 if (!msg)
4c476991 3327 return -ENOMEM;
fd5b74dc 3328
15e47304 3329 if (nl80211_send_station(msg, info->snd_portid, info->snd_seq, 0,
66266b3a 3330 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
3331 nlmsg_free(msg);
3332 return -ENOBUFS;
3333 }
3b85875a 3334
4c476991 3335 return genlmsg_reply(msg, info);
5727ef1b
JB
3336}
3337
3338/*
c258d2de 3339 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 3340 */
80b99899
JB
3341static struct net_device *get_vlan(struct genl_info *info,
3342 struct cfg80211_registered_device *rdev)
5727ef1b 3343{
463d0183 3344 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
3345 struct net_device *v;
3346 int ret;
3347
3348 if (!vlanattr)
3349 return NULL;
3350
3351 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
3352 if (!v)
3353 return ERR_PTR(-ENODEV);
3354
3355 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
3356 ret = -EINVAL;
3357 goto error;
5727ef1b 3358 }
80b99899
JB
3359
3360 if (!netif_running(v)) {
3361 ret = -ENETDOWN;
3362 goto error;
3363 }
3364
3365 return v;
3366 error:
3367 dev_put(v);
3368 return ERR_PTR(ret);
5727ef1b
JB
3369}
3370
3371static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
3372{
4c476991 3373 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3374 int err;
4c476991 3375 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3376 struct station_parameters params;
3377 u8 *mac_addr = NULL;
3378
3379 memset(&params, 0, sizeof(params));
3380
3381 params.listen_interval = -1;
57cf8043 3382 params.plink_state = -1;
5727ef1b
JB
3383
3384 if (info->attrs[NL80211_ATTR_STA_AID])
3385 return -EINVAL;
3386
3387 if (!info->attrs[NL80211_ATTR_MAC])
3388 return -EINVAL;
3389
3390 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3391
3392 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
3393 params.supported_rates =
3394 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3395 params.supported_rates_len =
3396 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3397 }
3398
ba23d206
JB
3399 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL] ||
3400 info->attrs[NL80211_ATTR_HT_CAPABILITY])
3401 return -EINVAL;
36aedc90 3402
bdd90d5e
JB
3403 if (!rdev->ops->change_station)
3404 return -EOPNOTSUPP;
3405
bdd3ae3d 3406 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3407 return -EINVAL;
3408
2ec600d6
LCC
3409 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3410 params.plink_action =
3411 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3412
9c3990aa
JC
3413 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
3414 params.plink_state =
3415 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3416
3b1c5a53
MP
3417 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
3418 enum nl80211_mesh_power_mode pm = nla_get_u32(
3419 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
3420
3421 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
3422 pm > NL80211_MESH_POWER_MAX)
3423 return -EINVAL;
3424
3425 params.local_pm = pm;
3426 }
3427
a97f4424
JB
3428 switch (dev->ieee80211_ptr->iftype) {
3429 case NL80211_IFTYPE_AP:
3430 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3431 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
3432 /* disallow mesh-specific things */
3433 if (params.plink_action)
bdd90d5e 3434 return -EINVAL;
3b1c5a53
MP
3435 if (params.local_pm)
3436 return -EINVAL;
bdd90d5e
JB
3437
3438 /* TDLS can't be set, ... */
3439 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3440 return -EINVAL;
3441 /*
3442 * ... but don't bother the driver with it. This works around
3443 * a hostapd/wpa_supplicant issue -- it always includes the
3444 * TLDS_PEER flag in the mask even for AP mode.
3445 */
3446 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3447
3448 /* accept only the listed bits */
3449 if (params.sta_flags_mask &
3450 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
d582cffb
JB
3451 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3452 BIT(NL80211_STA_FLAG_ASSOCIATED) |
bdd90d5e
JB
3453 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3454 BIT(NL80211_STA_FLAG_WME) |
3455 BIT(NL80211_STA_FLAG_MFP)))
3456 return -EINVAL;
3457
d582cffb
JB
3458 /* but authenticated/associated only if driver handles it */
3459 if (!(rdev->wiphy.features &
3460 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3461 params.sta_flags_mask &
3462 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3463 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3464 return -EINVAL;
3465
ba23d206
JB
3466 /* reject other things that can't change */
3467 if (params.supported_rates)
3468 return -EINVAL;
3469
bdd90d5e
JB
3470 /* must be last in here for error handling */
3471 params.vlan = get_vlan(info, rdev);
3472 if (IS_ERR(params.vlan))
3473 return PTR_ERR(params.vlan);
a97f4424 3474 break;
074ac8df 3475 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3476 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
3477 /*
3478 * Don't allow userspace to change the TDLS_PEER flag,
3479 * but silently ignore attempts to change it since we
3480 * don't have state here to verify that it doesn't try
3481 * to change the flag.
3482 */
3483 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
3484 /* fall through */
3485 case NL80211_IFTYPE_ADHOC:
3486 /* disallow things sta doesn't support */
3487 if (params.plink_action)
3488 return -EINVAL;
3b1c5a53
MP
3489 if (params.local_pm)
3490 return -EINVAL;
bdd90d5e
JB
3491 /* reject any changes other than AUTHORIZED */
3492 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3493 return -EINVAL;
a97f4424
JB
3494 break;
3495 case NL80211_IFTYPE_MESH_POINT:
3496 /* disallow things mesh doesn't support */
3497 if (params.vlan)
bdd90d5e 3498 return -EINVAL;
ba23d206 3499 if (params.supported_rates)
bdd90d5e
JB
3500 return -EINVAL;
3501 /*
3502 * No special handling for TDLS here -- the userspace
3503 * mesh code doesn't have this bug.
3504 */
b39c48fa
JC
3505 if (params.sta_flags_mask &
3506 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 3507 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 3508 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 3509 return -EINVAL;
a97f4424
JB
3510 break;
3511 default:
bdd90d5e 3512 return -EOPNOTSUPP;
034d655e
JB
3513 }
3514
bdd90d5e 3515 /* be aware of params.vlan when changing code here */
5727ef1b 3516
e35e4d28 3517 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 3518
5727ef1b
JB
3519 if (params.vlan)
3520 dev_put(params.vlan);
3b85875a 3521
5727ef1b
JB
3522 return err;
3523}
3524
c75786c9
EP
3525static struct nla_policy
3526nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3527 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3528 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3529};
3530
5727ef1b
JB
3531static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3532{
4c476991 3533 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3534 int err;
4c476991 3535 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3536 struct station_parameters params;
3537 u8 *mac_addr = NULL;
3538
3539 memset(&params, 0, sizeof(params));
3540
3541 if (!info->attrs[NL80211_ATTR_MAC])
3542 return -EINVAL;
3543
5727ef1b
JB
3544 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3545 return -EINVAL;
3546
3547 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3548 return -EINVAL;
3549
0e956c13
TLSC
3550 if (!info->attrs[NL80211_ATTR_STA_AID])
3551 return -EINVAL;
3552
5727ef1b
JB
3553 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3554 params.supported_rates =
3555 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3556 params.supported_rates_len =
3557 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3558 params.listen_interval =
3559 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3560
0e956c13
TLSC
3561 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
3562 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3563 return -EINVAL;
51b50fbe 3564
36aedc90
JM
3565 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3566 params.ht_capa =
3567 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 3568
f461be3e
MP
3569 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
3570 params.vht_capa =
3571 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
3572
96b78dff
JC
3573 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3574 params.plink_action =
3575 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3576
bdd90d5e
JB
3577 if (!rdev->ops->add_station)
3578 return -EOPNOTSUPP;
3579
bdd3ae3d 3580 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3581 return -EINVAL;
3582
bdd90d5e
JB
3583 switch (dev->ieee80211_ptr->iftype) {
3584 case NL80211_IFTYPE_AP:
3585 case NL80211_IFTYPE_AP_VLAN:
3586 case NL80211_IFTYPE_P2P_GO:
3587 /* parse WME attributes if sta is WME capable */
3588 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3589 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
3590 info->attrs[NL80211_ATTR_STA_WME]) {
3591 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3592 struct nlattr *nla;
3593
3594 nla = info->attrs[NL80211_ATTR_STA_WME];
3595 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3596 nl80211_sta_wme_policy);
3597 if (err)
3598 return err;
3599
3600 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3601 params.uapsd_queues =
3602 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
3603 if (params.uapsd_queues &
3604 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3605 return -EINVAL;
c75786c9 3606
bdd90d5e
JB
3607 if (tb[NL80211_STA_WME_MAX_SP])
3608 params.max_sp =
3609 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 3610
bdd90d5e
JB
3611 if (params.max_sp &
3612 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3613 return -EINVAL;
4319e193 3614
bdd90d5e
JB
3615 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3616 }
3617 /* TDLS peers cannot be added */
3618 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3619 return -EINVAL;
bdd90d5e
JB
3620 /* but don't bother the driver with it */
3621 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3622
d582cffb
JB
3623 /* allow authenticated/associated only if driver handles it */
3624 if (!(rdev->wiphy.features &
3625 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
3626 params.sta_flags_mask &
3627 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
3628 BIT(NL80211_STA_FLAG_ASSOCIATED)))
3629 return -EINVAL;
3630
bdd90d5e
JB
3631 /* must be last in here for error handling */
3632 params.vlan = get_vlan(info, rdev);
3633 if (IS_ERR(params.vlan))
3634 return PTR_ERR(params.vlan);
3635 break;
3636 case NL80211_IFTYPE_MESH_POINT:
d582cffb
JB
3637 /* associated is disallowed */
3638 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3639 return -EINVAL;
bdd90d5e
JB
3640 /* TDLS peers cannot be added */
3641 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3642 return -EINVAL;
3643 break;
3644 case NL80211_IFTYPE_STATION:
d582cffb
JB
3645 /* associated is disallowed */
3646 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
3647 return -EINVAL;
bdd90d5e
JB
3648 /* Only TDLS peers can be added */
3649 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3650 return -EINVAL;
3651 /* Can only add if TDLS ... */
3652 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3653 return -EOPNOTSUPP;
3654 /* ... with external setup is supported */
3655 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3656 return -EOPNOTSUPP;
3657 break;
3658 default:
3659 return -EOPNOTSUPP;
c75786c9
EP
3660 }
3661
bdd90d5e 3662 /* be aware of params.vlan when changing code here */
5727ef1b 3663
e35e4d28 3664 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 3665
5727ef1b
JB
3666 if (params.vlan)
3667 dev_put(params.vlan);
5727ef1b
JB
3668 return err;
3669}
3670
3671static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3672{
4c476991
JB
3673 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3674 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3675 u8 *mac_addr = NULL;
3676
3677 if (info->attrs[NL80211_ATTR_MAC])
3678 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3679
e80cf853 3680 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3681 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3682 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3683 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3684 return -EINVAL;
5727ef1b 3685
4c476991
JB
3686 if (!rdev->ops->del_station)
3687 return -EOPNOTSUPP;
3b85875a 3688
e35e4d28 3689 return rdev_del_station(rdev, dev, mac_addr);
5727ef1b
JB
3690}
3691
15e47304 3692static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
3693 int flags, struct net_device *dev,
3694 u8 *dst, u8 *next_hop,
3695 struct mpath_info *pinfo)
3696{
3697 void *hdr;
3698 struct nlattr *pinfoattr;
3699
15e47304 3700 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_STATION);
2ec600d6
LCC
3701 if (!hdr)
3702 return -1;
3703
9360ffd1
DM
3704 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3705 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3706 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3707 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3708 goto nla_put_failure;
f5ea9120 3709
2ec600d6
LCC
3710 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3711 if (!pinfoattr)
3712 goto nla_put_failure;
9360ffd1
DM
3713 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3714 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3715 pinfo->frame_qlen))
3716 goto nla_put_failure;
3717 if (((pinfo->filled & MPATH_INFO_SN) &&
3718 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3719 ((pinfo->filled & MPATH_INFO_METRIC) &&
3720 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3721 pinfo->metric)) ||
3722 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3723 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3724 pinfo->exptime)) ||
3725 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3726 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3727 pinfo->flags)) ||
3728 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3729 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3730 pinfo->discovery_timeout)) ||
3731 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3732 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3733 pinfo->discovery_retries)))
3734 goto nla_put_failure;
2ec600d6
LCC
3735
3736 nla_nest_end(msg, pinfoattr);
3737
3738 return genlmsg_end(msg, hdr);
3739
3740 nla_put_failure:
bc3ed28c
TG
3741 genlmsg_cancel(msg, hdr);
3742 return -EMSGSIZE;
2ec600d6
LCC
3743}
3744
3745static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3746 struct netlink_callback *cb)
2ec600d6 3747{
2ec600d6
LCC
3748 struct mpath_info pinfo;
3749 struct cfg80211_registered_device *dev;
bba95fef 3750 struct net_device *netdev;
2ec600d6
LCC
3751 u8 dst[ETH_ALEN];
3752 u8 next_hop[ETH_ALEN];
bba95fef 3753 int path_idx = cb->args[1];
2ec600d6 3754 int err;
2ec600d6 3755
67748893
JB
3756 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3757 if (err)
3758 return err;
bba95fef
JB
3759
3760 if (!dev->ops->dump_mpath) {
eec60b03 3761 err = -EOPNOTSUPP;
bba95fef
JB
3762 goto out_err;
3763 }
3764
eec60b03
JM
3765 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3766 err = -EOPNOTSUPP;
0448b5fc 3767 goto out_err;
eec60b03
JM
3768 }
3769
bba95fef 3770 while (1) {
e35e4d28
HG
3771 err = rdev_dump_mpath(dev, netdev, path_idx, dst, next_hop,
3772 &pinfo);
bba95fef 3773 if (err == -ENOENT)
2ec600d6 3774 break;
bba95fef 3775 if (err)
3b85875a 3776 goto out_err;
2ec600d6 3777
15e47304 3778 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef
JB
3779 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3780 netdev, dst, next_hop,
3781 &pinfo) < 0)
3782 goto out;
2ec600d6 3783
bba95fef 3784 path_idx++;
2ec600d6 3785 }
2ec600d6 3786
2ec600d6 3787
bba95fef
JB
3788 out:
3789 cb->args[1] = path_idx;
3790 err = skb->len;
bba95fef 3791 out_err:
67748893 3792 nl80211_finish_netdev_dump(dev);
bba95fef 3793 return err;
2ec600d6
LCC
3794}
3795
3796static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3797{
4c476991 3798 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3799 int err;
4c476991 3800 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3801 struct mpath_info pinfo;
3802 struct sk_buff *msg;
3803 u8 *dst = NULL;
3804 u8 next_hop[ETH_ALEN];
3805
3806 memset(&pinfo, 0, sizeof(pinfo));
3807
3808 if (!info->attrs[NL80211_ATTR_MAC])
3809 return -EINVAL;
3810
3811 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3812
4c476991
JB
3813 if (!rdev->ops->get_mpath)
3814 return -EOPNOTSUPP;
2ec600d6 3815
4c476991
JB
3816 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3817 return -EOPNOTSUPP;
eec60b03 3818
e35e4d28 3819 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 3820 if (err)
4c476991 3821 return err;
2ec600d6 3822
fd2120ca 3823 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3824 if (!msg)
4c476991 3825 return -ENOMEM;
2ec600d6 3826
15e47304 3827 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
3828 dev, dst, next_hop, &pinfo) < 0) {
3829 nlmsg_free(msg);
3830 return -ENOBUFS;
3831 }
3b85875a 3832
4c476991 3833 return genlmsg_reply(msg, info);
2ec600d6
LCC
3834}
3835
3836static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3837{
4c476991
JB
3838 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3839 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3840 u8 *dst = NULL;
3841 u8 *next_hop = NULL;
3842
3843 if (!info->attrs[NL80211_ATTR_MAC])
3844 return -EINVAL;
3845
3846 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3847 return -EINVAL;
3848
3849 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3850 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3851
4c476991
JB
3852 if (!rdev->ops->change_mpath)
3853 return -EOPNOTSUPP;
35a8efe1 3854
4c476991
JB
3855 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3856 return -EOPNOTSUPP;
2ec600d6 3857
e35e4d28 3858 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 3859}
4c476991 3860
2ec600d6
LCC
3861static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3862{
4c476991
JB
3863 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3864 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3865 u8 *dst = NULL;
3866 u8 *next_hop = NULL;
3867
3868 if (!info->attrs[NL80211_ATTR_MAC])
3869 return -EINVAL;
3870
3871 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3872 return -EINVAL;
3873
3874 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3875 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3876
4c476991
JB
3877 if (!rdev->ops->add_mpath)
3878 return -EOPNOTSUPP;
35a8efe1 3879
4c476991
JB
3880 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3881 return -EOPNOTSUPP;
2ec600d6 3882
e35e4d28 3883 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
3884}
3885
3886static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3887{
4c476991
JB
3888 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3889 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3890 u8 *dst = NULL;
3891
3892 if (info->attrs[NL80211_ATTR_MAC])
3893 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3894
4c476991
JB
3895 if (!rdev->ops->del_mpath)
3896 return -EOPNOTSUPP;
3b85875a 3897
e35e4d28 3898 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
3899}
3900
9f1ba906
JM
3901static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3902{
4c476991
JB
3903 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3904 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3905 struct bss_parameters params;
3906
3907 memset(&params, 0, sizeof(params));
3908 /* default to not changing parameters */
3909 params.use_cts_prot = -1;
3910 params.use_short_preamble = -1;
3911 params.use_short_slot_time = -1;
fd8aaaf3 3912 params.ap_isolate = -1;
50b12f59 3913 params.ht_opmode = -1;
53cabad7
JB
3914 params.p2p_ctwindow = -1;
3915 params.p2p_opp_ps = -1;
9f1ba906
JM
3916
3917 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3918 params.use_cts_prot =
3919 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3920 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3921 params.use_short_preamble =
3922 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3923 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3924 params.use_short_slot_time =
3925 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3926 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3927 params.basic_rates =
3928 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3929 params.basic_rates_len =
3930 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3931 }
fd8aaaf3
FF
3932 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3933 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3934 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3935 params.ht_opmode =
3936 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3937
53cabad7
JB
3938 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
3939 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3940 return -EINVAL;
3941 params.p2p_ctwindow =
3942 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
3943 if (params.p2p_ctwindow < 0)
3944 return -EINVAL;
3945 if (params.p2p_ctwindow != 0 &&
3946 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
3947 return -EINVAL;
3948 }
3949
3950 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
3951 u8 tmp;
3952
3953 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3954 return -EINVAL;
3955 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
3956 if (tmp > 1)
3957 return -EINVAL;
3958 params.p2p_opp_ps = tmp;
3959 if (params.p2p_opp_ps &&
3960 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
3961 return -EINVAL;
3962 }
3963
4c476991
JB
3964 if (!rdev->ops->change_bss)
3965 return -EOPNOTSUPP;
9f1ba906 3966
074ac8df 3967 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3968 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3969 return -EOPNOTSUPP;
3b85875a 3970
e35e4d28 3971 return rdev_change_bss(rdev, dev, &params);
9f1ba906
JM
3972}
3973
b54452b0 3974static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3975 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3976 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3977 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3978 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3979 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3980 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3981};
3982
3983static int parse_reg_rule(struct nlattr *tb[],
3984 struct ieee80211_reg_rule *reg_rule)
3985{
3986 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3987 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3988
3989 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3990 return -EINVAL;
3991 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3992 return -EINVAL;
3993 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3994 return -EINVAL;
3995 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3996 return -EINVAL;
3997 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3998 return -EINVAL;
3999
4000 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
4001
4002 freq_range->start_freq_khz =
4003 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
4004 freq_range->end_freq_khz =
4005 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
4006 freq_range->max_bandwidth_khz =
4007 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
4008
4009 power_rule->max_eirp =
4010 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
4011
4012 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
4013 power_rule->max_antenna_gain =
4014 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
4015
4016 return 0;
4017}
4018
4019static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
4020{
4021 int r;
4022 char *data = NULL;
57b5ce07 4023 enum nl80211_user_reg_hint_type user_reg_hint_type;
b2e1b302 4024
80778f18
LR
4025 /*
4026 * You should only get this when cfg80211 hasn't yet initialized
4027 * completely when built-in to the kernel right between the time
4028 * window between nl80211_init() and regulatory_init(), if that is
4029 * even possible.
