cfg80211: allow registering to beacons
[deliverable/linux.git] / net / wireless / nl80211.c
1 /*
2 * This is the new netlink-based wireless configuration interface.
3 *
4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
5 */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/slab.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/net_namespace.h>
19 #include <net/genetlink.h>
20 #include <net/cfg80211.h>
21 #include <net/sock.h>
22 #include "core.h"
23 #include "nl80211.h"
24 #include "reg.h"
25
26 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
32 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
37 /* the netlink family */
38 static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
44 .netnsok = true,
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
47 };
48
49 /* internal helper: get rdev and dev */
50 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
51 struct cfg80211_registered_device **rdev,
52 struct net_device **dev)
53 {
54 struct nlattr **attrs = info->attrs;
55 int ifindex;
56
57 if (!attrs[NL80211_ATTR_IFINDEX])
58 return -EINVAL;
59
60 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
61 *dev = dev_get_by_index(genl_info_net(info), ifindex);
62 if (!*dev)
63 return -ENODEV;
64
65 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
66 if (IS_ERR(*rdev)) {
67 dev_put(*dev);
68 return PTR_ERR(*rdev);
69 }
70
71 return 0;
72 }
73
74 /* policy for the attributes */
75 static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
76 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
77 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
78 .len = 20-1 },
79 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
80 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
81 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
82 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
84 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
85 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
86 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
87
88 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
90 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
91
92 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
93 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
94
95 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
96 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
97 .len = WLAN_MAX_KEY_LEN },
98 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
99 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
100 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
101 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
102 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
103
104 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
105 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
106 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
107 .len = IEEE80211_MAX_DATA_LEN },
108 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
109 .len = IEEE80211_MAX_DATA_LEN },
110 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
111 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
112 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
113 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
114 .len = NL80211_MAX_SUPP_RATES },
115 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
116 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
117 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
118 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
119 .len = IEEE80211_MAX_MESH_ID_LEN },
120 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
121
122 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
123 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
124
125 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
127 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
128 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
129 .len = NL80211_MAX_SUPP_RATES },
130 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
131
132 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
133 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
134
135 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
136
137 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
138 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
139 .len = IEEE80211_MAX_DATA_LEN },
140 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
141 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
142
143 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
144 .len = IEEE80211_MAX_SSID_LEN },
145 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
146 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
147 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
148 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
149 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
150 [NL80211_ATTR_STA_FLAGS2] = {
151 .len = sizeof(struct nl80211_sta_flag_update),
152 },
153 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
154 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
155 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
156 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
157 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
158 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
159 [NL80211_ATTR_PID] = { .type = NLA_U32 },
160 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
161 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
162 .len = WLAN_PMKID_LEN },
163 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
164 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
165 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
166 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
167 .len = IEEE80211_MAX_DATA_LEN },
168 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
169 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
170 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
171 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
172 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
173 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
174 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
175 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
176 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
177 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
178 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
179 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
180 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
181 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
182 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
183 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
184 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
185 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
186 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
187 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
188 .len = IEEE80211_MAX_DATA_LEN },
189 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
190 .len = IEEE80211_MAX_DATA_LEN },
191 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
192 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
193 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
194 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
197 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
198 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
199 };
200
201 /* policy for the key attributes */
202 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
203 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
204 [NL80211_KEY_IDX] = { .type = NLA_U8 },
205 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
206 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
207 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
208 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
209 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
210 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
211 };
212
213 /* policy for the key default flags */
214 static const struct nla_policy
215 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
216 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
217 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
218 };
219
220 /* policy for WoWLAN attributes */
221 static const struct nla_policy
222 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
223 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
224 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
225 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
226 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
227 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
228 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
229 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
230 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
231 };
232
233 /* policy for GTK rekey offload attributes */
234 static const struct nla_policy
235 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
236 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
237 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
238 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
239 };
240
241 static const struct nla_policy
242 nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
243 [NL80211_ATTR_SCHED_SCAN_MATCH_SSID] = { .type = NLA_BINARY,
244 .len = IEEE80211_MAX_SSID_LEN },
245 };
246
247 /* ifidx get helper */
248 static int nl80211_get_ifidx(struct netlink_callback *cb)
249 {
250 int res;
251
252 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
253 nl80211_fam.attrbuf, nl80211_fam.maxattr,
254 nl80211_policy);
255 if (res)
256 return res;
257
258 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
259 return -EINVAL;
260
261 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
262 if (!res)
263 return -EINVAL;
264 return res;
265 }
266
267 static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
268 struct netlink_callback *cb,
269 struct cfg80211_registered_device **rdev,
270 struct net_device **dev)
271 {
272 int ifidx = cb->args[0];
273 int err;
274
275 if (!ifidx)
276 ifidx = nl80211_get_ifidx(cb);
277 if (ifidx < 0)
278 return ifidx;
279
280 cb->args[0] = ifidx;
281
282 rtnl_lock();
283
284 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
285 if (!*dev) {
286 err = -ENODEV;
287 goto out_rtnl;
288 }
289
290 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
291 if (IS_ERR(*rdev)) {
292 err = PTR_ERR(*rdev);
293 goto out_rtnl;
294 }
295
296 return 0;
297 out_rtnl:
298 rtnl_unlock();
299 return err;
300 }
301
302 static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
303 {
304 cfg80211_unlock_rdev(rdev);
305 rtnl_unlock();
306 }
307
308 /* IE validation */
309 static bool is_valid_ie_attr(const struct nlattr *attr)
310 {
311 const u8 *pos;
312 int len;
313
314 if (!attr)
315 return true;
316
317 pos = nla_data(attr);
318 len = nla_len(attr);
319
320 while (len) {
321 u8 elemlen;
322
323 if (len < 2)
324 return false;
325 len -= 2;
326
327 elemlen = pos[1];
328 if (elemlen > len)
329 return false;
330
331 len -= elemlen;
332 pos += 2 + elemlen;
333 }
334
335 return true;
336 }
337
338 /* message building helper */
339 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
340 int flags, u8 cmd)
341 {
342 /* since there is no private header just add the generic one */
343 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
344 }
345
346 static int nl80211_msg_put_channel(struct sk_buff *msg,
347 struct ieee80211_channel *chan)
348 {
349 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
350 chan->center_freq);
351
352 if (chan->flags & IEEE80211_CHAN_DISABLED)
353 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
354 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
355 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
356 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
357 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
358 if (chan->flags & IEEE80211_CHAN_RADAR)
359 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
360
361 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
362 DBM_TO_MBM(chan->max_power));
363
364 return 0;
365
366 nla_put_failure:
367 return -ENOBUFS;
368 }
369
370 /* netlink command implementations */
371
372 struct key_parse {
373 struct key_params p;
374 int idx;
375 int type;
376 bool def, defmgmt;
377 bool def_uni, def_multi;
378 };
379
380 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
381 {
382 struct nlattr *tb[NL80211_KEY_MAX + 1];
383 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
384 nl80211_key_policy);
385 if (err)
386 return err;
387
388 k->def = !!tb[NL80211_KEY_DEFAULT];
389 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
390
391 if (k->def) {
392 k->def_uni = true;
393 k->def_multi = true;
394 }
395 if (k->defmgmt)
396 k->def_multi = true;
397
398 if (tb[NL80211_KEY_IDX])
399 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
400
401 if (tb[NL80211_KEY_DATA]) {
402 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
403 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
404 }
405
406 if (tb[NL80211_KEY_SEQ]) {
407 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
408 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
409 }
410
411 if (tb[NL80211_KEY_CIPHER])
412 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
413
414 if (tb[NL80211_KEY_TYPE]) {
415 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
416 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
417 return -EINVAL;
418 }
419
420 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
421 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
422 int err = nla_parse_nested(kdt,
423 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
424 tb[NL80211_KEY_DEFAULT_TYPES],
425 nl80211_key_default_policy);
426 if (err)
427 return err;
428
429 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
430 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
431 }
432
433 return 0;
434 }
435
436 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
437 {
438 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
439 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
440 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
441 }
442
443 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
444 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
445 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
446 }
447
448 if (info->attrs[NL80211_ATTR_KEY_IDX])
449 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
450
451 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
452 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
453
454 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
455 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
456
457 if (k->def) {
458 k->def_uni = true;
459 k->def_multi = true;
460 }
461 if (k->defmgmt)
462 k->def_multi = true;
463
464 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
465 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
466 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
467 return -EINVAL;
468 }
469
470 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
471 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
472 int err = nla_parse_nested(
473 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
474 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
475 nl80211_key_default_policy);
476 if (err)
477 return err;
478
479 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
480 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
481 }
482
483 return 0;
484 }
485
486 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
487 {
488 int err;
489
490 memset(k, 0, sizeof(*k));
491 k->idx = -1;
492 k->type = -1;
493
494 if (info->attrs[NL80211_ATTR_KEY])
495 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
496 else
497 err = nl80211_parse_key_old(info, k);
498
499 if (err)
500 return err;
501
502 if (k->def && k->defmgmt)
503 return -EINVAL;
504
505 if (k->defmgmt) {
506 if (k->def_uni || !k->def_multi)
507 return -EINVAL;
508 }
509
510 if (k->idx != -1) {
511 if (k->defmgmt) {
512 if (k->idx < 4 || k->idx > 5)
513 return -EINVAL;
514 } else if (k->def) {
515 if (k->idx < 0 || k->idx > 3)
516 return -EINVAL;
517 } else {
518 if (k->idx < 0 || k->idx > 5)
519 return -EINVAL;
520 }
521 }
522
523 return 0;
524 }
525
526 static struct cfg80211_cached_keys *
527 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
528 struct nlattr *keys)
529 {
530 struct key_parse parse;
531 struct nlattr *key;
532 struct cfg80211_cached_keys *result;
533 int rem, err, def = 0;
534
535 result = kzalloc(sizeof(*result), GFP_KERNEL);
536 if (!result)
537 return ERR_PTR(-ENOMEM);
538
539 result->def = -1;
540 result->defmgmt = -1;
541
542 nla_for_each_nested(key, keys, rem) {
543 memset(&parse, 0, sizeof(parse));
544 parse.idx = -1;
545
546 err = nl80211_parse_key_new(key, &parse);
547 if (err)
548 goto error;
549 err = -EINVAL;
550 if (!parse.p.key)
551 goto error;
552 if (parse.idx < 0 || parse.idx > 4)
553 goto error;
554 if (parse.def) {
555 if (def)
556 goto error;
557 def = 1;
558 result->def = parse.idx;
559 if (!parse.def_uni || !parse.def_multi)
560 goto error;
561 } else if (parse.defmgmt)
562 goto error;
563 err = cfg80211_validate_key_settings(rdev, &parse.p,
564 parse.idx, false, NULL);
565 if (err)
566 goto error;
567 result->params[parse.idx].cipher = parse.p.cipher;
568 result->params[parse.idx].key_len = parse.p.key_len;
569 result->params[parse.idx].key = result->data[parse.idx];
570 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
571 }
572
573 return result;
574 error:
575 kfree(result);
576 return ERR_PTR(err);
577 }
578
579 static int nl80211_key_allowed(struct wireless_dev *wdev)
580 {
581 ASSERT_WDEV_LOCK(wdev);
582
583 switch (wdev->iftype) {
584 case NL80211_IFTYPE_AP:
585 case NL80211_IFTYPE_AP_VLAN:
586 case NL80211_IFTYPE_P2P_GO:
587 case NL80211_IFTYPE_MESH_POINT:
588 break;
589 case NL80211_IFTYPE_ADHOC:
590 if (!wdev->current_bss)
591 return -ENOLINK;
592 break;
593 case NL80211_IFTYPE_STATION:
594 case NL80211_IFTYPE_P2P_CLIENT:
595 if (wdev->sme_state != CFG80211_SME_CONNECTED)
596 return -ENOLINK;
597 break;
598 default:
599 return -EINVAL;
600 }
601
602 return 0;
603 }
604
605 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
606 {
607 struct nlattr *nl_modes = nla_nest_start(msg, attr);
608 int i;
609
610 if (!nl_modes)
611 goto nla_put_failure;
612
613 i = 0;
614 while (ifmodes) {
615 if (ifmodes & 1)
616 NLA_PUT_FLAG(msg, i);
617 ifmodes >>= 1;
618 i++;
619 }
620
621 nla_nest_end(msg, nl_modes);
622 return 0;
623
624 nla_put_failure:
625 return -ENOBUFS;
626 }
627
628 static int nl80211_put_iface_combinations(struct wiphy *wiphy,
629 struct sk_buff *msg)
630 {
631 struct nlattr *nl_combis;
632 int i, j;
633
634 nl_combis = nla_nest_start(msg,
635 NL80211_ATTR_INTERFACE_COMBINATIONS);
636 if (!nl_combis)
637 goto nla_put_failure;
638
639 for (i = 0; i < wiphy->n_iface_combinations; i++) {
640 const struct ieee80211_iface_combination *c;
641 struct nlattr *nl_combi, *nl_limits;
642
643 c = &wiphy->iface_combinations[i];
644
645 nl_combi = nla_nest_start(msg, i + 1);
646 if (!nl_combi)
647 goto nla_put_failure;
648
649 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
650 if (!nl_limits)
651 goto nla_put_failure;
652
653 for (j = 0; j < c->n_limits; j++) {
654 struct nlattr *nl_limit;
655
656 nl_limit = nla_nest_start(msg, j + 1);
657 if (!nl_limit)
658 goto nla_put_failure;
659 NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
660 c->limits[j].max);
661 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
662 c->limits[j].types))
663 goto nla_put_failure;
664 nla_nest_end(msg, nl_limit);
665 }
666
667 nla_nest_end(msg, nl_limits);
668
669 if (c->beacon_int_infra_match)
670 NLA_PUT_FLAG(msg,
671 NL80211_IFACE_COMB_STA_AP_BI_MATCH);
672 NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
673 c->num_different_channels);
674 NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
675 c->max_interfaces);
676
677 nla_nest_end(msg, nl_combi);
678 }
679
680 nla_nest_end(msg, nl_combis);
681
682 return 0;
683 nla_put_failure:
684 return -ENOBUFS;
685 }
686
687 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
688 struct cfg80211_registered_device *dev)
689 {
690 void *hdr;
691 struct nlattr *nl_bands, *nl_band;
692 struct nlattr *nl_freqs, *nl_freq;
693 struct nlattr *nl_rates, *nl_rate;
694 struct nlattr *nl_cmds;
695 enum ieee80211_band band;
696 struct ieee80211_channel *chan;
697 struct ieee80211_rate *rate;
698 int i;
699 const struct ieee80211_txrx_stypes *mgmt_stypes =
700 dev->wiphy.mgmt_stypes;
701
702 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
703 if (!hdr)
704 return -1;
705
706 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
707 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
708
709 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
710 cfg80211_rdev_list_generation);
711
712 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
713 dev->wiphy.retry_short);
714 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
715 dev->wiphy.retry_long);
716 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
717 dev->wiphy.frag_threshold);
718 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
719 dev->wiphy.rts_threshold);
720 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
721 dev->wiphy.coverage_class);
722 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
723 dev->wiphy.max_scan_ssids);
724 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
725 dev->wiphy.max_sched_scan_ssids);
726 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
727 dev->wiphy.max_scan_ie_len);
728 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
729 dev->wiphy.max_sched_scan_ie_len);
730 NLA_PUT_U8(msg, NL80211_ATTR_MAX_MATCH_SETS,
731 dev->wiphy.max_match_sets);
732
733 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
734 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
735 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
736 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
737 if (dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD)
738 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_AP_UAPSD);
739 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)
740 NLA_PUT_FLAG(msg, NL80211_ATTR_ROAM_SUPPORT);
741 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)
742 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_SUPPORT);
743 if (dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)
744 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP);
745
746 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
747 sizeof(u32) * dev->wiphy.n_cipher_suites,
748 dev->wiphy.cipher_suites);
749
750 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
751 dev->wiphy.max_num_pmkids);
752
753 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
754 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
755
756 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
757 dev->wiphy.available_antennas_tx);
758 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
759 dev->wiphy.available_antennas_rx);
760
761 if ((dev->wiphy.available_antennas_tx ||
762 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
763 u32 tx_ant = 0, rx_ant = 0;
764 int res;
765 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
766 if (!res) {
767 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
768 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
769 }
770 }
771
772 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
773 dev->wiphy.interface_modes))
774 goto nla_put_failure;
775
776 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
777 if (!nl_bands)
778 goto nla_put_failure;
779
780 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
781 if (!dev->wiphy.bands[band])
782 continue;
783
784 nl_band = nla_nest_start(msg, band);
785 if (!nl_band)
786 goto nla_put_failure;
787
788 /* add HT info */
789 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
790 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
791 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
792 &dev->wiphy.bands[band]->ht_cap.mcs);
793 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
794 dev->wiphy.bands[band]->ht_cap.cap);
795 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
796 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
797 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
798 dev->wiphy.bands[band]->ht_cap.ampdu_density);
799 }
800
801 /* add frequencies */
802 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
803 if (!nl_freqs)
804 goto nla_put_failure;
805
806 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
807 nl_freq = nla_nest_start(msg, i);
808 if (!nl_freq)
809 goto nla_put_failure;
810
811 chan = &dev->wiphy.bands[band]->channels[i];
812
813 if (nl80211_msg_put_channel(msg, chan))
814 goto nla_put_failure;
815
816 nla_nest_end(msg, nl_freq);
817 }
818
819 nla_nest_end(msg, nl_freqs);
820
821 /* add bitrates */
822 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
823 if (!nl_rates)
824 goto nla_put_failure;
825
826 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
827 nl_rate = nla_nest_start(msg, i);
828 if (!nl_rate)
829 goto nla_put_failure;
830
831 rate = &dev->wiphy.bands[band]->bitrates[i];
832 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
833 rate->bitrate);
834 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
835 NLA_PUT_FLAG(msg,
836 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
837
838 nla_nest_end(msg, nl_rate);
839 }
840
841 nla_nest_end(msg, nl_rates);
842
843 nla_nest_end(msg, nl_band);
844 }
845 nla_nest_end(msg, nl_bands);
846
847 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
848 if (!nl_cmds)
849 goto nla_put_failure;
850
851 i = 0;
852 #define CMD(op, n) \
853 do { \
854 if (dev->ops->op) { \
855 i++; \
856 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
857 } \
858 } while (0)
859
860 CMD(add_virtual_intf, NEW_INTERFACE);
861 CMD(change_virtual_intf, SET_INTERFACE);
862 CMD(add_key, NEW_KEY);
863 CMD(add_beacon, NEW_BEACON);
864 CMD(add_station, NEW_STATION);
865 CMD(add_mpath, NEW_MPATH);
866 CMD(update_mesh_config, SET_MESH_CONFIG);
867 CMD(change_bss, SET_BSS);
868 CMD(auth, AUTHENTICATE);
869 CMD(assoc, ASSOCIATE);
870 CMD(deauth, DEAUTHENTICATE);
871 CMD(disassoc, DISASSOCIATE);
872 CMD(join_ibss, JOIN_IBSS);
873 CMD(join_mesh, JOIN_MESH);
874 CMD(set_pmksa, SET_PMKSA);
875 CMD(del_pmksa, DEL_PMKSA);
876 CMD(flush_pmksa, FLUSH_PMKSA);
877 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
878 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
879 CMD(mgmt_tx, FRAME);
880 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
881 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
882 i++;
883 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
884 }
885 CMD(set_channel, SET_CHANNEL);
886 CMD(set_wds_peer, SET_WDS_PEER);
887 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
888 CMD(tdls_mgmt, TDLS_MGMT);
889 CMD(tdls_oper, TDLS_OPER);
890 }
891 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
892 CMD(sched_scan_start, START_SCHED_SCAN);
893 CMD(probe_client, PROBE_CLIENT);
894 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
895 i++;
896 NLA_PUT_U32(msg, i, NL80211_CMD_REGISTER_BEACONS);
897 }
898
899 #undef CMD
900
901 if (dev->ops->connect || dev->ops->auth) {
902 i++;
903 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
904 }
905
906 if (dev->ops->disconnect || dev->ops->deauth) {
907 i++;
908 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
909 }
910
911 nla_nest_end(msg, nl_cmds);
912
913 if (dev->ops->remain_on_channel)
914 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
915 dev->wiphy.max_remain_on_channel_duration);
916
917 if (dev->ops->mgmt_tx_cancel_wait)
918 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
919
920 if (mgmt_stypes) {
921 u16 stypes;
922 struct nlattr *nl_ftypes, *nl_ifs;
923 enum nl80211_iftype ift;
924
925 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
926 if (!nl_ifs)
927 goto nla_put_failure;
928
929 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
930 nl_ftypes = nla_nest_start(msg, ift);
931 if (!nl_ftypes)
932 goto nla_put_failure;
933 i = 0;
934 stypes = mgmt_stypes[ift].tx;
935 while (stypes) {
936 if (stypes & 1)
937 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
938 (i << 4) | IEEE80211_FTYPE_MGMT);
939 stypes >>= 1;
940 i++;
941 }
942 nla_nest_end(msg, nl_ftypes);
943 }
944
945 nla_nest_end(msg, nl_ifs);
946
947 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
948 if (!nl_ifs)
949 goto nla_put_failure;
950
951 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
952 nl_ftypes = nla_nest_start(msg, ift);
953 if (!nl_ftypes)
954 goto nla_put_failure;
955 i = 0;
956 stypes = mgmt_stypes[ift].rx;
957 while (stypes) {
958 if (stypes & 1)
959 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
960 (i << 4) | IEEE80211_FTYPE_MGMT);
961 stypes >>= 1;
962 i++;
963 }
964 nla_nest_end(msg, nl_ftypes);
965 }
966 nla_nest_end(msg, nl_ifs);
967 }
968
969 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
970 struct nlattr *nl_wowlan;
971
972 nl_wowlan = nla_nest_start(msg,
973 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
974 if (!nl_wowlan)
975 goto nla_put_failure;
976
977 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
978 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
979 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
980 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
981 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
982 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
983 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
984 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
985 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
986 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
987 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
988 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
989 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
990 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
991 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
992 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
993 if (dev->wiphy.wowlan.n_patterns) {
994 struct nl80211_wowlan_pattern_support pat = {
995 .max_patterns = dev->wiphy.wowlan.n_patterns,
996 .min_pattern_len =
997 dev->wiphy.wowlan.pattern_min_len,
998 .max_pattern_len =
999 dev->wiphy.wowlan.pattern_max_len,
1000 };
1001 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1002 sizeof(pat), &pat);
1003 }
1004
1005 nla_nest_end(msg, nl_wowlan);
1006 }
1007
1008 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1009 dev->wiphy.software_iftypes))
1010 goto nla_put_failure;
1011
1012 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1013 goto nla_put_failure;
1014
1015 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME)
1016 NLA_PUT_U32(msg, NL80211_ATTR_DEVICE_AP_SME,
1017 dev->wiphy.ap_sme_capa);
1018
1019 return genlmsg_end(msg, hdr);
1020
1021 nla_put_failure:
1022 genlmsg_cancel(msg, hdr);
1023 return -EMSGSIZE;
1024 }
1025
1026 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1027 {
1028 int idx = 0;
1029 int start = cb->args[0];
1030 struct cfg80211_registered_device *dev;
1031
1032 mutex_lock(&cfg80211_mutex);
1033 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
1034 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1035 continue;
1036 if (++idx <= start)
1037 continue;
1038 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1039 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1040 dev) < 0) {
1041 idx--;
1042 break;
1043 }
1044 }
1045 mutex_unlock(&cfg80211_mutex);
1046
1047 cb->args[0] = idx;
1048
1049 return skb->len;
1050 }
1051
1052 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1053 {
1054 struct sk_buff *msg;
1055 struct cfg80211_registered_device *dev = info->user_ptr[0];
1056
1057 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1058 if (!msg)
1059 return -ENOMEM;
1060
1061 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1062 nlmsg_free(msg);
1063 return -ENOBUFS;
1064 }
1065
1066 return genlmsg_reply(msg, info);
1067 }
1068
1069 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1070 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1071 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1072 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1073 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1074 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1075 };
1076
1077 static int parse_txq_params(struct nlattr *tb[],
1078 struct ieee80211_txq_params *txq_params)
1079 {
1080 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
1081 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1082 !tb[NL80211_TXQ_ATTR_AIFS])
1083 return -EINVAL;
1084
1085 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
1086 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1087 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1088 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1089 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1090
1091 return 0;
1092 }
1093
1094 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1095 {
1096 /*
1097 * You can only set the channel explicitly for AP, mesh
1098 * and WDS type interfaces; all others have their channel
1099 * managed via their respective "establish a connection"
1100 * command (connect, join, ...)
