1d6ef24254fee94dfd3f89cd3c595c6474de808d
[deliverable/linux.git] / net / wireless / nl80211.c
1 /*
2 * This is the new netlink-based wireless configuration interface.
3 *
4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
5 */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/slab.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/net_namespace.h>
19 #include <net/genetlink.h>
20 #include <net/cfg80211.h>
21 #include <net/sock.h>
22 #include "core.h"
23 #include "nl80211.h"
24 #include "reg.h"
25
26 /* the netlink family */
27 static struct genl_family nl80211_fam = {
28 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
29 .name = "nl80211", /* have users key off the name instead */
30 .hdrsize = 0, /* no private header */
31 .version = 1, /* no particular meaning now */
32 .maxattr = NL80211_ATTR_MAX,
33 .netnsok = true,
34 };
35
36 /* internal helper: get rdev and dev */
37 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
38 struct cfg80211_registered_device **rdev,
39 struct net_device **dev)
40 {
41 struct nlattr **attrs = info->attrs;
42 int ifindex;
43
44 if (!attrs[NL80211_ATTR_IFINDEX])
45 return -EINVAL;
46
47 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
48 *dev = dev_get_by_index(genl_info_net(info), ifindex);
49 if (!*dev)
50 return -ENODEV;
51
52 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
53 if (IS_ERR(*rdev)) {
54 dev_put(*dev);
55 return PTR_ERR(*rdev);
56 }
57
58 return 0;
59 }
60
61 /* policy for the attributes */
62 static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
63 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
64 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
65 .len = 20-1 },
66 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
67 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
68 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
69 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
71 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
72 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
73 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
74
75 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
76 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
77 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
78
79 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
80 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
81
82 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
83 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
84 .len = WLAN_MAX_KEY_LEN },
85 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
86 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
87 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
88 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
89
90 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
91 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
92 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
95 .len = IEEE80211_MAX_DATA_LEN },
96 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
98 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
99 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
100 .len = NL80211_MAX_SUPP_RATES },
101 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
102 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
103 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
104 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
105 .len = IEEE80211_MAX_MESH_ID_LEN },
106 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
107
108 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
109 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
110
111 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
113 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
114 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
115 .len = NL80211_MAX_SUPP_RATES },
116
117 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
118
119 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
120 .len = NL80211_HT_CAPABILITY_LEN },
121
122 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
123 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
124 .len = IEEE80211_MAX_DATA_LEN },
125 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
126 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
127
128 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
129 .len = IEEE80211_MAX_SSID_LEN },
130 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
131 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
132 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
133 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
134 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
135 [NL80211_ATTR_STA_FLAGS2] = {
136 .len = sizeof(struct nl80211_sta_flag_update),
137 },
138 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
139 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
140 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
141 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
142 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
143 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
144 [NL80211_ATTR_PID] = { .type = NLA_U32 },
145 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
146 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
147 .len = WLAN_PMKID_LEN },
148 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
149 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
150 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
151 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
152 .len = IEEE80211_MAX_DATA_LEN },
153 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
154 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
155 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
156 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
157 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
158
159 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
160 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
161 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
162 };
163
164 /* policy for the attributes */
165 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
166 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
167 [NL80211_KEY_IDX] = { .type = NLA_U8 },
168 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
169 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
170 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
171 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
172 };
173
174 /* ifidx get helper */
175 static int nl80211_get_ifidx(struct netlink_callback *cb)
176 {
177 int res;
178
179 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
180 nl80211_fam.attrbuf, nl80211_fam.maxattr,
181 nl80211_policy);
182 if (res)
183 return res;
184
185 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
186 return -EINVAL;
187
188 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
189 if (!res)
190 return -EINVAL;
191 return res;
192 }
193
194 /* IE validation */
195 static bool is_valid_ie_attr(const struct nlattr *attr)
196 {
197 const u8 *pos;
198 int len;
199
200 if (!attr)
201 return true;
202
203 pos = nla_data(attr);
204 len = nla_len(attr);
205
206 while (len) {
207 u8 elemlen;
208
209 if (len < 2)
210 return false;
211 len -= 2;
212
213 elemlen = pos[1];
214 if (elemlen > len)
215 return false;
216
217 len -= elemlen;
218 pos += 2 + elemlen;
219 }
220
221 return true;
222 }
223
224 /* message building helper */
225 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
226 int flags, u8 cmd)
227 {
228 /* since there is no private header just add the generic one */
229 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
230 }
231
232 static int nl80211_msg_put_channel(struct sk_buff *msg,
233 struct ieee80211_channel *chan)
234 {
235 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
236 chan->center_freq);
237
238 if (chan->flags & IEEE80211_CHAN_DISABLED)
239 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
240 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
241 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
242 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
243 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
244 if (chan->flags & IEEE80211_CHAN_RADAR)
245 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
246
247 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
248 DBM_TO_MBM(chan->max_power));
249
250 return 0;
251
252 nla_put_failure:
253 return -ENOBUFS;
254 }
255
256 /* netlink command implementations */
257
258 struct key_parse {
259 struct key_params p;
260 int idx;
261 bool def, defmgmt;
262 };
263
264 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
265 {
266 struct nlattr *tb[NL80211_KEY_MAX + 1];
267 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
268 nl80211_key_policy);
269 if (err)
270 return err;
271
272 k->def = !!tb[NL80211_KEY_DEFAULT];
273 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
274
275 if (tb[NL80211_KEY_IDX])
276 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
277
278 if (tb[NL80211_KEY_DATA]) {
279 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
280 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
281 }
282
283 if (tb[NL80211_KEY_SEQ]) {
284 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
285 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
286 }
287
288 if (tb[NL80211_KEY_CIPHER])
289 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
290
291 return 0;
292 }
293
294 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
295 {
296 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
297 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
298 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
299 }
300
301 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
302 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
303 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
304 }
305
306 if (info->attrs[NL80211_ATTR_KEY_IDX])
307 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
308
309 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
310 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
311
312 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
313 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
314
315 return 0;
316 }
317
318 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
319 {
320 int err;
321
322 memset(k, 0, sizeof(*k));
323 k->idx = -1;
324
325 if (info->attrs[NL80211_ATTR_KEY])
326 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
327 else
328 err = nl80211_parse_key_old(info, k);
329
330 if (err)
331 return err;
332
333 if (k->def && k->defmgmt)
334 return -EINVAL;
335
336 if (k->idx != -1) {
337 if (k->defmgmt) {
338 if (k->idx < 4 || k->idx > 5)
339 return -EINVAL;
340 } else if (k->def) {
341 if (k->idx < 0 || k->idx > 3)
342 return -EINVAL;
343 } else {
344 if (k->idx < 0 || k->idx > 5)
345 return -EINVAL;
346 }
347 }
348
349 return 0;
350 }
351
352 static struct cfg80211_cached_keys *
353 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
354 struct nlattr *keys)
355 {
356 struct key_parse parse;
357 struct nlattr *key;
358 struct cfg80211_cached_keys *result;
359 int rem, err, def = 0;
360
361 result = kzalloc(sizeof(*result), GFP_KERNEL);
362 if (!result)
363 return ERR_PTR(-ENOMEM);
364
365 result->def = -1;
366 result->defmgmt = -1;
367
368 nla_for_each_nested(key, keys, rem) {
369 memset(&parse, 0, sizeof(parse));
370 parse.idx = -1;
371
372 err = nl80211_parse_key_new(key, &parse);
373 if (err)
374 goto error;
375 err = -EINVAL;
376 if (!parse.p.key)
377 goto error;
378 if (parse.idx < 0 || parse.idx > 4)
379 goto error;
380 if (parse.def) {
381 if (def)
382 goto error;
383 def = 1;
384 result->def = parse.idx;
385 } else if (parse.defmgmt)
386 goto error;
387 err = cfg80211_validate_key_settings(rdev, &parse.p,
388 parse.idx, NULL);
389 if (err)
390 goto error;
391 result->params[parse.idx].cipher = parse.p.cipher;
392 result->params[parse.idx].key_len = parse.p.key_len;
393 result->params[parse.idx].key = result->data[parse.idx];
394 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
395 }
396
397 return result;
398 error:
399 kfree(result);
400 return ERR_PTR(err);
401 }
402
403 static int nl80211_key_allowed(struct wireless_dev *wdev)
404 {
405 ASSERT_WDEV_LOCK(wdev);
406
407 if (!netif_running(wdev->netdev))
408 return -ENETDOWN;
409
410 switch (wdev->iftype) {
411 case NL80211_IFTYPE_AP:
412 case NL80211_IFTYPE_AP_VLAN:
413 break;
414 case NL80211_IFTYPE_ADHOC:
415 if (!wdev->current_bss)
416 return -ENOLINK;
417 break;
418 case NL80211_IFTYPE_STATION:
419 if (wdev->sme_state != CFG80211_SME_CONNECTED)
420 return -ENOLINK;
421 break;
422 default:
423 return -EINVAL;
424 }
425
426 return 0;
427 }
428
429 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
430 struct cfg80211_registered_device *dev)
431 {
432 void *hdr;
433 struct nlattr *nl_bands, *nl_band;
434 struct nlattr *nl_freqs, *nl_freq;
435 struct nlattr *nl_rates, *nl_rate;
436 struct nlattr *nl_modes;
437 struct nlattr *nl_cmds;
438 enum ieee80211_band band;
439 struct ieee80211_channel *chan;
440 struct ieee80211_rate *rate;
441 int i;
442 u16 ifmodes = dev->wiphy.interface_modes;
443 const struct ieee80211_txrx_stypes *mgmt_stypes =
444 dev->wiphy.mgmt_stypes;
445
446 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
447 if (!hdr)
448 return -1;
449
450 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
451 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
452
453 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
454 cfg80211_rdev_list_generation);
455
456 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
457 dev->wiphy.retry_short);
458 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
459 dev->wiphy.retry_long);
460 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
461 dev->wiphy.frag_threshold);
462 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
463 dev->wiphy.rts_threshold);
464 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
465 dev->wiphy.coverage_class);
466
467 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
468 dev->wiphy.max_scan_ssids);
469 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
470 dev->wiphy.max_scan_ie_len);
471
472 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
473 sizeof(u32) * dev->wiphy.n_cipher_suites,
474 dev->wiphy.cipher_suites);
475
476 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
477 dev->wiphy.max_num_pmkids);
478
479 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
480 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
481
482 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
483 if (!nl_modes)
484 goto nla_put_failure;
485
486 i = 0;
487 while (ifmodes) {
488 if (ifmodes & 1)
489 NLA_PUT_FLAG(msg, i);
490 ifmodes >>= 1;
491 i++;
492 }
493
494 nla_nest_end(msg, nl_modes);
495
496 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
497 if (!nl_bands)
498 goto nla_put_failure;
499
500 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
501 if (!dev->wiphy.bands[band])
502 continue;
503
504 nl_band = nla_nest_start(msg, band);
505 if (!nl_band)
506 goto nla_put_failure;
507
508 /* add HT info */
509 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
510 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
511 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
512 &dev->wiphy.bands[band]->ht_cap.mcs);
513 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
514 dev->wiphy.bands[band]->ht_cap.cap);
515 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
516 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
517 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
518 dev->wiphy.bands[band]->ht_cap.ampdu_density);
519 }
520
521 /* add frequencies */
522 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
523 if (!nl_freqs)
524 goto nla_put_failure;
525
526 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
527 nl_freq = nla_nest_start(msg, i);
528 if (!nl_freq)
529 goto nla_put_failure;
530
531 chan = &dev->wiphy.bands[band]->channels[i];
532
533 if (nl80211_msg_put_channel(msg, chan))
534 goto nla_put_failure;
535
536 nla_nest_end(msg, nl_freq);
537 }
538
539 nla_nest_end(msg, nl_freqs);
540
541 /* add bitrates */
542 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
543 if (!nl_rates)
544 goto nla_put_failure;
545
546 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
547 nl_rate = nla_nest_start(msg, i);
548 if (!nl_rate)
549 goto nla_put_failure;
550
551 rate = &dev->wiphy.bands[band]->bitrates[i];
552 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
553 rate->bitrate);
554 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
555 NLA_PUT_FLAG(msg,
556 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
557
558 nla_nest_end(msg, nl_rate);
559 }
560
561 nla_nest_end(msg, nl_rates);
562
563 nla_nest_end(msg, nl_band);
564 }
565 nla_nest_end(msg, nl_bands);
566
567 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
568 if (!nl_cmds)
569 goto nla_put_failure;
570
571 i = 0;
572 #define CMD(op, n) \
573 do { \
574 if (dev->ops->op) { \
575 i++; \
576 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
577 } \
578 } while (0)
579
580 CMD(add_virtual_intf, NEW_INTERFACE);
581 CMD(change_virtual_intf, SET_INTERFACE);
582 CMD(add_key, NEW_KEY);
583 CMD(add_beacon, NEW_BEACON);
584 CMD(add_station, NEW_STATION);
585 CMD(add_mpath, NEW_MPATH);
586 CMD(set_mesh_params, SET_MESH_PARAMS);
587 CMD(change_bss, SET_BSS);
588 CMD(auth, AUTHENTICATE);
589 CMD(assoc, ASSOCIATE);
590 CMD(deauth, DEAUTHENTICATE);
591 CMD(disassoc, DISASSOCIATE);
592 CMD(join_ibss, JOIN_IBSS);
593 CMD(set_pmksa, SET_PMKSA);
594 CMD(del_pmksa, DEL_PMKSA);
595 CMD(flush_pmksa, FLUSH_PMKSA);
596 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
597 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
598 CMD(mgmt_tx, FRAME);
599 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
600 i++;
601 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
602 }
603 CMD(set_channel, SET_CHANNEL);
604
605 #undef CMD
606
607 if (dev->ops->connect || dev->ops->auth) {
608 i++;
609 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
610 }
611
612 if (dev->ops->disconnect || dev->ops->deauth) {
613 i++;
614 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
615 }
616
617 nla_nest_end(msg, nl_cmds);
618
619 if (mgmt_stypes) {
620 u16 stypes;
621 struct nlattr *nl_ftypes, *nl_ifs;
622 enum nl80211_iftype ift;
623
624 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
625 if (!nl_ifs)
626 goto nla_put_failure;
627
628 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
629 nl_ftypes = nla_nest_start(msg, ift);
630 if (!nl_ftypes)
631 goto nla_put_failure;
632 i = 0;
633 stypes = mgmt_stypes[ift].tx;
634 while (stypes) {
635 if (stypes & 1)
636 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
637 (i << 4) | IEEE80211_FTYPE_MGMT);
638 stypes >>= 1;
639 i++;
640 }
641 nla_nest_end(msg, nl_ftypes);
642 }
643
644 nla_nest_end(msg, nl_ifs);
645
646 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
647 if (!nl_ifs)
648 goto nla_put_failure;
649
650 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
651 nl_ftypes = nla_nest_start(msg, ift);
652 if (!nl_ftypes)
653 goto nla_put_failure;
654 i = 0;
655 stypes = mgmt_stypes[ift].rx;
656 while (stypes) {
657 if (stypes & 1)
658 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
659 (i << 4) | IEEE80211_FTYPE_MGMT);
660 stypes >>= 1;
661 i++;
662 }
663 nla_nest_end(msg, nl_ftypes);
664 }
665 nla_nest_end(msg, nl_ifs);
666 }
667
668 return genlmsg_end(msg, hdr);
669
670 nla_put_failure:
671 genlmsg_cancel(msg, hdr);
672 return -EMSGSIZE;
673 }
674
675 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
676 {
677 int idx = 0;
678 int start = cb->args[0];
679 struct cfg80211_registered_device *dev;
680
681 mutex_lock(&cfg80211_mutex);
682 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
683 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
684 continue;
685 if (++idx <= start)
686 continue;
687 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
688 cb->nlh->nlmsg_seq, NLM_F_MULTI,
689 dev) < 0) {
690 idx--;
691 break;
692 }
693 }
694 mutex_unlock(&cfg80211_mutex);
695
696 cb->args[0] = idx;
697
698 return skb->len;
699 }
700
701 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
702 {
703 struct sk_buff *msg;
704 struct cfg80211_registered_device *dev;
705
706 dev = cfg80211_get_dev_from_info(info);
707 if (IS_ERR(dev))
708 return PTR_ERR(dev);
709
710 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
711 if (!msg)
712 goto out_err;
713
714 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
715 goto out_free;
716
717 cfg80211_unlock_rdev(dev);
718
719 return genlmsg_reply(msg, info);
720
721 out_free:
722 nlmsg_free(msg);
723 out_err:
724 cfg80211_unlock_rdev(dev);
725 return -ENOBUFS;
726 }
727
728 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
729 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
730 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
731 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
732 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
733 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
734 };
735
736 static int parse_txq_params(struct nlattr *tb[],
737 struct ieee80211_txq_params *txq_params)
738 {
739 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
740 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
741 !tb[NL80211_TXQ_ATTR_AIFS])
742 return -EINVAL;
743
744 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
745 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
746 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
747 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
748 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
749
750 return 0;
751 }
752
753 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
754 {
755 /*
756 * You can only set the channel explicitly for AP, mesh
757 * and WDS type interfaces; all others have their channel
758 * managed via their respective "establish a connection"
759 * command (connect, join, ...)
760 *
761 * Monitors are special as they are normally slaved to
762 * whatever else is going on, so they behave as though
763 * you tried setting the wiphy channel itself.
764 */
765 return !wdev ||
766 wdev->iftype == NL80211_IFTYPE_AP ||
767 wdev->iftype == NL80211_IFTYPE_WDS ||
768 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
769 wdev->iftype == NL80211_IFTYPE_MONITOR;
770 }
771
772 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
773 struct wireless_dev *wdev,
774 struct genl_info *info)
775 {
776 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
777 u32 freq;
778 int result;
779
780 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
781 return -EINVAL;
782
783 if (!nl80211_can_set_dev_channel(wdev))
784 return -EOPNOTSUPP;
785
786 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
787 channel_type = nla_get_u32(info->attrs[
788 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
789 if (channel_type != NL80211_CHAN_NO_HT &&
790 channel_type != NL80211_CHAN_HT20 &&
791 channel_type != NL80211_CHAN_HT40PLUS &&
792 channel_type != NL80211_CHAN_HT40MINUS)
793 return -EINVAL;
794 }
795
796 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
797
798 mutex_lock(&rdev->devlist_mtx);
799 if (wdev) {
800 wdev_lock(wdev);
801 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
802 wdev_unlock(wdev);
803 } else {
804 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
805 }
806 mutex_unlock(&rdev->devlist_mtx);
807
808 return result;
809 }
810
811 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
812 {
813 struct cfg80211_registered_device *rdev;
814 struct net_device *netdev;
815 int result;
816
817 rtnl_lock();
818
819 result = get_rdev_dev_by_info_ifindex(info, &rdev, &netdev);
820 if (result)
821 goto unlock;
822
823 result = __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
824
825 unlock:
826 rtnl_unlock();
827
828 return result;
829 }
830
831 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
832 {
833 struct cfg80211_registered_device *rdev;
834 struct net_device *netdev = NULL;
835 struct wireless_dev *wdev;
836 int result = 0, rem_txq_params = 0;
837 struct nlattr *nl_txq_params;
838 u32 changed;
839 u8 retry_short = 0, retry_long = 0;
840 u32 frag_threshold = 0, rts_threshold = 0;
841 u8 coverage_class = 0;
842
843 rtnl_lock();
844
845 /*
846 * Try to find the wiphy and netdev. Normally this
847 * function shouldn't need the netdev, but this is
848 * done for backward compatibility -- previously
849 * setting the channel was done per wiphy, but now
850 * it is per netdev. Previous userland like hostapd
851 * also passed a netdev to set_wiphy, so that it is
852 * possible to let that go to the right netdev!