4030 */
458f4f9e 4031 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 4032 return -EINPROGRESS;
80778f18 4033
fe33eb39
LR
4034 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4035 return -EINVAL;
b2e1b302
LR
4036
4037 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4038
57b5ce07
LR
4039 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
4040 user_reg_hint_type =
4041 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
4042 else
4043 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
4044
4045 switch (user_reg_hint_type) {
4046 case NL80211_USER_REG_HINT_USER:
4047 case NL80211_USER_REG_HINT_CELL_BASE:
4048 break;
4049 default:
4050 return -EINVAL;
4051 }
4052
4053 r = regulatory_hint_user(data, user_reg_hint_type);
fe33eb39 4054
b2e1b302
LR
4055 return r;
4056}
4057
24bdd9f4 4058static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 4059 struct genl_info *info)
93da9cc1 4060{
4c476991 4061 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4062 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
4063 struct wireless_dev *wdev = dev->ieee80211_ptr;
4064 struct mesh_config cur_params;
4065 int err = 0;
93da9cc1 4066 void *hdr;
4067 struct nlattr *pinfoattr;
4068 struct sk_buff *msg;
4069
29cbe68c
JB
4070 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4071 return -EOPNOTSUPP;
4072
24bdd9f4 4073 if (!rdev->ops->get_mesh_config)
4c476991 4074 return -EOPNOTSUPP;
f3f92586 4075
29cbe68c
JB
4076 wdev_lock(wdev);
4077 /* If not connected, get default parameters */
4078 if (!wdev->mesh_id_len)
4079 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
4080 else
e35e4d28 4081 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
4082 wdev_unlock(wdev);
4083
93da9cc1 4084 if (err)
4c476991 4085 return err;
93da9cc1 4086
4087 /* Draw up a netlink message to send back */
fd2120ca 4088 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4089 if (!msg)
4090 return -ENOMEM;
15e47304 4091 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 4092 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 4093 if (!hdr)
efe1cf0c 4094 goto out;
24bdd9f4 4095 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 4096 if (!pinfoattr)
4097 goto nla_put_failure;
9360ffd1
DM
4098 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4099 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
4100 cur_params.dot11MeshRetryTimeout) ||
4101 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4102 cur_params.dot11MeshConfirmTimeout) ||
4103 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
4104 cur_params.dot11MeshHoldingTimeout) ||
4105 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
4106 cur_params.dot11MeshMaxPeerLinks) ||
4107 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
4108 cur_params.dot11MeshMaxRetries) ||
4109 nla_put_u8(msg, NL80211_MESHCONF_TTL,
4110 cur_params.dot11MeshTTL) ||
4111 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
4112 cur_params.element_ttl) ||
4113 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4114 cur_params.auto_open_plinks) ||
7eab0f64
JL
4115 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4116 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
4117 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4118 cur_params.dot11MeshHWMPmaxPREQretries) ||
4119 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
4120 cur_params.path_refresh_time) ||
4121 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4122 cur_params.min_discovery_timeout) ||
4123 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4124 cur_params.dot11MeshHWMPactivePathTimeout) ||
4125 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
4126 cur_params.dot11MeshHWMPpreqMinInterval) ||
4127 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
4128 cur_params.dot11MeshHWMPperrMinInterval) ||
4129 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4130 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
4131 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
4132 cur_params.dot11MeshHWMPRootMode) ||
4133 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
4134 cur_params.dot11MeshHWMPRannInterval) ||
4135 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
4136 cur_params.dot11MeshGateAnnouncementProtocol) ||
4137 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
4138 cur_params.dot11MeshForwarding) ||
4139 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
4140 cur_params.rssi_threshold) ||
4141 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4142 cur_params.ht_opmode) ||
4143 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4144 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
4145 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4146 cur_params.dot11MeshHWMProotInterval) ||
4147 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
4148 cur_params.dot11MeshHWMPconfirmationInterval) ||
4149 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
4150 cur_params.power_mode) ||
4151 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
4152 cur_params.dot11MeshAwakeWindowDuration))
9360ffd1 4153 goto nla_put_failure;
93da9cc1 4154 nla_nest_end(msg, pinfoattr);
4155 genlmsg_end(msg, hdr);
4c476991 4156 return genlmsg_reply(msg, info);
93da9cc1 4157
3b85875a 4158 nla_put_failure:
93da9cc1 4159 genlmsg_cancel(msg, hdr);
efe1cf0c 4160 out:
d080e275 4161 nlmsg_free(msg);
4c476991 4162 return -ENOBUFS;
93da9cc1 4163}
4164
b54452b0 4165static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 4166 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
4167 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
4168 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
4169 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
4170 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
4171 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 4172 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 4173 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 4174 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 4175 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
4176 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
4177 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
4178 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
4179 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 4180 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 4181 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 4182 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 4183 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 4184 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 4185 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
4186 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
4187 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
4188 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
4189 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 4190 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
4191 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
4192 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
93da9cc1 4193};
4194
c80d545d
JC
4195static const struct nla_policy
4196 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 4197 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
4198 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
4199 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 4200 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 4201 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 4202 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 4203 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
4204};
4205
24bdd9f4 4206static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
4207 struct mesh_config *cfg,
4208 u32 *mask_out)
93da9cc1 4209{
93da9cc1 4210 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 4211 u32 mask = 0;
93da9cc1 4212
ea54fba2
MP
4213#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
4214do { \
4215 if (tb[attr]) { \
4216 if (fn(tb[attr]) < min || fn(tb[attr]) > max) \
4217 return -EINVAL; \
4218 cfg->param = fn(tb[attr]); \
4219 mask |= (1 << (attr - 1)); \
4220 } \
4221} while (0)
bd90fdcc
JB
4222
4223
24bdd9f4 4224 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 4225 return -EINVAL;
4226 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 4227 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 4228 nl80211_meshconf_params_policy))
93da9cc1 4229 return -EINVAL;
4230
93da9cc1 4231 /* This makes sure that there aren't more than 32 mesh config
4232 * parameters (otherwise our bitfield scheme would not work.) */
4233 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
4234
4235 /* Fill in the params struct */
ea54fba2 4236 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea
CYY
4237 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
4238 nla_get_u16);
ea54fba2 4239 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea
CYY
4240 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
4241 nla_get_u16);
ea54fba2 4242 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea
CYY
4243 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
4244 nla_get_u16);
ea54fba2 4245 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea
CYY
4246 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
4247 nla_get_u16);
ea54fba2 4248 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea
CYY
4249 mask, NL80211_MESHCONF_MAX_RETRIES,
4250 nla_get_u8);
ea54fba2 4251 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
a4f606ea 4252 mask, NL80211_MESHCONF_TTL, nla_get_u8);
ea54fba2 4253 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea
CYY
4254 mask, NL80211_MESHCONF_ELEMENT_TTL,
4255 nla_get_u8);
ea54fba2 4256 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea
CYY
4257 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
4258 nla_get_u8);
ea54fba2
MP
4259 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
4260 1, 255, mask,
a4f606ea
CYY
4261 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
4262 nla_get_u32);
ea54fba2 4263 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea
CYY
4264 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
4265 nla_get_u8);
ea54fba2 4266 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea
CYY
4267 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
4268 nla_get_u32);
ea54fba2 4269 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea
CYY
4270 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
4271 nla_get_u16);
ea54fba2
MP
4272 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
4273 1, 65535, mask,
a4f606ea
CYY
4274 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
4275 nla_get_u32);
93da9cc1 4276 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
4277 1, 65535, mask,
4278 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
a4f606ea 4279 nla_get_u16);
dca7e943 4280 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
4281 1, 65535, mask,
4282 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
a4f606ea 4283 nla_get_u16);
93da9cc1 4284 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4285 dot11MeshHWMPnetDiameterTraversalTime,
4286 1, 65535, mask,
a4f606ea
CYY
4287 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
4288 nla_get_u16);
ea54fba2
MP
4289 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
4290 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
4291 nla_get_u8);
4292 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
4293 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
a4f606ea 4294 nla_get_u16);
63c5723b 4295 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4296 dot11MeshGateAnnouncementProtocol, 0, 1,
4297 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
a4f606ea 4298 nla_get_u8);
ea54fba2 4299 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea
CYY
4300 mask, NL80211_MESHCONF_FORWARDING,
4301 nla_get_u8);
ea54fba2 4302 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, 1, 255,
a4f606ea
CYY
4303 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
4304 nla_get_u32);
ea54fba2 4305 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode, 0, 16,
a4f606ea 4306 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
4307 nla_get_u16);
4308 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 4309 1, 65535, mask,
ac1073a6
CYY
4310 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
4311 nla_get_u32);
ea54fba2 4312 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 4313 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
4314 nla_get_u16);
4315 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
4316 dot11MeshHWMPconfirmationInterval,
4317 1, 65535, mask,
728b19e5 4318 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 4319 nla_get_u16);
3b1c5a53
MP
4320 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
4321 NL80211_MESH_POWER_ACTIVE,
4322 NL80211_MESH_POWER_MAX,
4323 mask, NL80211_MESHCONF_POWER_MODE,
4324 nla_get_u32);
4325 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
4326 0, 65535, mask,
4327 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
bd90fdcc
JB
4328 if (mask_out)
4329 *mask_out = mask;
c80d545d 4330
bd90fdcc
JB
4331 return 0;
4332
4333#undef FILL_IN_MESH_PARAM_IF_SET
4334}
4335
c80d545d
JC
4336static int nl80211_parse_mesh_setup(struct genl_info *info,
4337 struct mesh_setup *setup)
4338{
4339 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
4340
4341 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
4342 return -EINVAL;
4343 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
4344 info->attrs[NL80211_ATTR_MESH_SETUP],
4345 nl80211_mesh_setup_params_policy))
4346 return -EINVAL;
4347
d299a1f2
JC
4348 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
4349 setup->sync_method =
4350 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
4351 IEEE80211_SYNC_METHOD_VENDOR :
4352 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
4353
c80d545d
JC
4354 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
4355 setup->path_sel_proto =
4356 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
4357 IEEE80211_PATH_PROTOCOL_VENDOR :
4358 IEEE80211_PATH_PROTOCOL_HWMP;
4359
4360 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
4361 setup->path_metric =
4362 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
4363 IEEE80211_PATH_METRIC_VENDOR :
4364 IEEE80211_PATH_METRIC_AIRTIME;
4365
581a8b0f
JC
4366
4367 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 4368 struct nlattr *ieattr =
581a8b0f 4369 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
4370 if (!is_valid_ie_attr(ieattr))
4371 return -EINVAL;
581a8b0f
JC
4372 setup->ie = nla_data(ieattr);
4373 setup->ie_len = nla_len(ieattr);
c80d545d 4374 }
b130e5ce
JC
4375 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
4376 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
4377
4378 return 0;
4379}
4380
24bdd9f4 4381static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 4382 struct genl_info *info)
bd90fdcc
JB
4383{
4384 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4385 struct net_device *dev = info->user_ptr[1];
29cbe68c 4386 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
4387 struct mesh_config cfg;
4388 u32 mask;
4389 int err;
4390
29cbe68c
JB
4391 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
4392 return -EOPNOTSUPP;
4393
24bdd9f4 4394 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
4395 return -EOPNOTSUPP;
4396
24bdd9f4 4397 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
4398 if (err)
4399 return err;
4400
29cbe68c
JB
4401 wdev_lock(wdev);
4402 if (!wdev->mesh_id_len)
4403 err = -ENOLINK;
4404
4405 if (!err)
e35e4d28 4406 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
4407
4408 wdev_unlock(wdev);
4409
4410 return err;
93da9cc1 4411}
4412
f130347c
LR
4413static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
4414{
458f4f9e 4415 const struct ieee80211_regdomain *regdom;
f130347c
LR
4416 struct sk_buff *msg;
4417 void *hdr = NULL;
4418 struct nlattr *nl_reg_rules;
4419 unsigned int i;
4420 int err = -EINVAL;
4421
a1794390 4422 mutex_lock(&cfg80211_mutex);
f130347c
LR
4423
4424 if (!cfg80211_regdomain)
4425 goto out;
4426
fd2120ca 4427 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
4428 if (!msg) {
4429 err = -ENOBUFS;
4430 goto out;
4431 }
4432
15e47304 4433 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
f130347c
LR
4434 NL80211_CMD_GET_REG);
4435 if (!hdr)
efe1cf0c 4436 goto put_failure;
f130347c 4437
57b5ce07
LR
4438 if (reg_last_request_cell_base() &&
4439 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
4440 NL80211_USER_REG_HINT_CELL_BASE))
4441 goto nla_put_failure;
4442
458f4f9e
JB
4443 rcu_read_lock();
4444 regdom = rcu_dereference(cfg80211_regdomain);
4445
4446 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
4447 (regdom->dfs_region &&
4448 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
4449 goto nla_put_failure_rcu;
4450
f130347c
LR
4451 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
4452 if (!nl_reg_rules)
458f4f9e 4453 goto nla_put_failure_rcu;
f130347c 4454
458f4f9e 4455 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
4456 struct nlattr *nl_reg_rule;
4457 const struct ieee80211_reg_rule *reg_rule;
4458 const struct ieee80211_freq_range *freq_range;
4459 const struct ieee80211_power_rule *power_rule;
4460
458f4f9e 4461 reg_rule = &regdom->reg_rules[i];
f130347c
LR
4462 freq_range = &reg_rule->freq_range;
4463 power_rule = &reg_rule->power_rule;
4464
4465 nl_reg_rule = nla_nest_start(msg, i);
4466 if (!nl_reg_rule)
458f4f9e 4467 goto nla_put_failure_rcu;
f130347c 4468
9360ffd1
DM
4469 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
4470 reg_rule->flags) ||
4471 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
4472 freq_range->start_freq_khz) ||
4473 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
4474 freq_range->end_freq_khz) ||
4475 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
4476 freq_range->max_bandwidth_khz) ||
4477 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
4478 power_rule->max_antenna_gain) ||
4479 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
4480 power_rule->max_eirp))
458f4f9e 4481 goto nla_put_failure_rcu;
f130347c
LR
4482
4483 nla_nest_end(msg, nl_reg_rule);
4484 }
458f4f9e 4485 rcu_read_unlock();
f130347c
LR
4486
4487 nla_nest_end(msg, nl_reg_rules);
4488
4489 genlmsg_end(msg, hdr);
134e6375 4490 err = genlmsg_reply(msg, info);
f130347c
LR
4491 goto out;
4492
458f4f9e
JB
4493nla_put_failure_rcu:
4494 rcu_read_unlock();
f130347c
LR
4495nla_put_failure:
4496 genlmsg_cancel(msg, hdr);
efe1cf0c 4497put_failure:
d080e275 4498 nlmsg_free(msg);
f130347c
LR
4499 err = -EMSGSIZE;
4500out:
a1794390 4501 mutex_unlock(&cfg80211_mutex);
f130347c
LR
4502 return err;
4503}
4504
b2e1b302
LR
4505static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
4506{
4507 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
4508 struct nlattr *nl_reg_rule;
4509 char *alpha2 = NULL;
4510 int rem_reg_rules = 0, r = 0;
4511 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4512 u8 dfs_region = 0;
b2e1b302
LR
4513 struct ieee80211_regdomain *rd = NULL;
4514
4515 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4516 return -EINVAL;
4517
4518 if (!info->attrs[NL80211_ATTR_REG_RULES])
4519 return -EINVAL;
4520
4521 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4522
8b60b078
LR
4523 if (info->attrs[NL80211_ATTR_DFS_REGION])
4524 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4525
b2e1b302 4526 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4527 rem_reg_rules) {
b2e1b302
LR
4528 num_rules++;
4529 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4530 return -EINVAL;
b2e1b302
LR
4531 }
4532
b2e1b302 4533 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 4534 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
4535
4536 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
4537 if (!rd)
4538 return -ENOMEM;
b2e1b302
LR
4539
4540 rd->n_reg_rules = num_rules;
4541 rd->alpha2[0] = alpha2[0];
4542 rd->alpha2[1] = alpha2[1];
4543
8b60b078
LR
4544 /*
4545 * Disable DFS master mode if the DFS region was
4546 * not supported or known on this kernel.
4547 */
4548 if (reg_supported_dfs_region(dfs_region))
4549 rd->dfs_region = dfs_region;
4550
b2e1b302 4551 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 4552 rem_reg_rules) {
b2e1b302 4553 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
1a919318
JB
4554 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
4555 reg_rule_policy);
b2e1b302
LR
4556 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
4557 if (r)
4558 goto bad_reg;
4559
4560 rule_idx++;
4561
d0e18f83
LR
4562 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
4563 r = -EINVAL;
b2e1b302 4564 goto bad_reg;
d0e18f83 4565 }
b2e1b302
LR
4566 }
4567
6913b49a
JB
4568 mutex_lock(&cfg80211_mutex);
4569
b2e1b302 4570 r = set_regdom(rd);
6913b49a 4571 /* set_regdom took ownership */
1a919318 4572 rd = NULL;
6913b49a 4573 mutex_unlock(&cfg80211_mutex);
b2e1b302 4574
d2372b31 4575 bad_reg:
b2e1b302 4576 kfree(rd);
d0e18f83 4577 return r;
b2e1b302
LR
4578}
4579
83f5e2cf
JB
4580static int validate_scan_freqs(struct nlattr *freqs)
4581{
4582 struct nlattr *attr1, *attr2;
4583 int n_channels = 0, tmp1, tmp2;
4584
4585 nla_for_each_nested(attr1, freqs, tmp1) {
4586 n_channels++;
4587 /*
4588 * Some hardware has a limited channel list for
4589 * scanning, and it is pretty much nonsensical
4590 * to scan for a channel twice, so disallow that
4591 * and don't require drivers to check that the
4592 * channel list they get isn't longer than what
4593 * they can scan, as long as they can scan all
4594 * the channels they registered at once.
4595 */
4596 nla_for_each_nested(attr2, freqs, tmp2)
4597 if (attr1 != attr2 &&
4598 nla_get_u32(attr1) == nla_get_u32(attr2))
4599 return 0;
4600 }
4601
4602 return n_channels;
4603}
4604
2a519311
JB
4605static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
4606{
4c476991 4607 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 4608 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 4609 struct cfg80211_scan_request *request;
2a519311
JB
4610 struct nlattr *attr;
4611 struct wiphy *wiphy;
83f5e2cf 4612 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 4613 size_t ie_len;
2a519311 4614
f4a11bb0
JB
4615 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4616 return -EINVAL;
4617
79c97e97 4618 wiphy = &rdev->wiphy;
2a519311 4619
4c476991
JB
4620 if (!rdev->ops->scan)
4621 return -EOPNOTSUPP;
2a519311 4622
4c476991
JB
4623 if (rdev->scan_req)
4624 return -EBUSY;
2a519311
JB
4625
4626 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
4627 n_channels = validate_scan_freqs(
4628 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
4629 if (!n_channels)
4630 return -EINVAL;
2a519311 4631 } else {
34850ab2 4632 enum ieee80211_band band;
83f5e2cf
JB
4633 n_channels = 0;
4634
2a519311
JB
4635 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4636 if (wiphy->bands[band])
4637 n_channels += wiphy->bands[band]->n_channels;
4638 }
4639
4640 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4641 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
4642 n_ssids++;
4643
4c476991
JB
4644 if (n_ssids > wiphy->max_scan_ssids)
4645 return -EINVAL;
2a519311 4646
70692ad2
JM
4647 if (info->attrs[NL80211_ATTR_IE])
4648 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4649 else
4650 ie_len = 0;
4651
4c476991
JB
4652 if (ie_len > wiphy->max_scan_ie_len)
4653 return -EINVAL;
18a83659 4654
2a519311 4655 request = kzalloc(sizeof(*request)
a2cd43c5
LC
4656 + sizeof(*request->ssids) * n_ssids
4657 + sizeof(*request->channels) * n_channels
70692ad2 4658 + ie_len, GFP_KERNEL);
4c476991
JB
4659 if (!request)
4660 return -ENOMEM;
2a519311 4661
2a519311 4662 if (n_ssids)
5ba63533 4663 request->ssids = (void *)&request->channels[n_channels];
2a519311 4664 request->n_ssids = n_ssids;
70692ad2
JM
4665 if (ie_len) {
4666 if (request->ssids)
4667 request->ie = (void *)(request->ssids + n_ssids);
4668 else
4669 request->ie = (void *)(request->channels + n_channels);
4670 }
2a519311 4671
584991dc 4672 i = 0;
2a519311
JB
4673 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4674 /* user specified, bail out if channel not found */
2a519311 4675 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
4676 struct ieee80211_channel *chan;
4677
4678 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4679
4680 if (!chan) {
2a519311
JB
4681 err = -EINVAL;
4682 goto out_free;
4683 }
584991dc
JB
4684
4685 /* ignore disabled channels */
4686 if (chan->flags & IEEE80211_CHAN_DISABLED)
4687 continue;
4688
4689 request->channels[i] = chan;
2a519311
JB
4690 i++;
4691 }
4692 } else {
34850ab2
JB
4693 enum ieee80211_band band;
4694
2a519311 4695 /* all channels */
2a519311
JB
4696 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4697 int j;
4698 if (!wiphy->bands[band])
4699 continue;
4700 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4701 struct ieee80211_channel *chan;
4702
4703 chan = &wiphy->bands[band]->channels[j];
4704
4705 if (chan->flags & IEEE80211_CHAN_DISABLED)
4706 continue;
4707
4708 request->channels[i] = chan;
2a519311
JB
4709 i++;
4710 }
4711 }
4712 }
4713
584991dc
JB
4714 if (!i) {
4715 err = -EINVAL;
4716 goto out_free;
4717 }
4718
4719 request->n_channels = i;
4720
2a519311
JB
4721 i = 0;
4722 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4723 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4724 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4725 err = -EINVAL;
4726 goto out_free;
4727 }
57a27e1d 4728 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4729 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4730 i++;
4731 }
4732 }
4733
70692ad2
JM
4734 if (info->attrs[NL80211_ATTR_IE]) {
4735 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4736 memcpy((void *)request->ie,
4737 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4738 request->ie_len);
4739 }
4740
34850ab2 4741 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4742 if (wiphy->bands[i])
4743 request->rates[i] =
4744 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4745
4746 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4747 nla_for_each_nested(attr,
4748 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4749 tmp) {
4750 enum ieee80211_band band = nla_type(attr);
4751
84404623 4752 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4753 err = -EINVAL;
4754 goto out_free;
4755 }
4756 err = ieee80211_get_ratemask(wiphy->bands[band],
4757 nla_data(attr),
4758 nla_len(attr),
4759 &request->rates[band]);
4760 if (err)
4761 goto out_free;
4762 }
4763 }
4764
46856bbf 4765 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
4766 request->flags = nla_get_u32(
4767 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
4768 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
4769 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
4770 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
4771 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
4772 err = -EOPNOTSUPP;
4773 goto out_free;
4774 }
4775 }
ed473771 4776
e9f935e3
RM
4777 request->no_cck =
4778 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4779
fd014284 4780 request->wdev = wdev;
79c97e97 4781 request->wiphy = &rdev->wiphy;
15d6030b 4782 request->scan_start = jiffies;
2a519311 4783
79c97e97 4784 rdev->scan_req = request;
e35e4d28 4785 err = rdev_scan(rdev, request);
2a519311 4786
463d0183 4787 if (!err) {
fd014284
JB
4788 nl80211_send_scan_start(rdev, wdev);
4789 if (wdev->netdev)
4790 dev_hold(wdev->netdev);
4c476991 4791 } else {
2a519311 4792 out_free:
79c97e97 4793 rdev->scan_req = NULL;
2a519311
JB
4794 kfree(request);
4795 }
3b85875a 4796
2a519311
JB
4797 return err;
4798}
4799
807f8a8c
LC
4800static int nl80211_start_sched_scan(struct sk_buff *skb,
4801 struct genl_info *info)
4802{
4803 struct cfg80211_sched_scan_request *request;
4804 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4805 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4806 struct nlattr *attr;
4807 struct wiphy *wiphy;
a1f1c21c 4808 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4809 u32 interval;
807f8a8c
LC
4810 enum ieee80211_band band;
4811 size_t ie_len;
a1f1c21c 4812 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4813
4814 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4815 !rdev->ops->sched_scan_start)
4816 return -EOPNOTSUPP;
4817
4818 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4819 return -EINVAL;
4820
bbe6ad6d
LC
4821 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4822 return -EINVAL;
4823
4824 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4825 if (interval == 0)
4826 return -EINVAL;
4827
807f8a8c
LC
4828 wiphy = &rdev->wiphy;
4829
4830 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4831 n_channels = validate_scan_freqs(
4832 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4833 if (!n_channels)
4834 return -EINVAL;
4835 } else {
4836 n_channels = 0;
4837
4838 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4839 if (wiphy->bands[band])
4840 n_channels += wiphy->bands[band]->n_channels;
4841 }
4842
4843 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4844 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4845 tmp)
4846 n_ssids++;
4847
93b6aa69 4848 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4849 return -EINVAL;
4850
a1f1c21c
LC
4851 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4852 nla_for_each_nested(attr,
4853 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4854 tmp)
4855 n_match_sets++;
4856
4857 if (n_match_sets > wiphy->max_match_sets)
4858 return -EINVAL;
4859
807f8a8c
LC
4860 if (info->attrs[NL80211_ATTR_IE])
4861 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4862 else
4863 ie_len = 0;
4864
5a865bad 4865 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4866 return -EINVAL;
4867
c10841ca
LC
4868 mutex_lock(&rdev->sched_scan_mtx);
4869
4870 if (rdev->sched_scan_req) {
4871 err = -EINPROGRESS;
4872 goto out;
4873 }
4874
807f8a8c 4875 request = kzalloc(sizeof(*request)
a2cd43c5 4876 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4877 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4878 + sizeof(*request->channels) * n_channels
807f8a8c 4879 + ie_len, GFP_KERNEL);
c10841ca
LC
4880 if (!request) {
4881 err = -ENOMEM;
4882 goto out;
4883 }
807f8a8c
LC
4884
4885 if (n_ssids)
4886 request->ssids = (void *)&request->channels[n_channels];
4887 request->n_ssids = n_ssids;
4888 if (ie_len) {
4889 if (request->ssids)
4890 request->ie = (void *)(request->ssids + n_ssids);
4891 else
4892 request->ie = (void *)(request->channels + n_channels);
4893 }
4894
a1f1c21c
LC
4895 if (n_match_sets) {
4896 if (request->ie)
4897 request->match_sets = (void *)(request->ie + ie_len);
4898 else if (request->ssids)
4899 request->match_sets =
4900 (void *)(request->ssids + n_ssids);
4901 else
4902 request->match_sets =
4903 (void *)(request->channels + n_channels);
4904 }
4905 request->n_match_sets = n_match_sets;
4906
807f8a8c
LC
4907 i = 0;
4908 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4909 /* user specified, bail out if channel not found */
4910 nla_for_each_nested(attr,
4911 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4912 tmp) {
4913 struct ieee80211_channel *chan;
4914
4915 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4916
4917 if (!chan) {
4918 err = -EINVAL;
4919 goto out_free;
4920 }
4921