1101 *
1102 * Monitors are special as they are normally slaved to
1103 * whatever else is going on, so they behave as though
1104 * you tried setting the wiphy channel itself.
1105 */
1106 return !wdev ||
1107 wdev->iftype == NL80211_IFTYPE_AP ||
1108 wdev->iftype == NL80211_IFTYPE_WDS ||
1109 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
1110 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1111 wdev->iftype == NL80211_IFTYPE_P2P_GO;
1112 }
1113
1114 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1115 struct wireless_dev *wdev,
1116 struct genl_info *info)
1117 {
1118 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1119 u32 freq;
1120 int result;
1121
1122 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1123 return -EINVAL;
1124
1125 if (!nl80211_can_set_dev_channel(wdev))
1126 return -EOPNOTSUPP;
1127
1128 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1129 channel_type = nla_get_u32(info->attrs[
1130 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1131 if (channel_type != NL80211_CHAN_NO_HT &&
1132 channel_type != NL80211_CHAN_HT20 &&
1133 channel_type != NL80211_CHAN_HT40PLUS &&
1134 channel_type != NL80211_CHAN_HT40MINUS)
1135 return -EINVAL;
1136 }
1137
1138 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1139
1140 mutex_lock(&rdev->devlist_mtx);
1141 if (wdev) {
1142 wdev_lock(wdev);
1143 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1144 wdev_unlock(wdev);
1145 } else {
1146 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1147 }
1148 mutex_unlock(&rdev->devlist_mtx);
1149
1150 return result;
1151 }
1152
1153 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1154 {
1155 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1156 struct net_device *netdev = info->user_ptr[1];
1157
1158 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
1159 }
1160
1161 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1162 {
1163 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1164 struct net_device *dev = info->user_ptr[1];
1165 struct wireless_dev *wdev = dev->ieee80211_ptr;
1166 const u8 *bssid;
1167
1168 if (!info->attrs[NL80211_ATTR_MAC])
1169 return -EINVAL;
1170
1171 if (netif_running(dev))
1172 return -EBUSY;
1173
1174 if (!rdev->ops->set_wds_peer)
1175 return -EOPNOTSUPP;
1176
1177 if (wdev->iftype != NL80211_IFTYPE_WDS)
1178 return -EOPNOTSUPP;
1179
1180 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1181 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
1182 }
1183
1184
1185 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1186 {
1187 struct cfg80211_registered_device *rdev;
1188 struct net_device *netdev = NULL;
1189 struct wireless_dev *wdev;
1190 int result = 0, rem_txq_params = 0;
1191 struct nlattr *nl_txq_params;
1192 u32 changed;
1193 u8 retry_short = 0, retry_long = 0;
1194 u32 frag_threshold = 0, rts_threshold = 0;
1195 u8 coverage_class = 0;
1196
1197 /*
1198 * Try to find the wiphy and netdev. Normally this
1199 * function shouldn't need the netdev, but this is
1200 * done for backward compatibility -- previously
1201 * setting the channel was done per wiphy, but now
1202 * it is per netdev. Previous userland like hostapd
1203 * also passed a netdev to set_wiphy, so that it is
1204 * possible to let that go to the right netdev!
1205 */
1206 mutex_lock(&cfg80211_mutex);
1207
1208 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1209 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1210
1211 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1212 if (netdev && netdev->ieee80211_ptr) {
1213 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1214 mutex_lock(&rdev->mtx);
1215 } else
1216 netdev = NULL;
1217 }
1218
1219 if (!netdev) {
1220 rdev = __cfg80211_rdev_from_info(info);
1221 if (IS_ERR(rdev)) {
1222 mutex_unlock(&cfg80211_mutex);
1223 return PTR_ERR(rdev);
1224 }
1225 wdev = NULL;
1226 netdev = NULL;
1227 result = 0;
1228
1229 mutex_lock(&rdev->mtx);
1230 } else if (netif_running(netdev) &&
1231 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1232 wdev = netdev->ieee80211_ptr;
1233 else
1234 wdev = NULL;
1235
1236 /*
1237 * end workaround code, by now the rdev is available
1238 * and locked, and wdev may or may not be NULL.
1239 */
1240
1241 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
1242 result = cfg80211_dev_rename(
1243 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
1244
1245 mutex_unlock(&cfg80211_mutex);
1246
1247 if (result)
1248 goto bad_res;
1249
1250 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1251 struct ieee80211_txq_params txq_params;
1252 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1253
1254 if (!rdev->ops->set_txq_params) {
1255 result = -EOPNOTSUPP;
1256 goto bad_res;
1257 }
1258
1259 if (!netdev) {
1260 result = -EINVAL;
1261 goto bad_res;
1262 }
1263
1264 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1265 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1266 result = -EINVAL;
1267 goto bad_res;
1268 }
1269
1270 nla_for_each_nested(nl_txq_params,
1271 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1272 rem_txq_params) {
1273 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1274 nla_data(nl_txq_params),
1275 nla_len(nl_txq_params),
1276 txq_params_policy);
1277 result = parse_txq_params(tb, &txq_params);
1278 if (result)
1279 goto bad_res;
1280
1281 result = rdev->ops->set_txq_params(&rdev->wiphy,
1282 netdev,
1283 &txq_params);
1284 if (result)
1285 goto bad_res;
1286 }
1287 }
1288
1289 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
1290 result = __nl80211_set_channel(rdev, wdev, info);
1291 if (result)
1292 goto bad_res;
1293 }
1294
1295 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1296 enum nl80211_tx_power_setting type;
1297 int idx, mbm = 0;
1298
1299 if (!rdev->ops->set_tx_power) {
1300 result = -EOPNOTSUPP;
1301 goto bad_res;
1302 }
1303
1304 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1305 type = nla_get_u32(info->attrs[idx]);
1306
1307 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1308 (type != NL80211_TX_POWER_AUTOMATIC)) {
1309 result = -EINVAL;
1310 goto bad_res;
1311 }
1312
1313 if (type != NL80211_TX_POWER_AUTOMATIC) {
1314 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1315 mbm = nla_get_u32(info->attrs[idx]);
1316 }
1317
1318 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1319 if (result)
1320 goto bad_res;
1321 }
1322
1323 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1324 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1325 u32 tx_ant, rx_ant;
1326 if ((!rdev->wiphy.available_antennas_tx &&
1327 !rdev->wiphy.available_antennas_rx) ||
1328 !rdev->ops->set_antenna) {
1329 result = -EOPNOTSUPP;
1330 goto bad_res;
1331 }
1332
1333 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1334 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1335
1336 /* reject antenna configurations which don't match the
1337 * available antenna masks, except for the "all" mask */
1338 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1339 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
1340 result = -EINVAL;
1341 goto bad_res;
1342 }
1343
1344 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1345 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
1346
1347 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1348 if (result)
1349 goto bad_res;
1350 }
1351
1352 changed = 0;
1353
1354 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1355 retry_short = nla_get_u8(
1356 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1357 if (retry_short == 0) {
1358 result = -EINVAL;
1359 goto bad_res;
1360 }
1361 changed |= WIPHY_PARAM_RETRY_SHORT;
1362 }
1363
1364 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1365 retry_long = nla_get_u8(
1366 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1367 if (retry_long == 0) {
1368 result = -EINVAL;
1369 goto bad_res;
1370 }
1371 changed |= WIPHY_PARAM_RETRY_LONG;
1372 }
1373
1374 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1375 frag_threshold = nla_get_u32(
1376 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1377 if (frag_threshold < 256) {
1378 result = -EINVAL;
1379 goto bad_res;
1380 }
1381 if (frag_threshold != (u32) -1) {
1382 /*
1383 * Fragments (apart from the last one) are required to
1384 * have even length. Make the fragmentation code
1385 * simpler by stripping LSB should someone try to use
1386 * odd threshold value.
1387 */
1388 frag_threshold &= ~0x1;
1389 }
1390 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1391 }
1392
1393 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1394 rts_threshold = nla_get_u32(
1395 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1396 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1397 }
1398
1399 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1400 coverage_class = nla_get_u8(
1401 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1402 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1403 }
1404
1405 if (changed) {
1406 u8 old_retry_short, old_retry_long;
1407 u32 old_frag_threshold, old_rts_threshold;
1408 u8 old_coverage_class;
1409
1410 if (!rdev->ops->set_wiphy_params) {
1411 result = -EOPNOTSUPP;
1412 goto bad_res;
1413 }
1414
1415 old_retry_short = rdev->wiphy.retry_short;
1416 old_retry_long = rdev->wiphy.retry_long;
1417 old_frag_threshold = rdev->wiphy.frag_threshold;
1418 old_rts_threshold = rdev->wiphy.rts_threshold;
1419 old_coverage_class = rdev->wiphy.coverage_class;
1420
1421 if (changed & WIPHY_PARAM_RETRY_SHORT)
1422 rdev->wiphy.retry_short = retry_short;
1423 if (changed & WIPHY_PARAM_RETRY_LONG)
1424 rdev->wiphy.retry_long = retry_long;
1425 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1426 rdev->wiphy.frag_threshold = frag_threshold;
1427 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1428 rdev->wiphy.rts_threshold = rts_threshold;
1429 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1430 rdev->wiphy.coverage_class = coverage_class;
1431
1432 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1433 if (result) {
1434 rdev->wiphy.retry_short = old_retry_short;
1435 rdev->wiphy.retry_long = old_retry_long;
1436 rdev->wiphy.frag_threshold = old_frag_threshold;
1437 rdev->wiphy.rts_threshold = old_rts_threshold;
1438 rdev->wiphy.coverage_class = old_coverage_class;
1439 }
1440 }
1441
1442 bad_res:
1443 mutex_unlock(&rdev->mtx);
1444 if (netdev)
1445 dev_put(netdev);
1446 return result;
1447 }
1448
1449
1450 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
1451 struct cfg80211_registered_device *rdev,
1452 struct net_device *dev)
1453 {
1454 void *hdr;
1455
1456 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1457 if (!hdr)
1458 return -1;
1459
1460 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1461 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
1462 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
1463 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
1464
1465 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1466 rdev->devlist_generation ^
1467 (cfg80211_rdev_list_generation << 2));
1468
1469 return genlmsg_end(msg, hdr);
1470
1471 nla_put_failure:
1472 genlmsg_cancel(msg, hdr);
1473 return -EMSGSIZE;
1474 }
1475
1476 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1477 {
1478 int wp_idx = 0;
1479 int if_idx = 0;
1480 int wp_start = cb->args[0];
1481 int if_start = cb->args[1];
1482 struct cfg80211_registered_device *rdev;
1483 struct wireless_dev *wdev;
1484
1485 mutex_lock(&cfg80211_mutex);
1486 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1487 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
1488 continue;
1489 if (wp_idx < wp_start) {
1490 wp_idx++;
1491 continue;
1492 }
1493 if_idx = 0;
1494
1495 mutex_lock(&rdev->devlist_mtx);
1496 list_for_each_entry(wdev, &rdev->netdev_list, list) {
1497 if (if_idx < if_start) {
1498 if_idx++;
1499 continue;
1500 }
1501 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1502 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1503 rdev, wdev->netdev) < 0) {
1504 mutex_unlock(&rdev->devlist_mtx);
1505 goto out;
1506 }
1507 if_idx++;
1508 }
1509 mutex_unlock(&rdev->devlist_mtx);
1510
1511 wp_idx++;
1512 }
1513 out:
1514 mutex_unlock(&cfg80211_mutex);
1515
1516 cb->args[0] = wp_idx;
1517 cb->args[1] = if_idx;
1518
1519 return skb->len;
1520 }
1521
1522 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1523 {
1524 struct sk_buff *msg;
1525 struct cfg80211_registered_device *dev = info->user_ptr[0];
1526 struct net_device *netdev = info->user_ptr[1];
1527
1528 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1529 if (!msg)
1530 return -ENOMEM;
1531
1532 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1533 dev, netdev) < 0) {
1534 nlmsg_free(msg);
1535 return -ENOBUFS;
1536 }
1537
1538 return genlmsg_reply(msg, info);
1539 }
1540
1541 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1542 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1543 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1544 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1545 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1546 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1547 };
1548
1549 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1550 {
1551 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1552 int flag;
1553
1554 *mntrflags = 0;
1555
1556 if (!nla)
1557 return -EINVAL;
1558
1559 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1560 nla, mntr_flags_policy))
1561 return -EINVAL;
1562
1563 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1564 if (flags[flag])
1565 *mntrflags |= (1<<flag);
1566
1567 return 0;
1568 }
1569
1570 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
1571 struct net_device *netdev, u8 use_4addr,
1572 enum nl80211_iftype iftype)
1573 {
1574 if (!use_4addr) {
1575 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
1576 return -EBUSY;
1577 return 0;
1578 }
1579
1580 switch (iftype) {
1581 case NL80211_IFTYPE_AP_VLAN:
1582 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1583 return 0;
1584 break;
1585 case NL80211_IFTYPE_STATION:
1586 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1587 return 0;
1588 break;
1589 default:
1590 break;
1591 }
1592
1593 return -EOPNOTSUPP;
1594 }
1595
1596 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1597 {
1598 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1599 struct vif_params params;
1600 int err;
1601 enum nl80211_iftype otype, ntype;
1602 struct net_device *dev = info->user_ptr[1];
1603 u32 _flags, *flags = NULL;
1604 bool change = false;
1605
1606 memset(&params, 0, sizeof(params));
1607
1608 otype = ntype = dev->ieee80211_ptr->iftype;
1609
1610 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1611 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1612 if (otype != ntype)
1613 change = true;
1614 if (ntype > NL80211_IFTYPE_MAX)
1615 return -EINVAL;
1616 }
1617
1618 if (info->attrs[NL80211_ATTR_MESH_ID]) {
1619 struct wireless_dev *wdev = dev->ieee80211_ptr;
1620
1621 if (ntype != NL80211_IFTYPE_MESH_POINT)
1622 return -EINVAL;
1623 if (netif_running(dev))
1624 return -EBUSY;
1625
1626 wdev_lock(wdev);
1627 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1628 IEEE80211_MAX_MESH_ID_LEN);
1629 wdev->mesh_id_up_len =
1630 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1631 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1632 wdev->mesh_id_up_len);
1633 wdev_unlock(wdev);
1634 }
1635
1636 if (info->attrs[NL80211_ATTR_4ADDR]) {
1637 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1638 change = true;
1639 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1640 if (err)
1641 return err;
1642 } else {
1643 params.use_4addr = -1;
1644 }
1645
1646 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1647 if (ntype != NL80211_IFTYPE_MONITOR)
1648 return -EINVAL;
1649 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1650 &_flags);
1651 if (err)
1652 return err;
1653
1654 flags = &_flags;
1655 change = true;
1656 }
1657
1658 if (change)
1659 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1660 else
1661 err = 0;
1662
1663 if (!err && params.use_4addr != -1)
1664 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1665
1666 return err;
1667 }
1668
1669 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1670 {
1671 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1672 struct vif_params params;
1673 struct net_device *dev;
1674 int err;
1675 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1676 u32 flags;
1677
1678 memset(&params, 0, sizeof(params));
1679
1680 if (!info->attrs[NL80211_ATTR_IFNAME])
1681 return -EINVAL;
1682
1683 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1684 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1685 if (type > NL80211_IFTYPE_MAX)
1686 return -EINVAL;
1687 }
1688
1689 if (!rdev->ops->add_virtual_intf ||
1690 !(rdev->wiphy.interface_modes & (1 << type)))
1691 return -EOPNOTSUPP;
1692
1693 if (info->attrs[NL80211_ATTR_4ADDR]) {
1694 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1695 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1696 if (err)
1697 return err;
1698 }
1699
1700 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1701 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1702 &flags);
1703 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
1704 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1705 type, err ? NULL : &flags, &params);
1706 if (IS_ERR(dev))
1707 return PTR_ERR(dev);
1708
1709 if (type == NL80211_IFTYPE_MESH_POINT &&
1710 info->attrs[NL80211_ATTR_MESH_ID]) {
1711 struct wireless_dev *wdev = dev->ieee80211_ptr;
1712
1713 wdev_lock(wdev);
1714 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1715 IEEE80211_MAX_MESH_ID_LEN);
1716 wdev->mesh_id_up_len =
1717 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1718 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1719 wdev->mesh_id_up_len);
1720 wdev_unlock(wdev);
1721 }
1722
1723 return 0;
1724 }
1725
1726 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1727 {
1728 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1729 struct net_device *dev = info->user_ptr[1];
1730
1731 if (!rdev->ops->del_virtual_intf)
1732 return -EOPNOTSUPP;
1733
1734 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1735 }
1736
1737 struct get_key_cookie {
1738 struct sk_buff *msg;
1739 int error;
1740 int idx;
1741 };
1742
1743 static void get_key_callback(void *c, struct key_params *params)
1744 {
1745 struct nlattr *key;
1746 struct get_key_cookie *cookie = c;
1747
1748 if (params->key)
1749 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1750 params->key_len, params->key);
1751
1752 if (params->seq)
1753 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1754 params->seq_len, params->seq);
1755
1756 if (params->cipher)
1757 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1758 params->cipher);
1759
1760 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1761 if (!key)
1762 goto nla_put_failure;
1763
1764 if (params->key)
1765 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1766 params->key_len, params->key);
1767
1768 if (params->seq)
1769 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1770 params->seq_len, params->seq);
1771
1772 if (params->cipher)
1773 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1774 params->cipher);
1775
1776 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1777
1778 nla_nest_end(cookie->msg, key);
1779
1780 return;
1781 nla_put_failure:
1782 cookie->error = 1;
1783 }
1784
1785 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1786 {
1787 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1788 int err;
1789 struct net_device *dev = info->user_ptr[1];
1790 u8 key_idx = 0;
1791 const u8 *mac_addr = NULL;
1792 bool pairwise;
1793 struct get_key_cookie cookie = {
1794 .error = 0,
1795 };
1796 void *hdr;
1797 struct sk_buff *msg;
1798
1799 if (info->attrs[NL80211_ATTR_KEY_IDX])
1800 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1801
1802 if (key_idx > 5)
1803 return -EINVAL;
1804
1805 if (info->attrs[NL80211_ATTR_MAC])
1806 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1807
1808 pairwise = !!mac_addr;
1809 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1810 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1811 if (kt >= NUM_NL80211_KEYTYPES)
1812 return -EINVAL;
1813 if (kt != NL80211_KEYTYPE_GROUP &&
1814 kt != NL80211_KEYTYPE_PAIRWISE)
1815 return -EINVAL;
1816 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1817 }
1818
1819 if (!rdev->ops->get_key)
1820 return -EOPNOTSUPP;
1821
1822 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1823 if (!msg)
1824 return -ENOMEM;
1825
1826 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1827 NL80211_CMD_NEW_KEY);
1828 if (IS_ERR(hdr))
1829 return PTR_ERR(hdr);
1830
1831 cookie.msg = msg;
1832 cookie.idx = key_idx;
1833
1834 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1835 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1836 if (mac_addr)
1837 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1838
1839 if (pairwise && mac_addr &&
1840 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1841 return -ENOENT;
1842
1843 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1844 mac_addr, &cookie, get_key_callback);
1845
1846 if (err)
1847 goto free_msg;
1848
1849 if (cookie.error)
1850 goto nla_put_failure;
1851
1852 genlmsg_end(msg, hdr);
1853 return genlmsg_reply(msg, info);
1854
1855 nla_put_failure:
1856 err = -ENOBUFS;
1857 free_msg:
1858 nlmsg_free(msg);
1859 return err;
1860 }
1861
1862 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1863 {
1864 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1865 struct key_parse key;
1866 int err;
1867 struct net_device *dev = info->user_ptr[1];
1868
1869 err = nl80211_parse_key(info, &key);
1870 if (err)
1871 return err;
1872
1873 if (key.idx < 0)
1874 return -EINVAL;
1875
1876 /* only support setting default key */
1877 if (!key.def && !key.defmgmt)
1878 return -EINVAL;
1879
1880 wdev_lock(dev->ieee80211_ptr);
1881
1882 if (key.def) {
1883 if (!rdev->ops->set_default_key) {
1884 err = -EOPNOTSUPP;
1885 goto out;
1886 }
1887
1888 err = nl80211_key_allowed(dev->ieee80211_ptr);
1889 if (err)
1890 goto out;
1891
1892 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1893 key.def_uni, key.def_multi);
1894
1895 if (err)
1896 goto out;
1897
1898 #ifdef CONFIG_CFG80211_WEXT
1899 dev->ieee80211_ptr->wext.default_key = key.idx;
1900 #endif
1901 } else {
1902 if (key.def_uni || !key.def_multi) {
1903 err = -EINVAL;
1904 goto out;
1905 }
1906
1907 if (!rdev->ops->set_default_mgmt_key) {
1908 err = -EOPNOTSUPP;
1909 goto out;
1910 }
1911
1912 err = nl80211_key_allowed(dev->ieee80211_ptr);
1913 if (err)
1914 goto out;
1915
1916 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1917 dev, key.idx);
1918 if (err)
1919 goto out;
1920
1921 #ifdef CONFIG_CFG80211_WEXT
1922 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1923 #endif
1924 }
1925
1926 out:
1927 wdev_unlock(dev->ieee80211_ptr);
1928
1929 return err;
1930 }
1931
1932 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1933 {
1934 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1935 int err;
1936 struct net_device *dev = info->user_ptr[1];