853 */
854 mutex_lock(&cfg80211_mutex);
855
856 if (info->attrs[NL80211_ATTR_IFINDEX]) {
857 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
858
859 netdev = dev_get_by_index(genl_info_net(info), ifindex);
860 if (netdev && netdev->ieee80211_ptr) {
861 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
862 mutex_lock(&rdev->mtx);
863 } else
864 netdev = NULL;
865 }
866
867 if (!netdev) {
868 rdev = __cfg80211_rdev_from_info(info);
869 if (IS_ERR(rdev)) {
870 mutex_unlock(&cfg80211_mutex);
871 result = PTR_ERR(rdev);
872 goto unlock;
873 }
874 wdev = NULL;
875 netdev = NULL;
876 result = 0;
877
878 mutex_lock(&rdev->mtx);
879 } else if (netif_running(netdev) &&
880 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
881 wdev = netdev->ieee80211_ptr;
882 else
883 wdev = NULL;
884
885 /*
886 * end workaround code, by now the rdev is available
887 * and locked, and wdev may or may not be NULL.
888 */
889
890 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
891 result = cfg80211_dev_rename(
892 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
893
894 mutex_unlock(&cfg80211_mutex);
895
896 if (result)
897 goto bad_res;
898
899 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
900 struct ieee80211_txq_params txq_params;
901 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
902
903 if (!rdev->ops->set_txq_params) {
904 result = -EOPNOTSUPP;
905 goto bad_res;
906 }
907
908 nla_for_each_nested(nl_txq_params,
909 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
910 rem_txq_params) {
911 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
912 nla_data(nl_txq_params),
913 nla_len(nl_txq_params),
914 txq_params_policy);
915 result = parse_txq_params(tb, &txq_params);
916 if (result)
917 goto bad_res;
918
919 result = rdev->ops->set_txq_params(&rdev->wiphy,
920 &txq_params);
921 if (result)
922 goto bad_res;
923 }
924 }
925
926 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
927 result = __nl80211_set_channel(rdev, wdev, info);
928 if (result)
929 goto bad_res;
930 }
931
932 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
933 enum nl80211_tx_power_setting type;
934 int idx, mbm = 0;
935
936 if (!rdev->ops->set_tx_power) {
937 result = -EOPNOTSUPP;
938 goto bad_res;
939 }
940
941 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
942 type = nla_get_u32(info->attrs[idx]);
943
944 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
945 (type != NL80211_TX_POWER_AUTOMATIC)) {
946 result = -EINVAL;
947 goto bad_res;
948 }
949
950 if (type != NL80211_TX_POWER_AUTOMATIC) {
951 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
952 mbm = nla_get_u32(info->attrs[idx]);
953 }
954
955 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
956 if (result)
957 goto bad_res;
958 }
959
960 changed = 0;
961
962 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
963 retry_short = nla_get_u8(
964 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
965 if (retry_short == 0) {
966 result = -EINVAL;
967 goto bad_res;
968 }
969 changed |= WIPHY_PARAM_RETRY_SHORT;
970 }
971
972 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
973 retry_long = nla_get_u8(
974 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
975 if (retry_long == 0) {
976 result = -EINVAL;
977 goto bad_res;
978 }
979 changed |= WIPHY_PARAM_RETRY_LONG;
980 }
981
982 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
983 frag_threshold = nla_get_u32(
984 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
985 if (frag_threshold < 256) {
986 result = -EINVAL;
987 goto bad_res;
988 }
989 if (frag_threshold != (u32) -1) {
990 /*
991 * Fragments (apart from the last one) are required to
992 * have even length. Make the fragmentation code
993 * simpler by stripping LSB should someone try to use
994 * odd threshold value.
995 */
996 frag_threshold &= ~0x1;
997 }
998 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
999 }
1000
1001 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1002 rts_threshold = nla_get_u32(
1003 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1004 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1005 }
1006
1007 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1008 coverage_class = nla_get_u8(
1009 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1010 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1011 }
1012
1013 if (changed) {
1014 u8 old_retry_short, old_retry_long;
1015 u32 old_frag_threshold, old_rts_threshold;
1016 u8 old_coverage_class;
1017
1018 if (!rdev->ops->set_wiphy_params) {
1019 result = -EOPNOTSUPP;
1020 goto bad_res;
1021 }
1022
1023 old_retry_short = rdev->wiphy.retry_short;
1024 old_retry_long = rdev->wiphy.retry_long;
1025 old_frag_threshold = rdev->wiphy.frag_threshold;
1026 old_rts_threshold = rdev->wiphy.rts_threshold;
1027 old_coverage_class = rdev->wiphy.coverage_class;
1028
1029 if (changed & WIPHY_PARAM_RETRY_SHORT)
1030 rdev->wiphy.retry_short = retry_short;
1031 if (changed & WIPHY_PARAM_RETRY_LONG)
1032 rdev->wiphy.retry_long = retry_long;
1033 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1034 rdev->wiphy.frag_threshold = frag_threshold;
1035 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1036 rdev->wiphy.rts_threshold = rts_threshold;
1037 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1038 rdev->wiphy.coverage_class = coverage_class;
1039
1040 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1041 if (result) {
1042 rdev->wiphy.retry_short = old_retry_short;
1043 rdev->wiphy.retry_long = old_retry_long;
1044 rdev->wiphy.frag_threshold = old_frag_threshold;
1045 rdev->wiphy.rts_threshold = old_rts_threshold;
1046 rdev->wiphy.coverage_class = old_coverage_class;
1047 }
1048 }
1049
1050 bad_res:
1051 mutex_unlock(&rdev->mtx);
1052 if (netdev)
1053 dev_put(netdev);
1054 unlock:
1055 rtnl_unlock();
1056 return result;
1057 }
1058
1059
1060 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
1061 struct cfg80211_registered_device *rdev,
1062 struct net_device *dev)
1063 {
1064 void *hdr;
1065
1066 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1067 if (!hdr)
1068 return -1;
1069
1070 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1071 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
1072 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
1073 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
1074
1075 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1076 rdev->devlist_generation ^
1077 (cfg80211_rdev_list_generation << 2));
1078
1079 return genlmsg_end(msg, hdr);
1080
1081 nla_put_failure:
1082 genlmsg_cancel(msg, hdr);
1083 return -EMSGSIZE;
1084 }
1085
1086 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1087 {
1088 int wp_idx = 0;
1089 int if_idx = 0;
1090 int wp_start = cb->args[0];
1091 int if_start = cb->args[1];
1092 struct cfg80211_registered_device *rdev;
1093 struct wireless_dev *wdev;
1094
1095 mutex_lock(&cfg80211_mutex);
1096 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1097 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
1098 continue;
1099 if (wp_idx < wp_start) {
1100 wp_idx++;
1101 continue;
1102 }
1103 if_idx = 0;
1104
1105 mutex_lock(&rdev->devlist_mtx);
1106 list_for_each_entry(wdev, &rdev->netdev_list, list) {
1107 if (if_idx < if_start) {
1108 if_idx++;
1109 continue;
1110 }
1111 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1112 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1113 rdev, wdev->netdev) < 0) {
1114 mutex_unlock(&rdev->devlist_mtx);
1115 goto out;
1116 }
1117 if_idx++;
1118 }
1119 mutex_unlock(&rdev->devlist_mtx);
1120
1121 wp_idx++;
1122 }
1123 out:
1124 mutex_unlock(&cfg80211_mutex);
1125
1126 cb->args[0] = wp_idx;
1127 cb->args[1] = if_idx;
1128
1129 return skb->len;
1130 }
1131
1132 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1133 {
1134 struct sk_buff *msg;
1135 struct cfg80211_registered_device *dev;
1136 struct net_device *netdev;
1137 int err;
1138
1139 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
1140 if (err)
1141 return err;
1142
1143 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1144 if (!msg)
1145 goto out_err;
1146
1147 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1148 dev, netdev) < 0)
1149 goto out_free;
1150
1151 dev_put(netdev);
1152 cfg80211_unlock_rdev(dev);
1153
1154 return genlmsg_reply(msg, info);
1155
1156 out_free:
1157 nlmsg_free(msg);
1158 out_err:
1159 dev_put(netdev);
1160 cfg80211_unlock_rdev(dev);
1161 return -ENOBUFS;
1162 }
1163
1164 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1165 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1166 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1167 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1168 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1169 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1170 };
1171
1172 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1173 {
1174 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1175 int flag;
1176
1177 *mntrflags = 0;
1178
1179 if (!nla)
1180 return -EINVAL;
1181
1182 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1183 nla, mntr_flags_policy))
1184 return -EINVAL;
1185
1186 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1187 if (flags[flag])
1188 *mntrflags |= (1<<flag);
1189
1190 return 0;
1191 }
1192
1193 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
1194 struct net_device *netdev, u8 use_4addr,
1195 enum nl80211_iftype iftype)
1196 {
1197 if (!use_4addr) {
1198 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
1199 return -EBUSY;
1200 return 0;
1201 }
1202
1203 switch (iftype) {
1204 case NL80211_IFTYPE_AP_VLAN:
1205 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1206 return 0;
1207 break;
1208 case NL80211_IFTYPE_STATION:
1209 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1210 return 0;
1211 break;
1212 default:
1213 break;
1214 }
1215
1216 return -EOPNOTSUPP;
1217 }
1218
1219 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1220 {
1221 struct cfg80211_registered_device *rdev;
1222 struct vif_params params;
1223 int err;
1224 enum nl80211_iftype otype, ntype;
1225 struct net_device *dev;
1226 u32 _flags, *flags = NULL;
1227 bool change = false;
1228
1229 memset(&params, 0, sizeof(params));
1230
1231 rtnl_lock();
1232
1233 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1234 if (err)
1235 goto unlock_rtnl;
1236
1237 otype = ntype = dev->ieee80211_ptr->iftype;
1238
1239 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1240 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1241 if (otype != ntype)
1242 change = true;
1243 if (ntype > NL80211_IFTYPE_MAX) {
1244 err = -EINVAL;
1245 goto unlock;
1246 }
1247 }
1248
1249 if (info->attrs[NL80211_ATTR_MESH_ID]) {
1250 if (ntype != NL80211_IFTYPE_MESH_POINT) {
1251 err = -EINVAL;
1252 goto unlock;
1253 }
1254 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1255 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1256 change = true;
1257 }
1258
1259 if (info->attrs[NL80211_ATTR_4ADDR]) {
1260 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1261 change = true;
1262 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1263 if (err)
1264 goto unlock;
1265 } else {
1266 params.use_4addr = -1;
1267 }
1268
1269 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1270 if (ntype != NL80211_IFTYPE_MONITOR) {
1271 err = -EINVAL;
1272 goto unlock;
1273 }
1274 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1275 &_flags);
1276 if (err)
1277 goto unlock;
1278
1279 flags = &_flags;
1280 change = true;
1281 }
1282
1283 if (change)
1284 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1285 else
1286 err = 0;
1287
1288 if (!err && params.use_4addr != -1)
1289 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1290
1291 unlock:
1292 dev_put(dev);
1293 cfg80211_unlock_rdev(rdev);
1294 unlock_rtnl:
1295 rtnl_unlock();
1296 return err;
1297 }
1298
1299 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1300 {
1301 struct cfg80211_registered_device *rdev;
1302 struct vif_params params;
1303 int err;
1304 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1305 u32 flags;
1306
1307 memset(&params, 0, sizeof(params));
1308
1309 if (!info->attrs[NL80211_ATTR_IFNAME])
1310 return -EINVAL;
1311
1312 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1313 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1314 if (type > NL80211_IFTYPE_MAX)
1315 return -EINVAL;
1316 }
1317
1318 rtnl_lock();
1319
1320 rdev = cfg80211_get_dev_from_info(info);
1321 if (IS_ERR(rdev)) {
1322 err = PTR_ERR(rdev);
1323 goto unlock_rtnl;
1324 }
1325
1326 if (!rdev->ops->add_virtual_intf ||
1327 !(rdev->wiphy.interface_modes & (1 << type))) {
1328 err = -EOPNOTSUPP;
1329 goto unlock;
1330 }
1331
1332 if (type == NL80211_IFTYPE_MESH_POINT &&
1333 info->attrs[NL80211_ATTR_MESH_ID]) {
1334 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1335 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1336 }
1337
1338 if (info->attrs[NL80211_ATTR_4ADDR]) {
1339 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1340 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1341 if (err)
1342 goto unlock;
1343 }
1344
1345 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1346 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1347 &flags);
1348 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1349 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1350 type, err ? NULL : &flags, &params);
1351
1352 unlock:
1353 cfg80211_unlock_rdev(rdev);
1354 unlock_rtnl:
1355 rtnl_unlock();
1356 return err;
1357 }
1358
1359 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1360 {
1361 struct cfg80211_registered_device *rdev;
1362 int err;
1363 struct net_device *dev;
1364
1365 rtnl_lock();
1366
1367 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1368 if (err)
1369 goto unlock_rtnl;
1370
1371 if (!rdev->ops->del_virtual_intf) {
1372 err = -EOPNOTSUPP;
1373 goto out;
1374 }
1375
1376 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1377
1378 out:
1379 cfg80211_unlock_rdev(rdev);
1380 dev_put(dev);
1381 unlock_rtnl:
1382 rtnl_unlock();
1383 return err;
1384 }
1385
1386 struct get_key_cookie {
1387 struct sk_buff *msg;
1388 int error;
1389 int idx;
1390 };
1391
1392 static void get_key_callback(void *c, struct key_params *params)
1393 {
1394 struct nlattr *key;
1395 struct get_key_cookie *cookie = c;
1396
1397 if (params->key)
1398 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1399 params->key_len, params->key);
1400
1401 if (params->seq)
1402 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1403 params->seq_len, params->seq);
1404
1405 if (params->cipher)
1406 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1407 params->cipher);
1408
1409 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1410 if (!key)
1411 goto nla_put_failure;
1412
1413 if (params->key)
1414 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1415 params->key_len, params->key);
1416
1417 if (params->seq)
1418 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1419 params->seq_len, params->seq);
1420
1421 if (params->cipher)
1422 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1423 params->cipher);
1424
1425 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1426
1427 nla_nest_end(cookie->msg, key);
1428
1429 return;
1430 nla_put_failure:
1431 cookie->error = 1;
1432 }
1433
1434 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1435 {
1436 struct cfg80211_registered_device *rdev;
1437 int err;
1438 struct net_device *dev;
1439 u8 key_idx = 0;
1440 u8 *mac_addr = NULL;
1441 struct get_key_cookie cookie = {
1442 .error = 0,
1443 };
1444 void *hdr;
1445 struct sk_buff *msg;
1446
1447 if (info->attrs[NL80211_ATTR_KEY_IDX])
1448 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1449
1450 if (key_idx > 5)
1451 return -EINVAL;
1452
1453 if (info->attrs[NL80211_ATTR_MAC])
1454 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1455
1456 rtnl_lock();
1457
1458 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1459 if (err)
1460 goto unlock_rtnl;
1461
1462 if (!rdev->ops->get_key) {
1463 err = -EOPNOTSUPP;
1464 goto out;
1465 }
1466
1467 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1468 if (!msg) {
1469 err = -ENOMEM;
1470 goto out;
1471 }
1472
1473 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1474 NL80211_CMD_NEW_KEY);
1475
1476 if (IS_ERR(hdr)) {
1477 err = PTR_ERR(hdr);
1478 goto free_msg;
1479 }
1480
1481 cookie.msg = msg;
1482 cookie.idx = key_idx;
1483
1484 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1485 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1486 if (mac_addr)
1487 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1488
1489 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
1490 &cookie, get_key_callback);
1491
1492 if (err)
1493 goto free_msg;
1494
1495 if (cookie.error)
1496 goto nla_put_failure;
1497
1498 genlmsg_end(msg, hdr);
1499 err = genlmsg_reply(msg, info);
1500 goto out;
1501
1502 nla_put_failure:
1503 err = -ENOBUFS;
1504 free_msg:
1505 nlmsg_free(msg);
1506 out:
1507 cfg80211_unlock_rdev(rdev);
1508 dev_put(dev);
1509 unlock_rtnl:
1510 rtnl_unlock();
1511
1512 return err;
1513 }
1514
1515 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1516 {
1517 struct cfg80211_registered_device *rdev;
1518 struct key_parse key;
1519 int err;
1520 struct net_device *dev;
1521 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1522 u8 key_index);
1523
1524 err = nl80211_parse_key(info, &key);
1525 if (err)
1526 return err;
1527
1528 if (key.idx < 0)
1529 return -EINVAL;
1530
1531 /* only support setting default key */
1532 if (!key.def && !key.defmgmt)
1533 return -EINVAL;
1534
1535 rtnl_lock();
1536
1537 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1538 if (err)
1539 goto unlock_rtnl;
1540
1541 if (key.def)
1542 func = rdev->ops->set_default_key;
1543 else
1544 func = rdev->ops->set_default_mgmt_key;
1545
1546 if (!func) {
1547 err = -EOPNOTSUPP;
1548 goto out;
1549 }
1550
1551 wdev_lock(dev->ieee80211_ptr);
1552 err = nl80211_key_allowed(dev->ieee80211_ptr);
1553 if (!err)
1554 err = func(&rdev->wiphy, dev, key.idx);
1555
1556 #ifdef CONFIG_CFG80211_WEXT
1557 if (!err) {
1558 if (func == rdev->ops->set_default_key)
1559 dev->ieee80211_ptr->wext.default_key = key.idx;
1560 else
1561 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1562 }
1563 #endif
1564 wdev_unlock(dev->ieee80211_ptr);
1565
1566 out:
1567 cfg80211_unlock_rdev(rdev);
1568 dev_put(dev);
1569
1570 unlock_rtnl:
1571 rtnl_unlock();
1572
1573 return err;
1574 }
1575
1576 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1577 {
1578 struct cfg80211_registered_device *rdev;
1579 int err;
1580 struct net_device *dev;
1581 struct key_parse key;
1582 u8 *mac_addr = NULL;
1583
1584 err = nl80211_parse_key(info, &key);
1585 if (err)
1586 return err;
1587
1588 if (!key.p.key)
1589 return -EINVAL;
1590
1591 if (info->attrs[NL80211_ATTR_MAC])
1592 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1593
1594 rtnl_lock();
1595
1596 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1597 if (err)
1598 goto unlock_rtnl;
1599
1600 if (!rdev->ops->add_key) {
1601 err = -EOPNOTSUPP;
1602 goto out;
1603 }
1604
1605 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1606 err = -EINVAL;
1607 goto out;
1608 }
1609
1610 wdev_lock(dev->ieee80211_ptr);
1611 err = nl80211_key_allowed(dev->ieee80211_ptr);
1612 if (!err)
1613 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1614 mac_addr, &key.p);
1615 wdev_unlock(dev->ieee80211_ptr);
1616
1617 out:
1618 cfg80211_unlock_rdev(rdev);
1619 dev_put(dev);
1620 unlock_rtnl:
1621 rtnl_unlock();
1622
1623 return err;
1624 }
1625
1626 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1627 {
1628 struct cfg80211_registered_device *rdev;
1629 int err;
1630 struct net_device *dev;
1631 u8 *mac_addr = NULL;
1632 struct key_parse key;
1633
1634 err = nl80211_parse_key(info, &key);
1635 if (err)
1636 return err;
1637
1638 if (info->attrs[NL80211_ATTR_MAC])
1639 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1640
1641 rtnl_lock();
1642
1643 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1644 if (err)
1645 goto unlock_rtnl;
1646
1647 if (!rdev->ops->del_key) {
1648 err = -EOPNOTSUPP;
1649 goto out;
1650 }
1651
1652 wdev_lock(dev->ieee80211_ptr);
1653 err = nl80211_key_allowed(dev->ieee80211_ptr);
1654 if (!err)
1655 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
1656
1657 #ifdef CONFIG_CFG80211_WEXT
1658 if (!err) {
1659 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1660 dev->ieee80211_ptr->wext.default_key = -1;
1661 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1662 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1663 }
1664 #endif
1665 wdev_unlock(dev->ieee80211_ptr);
1666
1667 out:
1668 cfg80211_unlock_rdev(rdev);
1669 dev_put(dev);
1670
1671 unlock_rtnl:
1672 rtnl_unlock();
1673
1674 return err;
1675 }
1676
1677 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1678 {
1679 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1680 struct beacon_parameters *info);
1681 struct cfg80211_registered_device *rdev;
1682 int err;
1683 struct net_device *dev;
1684 struct beacon_parameters params;
1685 int haveinfo = 0;
1686
1687 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1688 return -EINVAL;
1689
1690 rtnl_lock();
1691
1692 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1693 if (err)
1694 goto unlock_rtnl;
1695
1696 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1697 err = -EOPNOTSUPP;
1698 goto out;
1699 }
1700
1701 switch (info->genlhdr->cmd) {
1702 case NL80211_CMD_NEW_BEACON:
1703 /* these are required for NEW_BEACON */
1704 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1705 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1706 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1707 err = -EINVAL;
1708 goto out;
1709 }
1710
1711 call = rdev->ops->add_beacon;
1712 break;
1713 case NL80211_CMD_SET_BEACON:
1714 call = rdev->ops->set_beacon;
1715 break;
1716 default:
1717 WARN_ON(1);
1718 err = -EOPNOTSUPP;
1719 goto out;
1720 }
1721
1722 if (!call) {
1723 err = -EOPNOTSUPP;
1724 goto out;
1725 }
1726
1727 memset(&params, 0, sizeof(params));
1728
1729 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1730 params.interval =
1731 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1732 haveinfo = 1;
1733 }
1734
1735 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1736 params.dtim_period =
1737 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1738 haveinfo = 1;
1739 }
1740
1741 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1742 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1743 params.head_len =
1744 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1745 haveinfo = 1;
1746 }
1747
1748 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1749 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1750 params.tail_len =
1751 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1752 haveinfo = 1;
1753 }
1754
1755 if (!haveinfo) {
1756 err = -EINVAL;
1757 goto out;
1758 }
1759
1760 err = call(&rdev->wiphy, dev, &params);
1761
1762 out:
1763 cfg80211_unlock_rdev(rdev);
1764 dev_put(dev);
1765 unlock_rtnl:
1766 rtnl_unlock();
1767
1768 return err;
1769 }
1770
1771 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1772 {
1773 struct cfg80211_registered_device *rdev;
1774 int err;
1775 struct net_device *dev;
1776
1777 rtnl_lock();
1778
1779 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1780 if (err)
1781 goto unlock_rtnl;
1782
1783 if (!rdev->ops->del_beacon) {
1784 err = -EOPNOTSUPP;
1785 goto out;
1786 }
1787
1788 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1789 err = -EOPNOTSUPP;
1790 goto out;
1791 }
1792 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
1793
1794 out:
1795 cfg80211_unlock_rdev(rdev);
1796 dev_put(dev);
1797 unlock_rtnl:
1798 rtnl_unlock();
1799
1800 return err;
1801 }
1802
1803 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1804 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1805 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1806 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1807 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1808 };
1809
1810 static int parse_station_flags(struct genl_info *info,
1811 struct station_parameters *params)
1812 {
1813 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1814 struct nlattr *nla;
1815 int flag;
1816
1817 /*
1818 * Try parsing the new attribute first so userspace
1819 * can specify both for older kernels.