4922 /* ignore disabled channels */
4923 if (chan->flags & IEEE80211_CHAN_DISABLED)
4924 continue;
4925
4926 request->channels[i] = chan;
4927 i++;
4928 }
4929 } else {
4930 /* all channels */
4931 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4932 int j;
4933 if (!wiphy->bands[band])
4934 continue;
4935 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4936 struct ieee80211_channel *chan;
4937
4938 chan = &wiphy->bands[band]->channels[j];
4939
4940 if (chan->flags & IEEE80211_CHAN_DISABLED)
4941 continue;
4942
4943 request->channels[i] = chan;
4944 i++;
4945 }
4946 }
4947 }
4948
4949 if (!i) {
4950 err = -EINVAL;
4951 goto out_free;
4952 }
4953
4954 request->n_channels = i;
4955
4956 i = 0;
4957 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4958 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4959 tmp) {
57a27e1d 4960 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4961 err = -EINVAL;
4962 goto out_free;
4963 }
57a27e1d 4964 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4965 memcpy(request->ssids[i].ssid, nla_data(attr),
4966 nla_len(attr));
807f8a8c
LC
4967 i++;
4968 }
4969 }
4970
a1f1c21c
LC
4971 i = 0;
4972 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4973 nla_for_each_nested(attr,
4974 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4975 tmp) {
88e920b4 4976 struct nlattr *ssid, *rssi;
a1f1c21c
LC
4977
4978 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4979 nla_data(attr), nla_len(attr),
4980 nl80211_match_policy);
4a4ab0d7 4981 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4982 if (ssid) {
4983 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4984 err = -EINVAL;
4985 goto out_free;
4986 }
4987 memcpy(request->match_sets[i].ssid.ssid,
4988 nla_data(ssid), nla_len(ssid));
4989 request->match_sets[i].ssid.ssid_len =
4990 nla_len(ssid);
4991 }
88e920b4
TP
4992 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
4993 if (rssi)
4994 request->rssi_thold = nla_get_u32(rssi);
4995 else
4996 request->rssi_thold =
4997 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
4998 i++;
4999 }
5000 }
5001
807f8a8c
LC
5002 if (info->attrs[NL80211_ATTR_IE]) {
5003 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5004 memcpy((void *)request->ie,
5005 nla_data(info->attrs[NL80211_ATTR_IE]),
5006 request->ie_len);
5007 }
5008
46856bbf 5009 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) {
ed473771
SL
5010 request->flags = nla_get_u32(
5011 info->attrs[NL80211_ATTR_SCAN_FLAGS]);
15d6030b
SL
5012 if (((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
5013 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
5014 ((request->flags & NL80211_SCAN_FLAG_FLUSH) &&
5015 !(wiphy->features & NL80211_FEATURE_SCAN_FLUSH))) {
46856bbf
SL
5016 err = -EOPNOTSUPP;
5017 goto out_free;
5018 }
5019 }
ed473771 5020
807f8a8c
LC
5021 request->dev = dev;
5022 request->wiphy = &rdev->wiphy;
bbe6ad6d 5023 request->interval = interval;
15d6030b 5024 request->scan_start = jiffies;
807f8a8c 5025
e35e4d28 5026 err = rdev_sched_scan_start(rdev, dev, request);
807f8a8c
LC
5027 if (!err) {
5028 rdev->sched_scan_req = request;
5029 nl80211_send_sched_scan(rdev, dev,
5030 NL80211_CMD_START_SCHED_SCAN);
5031 goto out;
5032 }
5033
5034out_free:
5035 kfree(request);
5036out:
c10841ca 5037 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
5038 return err;
5039}
5040
5041static int nl80211_stop_sched_scan(struct sk_buff *skb,
5042 struct genl_info *info)
5043{
5044 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 5045 int err;
807f8a8c
LC
5046
5047 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
5048 !rdev->ops->sched_scan_stop)
5049 return -EOPNOTSUPP;
5050
c10841ca
LC
5051 mutex_lock(&rdev->sched_scan_mtx);
5052 err = __cfg80211_stop_sched_scan(rdev, false);
5053 mutex_unlock(&rdev->sched_scan_mtx);
5054
5055 return err;
807f8a8c
LC
5056}
5057
9720bb3a
JB
5058static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
5059 u32 seq, int flags,
2a519311 5060 struct cfg80211_registered_device *rdev,
48ab905d
JB
5061 struct wireless_dev *wdev,
5062 struct cfg80211_internal_bss *intbss)
2a519311 5063{
48ab905d 5064 struct cfg80211_bss *res = &intbss->pub;
9caf0364 5065 const struct cfg80211_bss_ies *ies;
2a519311
JB
5066 void *hdr;
5067 struct nlattr *bss;
8cef2c9d 5068 bool tsf = false;
48ab905d
JB
5069
5070 ASSERT_WDEV_LOCK(wdev);
2a519311 5071
15e47304 5072 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
5073 NL80211_CMD_NEW_SCAN_RESULTS);
5074 if (!hdr)
5075 return -1;
5076
9720bb3a
JB
5077 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
5078
9360ffd1
DM
5079 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
5080 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
5081 goto nla_put_failure;
2a519311
JB
5082
5083 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
5084 if (!bss)
5085 goto nla_put_failure;
9360ffd1 5086 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 5087 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 5088 goto nla_put_failure;
9caf0364
JB
5089
5090 rcu_read_lock();
5091 ies = rcu_dereference(res->ies);
8cef2c9d
JB
5092 if (ies) {
5093 if (nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5094 goto fail_unlock_rcu;
5095 tsf = true;
5096 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
5097 ies->len, ies->data))
5098 goto fail_unlock_rcu;
9caf0364
JB
5099 }
5100 ies = rcu_dereference(res->beacon_ies);
8cef2c9d
JB
5101 if (ies) {
5102 if (!tsf && nla_put_u64(msg, NL80211_BSS_TSF, ies->tsf))
5103 goto fail_unlock_rcu;
5104 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
5105 ies->len, ies->data))
5106 goto fail_unlock_rcu;
9caf0364
JB
5107 }
5108 rcu_read_unlock();
5109
9360ffd1
DM
5110 if (res->beacon_interval &&
5111 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
5112 goto nla_put_failure;
5113 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
5114 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
5115 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
5116 jiffies_to_msecs(jiffies - intbss->ts)))
5117 goto nla_put_failure;
2a519311 5118
77965c97 5119 switch (rdev->wiphy.signal_type) {
2a519311 5120 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
5121 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
5122 goto nla_put_failure;
2a519311
JB
5123 break;
5124 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
5125 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
5126 goto nla_put_failure;
2a519311
JB
5127 break;
5128 default:
5129 break;
5130 }
5131
48ab905d 5132 switch (wdev->iftype) {
074ac8df 5133 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 5134 case NL80211_IFTYPE_STATION:
9360ffd1
DM
5135 if (intbss == wdev->current_bss &&
5136 nla_put_u32(msg, NL80211_BSS_STATUS,
5137 NL80211_BSS_STATUS_ASSOCIATED))
5138 goto nla_put_failure;
48ab905d
JB
5139 break;
5140 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
5141 if (intbss == wdev->current_bss &&
5142 nla_put_u32(msg, NL80211_BSS_STATUS,
5143 NL80211_BSS_STATUS_IBSS_JOINED))
5144 goto nla_put_failure;
48ab905d
JB
5145 break;
5146 default:
5147 break;
5148 }
5149
2a519311
JB
5150 nla_nest_end(msg, bss);
5151
5152 return genlmsg_end(msg, hdr);
5153
8cef2c9d
JB
5154 fail_unlock_rcu:
5155 rcu_read_unlock();
2a519311
JB
5156 nla_put_failure:
5157 genlmsg_cancel(msg, hdr);
5158 return -EMSGSIZE;
5159}
5160
5161static int nl80211_dump_scan(struct sk_buff *skb,
5162 struct netlink_callback *cb)
5163{
48ab905d
JB
5164 struct cfg80211_registered_device *rdev;
5165 struct net_device *dev;
2a519311 5166 struct cfg80211_internal_bss *scan;
48ab905d 5167 struct wireless_dev *wdev;
2a519311
JB
5168 int start = cb->args[1], idx = 0;
5169 int err;
5170
67748893
JB
5171 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
5172 if (err)
5173 return err;
2a519311 5174
48ab905d 5175 wdev = dev->ieee80211_ptr;
2a519311 5176
48ab905d
JB
5177 wdev_lock(wdev);
5178 spin_lock_bh(&rdev->bss_lock);
5179 cfg80211_bss_expire(rdev);
5180
9720bb3a
JB
5181 cb->seq = rdev->bss_generation;
5182
48ab905d 5183 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
5184 if (++idx <= start)
5185 continue;
9720bb3a 5186 if (nl80211_send_bss(skb, cb,
2a519311 5187 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 5188 rdev, wdev, scan) < 0) {
2a519311 5189 idx--;
67748893 5190 break;
2a519311
JB
5191 }
5192 }
5193
48ab905d
JB
5194 spin_unlock_bh(&rdev->bss_lock);
5195 wdev_unlock(wdev);
2a519311
JB
5196
5197 cb->args[1] = idx;
67748893 5198 nl80211_finish_netdev_dump(rdev);
2a519311 5199
67748893 5200 return skb->len;
2a519311
JB
5201}
5202
15e47304 5203static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
61fa713c
HS
5204 int flags, struct net_device *dev,
5205 struct survey_info *survey)
5206{
5207 void *hdr;
5208 struct nlattr *infoattr;
5209
15e47304 5210 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
5211 NL80211_CMD_NEW_SURVEY_RESULTS);
5212 if (!hdr)
5213 return -ENOMEM;
5214
9360ffd1
DM
5215 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
5216 goto nla_put_failure;
61fa713c
HS
5217
5218 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
5219 if (!infoattr)
5220 goto nla_put_failure;
5221
9360ffd1
DM
5222 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
5223 survey->channel->center_freq))
5224 goto nla_put_failure;
5225
5226 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
5227 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
5228 goto nla_put_failure;
5229 if ((survey->filled & SURVEY_INFO_IN_USE) &&
5230 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
5231 goto nla_put_failure;
5232 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
5233 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
5234 survey->channel_time))
5235 goto nla_put_failure;
5236 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
5237 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
5238 survey->channel_time_busy))
5239 goto nla_put_failure;
5240 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
5241 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
5242 survey->channel_time_ext_busy))
5243 goto nla_put_failure;
5244 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
5245 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
5246 survey->channel_time_rx))
5247 goto nla_put_failure;
5248 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
5249 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
5250 survey->channel_time_tx))
5251 goto nla_put_failure;
61fa713c
HS
5252
5253 nla_nest_end(msg, infoattr);
5254
5255 return genlmsg_end(msg, hdr);
5256
5257 nla_put_failure:
5258 genlmsg_cancel(msg, hdr);
5259 return -EMSGSIZE;
5260}
5261
5262static int nl80211_dump_survey(struct sk_buff *skb,
5263 struct netlink_callback *cb)
5264{
5265 struct survey_info survey;
5266 struct cfg80211_registered_device *dev;
5267 struct net_device *netdev;
61fa713c
HS
5268 int survey_idx = cb->args[1];
5269 int res;
5270
67748893
JB
5271 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
5272 if (res)
5273 return res;
61fa713c
HS
5274
5275 if (!dev->ops->dump_survey) {
5276 res = -EOPNOTSUPP;
5277 goto out_err;
5278 }
5279
5280 while (1) {
180cdc79
LR
5281 struct ieee80211_channel *chan;
5282
e35e4d28 5283 res = rdev_dump_survey(dev, netdev, survey_idx, &survey);
61fa713c
HS
5284 if (res == -ENOENT)
5285 break;
5286 if (res)
5287 goto out_err;
5288
180cdc79
LR
5289 /* Survey without a channel doesn't make sense */
5290 if (!survey.channel) {
5291 res = -EINVAL;
5292 goto out;
5293 }
5294
5295 chan = ieee80211_get_channel(&dev->wiphy,
5296 survey.channel->center_freq);
5297 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
5298 survey_idx++;
5299 continue;
5300 }
5301
61fa713c 5302 if (nl80211_send_survey(skb,
15e47304 5303 NETLINK_CB(cb->skb).portid,
61fa713c
HS
5304 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5305 netdev,
5306 &survey) < 0)
5307 goto out;
5308 survey_idx++;
5309 }
5310
5311 out:
5312 cb->args[1] = survey_idx;
5313 res = skb->len;
5314 out_err:
67748893 5315 nl80211_finish_netdev_dump(dev);
61fa713c
HS
5316 return res;
5317}
5318
b23aa676
SO
5319static bool nl80211_valid_wpa_versions(u32 wpa_versions)
5320{
5321 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
5322 NL80211_WPA_VERSION_2));
5323}
5324
636a5d36
JM
5325static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
5326{
4c476991
JB
5327 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5328 struct net_device *dev = info->user_ptr[1];
19957bb3 5329 struct ieee80211_channel *chan;
e39e5b5e
JM
5330 const u8 *bssid, *ssid, *ie = NULL, *sae_data = NULL;
5331 int err, ssid_len, ie_len = 0, sae_data_len = 0;
19957bb3 5332 enum nl80211_auth_type auth_type;
fffd0934 5333 struct key_parse key;
d5cdfacb 5334 bool local_state_change;
636a5d36 5335
f4a11bb0
JB
5336 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5337 return -EINVAL;
5338
5339 if (!info->attrs[NL80211_ATTR_MAC])
5340 return -EINVAL;
5341
1778092e
JM
5342 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
5343 return -EINVAL;
5344
19957bb3
JB
5345 if (!info->attrs[NL80211_ATTR_SSID])
5346 return -EINVAL;
5347
5348 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
5349 return -EINVAL;
5350
fffd0934
JB
5351 err = nl80211_parse_key(info, &key);
5352 if (err)
5353 return err;
5354
5355 if (key.idx >= 0) {
e31b8213
JB
5356 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
5357 return -EINVAL;
fffd0934
JB
5358 if (!key.p.key || !key.p.key_len)
5359 return -EINVAL;
5360 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
5361 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
5362 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
5363 key.p.key_len != WLAN_KEY_LEN_WEP104))
5364 return -EINVAL;
5365 if (key.idx > 4)
5366 return -EINVAL;
5367 } else {
5368 key.p.key_len = 0;
5369 key.p.key = NULL;
5370 }
5371
afea0b7a
JB
5372 if (key.idx >= 0) {
5373 int i;
5374 bool ok = false;
5375 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
5376 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
5377 ok = true;
5378 break;
5379 }
5380 }
4c476991
JB
5381 if (!ok)
5382 return -EINVAL;
afea0b7a
JB
5383 }
5384
4c476991
JB
5385 if (!rdev->ops->auth)
5386 return -EOPNOTSUPP;
636a5d36 5387
074ac8df 5388 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5389 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5390 return -EOPNOTSUPP;
eec60b03 5391
19957bb3 5392 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 5393 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 5394 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5395 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5396 return -EINVAL;
636a5d36 5397
19957bb3
JB
5398 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5399 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5400
5401 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5402 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5403 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5404 }
5405
19957bb3 5406 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 5407 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 5408 return -EINVAL;
636a5d36 5409
e39e5b5e
JM
5410 if (auth_type == NL80211_AUTHTYPE_SAE &&
5411 !info->attrs[NL80211_ATTR_SAE_DATA])
5412 return -EINVAL;
5413
5414 if (info->attrs[NL80211_ATTR_SAE_DATA]) {
5415 if (auth_type != NL80211_AUTHTYPE_SAE)
5416 return -EINVAL;
5417 sae_data = nla_data(info->attrs[NL80211_ATTR_SAE_DATA]);
5418 sae_data_len = nla_len(info->attrs[NL80211_ATTR_SAE_DATA]);
5419 /* need to include at least Auth Transaction and Status Code */
5420 if (sae_data_len < 4)
5421 return -EINVAL;
5422 }
5423
d5cdfacb
JM
5424 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5425
95de817b
JB
5426 /*
5427 * Since we no longer track auth state, ignore
5428 * requests to only change local state.
5429 */
5430 if (local_state_change)
5431 return 0;
5432
4c476991
JB
5433 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
5434 ssid, ssid_len, ie, ie_len,
e39e5b5e
JM
5435 key.p.key, key.p.key_len, key.idx,
5436 sae_data, sae_data_len);
636a5d36
JM
5437}
5438
c0692b8f
JB
5439static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
5440 struct genl_info *info,
3dc27d25
JB
5441 struct cfg80211_crypto_settings *settings,
5442 int cipher_limit)
b23aa676 5443{
c0b2bbd8
JB
5444 memset(settings, 0, sizeof(*settings));
5445
b23aa676
SO
5446 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
5447
c0692b8f
JB
5448 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
5449 u16 proto;
5450 proto = nla_get_u16(
5451 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
5452 settings->control_port_ethertype = cpu_to_be16(proto);
5453 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
5454 proto != ETH_P_PAE)
5455 return -EINVAL;
5456 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
5457 settings->control_port_no_encrypt = true;
5458 } else
5459 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
5460
b23aa676
SO
5461 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
5462 void *data;
5463 int len, i;
5464
5465 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5466 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
5467 settings->n_ciphers_pairwise = len / sizeof(u32);
5468
5469 if (len % sizeof(u32))
5470 return -EINVAL;
5471
3dc27d25 5472 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
5473 return -EINVAL;
5474
5475 memcpy(settings->ciphers_pairwise, data, len);
5476
5477 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
5478 if (!cfg80211_supported_cipher_suite(
5479 &rdev->wiphy,
b23aa676
SO
5480 settings->ciphers_pairwise[i]))
5481 return -EINVAL;
5482 }
5483
5484 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
5485 settings->cipher_group =
5486 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
5487 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
5488 settings->cipher_group))
b23aa676
SO
5489 return -EINVAL;
5490 }
5491
5492 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
5493 settings->wpa_versions =
5494 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
5495 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
5496 return -EINVAL;
5497 }
5498
5499 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
5500 void *data;
6d30240e 5501 int len;
b23aa676
SO
5502
5503 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
5504 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
5505 settings->n_akm_suites = len / sizeof(u32);
5506
5507 if (len % sizeof(u32))
5508 return -EINVAL;
5509
1b9ca027
JM
5510 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
5511 return -EINVAL;
5512
b23aa676 5513 memcpy(settings->akm_suites, data, len);
b23aa676
SO
5514 }
5515
5516 return 0;
5517}
5518
636a5d36
JM
5519static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
5520{
4c476991
JB
5521 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5522 struct net_device *dev = info->user_ptr[1];
19957bb3 5523 struct cfg80211_crypto_settings crypto;
f444de05 5524 struct ieee80211_channel *chan;
3e5d7649 5525 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
5526 int err, ssid_len, ie_len = 0;
5527 bool use_mfp = false;
7e7c8926
BG
5528 u32 flags = 0;
5529 struct ieee80211_ht_cap *ht_capa = NULL;
5530 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 5531
f4a11bb0
JB
5532 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5533 return -EINVAL;
5534
5535 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
5536 !info->attrs[NL80211_ATTR_SSID] ||
5537 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
5538 return -EINVAL;
5539
4c476991
JB
5540 if (!rdev->ops->assoc)
5541 return -EOPNOTSUPP;
636a5d36 5542
074ac8df 5543 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5544 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5545 return -EOPNOTSUPP;
eec60b03 5546
19957bb3 5547 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5548
19957bb3
JB
5549 chan = ieee80211_get_channel(&rdev->wiphy,
5550 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5551 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5552 return -EINVAL;
636a5d36 5553
19957bb3
JB
5554 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5555 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5556
5557 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5558 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5559 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5560 }
5561
dc6382ce 5562 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 5563 enum nl80211_mfp mfp =
dc6382ce 5564 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 5565 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 5566 use_mfp = true;
4c476991
JB
5567 else if (mfp != NL80211_MFP_NO)
5568 return -EINVAL;
dc6382ce
JM
5569 }
5570
3e5d7649
JB
5571 if (info->attrs[NL80211_ATTR_PREV_BSSID])
5572 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
5573
7e7c8926
BG
5574 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5575 flags |= ASSOC_REQ_DISABLE_HT;
5576
5577 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5578 ht_capa_mask =
5579 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
5580
5581 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5582 if (!ht_capa_mask)
5583 return -EINVAL;
5584 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5585 }
5586
c0692b8f 5587 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 5588 if (!err)
3e5d7649
JB
5589 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
5590 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
5591 &crypto, flags, ht_capa,
5592 ht_capa_mask);
636a5d36 5593
636a5d36
JM
5594 return err;
5595}
5596
5597static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
5598{
4c476991
JB
5599 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5600 struct net_device *dev = info->user_ptr[1];
19957bb3 5601 const u8 *ie = NULL, *bssid;
4c476991 5602 int ie_len = 0;
19957bb3 5603 u16 reason_code;
d5cdfacb 5604 bool local_state_change;
636a5d36 5605
f4a11bb0
JB
5606 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5607 return -EINVAL;
5608
5609 if (!info->attrs[NL80211_ATTR_MAC])
5610 return -EINVAL;
5611
5612 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5613 return -EINVAL;
5614
4c476991
JB
5615 if (!rdev->ops->deauth)
5616 return -EOPNOTSUPP;
636a5d36 5617
074ac8df 5618 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5619 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5620 return -EOPNOTSUPP;
eec60b03 5621
19957bb3 5622 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5623
19957bb3
JB
5624 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5625 if (reason_code == 0) {
f4a11bb0 5626 /* Reason Code 0 is reserved */
4c476991 5627 return -EINVAL;
255e737e 5628 }
636a5d36
JM
5629
5630 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5631 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5632 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5633 }
5634
d5cdfacb
JM
5635 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5636
4c476991
JB
5637 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
5638 local_state_change);
636a5d36
JM
5639}
5640
5641static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
5642{
4c476991
JB
5643 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5644 struct net_device *dev = info->user_ptr[1];
19957bb3 5645 const u8 *ie = NULL, *bssid;
4c476991 5646 int ie_len = 0;
19957bb3 5647 u16 reason_code;
d5cdfacb 5648 bool local_state_change;
636a5d36 5649
f4a11bb0
JB
5650 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5651 return -EINVAL;
5652
5653 if (!info->attrs[NL80211_ATTR_MAC])
5654 return -EINVAL;
5655
5656 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5657 return -EINVAL;
5658
4c476991
JB
5659 if (!rdev->ops->disassoc)
5660 return -EOPNOTSUPP;
636a5d36 5661
074ac8df 5662 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5663 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5664 return -EOPNOTSUPP;
eec60b03 5665
19957bb3 5666 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5667
19957bb3
JB
5668 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5669 if (reason_code == 0) {
f4a11bb0 5670 /* Reason Code 0 is reserved */
4c476991 5671 return -EINVAL;
255e737e 5672 }
636a5d36
JM
5673
5674 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5675 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5676 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5677 }
5678
d5cdfacb
JM
5679 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5680
4c476991
JB
5681 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
5682 local_state_change);
636a5d36
JM
5683}
5684
dd5b4cc7
FF
5685static bool
5686nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
5687 int mcast_rate[IEEE80211_NUM_BANDS],
5688 int rateval)
5689{
5690 struct wiphy *wiphy = &rdev->wiphy;
5691 bool found = false;
5692 int band, i;
5693
5694 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5695 struct ieee80211_supported_band *sband;
5696
5697 sband = wiphy->bands[band];
5698 if (!sband)
5699 continue;
5700
5701 for (i = 0; i < sband->n_bitrates; i++) {
5702 if (sband->bitrates[i].bitrate == rateval) {
5703 mcast_rate[band] = i + 1;
5704 found = true;
5705 break;
5706 }
5707 }
5708 }
5709
5710 return found;
5711}
5712
04a773ad
JB
5713static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
5714{
4c476991
JB
5715 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5716 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
5717 struct cfg80211_ibss_params ibss;
5718 struct wiphy *wiphy;
fffd0934 5719 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
5720 int err;
5721
8e30bc55
JB
5722 memset(&ibss, 0, sizeof(ibss));
5723
04a773ad
JB
5724 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5725 return -EINVAL;
5726
683b6d3b 5727 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
5728 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5729 return -EINVAL;
5730
8e30bc55
JB
5731 ibss.beacon_interval = 100;
5732
5733 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
5734 ibss.beacon_interval =
5735 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5736 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
5737 return -EINVAL;
5738 }
5739
4c476991
JB
5740 if (!rdev->ops->join_ibss)
5741 return -EOPNOTSUPP;
04a773ad 5742
4c476991
JB
5743 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5744 return -EOPNOTSUPP;
04a773ad 5745
79c97e97 5746 wiphy = &rdev->wiphy;
04a773ad 5747
39193498 5748 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 5749 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
5750
5751 if (!is_valid_ether_addr(ibss.bssid))
5752 return -EINVAL;
5753 }
04a773ad
JB
5754 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5755 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5756
5757 if (info->attrs[NL80211_ATTR_IE]) {
5758 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5759 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5760 }
5761
683b6d3b
JB
5762 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
5763 if (err)
5764 return err;
04a773ad 5765
683b6d3b 5766 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef))
54858ee5
AS
5767 return -EINVAL;
5768
db9c64cf
JB
5769 if (ibss.chandef.width > NL80211_CHAN_WIDTH_40)
5770 return -EINVAL;
5771 if (ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
5772 !(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
c04d6150 5773 return -EINVAL;
db9c64cf 5774
04a773ad 5775 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5776 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5777
fbd2c8dc
TP
5778 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5779 u8 *rates =
5780 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5781 int n_rates =
5782 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5783 struct ieee80211_supported_band *sband =
683b6d3b 5784 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 5785
34850ab2
JB
5786 err = ieee80211_get_ratemask(sband, rates, n_rates,
5787 &ibss.basic_rates);
5788 if (err)
5789 return err;
fbd2c8dc 5790 }
dd5b4cc7
FF
5791
5792 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5793 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5794 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5795 return -EINVAL;
fbd2c8dc 5796
4c476991 5797 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
5798 bool no_ht = false;
5799
4c476991 5800 connkeys = nl80211_parse_connkeys(rdev,
de7044ee
SM
5801 info->attrs[NL80211_ATTR_KEYS],
5802 &no_ht);
4c476991
JB
5803 if (IS_ERR(connkeys))
5804 return PTR_ERR(connkeys);
de7044ee 5805
3d9d1d66
JB
5806 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
5807 no_ht) {
de7044ee
SM
5808 kfree(connkeys);
5809 return -EINVAL;
5810 }
4c476991 5811 }
04a773ad 5812
267335d6
AQ
5813 ibss.control_port =
5814 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5815
4c476991 5816 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5817 if (err)
5818 kfree(connkeys);
04a773ad
JB
5819 return err;
5820}
5821
5822static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5823{
4c476991
JB
5824 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5825 struct net_device *dev = info->user_ptr[1];
04a773ad 5826
4c476991
JB
5827 if (!rdev->ops->leave_ibss)
5828 return -EOPNOTSUPP;
04a773ad 5829
4c476991
JB
5830 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5831 return -EOPNOTSUPP;
04a773ad 5832
4c476991 5833 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5834}
5835
f4e583c8
AQ
5836static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
5837{
5838 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5839 struct net_device *dev = info->user_ptr[1];
5840 int mcast_rate[IEEE80211_NUM_BANDS];
5841 u32 nla_rate;
5842 int err;
5843
5844 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5845 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5846 return -EOPNOTSUPP;
5847
5848 if (!rdev->ops->set_mcast_rate)
5849 return -EOPNOTSUPP;
5850
5851 memset(mcast_rate, 0, sizeof(mcast_rate));
5852
5853 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
5854 return -EINVAL;
5855
5856 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
5857 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
5858 return -EINVAL;
5859
5860 err = rdev->ops->set_mcast_rate(&rdev->wiphy, dev, mcast_rate);
5861
5862 return err;
5863}
5864
5865
aff89a9b
JB
5866#ifdef CONFIG_NL80211_TESTMODE
5867static struct genl_multicast_group nl80211_testmode_mcgrp = {
5868 .name = "testmode",
5869};
5870
5871static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5872{
4c476991 5873 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5874 int err;
5875
5876 if (!info->attrs[NL80211_ATTR_TESTDATA])
5877 return -EINVAL;
5878
aff89a9b
JB
5879 err = -EOPNOTSUPP;
5880 if (rdev->ops->testmode_cmd) {
5881 rdev->testmode_info = info;
e35e4d28 5882 err = rdev_testmode_cmd(rdev,
aff89a9b
JB
5883 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5884 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5885 rdev->testmode_info = NULL;
5886 }
5887
aff89a9b
JB
5888 return err;
5889}
5890
71063f0e
WYG
5891static int nl80211_testmode_dump(struct sk_buff *skb,
5892 struct netlink_callback *cb)
5893{
00918d33 5894 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5895 int err;
5896 long phy_idx;
5897 void *data = NULL;
5898 int data_len = 0;
5899
5900 if (cb->args[0]) {
5901 /*
5902 * 0 is a valid index, but not valid for args[0],
5903 * so we need to offset by 1.