1937 struct key_parse key;
1938 const u8 *mac_addr = NULL;
1939
1940 err = nl80211_parse_key(info, &key);
1941 if (err)
1942 return err;
1943
1944 if (!key.p.key)
1945 return -EINVAL;
1946
1947 if (info->attrs[NL80211_ATTR_MAC])
1948 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1949
1950 if (key.type == -1) {
1951 if (mac_addr)
1952 key.type = NL80211_KEYTYPE_PAIRWISE;
1953 else
1954 key.type = NL80211_KEYTYPE_GROUP;
1955 }
1956
1957 /* for now */
1958 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1959 key.type != NL80211_KEYTYPE_GROUP)
1960 return -EINVAL;
1961
1962 if (!rdev->ops->add_key)
1963 return -EOPNOTSUPP;
1964
1965 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1966 key.type == NL80211_KEYTYPE_PAIRWISE,
1967 mac_addr))
1968 return -EINVAL;
1969
1970 wdev_lock(dev->ieee80211_ptr);
1971 err = nl80211_key_allowed(dev->ieee80211_ptr);
1972 if (!err)
1973 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1974 key.type == NL80211_KEYTYPE_PAIRWISE,
1975 mac_addr, &key.p);
1976 wdev_unlock(dev->ieee80211_ptr);
1977
1978 return err;
1979 }
1980
1981 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1982 {
1983 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1984 int err;
1985 struct net_device *dev = info->user_ptr[1];
1986 u8 *mac_addr = NULL;
1987 struct key_parse key;
1988
1989 err = nl80211_parse_key(info, &key);
1990 if (err)
1991 return err;
1992
1993 if (info->attrs[NL80211_ATTR_MAC])
1994 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1995
1996 if (key.type == -1) {
1997 if (mac_addr)
1998 key.type = NL80211_KEYTYPE_PAIRWISE;
1999 else
2000 key.type = NL80211_KEYTYPE_GROUP;
2001 }
2002
2003 /* for now */
2004 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2005 key.type != NL80211_KEYTYPE_GROUP)
2006 return -EINVAL;
2007
2008 if (!rdev->ops->del_key)
2009 return -EOPNOTSUPP;
2010
2011 wdev_lock(dev->ieee80211_ptr);
2012 err = nl80211_key_allowed(dev->ieee80211_ptr);
2013
2014 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2015 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2016 err = -ENOENT;
2017
2018 if (!err)
2019 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2020 key.type == NL80211_KEYTYPE_PAIRWISE,
2021 mac_addr);
2022
2023 #ifdef CONFIG_CFG80211_WEXT
2024 if (!err) {
2025 if (key.idx == dev->ieee80211_ptr->wext.default_key)
2026 dev->ieee80211_ptr->wext.default_key = -1;
2027 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
2028 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2029 }
2030 #endif
2031 wdev_unlock(dev->ieee80211_ptr);
2032
2033 return err;
2034 }
2035
2036 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
2037 {
2038 int (*call)(struct wiphy *wiphy, struct net_device *dev,
2039 struct beacon_parameters *info);
2040 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2041 struct net_device *dev = info->user_ptr[1];
2042 struct wireless_dev *wdev = dev->ieee80211_ptr;
2043 struct beacon_parameters params;
2044 int haveinfo = 0, err;
2045
2046 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2047 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2048 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2049 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
2050 return -EINVAL;
2051
2052 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2053 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2054 return -EOPNOTSUPP;
2055
2056 memset(&params, 0, sizeof(params));
2057
2058 switch (info->genlhdr->cmd) {
2059 case NL80211_CMD_NEW_BEACON:
2060 /* these are required for NEW_BEACON */
2061 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2062 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2063 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2064 return -EINVAL;
2065
2066 params.interval =
2067 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2068 params.dtim_period =
2069 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2070
2071 err = cfg80211_validate_beacon_int(rdev, params.interval);
2072 if (err)
2073 return err;
2074
2075 /*
2076 * In theory, some of these attributes could be required for
2077 * NEW_BEACON, but since they were not used when the command was
2078 * originally added, keep them optional for old user space
2079 * programs to work with drivers that do not need the additional
2080 * information.
2081 */
2082 if (info->attrs[NL80211_ATTR_SSID]) {
2083 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2084 params.ssid_len =
2085 nla_len(info->attrs[NL80211_ATTR_SSID]);
2086 if (params.ssid_len == 0 ||
2087 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2088 return -EINVAL;
2089 }
2090
2091 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2092 params.hidden_ssid = nla_get_u32(
2093 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2094 if (params.hidden_ssid !=
2095 NL80211_HIDDEN_SSID_NOT_IN_USE &&
2096 params.hidden_ssid !=
2097 NL80211_HIDDEN_SSID_ZERO_LEN &&
2098 params.hidden_ssid !=
2099 NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2100 return -EINVAL;
2101 }
2102
2103 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2104
2105 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2106 params.auth_type = nla_get_u32(
2107 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2108 if (!nl80211_valid_auth_type(params.auth_type))
2109 return -EINVAL;
2110 } else
2111 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2112
2113 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2114 NL80211_MAX_NR_CIPHER_SUITES);
2115 if (err)
2116 return err;
2117
2118 call = rdev->ops->add_beacon;
2119 break;
2120 case NL80211_CMD_SET_BEACON:
2121 call = rdev->ops->set_beacon;
2122 break;
2123 default:
2124 WARN_ON(1);
2125 return -EOPNOTSUPP;
2126 }
2127
2128 if (!call)
2129 return -EOPNOTSUPP;
2130
2131 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
2132 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2133 params.head_len =
2134 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2135 haveinfo = 1;
2136 }
2137
2138 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
2139 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2140 params.tail_len =
2141 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2142 haveinfo = 1;
2143 }
2144
2145 if (!haveinfo)
2146 return -EINVAL;
2147
2148 if (info->attrs[NL80211_ATTR_IE]) {
2149 params.beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2150 params.beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2151 }
2152
2153 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
2154 params.proberesp_ies =
2155 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2156 params.proberesp_ies_len =
2157 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2158 }
2159
2160 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
2161 params.assocresp_ies =
2162 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2163 params.assocresp_ies_len =
2164 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2165 }
2166
2167 err = call(&rdev->wiphy, dev, &params);
2168 if (!err && params.interval)
2169 wdev->beacon_interval = params.interval;
2170 return err;
2171 }
2172
2173 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
2174 {
2175 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2176 struct net_device *dev = info->user_ptr[1];
2177 struct wireless_dev *wdev = dev->ieee80211_ptr;
2178 int err;
2179
2180 if (!rdev->ops->del_beacon)
2181 return -EOPNOTSUPP;
2182
2183 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2184 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2185 return -EOPNOTSUPP;
2186
2187 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
2188 if (!err)
2189 wdev->beacon_interval = 0;
2190 return err;
2191 }
2192
2193 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2194 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2195 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2196 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
2197 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
2198 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
2199 };
2200
2201 static int parse_station_flags(struct genl_info *info,
2202 struct station_parameters *params)
2203 {
2204 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
2205 struct nlattr *nla;
2206 int flag;
2207
2208 /*
2209 * Try parsing the new attribute first so userspace
2210 * can specify both for older kernels.
2211 */
2212 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2213 if (nla) {
2214 struct nl80211_sta_flag_update *sta_flags;
2215
2216 sta_flags = nla_data(nla);
2217 params->sta_flags_mask = sta_flags->mask;
2218 params->sta_flags_set = sta_flags->set;
2219 if ((params->sta_flags_mask |
2220 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2221 return -EINVAL;
2222 return 0;
2223 }
2224
2225 /* if present, parse the old attribute */
2226
2227 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
2228 if (!nla)
2229 return 0;
2230
2231 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2232 nla, sta_flags_policy))
2233 return -EINVAL;
2234
2235 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
2236 params->sta_flags_mask &= ~1;
2237
2238 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2239 if (flags[flag])
2240 params->sta_flags_set |= (1<<flag);
2241
2242 return 0;
2243 }
2244
2245 static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2246 int attr)
2247 {
2248 struct nlattr *rate;
2249 u16 bitrate;
2250
2251 rate = nla_nest_start(msg, attr);
2252 if (!rate)
2253 goto nla_put_failure;
2254
2255 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2256 bitrate = cfg80211_calculate_bitrate(info);
2257 if (bitrate > 0)
2258 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2259
2260 if (info->flags & RATE_INFO_FLAGS_MCS)
2261 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2262 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2263 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2264 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2265 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2266
2267 nla_nest_end(msg, rate);
2268 return true;
2269
2270 nla_put_failure:
2271 return false;
2272 }
2273
2274 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2275 int flags, struct net_device *dev,
2276 const u8 *mac_addr, struct station_info *sinfo)
2277 {
2278 void *hdr;
2279 struct nlattr *sinfoattr, *bss_param;
2280
2281 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2282 if (!hdr)
2283 return -1;
2284
2285 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2286 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2287
2288 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2289
2290 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2291 if (!sinfoattr)
2292 goto nla_put_failure;
2293 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2294 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2295 sinfo->connected_time);
2296 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2297 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2298 sinfo->inactive_time);
2299 if (sinfo->filled & STATION_INFO_RX_BYTES)
2300 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2301 sinfo->rx_bytes);
2302 if (sinfo->filled & STATION_INFO_TX_BYTES)
2303 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2304 sinfo->tx_bytes);
2305 if (sinfo->filled & STATION_INFO_LLID)
2306 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2307 sinfo->llid);
2308 if (sinfo->filled & STATION_INFO_PLID)
2309 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2310 sinfo->plid);
2311 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2312 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2313 sinfo->plink_state);
2314 if (sinfo->filled & STATION_INFO_SIGNAL)
2315 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2316 sinfo->signal);
2317 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2318 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2319 sinfo->signal_avg);
2320 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
2321 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2322 NL80211_STA_INFO_TX_BITRATE))
2323 goto nla_put_failure;
2324 }
2325 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2326 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2327 NL80211_STA_INFO_RX_BITRATE))
2328 goto nla_put_failure;
2329 }
2330 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2331 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2332 sinfo->rx_packets);
2333 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2334 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2335 sinfo->tx_packets);
2336 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2337 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2338 sinfo->tx_retries);
2339 if (sinfo->filled & STATION_INFO_TX_FAILED)
2340 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2341 sinfo->tx_failed);
2342 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2343 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2344 if (!bss_param)
2345 goto nla_put_failure;
2346
2347 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2348 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2349 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2350 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2351 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2352 NLA_PUT_FLAG(msg,
2353 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2354 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2355 sinfo->bss_param.dtim_period);
2356 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2357 sinfo->bss_param.beacon_interval);
2358
2359 nla_nest_end(msg, bss_param);
2360 }
2361 if (sinfo->filled & STATION_INFO_STA_FLAGS)
2362 NLA_PUT(msg, NL80211_STA_INFO_STA_FLAGS,
2363 sizeof(struct nl80211_sta_flag_update),
2364 &sinfo->sta_flags);
2365 nla_nest_end(msg, sinfoattr);
2366
2367 if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
2368 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2369 sinfo->assoc_req_ies);
2370
2371 return genlmsg_end(msg, hdr);
2372
2373 nla_put_failure:
2374 genlmsg_cancel(msg, hdr);
2375 return -EMSGSIZE;
2376 }
2377
2378 static int nl80211_dump_station(struct sk_buff *skb,
2379 struct netlink_callback *cb)
2380 {
2381 struct station_info sinfo;
2382 struct cfg80211_registered_device *dev;
2383 struct net_device *netdev;
2384 u8 mac_addr[ETH_ALEN];
2385 int sta_idx = cb->args[1];
2386 int err;
2387
2388 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2389 if (err)
2390 return err;
2391
2392 if (!dev->ops->dump_station) {
2393 err = -EOPNOTSUPP;
2394 goto out_err;
2395 }
2396
2397 while (1) {
2398 memset(&sinfo, 0, sizeof(sinfo));
2399 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2400 mac_addr, &sinfo);
2401 if (err == -ENOENT)
2402 break;
2403 if (err)
2404 goto out_err;
2405
2406 if (nl80211_send_station(skb,
2407 NETLINK_CB(cb->skb).pid,
2408 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2409 netdev, mac_addr,
2410 &sinfo) < 0)
2411 goto out;
2412
2413 sta_idx++;
2414 }
2415
2416
2417 out:
2418 cb->args[1] = sta_idx;
2419 err = skb->len;
2420 out_err:
2421 nl80211_finish_netdev_dump(dev);
2422
2423 return err;
2424 }
2425
2426 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2427 {
2428 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2429 struct net_device *dev = info->user_ptr[1];
2430 struct station_info sinfo;
2431 struct sk_buff *msg;
2432 u8 *mac_addr = NULL;
2433 int err;
2434
2435 memset(&sinfo, 0, sizeof(sinfo));
2436
2437 if (!info->attrs[NL80211_ATTR_MAC])
2438 return -EINVAL;
2439
2440 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2441
2442 if (!rdev->ops->get_station)
2443 return -EOPNOTSUPP;
2444
2445 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2446 if (err)
2447 return err;
2448
2449 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2450 if (!msg)
2451 return -ENOMEM;
2452
2453 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2454 dev, mac_addr, &sinfo) < 0) {
2455 nlmsg_free(msg);
2456 return -ENOBUFS;
2457 }
2458
2459 return genlmsg_reply(msg, info);
2460 }
2461
2462 /*
2463 * Get vlan interface making sure it is running and on the right wiphy.
2464 */
2465 static int get_vlan(struct genl_info *info,
2466 struct cfg80211_registered_device *rdev,
2467 struct net_device **vlan)
2468 {
2469 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
2470 *vlan = NULL;
2471
2472 if (vlanattr) {
2473 *vlan = dev_get_by_index(genl_info_net(info),
2474 nla_get_u32(vlanattr));
2475 if (!*vlan)
2476 return -ENODEV;
2477 if (!(*vlan)->ieee80211_ptr)
2478 return -EINVAL;
2479 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2480 return -EINVAL;
2481 if (!netif_running(*vlan))
2482 return -ENETDOWN;
2483 }
2484 return 0;
2485 }
2486
2487 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2488 {
2489 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2490 int err;
2491 struct net_device *dev = info->user_ptr[1];
2492 struct station_parameters params;
2493 u8 *mac_addr = NULL;
2494
2495 memset(&params, 0, sizeof(params));
2496
2497 params.listen_interval = -1;
2498 params.plink_state = -1;
2499
2500 if (info->attrs[NL80211_ATTR_STA_AID])
2501 return -EINVAL;
2502
2503 if (!info->attrs[NL80211_ATTR_MAC])
2504 return -EINVAL;
2505
2506 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2507
2508 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2509 params.supported_rates =
2510 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2511 params.supported_rates_len =
2512 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2513 }
2514
2515 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2516 params.listen_interval =
2517 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2518
2519 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2520 params.ht_capa =
2521 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2522
2523 if (parse_station_flags(info, &params))
2524 return -EINVAL;
2525
2526 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2527 params.plink_action =
2528 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2529
2530 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2531 params.plink_state =
2532 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2533
2534 err = get_vlan(info, rdev, &params.vlan);
2535 if (err)
2536 goto out;
2537
2538 /* validate settings */
2539 err = 0;
2540
2541 switch (dev->ieee80211_ptr->iftype) {
2542 case NL80211_IFTYPE_AP:
2543 case NL80211_IFTYPE_AP_VLAN:
2544 case NL80211_IFTYPE_P2P_GO:
2545 /* disallow mesh-specific things */
2546 if (params.plink_action)
2547 err = -EINVAL;
2548 break;
2549 case NL80211_IFTYPE_P2P_CLIENT:
2550 case NL80211_IFTYPE_STATION:
2551 /* disallow things sta doesn't support */
2552 if (params.plink_action)
2553 err = -EINVAL;
2554 if (params.vlan)
2555 err = -EINVAL;
2556 if (params.supported_rates &&
2557 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
2558 err = -EINVAL;
2559 if (params.ht_capa)
2560 err = -EINVAL;
2561 if (params.listen_interval >= 0)
2562 err = -EINVAL;
2563 if (params.sta_flags_mask &
2564 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2565 BIT(NL80211_STA_FLAG_TDLS_PEER)))
2566 err = -EINVAL;
2567 /* can't change the TDLS bit */
2568 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
2569 (params.sta_flags_mask & BIT(NL80211_STA_FLAG_TDLS_PEER)))
2570 err = -EINVAL;
2571 break;
2572 case NL80211_IFTYPE_MESH_POINT:
2573 /* disallow things mesh doesn't support */
2574 if (params.vlan)
2575 err = -EINVAL;
2576 if (params.ht_capa)
2577 err = -EINVAL;
2578 if (params.listen_interval >= 0)
2579 err = -EINVAL;
2580 if (params.sta_flags_mask &
2581 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2582 BIT(NL80211_STA_FLAG_MFP) |
2583 BIT(NL80211_STA_FLAG_AUTHORIZED)))
2584 err = -EINVAL;
2585 break;
2586 default:
2587 err = -EINVAL;
2588 }
2589
2590 if (err)
2591 goto out;
2592
2593 if (!rdev->ops->change_station) {
2594 err = -EOPNOTSUPP;
2595 goto out;
2596 }
2597
2598 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
2599
2600 out:
2601 if (params.vlan)
2602 dev_put(params.vlan);
2603
2604 return err;
2605 }
2606
2607 static struct nla_policy
2608 nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2609 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2610 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2611 };
2612
2613 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2614 {
2615 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2616 int err;
2617 struct net_device *dev = info->user_ptr[1];
2618 struct station_parameters params;
2619 u8 *mac_addr = NULL;
2620
2621 memset(&params, 0, sizeof(params));
2622
2623 if (!info->attrs[NL80211_ATTR_MAC])
2624 return -EINVAL;
2625
2626 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2627 return -EINVAL;
2628
2629 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2630 return -EINVAL;
2631
2632 if (!info->attrs[NL80211_ATTR_STA_AID])
2633 return -EINVAL;
2634
2635 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2636 params.supported_rates =
2637 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2638 params.supported_rates_len =
2639 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2640 params.listen_interval =
2641 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2642
2643 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2644 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2645 return -EINVAL;
2646
2647 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2648 params.ht_capa =
2649 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2650
2651 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2652 params.plink_action =
2653 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2654
2655 if (parse_station_flags(info, &params))
2656 return -EINVAL;
2657
2658 /* parse WME attributes if sta is WME capable */
2659 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2660 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
2661 info->attrs[NL80211_ATTR_STA_WME]) {
2662 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2663 struct nlattr *nla;
2664
2665 nla = info->attrs[NL80211_ATTR_STA_WME];
2666 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2667 nl80211_sta_wme_policy);
2668 if (err)
2669 return err;
2670
2671 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2672 params.uapsd_queues =
2673 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
2674 if (params.uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2675 return -EINVAL;
2676
2677 if (tb[NL80211_STA_WME_MAX_SP])
2678 params.max_sp =
2679 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
2680
2681 if (params.max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2682 return -EINVAL;
2683
2684 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
2685 }
2686
2687 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2688 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2689 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2690 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO &&
2691 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION)
2692 return -EINVAL;
2693
2694 /*
2695 * Only managed stations can add TDLS peers, and only when the
2696 * wiphy supports external TDLS setup.