1820 */
1821 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1822 if (nla) {
1823 struct nl80211_sta_flag_update *sta_flags;
1824
1825 sta_flags = nla_data(nla);
1826 params->sta_flags_mask = sta_flags->mask;
1827 params->sta_flags_set = sta_flags->set;
1828 if ((params->sta_flags_mask |
1829 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1830 return -EINVAL;
1831 return 0;
1832 }
1833
1834 /* if present, parse the old attribute */
1835
1836 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1837 if (!nla)
1838 return 0;
1839
1840 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1841 nla, sta_flags_policy))
1842 return -EINVAL;
1843
1844 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1845 params->sta_flags_mask &= ~1;
1846
1847 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1848 if (flags[flag])
1849 params->sta_flags_set |= (1<<flag);
1850
1851 return 0;
1852 }
1853
1854 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1855 int flags, struct net_device *dev,
1856 const u8 *mac_addr, struct station_info *sinfo)
1857 {
1858 void *hdr;
1859 struct nlattr *sinfoattr, *txrate;
1860 u16 bitrate;
1861
1862 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1863 if (!hdr)
1864 return -1;
1865
1866 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1867 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1868
1869 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1870
1871 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1872 if (!sinfoattr)
1873 goto nla_put_failure;
1874 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1875 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1876 sinfo->inactive_time);
1877 if (sinfo->filled & STATION_INFO_RX_BYTES)
1878 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1879 sinfo->rx_bytes);
1880 if (sinfo->filled & STATION_INFO_TX_BYTES)
1881 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1882 sinfo->tx_bytes);
1883 if (sinfo->filled & STATION_INFO_LLID)
1884 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1885 sinfo->llid);
1886 if (sinfo->filled & STATION_INFO_PLID)
1887 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1888 sinfo->plid);
1889 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1890 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1891 sinfo->plink_state);
1892 if (sinfo->filled & STATION_INFO_SIGNAL)
1893 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1894 sinfo->signal);
1895 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1896 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1897 if (!txrate)
1898 goto nla_put_failure;
1899
1900 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1901 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
1902 if (bitrate > 0)
1903 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1904
1905 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1906 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1907 sinfo->txrate.mcs);
1908 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1909 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1910 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1911 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1912
1913 nla_nest_end(msg, txrate);
1914 }
1915 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1916 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1917 sinfo->rx_packets);
1918 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1919 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1920 sinfo->tx_packets);
1921 nla_nest_end(msg, sinfoattr);
1922
1923 return genlmsg_end(msg, hdr);
1924
1925 nla_put_failure:
1926 genlmsg_cancel(msg, hdr);
1927 return -EMSGSIZE;
1928 }
1929
1930 static int nl80211_dump_station(struct sk_buff *skb,
1931 struct netlink_callback *cb)
1932 {
1933 struct station_info sinfo;
1934 struct cfg80211_registered_device *dev;
1935 struct net_device *netdev;
1936 u8 mac_addr[ETH_ALEN];
1937 int ifidx = cb->args[0];
1938 int sta_idx = cb->args[1];
1939 int err;
1940
1941 if (!ifidx)
1942 ifidx = nl80211_get_ifidx(cb);
1943 if (ifidx < 0)
1944 return ifidx;
1945
1946 rtnl_lock();
1947
1948 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
1949 if (!netdev) {
1950 err = -ENODEV;
1951 goto out_rtnl;
1952 }
1953
1954 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
1955 if (IS_ERR(dev)) {
1956 err = PTR_ERR(dev);
1957 goto out_rtnl;
1958 }
1959
1960 if (!dev->ops->dump_station) {
1961 err = -EOPNOTSUPP;
1962 goto out_err;
1963 }
1964
1965 while (1) {
1966 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1967 mac_addr, &sinfo);
1968 if (err == -ENOENT)
1969 break;
1970 if (err)
1971 goto out_err;
1972
1973 if (nl80211_send_station(skb,
1974 NETLINK_CB(cb->skb).pid,
1975 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1976 netdev, mac_addr,
1977 &sinfo) < 0)
1978 goto out;
1979
1980 sta_idx++;
1981 }
1982
1983
1984 out:
1985 cb->args[1] = sta_idx;
1986 err = skb->len;
1987 out_err:
1988 cfg80211_unlock_rdev(dev);
1989 out_rtnl:
1990 rtnl_unlock();
1991
1992 return err;
1993 }
1994
1995 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1996 {
1997 struct cfg80211_registered_device *rdev;
1998 int err;
1999 struct net_device *dev;
2000 struct station_info sinfo;
2001 struct sk_buff *msg;
2002 u8 *mac_addr = NULL;
2003
2004 memset(&sinfo, 0, sizeof(sinfo));
2005
2006 if (!info->attrs[NL80211_ATTR_MAC])
2007 return -EINVAL;
2008
2009 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2010
2011 rtnl_lock();
2012
2013 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2014 if (err)
2015 goto out_rtnl;
2016
2017 if (!rdev->ops->get_station) {
2018 err = -EOPNOTSUPP;
2019 goto out;
2020 }
2021
2022 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2023 if (err)
2024 goto out;
2025
2026 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2027 if (!msg)
2028 goto out;
2029
2030 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2031 dev, mac_addr, &sinfo) < 0)
2032 goto out_free;
2033
2034 err = genlmsg_reply(msg, info);
2035 goto out;
2036
2037 out_free:
2038 nlmsg_free(msg);
2039 out:
2040 cfg80211_unlock_rdev(rdev);
2041 dev_put(dev);
2042 out_rtnl:
2043 rtnl_unlock();
2044
2045 return err;
2046 }
2047
2048 /*
2049 * Get vlan interface making sure it is running and on the right wiphy.
2050 */
2051 static int get_vlan(struct genl_info *info,
2052 struct cfg80211_registered_device *rdev,
2053 struct net_device **vlan)
2054 {
2055 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
2056 *vlan = NULL;
2057
2058 if (vlanattr) {
2059 *vlan = dev_get_by_index(genl_info_net(info),
2060 nla_get_u32(vlanattr));
2061 if (!*vlan)
2062 return -ENODEV;
2063 if (!(*vlan)->ieee80211_ptr)
2064 return -EINVAL;
2065 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2066 return -EINVAL;
2067 if (!netif_running(*vlan))
2068 return -ENETDOWN;
2069 }
2070 return 0;
2071 }
2072
2073 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2074 {
2075 struct cfg80211_registered_device *rdev;
2076 int err;
2077 struct net_device *dev;
2078 struct station_parameters params;
2079 u8 *mac_addr = NULL;
2080
2081 memset(&params, 0, sizeof(params));
2082
2083 params.listen_interval = -1;
2084
2085 if (info->attrs[NL80211_ATTR_STA_AID])
2086 return -EINVAL;
2087
2088 if (!info->attrs[NL80211_ATTR_MAC])
2089 return -EINVAL;
2090
2091 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2092
2093 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2094 params.supported_rates =
2095 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2096 params.supported_rates_len =
2097 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2098 }
2099
2100 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2101 params.listen_interval =
2102 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2103
2104 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2105 params.ht_capa =
2106 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2107
2108 if (parse_station_flags(info, &params))
2109 return -EINVAL;
2110
2111 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2112 params.plink_action =
2113 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2114
2115 rtnl_lock();
2116
2117 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2118 if (err)
2119 goto out_rtnl;
2120
2121 err = get_vlan(info, rdev, &params.vlan);
2122 if (err)
2123 goto out;
2124
2125 /* validate settings */
2126 err = 0;
2127
2128 switch (dev->ieee80211_ptr->iftype) {
2129 case NL80211_IFTYPE_AP:
2130 case NL80211_IFTYPE_AP_VLAN:
2131 /* disallow mesh-specific things */
2132 if (params.plink_action)
2133 err = -EINVAL;
2134 break;
2135 case NL80211_IFTYPE_STATION:
2136 /* disallow everything but AUTHORIZED flag */
2137 if (params.plink_action)
2138 err = -EINVAL;
2139 if (params.vlan)
2140 err = -EINVAL;
2141 if (params.supported_rates)
2142 err = -EINVAL;
2143 if (params.ht_capa)
2144 err = -EINVAL;
2145 if (params.listen_interval >= 0)
2146 err = -EINVAL;
2147 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2148 err = -EINVAL;
2149 break;
2150 case NL80211_IFTYPE_MESH_POINT:
2151 /* disallow things mesh doesn't support */
2152 if (params.vlan)
2153 err = -EINVAL;
2154 if (params.ht_capa)
2155 err = -EINVAL;
2156 if (params.listen_interval >= 0)
2157 err = -EINVAL;
2158 if (params.supported_rates)
2159 err = -EINVAL;
2160 if (params.sta_flags_mask)
2161 err = -EINVAL;
2162 break;
2163 default:
2164 err = -EINVAL;
2165 }
2166
2167 if (err)
2168 goto out;
2169
2170 if (!rdev->ops->change_station) {
2171 err = -EOPNOTSUPP;
2172 goto out;
2173 }
2174
2175 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
2176
2177 out:
2178 if (params.vlan)
2179 dev_put(params.vlan);
2180 cfg80211_unlock_rdev(rdev);
2181 dev_put(dev);
2182 out_rtnl:
2183 rtnl_unlock();
2184
2185 return err;
2186 }
2187
2188 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2189 {
2190 struct cfg80211_registered_device *rdev;
2191 int err;
2192 struct net_device *dev;
2193 struct station_parameters params;
2194 u8 *mac_addr = NULL;
2195
2196 memset(&params, 0, sizeof(params));
2197
2198 if (!info->attrs[NL80211_ATTR_MAC])
2199 return -EINVAL;
2200
2201 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2202 return -EINVAL;
2203
2204 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2205 return -EINVAL;
2206
2207 if (!info->attrs[NL80211_ATTR_STA_AID])
2208 return -EINVAL;
2209
2210 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2211 params.supported_rates =
2212 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2213 params.supported_rates_len =
2214 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2215 params.listen_interval =
2216 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2217
2218 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2219 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2220 return -EINVAL;
2221
2222 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2223 params.ht_capa =
2224 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2225
2226 if (parse_station_flags(info, &params))
2227 return -EINVAL;
2228
2229 rtnl_lock();
2230
2231 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2232 if (err)
2233 goto out_rtnl;
2234
2235 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2236 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN) {
2237 err = -EINVAL;
2238 goto out;
2239 }
2240
2241 err = get_vlan(info, rdev, &params.vlan);
2242 if (err)
2243 goto out;
2244
2245 /* validate settings */
2246 err = 0;
2247
2248 if (!rdev->ops->add_station) {
2249 err = -EOPNOTSUPP;
2250 goto out;
2251 }
2252
2253 if (!netif_running(dev)) {
2254 err = -ENETDOWN;
2255 goto out;
2256 }
2257
2258 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2259
2260 out:
2261 if (params.vlan)
2262 dev_put(params.vlan);
2263 cfg80211_unlock_rdev(rdev);
2264 dev_put(dev);
2265 out_rtnl:
2266 rtnl_unlock();
2267
2268 return err;
2269 }
2270
2271 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2272 {
2273 struct cfg80211_registered_device *rdev;
2274 int err;
2275 struct net_device *dev;
2276 u8 *mac_addr = NULL;
2277
2278 if (info->attrs[NL80211_ATTR_MAC])
2279 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2280
2281 rtnl_lock();
2282
2283 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2284 if (err)
2285 goto out_rtnl;
2286
2287 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2288 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2289 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2290 err = -EINVAL;
2291 goto out;
2292 }
2293
2294 if (!rdev->ops->del_station) {
2295 err = -EOPNOTSUPP;
2296 goto out;
2297 }
2298
2299 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2300
2301 out:
2302 cfg80211_unlock_rdev(rdev);
2303 dev_put(dev);
2304 out_rtnl:
2305 rtnl_unlock();
2306
2307 return err;
2308 }
2309
2310 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2311 int flags, struct net_device *dev,
2312 u8 *dst, u8 *next_hop,
2313 struct mpath_info *pinfo)
2314 {
2315 void *hdr;
2316 struct nlattr *pinfoattr;
2317
2318 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2319 if (!hdr)
2320 return -1;
2321
2322 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2323 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2324 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2325
2326 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2327
2328 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2329 if (!pinfoattr)
2330 goto nla_put_failure;
2331 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2332 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2333 pinfo->frame_qlen);
2334 if (pinfo->filled & MPATH_INFO_SN)
2335 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2336 pinfo->sn);
2337 if (pinfo->filled & MPATH_INFO_METRIC)
2338 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2339 pinfo->metric);
2340 if (pinfo->filled & MPATH_INFO_EXPTIME)
2341 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2342 pinfo->exptime);
2343 if (pinfo->filled & MPATH_INFO_FLAGS)
2344 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2345 pinfo->flags);
2346 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2347 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2348 pinfo->discovery_timeout);
2349 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2350 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2351 pinfo->discovery_retries);
2352
2353 nla_nest_end(msg, pinfoattr);
2354
2355 return genlmsg_end(msg, hdr);
2356
2357 nla_put_failure:
2358 genlmsg_cancel(msg, hdr);
2359 return -EMSGSIZE;
2360 }
2361
2362 static int nl80211_dump_mpath(struct sk_buff *skb,
2363 struct netlink_callback *cb)
2364 {
2365 struct mpath_info pinfo;
2366 struct cfg80211_registered_device *dev;
2367 struct net_device *netdev;
2368 u8 dst[ETH_ALEN];
2369 u8 next_hop[ETH_ALEN];
2370 int ifidx = cb->args[0];
2371 int path_idx = cb->args[1];
2372 int err;
2373
2374 if (!ifidx)
2375 ifidx = nl80211_get_ifidx(cb);
2376 if (ifidx < 0)
2377 return ifidx;
2378
2379 rtnl_lock();
2380
2381 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
2382 if (!netdev) {
2383 err = -ENODEV;
2384 goto out_rtnl;
2385 }
2386
2387 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
2388 if (IS_ERR(dev)) {
2389 err = PTR_ERR(dev);
2390 goto out_rtnl;
2391 }
2392
2393 if (!dev->ops->dump_mpath) {
2394 err = -EOPNOTSUPP;
2395 goto out_err;
2396 }
2397
2398 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2399 err = -EOPNOTSUPP;
2400 goto out_err;
2401 }
2402
2403 while (1) {
2404 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2405 dst, next_hop, &pinfo);
2406 if (err == -ENOENT)
2407 break;
2408 if (err)
2409 goto out_err;
2410
2411 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2412 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2413 netdev, dst, next_hop,
2414 &pinfo) < 0)
2415 goto out;
2416
2417 path_idx++;
2418 }
2419
2420
2421 out:
2422 cb->args[1] = path_idx;
2423 err = skb->len;
2424 out_err:
2425 cfg80211_unlock_rdev(dev);
2426 out_rtnl:
2427 rtnl_unlock();
2428
2429 return err;
2430 }
2431
2432 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2433 {
2434 struct cfg80211_registered_device *rdev;
2435 int err;
2436 struct net_device *dev;
2437 struct mpath_info pinfo;
2438 struct sk_buff *msg;
2439 u8 *dst = NULL;
2440 u8 next_hop[ETH_ALEN];
2441
2442 memset(&pinfo, 0, sizeof(pinfo));
2443
2444 if (!info->attrs[NL80211_ATTR_MAC])
2445 return -EINVAL;
2446
2447 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2448
2449 rtnl_lock();
2450
2451 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2452 if (err)
2453 goto out_rtnl;
2454
2455 if (!rdev->ops->get_mpath) {
2456 err = -EOPNOTSUPP;
2457 goto out;
2458 }
2459
2460 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2461 err = -EOPNOTSUPP;
2462 goto out;
2463 }
2464
2465 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2466 if (err)
2467 goto out;
2468
2469 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2470 if (!msg)
2471 goto out;
2472
2473 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2474 dev, dst, next_hop, &pinfo) < 0)
2475 goto out_free;
2476
2477 err = genlmsg_reply(msg, info);
2478 goto out;
2479
2480 out_free:
2481 nlmsg_free(msg);
2482 out:
2483 cfg80211_unlock_rdev(rdev);
2484 dev_put(dev);
2485 out_rtnl:
2486 rtnl_unlock();
2487
2488 return err;
2489 }
2490
2491 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2492 {
2493 struct cfg80211_registered_device *rdev;
2494 int err;
2495 struct net_device *dev;
2496 u8 *dst = NULL;
2497 u8 *next_hop = NULL;
2498
2499 if (!info->attrs[NL80211_ATTR_MAC])
2500 return -EINVAL;
2501
2502 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2503 return -EINVAL;
2504
2505 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2506 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2507
2508 rtnl_lock();
2509
2510 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2511 if (err)
2512 goto out_rtnl;
2513
2514 if (!rdev->ops->change_mpath) {
2515 err = -EOPNOTSUPP;
2516 goto out;
2517 }
2518
2519 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2520 err = -EOPNOTSUPP;
2521 goto out;
2522 }
2523
2524 if (!netif_running(dev)) {
2525 err = -ENETDOWN;
2526 goto out;
2527 }
2528
2529 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2530
2531 out:
2532 cfg80211_unlock_rdev(rdev);
2533 dev_put(dev);
2534 out_rtnl:
2535 rtnl_unlock();
2536
2537 return err;
2538 }
2539 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2540 {
2541 struct cfg80211_registered_device *rdev;
2542 int err;
2543 struct net_device *dev;
2544 u8 *dst = NULL;
2545 u8 *next_hop = NULL;
2546
2547 if (!info->attrs[NL80211_ATTR_MAC])
2548 return -EINVAL;
2549
2550 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2551 return -EINVAL;
2552
2553 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2554 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2555
2556 rtnl_lock();
2557
2558 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2559 if (err)
2560 goto out_rtnl;
2561
2562 if (!rdev->ops->add_mpath) {
2563 err = -EOPNOTSUPP;
2564 goto out;
2565 }
2566
2567 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2568 err = -EOPNOTSUPP;
2569 goto out;
2570 }
2571
2572 if (!netif_running(dev)) {
2573 err = -ENETDOWN;
2574 goto out;
2575 }
2576
2577 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2578
2579 out:
2580 cfg80211_unlock_rdev(rdev);
2581 dev_put(dev);
2582 out_rtnl:
2583 rtnl_unlock();
2584
2585 return err;
2586 }
2587
2588 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2589 {
2590 struct cfg80211_registered_device *rdev;
2591 int err;
2592 struct net_device *dev;
2593 u8 *dst = NULL;
2594
2595 if (info->attrs[NL80211_ATTR_MAC])
2596 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2597
2598 rtnl_lock();
2599
2600 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2601 if (err)
2602 goto out_rtnl;
2603
2604 if (!rdev->ops->del_mpath) {
2605 err = -EOPNOTSUPP;
2606 goto out;
2607 }
2608
2609 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2610
2611 out:
2612 cfg80211_unlock_rdev(rdev);
2613 dev_put(dev);
2614 out_rtnl:
2615 rtnl_unlock();
2616
2617 return err;
2618 }
2619
2620 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2621 {
2622 struct cfg80211_registered_device *rdev;
2623 int err;
2624 struct net_device *dev;
2625 struct bss_parameters params;
2626
2627 memset(&params, 0, sizeof(params));
2628 /* default to not changing parameters */
2629 params.use_cts_prot = -1;
2630 params.use_short_preamble = -1;
2631 params.use_short_slot_time = -1;
2632 params.ap_isolate = -1;
2633
2634 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2635 params.use_cts_prot =
2636 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2637 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2638 params.use_short_preamble =
2639 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2640 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2641 params.use_short_slot_time =
2642 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2643 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2644 params.basic_rates =
2645 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2646 params.basic_rates_len =
2647 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2648 }
2649 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2650 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
2651
2652 rtnl_lock();
2653
2654 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2655 if (err)
2656 goto out_rtnl;
2657
2658 if (!rdev->ops->change_bss) {
2659 err = -EOPNOTSUPP;
2660 goto out;
2661 }
2662
2663 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2664 err = -EOPNOTSUPP;
2665 goto out;
2666 }
2667
2668 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2669
2670 out:
2671 cfg80211_unlock_rdev(rdev);
2672 dev_put(dev);
2673 out_rtnl:
2674 rtnl_unlock();
2675
2676 return err;
2677 }
2678
2679 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2680 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2681 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2682 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2683 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2684 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2685 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2686 };
2687
2688 static int parse_reg_rule(struct nlattr *tb[],
2689 struct ieee80211_reg_rule *reg_rule)
2690 {
2691 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2692 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2693
2694 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2695 return -EINVAL;
2696 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2697 return -EINVAL;
2698 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2699 return -EINVAL;
2700 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2701 return -EINVAL;
2702 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2703 return -EINVAL;
2704
2705 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2706
2707 freq_range->start_freq_khz =
2708 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2709 freq_range->end_freq_khz =
2710 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2711 freq_range->max_bandwidth_khz =
2712 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2713
2714 power_rule->max_eirp =
2715 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2716
2717 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2718 power_rule->max_antenna_gain =
2719 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2720
2721 return 0;
2722 }
2723
2724 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2725 {
2726 int r;
2727 char *data = NULL;
2728
2729 /*
2730 * You should only get this when cfg80211 hasn't yet initialized
2731 * completely when built-in to the kernel right between the time
2732 * window between nl80211_init() and regulatory_init(), if that is
2733 * even possible.
