cfg80211: Separate available antennas for RX and TX
[deliverable/linux.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
e31b8213 96 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
97
98 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101 .len = IEEE80211_MAX_DATA_LEN },
102 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
104 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 109 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 110 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 111 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
112 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113 .len = IEEE80211_MAX_MESH_ID_LEN },
114 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 115
b2e1b302
LR
116 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
9f1ba906
JM
119 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
122 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123 .len = NL80211_MAX_SUPP_RATES },
50b12f59 124 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 125
24bdd9f4 126 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
93da9cc1 127
36aedc90
JM
128 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
129 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
130
131 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
132 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
133 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
134 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
135 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
136
137 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
138 .len = IEEE80211_MAX_SSID_LEN },
139 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
140 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 141 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 142 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 143 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
144 [NL80211_ATTR_STA_FLAGS2] = {
145 .len = sizeof(struct nl80211_sta_flag_update),
146 },
3f77316c 147 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
148 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
149 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
150 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
151 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
152 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 153 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 154 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
155 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
156 .len = WLAN_PMKID_LEN },
9588bbd5
JM
157 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
158 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 159 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
160 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
161 .len = IEEE80211_MAX_DATA_LEN },
162 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 163 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 164 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 165 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 166 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
167 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
168 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 169 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
170 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
171 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 172 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 173 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 174 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
55682965
JB
175};
176
e31b8213 177/* policy for the key attributes */
b54452b0 178static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 179 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
180 [NL80211_KEY_IDX] = { .type = NLA_U8 },
181 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
182 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
183 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
184 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 185 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
186 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
187};
188
189/* policy for the key default flags */
190static const struct nla_policy
191nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
192 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
193 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
194};
195
a043897a
HS
196/* ifidx get helper */
197static int nl80211_get_ifidx(struct netlink_callback *cb)
198{
199 int res;
200
201 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
202 nl80211_fam.attrbuf, nl80211_fam.maxattr,
203 nl80211_policy);
204 if (res)
205 return res;
206
207 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
208 return -EINVAL;
209
210 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
211 if (!res)
212 return -EINVAL;
213 return res;
214}
215
67748893
JB
216static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
217 struct netlink_callback *cb,
218 struct cfg80211_registered_device **rdev,
219 struct net_device **dev)
220{
221 int ifidx = cb->args[0];
222 int err;
223
224 if (!ifidx)
225 ifidx = nl80211_get_ifidx(cb);
226 if (ifidx < 0)
227 return ifidx;
228
229 cb->args[0] = ifidx;
230
231 rtnl_lock();
232
233 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
234 if (!*dev) {
235 err = -ENODEV;
236 goto out_rtnl;
237 }
238
239 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
240 if (IS_ERR(*rdev)) {
241 err = PTR_ERR(*rdev);
67748893
JB
242 goto out_rtnl;
243 }
244
245 return 0;
246 out_rtnl:
247 rtnl_unlock();
248 return err;
249}
250
251static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
252{
253 cfg80211_unlock_rdev(rdev);
254 rtnl_unlock();
255}
256
f4a11bb0
JB
257/* IE validation */
258static bool is_valid_ie_attr(const struct nlattr *attr)
259{
260 const u8 *pos;
261 int len;
262
263 if (!attr)
264 return true;
265
266 pos = nla_data(attr);
267 len = nla_len(attr);
268
269 while (len) {
270 u8 elemlen;
271
272 if (len < 2)
273 return false;
274 len -= 2;
275
276 elemlen = pos[1];
277 if (elemlen > len)
278 return false;
279
280 len -= elemlen;
281 pos += 2 + elemlen;
282 }
283
284 return true;
285}
286
55682965
JB
287/* message building helper */
288static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
289 int flags, u8 cmd)
290{
291 /* since there is no private header just add the generic one */
292 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
293}
294
5dab3b8a
LR
295static int nl80211_msg_put_channel(struct sk_buff *msg,
296 struct ieee80211_channel *chan)
297{
298 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
299 chan->center_freq);
300
301 if (chan->flags & IEEE80211_CHAN_DISABLED)
302 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
303 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
304 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
305 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
306 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
307 if (chan->flags & IEEE80211_CHAN_RADAR)
308 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
309
310 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
311 DBM_TO_MBM(chan->max_power));
312
313 return 0;
314
315 nla_put_failure:
316 return -ENOBUFS;
317}
318
55682965
JB
319/* netlink command implementations */
320
b9454e83
JB
321struct key_parse {
322 struct key_params p;
323 int idx;
e31b8213 324 int type;
b9454e83 325 bool def, defmgmt;
dbd2fd65 326 bool def_uni, def_multi;
b9454e83
JB
327};
328
329static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
330{
331 struct nlattr *tb[NL80211_KEY_MAX + 1];
332 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
333 nl80211_key_policy);
334 if (err)
335 return err;
336
337 k->def = !!tb[NL80211_KEY_DEFAULT];
338 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
339
dbd2fd65
JB
340 if (k->def) {
341 k->def_uni = true;
342 k->def_multi = true;
343 }
344 if (k->defmgmt)
345 k->def_multi = true;
346
b9454e83
JB
347 if (tb[NL80211_KEY_IDX])
348 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
349
350 if (tb[NL80211_KEY_DATA]) {
351 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
352 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
353 }
354
355 if (tb[NL80211_KEY_SEQ]) {
356 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
357 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
358 }
359
360 if (tb[NL80211_KEY_CIPHER])
361 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
362
e31b8213
JB
363 if (tb[NL80211_KEY_TYPE]) {
364 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
365 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
366 return -EINVAL;
367 }
368
dbd2fd65
JB
369 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
370 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
371 int err = nla_parse_nested(kdt,
372 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
373 tb[NL80211_KEY_DEFAULT_TYPES],
374 nl80211_key_default_policy);
375 if (err)
376 return err;
377
378 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
379 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
380 }
381
b9454e83
JB
382 return 0;
383}
384
385static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
386{
387 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
388 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
389 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
390 }
391
392 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
393 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
394 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
395 }
396
397 if (info->attrs[NL80211_ATTR_KEY_IDX])
398 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
399
400 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
401 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
402
403 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
404 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
405
dbd2fd65
JB
406 if (k->def) {
407 k->def_uni = true;
408 k->def_multi = true;
409 }
410 if (k->defmgmt)
411 k->def_multi = true;
412
e31b8213
JB
413 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
414 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
415 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
416 return -EINVAL;
417 }
418
dbd2fd65
JB
419 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
420 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
421 int err = nla_parse_nested(
422 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
423 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
424 nl80211_key_default_policy);
425 if (err)
426 return err;
427
428 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
429 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
430 }
431
b9454e83
JB
432 return 0;
433}
434
435static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
436{
437 int err;
438
439 memset(k, 0, sizeof(*k));
440 k->idx = -1;
e31b8213 441 k->type = -1;
b9454e83
JB
442
443 if (info->attrs[NL80211_ATTR_KEY])
444 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
445 else
446 err = nl80211_parse_key_old(info, k);
447
448 if (err)
449 return err;
450
451 if (k->def && k->defmgmt)
452 return -EINVAL;
453
dbd2fd65
JB
454 if (k->defmgmt) {
455 if (k->def_uni || !k->def_multi)
456 return -EINVAL;
457 }
458
b9454e83
JB
459 if (k->idx != -1) {
460 if (k->defmgmt) {
461 if (k->idx < 4 || k->idx > 5)
462 return -EINVAL;
463 } else if (k->def) {
464 if (k->idx < 0 || k->idx > 3)
465 return -EINVAL;
466 } else {
467 if (k->idx < 0 || k->idx > 5)
468 return -EINVAL;
469 }
470 }
471
472 return 0;
473}
474
fffd0934
JB
475static struct cfg80211_cached_keys *
476nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
477 struct nlattr *keys)
478{
479 struct key_parse parse;
480 struct nlattr *key;
481 struct cfg80211_cached_keys *result;
482 int rem, err, def = 0;
483
484 result = kzalloc(sizeof(*result), GFP_KERNEL);
485 if (!result)
486 return ERR_PTR(-ENOMEM);
487
488 result->def = -1;
489 result->defmgmt = -1;
490
491 nla_for_each_nested(key, keys, rem) {
492 memset(&parse, 0, sizeof(parse));
493 parse.idx = -1;
494
495 err = nl80211_parse_key_new(key, &parse);
496 if (err)
497 goto error;
498 err = -EINVAL;
499 if (!parse.p.key)
500 goto error;
501 if (parse.idx < 0 || parse.idx > 4)
502 goto error;
503 if (parse.def) {
504 if (def)
505 goto error;
506 def = 1;
507 result->def = parse.idx;
dbd2fd65
JB
508 if (!parse.def_uni || !parse.def_multi)
509 goto error;
fffd0934
JB
510 } else if (parse.defmgmt)
511 goto error;
512 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 513 parse.idx, false, NULL);
fffd0934
JB
514 if (err)
515 goto error;
516 result->params[parse.idx].cipher = parse.p.cipher;
517 result->params[parse.idx].key_len = parse.p.key_len;
518 result->params[parse.idx].key = result->data[parse.idx];
519 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
520 }
521
522 return result;
523 error:
524 kfree(result);
525 return ERR_PTR(err);
526}
527
528static int nl80211_key_allowed(struct wireless_dev *wdev)
529{
530 ASSERT_WDEV_LOCK(wdev);
531
fffd0934
JB
532 switch (wdev->iftype) {
533 case NL80211_IFTYPE_AP:
534 case NL80211_IFTYPE_AP_VLAN:
074ac8df 535 case NL80211_IFTYPE_P2P_GO:
fffd0934
JB
536 break;
537 case NL80211_IFTYPE_ADHOC:
538 if (!wdev->current_bss)
539 return -ENOLINK;
540 break;
541 case NL80211_IFTYPE_STATION:
074ac8df 542 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
543 if (wdev->sme_state != CFG80211_SME_CONNECTED)
544 return -ENOLINK;
545 break;
546 default:
547 return -EINVAL;
548 }
549
550 return 0;
551}
552
55682965
JB
553static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
554 struct cfg80211_registered_device *dev)
555{
556 void *hdr;
ee688b00
JB
557 struct nlattr *nl_bands, *nl_band;
558 struct nlattr *nl_freqs, *nl_freq;
559 struct nlattr *nl_rates, *nl_rate;
f59ac048 560 struct nlattr *nl_modes;
8fdc621d 561 struct nlattr *nl_cmds;
ee688b00
JB
562 enum ieee80211_band band;
563 struct ieee80211_channel *chan;
564 struct ieee80211_rate *rate;
565 int i;
f59ac048 566 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
567 const struct ieee80211_txrx_stypes *mgmt_stypes =
568 dev->wiphy.mgmt_stypes;
55682965
JB
569
570 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
571 if (!hdr)
572 return -1;
573
b5850a7a 574 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 575 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 576
f5ea9120
JB
577 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
578 cfg80211_rdev_list_generation);
579
b9a5f8ca
JM
580 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
581 dev->wiphy.retry_short);
582 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
583 dev->wiphy.retry_long);
584 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
585 dev->wiphy.frag_threshold);
586 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
587 dev->wiphy.rts_threshold);
81077e82
LT
588 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
589 dev->wiphy.coverage_class);
2a519311
JB
590 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
591 dev->wiphy.max_scan_ssids);
18a83659
JB
592 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
593 dev->wiphy.max_scan_ie_len);
ee688b00 594
e31b8213
JB
595 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
596 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
597
25e47c18
JB
598 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
599 sizeof(u32) * dev->wiphy.n_cipher_suites,
600 dev->wiphy.cipher_suites);
601
67fbb16b
SO
602 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
603 dev->wiphy.max_num_pmkids);
604
c0692b8f
JB
605 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
606 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
607
7f531e03
BR
608 if ((dev->wiphy.available_antennas_tx ||
609 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
610 u32 tx_ant = 0, rx_ant = 0;
611 int res;
612 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
613 if (!res) {
614 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
615 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
616 }
617 }
618
f59ac048
LR
619 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
620 if (!nl_modes)
621 goto nla_put_failure;
622
623 i = 0;
624 while (ifmodes) {
625 if (ifmodes & 1)
626 NLA_PUT_FLAG(msg, i);
627 ifmodes >>= 1;
628 i++;
629 }
630
631 nla_nest_end(msg, nl_modes);
632
ee688b00
JB
633 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
634 if (!nl_bands)
635 goto nla_put_failure;
636
637 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
638 if (!dev->wiphy.bands[band])
639 continue;
640
641 nl_band = nla_nest_start(msg, band);
642 if (!nl_band)
643 goto nla_put_failure;
644
d51626df
JB
645 /* add HT info */
646 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
647 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
648 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
649 &dev->wiphy.bands[band]->ht_cap.mcs);
650 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
651 dev->wiphy.bands[band]->ht_cap.cap);
652 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
653 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
654 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
655 dev->wiphy.bands[band]->ht_cap.ampdu_density);
656 }
657
ee688b00
JB
658 /* add frequencies */
659 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
660 if (!nl_freqs)
661 goto nla_put_failure;
662
663 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
664 nl_freq = nla_nest_start(msg, i);
665 if (!nl_freq)
666 goto nla_put_failure;
667
668 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
669
670 if (nl80211_msg_put_channel(msg, chan))
671 goto nla_put_failure;
e2f367f2 672
ee688b00
JB
673 nla_nest_end(msg, nl_freq);
674 }
675
676 nla_nest_end(msg, nl_freqs);
677
678 /* add bitrates */
679 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
680 if (!nl_rates)
681 goto nla_put_failure;
682
683 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
684 nl_rate = nla_nest_start(msg, i);
685 if (!nl_rate)
686 goto nla_put_failure;
687
688 rate = &dev->wiphy.bands[band]->bitrates[i];
689 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
690 rate->bitrate);
691 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
692 NLA_PUT_FLAG(msg,
693 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
694
695 nla_nest_end(msg, nl_rate);
696 }
697
698 nla_nest_end(msg, nl_rates);
699
700 nla_nest_end(msg, nl_band);
701 }
702 nla_nest_end(msg, nl_bands);
703
8fdc621d
JB
704 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
705 if (!nl_cmds)
706 goto nla_put_failure;
707
708 i = 0;
709#define CMD(op, n) \
710 do { \
711 if (dev->ops->op) { \
712 i++; \
713 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
714 } \
715 } while (0)
716
717 CMD(add_virtual_intf, NEW_INTERFACE);
718 CMD(change_virtual_intf, SET_INTERFACE);
719 CMD(add_key, NEW_KEY);
720 CMD(add_beacon, NEW_BEACON);
721 CMD(add_station, NEW_STATION);
722 CMD(add_mpath, NEW_MPATH);
24bdd9f4 723 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 724 CMD(change_bss, SET_BSS);
636a5d36
JM
725 CMD(auth, AUTHENTICATE);
726 CMD(assoc, ASSOCIATE);
727 CMD(deauth, DEAUTHENTICATE);
728 CMD(disassoc, DISASSOCIATE);
04a773ad 729 CMD(join_ibss, JOIN_IBSS);
29cbe68c 730 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
731 CMD(set_pmksa, SET_PMKSA);
732 CMD(del_pmksa, DEL_PMKSA);
733 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 734 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 735 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 736 CMD(mgmt_tx, FRAME);
f7ca38df 737 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 738 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
739 i++;
740 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
741 }
f444de05 742 CMD(set_channel, SET_CHANNEL);
e8347eba 743 CMD(set_wds_peer, SET_WDS_PEER);
8fdc621d
JB
744
745#undef CMD
b23aa676 746
6829c878 747 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
748 i++;
749 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
750 }
751
6829c878 752 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
753 i++;
754 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
755 }
756
8fdc621d
JB
757 nla_nest_end(msg, nl_cmds);
758
a293911d
JB
759 if (dev->ops->remain_on_channel)
760 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
761 dev->wiphy.max_remain_on_channel_duration);
762
f7ca38df
JB
763 /* for now at least assume all drivers have it */
764 if (dev->ops->mgmt_tx)
765 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
766
2e161f78
JB
767 if (mgmt_stypes) {
768 u16 stypes;
769 struct nlattr *nl_ftypes, *nl_ifs;
770 enum nl80211_iftype ift;
771
772 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
773 if (!nl_ifs)
774 goto nla_put_failure;
775
776 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
777 nl_ftypes = nla_nest_start(msg, ift);
778 if (!nl_ftypes)
779 goto nla_put_failure;
780 i = 0;
781 stypes = mgmt_stypes[ift].tx;
782 while (stypes) {
783 if (stypes & 1)
784 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
785 (i << 4) | IEEE80211_FTYPE_MGMT);
786 stypes >>= 1;
787 i++;
788 }
789 nla_nest_end(msg, nl_ftypes);
790 }
791
74b70a4e
JB
792 nla_nest_end(msg, nl_ifs);
793
2e161f78
JB
794 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
795 if (!nl_ifs)
796 goto nla_put_failure;
797
798 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
799 nl_ftypes = nla_nest_start(msg, ift);
800 if (!nl_ftypes)
801 goto nla_put_failure;
802 i = 0;
803 stypes = mgmt_stypes[ift].rx;
804 while (stypes) {
805 if (stypes & 1)
806 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
807 (i << 4) | IEEE80211_FTYPE_MGMT);
808 stypes >>= 1;
809 i++;
810 }
811 nla_nest_end(msg, nl_ftypes);
812 }
813 nla_nest_end(msg, nl_ifs);
814 }
815
55682965
JB
816 return genlmsg_end(msg, hdr);
817
818 nla_put_failure:
bc3ed28c
TG
819 genlmsg_cancel(msg, hdr);
820 return -EMSGSIZE;
55682965
JB
821}
822
823static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
824{
825 int idx = 0;
826 int start = cb->args[0];
827 struct cfg80211_registered_device *dev;
828
a1794390 829 mutex_lock(&cfg80211_mutex);
79c97e97 830 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
831 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
832 continue;
b4637271 833 if (++idx <= start)
55682965
JB
834 continue;
835 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
836 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
837 dev) < 0) {
838 idx--;
55682965 839 break;
b4637271 840 }
55682965 841 }
a1794390 842 mutex_unlock(&cfg80211_mutex);
55682965
JB
843
844 cb->args[0] = idx;
845
846 return skb->len;
847}
848
849static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
850{
851 struct sk_buff *msg;
4c476991 852 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 853
fd2120ca 854 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 855 if (!msg)
4c476991 856 return -ENOMEM;
55682965 857
4c476991
JB
858 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
859 nlmsg_free(msg);
860 return -ENOBUFS;
861 }
55682965 862
134e6375 863 return genlmsg_reply(msg, info);
55682965
JB
864}
865
31888487
JM
866static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
867 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
868 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
869 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
870 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
871 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
872};
873
874static int parse_txq_params(struct nlattr *tb[],
875 struct ieee80211_txq_params *txq_params)
876{
877 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
878 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
879 !tb[NL80211_TXQ_ATTR_AIFS])
880 return -EINVAL;
881
882 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
883 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
884 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
885 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
886 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
887
888 return 0;
889}
890
f444de05
JB
891static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
892{
893 /*
894 * You can only set the channel explicitly for AP, mesh
895 * and WDS type interfaces; all others have their channel
896 * managed via their respective "establish a connection"
897 * command (connect, join, ...)
898 *
899 * Monitors are special as they are normally slaved to
900 * whatever else is going on, so they behave as though
901 * you tried setting the wiphy channel itself.