5904 */
5905 phy_idx = cb->args[0] - 1;
5906 } else {
5907 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5908 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5909 nl80211_policy);
5910 if (err)
5911 return err;
00918d33 5912
2bd7e35d
JB
5913 mutex_lock(&cfg80211_mutex);
5914 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
5915 nl80211_fam.attrbuf);
5916 if (IS_ERR(rdev)) {
5917 mutex_unlock(&cfg80211_mutex);
5918 return PTR_ERR(rdev);
00918d33 5919 }
2bd7e35d
JB
5920 phy_idx = rdev->wiphy_idx;
5921 rdev = NULL;
5922 mutex_unlock(&cfg80211_mutex);
5923
71063f0e
WYG
5924 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5925 cb->args[1] =
5926 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5927 }
5928
5929 if (cb->args[1]) {
5930 data = nla_data((void *)cb->args[1]);
5931 data_len = nla_len((void *)cb->args[1]);
5932 }
5933
5934 mutex_lock(&cfg80211_mutex);
00918d33
JB
5935 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5936 if (!rdev) {
71063f0e
WYG
5937 mutex_unlock(&cfg80211_mutex);
5938 return -ENOENT;
5939 }
00918d33 5940 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5941 mutex_unlock(&cfg80211_mutex);
5942
00918d33 5943 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5944 err = -EOPNOTSUPP;
5945 goto out_err;
5946 }
5947
5948 while (1) {
15e47304 5949 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
5950 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5951 NL80211_CMD_TESTMODE);
5952 struct nlattr *tmdata;
5953
9360ffd1 5954 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5955 genlmsg_cancel(skb, hdr);
5956 break;
5957 }
5958
5959 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5960 if (!tmdata) {
5961 genlmsg_cancel(skb, hdr);
5962 break;
5963 }
e35e4d28 5964 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
5965 nla_nest_end(skb, tmdata);
5966
5967 if (err == -ENOBUFS || err == -ENOENT) {
5968 genlmsg_cancel(skb, hdr);
5969 break;
5970 } else if (err) {
5971 genlmsg_cancel(skb, hdr);
5972 goto out_err;
5973 }
5974
5975 genlmsg_end(skb, hdr);
5976 }
5977
5978 err = skb->len;
5979 /* see above */
5980 cb->args[0] = phy_idx + 1;
5981 out_err:
00918d33 5982 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5983 return err;
5984}
5985
aff89a9b
JB
5986static struct sk_buff *
5987__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
15e47304 5988 int approxlen, u32 portid, u32 seq, gfp_t gfp)
aff89a9b
JB
5989{
5990 struct sk_buff *skb;
5991 void *hdr;
5992 struct nlattr *data;
5993
5994 skb = nlmsg_new(approxlen + 100, gfp);
5995 if (!skb)
5996 return NULL;
5997
15e47304 5998 hdr = nl80211hdr_put(skb, portid, seq, 0, NL80211_CMD_TESTMODE);
aff89a9b
JB
5999 if (!hdr) {
6000 kfree_skb(skb);
6001 return NULL;
6002 }
6003
9360ffd1
DM
6004 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
6005 goto nla_put_failure;
aff89a9b
JB
6006 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
6007
6008 ((void **)skb->cb)[0] = rdev;
6009 ((void **)skb->cb)[1] = hdr;
6010 ((void **)skb->cb)[2] = data;
6011
6012 return skb;
6013
6014 nla_put_failure:
6015 kfree_skb(skb);
6016 return NULL;
6017}
6018
6019struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
6020 int approxlen)
6021{
6022 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6023
6024 if (WARN_ON(!rdev->testmode_info))
6025 return NULL;
6026
6027 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
15e47304 6028 rdev->testmode_info->snd_portid,
aff89a9b
JB
6029 rdev->testmode_info->snd_seq,
6030 GFP_KERNEL);
6031}
6032EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
6033
6034int cfg80211_testmode_reply(struct sk_buff *skb)
6035{
6036 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
6037 void *hdr = ((void **)skb->cb)[1];
6038 struct nlattr *data = ((void **)skb->cb)[2];
6039
6040 if (WARN_ON(!rdev->testmode_info)) {
6041 kfree_skb(skb);
6042 return -EINVAL;
6043 }
6044
6045 nla_nest_end(skb, data);
6046 genlmsg_end(skb, hdr);
6047 return genlmsg_reply(skb, rdev->testmode_info);
6048}
6049EXPORT_SYMBOL(cfg80211_testmode_reply);
6050
6051struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
6052 int approxlen, gfp_t gfp)
6053{
6054 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
6055
6056 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
6057}
6058EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
6059
6060void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
6061{
6062 void *hdr = ((void **)skb->cb)[1];
6063 struct nlattr *data = ((void **)skb->cb)[2];
6064
6065 nla_nest_end(skb, data);
6066 genlmsg_end(skb, hdr);
6067 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
6068}
6069EXPORT_SYMBOL(cfg80211_testmode_event);
6070#endif
6071
b23aa676
SO
6072static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
6073{
4c476991
JB
6074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6075 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6076 struct cfg80211_connect_params connect;
6077 struct wiphy *wiphy;
fffd0934 6078 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
6079 int err;
6080
6081 memset(&connect, 0, sizeof(connect));
6082
6083 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6084 return -EINVAL;
6085
6086 if (!info->attrs[NL80211_ATTR_SSID] ||
6087 !nla_len(info->attrs[NL80211_ATTR_SSID]))
6088 return -EINVAL;
6089
6090 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
6091 connect.auth_type =
6092 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
6093 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
6094 NL80211_CMD_CONNECT))
b23aa676
SO
6095 return -EINVAL;
6096 } else
6097 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
6098
6099 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
6100
c0692b8f 6101 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 6102 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
6103 if (err)
6104 return err;
b23aa676 6105
074ac8df 6106 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6107 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6108 return -EOPNOTSUPP;
b23aa676 6109
79c97e97 6110 wiphy = &rdev->wiphy;
b23aa676 6111
4486ea98
BS
6112 connect.bg_scan_period = -1;
6113 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
6114 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
6115 connect.bg_scan_period =
6116 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
6117 }
6118
b23aa676
SO
6119 if (info->attrs[NL80211_ATTR_MAC])
6120 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6121 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
6122 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
6123
6124 if (info->attrs[NL80211_ATTR_IE]) {
6125 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
6126 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6127 }
6128
cee00a95
JM
6129 if (info->attrs[NL80211_ATTR_USE_MFP]) {
6130 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
6131 if (connect.mfp != NL80211_MFP_REQUIRED &&
6132 connect.mfp != NL80211_MFP_NO)
6133 return -EINVAL;
6134 } else {
6135 connect.mfp = NL80211_MFP_NO;
6136 }
6137
b23aa676
SO
6138 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6139 connect.channel =
6140 ieee80211_get_channel(wiphy,
6141 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
6142 if (!connect.channel ||
4c476991
JB
6143 connect.channel->flags & IEEE80211_CHAN_DISABLED)
6144 return -EINVAL;
b23aa676
SO
6145 }
6146
fffd0934
JB
6147 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
6148 connkeys = nl80211_parse_connkeys(rdev,
de7044ee 6149 info->attrs[NL80211_ATTR_KEYS], NULL);
4c476991
JB
6150 if (IS_ERR(connkeys))
6151 return PTR_ERR(connkeys);
fffd0934
JB
6152 }
6153
7e7c8926
BG
6154 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
6155 connect.flags |= ASSOC_REQ_DISABLE_HT;
6156
6157 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
6158 memcpy(&connect.ht_capa_mask,
6159 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
6160 sizeof(connect.ht_capa_mask));
6161
6162 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e
WY
6163 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
6164 kfree(connkeys);
7e7c8926 6165 return -EINVAL;
b4e4f47e 6166 }
7e7c8926
BG
6167 memcpy(&connect.ht_capa,
6168 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
6169 sizeof(connect.ht_capa));
6170 }
6171
fffd0934 6172 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
6173 if (err)
6174 kfree(connkeys);
b23aa676
SO
6175 return err;
6176}
6177
6178static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
6179{
4c476991
JB
6180 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6181 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
6182 u16 reason;
6183
6184 if (!info->attrs[NL80211_ATTR_REASON_CODE])
6185 reason = WLAN_REASON_DEAUTH_LEAVING;
6186 else
6187 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6188
6189 if (reason == 0)
6190 return -EINVAL;
6191
074ac8df 6192 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6193 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6194 return -EOPNOTSUPP;
b23aa676 6195
4c476991 6196 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
6197}
6198
463d0183
JB
6199static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
6200{
4c476991 6201 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
6202 struct net *net;
6203 int err;
6204 u32 pid;
6205
6206 if (!info->attrs[NL80211_ATTR_PID])
6207 return -EINVAL;
6208
6209 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
6210
463d0183 6211 net = get_net_ns_by_pid(pid);
4c476991
JB
6212 if (IS_ERR(net))
6213 return PTR_ERR(net);
463d0183
JB
6214
6215 err = 0;
6216
6217 /* check if anything to do */
4c476991
JB
6218 if (!net_eq(wiphy_net(&rdev->wiphy), net))
6219 err = cfg80211_switch_netns(rdev, net);
463d0183 6220
463d0183 6221 put_net(net);
463d0183
JB
6222 return err;
6223}
6224
67fbb16b
SO
6225static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
6226{
4c476991 6227 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
6228 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
6229 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 6230 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
6231 struct cfg80211_pmksa pmksa;
6232
6233 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
6234
6235 if (!info->attrs[NL80211_ATTR_MAC])
6236 return -EINVAL;
6237
6238 if (!info->attrs[NL80211_ATTR_PMKID])
6239 return -EINVAL;
6240
67fbb16b
SO
6241 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
6242 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
6243
074ac8df 6244 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6245 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6246 return -EOPNOTSUPP;
67fbb16b
SO
6247
6248 switch (info->genlhdr->cmd) {
6249 case NL80211_CMD_SET_PMKSA:
6250 rdev_ops = rdev->ops->set_pmksa;
6251 break;
6252 case NL80211_CMD_DEL_PMKSA:
6253 rdev_ops = rdev->ops->del_pmksa;
6254 break;
6255 default:
6256 WARN_ON(1);
6257 break;
6258 }
6259
4c476991
JB
6260 if (!rdev_ops)
6261 return -EOPNOTSUPP;
67fbb16b 6262
4c476991 6263 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
6264}
6265
6266static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
6267{
4c476991
JB
6268 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6269 struct net_device *dev = info->user_ptr[1];
67fbb16b 6270
074ac8df 6271 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6272 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
6273 return -EOPNOTSUPP;
67fbb16b 6274
4c476991
JB
6275 if (!rdev->ops->flush_pmksa)
6276 return -EOPNOTSUPP;
67fbb16b 6277
e35e4d28 6278 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
6279}
6280
109086ce
AN
6281static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
6282{
6283 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6284 struct net_device *dev = info->user_ptr[1];
6285 u8 action_code, dialog_token;
6286 u16 status_code;
6287 u8 *peer;
6288
6289 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6290 !rdev->ops->tdls_mgmt)
6291 return -EOPNOTSUPP;
6292
6293 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
6294 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
6295 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
6296 !info->attrs[NL80211_ATTR_IE] ||
6297 !info->attrs[NL80211_ATTR_MAC])
6298 return -EINVAL;
6299
6300 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6301 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
6302 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
6303 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
6304
e35e4d28
HG
6305 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
6306 dialog_token, status_code,
6307 nla_data(info->attrs[NL80211_ATTR_IE]),
6308 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
6309}
6310
6311static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
6312{
6313 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6314 struct net_device *dev = info->user_ptr[1];
6315 enum nl80211_tdls_operation operation;
6316 u8 *peer;
6317
6318 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
6319 !rdev->ops->tdls_oper)
6320 return -EOPNOTSUPP;
6321
6322 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
6323 !info->attrs[NL80211_ATTR_MAC])
6324 return -EINVAL;
6325
6326 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
6327 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
6328
e35e4d28 6329 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
6330}
6331
9588bbd5
JM
6332static int nl80211_remain_on_channel(struct sk_buff *skb,
6333 struct genl_info *info)
6334{
4c476991 6335 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6336 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6337 struct cfg80211_chan_def chandef;
9588bbd5
JM
6338 struct sk_buff *msg;
6339 void *hdr;
6340 u64 cookie;
683b6d3b 6341 u32 duration;
9588bbd5
JM
6342 int err;
6343
6344 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
6345 !info->attrs[NL80211_ATTR_DURATION])
6346 return -EINVAL;
6347
6348 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
6349
ebf348fc
JB
6350 if (!rdev->ops->remain_on_channel ||
6351 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
6352 return -EOPNOTSUPP;
6353
9588bbd5 6354 /*
ebf348fc
JB
6355 * We should be on that channel for at least a minimum amount of
6356 * time (10ms) but no longer than the driver supports.
9588bbd5 6357 */
ebf348fc 6358 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 6359 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
6360 return -EINVAL;
6361
683b6d3b
JB
6362 err = nl80211_parse_chandef(rdev, info, &chandef);
6363 if (err)
6364 return err;
9588bbd5
JM
6365
6366 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6367 if (!msg)
6368 return -ENOMEM;
9588bbd5 6369
15e47304 6370 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5
JM
6371 NL80211_CMD_REMAIN_ON_CHANNEL);
6372
6373 if (IS_ERR(hdr)) {
6374 err = PTR_ERR(hdr);
6375 goto free_msg;
6376 }
6377
683b6d3b
JB
6378 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
6379 duration, &cookie);
9588bbd5
JM
6380
6381 if (err)
6382 goto free_msg;
6383
9360ffd1
DM
6384 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6385 goto nla_put_failure;
9588bbd5
JM
6386
6387 genlmsg_end(msg, hdr);
4c476991
JB
6388
6389 return genlmsg_reply(msg, info);
9588bbd5
JM
6390
6391 nla_put_failure:
6392 err = -ENOBUFS;
6393 free_msg:
6394 nlmsg_free(msg);
9588bbd5
JM
6395 return err;
6396}
6397
6398static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
6399 struct genl_info *info)
6400{
4c476991 6401 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6402 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 6403 u64 cookie;
9588bbd5
JM
6404
6405 if (!info->attrs[NL80211_ATTR_COOKIE])
6406 return -EINVAL;
6407
4c476991
JB
6408 if (!rdev->ops->cancel_remain_on_channel)
6409 return -EOPNOTSUPP;
9588bbd5 6410
9588bbd5
JM
6411 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6412
e35e4d28 6413 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
6414}
6415
13ae75b1
JM
6416static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
6417 u8 *rates, u8 rates_len)
6418{
6419 u8 i;
6420 u32 mask = 0;
6421
6422 for (i = 0; i < rates_len; i++) {
6423 int rate = (rates[i] & 0x7f) * 5;
6424 int ridx;
6425 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
6426 struct ieee80211_rate *srate =
6427 &sband->bitrates[ridx];
6428 if (rate == srate->bitrate) {
6429 mask |= 1 << ridx;
6430 break;
6431 }
6432 }
6433 if (ridx == sband->n_bitrates)
6434 return 0; /* rate not found */
6435 }
6436
6437 return mask;
6438}
6439
24db78c0
SW
6440static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
6441 u8 *rates, u8 rates_len,
6442 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
6443{
6444 u8 i;
6445
6446 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
6447
6448 for (i = 0; i < rates_len; i++) {
6449 int ridx, rbit;
6450
6451 ridx = rates[i] / 8;
6452 rbit = BIT(rates[i] % 8);
6453
6454 /* check validity */
910570b5 6455 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
6456 return false;
6457
6458 /* check availability */
6459 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
6460 mcs[ridx] |= rbit;
6461 else
6462 return false;
6463 }
6464
6465 return true;
6466}
6467
b54452b0 6468static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
6469 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
6470 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
6471 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
6472 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
6473};
6474
6475static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
6476 struct genl_info *info)
6477{
6478 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 6479 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 6480 struct cfg80211_bitrate_mask mask;
4c476991
JB
6481 int rem, i;
6482 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
6483 struct nlattr *tx_rates;
6484 struct ieee80211_supported_band *sband;
6485
6486 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
6487 return -EINVAL;
6488
4c476991
JB
6489 if (!rdev->ops->set_bitrate_mask)
6490 return -EOPNOTSUPP;
13ae75b1
JM
6491
6492 memset(&mask, 0, sizeof(mask));
6493 /* Default to all rates enabled */
6494 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
6495 sband = rdev->wiphy.bands[i];
6496 mask.control[i].legacy =
6497 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
6498 if (sband)
6499 memcpy(mask.control[i].mcs,
6500 sband->ht_cap.mcs.rx_mask,
6501 sizeof(mask.control[i].mcs));
6502 else
6503 memset(mask.control[i].mcs, 0,
6504 sizeof(mask.control[i].mcs));
13ae75b1
JM
6505 }
6506
6507 /*
6508 * The nested attribute uses enum nl80211_band as the index. This maps
6509 * directly to the enum ieee80211_band values used in cfg80211.
6510 */
24db78c0 6511 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
6512 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
6513 {
6514 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
6515 if (band < 0 || band >= IEEE80211_NUM_BANDS)
6516 return -EINVAL;
13ae75b1 6517 sband = rdev->wiphy.bands[band];
4c476991
JB
6518 if (sband == NULL)
6519 return -EINVAL;
13ae75b1
JM
6520 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
6521 nla_len(tx_rates), nl80211_txattr_policy);
6522 if (tb[NL80211_TXRATE_LEGACY]) {
6523 mask.control[band].legacy = rateset_to_mask(
6524 sband,
6525 nla_data(tb[NL80211_TXRATE_LEGACY]),
6526 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
6527 if ((mask.control[band].legacy == 0) &&
6528 nla_len(tb[NL80211_TXRATE_LEGACY]))
6529 return -EINVAL;
24db78c0
SW
6530 }
6531 if (tb[NL80211_TXRATE_MCS]) {
6532 if (!ht_rateset_to_mask(
6533 sband,
6534 nla_data(tb[NL80211_TXRATE_MCS]),
6535 nla_len(tb[NL80211_TXRATE_MCS]),
6536 mask.control[band].mcs))
6537 return -EINVAL;
6538 }
6539
6540 if (mask.control[band].legacy == 0) {
6541 /* don't allow empty legacy rates if HT
6542 * is not even supported. */
6543 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
6544 return -EINVAL;
6545
6546 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
6547 if (mask.control[band].mcs[i])
6548 break;
6549
6550 /* legacy and mcs rates may not be both empty */
6551 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 6552 return -EINVAL;
13ae75b1
JM
6553 }
6554 }
6555
e35e4d28 6556 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
6557}
6558
2e161f78 6559static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6560{
4c476991 6561 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6562 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 6563 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
6564
6565 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
6566 return -EINVAL;
6567
2e161f78
JB
6568 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
6569 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 6570
71bbc994
JB
6571 switch (wdev->iftype) {
6572 case NL80211_IFTYPE_STATION:
6573 case NL80211_IFTYPE_ADHOC:
6574 case NL80211_IFTYPE_P2P_CLIENT:
6575 case NL80211_IFTYPE_AP:
6576 case NL80211_IFTYPE_AP_VLAN:
6577 case NL80211_IFTYPE_MESH_POINT:
6578 case NL80211_IFTYPE_P2P_GO:
98104fde 6579 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6580 break;
6581 default:
4c476991 6582 return -EOPNOTSUPP;
71bbc994 6583 }
026331c4
JM
6584
6585 /* not much point in registering if we can't reply */
4c476991
JB
6586 if (!rdev->ops->mgmt_tx)
6587 return -EOPNOTSUPP;
026331c4 6588
15e47304 6589 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
6590 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
6591 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
6592}
6593
2e161f78 6594static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6595{
4c476991 6596 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6597 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 6598 struct cfg80211_chan_def chandef;
026331c4 6599 int err;
d64d373f 6600 void *hdr = NULL;
026331c4 6601 u64 cookie;
e247bd90 6602 struct sk_buff *msg = NULL;
f7ca38df 6603 unsigned int wait = 0;
e247bd90
JB
6604 bool offchan, no_cck, dont_wait_for_ack;
6605
6606 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4 6607
683b6d3b 6608 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
6609 return -EINVAL;
6610
4c476991
JB
6611 if (!rdev->ops->mgmt_tx)
6612 return -EOPNOTSUPP;
026331c4 6613
71bbc994
JB
6614 switch (wdev->iftype) {
6615 case NL80211_IFTYPE_STATION:
6616 case NL80211_IFTYPE_ADHOC:
6617 case NL80211_IFTYPE_P2P_CLIENT:
6618 case NL80211_IFTYPE_AP:
6619 case NL80211_IFTYPE_AP_VLAN:
6620 case NL80211_IFTYPE_MESH_POINT:
6621 case NL80211_IFTYPE_P2P_GO:
98104fde 6622 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6623 break;
6624 default:
4c476991 6625 return -EOPNOTSUPP;
71bbc994 6626 }
026331c4 6627
f7ca38df 6628 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 6629 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
6630 return -EINVAL;
6631 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
6632
6633 /*
6634 * We should wait on the channel for at least a minimum amount
6635 * of time (10ms) but no longer than the driver supports.