2734 */
2735 mutex_lock(&cfg80211_mutex);
2736 if (unlikely(!cfg80211_regdomain)) {
2737 mutex_unlock(&cfg80211_mutex);
2738 return -EINPROGRESS;
2739 }
2740 mutex_unlock(&cfg80211_mutex);
2741
2742 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2743 return -EINVAL;
2744
2745 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2746
2747 r = regulatory_hint_user(data);
2748
2749 return r;
2750 }
2751
2752 static int nl80211_get_mesh_params(struct sk_buff *skb,
2753 struct genl_info *info)
2754 {
2755 struct cfg80211_registered_device *rdev;
2756 struct mesh_config cur_params;
2757 int err;
2758 struct net_device *dev;
2759 void *hdr;
2760 struct nlattr *pinfoattr;
2761 struct sk_buff *msg;
2762
2763 rtnl_lock();
2764
2765 /* Look up our device */
2766 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2767 if (err)
2768 goto out_rtnl;
2769
2770 if (!rdev->ops->get_mesh_params) {
2771 err = -EOPNOTSUPP;
2772 goto out;
2773 }
2774
2775 /* Get the mesh params */
2776 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2777 if (err)
2778 goto out;
2779
2780 /* Draw up a netlink message to send back */
2781 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2782 if (!msg) {
2783 err = -ENOBUFS;
2784 goto out;
2785 }
2786 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2787 NL80211_CMD_GET_MESH_PARAMS);
2788 if (!hdr)
2789 goto nla_put_failure;
2790 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2791 if (!pinfoattr)
2792 goto nla_put_failure;
2793 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2794 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2795 cur_params.dot11MeshRetryTimeout);
2796 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2797 cur_params.dot11MeshConfirmTimeout);
2798 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2799 cur_params.dot11MeshHoldingTimeout);
2800 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2801 cur_params.dot11MeshMaxPeerLinks);
2802 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2803 cur_params.dot11MeshMaxRetries);
2804 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2805 cur_params.dot11MeshTTL);
2806 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2807 cur_params.auto_open_plinks);
2808 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2809 cur_params.dot11MeshHWMPmaxPREQretries);
2810 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2811 cur_params.path_refresh_time);
2812 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2813 cur_params.min_discovery_timeout);
2814 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2815 cur_params.dot11MeshHWMPactivePathTimeout);
2816 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2817 cur_params.dot11MeshHWMPpreqMinInterval);
2818 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2819 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2820 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2821 cur_params.dot11MeshHWMPRootMode);
2822 nla_nest_end(msg, pinfoattr);
2823 genlmsg_end(msg, hdr);
2824 err = genlmsg_reply(msg, info);
2825 goto out;
2826
2827 nla_put_failure:
2828 genlmsg_cancel(msg, hdr);
2829 nlmsg_free(msg);
2830 err = -EMSGSIZE;
2831 out:
2832 /* Cleanup */
2833 cfg80211_unlock_rdev(rdev);
2834 dev_put(dev);
2835 out_rtnl:
2836 rtnl_unlock();
2837
2838 return err;
2839 }
2840
2841 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2842 do {\
2843 if (table[attr_num]) {\
2844 cfg.param = nla_fn(table[attr_num]); \
2845 mask |= (1 << (attr_num - 1)); \
2846 } \
2847 } while (0);\
2848
2849 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
2850 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2851 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2852 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2853 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2854 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2855 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2856 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2857
2858 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2859 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2860 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2861 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2862 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2863 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2864 };
2865
2866 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2867 {
2868 int err;
2869 u32 mask;
2870 struct cfg80211_registered_device *rdev;
2871 struct net_device *dev;
2872 struct mesh_config cfg;
2873 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2874 struct nlattr *parent_attr;
2875
2876 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2877 if (!parent_attr)
2878 return -EINVAL;
2879 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2880 parent_attr, nl80211_meshconf_params_policy))
2881 return -EINVAL;
2882
2883 rtnl_lock();
2884
2885 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2886 if (err)
2887 goto out_rtnl;
2888
2889 if (!rdev->ops->set_mesh_params) {
2890 err = -EOPNOTSUPP;
2891 goto out;
2892 }
2893
2894 /* This makes sure that there aren't more than 32 mesh config
2895 * parameters (otherwise our bitfield scheme would not work.) */
2896 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2897
2898 /* Fill in the params struct */
2899 mask = 0;
2900 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2901 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2902 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2903 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2904 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2905 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2906 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2907 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2908 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2909 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2910 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2911 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2912 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2913 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2914 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2915 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2916 nla_get_u8);
2917 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2918 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2919 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2920 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2921 nla_get_u16);
2922 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2923 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2924 nla_get_u32);
2925 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2926 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2927 nla_get_u16);
2928 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2929 dot11MeshHWMPnetDiameterTraversalTime,
2930 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2931 nla_get_u16);
2932 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2933 dot11MeshHWMPRootMode, mask,
2934 NL80211_MESHCONF_HWMP_ROOTMODE,
2935 nla_get_u8);
2936
2937 /* Apply changes */
2938 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2939
2940 out:
2941 /* cleanup */
2942 cfg80211_unlock_rdev(rdev);
2943 dev_put(dev);
2944 out_rtnl:
2945 rtnl_unlock();
2946
2947 return err;
2948 }
2949
2950 #undef FILL_IN_MESH_PARAM_IF_SET
2951
2952 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2953 {
2954 struct sk_buff *msg;
2955 void *hdr = NULL;
2956 struct nlattr *nl_reg_rules;
2957 unsigned int i;
2958 int err = -EINVAL;
2959
2960 mutex_lock(&cfg80211_mutex);
2961
2962 if (!cfg80211_regdomain)
2963 goto out;
2964
2965 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2966 if (!msg) {
2967 err = -ENOBUFS;
2968 goto out;
2969 }
2970
2971 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2972 NL80211_CMD_GET_REG);
2973 if (!hdr)
2974 goto nla_put_failure;
2975
2976 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2977 cfg80211_regdomain->alpha2);
2978
2979 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2980 if (!nl_reg_rules)
2981 goto nla_put_failure;
2982
2983 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2984 struct nlattr *nl_reg_rule;
2985 const struct ieee80211_reg_rule *reg_rule;
2986 const struct ieee80211_freq_range *freq_range;
2987 const struct ieee80211_power_rule *power_rule;
2988
2989 reg_rule = &cfg80211_regdomain->reg_rules[i];
2990 freq_range = &reg_rule->freq_range;
2991 power_rule = &reg_rule->power_rule;
2992
2993 nl_reg_rule = nla_nest_start(msg, i);
2994 if (!nl_reg_rule)
2995 goto nla_put_failure;
2996
2997 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2998 reg_rule->flags);
2999 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3000 freq_range->start_freq_khz);
3001 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3002 freq_range->end_freq_khz);
3003 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3004 freq_range->max_bandwidth_khz);
3005 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3006 power_rule->max_antenna_gain);
3007 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3008 power_rule->max_eirp);
3009
3010 nla_nest_end(msg, nl_reg_rule);
3011 }
3012
3013 nla_nest_end(msg, nl_reg_rules);
3014
3015 genlmsg_end(msg, hdr);
3016 err = genlmsg_reply(msg, info);
3017 goto out;
3018
3019 nla_put_failure:
3020 genlmsg_cancel(msg, hdr);
3021 nlmsg_free(msg);
3022 err = -EMSGSIZE;
3023 out:
3024 mutex_unlock(&cfg80211_mutex);
3025 return err;
3026 }
3027
3028 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3029 {
3030 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3031 struct nlattr *nl_reg_rule;
3032 char *alpha2 = NULL;
3033 int rem_reg_rules = 0, r = 0;
3034 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3035 struct ieee80211_regdomain *rd = NULL;
3036
3037 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3038 return -EINVAL;
3039
3040 if (!info->attrs[NL80211_ATTR_REG_RULES])
3041 return -EINVAL;
3042
3043 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3044
3045 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3046 rem_reg_rules) {
3047 num_rules++;
3048 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
3049 return -EINVAL;
3050 }
3051
3052 mutex_lock(&cfg80211_mutex);
3053
3054 if (!reg_is_valid_request(alpha2)) {
3055 r = -EINVAL;
3056 goto bad_reg;
3057 }
3058
3059 size_of_regd = sizeof(struct ieee80211_regdomain) +
3060 (num_rules * sizeof(struct ieee80211_reg_rule));
3061
3062 rd = kzalloc(size_of_regd, GFP_KERNEL);
3063 if (!rd) {
3064 r = -ENOMEM;
3065 goto bad_reg;
3066 }
3067
3068 rd->n_reg_rules = num_rules;
3069 rd->alpha2[0] = alpha2[0];
3070 rd->alpha2[1] = alpha2[1];
3071
3072 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3073 rem_reg_rules) {
3074 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3075 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3076 reg_rule_policy);
3077 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3078 if (r)
3079 goto bad_reg;
3080
3081 rule_idx++;
3082
3083 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3084 r = -EINVAL;
3085 goto bad_reg;
3086 }
3087 }
3088
3089 BUG_ON(rule_idx != num_rules);
3090
3091 r = set_regdom(rd);
3092
3093 mutex_unlock(&cfg80211_mutex);
3094
3095 return r;
3096
3097 bad_reg:
3098 mutex_unlock(&cfg80211_mutex);
3099 kfree(rd);
3100 return r;
3101 }
3102
3103 static int validate_scan_freqs(struct nlattr *freqs)
3104 {
3105 struct nlattr *attr1, *attr2;
3106 int n_channels = 0, tmp1, tmp2;
3107
3108 nla_for_each_nested(attr1, freqs, tmp1) {
3109 n_channels++;
3110 /*
3111 * Some hardware has a limited channel list for
3112 * scanning, and it is pretty much nonsensical
3113 * to scan for a channel twice, so disallow that
3114 * and don't require drivers to check that the
3115 * channel list they get isn't longer than what
3116 * they can scan, as long as they can scan all
3117 * the channels they registered at once.