2697 */
2698 if (dev->ieee80211_ptr->iftype == NL80211_IFTYPE_STATION &&
2699 !((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
2700 (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
2701 (rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)))
2702 return -EINVAL;
2703
2704 err = get_vlan(info, rdev, &params.vlan);
2705 if (err)
2706 goto out;
2707
2708 /* validate settings */
2709 err = 0;
2710
2711 if (!rdev->ops->add_station) {
2712 err = -EOPNOTSUPP;
2713 goto out;
2714 }
2715
2716 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2717
2718 out:
2719 if (params.vlan)
2720 dev_put(params.vlan);
2721 return err;
2722 }
2723
2724 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2725 {
2726 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2727 struct net_device *dev = info->user_ptr[1];
2728 u8 *mac_addr = NULL;
2729
2730 if (info->attrs[NL80211_ATTR_MAC])
2731 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2732
2733 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2734 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2735 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2736 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2737 return -EINVAL;
2738
2739 if (!rdev->ops->del_station)
2740 return -EOPNOTSUPP;
2741
2742 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2743 }
2744
2745 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2746 int flags, struct net_device *dev,
2747 u8 *dst, u8 *next_hop,
2748 struct mpath_info *pinfo)
2749 {
2750 void *hdr;
2751 struct nlattr *pinfoattr;
2752
2753 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2754 if (!hdr)
2755 return -1;
2756
2757 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2758 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2759 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2760
2761 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2762
2763 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2764 if (!pinfoattr)
2765 goto nla_put_failure;
2766 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2767 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2768 pinfo->frame_qlen);
2769 if (pinfo->filled & MPATH_INFO_SN)
2770 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2771 pinfo->sn);
2772 if (pinfo->filled & MPATH_INFO_METRIC)
2773 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2774 pinfo->metric);
2775 if (pinfo->filled & MPATH_INFO_EXPTIME)
2776 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2777 pinfo->exptime);
2778 if (pinfo->filled & MPATH_INFO_FLAGS)
2779 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2780 pinfo->flags);
2781 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2782 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2783 pinfo->discovery_timeout);
2784 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2785 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2786 pinfo->discovery_retries);
2787
2788 nla_nest_end(msg, pinfoattr);
2789
2790 return genlmsg_end(msg, hdr);
2791
2792 nla_put_failure:
2793 genlmsg_cancel(msg, hdr);
2794 return -EMSGSIZE;
2795 }
2796
2797 static int nl80211_dump_mpath(struct sk_buff *skb,
2798 struct netlink_callback *cb)
2799 {
2800 struct mpath_info pinfo;
2801 struct cfg80211_registered_device *dev;
2802 struct net_device *netdev;
2803 u8 dst[ETH_ALEN];
2804 u8 next_hop[ETH_ALEN];
2805 int path_idx = cb->args[1];
2806 int err;
2807
2808 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2809 if (err)
2810 return err;
2811
2812 if (!dev->ops->dump_mpath) {
2813 err = -EOPNOTSUPP;
2814 goto out_err;
2815 }
2816
2817 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2818 err = -EOPNOTSUPP;
2819 goto out_err;
2820 }
2821
2822 while (1) {
2823 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2824 dst, next_hop, &pinfo);
2825 if (err == -ENOENT)
2826 break;
2827 if (err)
2828 goto out_err;
2829
2830 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2831 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2832 netdev, dst, next_hop,
2833 &pinfo) < 0)
2834 goto out;
2835
2836 path_idx++;
2837 }
2838
2839
2840 out:
2841 cb->args[1] = path_idx;
2842 err = skb->len;
2843 out_err:
2844 nl80211_finish_netdev_dump(dev);
2845 return err;
2846 }
2847
2848 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2849 {
2850 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2851 int err;
2852 struct net_device *dev = info->user_ptr[1];
2853 struct mpath_info pinfo;
2854 struct sk_buff *msg;
2855 u8 *dst = NULL;
2856 u8 next_hop[ETH_ALEN];
2857
2858 memset(&pinfo, 0, sizeof(pinfo));
2859
2860 if (!info->attrs[NL80211_ATTR_MAC])
2861 return -EINVAL;
2862
2863 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2864
2865 if (!rdev->ops->get_mpath)
2866 return -EOPNOTSUPP;
2867
2868 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2869 return -EOPNOTSUPP;
2870
2871 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2872 if (err)
2873 return err;
2874
2875 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2876 if (!msg)
2877 return -ENOMEM;
2878
2879 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2880 dev, dst, next_hop, &pinfo) < 0) {
2881 nlmsg_free(msg);
2882 return -ENOBUFS;
2883 }
2884
2885 return genlmsg_reply(msg, info);
2886 }
2887
2888 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2889 {
2890 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2891 struct net_device *dev = info->user_ptr[1];
2892 u8 *dst = NULL;
2893 u8 *next_hop = NULL;
2894
2895 if (!info->attrs[NL80211_ATTR_MAC])
2896 return -EINVAL;
2897
2898 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2899 return -EINVAL;
2900
2901 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2902 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2903
2904 if (!rdev->ops->change_mpath)
2905 return -EOPNOTSUPP;
2906
2907 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2908 return -EOPNOTSUPP;
2909
2910 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2911 }
2912
2913 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2914 {
2915 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2916 struct net_device *dev = info->user_ptr[1];
2917 u8 *dst = NULL;
2918 u8 *next_hop = NULL;
2919
2920 if (!info->attrs[NL80211_ATTR_MAC])
2921 return -EINVAL;
2922
2923 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2924 return -EINVAL;
2925
2926 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2927 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2928
2929 if (!rdev->ops->add_mpath)
2930 return -EOPNOTSUPP;
2931
2932 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2933 return -EOPNOTSUPP;
2934
2935 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2936 }
2937
2938 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2939 {
2940 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2941 struct net_device *dev = info->user_ptr[1];
2942 u8 *dst = NULL;
2943
2944 if (info->attrs[NL80211_ATTR_MAC])
2945 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2946
2947 if (!rdev->ops->del_mpath)
2948 return -EOPNOTSUPP;
2949
2950 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2951 }
2952
2953 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2954 {
2955 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2956 struct net_device *dev = info->user_ptr[1];
2957 struct bss_parameters params;
2958
2959 memset(&params, 0, sizeof(params));
2960 /* default to not changing parameters */
2961 params.use_cts_prot = -1;
2962 params.use_short_preamble = -1;
2963 params.use_short_slot_time = -1;
2964 params.ap_isolate = -1;
2965 params.ht_opmode = -1;
2966
2967 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2968 params.use_cts_prot =
2969 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2970 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2971 params.use_short_preamble =
2972 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2973 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2974 params.use_short_slot_time =
2975 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2976 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2977 params.basic_rates =
2978 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2979 params.basic_rates_len =
2980 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2981 }
2982 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2983 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
2984 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2985 params.ht_opmode =
2986 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
2987
2988 if (!rdev->ops->change_bss)
2989 return -EOPNOTSUPP;
2990
2991 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2992 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2993 return -EOPNOTSUPP;
2994
2995 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2996 }
2997
2998 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2999 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3000 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3001 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3002 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3003 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3004 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3005 };
3006
3007 static int parse_reg_rule(struct nlattr *tb[],
3008 struct ieee80211_reg_rule *reg_rule)
3009 {
3010 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3011 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3012
3013 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3014 return -EINVAL;
3015 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3016 return -EINVAL;
3017 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3018 return -EINVAL;
3019 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3020 return -EINVAL;
3021 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3022 return -EINVAL;
3023
3024 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3025
3026 freq_range->start_freq_khz =
3027 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3028 freq_range->end_freq_khz =
3029 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3030 freq_range->max_bandwidth_khz =
3031 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3032
3033 power_rule->max_eirp =
3034 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3035
3036 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3037 power_rule->max_antenna_gain =
3038 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3039
3040 return 0;
3041 }
3042
3043 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3044 {
3045 int r;
3046 char *data = NULL;
3047
3048 /*
3049 * You should only get this when cfg80211 hasn't yet initialized
3050 * completely when built-in to the kernel right between the time
3051 * window between nl80211_init() and regulatory_init(), if that is
3052 * even possible.
3053 */
3054 mutex_lock(&cfg80211_mutex);
3055 if (unlikely(!cfg80211_regdomain)) {
3056 mutex_unlock(&cfg80211_mutex);
3057 return -EINPROGRESS;
3058 }
3059 mutex_unlock(&cfg80211_mutex);
3060
3061 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3062 return -EINVAL;
3063
3064 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3065
3066 r = regulatory_hint_user(data);
3067
3068 return r;
3069 }
3070
3071 static int nl80211_get_mesh_config(struct sk_buff *skb,
3072 struct genl_info *info)
3073 {
3074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3075 struct net_device *dev = info->user_ptr[1];
3076 struct wireless_dev *wdev = dev->ieee80211_ptr;
3077 struct mesh_config cur_params;
3078 int err = 0;
3079 void *hdr;
3080 struct nlattr *pinfoattr;
3081 struct sk_buff *msg;
3082
3083 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3084 return -EOPNOTSUPP;
3085
3086 if (!rdev->ops->get_mesh_config)
3087 return -EOPNOTSUPP;
3088
3089 wdev_lock(wdev);
3090 /* If not connected, get default parameters */
3091 if (!wdev->mesh_id_len)
3092 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3093 else
3094 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
3095 &cur_params);
3096 wdev_unlock(wdev);
3097
3098 if (err)
3099 return err;
3100
3101 /* Draw up a netlink message to send back */
3102 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3103 if (!msg)
3104 return -ENOMEM;
3105 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3106 NL80211_CMD_GET_MESH_CONFIG);
3107 if (!hdr)
3108 goto out;
3109 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
3110 if (!pinfoattr)
3111 goto nla_put_failure;
3112 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3113 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3114 cur_params.dot11MeshRetryTimeout);
3115 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3116 cur_params.dot11MeshConfirmTimeout);
3117 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3118 cur_params.dot11MeshHoldingTimeout);
3119 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3120 cur_params.dot11MeshMaxPeerLinks);
3121 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
3122 cur_params.dot11MeshMaxRetries);
3123 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
3124 cur_params.dot11MeshTTL);
3125 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3126 cur_params.element_ttl);
3127 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3128 cur_params.auto_open_plinks);
3129 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3130 cur_params.dot11MeshHWMPmaxPREQretries);
3131 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3132 cur_params.path_refresh_time);
3133 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3134 cur_params.min_discovery_timeout);
3135 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3136 cur_params.dot11MeshHWMPactivePathTimeout);
3137 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3138 cur_params.dot11MeshHWMPpreqMinInterval);
3139 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3140 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
3141 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3142 cur_params.dot11MeshHWMPRootMode);
3143 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3144 cur_params.dot11MeshHWMPRannInterval);
3145 NLA_PUT_U8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3146 cur_params.dot11MeshGateAnnouncementProtocol);
3147 nla_nest_end(msg, pinfoattr);
3148 genlmsg_end(msg, hdr);
3149 return genlmsg_reply(msg, info);
3150
3151 nla_put_failure:
3152 genlmsg_cancel(msg, hdr);
3153 out:
3154 nlmsg_free(msg);
3155 return -ENOBUFS;
3156 }
3157
3158 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
3159 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3160 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3161 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3162 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3163 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3164 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
3165 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
3166 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
3167
3168 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3169 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3170 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3171 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3172 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
3173 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
3174 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
3175 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
3176 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
3177 };
3178
3179 static const struct nla_policy
3180 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
3181 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3182 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
3183 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
3184 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
3185 .len = IEEE80211_MAX_DATA_LEN },
3186 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
3187 };
3188
3189 static int nl80211_parse_mesh_config(struct genl_info *info,
3190 struct mesh_config *cfg,
3191 u32 *mask_out)
3192 {
3193 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
3194 u32 mask = 0;
3195
3196 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3197 do {\
3198 if (table[attr_num]) {\
3199 cfg->param = nla_fn(table[attr_num]); \
3200 mask |= (1 << (attr_num - 1)); \
3201 } \
3202 } while (0);\
3203
3204
3205 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
3206 return -EINVAL;
3207 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
3208 info->attrs[NL80211_ATTR_MESH_CONFIG],
3209 nl80211_meshconf_params_policy))
3210 return -EINVAL;
3211
3212 /* This makes sure that there aren't more than 32 mesh config
3213 * parameters (otherwise our bitfield scheme would not work.) */
3214 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3215
3216 /* Fill in the params struct */
3217 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3218 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3219 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3220 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3221 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3222 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3223 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3224 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3225 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3226 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3227 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3228 mask, NL80211_MESHCONF_TTL, nla_get_u8);
3229 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3230 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
3231 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3232 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
3233 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3234 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3235 nla_get_u8);
3236 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3237 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3238 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3239 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3240 nla_get_u16);
3241 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3242 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3243 nla_get_u32);
3244 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3245 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3246 nla_get_u16);
3247 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3248 dot11MeshHWMPnetDiameterTraversalTime,
3249 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3250 nla_get_u16);
3251 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3252 dot11MeshHWMPRootMode, mask,
3253 NL80211_MESHCONF_HWMP_ROOTMODE,
3254 nla_get_u8);
3255 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3256 dot11MeshHWMPRannInterval, mask,
3257 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3258 nla_get_u16);
3259 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3260 dot11MeshGateAnnouncementProtocol, mask,
3261 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3262 nla_get_u8);
3263 if (mask_out)
3264 *mask_out = mask;
3265
3266 return 0;
3267
3268 #undef FILL_IN_MESH_PARAM_IF_SET
3269 }
3270
3271 static int nl80211_parse_mesh_setup(struct genl_info *info,
3272 struct mesh_setup *setup)
3273 {
3274 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3275
3276 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3277 return -EINVAL;
3278 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3279 info->attrs[NL80211_ATTR_MESH_SETUP],
3280 nl80211_mesh_setup_params_policy))
3281 return -EINVAL;
3282
3283 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3284 setup->path_sel_proto =
3285 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3286 IEEE80211_PATH_PROTOCOL_VENDOR :
3287 IEEE80211_PATH_PROTOCOL_HWMP;
3288
3289 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3290 setup->path_metric =
3291 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3292 IEEE80211_PATH_METRIC_VENDOR :
3293 IEEE80211_PATH_METRIC_AIRTIME;
3294
3295
3296 if (tb[NL80211_MESH_SETUP_IE]) {
3297 struct nlattr *ieattr =
3298 tb[NL80211_MESH_SETUP_IE];
3299 if (!is_valid_ie_attr(ieattr))
3300 return -EINVAL;
3301 setup->ie = nla_data(ieattr);
3302 setup->ie_len = nla_len(ieattr);
3303 }
3304 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3305 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
3306
3307 return 0;
3308 }
3309
3310 static int nl80211_update_mesh_config(struct sk_buff *skb,
3311 struct genl_info *info)
3312 {
3313 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3314 struct net_device *dev = info->user_ptr[1];
3315 struct wireless_dev *wdev = dev->ieee80211_ptr;
3316 struct mesh_config cfg;
3317 u32 mask;
3318 int err;
3319
3320 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3321 return -EOPNOTSUPP;
3322
3323 if (!rdev->ops->update_mesh_config)
3324 return -EOPNOTSUPP;
3325
3326 err = nl80211_parse_mesh_config(info, &cfg, &mask);
3327 if (err)
3328 return err;
3329
3330 wdev_lock(wdev);
3331 if (!wdev->mesh_id_len)
3332 err = -ENOLINK;
3333
3334 if (!err)
3335 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
3336 mask, &cfg);
3337
3338 wdev_unlock(wdev);
3339
3340 return err;
3341 }
3342
3343 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3344 {
3345 struct sk_buff *msg;
3346 void *hdr = NULL;
3347 struct nlattr *nl_reg_rules;
3348 unsigned int i;
3349 int err = -EINVAL;
3350
3351 mutex_lock(&cfg80211_mutex);
3352
3353 if (!cfg80211_regdomain)
3354 goto out;
3355
3356 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3357 if (!msg) {
3358 err = -ENOBUFS;
3359 goto out;
3360 }
3361
3362 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3363 NL80211_CMD_GET_REG);
3364 if (!hdr)
3365 goto put_failure;
3366
3367 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3368 cfg80211_regdomain->alpha2);
3369
3370 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3371 if (!nl_reg_rules)
3372 goto nla_put_failure;
3373
3374 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3375 struct nlattr *nl_reg_rule;
3376 const struct ieee80211_reg_rule *reg_rule;
3377 const struct ieee80211_freq_range *freq_range;
3378 const struct ieee80211_power_rule *power_rule;
3379
3380 reg_rule = &cfg80211_regdomain->reg_rules[i];
3381 freq_range = &reg_rule->freq_range;
3382 power_rule = &reg_rule->power_rule;
3383
3384 nl_reg_rule = nla_nest_start(msg, i);
3385 if (!nl_reg_rule)
3386 goto nla_put_failure;
3387
3388 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3389 reg_rule->flags);
3390 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3391 freq_range->start_freq_khz);
3392 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3393 freq_range->end_freq_khz);
3394 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3395 freq_range->max_bandwidth_khz);
3396 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3397 power_rule->max_antenna_gain);
3398 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3399 power_rule->max_eirp);
3400
3401 nla_nest_end(msg, nl_reg_rule);
3402 }
3403
3404 nla_nest_end(msg, nl_reg_rules);
3405
3406 genlmsg_end(msg, hdr);
3407 err = genlmsg_reply(msg, info);
3408 goto out;
3409
3410 nla_put_failure:
3411 genlmsg_cancel(msg, hdr);
3412 put_failure:
3413 nlmsg_free(msg);
3414 err = -EMSGSIZE;
3415 out:
3416 mutex_unlock(&cfg80211_mutex);
3417 return err;
3418 }
3419
3420 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3421 {
3422 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3423 struct nlattr *nl_reg_rule;
3424 char *alpha2 = NULL;
3425 int rem_reg_rules = 0, r = 0;
3426 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3427 struct ieee80211_regdomain *rd = NULL;
3428
3429 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3430 return -EINVAL;
3431
3432 if (!info->attrs[NL80211_ATTR_REG_RULES])
3433 return -EINVAL;
3434
3435 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3436
3437 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3438 rem_reg_rules) {
3439 num_rules++;
3440 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
3441 return -EINVAL;
3442 }
3443
3444 mutex_lock(&cfg80211_mutex);
3445
3446 if (!reg_is_valid_request(alpha2)) {
3447 r = -EINVAL;
3448 goto bad_reg;
3449 }
3450
3451 size_of_regd = sizeof(struct ieee80211_regdomain) +
3452 (num_rules * sizeof(struct ieee80211_reg_rule));
3453
3454 rd = kzalloc(size_of_regd, GFP_KERNEL);
3455 if (!rd) {
3456 r = -ENOMEM;
3457 goto bad_reg;
3458 }
3459
3460 rd->n_reg_rules = num_rules;
3461 rd->alpha2[0] = alpha2[0];
3462 rd->alpha2[1] = alpha2[1];
3463
3464 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3465 rem_reg_rules) {
3466 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3467 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3468 reg_rule_policy);
3469 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3470 if (r)
3471 goto bad_reg;
3472
3473 rule_idx++;
3474
3475 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3476 r = -EINVAL;
3477 goto bad_reg;
3478 }
3479 }
3480
3481 BUG_ON(rule_idx != num_rules);
3482
3483 r = set_regdom(rd);
3484
3485 mutex_unlock(&cfg80211_mutex);
3486
3487 return r;
3488
3489 bad_reg:
3490 mutex_unlock(&cfg80211_mutex);
3491 kfree(rd);
3492 return r;
3493 }
3494
3495 static int validate_scan_freqs(struct nlattr *freqs)
3496 {
3497 struct nlattr *attr1, *attr2;
3498 int n_channels = 0, tmp1, tmp2;
3499
3500 nla_for_each_nested(attr1, freqs, tmp1) {
3501 n_channels++;
3502 /*
3503 * Some hardware has a limited channel list for
3504 * scanning, and it is pretty much nonsensical
3505 * to scan for a channel twice, so disallow that
3506 * and don't require drivers to check that the
3507 * channel list they get isn't longer than what
3508 * they can scan, as long as they can scan all
3509 * the channels they registered at once.