6636 */
6637 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
6638 wait > rdev->wiphy.max_remain_on_channel_duration)
6639 return -EINVAL;
6640
f7ca38df
JB
6641 }
6642
f7ca38df
JB
6643 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
6644
7c4ef712
JB
6645 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
6646 return -EINVAL;
6647
e9f935e3
RM
6648 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6649
683b6d3b
JB
6650 err = nl80211_parse_chandef(rdev, info, &chandef);
6651 if (err)
6652 return err;
026331c4 6653
e247bd90
JB
6654 if (!dont_wait_for_ack) {
6655 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6656 if (!msg)
6657 return -ENOMEM;
026331c4 6658
15e47304 6659 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 6660 NL80211_CMD_FRAME);
026331c4 6661
e247bd90
JB
6662 if (IS_ERR(hdr)) {
6663 err = PTR_ERR(hdr);
6664 goto free_msg;
6665 }
026331c4 6666 }
e247bd90 6667
683b6d3b 6668 err = cfg80211_mlme_mgmt_tx(rdev, wdev, chandef.chan, offchan, wait,
2e161f78
JB
6669 nla_data(info->attrs[NL80211_ATTR_FRAME]),
6670 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 6671 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
6672 if (err)
6673 goto free_msg;
6674
e247bd90 6675 if (msg) {
9360ffd1
DM
6676 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6677 goto nla_put_failure;
026331c4 6678
e247bd90
JB
6679 genlmsg_end(msg, hdr);
6680 return genlmsg_reply(msg, info);
6681 }
6682
6683 return 0;
026331c4
JM
6684
6685 nla_put_failure:
6686 err = -ENOBUFS;
6687 free_msg:
6688 nlmsg_free(msg);
026331c4
JM
6689 return err;
6690}
6691
f7ca38df
JB
6692static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
6693{
6694 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 6695 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
6696 u64 cookie;
6697
6698 if (!info->attrs[NL80211_ATTR_COOKIE])
6699 return -EINVAL;
6700
6701 if (!rdev->ops->mgmt_tx_cancel_wait)
6702 return -EOPNOTSUPP;
6703
71bbc994
JB
6704 switch (wdev->iftype) {
6705 case NL80211_IFTYPE_STATION:
6706 case NL80211_IFTYPE_ADHOC:
6707 case NL80211_IFTYPE_P2P_CLIENT:
6708 case NL80211_IFTYPE_AP:
6709 case NL80211_IFTYPE_AP_VLAN:
6710 case NL80211_IFTYPE_P2P_GO:
98104fde 6711 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994
JB
6712 break;
6713 default:
f7ca38df 6714 return -EOPNOTSUPP;
71bbc994 6715 }
f7ca38df
JB
6716
6717 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6718
e35e4d28 6719 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
6720}
6721
ffb9eb3d
KV
6722static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
6723{
4c476991 6724 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 6725 struct wireless_dev *wdev;
4c476991 6726 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6727 u8 ps_state;
6728 bool state;
6729 int err;
6730
4c476991
JB
6731 if (!info->attrs[NL80211_ATTR_PS_STATE])
6732 return -EINVAL;
ffb9eb3d
KV
6733
6734 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
6735
4c476991
JB
6736 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
6737 return -EINVAL;
ffb9eb3d
KV
6738
6739 wdev = dev->ieee80211_ptr;
6740
4c476991
JB
6741 if (!rdev->ops->set_power_mgmt)
6742 return -EOPNOTSUPP;
ffb9eb3d
KV
6743
6744 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
6745
6746 if (state == wdev->ps)
4c476991 6747 return 0;
ffb9eb3d 6748
e35e4d28 6749 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
6750 if (!err)
6751 wdev->ps = state;
ffb9eb3d
KV
6752 return err;
6753}
6754
6755static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
6756{
4c476991 6757 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
6758 enum nl80211_ps_state ps_state;
6759 struct wireless_dev *wdev;
4c476991 6760 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6761 struct sk_buff *msg;
6762 void *hdr;
6763 int err;
6764
ffb9eb3d
KV
6765 wdev = dev->ieee80211_ptr;
6766
4c476991
JB
6767 if (!rdev->ops->set_power_mgmt)
6768 return -EOPNOTSUPP;
ffb9eb3d
KV
6769
6770 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6771 if (!msg)
6772 return -ENOMEM;
ffb9eb3d 6773
15e47304 6774 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
6775 NL80211_CMD_GET_POWER_SAVE);
6776 if (!hdr) {
4c476991 6777 err = -ENOBUFS;
ffb9eb3d
KV
6778 goto free_msg;
6779 }
6780
6781 if (wdev->ps)
6782 ps_state = NL80211_PS_ENABLED;
6783 else
6784 ps_state = NL80211_PS_DISABLED;
6785
9360ffd1
DM
6786 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6787 goto nla_put_failure;
ffb9eb3d
KV
6788
6789 genlmsg_end(msg, hdr);
4c476991 6790 return genlmsg_reply(msg, info);
ffb9eb3d 6791
4c476991 6792 nla_put_failure:
ffb9eb3d 6793 err = -ENOBUFS;
4c476991 6794 free_msg:
ffb9eb3d 6795 nlmsg_free(msg);
ffb9eb3d
KV
6796 return err;
6797}
6798
d6dc1a38
JO
6799static struct nla_policy
6800nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6801 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6802 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6803 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
6804 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
6805 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
6806 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
d6dc1a38
JO
6807};
6808
84f10708 6809static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 6810 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
6811{
6812 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6813 struct wireless_dev *wdev;
6814 struct net_device *dev = info->user_ptr[1];
6815
d9d8b019 6816 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
6817 return -EINVAL;
6818
6819 wdev = dev->ieee80211_ptr;
6820
6821 if (!rdev->ops->set_cqm_txe_config)
6822 return -EOPNOTSUPP;
6823
6824 if (wdev->iftype != NL80211_IFTYPE_STATION &&
6825 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6826 return -EOPNOTSUPP;
6827
e35e4d28 6828 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
6829}
6830
d6dc1a38
JO
6831static int nl80211_set_cqm_rssi(struct genl_info *info,
6832 s32 threshold, u32 hysteresis)
6833{
4c476991 6834 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6835 struct wireless_dev *wdev;
4c476991 6836 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6837
6838 if (threshold > 0)
6839 return -EINVAL;
6840
d6dc1a38
JO
6841 wdev = dev->ieee80211_ptr;
6842
4c476991
JB
6843 if (!rdev->ops->set_cqm_rssi_config)
6844 return -EOPNOTSUPP;
d6dc1a38 6845
074ac8df 6846 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6847 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6848 return -EOPNOTSUPP;
d6dc1a38 6849
e35e4d28 6850 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis);
d6dc1a38
JO
6851}
6852
6853static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6854{
6855 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6856 struct nlattr *cqm;
6857 int err;
6858
6859 cqm = info->attrs[NL80211_ATTR_CQM];
6860 if (!cqm) {
6861 err = -EINVAL;
6862 goto out;
6863 }
6864
6865 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6866 nl80211_attr_cqm_policy);
6867 if (err)
6868 goto out;
6869
6870 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6871 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6872 s32 threshold;
6873 u32 hysteresis;
6874 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6875 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6876 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
84f10708
TP
6877 } else if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
6878 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
6879 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
6880 u32 rate, pkts, intvl;
6881 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
6882 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
6883 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
6884 err = nl80211_set_cqm_txe(info, rate, pkts, intvl);
d6dc1a38
JO
6885 } else
6886 err = -EINVAL;
6887
6888out:
6889 return err;
6890}
6891
29cbe68c
JB
6892static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6893{
6894 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6895 struct net_device *dev = info->user_ptr[1];
6896 struct mesh_config cfg;
c80d545d 6897 struct mesh_setup setup;
29cbe68c
JB
6898 int err;
6899
6900 /* start with default */
6901 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6902 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6903
24bdd9f4 6904 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6905 /* and parse parameters if given */
24bdd9f4 6906 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6907 if (err)
6908 return err;
6909 }
6910
6911 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6912 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6913 return -EINVAL;
6914
c80d545d
JC
6915 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6916 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6917
4bb62344
CYY
6918 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6919 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6920 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6921 return -EINVAL;
6922
9bdbf04d
MP
6923 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
6924 setup.beacon_interval =
6925 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
6926 if (setup.beacon_interval < 10 ||
6927 setup.beacon_interval > 10000)
6928 return -EINVAL;
6929 }
6930
6931 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
6932 setup.dtim_period =
6933 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
6934 if (setup.dtim_period < 1 || setup.dtim_period > 100)
6935 return -EINVAL;
6936 }
6937
c80d545d
JC
6938 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6939 /* parse additional setup parameters if given */
6940 err = nl80211_parse_mesh_setup(info, &setup);
6941 if (err)
6942 return err;
6943 }
6944
cc1d2806 6945 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
6946 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
6947 if (err)
6948 return err;
cc1d2806
JB
6949 } else {
6950 /* cfg80211_join_mesh() will sort it out */
683b6d3b 6951 setup.chandef.chan = NULL;
cc1d2806
JB
6952 }
6953
c80d545d 6954 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6955}
6956
6957static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6958{
6959 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6960 struct net_device *dev = info->user_ptr[1];
6961
6962 return cfg80211_leave_mesh(rdev, dev);
6963}
6964
dfb89c56 6965#ifdef CONFIG_PM
bb92d199
AK
6966static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
6967 struct cfg80211_registered_device *rdev)
6968{
6969 struct nlattr *nl_pats, *nl_pat;
6970 int i, pat_len;
6971
6972 if (!rdev->wowlan->n_patterns)
6973 return 0;
6974
6975 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
6976 if (!nl_pats)
6977 return -ENOBUFS;
6978
6979 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6980 nl_pat = nla_nest_start(msg, i + 1);
6981 if (!nl_pat)
6982 return -ENOBUFS;
6983 pat_len = rdev->wowlan->patterns[i].pattern_len;
6984 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6985 DIV_ROUND_UP(pat_len, 8),
6986 rdev->wowlan->patterns[i].mask) ||
6987 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6988 pat_len, rdev->wowlan->patterns[i].pattern) ||
6989 nla_put_u32(msg, NL80211_WOWLAN_PKTPAT_OFFSET,
6990 rdev->wowlan->patterns[i].pkt_offset))
6991 return -ENOBUFS;
6992 nla_nest_end(msg, nl_pat);
6993 }
6994 nla_nest_end(msg, nl_pats);
6995
6996 return 0;
6997}
6998
2a0e047e
JB
6999static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
7000 struct cfg80211_wowlan_tcp *tcp)
7001{
7002 struct nlattr *nl_tcp;
7003
7004 if (!tcp)
7005 return 0;
7006
7007 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
7008 if (!nl_tcp)
7009 return -ENOBUFS;
7010
7011 if (nla_put_be32(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
7012 nla_put_be32(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
7013 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
7014 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
7015 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
7016 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
7017 tcp->payload_len, tcp->payload) ||
7018 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
7019 tcp->data_interval) ||
7020 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
7021 tcp->wake_len, tcp->wake_data) ||
7022 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
7023 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
7024 return -ENOBUFS;
7025
7026 if (tcp->payload_seq.len &&
7027 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
7028 sizeof(tcp->payload_seq), &tcp->payload_seq))
7029 return -ENOBUFS;
7030
7031 if (tcp->payload_tok.len &&
7032 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
7033 sizeof(tcp->payload_tok) + tcp->tokens_size,
7034 &tcp->payload_tok))
7035 return -ENOBUFS;
7036
7037 return 0;
7038}
7039
ff1b6e69
JB
7040static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
7041{
7042 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7043 struct sk_buff *msg;
7044 void *hdr;
2a0e047e 7045 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 7046
2a0e047e
JB
7047 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns &&
7048 !rdev->wiphy.wowlan.tcp)
ff1b6e69
JB
7049 return -EOPNOTSUPP;
7050
2a0e047e
JB
7051 if (rdev->wowlan && rdev->wowlan->tcp) {
7052 /* adjust size to have room for all the data */
7053 size += rdev->wowlan->tcp->tokens_size +
7054 rdev->wowlan->tcp->payload_len +
7055 rdev->wowlan->tcp->wake_len +
7056 rdev->wowlan->tcp->wake_len / 8;
7057 }
7058
7059 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
7060 if (!msg)
7061 return -ENOMEM;
7062
15e47304 7063 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
7064 NL80211_CMD_GET_WOWLAN);
7065 if (!hdr)
7066 goto nla_put_failure;
7067
7068 if (rdev->wowlan) {
7069 struct nlattr *nl_wowlan;
7070
7071 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7072 if (!nl_wowlan)
7073 goto nla_put_failure;
7074
9360ffd1
DM
7075 if ((rdev->wowlan->any &&
7076 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
7077 (rdev->wowlan->disconnect &&
7078 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
7079 (rdev->wowlan->magic_pkt &&
7080 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
7081 (rdev->wowlan->gtk_rekey_failure &&
7082 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
7083 (rdev->wowlan->eap_identity_req &&
7084 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
7085 (rdev->wowlan->four_way_handshake &&
7086 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
7087 (rdev->wowlan->rfkill_release &&
7088 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
7089 goto nla_put_failure;
2a0e047e 7090
bb92d199
AK
7091 if (nl80211_send_wowlan_patterns(msg, rdev))
7092 goto nla_put_failure;
2a0e047e
JB
7093
7094 if (nl80211_send_wowlan_tcp(msg, rdev->wowlan->tcp))
7095 goto nla_put_failure;
7096
ff1b6e69
JB
7097 nla_nest_end(msg, nl_wowlan);
7098 }
7099
7100 genlmsg_end(msg, hdr);
7101 return genlmsg_reply(msg, info);
7102
7103nla_put_failure:
7104 nlmsg_free(msg);
7105 return -ENOBUFS;
7106}
7107
2a0e047e
JB
7108static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
7109 struct nlattr *attr,
7110 struct cfg80211_wowlan *trig)
7111{
7112 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
7113 struct cfg80211_wowlan_tcp *cfg;
7114 struct nl80211_wowlan_tcp_data_token *tok = NULL;
7115 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
7116 u32 size;
7117 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
7118 int err, port;
7119
7120 if (!rdev->wiphy.wowlan.tcp)
7121 return -EINVAL;
7122
7123 err = nla_parse(tb, MAX_NL80211_WOWLAN_TCP,
7124 nla_data(attr), nla_len(attr),
7125 nl80211_wowlan_tcp_policy);
7126 if (err)
7127 return err;
7128
7129 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
7130 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
7131 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
7132 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
7133 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
7134 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
7135 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
7136 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
7137 return -EINVAL;
7138
7139 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
7140 if (data_size > rdev->wiphy.wowlan.tcp->data_payload_max)
7141 return -EINVAL;
7142
7143 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
7144 rdev->wiphy.wowlan.tcp->data_interval_max)
7145 return -EINVAL;
7146
7147 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
7148 if (wake_size > rdev->wiphy.wowlan.tcp->wake_payload_max)
7149 return -EINVAL;
7150
7151 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
7152 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
7153 return -EINVAL;
7154
7155 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
7156 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
7157
7158 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
7159 tokens_size = tokln - sizeof(*tok);
7160
7161 if (!tok->len || tokens_size % tok->len)
7162 return -EINVAL;
7163 if (!rdev->wiphy.wowlan.tcp->tok)
7164 return -EINVAL;
7165 if (tok->len > rdev->wiphy.wowlan.tcp->tok->max_len)
7166 return -EINVAL;
7167 if (tok->len < rdev->wiphy.wowlan.tcp->tok->min_len)
7168 return -EINVAL;
7169 if (tokens_size > rdev->wiphy.wowlan.tcp->tok->bufsize)
7170 return -EINVAL;
7171 if (tok->offset + tok->len > data_size)
7172 return -EINVAL;
7173 }
7174
7175 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
7176 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
7177 if (!rdev->wiphy.wowlan.tcp->seq)
7178 return -EINVAL;
7179 if (seq->len == 0 || seq->len > 4)
7180 return -EINVAL;
7181 if (seq->len + seq->offset > data_size)
7182 return -EINVAL;
7183 }
7184
7185 size = sizeof(*cfg);
7186 size += data_size;
7187 size += wake_size + wake_mask_size;
7188 size += tokens_size;
7189
7190 cfg = kzalloc(size, GFP_KERNEL);
7191 if (!cfg)
7192 return -ENOMEM;
7193 cfg->src = nla_get_be32(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
7194 cfg->dst = nla_get_be32(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
7195 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
7196 ETH_ALEN);
7197 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
7198 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
7199 else
7200 port = 0;
7201#ifdef CONFIG_INET
7202 /* allocate a socket and port for it and use it */
7203 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
7204 IPPROTO_TCP, &cfg->sock, 1);
7205 if (err) {
7206 kfree(cfg);
7207 return err;
7208 }
7209 if (inet_csk_get_port(cfg->sock->sk, port)) {
7210 sock_release(cfg->sock);
7211 kfree(cfg);
7212 return -EADDRINUSE;
7213 }
7214 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
7215#else
7216 if (!port) {
7217 kfree(cfg);
7218 return -EINVAL;
7219 }
7220 cfg->src_port = port;
7221#endif
7222
7223 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
7224 cfg->payload_len = data_size;
7225 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
7226 memcpy((void *)cfg->payload,
7227 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
7228 data_size);
7229 if (seq)
7230 cfg->payload_seq = *seq;
7231 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
7232 cfg->wake_len = wake_size;
7233 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
7234 memcpy((void *)cfg->wake_data,
7235 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
7236 wake_size);
7237 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
7238 data_size + wake_size;
7239 memcpy((void *)cfg->wake_mask,
7240 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
7241 wake_mask_size);
7242 if (tok) {
7243 cfg->tokens_size = tokens_size;
7244 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
7245 }
7246
7247 trig->tcp = cfg;
7248
7249 return 0;
7250}
7251
ff1b6e69
JB
7252static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
7253{
7254 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7255 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 7256 struct cfg80211_wowlan new_triggers = {};
ae33bd81 7257 struct cfg80211_wowlan *ntrig;
ff1b6e69
JB
7258 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
7259 int err, i;
6d52563f 7260 bool prev_enabled = rdev->wowlan;
ff1b6e69 7261
2a0e047e
JB
7262 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns &&
7263 !rdev->wiphy.wowlan.tcp)
ff1b6e69
JB
7264 return -EOPNOTSUPP;
7265
ae33bd81
JB
7266 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
7267 cfg80211_rdev_free_wowlan(rdev);
7268 rdev->wowlan = NULL;
7269 goto set_wakeup;
7270 }
ff1b6e69
JB
7271
7272 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
7273 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
7274 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
7275 nl80211_wowlan_policy);
7276 if (err)
7277 return err;
7278
7279 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
7280 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
7281 return -EINVAL;
7282 new_triggers.any = true;
7283 }
7284
7285 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
7286 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
7287 return -EINVAL;
7288 new_triggers.disconnect = true;
7289 }
7290
7291 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
7292 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
7293 return -EINVAL;
7294 new_triggers.magic_pkt = true;
7295 }
7296
77dbbb13
JB
7297 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
7298 return -EINVAL;
7299
7300 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
7301 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
7302 return -EINVAL;
7303 new_triggers.gtk_rekey_failure = true;
7304 }
7305
7306 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
7307 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
7308 return -EINVAL;
7309 new_triggers.eap_identity_req = true;
7310 }
7311
7312 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
7313 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
7314 return -EINVAL;
7315 new_triggers.four_way_handshake = true;
7316 }
7317
7318 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
7319 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
7320 return -EINVAL;
7321 new_triggers.rfkill_release = true;
7322 }
7323
ff1b6e69
JB
7324 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
7325 struct nlattr *pat;
7326 int n_patterns = 0;
bb92d199 7327 int rem, pat_len, mask_len, pkt_offset;
ff1b6e69
JB
7328 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
7329
7330 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7331 rem)
7332 n_patterns++;
7333 if (n_patterns > wowlan->n_patterns)
7334 return -EINVAL;
7335
7336 new_triggers.patterns = kcalloc(n_patterns,
7337 sizeof(new_triggers.patterns[0]),
7338 GFP_KERNEL);
7339 if (!new_triggers.patterns)
7340 return -ENOMEM;
7341
7342 new_triggers.n_patterns = n_patterns;
7343 i = 0;
7344
7345 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
7346 rem) {
7347 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
7348 nla_data(pat), nla_len(pat), NULL);
7349 err = -EINVAL;
7350 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
7351 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
7352 goto error;
7353 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
7354 mask_len = DIV_ROUND_UP(pat_len, 8);
7355 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
7356 mask_len)
7357 goto error;
7358 if (pat_len > wowlan->pattern_max_len ||
7359 pat_len < wowlan->pattern_min_len)
7360 goto error;
7361
bb92d199
AK
7362 if (!pat_tb[NL80211_WOWLAN_PKTPAT_OFFSET])
7363 pkt_offset = 0;
7364 else
7365 pkt_offset = nla_get_u32(
7366 pat_tb[NL80211_WOWLAN_PKTPAT_OFFSET]);
7367 if (pkt_offset > wowlan->max_pkt_offset)
7368 goto error;
7369 new_triggers.patterns[i].pkt_offset = pkt_offset;
7370
ff1b6e69
JB
7371 new_triggers.patterns[i].mask =
7372 kmalloc(mask_len + pat_len, GFP_KERNEL);
7373 if (!new_triggers.patterns[i].mask) {
7374 err = -ENOMEM;
7375 goto error;
7376 }
7377 new_triggers.patterns[i].pattern =
7378 new_triggers.patterns[i].mask + mask_len;
7379 memcpy(new_triggers.patterns[i].mask,
7380 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
7381 mask_len);
7382 new_triggers.patterns[i].pattern_len = pat_len;
7383 memcpy(new_triggers.patterns[i].pattern,
7384 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
7385 pat_len);
7386 i++;
7387 }
7388 }
7389
2a0e047e
JB
7390 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
7391 err = nl80211_parse_wowlan_tcp(
7392 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
7393 &new_triggers);
7394 if (err)
7395 goto error;
7396 }
7397
ae33bd81
JB
7398 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
7399 if (!ntrig) {
7400 err = -ENOMEM;
7401 goto error;
ff1b6e69 7402 }
ae33bd81
JB
7403 cfg80211_rdev_free_wowlan(rdev);
7404 rdev->wowlan = ntrig;
ff1b6e69 7405
ae33bd81 7406 set_wakeup:
6d52563f 7407 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