3118 */
3119 nla_for_each_nested(attr2, freqs, tmp2)
3120 if (attr1 != attr2 &&
3121 nla_get_u32(attr1) == nla_get_u32(attr2))
3122 return 0;
3123 }
3124
3125 return n_channels;
3126 }
3127
3128 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3129 {
3130 struct cfg80211_registered_device *rdev;
3131 struct net_device *dev;
3132 struct cfg80211_scan_request *request;
3133 struct cfg80211_ssid *ssid;
3134 struct ieee80211_channel *channel;
3135 struct nlattr *attr;
3136 struct wiphy *wiphy;
3137 int err, tmp, n_ssids = 0, n_channels, i;
3138 enum ieee80211_band band;
3139 size_t ie_len;
3140
3141 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3142 return -EINVAL;
3143
3144 rtnl_lock();
3145
3146 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3147 if (err)
3148 goto out_rtnl;
3149
3150 wiphy = &rdev->wiphy;
3151
3152 if (!rdev->ops->scan) {
3153 err = -EOPNOTSUPP;
3154 goto out;
3155 }
3156
3157 if (!netif_running(dev)) {
3158 err = -ENETDOWN;
3159 goto out;
3160 }
3161
3162 if (rdev->scan_req) {
3163 err = -EBUSY;
3164 goto out;
3165 }
3166
3167 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3168 n_channels = validate_scan_freqs(
3169 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3170 if (!n_channels) {
3171 err = -EINVAL;
3172 goto out;
3173 }
3174 } else {
3175 n_channels = 0;
3176
3177 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3178 if (wiphy->bands[band])
3179 n_channels += wiphy->bands[band]->n_channels;
3180 }
3181
3182 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3183 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3184 n_ssids++;
3185
3186 if (n_ssids > wiphy->max_scan_ssids) {
3187 err = -EINVAL;
3188 goto out;
3189 }
3190
3191 if (info->attrs[NL80211_ATTR_IE])
3192 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3193 else
3194 ie_len = 0;
3195
3196 if (ie_len > wiphy->max_scan_ie_len) {
3197 err = -EINVAL;
3198 goto out;
3199 }
3200
3201 request = kzalloc(sizeof(*request)
3202 + sizeof(*ssid) * n_ssids
3203 + sizeof(channel) * n_channels
3204 + ie_len, GFP_KERNEL);
3205 if (!request) {
3206 err = -ENOMEM;
3207 goto out;
3208 }
3209
3210 if (n_ssids)
3211 request->ssids = (void *)&request->channels[n_channels];
3212 request->n_ssids = n_ssids;
3213 if (ie_len) {
3214 if (request->ssids)
3215 request->ie = (void *)(request->ssids + n_ssids);
3216 else
3217 request->ie = (void *)(request->channels + n_channels);
3218 }
3219
3220 i = 0;
3221 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3222 /* user specified, bail out if channel not found */
3223 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3224 struct ieee80211_channel *chan;
3225
3226 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3227
3228 if (!chan) {
3229 err = -EINVAL;
3230 goto out_free;
3231 }
3232
3233 /* ignore disabled channels */
3234 if (chan->flags & IEEE80211_CHAN_DISABLED)
3235 continue;
3236
3237 request->channels[i] = chan;
3238 i++;
3239 }
3240 } else {
3241 /* all channels */
3242 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3243 int j;
3244 if (!wiphy->bands[band])
3245 continue;
3246 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3247 struct ieee80211_channel *chan;
3248
3249 chan = &wiphy->bands[band]->channels[j];
3250
3251 if (chan->flags & IEEE80211_CHAN_DISABLED)
3252 continue;
3253
3254 request->channels[i] = chan;
3255 i++;
3256 }
3257 }
3258 }
3259
3260 if (!i) {
3261 err = -EINVAL;
3262 goto out_free;
3263 }
3264
3265 request->n_channels = i;
3266
3267 i = 0;
3268 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3269 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3270 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3271 err = -EINVAL;
3272 goto out_free;
3273 }
3274 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3275 request->ssids[i].ssid_len = nla_len(attr);
3276 i++;
3277 }
3278 }
3279
3280 if (info->attrs[NL80211_ATTR_IE]) {
3281 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3282 memcpy((void *)request->ie,
3283 nla_data(info->attrs[NL80211_ATTR_IE]),
3284 request->ie_len);
3285 }
3286
3287 request->dev = dev;
3288 request->wiphy = &rdev->wiphy;
3289
3290 rdev->scan_req = request;
3291 err = rdev->ops->scan(&rdev->wiphy, dev, request);
3292
3293 if (!err) {
3294 nl80211_send_scan_start(rdev, dev);
3295 dev_hold(dev);
3296 }
3297
3298 out_free:
3299 if (err) {
3300 rdev->scan_req = NULL;
3301 kfree(request);
3302 }
3303 out:
3304 cfg80211_unlock_rdev(rdev);
3305 dev_put(dev);
3306 out_rtnl:
3307 rtnl_unlock();
3308
3309 return err;
3310 }
3311
3312 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3313 struct cfg80211_registered_device *rdev,
3314 struct wireless_dev *wdev,
3315 struct cfg80211_internal_bss *intbss)
3316 {
3317 struct cfg80211_bss *res = &intbss->pub;
3318 void *hdr;
3319 struct nlattr *bss;
3320 int i;
3321
3322 ASSERT_WDEV_LOCK(wdev);
3323
3324 hdr = nl80211hdr_put(msg, pid, seq, flags,
3325 NL80211_CMD_NEW_SCAN_RESULTS);
3326 if (!hdr)
3327 return -1;
3328
3329 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3330 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3331
3332 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3333 if (!bss)
3334 goto nla_put_failure;
3335 if (!is_zero_ether_addr(res->bssid))
3336 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3337 if (res->information_elements && res->len_information_elements)
3338 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3339 res->len_information_elements,
3340 res->information_elements);
3341 if (res->beacon_ies && res->len_beacon_ies &&
3342 res->beacon_ies != res->information_elements)
3343 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3344 res->len_beacon_ies, res->beacon_ies);
3345 if (res->tsf)
3346 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3347 if (res->beacon_interval)
3348 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3349 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3350 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3351 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3352 jiffies_to_msecs(jiffies - intbss->ts));
3353
3354 switch (rdev->wiphy.signal_type) {
3355 case CFG80211_SIGNAL_TYPE_MBM:
3356 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3357 break;
3358 case CFG80211_SIGNAL_TYPE_UNSPEC:
3359 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3360 break;
3361 default:
3362 break;
3363 }
3364
3365 switch (wdev->iftype) {
3366 case NL80211_IFTYPE_STATION:
3367 if (intbss == wdev->current_bss)
3368 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3369 NL80211_BSS_STATUS_ASSOCIATED);
3370 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3371 if (intbss != wdev->auth_bsses[i])
3372 continue;
3373 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3374 NL80211_BSS_STATUS_AUTHENTICATED);
3375 break;
3376 }
3377 break;
3378 case NL80211_IFTYPE_ADHOC:
3379 if (intbss == wdev->current_bss)
3380 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3381 NL80211_BSS_STATUS_IBSS_JOINED);
3382 break;
3383 default:
3384 break;
3385 }
3386
3387 nla_nest_end(msg, bss);
3388
3389 return genlmsg_end(msg, hdr);
3390
3391 nla_put_failure:
3392 genlmsg_cancel(msg, hdr);
3393 return -EMSGSIZE;
3394 }
3395
3396 static int nl80211_dump_scan(struct sk_buff *skb,
3397 struct netlink_callback *cb)
3398 {
3399 struct cfg80211_registered_device *rdev;
3400 struct net_device *dev;
3401 struct cfg80211_internal_bss *scan;
3402 struct wireless_dev *wdev;
3403 int ifidx = cb->args[0];
3404 int start = cb->args[1], idx = 0;
3405 int err;
3406
3407 if (!ifidx)
3408 ifidx = nl80211_get_ifidx(cb);
3409 if (ifidx < 0)
3410 return ifidx;
3411 cb->args[0] = ifidx;
3412
3413 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
3414 if (!dev)
3415 return -ENODEV;
3416
3417 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3418 if (IS_ERR(rdev)) {
3419 err = PTR_ERR(rdev);
3420 goto out_put_netdev;
3421 }
3422
3423 wdev = dev->ieee80211_ptr;
3424
3425 wdev_lock(wdev);
3426 spin_lock_bh(&rdev->bss_lock);
3427 cfg80211_bss_expire(rdev);
3428
3429 list_for_each_entry(scan, &rdev->bss_list, list) {
3430 if (++idx <= start)
3431 continue;
3432 if (nl80211_send_bss(skb,
3433 NETLINK_CB(cb->skb).pid,
3434 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3435 rdev, wdev, scan) < 0) {
3436 idx--;
3437 goto out;
3438 }
3439 }
3440
3441 out:
3442 spin_unlock_bh(&rdev->bss_lock);
3443 wdev_unlock(wdev);
3444
3445 cb->args[1] = idx;
3446 err = skb->len;
3447 cfg80211_unlock_rdev(rdev);
3448 out_put_netdev:
3449 dev_put(dev);
3450
3451 return err;
3452 }
3453
3454 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3455 int flags, struct net_device *dev,
3456 struct survey_info *survey)
3457 {
3458 void *hdr;
3459 struct nlattr *infoattr;
3460
3461 /* Survey without a channel doesn't make sense */
3462 if (!survey->channel)
3463 return -EINVAL;
3464
3465 hdr = nl80211hdr_put(msg, pid, seq, flags,
3466 NL80211_CMD_NEW_SURVEY_RESULTS);
3467 if (!hdr)
3468 return -ENOMEM;
3469
3470 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3471
3472 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3473 if (!infoattr)
3474 goto nla_put_failure;
3475
3476 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3477 survey->channel->center_freq);
3478 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3479 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3480 survey->noise);
3481
3482 nla_nest_end(msg, infoattr);
3483
3484 return genlmsg_end(msg, hdr);
3485
3486 nla_put_failure:
3487 genlmsg_cancel(msg, hdr);
3488 return -EMSGSIZE;
3489 }
3490
3491 static int nl80211_dump_survey(struct sk_buff *skb,
3492 struct netlink_callback *cb)
3493 {
3494 struct survey_info survey;
3495 struct cfg80211_registered_device *dev;
3496 struct net_device *netdev;
3497 int ifidx = cb->args[0];
3498 int survey_idx = cb->args[1];
3499 int res;
3500
3501 if (!ifidx)
3502 ifidx = nl80211_get_ifidx(cb);
3503 if (ifidx < 0)
3504 return ifidx;
3505 cb->args[0] = ifidx;
3506
3507 rtnl_lock();
3508
3509 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3510 if (!netdev) {
3511 res = -ENODEV;
3512 goto out_rtnl;
3513 }
3514
3515 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3516 if (IS_ERR(dev)) {
3517 res = PTR_ERR(dev);
3518 goto out_rtnl;
3519 }
3520
3521 if (!dev->ops->dump_survey) {
3522 res = -EOPNOTSUPP;
3523 goto out_err;
3524 }
3525
3526 while (1) {
3527 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3528 &survey);
3529 if (res == -ENOENT)
3530 break;
3531 if (res)
3532 goto out_err;
3533
3534 if (nl80211_send_survey(skb,
3535 NETLINK_CB(cb->skb).pid,
3536 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3537 netdev,
3538 &survey) < 0)
3539 goto out;
3540 survey_idx++;
3541 }
3542
3543 out:
3544 cb->args[1] = survey_idx;
3545 res = skb->len;
3546 out_err:
3547 cfg80211_unlock_rdev(dev);
3548 out_rtnl:
3549 rtnl_unlock();
3550
3551 return res;
3552 }
3553
3554 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3555 {
3556 return auth_type <= NL80211_AUTHTYPE_MAX;
3557 }
3558
3559 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3560 {
3561 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3562 NL80211_WPA_VERSION_2));
3563 }
3564
3565 static bool nl80211_valid_akm_suite(u32 akm)
3566 {
3567 return akm == WLAN_AKM_SUITE_8021X ||
3568 akm == WLAN_AKM_SUITE_PSK;
3569 }
3570
3571 static bool nl80211_valid_cipher_suite(u32 cipher)
3572 {
3573 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3574 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3575 cipher == WLAN_CIPHER_SUITE_TKIP ||
3576 cipher == WLAN_CIPHER_SUITE_CCMP ||
3577 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3578 }
3579
3580
3581 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3582 {
3583 struct cfg80211_registered_device *rdev;
3584 struct net_device *dev;
3585 struct ieee80211_channel *chan;
3586 const u8 *bssid, *ssid, *ie = NULL;
3587 int err, ssid_len, ie_len = 0;
3588 enum nl80211_auth_type auth_type;
3589 struct key_parse key;
3590 bool local_state_change;
3591
3592 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3593 return -EINVAL;
3594
3595 if (!info->attrs[NL80211_ATTR_MAC])
3596 return -EINVAL;
3597
3598 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3599 return -EINVAL;
3600
3601 if (!info->attrs[NL80211_ATTR_SSID])
3602 return -EINVAL;
3603
3604 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3605 return -EINVAL;
3606
3607 err = nl80211_parse_key(info, &key);
3608 if (err)
3609 return err;
3610
3611 if (key.idx >= 0) {
3612 if (!key.p.key || !key.p.key_len)
3613 return -EINVAL;
3614 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3615 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3616 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3617 key.p.key_len != WLAN_KEY_LEN_WEP104))
3618 return -EINVAL;
3619 if (key.idx > 4)
3620 return -EINVAL;
3621 } else {
3622 key.p.key_len = 0;
3623 key.p.key = NULL;
3624 }
3625
3626 rtnl_lock();
3627
3628 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3629 if (err)
3630 goto unlock_rtnl;
3631
3632 if (key.idx >= 0) {
3633 int i;
3634 bool ok = false;
3635 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3636 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3637 ok = true;
3638 break;
3639 }
3640 }
3641 if (!ok) {
3642 err = -EINVAL;
3643 goto out;
3644 }
3645 }
3646
3647 if (!rdev->ops->auth) {
3648 err = -EOPNOTSUPP;
3649 goto out;
3650 }
3651
3652 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3653 err = -EOPNOTSUPP;
3654 goto out;
3655 }
3656
3657 if (!netif_running(dev)) {
3658 err = -ENETDOWN;
3659 goto out;
3660 }
3661
3662 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3663 chan = ieee80211_get_channel(&rdev->wiphy,
3664 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3665 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3666 err = -EINVAL;
3667 goto out;
3668 }
3669
3670 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3671 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3672
3673 if (info->attrs[NL80211_ATTR_IE]) {
3674 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3675 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3676 }
3677
3678 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3679 if (!nl80211_valid_auth_type(auth_type)) {
3680 err = -EINVAL;
3681 goto out;
3682 }
3683
3684 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3685
3686 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3687 ssid, ssid_len, ie, ie_len,
3688 key.p.key, key.p.key_len, key.idx,
3689 local_state_change);
3690
3691 out:
3692 cfg80211_unlock_rdev(rdev);
3693 dev_put(dev);
3694 unlock_rtnl:
3695 rtnl_unlock();
3696 return err;
3697 }
3698
3699 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3700 struct genl_info *info,
3701 struct cfg80211_crypto_settings *settings,
3702 int cipher_limit)
3703 {
3704 memset(settings, 0, sizeof(*settings));
3705
3706 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3707
3708 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3709 u16 proto;
3710 proto = nla_get_u16(
3711 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3712 settings->control_port_ethertype = cpu_to_be16(proto);
3713 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3714 proto != ETH_P_PAE)
3715 return -EINVAL;
3716 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3717 settings->control_port_no_encrypt = true;
3718 } else
3719 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3720
3721 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3722 void *data;
3723 int len, i;
3724
3725 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3726 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3727 settings->n_ciphers_pairwise = len / sizeof(u32);
3728
3729 if (len % sizeof(u32))
3730 return -EINVAL;
3731
3732 if (settings->n_ciphers_pairwise > cipher_limit)
3733 return -EINVAL;
3734
3735 memcpy(settings->ciphers_pairwise, data, len);
3736
3737 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3738 if (!nl80211_valid_cipher_suite(
3739 settings->ciphers_pairwise[i]))
3740 return -EINVAL;
3741 }
3742
3743 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3744 settings->cipher_group =
3745 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3746 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3747 return -EINVAL;
3748 }
3749
3750 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3751 settings->wpa_versions =
3752 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3753 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3754 return -EINVAL;
3755 }
3756
3757 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3758 void *data;
3759 int len, i;
3760
3761 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3762 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3763 settings->n_akm_suites = len / sizeof(u32);
3764
3765 if (len % sizeof(u32))
3766 return -EINVAL;
3767
3768 memcpy(settings->akm_suites, data, len);
3769
3770 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3771 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3772 return -EINVAL;
3773 }
3774
3775 return 0;
3776 }
3777
3778 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3779 {
3780 struct cfg80211_registered_device *rdev;
3781 struct net_device *dev;
3782 struct cfg80211_crypto_settings crypto;
3783 struct ieee80211_channel *chan;
3784 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3785 int err, ssid_len, ie_len = 0;
3786 bool use_mfp = false;
3787
3788 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3789 return -EINVAL;
3790
3791 if (!info->attrs[NL80211_ATTR_MAC] ||
3792 !info->attrs[NL80211_ATTR_SSID] ||
3793 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3794 return -EINVAL;
3795
3796 rtnl_lock();
3797
3798 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3799 if (err)
3800 goto unlock_rtnl;
3801
3802 if (!rdev->ops->assoc) {
3803 err = -EOPNOTSUPP;
3804 goto out;
3805 }
3806
3807 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3808 err = -EOPNOTSUPP;
3809 goto out;
3810 }
3811
3812 if (!netif_running(dev)) {
3813 err = -ENETDOWN;
3814 goto out;
3815 }
3816
3817 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3818
3819 chan = ieee80211_get_channel(&rdev->wiphy,
3820 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3821 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3822 err = -EINVAL;
3823 goto out;
3824 }
3825
3826 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3827 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3828
3829 if (info->attrs[NL80211_ATTR_IE]) {
3830 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3831 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3832 }
3833
3834 if (info->attrs[NL80211_ATTR_USE_MFP]) {
3835 enum nl80211_mfp mfp =
3836 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3837 if (mfp == NL80211_MFP_REQUIRED)
3838 use_mfp = true;
3839 else if (mfp != NL80211_MFP_NO) {
3840 err = -EINVAL;
3841 goto out;
3842 }
3843 }
3844
3845 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3846 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3847
3848 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
3849 if (!err)
3850 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3851 ssid, ssid_len, ie, ie_len, use_mfp,
3852 &crypto);
3853
3854 out:
3855 cfg80211_unlock_rdev(rdev);
3856 dev_put(dev);
3857 unlock_rtnl:
3858 rtnl_unlock();
3859 return err;
3860 }
3861
3862 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3863 {
3864 struct cfg80211_registered_device *rdev;
3865 struct net_device *dev;
3866 const u8 *ie = NULL, *bssid;
3867 int err, ie_len = 0;
3868 u16 reason_code;
3869 bool local_state_change;
3870
3871 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3872 return -EINVAL;
3873
3874 if (!info->attrs[NL80211_ATTR_MAC])
3875 return -EINVAL;
3876
3877 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3878 return -EINVAL;
3879
3880 rtnl_lock();
3881
3882 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3883 if (err)
3884 goto unlock_rtnl;
3885
3886 if (!rdev->ops->deauth) {
3887 err = -EOPNOTSUPP;
3888 goto out;
3889 }
3890
3891 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3892 err = -EOPNOTSUPP;
3893 goto out;
3894 }
3895
3896 if (!netif_running(dev)) {
3897 err = -ENETDOWN;
3898 goto out;
3899 }
3900
3901 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3902
3903 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3904 if (reason_code == 0) {
3905 /* Reason Code 0 is reserved */
3906 err = -EINVAL;
3907 goto out;
3908 }
3909
3910 if (info->attrs[NL80211_ATTR_IE]) {
3911 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3912 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3913 }
3914
3915 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3916
3917 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3918 local_state_change);
3919
3920 out:
3921 cfg80211_unlock_rdev(rdev);
3922 dev_put(dev);
3923 unlock_rtnl:
3924 rtnl_unlock();
3925 return err;
3926 }
3927
3928 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3929 {
3930 struct cfg80211_registered_device *rdev;
3931 struct net_device *dev;
3932 const u8 *ie = NULL, *bssid;
3933 int err, ie_len = 0;
3934 u16 reason_code;
3935 bool local_state_change;
3936
3937 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3938 return -EINVAL;
3939
3940 if (!info->attrs[NL80211_ATTR_MAC])
3941 return -EINVAL;
3942
3943 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3944 return -EINVAL;
3945
3946 rtnl_lock();
3947
3948 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3949 if (err)
3950 goto unlock_rtnl;
3951
3952 if (!rdev->ops->disassoc) {
3953 err = -EOPNOTSUPP;
3954 goto out;
3955 }
3956
3957 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3958 err = -EOPNOTSUPP;
3959 goto out;
3960 }
3961
3962 if (!netif_running(dev)) {
3963 err = -ENETDOWN;
3964 goto out;
3965 }
3966
3967 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3968
3969 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3970 if (reason_code == 0) {
3971 /* Reason Code 0 is reserved */
3972 err = -EINVAL;
3973 goto out;
3974 }
3975
3976 if (info->attrs[NL80211_ATTR_IE]) {
3977 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3978 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3979 }
3980
3981 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3982
3983 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3984 local_state_change);
3985
3986 out:
3987 cfg80211_unlock_rdev(rdev);
3988 dev_put(dev);
3989 unlock_rtnl:
3990 rtnl_unlock();
3991 return err;
3992 }
3993
3994 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3995 {
3996 struct cfg80211_registered_device *rdev;
3997 struct net_device *dev;
3998 struct cfg80211_ibss_params ibss;
3999 struct wiphy *wiphy;
4000 struct cfg80211_cached_keys *connkeys = NULL;
4001 int err;
4002
4003 memset(&ibss, 0, sizeof(ibss));
4004
4005 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4006 return -EINVAL;
4007
4008 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4009 !info->attrs[NL80211_ATTR_SSID] ||
4010 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4011 return -EINVAL;
4012
4013 ibss.beacon_interval = 100;
4014
4015 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4016 ibss.beacon_interval =
4017 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4018 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4019 return -EINVAL;
4020 }
4021
4022 rtnl_lock();
4023
4024 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4025 if (err)
4026 goto unlock_rtnl;
4027
4028 if (!rdev->ops->join_ibss) {
4029 err = -EOPNOTSUPP;
4030 goto out;
4031 }
4032
4033 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4034 err = -EOPNOTSUPP;
4035 goto out;
4036 }
4037
4038 if (!netif_running(dev)) {
4039 err = -ENETDOWN;
4040 goto out;
4041 }
4042
4043 wiphy = &rdev->wiphy;
4044
4045 if (info->attrs[NL80211_ATTR_MAC])
4046 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4047 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4048 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4049
4050 if (info->attrs[NL80211_ATTR_IE]) {
4051 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4052 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4053 }
4054
4055 ibss.channel = ieee80211_get_channel(wiphy,
4056 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4057 if (!ibss.channel ||
4058 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4059 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
4060 err = -EINVAL;
4061 goto out;
4062 }
4063
4064 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
4065 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4066
4067 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4068 connkeys = nl80211_parse_connkeys(rdev,
4069 info->attrs[NL80211_ATTR_KEYS]);
4070 if (IS_ERR(connkeys)) {
4071 err = PTR_ERR(connkeys);
4072 connkeys = NULL;
4073 goto out;
4074 }
4075 }
4076
4077 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4078 u8 *rates =
4079 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4080 int n_rates =
4081 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4082 struct ieee80211_supported_band *sband =
4083 wiphy->bands[ibss.channel->band];
4084 int i, j;
4085
4086 if (n_rates == 0) {
4087 err = -EINVAL;
4088 goto out;
4089 }
4090
4091 for (i = 0; i < n_rates; i++) {
4092 int rate = (rates[i] & 0x7f) * 5;
4093 bool found = false;
4094
4095 for (j = 0; j < sband->n_bitrates; j++) {
4096 if (sband->bitrates[j].bitrate == rate) {
4097 found = true;
4098 ibss.basic_rates |= BIT(j);
4099 break;
4100 }
4101 }
4102 if (!found) {
4103 err = -EINVAL;
4104 goto out;
4105 }
4106 }
4107 } else {
4108 /*
4109 * If no rates were explicitly configured,
4110 * use the mandatory rate set for 11b or
4111 * 11a for maximum compatibility.
