bpf: fix arraymap NULL deref and missing overflow and zero size checks
[deliverable/linux.git] / net / wireless / core.c
1 /*
2 * This is the linux wireless configuration interface.
3 *
4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
5 * Copyright 2013-2014 Intel Mobile Communications GmbH
6 */
7
8 #define pr_fmt(fmt) KBUILD_MODNAME ": " fmt
9
10 #include <linux/if.h>
11 #include <linux/module.h>
12 #include <linux/err.h>
13 #include <linux/list.h>
14 #include <linux/slab.h>
15 #include <linux/nl80211.h>
16 #include <linux/debugfs.h>
17 #include <linux/notifier.h>
18 #include <linux/device.h>
19 #include <linux/etherdevice.h>
20 #include <linux/rtnetlink.h>
21 #include <linux/sched.h>
22 #include <net/genetlink.h>
23 #include <net/cfg80211.h>
24 #include "nl80211.h"
25 #include "core.h"
26 #include "sysfs.h"
27 #include "debugfs.h"
28 #include "wext-compat.h"
29 #include "rdev-ops.h"
30
31 /* name for sysfs, %d is appended */
32 #define PHY_NAME "phy"
33
34 MODULE_AUTHOR("Johannes Berg");
35 MODULE_LICENSE("GPL");
36 MODULE_DESCRIPTION("wireless configuration support");
37 MODULE_ALIAS_GENL_FAMILY(NL80211_GENL_NAME);
38
39 /* RCU-protected (and RTNL for writers) */
40 LIST_HEAD(cfg80211_rdev_list);
41 int cfg80211_rdev_list_generation;
42
43 /* for debugfs */
44 static struct dentry *ieee80211_debugfs_dir;
45
46 /* for the cleanup, scan and event works */
47 struct workqueue_struct *cfg80211_wq;
48
49 static bool cfg80211_disable_40mhz_24ghz;
50 module_param(cfg80211_disable_40mhz_24ghz, bool, 0644);
51 MODULE_PARM_DESC(cfg80211_disable_40mhz_24ghz,
52 "Disable 40MHz support in the 2.4GHz band");
53
54 struct cfg80211_registered_device *cfg80211_rdev_by_wiphy_idx(int wiphy_idx)
55 {
56 struct cfg80211_registered_device *result = NULL, *rdev;
57
58 ASSERT_RTNL();
59
60 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
61 if (rdev->wiphy_idx == wiphy_idx) {
62 result = rdev;
63 break;
64 }
65 }
66
67 return result;
68 }
69
70 int get_wiphy_idx(struct wiphy *wiphy)
71 {
72 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
73
74 return rdev->wiphy_idx;
75 }
76
77 struct wiphy *wiphy_idx_to_wiphy(int wiphy_idx)
78 {
79 struct cfg80211_registered_device *rdev;
80
81 ASSERT_RTNL();
82
83 rdev = cfg80211_rdev_by_wiphy_idx(wiphy_idx);
84 if (!rdev)
85 return NULL;
86 return &rdev->wiphy;
87 }
88
89 static int cfg80211_dev_check_name(struct cfg80211_registered_device *rdev,
90 const char *newname)
91 {
92 struct cfg80211_registered_device *rdev2;
93 int wiphy_idx, taken = -1, digits;
94
95 ASSERT_RTNL();
96
97 /* prohibit calling the thing phy%d when %d is not its number */
98 sscanf(newname, PHY_NAME "%d%n", &wiphy_idx, &taken);
99 if (taken == strlen(newname) && wiphy_idx != rdev->wiphy_idx) {
100 /* count number of places needed to print wiphy_idx */
101 digits = 1;
102 while (wiphy_idx /= 10)
103 digits++;
104 /*
105 * deny the name if it is phy<idx> where <idx> is printed
106 * without leading zeroes. taken == strlen(newname) here
107 */
108 if (taken == strlen(PHY_NAME) + digits)
109 return -EINVAL;
110 }
111
112 /* Ensure another device does not already have this name. */
113 list_for_each_entry(rdev2, &cfg80211_rdev_list, list)
114 if (strcmp(newname, wiphy_name(&rdev2->wiphy)) == 0)
115 return -EINVAL;
116
117 return 0;
118 }
119
120 int cfg80211_dev_rename(struct cfg80211_registered_device *rdev,
121 char *newname)
122 {
123 int result;
124
125 ASSERT_RTNL();
126
127 /* Ignore nop renames */
128 if (strcmp(newname, wiphy_name(&rdev->wiphy)) == 0)
129 return 0;
130
131 result = cfg80211_dev_check_name(rdev, newname);
132 if (result < 0)
133 return result;
134
135 result = device_rename(&rdev->wiphy.dev, newname);
136 if (result)
137 return result;
138
139 if (rdev->wiphy.debugfsdir &&
140 !debugfs_rename(rdev->wiphy.debugfsdir->d_parent,
141 rdev->wiphy.debugfsdir,
142 rdev->wiphy.debugfsdir->d_parent,
143 newname))
144 pr_err("failed to rename debugfs dir to %s!\n", newname);
145
146 nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
147
148 return 0;
149 }
150
151 int cfg80211_switch_netns(struct cfg80211_registered_device *rdev,
152 struct net *net)
153 {
154 struct wireless_dev *wdev;
155 int err = 0;
156