3510 */
3511 nla_for_each_nested(attr2, freqs, tmp2)
3512 if (attr1 != attr2 &&
3513 nla_get_u32(attr1) == nla_get_u32(attr2))
3514 return 0;
3515 }
3516
3517 return n_channels;
3518 }
3519
3520 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3521 {
3522 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3523 struct net_device *dev = info->user_ptr[1];
3524 struct cfg80211_scan_request *request;
3525 struct nlattr *attr;
3526 struct wiphy *wiphy;
3527 int err, tmp, n_ssids = 0, n_channels, i;
3528 size_t ie_len;
3529
3530 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3531 return -EINVAL;
3532
3533 wiphy = &rdev->wiphy;
3534
3535 if (!rdev->ops->scan)
3536 return -EOPNOTSUPP;
3537
3538 if (rdev->scan_req)
3539 return -EBUSY;
3540
3541 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3542 n_channels = validate_scan_freqs(
3543 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3544 if (!n_channels)
3545 return -EINVAL;
3546 } else {
3547 enum ieee80211_band band;
3548 n_channels = 0;
3549
3550 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3551 if (wiphy->bands[band])
3552 n_channels += wiphy->bands[band]->n_channels;
3553 }
3554
3555 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3556 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3557 n_ssids++;
3558
3559 if (n_ssids > wiphy->max_scan_ssids)
3560 return -EINVAL;
3561
3562 if (info->attrs[NL80211_ATTR_IE])
3563 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3564 else
3565 ie_len = 0;
3566
3567 if (ie_len > wiphy->max_scan_ie_len)
3568 return -EINVAL;
3569
3570 request = kzalloc(sizeof(*request)
3571 + sizeof(*request->ssids) * n_ssids
3572 + sizeof(*request->channels) * n_channels
3573 + ie_len, GFP_KERNEL);
3574 if (!request)
3575 return -ENOMEM;
3576
3577 if (n_ssids)
3578 request->ssids = (void *)&request->channels[n_channels];
3579 request->n_ssids = n_ssids;
3580 if (ie_len) {
3581 if (request->ssids)
3582 request->ie = (void *)(request->ssids + n_ssids);
3583 else
3584 request->ie = (void *)(request->channels + n_channels);
3585 }
3586
3587 i = 0;
3588 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3589 /* user specified, bail out if channel not found */
3590 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3591 struct ieee80211_channel *chan;
3592
3593 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3594
3595 if (!chan) {
3596 err = -EINVAL;
3597 goto out_free;
3598 }
3599
3600 /* ignore disabled channels */
3601 if (chan->flags & IEEE80211_CHAN_DISABLED)
3602 continue;
3603
3604 request->channels[i] = chan;
3605 i++;
3606 }
3607 } else {
3608 enum ieee80211_band band;
3609
3610 /* all channels */
3611 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3612 int j;
3613 if (!wiphy->bands[band])
3614 continue;
3615 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3616 struct ieee80211_channel *chan;
3617
3618 chan = &wiphy->bands[band]->channels[j];
3619
3620 if (chan->flags & IEEE80211_CHAN_DISABLED)
3621 continue;
3622
3623 request->channels[i] = chan;
3624 i++;
3625 }
3626 }
3627 }
3628
3629 if (!i) {
3630 err = -EINVAL;
3631 goto out_free;
3632 }
3633
3634 request->n_channels = i;
3635
3636 i = 0;
3637 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3638 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3639 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
3640 err = -EINVAL;
3641 goto out_free;
3642 }
3643 request->ssids[i].ssid_len = nla_len(attr);
3644 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3645 i++;
3646 }
3647 }
3648
3649 if (info->attrs[NL80211_ATTR_IE]) {
3650 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3651 memcpy((void *)request->ie,
3652 nla_data(info->attrs[NL80211_ATTR_IE]),
3653 request->ie_len);
3654 }
3655
3656 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
3657 if (wiphy->bands[i])
3658 request->rates[i] =
3659 (1 << wiphy->bands[i]->n_bitrates) - 1;
3660
3661 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
3662 nla_for_each_nested(attr,
3663 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
3664 tmp) {
3665 enum ieee80211_band band = nla_type(attr);
3666
3667 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
3668 err = -EINVAL;
3669 goto out_free;
3670 }
3671 err = ieee80211_get_ratemask(wiphy->bands[band],
3672 nla_data(attr),
3673 nla_len(attr),
3674 &request->rates[band]);
3675 if (err)
3676 goto out_free;
3677 }
3678 }
3679
3680 request->no_cck =
3681 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
3682
3683 request->dev = dev;
3684 request->wiphy = &rdev->wiphy;
3685
3686 rdev->scan_req = request;
3687 err = rdev->ops->scan(&rdev->wiphy, dev, request);
3688
3689 if (!err) {
3690 nl80211_send_scan_start(rdev, dev);
3691 dev_hold(dev);
3692 } else {
3693 out_free:
3694 rdev->scan_req = NULL;
3695 kfree(request);
3696 }
3697
3698 return err;
3699 }
3700
3701 static int nl80211_start_sched_scan(struct sk_buff *skb,
3702 struct genl_info *info)
3703 {
3704 struct cfg80211_sched_scan_request *request;
3705 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3706 struct net_device *dev = info->user_ptr[1];
3707 struct nlattr *attr;
3708 struct wiphy *wiphy;
3709 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
3710 u32 interval;
3711 enum ieee80211_band band;
3712 size_t ie_len;
3713 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
3714
3715 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3716 !rdev->ops->sched_scan_start)
3717 return -EOPNOTSUPP;
3718
3719 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3720 return -EINVAL;
3721
3722 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3723 return -EINVAL;
3724
3725 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3726 if (interval == 0)
3727 return -EINVAL;
3728
3729 wiphy = &rdev->wiphy;
3730
3731 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3732 n_channels = validate_scan_freqs(
3733 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3734 if (!n_channels)
3735 return -EINVAL;
3736 } else {
3737 n_channels = 0;
3738
3739 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3740 if (wiphy->bands[band])
3741 n_channels += wiphy->bands[band]->n_channels;
3742 }
3743
3744 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3745 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3746 tmp)
3747 n_ssids++;
3748
3749 if (n_ssids > wiphy->max_sched_scan_ssids)
3750 return -EINVAL;
3751
3752 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
3753 nla_for_each_nested(attr,
3754 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3755 tmp)
3756 n_match_sets++;
3757
3758 if (n_match_sets > wiphy->max_match_sets)
3759 return -EINVAL;
3760
3761 if (info->attrs[NL80211_ATTR_IE])
3762 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3763 else
3764 ie_len = 0;
3765
3766 if (ie_len > wiphy->max_sched_scan_ie_len)
3767 return -EINVAL;
3768
3769 mutex_lock(&rdev->sched_scan_mtx);
3770
3771 if (rdev->sched_scan_req) {
3772 err = -EINPROGRESS;
3773 goto out;
3774 }
3775
3776 request = kzalloc(sizeof(*request)
3777 + sizeof(*request->ssids) * n_ssids
3778 + sizeof(*request->match_sets) * n_match_sets
3779 + sizeof(*request->channels) * n_channels
3780 + ie_len, GFP_KERNEL);
3781 if (!request) {
3782 err = -ENOMEM;
3783 goto out;
3784 }
3785
3786 if (n_ssids)
3787 request->ssids = (void *)&request->channels[n_channels];
3788 request->n_ssids = n_ssids;
3789 if (ie_len) {
3790 if (request->ssids)
3791 request->ie = (void *)(request->ssids + n_ssids);
3792 else
3793 request->ie = (void *)(request->channels + n_channels);
3794 }
3795
3796 if (n_match_sets) {
3797 if (request->ie)
3798 request->match_sets = (void *)(request->ie + ie_len);
3799 else if (request->ssids)
3800 request->match_sets =
3801 (void *)(request->ssids + n_ssids);
3802 else
3803 request->match_sets =
3804 (void *)(request->channels + n_channels);
3805 }
3806 request->n_match_sets = n_match_sets;
3807
3808 i = 0;
3809 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3810 /* user specified, bail out if channel not found */
3811 nla_for_each_nested(attr,
3812 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
3813 tmp) {
3814 struct ieee80211_channel *chan;
3815
3816 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3817
3818 if (!chan) {
3819 err = -EINVAL;
3820 goto out_free;
3821 }
3822
3823 /* ignore disabled channels */
3824 if (chan->flags & IEEE80211_CHAN_DISABLED)
3825 continue;
3826
3827 request->channels[i] = chan;
3828 i++;
3829 }
3830 } else {
3831 /* all channels */
3832 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3833 int j;
3834 if (!wiphy->bands[band])
3835 continue;
3836 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3837 struct ieee80211_channel *chan;
3838
3839 chan = &wiphy->bands[band]->channels[j];
3840
3841 if (chan->flags & IEEE80211_CHAN_DISABLED)
3842 continue;
3843
3844 request->channels[i] = chan;
3845 i++;
3846 }
3847 }
3848 }
3849
3850 if (!i) {
3851 err = -EINVAL;
3852 goto out_free;
3853 }
3854
3855 request->n_channels = i;
3856
3857 i = 0;
3858 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3859 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3860 tmp) {
3861 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
3862 err = -EINVAL;
3863 goto out_free;
3864 }
3865 request->ssids[i].ssid_len = nla_len(attr);
3866 memcpy(request->ssids[i].ssid, nla_data(attr),
3867 nla_len(attr));
3868 i++;
3869 }
3870 }
3871
3872 i = 0;
3873 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
3874 nla_for_each_nested(attr,
3875 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3876 tmp) {
3877 struct nlattr *ssid;
3878
3879 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
3880 nla_data(attr), nla_len(attr),
3881 nl80211_match_policy);
3882 ssid = tb[NL80211_ATTR_SCHED_SCAN_MATCH_SSID];
3883 if (ssid) {
3884 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
3885 err = -EINVAL;
3886 goto out_free;
3887 }
3888 memcpy(request->match_sets[i].ssid.ssid,
3889 nla_data(ssid), nla_len(ssid));
3890 request->match_sets[i].ssid.ssid_len =
3891 nla_len(ssid);
3892 }
3893 i++;
3894 }
3895 }
3896
3897 if (info->attrs[NL80211_ATTR_IE]) {
3898 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3899 memcpy((void *)request->ie,
3900 nla_data(info->attrs[NL80211_ATTR_IE]),
3901 request->ie_len);
3902 }
3903
3904 request->dev = dev;
3905 request->wiphy = &rdev->wiphy;
3906 request->interval = interval;
3907
3908 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
3909 if (!err) {
3910 rdev->sched_scan_req = request;
3911 nl80211_send_sched_scan(rdev, dev,
3912 NL80211_CMD_START_SCHED_SCAN);
3913 goto out;
3914 }
3915
3916 out_free:
3917 kfree(request);
3918 out:
3919 mutex_unlock(&rdev->sched_scan_mtx);
3920 return err;
3921 }
3922
3923 static int nl80211_stop_sched_scan(struct sk_buff *skb,
3924 struct genl_info *info)
3925 {
3926 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3927 int err;
3928
3929 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3930 !rdev->ops->sched_scan_stop)
3931 return -EOPNOTSUPP;
3932
3933 mutex_lock(&rdev->sched_scan_mtx);
3934 err = __cfg80211_stop_sched_scan(rdev, false);
3935 mutex_unlock(&rdev->sched_scan_mtx);
3936
3937 return err;
3938 }
3939
3940 static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
3941 u32 seq, int flags,
3942 struct cfg80211_registered_device *rdev,
3943 struct wireless_dev *wdev,
3944 struct cfg80211_internal_bss *intbss)
3945 {
3946 struct cfg80211_bss *res = &intbss->pub;
3947 void *hdr;
3948 struct nlattr *bss;
3949 int i;
3950
3951 ASSERT_WDEV_LOCK(wdev);
3952
3953 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
3954 NL80211_CMD_NEW_SCAN_RESULTS);
3955 if (!hdr)
3956 return -1;
3957
3958 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
3959
3960 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3961 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3962
3963 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3964 if (!bss)
3965 goto nla_put_failure;
3966 if (!is_zero_ether_addr(res->bssid))
3967 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3968 if (res->information_elements && res->len_information_elements)
3969 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3970 res->len_information_elements,
3971 res->information_elements);
3972 if (res->beacon_ies && res->len_beacon_ies &&
3973 res->beacon_ies != res->information_elements)
3974 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3975 res->len_beacon_ies, res->beacon_ies);
3976 if (res->tsf)
3977 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3978 if (res->beacon_interval)
3979 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3980 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3981 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3982 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3983 jiffies_to_msecs(jiffies - intbss->ts));
3984
3985 switch (rdev->wiphy.signal_type) {
3986 case CFG80211_SIGNAL_TYPE_MBM:
3987 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3988 break;
3989 case CFG80211_SIGNAL_TYPE_UNSPEC:
3990 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3991 break;
3992 default:
3993 break;
3994 }
3995
3996 switch (wdev->iftype) {
3997 case NL80211_IFTYPE_P2P_CLIENT:
3998 case NL80211_IFTYPE_STATION:
3999 if (intbss == wdev->current_bss)
4000 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4001 NL80211_BSS_STATUS_ASSOCIATED);
4002 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
4003 if (intbss != wdev->auth_bsses[i])
4004 continue;
4005 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4006 NL80211_BSS_STATUS_AUTHENTICATED);
4007 break;
4008 }
4009 break;
4010 case NL80211_IFTYPE_ADHOC:
4011 if (intbss == wdev->current_bss)
4012 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4013 NL80211_BSS_STATUS_IBSS_JOINED);
4014 break;
4015 default:
4016 break;
4017 }
4018
4019 nla_nest_end(msg, bss);
4020
4021 return genlmsg_end(msg, hdr);
4022
4023 nla_put_failure:
4024 genlmsg_cancel(msg, hdr);
4025 return -EMSGSIZE;
4026 }
4027
4028 static int nl80211_dump_scan(struct sk_buff *skb,
4029 struct netlink_callback *cb)
4030 {
4031 struct cfg80211_registered_device *rdev;
4032 struct net_device *dev;
4033 struct cfg80211_internal_bss *scan;
4034 struct wireless_dev *wdev;
4035 int start = cb->args[1], idx = 0;
4036 int err;
4037
4038 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4039 if (err)
4040 return err;
4041
4042 wdev = dev->ieee80211_ptr;
4043
4044 wdev_lock(wdev);
4045 spin_lock_bh(&rdev->bss_lock);
4046 cfg80211_bss_expire(rdev);
4047
4048 cb->seq = rdev->bss_generation;
4049
4050 list_for_each_entry(scan, &rdev->bss_list, list) {
4051 if (++idx <= start)
4052 continue;
4053 if (nl80211_send_bss(skb, cb,
4054 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4055 rdev, wdev, scan) < 0) {
4056 idx--;
4057 break;
4058 }
4059 }
4060
4061 spin_unlock_bh(&rdev->bss_lock);
4062 wdev_unlock(wdev);
4063
4064 cb->args[1] = idx;
4065 nl80211_finish_netdev_dump(rdev);
4066
4067 return skb->len;
4068 }
4069
4070 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4071 int flags, struct net_device *dev,
4072 struct survey_info *survey)
4073 {
4074 void *hdr;
4075 struct nlattr *infoattr;
4076
4077 hdr = nl80211hdr_put(msg, pid, seq, flags,
4078 NL80211_CMD_NEW_SURVEY_RESULTS);
4079 if (!hdr)
4080 return -ENOMEM;
4081
4082 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
4083
4084 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4085 if (!infoattr)
4086 goto nla_put_failure;
4087
4088 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4089 survey->channel->center_freq);
4090 if (survey->filled & SURVEY_INFO_NOISE_DBM)
4091 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
4092 survey->noise);
4093 if (survey->filled & SURVEY_INFO_IN_USE)
4094 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
4095 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
4096 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4097 survey->channel_time);
4098 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
4099 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4100 survey->channel_time_busy);
4101 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
4102 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4103 survey->channel_time_ext_busy);
4104 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
4105 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4106 survey->channel_time_rx);
4107 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
4108 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4109 survey->channel_time_tx);
4110
4111 nla_nest_end(msg, infoattr);
4112
4113 return genlmsg_end(msg, hdr);
4114
4115 nla_put_failure:
4116 genlmsg_cancel(msg, hdr);
4117 return -EMSGSIZE;
4118 }
4119
4120 static int nl80211_dump_survey(struct sk_buff *skb,
4121 struct netlink_callback *cb)
4122 {
4123 struct survey_info survey;
4124 struct cfg80211_registered_device *dev;
4125 struct net_device *netdev;
4126 int survey_idx = cb->args[1];
4127 int res;
4128
4129 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4130 if (res)
4131 return res;
4132
4133 if (!dev->ops->dump_survey) {
4134 res = -EOPNOTSUPP;
4135 goto out_err;
4136 }
4137
4138 while (1) {
4139 struct ieee80211_channel *chan;
4140
4141 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4142 &survey);
4143 if (res == -ENOENT)
4144 break;
4145 if (res)
4146 goto out_err;
4147
4148 /* Survey without a channel doesn't make sense */
4149 if (!survey.channel) {
4150 res = -EINVAL;
4151 goto out;
4152 }
4153
4154 chan = ieee80211_get_channel(&dev->wiphy,
4155 survey.channel->center_freq);
4156 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4157 survey_idx++;
4158 continue;
4159 }
4160
4161 if (nl80211_send_survey(skb,
4162 NETLINK_CB(cb->skb).pid,
4163 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4164 netdev,
4165 &survey) < 0)
4166 goto out;
4167 survey_idx++;
4168 }
4169
4170 out:
4171 cb->args[1] = survey_idx;
4172 res = skb->len;
4173 out_err:
4174 nl80211_finish_netdev_dump(dev);
4175 return res;
4176 }
4177
4178 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4179 {
4180 return auth_type <= NL80211_AUTHTYPE_MAX;
4181 }
4182
4183 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4184 {
4185 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4186 NL80211_WPA_VERSION_2));
4187 }
4188
4189 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4190 {
4191 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4192 struct net_device *dev = info->user_ptr[1];
4193 struct ieee80211_channel *chan;
4194 const u8 *bssid, *ssid, *ie = NULL;
4195 int err, ssid_len, ie_len = 0;
4196 enum nl80211_auth_type auth_type;
4197 struct key_parse key;
4198 bool local_state_change;
4199
4200 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4201 return -EINVAL;
4202
4203 if (!info->attrs[NL80211_ATTR_MAC])
4204 return -EINVAL;
4205
4206 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4207 return -EINVAL;
4208
4209 if (!info->attrs[NL80211_ATTR_SSID])
4210 return -EINVAL;
4211
4212 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4213 return -EINVAL;
4214
4215 err = nl80211_parse_key(info, &key);
4216 if (err)
4217 return err;
4218
4219 if (key.idx >= 0) {
4220 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4221 return -EINVAL;
4222 if (!key.p.key || !key.p.key_len)
4223 return -EINVAL;
4224 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4225 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4226 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4227 key.p.key_len != WLAN_KEY_LEN_WEP104))
4228 return -EINVAL;
4229 if (key.idx > 4)
4230 return -EINVAL;
4231 } else {
4232 key.p.key_len = 0;
4233 key.p.key = NULL;
4234 }
4235
4236 if (key.idx >= 0) {
4237 int i;
4238 bool ok = false;
4239 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4240 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4241 ok = true;
4242 break;
4243 }
4244 }
4245 if (!ok)
4246 return -EINVAL;
4247 }
4248
4249 if (!rdev->ops->auth)
4250 return -EOPNOTSUPP;
4251
4252 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4253 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4254 return -EOPNOTSUPP;
4255
4256 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4257 chan = ieee80211_get_channel(&rdev->wiphy,
4258 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4259 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4260 return -EINVAL;
4261
4262 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4263 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4264
4265 if (info->attrs[NL80211_ATTR_IE]) {
4266 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4267 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4268 }
4269
4270 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4271 if (!nl80211_valid_auth_type(auth_type))
4272 return -EINVAL;
4273
4274 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4275
4276 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4277 ssid, ssid_len, ie, ie_len,
4278 key.p.key, key.p.key_len, key.idx,
4279 local_state_change);
4280 }
4281
4282 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4283 struct genl_info *info,
4284 struct cfg80211_crypto_settings *settings,
4285 int cipher_limit)
4286 {
4287 memset(settings, 0, sizeof(*settings));
4288
4289 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4290
4291 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4292 u16 proto;
4293 proto = nla_get_u16(
4294 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4295 settings->control_port_ethertype = cpu_to_be16(proto);
4296 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4297 proto != ETH_P_PAE)
4298 return -EINVAL;
4299 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4300 settings->control_port_no_encrypt = true;
4301 } else
4302 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4303
4304 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4305 void *data;
4306 int len, i;
4307
4308 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4309 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4310 settings->n_ciphers_pairwise = len / sizeof(u32);
4311
4312 if (len % sizeof(u32))
4313 return -EINVAL;
4314
4315 if (settings->n_ciphers_pairwise > cipher_limit)
4316 return -EINVAL;
4317
4318 memcpy(settings->ciphers_pairwise, data, len);
4319
4320 for (i = 0; i < settings->n_ciphers_pairwise; i++)