4112 */
4113 struct ieee80211_supported_band *sband =
4114 wiphy->bands[ibss.channel->band];
4115 int j;
4116 u32 flag = ibss.channel->band == IEEE80211_BAND_5GHZ ?
4117 IEEE80211_RATE_MANDATORY_A :
4118 IEEE80211_RATE_MANDATORY_B;
4119
4120 for (j = 0; j < sband->n_bitrates; j++) {
4121 if (sband->bitrates[j].flags & flag)
4122 ibss.basic_rates |= BIT(j);
4123 }
4124 }
4125
4126 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
4127
4128 out:
4129 cfg80211_unlock_rdev(rdev);
4130 dev_put(dev);
4131 unlock_rtnl:
4132 if (err)
4133 kfree(connkeys);
4134 rtnl_unlock();
4135 return err;
4136 }
4137
4138 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4139 {
4140 struct cfg80211_registered_device *rdev;
4141 struct net_device *dev;
4142 int err;
4143
4144 rtnl_lock();
4145
4146 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4147 if (err)
4148 goto unlock_rtnl;
4149
4150 if (!rdev->ops->leave_ibss) {
4151 err = -EOPNOTSUPP;
4152 goto out;
4153 }
4154
4155 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4156 err = -EOPNOTSUPP;
4157 goto out;
4158 }
4159
4160 if (!netif_running(dev)) {
4161 err = -ENETDOWN;
4162 goto out;
4163 }
4164
4165 err = cfg80211_leave_ibss(rdev, dev, false);
4166
4167 out:
4168 cfg80211_unlock_rdev(rdev);
4169 dev_put(dev);
4170 unlock_rtnl:
4171 rtnl_unlock();
4172 return err;
4173 }
4174
4175 #ifdef CONFIG_NL80211_TESTMODE
4176 static struct genl_multicast_group nl80211_testmode_mcgrp = {
4177 .name = "testmode",
4178 };
4179
4180 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4181 {
4182 struct cfg80211_registered_device *rdev;
4183 int err;
4184
4185 if (!info->attrs[NL80211_ATTR_TESTDATA])
4186 return -EINVAL;
4187
4188 rtnl_lock();
4189
4190 rdev = cfg80211_get_dev_from_info(info);
4191 if (IS_ERR(rdev)) {
4192 err = PTR_ERR(rdev);
4193 goto unlock_rtnl;
4194 }
4195
4196 err = -EOPNOTSUPP;
4197 if (rdev->ops->testmode_cmd) {
4198 rdev->testmode_info = info;
4199 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4200 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4201 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4202 rdev->testmode_info = NULL;
4203 }
4204
4205 cfg80211_unlock_rdev(rdev);
4206
4207 unlock_rtnl:
4208 rtnl_unlock();
4209 return err;
4210 }
4211
4212 static struct sk_buff *
4213 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4214 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4215 {
4216 struct sk_buff *skb;
4217 void *hdr;
4218 struct nlattr *data;
4219
4220 skb = nlmsg_new(approxlen + 100, gfp);
4221 if (!skb)
4222 return NULL;
4223
4224 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4225 if (!hdr) {
4226 kfree_skb(skb);
4227 return NULL;
4228 }
4229
4230 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4231 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4232
4233 ((void **)skb->cb)[0] = rdev;
4234 ((void **)skb->cb)[1] = hdr;
4235 ((void **)skb->cb)[2] = data;
4236
4237 return skb;
4238
4239 nla_put_failure:
4240 kfree_skb(skb);
4241 return NULL;
4242 }
4243
4244 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4245 int approxlen)
4246 {
4247 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4248
4249 if (WARN_ON(!rdev->testmode_info))
4250 return NULL;
4251
4252 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4253 rdev->testmode_info->snd_pid,
4254 rdev->testmode_info->snd_seq,
4255 GFP_KERNEL);
4256 }
4257 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4258
4259 int cfg80211_testmode_reply(struct sk_buff *skb)
4260 {
4261 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4262 void *hdr = ((void **)skb->cb)[1];
4263 struct nlattr *data = ((void **)skb->cb)[2];
4264
4265 if (WARN_ON(!rdev->testmode_info)) {
4266 kfree_skb(skb);
4267 return -EINVAL;
4268 }
4269
4270 nla_nest_end(skb, data);
4271 genlmsg_end(skb, hdr);
4272 return genlmsg_reply(skb, rdev->testmode_info);
4273 }
4274 EXPORT_SYMBOL(cfg80211_testmode_reply);
4275
4276 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4277 int approxlen, gfp_t gfp)
4278 {
4279 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4280
4281 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4282 }
4283 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4284
4285 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4286 {
4287 void *hdr = ((void **)skb->cb)[1];
4288 struct nlattr *data = ((void **)skb->cb)[2];
4289
4290 nla_nest_end(skb, data);
4291 genlmsg_end(skb, hdr);
4292 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4293 }
4294 EXPORT_SYMBOL(cfg80211_testmode_event);
4295 #endif
4296
4297 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4298 {
4299 struct cfg80211_registered_device *rdev;
4300 struct net_device *dev;
4301 struct cfg80211_connect_params connect;
4302 struct wiphy *wiphy;
4303 struct cfg80211_cached_keys *connkeys = NULL;
4304 int err;
4305
4306 memset(&connect, 0, sizeof(connect));
4307
4308 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4309 return -EINVAL;
4310
4311 if (!info->attrs[NL80211_ATTR_SSID] ||
4312 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4313 return -EINVAL;
4314
4315 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4316 connect.auth_type =
4317 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4318 if (!nl80211_valid_auth_type(connect.auth_type))
4319 return -EINVAL;
4320 } else
4321 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4322
4323 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4324
4325 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
4326 NL80211_MAX_NR_CIPHER_SUITES);
4327 if (err)
4328 return err;
4329 rtnl_lock();
4330
4331 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4332 if (err)
4333 goto unlock_rtnl;
4334
4335 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4336 err = -EOPNOTSUPP;
4337 goto out;
4338 }
4339
4340 if (!netif_running(dev)) {
4341 err = -ENETDOWN;
4342 goto out;
4343 }
4344
4345 wiphy = &rdev->wiphy;
4346
4347 if (info->attrs[NL80211_ATTR_MAC])
4348 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4349 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4350 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4351
4352 if (info->attrs[NL80211_ATTR_IE]) {
4353 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4354 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4355 }
4356
4357 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4358 connect.channel =
4359 ieee80211_get_channel(wiphy,
4360 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4361 if (!connect.channel ||
4362 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4363 err = -EINVAL;
4364 goto out;
4365 }
4366 }
4367
4368 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4369 connkeys = nl80211_parse_connkeys(rdev,
4370 info->attrs[NL80211_ATTR_KEYS]);
4371 if (IS_ERR(connkeys)) {
4372 err = PTR_ERR(connkeys);
4373 connkeys = NULL;
4374 goto out;
4375 }
4376 }
4377
4378 err = cfg80211_connect(rdev, dev, &connect, connkeys);
4379
4380 out:
4381 cfg80211_unlock_rdev(rdev);
4382 dev_put(dev);
4383 unlock_rtnl:
4384 if (err)
4385 kfree(connkeys);
4386 rtnl_unlock();
4387 return err;
4388 }
4389
4390 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4391 {
4392 struct cfg80211_registered_device *rdev;
4393 struct net_device *dev;
4394 int err;
4395 u16 reason;
4396
4397 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4398 reason = WLAN_REASON_DEAUTH_LEAVING;
4399 else
4400 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4401
4402 if (reason == 0)
4403 return -EINVAL;
4404
4405 rtnl_lock();
4406
4407 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4408 if (err)
4409 goto unlock_rtnl;
4410
4411 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4412 err = -EOPNOTSUPP;
4413 goto out;
4414 }
4415
4416 if (!netif_running(dev)) {
4417 err = -ENETDOWN;
4418 goto out;
4419 }
4420
4421 err = cfg80211_disconnect(rdev, dev, reason, true);
4422
4423 out:
4424 cfg80211_unlock_rdev(rdev);
4425 dev_put(dev);
4426 unlock_rtnl:
4427 rtnl_unlock();
4428 return err;
4429 }
4430
4431 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4432 {
4433 struct cfg80211_registered_device *rdev;
4434 struct net *net;
4435 int err;
4436 u32 pid;
4437
4438 if (!info->attrs[NL80211_ATTR_PID])
4439 return -EINVAL;
4440
4441 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4442
4443 rtnl_lock();
4444
4445 rdev = cfg80211_get_dev_from_info(info);
4446 if (IS_ERR(rdev)) {
4447 err = PTR_ERR(rdev);
4448 goto out_rtnl;
4449 }
4450
4451 net = get_net_ns_by_pid(pid);
4452 if (IS_ERR(net)) {
4453 err = PTR_ERR(net);
4454 goto out;
4455 }
4456
4457 err = 0;
4458
4459 /* check if anything to do */
4460 if (net_eq(wiphy_net(&rdev->wiphy), net))
4461 goto out_put_net;
4462
4463 err = cfg80211_switch_netns(rdev, net);
4464 out_put_net:
4465 put_net(net);
4466 out:
4467 cfg80211_unlock_rdev(rdev);
4468 out_rtnl:
4469 rtnl_unlock();
4470 return err;
4471 }
4472
4473 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4474 {
4475 struct cfg80211_registered_device *rdev;
4476 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4477 struct cfg80211_pmksa *pmksa) = NULL;
4478 int err;
4479 struct net_device *dev;
4480 struct cfg80211_pmksa pmksa;
4481
4482 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4483
4484 if (!info->attrs[NL80211_ATTR_MAC])
4485 return -EINVAL;
4486
4487 if (!info->attrs[NL80211_ATTR_PMKID])
4488 return -EINVAL;
4489
4490 rtnl_lock();
4491
4492 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4493 if (err)
4494 goto out_rtnl;
4495
4496 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4497 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4498
4499 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4500 err = -EOPNOTSUPP;
4501 goto out;
4502 }
4503
4504 switch (info->genlhdr->cmd) {
4505 case NL80211_CMD_SET_PMKSA:
4506 rdev_ops = rdev->ops->set_pmksa;
4507 break;
4508 case NL80211_CMD_DEL_PMKSA:
4509 rdev_ops = rdev->ops->del_pmksa;
4510 break;
4511 default:
4512 WARN_ON(1);
4513 break;
4514 }
4515
4516 if (!rdev_ops) {
4517 err = -EOPNOTSUPP;
4518 goto out;
4519 }
4520
4521 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4522
4523 out:
4524 cfg80211_unlock_rdev(rdev);
4525 dev_put(dev);
4526 out_rtnl:
4527 rtnl_unlock();
4528
4529 return err;
4530 }
4531
4532 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4533 {
4534 struct cfg80211_registered_device *rdev;
4535 int err;
4536 struct net_device *dev;
4537
4538 rtnl_lock();
4539
4540 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4541 if (err)
4542 goto out_rtnl;
4543
4544 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4545 err = -EOPNOTSUPP;
4546 goto out;
4547 }
4548
4549 if (!rdev->ops->flush_pmksa) {
4550 err = -EOPNOTSUPP;
4551 goto out;
4552 }
4553
4554 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4555
4556 out:
4557 cfg80211_unlock_rdev(rdev);
4558 dev_put(dev);
4559 out_rtnl:
4560 rtnl_unlock();
4561
4562 return err;
4563
4564 }
4565
4566 static int nl80211_remain_on_channel(struct sk_buff *skb,
4567 struct genl_info *info)
4568 {
4569 struct cfg80211_registered_device *rdev;
4570 struct net_device *dev;
4571 struct ieee80211_channel *chan;
4572 struct sk_buff *msg;
4573 void *hdr;
4574 u64 cookie;
4575 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4576 u32 freq, duration;
4577 int err;
4578
4579 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4580 !info->attrs[NL80211_ATTR_DURATION])
4581 return -EINVAL;
4582
4583 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4584
4585 /*
4586 * We should be on that channel for at least one jiffie,
4587 * and more than 5 seconds seems excessive.
4588 */
4589 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4590 return -EINVAL;
4591
4592 rtnl_lock();
4593
4594 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4595 if (err)
4596 goto unlock_rtnl;
4597
4598 if (!rdev->ops->remain_on_channel) {
4599 err = -EOPNOTSUPP;
4600 goto out;
4601 }
4602
4603 if (!netif_running(dev)) {
4604 err = -ENETDOWN;
4605 goto out;
4606 }
4607
4608 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4609 channel_type = nla_get_u32(
4610 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4611 if (channel_type != NL80211_CHAN_NO_HT &&
4612 channel_type != NL80211_CHAN_HT20 &&
4613 channel_type != NL80211_CHAN_HT40PLUS &&
4614 channel_type != NL80211_CHAN_HT40MINUS) {
4615 err = -EINVAL;
4616 goto out;
4617 }
4618 }
4619
4620 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4621 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4622 if (chan == NULL) {
4623 err = -EINVAL;
4624 goto out;
4625 }
4626
4627 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4628 if (!msg) {
4629 err = -ENOMEM;
4630 goto out;
4631 }
4632
4633 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4634 NL80211_CMD_REMAIN_ON_CHANNEL);
4635
4636 if (IS_ERR(hdr)) {
4637 err = PTR_ERR(hdr);
4638 goto free_msg;
4639 }
4640
4641 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4642 channel_type, duration, &cookie);
4643
4644 if (err)
4645 goto free_msg;
4646
4647 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4648
4649 genlmsg_end(msg, hdr);
4650 err = genlmsg_reply(msg, info);
4651 goto out;
4652
4653 nla_put_failure:
4654 err = -ENOBUFS;
4655 free_msg:
4656 nlmsg_free(msg);
4657 out:
4658 cfg80211_unlock_rdev(rdev);
4659 dev_put(dev);
4660 unlock_rtnl:
4661 rtnl_unlock();
4662 return err;
4663 }
4664
4665 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4666 struct genl_info *info)
4667 {
4668 struct cfg80211_registered_device *rdev;
4669 struct net_device *dev;
4670 u64 cookie;
4671 int err;
4672
4673 if (!info->attrs[NL80211_ATTR_COOKIE])
4674 return -EINVAL;
4675
4676 rtnl_lock();
4677
4678 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4679 if (err)
4680 goto unlock_rtnl;
4681
4682 if (!rdev->ops->cancel_remain_on_channel) {
4683 err = -EOPNOTSUPP;
4684 goto out;
4685 }
4686
4687 if (!netif_running(dev)) {
4688 err = -ENETDOWN;
4689 goto out;
4690 }
4691
4692 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4693
4694 err = rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4695
4696 out:
4697 cfg80211_unlock_rdev(rdev);
4698 dev_put(dev);
4699 unlock_rtnl:
4700 rtnl_unlock();
4701 return err;
4702 }
4703
4704 static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4705 u8 *rates, u8 rates_len)
4706 {
4707 u8 i;
4708 u32 mask = 0;
4709
4710 for (i = 0; i < rates_len; i++) {
4711 int rate = (rates[i] & 0x7f) * 5;
4712 int ridx;
4713 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4714 struct ieee80211_rate *srate =
4715 &sband->bitrates[ridx];
4716 if (rate == srate->bitrate) {
4717 mask |= 1 << ridx;
4718 break;
4719 }
4720 }
4721 if (ridx == sband->n_bitrates)
4722 return 0; /* rate not found */
4723 }
4724
4725 return mask;
4726 }
4727
4728 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
4729 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4730 .len = NL80211_MAX_SUPP_RATES },
4731 };
4732
4733 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4734 struct genl_info *info)
4735 {
4736 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4737 struct cfg80211_registered_device *rdev;
4738 struct cfg80211_bitrate_mask mask;
4739 int err, rem, i;
4740 struct net_device *dev;
4741 struct nlattr *tx_rates;
4742 struct ieee80211_supported_band *sband;
4743
4744 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4745 return -EINVAL;
4746
4747 rtnl_lock();
4748
4749 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4750 if (err)
4751 goto unlock_rtnl;
4752
4753 if (!rdev->ops->set_bitrate_mask) {
4754 err = -EOPNOTSUPP;
4755 goto unlock;
4756 }
4757
4758 memset(&mask, 0, sizeof(mask));
4759 /* Default to all rates enabled */
4760 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4761 sband = rdev->wiphy.bands[i];
4762 mask.control[i].legacy =
4763 sband ? (1 << sband->n_bitrates) - 1 : 0;
4764 }
4765
4766 /*
4767 * The nested attribute uses enum nl80211_band as the index. This maps
4768 * directly to the enum ieee80211_band values used in cfg80211.