157 if (!(rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK))
158 return -EOPNOTSUPP;
159
160 list_for_each_entry(wdev, &rdev->wdev_list, list) {
161 if (!wdev->netdev)
162 continue;
163 wdev->netdev->features &= ~NETIF_F_NETNS_LOCAL;
164 err = dev_change_net_namespace(wdev->netdev, net, "wlan%d");
165 if (err)
166 break;
167 wdev->netdev->features |= NETIF_F_NETNS_LOCAL;
168 }
169
170 if (err) {
171 /* failed -- clean up to old netns */
172 net = wiphy_net(&rdev->wiphy);
173
174 list_for_each_entry_continue_reverse(wdev, &rdev->wdev_list,
175 list) {
176 if (!wdev->netdev)
177 continue;
178 wdev->netdev->features &= ~NETIF_F_NETNS_LOCAL;
179 err = dev_change_net_namespace(wdev->netdev, net,
180 "wlan%d");
181 WARN_ON(err);
182 wdev->netdev->features |= NETIF_F_NETNS_LOCAL;
183 }
184
185 return err;
186 }
187
188 wiphy_net_set(&rdev->wiphy, net);
189
190 err = device_rename(&rdev->wiphy.dev, dev_name(&rdev->wiphy.dev));
191 WARN_ON(err);
192
193 return 0;
194 }
195
196 static void cfg80211_rfkill_poll(struct rfkill *rfkill, void *data)
197 {
198 struct cfg80211_registered_device *rdev = data;
199
200 rdev_rfkill_poll(rdev);
201 }
202
203 void cfg80211_stop_p2p_device(struct cfg80211_registered_device *rdev,
204 struct wireless_dev *wdev)
205 {
206 ASSERT_RTNL();
207
208 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_P2P_DEVICE))
209 return;
210
211 if (!wdev->p2p_started)
212 return;
213
214 rdev_stop_p2p_device(rdev, wdev);
215 wdev->p2p_started = false;
216
217 rdev->opencount--;
218
219 if (rdev->scan_req && rdev->scan_req->wdev == wdev) {
220 if (WARN_ON(!rdev->scan_req->notified))
221 rdev->scan_req->aborted = true;
222 ___cfg80211_scan_done(rdev, false);
223 }
224 }
225
226 void cfg80211_shutdown_all_interfaces(struct wiphy *wiphy)
227 {
228 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
229 struct wireless_dev *wdev;
230
231 ASSERT_RTNL();
232
233 list_for_each_entry(wdev, &rdev->wdev_list, list) {
234 if (wdev->netdev) {
235 dev_close(wdev->netdev);
236 continue;
237 }
238 /* otherwise, check iftype */
239 switch (wdev->iftype) {
240 case NL80211_IFTYPE_P2P_DEVICE:
241 cfg80211_stop_p2p_device(rdev, wdev);
242 break;
243 default:
244 break;
245 }
246 }
247 }
248 EXPORT_SYMBOL_GPL(cfg80211_shutdown_all_interfaces);
249
250 static int cfg80211_rfkill_set_block(void *data, bool blocked)
251 {
252 struct cfg80211_registered_device *rdev = data;
253
254 if (!blocked)
255 return 0;
256
257 rtnl_lock();
258 cfg80211_shutdown_all_interfaces(&rdev->wiphy);
259 rtnl_unlock();
260
261 return 0;
262 }
263
264 static void cfg80211_rfkill_sync_work(struct work_struct *work)
265 {
266 struct cfg80211_registered_device *rdev;
267
268 rdev = container_of(work, struct cfg80211_registered_device, rfkill_sync);
269 cfg80211_rfkill_set_block(rdev, rfkill_blocked(rdev->rfkill));
270 }
271
272 static void cfg80211_event_work(struct work_struct *work)
273 {
274 struct cfg80211_registered_device *rdev;
275
276 rdev = container_of(work, struct cfg80211_registered_device,
277 event_work);
278
279 rtnl_lock();
280 cfg80211_process_rdev_events(rdev);
281 rtnl_unlock();
282 }
283
284 void cfg80211_destroy_ifaces(struct cfg80211_registered_device *rdev)
285 {
286 struct cfg80211_iface_destroy *item;
287
288 ASSERT_RTNL();
289
290 spin_lock_irq(&rdev->destroy_list_lock);
291 while ((item = list_first_entry_or_null(&rdev->destroy_list,
292 struct cfg80211_iface_destroy,
293 list))) {
294 struct wireless_dev *wdev, *tmp;
295 u32 nlportid = item->nlportid;
296
297 list_del(&item->list);
298 kfree(item);
299 spin_unlock_irq(&rdev->destroy_list_lock);
300
301 list_for_each_entry_safe(wdev, tmp, &rdev->wdev_list, list) {
302 if (nlportid == wdev->owner_nlportid)
303 rdev_del_virtual_intf(rdev, wdev);
304 }
305
306 spin_lock_irq(&rdev->destroy_list_lock);
307 }
308 spin_unlock_irq(&rdev->destroy_list_lock);
309 }
310
311 static void cfg80211_destroy_iface_wk(struct work_struct *work)
312 {
313 struct cfg80211_registered_device *rdev;
314
315 rdev = container_of(work, struct cfg80211_registered_device,
316 destroy_work);
317
318 rtnl_lock();
319 cfg80211_destroy_ifaces(rdev);
320 rtnl_unlock();
321 }
322
323 /* exported functions */
324
325 struct wiphy *wiphy_new_nm(const struct cfg80211_ops *ops, int sizeof_priv,