4321 if (!cfg80211_supported_cipher_suite(
4322 &rdev->wiphy,
4323 settings->ciphers_pairwise[i]))
4324 return -EINVAL;
4325 }
4326
4327 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4328 settings->cipher_group =
4329 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
4330 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4331 settings->cipher_group))
4332 return -EINVAL;
4333 }
4334
4335 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4336 settings->wpa_versions =
4337 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4338 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4339 return -EINVAL;
4340 }
4341
4342 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4343 void *data;
4344 int len;
4345
4346 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4347 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4348 settings->n_akm_suites = len / sizeof(u32);
4349
4350 if (len % sizeof(u32))
4351 return -EINVAL;
4352
4353 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4354 return -EINVAL;
4355
4356 memcpy(settings->akm_suites, data, len);
4357 }
4358
4359 return 0;
4360 }
4361
4362 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4363 {
4364 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4365 struct net_device *dev = info->user_ptr[1];
4366 struct cfg80211_crypto_settings crypto;
4367 struct ieee80211_channel *chan;
4368 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
4369 int err, ssid_len, ie_len = 0;
4370 bool use_mfp = false;
4371
4372 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4373 return -EINVAL;
4374
4375 if (!info->attrs[NL80211_ATTR_MAC] ||
4376 !info->attrs[NL80211_ATTR_SSID] ||
4377 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4378 return -EINVAL;
4379
4380 if (!rdev->ops->assoc)
4381 return -EOPNOTSUPP;
4382
4383 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4384 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4385 return -EOPNOTSUPP;
4386
4387 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4388
4389 chan = ieee80211_get_channel(&rdev->wiphy,
4390 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4391 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4392 return -EINVAL;
4393
4394 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4395 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4396
4397 if (info->attrs[NL80211_ATTR_IE]) {
4398 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4399 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4400 }
4401
4402 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4403 enum nl80211_mfp mfp =
4404 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4405 if (mfp == NL80211_MFP_REQUIRED)
4406 use_mfp = true;
4407 else if (mfp != NL80211_MFP_NO)
4408 return -EINVAL;
4409 }
4410
4411 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4412 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4413
4414 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
4415 if (!err)
4416 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4417 ssid, ssid_len, ie, ie_len, use_mfp,
4418 &crypto);
4419
4420 return err;
4421 }
4422
4423 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4424 {
4425 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4426 struct net_device *dev = info->user_ptr[1];
4427 const u8 *ie = NULL, *bssid;
4428 int ie_len = 0;
4429 u16 reason_code;
4430 bool local_state_change;
4431
4432 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4433 return -EINVAL;
4434
4435 if (!info->attrs[NL80211_ATTR_MAC])
4436 return -EINVAL;
4437
4438 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4439 return -EINVAL;
4440
4441 if (!rdev->ops->deauth)
4442 return -EOPNOTSUPP;
4443
4444 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4445 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4446 return -EOPNOTSUPP;
4447
4448 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4449
4450 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4451 if (reason_code == 0) {
4452 /* Reason Code 0 is reserved */
4453 return -EINVAL;
4454 }
4455
4456 if (info->attrs[NL80211_ATTR_IE]) {
4457 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4458 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4459 }
4460
4461 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4462
4463 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4464 local_state_change);
4465 }
4466
4467 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4468 {
4469 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4470 struct net_device *dev = info->user_ptr[1];
4471 const u8 *ie = NULL, *bssid;
4472 int ie_len = 0;
4473 u16 reason_code;
4474 bool local_state_change;
4475
4476 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4477 return -EINVAL;
4478
4479 if (!info->attrs[NL80211_ATTR_MAC])
4480 return -EINVAL;
4481
4482 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4483 return -EINVAL;
4484
4485 if (!rdev->ops->disassoc)
4486 return -EOPNOTSUPP;
4487
4488 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4489 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4490 return -EOPNOTSUPP;
4491
4492 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4493
4494 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4495 if (reason_code == 0) {
4496 /* Reason Code 0 is reserved */
4497 return -EINVAL;
4498 }
4499
4500 if (info->attrs[NL80211_ATTR_IE]) {
4501 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4502 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4503 }
4504
4505 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4506
4507 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4508 local_state_change);
4509 }
4510
4511 static bool
4512 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4513 int mcast_rate[IEEE80211_NUM_BANDS],
4514 int rateval)
4515 {
4516 struct wiphy *wiphy = &rdev->wiphy;
4517 bool found = false;
4518 int band, i;
4519
4520 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4521 struct ieee80211_supported_band *sband;
4522
4523 sband = wiphy->bands[band];
4524 if (!sband)
4525 continue;
4526
4527 for (i = 0; i < sband->n_bitrates; i++) {
4528 if (sband->bitrates[i].bitrate == rateval) {
4529 mcast_rate[band] = i + 1;
4530 found = true;
4531 break;
4532 }
4533 }
4534 }
4535
4536 return found;
4537 }
4538
4539 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4540 {
4541 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4542 struct net_device *dev = info->user_ptr[1];
4543 struct cfg80211_ibss_params ibss;
4544 struct wiphy *wiphy;
4545 struct cfg80211_cached_keys *connkeys = NULL;
4546 int err;
4547
4548 memset(&ibss, 0, sizeof(ibss));
4549
4550 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4551 return -EINVAL;
4552
4553 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4554 !info->attrs[NL80211_ATTR_SSID] ||
4555 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4556 return -EINVAL;
4557
4558 ibss.beacon_interval = 100;
4559
4560 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4561 ibss.beacon_interval =
4562 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4563 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4564 return -EINVAL;
4565 }
4566
4567 if (!rdev->ops->join_ibss)
4568 return -EOPNOTSUPP;
4569
4570 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4571 return -EOPNOTSUPP;
4572
4573 wiphy = &rdev->wiphy;
4574
4575 if (info->attrs[NL80211_ATTR_MAC]) {
4576 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4577
4578 if (!is_valid_ether_addr(ibss.bssid))
4579 return -EINVAL;
4580 }
4581 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4582 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4583
4584 if (info->attrs[NL80211_ATTR_IE]) {
4585 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4586 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4587 }
4588
4589 ibss.channel = ieee80211_get_channel(wiphy,
4590 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4591 if (!ibss.channel ||
4592 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4593 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4594 return -EINVAL;
4595
4596 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
4597 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4598
4599 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4600 u8 *rates =
4601 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4602 int n_rates =
4603 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4604 struct ieee80211_supported_band *sband =
4605 wiphy->bands[ibss.channel->band];
4606 int err;
4607
4608 err = ieee80211_get_ratemask(sband, rates, n_rates,
4609 &ibss.basic_rates);
4610 if (err)
4611 return err;
4612 }
4613
4614 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4615 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4616 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4617 return -EINVAL;
4618
4619 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4620 connkeys = nl80211_parse_connkeys(rdev,
4621 info->attrs[NL80211_ATTR_KEYS]);
4622 if (IS_ERR(connkeys))
4623 return PTR_ERR(connkeys);
4624 }
4625
4626 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
4627 if (err)
4628 kfree(connkeys);
4629 return err;
4630 }
4631
4632 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4633 {
4634 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4635 struct net_device *dev = info->user_ptr[1];
4636
4637 if (!rdev->ops->leave_ibss)
4638 return -EOPNOTSUPP;
4639
4640 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4641 return -EOPNOTSUPP;
4642
4643 return cfg80211_leave_ibss(rdev, dev, false);
4644 }
4645
4646 #ifdef CONFIG_NL80211_TESTMODE
4647 static struct genl_multicast_group nl80211_testmode_mcgrp = {
4648 .name = "testmode",
4649 };
4650
4651 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4652 {
4653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4654 int err;
4655
4656 if (!info->attrs[NL80211_ATTR_TESTDATA])
4657 return -EINVAL;
4658
4659 err = -EOPNOTSUPP;
4660 if (rdev->ops->testmode_cmd) {
4661 rdev->testmode_info = info;
4662 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4663 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4664 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4665 rdev->testmode_info = NULL;
4666 }
4667
4668 return err;
4669 }
4670
4671 static int nl80211_testmode_dump(struct sk_buff *skb,
4672 struct netlink_callback *cb)
4673 {
4674 struct cfg80211_registered_device *dev;
4675 int err;
4676 long phy_idx;
4677 void *data = NULL;
4678 int data_len = 0;
4679
4680 if (cb->args[0]) {
4681 /*
4682 * 0 is a valid index, but not valid for args[0],
4683 * so we need to offset by 1.
4684 */
4685 phy_idx = cb->args[0] - 1;
4686 } else {
4687 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
4688 nl80211_fam.attrbuf, nl80211_fam.maxattr,
4689 nl80211_policy);
4690 if (err)
4691 return err;
4692 if (!nl80211_fam.attrbuf[NL80211_ATTR_WIPHY])
4693 return -EINVAL;
4694 phy_idx = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
4695 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
4696 cb->args[1] =
4697 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
4698 }
4699
4700 if (cb->args[1]) {
4701 data = nla_data((void *)cb->args[1]);
4702 data_len = nla_len((void *)cb->args[1]);
4703 }
4704
4705 mutex_lock(&cfg80211_mutex);
4706 dev = cfg80211_rdev_by_wiphy_idx(phy_idx);
4707 if (!dev) {
4708 mutex_unlock(&cfg80211_mutex);
4709 return -ENOENT;
4710 }
4711 cfg80211_lock_rdev(dev);
4712 mutex_unlock(&cfg80211_mutex);
4713
4714 if (!dev->ops->testmode_dump) {
4715 err = -EOPNOTSUPP;
4716 goto out_err;
4717 }
4718
4719 while (1) {
4720 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
4721 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4722 NL80211_CMD_TESTMODE);
4723 struct nlattr *tmdata;
4724
4725 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, dev->wiphy_idx) < 0) {
4726 genlmsg_cancel(skb, hdr);
4727 break;
4728 }
4729
4730 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4731 if (!tmdata) {
4732 genlmsg_cancel(skb, hdr);
4733 break;
4734 }
4735 err = dev->ops->testmode_dump(&dev->wiphy, skb, cb,
4736 data, data_len);
4737 nla_nest_end(skb, tmdata);
4738
4739 if (err == -ENOBUFS || err == -ENOENT) {
4740 genlmsg_cancel(skb, hdr);
4741 break;
4742 } else if (err) {
4743 genlmsg_cancel(skb, hdr);
4744 goto out_err;
4745 }
4746
4747 genlmsg_end(skb, hdr);
4748 }
4749
4750 err = skb->len;
4751 /* see above */
4752 cb->args[0] = phy_idx + 1;
4753 out_err:
4754 cfg80211_unlock_rdev(dev);
4755 return err;
4756 }
4757
4758 static struct sk_buff *
4759 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4760 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4761 {
4762 struct sk_buff *skb;
4763 void *hdr;
4764 struct nlattr *data;
4765
4766 skb = nlmsg_new(approxlen + 100, gfp);
4767 if (!skb)
4768 return NULL;
4769
4770 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4771 if (!hdr) {
4772 kfree_skb(skb);
4773 return NULL;
4774 }
4775
4776 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4777 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4778
4779 ((void **)skb->cb)[0] = rdev;
4780 ((void **)skb->cb)[1] = hdr;
4781 ((void **)skb->cb)[2] = data;
4782
4783 return skb;
4784
4785 nla_put_failure:
4786 kfree_skb(skb);
4787 return NULL;
4788 }
4789
4790 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4791 int approxlen)
4792 {
4793 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4794
4795 if (WARN_ON(!rdev->testmode_info))
4796 return NULL;
4797
4798 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4799 rdev->testmode_info->snd_pid,
4800 rdev->testmode_info->snd_seq,
4801 GFP_KERNEL);
4802 }
4803 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4804
4805 int cfg80211_testmode_reply(struct sk_buff *skb)
4806 {
4807 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4808 void *hdr = ((void **)skb->cb)[1];
4809 struct nlattr *data = ((void **)skb->cb)[2];
4810
4811 if (WARN_ON(!rdev->testmode_info)) {
4812 kfree_skb(skb);
4813 return -EINVAL;
4814 }
4815
4816 nla_nest_end(skb, data);
4817 genlmsg_end(skb, hdr);
4818 return genlmsg_reply(skb, rdev->testmode_info);
4819 }
4820 EXPORT_SYMBOL(cfg80211_testmode_reply);
4821
4822 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4823 int approxlen, gfp_t gfp)
4824 {
4825 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4826
4827 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4828 }
4829 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4830
4831 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4832 {
4833 void *hdr = ((void **)skb->cb)[1];
4834 struct nlattr *data = ((void **)skb->cb)[2];
4835
4836 nla_nest_end(skb, data);
4837 genlmsg_end(skb, hdr);
4838 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4839 }
4840 EXPORT_SYMBOL(cfg80211_testmode_event);
4841 #endif
4842
4843 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4844 {
4845 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4846 struct net_device *dev = info->user_ptr[1];
4847 struct cfg80211_connect_params connect;
4848 struct wiphy *wiphy;
4849 struct cfg80211_cached_keys *connkeys = NULL;
4850 int err;
4851
4852 memset(&connect, 0, sizeof(connect));
4853
4854 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4855 return -EINVAL;
4856
4857 if (!info->attrs[NL80211_ATTR_SSID] ||
4858 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4859 return -EINVAL;
4860
4861 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4862 connect.auth_type =
4863 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4864 if (!nl80211_valid_auth_type(connect.auth_type))
4865 return -EINVAL;
4866 } else
4867 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4868
4869 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4870
4871 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
4872 NL80211_MAX_NR_CIPHER_SUITES);
4873 if (err)
4874 return err;
4875
4876 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4877 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4878 return -EOPNOTSUPP;
4879
4880 wiphy = &rdev->wiphy;
4881
4882 if (info->attrs[NL80211_ATTR_MAC])
4883 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4884 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4885 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4886
4887 if (info->attrs[NL80211_ATTR_IE]) {
4888 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4889 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4890 }
4891
4892 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4893 connect.channel =
4894 ieee80211_get_channel(wiphy,
4895 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4896 if (!connect.channel ||
4897 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4898 return -EINVAL;
4899 }
4900
4901 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4902 connkeys = nl80211_parse_connkeys(rdev,
4903 info->attrs[NL80211_ATTR_KEYS]);
4904 if (IS_ERR(connkeys))
4905 return PTR_ERR(connkeys);
4906 }
4907
4908 err = cfg80211_connect(rdev, dev, &connect, connkeys);
4909 if (err)
4910 kfree(connkeys);
4911 return err;
4912 }
4913
4914 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4915 {
4916 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4917 struct net_device *dev = info->user_ptr[1];
4918 u16 reason;
4919
4920 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4921 reason = WLAN_REASON_DEAUTH_LEAVING;
4922 else
4923 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4924
4925 if (reason == 0)
4926 return -EINVAL;
4927
4928 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4929 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4930 return -EOPNOTSUPP;
4931
4932 return cfg80211_disconnect(rdev, dev, reason, true);
4933 }
4934
4935 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4936 {
4937 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4938 struct net *net;
4939 int err;
4940 u32 pid;
4941
4942 if (!info->attrs[NL80211_ATTR_PID])
4943 return -EINVAL;
4944
4945 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4946
4947 net = get_net_ns_by_pid(pid);
4948 if (IS_ERR(net))
4949 return PTR_ERR(net);
4950
4951 err = 0;
4952
4953 /* check if anything to do */
4954 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4955 err = cfg80211_switch_netns(rdev, net);
4956
4957 put_net(net);
4958 return err;
4959 }
4960
4961 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4962 {
4963 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4964 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4965 struct cfg80211_pmksa *pmksa) = NULL;
4966 struct net_device *dev = info->user_ptr[1];
4967 struct cfg80211_pmksa pmksa;
4968
4969 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4970
4971 if (!info->attrs[NL80211_ATTR_MAC])
4972 return -EINVAL;
4973
4974 if (!info->attrs[NL80211_ATTR_PMKID])
4975 return -EINVAL;
4976
4977 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4978 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4979
4980 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4981 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4982 return -EOPNOTSUPP;
4983
4984 switch (info->genlhdr->cmd) {
4985 case NL80211_CMD_SET_PMKSA:
4986 rdev_ops = rdev->ops->set_pmksa;
4987 break;
4988 case NL80211_CMD_DEL_PMKSA:
4989 rdev_ops = rdev->ops->del_pmksa;
4990 break;
4991 default:
4992 WARN_ON(1);
4993 break;
4994 }
4995
4996 if (!rdev_ops)
4997 return -EOPNOTSUPP;
4998
4999 return rdev_ops(&rdev->wiphy, dev, &pmksa);
5000 }
5001
5002 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5003 {
5004 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5005 struct net_device *dev = info->user_ptr[1];
5006
5007 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5008 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5009 return -EOPNOTSUPP;
5010
5011 if (!rdev->ops->flush_pmksa)
5012 return -EOPNOTSUPP;
5013
5014 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
5015 }
5016
5017 static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5018 {
5019 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5020 struct net_device *dev = info->user_ptr[1];
5021 u8 action_code, dialog_token;
5022 u16 status_code;
5023 u8 *peer;
5024
5025 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5026 !rdev->ops->tdls_mgmt)
5027 return -EOPNOTSUPP;
5028
5029 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5030 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5031 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5032 !info->attrs[NL80211_ATTR_IE] ||
5033 !info->attrs[NL80211_ATTR_MAC])
5034 return -EINVAL;
5035
5036 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5037 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5038 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5039 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5040
5041 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5042 dialog_token, status_code,
5043 nla_data(info->attrs[NL80211_ATTR_IE]),
5044 nla_len(info->attrs[NL80211_ATTR_IE]));
5045 }
5046
5047 static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5048 {
5049 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5050 struct net_device *dev = info->user_ptr[1];
5051 enum nl80211_tdls_operation operation;
5052 u8 *peer;
5053
5054 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5055 !rdev->ops->tdls_oper)
5056 return -EOPNOTSUPP;
5057
5058 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5059 !info->attrs[NL80211_ATTR_MAC])
5060 return -EINVAL;
5061
5062 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5063 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5064
5065 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5066 }
5067
5068 static int nl80211_remain_on_channel(struct sk_buff *skb,
5069 struct genl_info *info)
5070 {
5071 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5072 struct net_device *dev = info->user_ptr[1];
5073 struct ieee80211_channel *chan;
5074 struct sk_buff *msg;
5075 void *hdr;
5076 u64 cookie;
5077 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5078 u32 freq, duration;
5079 int err;
5080
5081 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5082 !info->attrs[NL80211_ATTR_DURATION])
5083 return -EINVAL;
5084
5085 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5086
5087 /*
5088 * We should be on that channel for at least one jiffie,
5089 * and more than 5 seconds seems excessive.