902 */
903 return !wdev ||
904 wdev->iftype == NL80211_IFTYPE_AP ||
905 wdev->iftype == NL80211_IFTYPE_WDS ||
906 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
907 wdev->iftype == NL80211_IFTYPE_MONITOR ||
908 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
909}
910
911static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
912 struct wireless_dev *wdev,
913 struct genl_info *info)
914{
915 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
916 u32 freq;
917 int result;
918
919 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
920 return -EINVAL;
921
922 if (!nl80211_can_set_dev_channel(wdev))
923 return -EOPNOTSUPP;
924
925 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
926 channel_type = nla_get_u32(info->attrs[
927 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
928 if (channel_type != NL80211_CHAN_NO_HT &&
929 channel_type != NL80211_CHAN_HT20 &&
930 channel_type != NL80211_CHAN_HT40PLUS &&
931 channel_type != NL80211_CHAN_HT40MINUS)
932 return -EINVAL;
933 }
934
935 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
936
937 mutex_lock(&rdev->devlist_mtx);
938 if (wdev) {
939 wdev_lock(wdev);
940 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
941 wdev_unlock(wdev);
942 } else {
943 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
944 }
945 mutex_unlock(&rdev->devlist_mtx);
946
947 return result;
948}
949
950static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
951{
4c476991
JB
952 struct cfg80211_registered_device *rdev = info->user_ptr[0];
953 struct net_device *netdev = info->user_ptr[1];
f444de05 954
4c476991 955 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
956}
957
e8347eba
BJ
958static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
959{
43b19952
JB
960 struct cfg80211_registered_device *rdev = info->user_ptr[0];
961 struct net_device *dev = info->user_ptr[1];
962 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 963 const u8 *bssid;
e8347eba
BJ
964
965 if (!info->attrs[NL80211_ATTR_MAC])
966 return -EINVAL;
967
43b19952
JB
968 if (netif_running(dev))
969 return -EBUSY;
e8347eba 970
43b19952
JB
971 if (!rdev->ops->set_wds_peer)
972 return -EOPNOTSUPP;
e8347eba 973
43b19952
JB
974 if (wdev->iftype != NL80211_IFTYPE_WDS)
975 return -EOPNOTSUPP;
e8347eba
BJ
976
977 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 978 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
979}
980
981
55682965
JB
982static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
983{
984 struct cfg80211_registered_device *rdev;
f444de05
JB
985 struct net_device *netdev = NULL;
986 struct wireless_dev *wdev;
a1e567c8 987 int result = 0, rem_txq_params = 0;
31888487 988 struct nlattr *nl_txq_params;
b9a5f8ca
JM
989 u32 changed;
990 u8 retry_short = 0, retry_long = 0;
991 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 992 u8 coverage_class = 0;
55682965 993
f444de05
JB
994 /*
995 * Try to find the wiphy and netdev. Normally this
996 * function shouldn't need the netdev, but this is
997 * done for backward compatibility -- previously
998 * setting the channel was done per wiphy, but now
999 * it is per netdev. Previous userland like hostapd
1000 * also passed a netdev to set_wiphy, so that it is
1001 * possible to let that go to the right netdev!
1002 */
4bbf4d56
JB
1003 mutex_lock(&cfg80211_mutex);
1004
f444de05
JB
1005 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1006 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1007
1008 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1009 if (netdev && netdev->ieee80211_ptr) {
1010 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1011 mutex_lock(&rdev->mtx);
1012 } else
1013 netdev = NULL;
4bbf4d56
JB
1014 }
1015
f444de05
JB
1016 if (!netdev) {
1017 rdev = __cfg80211_rdev_from_info(info);
1018 if (IS_ERR(rdev)) {
1019 mutex_unlock(&cfg80211_mutex);
4c476991 1020 return PTR_ERR(rdev);
f444de05
JB
1021 }
1022 wdev = NULL;
1023 netdev = NULL;
1024 result = 0;
1025
1026 mutex_lock(&rdev->mtx);
1027 } else if (netif_running(netdev) &&
1028 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1029 wdev = netdev->ieee80211_ptr;
1030 else
1031 wdev = NULL;
1032
1033 /*
1034 * end workaround code, by now the rdev is available
1035 * and locked, and wdev may or may not be NULL.
1036 */
4bbf4d56
JB
1037
1038 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1039 result = cfg80211_dev_rename(
1040 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1041
1042 mutex_unlock(&cfg80211_mutex);
1043
1044 if (result)
1045 goto bad_res;
31888487
JM
1046
1047 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1048 struct ieee80211_txq_params txq_params;
1049 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1050
1051 if (!rdev->ops->set_txq_params) {
1052 result = -EOPNOTSUPP;
1053 goto bad_res;
1054 }
1055
1056 nla_for_each_nested(nl_txq_params,
1057 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1058 rem_txq_params) {
1059 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1060 nla_data(nl_txq_params),
1061 nla_len(nl_txq_params),
1062 txq_params_policy);
1063 result = parse_txq_params(tb, &txq_params);
1064 if (result)
1065 goto bad_res;
1066
1067 result = rdev->ops->set_txq_params(&rdev->wiphy,
1068 &txq_params);
1069 if (result)
1070 goto bad_res;
1071 }
1072 }
55682965 1073
72bdcf34 1074 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1075 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1076 if (result)
1077 goto bad_res;
1078 }
1079
98d2ff8b
JO
1080 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1081 enum nl80211_tx_power_setting type;
1082 int idx, mbm = 0;
1083
1084 if (!rdev->ops->set_tx_power) {
60ea385f 1085 result = -EOPNOTSUPP;
98d2ff8b
JO
1086 goto bad_res;
1087 }
1088
1089 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1090 type = nla_get_u32(info->attrs[idx]);
1091
1092 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1093 (type != NL80211_TX_POWER_AUTOMATIC)) {
1094 result = -EINVAL;
1095 goto bad_res;
1096 }
1097
1098 if (type != NL80211_TX_POWER_AUTOMATIC) {
1099 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1100 mbm = nla_get_u32(info->attrs[idx]);
1101 }
1102
1103 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1104 if (result)
1105 goto bad_res;
1106 }
1107
afe0cbf8
BR
1108 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1109 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1110 u32 tx_ant, rx_ant;
7f531e03
BR
1111 if ((!rdev->wiphy.available_antennas_tx &&
1112 !rdev->wiphy.available_antennas_rx) ||
1113 !rdev->ops->set_antenna) {
afe0cbf8
BR
1114 result = -EOPNOTSUPP;
1115 goto bad_res;
1116 }
1117
1118 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1119 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1120
a7ffac95 1121 /* reject antenna configurations which don't match the
7f531e03
BR
1122 * available antenna masks, except for the "all" mask */
1123 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1124 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1125 result = -EINVAL;
1126 goto bad_res;
1127 }
1128
7f531e03
BR
1129 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1130 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1131
afe0cbf8
BR
1132 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1133 if (result)
1134 goto bad_res;
1135 }
1136
b9a5f8ca
JM
1137 changed = 0;
1138
1139 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1140 retry_short = nla_get_u8(
1141 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1142 if (retry_short == 0) {
1143 result = -EINVAL;
1144 goto bad_res;
1145 }
1146 changed |= WIPHY_PARAM_RETRY_SHORT;
1147 }
1148
1149 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1150 retry_long = nla_get_u8(
1151 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1152 if (retry_long == 0) {
1153 result = -EINVAL;
1154 goto bad_res;
1155 }
1156 changed |= WIPHY_PARAM_RETRY_LONG;
1157 }
1158
1159 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1160 frag_threshold = nla_get_u32(
1161 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1162 if (frag_threshold < 256) {
1163 result = -EINVAL;
1164 goto bad_res;
1165 }
1166 if (frag_threshold != (u32) -1) {
1167 /*
1168 * Fragments (apart from the last one) are required to
1169 * have even length. Make the fragmentation code
1170 * simpler by stripping LSB should someone try to use
1171 * odd threshold value.
1172 */
1173 frag_threshold &= ~0x1;
1174 }
1175 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1176 }
1177
1178 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1179 rts_threshold = nla_get_u32(
1180 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1181 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1182 }
1183
81077e82
LT
1184 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1185 coverage_class = nla_get_u8(
1186 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1187 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1188 }
1189
b9a5f8ca
JM
1190 if (changed) {
1191 u8 old_retry_short, old_retry_long;
1192 u32 old_frag_threshold, old_rts_threshold;
81077e82 1193 u8 old_coverage_class;
b9a5f8ca
JM
1194
1195 if (!rdev->ops->set_wiphy_params) {
1196 result = -EOPNOTSUPP;
1197 goto bad_res;
1198 }
1199
1200 old_retry_short = rdev->wiphy.retry_short;
1201 old_retry_long = rdev->wiphy.retry_long;
1202 old_frag_threshold = rdev->wiphy.frag_threshold;
1203 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1204 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1205
1206 if (changed & WIPHY_PARAM_RETRY_SHORT)
1207 rdev->wiphy.retry_short = retry_short;
1208 if (changed & WIPHY_PARAM_RETRY_LONG)
1209 rdev->wiphy.retry_long = retry_long;
1210 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1211 rdev->wiphy.frag_threshold = frag_threshold;
1212 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1213 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1214 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1215 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1216
1217 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1218 if (result) {
1219 rdev->wiphy.retry_short = old_retry_short;
1220 rdev->wiphy.retry_long = old_retry_long;
1221 rdev->wiphy.frag_threshold = old_frag_threshold;
1222 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1223 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1224 }
1225 }
72bdcf34 1226
306d6112 1227 bad_res:
4bbf4d56 1228 mutex_unlock(&rdev->mtx);
f444de05
JB
1229 if (netdev)
1230 dev_put(netdev);
55682965
JB
1231 return result;
1232}
1233
1234
1235static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1236 struct cfg80211_registered_device *rdev,
55682965
JB
1237 struct net_device *dev)
1238{
1239 void *hdr;
1240
1241 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1242 if (!hdr)
1243 return -1;
1244
1245 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1246 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1247 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1248 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1249
1250 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1251 rdev->devlist_generation ^
1252 (cfg80211_rdev_list_generation << 2));
1253
55682965
JB
1254 return genlmsg_end(msg, hdr);
1255
1256 nla_put_failure:
bc3ed28c
TG
1257 genlmsg_cancel(msg, hdr);
1258 return -EMSGSIZE;
55682965
JB
1259}
1260
1261static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1262{
1263 int wp_idx = 0;
1264 int if_idx = 0;
1265 int wp_start = cb->args[0];
1266 int if_start = cb->args[1];
f5ea9120 1267 struct cfg80211_registered_device *rdev;
55682965
JB
1268 struct wireless_dev *wdev;
1269
a1794390 1270 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1271 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1272 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1273 continue;
bba95fef
JB
1274 if (wp_idx < wp_start) {
1275 wp_idx++;
55682965 1276 continue;
bba95fef 1277 }
55682965
JB
1278 if_idx = 0;
1279
f5ea9120
JB
1280 mutex_lock(&rdev->devlist_mtx);
1281 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1282 if (if_idx < if_start) {
1283 if_idx++;
55682965 1284 continue;
bba95fef 1285 }
55682965
JB
1286 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1287 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1288 rdev, wdev->netdev) < 0) {
1289 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1290 goto out;
1291 }
1292 if_idx++;
55682965 1293 }
f5ea9120 1294 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1295
1296 wp_idx++;
55682965 1297 }
bba95fef 1298 out:
a1794390 1299 mutex_unlock(&cfg80211_mutex);
55682965
JB
1300
1301 cb->args[0] = wp_idx;
1302 cb->args[1] = if_idx;
1303
1304 return skb->len;
1305}
1306
1307static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1308{
1309 struct sk_buff *msg;
4c476991
JB
1310 struct cfg80211_registered_device *dev = info->user_ptr[0];
1311 struct net_device *netdev = info->user_ptr[1];
55682965 1312
fd2120ca 1313 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1314 if (!msg)
4c476991 1315 return -ENOMEM;
55682965 1316
d726405a 1317 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1318 dev, netdev) < 0) {
1319 nlmsg_free(msg);
1320 return -ENOBUFS;
1321 }
55682965 1322
134e6375 1323 return genlmsg_reply(msg, info);
55682965
JB
1324}
1325
66f7ac50
MW
1326static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1327 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1328 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1329 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1330 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1331 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1332};
1333
1334static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1335{
1336 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1337 int flag;
1338
1339 *mntrflags = 0;
1340
1341 if (!nla)
1342 return -EINVAL;
1343
1344 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1345 nla, mntr_flags_policy))
1346 return -EINVAL;
1347
1348 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1349 if (flags[flag])
1350 *mntrflags |= (1<<flag);
1351
1352 return 0;
1353}
1354
9bc383de 1355static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1356 struct net_device *netdev, u8 use_4addr,
1357 enum nl80211_iftype iftype)
9bc383de 1358{
ad4bb6f8 1359 if (!use_4addr) {
f350a0a8 1360 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1361 return -EBUSY;
9bc383de 1362 return 0;
ad4bb6f8 1363 }
9bc383de
JB
1364
1365 switch (iftype) {
1366 case NL80211_IFTYPE_AP_VLAN:
1367 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1368 return 0;
1369 break;
1370 case NL80211_IFTYPE_STATION:
1371 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1372 return 0;
1373 break;
1374 default:
1375 break;
1376 }
1377
1378 return -EOPNOTSUPP;
1379}
1380
55682965
JB
1381static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1382{
4c476991 1383 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1384 struct vif_params params;
e36d56b6 1385 int err;
04a773ad 1386 enum nl80211_iftype otype, ntype;
4c476991 1387 struct net_device *dev = info->user_ptr[1];
92ffe055 1388 u32 _flags, *flags = NULL;
ac7f9cfa 1389 bool change = false;
55682965 1390
2ec600d6
LCC
1391 memset(&params, 0, sizeof(params));
1392
04a773ad 1393 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1394
723b038d 1395 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1396 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1397 if (otype != ntype)
ac7f9cfa 1398 change = true;
4c476991
JB
1399 if (ntype > NL80211_IFTYPE_MAX)
1400 return -EINVAL;
723b038d
JB
1401 }
1402
92ffe055 1403 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1404 struct wireless_dev *wdev = dev->ieee80211_ptr;
1405
4c476991
JB
1406 if (ntype != NL80211_IFTYPE_MESH_POINT)
1407 return -EINVAL;
29cbe68c
JB
1408 if (netif_running(dev))
1409 return -EBUSY;
1410
1411 wdev_lock(wdev);
1412 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1413 IEEE80211_MAX_MESH_ID_LEN);
1414 wdev->mesh_id_up_len =
1415 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1416 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1417 wdev->mesh_id_up_len);
1418 wdev_unlock(wdev);
2ec600d6
LCC
1419 }
1420
8b787643
FF
1421 if (info->attrs[NL80211_ATTR_4ADDR]) {
1422 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1423 change = true;
ad4bb6f8 1424 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1425 if (err)
4c476991 1426 return err;
8b787643
FF
1427 } else {
1428 params.use_4addr = -1;
1429 }
1430
92ffe055 1431 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1432 if (ntype != NL80211_IFTYPE_MONITOR)
1433 return -EINVAL;
92ffe055
JB
1434 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1435 &_flags);
ac7f9cfa 1436 if (err)
4c476991 1437 return err;
ac7f9cfa
JB
1438
1439 flags = &_flags;
1440 change = true;
92ffe055 1441 }
3b85875a 1442
ac7f9cfa 1443 if (change)
3d54d255 1444 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1445 else
1446 err = 0;
60719ffd 1447
9bc383de
JB
1448 if (!err && params.use_4addr != -1)
1449 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1450
55682965
JB
1451 return err;
1452}
1453
1454static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1455{
4c476991 1456 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1457 struct vif_params params;
f9e10ce4 1458 struct net_device *dev;
55682965
JB
1459 int err;
1460 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1461 u32 flags;
55682965 1462
2ec600d6
LCC
1463 memset(&params, 0, sizeof(params));
1464
55682965
JB
1465 if (!info->attrs[NL80211_ATTR_IFNAME])
1466 return -EINVAL;
1467
1468 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1469 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1470 if (type > NL80211_IFTYPE_MAX)
1471 return -EINVAL;
1472 }
1473
79c97e97 1474 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1475 !(rdev->wiphy.interface_modes & (1 << type)))
1476 return -EOPNOTSUPP;
55682965 1477
9bc383de 1478 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1479 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1480 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1481 if (err)
4c476991 1482 return err;
9bc383de 1483 }
8b787643 1484
66f7ac50
MW
1485 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1486 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1487 &flags);
f9e10ce4 1488 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1489 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1490 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1491 if (IS_ERR(dev))
1492 return PTR_ERR(dev);
2ec600d6 1493
29cbe68c
JB
1494 if (type == NL80211_IFTYPE_MESH_POINT &&
1495 info->attrs[NL80211_ATTR_MESH_ID]) {
1496 struct wireless_dev *wdev = dev->ieee80211_ptr;
1497
1498 wdev_lock(wdev);
1499 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1500 IEEE80211_MAX_MESH_ID_LEN);
1501 wdev->mesh_id_up_len =
1502 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1503 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1504 wdev->mesh_id_up_len);
1505 wdev_unlock(wdev);
1506 }
1507
f9e10ce4 1508 return 0;
55682965
JB
1509}
1510
1511static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1512{
4c476991
JB
1513 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1514 struct net_device *dev = info->user_ptr[1];
55682965 1515
4c476991
JB
1516 if (!rdev->ops->del_virtual_intf)
1517 return -EOPNOTSUPP;
55682965 1518
4c476991 1519 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1520}
1521
41ade00f
JB
1522struct get_key_cookie {
1523 struct sk_buff *msg;
1524 int error;
b9454e83 1525 int idx;
41ade00f
JB
1526};
1527
1528static void get_key_callback(void *c, struct key_params *params)
1529{
b9454e83 1530 struct nlattr *key;
41ade00f
JB
1531 struct get_key_cookie *cookie = c;
1532
1533 if (params->key)
1534 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1535 params->key_len, params->key);
1536
1537 if (params->seq)
1538 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1539 params->seq_len, params->seq);
1540
1541 if (params->cipher)
1542 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1543 params->cipher);
1544
b9454e83
JB
1545 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1546 if (!key)
1547 goto nla_put_failure;
1548
1549 if (params->key)
1550 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1551 params->key_len, params->key);
1552
1553 if (params->seq)
1554 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1555 params->seq_len, params->seq);
1556
1557 if (params->cipher)
1558 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1559 params->cipher);
1560
1561 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1562
1563 nla_nest_end(cookie->msg, key);
1564
41ade00f
JB
1565 return;
1566 nla_put_failure:
1567 cookie->error = 1;
1568}
1569
1570static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1571{
4c476991 1572 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1573 int err;
4c476991 1574 struct net_device *dev = info->user_ptr[1];
41ade00f 1575 u8 key_idx = 0;
e31b8213
JB
1576 const u8 *mac_addr = NULL;
1577 bool pairwise;
41ade00f
JB
1578 struct get_key_cookie cookie = {
1579 .error = 0,
1580 };
1581 void *hdr;
1582 struct sk_buff *msg;
1583
1584 if (info->attrs[NL80211_ATTR_KEY_IDX])
1585 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1586
3cfcf6ac 1587 if (key_idx > 5)
41ade00f
JB
1588 return -EINVAL;
1589
1590 if (info->attrs[NL80211_ATTR_MAC])
1591 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1592
e31b8213
JB
1593 pairwise = !!mac_addr;
1594 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1595 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1596 if (kt >= NUM_NL80211_KEYTYPES)
1597 return -EINVAL;
1598 if (kt != NL80211_KEYTYPE_GROUP &&
1599 kt != NL80211_KEYTYPE_PAIRWISE)
1600 return -EINVAL;
1601 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1602 }
1603
4c476991
JB
1604 if (!rdev->ops->get_key)
1605 return -EOPNOTSUPP;
41ade00f 1606
fd2120ca 1607 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1608 if (!msg)
1609 return -ENOMEM;
41ade00f
JB
1610
1611 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1612 NL80211_CMD_NEW_KEY);
4c476991
JB
1613 if (IS_ERR(hdr))
1614 return PTR_ERR(hdr);
41ade00f
JB
1615
1616 cookie.msg = msg;
b9454e83 1617 cookie.idx = key_idx;
41ade00f
JB
1618
1619 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1620 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1621 if (mac_addr)
1622 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1623
e31b8213
JB
1624 if (pairwise && mac_addr &&
1625 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1626 return -ENOENT;
1627
1628 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1629 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1630
1631 if (err)
6c95e2a2 1632 goto free_msg;
41ade00f
JB
1633
1634 if (cookie.error)
1635 goto nla_put_failure;
1636
1637 genlmsg_end(msg, hdr);
4c476991 1638 return genlmsg_reply(msg, info);
41ade00f
JB
1639
1640 nla_put_failure:
1641 err = -ENOBUFS;
6c95e2a2 1642 free_msg:
41ade00f 1643 nlmsg_free(msg);
41ade00f
JB
1644 return err;
1645}
1646
1647static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1648{
4c476991 1649 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1650 struct key_parse key;
41ade00f 1651 int err;
4c476991 1652 struct net_device *dev = info->user_ptr[1];
41ade00f 1653
b9454e83
JB
1654 err = nl80211_parse_key(info, &key);
1655 if (err)
1656 return err;
41ade00f 1657
b9454e83 1658 if (key.idx < 0)
41ade00f
JB
1659 return -EINVAL;
1660
b9454e83
JB
1661 /* only support setting default key */
1662 if (!key.def && !key.defmgmt)
41ade00f
JB
1663 return -EINVAL;
1664
dbd2fd65 1665 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1666
dbd2fd65
JB
1667 if (key.def) {
1668 if (!rdev->ops->set_default_key) {
1669 err = -EOPNOTSUPP;
1670 goto out;
1671 }
41ade00f 1672
dbd2fd65
JB
1673 err = nl80211_key_allowed(dev->ieee80211_ptr);
1674 if (err)
1675 goto out;
1676
1677 if (!(rdev->wiphy.flags &
1678 WIPHY_FLAG_SUPPORTS_SEPARATE_DEFAULT_KEYS)) {
1679 if (!key.def_uni || !key.def_multi) {
1680 err = -EOPNOTSUPP;
1681 goto out;
1682 }
1683 }
1684
1685 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1686 key.def_uni, key.def_multi);
1687
1688 if (err)
1689 goto out;
fffd0934 1690
3d23e349 1691#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1692 dev->ieee80211_ptr->wext.default_key = key.idx;
1693#endif
1694 } else {
1695 if (key.def_uni || !key.def_multi) {
1696 err = -EINVAL;
1697 goto out;
1698 }
1699
1700 if (!rdev->ops->set_default_mgmt_key) {
1701 err = -EOPNOTSUPP;
1702 goto out;
1703 }
1704
1705 err = nl80211_key_allowed(dev->ieee80211_ptr);
1706 if (err)
1707 goto out;
1708
1709 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1710 dev, key.idx);
1711 if (err)
1712 goto out;
1713
1714#ifdef CONFIG_CFG80211_WEXT
1715 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1716#endif
dbd2fd65
JB
1717 }
1718
1719 out:
fffd0934 1720 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1721
41ade00f
JB
1722 return err;
1723}
1724
1725static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1726{
4c476991 1727 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1728 int err;
4c476991 1729 struct net_device *dev = info->user_ptr[1];
b9454e83 1730 struct key_parse key;
e31b8213 1731 const u8 *mac_addr = NULL;
41ade00f 1732
b9454e83
JB
1733 err = nl80211_parse_key(info, &key);
1734 if (err)
1735 return err;
41ade00f 1736
b9454e83 1737 if (!key.p.key)
41ade00f
JB
1738 return -EINVAL;
1739
41ade00f
JB
1740 if (info->attrs[NL80211_ATTR_MAC])
1741 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1742
e31b8213
JB
1743 if (key.type == -1) {
1744 if (mac_addr)
1745 key.type = NL80211_KEYTYPE_PAIRWISE;
1746 else
1747 key.type = NL80211_KEYTYPE_GROUP;
1748 }
1749
1750 /* for now */
1751 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1752 key.type != NL80211_KEYTYPE_GROUP)
1753 return -EINVAL;
1754
4c476991
JB
1755 if (!rdev->ops->add_key)
1756 return -EOPNOTSUPP;
25e47c18 1757
e31b8213
JB
1758 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1759 key.type == NL80211_KEYTYPE_PAIRWISE,
1760 mac_addr))
4c476991 1761 return -EINVAL;
41ade00f 1762
fffd0934
JB
1763 wdev_lock(dev->ieee80211_ptr);
1764 err = nl80211_key_allowed(dev->ieee80211_ptr);
1765 if (!err)
1766 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1767 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1768 mac_addr, &key.p);
1769 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1770
41ade00f
JB
1771 return err;
1772}
1773
1774static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1775{
4c476991 1776 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1777 int err;
4c476991 1778 struct net_device *dev = info->user_ptr[1];
41ade00f 1779 u8 *mac_addr = NULL;
b9454e83 1780 struct key_parse key;
41ade00f 1781
b9454e83
JB
1782 err = nl80211_parse_key(info, &key);
1783 if (err)
1784 return err;
41ade00f
JB
1785
1786 if (info->attrs[NL80211_ATTR_MAC])
1787 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1788
e31b8213
JB
1789 if (key.type == -1) {
1790 if (mac_addr)
1791 key.type = NL80211_KEYTYPE_PAIRWISE;
1792 else
1793 key.type = NL80211_KEYTYPE_GROUP;
1794 }
1795
1796 /* for now */
1797 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1798 key.type != NL80211_KEYTYPE_GROUP)
1799 return -EINVAL;
1800
4c476991
JB
1801 if (!rdev->ops->del_key)
1802 return -EOPNOTSUPP;
41ade00f 1803
fffd0934
JB
1804 wdev_lock(dev->ieee80211_ptr);
1805 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
1806
1807 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1808 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1809 err = -ENOENT;
1810
fffd0934 1811 if (!err)
e31b8213
JB
1812 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1813 key.type == NL80211_KEYTYPE_PAIRWISE,