4769 */
4770 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4771 {
4772 enum ieee80211_band band = nla_type(tx_rates);
4773 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
4774 err = -EINVAL;
4775 goto unlock;
4776 }
4777 sband = rdev->wiphy.bands[band];
4778 if (sband == NULL) {
4779 err = -EINVAL;
4780 goto unlock;
4781 }
4782 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4783 nla_len(tx_rates), nl80211_txattr_policy);
4784 if (tb[NL80211_TXRATE_LEGACY]) {
4785 mask.control[band].legacy = rateset_to_mask(
4786 sband,
4787 nla_data(tb[NL80211_TXRATE_LEGACY]),
4788 nla_len(tb[NL80211_TXRATE_LEGACY]));
4789 if (mask.control[band].legacy == 0) {
4790 err = -EINVAL;
4791 goto unlock;
4792 }
4793 }
4794 }
4795
4796 err = rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4797
4798 unlock:
4799 dev_put(dev);
4800 cfg80211_unlock_rdev(rdev);
4801 unlock_rtnl:
4802 rtnl_unlock();
4803 return err;
4804 }
4805
4806 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
4807 {
4808 struct cfg80211_registered_device *rdev;
4809 struct net_device *dev;
4810 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
4811 int err;
4812
4813 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4814 return -EINVAL;
4815
4816 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4817 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
4818
4819 rtnl_lock();
4820
4821 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4822 if (err)
4823 goto unlock_rtnl;
4824
4825 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4826 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4827 err = -EOPNOTSUPP;
4828 goto out;
4829 }
4830
4831 /* not much point in registering if we can't reply */
4832 if (!rdev->ops->mgmt_tx) {
4833 err = -EOPNOTSUPP;
4834 goto out;
4835 }
4836
4837 err = cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
4838 frame_type,
4839 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4840 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4841 out:
4842 cfg80211_unlock_rdev(rdev);
4843 dev_put(dev);
4844 unlock_rtnl:
4845 rtnl_unlock();
4846 return err;
4847 }
4848
4849 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
4850 {
4851 struct cfg80211_registered_device *rdev;
4852 struct net_device *dev;
4853 struct ieee80211_channel *chan;
4854 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4855 bool channel_type_valid = false;
4856 u32 freq;
4857 int err;
4858 void *hdr;
4859 u64 cookie;
4860 struct sk_buff *msg;
4861
4862 if (!info->attrs[NL80211_ATTR_FRAME] ||
4863 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4864 return -EINVAL;
4865
4866 rtnl_lock();
4867
4868 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4869 if (err)
4870 goto unlock_rtnl;
4871
4872 if (!rdev->ops->mgmt_tx) {
4873 err = -EOPNOTSUPP;
4874 goto out;
4875 }
4876
4877 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4878 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4879 err = -EOPNOTSUPP;
4880 goto out;
4881 }
4882
4883 if (!netif_running(dev)) {
4884 err = -ENETDOWN;
4885 goto out;
4886 }
4887
4888 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4889 channel_type = nla_get_u32(
4890 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4891 if (channel_type != NL80211_CHAN_NO_HT &&
4892 channel_type != NL80211_CHAN_HT20 &&
4893 channel_type != NL80211_CHAN_HT40PLUS &&
4894 channel_type != NL80211_CHAN_HT40MINUS) {
4895 err = -EINVAL;
4896 goto out;
4897 }
4898 channel_type_valid = true;
4899 }
4900
4901 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4902 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4903 if (chan == NULL) {
4904 err = -EINVAL;
4905 goto out;
4906 }
4907
4908 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4909 if (!msg) {
4910 err = -ENOMEM;
4911 goto out;
4912 }
4913
4914 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4915 NL80211_CMD_FRAME);
4916
4917 if (IS_ERR(hdr)) {
4918 err = PTR_ERR(hdr);
4919 goto free_msg;
4920 }
4921 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, channel_type,
4922 channel_type_valid,
4923 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4924 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4925 &cookie);
4926 if (err)
4927 goto free_msg;
4928
4929 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4930
4931 genlmsg_end(msg, hdr);
4932 err = genlmsg_reply(msg, info);
4933 goto out;
4934
4935 nla_put_failure:
4936 err = -ENOBUFS;
4937 free_msg:
4938 nlmsg_free(msg);
4939 out:
4940 cfg80211_unlock_rdev(rdev);
4941 dev_put(dev);
4942 unlock_rtnl:
4943 rtnl_unlock();
4944 return err;
4945 }
4946
4947 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4948 {
4949 struct cfg80211_registered_device *rdev;
4950 struct wireless_dev *wdev;
4951 struct net_device *dev;
4952 u8 ps_state;
4953 bool state;
4954 int err;
4955
4956 if (!info->attrs[NL80211_ATTR_PS_STATE]) {
4957 err = -EINVAL;
4958 goto out;
4959 }
4960
4961 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4962
4963 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) {
4964 err = -EINVAL;
4965 goto out;
4966 }
4967
4968 rtnl_lock();
4969
4970 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4971 if (err)
4972 goto unlock_rdev;
4973
4974 wdev = dev->ieee80211_ptr;
4975
4976 if (!rdev->ops->set_power_mgmt) {
4977 err = -EOPNOTSUPP;
4978 goto unlock_rdev;
4979 }
4980
4981 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4982
4983 if (state == wdev->ps)
4984 goto unlock_rdev;
4985
4986 wdev->ps = state;
4987
4988 if (rdev->ops->set_power_mgmt(wdev->wiphy, dev, wdev->ps,
4989 wdev->ps_timeout))
4990 /* assume this means it's off */
4991 wdev->ps = false;
4992
4993 unlock_rdev:
4994 cfg80211_unlock_rdev(rdev);
4995 dev_put(dev);
4996 rtnl_unlock();
4997
4998 out:
4999 return err;
5000 }
5001
5002 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5003 {
5004 struct cfg80211_registered_device *rdev;
5005 enum nl80211_ps_state ps_state;
5006 struct wireless_dev *wdev;
5007 struct net_device *dev;
5008 struct sk_buff *msg;
5009 void *hdr;
5010 int err;
5011
5012 rtnl_lock();
5013
5014 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5015 if (err)
5016 goto unlock_rtnl;
5017
5018 wdev = dev->ieee80211_ptr;
5019
5020 if (!rdev->ops->set_power_mgmt) {
5021 err = -EOPNOTSUPP;
5022 goto out;
5023 }
5024
5025 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5026 if (!msg) {
5027 err = -ENOMEM;
5028 goto out;
5029 }
5030
5031 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5032 NL80211_CMD_GET_POWER_SAVE);
5033 if (!hdr) {
5034 err = -ENOMEM;
5035 goto free_msg;
5036 }
5037
5038 if (wdev->ps)
5039 ps_state = NL80211_PS_ENABLED;
5040 else
5041 ps_state = NL80211_PS_DISABLED;
5042
5043 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5044
5045 genlmsg_end(msg, hdr);
5046 err = genlmsg_reply(msg, info);
5047 goto out;
5048
5049 nla_put_failure:
5050 err = -ENOBUFS;
5051
5052 free_msg:
5053 nlmsg_free(msg);
5054
5055 out:
5056 cfg80211_unlock_rdev(rdev);
5057 dev_put(dev);
5058
5059 unlock_rtnl:
5060 rtnl_unlock();
5061
5062 return err;
5063 }
5064
5065 static struct nla_policy
5066 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5067 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5068 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5069 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5070 };
5071
5072 static int nl80211_set_cqm_rssi(struct genl_info *info,
5073 s32 threshold, u32 hysteresis)
5074 {
5075 struct cfg80211_registered_device *rdev;
5076 struct wireless_dev *wdev;
5077 struct net_device *dev;
5078 int err;
5079
5080 if (threshold > 0)
5081 return -EINVAL;
5082
5083 rtnl_lock();
5084
5085 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5086 if (err)
5087 goto unlock_rdev;
5088
5089 wdev = dev->ieee80211_ptr;
5090
5091 if (!rdev->ops->set_cqm_rssi_config) {
5092 err = -EOPNOTSUPP;
5093 goto unlock_rdev;
5094 }
5095
5096 if (wdev->iftype != NL80211_IFTYPE_STATION) {
5097 err = -EOPNOTSUPP;
5098 goto unlock_rdev;
5099 }
5100
5101 err = rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5102 threshold, hysteresis);
5103
5104 unlock_rdev:
5105 cfg80211_unlock_rdev(rdev);
5106 dev_put(dev);
5107 rtnl_unlock();
5108
5109 return err;
5110 }
5111
5112 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5113 {
5114 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5115 struct nlattr *cqm;
5116 int err;
5117
5118 cqm = info->attrs[NL80211_ATTR_CQM];
5119 if (!cqm) {
5120 err = -EINVAL;
5121 goto out;
5122 }
5123
5124 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5125 nl80211_attr_cqm_policy);
5126 if (err)
5127 goto out;
5128
5129 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5130 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5131 s32 threshold;
5132 u32 hysteresis;
5133 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5134 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5135 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5136 } else
5137 err = -EINVAL;
5138
5139 out:
5140 return err;
5141 }
5142
5143 static struct genl_ops nl80211_ops[] = {
5144 {
5145 .cmd = NL80211_CMD_GET_WIPHY,
5146 .doit = nl80211_get_wiphy,
5147 .dumpit = nl80211_dump_wiphy,
5148 .policy = nl80211_policy,
5149 /* can be retrieved by unprivileged users */
5150 },
5151 {
5152 .cmd = NL80211_CMD_SET_WIPHY,
5153 .doit = nl80211_set_wiphy,
5154 .policy = nl80211_policy,
5155 .flags = GENL_ADMIN_PERM,
5156 },
5157 {
5158 .cmd = NL80211_CMD_GET_INTERFACE,
5159 .doit = nl80211_get_interface,
5160 .dumpit = nl80211_dump_interface,
5161 .policy = nl80211_policy,
5162 /* can be retrieved by unprivileged users */
5163 },
5164 {
5165 .cmd = NL80211_CMD_SET_INTERFACE,
5166 .doit = nl80211_set_interface,
5167 .policy = nl80211_policy,
5168 .flags = GENL_ADMIN_PERM,
5169 },
5170 {
5171 .cmd = NL80211_CMD_NEW_INTERFACE,
5172 .doit = nl80211_new_interface,
5173 .policy = nl80211_policy,
5174 .flags = GENL_ADMIN_PERM,
5175 },
5176 {
5177 .cmd = NL80211_CMD_DEL_INTERFACE,
5178 .doit = nl80211_del_interface,
5179 .policy = nl80211_policy,
5180 .flags = GENL_ADMIN_PERM,
5181 },
5182 {
5183 .cmd = NL80211_CMD_GET_KEY,
5184 .doit = nl80211_get_key,
5185 .policy = nl80211_policy,
5186 .flags = GENL_ADMIN_PERM,
5187 },
5188 {
5189 .cmd = NL80211_CMD_SET_KEY,
5190 .doit = nl80211_set_key,
5191 .policy = nl80211_policy,
5192 .flags = GENL_ADMIN_PERM,
5193 },
5194 {
5195 .cmd = NL80211_CMD_NEW_KEY,
5196 .doit = nl80211_new_key,
5197 .policy = nl80211_policy,
5198 .flags = GENL_ADMIN_PERM,
5199 },
5200 {
5201 .cmd = NL80211_CMD_DEL_KEY,
5202 .doit = nl80211_del_key,
5203 .policy = nl80211_policy,
5204 .flags = GENL_ADMIN_PERM,
5205 },
5206 {
5207 .cmd = NL80211_CMD_SET_BEACON,
5208 .policy = nl80211_policy,
5209 .flags = GENL_ADMIN_PERM,
5210 .doit = nl80211_addset_beacon,
5211 },
5212 {
5213 .cmd = NL80211_CMD_NEW_BEACON,
5214 .policy = nl80211_policy,
5215 .flags = GENL_ADMIN_PERM,
5216 .doit = nl80211_addset_beacon,
5217 },
5218 {
5219 .cmd = NL80211_CMD_DEL_BEACON,
5220 .policy = nl80211_policy,
5221 .flags = GENL_ADMIN_PERM,
5222 .doit = nl80211_del_beacon,
5223 },
5224 {
5225 .cmd = NL80211_CMD_GET_STATION,
5226 .doit = nl80211_get_station,
5227 .dumpit = nl80211_dump_station,
5228 .policy = nl80211_policy,
5229 },
5230 {
5231 .cmd = NL80211_CMD_SET_STATION,
5232 .doit = nl80211_set_station,
5233 .policy = nl80211_policy,
5234 .flags = GENL_ADMIN_PERM,
5235 },
5236 {
5237 .cmd = NL80211_CMD_NEW_STATION,
5238 .doit = nl80211_new_station,
5239 .policy = nl80211_policy,
5240 .flags = GENL_ADMIN_PERM,
5241 },
5242 {
5243 .cmd = NL80211_CMD_DEL_STATION,
5244 .doit = nl80211_del_station,
5245 .policy = nl80211_policy,
5246 .flags = GENL_ADMIN_PERM,
5247 },
5248 {
5249 .cmd = NL80211_CMD_GET_MPATH,
5250 .doit = nl80211_get_mpath,
5251 .dumpit = nl80211_dump_mpath,
5252 .policy = nl80211_policy,
5253 .flags = GENL_ADMIN_PERM,
5254 },
5255 {
5256 .cmd = NL80211_CMD_SET_MPATH,
5257 .doit = nl80211_set_mpath,
5258 .policy = nl80211_policy,
5259 .flags = GENL_ADMIN_PERM,
5260 },
5261 {
5262 .cmd = NL80211_CMD_NEW_MPATH,
5263 .doit = nl80211_new_mpath,
5264 .policy = nl80211_policy,
5265 .flags = GENL_ADMIN_PERM,
5266 },
5267 {
5268 .cmd = NL80211_CMD_DEL_MPATH,
5269 .doit = nl80211_del_mpath,
5270 .policy = nl80211_policy,
5271 .flags = GENL_ADMIN_PERM,
5272 },
5273 {
5274 .cmd = NL80211_CMD_SET_BSS,
5275 .doit = nl80211_set_bss,
5276 .policy = nl80211_policy,
5277 .flags = GENL_ADMIN_PERM,
5278 },
5279 {
5280 .cmd = NL80211_CMD_GET_REG,
5281 .doit = nl80211_get_reg,
5282 .policy = nl80211_policy,
5283 /* can be retrieved by unprivileged users */
5284 },
5285 {
5286 .cmd = NL80211_CMD_SET_REG,
5287 .doit = nl80211_set_reg,
5288 .policy = nl80211_policy,
5289 .flags = GENL_ADMIN_PERM,
5290 },
5291 {
5292 .cmd = NL80211_CMD_REQ_SET_REG,
5293 .doit = nl80211_req_set_reg,
5294 .policy = nl80211_policy,
5295 .flags = GENL_ADMIN_PERM,
5296 },
5297 {
5298 .cmd = NL80211_CMD_GET_MESH_PARAMS,
5299 .doit = nl80211_get_mesh_params,
5300 .policy = nl80211_policy,
5301 /* can be retrieved by unprivileged users */
5302 },
5303 {
5304 .cmd = NL80211_CMD_SET_MESH_PARAMS,
5305 .doit = nl80211_set_mesh_params,
5306 .policy = nl80211_policy,
5307 .flags = GENL_ADMIN_PERM,
5308 },
5309 {
5310 .cmd = NL80211_CMD_TRIGGER_SCAN,
5311 .doit = nl80211_trigger_scan,
5312 .policy = nl80211_policy,
5313 .flags = GENL_ADMIN_PERM,
5314 },
5315 {
5316 .cmd = NL80211_CMD_GET_SCAN,
5317 .policy = nl80211_policy,
5318 .dumpit = nl80211_dump_scan,
5319 },
5320 {
5321 .cmd = NL80211_CMD_AUTHENTICATE,
5322 .doit = nl80211_authenticate,
5323 .policy = nl80211_policy,
5324 .flags = GENL_ADMIN_PERM,
5325 },
5326 {
5327 .cmd = NL80211_CMD_ASSOCIATE,
5328 .doit = nl80211_associate,
5329 .policy = nl80211_policy,
5330 .flags = GENL_ADMIN_PERM,
5331 },
5332 {
5333 .cmd = NL80211_CMD_DEAUTHENTICATE,
5334 .doit = nl80211_deauthenticate,
5335 .policy = nl80211_policy,
5336 .flags = GENL_ADMIN_PERM,
5337 },
5338 {
5339 .cmd = NL80211_CMD_DISASSOCIATE,
5340 .doit = nl80211_disassociate,
5341 .policy = nl80211_policy,
5342 .flags = GENL_ADMIN_PERM,
5343 },
5344 {
5345 .cmd = NL80211_CMD_JOIN_IBSS,
5346 .doit = nl80211_join_ibss,
5347 .policy = nl80211_policy,
5348 .flags = GENL_ADMIN_PERM,
5349 },
5350 {
5351 .cmd = NL80211_CMD_LEAVE_IBSS,
5352 .doit = nl80211_leave_ibss,
5353 .policy = nl80211_policy,
5354 .flags = GENL_ADMIN_PERM,
5355 },
5356 #ifdef CONFIG_NL80211_TESTMODE
5357 {
5358 .cmd = NL80211_CMD_TESTMODE,
5359 .doit = nl80211_testmode_do,
5360 .policy = nl80211_policy,
5361 .flags = GENL_ADMIN_PERM,
5362 },
5363 #endif
5364 {
5365 .cmd = NL80211_CMD_CONNECT,
5366 .doit = nl80211_connect,
5367 .policy = nl80211_policy,
5368 .flags = GENL_ADMIN_PERM,
5369 },
5370 {
5371 .cmd = NL80211_CMD_DISCONNECT,
5372 .doit = nl80211_disconnect,
5373 .policy = nl80211_policy,
5374 .flags = GENL_ADMIN_PERM,
5375 },
5376 {
5377 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5378 .doit = nl80211_wiphy_netns,
5379 .policy = nl80211_policy,
5380 .flags = GENL_ADMIN_PERM,
5381 },
5382 {
5383 .cmd = NL80211_CMD_GET_SURVEY,
5384 .policy = nl80211_policy,
5385 .dumpit = nl80211_dump_survey,
5386 },
5387 {
5388 .cmd = NL80211_CMD_SET_PMKSA,
5389 .doit = nl80211_setdel_pmksa,
5390 .policy = nl80211_policy,
5391 .flags = GENL_ADMIN_PERM,
5392 },
5393 {
5394 .cmd = NL80211_CMD_DEL_PMKSA,
5395 .doit = nl80211_setdel_pmksa,
5396 .policy = nl80211_policy,
5397 .flags = GENL_ADMIN_PERM,
5398 },
5399 {
5400 .cmd = NL80211_CMD_FLUSH_PMKSA,
5401 .doit = nl80211_flush_pmksa,
5402 .policy = nl80211_policy,
5403 .flags = GENL_ADMIN_PERM,
5404 },
5405 {
5406 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5407 .doit = nl80211_remain_on_channel,
5408 .policy = nl80211_policy,
5409 .flags = GENL_ADMIN_PERM,
5410 },
5411 {
5412 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5413 .doit = nl80211_cancel_remain_on_channel,
5414 .policy = nl80211_policy,
5415 .flags = GENL_ADMIN_PERM,
5416 },
5417 {
5418 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5419 .doit = nl80211_set_tx_bitrate_mask,
5420 .policy = nl80211_policy,
5421 .flags = GENL_ADMIN_PERM,
5422 },
5423 {
5424 .cmd = NL80211_CMD_REGISTER_FRAME,
5425 .doit = nl80211_register_mgmt,
5426 .policy = nl80211_policy,
5427 .flags = GENL_ADMIN_PERM,
5428 },
5429 {
5430 .cmd = NL80211_CMD_FRAME,
5431 .doit = nl80211_tx_mgmt,
5432 .policy = nl80211_policy,
5433 .flags = GENL_ADMIN_PERM,
5434 },
5435 {
5436 .cmd = NL80211_CMD_SET_POWER_SAVE,
5437 .doit = nl80211_set_power_save,
5438 .policy = nl80211_policy,
5439 .flags = GENL_ADMIN_PERM,
5440 },
5441 {
5442 .cmd = NL80211_CMD_GET_POWER_SAVE,
5443 .doit = nl80211_get_power_save,
5444 .policy = nl80211_policy,
5445 /* can be retrieved by unprivileged users */
5446 },
5447 {
5448 .cmd = NL80211_CMD_SET_CQM,
5449 .doit = nl80211_set_cqm,
5450 .policy = nl80211_policy,
5451 .flags = GENL_ADMIN_PERM,
5452 },
5453 {
5454 .cmd = NL80211_CMD_SET_CHANNEL,
5455 .doit = nl80211_set_channel,
5456 .policy = nl80211_policy,
5457 .flags = GENL_ADMIN_PERM,
5458 },
5459 };
5460
5461 static struct genl_multicast_group nl80211_mlme_mcgrp = {
5462 .name = "mlme",
5463 };
5464
5465 /* multicast groups */
5466 static struct genl_multicast_group nl80211_config_mcgrp = {
5467 .name = "config",
5468 };
5469 static struct genl_multicast_group nl80211_scan_mcgrp = {
5470 .name = "scan",
5471 };
5472 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5473 .name = "regulatory",
5474 };
5475
5476 /* notification functions */
5477
5478 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5479 {
5480 struct sk_buff *msg;
5481
5482 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5483 if (!msg)
5484 return;
5485
5486 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5487 nlmsg_free(msg);
5488 return;
5489 }
5490
5491 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5492 nl80211_config_mcgrp.id, GFP_KERNEL);
5493 }
5494
5495 static int nl80211_add_scan_req(struct sk_buff *msg,
5496 struct cfg80211_registered_device *rdev)
5497 {
5498 struct cfg80211_scan_request *req = rdev->scan_req;
5499 struct nlattr *nest;
5500 int i;
5501
5502 ASSERT_RDEV_LOCK(rdev);
5503
5504 if (WARN_ON(!req))
5505 return 0;
5506
5507 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5508 if (!nest)
5509 goto nla_put_failure;
5510 for (i = 0; i < req->n_ssids; i++)
5511 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5512 nla_nest_end(msg, nest);
5513
5514 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5515 if (!nest)
5516 goto nla_put_failure;
5517 for (i = 0; i < req->n_channels; i++)
5518 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5519 nla_nest_end(msg, nest);
5520
5521 if (req->ie)
5522 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5523
5524 return 0;
5525 nla_put_failure:
5526 return -ENOBUFS;
5527 }
5528
5529 static int nl80211_send_scan_msg(struct sk_buff *msg,
5530 struct cfg80211_registered_device *rdev,
5531 struct net_device *netdev,
5532 u32 pid, u32 seq, int flags,
5533 u32 cmd)
5534 {
5535 void *hdr;
5536
5537 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5538 if (!hdr)
5539 return -1;
5540
5541 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5542 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5543
5544 /* ignore errors and send incomplete event anyway */
5545 nl80211_add_scan_req(msg, rdev);
5546
5547 return genlmsg_end(msg, hdr);
5548
5549 nla_put_failure:
5550 genlmsg_cancel(msg, hdr);
5551 return -EMSGSIZE;
5552 }
5553
5554 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5555 struct net_device *netdev)
5556 {
5557 struct sk_buff *msg;
5558
5559 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5560 if (!msg)
5561 return;
5562
5563 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5564 NL80211_CMD_TRIGGER_SCAN) < 0) {
5565 nlmsg_free(msg);
5566 return;
5567 }
5568
5569 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5570 nl80211_scan_mcgrp.id, GFP_KERNEL);
5571 }
5572
5573 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5574 struct net_device *netdev)
5575 {
5576 struct sk_buff *msg;
5577
5578 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5579 if (!msg)
5580 return;
5581
5582 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5583 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
5584 nlmsg_free(msg);
5585 return;
5586 }
5587
5588 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5589 nl80211_scan_mcgrp.id, GFP_KERNEL);
5590 }
5591
5592 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5593 struct net_device *netdev)
5594 {
5595 struct sk_buff *msg;
5596
5597 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5598 if (!msg)
5599 return;
5600
5601 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5602 NL80211_CMD_SCAN_ABORTED) < 0) {
5603 nlmsg_free(msg);
5604 return;
5605 }
5606
5607 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5608 nl80211_scan_mcgrp.id, GFP_KERNEL);
5609 }
5610
5611 /*
5612 * This can happen on global regulatory changes or device specific settings
5613 * based on custom world regulatory domains.