326 const char *requested_name)
327 {
328 static atomic_t wiphy_counter = ATOMIC_INIT(0);
329
330 struct cfg80211_registered_device *rdev;
331 int alloc_size;
332
333 WARN_ON(ops->add_key && (!ops->del_key || !ops->set_default_key));
334 WARN_ON(ops->auth && (!ops->assoc || !ops->deauth || !ops->disassoc));
335 WARN_ON(ops->connect && !ops->disconnect);
336 WARN_ON(ops->join_ibss && !ops->leave_ibss);
337 WARN_ON(ops->add_virtual_intf && !ops->del_virtual_intf);
338 WARN_ON(ops->add_station && !ops->del_station);
339 WARN_ON(ops->add_mpath && !ops->del_mpath);
340 WARN_ON(ops->join_mesh && !ops->leave_mesh);
341
342 alloc_size = sizeof(*rdev) + sizeof_priv;
343
344 rdev = kzalloc(alloc_size, GFP_KERNEL);
345 if (!rdev)
346 return NULL;
347
348 rdev->ops = ops;
349
350 rdev->wiphy_idx = atomic_inc_return(&wiphy_counter);
351
352 if (unlikely(rdev->wiphy_idx < 0)) {
353 /* ugh, wrapped! */
354 atomic_dec(&wiphy_counter);
355 kfree(rdev);
356 return NULL;
357 }
358
359 /* atomic_inc_return makes it start at 1, make it start at 0 */
360 rdev->wiphy_idx--;
361
362 /* give it a proper name */
363 if (requested_name && requested_name[0]) {
364 int rv;
365
366 rtnl_lock();
367 rv = cfg80211_dev_check_name(rdev, requested_name);
368
369 if (rv < 0) {
370 rtnl_unlock();
371 goto use_default_name;
372 }
373
374 rv = dev_set_name(&rdev->wiphy.dev, "%s", requested_name);
375 rtnl_unlock();
376 if (rv)
377 goto use_default_name;
378 } else {
379 use_default_name:
380 /* NOTE: This is *probably* safe w/out holding rtnl because of
381 * the restrictions on phy names. Probably this call could
382 * fail if some other part of the kernel (re)named a device
383 * phyX. But, might should add some locking and check return
384 * value, and use a different name if this one exists?
385 */
386 dev_set_name(&rdev->wiphy.dev, PHY_NAME "%d", rdev->wiphy_idx);
387 }
388
389 INIT_LIST_HEAD(&rdev->wdev_list);
390 INIT_LIST_HEAD(&rdev->beacon_registrations);
391 spin_lock_init(&rdev->beacon_registrations_lock);
392 spin_lock_init(&rdev->bss_lock);
393 INIT_LIST_HEAD(&rdev->bss_list);
394 INIT_WORK(&rdev->scan_done_wk, __cfg80211_scan_done);
395 INIT_WORK(&rdev->sched_scan_results_wk, __cfg80211_sched_scan_results);
396 INIT_DELAYED_WORK(&rdev->dfs_update_channels_wk,
397 cfg80211_dfs_channels_update_work);
398 #ifdef CONFIG_CFG80211_WEXT
399 rdev->wiphy.wext = &cfg80211_wext_handler;
400 #endif
401
402 device_initialize(&rdev->wiphy.dev);
403 rdev->wiphy.dev.class = &ieee80211_class;
404 rdev->wiphy.dev.platform_data = rdev;
405
406 INIT_LIST_HEAD(&rdev->destroy_list);
407 spin_lock_init(&rdev->destroy_list_lock);
408 INIT_WORK(&rdev->destroy_work, cfg80211_destroy_iface_wk);
409
410 #ifdef CONFIG_CFG80211_DEFAULT_PS
411 rdev->wiphy.flags |= WIPHY_FLAG_PS_ON_BY_DEFAULT;
412 #endif
413
414 wiphy_net_set(&rdev->wiphy, &init_net);
415
416 rdev->rfkill_ops.set_block = cfg80211_rfkill_set_block;
417 rdev->rfkill = rfkill_alloc(dev_name(&rdev->wiphy.dev),
418 &rdev->wiphy.dev, RFKILL_TYPE_WLAN,
419 &rdev->rfkill_ops, rdev);
420
421 if (!rdev->rfkill) {
422 kfree(rdev);
423 return NULL;
424 }
425
426 INIT_WORK(&rdev->rfkill_sync, cfg80211_rfkill_sync_work);
427 INIT_WORK(&rdev->conn_work, cfg80211_conn_work);
428 INIT_WORK(&rdev->event_work, cfg80211_event_work);
429
430 init_waitqueue_head(&rdev->dev_wait);
431
432 /*
433 * Initialize wiphy parameters to IEEE 802.11 MIB default values.
434 * Fragmentation and RTS threshold are disabled by default with the
435 * special -1 value.
436 */
437 rdev->wiphy.retry_short = 7;
438 rdev->wiphy.retry_long = 4;
439 rdev->wiphy.frag_threshold = (u32) -1;
440 rdev->wiphy.rts_threshold = (u32) -1;
441 rdev->wiphy.coverage_class = 0;
442
443 rdev->wiphy.max_num_csa_counters = 1;
444
445 return &rdev->wiphy;
446 }
447 EXPORT_SYMBOL(wiphy_new_nm);
448
449 static int wiphy_verify_combinations(struct wiphy *wiphy)
450 {
451 const struct ieee80211_iface_combination *c;
452 int i, j;
453
454 for (i = 0; i < wiphy->n_iface_combinations; i++) {
455 u32 cnt = 0;
456 u16 all_iftypes = 0;
457
458 c = &wiphy->iface_combinations[i];
459
460 /*
461 * Combinations with just one interface aren't real,
462 * however we make an exception for DFS.