1814 mac_addr);
41ade00f 1815
3d23e349 1816#ifdef CONFIG_CFG80211_WEXT
08645126 1817 if (!err) {
b9454e83 1818 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1819 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1820 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1821 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1822 }
1823#endif
fffd0934 1824 wdev_unlock(dev->ieee80211_ptr);
08645126 1825
41ade00f
JB
1826 return err;
1827}
1828
ed1b6cc7
JB
1829static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1830{
1831 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1832 struct beacon_parameters *info);
4c476991
JB
1833 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1834 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1835 struct beacon_parameters params;
1836 int haveinfo = 0;
1837
f4a11bb0
JB
1838 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1839 return -EINVAL;
1840
074ac8df 1841 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1842 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1843 return -EOPNOTSUPP;
eec60b03 1844
ed1b6cc7
JB
1845 switch (info->genlhdr->cmd) {
1846 case NL80211_CMD_NEW_BEACON:
1847 /* these are required for NEW_BEACON */
1848 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1849 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1850 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1851 return -EINVAL;
ed1b6cc7 1852
79c97e97 1853 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1854 break;
1855 case NL80211_CMD_SET_BEACON:
79c97e97 1856 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1857 break;
1858 default:
1859 WARN_ON(1);
4c476991 1860 return -EOPNOTSUPP;
ed1b6cc7
JB
1861 }
1862
4c476991
JB
1863 if (!call)
1864 return -EOPNOTSUPP;
ed1b6cc7
JB
1865
1866 memset(&params, 0, sizeof(params));
1867
1868 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1869 params.interval =
1870 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1871 haveinfo = 1;
1872 }
1873
1874 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1875 params.dtim_period =
1876 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1877 haveinfo = 1;
1878 }
1879
1880 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1881 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1882 params.head_len =
1883 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1884 haveinfo = 1;
1885 }
1886
1887 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1888 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1889 params.tail_len =
1890 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1891 haveinfo = 1;
1892 }
1893
4c476991
JB
1894 if (!haveinfo)
1895 return -EINVAL;
3b85875a 1896
4c476991 1897 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1898}
1899
1900static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1901{
4c476991
JB
1902 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1903 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1904
4c476991
JB
1905 if (!rdev->ops->del_beacon)
1906 return -EOPNOTSUPP;
ed1b6cc7 1907
074ac8df 1908 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1909 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1910 return -EOPNOTSUPP;
3b85875a 1911
4c476991 1912 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1913}
1914
5727ef1b
JB
1915static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1916 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1917 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1918 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1919 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1920};
1921
eccb8e8f
JB
1922static int parse_station_flags(struct genl_info *info,
1923 struct station_parameters *params)
5727ef1b
JB
1924{
1925 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1926 struct nlattr *nla;
5727ef1b
JB
1927 int flag;
1928
eccb8e8f
JB
1929 /*
1930 * Try parsing the new attribute first so userspace
1931 * can specify both for older kernels.
1932 */
1933 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1934 if (nla) {
1935 struct nl80211_sta_flag_update *sta_flags;
1936
1937 sta_flags = nla_data(nla);
1938 params->sta_flags_mask = sta_flags->mask;
1939 params->sta_flags_set = sta_flags->set;
1940 if ((params->sta_flags_mask |
1941 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1942 return -EINVAL;
1943 return 0;
1944 }
1945
1946 /* if present, parse the old attribute */
5727ef1b 1947
eccb8e8f 1948 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1949 if (!nla)
1950 return 0;
1951
1952 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1953 nla, sta_flags_policy))
1954 return -EINVAL;
1955
eccb8e8f
JB
1956 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1957 params->sta_flags_mask &= ~1;
5727ef1b
JB
1958
1959 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1960 if (flags[flag])
eccb8e8f 1961 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1962
1963 return 0;
1964}
1965
fd5b74dc
JB
1966static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1967 int flags, struct net_device *dev,
98b62183 1968 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1969{
1970 void *hdr;
420e7fab
HR
1971 struct nlattr *sinfoattr, *txrate;
1972 u16 bitrate;
fd5b74dc
JB
1973
1974 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1975 if (!hdr)
1976 return -1;
1977
1978 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1979 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1980
f5ea9120
JB
1981 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1982
2ec600d6
LCC
1983 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1984 if (!sinfoattr)
fd5b74dc 1985 goto nla_put_failure;
2ec600d6
LCC
1986 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1987 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1988 sinfo->inactive_time);
1989 if (sinfo->filled & STATION_INFO_RX_BYTES)
1990 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1991 sinfo->rx_bytes);
1992 if (sinfo->filled & STATION_INFO_TX_BYTES)
1993 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1994 sinfo->tx_bytes);
1995 if (sinfo->filled & STATION_INFO_LLID)
1996 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1997 sinfo->llid);
1998 if (sinfo->filled & STATION_INFO_PLID)
1999 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2000 sinfo->plid);
2001 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2002 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2003 sinfo->plink_state);
420e7fab
HR
2004 if (sinfo->filled & STATION_INFO_SIGNAL)
2005 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2006 sinfo->signal);
541a45a1
BR
2007 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2008 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2009 sinfo->signal_avg);
420e7fab
HR
2010 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
2011 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
2012 if (!txrate)
2013 goto nla_put_failure;
2014
254416aa
JL
2015 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2016 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
2017 if (bitrate > 0)
2018 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 2019
420e7fab
HR
2020 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
2021 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
2022 sinfo->txrate.mcs);
2023 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2024 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2025 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
2026 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2027
2028 nla_nest_end(msg, txrate);
2029 }
98c8a60a
JM
2030 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2031 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2032 sinfo->rx_packets);
2033 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2034 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2035 sinfo->tx_packets);
b206b4ef
BR
2036 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2037 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2038 sinfo->tx_retries);
2039 if (sinfo->filled & STATION_INFO_TX_FAILED)
2040 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2041 sinfo->tx_failed);
2ec600d6 2042 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
2043
2044 return genlmsg_end(msg, hdr);
2045
2046 nla_put_failure:
bc3ed28c
TG
2047 genlmsg_cancel(msg, hdr);
2048 return -EMSGSIZE;
fd5b74dc
JB
2049}
2050
2ec600d6 2051static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2052 struct netlink_callback *cb)
2ec600d6 2053{
2ec600d6
LCC
2054 struct station_info sinfo;
2055 struct cfg80211_registered_device *dev;
bba95fef 2056 struct net_device *netdev;
2ec600d6 2057 u8 mac_addr[ETH_ALEN];
bba95fef 2058 int sta_idx = cb->args[1];
2ec600d6 2059 int err;
2ec600d6 2060
67748893
JB
2061 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2062 if (err)
2063 return err;
bba95fef
JB
2064
2065 if (!dev->ops->dump_station) {
eec60b03 2066 err = -EOPNOTSUPP;
bba95fef
JB
2067 goto out_err;
2068 }
2069
bba95fef
JB
2070 while (1) {
2071 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2072 mac_addr, &sinfo);
2073 if (err == -ENOENT)
2074 break;
2075 if (err)
3b85875a 2076 goto out_err;
bba95fef
JB
2077
2078 if (nl80211_send_station(skb,
2079 NETLINK_CB(cb->skb).pid,
2080 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2081 netdev, mac_addr,
2082 &sinfo) < 0)
2083 goto out;
2084
2085 sta_idx++;
2086 }
2087
2088
2089 out:
2090 cb->args[1] = sta_idx;
2091 err = skb->len;
bba95fef 2092 out_err:
67748893 2093 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2094
2095 return err;
2ec600d6 2096}
fd5b74dc 2097
5727ef1b
JB
2098static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2099{
4c476991
JB
2100 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2101 struct net_device *dev = info->user_ptr[1];
2ec600d6 2102 struct station_info sinfo;
fd5b74dc
JB
2103 struct sk_buff *msg;
2104 u8 *mac_addr = NULL;
4c476991 2105 int err;
fd5b74dc 2106
2ec600d6 2107 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2108
2109 if (!info->attrs[NL80211_ATTR_MAC])
2110 return -EINVAL;
2111
2112 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2113
4c476991
JB
2114 if (!rdev->ops->get_station)
2115 return -EOPNOTSUPP;
3b85875a 2116
4c476991 2117 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2118 if (err)
4c476991 2119 return err;
2ec600d6 2120
fd2120ca 2121 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2122 if (!msg)
4c476991 2123 return -ENOMEM;
fd5b74dc
JB
2124
2125 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2126 dev, mac_addr, &sinfo) < 0) {
2127 nlmsg_free(msg);
2128 return -ENOBUFS;
2129 }
3b85875a 2130
4c476991 2131 return genlmsg_reply(msg, info);
5727ef1b
JB
2132}
2133
2134/*
c258d2de 2135 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2136 */
463d0183 2137static int get_vlan(struct genl_info *info,
5727ef1b
JB
2138 struct cfg80211_registered_device *rdev,
2139 struct net_device **vlan)
2140{
463d0183 2141 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2142 *vlan = NULL;
2143
2144 if (vlanattr) {
463d0183
JB
2145 *vlan = dev_get_by_index(genl_info_net(info),
2146 nla_get_u32(vlanattr));
5727ef1b
JB
2147 if (!*vlan)
2148 return -ENODEV;
2149 if (!(*vlan)->ieee80211_ptr)
2150 return -EINVAL;
2151 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2152 return -EINVAL;
c258d2de
FF
2153 if (!netif_running(*vlan))
2154 return -ENETDOWN;
5727ef1b
JB
2155 }
2156 return 0;
2157}
2158
2159static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2160{
4c476991 2161 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2162 int err;
4c476991 2163 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2164 struct station_parameters params;
2165 u8 *mac_addr = NULL;
2166
2167 memset(&params, 0, sizeof(params));
2168
2169 params.listen_interval = -1;
2170
2171 if (info->attrs[NL80211_ATTR_STA_AID])
2172 return -EINVAL;
2173
2174 if (!info->attrs[NL80211_ATTR_MAC])
2175 return -EINVAL;
2176
2177 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2178
2179 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2180 params.supported_rates =
2181 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2182 params.supported_rates_len =
2183 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2184 }
2185
2186 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2187 params.listen_interval =
2188 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2189
36aedc90
JM
2190 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2191 params.ht_capa =
2192 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2193
eccb8e8f 2194 if (parse_station_flags(info, &params))
5727ef1b
JB
2195 return -EINVAL;
2196
2ec600d6
LCC
2197 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2198 params.plink_action =
2199 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2200
463d0183 2201 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2202 if (err)
034d655e 2203 goto out;
a97f4424
JB
2204
2205 /* validate settings */
2206 err = 0;
2207
2208 switch (dev->ieee80211_ptr->iftype) {
2209 case NL80211_IFTYPE_AP:
2210 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2211 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2212 /* disallow mesh-specific things */
2213 if (params.plink_action)
2214 err = -EINVAL;
2215 break;
074ac8df 2216 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2217 case NL80211_IFTYPE_STATION:
2218 /* disallow everything but AUTHORIZED flag */
2219 if (params.plink_action)
2220 err = -EINVAL;
2221 if (params.vlan)
2222 err = -EINVAL;
2223 if (params.supported_rates)
2224 err = -EINVAL;
2225 if (params.ht_capa)
2226 err = -EINVAL;
2227 if (params.listen_interval >= 0)
2228 err = -EINVAL;
2229 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2230 err = -EINVAL;
2231 break;
2232 case NL80211_IFTYPE_MESH_POINT:
2233 /* disallow things mesh doesn't support */
2234 if (params.vlan)
2235 err = -EINVAL;
2236 if (params.ht_capa)
2237 err = -EINVAL;
2238 if (params.listen_interval >= 0)
2239 err = -EINVAL;
2240 if (params.supported_rates)
2241 err = -EINVAL;
2242 if (params.sta_flags_mask)
2243 err = -EINVAL;
2244 break;
2245 default:
2246 err = -EINVAL;
034d655e
JB
2247 }
2248
5727ef1b
JB
2249 if (err)
2250 goto out;
2251
79c97e97 2252 if (!rdev->ops->change_station) {
5727ef1b
JB
2253 err = -EOPNOTSUPP;
2254 goto out;
2255 }
2256
79c97e97 2257 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2258
2259 out:
2260 if (params.vlan)
2261 dev_put(params.vlan);
3b85875a 2262
5727ef1b
JB
2263 return err;
2264}
2265
2266static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2267{
4c476991 2268 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2269 int err;
4c476991 2270 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2271 struct station_parameters params;
2272 u8 *mac_addr = NULL;
2273
2274 memset(&params, 0, sizeof(params));
2275
2276 if (!info->attrs[NL80211_ATTR_MAC])
2277 return -EINVAL;
2278
5727ef1b
JB
2279 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2280 return -EINVAL;
2281
2282 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2283 return -EINVAL;
2284
0e956c13
TLSC
2285 if (!info->attrs[NL80211_ATTR_STA_AID])
2286 return -EINVAL;
2287
5727ef1b
JB
2288 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2289 params.supported_rates =
2290 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2291 params.supported_rates_len =
2292 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2293 params.listen_interval =
2294 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2295
0e956c13
TLSC
2296 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2297 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2298 return -EINVAL;
51b50fbe 2299
36aedc90
JM
2300 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2301 params.ht_capa =
2302 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2303
eccb8e8f 2304 if (parse_station_flags(info, &params))
5727ef1b
JB
2305 return -EINVAL;
2306
0e956c13 2307 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2308 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4c476991
JB
2309 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2310 return -EINVAL;
0e956c13 2311
463d0183 2312 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2313 if (err)
e80cf853 2314 goto out;
a97f4424
JB
2315
2316 /* validate settings */
2317 err = 0;
2318
79c97e97 2319 if (!rdev->ops->add_station) {
5727ef1b
JB
2320 err = -EOPNOTSUPP;
2321 goto out;
2322 }
2323
79c97e97 2324 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2325
2326 out:
2327 if (params.vlan)
2328 dev_put(params.vlan);
5727ef1b
JB
2329 return err;
2330}
2331
2332static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2333{
4c476991
JB
2334 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2335 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2336 u8 *mac_addr = NULL;
2337
2338 if (info->attrs[NL80211_ATTR_MAC])
2339 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2340
e80cf853 2341 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2342 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2343 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2344 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2345 return -EINVAL;
5727ef1b 2346
4c476991
JB
2347 if (!rdev->ops->del_station)
2348 return -EOPNOTSUPP;
3b85875a 2349
4c476991 2350 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2351}
2352
2ec600d6
LCC
2353static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2354 int flags, struct net_device *dev,
2355 u8 *dst, u8 *next_hop,
2356 struct mpath_info *pinfo)
2357{
2358 void *hdr;
2359 struct nlattr *pinfoattr;
2360
2361 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2362 if (!hdr)
2363 return -1;
2364
2365 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2366 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2367 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2368
f5ea9120
JB
2369 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2370
2ec600d6
LCC
2371 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2372 if (!pinfoattr)
2373 goto nla_put_failure;
2374 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2375 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2376 pinfo->frame_qlen);
d19b3bf6
RP
2377 if (pinfo->filled & MPATH_INFO_SN)
2378 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2379 pinfo->sn);
2ec600d6
LCC
2380 if (pinfo->filled & MPATH_INFO_METRIC)
2381 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2382 pinfo->metric);
2383 if (pinfo->filled & MPATH_INFO_EXPTIME)
2384 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2385 pinfo->exptime);
2386 if (pinfo->filled & MPATH_INFO_FLAGS)
2387 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2388 pinfo->flags);
2389 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2390 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2391 pinfo->discovery_timeout);
2392 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2393 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2394 pinfo->discovery_retries);
2395
2396 nla_nest_end(msg, pinfoattr);
2397
2398 return genlmsg_end(msg, hdr);
2399
2400 nla_put_failure:
bc3ed28c
TG
2401 genlmsg_cancel(msg, hdr);
2402 return -EMSGSIZE;
2ec600d6
LCC
2403}
2404
2405static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2406 struct netlink_callback *cb)
2ec600d6 2407{
2ec600d6
LCC
2408 struct mpath_info pinfo;
2409 struct cfg80211_registered_device *dev;
bba95fef 2410 struct net_device *netdev;
2ec600d6
LCC
2411 u8 dst[ETH_ALEN];
2412 u8 next_hop[ETH_ALEN];
bba95fef 2413 int path_idx = cb->args[1];
2ec600d6 2414 int err;
2ec600d6 2415
67748893
JB
2416 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2417 if (err)
2418 return err;
bba95fef
JB
2419
2420 if (!dev->ops->dump_mpath) {
eec60b03 2421 err = -EOPNOTSUPP;
bba95fef
JB
2422 goto out_err;
2423 }
2424
eec60b03
JM
2425 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2426 err = -EOPNOTSUPP;
0448b5fc 2427 goto out_err;
eec60b03
JM
2428 }
2429
bba95fef
JB
2430 while (1) {
2431 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2432 dst, next_hop, &pinfo);
2433 if (err == -ENOENT)
2ec600d6 2434 break;
bba95fef 2435 if (err)
3b85875a 2436 goto out_err;
2ec600d6 2437
bba95fef
JB
2438 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2439 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2440 netdev, dst, next_hop,
2441 &pinfo) < 0)
2442 goto out;
2ec600d6 2443
bba95fef 2444 path_idx++;
2ec600d6 2445 }
2ec600d6 2446
2ec600d6 2447
bba95fef
JB
2448 out:
2449 cb->args[1] = path_idx;
2450 err = skb->len;
bba95fef 2451 out_err:
67748893 2452 nl80211_finish_netdev_dump(dev);
bba95fef 2453 return err;
2ec600d6
LCC
2454}
2455
2456static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2457{
4c476991 2458 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2459 int err;
4c476991 2460 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2461 struct mpath_info pinfo;
2462 struct sk_buff *msg;
2463 u8 *dst = NULL;
2464 u8 next_hop[ETH_ALEN];
2465
2466 memset(&pinfo, 0, sizeof(pinfo));
2467
2468 if (!info->attrs[NL80211_ATTR_MAC])
2469 return -EINVAL;
2470
2471 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2472
4c476991
JB
2473 if (!rdev->ops->get_mpath)
2474 return -EOPNOTSUPP;
2ec600d6 2475
4c476991
JB
2476 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2477 return -EOPNOTSUPP;
eec60b03 2478
79c97e97 2479 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2480 if (err)
4c476991 2481 return err;
2ec600d6 2482
fd2120ca 2483 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2484 if (!msg)
4c476991 2485 return -ENOMEM;
2ec600d6
LCC
2486
2487 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2488 dev, dst, next_hop, &pinfo) < 0) {
2489 nlmsg_free(msg);
2490 return -ENOBUFS;
2491 }
3b85875a 2492
4c476991 2493 return genlmsg_reply(msg, info);
2ec600d6
LCC
2494}
2495
2496static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2497{
4c476991
JB
2498 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2499 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2500 u8 *dst = NULL;
2501 u8 *next_hop = NULL;
2502
2503 if (!info->attrs[NL80211_ATTR_MAC])
2504 return -EINVAL;
2505
2506 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2507 return -EINVAL;
2508
2509 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2510 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2511
4c476991
JB
2512 if (!rdev->ops->change_mpath)
2513 return -EOPNOTSUPP;
35a8efe1 2514
4c476991
JB
2515 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2516 return -EOPNOTSUPP;
2ec600d6 2517
4c476991 2518 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2519}
4c476991 2520
2ec600d6
LCC
2521static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2522{
4c476991
JB
2523 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2524 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2525 u8 *dst = NULL;
2526 u8 *next_hop = NULL;
2527
2528 if (!info->attrs[NL80211_ATTR_MAC])
2529 return -EINVAL;
2530
2531 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2532 return -EINVAL;
2533
2534 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2535 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2536
4c476991
JB
2537 if (!rdev->ops->add_mpath)
2538 return -EOPNOTSUPP;
35a8efe1 2539
4c476991
JB
2540 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2541 return -EOPNOTSUPP;
2ec600d6 2542
4c476991 2543 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2544}
2545
2546static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2547{
4c476991
JB
2548 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2549 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2550 u8 *dst = NULL;
2551
2552 if (info->attrs[NL80211_ATTR_MAC])
2553 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2554
4c476991
JB
2555 if (!rdev->ops->del_mpath)
2556 return -EOPNOTSUPP;
3b85875a 2557
4c476991 2558 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2559}
2560
9f1ba906
JM
2561static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2562{
4c476991
JB
2563 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2564 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2565 struct bss_parameters params;
2566
2567 memset(&params, 0, sizeof(params));
2568 /* default to not changing parameters */
2569 params.use_cts_prot = -1;
2570 params.use_short_preamble = -1;
2571 params.use_short_slot_time = -1;
fd8aaaf3 2572 params.ap_isolate = -1;
50b12f59 2573 params.ht_opmode = -1;
9f1ba906
JM
2574
2575 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2576 params.use_cts_prot =
2577 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2578 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2579 params.use_short_preamble =
2580 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2581 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2582 params.use_short_slot_time =
2583 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2584 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2585 params.basic_rates =
2586 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2587 params.basic_rates_len =
2588 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2589 }
fd8aaaf3
FF
2590 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2591 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2592 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2593 params.ht_opmode =
2594 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2595
4c476991
JB
2596 if (!rdev->ops->change_bss)
2597 return -EOPNOTSUPP;
9f1ba906 2598
074ac8df 2599 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2600 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2601 return -EOPNOTSUPP;
3b85875a 2602
4c476991 2603 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2604}
2605
b54452b0 2606static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2607 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2608 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2609 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2610 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2611 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2612 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2613};
2614
2615static int parse_reg_rule(struct nlattr *tb[],
2616 struct ieee80211_reg_rule *reg_rule)
2617{
2618 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2619 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2620
2621 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2622 return -EINVAL;
2623 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2624 return -EINVAL;
2625 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2626 return -EINVAL;
2627 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2628 return -EINVAL;
2629 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2630 return -EINVAL;
2631
2632 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2633
2634 freq_range->start_freq_khz =
2635 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2636 freq_range->end_freq_khz =
2637 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2638 freq_range->max_bandwidth_khz =
2639 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2640
2641 power_rule->max_eirp =
2642 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2643
2644 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2645 power_rule->max_antenna_gain =
2646 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2647
2648 return 0;
2649}
2650
2651static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2652{
2653 int r;
2654 char *data = NULL;
2655
80778f18
LR
2656 /*
2657 * You should only get this when cfg80211 hasn't yet initialized
2658 * completely when built-in to the kernel right between the time
2659 * window between nl80211_init() and regulatory_init(), if that is
2660 * even possible.