e35e4d28 7408 rdev_set_wakeup(rdev, rdev->wowlan);
6d52563f 7409
ff1b6e69
JB
7410 return 0;
7411 error:
7412 for (i = 0; i < new_triggers.n_patterns; i++)
7413 kfree(new_triggers.patterns[i].mask);
7414 kfree(new_triggers.patterns);
2a0e047e
JB
7415 if (new_triggers.tcp && new_triggers.tcp->sock)
7416 sock_release(new_triggers.tcp->sock);
7417 kfree(new_triggers.tcp);
ff1b6e69
JB
7418 return err;
7419}
dfb89c56 7420#endif
ff1b6e69 7421
e5497d76
JB
7422static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
7423{
7424 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7425 struct net_device *dev = info->user_ptr[1];
7426 struct wireless_dev *wdev = dev->ieee80211_ptr;
7427 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
7428 struct cfg80211_gtk_rekey_data rekey_data;
7429 int err;
7430
7431 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
7432 return -EINVAL;
7433
7434 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
7435 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
7436 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
7437 nl80211_rekey_policy);
7438 if (err)
7439 return err;
7440
7441 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
7442 return -ERANGE;
7443 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
7444 return -ERANGE;
7445 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
7446 return -ERANGE;
7447
7448 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
7449 NL80211_KEK_LEN);
7450 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
7451 NL80211_KCK_LEN);
7452 memcpy(rekey_data.replay_ctr,
7453 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
7454 NL80211_REPLAY_CTR_LEN);
7455
7456 wdev_lock(wdev);
7457 if (!wdev->current_bss) {
7458 err = -ENOTCONN;
7459 goto out;
7460 }
7461
7462 if (!rdev->ops->set_rekey_data) {
7463 err = -EOPNOTSUPP;
7464 goto out;
7465 }
7466
e35e4d28 7467 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
7468 out:
7469 wdev_unlock(wdev);
7470 return err;
7471}
7472
28946da7
JB
7473static int nl80211_register_unexpected_frame(struct sk_buff *skb,
7474 struct genl_info *info)
7475{
7476 struct net_device *dev = info->user_ptr[1];
7477 struct wireless_dev *wdev = dev->ieee80211_ptr;
7478
7479 if (wdev->iftype != NL80211_IFTYPE_AP &&
7480 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7481 return -EINVAL;
7482
15e47304 7483 if (wdev->ap_unexpected_nlportid)
28946da7
JB
7484 return -EBUSY;
7485
15e47304 7486 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
7487 return 0;
7488}
7489
7f6cf311
JB
7490static int nl80211_probe_client(struct sk_buff *skb,
7491 struct genl_info *info)
7492{
7493 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7494 struct net_device *dev = info->user_ptr[1];
7495 struct wireless_dev *wdev = dev->ieee80211_ptr;
7496 struct sk_buff *msg;
7497 void *hdr;
7498 const u8 *addr;
7499 u64 cookie;
7500 int err;
7501
7502 if (wdev->iftype != NL80211_IFTYPE_AP &&
7503 wdev->iftype != NL80211_IFTYPE_P2P_GO)
7504 return -EOPNOTSUPP;
7505
7506 if (!info->attrs[NL80211_ATTR_MAC])
7507 return -EINVAL;
7508
7509 if (!rdev->ops->probe_client)
7510 return -EOPNOTSUPP;
7511
7512 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7513 if (!msg)
7514 return -ENOMEM;
7515
15e47304 7516 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311
JB
7517 NL80211_CMD_PROBE_CLIENT);
7518
7519 if (IS_ERR(hdr)) {
7520 err = PTR_ERR(hdr);
7521 goto free_msg;
7522 }
7523
7524 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
7525
e35e4d28 7526 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
7527 if (err)
7528 goto free_msg;
7529
9360ffd1
DM
7530 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
7531 goto nla_put_failure;
7f6cf311
JB
7532
7533 genlmsg_end(msg, hdr);
7534
7535 return genlmsg_reply(msg, info);
7536
7537 nla_put_failure:
7538 err = -ENOBUFS;
7539 free_msg:
7540 nlmsg_free(msg);
7541 return err;
7542}
7543
5e760230
JB
7544static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
7545{
7546 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
7547 struct cfg80211_beacon_registration *reg, *nreg;
7548 int rv;
5e760230
JB
7549
7550 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
7551 return -EOPNOTSUPP;
7552
37c73b5f
BG
7553 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
7554 if (!nreg)
7555 return -ENOMEM;
7556
7557 /* First, check if already registered. */
7558 spin_lock_bh(&rdev->beacon_registrations_lock);
7559 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
7560 if (reg->nlportid == info->snd_portid) {
7561 rv = -EALREADY;
7562 goto out_err;
7563 }
7564 }
7565 /* Add it to the list */
7566 nreg->nlportid = info->snd_portid;
7567 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 7568
37c73b5f 7569 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
7570
7571 return 0;
37c73b5f
BG
7572out_err:
7573 spin_unlock_bh(&rdev->beacon_registrations_lock);
7574 kfree(nreg);
7575 return rv;
5e760230
JB
7576}
7577
98104fde
JB
7578static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
7579{
7580 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7581 struct wireless_dev *wdev = info->user_ptr[1];
7582 int err;
7583
7584 if (!rdev->ops->start_p2p_device)
7585 return -EOPNOTSUPP;
7586
7587 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7588 return -EOPNOTSUPP;
7589
7590 if (wdev->p2p_started)
7591 return 0;
7592
7593 mutex_lock(&rdev->devlist_mtx);
7594 err = cfg80211_can_add_interface(rdev, wdev->iftype);
7595 mutex_unlock(&rdev->devlist_mtx);
7596 if (err)
7597 return err;
7598
eeb126e9 7599 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
7600 if (err)
7601 return err;
7602
7603 wdev->p2p_started = true;
7604 mutex_lock(&rdev->devlist_mtx);
7605 rdev->opencount++;
7606 mutex_unlock(&rdev->devlist_mtx);
7607
7608 return 0;
7609}
7610
7611static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
7612{
7613 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7614 struct wireless_dev *wdev = info->user_ptr[1];
7615
7616 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
7617 return -EOPNOTSUPP;
7618
7619 if (!rdev->ops->stop_p2p_device)
7620 return -EOPNOTSUPP;
7621
7622 if (!wdev->p2p_started)
7623 return 0;
7624
eeb126e9 7625 rdev_stop_p2p_device(rdev, wdev);
98104fde
JB
7626 wdev->p2p_started = false;
7627
7628 mutex_lock(&rdev->devlist_mtx);
7629 rdev->opencount--;
7630 mutex_unlock(&rdev->devlist_mtx);
7631
7632 if (WARN_ON(rdev->scan_req && rdev->scan_req->wdev == wdev)) {
7633 rdev->scan_req->aborted = true;
7634 ___cfg80211_scan_done(rdev, true);
7635 }
7636
7637 return 0;
7638}
7639
4c476991
JB
7640#define NL80211_FLAG_NEED_WIPHY 0x01
7641#define NL80211_FLAG_NEED_NETDEV 0x02
7642#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
7643#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
7644#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
7645 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 7646#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 7647/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
7648#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
7649 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
7650
7651static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
7652 struct genl_info *info)
7653{
7654 struct cfg80211_registered_device *rdev;
89a54e48 7655 struct wireless_dev *wdev;
4c476991 7656 struct net_device *dev;
4c476991
JB
7657 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
7658
7659 if (rtnl)
7660 rtnl_lock();
7661
7662 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 7663 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
7664 if (IS_ERR(rdev)) {
7665 if (rtnl)
7666 rtnl_unlock();
7667 return PTR_ERR(rdev);
7668 }
7669 info->user_ptr[0] = rdev;
1bf614ef
JB
7670 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
7671 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
89a54e48
JB
7672 mutex_lock(&cfg80211_mutex);
7673 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
7674 info->attrs);
7675 if (IS_ERR(wdev)) {
7676 mutex_unlock(&cfg80211_mutex);
4c476991
JB
7677 if (rtnl)
7678 rtnl_unlock();
89a54e48 7679 return PTR_ERR(wdev);
4c476991 7680 }
89a54e48 7681
89a54e48
JB
7682 dev = wdev->netdev;
7683 rdev = wiphy_to_dev(wdev->wiphy);
7684
1bf614ef
JB
7685 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
7686 if (!dev) {
7687 mutex_unlock(&cfg80211_mutex);
7688 if (rtnl)
7689 rtnl_unlock();
7690 return -EINVAL;
7691 }
7692
7693 info->user_ptr[1] = dev;
7694 } else {
7695 info->user_ptr[1] = wdev;
41265714 7696 }
1bf614ef
JB
7697
7698 if (dev) {
7699 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
7700 !netif_running(dev)) {
7701 mutex_unlock(&cfg80211_mutex);
7702 if (rtnl)
7703 rtnl_unlock();
7704 return -ENETDOWN;
7705 }
7706
7707 dev_hold(dev);
98104fde
JB
7708 } else if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP) {
7709 if (!wdev->p2p_started) {
7710 mutex_unlock(&cfg80211_mutex);
7711 if (rtnl)
7712 rtnl_unlock();
7713 return -ENETDOWN;
7714 }
41265714 7715 }
89a54e48 7716
89a54e48
JB
7717 cfg80211_lock_rdev(rdev);
7718
7719 mutex_unlock(&cfg80211_mutex);
7720
4c476991 7721 info->user_ptr[0] = rdev;
4c476991
JB
7722 }
7723
7724 return 0;
7725}
7726
7727static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
7728 struct genl_info *info)
7729{
7730 if (info->user_ptr[0])
7731 cfg80211_unlock_rdev(info->user_ptr[0]);
1bf614ef
JB
7732 if (info->user_ptr[1]) {
7733 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
7734 struct wireless_dev *wdev = info->user_ptr[1];
7735
7736 if (wdev->netdev)
7737 dev_put(wdev->netdev);
7738 } else {
7739 dev_put(info->user_ptr[1]);
7740 }
7741 }
4c476991
JB
7742 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
7743 rtnl_unlock();
7744}
7745
55682965
JB
7746static struct genl_ops nl80211_ops[] = {
7747 {
7748 .cmd = NL80211_CMD_GET_WIPHY,
7749 .doit = nl80211_get_wiphy,
7750 .dumpit = nl80211_dump_wiphy,
7751 .policy = nl80211_policy,
7752 /* can be retrieved by unprivileged users */
4c476991 7753 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
7754 },
7755 {
7756 .cmd = NL80211_CMD_SET_WIPHY,
7757 .doit = nl80211_set_wiphy,
7758 .policy = nl80211_policy,
7759 .flags = GENL_ADMIN_PERM,
4c476991 7760 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
7761 },
7762 {
7763 .cmd = NL80211_CMD_GET_INTERFACE,
7764 .doit = nl80211_get_interface,
7765 .dumpit = nl80211_dump_interface,
7766 .policy = nl80211_policy,
7767 /* can be retrieved by unprivileged users */
72fb2abc 7768 .internal_flags = NL80211_FLAG_NEED_WDEV,
55682965
JB
7769 },
7770 {
7771 .cmd = NL80211_CMD_SET_INTERFACE,
7772 .doit = nl80211_set_interface,
7773 .policy = nl80211_policy,
7774 .flags = GENL_ADMIN_PERM,
4c476991
JB
7775 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7776 NL80211_FLAG_NEED_RTNL,
55682965
JB
7777 },
7778 {
7779 .cmd = NL80211_CMD_NEW_INTERFACE,
7780 .doit = nl80211_new_interface,
7781 .policy = nl80211_policy,
7782 .flags = GENL_ADMIN_PERM,
4c476991
JB
7783 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7784 NL80211_FLAG_NEED_RTNL,
55682965
JB
7785 },
7786 {
7787 .cmd = NL80211_CMD_DEL_INTERFACE,
7788 .doit = nl80211_del_interface,
7789 .policy = nl80211_policy,
41ade00f 7790 .flags = GENL_ADMIN_PERM,
84efbb84 7791 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 7792 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7793 },
7794 {
7795 .cmd = NL80211_CMD_GET_KEY,
7796 .doit = nl80211_get_key,
7797 .policy = nl80211_policy,
7798 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7799 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7800 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7801 },
7802 {
7803 .cmd = NL80211_CMD_SET_KEY,
7804 .doit = nl80211_set_key,
7805 .policy = nl80211_policy,
7806 .flags = GENL_ADMIN_PERM,
41265714 7807 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7808 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7809 },
7810 {
7811 .cmd = NL80211_CMD_NEW_KEY,
7812 .doit = nl80211_new_key,
7813 .policy = nl80211_policy,
7814 .flags = GENL_ADMIN_PERM,
41265714 7815 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7816 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
7817 },
7818 {
7819 .cmd = NL80211_CMD_DEL_KEY,
7820 .doit = nl80211_del_key,
7821 .policy = nl80211_policy,
55682965 7822 .flags = GENL_ADMIN_PERM,
41265714 7823 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7824 NL80211_FLAG_NEED_RTNL,
55682965 7825 },
ed1b6cc7
JB
7826 {
7827 .cmd = NL80211_CMD_SET_BEACON,
7828 .policy = nl80211_policy,
7829 .flags = GENL_ADMIN_PERM,
8860020e 7830 .doit = nl80211_set_beacon,
2b5f8b0b 7831 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7832 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7833 },
7834 {
8860020e 7835 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
7836 .policy = nl80211_policy,
7837 .flags = GENL_ADMIN_PERM,
8860020e 7838 .doit = nl80211_start_ap,
2b5f8b0b 7839 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7840 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
7841 },
7842 {
8860020e 7843 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
7844 .policy = nl80211_policy,
7845 .flags = GENL_ADMIN_PERM,
8860020e 7846 .doit = nl80211_stop_ap,
2b5f8b0b 7847 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7848 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 7849 },
5727ef1b
JB
7850 {
7851 .cmd = NL80211_CMD_GET_STATION,
7852 .doit = nl80211_get_station,
2ec600d6 7853 .dumpit = nl80211_dump_station,
5727ef1b 7854 .policy = nl80211_policy,
4c476991
JB
7855 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7856 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7857 },
7858 {
7859 .cmd = NL80211_CMD_SET_STATION,
7860 .doit = nl80211_set_station,
7861 .policy = nl80211_policy,
7862 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7863 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7864 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7865 },
7866 {
7867 .cmd = NL80211_CMD_NEW_STATION,
7868 .doit = nl80211_new_station,
7869 .policy = nl80211_policy,
7870 .flags = GENL_ADMIN_PERM,
41265714 7871 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7872 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
7873 },
7874 {
7875 .cmd = NL80211_CMD_DEL_STATION,
7876 .doit = nl80211_del_station,
7877 .policy = nl80211_policy,
2ec600d6 7878 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7879 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7880 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7881 },
7882 {
7883 .cmd = NL80211_CMD_GET_MPATH,
7884 .doit = nl80211_get_mpath,
7885 .dumpit = nl80211_dump_mpath,
7886 .policy = nl80211_policy,
7887 .flags = GENL_ADMIN_PERM,
41265714 7888 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7889 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7890 },
7891 {
7892 .cmd = NL80211_CMD_SET_MPATH,
7893 .doit = nl80211_set_mpath,
7894 .policy = nl80211_policy,
7895 .flags = GENL_ADMIN_PERM,
41265714 7896 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7897 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7898 },
7899 {
7900 .cmd = NL80211_CMD_NEW_MPATH,
7901 .doit = nl80211_new_mpath,
7902 .policy = nl80211_policy,
7903 .flags = GENL_ADMIN_PERM,
41265714 7904 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7905 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
7906 },
7907 {
7908 .cmd = NL80211_CMD_DEL_MPATH,
7909 .doit = nl80211_del_mpath,
7910 .policy = nl80211_policy,
9f1ba906 7911 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7912 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7913 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
7914 },
7915 {
7916 .cmd = NL80211_CMD_SET_BSS,
7917 .doit = nl80211_set_bss,
7918 .policy = nl80211_policy,
b2e1b302 7919 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7920 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7921 NL80211_FLAG_NEED_RTNL,
b2e1b302 7922 },
f130347c
LR
7923 {
7924 .cmd = NL80211_CMD_GET_REG,
7925 .doit = nl80211_get_reg,
7926 .policy = nl80211_policy,
7927 /* can be retrieved by unprivileged users */
7928 },
b2e1b302
LR
7929 {
7930 .cmd = NL80211_CMD_SET_REG,
7931 .doit = nl80211_set_reg,
7932 .policy = nl80211_policy,
7933 .flags = GENL_ADMIN_PERM,
7934 },
7935 {
7936 .cmd = NL80211_CMD_REQ_SET_REG,
7937 .doit = nl80211_req_set_reg,
7938 .policy = nl80211_policy,
93da9cc1 7939 .flags = GENL_ADMIN_PERM,
7940 },
7941 {
24bdd9f4
JC
7942 .cmd = NL80211_CMD_GET_MESH_CONFIG,
7943 .doit = nl80211_get_mesh_config,
93da9cc1 7944 .policy = nl80211_policy,
7945 /* can be retrieved by unprivileged users */
2b5f8b0b 7946 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7947 NL80211_FLAG_NEED_RTNL,
93da9cc1 7948 },
7949 {
24bdd9f4
JC
7950 .cmd = NL80211_CMD_SET_MESH_CONFIG,
7951 .doit = nl80211_update_mesh_config,
93da9cc1 7952 .policy = nl80211_policy,
9aed3cc1 7953 .flags = GENL_ADMIN_PERM,
29cbe68c 7954 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7955 NL80211_FLAG_NEED_RTNL,
9aed3cc1 7956 },
2a519311
JB
7957 {
7958 .cmd = NL80211_CMD_TRIGGER_SCAN,
7959 .doit = nl80211_trigger_scan,
7960 .policy = nl80211_policy,
7961 .flags = GENL_ADMIN_PERM,
fd014284 7962 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 7963 NL80211_FLAG_NEED_RTNL,
2a519311
JB
7964 },
7965 {
7966 .cmd = NL80211_CMD_GET_SCAN,
7967 .policy = nl80211_policy,
7968 .dumpit = nl80211_dump_scan,
7969 },
807f8a8c
LC
7970 {
7971 .cmd = NL80211_CMD_START_SCHED_SCAN,
7972 .doit = nl80211_start_sched_scan,
7973 .policy = nl80211_policy,
7974 .flags = GENL_ADMIN_PERM,
7975 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7976 NL80211_FLAG_NEED_RTNL,
7977 },
7978 {
7979 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
7980 .doit = nl80211_stop_sched_scan,
7981 .policy = nl80211_policy,
7982 .flags = GENL_ADMIN_PERM,
7983 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7984 NL80211_FLAG_NEED_RTNL,
7985 },
636a5d36
JM
7986 {
7987 .cmd = NL80211_CMD_AUTHENTICATE,
7988 .doit = nl80211_authenticate,
7989 .policy = nl80211_policy,
7990 .flags = GENL_ADMIN_PERM,
41265714 7991 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7992 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7993 },
7994 {
7995 .cmd = NL80211_CMD_ASSOCIATE,
7996 .doit = nl80211_associate,
7997 .policy = nl80211_policy,
7998 .flags = GENL_ADMIN_PERM,
41265714 7999 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8000 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
8001 },
8002 {
8003 .cmd = NL80211_CMD_DEAUTHENTICATE,
8004 .doit = nl80211_deauthenticate,
8005 .policy = nl80211_policy,
8006 .flags = GENL_ADMIN_PERM,
41265714 8007 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8008 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
8009 },
8010 {
8011 .cmd = NL80211_CMD_DISASSOCIATE,
8012 .doit = nl80211_disassociate,
8013 .policy = nl80211_policy,
8014 .flags = GENL_ADMIN_PERM,
41265714 8015 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8016 NL80211_FLAG_NEED_RTNL,
636a5d36 8017 },
04a773ad
JB
8018 {
8019 .cmd = NL80211_CMD_JOIN_IBSS,
8020 .doit = nl80211_join_ibss,
8021 .policy = nl80211_policy,
8022 .flags = GENL_ADMIN_PERM,
41265714 8023 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8024 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
8025 },
8026 {
8027 .cmd = NL80211_CMD_LEAVE_IBSS,
8028 .doit = nl80211_leave_ibss,
8029 .policy = nl80211_policy,
8030 .flags = GENL_ADMIN_PERM,
41265714 8031 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8032 NL80211_FLAG_NEED_RTNL,
04a773ad 8033 },
aff89a9b
JB
8034#ifdef CONFIG_NL80211_TESTMODE
8035 {
8036 .cmd = NL80211_CMD_TESTMODE,
8037 .doit = nl80211_testmode_do,
71063f0e 8038 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
8039 .policy = nl80211_policy,
8040 .flags = GENL_ADMIN_PERM,
4c476991
JB
8041 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8042 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
8043 },
8044#endif
b23aa676
SO
8045 {
8046 .cmd = NL80211_CMD_CONNECT,
8047 .doit = nl80211_connect,
8048 .policy = nl80211_policy,
8049 .flags = GENL_ADMIN_PERM,
41265714 8050 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8051 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
8052 },
8053 {
8054 .cmd = NL80211_CMD_DISCONNECT,
8055 .doit = nl80211_disconnect,
8056 .policy = nl80211_policy,
8057 .flags = GENL_ADMIN_PERM,
41265714 8058 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8059 NL80211_FLAG_NEED_RTNL,
b23aa676 8060 },
463d0183
JB
8061 {
8062 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
8063 .doit = nl80211_wiphy_netns,
8064 .policy = nl80211_policy,
8065 .flags = GENL_ADMIN_PERM,
4c476991
JB
8066 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8067 NL80211_FLAG_NEED_RTNL,
463d0183 8068 },
61fa713c
HS
8069 {
8070 .cmd = NL80211_CMD_GET_SURVEY,
8071 .policy = nl80211_policy,
8072 .dumpit = nl80211_dump_survey,
8073 },
67fbb16b
SO
8074 {
8075 .cmd = NL80211_CMD_SET_PMKSA,
8076 .doit = nl80211_setdel_pmksa,
8077 .policy = nl80211_policy,
8078 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8079 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8080 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
8081 },
8082 {
8083 .cmd = NL80211_CMD_DEL_PMKSA,
8084 .doit = nl80211_setdel_pmksa,
8085 .policy = nl80211_policy,
8086 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8087 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8088 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
8089 },
8090 {
8091 .cmd = NL80211_CMD_FLUSH_PMKSA,
8092 .doit = nl80211_flush_pmksa,
8093 .policy = nl80211_policy,
8094 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8095 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 8096 NL80211_FLAG_NEED_RTNL,
67fbb16b 8097 },
9588bbd5
JM
8098 {
8099 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
8100 .doit = nl80211_remain_on_channel,
8101 .policy = nl80211_policy,
8102 .flags = GENL_ADMIN_PERM,
71bbc994 8103 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8104 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
8105 },
8106 {
8107 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
8108 .doit = nl80211_cancel_remain_on_channel,
8109 .policy = nl80211_policy,
8110 .flags = GENL_ADMIN_PERM,
71bbc994 8111 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8112 NL80211_FLAG_NEED_RTNL,
9588bbd5 8113 },
13ae75b1
JM
8114 {
8115 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
8116 .doit = nl80211_set_tx_bitrate_mask,
8117 .policy = nl80211_policy,
8118 .flags = GENL_ADMIN_PERM,
4c476991
JB
8119 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8120 NL80211_FLAG_NEED_RTNL,
13ae75b1 8121 },
026331c4 8122 {
2e161f78
JB
8123 .cmd = NL80211_CMD_REGISTER_FRAME,
8124 .doit = nl80211_register_mgmt,
026331c4
JM
8125 .policy = nl80211_policy,
8126 .flags = GENL_ADMIN_PERM,
71bbc994 8127 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 8128 NL80211_FLAG_NEED_RTNL,
026331c4
JM
8129 },
8130 {
2e161f78
JB
8131 .cmd = NL80211_CMD_FRAME,
8132 .doit = nl80211_tx_mgmt,
026331c4 8133 .policy = nl80211_policy,
f7ca38df 8134 .flags = GENL_ADMIN_PERM,
71bbc994 8135 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
8136 NL80211_FLAG_NEED_RTNL,
8137 },
8138 {
8139 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
8140 .doit = nl80211_tx_mgmt_cancel_wait,
8141 .policy = nl80211_policy,
026331c4 8142 .flags = GENL_ADMIN_PERM,
71bbc994 8143 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 8144 NL80211_FLAG_NEED_RTNL,
026331c4 8145 },
ffb9eb3d
KV
8146 {
8147 .cmd = NL80211_CMD_SET_POWER_SAVE,
8148 .doit = nl80211_set_power_save,
8149 .policy = nl80211_policy,
8150 .flags = GENL_ADMIN_PERM,
4c476991
JB
8151 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8152 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
8153 },
8154 {
8155 .cmd = NL80211_CMD_GET_POWER_SAVE,
8156 .doit = nl80211_get_power_save,
8157 .policy = nl80211_policy,
8158 /* can be retrieved by unprivileged users */
4c476991
JB
8159 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8160 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 8161 },
d6dc1a38
JO
8162 {
8163 .cmd = NL80211_CMD_SET_CQM,
8164 .doit = nl80211_set_cqm,
8165 .policy = nl80211_policy,
8166 .flags = GENL_ADMIN_PERM,
4c476991
JB
8167 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8168 NL80211_FLAG_NEED_RTNL,
d6dc1a38 8169 },
f444de05
JB
8170 {
8171 .cmd = NL80211_CMD_SET_CHANNEL,
8172 .doit = nl80211_set_channel,
8173 .policy = nl80211_policy,
8174 .flags = GENL_ADMIN_PERM,
4c476991
JB
8175 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8176 NL80211_FLAG_NEED_RTNL,
f444de05 8177 },
e8347eba
BJ
8178 {
8179 .cmd = NL80211_CMD_SET_WDS_PEER,
8180 .doit = nl80211_set_wds_peer,
8181 .policy = nl80211_policy,
8182 .flags = GENL_ADMIN_PERM,
43b19952
JB
8183 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8184 NL80211_FLAG_NEED_RTNL,
e8347eba 8185 },
29cbe68c
JB
8186 {
8187 .cmd = NL80211_CMD_JOIN_MESH,