463 */
464 if (WARN_ON((c->max_interfaces < 2) && !c->radar_detect_widths))
465 return -EINVAL;
466
467 /* Need at least one channel */
468 if (WARN_ON(!c->num_different_channels))
469 return -EINVAL;
470
471 /*
472 * Put a sane limit on maximum number of different
473 * channels to simplify channel accounting code.
474 */
475 if (WARN_ON(c->num_different_channels >
476 CFG80211_MAX_NUM_DIFFERENT_CHANNELS))
477 return -EINVAL;
478
479 /* DFS only works on one channel. */
480 if (WARN_ON(c->radar_detect_widths &&
481 (c->num_different_channels > 1)))
482 return -EINVAL;
483
484 if (WARN_ON(!c->n_limits))
485 return -EINVAL;
486
487 for (j = 0; j < c->n_limits; j++) {
488 u16 types = c->limits[j].types;
489
490 /* interface types shouldn't overlap */
491 if (WARN_ON(types & all_iftypes))
492 return -EINVAL;
493 all_iftypes |= types;
494
495 if (WARN_ON(!c->limits[j].max))
496 return -EINVAL;
497
498 /* Shouldn't list software iftypes in combinations! */
499 if (WARN_ON(wiphy->software_iftypes & types))
500 return -EINVAL;
501
502 /* Only a single P2P_DEVICE can be allowed */
503 if (WARN_ON(types & BIT(NL80211_IFTYPE_P2P_DEVICE) &&
504 c->limits[j].max > 1))
505 return -EINVAL;
506
507 cnt += c->limits[j].max;
508 /*
509 * Don't advertise an unsupported type
510 * in a combination.
511 */
512 if (WARN_ON((wiphy->interface_modes & types) != types))
513 return -EINVAL;
514 }
515
516 /* You can't even choose that many! */
517 if (WARN_ON(cnt < c->max_interfaces))
518 return -EINVAL;
519 }
520
521 return 0;
522 }
523
524 int wiphy_register(struct wiphy *wiphy)
525 {
526 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
527 int res;
528 enum ieee80211_band band;
529 struct ieee80211_supported_band *sband;
530 bool have_band = false;
531 int i;
532 u16 ifmodes = wiphy->interface_modes;
533
534 #ifdef CONFIG_PM
535 if (WARN_ON(wiphy->wowlan &&
536 (wiphy->wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
537 !(wiphy->wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)))
538 return -EINVAL;
539 if (WARN_ON(wiphy->wowlan &&
540 !wiphy->wowlan->flags && !wiphy->wowlan->n_patterns &&
541 !wiphy->wowlan->tcp))
542 return -EINVAL;
543 #endif
544
545 if (WARN_ON(wiphy->coalesce &&
546 (!wiphy->coalesce->n_rules ||
547 !wiphy->coalesce->n_patterns) &&
548 (!wiphy->coalesce->pattern_min_len ||
549 wiphy->coalesce->pattern_min_len >
550 wiphy->coalesce->pattern_max_len)))
551 return -EINVAL;
552
553 if (WARN_ON(wiphy->ap_sme_capa &&
554 !(wiphy->flags & WIPHY_FLAG_HAVE_AP_SME)))
555 return -EINVAL;
556
557 if (WARN_ON(wiphy->addresses && !wiphy->n_addresses))
558 return -EINVAL;
559
560 if (WARN_ON(wiphy->addresses &&
561 !is_zero_ether_addr(wiphy->perm_addr) &&
562 memcmp(wiphy->perm_addr, wiphy->addresses[0].addr,
563 ETH_ALEN)))
564 return -EINVAL;
565
566 if (WARN_ON(wiphy->max_acl_mac_addrs &&
567 (!(wiphy->flags & WIPHY_FLAG_HAVE_AP_SME) ||
568 !rdev->ops->set_mac_acl)))
569 return -EINVAL;
570
571 if (wiphy->addresses)
572 memcpy(wiphy->perm_addr, wiphy->addresses[0].addr, ETH_ALEN);
573
574 /* sanity check ifmodes */
575 WARN_ON(!ifmodes);
576 ifmodes &= ((1 << NUM_NL80211_IFTYPES) - 1) & ~1;
577 if (WARN_ON(ifmodes != wiphy->interface_modes))
578 wiphy->interface_modes = ifmodes;
579
580 res = wiphy_verify_combinations(wiphy);
581 if (res)
582 return res;
583
584 /* sanity check supported bands/channels */
585 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
586 sband = wiphy->bands[band];
587 if (!sband)
588 continue;
589
590 sband->band = band;
591 if (WARN_ON(!sband->n_channels))
592 return -EINVAL;
593 /*
594 * on 60gHz band, there are no legacy rates, so
595 * n_bitrates is 0
596 */
597 if (WARN_ON(band != IEEE80211_BAND_60GHZ &&
598 !sband->n_bitrates))
599 return -EINVAL;
600
601 /*
602 * Since cfg80211_disable_40mhz_24ghz is global, we can
603 * modify the sband's ht data even if the driver uses a
604 * global structure for that.