2661 */
2662 mutex_lock(&cfg80211_mutex);
2663 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2664 mutex_unlock(&cfg80211_mutex);
2665 return -EINPROGRESS;
80778f18 2666 }
fe33eb39 2667 mutex_unlock(&cfg80211_mutex);
80778f18 2668
fe33eb39
LR
2669 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2670 return -EINVAL;
b2e1b302
LR
2671
2672 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2673
fe33eb39
LR
2674 r = regulatory_hint_user(data);
2675
b2e1b302
LR
2676 return r;
2677}
2678
24bdd9f4 2679static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 2680 struct genl_info *info)
93da9cc1 2681{
4c476991 2682 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 2683 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
2684 struct wireless_dev *wdev = dev->ieee80211_ptr;
2685 struct mesh_config cur_params;
2686 int err = 0;
93da9cc1 2687 void *hdr;
2688 struct nlattr *pinfoattr;
2689 struct sk_buff *msg;
2690
29cbe68c
JB
2691 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2692 return -EOPNOTSUPP;
2693
24bdd9f4 2694 if (!rdev->ops->get_mesh_config)
4c476991 2695 return -EOPNOTSUPP;
f3f92586 2696
29cbe68c
JB
2697 wdev_lock(wdev);
2698 /* If not connected, get default parameters */
2699 if (!wdev->mesh_id_len)
2700 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2701 else
24bdd9f4 2702 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2703 &cur_params);
2704 wdev_unlock(wdev);
2705
93da9cc1 2706 if (err)
4c476991 2707 return err;
93da9cc1 2708
2709 /* Draw up a netlink message to send back */
fd2120ca 2710 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2711 if (!msg)
2712 return -ENOMEM;
93da9cc1 2713 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 2714 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 2715 if (!hdr)
2716 goto nla_put_failure;
24bdd9f4 2717 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 2718 if (!pinfoattr)
2719 goto nla_put_failure;
2720 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2721 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2722 cur_params.dot11MeshRetryTimeout);
2723 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2724 cur_params.dot11MeshConfirmTimeout);
2725 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2726 cur_params.dot11MeshHoldingTimeout);
2727 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2728 cur_params.dot11MeshMaxPeerLinks);
2729 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2730 cur_params.dot11MeshMaxRetries);
2731 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2732 cur_params.dot11MeshTTL);
45904f21
JC
2733 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2734 cur_params.element_ttl);
93da9cc1 2735 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2736 cur_params.auto_open_plinks);
2737 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2738 cur_params.dot11MeshHWMPmaxPREQretries);
2739 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2740 cur_params.path_refresh_time);
2741 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2742 cur_params.min_discovery_timeout);
2743 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2744 cur_params.dot11MeshHWMPactivePathTimeout);
2745 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2746 cur_params.dot11MeshHWMPpreqMinInterval);
2747 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2748 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2749 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2750 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2751 nla_nest_end(msg, pinfoattr);
2752 genlmsg_end(msg, hdr);
4c476991 2753 return genlmsg_reply(msg, info);
93da9cc1 2754
3b85875a 2755 nla_put_failure:
93da9cc1 2756 genlmsg_cancel(msg, hdr);
d080e275 2757 nlmsg_free(msg);
4c476991 2758 return -ENOBUFS;
93da9cc1 2759}
2760
b54452b0 2761static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2762 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2763 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2764 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2765 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2766 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2767 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 2768 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 2769 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2770
2771 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2772 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2773 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2774 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2775 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2776 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2777};
2778
c80d545d
JC
2779static const struct nla_policy
2780 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2781 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2782 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
2783 [NL80211_MESH_SETUP_VENDOR_PATH_SEL_IE] = { .type = NLA_BINARY,
2784 .len = IEEE80211_MAX_DATA_LEN },
2785};
2786
24bdd9f4 2787static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
2788 struct mesh_config *cfg,
2789 u32 *mask_out)
93da9cc1 2790{
93da9cc1 2791 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 2792 u32 mask = 0;
93da9cc1 2793
bd90fdcc
JB
2794#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2795do {\
2796 if (table[attr_num]) {\
2797 cfg->param = nla_fn(table[attr_num]); \
2798 mask |= (1 << (attr_num - 1)); \
2799 } \
2800} while (0);\
2801
2802
24bdd9f4 2803 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 2804 return -EINVAL;
2805 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 2806 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 2807 nl80211_meshconf_params_policy))
93da9cc1 2808 return -EINVAL;
2809
93da9cc1 2810 /* This makes sure that there aren't more than 32 mesh config
2811 * parameters (otherwise our bitfield scheme would not work.) */
2812 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2813
2814 /* Fill in the params struct */
93da9cc1 2815 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2816 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2817 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2818 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2819 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2820 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2821 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2822 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2823 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2824 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2825 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2826 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
2827 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2828 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 2829 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2830 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2831 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2832 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2833 nla_get_u8);
2834 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2835 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2836 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2837 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2838 nla_get_u16);
2839 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2840 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2841 nla_get_u32);
2842 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2843 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2844 nla_get_u16);
2845 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2846 dot11MeshHWMPnetDiameterTraversalTime,
2847 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2848 nla_get_u16);
63c5723b
RP
2849 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2850 dot11MeshHWMPRootMode, mask,
2851 NL80211_MESHCONF_HWMP_ROOTMODE,
2852 nla_get_u8);
bd90fdcc
JB
2853 if (mask_out)
2854 *mask_out = mask;
c80d545d 2855
bd90fdcc
JB
2856 return 0;
2857
2858#undef FILL_IN_MESH_PARAM_IF_SET
2859}
2860
c80d545d
JC
2861static int nl80211_parse_mesh_setup(struct genl_info *info,
2862 struct mesh_setup *setup)
2863{
2864 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
2865
2866 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
2867 return -EINVAL;
2868 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
2869 info->attrs[NL80211_ATTR_MESH_SETUP],
2870 nl80211_mesh_setup_params_policy))
2871 return -EINVAL;
2872
2873 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
2874 setup->path_sel_proto =
2875 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
2876 IEEE80211_PATH_PROTOCOL_VENDOR :
2877 IEEE80211_PATH_PROTOCOL_HWMP;
2878
2879 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
2880 setup->path_metric =
2881 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
2882 IEEE80211_PATH_METRIC_VENDOR :
2883 IEEE80211_PATH_METRIC_AIRTIME;
2884
2885 if (tb[NL80211_MESH_SETUP_VENDOR_PATH_SEL_IE]) {
2886 struct nlattr *ieattr =
2887 tb[NL80211_MESH_SETUP_VENDOR_PATH_SEL_IE];
2888 if (!is_valid_ie_attr(ieattr))
2889 return -EINVAL;
2890 setup->vendor_ie = nla_data(ieattr);
2891 setup->vendor_ie_len = nla_len(ieattr);
2892 }
2893
2894 return 0;
2895}
2896
24bdd9f4 2897static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 2898 struct genl_info *info)
bd90fdcc
JB
2899{
2900 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2901 struct net_device *dev = info->user_ptr[1];
29cbe68c 2902 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
2903 struct mesh_config cfg;
2904 u32 mask;
2905 int err;
2906
29cbe68c
JB
2907 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2908 return -EOPNOTSUPP;
2909
24bdd9f4 2910 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
2911 return -EOPNOTSUPP;
2912
24bdd9f4 2913 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
2914 if (err)
2915 return err;
2916
29cbe68c
JB
2917 wdev_lock(wdev);
2918 if (!wdev->mesh_id_len)
2919 err = -ENOLINK;
2920
2921 if (!err)
24bdd9f4 2922 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2923 mask, &cfg);
2924
2925 wdev_unlock(wdev);
2926
2927 return err;
93da9cc1 2928}
2929
f130347c
LR
2930static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2931{
2932 struct sk_buff *msg;
2933 void *hdr = NULL;
2934 struct nlattr *nl_reg_rules;
2935 unsigned int i;
2936 int err = -EINVAL;
2937
a1794390 2938 mutex_lock(&cfg80211_mutex);
f130347c
LR
2939
2940 if (!cfg80211_regdomain)
2941 goto out;
2942
fd2120ca 2943 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2944 if (!msg) {
2945 err = -ENOBUFS;
2946 goto out;
2947 }
2948
2949 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2950 NL80211_CMD_GET_REG);
2951 if (!hdr)
2952 goto nla_put_failure;
2953
2954 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2955 cfg80211_regdomain->alpha2);
2956
2957 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2958 if (!nl_reg_rules)
2959 goto nla_put_failure;
2960
2961 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2962 struct nlattr *nl_reg_rule;
2963 const struct ieee80211_reg_rule *reg_rule;
2964 const struct ieee80211_freq_range *freq_range;
2965 const struct ieee80211_power_rule *power_rule;
2966
2967 reg_rule = &cfg80211_regdomain->reg_rules[i];
2968 freq_range = &reg_rule->freq_range;
2969 power_rule = &reg_rule->power_rule;
2970
2971 nl_reg_rule = nla_nest_start(msg, i);
2972 if (!nl_reg_rule)
2973 goto nla_put_failure;
2974
2975 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2976 reg_rule->flags);
2977 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2978 freq_range->start_freq_khz);
2979 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2980 freq_range->end_freq_khz);
2981 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2982 freq_range->max_bandwidth_khz);
2983 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2984 power_rule->max_antenna_gain);
2985 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2986 power_rule->max_eirp);
2987
2988 nla_nest_end(msg, nl_reg_rule);
2989 }
2990
2991 nla_nest_end(msg, nl_reg_rules);
2992
2993 genlmsg_end(msg, hdr);
134e6375 2994 err = genlmsg_reply(msg, info);
f130347c
LR
2995 goto out;
2996
2997nla_put_failure:
2998 genlmsg_cancel(msg, hdr);
d080e275 2999 nlmsg_free(msg);
f130347c
LR
3000 err = -EMSGSIZE;
3001out:
a1794390 3002 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3003 return err;
3004}
3005
b2e1b302
LR
3006static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3007{
3008 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3009 struct nlattr *nl_reg_rule;
3010 char *alpha2 = NULL;
3011 int rem_reg_rules = 0, r = 0;
3012 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3013 struct ieee80211_regdomain *rd = NULL;
3014
3015 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3016 return -EINVAL;
3017
3018 if (!info->attrs[NL80211_ATTR_REG_RULES])
3019 return -EINVAL;
3020
3021 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3022
3023 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3024 rem_reg_rules) {
3025 num_rules++;
3026 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3027 return -EINVAL;
b2e1b302
LR
3028 }
3029
61405e97
LR
3030 mutex_lock(&cfg80211_mutex);
3031
d0e18f83
LR
3032 if (!reg_is_valid_request(alpha2)) {
3033 r = -EINVAL;
3034 goto bad_reg;
3035 }
b2e1b302
LR
3036
3037 size_of_regd = sizeof(struct ieee80211_regdomain) +
3038 (num_rules * sizeof(struct ieee80211_reg_rule));
3039
3040 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3041 if (!rd) {
3042 r = -ENOMEM;
3043 goto bad_reg;
3044 }
b2e1b302
LR
3045
3046 rd->n_reg_rules = num_rules;
3047 rd->alpha2[0] = alpha2[0];
3048 rd->alpha2[1] = alpha2[1];
3049
3050 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3051 rem_reg_rules) {
3052 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3053 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3054 reg_rule_policy);
3055 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3056 if (r)
3057 goto bad_reg;
3058
3059 rule_idx++;
3060
d0e18f83
LR
3061 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3062 r = -EINVAL;
b2e1b302 3063 goto bad_reg;
d0e18f83 3064 }
b2e1b302
LR
3065 }
3066
3067 BUG_ON(rule_idx != num_rules);
3068
b2e1b302 3069 r = set_regdom(rd);
61405e97 3070
a1794390 3071 mutex_unlock(&cfg80211_mutex);
d0e18f83 3072
b2e1b302
LR
3073 return r;
3074
d2372b31 3075 bad_reg:
61405e97 3076 mutex_unlock(&cfg80211_mutex);
b2e1b302 3077 kfree(rd);
d0e18f83 3078 return r;
b2e1b302
LR
3079}
3080
83f5e2cf
JB
3081static int validate_scan_freqs(struct nlattr *freqs)
3082{
3083 struct nlattr *attr1, *attr2;
3084 int n_channels = 0, tmp1, tmp2;
3085
3086 nla_for_each_nested(attr1, freqs, tmp1) {
3087 n_channels++;
3088 /*
3089 * Some hardware has a limited channel list for
3090 * scanning, and it is pretty much nonsensical
3091 * to scan for a channel twice, so disallow that
3092 * and don't require drivers to check that the
3093 * channel list they get isn't longer than what
3094 * they can scan, as long as they can scan all
3095 * the channels they registered at once.