5614 */
5615 void nl80211_send_reg_change_event(struct regulatory_request *request)
5616 {
5617 struct sk_buff *msg;
5618 void *hdr;
5619
5620 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5621 if (!msg)
5622 return;
5623
5624 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5625 if (!hdr) {
5626 nlmsg_free(msg);
5627 return;
5628 }
5629
5630 /* Userspace can always count this one always being set */
5631 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5632
5633 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5634 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5635 NL80211_REGDOM_TYPE_WORLD);
5636 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5637 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5638 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5639 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5640 request->intersect)
5641 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5642 NL80211_REGDOM_TYPE_INTERSECTION);
5643 else {
5644 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5645 NL80211_REGDOM_TYPE_COUNTRY);
5646 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5647 }
5648
5649 if (wiphy_idx_valid(request->wiphy_idx))
5650 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5651
5652 if (genlmsg_end(msg, hdr) < 0) {
5653 nlmsg_free(msg);
5654 return;
5655 }
5656
5657 rcu_read_lock();
5658 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5659 GFP_ATOMIC);
5660 rcu_read_unlock();
5661
5662 return;
5663
5664 nla_put_failure:
5665 genlmsg_cancel(msg, hdr);
5666 nlmsg_free(msg);
5667 }
5668
5669 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5670 struct net_device *netdev,
5671 const u8 *buf, size_t len,
5672 enum nl80211_commands cmd, gfp_t gfp)
5673 {
5674 struct sk_buff *msg;
5675 void *hdr;
5676
5677 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5678 if (!msg)
5679 return;
5680
5681 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5682 if (!hdr) {
5683 nlmsg_free(msg);
5684 return;
5685 }
5686
5687 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5688 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5689 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5690
5691 if (genlmsg_end(msg, hdr) < 0) {
5692 nlmsg_free(msg);
5693 return;
5694 }
5695
5696 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5697 nl80211_mlme_mcgrp.id, gfp);
5698 return;
5699
5700 nla_put_failure:
5701 genlmsg_cancel(msg, hdr);
5702 nlmsg_free(msg);
5703 }
5704
5705 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
5706 struct net_device *netdev, const u8 *buf,
5707 size_t len, gfp_t gfp)
5708 {
5709 nl80211_send_mlme_event(rdev, netdev, buf, len,
5710 NL80211_CMD_AUTHENTICATE, gfp);
5711 }
5712
5713 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5714 struct net_device *netdev, const u8 *buf,
5715 size_t len, gfp_t gfp)
5716 {
5717 nl80211_send_mlme_event(rdev, netdev, buf, len,
5718 NL80211_CMD_ASSOCIATE, gfp);
5719 }
5720
5721 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
5722 struct net_device *netdev, const u8 *buf,
5723 size_t len, gfp_t gfp)
5724 {
5725 nl80211_send_mlme_event(rdev, netdev, buf, len,
5726 NL80211_CMD_DEAUTHENTICATE, gfp);
5727 }
5728
5729 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5730 struct net_device *netdev, const u8 *buf,
5731 size_t len, gfp_t gfp)
5732 {
5733 nl80211_send_mlme_event(rdev, netdev, buf, len,
5734 NL80211_CMD_DISASSOCIATE, gfp);
5735 }
5736
5737 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5738 struct net_device *netdev, int cmd,
5739 const u8 *addr, gfp_t gfp)
5740 {
5741 struct sk_buff *msg;
5742 void *hdr;
5743
5744 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5745 if (!msg)
5746 return;
5747
5748 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5749 if (!hdr) {
5750 nlmsg_free(msg);
5751 return;
5752 }
5753
5754 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5755 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5756 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5757 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5758
5759 if (genlmsg_end(msg, hdr) < 0) {
5760 nlmsg_free(msg);
5761 return;
5762 }
5763
5764 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5765 nl80211_mlme_mcgrp.id, gfp);
5766 return;
5767
5768 nla_put_failure:
5769 genlmsg_cancel(msg, hdr);
5770 nlmsg_free(msg);
5771 }
5772
5773 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
5774 struct net_device *netdev, const u8 *addr,
5775 gfp_t gfp)
5776 {
5777 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
5778 addr, gfp);
5779 }
5780
5781 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
5782 struct net_device *netdev, const u8 *addr,
5783 gfp_t gfp)
5784 {
5785 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5786 addr, gfp);
5787 }
5788
5789 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5790 struct net_device *netdev, const u8 *bssid,
5791 const u8 *req_ie, size_t req_ie_len,
5792 const u8 *resp_ie, size_t resp_ie_len,
5793 u16 status, gfp_t gfp)
5794 {
5795 struct sk_buff *msg;
5796 void *hdr;
5797
5798 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5799 if (!msg)
5800 return;
5801
5802 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5803 if (!hdr) {
5804 nlmsg_free(msg);
5805 return;
5806 }
5807
5808 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5809 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5810 if (bssid)
5811 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5812 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5813 if (req_ie)
5814 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5815 if (resp_ie)
5816 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5817
5818 if (genlmsg_end(msg, hdr) < 0) {
5819 nlmsg_free(msg);
5820 return;
5821 }
5822
5823 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5824 nl80211_mlme_mcgrp.id, gfp);
5825 return;
5826
5827 nla_put_failure:
5828 genlmsg_cancel(msg, hdr);
5829 nlmsg_free(msg);
5830
5831 }
5832
5833 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5834 struct net_device *netdev, const u8 *bssid,
5835 const u8 *req_ie, size_t req_ie_len,
5836 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5837 {
5838 struct sk_buff *msg;
5839 void *hdr;
5840
5841 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5842 if (!msg)
5843 return;
5844
5845 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5846 if (!hdr) {
5847 nlmsg_free(msg);
5848 return;
5849 }
5850
5851 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5852 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5853 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5854 if (req_ie)
5855 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5856 if (resp_ie)
5857 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5858
5859 if (genlmsg_end(msg, hdr) < 0) {
5860 nlmsg_free(msg);
5861 return;
5862 }
5863
5864 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5865 nl80211_mlme_mcgrp.id, gfp);
5866 return;
5867
5868 nla_put_failure:
5869 genlmsg_cancel(msg, hdr);
5870 nlmsg_free(msg);
5871
5872 }
5873
5874 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5875 struct net_device *netdev, u16 reason,
5876 const u8 *ie, size_t ie_len, bool from_ap)
5877 {
5878 struct sk_buff *msg;
5879 void *hdr;
5880
5881 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5882 if (!msg)
5883 return;
5884
5885 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5886 if (!hdr) {
5887 nlmsg_free(msg);
5888 return;
5889 }
5890
5891 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5892 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5893 if (from_ap && reason)
5894 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5895 if (from_ap)
5896 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5897 if (ie)
5898 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5899
5900 if (genlmsg_end(msg, hdr) < 0) {
5901 nlmsg_free(msg);
5902 return;
5903 }
5904
5905 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5906 nl80211_mlme_mcgrp.id, GFP_KERNEL);
5907 return;
5908
5909 nla_put_failure:
5910 genlmsg_cancel(msg, hdr);
5911 nlmsg_free(msg);
5912
5913 }
5914
5915 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5916 struct net_device *netdev, const u8 *bssid,
5917 gfp_t gfp)
5918 {
5919 struct sk_buff *msg;
5920 void *hdr;
5921
5922 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5923 if (!msg)
5924 return;
5925
5926 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5927 if (!hdr) {
5928 nlmsg_free(msg);
5929 return;
5930 }
5931
5932 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5933 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5934 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5935
5936 if (genlmsg_end(msg, hdr) < 0) {
5937 nlmsg_free(msg);
5938 return;
5939 }
5940
5941 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5942 nl80211_mlme_mcgrp.id, gfp);
5943 return;
5944
5945 nla_put_failure:
5946 genlmsg_cancel(msg, hdr);
5947 nlmsg_free(msg);
5948 }
5949
5950 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5951 struct net_device *netdev, const u8 *addr,
5952 enum nl80211_key_type key_type, int key_id,
5953 const u8 *tsc, gfp_t gfp)
5954 {
5955 struct sk_buff *msg;
5956 void *hdr;
5957
5958 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5959 if (!msg)
5960 return;
5961
5962 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5963 if (!hdr) {
5964 nlmsg_free(msg);
5965 return;
5966 }
5967
5968 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5969 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5970 if (addr)
5971 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5972 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5973 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5974 if (tsc)
5975 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5976
5977 if (genlmsg_end(msg, hdr) < 0) {
5978 nlmsg_free(msg);
5979 return;
5980 }
5981
5982 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5983 nl80211_mlme_mcgrp.id, gfp);
5984 return;
5985
5986 nla_put_failure:
5987 genlmsg_cancel(msg, hdr);
5988 nlmsg_free(msg);
5989 }
5990
5991 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5992 struct ieee80211_channel *channel_before,
5993 struct ieee80211_channel *channel_after)
5994 {
5995 struct sk_buff *msg;
5996 void *hdr;
5997 struct nlattr *nl_freq;
5998
5999 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6000 if (!msg)
6001 return;
6002
6003 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
6004 if (!hdr) {
6005 nlmsg_free(msg);
6006 return;
6007 }
6008
6009 /*
6010 * Since we are applying the beacon hint to a wiphy we know its
6011 * wiphy_idx is valid
6012 */
6013 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
6014
6015 /* Before */
6016 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
6017 if (!nl_freq)
6018 goto nla_put_failure;
6019 if (nl80211_msg_put_channel(msg, channel_before))
6020 goto nla_put_failure;
6021 nla_nest_end(msg, nl_freq);
6022
6023 /* After */
6024 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
6025 if (!nl_freq)
6026 goto nla_put_failure;
6027 if (nl80211_msg_put_channel(msg, channel_after))
6028 goto nla_put_failure;
6029 nla_nest_end(msg, nl_freq);
6030
6031 if (genlmsg_end(msg, hdr) < 0) {
6032 nlmsg_free(msg);
6033 return;
6034 }
6035
6036 rcu_read_lock();
6037 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6038 GFP_ATOMIC);
6039 rcu_read_unlock();
6040
6041 return;
6042
6043 nla_put_failure:
6044 genlmsg_cancel(msg, hdr);
6045 nlmsg_free(msg);
6046 }
6047
6048 static void nl80211_send_remain_on_chan_event(
6049 int cmd, struct cfg80211_registered_device *rdev,
6050 struct net_device *netdev, u64 cookie,
6051 struct ieee80211_channel *chan,
6052 enum nl80211_channel_type channel_type,
6053 unsigned int duration, gfp_t gfp)
6054 {
6055 struct sk_buff *msg;
6056 void *hdr;
6057
6058 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6059 if (!msg)
6060 return;
6061
6062 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6063 if (!hdr) {
6064 nlmsg_free(msg);
6065 return;
6066 }
6067
6068 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6069 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6070 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
6071 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
6072 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6073
6074 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
6075 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
6076
6077 if (genlmsg_end(msg, hdr) < 0) {
6078 nlmsg_free(msg);
6079 return;
6080 }
6081
6082 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6083 nl80211_mlme_mcgrp.id, gfp);
6084 return;
6085
6086 nla_put_failure:
6087 genlmsg_cancel(msg, hdr);
6088 nlmsg_free(msg);
6089 }
6090
6091 void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
6092 struct net_device *netdev, u64 cookie,
6093 struct ieee80211_channel *chan,
6094 enum nl80211_channel_type channel_type,
6095 unsigned int duration, gfp_t gfp)
6096 {
6097 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
6098 rdev, netdev, cookie, chan,
6099 channel_type, duration, gfp);
6100 }
6101
6102 void nl80211_send_remain_on_channel_cancel(
6103 struct cfg80211_registered_device *rdev, struct net_device *netdev,
6104 u64 cookie, struct ieee80211_channel *chan,
6105 enum nl80211_channel_type channel_type, gfp_t gfp)
6106 {
6107 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6108 rdev, netdev, cookie, chan,
6109 channel_type, 0, gfp);
6110 }
6111
6112 void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
6113 struct net_device *dev, const u8 *mac_addr,
6114 struct station_info *sinfo, gfp_t gfp)
6115 {
6116 struct sk_buff *msg;
6117
6118 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6119 if (!msg)
6120 return;
6121
6122 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6123 nlmsg_free(msg);
6124 return;
6125 }
6126
6127 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6128 nl80211_mlme_mcgrp.id, gfp);
6129 }
6130
6131 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
6132 struct net_device *netdev, u32 nlpid,
6133 int freq, const u8 *buf, size_t len, gfp_t gfp)
6134 {
6135 struct sk_buff *msg;
6136 void *hdr;
6137 int err;
6138
6139 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6140 if (!msg)
6141 return -ENOMEM;
6142
6143 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
6144 if (!hdr) {
6145 nlmsg_free(msg);
6146 return -ENOMEM;
6147 }
6148
6149 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6150 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6151 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6152 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6153
6154 err = genlmsg_end(msg, hdr);
6155 if (err < 0) {
6156 nlmsg_free(msg);
6157 return err;
6158 }
6159
6160 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6161 if (err < 0)
6162 return err;
6163 return 0;
6164
6165 nla_put_failure:
6166 genlmsg_cancel(msg, hdr);
6167 nlmsg_free(msg);
6168 return -ENOBUFS;
6169 }
6170
6171 void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
6172 struct net_device *netdev, u64 cookie,
6173 const u8 *buf, size_t len, bool ack,
6174 gfp_t gfp)
6175 {
6176 struct sk_buff *msg;
6177 void *hdr;
6178
6179 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6180 if (!msg)
6181 return;
6182
6183 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
6184 if (!hdr) {
6185 nlmsg_free(msg);
6186 return;
6187 }
6188
6189 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6190 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6191 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6192 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6193 if (ack)
6194 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6195
6196 if (genlmsg_end(msg, hdr) < 0) {
6197 nlmsg_free(msg);
6198 return;
6199 }
6200
6201 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6202 return;
6203
6204 nla_put_failure:
6205 genlmsg_cancel(msg, hdr);
6206 nlmsg_free(msg);
6207 }
6208
6209 void
6210 nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6211 struct net_device *netdev,
6212 enum nl80211_cqm_rssi_threshold_event rssi_event,
6213 gfp_t gfp)
6214 {
6215 struct sk_buff *msg;
6216 struct nlattr *pinfoattr;
6217 void *hdr;
6218
6219 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6220 if (!msg)
6221 return;
6222
6223 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6224 if (!hdr) {
6225 nlmsg_free(msg);
6226 return;
6227 }
6228
6229 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6230 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6231
6232 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6233 if (!pinfoattr)
6234 goto nla_put_failure;
6235
6236 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6237 rssi_event);
6238
6239 nla_nest_end(msg, pinfoattr);
6240
6241 if (genlmsg_end(msg, hdr) < 0) {
6242 nlmsg_free(msg);
6243 return;
6244 }
6245
6246 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6247 nl80211_mlme_mcgrp.id, gfp);
6248 return;
6249
6250 nla_put_failure:
6251 genlmsg_cancel(msg, hdr);
6252 nlmsg_free(msg);
6253 }
6254
6255 static int nl80211_netlink_notify(struct notifier_block * nb,
6256 unsigned long state,
6257 void *_notify)
6258 {
6259 struct netlink_notify *notify = _notify;
6260 struct cfg80211_registered_device *rdev;
6261 struct wireless_dev *wdev;
6262
6263 if (state != NETLINK_URELEASE)
6264 return NOTIFY_DONE;
6265
6266 rcu_read_lock();
6267
6268 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6269 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
6270 cfg80211_mlme_unregister_socket(wdev, notify->pid);
6271
6272 rcu_read_unlock();
6273
6274 return NOTIFY_DONE;
6275 }
6276
6277 static struct notifier_block nl80211_netlink_notifier = {
6278 .notifier_call = nl80211_netlink_notify,
6279 };
6280
6281 /* initialisation/exit functions */
6282
6283 int nl80211_init(void)
6284 {
6285 int err;
6286
6287 err = genl_register_family_with_ops(&nl80211_fam,
6288 nl80211_ops, ARRAY_SIZE(nl80211_ops));
6289 if (err)
6290 return err;
6291
6292 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6293 if (err)
6294 goto err_out;
6295
6296 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6297 if (err)
6298 goto err_out;
6299
6300 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6301 if (err)
6302 goto err_out;
6303
6304 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6305 if (err)
6306 goto err_out;
6307
6308 #ifdef CONFIG_NL80211_TESTMODE
6309 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6310 if (err)
6311 goto err_out;
6312 #endif
6313
6314 err = netlink_register_notifier(&nl80211_netlink_notifier);
6315 if (err)
6316 goto err_out;
6317
6318 return 0;
6319 err_out:
6320 genl_unregister_family(&nl80211_fam);
6321 return err;
6322 }
6323
6324 void nl80211_exit(void)
6325 {
6326 netlink_unregister_notifier(&nl80211_netlink_notifier);
6327 genl_unregister_family(&nl80211_fam);
6328 }
This page took 0.206359 seconds and 4 git commands to generate.