605 */
606 if (cfg80211_disable_40mhz_24ghz &&
607 band == IEEE80211_BAND_2GHZ &&
608 sband->ht_cap.ht_supported) {
609 sband->ht_cap.cap &= ~IEEE80211_HT_CAP_SUP_WIDTH_20_40;
610 sband->ht_cap.cap &= ~IEEE80211_HT_CAP_SGI_40;
611 }
612
613 /*
614 * Since we use a u32 for rate bitmaps in
615 * ieee80211_get_response_rate, we cannot
616 * have more than 32 legacy rates.
617 */
618 if (WARN_ON(sband->n_bitrates > 32))
619 return -EINVAL;
620
621 for (i = 0; i < sband->n_channels; i++) {
622 sband->channels[i].orig_flags =
623 sband->channels[i].flags;
624 sband->channels[i].orig_mag = INT_MAX;
625 sband->channels[i].orig_mpwr =
626 sband->channels[i].max_power;
627 sband->channels[i].band = band;
628 }
629
630 have_band = true;
631 }
632
633 if (!have_band) {
634 WARN_ON(1);
635 return -EINVAL;
636 }
637
638 #ifdef CONFIG_PM
639 if (WARN_ON(rdev->wiphy.wowlan && rdev->wiphy.wowlan->n_patterns &&
640 (!rdev->wiphy.wowlan->pattern_min_len ||
641 rdev->wiphy.wowlan->pattern_min_len >
642 rdev->wiphy.wowlan->pattern_max_len)))
643 return -EINVAL;
644 #endif
645
646 /* check and set up bitrates */
647 ieee80211_set_bitrate_flags(wiphy);
648
649 rdev->wiphy.features |= NL80211_FEATURE_SCAN_FLUSH;
650
651 rtnl_lock();
652 res = device_add(&rdev->wiphy.dev);
653 if (res) {
654 rtnl_unlock();
655 return res;
656 }
657
658 /* set up regulatory info */
659 wiphy_regulatory_register(wiphy);
660
661 list_add_rcu(&rdev->list, &cfg80211_rdev_list);
662 cfg80211_rdev_list_generation++;
663
664 /* add to debugfs */
665 rdev->wiphy.debugfsdir =
666 debugfs_create_dir(wiphy_name(&rdev->wiphy),
667 ieee80211_debugfs_dir);
668 if (IS_ERR(rdev->wiphy.debugfsdir))
669 rdev->wiphy.debugfsdir = NULL;
670
671 cfg80211_debugfs_rdev_add(rdev);
672 nl80211_notify_wiphy(rdev, NL80211_CMD_NEW_WIPHY);
673
674 if (wiphy->regulatory_flags & REGULATORY_CUSTOM_REG) {
675 struct regulatory_request request;
676
677 request.wiphy_idx = get_wiphy_idx(wiphy);
678 request.initiator = NL80211_REGDOM_SET_BY_DRIVER;
679 request.alpha2[0] = '9';
680 request.alpha2[1] = '9';
681
682 nl80211_send_reg_change_event(&request);
683 }
684
685 rdev->wiphy.registered = true;
686 rtnl_unlock();
687
688 res = rfkill_register(rdev->rfkill);
689 if (res) {
690 rfkill_destroy(rdev->rfkill);
691 rdev->rfkill = NULL;
692 wiphy_unregister(&rdev->wiphy);
693 return res;
694 }
695
696 return 0;
697 }
698 EXPORT_SYMBOL(wiphy_register);
699
700 void wiphy_rfkill_start_polling(struct wiphy *wiphy)
701 {
702 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
703
704 if (!rdev->ops->rfkill_poll)
705 return;
706 rdev->rfkill_ops.poll = cfg80211_rfkill_poll;
707 rfkill_resume_polling(rdev->rfkill);
708 }
709 EXPORT_SYMBOL(wiphy_rfkill_start_polling);
710
711 void wiphy_rfkill_stop_polling(struct wiphy *wiphy)
712 {
713 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
714
715 rfkill_pause_polling(rdev->rfkill);
716 }
717 EXPORT_SYMBOL(wiphy_rfkill_stop_polling);
718
719 void wiphy_unregister(struct wiphy *wiphy)
720 {
721 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
722
723 wait_event(rdev->dev_wait, ({
724 int __count;
725 rtnl_lock();
726 __count = rdev->opencount;
727 rtnl_unlock();
728 __count == 0; }));
729
730 if (rdev->rfkill)
731 rfkill_unregister(rdev->rfkill);
732
733 rtnl_lock();
734 nl80211_notify_wiphy(rdev, NL80211_CMD_DEL_WIPHY);
735 rdev->wiphy.registered = false;
736
737 WARN_ON(!list_empty(&rdev->wdev_list));
738
739 /*
740 * First remove the hardware from everywhere, this makes
741 * it impossible to find from userspace.