3096 */
3097 nla_for_each_nested(attr2, freqs, tmp2)
3098 if (attr1 != attr2 &&
3099 nla_get_u32(attr1) == nla_get_u32(attr2))
3100 return 0;
3101 }
3102
3103 return n_channels;
3104}
3105
2a519311
JB
3106static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3107{
4c476991
JB
3108 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3109 struct net_device *dev = info->user_ptr[1];
2a519311
JB
3110 struct cfg80211_scan_request *request;
3111 struct cfg80211_ssid *ssid;
3112 struct ieee80211_channel *channel;
3113 struct nlattr *attr;
3114 struct wiphy *wiphy;
83f5e2cf 3115 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3116 enum ieee80211_band band;
70692ad2 3117 size_t ie_len;
2a519311 3118
f4a11bb0
JB
3119 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3120 return -EINVAL;
3121
79c97e97 3122 wiphy = &rdev->wiphy;
2a519311 3123
4c476991
JB
3124 if (!rdev->ops->scan)
3125 return -EOPNOTSUPP;
2a519311 3126
4c476991
JB
3127 if (rdev->scan_req)
3128 return -EBUSY;
2a519311
JB
3129
3130 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3131 n_channels = validate_scan_freqs(
3132 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3133 if (!n_channels)
3134 return -EINVAL;
2a519311 3135 } else {
83f5e2cf
JB
3136 n_channels = 0;
3137
2a519311
JB
3138 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3139 if (wiphy->bands[band])
3140 n_channels += wiphy->bands[band]->n_channels;
3141 }
3142
3143 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3144 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3145 n_ssids++;
3146
4c476991
JB
3147 if (n_ssids > wiphy->max_scan_ssids)
3148 return -EINVAL;
2a519311 3149
70692ad2
JM
3150 if (info->attrs[NL80211_ATTR_IE])
3151 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3152 else
3153 ie_len = 0;
3154
4c476991
JB
3155 if (ie_len > wiphy->max_scan_ie_len)
3156 return -EINVAL;
18a83659 3157
2a519311
JB
3158 request = kzalloc(sizeof(*request)
3159 + sizeof(*ssid) * n_ssids
70692ad2
JM
3160 + sizeof(channel) * n_channels
3161 + ie_len, GFP_KERNEL);
4c476991
JB
3162 if (!request)
3163 return -ENOMEM;
2a519311 3164
2a519311 3165 if (n_ssids)
5ba63533 3166 request->ssids = (void *)&request->channels[n_channels];
2a519311 3167 request->n_ssids = n_ssids;
70692ad2
JM
3168 if (ie_len) {
3169 if (request->ssids)
3170 request->ie = (void *)(request->ssids + n_ssids);
3171 else
3172 request->ie = (void *)(request->channels + n_channels);
3173 }
2a519311 3174
584991dc 3175 i = 0;
2a519311
JB
3176 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3177 /* user specified, bail out if channel not found */
2a519311 3178 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3179 struct ieee80211_channel *chan;
3180
3181 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3182
3183 if (!chan) {
2a519311
JB
3184 err = -EINVAL;
3185 goto out_free;
3186 }
584991dc
JB
3187
3188 /* ignore disabled channels */
3189 if (chan->flags & IEEE80211_CHAN_DISABLED)
3190 continue;
3191
3192 request->channels[i] = chan;
2a519311
JB
3193 i++;
3194 }
3195 } else {
3196 /* all channels */
2a519311
JB
3197 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3198 int j;
3199 if (!wiphy->bands[band])
3200 continue;
3201 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3202 struct ieee80211_channel *chan;
3203
3204 chan = &wiphy->bands[band]->channels[j];
3205
3206 if (chan->flags & IEEE80211_CHAN_DISABLED)
3207 continue;
3208
3209 request->channels[i] = chan;
2a519311
JB
3210 i++;
3211 }
3212 }
3213 }
3214
584991dc
JB
3215 if (!i) {
3216 err = -EINVAL;
3217 goto out_free;
3218 }
3219
3220 request->n_channels = i;
3221
2a519311
JB
3222 i = 0;
3223 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3224 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3225 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3226 err = -EINVAL;
3227 goto out_free;
3228 }
3229 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3230 request->ssids[i].ssid_len = nla_len(attr);
3231 i++;
3232 }
3233 }
3234
70692ad2
JM
3235 if (info->attrs[NL80211_ATTR_IE]) {
3236 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3237 memcpy((void *)request->ie,
3238 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3239 request->ie_len);
3240 }
3241
463d0183 3242 request->dev = dev;
79c97e97 3243 request->wiphy = &rdev->wiphy;
2a519311 3244
79c97e97
JB
3245 rdev->scan_req = request;
3246 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3247
463d0183 3248 if (!err) {
79c97e97 3249 nl80211_send_scan_start(rdev, dev);
463d0183 3250 dev_hold(dev);
4c476991 3251 } else {
2a519311 3252 out_free:
79c97e97 3253 rdev->scan_req = NULL;
2a519311
JB
3254 kfree(request);
3255 }
3b85875a 3256
2a519311
JB
3257 return err;
3258}
3259
3260static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3261 struct cfg80211_registered_device *rdev,
48ab905d
JB
3262 struct wireless_dev *wdev,
3263 struct cfg80211_internal_bss *intbss)
2a519311 3264{
48ab905d 3265 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3266 void *hdr;
3267 struct nlattr *bss;
48ab905d
JB
3268 int i;
3269
3270 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3271
3272 hdr = nl80211hdr_put(msg, pid, seq, flags,
3273 NL80211_CMD_NEW_SCAN_RESULTS);
3274 if (!hdr)
3275 return -1;
3276
f5ea9120 3277 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3278 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3279
3280 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3281 if (!bss)
3282 goto nla_put_failure;
3283 if (!is_zero_ether_addr(res->bssid))
3284 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3285 if (res->information_elements && res->len_information_elements)
3286 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3287 res->len_information_elements,
3288 res->information_elements);
34a6eddb
JM
3289 if (res->beacon_ies && res->len_beacon_ies &&
3290 res->beacon_ies != res->information_elements)
3291 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3292 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3293 if (res->tsf)
3294 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3295 if (res->beacon_interval)
3296 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3297 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3298 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3299 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3300 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3301
77965c97 3302 switch (rdev->wiphy.signal_type) {
2a519311
JB
3303 case CFG80211_SIGNAL_TYPE_MBM:
3304 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3305 break;
3306 case CFG80211_SIGNAL_TYPE_UNSPEC:
3307 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3308 break;
3309 default:
3310 break;
3311 }
3312
48ab905d 3313 switch (wdev->iftype) {
074ac8df 3314 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3315 case NL80211_IFTYPE_STATION:
3316 if (intbss == wdev->current_bss)
3317 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3318 NL80211_BSS_STATUS_ASSOCIATED);
3319 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3320 if (intbss != wdev->auth_bsses[i])
3321 continue;
3322 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3323 NL80211_BSS_STATUS_AUTHENTICATED);
3324 break;
3325 }
3326 break;
3327 case NL80211_IFTYPE_ADHOC:
3328 if (intbss == wdev->current_bss)
3329 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3330 NL80211_BSS_STATUS_IBSS_JOINED);
3331 break;
3332 default:
3333 break;
3334 }
3335
2a519311
JB
3336 nla_nest_end(msg, bss);
3337
3338 return genlmsg_end(msg, hdr);
3339
3340 nla_put_failure:
3341 genlmsg_cancel(msg, hdr);
3342 return -EMSGSIZE;
3343}
3344
3345static int nl80211_dump_scan(struct sk_buff *skb,
3346 struct netlink_callback *cb)
3347{
48ab905d
JB
3348 struct cfg80211_registered_device *rdev;
3349 struct net_device *dev;
2a519311 3350 struct cfg80211_internal_bss *scan;
48ab905d 3351 struct wireless_dev *wdev;
2a519311
JB
3352 int start = cb->args[1], idx = 0;
3353 int err;
3354
67748893
JB
3355 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3356 if (err)
3357 return err;
2a519311 3358
48ab905d 3359 wdev = dev->ieee80211_ptr;
2a519311 3360
48ab905d
JB
3361 wdev_lock(wdev);
3362 spin_lock_bh(&rdev->bss_lock);
3363 cfg80211_bss_expire(rdev);
3364
3365 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3366 if (++idx <= start)
3367 continue;
3368 if (nl80211_send_bss(skb,
3369 NETLINK_CB(cb->skb).pid,
3370 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3371 rdev, wdev, scan) < 0) {
2a519311 3372 idx--;
67748893 3373 break;
2a519311
JB
3374 }
3375 }
3376
48ab905d
JB
3377 spin_unlock_bh(&rdev->bss_lock);
3378 wdev_unlock(wdev);
2a519311
JB
3379
3380 cb->args[1] = idx;
67748893 3381 nl80211_finish_netdev_dump(rdev);
2a519311 3382
67748893 3383 return skb->len;
2a519311
JB
3384}
3385
61fa713c
HS
3386static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3387 int flags, struct net_device *dev,
3388 struct survey_info *survey)
3389{
3390 void *hdr;
3391 struct nlattr *infoattr;
3392
3393 /* Survey without a channel doesn't make sense */
3394 if (!survey->channel)
3395 return -EINVAL;
3396
3397 hdr = nl80211hdr_put(msg, pid, seq, flags,
3398 NL80211_CMD_NEW_SURVEY_RESULTS);
3399 if (!hdr)
3400 return -ENOMEM;
3401
3402 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3403
3404 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3405 if (!infoattr)
3406 goto nla_put_failure;
3407
3408 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3409 survey->channel->center_freq);
3410 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3411 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3412 survey->noise);
17e5a808
FF
3413 if (survey->filled & SURVEY_INFO_IN_USE)
3414 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
3415 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3416 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3417 survey->channel_time);
3418 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3419 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3420 survey->channel_time_busy);
3421 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3422 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3423 survey->channel_time_ext_busy);
3424 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3425 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3426 survey->channel_time_rx);
3427 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3428 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3429 survey->channel_time_tx);
61fa713c
HS
3430
3431 nla_nest_end(msg, infoattr);
3432
3433 return genlmsg_end(msg, hdr);
3434
3435 nla_put_failure:
3436 genlmsg_cancel(msg, hdr);
3437 return -EMSGSIZE;
3438}
3439
3440static int nl80211_dump_survey(struct sk_buff *skb,
3441 struct netlink_callback *cb)
3442{
3443 struct survey_info survey;
3444 struct cfg80211_registered_device *dev;
3445 struct net_device *netdev;
61fa713c
HS
3446 int survey_idx = cb->args[1];
3447 int res;
3448
67748893
JB
3449 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3450 if (res)
3451 return res;
61fa713c
HS
3452
3453 if (!dev->ops->dump_survey) {
3454 res = -EOPNOTSUPP;
3455 goto out_err;
3456 }
3457
3458 while (1) {
3459 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3460 &survey);
3461 if (res == -ENOENT)
3462 break;
3463 if (res)
3464 goto out_err;
3465
3466 if (nl80211_send_survey(skb,
3467 NETLINK_CB(cb->skb).pid,
3468 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3469 netdev,
3470 &survey) < 0)
3471 goto out;
3472 survey_idx++;
3473 }
3474
3475 out:
3476 cb->args[1] = survey_idx;
3477 res = skb->len;
3478 out_err:
67748893 3479 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3480 return res;
3481}
3482
255e737e
JM
3483static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3484{
b23aa676
SO
3485 return auth_type <= NL80211_AUTHTYPE_MAX;
3486}
3487
3488static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3489{
3490 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3491 NL80211_WPA_VERSION_2));
3492}
3493
3494static bool nl80211_valid_akm_suite(u32 akm)
3495{
3496 return akm == WLAN_AKM_SUITE_8021X ||
3497 akm == WLAN_AKM_SUITE_PSK;
3498}
3499
3500static bool nl80211_valid_cipher_suite(u32 cipher)
3501{
3502 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3503 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3504 cipher == WLAN_CIPHER_SUITE_TKIP ||
3505 cipher == WLAN_CIPHER_SUITE_CCMP ||
3506 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3507}
3508
b23aa676 3509
636a5d36
JM
3510static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3511{
4c476991
JB
3512 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3513 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3514 struct ieee80211_channel *chan;
3515 const u8 *bssid, *ssid, *ie = NULL;
3516 int err, ssid_len, ie_len = 0;
3517 enum nl80211_auth_type auth_type;
fffd0934 3518 struct key_parse key;
d5cdfacb 3519 bool local_state_change;
636a5d36 3520
f4a11bb0
JB
3521 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3522 return -EINVAL;
3523
3524 if (!info->attrs[NL80211_ATTR_MAC])
3525 return -EINVAL;
3526
1778092e
JM
3527 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3528 return -EINVAL;
3529
19957bb3
JB
3530 if (!info->attrs[NL80211_ATTR_SSID])
3531 return -EINVAL;
3532
3533 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3534 return -EINVAL;
3535
fffd0934
JB
3536 err = nl80211_parse_key(info, &key);
3537 if (err)
3538 return err;
3539
3540 if (key.idx >= 0) {
e31b8213
JB
3541 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3542 return -EINVAL;
fffd0934
JB
3543 if (!key.p.key || !key.p.key_len)
3544 return -EINVAL;
3545 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3546 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3547 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3548 key.p.key_len != WLAN_KEY_LEN_WEP104))
3549 return -EINVAL;
3550 if (key.idx > 4)
3551 return -EINVAL;
3552 } else {
3553 key.p.key_len = 0;
3554 key.p.key = NULL;
3555 }
3556
afea0b7a
JB
3557 if (key.idx >= 0) {
3558 int i;
3559 bool ok = false;
3560 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3561 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3562 ok = true;
3563 break;
3564 }
3565 }
4c476991
JB
3566 if (!ok)
3567 return -EINVAL;
afea0b7a
JB
3568 }
3569
4c476991
JB
3570 if (!rdev->ops->auth)
3571 return -EOPNOTSUPP;
636a5d36 3572
074ac8df 3573 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3574 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3575 return -EOPNOTSUPP;
eec60b03 3576
19957bb3 3577 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3578 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3579 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3580 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3581 return -EINVAL;
636a5d36 3582
19957bb3
JB
3583 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3584 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3585
3586 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3587 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3588 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3589 }
3590
19957bb3 3591 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3592 if (!nl80211_valid_auth_type(auth_type))
3593 return -EINVAL;
636a5d36 3594
d5cdfacb
JM
3595 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3596
4c476991
JB
3597 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3598 ssid, ssid_len, ie, ie_len,
3599 key.p.key, key.p.key_len, key.idx,
3600 local_state_change);
636a5d36
JM
3601}
3602
c0692b8f
JB
3603static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3604 struct genl_info *info,
3dc27d25
JB
3605 struct cfg80211_crypto_settings *settings,
3606 int cipher_limit)
b23aa676 3607{
c0b2bbd8
JB
3608 memset(settings, 0, sizeof(*settings));
3609
b23aa676
SO
3610 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3611
c0692b8f
JB
3612 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3613 u16 proto;
3614 proto = nla_get_u16(
3615 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3616 settings->control_port_ethertype = cpu_to_be16(proto);
3617 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3618 proto != ETH_P_PAE)
3619 return -EINVAL;
3620 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3621 settings->control_port_no_encrypt = true;
3622 } else
3623 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3624
b23aa676
SO
3625 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3626 void *data;
3627 int len, i;
3628
3629 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3630 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3631 settings->n_ciphers_pairwise = len / sizeof(u32);
3632
3633 if (len % sizeof(u32))
3634 return -EINVAL;
3635
3dc27d25 3636 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3637 return -EINVAL;
3638
3639 memcpy(settings->ciphers_pairwise, data, len);
3640
3641 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3642 if (!nl80211_valid_cipher_suite(
3643 settings->ciphers_pairwise[i]))
3644 return -EINVAL;
3645 }
3646
3647 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3648 settings->cipher_group =
3649 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3650 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3651 return -EINVAL;
3652 }
3653
3654 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3655 settings->wpa_versions =
3656 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3657 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3658 return -EINVAL;
3659 }
3660
3661 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3662 void *data;
3663 int len, i;
3664
3665 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3666 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3667 settings->n_akm_suites = len / sizeof(u32);
3668
3669 if (len % sizeof(u32))
3670 return -EINVAL;
3671
3672 memcpy(settings->akm_suites, data, len);
3673
3674 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3675 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3676 return -EINVAL;
3677 }
3678
3679 return 0;
3680}
3681
636a5d36
JM
3682static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3683{
4c476991
JB
3684 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3685 struct net_device *dev = info->user_ptr[1];
19957bb3 3686 struct cfg80211_crypto_settings crypto;
f444de05 3687 struct ieee80211_channel *chan;
3e5d7649 3688 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3689 int err, ssid_len, ie_len = 0;
3690 bool use_mfp = false;
636a5d36 3691
f4a11bb0
JB
3692 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3693 return -EINVAL;
3694
3695 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3696 !info->attrs[NL80211_ATTR_SSID] ||
3697 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3698 return -EINVAL;
3699
4c476991
JB
3700 if (!rdev->ops->assoc)
3701 return -EOPNOTSUPP;
636a5d36 3702
074ac8df 3703 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3704 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3705 return -EOPNOTSUPP;
eec60b03 3706
19957bb3 3707 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3708
19957bb3
JB
3709 chan = ieee80211_get_channel(&rdev->wiphy,
3710 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3711 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3712 return -EINVAL;
636a5d36 3713
19957bb3
JB
3714 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3715 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3716
3717 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3718 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3719 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3720 }
3721
dc6382ce 3722 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3723 enum nl80211_mfp mfp =
dc6382ce 3724 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3725 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3726 use_mfp = true;
4c476991
JB
3727 else if (mfp != NL80211_MFP_NO)
3728 return -EINVAL;
dc6382ce
JM
3729 }
3730
3e5d7649
JB
3731 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3732 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3733
c0692b8f 3734 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3735 if (!err)
3e5d7649
JB
3736 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3737 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3738 &crypto);
636a5d36 3739
636a5d36
JM
3740 return err;
3741}
3742
3743static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3744{
4c476991
JB
3745 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3746 struct net_device *dev = info->user_ptr[1];
19957bb3 3747 const u8 *ie = NULL, *bssid;
4c476991 3748 int ie_len = 0;
19957bb3 3749 u16 reason_code;
d5cdfacb 3750 bool local_state_change;
636a5d36 3751
f4a11bb0
JB
3752 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3753 return -EINVAL;
3754
3755 if (!info->attrs[NL80211_ATTR_MAC])
3756 return -EINVAL;
3757
3758 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3759 return -EINVAL;
3760
4c476991
JB
3761 if (!rdev->ops->deauth)
3762 return -EOPNOTSUPP;
636a5d36 3763
074ac8df 3764 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3765 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3766 return -EOPNOTSUPP;
eec60b03 3767
19957bb3 3768 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3769
19957bb3
JB
3770 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3771 if (reason_code == 0) {
f4a11bb0 3772 /* Reason Code 0 is reserved */
4c476991 3773 return -EINVAL;
255e737e 3774 }
636a5d36
JM
3775
3776 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3777 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3778 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3779 }
3780
d5cdfacb
JM
3781 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3782
4c476991
JB
3783 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3784 local_state_change);
636a5d36
JM
3785}
3786
3787static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3788{
4c476991
JB
3789 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3790 struct net_device *dev = info->user_ptr[1];
19957bb3 3791 const u8 *ie = NULL, *bssid;
4c476991 3792 int ie_len = 0;
19957bb3 3793 u16 reason_code;
d5cdfacb 3794 bool local_state_change;
636a5d36 3795
f4a11bb0
JB
3796 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3797 return -EINVAL;
3798
3799 if (!info->attrs[NL80211_ATTR_MAC])
3800 return -EINVAL;
3801
3802 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3803 return -EINVAL;
3804
4c476991
JB
3805 if (!rdev->ops->disassoc)
3806 return -EOPNOTSUPP;
636a5d36 3807
074ac8df 3808 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3809 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3810 return -EOPNOTSUPP;
eec60b03 3811
19957bb3 3812 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3813
19957bb3
JB
3814 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3815 if (reason_code == 0) {
f4a11bb0 3816 /* Reason Code 0 is reserved */
4c476991 3817 return -EINVAL;
255e737e 3818 }
636a5d36
JM
3819
3820 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3821 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3822 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3823 }
3824
d5cdfacb
JM
3825 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3826
4c476991
JB
3827 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3828 local_state_change);
636a5d36
JM
3829}
3830
dd5b4cc7
FF
3831static bool
3832nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3833 int mcast_rate[IEEE80211_NUM_BANDS],
3834 int rateval)
3835{
3836 struct wiphy *wiphy = &rdev->wiphy;
3837 bool found = false;
3838 int band, i;
3839
3840 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3841 struct ieee80211_supported_band *sband;
3842
3843 sband = wiphy->bands[band];
3844 if (!sband)
3845 continue;
3846
3847 for (i = 0; i < sband->n_bitrates; i++) {
3848 if (sband->bitrates[i].bitrate == rateval) {
3849 mcast_rate[band] = i + 1;
3850 found = true;
3851 break;
3852 }
3853 }
3854 }
3855
3856 return found;
3857}
3858
04a773ad
JB
3859static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3860{
4c476991
JB
3861 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3862 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
3863 struct cfg80211_ibss_params ibss;
3864 struct wiphy *wiphy;
fffd0934 3865 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3866 int err;
3867
8e30bc55
JB
3868 memset(&ibss, 0, sizeof(ibss));
3869
04a773ad
JB
3870 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3871 return -EINVAL;