8188 .doit = nl80211_join_mesh,
8189 .policy = nl80211_policy,
8190 .flags = GENL_ADMIN_PERM,
8191 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8192 NL80211_FLAG_NEED_RTNL,
8193 },
8194 {
8195 .cmd = NL80211_CMD_LEAVE_MESH,
8196 .doit = nl80211_leave_mesh,
8197 .policy = nl80211_policy,
8198 .flags = GENL_ADMIN_PERM,
8199 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8200 NL80211_FLAG_NEED_RTNL,
8201 },
dfb89c56 8202#ifdef CONFIG_PM
ff1b6e69
JB
8203 {
8204 .cmd = NL80211_CMD_GET_WOWLAN,
8205 .doit = nl80211_get_wowlan,
8206 .policy = nl80211_policy,
8207 /* can be retrieved by unprivileged users */
8208 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8209 NL80211_FLAG_NEED_RTNL,
8210 },
8211 {
8212 .cmd = NL80211_CMD_SET_WOWLAN,
8213 .doit = nl80211_set_wowlan,
8214 .policy = nl80211_policy,
8215 .flags = GENL_ADMIN_PERM,
8216 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8217 NL80211_FLAG_NEED_RTNL,
8218 },
dfb89c56 8219#endif
e5497d76
JB
8220 {
8221 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
8222 .doit = nl80211_set_rekey_data,
8223 .policy = nl80211_policy,
8224 .flags = GENL_ADMIN_PERM,
8225 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8226 NL80211_FLAG_NEED_RTNL,
8227 },
109086ce
AN
8228 {
8229 .cmd = NL80211_CMD_TDLS_MGMT,
8230 .doit = nl80211_tdls_mgmt,
8231 .policy = nl80211_policy,
8232 .flags = GENL_ADMIN_PERM,
8233 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8234 NL80211_FLAG_NEED_RTNL,
8235 },
8236 {
8237 .cmd = NL80211_CMD_TDLS_OPER,
8238 .doit = nl80211_tdls_oper,
8239 .policy = nl80211_policy,
8240 .flags = GENL_ADMIN_PERM,
8241 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
8242 NL80211_FLAG_NEED_RTNL,
8243 },
28946da7
JB
8244 {
8245 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
8246 .doit = nl80211_register_unexpected_frame,
8247 .policy = nl80211_policy,
8248 .flags = GENL_ADMIN_PERM,
8249 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8250 NL80211_FLAG_NEED_RTNL,
8251 },
7f6cf311
JB
8252 {
8253 .cmd = NL80211_CMD_PROBE_CLIENT,
8254 .doit = nl80211_probe_client,
8255 .policy = nl80211_policy,
8256 .flags = GENL_ADMIN_PERM,
2b5f8b0b 8257 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
8258 NL80211_FLAG_NEED_RTNL,
8259 },
5e760230
JB
8260 {
8261 .cmd = NL80211_CMD_REGISTER_BEACONS,
8262 .doit = nl80211_register_beacons,
8263 .policy = nl80211_policy,
8264 .flags = GENL_ADMIN_PERM,
8265 .internal_flags = NL80211_FLAG_NEED_WIPHY |
8266 NL80211_FLAG_NEED_RTNL,
8267 },
1d9d9213
SW
8268 {
8269 .cmd = NL80211_CMD_SET_NOACK_MAP,
8270 .doit = nl80211_set_noack_map,
8271 .policy = nl80211_policy,
8272 .flags = GENL_ADMIN_PERM,
8273 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8274 NL80211_FLAG_NEED_RTNL,
8275 },
98104fde
JB
8276 {
8277 .cmd = NL80211_CMD_START_P2P_DEVICE,
8278 .doit = nl80211_start_p2p_device,
8279 .policy = nl80211_policy,
8280 .flags = GENL_ADMIN_PERM,
8281 .internal_flags = NL80211_FLAG_NEED_WDEV |
8282 NL80211_FLAG_NEED_RTNL,
8283 },
8284 {
8285 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
8286 .doit = nl80211_stop_p2p_device,
8287 .policy = nl80211_policy,
8288 .flags = GENL_ADMIN_PERM,
8289 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
8290 NL80211_FLAG_NEED_RTNL,
8291 },
f4e583c8
AQ
8292 {
8293 .cmd = NL80211_CMD_SET_MCAST_RATE,
8294 .doit = nl80211_set_mcast_rate,
77765eaf
VT
8295 .policy = nl80211_policy,
8296 .flags = GENL_ADMIN_PERM,
8297 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8298 NL80211_FLAG_NEED_RTNL,
8299 },
8300 {
8301 .cmd = NL80211_CMD_SET_MAC_ACL,
8302 .doit = nl80211_set_mac_acl,
f4e583c8
AQ
8303 .policy = nl80211_policy,
8304 .flags = GENL_ADMIN_PERM,
8305 .internal_flags = NL80211_FLAG_NEED_NETDEV |
8306 NL80211_FLAG_NEED_RTNL,
8307 },
55682965 8308};
9588bbd5 8309
6039f6d2
JM
8310static struct genl_multicast_group nl80211_mlme_mcgrp = {
8311 .name = "mlme",
8312};
55682965
JB
8313
8314/* multicast groups */
8315static struct genl_multicast_group nl80211_config_mcgrp = {
8316 .name = "config",
8317};
2a519311
JB
8318static struct genl_multicast_group nl80211_scan_mcgrp = {
8319 .name = "scan",
8320};
73d54c9e
LR
8321static struct genl_multicast_group nl80211_regulatory_mcgrp = {
8322 .name = "regulatory",
8323};
55682965
JB
8324
8325/* notification functions */
8326
8327void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
8328{
8329 struct sk_buff *msg;
8330
fd2120ca 8331 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
8332 if (!msg)
8333 return;
8334
8335 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
8336 nlmsg_free(msg);
8337 return;
8338 }
8339
463d0183
JB
8340 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8341 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
8342}
8343
362a415d
JB
8344static int nl80211_add_scan_req(struct sk_buff *msg,
8345 struct cfg80211_registered_device *rdev)
8346{
8347 struct cfg80211_scan_request *req = rdev->scan_req;
8348 struct nlattr *nest;
8349 int i;
8350
667503dd
JB
8351 ASSERT_RDEV_LOCK(rdev);
8352
362a415d
JB
8353 if (WARN_ON(!req))
8354 return 0;
8355
8356 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
8357 if (!nest)
8358 goto nla_put_failure;
9360ffd1
DM
8359 for (i = 0; i < req->n_ssids; i++) {
8360 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
8361 goto nla_put_failure;
8362 }
362a415d
JB
8363 nla_nest_end(msg, nest);
8364
8365 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
8366 if (!nest)
8367 goto nla_put_failure;
9360ffd1
DM
8368 for (i = 0; i < req->n_channels; i++) {
8369 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
8370 goto nla_put_failure;
8371 }
362a415d
JB
8372 nla_nest_end(msg, nest);
8373
9360ffd1
DM
8374 if (req->ie &&
8375 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
8376 goto nla_put_failure;
362a415d 8377
ed473771
SL
8378 if (req->flags)
8379 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags);
8380
362a415d
JB
8381 return 0;
8382 nla_put_failure:
8383 return -ENOBUFS;
8384}
8385
a538e2d5
JB
8386static int nl80211_send_scan_msg(struct sk_buff *msg,
8387 struct cfg80211_registered_device *rdev,
fd014284 8388 struct wireless_dev *wdev,
15e47304 8389 u32 portid, u32 seq, int flags,
a538e2d5 8390 u32 cmd)
2a519311
JB
8391{
8392 void *hdr;
8393
15e47304 8394 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
8395 if (!hdr)
8396 return -1;
8397
9360ffd1 8398 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
8399 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
8400 wdev->netdev->ifindex)) ||
8401 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9360ffd1 8402 goto nla_put_failure;
2a519311 8403
362a415d
JB
8404 /* ignore errors and send incomplete event anyway */
8405 nl80211_add_scan_req(msg, rdev);
2a519311
JB
8406
8407 return genlmsg_end(msg, hdr);
8408
8409 nla_put_failure:
8410 genlmsg_cancel(msg, hdr);
8411 return -EMSGSIZE;
8412}
8413
807f8a8c
LC
8414static int
8415nl80211_send_sched_scan_msg(struct sk_buff *msg,
8416 struct cfg80211_registered_device *rdev,
8417 struct net_device *netdev,
15e47304 8418 u32 portid, u32 seq, int flags, u32 cmd)
807f8a8c
LC
8419{
8420 void *hdr;
8421
15e47304 8422 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
807f8a8c
LC
8423 if (!hdr)
8424 return -1;
8425
9360ffd1
DM
8426 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8427 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8428 goto nla_put_failure;
807f8a8c
LC
8429
8430 return genlmsg_end(msg, hdr);
8431
8432 nla_put_failure:
8433 genlmsg_cancel(msg, hdr);
8434 return -EMSGSIZE;
8435}
8436
a538e2d5 8437void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 8438 struct wireless_dev *wdev)
a538e2d5
JB
8439{
8440 struct sk_buff *msg;
8441
58050fce 8442 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
8443 if (!msg)
8444 return;
8445
fd014284 8446 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
8447 NL80211_CMD_TRIGGER_SCAN) < 0) {
8448 nlmsg_free(msg);
8449 return;
8450 }
8451
463d0183
JB
8452 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8453 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
8454}
8455
2a519311 8456void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
fd014284 8457 struct wireless_dev *wdev)
2a519311
JB
8458{
8459 struct sk_buff *msg;
8460
fd2120ca 8461 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8462 if (!msg)
8463 return;
8464
fd014284 8465 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8466 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
8467 nlmsg_free(msg);
8468 return;
8469 }
8470
463d0183
JB
8471 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8472 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8473}
8474
8475void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
fd014284 8476 struct wireless_dev *wdev)
2a519311
JB
8477{
8478 struct sk_buff *msg;
8479
fd2120ca 8480 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
8481 if (!msg)
8482 return;
8483
fd014284 8484 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5 8485 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
8486 nlmsg_free(msg);
8487 return;
8488 }
8489
463d0183
JB
8490 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8491 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
8492}
8493
807f8a8c
LC
8494void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
8495 struct net_device *netdev)
8496{
8497 struct sk_buff *msg;
8498
8499 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
8500 if (!msg)
8501 return;
8502
8503 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
8504 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
8505 nlmsg_free(msg);
8506 return;
8507 }
8508
8509 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8510 nl80211_scan_mcgrp.id, GFP_KERNEL);
8511}
8512
8513void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
8514 struct net_device *netdev, u32 cmd)
8515{
8516 struct sk_buff *msg;
8517
58050fce 8518 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
8519 if (!msg)
8520 return;
8521
8522 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
8523 nlmsg_free(msg);
8524 return;
8525 }
8526
8527 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8528 nl80211_scan_mcgrp.id, GFP_KERNEL);
8529}
8530
73d54c9e
LR
8531/*
8532 * This can happen on global regulatory changes or device specific settings
8533 * based on custom world regulatory domains.
8534 */
8535void nl80211_send_reg_change_event(struct regulatory_request *request)
8536{
8537 struct sk_buff *msg;
8538 void *hdr;
8539
fd2120ca 8540 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
8541 if (!msg)
8542 return;
8543
8544 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
8545 if (!hdr) {
8546 nlmsg_free(msg);
8547 return;
8548 }
8549
8550 /* Userspace can always count this one always being set */
9360ffd1
DM
8551 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
8552 goto nla_put_failure;
8553
8554 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
8555 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8556 NL80211_REGDOM_TYPE_WORLD))
8557 goto nla_put_failure;
8558 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
8559 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8560 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
8561 goto nla_put_failure;
8562 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
8563 request->intersect) {
8564 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8565 NL80211_REGDOM_TYPE_INTERSECTION))
8566 goto nla_put_failure;
8567 } else {
8568 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
8569 NL80211_REGDOM_TYPE_COUNTRY) ||
8570 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
8571 request->alpha2))
8572 goto nla_put_failure;
8573 }
8574
f4173766 8575 if (request->wiphy_idx != WIPHY_IDX_INVALID &&
9360ffd1
DM
8576 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
8577 goto nla_put_failure;
73d54c9e 8578
3b7b72ee 8579 genlmsg_end(msg, hdr);
73d54c9e 8580
bc43b28c 8581 rcu_read_lock();
463d0183 8582 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
8583 GFP_ATOMIC);
8584 rcu_read_unlock();
73d54c9e
LR
8585
8586 return;
8587
8588nla_put_failure:
8589 genlmsg_cancel(msg, hdr);
8590 nlmsg_free(msg);
8591}
8592
6039f6d2
JM
8593static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
8594 struct net_device *netdev,
8595 const u8 *buf, size_t len,
e6d6e342 8596 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
8597{
8598 struct sk_buff *msg;
8599 void *hdr;
8600
e6d6e342 8601 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
8602 if (!msg)
8603 return;
8604
8605 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8606 if (!hdr) {
8607 nlmsg_free(msg);
8608 return;
8609 }
8610
9360ffd1
DM
8611 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8612 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8613 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8614 goto nla_put_failure;
6039f6d2 8615
3b7b72ee 8616 genlmsg_end(msg, hdr);
6039f6d2 8617
463d0183
JB
8618 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8619 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
8620 return;
8621
8622 nla_put_failure:
8623 genlmsg_cancel(msg, hdr);
8624 nlmsg_free(msg);
8625}
8626
8627void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8628 struct net_device *netdev, const u8 *buf,
8629 size_t len, gfp_t gfp)
6039f6d2
JM
8630{
8631 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8632 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
8633}
8634
8635void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
8636 struct net_device *netdev, const u8 *buf,
e6d6e342 8637 size_t len, gfp_t gfp)
6039f6d2 8638{
e6d6e342
JB
8639 nl80211_send_mlme_event(rdev, netdev, buf, len,
8640 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
8641}
8642
53b46b84 8643void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8644 struct net_device *netdev, const u8 *buf,
8645 size_t len, gfp_t gfp)
6039f6d2
JM
8646{
8647 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8648 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
8649}
8650
53b46b84
JM
8651void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
8652 struct net_device *netdev, const u8 *buf,
e6d6e342 8653 size_t len, gfp_t gfp)
6039f6d2
JM
8654{
8655 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 8656 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
8657}
8658
cf4e594e
JM
8659void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
8660 struct net_device *netdev, const u8 *buf,
8661 size_t len, gfp_t gfp)
8662{
8663 nl80211_send_mlme_event(rdev, netdev, buf, len,
8664 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
8665}
8666
8667void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
8668 struct net_device *netdev, const u8 *buf,
8669 size_t len, gfp_t gfp)
8670{
8671 nl80211_send_mlme_event(rdev, netdev, buf, len,
8672 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
8673}
8674
1b06bb40
LR
8675static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
8676 struct net_device *netdev, int cmd,
e6d6e342 8677 const u8 *addr, gfp_t gfp)
1965c853
JM
8678{
8679 struct sk_buff *msg;
8680 void *hdr;
8681
e6d6e342 8682 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
8683 if (!msg)
8684 return;
8685
8686 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8687 if (!hdr) {
8688 nlmsg_free(msg);
8689 return;
8690 }
8691
9360ffd1
DM
8692 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8693 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8694 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
8695 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8696 goto nla_put_failure;
1965c853 8697
3b7b72ee 8698 genlmsg_end(msg, hdr);
1965c853 8699
463d0183
JB
8700 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8701 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
8702 return;
8703
8704 nla_put_failure:
8705 genlmsg_cancel(msg, hdr);
8706 nlmsg_free(msg);
8707}
8708
8709void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8710 struct net_device *netdev, const u8 *addr,
8711 gfp_t gfp)
1965c853
JM
8712{
8713 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 8714 addr, gfp);
1965c853
JM
8715}
8716
8717void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
8718 struct net_device *netdev, const u8 *addr,
8719 gfp_t gfp)
1965c853 8720{
e6d6e342
JB
8721 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
8722 addr, gfp);
1965c853
JM
8723}
8724
b23aa676
SO
8725void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
8726 struct net_device *netdev, const u8 *bssid,
8727 const u8 *req_ie, size_t req_ie_len,
8728 const u8 *resp_ie, size_t resp_ie_len,
8729 u16 status, gfp_t gfp)
8730{
8731 struct sk_buff *msg;
8732 void *hdr;
8733
58050fce 8734 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8735 if (!msg)
8736 return;
8737
8738 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
8739 if (!hdr) {
8740 nlmsg_free(msg);
8741 return;
8742 }
8743
9360ffd1
DM
8744 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8745 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8746 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
8747 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
8748 (req_ie &&
8749 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8750 (resp_ie &&
8751 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8752 goto nla_put_failure;
b23aa676 8753
3b7b72ee 8754 genlmsg_end(msg, hdr);
b23aa676 8755
463d0183
JB
8756 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8757 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8758 return;
8759
8760 nla_put_failure:
8761 genlmsg_cancel(msg, hdr);
8762 nlmsg_free(msg);
8763
8764}
8765
8766void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
8767 struct net_device *netdev, const u8 *bssid,
8768 const u8 *req_ie, size_t req_ie_len,
8769 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
8770{
8771 struct sk_buff *msg;
8772 void *hdr;
8773
58050fce 8774 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
b23aa676
SO
8775 if (!msg)
8776 return;
8777
8778 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
8779 if (!hdr) {
8780 nlmsg_free(msg);
8781 return;
8782 }
8783
9360ffd1
DM
8784 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8785 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8786 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
8787 (req_ie &&
8788 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
8789 (resp_ie &&
8790 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
8791 goto nla_put_failure;
b23aa676 8792
3b7b72ee 8793 genlmsg_end(msg, hdr);
b23aa676 8794
463d0183
JB
8795 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8796 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
8797 return;
8798
8799 nla_put_failure:
8800 genlmsg_cancel(msg, hdr);
8801 nlmsg_free(msg);
8802
8803}
8804
8805void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
8806 struct net_device *netdev, u16 reason,
667503dd 8807 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
8808{
8809 struct sk_buff *msg;
8810 void *hdr;
8811
58050fce 8812 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
b23aa676
SO
8813 if (!msg)
8814 return;
8815
8816 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
8817 if (!hdr) {
8818 nlmsg_free(msg);
8819 return;
8820 }
8821
9360ffd1
DM
8822 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8823 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8824 (from_ap && reason &&
8825 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
8826 (from_ap &&
8827 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
8828 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
8829 goto nla_put_failure;
b23aa676 8830
3b7b72ee 8831 genlmsg_end(msg, hdr);
b23aa676 8832
463d0183
JB
8833 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8834 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
8835 return;
8836
8837 nla_put_failure:
8838 genlmsg_cancel(msg, hdr);
8839 nlmsg_free(msg);
8840
8841}
8842
04a773ad
JB
8843void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
8844 struct net_device *netdev, const u8 *bssid,
8845 gfp_t gfp)
8846{
8847 struct sk_buff *msg;
8848 void *hdr;
8849
fd2120ca 8850 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
8851 if (!msg)
8852 return;
8853
8854 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
8855 if (!hdr) {
8856 nlmsg_free(msg);
8857 return;
8858 }
8859
9360ffd1
DM
8860 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8861 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8862 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8863 goto nla_put_failure;
04a773ad 8864
3b7b72ee 8865 genlmsg_end(msg, hdr);
04a773ad 8866
463d0183
JB
8867 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8868 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
8869 return;
8870
8871 nla_put_failure:
8872 genlmsg_cancel(msg, hdr);
8873 nlmsg_free(msg);
8874}
8875
c93b5e71
JC
8876void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
8877 struct net_device *netdev,
8878 const u8 *macaddr, const u8* ie, u8 ie_len,
8879 gfp_t gfp)
8880{
8881 struct sk_buff *msg;
8882 void *hdr;
8883
8884 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8885 if (!msg)
8886 return;
8887
8888 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
8889 if (!hdr) {
8890 nlmsg_free(msg);
8891 return;
8892 }
8893
9360ffd1
DM
8894 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8895 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8896 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
8897 (ie_len && ie &&
8898 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
8899 goto nla_put_failure;
c93b5e71 8900
3b7b72ee 8901 genlmsg_end(msg, hdr);
c93b5e71
JC
8902
8903 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8904 nl80211_mlme_mcgrp.id, gfp);
8905 return;
8906
8907 nla_put_failure:
8908 genlmsg_cancel(msg, hdr);
8909 nlmsg_free(msg);
8910}
8911
a3b8b056
JM
8912void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
8913 struct net_device *netdev, const u8 *addr,
8914 enum nl80211_key_type key_type, int key_id,
e6d6e342 8915 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
8916{
8917 struct sk_buff *msg;
8918 void *hdr;
8919
e6d6e342 8920 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
8921 if (!msg)
8922 return;
8923
8924 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
8925 if (!hdr) {
8926 nlmsg_free(msg);
8927 return;
8928 }
8929
9360ffd1
DM
8930 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8931 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8932 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
8933 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
8934 (key_id != -1 &&
8935 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
8936 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
8937 goto nla_put_failure;
a3b8b056 8938
3b7b72ee 8939 genlmsg_end(msg, hdr);
a3b8b056 8940
463d0183
JB
8941 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8942 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
8943 return;
8944
8945 nla_put_failure:
8946 genlmsg_cancel(msg, hdr);
8947 nlmsg_free(msg);
8948}
8949
6bad8766
LR
8950void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
8951 struct ieee80211_channel *channel_before,
8952 struct ieee80211_channel *channel_after)
8953{
8954 struct sk_buff *msg;
8955 void *hdr;
8956 struct nlattr *nl_freq;
8957
fd2120ca 8958 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
8959 if (!msg)
8960 return;
8961
8962 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
8963 if (!hdr) {
8964 nlmsg_free(msg);
8965 return;
8966 }
8967
8968 /*
8969 * Since we are applying the beacon hint to a wiphy we know its
8970 * wiphy_idx is valid
8971 */
9360ffd1
DM
8972 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8973 goto nla_put_failure;
6bad8766
LR
8974
8975 /* Before */
8976 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
8977 if (!nl_freq)
8978 goto nla_put_failure;
8979 if (nl80211_msg_put_channel(msg, channel_before))
8980 goto nla_put_failure;
8981 nla_nest_end(msg, nl_freq);
8982
8983 /* After */
8984 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
8985 if (!nl_freq)
8986 goto nla_put_failure;
8987 if (nl80211_msg_put_channel(msg, channel_after))
8988 goto nla_put_failure;
8989 nla_nest_end(msg, nl_freq);
8990
3b7b72ee 8991 genlmsg_end(msg, hdr);
6bad8766 8992
463d0183
JB
8993 rcu_read_lock();
8994 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
8995 GFP_ATOMIC);
8996 rcu_read_unlock();
6bad8766
LR
8997
8998 return;
8999
9000nla_put_failure:
9001 genlmsg_cancel(msg, hdr);
9002 nlmsg_free(msg);
9003}
9004
9588bbd5
JM
9005static void nl80211_send_remain_on_chan_event(
9006 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 9007 struct wireless_dev *wdev, u64 cookie,
9588bbd5 9008 struct ieee80211_channel *chan,
9588bbd5
JM
9009 unsigned int duration, gfp_t gfp)
9010{
9011 struct sk_buff *msg;
9012 void *hdr;
9013
9014 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9015 if (!msg)