742 */
743 debugfs_remove_recursive(rdev->wiphy.debugfsdir);
744 list_del_rcu(&rdev->list);
745 synchronize_rcu();
746
747 /*
748 * If this device got a regulatory hint tell core its
749 * free to listen now to a new shiny device regulatory hint
750 */
751 wiphy_regulatory_deregister(wiphy);
752
753 cfg80211_rdev_list_generation++;
754 device_del(&rdev->wiphy.dev);
755
756 rtnl_unlock();
757
758 flush_work(&rdev->scan_done_wk);
759 cancel_work_sync(&rdev->conn_work);
760 flush_work(&rdev->event_work);
761 cancel_delayed_work_sync(&rdev->dfs_update_channels_wk);
762 flush_work(&rdev->destroy_work);
763
764 #ifdef CONFIG_PM
765 if (rdev->wiphy.wowlan_config && rdev->ops->set_wakeup)
766 rdev_set_wakeup(rdev, false);
767 #endif
768 cfg80211_rdev_free_wowlan(rdev);
769 cfg80211_rdev_free_coalesce(rdev);
770 }
771 EXPORT_SYMBOL(wiphy_unregister);
772
773 void cfg80211_dev_free(struct cfg80211_registered_device *rdev)
774 {
775 struct cfg80211_internal_bss *scan, *tmp;
776 struct cfg80211_beacon_registration *reg, *treg;
777 rfkill_destroy(rdev->rfkill);
778 list_for_each_entry_safe(reg, treg, &rdev->beacon_registrations, list) {
779 list_del(&reg->list);
780 kfree(reg);
781 }
782 list_for_each_entry_safe(scan, tmp, &rdev->bss_list, list)
783 cfg80211_put_bss(&rdev->wiphy, &scan->pub);
784 kfree(rdev);
785 }
786
787 void wiphy_free(struct wiphy *wiphy)
788 {
789 put_device(&wiphy->dev);
790 }
791 EXPORT_SYMBOL(wiphy_free);
792
793 void wiphy_rfkill_set_hw_state(struct wiphy *wiphy, bool blocked)
794 {
795 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
796
797 if (rfkill_set_hw_state(rdev->rfkill, blocked))
798 schedule_work(&rdev->rfkill_sync);
799 }
800 EXPORT_SYMBOL(wiphy_rfkill_set_hw_state);
801
802 void cfg80211_unregister_wdev(struct wireless_dev *wdev)
803 {
804 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
805
806 ASSERT_RTNL();
807
808 if (WARN_ON(wdev->netdev))
809 return;
810
811 list_del_rcu(&wdev->list);
812 rdev->devlist_generation++;
813
814 switch (wdev->iftype) {
815 case NL80211_IFTYPE_P2P_DEVICE:
816 cfg80211_stop_p2p_device(rdev, wdev);
817 break;
818 default:
819 WARN_ON_ONCE(1);
820 break;
821 }
822 }
823 EXPORT_SYMBOL(cfg80211_unregister_wdev);
824
825 static const struct device_type wiphy_type = {
826 .name = "wlan",
827 };
828
829 void cfg80211_update_iface_num(struct cfg80211_registered_device *rdev,
830 enum nl80211_iftype iftype, int num)
831 {
832 ASSERT_RTNL();
833
834 rdev->num_running_ifaces += num;
835 if (iftype == NL80211_IFTYPE_MONITOR)
836 rdev->num_running_monitor_ifaces += num;
837 }
838
839 void __cfg80211_leave(struct cfg80211_registered_device *rdev,
840 struct wireless_dev *wdev)
841 {
842 struct net_device *dev = wdev->netdev;
843
844 ASSERT_RTNL();
845 ASSERT_WDEV_LOCK(wdev);
846
847 switch (wdev->iftype) {
848 case NL80211_IFTYPE_ADHOC:
849 __cfg80211_leave_ibss(rdev, dev, true);
850 break;
851 case NL80211_IFTYPE_P2P_CLIENT:
852 case NL80211_IFTYPE_STATION:
853 if (rdev->sched_scan_req && dev == rdev->sched_scan_req->dev)
854 __cfg80211_stop_sched_scan(rdev, false);
855
856 #ifdef CONFIG_CFG80211_WEXT
857 kfree(wdev->wext.ie);
858 wdev->wext.ie = NULL;
859 wdev->wext.ie_len = 0;
860 wdev->wext.connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
861 #endif
862 cfg80211_disconnect(rdev, dev,
863 WLAN_REASON_DEAUTH_LEAVING, true);
864 break;
865 case NL80211_IFTYPE_MESH_POINT:
866 __cfg80211_leave_mesh(rdev, dev);
867 break;
868 case NL80211_IFTYPE_AP:
869 case NL80211_IFTYPE_P2P_GO:
870 __cfg80211_stop_ap(rdev, dev, true);
871 break;
872 case NL80211_IFTYPE_OCB:
873 __cfg80211_leave_ocb(rdev, dev);
874 break;
875 case NL80211_IFTYPE_WDS:
876 /* must be handled by mac80211/driver, has no APIs */
877 break;
878 case NL80211_IFTYPE_P2P_DEVICE:
879 /* cannot happen, has no netdev */
880 break;
881 case NL80211_IFTYPE_AP_VLAN:
882 case NL80211_IFTYPE_MONITOR:
883 /* nothing to do */
884 break;
885 case NL80211_IFTYPE_UNSPECIFIED:
886 case NUM_NL80211_IFTYPES:
887 /* invalid */
888 break;
889 }
890 }
891
892 void cfg80211_leave(struct cfg80211_registered_device *rdev,
893 struct wireless_dev *wdev)
894 {
895 wdev_lock(wdev);