3872
3873 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3874 !info->attrs[NL80211_ATTR_SSID] ||
3875 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3876 return -EINVAL;
3877
8e30bc55
JB
3878 ibss.beacon_interval = 100;
3879
3880 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3881 ibss.beacon_interval =
3882 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3883 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3884 return -EINVAL;
3885 }
3886
4c476991
JB
3887 if (!rdev->ops->join_ibss)
3888 return -EOPNOTSUPP;
04a773ad 3889
4c476991
JB
3890 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3891 return -EOPNOTSUPP;
04a773ad 3892
79c97e97 3893 wiphy = &rdev->wiphy;
04a773ad
JB
3894
3895 if (info->attrs[NL80211_ATTR_MAC])
3896 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3897 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3898 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3899
3900 if (info->attrs[NL80211_ATTR_IE]) {
3901 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3902 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3903 }
3904
3905 ibss.channel = ieee80211_get_channel(wiphy,
3906 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3907 if (!ibss.channel ||
3908 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
3909 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
3910 return -EINVAL;
04a773ad
JB
3911
3912 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3913 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3914
fbd2c8dc
TP
3915 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3916 u8 *rates =
3917 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3918 int n_rates =
3919 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3920 struct ieee80211_supported_band *sband =
3921 wiphy->bands[ibss.channel->band];
3922 int i, j;
3923
4c476991
JB
3924 if (n_rates == 0)
3925 return -EINVAL;
fbd2c8dc
TP
3926
3927 for (i = 0; i < n_rates; i++) {
3928 int rate = (rates[i] & 0x7f) * 5;
3929 bool found = false;
3930
3931 for (j = 0; j < sband->n_bitrates; j++) {
3932 if (sband->bitrates[j].bitrate == rate) {
3933 found = true;
3934 ibss.basic_rates |= BIT(j);
3935 break;
3936 }
3937 }
4c476991
JB
3938 if (!found)
3939 return -EINVAL;
fbd2c8dc 3940 }
fbd2c8dc 3941 }
dd5b4cc7
FF
3942
3943 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
3944 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
3945 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
3946 return -EINVAL;
fbd2c8dc 3947
4c476991
JB
3948 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3949 connkeys = nl80211_parse_connkeys(rdev,
3950 info->attrs[NL80211_ATTR_KEYS]);
3951 if (IS_ERR(connkeys))
3952 return PTR_ERR(connkeys);
3953 }
04a773ad 3954
4c476991 3955 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
3956 if (err)
3957 kfree(connkeys);
04a773ad
JB
3958 return err;
3959}
3960
3961static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3962{
4c476991
JB
3963 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3964 struct net_device *dev = info->user_ptr[1];
04a773ad 3965
4c476991
JB
3966 if (!rdev->ops->leave_ibss)
3967 return -EOPNOTSUPP;
04a773ad 3968
4c476991
JB
3969 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3970 return -EOPNOTSUPP;
04a773ad 3971
4c476991 3972 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3973}
3974
aff89a9b
JB
3975#ifdef CONFIG_NL80211_TESTMODE
3976static struct genl_multicast_group nl80211_testmode_mcgrp = {
3977 .name = "testmode",
3978};
3979
3980static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3981{
4c476991 3982 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
3983 int err;
3984
3985 if (!info->attrs[NL80211_ATTR_TESTDATA])
3986 return -EINVAL;
3987
aff89a9b
JB
3988 err = -EOPNOTSUPP;
3989 if (rdev->ops->testmode_cmd) {
3990 rdev->testmode_info = info;
3991 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3992 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3993 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3994 rdev->testmode_info = NULL;
3995 }
3996
aff89a9b
JB
3997 return err;
3998}
3999
4000static struct sk_buff *
4001__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4002 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4003{
4004 struct sk_buff *skb;
4005 void *hdr;
4006 struct nlattr *data;
4007
4008 skb = nlmsg_new(approxlen + 100, gfp);
4009 if (!skb)
4010 return NULL;
4011
4012 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4013 if (!hdr) {
4014 kfree_skb(skb);
4015 return NULL;
4016 }
4017
4018 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4019 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4020
4021 ((void **)skb->cb)[0] = rdev;
4022 ((void **)skb->cb)[1] = hdr;
4023 ((void **)skb->cb)[2] = data;
4024
4025 return skb;
4026
4027 nla_put_failure:
4028 kfree_skb(skb);
4029 return NULL;
4030}
4031
4032struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4033 int approxlen)
4034{
4035 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4036
4037 if (WARN_ON(!rdev->testmode_info))
4038 return NULL;
4039
4040 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4041 rdev->testmode_info->snd_pid,
4042 rdev->testmode_info->snd_seq,
4043 GFP_KERNEL);
4044}
4045EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4046
4047int cfg80211_testmode_reply(struct sk_buff *skb)
4048{
4049 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4050 void *hdr = ((void **)skb->cb)[1];
4051 struct nlattr *data = ((void **)skb->cb)[2];
4052
4053 if (WARN_ON(!rdev->testmode_info)) {
4054 kfree_skb(skb);
4055 return -EINVAL;
4056 }
4057
4058 nla_nest_end(skb, data);
4059 genlmsg_end(skb, hdr);
4060 return genlmsg_reply(skb, rdev->testmode_info);
4061}
4062EXPORT_SYMBOL(cfg80211_testmode_reply);
4063
4064struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4065 int approxlen, gfp_t gfp)
4066{
4067 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4068
4069 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4070}
4071EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4072
4073void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4074{
4075 void *hdr = ((void **)skb->cb)[1];
4076 struct nlattr *data = ((void **)skb->cb)[2];
4077
4078 nla_nest_end(skb, data);
4079 genlmsg_end(skb, hdr);
4080 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4081}
4082EXPORT_SYMBOL(cfg80211_testmode_event);
4083#endif
4084
b23aa676
SO
4085static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4086{
4c476991
JB
4087 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4088 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4089 struct cfg80211_connect_params connect;
4090 struct wiphy *wiphy;
fffd0934 4091 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4092 int err;
4093
4094 memset(&connect, 0, sizeof(connect));
4095
4096 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4097 return -EINVAL;
4098
4099 if (!info->attrs[NL80211_ATTR_SSID] ||
4100 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4101 return -EINVAL;
4102
4103 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4104 connect.auth_type =
4105 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4106 if (!nl80211_valid_auth_type(connect.auth_type))
4107 return -EINVAL;
4108 } else
4109 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4110
4111 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4112
c0692b8f 4113 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4114 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4115 if (err)
4116 return err;
b23aa676 4117
074ac8df 4118 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4119 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4120 return -EOPNOTSUPP;
b23aa676 4121
79c97e97 4122 wiphy = &rdev->wiphy;
b23aa676 4123
b23aa676
SO
4124 if (info->attrs[NL80211_ATTR_MAC])
4125 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4126 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4127 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4128
4129 if (info->attrs[NL80211_ATTR_IE]) {
4130 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4131 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4132 }
4133
4134 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4135 connect.channel =
4136 ieee80211_get_channel(wiphy,
4137 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4138 if (!connect.channel ||
4c476991
JB
4139 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4140 return -EINVAL;
b23aa676
SO
4141 }
4142
fffd0934
JB
4143 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4144 connkeys = nl80211_parse_connkeys(rdev,
4145 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4146 if (IS_ERR(connkeys))
4147 return PTR_ERR(connkeys);
fffd0934
JB
4148 }
4149
4150 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4151 if (err)
4152 kfree(connkeys);
b23aa676
SO
4153 return err;
4154}
4155
4156static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4157{
4c476991
JB
4158 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4159 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4160 u16 reason;
4161
4162 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4163 reason = WLAN_REASON_DEAUTH_LEAVING;
4164 else
4165 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4166
4167 if (reason == 0)
4168 return -EINVAL;
4169
074ac8df 4170 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4171 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4172 return -EOPNOTSUPP;
b23aa676 4173
4c476991 4174 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4175}
4176
463d0183
JB
4177static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4178{
4c476991 4179 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4180 struct net *net;
4181 int err;
4182 u32 pid;
4183
4184 if (!info->attrs[NL80211_ATTR_PID])
4185 return -EINVAL;
4186
4187 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4188
463d0183 4189 net = get_net_ns_by_pid(pid);
4c476991
JB
4190 if (IS_ERR(net))
4191 return PTR_ERR(net);
463d0183
JB
4192
4193 err = 0;
4194
4195 /* check if anything to do */
4c476991
JB
4196 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4197 err = cfg80211_switch_netns(rdev, net);
463d0183 4198
463d0183 4199 put_net(net);
463d0183
JB
4200 return err;
4201}
4202
67fbb16b
SO
4203static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4204{
4c476991 4205 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4206 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4207 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4208 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4209 struct cfg80211_pmksa pmksa;
4210
4211 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4212
4213 if (!info->attrs[NL80211_ATTR_MAC])
4214 return -EINVAL;
4215
4216 if (!info->attrs[NL80211_ATTR_PMKID])
4217 return -EINVAL;
4218
67fbb16b
SO
4219 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4220 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4221
074ac8df 4222 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4223 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4224 return -EOPNOTSUPP;
67fbb16b
SO
4225
4226 switch (info->genlhdr->cmd) {
4227 case NL80211_CMD_SET_PMKSA:
4228 rdev_ops = rdev->ops->set_pmksa;
4229 break;
4230 case NL80211_CMD_DEL_PMKSA:
4231 rdev_ops = rdev->ops->del_pmksa;
4232 break;
4233 default:
4234 WARN_ON(1);
4235 break;
4236 }
4237
4c476991
JB
4238 if (!rdev_ops)
4239 return -EOPNOTSUPP;
67fbb16b 4240
4c476991 4241 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4242}
4243
4244static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4245{
4c476991
JB
4246 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4247 struct net_device *dev = info->user_ptr[1];
67fbb16b 4248
074ac8df 4249 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4250 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4251 return -EOPNOTSUPP;
67fbb16b 4252
4c476991
JB
4253 if (!rdev->ops->flush_pmksa)
4254 return -EOPNOTSUPP;
67fbb16b 4255
4c476991 4256 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
4257}
4258
9588bbd5
JM
4259static int nl80211_remain_on_channel(struct sk_buff *skb,
4260 struct genl_info *info)
4261{
4c476991
JB
4262 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4263 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
4264 struct ieee80211_channel *chan;
4265 struct sk_buff *msg;
4266 void *hdr;
4267 u64 cookie;
4268 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4269 u32 freq, duration;
4270 int err;
4271
4272 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4273 !info->attrs[NL80211_ATTR_DURATION])
4274 return -EINVAL;
4275
4276 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4277
4278 /*
4279 * We should be on that channel for at least one jiffie,
4280 * and more than 5 seconds seems excessive.
4281 */
a293911d
JB
4282 if (!duration || !msecs_to_jiffies(duration) ||
4283 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
4284 return -EINVAL;
4285
4c476991
JB
4286 if (!rdev->ops->remain_on_channel)
4287 return -EOPNOTSUPP;
9588bbd5 4288
9588bbd5
JM
4289 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4290 channel_type = nla_get_u32(
4291 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4292 if (channel_type != NL80211_CHAN_NO_HT &&
4293 channel_type != NL80211_CHAN_HT20 &&
4294 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4295 channel_type != NL80211_CHAN_HT40MINUS)
4296 return -EINVAL;
9588bbd5
JM
4297 }
4298
4299 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4300 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4301 if (chan == NULL)
4302 return -EINVAL;
9588bbd5
JM
4303
4304 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4305 if (!msg)
4306 return -ENOMEM;
9588bbd5
JM
4307
4308 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4309 NL80211_CMD_REMAIN_ON_CHANNEL);
4310
4311 if (IS_ERR(hdr)) {
4312 err = PTR_ERR(hdr);
4313 goto free_msg;
4314 }
4315
4316 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4317 channel_type, duration, &cookie);
4318
4319 if (err)
4320 goto free_msg;
4321
4322 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4323
4324 genlmsg_end(msg, hdr);
4c476991
JB
4325
4326 return genlmsg_reply(msg, info);
9588bbd5
JM
4327
4328 nla_put_failure:
4329 err = -ENOBUFS;
4330 free_msg:
4331 nlmsg_free(msg);
9588bbd5
JM
4332 return err;
4333}
4334
4335static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4336 struct genl_info *info)
4337{
4c476991
JB
4338 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4339 struct net_device *dev = info->user_ptr[1];
9588bbd5 4340 u64 cookie;
9588bbd5
JM
4341
4342 if (!info->attrs[NL80211_ATTR_COOKIE])
4343 return -EINVAL;
4344
4c476991
JB
4345 if (!rdev->ops->cancel_remain_on_channel)
4346 return -EOPNOTSUPP;
9588bbd5 4347
9588bbd5
JM
4348 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4349
4c476991 4350 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
4351}
4352
13ae75b1
JM
4353static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4354 u8 *rates, u8 rates_len)
4355{
4356 u8 i;
4357 u32 mask = 0;
4358
4359 for (i = 0; i < rates_len; i++) {
4360 int rate = (rates[i] & 0x7f) * 5;
4361 int ridx;
4362 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4363 struct ieee80211_rate *srate =
4364 &sband->bitrates[ridx];
4365 if (rate == srate->bitrate) {
4366 mask |= 1 << ridx;
4367 break;
4368 }
4369 }
4370 if (ridx == sband->n_bitrates)
4371 return 0; /* rate not found */
4372 }
4373
4374 return mask;
4375}
4376
b54452b0 4377static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4378 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4379 .len = NL80211_MAX_SUPP_RATES },
4380};
4381
4382static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4383 struct genl_info *info)
4384{
4385 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4386 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4387 struct cfg80211_bitrate_mask mask;
4c476991
JB
4388 int rem, i;
4389 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4390 struct nlattr *tx_rates;
4391 struct ieee80211_supported_band *sband;
4392
4393 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4394 return -EINVAL;
4395
4c476991
JB
4396 if (!rdev->ops->set_bitrate_mask)
4397 return -EOPNOTSUPP;
13ae75b1
JM
4398
4399 memset(&mask, 0, sizeof(mask));
4400 /* Default to all rates enabled */
4401 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4402 sband = rdev->wiphy.bands[i];
4403 mask.control[i].legacy =
4404 sband ? (1 << sband->n_bitrates) - 1 : 0;
4405 }
4406
4407 /*
4408 * The nested attribute uses enum nl80211_band as the index. This maps
4409 * directly to the enum ieee80211_band values used in cfg80211.
4410 */
4411 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4412 {
4413 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4414 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4415 return -EINVAL;
13ae75b1 4416 sband = rdev->wiphy.bands[band];
4c476991
JB
4417 if (sband == NULL)
4418 return -EINVAL;
13ae75b1
JM
4419 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4420 nla_len(tx_rates), nl80211_txattr_policy);
4421 if (tb[NL80211_TXRATE_LEGACY]) {
4422 mask.control[band].legacy = rateset_to_mask(
4423 sband,
4424 nla_data(tb[NL80211_TXRATE_LEGACY]),
4425 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4426 if (mask.control[band].legacy == 0)
4427 return -EINVAL;
13ae75b1
JM
4428 }
4429 }
4430
4c476991 4431 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4432}
4433
2e161f78 4434static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4435{
4c476991
JB
4436 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4437 struct net_device *dev = info->user_ptr[1];
2e161f78 4438 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4439
4440 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4441 return -EINVAL;
4442
2e161f78
JB
4443 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4444 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4445
9d38d85d 4446 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4447 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4448 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4449 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4450 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4451 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4452 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4453 return -EOPNOTSUPP;
026331c4
JM
4454
4455 /* not much point in registering if we can't reply */
4c476991
JB
4456 if (!rdev->ops->mgmt_tx)
4457 return -EOPNOTSUPP;
026331c4 4458
4c476991 4459 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4460 frame_type,
026331c4
JM
4461 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4462 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4463}
4464
2e161f78 4465static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4466{
4c476991
JB
4467 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4468 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4469 struct ieee80211_channel *chan;
4470 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4471 bool channel_type_valid = false;
026331c4
JM
4472 u32 freq;
4473 int err;
4474 void *hdr;
4475 u64 cookie;
4476 struct sk_buff *msg;
f7ca38df
JB
4477 unsigned int wait = 0;
4478 bool offchan;
026331c4
JM
4479
4480 if (!info->attrs[NL80211_ATTR_FRAME] ||
4481 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4482 return -EINVAL;
4483
4c476991
JB
4484 if (!rdev->ops->mgmt_tx)
4485 return -EOPNOTSUPP;
026331c4 4486
9d38d85d 4487 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4488 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4489 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4490 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4491 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4492 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4493 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4494 return -EOPNOTSUPP;
026331c4 4495
f7ca38df
JB
4496 if (info->attrs[NL80211_ATTR_DURATION]) {
4497 if (!rdev->ops->mgmt_tx_cancel_wait)
4498 return -EINVAL;
4499 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4500 }
4501
026331c4
JM
4502 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4503 channel_type = nla_get_u32(
4504 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4505 if (channel_type != NL80211_CHAN_NO_HT &&
4506 channel_type != NL80211_CHAN_HT20 &&
4507 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4508 channel_type != NL80211_CHAN_HT40MINUS)
4509 return -EINVAL;
252aa631 4510 channel_type_valid = true;
026331c4
JM
4511 }
4512
f7ca38df
JB
4513 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4514
026331c4
JM
4515 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4516 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4517 if (chan == NULL)
4518 return -EINVAL;
026331c4
JM
4519
4520 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4521 if (!msg)
4522 return -ENOMEM;
026331c4
JM
4523
4524 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4525 NL80211_CMD_FRAME);
026331c4
JM
4526
4527 if (IS_ERR(hdr)) {
4528 err = PTR_ERR(hdr);
4529 goto free_msg;
4530 }
f7ca38df
JB
4531 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4532 channel_type_valid, wait,
2e161f78
JB
4533 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4534 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4535 &cookie);
026331c4
JM
4536 if (err)
4537 goto free_msg;
4538
4539 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4540
4541 genlmsg_end(msg, hdr);
4c476991 4542 return genlmsg_reply(msg, info);
026331c4
JM
4543
4544 nla_put_failure:
4545 err = -ENOBUFS;
4546 free_msg:
4547 nlmsg_free(msg);
026331c4
JM
4548 return err;
4549}
4550
f7ca38df
JB
4551static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4552{
4553 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4554 struct net_device *dev = info->user_ptr[1];
4555 u64 cookie;
4556
4557 if (!info->attrs[NL80211_ATTR_COOKIE])
4558 return -EINVAL;
4559
4560 if (!rdev->ops->mgmt_tx_cancel_wait)
4561 return -EOPNOTSUPP;
4562
4563 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4564 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4565 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4566 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4567 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4568 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4569 return -EOPNOTSUPP;
4570
4571 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4572
4573 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4574}
4575
ffb9eb3d
KV
4576static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4577{
4c476991 4578 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4579 struct wireless_dev *wdev;
4c476991 4580 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4581 u8 ps_state;
4582 bool state;
4583 int err;
4584
4c476991
JB
4585 if (!info->attrs[NL80211_ATTR_PS_STATE])
4586 return -EINVAL;
ffb9eb3d
KV
4587
4588 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4589
4c476991
JB
4590 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4591 return -EINVAL;
ffb9eb3d
KV
4592
4593 wdev = dev->ieee80211_ptr;
4594
4c476991
JB
4595 if (!rdev->ops->set_power_mgmt)
4596 return -EOPNOTSUPP;
ffb9eb3d
KV
4597
4598 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4599
4600 if (state == wdev->ps)
4c476991 4601 return 0;
ffb9eb3d 4602
4c476991
JB
4603 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4604 wdev->ps_timeout);
4605 if (!err)
4606 wdev->ps = state;
ffb9eb3d
KV
4607 return err;
4608}
4609
4610static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4611{
4c476991 4612 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4613 enum nl80211_ps_state ps_state;
4614 struct wireless_dev *wdev;
4c476991 4615 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4616 struct sk_buff *msg;
4617 void *hdr;
4618 int err;
4619
ffb9eb3d
KV
4620 wdev = dev->ieee80211_ptr;
4621
4c476991
JB
4622 if (!rdev->ops->set_power_mgmt)
4623 return -EOPNOTSUPP;
ffb9eb3d
KV
4624
4625 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4626 if (!msg)
4627 return -ENOMEM;
ffb9eb3d
KV
4628
4629 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4630 NL80211_CMD_GET_POWER_SAVE);
4631 if (!hdr) {
4c476991 4632 err = -ENOBUFS;
ffb9eb3d
KV
4633 goto free_msg;
4634 }
4635
4636 if (wdev->ps)
4637 ps_state = NL80211_PS_ENABLED;
4638 else
4639 ps_state = NL80211_PS_DISABLED;
4640
4641 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4642