9016 return;
9017
9018 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
9019 if (!hdr) {
9020 nlmsg_free(msg);
9021 return;
9022 }
9023
9360ffd1 9024 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
9025 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9026 wdev->netdev->ifindex)) ||
00f53350 9027 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)) ||
9360ffd1 9028 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
9029 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
9030 NL80211_CHAN_NO_HT) ||
9360ffd1
DM
9031 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
9032 goto nla_put_failure;
9588bbd5 9033
9360ffd1
DM
9034 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
9035 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
9036 goto nla_put_failure;
9588bbd5 9037
3b7b72ee 9038 genlmsg_end(msg, hdr);
9588bbd5
JM
9039
9040 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9041 nl80211_mlme_mcgrp.id, gfp);
9042 return;
9043
9044 nla_put_failure:
9045 genlmsg_cancel(msg, hdr);
9046 nlmsg_free(msg);
9047}
9048
9049void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
71bbc994 9050 struct wireless_dev *wdev, u64 cookie,
9588bbd5 9051 struct ieee80211_channel *chan,
9588bbd5
JM
9052 unsigned int duration, gfp_t gfp)
9053{
9054 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 9055 rdev, wdev, cookie, chan,
42d97a59 9056 duration, gfp);
9588bbd5
JM
9057}
9058
9059void nl80211_send_remain_on_channel_cancel(
71bbc994
JB
9060 struct cfg80211_registered_device *rdev,
9061 struct wireless_dev *wdev,
42d97a59 9062 u64 cookie, struct ieee80211_channel *chan, gfp_t gfp)
9588bbd5
JM
9063{
9064 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 9065 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5
JM
9066}
9067
98b62183
JB
9068void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
9069 struct net_device *dev, const u8 *mac_addr,
9070 struct station_info *sinfo, gfp_t gfp)
9071{
9072 struct sk_buff *msg;
9073
58050fce 9074 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
9075 if (!msg)
9076 return;
9077
66266b3a
JL
9078 if (nl80211_send_station(msg, 0, 0, 0,
9079 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
9080 nlmsg_free(msg);
9081 return;
9082 }
9083
9084 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9085 nl80211_mlme_mcgrp.id, gfp);
9086}
9087
ec15e68b
JM
9088void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
9089 struct net_device *dev, const u8 *mac_addr,
9090 gfp_t gfp)
9091{
9092 struct sk_buff *msg;
9093 void *hdr;
9094
58050fce 9095 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
9096 if (!msg)
9097 return;
9098
9099 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
9100 if (!hdr) {
9101 nlmsg_free(msg);
9102 return;
9103 }
9104
9360ffd1
DM
9105 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9106 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
9107 goto nla_put_failure;
ec15e68b 9108
3b7b72ee 9109 genlmsg_end(msg, hdr);
ec15e68b
JM
9110
9111 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9112 nl80211_mlme_mcgrp.id, gfp);
9113 return;
9114
9115 nla_put_failure:
9116 genlmsg_cancel(msg, hdr);
9117 nlmsg_free(msg);
9118}
9119
ed44a951
PP
9120void nl80211_send_conn_failed_event(struct cfg80211_registered_device *rdev,
9121 struct net_device *dev, const u8 *mac_addr,
9122 enum nl80211_connect_failed_reason reason,
9123 gfp_t gfp)
9124{
9125 struct sk_buff *msg;
9126 void *hdr;
9127
9128 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
9129 if (!msg)
9130 return;
9131
9132 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
9133 if (!hdr) {
9134 nlmsg_free(msg);
9135 return;
9136 }
9137
9138 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9139 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
9140 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
9141 goto nla_put_failure;
9142
9143 genlmsg_end(msg, hdr);
9144
9145 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9146 nl80211_mlme_mcgrp.id, gfp);
9147 return;
9148
9149 nla_put_failure:
9150 genlmsg_cancel(msg, hdr);
9151 nlmsg_free(msg);
9152}
9153
b92ab5d8
JB
9154static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
9155 const u8 *addr, gfp_t gfp)
28946da7
JB
9156{
9157 struct wireless_dev *wdev = dev->ieee80211_ptr;
9158 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9159 struct sk_buff *msg;
9160 void *hdr;
9161 int err;
15e47304 9162 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid);
28946da7 9163
15e47304 9164 if (!nlportid)
28946da7
JB
9165 return false;
9166
9167 msg = nlmsg_new(100, gfp);
9168 if (!msg)
9169 return true;
9170
b92ab5d8 9171 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
9172 if (!hdr) {
9173 nlmsg_free(msg);
9174 return true;
9175 }
9176
9360ffd1
DM
9177 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9178 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9179 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
9180 goto nla_put_failure;
28946da7
JB
9181
9182 err = genlmsg_end(msg, hdr);
9183 if (err < 0) {
9184 nlmsg_free(msg);
9185 return true;
9186 }
9187
15e47304 9188 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
9189 return true;
9190
9191 nla_put_failure:
9192 genlmsg_cancel(msg, hdr);
9193 nlmsg_free(msg);
9194 return true;
9195}
9196
b92ab5d8
JB
9197bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
9198{
9199 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
9200 addr, gfp);
9201}
9202
9203bool nl80211_unexpected_4addr_frame(struct net_device *dev,
9204 const u8 *addr, gfp_t gfp)
9205{
9206 return __nl80211_unexpected_frame(dev,
9207 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
9208 addr, gfp);
9209}
9210
2e161f78 9211int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 9212 struct wireless_dev *wdev, u32 nlportid,
804483e9
JB
9213 int freq, int sig_dbm,
9214 const u8 *buf, size_t len, gfp_t gfp)
026331c4 9215{
71bbc994 9216 struct net_device *netdev = wdev->netdev;
026331c4
JM
9217 struct sk_buff *msg;
9218 void *hdr;
026331c4
JM
9219
9220 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9221 if (!msg)
9222 return -ENOMEM;
9223
2e161f78 9224 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
9225 if (!hdr) {
9226 nlmsg_free(msg);
9227 return -ENOMEM;
9228 }
9229
9360ffd1 9230 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
9231 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9232 netdev->ifindex)) ||
9360ffd1
DM
9233 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
9234 (sig_dbm &&
9235 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9236 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
9237 goto nla_put_failure;
026331c4 9238
3b7b72ee 9239 genlmsg_end(msg, hdr);
026331c4 9240
15e47304 9241 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
9242
9243 nla_put_failure:
9244 genlmsg_cancel(msg, hdr);
9245 nlmsg_free(msg);
9246 return -ENOBUFS;
9247}
9248
2e161f78 9249void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
71bbc994 9250 struct wireless_dev *wdev, u64 cookie,
2e161f78
JB
9251 const u8 *buf, size_t len, bool ack,
9252 gfp_t gfp)
026331c4 9253{
71bbc994 9254 struct net_device *netdev = wdev->netdev;
026331c4
JM
9255 struct sk_buff *msg;
9256 void *hdr;
9257
9258 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9259 if (!msg)
9260 return;
9261
2e161f78 9262 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
9263 if (!hdr) {
9264 nlmsg_free(msg);
9265 return;
9266 }
9267
9360ffd1 9268 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
9269 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9270 netdev->ifindex)) ||
9360ffd1
DM
9271 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
9272 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
9273 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
9274 goto nla_put_failure;
026331c4 9275
3b7b72ee 9276 genlmsg_end(msg, hdr);
026331c4
JM
9277
9278 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
9279 return;
9280
9281 nla_put_failure:
9282 genlmsg_cancel(msg, hdr);
9283 nlmsg_free(msg);
9284}
9285
d6dc1a38
JO
9286void
9287nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
9288 struct net_device *netdev,
9289 enum nl80211_cqm_rssi_threshold_event rssi_event,
9290 gfp_t gfp)
9291{
9292 struct sk_buff *msg;
9293 struct nlattr *pinfoattr;
9294 void *hdr;
9295
58050fce 9296 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
d6dc1a38
JO
9297 if (!msg)
9298 return;
9299
9300 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9301 if (!hdr) {
9302 nlmsg_free(msg);
9303 return;
9304 }
9305
9360ffd1
DM
9306 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9307 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9308 goto nla_put_failure;
d6dc1a38
JO
9309
9310 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9311 if (!pinfoattr)
9312 goto nla_put_failure;
9313
9360ffd1
DM
9314 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
9315 rssi_event))
9316 goto nla_put_failure;
d6dc1a38
JO
9317
9318 nla_nest_end(msg, pinfoattr);
9319
3b7b72ee 9320 genlmsg_end(msg, hdr);
d6dc1a38
JO
9321
9322 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9323 nl80211_mlme_mcgrp.id, gfp);
9324 return;
9325
9326 nla_put_failure:
9327 genlmsg_cancel(msg, hdr);
9328 nlmsg_free(msg);
9329}
9330
e5497d76
JB
9331void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
9332 struct net_device *netdev, const u8 *bssid,
9333 const u8 *replay_ctr, gfp_t gfp)
9334{
9335 struct sk_buff *msg;
9336 struct nlattr *rekey_attr;
9337 void *hdr;
9338
58050fce 9339 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
9340 if (!msg)
9341 return;
9342
9343 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
9344 if (!hdr) {
9345 nlmsg_free(msg);
9346 return;
9347 }
9348
9360ffd1
DM
9349 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9350 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9351 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
9352 goto nla_put_failure;
e5497d76
JB
9353
9354 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
9355 if (!rekey_attr)
9356 goto nla_put_failure;
9357
9360ffd1
DM
9358 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
9359 NL80211_REPLAY_CTR_LEN, replay_ctr))
9360 goto nla_put_failure;
e5497d76
JB
9361
9362 nla_nest_end(msg, rekey_attr);
9363
3b7b72ee 9364 genlmsg_end(msg, hdr);
e5497d76
JB
9365
9366 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9367 nl80211_mlme_mcgrp.id, gfp);
9368 return;
9369
9370 nla_put_failure:
9371 genlmsg_cancel(msg, hdr);
9372 nlmsg_free(msg);
9373}
9374
c9df56b4
JM
9375void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
9376 struct net_device *netdev, int index,
9377 const u8 *bssid, bool preauth, gfp_t gfp)
9378{
9379 struct sk_buff *msg;
9380 struct nlattr *attr;
9381 void *hdr;
9382
58050fce 9383 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
9384 if (!msg)
9385 return;
9386
9387 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
9388 if (!hdr) {
9389 nlmsg_free(msg);
9390 return;
9391 }
9392
9360ffd1
DM
9393 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9394 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9395 goto nla_put_failure;
c9df56b4
JM
9396
9397 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
9398 if (!attr)
9399 goto nla_put_failure;
9400
9360ffd1
DM
9401 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
9402 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
9403 (preauth &&
9404 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
9405 goto nla_put_failure;
c9df56b4
JM
9406
9407 nla_nest_end(msg, attr);
9408
3b7b72ee 9409 genlmsg_end(msg, hdr);
c9df56b4
JM
9410
9411 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9412 nl80211_mlme_mcgrp.id, gfp);
9413 return;
9414
9415 nla_put_failure:
9416 genlmsg_cancel(msg, hdr);
9417 nlmsg_free(msg);
9418}
9419
5314526b 9420void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
683b6d3b
JB
9421 struct net_device *netdev,
9422 struct cfg80211_chan_def *chandef, gfp_t gfp)
5314526b
TP
9423{
9424 struct sk_buff *msg;
9425 void *hdr;
9426
58050fce 9427 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
9428 if (!msg)
9429 return;
9430
9431 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
9432 if (!hdr) {
9433 nlmsg_free(msg);
9434 return;
9435 }
9436
683b6d3b
JB
9437 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
9438 goto nla_put_failure;
9439
9440 if (nl80211_send_chandef(msg, chandef))
7eab0f64 9441 goto nla_put_failure;
5314526b
TP
9442
9443 genlmsg_end(msg, hdr);
9444
9445 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9446 nl80211_mlme_mcgrp.id, gfp);
9447 return;
9448
9449 nla_put_failure:
9450 genlmsg_cancel(msg, hdr);
9451 nlmsg_free(msg);
9452}
9453
84f10708
TP
9454void
9455nl80211_send_cqm_txe_notify(struct cfg80211_registered_device *rdev,
9456 struct net_device *netdev, const u8 *peer,
9457 u32 num_packets, u32 rate, u32 intvl, gfp_t gfp)
9458{
9459 struct sk_buff *msg;
9460 struct nlattr *pinfoattr;
9461 void *hdr;
9462
9463 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
9464 if (!msg)
9465 return;
9466
9467 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9468 if (!hdr) {
9469 nlmsg_free(msg);
9470 return;
9471 }
9472
9473 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9474 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9475 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9476 goto nla_put_failure;
9477
9478 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9479 if (!pinfoattr)
9480 goto nla_put_failure;
9481
9482 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
9483 goto nla_put_failure;
9484
9485 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
9486 goto nla_put_failure;
9487
9488 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
9489 goto nla_put_failure;
9490
9491 nla_nest_end(msg, pinfoattr);
9492
9493 genlmsg_end(msg, hdr);
9494
9495 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9496 nl80211_mlme_mcgrp.id, gfp);
9497 return;
9498
9499 nla_put_failure:
9500 genlmsg_cancel(msg, hdr);
9501 nlmsg_free(msg);
9502}
9503
c063dbf5
JB
9504void
9505nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
9506 struct net_device *netdev, const u8 *peer,
9507 u32 num_packets, gfp_t gfp)
9508{
9509 struct sk_buff *msg;
9510 struct nlattr *pinfoattr;
9511 void *hdr;
9512
58050fce 9513 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c063dbf5
JB
9514 if (!msg)
9515 return;
9516
9517 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
9518 if (!hdr) {
9519 nlmsg_free(msg);
9520 return;
9521 }
9522
9360ffd1
DM
9523 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9524 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
9525 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
9526 goto nla_put_failure;
c063dbf5
JB
9527
9528 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
9529 if (!pinfoattr)
9530 goto nla_put_failure;
9531
9360ffd1
DM
9532 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
9533 goto nla_put_failure;
c063dbf5
JB
9534
9535 nla_nest_end(msg, pinfoattr);
9536
3b7b72ee 9537 genlmsg_end(msg, hdr);
c063dbf5
JB
9538
9539 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9540 nl80211_mlme_mcgrp.id, gfp);
9541 return;
9542
9543 nla_put_failure:
9544 genlmsg_cancel(msg, hdr);
9545 nlmsg_free(msg);
9546}
9547
7f6cf311
JB
9548void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
9549 u64 cookie, bool acked, gfp_t gfp)
9550{
9551 struct wireless_dev *wdev = dev->ieee80211_ptr;
9552 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9553 struct sk_buff *msg;
9554 void *hdr;
9555 int err;
9556
4ee3e063
BL
9557 trace_cfg80211_probe_status(dev, addr, cookie, acked);
9558
58050fce 9559 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 9560
7f6cf311
JB
9561 if (!msg)
9562 return;
9563
9564 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
9565 if (!hdr) {
9566 nlmsg_free(msg);
9567 return;
9568 }
9569
9360ffd1
DM
9570 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9571 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9572 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9573 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
9574 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
9575 goto nla_put_failure;
7f6cf311
JB
9576
9577 err = genlmsg_end(msg, hdr);
9578 if (err < 0) {
9579 nlmsg_free(msg);
9580 return;
9581 }
9582
9583 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9584 nl80211_mlme_mcgrp.id, gfp);
9585 return;
9586
9587 nla_put_failure:
9588 genlmsg_cancel(msg, hdr);
9589 nlmsg_free(msg);
9590}
9591EXPORT_SYMBOL(cfg80211_probe_status);
9592
5e760230
JB
9593void cfg80211_report_obss_beacon(struct wiphy *wiphy,
9594 const u8 *frame, size_t len,
37c73b5f 9595 int freq, int sig_dbm)
5e760230
JB
9596{
9597 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
9598 struct sk_buff *msg;
9599 void *hdr;
37c73b5f 9600 struct cfg80211_beacon_registration *reg;
5e760230 9601
4ee3e063
BL
9602 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
9603
37c73b5f
BG
9604 spin_lock_bh(&rdev->beacon_registrations_lock);
9605 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
9606 msg = nlmsg_new(len + 100, GFP_ATOMIC);
9607 if (!msg) {
9608 spin_unlock_bh(&rdev->beacon_registrations_lock);
9609 return;
9610 }
5e760230 9611
37c73b5f
BG
9612 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
9613 if (!hdr)
9614 goto nla_put_failure;
5e760230 9615
37c73b5f
BG
9616 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9617 (freq &&
9618 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
9619 (sig_dbm &&
9620 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
9621 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
9622 goto nla_put_failure;
5e760230 9623
37c73b5f 9624 genlmsg_end(msg, hdr);
5e760230 9625
37c73b5f
BG
9626 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
9627 }
9628 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
9629 return;
9630
9631 nla_put_failure:
37c73b5f
BG
9632 spin_unlock_bh(&rdev->beacon_registrations_lock);
9633 if (hdr)
9634 genlmsg_cancel(msg, hdr);
5e760230
JB
9635 nlmsg_free(msg);
9636}
9637EXPORT_SYMBOL(cfg80211_report_obss_beacon);
9638
cd8f7cb4
JB
9639#ifdef CONFIG_PM
9640void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
9641 struct cfg80211_wowlan_wakeup *wakeup,
9642 gfp_t gfp)
9643{
9644 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9645 struct sk_buff *msg;
9646 void *hdr;
9647 int err, size = 200;
9648
9649 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
9650
9651 if (wakeup)
9652 size += wakeup->packet_present_len;
9653
9654 msg = nlmsg_new(size, gfp);
9655 if (!msg)
9656 return;
9657
9658 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
9659 if (!hdr)
9660 goto free_msg;
9661
9662 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9663 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id(wdev)))
9664 goto free_msg;
9665
9666 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
9667 wdev->netdev->ifindex))
9668 goto free_msg;
9669
9670 if (wakeup) {
9671 struct nlattr *reasons;
9672
9673 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
9674
9675 if (wakeup->disconnect &&
9676 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
9677 goto free_msg;
9678 if (wakeup->magic_pkt &&
9679 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
9680 goto free_msg;
9681 if (wakeup->gtk_rekey_failure &&
9682 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
9683 goto free_msg;
9684 if (wakeup->eap_identity_req &&
9685 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
9686 goto free_msg;
9687 if (wakeup->four_way_handshake &&
9688 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
9689 goto free_msg;
9690 if (wakeup->rfkill_release &&
9691 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
9692 goto free_msg;
9693
9694 if (wakeup->pattern_idx >= 0 &&
9695 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
9696 wakeup->pattern_idx))
9697 goto free_msg;
9698
2a0e047e
JB
9699 if (wakeup->tcp_match)
9700 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH);
9701
9702 if (wakeup->tcp_connlost)
9703 nla_put_flag(msg,
9704 NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST);
9705
9706 if (wakeup->tcp_nomoretokens)
9707 nla_put_flag(msg,
9708 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS);
9709
cd8f7cb4
JB
9710 if (wakeup->packet) {
9711 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
9712 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
9713
9714 if (!wakeup->packet_80211) {
9715 pkt_attr =
9716 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
9717 len_attr =
9718 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
9719 }
9720
9721 if (wakeup->packet_len &&
9722 nla_put_u32(msg, len_attr, wakeup->packet_len))
9723 goto free_msg;
9724
9725 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
9726 wakeup->packet))
9727 goto free_msg;
9728 }
9729
9730 nla_nest_end(msg, reasons);
9731 }
9732
9733 err = genlmsg_end(msg, hdr);
9734 if (err < 0)
9735 goto free_msg;
9736
9737 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9738 nl80211_mlme_mcgrp.id, gfp);
9739 return;
9740
9741 free_msg:
9742 nlmsg_free(msg);
9743}
9744EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
9745#endif
9746
3475b094
JM
9747void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
9748 enum nl80211_tdls_operation oper,
9749 u16 reason_code, gfp_t gfp)
9750{
9751 struct wireless_dev *wdev = dev->ieee80211_ptr;
9752 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
9753 struct sk_buff *msg;
9754 void *hdr;
9755 int err;
9756
9757 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
9758 reason_code);
9759
9760 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
9761 if (!msg)
9762 return;
9763
9764 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
9765 if (!hdr) {
9766 nlmsg_free(msg);
9767 return;
9768 }
9769
9770 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
9771 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
9772 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
9773 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
9774 (reason_code > 0 &&
9775 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
9776 goto nla_put_failure;
9777
9778 err = genlmsg_end(msg, hdr);
9779 if (err < 0) {
9780 nlmsg_free(msg);
9781 return;
9782 }
9783
9784 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
9785 nl80211_mlme_mcgrp.id, gfp);
9786 return;
9787
9788 nla_put_failure:
9789 genlmsg_cancel(msg, hdr);
9790 nlmsg_free(msg);
9791}
9792EXPORT_SYMBOL(cfg80211_tdls_oper_request);
9793
026331c4
JM
9794static int nl80211_netlink_notify(struct notifier_block * nb,
9795 unsigned long state,
9796 void *_notify)
9797{
9798 struct netlink_notify *notify = _notify;
9799 struct cfg80211_registered_device *rdev;
9800 struct wireless_dev *wdev;
37c73b5f 9801 struct cfg80211_beacon_registration *reg, *tmp;
026331c4
JM
9802
9803 if (state != NETLINK_URELEASE)
9804 return NOTIFY_DONE;
9805
9806 rcu_read_lock();
9807
5e760230 9808 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 9809 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
15e47304 9810 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f
BG
9811
9812 spin_lock_bh(&rdev->beacon_registrations_lock);
9813 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
9814 list) {
9815 if (reg->nlportid == notify->portid) {
9816 list_del(&reg->list);
9817 kfree(reg);
9818 break;
9819 }
9820 }
9821 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 9822 }
026331c4
JM
9823
9824 rcu_read_unlock();
9825
9826 return NOTIFY_DONE;
9827}
9828
9829static struct notifier_block nl80211_netlink_notifier = {
9830 .notifier_call = nl80211_netlink_notify,
9831};
9832
55682965
JB
9833/* initialisation/exit functions */
9834
9835int nl80211_init(void)
9836{
0d63cbb5 9837 int err;
55682965 9838
0d63cbb5
MM
9839 err = genl_register_family_with_ops(&nl80211_fam,
9840 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
9841 if (err)
9842 return err;
9843
55682965
JB
9844 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
9845 if (err)
9846 goto err_out;
9847
2a519311
JB
9848 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
9849 if (err)
9850 goto err_out;
9851
73d54c9e
LR
9852 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
9853 if (err)
9854 goto err_out;
9855
6039f6d2
JM
9856 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
9857 if (err)
9858 goto err_out;
9859
aff89a9b
JB
9860#ifdef CONFIG_NL80211_TESTMODE
9861 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
9862 if (err)
9863 goto err_out;
9864#endif
9865
026331c4
JM
9866 err = netlink_register_notifier(&nl80211_netlink_notifier);
9867 if (err)
9868 goto err_out;
9869
55682965
JB
9870 return 0;
9871 err_out:
9872 genl_unregister_family(&nl80211_fam);
9873 return err;
9874}
9875
9876void nl80211_exit(void)
9877{
026331c4 9878 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
9879 genl_unregister_family(&nl80211_fam);
9880}
This page took 1.419713 seconds and 5 git commands to generate.