896 __cfg80211_leave(rdev, wdev);
897 wdev_unlock(wdev);
898 }
899
900 void cfg80211_stop_iface(struct wiphy *wiphy, struct wireless_dev *wdev,
901 gfp_t gfp)
902 {
903 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
904 struct cfg80211_event *ev;
905 unsigned long flags;
906
907 trace_cfg80211_stop_iface(wiphy, wdev);
908
909 ev = kzalloc(sizeof(*ev), gfp);
910 if (!ev)
911 return;
912
913 ev->type = EVENT_STOPPED;
914
915 spin_lock_irqsave(&wdev->event_lock, flags);
916 list_add_tail(&ev->list, &wdev->event_list);
917 spin_unlock_irqrestore(&wdev->event_lock, flags);
918 queue_work(cfg80211_wq, &rdev->event_work);
919 }
920 EXPORT_SYMBOL(cfg80211_stop_iface);
921
922 static int cfg80211_netdev_notifier_call(struct notifier_block *nb,
923 unsigned long state, void *ptr)
924 {
925 struct net_device *dev = netdev_notifier_info_to_dev(ptr);
926 struct wireless_dev *wdev = dev->ieee80211_ptr;
927 struct cfg80211_registered_device *rdev;
928
929 if (!wdev)
930 return NOTIFY_DONE;
931
932 rdev = wiphy_to_rdev(wdev->wiphy);
933
934 WARN_ON(wdev->iftype == NL80211_IFTYPE_UNSPECIFIED);
935
936 switch (state) {
937 case NETDEV_POST_INIT:
938 SET_NETDEV_DEVTYPE(dev, &wiphy_type);
939 break;
940 case NETDEV_REGISTER:
941 /*
942 * NB: cannot take rdev->mtx here because this may be
943 * called within code protected by it when interfaces
944 * are added with nl80211.
945 */
946 mutex_init(&wdev->mtx);
947 INIT_LIST_HEAD(&wdev->event_list);
948 spin_lock_init(&wdev->event_lock);
949 INIT_LIST_HEAD(&wdev->mgmt_registrations);
950 spin_lock_init(&wdev->mgmt_registrations_lock);
951
952 wdev->identifier = ++rdev->wdev_id;
953 list_add_rcu(&wdev->list, &rdev->wdev_list);
954 rdev->devlist_generation++;
955 /* can only change netns with wiphy */
956 dev->features |= NETIF_F_NETNS_LOCAL;
957
958 if (sysfs_create_link(&dev->dev.kobj, &rdev->wiphy.dev.kobj,
959 "phy80211")) {
960 pr_err("failed to add phy80211 symlink to netdev!\n");
961 }
962 wdev->netdev = dev;
963 #ifdef CONFIG_CFG80211_WEXT
964 wdev->wext.default_key = -1;
965 wdev->wext.default_mgmt_key = -1;
966 wdev->wext.connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
967 #endif
968
969 if (wdev->wiphy->flags & WIPHY_FLAG_PS_ON_BY_DEFAULT)
970 wdev->ps = true;
971 else
972 wdev->ps = false;
973 /* allow mac80211 to determine the timeout */
974 wdev->ps_timeout = -1;
975
976 if ((wdev->iftype == NL80211_IFTYPE_STATION ||
977 wdev->iftype == NL80211_IFTYPE_P2P_CLIENT ||
978 wdev->iftype == NL80211_IFTYPE_ADHOC) && !wdev->use_4addr)
979 dev->priv_flags |= IFF_DONT_BRIDGE;
980 break;
981 case NETDEV_GOING_DOWN:
982 cfg80211_leave(rdev, wdev);
983 break;
984 case NETDEV_DOWN:
985 cfg80211_update_iface_num(rdev, wdev->iftype, -1);
986 if (rdev->scan_req && rdev->scan_req->wdev == wdev) {
987 if (WARN_ON(!rdev->scan_req->notified))
988 rdev->scan_req->aborted = true;
989 ___cfg80211_scan_done(rdev, false);
990 }
991
992 if (WARN_ON(rdev->sched_scan_req &&
993 rdev->sched_scan_req->dev == wdev->netdev)) {
994 __cfg80211_stop_sched_scan(rdev, false);
995 }
996
997 rdev->opencount--;
998 wake_up(&rdev->dev_wait);
999 break;
1000 case NETDEV_UP:
1001 cfg80211_update_iface_num(rdev, wdev->iftype, 1);
1002 wdev_lock(wdev);
1003 switch (wdev->iftype) {
1004 #ifdef CONFIG_CFG80211_WEXT
1005 case NL80211_IFTYPE_ADHOC:
1006 cfg80211_ibss_wext_join(rdev, wdev);
1007 break;
1008 case NL80211_IFTYPE_STATION:
1009 cfg80211_mgd_wext_connect(rdev, wdev);
1010 break;
1011 #endif
1012 #ifdef CONFIG_MAC80211_MESH
1013 case NL80211_IFTYPE_MESH_POINT:
1014 {
1015 /* backward compat code... */
1016 struct mesh_setup setup;
1017 memcpy(&setup, &default_mesh_setup,
1018 sizeof(setup));
1019 /* back compat only needed for mesh_id */
1020 setup.mesh_id = wdev->ssid;
1021 setup.mesh_id_len = wdev->mesh_id_up_len;
1022 if (wdev->mesh_id_up_len)
1023 __cfg80211_join_mesh(rdev, dev,
1024 &setup,
1025 &default_mesh_config);
1026 break;
1027 }
1028 #endif
1029 default:
1030 break;
1031 }
1032 wdev_unlock(wdev);
1033 rdev->opencount++;
1034
1035 /*
1036 * Configure power management to the driver here so that its
1037 * correctly set also after interface type changes etc.