4643 genlmsg_end(msg, hdr);
4c476991 4644 return genlmsg_reply(msg, info);
ffb9eb3d 4645
4c476991 4646 nla_put_failure:
ffb9eb3d 4647 err = -ENOBUFS;
4c476991 4648 free_msg:
ffb9eb3d 4649 nlmsg_free(msg);
ffb9eb3d
KV
4650 return err;
4651}
4652
d6dc1a38
JO
4653static struct nla_policy
4654nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4655 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4656 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4657 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4658};
4659
4660static int nl80211_set_cqm_rssi(struct genl_info *info,
4661 s32 threshold, u32 hysteresis)
4662{
4c476991 4663 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4664 struct wireless_dev *wdev;
4c476991 4665 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4666
4667 if (threshold > 0)
4668 return -EINVAL;
4669
d6dc1a38
JO
4670 wdev = dev->ieee80211_ptr;
4671
4c476991
JB
4672 if (!rdev->ops->set_cqm_rssi_config)
4673 return -EOPNOTSUPP;
d6dc1a38 4674
074ac8df 4675 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4676 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4677 return -EOPNOTSUPP;
d6dc1a38 4678
4c476991
JB
4679 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4680 threshold, hysteresis);
d6dc1a38
JO
4681}
4682
4683static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4684{
4685 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4686 struct nlattr *cqm;
4687 int err;
4688
4689 cqm = info->attrs[NL80211_ATTR_CQM];
4690 if (!cqm) {
4691 err = -EINVAL;
4692 goto out;
4693 }
4694
4695 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4696 nl80211_attr_cqm_policy);
4697 if (err)
4698 goto out;
4699
4700 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4701 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4702 s32 threshold;
4703 u32 hysteresis;
4704 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4705 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4706 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4707 } else
4708 err = -EINVAL;
4709
4710out:
4711 return err;
4712}
4713
29cbe68c
JB
4714static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
4715{
4716 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4717 struct net_device *dev = info->user_ptr[1];
4718 struct mesh_config cfg;
c80d545d 4719 struct mesh_setup setup;
29cbe68c
JB
4720 int err;
4721
4722 /* start with default */
4723 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 4724 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 4725
24bdd9f4 4726 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 4727 /* and parse parameters if given */
24bdd9f4 4728 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
4729 if (err)
4730 return err;
4731 }
4732
4733 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
4734 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
4735 return -EINVAL;
4736
c80d545d
JC
4737 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
4738 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4739
4740 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
4741 /* parse additional setup parameters if given */
4742 err = nl80211_parse_mesh_setup(info, &setup);
4743 if (err)
4744 return err;
4745 }
4746
4747 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
4748}
4749
4750static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
4751{
4752 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4753 struct net_device *dev = info->user_ptr[1];
4754
4755 return cfg80211_leave_mesh(rdev, dev);
4756}
4757
4c476991
JB
4758#define NL80211_FLAG_NEED_WIPHY 0x01
4759#define NL80211_FLAG_NEED_NETDEV 0x02
4760#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
4761#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
4762#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
4763 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
4764
4765static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
4766 struct genl_info *info)
4767{
4768 struct cfg80211_registered_device *rdev;
4769 struct net_device *dev;
4770 int err;
4771 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
4772
4773 if (rtnl)
4774 rtnl_lock();
4775
4776 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4777 rdev = cfg80211_get_dev_from_info(info);
4778 if (IS_ERR(rdev)) {
4779 if (rtnl)
4780 rtnl_unlock();
4781 return PTR_ERR(rdev);
4782 }
4783 info->user_ptr[0] = rdev;
4784 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
4785 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4786 if (err) {
4787 if (rtnl)
4788 rtnl_unlock();
4789 return err;
4790 }
41265714
JB
4791 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
4792 !netif_running(dev)) {
d537f5fd
JB
4793 cfg80211_unlock_rdev(rdev);
4794 dev_put(dev);
41265714
JB
4795 if (rtnl)
4796 rtnl_unlock();
4797 return -ENETDOWN;
4798 }
4c476991
JB
4799 info->user_ptr[0] = rdev;
4800 info->user_ptr[1] = dev;
4801 }
4802
4803 return 0;
4804}
4805
4806static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
4807 struct genl_info *info)
4808{
4809 if (info->user_ptr[0])
4810 cfg80211_unlock_rdev(info->user_ptr[0]);
4811 if (info->user_ptr[1])
4812 dev_put(info->user_ptr[1]);
4813 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
4814 rtnl_unlock();
4815}
4816
55682965
JB
4817static struct genl_ops nl80211_ops[] = {
4818 {
4819 .cmd = NL80211_CMD_GET_WIPHY,
4820 .doit = nl80211_get_wiphy,
4821 .dumpit = nl80211_dump_wiphy,
4822 .policy = nl80211_policy,
4823 /* can be retrieved by unprivileged users */
4c476991 4824 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
4825 },
4826 {
4827 .cmd = NL80211_CMD_SET_WIPHY,
4828 .doit = nl80211_set_wiphy,
4829 .policy = nl80211_policy,
4830 .flags = GENL_ADMIN_PERM,
4c476991 4831 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
4832 },
4833 {
4834 .cmd = NL80211_CMD_GET_INTERFACE,
4835 .doit = nl80211_get_interface,
4836 .dumpit = nl80211_dump_interface,
4837 .policy = nl80211_policy,
4838 /* can be retrieved by unprivileged users */
4c476991 4839 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
4840 },
4841 {
4842 .cmd = NL80211_CMD_SET_INTERFACE,
4843 .doit = nl80211_set_interface,
4844 .policy = nl80211_policy,
4845 .flags = GENL_ADMIN_PERM,
4c476991
JB
4846 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4847 NL80211_FLAG_NEED_RTNL,
55682965
JB
4848 },
4849 {
4850 .cmd = NL80211_CMD_NEW_INTERFACE,
4851 .doit = nl80211_new_interface,
4852 .policy = nl80211_policy,
4853 .flags = GENL_ADMIN_PERM,
4c476991
JB
4854 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4855 NL80211_FLAG_NEED_RTNL,
55682965
JB
4856 },
4857 {
4858 .cmd = NL80211_CMD_DEL_INTERFACE,
4859 .doit = nl80211_del_interface,
4860 .policy = nl80211_policy,
41ade00f 4861 .flags = GENL_ADMIN_PERM,
4c476991
JB
4862 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4863 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4864 },
4865 {
4866 .cmd = NL80211_CMD_GET_KEY,
4867 .doit = nl80211_get_key,
4868 .policy = nl80211_policy,
4869 .flags = GENL_ADMIN_PERM,
4c476991
JB
4870 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4871 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4872 },
4873 {
4874 .cmd = NL80211_CMD_SET_KEY,
4875 .doit = nl80211_set_key,
4876 .policy = nl80211_policy,
4877 .flags = GENL_ADMIN_PERM,
41265714 4878 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4879 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4880 },
4881 {
4882 .cmd = NL80211_CMD_NEW_KEY,
4883 .doit = nl80211_new_key,
4884 .policy = nl80211_policy,
4885 .flags = GENL_ADMIN_PERM,
41265714 4886 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4887 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4888 },
4889 {
4890 .cmd = NL80211_CMD_DEL_KEY,
4891 .doit = nl80211_del_key,
4892 .policy = nl80211_policy,
55682965 4893 .flags = GENL_ADMIN_PERM,
41265714 4894 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4895 NL80211_FLAG_NEED_RTNL,
55682965 4896 },
ed1b6cc7
JB
4897 {
4898 .cmd = NL80211_CMD_SET_BEACON,
4899 .policy = nl80211_policy,
4900 .flags = GENL_ADMIN_PERM,
4901 .doit = nl80211_addset_beacon,
4c476991
JB
4902 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4903 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4904 },
4905 {
4906 .cmd = NL80211_CMD_NEW_BEACON,
4907 .policy = nl80211_policy,
4908 .flags = GENL_ADMIN_PERM,
4909 .doit = nl80211_addset_beacon,
4c476991
JB
4910 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4911 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4912 },
4913 {
4914 .cmd = NL80211_CMD_DEL_BEACON,
4915 .policy = nl80211_policy,
4916 .flags = GENL_ADMIN_PERM,
4917 .doit = nl80211_del_beacon,
4c476991
JB
4918 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4919 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 4920 },
5727ef1b
JB
4921 {
4922 .cmd = NL80211_CMD_GET_STATION,
4923 .doit = nl80211_get_station,
2ec600d6 4924 .dumpit = nl80211_dump_station,
5727ef1b 4925 .policy = nl80211_policy,
4c476991
JB
4926 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4927 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4928 },
4929 {
4930 .cmd = NL80211_CMD_SET_STATION,
4931 .doit = nl80211_set_station,
4932 .policy = nl80211_policy,
4933 .flags = GENL_ADMIN_PERM,
4c476991
JB
4934 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4935 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4936 },
4937 {
4938 .cmd = NL80211_CMD_NEW_STATION,
4939 .doit = nl80211_new_station,
4940 .policy = nl80211_policy,
4941 .flags = GENL_ADMIN_PERM,
41265714 4942 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4943 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4944 },
4945 {
4946 .cmd = NL80211_CMD_DEL_STATION,
4947 .doit = nl80211_del_station,
4948 .policy = nl80211_policy,
2ec600d6 4949 .flags = GENL_ADMIN_PERM,
4c476991
JB
4950 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4951 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4952 },
4953 {
4954 .cmd = NL80211_CMD_GET_MPATH,
4955 .doit = nl80211_get_mpath,
4956 .dumpit = nl80211_dump_mpath,
4957 .policy = nl80211_policy,
4958 .flags = GENL_ADMIN_PERM,
41265714 4959 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4960 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4961 },
4962 {
4963 .cmd = NL80211_CMD_SET_MPATH,
4964 .doit = nl80211_set_mpath,
4965 .policy = nl80211_policy,
4966 .flags = GENL_ADMIN_PERM,
41265714 4967 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4968 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4969 },
4970 {
4971 .cmd = NL80211_CMD_NEW_MPATH,
4972 .doit = nl80211_new_mpath,
4973 .policy = nl80211_policy,
4974 .flags = GENL_ADMIN_PERM,
41265714 4975 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4976 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4977 },
4978 {
4979 .cmd = NL80211_CMD_DEL_MPATH,
4980 .doit = nl80211_del_mpath,
4981 .policy = nl80211_policy,
9f1ba906 4982 .flags = GENL_ADMIN_PERM,
4c476991
JB
4983 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4984 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
4985 },
4986 {
4987 .cmd = NL80211_CMD_SET_BSS,
4988 .doit = nl80211_set_bss,
4989 .policy = nl80211_policy,
b2e1b302 4990 .flags = GENL_ADMIN_PERM,
4c476991
JB
4991 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4992 NL80211_FLAG_NEED_RTNL,
b2e1b302 4993 },
f130347c
LR
4994 {
4995 .cmd = NL80211_CMD_GET_REG,
4996 .doit = nl80211_get_reg,
4997 .policy = nl80211_policy,
4998 /* can be retrieved by unprivileged users */
4999 },
b2e1b302
LR
5000 {
5001 .cmd = NL80211_CMD_SET_REG,
5002 .doit = nl80211_set_reg,
5003 .policy = nl80211_policy,
5004 .flags = GENL_ADMIN_PERM,
5005 },
5006 {
5007 .cmd = NL80211_CMD_REQ_SET_REG,
5008 .doit = nl80211_req_set_reg,
5009 .policy = nl80211_policy,
93da9cc1 5010 .flags = GENL_ADMIN_PERM,
5011 },
5012 {
24bdd9f4
JC
5013 .cmd = NL80211_CMD_GET_MESH_CONFIG,
5014 .doit = nl80211_get_mesh_config,
93da9cc1 5015 .policy = nl80211_policy,
5016 /* can be retrieved by unprivileged users */
4c476991
JB
5017 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5018 NL80211_FLAG_NEED_RTNL,
93da9cc1 5019 },
5020 {
24bdd9f4
JC
5021 .cmd = NL80211_CMD_SET_MESH_CONFIG,
5022 .doit = nl80211_update_mesh_config,
93da9cc1 5023 .policy = nl80211_policy,
9aed3cc1 5024 .flags = GENL_ADMIN_PERM,
29cbe68c 5025 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5026 NL80211_FLAG_NEED_RTNL,
9aed3cc1 5027 },
2a519311
JB
5028 {
5029 .cmd = NL80211_CMD_TRIGGER_SCAN,
5030 .doit = nl80211_trigger_scan,
5031 .policy = nl80211_policy,
5032 .flags = GENL_ADMIN_PERM,
41265714 5033 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5034 NL80211_FLAG_NEED_RTNL,
2a519311
JB
5035 },
5036 {
5037 .cmd = NL80211_CMD_GET_SCAN,
5038 .policy = nl80211_policy,
5039 .dumpit = nl80211_dump_scan,
5040 },
636a5d36
JM
5041 {
5042 .cmd = NL80211_CMD_AUTHENTICATE,
5043 .doit = nl80211_authenticate,
5044 .policy = nl80211_policy,
5045 .flags = GENL_ADMIN_PERM,
41265714 5046 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5047 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5048 },
5049 {
5050 .cmd = NL80211_CMD_ASSOCIATE,
5051 .doit = nl80211_associate,
5052 .policy = nl80211_policy,
5053 .flags = GENL_ADMIN_PERM,
41265714 5054 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5055 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5056 },
5057 {
5058 .cmd = NL80211_CMD_DEAUTHENTICATE,
5059 .doit = nl80211_deauthenticate,
5060 .policy = nl80211_policy,
5061 .flags = GENL_ADMIN_PERM,
41265714 5062 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5063 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5064 },
5065 {
5066 .cmd = NL80211_CMD_DISASSOCIATE,
5067 .doit = nl80211_disassociate,
5068 .policy = nl80211_policy,
5069 .flags = GENL_ADMIN_PERM,
41265714 5070 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5071 NL80211_FLAG_NEED_RTNL,
636a5d36 5072 },
04a773ad
JB
5073 {
5074 .cmd = NL80211_CMD_JOIN_IBSS,
5075 .doit = nl80211_join_ibss,
5076 .policy = nl80211_policy,
5077 .flags = GENL_ADMIN_PERM,
41265714 5078 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5079 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
5080 },
5081 {
5082 .cmd = NL80211_CMD_LEAVE_IBSS,
5083 .doit = nl80211_leave_ibss,
5084 .policy = nl80211_policy,
5085 .flags = GENL_ADMIN_PERM,
41265714 5086 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5087 NL80211_FLAG_NEED_RTNL,
04a773ad 5088 },
aff89a9b
JB
5089#ifdef CONFIG_NL80211_TESTMODE
5090 {
5091 .cmd = NL80211_CMD_TESTMODE,
5092 .doit = nl80211_testmode_do,
5093 .policy = nl80211_policy,
5094 .flags = GENL_ADMIN_PERM,
4c476991
JB
5095 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5096 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
5097 },
5098#endif
b23aa676
SO
5099 {
5100 .cmd = NL80211_CMD_CONNECT,
5101 .doit = nl80211_connect,
5102 .policy = nl80211_policy,
5103 .flags = GENL_ADMIN_PERM,
41265714 5104 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5105 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
5106 },
5107 {
5108 .cmd = NL80211_CMD_DISCONNECT,
5109 .doit = nl80211_disconnect,
5110 .policy = nl80211_policy,
5111 .flags = GENL_ADMIN_PERM,
41265714 5112 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5113 NL80211_FLAG_NEED_RTNL,
b23aa676 5114 },
463d0183
JB
5115 {
5116 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5117 .doit = nl80211_wiphy_netns,
5118 .policy = nl80211_policy,
5119 .flags = GENL_ADMIN_PERM,
4c476991
JB
5120 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5121 NL80211_FLAG_NEED_RTNL,
463d0183 5122 },
61fa713c
HS
5123 {
5124 .cmd = NL80211_CMD_GET_SURVEY,
5125 .policy = nl80211_policy,
5126 .dumpit = nl80211_dump_survey,
5127 },
67fbb16b
SO
5128 {
5129 .cmd = NL80211_CMD_SET_PMKSA,
5130 .doit = nl80211_setdel_pmksa,
5131 .policy = nl80211_policy,
5132 .flags = GENL_ADMIN_PERM,
4c476991
JB
5133 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5134 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5135 },
5136 {
5137 .cmd = NL80211_CMD_DEL_PMKSA,
5138 .doit = nl80211_setdel_pmksa,
5139 .policy = nl80211_policy,
5140 .flags = GENL_ADMIN_PERM,
4c476991
JB
5141 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5142 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5143 },
5144 {
5145 .cmd = NL80211_CMD_FLUSH_PMKSA,
5146 .doit = nl80211_flush_pmksa,
5147 .policy = nl80211_policy,
5148 .flags = GENL_ADMIN_PERM,
4c476991
JB
5149 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5150 NL80211_FLAG_NEED_RTNL,
67fbb16b 5151 },
9588bbd5
JM
5152 {
5153 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5154 .doit = nl80211_remain_on_channel,
5155 .policy = nl80211_policy,
5156 .flags = GENL_ADMIN_PERM,
41265714 5157 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5158 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
5159 },
5160 {
5161 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5162 .doit = nl80211_cancel_remain_on_channel,
5163 .policy = nl80211_policy,
5164 .flags = GENL_ADMIN_PERM,
41265714 5165 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5166 NL80211_FLAG_NEED_RTNL,
9588bbd5 5167 },
13ae75b1
JM
5168 {
5169 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5170 .doit = nl80211_set_tx_bitrate_mask,
5171 .policy = nl80211_policy,
5172 .flags = GENL_ADMIN_PERM,
4c476991
JB
5173 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5174 NL80211_FLAG_NEED_RTNL,
13ae75b1 5175 },
026331c4 5176 {
2e161f78
JB
5177 .cmd = NL80211_CMD_REGISTER_FRAME,
5178 .doit = nl80211_register_mgmt,
026331c4
JM
5179 .policy = nl80211_policy,
5180 .flags = GENL_ADMIN_PERM,
4c476991
JB
5181 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5182 NL80211_FLAG_NEED_RTNL,
026331c4
JM
5183 },
5184 {
2e161f78
JB
5185 .cmd = NL80211_CMD_FRAME,
5186 .doit = nl80211_tx_mgmt,
026331c4 5187 .policy = nl80211_policy,
f7ca38df
JB
5188 .flags = GENL_ADMIN_PERM,
5189 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5190 NL80211_FLAG_NEED_RTNL,
5191 },
5192 {
5193 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5194 .doit = nl80211_tx_mgmt_cancel_wait,
5195 .policy = nl80211_policy,
026331c4 5196 .flags = GENL_ADMIN_PERM,
41265714 5197 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5198 NL80211_FLAG_NEED_RTNL,
026331c4 5199 },
ffb9eb3d
KV
5200 {
5201 .cmd = NL80211_CMD_SET_POWER_SAVE,
5202 .doit = nl80211_set_power_save,
5203 .policy = nl80211_policy,
5204 .flags = GENL_ADMIN_PERM,
4c476991
JB
5205 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5206 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
5207 },
5208 {
5209 .cmd = NL80211_CMD_GET_POWER_SAVE,
5210 .doit = nl80211_get_power_save,
5211 .policy = nl80211_policy,
5212 /* can be retrieved by unprivileged users */
4c476991
JB
5213 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5214 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 5215 },
d6dc1a38
JO
5216 {
5217 .cmd = NL80211_CMD_SET_CQM,
5218 .doit = nl80211_set_cqm,
5219 .policy = nl80211_policy,
5220 .flags = GENL_ADMIN_PERM,
4c476991
JB
5221 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5222 NL80211_FLAG_NEED_RTNL,
d6dc1a38 5223 },
f444de05
JB
5224 {
5225 .cmd = NL80211_CMD_SET_CHANNEL,
5226 .doit = nl80211_set_channel,
5227 .policy = nl80211_policy,
5228 .flags = GENL_ADMIN_PERM,
4c476991
JB
5229 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5230 NL80211_FLAG_NEED_RTNL,
f444de05 5231 },
e8347eba
BJ
5232 {
5233 .cmd = NL80211_CMD_SET_WDS_PEER,
5234 .doit = nl80211_set_wds_peer,
5235 .policy = nl80211_policy,
5236 .flags = GENL_ADMIN_PERM,
43b19952
JB
5237 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5238 NL80211_FLAG_NEED_RTNL,
e8347eba 5239 },
29cbe68c
JB
5240 {
5241 .cmd = NL80211_CMD_JOIN_MESH,
5242 .doit = nl80211_join_mesh,
5243 .policy = nl80211_policy,
5244 .flags = GENL_ADMIN_PERM,
5245 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5246 NL80211_FLAG_NEED_RTNL,
5247 },
5248 {
5249 .cmd = NL80211_CMD_LEAVE_MESH,
5250 .doit = nl80211_leave_mesh,
5251 .policy = nl80211_policy,
5252 .flags = GENL_ADMIN_PERM,
5253 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5254 NL80211_FLAG_NEED_RTNL,
5255 },
55682965 5256};
9588bbd5 5257
6039f6d2
JM
5258static struct genl_multicast_group nl80211_mlme_mcgrp = {
5259 .name = "mlme",
5260};
55682965
JB
5261
5262/* multicast groups */
5263static struct genl_multicast_group nl80211_config_mcgrp = {
5264 .name = "config",
5265};
2a519311
JB
5266static struct genl_multicast_group nl80211_scan_mcgrp = {
5267 .name = "scan",
5268};
73d54c9e
LR
5269static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5270 .name = "regulatory",
5271};
55682965
JB
5272
5273/* notification functions */
5274
5275void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5276{
5277 struct sk_buff *msg;
5278
fd2120ca 5279 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5280 if (!msg)
5281 return;
5282
5283 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5284 nlmsg_free(msg);
5285 return;
5286 }
5287
463d0183
JB
5288 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5289 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5290}
5291
362a415d
JB
5292static int nl80211_add_scan_req(struct sk_buff *msg,
5293 struct cfg80211_registered_device *rdev)
5294{
5295 struct cfg80211_scan_request *req = rdev->scan_req;
5296 struct nlattr *nest;
5297 int i;
5298
667503dd
JB
5299 ASSERT_RDEV_LOCK(rdev);
5300
362a415d
JB
5301 if (WARN_ON(!req))
5302 return 0;
5303
5304 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5305 if (!nest)
5306 goto nla_put_failure;
5307 for (i = 0; i < req->n_ssids; i++)
5308 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5309 nla_nest_end(msg, nest);
5310
5311 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5312 if (!nest)
5313 goto nla_put_failure;
5314 for (i = 0; i < req->n_channels; i++)
5315 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5316 nla_nest_end(msg, nest);
5317
5318 if (req->ie)
5319 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5320
5321 return 0;
5322 nla_put_failure:
5323 return -ENOBUFS;
5324}
5325
a538e2d5
JB
5326static int nl80211_send_scan_msg(struct sk_buff *msg,
5327 struct cfg80211_registered_device *rdev,
5328 struct net_device *netdev,
5329 u32 pid, u32 seq, int flags,
5330 u32 cmd)
2a519311
JB
5331{
5332 void *hdr;
5333
5334 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5335 if (!hdr)
5336 return -1;
5337
b5850a7a 5338 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5339 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5340
362a415d
JB
5341 /* ignore errors and send incomplete event anyway */
5342 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5343
5344 return genlmsg_end(msg, hdr);
5345
5346 nla_put_failure:
5347 genlmsg_cancel(msg, hdr);
5348 return -EMSGSIZE;
5349}
5350
a538e2d5
JB
5351void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5352 struct net_device *netdev)
5353{
5354 struct sk_buff *msg;
5355
5356 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5357 if (!msg)
5358 return;
5359
5360 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5361 NL80211_CMD_TRIGGER_SCAN) < 0) {
5362 nlmsg_free(msg);
5363 return;
5364 }
5365
463d0183
JB
5366 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5367 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5368}
5369
2a519311
JB
5370void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5371 struct net_device *netdev)
5372{
5373 struct sk_buff *msg;
5374
fd2120ca 5375 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5376 if (!msg)
5377 return;
5378
a538e2d5
JB
5379 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5380 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5381 nlmsg_free(msg);
5382 return;
5383 }
5384
463d0183
JB
5385 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5386 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5387}
5388
5389void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5390 struct net_device *netdev)
5391{
5392 struct sk_buff *msg;
5393
fd2120ca 5394 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5395 if (!msg)
5396 return;
5397
a538e2d5
JB
5398 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5399 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5400 nlmsg_free(msg);
5401 return;
5402 }
5403
463d0183
JB
5404 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5405 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5406}
5407
73d54c9e
LR
5408/*
5409 * This can happen on global regulatory changes or device specific settings
5410 * based on custom world regulatory domains.