5090 */
5091 if (!duration || !msecs_to_jiffies(duration) ||
5092 duration > rdev->wiphy.max_remain_on_channel_duration)
5093 return -EINVAL;
5094
5095 if (!rdev->ops->remain_on_channel)
5096 return -EOPNOTSUPP;
5097
5098 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5099 channel_type = nla_get_u32(
5100 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5101 if (channel_type != NL80211_CHAN_NO_HT &&
5102 channel_type != NL80211_CHAN_HT20 &&
5103 channel_type != NL80211_CHAN_HT40PLUS &&
5104 channel_type != NL80211_CHAN_HT40MINUS)
5105 return -EINVAL;
5106 }
5107
5108 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5109 chan = rdev_freq_to_chan(rdev, freq, channel_type);
5110 if (chan == NULL)
5111 return -EINVAL;
5112
5113 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5114 if (!msg)
5115 return -ENOMEM;
5116
5117 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5118 NL80211_CMD_REMAIN_ON_CHANNEL);
5119
5120 if (IS_ERR(hdr)) {
5121 err = PTR_ERR(hdr);
5122 goto free_msg;
5123 }
5124
5125 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5126 channel_type, duration, &cookie);
5127
5128 if (err)
5129 goto free_msg;
5130
5131 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5132
5133 genlmsg_end(msg, hdr);
5134
5135 return genlmsg_reply(msg, info);
5136
5137 nla_put_failure:
5138 err = -ENOBUFS;
5139 free_msg:
5140 nlmsg_free(msg);
5141 return err;
5142 }
5143
5144 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5145 struct genl_info *info)
5146 {
5147 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5148 struct net_device *dev = info->user_ptr[1];
5149 u64 cookie;
5150
5151 if (!info->attrs[NL80211_ATTR_COOKIE])
5152 return -EINVAL;
5153
5154 if (!rdev->ops->cancel_remain_on_channel)
5155 return -EOPNOTSUPP;
5156
5157 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5158
5159 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
5160 }
5161
5162 static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5163 u8 *rates, u8 rates_len)
5164 {
5165 u8 i;
5166 u32 mask = 0;
5167
5168 for (i = 0; i < rates_len; i++) {
5169 int rate = (rates[i] & 0x7f) * 5;
5170 int ridx;
5171 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5172 struct ieee80211_rate *srate =
5173 &sband->bitrates[ridx];
5174 if (rate == srate->bitrate) {
5175 mask |= 1 << ridx;
5176 break;
5177 }
5178 }
5179 if (ridx == sband->n_bitrates)
5180 return 0; /* rate not found */
5181 }
5182
5183 return mask;
5184 }
5185
5186 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
5187 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5188 .len = NL80211_MAX_SUPP_RATES },
5189 };
5190
5191 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5192 struct genl_info *info)
5193 {
5194 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
5195 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5196 struct cfg80211_bitrate_mask mask;
5197 int rem, i;
5198 struct net_device *dev = info->user_ptr[1];
5199 struct nlattr *tx_rates;
5200 struct ieee80211_supported_band *sband;
5201
5202 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5203 return -EINVAL;
5204
5205 if (!rdev->ops->set_bitrate_mask)
5206 return -EOPNOTSUPP;
5207
5208 memset(&mask, 0, sizeof(mask));
5209 /* Default to all rates enabled */
5210 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5211 sband = rdev->wiphy.bands[i];
5212 mask.control[i].legacy =
5213 sband ? (1 << sband->n_bitrates) - 1 : 0;
5214 }
5215
5216 /*
5217 * The nested attribute uses enum nl80211_band as the index. This maps
5218 * directly to the enum ieee80211_band values used in cfg80211.
5219 */
5220 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5221 {
5222 enum ieee80211_band band = nla_type(tx_rates);
5223 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5224 return -EINVAL;
5225 sband = rdev->wiphy.bands[band];
5226 if (sband == NULL)
5227 return -EINVAL;
5228 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5229 nla_len(tx_rates), nl80211_txattr_policy);
5230 if (tb[NL80211_TXRATE_LEGACY]) {
5231 mask.control[band].legacy = rateset_to_mask(
5232 sband,
5233 nla_data(tb[NL80211_TXRATE_LEGACY]),
5234 nla_len(tb[NL80211_TXRATE_LEGACY]));
5235 if (mask.control[band].legacy == 0)
5236 return -EINVAL;
5237 }
5238 }
5239
5240 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
5241 }
5242
5243 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
5244 {
5245 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5246 struct net_device *dev = info->user_ptr[1];
5247 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
5248
5249 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5250 return -EINVAL;
5251
5252 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5253 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
5254
5255 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5256 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5257 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5258 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5259 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5260 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
5261 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5262 return -EOPNOTSUPP;
5263
5264 /* not much point in registering if we can't reply */
5265 if (!rdev->ops->mgmt_tx)
5266 return -EOPNOTSUPP;
5267
5268 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
5269 frame_type,
5270 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5271 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
5272 }
5273
5274 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
5275 {
5276 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5277 struct net_device *dev = info->user_ptr[1];
5278 struct ieee80211_channel *chan;
5279 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5280 bool channel_type_valid = false;
5281 u32 freq;
5282 int err;
5283 void *hdr;
5284 u64 cookie;
5285 struct sk_buff *msg;
5286 unsigned int wait = 0;
5287 bool offchan;
5288 bool no_cck;
5289
5290 if (!info->attrs[NL80211_ATTR_FRAME] ||
5291 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5292 return -EINVAL;
5293
5294 if (!rdev->ops->mgmt_tx)
5295 return -EOPNOTSUPP;
5296
5297 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5298 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5299 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5300 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5301 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5302 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
5303 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5304 return -EOPNOTSUPP;
5305
5306 if (info->attrs[NL80211_ATTR_DURATION]) {
5307 if (!rdev->ops->mgmt_tx_cancel_wait)
5308 return -EINVAL;
5309 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5310 }
5311
5312 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5313 channel_type = nla_get_u32(
5314 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5315 if (channel_type != NL80211_CHAN_NO_HT &&
5316 channel_type != NL80211_CHAN_HT20 &&
5317 channel_type != NL80211_CHAN_HT40PLUS &&
5318 channel_type != NL80211_CHAN_HT40MINUS)
5319 return -EINVAL;
5320 channel_type_valid = true;
5321 }
5322
5323 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5324
5325 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5326
5327 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5328 chan = rdev_freq_to_chan(rdev, freq, channel_type);
5329 if (chan == NULL)
5330 return -EINVAL;
5331
5332 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5333 if (!msg)
5334 return -ENOMEM;
5335
5336 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5337 NL80211_CMD_FRAME);
5338
5339 if (IS_ERR(hdr)) {
5340 err = PTR_ERR(hdr);
5341 goto free_msg;
5342 }
5343 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5344 channel_type_valid, wait,
5345 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5346 nla_len(info->attrs[NL80211_ATTR_FRAME]),
5347 no_cck, &cookie);
5348 if (err)
5349 goto free_msg;
5350
5351 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5352
5353 genlmsg_end(msg, hdr);
5354 return genlmsg_reply(msg, info);
5355
5356 nla_put_failure:
5357 err = -ENOBUFS;
5358 free_msg:
5359 nlmsg_free(msg);
5360 return err;
5361 }
5362
5363 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5364 {
5365 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5366 struct net_device *dev = info->user_ptr[1];
5367 u64 cookie;
5368
5369 if (!info->attrs[NL80211_ATTR_COOKIE])
5370 return -EINVAL;
5371
5372 if (!rdev->ops->mgmt_tx_cancel_wait)
5373 return -EOPNOTSUPP;
5374
5375 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5376 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5377 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5378 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5379 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5380 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5381 return -EOPNOTSUPP;
5382
5383 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5384
5385 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5386 }
5387
5388 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5389 {
5390 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5391 struct wireless_dev *wdev;
5392 struct net_device *dev = info->user_ptr[1];
5393 u8 ps_state;
5394 bool state;
5395 int err;
5396
5397 if (!info->attrs[NL80211_ATTR_PS_STATE])
5398 return -EINVAL;
5399
5400 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5401
5402 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5403 return -EINVAL;
5404
5405 wdev = dev->ieee80211_ptr;
5406
5407 if (!rdev->ops->set_power_mgmt)
5408 return -EOPNOTSUPP;
5409
5410 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5411
5412 if (state == wdev->ps)
5413 return 0;
5414
5415 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5416 wdev->ps_timeout);
5417 if (!err)
5418 wdev->ps = state;
5419 return err;
5420 }
5421
5422 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5423 {
5424 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5425 enum nl80211_ps_state ps_state;
5426 struct wireless_dev *wdev;
5427 struct net_device *dev = info->user_ptr[1];
5428 struct sk_buff *msg;
5429 void *hdr;
5430 int err;
5431
5432 wdev = dev->ieee80211_ptr;
5433
5434 if (!rdev->ops->set_power_mgmt)
5435 return -EOPNOTSUPP;
5436
5437 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5438 if (!msg)
5439 return -ENOMEM;
5440
5441 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5442 NL80211_CMD_GET_POWER_SAVE);
5443 if (!hdr) {
5444 err = -ENOBUFS;
5445 goto free_msg;
5446 }
5447
5448 if (wdev->ps)
5449 ps_state = NL80211_PS_ENABLED;
5450 else
5451 ps_state = NL80211_PS_DISABLED;
5452
5453 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5454
5455 genlmsg_end(msg, hdr);
5456 return genlmsg_reply(msg, info);
5457
5458 nla_put_failure:
5459 err = -ENOBUFS;
5460 free_msg:
5461 nlmsg_free(msg);
5462 return err;
5463 }
5464
5465 static struct nla_policy
5466 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5467 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5468 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5469 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5470 };
5471
5472 static int nl80211_set_cqm_rssi(struct genl_info *info,
5473 s32 threshold, u32 hysteresis)
5474 {
5475 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5476 struct wireless_dev *wdev;
5477 struct net_device *dev = info->user_ptr[1];
5478
5479 if (threshold > 0)
5480 return -EINVAL;
5481
5482 wdev = dev->ieee80211_ptr;
5483
5484 if (!rdev->ops->set_cqm_rssi_config)
5485 return -EOPNOTSUPP;
5486
5487 if (wdev->iftype != NL80211_IFTYPE_STATION &&
5488 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
5489 return -EOPNOTSUPP;
5490
5491 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5492 threshold, hysteresis);
5493 }
5494
5495 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5496 {
5497 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5498 struct nlattr *cqm;
5499 int err;
5500
5501 cqm = info->attrs[NL80211_ATTR_CQM];
5502 if (!cqm) {
5503 err = -EINVAL;
5504 goto out;
5505 }
5506
5507 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5508 nl80211_attr_cqm_policy);
5509 if (err)
5510 goto out;
5511
5512 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5513 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5514 s32 threshold;
5515 u32 hysteresis;
5516 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5517 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5518 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5519 } else
5520 err = -EINVAL;
5521
5522 out:
5523 return err;
5524 }
5525
5526 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5527 {
5528 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5529 struct net_device *dev = info->user_ptr[1];
5530 struct mesh_config cfg;
5531 struct mesh_setup setup;
5532 int err;
5533
5534 /* start with default */
5535 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
5536 memcpy(&setup, &default_mesh_setup, sizeof(setup));
5537
5538 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
5539 /* and parse parameters if given */
5540 err = nl80211_parse_mesh_config(info, &cfg, NULL);
5541 if (err)
5542 return err;
5543 }
5544
5545 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5546 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5547 return -EINVAL;
5548
5549 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5550 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5551
5552 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5553 /* parse additional setup parameters if given */
5554 err = nl80211_parse_mesh_setup(info, &setup);
5555 if (err)
5556 return err;
5557 }
5558
5559 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
5560 }
5561
5562 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5563 {
5564 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5565 struct net_device *dev = info->user_ptr[1];
5566
5567 return cfg80211_leave_mesh(rdev, dev);
5568 }
5569
5570 static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5571 {
5572 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5573 struct sk_buff *msg;
5574 void *hdr;
5575
5576 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5577 return -EOPNOTSUPP;
5578
5579 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5580 if (!msg)
5581 return -ENOMEM;
5582
5583 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5584 NL80211_CMD_GET_WOWLAN);
5585 if (!hdr)
5586 goto nla_put_failure;
5587
5588 if (rdev->wowlan) {
5589 struct nlattr *nl_wowlan;
5590
5591 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5592 if (!nl_wowlan)
5593 goto nla_put_failure;
5594
5595 if (rdev->wowlan->any)
5596 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5597 if (rdev->wowlan->disconnect)
5598 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5599 if (rdev->wowlan->magic_pkt)
5600 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
5601 if (rdev->wowlan->gtk_rekey_failure)
5602 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
5603 if (rdev->wowlan->eap_identity_req)
5604 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
5605 if (rdev->wowlan->four_way_handshake)
5606 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
5607 if (rdev->wowlan->rfkill_release)
5608 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
5609 if (rdev->wowlan->n_patterns) {
5610 struct nlattr *nl_pats, *nl_pat;
5611 int i, pat_len;
5612
5613 nl_pats = nla_nest_start(msg,
5614 NL80211_WOWLAN_TRIG_PKT_PATTERN);
5615 if (!nl_pats)
5616 goto nla_put_failure;
5617
5618 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5619 nl_pat = nla_nest_start(msg, i + 1);
5620 if (!nl_pat)
5621 goto nla_put_failure;
5622 pat_len = rdev->wowlan->patterns[i].pattern_len;
5623 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5624 DIV_ROUND_UP(pat_len, 8),
5625 rdev->wowlan->patterns[i].mask);
5626 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5627 pat_len,
5628 rdev->wowlan->patterns[i].pattern);
5629 nla_nest_end(msg, nl_pat);
5630 }
5631 nla_nest_end(msg, nl_pats);
5632 }
5633
5634 nla_nest_end(msg, nl_wowlan);
5635 }
5636
5637 genlmsg_end(msg, hdr);
5638 return genlmsg_reply(msg, info);
5639
5640 nla_put_failure:
5641 nlmsg_free(msg);
5642 return -ENOBUFS;
5643 }
5644
5645 static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
5646 {
5647 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5648 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
5649 struct cfg80211_wowlan no_triggers = {};
5650 struct cfg80211_wowlan new_triggers = {};
5651 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
5652 int err, i;
5653
5654 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5655 return -EOPNOTSUPP;
5656
5657 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
5658 goto no_triggers;
5659
5660 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
5661 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5662 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5663 nl80211_wowlan_policy);
5664 if (err)
5665 return err;
5666
5667 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
5668 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
5669 return -EINVAL;
5670 new_triggers.any = true;
5671 }
5672
5673 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
5674 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
5675 return -EINVAL;
5676 new_triggers.disconnect = true;
5677 }
5678
5679 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
5680 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
5681 return -EINVAL;
5682 new_triggers.magic_pkt = true;
5683 }
5684
5685 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
5686 return -EINVAL;
5687
5688 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
5689 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
5690 return -EINVAL;
5691 new_triggers.gtk_rekey_failure = true;
5692 }
5693
5694 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
5695 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
5696 return -EINVAL;
5697 new_triggers.eap_identity_req = true;
5698 }
5699
5700 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
5701 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
5702 return -EINVAL;
5703 new_triggers.four_way_handshake = true;
5704 }
5705
5706 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
5707 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
5708 return -EINVAL;
5709 new_triggers.rfkill_release = true;
5710 }
5711
5712 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
5713 struct nlattr *pat;
5714 int n_patterns = 0;
5715 int rem, pat_len, mask_len;
5716 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
5717
5718 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5719 rem)
5720 n_patterns++;
5721 if (n_patterns > wowlan->n_patterns)
5722 return -EINVAL;
5723
5724 new_triggers.patterns = kcalloc(n_patterns,
5725 sizeof(new_triggers.patterns[0]),
5726 GFP_KERNEL);
5727 if (!new_triggers.patterns)
5728 return -ENOMEM;
5729
5730 new_triggers.n_patterns = n_patterns;
5731 i = 0;
5732
5733 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
5734 rem) {
5735 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
5736 nla_data(pat), nla_len(pat), NULL);
5737 err = -EINVAL;
5738 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
5739 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
5740 goto error;
5741 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
5742 mask_len = DIV_ROUND_UP(pat_len, 8);
5743 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
5744 mask_len)
5745 goto error;
5746 if (pat_len > wowlan->pattern_max_len ||
5747 pat_len < wowlan->pattern_min_len)
5748 goto error;
5749
5750 new_triggers.patterns[i].mask =
5751 kmalloc(mask_len + pat_len, GFP_KERNEL);
5752 if (!new_triggers.patterns[i].mask) {
5753 err = -ENOMEM;
5754 goto error;
5755 }
5756 new_triggers.patterns[i].pattern =
5757 new_triggers.patterns[i].mask + mask_len;
5758 memcpy(new_triggers.patterns[i].mask,
5759 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
5760 mask_len);
5761 new_triggers.patterns[i].pattern_len = pat_len;
5762 memcpy(new_triggers.patterns[i].pattern,
5763 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
5764 pat_len);
5765 i++;
5766 }
5767 }
5768
5769 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
5770 struct cfg80211_wowlan *ntrig;
5771 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
5772 GFP_KERNEL);
5773 if (!ntrig) {
5774 err = -ENOMEM;
5775 goto error;
5776 }
5777 cfg80211_rdev_free_wowlan(rdev);