1038 */
1039 if ((wdev->iftype == NL80211_IFTYPE_STATION ||
1040 wdev->iftype == NL80211_IFTYPE_P2P_CLIENT) &&
1041 rdev->ops->set_power_mgmt)
1042 if (rdev_set_power_mgmt(rdev, dev, wdev->ps,
1043 wdev->ps_timeout)) {
1044 /* assume this means it's off */
1045 wdev->ps = false;
1046 }
1047 break;
1048 case NETDEV_UNREGISTER:
1049 /*
1050 * It is possible to get NETDEV_UNREGISTER
1051 * multiple times. To detect that, check
1052 * that the interface is still on the list
1053 * of registered interfaces, and only then
1054 * remove and clean it up.
1055 */
1056 if (!list_empty(&wdev->list)) {
1057 sysfs_remove_link(&dev->dev.kobj, "phy80211");
1058 list_del_rcu(&wdev->list);
1059 rdev->devlist_generation++;
1060 cfg80211_mlme_purge_registrations(wdev);
1061 #ifdef CONFIG_CFG80211_WEXT
1062 kzfree(wdev->wext.keys);
1063 #endif
1064 }
1065 /*
1066 * synchronise (so that we won't find this netdev
1067 * from other code any more) and then clear the list
1068 * head so that the above code can safely check for
1069 * !list_empty() to avoid double-cleanup.
1070 */
1071 synchronize_rcu();
1072 INIT_LIST_HEAD(&wdev->list);
1073 /*
1074 * Ensure that all events have been processed and
1075 * freed.
1076 */
1077 cfg80211_process_wdev_events(wdev);
1078
1079 if (WARN_ON(wdev->current_bss)) {
1080 cfg80211_unhold_bss(wdev->current_bss);
1081 cfg80211_put_bss(wdev->wiphy, &wdev->current_bss->pub);
1082 wdev->current_bss = NULL;
1083 }
1084 break;
1085 case NETDEV_PRE_UP:
1086 if (!(wdev->wiphy->interface_modes & BIT(wdev->iftype)))
1087 return notifier_from_errno(-EOPNOTSUPP);
1088 if (rfkill_blocked(rdev->rfkill))
1089 return notifier_from_errno(-ERFKILL);
1090 break;
1091 default:
1092 return NOTIFY_DONE;
1093 }
1094
1095 return NOTIFY_OK;
1096 }
1097
1098 static struct notifier_block cfg80211_netdev_notifier = {
1099 .notifier_call = cfg80211_netdev_notifier_call,
1100 };
1101
1102 static void __net_exit cfg80211_pernet_exit(struct net *net)
1103 {
1104 struct cfg80211_registered_device *rdev;
1105
1106 rtnl_lock();
1107 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1108 if (net_eq(wiphy_net(&rdev->wiphy), net))
1109 WARN_ON(cfg80211_switch_netns(rdev, &init_net));
1110 }
1111 rtnl_unlock();
1112 }
1113
1114 static struct pernet_operations cfg80211_pernet_ops = {
1115 .exit = cfg80211_pernet_exit,
1116 };
1117
1118 static int __init cfg80211_init(void)
1119 {
1120 int err;
1121
1122 err = register_pernet_device(&cfg80211_pernet_ops);
1123 if (err)
1124 goto out_fail_pernet;
1125
1126 err = wiphy_sysfs_init();
1127 if (err)
1128 goto out_fail_sysfs;
1129
1130 err = register_netdevice_notifier(&cfg80211_netdev_notifier);
1131 if (err)
1132 goto out_fail_notifier;
1133
1134 err = nl80211_init();
1135 if (err)
1136 goto out_fail_nl80211;
1137
1138 ieee80211_debugfs_dir = debugfs_create_dir("ieee80211", NULL);
1139
1140 err = regulatory_init();
1141 if (err)
1142 goto out_fail_reg;
1143
1144 cfg80211_wq = create_singlethread_workqueue("cfg80211");
1145 if (!cfg80211_wq) {
1146 err = -ENOMEM;
1147 goto out_fail_wq;
1148 }
1149
1150 return 0;
1151
1152 out_fail_wq:
1153 regulatory_exit();
1154 out_fail_reg:
1155 debugfs_remove(ieee80211_debugfs_dir);
1156 out_fail_nl80211:
1157 unregister_netdevice_notifier(&cfg80211_netdev_notifier);
1158 out_fail_notifier:
1159 wiphy_sysfs_exit();
1160 out_fail_sysfs:
1161 unregister_pernet_device(&cfg80211_pernet_ops);
1162 out_fail_pernet:
1163 return err;
1164 }
1165 subsys_initcall(cfg80211_init);
1166
1167 static void __exit cfg80211_exit(void)
1168 {
1169 debugfs_remove(ieee80211_debugfs_dir);
1170 nl80211_exit();
1171 unregister_netdevice_notifier(&cfg80211_netdev_notifier);
1172 wiphy_sysfs_exit();
1173 regulatory_exit();
1174 unregister_pernet_device(&cfg80211_pernet_ops);
1175 destroy_workqueue(cfg80211_wq);
1176 }
1177 module_exit(cfg80211_exit);
This page took 0.060992 seconds and 5 git commands to generate.