5411 */
5412void nl80211_send_reg_change_event(struct regulatory_request *request)
5413{
5414 struct sk_buff *msg;
5415 void *hdr;
5416
fd2120ca 5417 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5418 if (!msg)
5419 return;
5420
5421 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5422 if (!hdr) {
5423 nlmsg_free(msg);
5424 return;
5425 }
5426
5427 /* Userspace can always count this one always being set */
5428 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5429
5430 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5431 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5432 NL80211_REGDOM_TYPE_WORLD);
5433 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5434 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5435 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5436 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5437 request->intersect)
5438 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5439 NL80211_REGDOM_TYPE_INTERSECTION);
5440 else {
5441 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5442 NL80211_REGDOM_TYPE_COUNTRY);
5443 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5444 }
5445
5446 if (wiphy_idx_valid(request->wiphy_idx))
5447 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5448
5449 if (genlmsg_end(msg, hdr) < 0) {
5450 nlmsg_free(msg);
5451 return;
5452 }
5453
bc43b28c 5454 rcu_read_lock();
463d0183 5455 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5456 GFP_ATOMIC);
5457 rcu_read_unlock();
73d54c9e
LR
5458
5459 return;
5460
5461nla_put_failure:
5462 genlmsg_cancel(msg, hdr);
5463 nlmsg_free(msg);
5464}
5465
6039f6d2
JM
5466static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5467 struct net_device *netdev,
5468 const u8 *buf, size_t len,
e6d6e342 5469 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5470{
5471 struct sk_buff *msg;
5472 void *hdr;
5473
e6d6e342 5474 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5475 if (!msg)
5476 return;
5477
5478 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5479 if (!hdr) {
5480 nlmsg_free(msg);
5481 return;
5482 }
5483
5484 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5485 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5486 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5487
5488 if (genlmsg_end(msg, hdr) < 0) {
5489 nlmsg_free(msg);
5490 return;
5491 }
5492
463d0183
JB
5493 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5494 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5495 return;
5496
5497 nla_put_failure:
5498 genlmsg_cancel(msg, hdr);
5499 nlmsg_free(msg);
5500}
5501
5502void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5503 struct net_device *netdev, const u8 *buf,
5504 size_t len, gfp_t gfp)
6039f6d2
JM
5505{
5506 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5507 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5508}
5509
5510void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5511 struct net_device *netdev, const u8 *buf,
e6d6e342 5512 size_t len, gfp_t gfp)
6039f6d2 5513{
e6d6e342
JB
5514 nl80211_send_mlme_event(rdev, netdev, buf, len,
5515 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5516}
5517
53b46b84 5518void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5519 struct net_device *netdev, const u8 *buf,
5520 size_t len, gfp_t gfp)
6039f6d2
JM
5521{
5522 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5523 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5524}
5525
53b46b84
JM
5526void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5527 struct net_device *netdev, const u8 *buf,
e6d6e342 5528 size_t len, gfp_t gfp)
6039f6d2
JM
5529{
5530 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5531 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5532}
5533
cf4e594e
JM
5534void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
5535 struct net_device *netdev, const u8 *buf,
5536 size_t len, gfp_t gfp)
5537{
5538 nl80211_send_mlme_event(rdev, netdev, buf, len,
5539 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
5540}
5541
5542void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
5543 struct net_device *netdev, const u8 *buf,
5544 size_t len, gfp_t gfp)
5545{
5546 nl80211_send_mlme_event(rdev, netdev, buf, len,
5547 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
5548}
5549
1b06bb40
LR
5550static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5551 struct net_device *netdev, int cmd,
e6d6e342 5552 const u8 *addr, gfp_t gfp)
1965c853
JM
5553{
5554 struct sk_buff *msg;
5555 void *hdr;
5556
e6d6e342 5557 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5558 if (!msg)
5559 return;
5560
5561 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5562 if (!hdr) {
5563 nlmsg_free(msg);
5564 return;
5565 }
5566
5567 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5568 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5569 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5570 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5571
5572 if (genlmsg_end(msg, hdr) < 0) {
5573 nlmsg_free(msg);
5574 return;
5575 }
5576
463d0183
JB
5577 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5578 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5579 return;
5580
5581 nla_put_failure:
5582 genlmsg_cancel(msg, hdr);
5583 nlmsg_free(msg);
5584}
5585
5586void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5587 struct net_device *netdev, const u8 *addr,
5588 gfp_t gfp)
1965c853
JM
5589{
5590 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5591 addr, gfp);
1965c853
JM
5592}
5593
5594void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5595 struct net_device *netdev, const u8 *addr,
5596 gfp_t gfp)
1965c853 5597{
e6d6e342
JB
5598 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5599 addr, gfp);
1965c853
JM
5600}
5601
b23aa676
SO
5602void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5603 struct net_device *netdev, const u8 *bssid,
5604 const u8 *req_ie, size_t req_ie_len,
5605 const u8 *resp_ie, size_t resp_ie_len,
5606 u16 status, gfp_t gfp)
5607{
5608 struct sk_buff *msg;
5609 void *hdr;
5610
5611 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5612 if (!msg)
5613 return;
5614
5615 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5616 if (!hdr) {
5617 nlmsg_free(msg);
5618 return;
5619 }
5620
5621 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5622 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5623 if (bssid)
5624 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5625 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5626 if (req_ie)
5627 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5628 if (resp_ie)
5629 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5630
5631 if (genlmsg_end(msg, hdr) < 0) {
5632 nlmsg_free(msg);
5633 return;
5634 }
5635
463d0183
JB
5636 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5637 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5638 return;
5639
5640 nla_put_failure:
5641 genlmsg_cancel(msg, hdr);
5642 nlmsg_free(msg);
5643
5644}
5645
5646void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5647 struct net_device *netdev, const u8 *bssid,
5648 const u8 *req_ie, size_t req_ie_len,
5649 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5650{
5651 struct sk_buff *msg;
5652 void *hdr;
5653
5654 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5655 if (!msg)
5656 return;
5657
5658 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5659 if (!hdr) {
5660 nlmsg_free(msg);
5661 return;
5662 }
5663
5664 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5665 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5666 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5667 if (req_ie)
5668 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5669 if (resp_ie)
5670 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5671
5672 if (genlmsg_end(msg, hdr) < 0) {
5673 nlmsg_free(msg);
5674 return;
5675 }
5676
463d0183
JB
5677 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5678 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5679 return;
5680
5681 nla_put_failure:
5682 genlmsg_cancel(msg, hdr);
5683 nlmsg_free(msg);
5684
5685}
5686
5687void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5688 struct net_device *netdev, u16 reason,
667503dd 5689 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5690{
5691 struct sk_buff *msg;
5692 void *hdr;
5693
667503dd 5694 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5695 if (!msg)
5696 return;
5697
5698 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5699 if (!hdr) {
5700 nlmsg_free(msg);
5701 return;
5702 }
5703
5704 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5705 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5706 if (from_ap && reason)
5707 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5708 if (from_ap)
5709 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5710 if (ie)
5711 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5712
5713 if (genlmsg_end(msg, hdr) < 0) {
5714 nlmsg_free(msg);
5715 return;
5716 }
5717
463d0183
JB
5718 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5719 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5720 return;
5721
5722 nla_put_failure:
5723 genlmsg_cancel(msg, hdr);
5724 nlmsg_free(msg);
5725
5726}
5727
04a773ad
JB
5728void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5729 struct net_device *netdev, const u8 *bssid,
5730 gfp_t gfp)
5731{
5732 struct sk_buff *msg;
5733 void *hdr;
5734
fd2120ca 5735 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5736 if (!msg)
5737 return;
5738
5739 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5740 if (!hdr) {
5741 nlmsg_free(msg);
5742 return;
5743 }
5744
5745 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5746 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5747 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5748
5749 if (genlmsg_end(msg, hdr) < 0) {
5750 nlmsg_free(msg);
5751 return;
5752 }
5753
463d0183
JB
5754 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5755 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5756 return;
5757
5758 nla_put_failure:
5759 genlmsg_cancel(msg, hdr);
5760 nlmsg_free(msg);
5761}
5762
a3b8b056
JM
5763void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5764 struct net_device *netdev, const u8 *addr,
5765 enum nl80211_key_type key_type, int key_id,
e6d6e342 5766 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5767{
5768 struct sk_buff *msg;
5769 void *hdr;
5770
e6d6e342 5771 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5772 if (!msg)
5773 return;
5774
5775 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5776 if (!hdr) {
5777 nlmsg_free(msg);
5778 return;
5779 }
5780
5781 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5782 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5783 if (addr)
5784 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5785 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5786 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5787 if (tsc)
5788 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5789
5790 if (genlmsg_end(msg, hdr) < 0) {
5791 nlmsg_free(msg);
5792 return;
5793 }
5794
463d0183
JB
5795 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5796 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5797 return;
5798
5799 nla_put_failure:
5800 genlmsg_cancel(msg, hdr);
5801 nlmsg_free(msg);
5802}
5803
6bad8766
LR
5804void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5805 struct ieee80211_channel *channel_before,
5806 struct ieee80211_channel *channel_after)
5807{
5808 struct sk_buff *msg;
5809 void *hdr;
5810 struct nlattr *nl_freq;
5811
fd2120ca 5812 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5813 if (!msg)
5814 return;
5815
5816 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5817 if (!hdr) {
5818 nlmsg_free(msg);
5819 return;
5820 }
5821
5822 /*
5823 * Since we are applying the beacon hint to a wiphy we know its
5824 * wiphy_idx is valid
5825 */
5826 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5827
5828 /* Before */
5829 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5830 if (!nl_freq)
5831 goto nla_put_failure;
5832 if (nl80211_msg_put_channel(msg, channel_before))
5833 goto nla_put_failure;
5834 nla_nest_end(msg, nl_freq);
5835
5836 /* After */
5837 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5838 if (!nl_freq)
5839 goto nla_put_failure;
5840 if (nl80211_msg_put_channel(msg, channel_after))
5841 goto nla_put_failure;
5842 nla_nest_end(msg, nl_freq);
5843
5844 if (genlmsg_end(msg, hdr) < 0) {
5845 nlmsg_free(msg);
5846 return;
5847 }
5848
463d0183
JB
5849 rcu_read_lock();
5850 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5851 GFP_ATOMIC);
5852 rcu_read_unlock();
6bad8766
LR
5853
5854 return;
5855
5856nla_put_failure:
5857 genlmsg_cancel(msg, hdr);
5858 nlmsg_free(msg);
5859}
5860
9588bbd5
JM
5861static void nl80211_send_remain_on_chan_event(
5862 int cmd, struct cfg80211_registered_device *rdev,
5863 struct net_device *netdev, u64 cookie,
5864 struct ieee80211_channel *chan,
5865 enum nl80211_channel_type channel_type,
5866 unsigned int duration, gfp_t gfp)
5867{
5868 struct sk_buff *msg;
5869 void *hdr;
5870
5871 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5872 if (!msg)
5873 return;
5874
5875 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5876 if (!hdr) {
5877 nlmsg_free(msg);
5878 return;
5879 }
5880
5881 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5882 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5883 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5884 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5885 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5886
5887 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5888 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5889
5890 if (genlmsg_end(msg, hdr) < 0) {
5891 nlmsg_free(msg);
5892 return;
5893 }
5894
5895 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5896 nl80211_mlme_mcgrp.id, gfp);
5897 return;
5898
5899 nla_put_failure:
5900 genlmsg_cancel(msg, hdr);
5901 nlmsg_free(msg);
5902}
5903
5904void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5905 struct net_device *netdev, u64 cookie,
5906 struct ieee80211_channel *chan,
5907 enum nl80211_channel_type channel_type,
5908 unsigned int duration, gfp_t gfp)
5909{
5910 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5911 rdev, netdev, cookie, chan,
5912 channel_type, duration, gfp);
5913}
5914
5915void nl80211_send_remain_on_channel_cancel(
5916 struct cfg80211_registered_device *rdev, struct net_device *netdev,
5917 u64 cookie, struct ieee80211_channel *chan,
5918 enum nl80211_channel_type channel_type, gfp_t gfp)
5919{
5920 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5921 rdev, netdev, cookie, chan,
5922 channel_type, 0, gfp);
5923}
5924
98b62183
JB
5925void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5926 struct net_device *dev, const u8 *mac_addr,
5927 struct station_info *sinfo, gfp_t gfp)
5928{
5929 struct sk_buff *msg;
5930
5931 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5932 if (!msg)
5933 return;
5934
5935 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5936 nlmsg_free(msg);
5937 return;
5938 }
5939
5940 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5941 nl80211_mlme_mcgrp.id, gfp);
5942}
5943
2e161f78
JB
5944int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
5945 struct net_device *netdev, u32 nlpid,
5946 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
5947{
5948 struct sk_buff *msg;
5949 void *hdr;
5950 int err;
5951
5952 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5953 if (!msg)
5954 return -ENOMEM;
5955
2e161f78 5956 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
5957 if (!hdr) {
5958 nlmsg_free(msg);
5959 return -ENOMEM;
5960 }
5961
5962 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5963 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5964 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
5965 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5966
5967 err = genlmsg_end(msg, hdr);
5968 if (err < 0) {
5969 nlmsg_free(msg);
5970 return err;
5971 }
5972
5973 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
5974 if (err < 0)
5975 return err;
5976 return 0;
5977
5978 nla_put_failure:
5979 genlmsg_cancel(msg, hdr);
5980 nlmsg_free(msg);
5981 return -ENOBUFS;
5982}
5983
2e161f78
JB
5984void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
5985 struct net_device *netdev, u64 cookie,
5986 const u8 *buf, size_t len, bool ack,
5987 gfp_t gfp)
026331c4
JM
5988{
5989 struct sk_buff *msg;
5990 void *hdr;
5991
5992 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5993 if (!msg)
5994 return;
5995
2e161f78 5996 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
5997 if (!hdr) {
5998 nlmsg_free(msg);
5999 return;
6000 }
6001
6002 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6003 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6004 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6005 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6006 if (ack)
6007 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6008
6009 if (genlmsg_end(msg, hdr) < 0) {
6010 nlmsg_free(msg);
6011 return;
6012 }
6013
6014 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6015 return;
6016
6017 nla_put_failure:
6018 genlmsg_cancel(msg, hdr);
6019 nlmsg_free(msg);
6020}
6021
d6dc1a38
JO
6022void
6023nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6024 struct net_device *netdev,
6025 enum nl80211_cqm_rssi_threshold_event rssi_event,
6026 gfp_t gfp)
6027{
6028 struct sk_buff *msg;
6029 struct nlattr *pinfoattr;
6030 void *hdr;
6031
6032 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6033 if (!msg)
6034 return;
6035
6036 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6037 if (!hdr) {
6038 nlmsg_free(msg);
6039 return;
6040 }
6041
6042 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6043 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6044
6045 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6046 if (!pinfoattr)
6047 goto nla_put_failure;
6048
6049 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6050 rssi_event);
6051
6052 nla_nest_end(msg, pinfoattr);
6053
6054 if (genlmsg_end(msg, hdr) < 0) {
6055 nlmsg_free(msg);
6056 return;
6057 }
6058
6059 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6060 nl80211_mlme_mcgrp.id, gfp);
6061 return;
6062
6063 nla_put_failure:
6064 genlmsg_cancel(msg, hdr);
6065 nlmsg_free(msg);
6066}
6067
c063dbf5
JB
6068void
6069nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6070 struct net_device *netdev, const u8 *peer,
6071 u32 num_packets, gfp_t gfp)
6072{
6073 struct sk_buff *msg;
6074 struct nlattr *pinfoattr;
6075 void *hdr;
6076
6077 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6078 if (!msg)
6079 return;
6080
6081 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6082 if (!hdr) {
6083 nlmsg_free(msg);
6084 return;
6085 }
6086
6087 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6088 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6089 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6090
6091 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6092 if (!pinfoattr)
6093 goto nla_put_failure;
6094
6095 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6096
6097 nla_nest_end(msg, pinfoattr);
6098
6099 if (genlmsg_end(msg, hdr) < 0) {
6100 nlmsg_free(msg);
6101 return;
6102 }
6103
6104 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6105 nl80211_mlme_mcgrp.id, gfp);
6106 return;
6107
6108 nla_put_failure:
6109 genlmsg_cancel(msg, hdr);
6110 nlmsg_free(msg);
6111}
6112
026331c4
JM
6113static int nl80211_netlink_notify(struct notifier_block * nb,
6114 unsigned long state,
6115 void *_notify)
6116{
6117 struct netlink_notify *notify = _notify;
6118 struct cfg80211_registered_device *rdev;
6119 struct wireless_dev *wdev;
6120
6121 if (state != NETLINK_URELEASE)
6122 return NOTIFY_DONE;
6123
6124 rcu_read_lock();
6125
6126 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6127 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6128 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6129
6130 rcu_read_unlock();
6131
6132 return NOTIFY_DONE;
6133}
6134
6135static struct notifier_block nl80211_netlink_notifier = {
6136 .notifier_call = nl80211_netlink_notify,
6137};
6138
55682965
JB
6139/* initialisation/exit functions */
6140
6141int nl80211_init(void)
6142{
0d63cbb5 6143 int err;
55682965 6144
0d63cbb5
MM
6145 err = genl_register_family_with_ops(&nl80211_fam,
6146 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6147 if (err)
6148 return err;
6149
55682965
JB
6150 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6151 if (err)
6152 goto err_out;
6153
2a519311
JB
6154 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6155 if (err)
6156 goto err_out;
6157
73d54c9e
LR
6158 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6159 if (err)
6160 goto err_out;
6161
6039f6d2
JM
6162 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6163 if (err)
6164 goto err_out;
6165
aff89a9b
JB
6166#ifdef CONFIG_NL80211_TESTMODE
6167 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6168 if (err)
6169 goto err_out;
6170#endif
6171
026331c4
JM
6172 err = netlink_register_notifier(&nl80211_netlink_notifier);
6173 if (err)
6174 goto err_out;
6175
55682965
JB
6176 return 0;
6177 err_out:
6178 genl_unregister_family(&nl80211_fam);
6179 return err;
6180}
6181
6182void nl80211_exit(void)
6183{
026331c4 6184 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6185 genl_unregister_family(&nl80211_fam);
6186}
This page took 0.743648 seconds and 5 git commands to generate.