5778 rdev->wowlan = ntrig;
5779 } else {
5780 no_triggers:
5781 cfg80211_rdev_free_wowlan(rdev);
5782 rdev->wowlan = NULL;
5783 }
5784
5785 return 0;
5786 error:
5787 for (i = 0; i < new_triggers.n_patterns; i++)
5788 kfree(new_triggers.patterns[i].mask);
5789 kfree(new_triggers.patterns);
5790 return err;
5791 }
5792
5793 static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
5794 {
5795 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5796 struct net_device *dev = info->user_ptr[1];
5797 struct wireless_dev *wdev = dev->ieee80211_ptr;
5798 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
5799 struct cfg80211_gtk_rekey_data rekey_data;
5800 int err;
5801
5802 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
5803 return -EINVAL;
5804
5805 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
5806 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
5807 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
5808 nl80211_rekey_policy);
5809 if (err)
5810 return err;
5811
5812 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
5813 return -ERANGE;
5814 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
5815 return -ERANGE;
5816 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
5817 return -ERANGE;
5818
5819 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
5820 NL80211_KEK_LEN);
5821 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
5822 NL80211_KCK_LEN);
5823 memcpy(rekey_data.replay_ctr,
5824 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
5825 NL80211_REPLAY_CTR_LEN);
5826
5827 wdev_lock(wdev);
5828 if (!wdev->current_bss) {
5829 err = -ENOTCONN;
5830 goto out;
5831 }
5832
5833 if (!rdev->ops->set_rekey_data) {
5834 err = -EOPNOTSUPP;
5835 goto out;
5836 }
5837
5838 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
5839 out:
5840 wdev_unlock(wdev);
5841 return err;
5842 }
5843
5844 static int nl80211_register_unexpected_frame(struct sk_buff *skb,
5845 struct genl_info *info)
5846 {
5847 struct net_device *dev = info->user_ptr[1];
5848 struct wireless_dev *wdev = dev->ieee80211_ptr;
5849
5850 if (wdev->iftype != NL80211_IFTYPE_AP &&
5851 wdev->iftype != NL80211_IFTYPE_P2P_GO)
5852 return -EINVAL;
5853
5854 if (wdev->ap_unexpected_nlpid)
5855 return -EBUSY;
5856
5857 wdev->ap_unexpected_nlpid = info->snd_pid;
5858 return 0;
5859 }
5860
5861 static int nl80211_probe_client(struct sk_buff *skb,
5862 struct genl_info *info)
5863 {
5864 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5865 struct net_device *dev = info->user_ptr[1];
5866 struct wireless_dev *wdev = dev->ieee80211_ptr;
5867 struct sk_buff *msg;
5868 void *hdr;
5869 const u8 *addr;
5870 u64 cookie;
5871 int err;
5872
5873 if (wdev->iftype != NL80211_IFTYPE_AP &&
5874 wdev->iftype != NL80211_IFTYPE_P2P_GO)
5875 return -EOPNOTSUPP;
5876
5877 if (!info->attrs[NL80211_ATTR_MAC])
5878 return -EINVAL;
5879
5880 if (!rdev->ops->probe_client)
5881 return -EOPNOTSUPP;
5882
5883 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5884 if (!msg)
5885 return -ENOMEM;
5886
5887 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5888 NL80211_CMD_PROBE_CLIENT);
5889
5890 if (IS_ERR(hdr)) {
5891 err = PTR_ERR(hdr);
5892 goto free_msg;
5893 }
5894
5895 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5896
5897 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
5898 if (err)
5899 goto free_msg;
5900
5901 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5902
5903 genlmsg_end(msg, hdr);
5904
5905 return genlmsg_reply(msg, info);
5906
5907 nla_put_failure:
5908 err = -ENOBUFS;
5909 free_msg:
5910 nlmsg_free(msg);
5911 return err;
5912 }
5913
5914 static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
5915 {
5916 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5917
5918 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
5919 return -EOPNOTSUPP;
5920
5921 if (rdev->ap_beacons_nlpid)
5922 return -EBUSY;
5923
5924 rdev->ap_beacons_nlpid = info->snd_pid;
5925
5926 return 0;
5927 }
5928
5929 #define NL80211_FLAG_NEED_WIPHY 0x01
5930 #define NL80211_FLAG_NEED_NETDEV 0x02
5931 #define NL80211_FLAG_NEED_RTNL 0x04
5932 #define NL80211_FLAG_CHECK_NETDEV_UP 0x08
5933 #define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
5934 NL80211_FLAG_CHECK_NETDEV_UP)
5935
5936 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
5937 struct genl_info *info)
5938 {
5939 struct cfg80211_registered_device *rdev;
5940 struct net_device *dev;
5941 int err;
5942 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
5943
5944 if (rtnl)
5945 rtnl_lock();
5946
5947 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
5948 rdev = cfg80211_get_dev_from_info(info);
5949 if (IS_ERR(rdev)) {
5950 if (rtnl)
5951 rtnl_unlock();
5952 return PTR_ERR(rdev);
5953 }
5954 info->user_ptr[0] = rdev;
5955 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
5956 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5957 if (err) {
5958 if (rtnl)
5959 rtnl_unlock();
5960 return err;
5961 }
5962 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
5963 !netif_running(dev)) {
5964 cfg80211_unlock_rdev(rdev);
5965 dev_put(dev);
5966 if (rtnl)
5967 rtnl_unlock();
5968 return -ENETDOWN;
5969 }
5970 info->user_ptr[0] = rdev;
5971 info->user_ptr[1] = dev;
5972 }
5973
5974 return 0;
5975 }
5976
5977 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
5978 struct genl_info *info)
5979 {
5980 if (info->user_ptr[0])
5981 cfg80211_unlock_rdev(info->user_ptr[0]);
5982 if (info->user_ptr[1])
5983 dev_put(info->user_ptr[1]);
5984 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
5985 rtnl_unlock();
5986 }
5987
5988 static struct genl_ops nl80211_ops[] = {
5989 {
5990 .cmd = NL80211_CMD_GET_WIPHY,
5991 .doit = nl80211_get_wiphy,
5992 .dumpit = nl80211_dump_wiphy,
5993 .policy = nl80211_policy,
5994 /* can be retrieved by unprivileged users */
5995 .internal_flags = NL80211_FLAG_NEED_WIPHY,
5996 },
5997 {
5998 .cmd = NL80211_CMD_SET_WIPHY,
5999 .doit = nl80211_set_wiphy,
6000 .policy = nl80211_policy,
6001 .flags = GENL_ADMIN_PERM,
6002 .internal_flags = NL80211_FLAG_NEED_RTNL,
6003 },
6004 {
6005 .cmd = NL80211_CMD_GET_INTERFACE,
6006 .doit = nl80211_get_interface,
6007 .dumpit = nl80211_dump_interface,
6008 .policy = nl80211_policy,
6009 /* can be retrieved by unprivileged users */
6010 .internal_flags = NL80211_FLAG_NEED_NETDEV,
6011 },
6012 {
6013 .cmd = NL80211_CMD_SET_INTERFACE,
6014 .doit = nl80211_set_interface,
6015 .policy = nl80211_policy,
6016 .flags = GENL_ADMIN_PERM,
6017 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6018 NL80211_FLAG_NEED_RTNL,
6019 },
6020 {
6021 .cmd = NL80211_CMD_NEW_INTERFACE,
6022 .doit = nl80211_new_interface,
6023 .policy = nl80211_policy,
6024 .flags = GENL_ADMIN_PERM,
6025 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6026 NL80211_FLAG_NEED_RTNL,
6027 },
6028 {
6029 .cmd = NL80211_CMD_DEL_INTERFACE,
6030 .doit = nl80211_del_interface,
6031 .policy = nl80211_policy,
6032 .flags = GENL_ADMIN_PERM,
6033 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6034 NL80211_FLAG_NEED_RTNL,
6035 },
6036 {
6037 .cmd = NL80211_CMD_GET_KEY,
6038 .doit = nl80211_get_key,
6039 .policy = nl80211_policy,
6040 .flags = GENL_ADMIN_PERM,
6041 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6042 NL80211_FLAG_NEED_RTNL,
6043 },
6044 {
6045 .cmd = NL80211_CMD_SET_KEY,
6046 .doit = nl80211_set_key,
6047 .policy = nl80211_policy,
6048 .flags = GENL_ADMIN_PERM,
6049 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6050 NL80211_FLAG_NEED_RTNL,
6051 },
6052 {
6053 .cmd = NL80211_CMD_NEW_KEY,
6054 .doit = nl80211_new_key,
6055 .policy = nl80211_policy,
6056 .flags = GENL_ADMIN_PERM,
6057 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6058 NL80211_FLAG_NEED_RTNL,
6059 },
6060 {
6061 .cmd = NL80211_CMD_DEL_KEY,
6062 .doit = nl80211_del_key,
6063 .policy = nl80211_policy,
6064 .flags = GENL_ADMIN_PERM,
6065 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6066 NL80211_FLAG_NEED_RTNL,
6067 },
6068 {
6069 .cmd = NL80211_CMD_SET_BEACON,
6070 .policy = nl80211_policy,
6071 .flags = GENL_ADMIN_PERM,
6072 .doit = nl80211_addset_beacon,
6073 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6074 NL80211_FLAG_NEED_RTNL,
6075 },
6076 {
6077 .cmd = NL80211_CMD_NEW_BEACON,
6078 .policy = nl80211_policy,
6079 .flags = GENL_ADMIN_PERM,
6080 .doit = nl80211_addset_beacon,
6081 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6082 NL80211_FLAG_NEED_RTNL,
6083 },
6084 {
6085 .cmd = NL80211_CMD_DEL_BEACON,
6086 .policy = nl80211_policy,
6087 .flags = GENL_ADMIN_PERM,
6088 .doit = nl80211_del_beacon,
6089 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6090 NL80211_FLAG_NEED_RTNL,
6091 },
6092 {
6093 .cmd = NL80211_CMD_GET_STATION,
6094 .doit = nl80211_get_station,
6095 .dumpit = nl80211_dump_station,
6096 .policy = nl80211_policy,
6097 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6098 NL80211_FLAG_NEED_RTNL,
6099 },
6100 {
6101 .cmd = NL80211_CMD_SET_STATION,
6102 .doit = nl80211_set_station,
6103 .policy = nl80211_policy,
6104 .flags = GENL_ADMIN_PERM,
6105 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6106 NL80211_FLAG_NEED_RTNL,
6107 },
6108 {
6109 .cmd = NL80211_CMD_NEW_STATION,
6110 .doit = nl80211_new_station,
6111 .policy = nl80211_policy,
6112 .flags = GENL_ADMIN_PERM,
6113 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6114 NL80211_FLAG_NEED_RTNL,
6115 },
6116 {
6117 .cmd = NL80211_CMD_DEL_STATION,
6118 .doit = nl80211_del_station,
6119 .policy = nl80211_policy,
6120 .flags = GENL_ADMIN_PERM,
6121 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6122 NL80211_FLAG_NEED_RTNL,
6123 },
6124 {
6125 .cmd = NL80211_CMD_GET_MPATH,
6126 .doit = nl80211_get_mpath,
6127 .dumpit = nl80211_dump_mpath,
6128 .policy = nl80211_policy,
6129 .flags = GENL_ADMIN_PERM,
6130 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6131 NL80211_FLAG_NEED_RTNL,
6132 },
6133 {
6134 .cmd = NL80211_CMD_SET_MPATH,
6135 .doit = nl80211_set_mpath,
6136 .policy = nl80211_policy,
6137 .flags = GENL_ADMIN_PERM,
6138 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6139 NL80211_FLAG_NEED_RTNL,
6140 },
6141 {
6142 .cmd = NL80211_CMD_NEW_MPATH,
6143 .doit = nl80211_new_mpath,
6144 .policy = nl80211_policy,
6145 .flags = GENL_ADMIN_PERM,
6146 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6147 NL80211_FLAG_NEED_RTNL,
6148 },
6149 {
6150 .cmd = NL80211_CMD_DEL_MPATH,
6151 .doit = nl80211_del_mpath,
6152 .policy = nl80211_policy,
6153 .flags = GENL_ADMIN_PERM,
6154 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6155 NL80211_FLAG_NEED_RTNL,
6156 },
6157 {
6158 .cmd = NL80211_CMD_SET_BSS,
6159 .doit = nl80211_set_bss,
6160 .policy = nl80211_policy,
6161 .flags = GENL_ADMIN_PERM,
6162 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6163 NL80211_FLAG_NEED_RTNL,
6164 },
6165 {
6166 .cmd = NL80211_CMD_GET_REG,
6167 .doit = nl80211_get_reg,
6168 .policy = nl80211_policy,
6169 /* can be retrieved by unprivileged users */
6170 },
6171 {
6172 .cmd = NL80211_CMD_SET_REG,
6173 .doit = nl80211_set_reg,
6174 .policy = nl80211_policy,
6175 .flags = GENL_ADMIN_PERM,
6176 },
6177 {
6178 .cmd = NL80211_CMD_REQ_SET_REG,
6179 .doit = nl80211_req_set_reg,
6180 .policy = nl80211_policy,
6181 .flags = GENL_ADMIN_PERM,
6182 },
6183 {
6184 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6185 .doit = nl80211_get_mesh_config,
6186 .policy = nl80211_policy,
6187 /* can be retrieved by unprivileged users */
6188 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6189 NL80211_FLAG_NEED_RTNL,
6190 },
6191 {
6192 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6193 .doit = nl80211_update_mesh_config,
6194 .policy = nl80211_policy,
6195 .flags = GENL_ADMIN_PERM,
6196 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6197 NL80211_FLAG_NEED_RTNL,
6198 },
6199 {
6200 .cmd = NL80211_CMD_TRIGGER_SCAN,
6201 .doit = nl80211_trigger_scan,
6202 .policy = nl80211_policy,
6203 .flags = GENL_ADMIN_PERM,
6204 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6205 NL80211_FLAG_NEED_RTNL,
6206 },
6207 {
6208 .cmd = NL80211_CMD_GET_SCAN,
6209 .policy = nl80211_policy,
6210 .dumpit = nl80211_dump_scan,
6211 },
6212 {
6213 .cmd = NL80211_CMD_START_SCHED_SCAN,
6214 .doit = nl80211_start_sched_scan,
6215 .policy = nl80211_policy,
6216 .flags = GENL_ADMIN_PERM,
6217 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6218 NL80211_FLAG_NEED_RTNL,
6219 },
6220 {
6221 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6222 .doit = nl80211_stop_sched_scan,
6223 .policy = nl80211_policy,
6224 .flags = GENL_ADMIN_PERM,
6225 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6226 NL80211_FLAG_NEED_RTNL,
6227 },
6228 {
6229 .cmd = NL80211_CMD_AUTHENTICATE,
6230 .doit = nl80211_authenticate,
6231 .policy = nl80211_policy,
6232 .flags = GENL_ADMIN_PERM,
6233 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6234 NL80211_FLAG_NEED_RTNL,
6235 },
6236 {
6237 .cmd = NL80211_CMD_ASSOCIATE,
6238 .doit = nl80211_associate,
6239 .policy = nl80211_policy,
6240 .flags = GENL_ADMIN_PERM,
6241 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6242 NL80211_FLAG_NEED_RTNL,
6243 },
6244 {
6245 .cmd = NL80211_CMD_DEAUTHENTICATE,
6246 .doit = nl80211_deauthenticate,
6247 .policy = nl80211_policy,
6248 .flags = GENL_ADMIN_PERM,
6249 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6250 NL80211_FLAG_NEED_RTNL,
6251 },
6252 {
6253 .cmd = NL80211_CMD_DISASSOCIATE,
6254 .doit = nl80211_disassociate,
6255 .policy = nl80211_policy,
6256 .flags = GENL_ADMIN_PERM,
6257 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6258 NL80211_FLAG_NEED_RTNL,
6259 },
6260 {
6261 .cmd = NL80211_CMD_JOIN_IBSS,
6262 .doit = nl80211_join_ibss,
6263 .policy = nl80211_policy,
6264 .flags = GENL_ADMIN_PERM,
6265 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6266 NL80211_FLAG_NEED_RTNL,
6267 },
6268 {
6269 .cmd = NL80211_CMD_LEAVE_IBSS,
6270 .doit = nl80211_leave_ibss,
6271 .policy = nl80211_policy,
6272 .flags = GENL_ADMIN_PERM,
6273 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6274 NL80211_FLAG_NEED_RTNL,
6275 },
6276 #ifdef CONFIG_NL80211_TESTMODE
6277 {
6278 .cmd = NL80211_CMD_TESTMODE,
6279 .doit = nl80211_testmode_do,
6280 .dumpit = nl80211_testmode_dump,
6281 .policy = nl80211_policy,
6282 .flags = GENL_ADMIN_PERM,
6283 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6284 NL80211_FLAG_NEED_RTNL,
6285 },
6286 #endif
6287 {
6288 .cmd = NL80211_CMD_CONNECT,
6289 .doit = nl80211_connect,
6290 .policy = nl80211_policy,
6291 .flags = GENL_ADMIN_PERM,
6292 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6293 NL80211_FLAG_NEED_RTNL,
6294 },
6295 {
6296 .cmd = NL80211_CMD_DISCONNECT,
6297 .doit = nl80211_disconnect,
6298 .policy = nl80211_policy,
6299 .flags = GENL_ADMIN_PERM,
6300 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6301 NL80211_FLAG_NEED_RTNL,
6302 },
6303 {
6304 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6305 .doit = nl80211_wiphy_netns,
6306 .policy = nl80211_policy,
6307 .flags = GENL_ADMIN_PERM,
6308 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6309 NL80211_FLAG_NEED_RTNL,
6310 },
6311 {
6312 .cmd = NL80211_CMD_GET_SURVEY,
6313 .policy = nl80211_policy,
6314 .dumpit = nl80211_dump_survey,
6315 },
6316 {
6317 .cmd = NL80211_CMD_SET_PMKSA,
6318 .doit = nl80211_setdel_pmksa,
6319 .policy = nl80211_policy,
6320 .flags = GENL_ADMIN_PERM,
6321 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6322 NL80211_FLAG_NEED_RTNL,
6323 },
6324 {
6325 .cmd = NL80211_CMD_DEL_PMKSA,
6326 .doit = nl80211_setdel_pmksa,
6327 .policy = nl80211_policy,
6328 .flags = GENL_ADMIN_PERM,
6329 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6330 NL80211_FLAG_NEED_RTNL,
6331 },
6332 {
6333 .cmd = NL80211_CMD_FLUSH_PMKSA,
6334 .doit = nl80211_flush_pmksa,
6335 .policy = nl80211_policy,
6336 .flags = GENL_ADMIN_PERM,
6337 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6338 NL80211_FLAG_NEED_RTNL,
6339 },
6340 {
6341 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6342 .doit = nl80211_remain_on_channel,
6343 .policy = nl80211_policy,
6344 .flags = GENL_ADMIN_PERM,
6345 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6346 NL80211_FLAG_NEED_RTNL,
6347 },
6348 {
6349 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6350 .doit = nl80211_cancel_remain_on_channel,
6351 .policy = nl80211_policy,
6352 .flags = GENL_ADMIN_PERM,
6353 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6354 NL80211_FLAG_NEED_RTNL,
6355 },
6356 {
6357 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6358 .doit = nl80211_set_tx_bitrate_mask,
6359 .policy = nl80211_policy,
6360 .flags = GENL_ADMIN_PERM,
6361 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6362 NL80211_FLAG_NEED_RTNL,
6363 },
6364 {
6365 .cmd = NL80211_CMD_REGISTER_FRAME,
6366 .doit = nl80211_register_mgmt,
6367 .policy = nl80211_policy,
6368 .flags = GENL_ADMIN_PERM,
6369 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6370 NL80211_FLAG_NEED_RTNL,
6371 },
6372 {
6373 .cmd = NL80211_CMD_FRAME,
6374 .doit = nl80211_tx_mgmt,
6375 .policy = nl80211_policy,
6376 .flags = GENL_ADMIN_PERM,
6377 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6378 NL80211_FLAG_NEED_RTNL,
6379 },
6380 {
6381 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6382 .doit = nl80211_tx_mgmt_cancel_wait,
6383 .policy = nl80211_policy,
6384 .flags = GENL_ADMIN_PERM,
6385 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6386 NL80211_FLAG_NEED_RTNL,
6387 },
6388 {
6389 .cmd = NL80211_CMD_SET_POWER_SAVE,
6390 .doit = nl80211_set_power_save,
6391 .policy = nl80211_policy,
6392 .flags = GENL_ADMIN_PERM,
6393 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6394 NL80211_FLAG_NEED_RTNL,
6395 },
6396 {
6397 .cmd = NL80211_CMD_GET_POWER_SAVE,
6398 .doit = nl80211_get_power_save,
6399 .policy = nl80211_policy,
6400 /* can be retrieved by unprivileged users */
6401 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6402 NL80211_FLAG_NEED_RTNL,
6403 },
6404 {
6405 .cmd = NL80211_CMD_SET_CQM,
6406 .doit = nl80211_set_cqm,
6407 .policy = nl80211_policy,
6408 .flags = GENL_ADMIN_PERM,
6409 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6410 NL80211_FLAG_NEED_RTNL,
6411 },
6412 {
6413 .cmd = NL80211_CMD_SET_CHANNEL,
6414 .doit = nl80211_set_channel,
6415 .policy = nl80211_policy,
6416 .flags = GENL_ADMIN_PERM,
6417 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6418 NL80211_FLAG_NEED_RTNL,
6419 },
6420 {
6421 .cmd = NL80211_CMD_SET_WDS_PEER,
6422 .doit = nl80211_set_wds_peer,
6423 .policy = nl80211_policy,
6424 .flags = GENL_ADMIN_PERM,
6425 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6426 NL80211_FLAG_NEED_RTNL,
6427 },
6428 {
6429 .cmd = NL80211_CMD_JOIN_MESH,
6430 .doit = nl80211_join_mesh,
6431 .policy = nl80211_policy,
6432 .flags = GENL_ADMIN_PERM,
6433 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6434 NL80211_FLAG_NEED_RTNL,
6435 },
6436 {
6437 .cmd = NL80211_CMD_LEAVE_MESH,
6438 .doit = nl80211_leave_mesh,
6439 .policy = nl80211_policy,
6440 .flags = GENL_ADMIN_PERM,
6441 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6442 NL80211_FLAG_NEED_RTNL,
6443 },
6444 {
6445 .cmd = NL80211_CMD_GET_WOWLAN,
6446 .doit = nl80211_get_wowlan,
6447 .policy = nl80211_policy,
6448 /* can be retrieved by unprivileged users */
6449 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6450 NL80211_FLAG_NEED_RTNL,
6451 },
6452 {
6453 .cmd = NL80211_CMD_SET_WOWLAN,
6454 .doit = nl80211_set_wowlan,
6455 .policy = nl80211_policy,
6456 .flags = GENL_ADMIN_PERM,
6457 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6458 NL80211_FLAG_NEED_RTNL,
6459 },
6460 {
6461 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
6462 .doit = nl80211_set_rekey_data,
6463 .policy = nl80211_policy,
6464 .flags = GENL_ADMIN_PERM,
6465 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6466 NL80211_FLAG_NEED_RTNL,
6467 },
6468 {
6469 .cmd = NL80211_CMD_TDLS_MGMT,
6470 .doit = nl80211_tdls_mgmt,
6471 .policy = nl80211_policy,
6472 .flags = GENL_ADMIN_PERM,
6473 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6474 NL80211_FLAG_NEED_RTNL,
6475 },
6476 {
6477 .cmd = NL80211_CMD_TDLS_OPER,
6478 .doit = nl80211_tdls_oper,
6479 .policy = nl80211_policy,
6480 .flags = GENL_ADMIN_PERM,
6481 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6482 NL80211_FLAG_NEED_RTNL,
6483 },
6484 {
6485 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
6486 .doit = nl80211_register_unexpected_frame,
6487 .policy = nl80211_policy,
6488 .flags = GENL_ADMIN_PERM,
6489 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6490 NL80211_FLAG_NEED_RTNL,
6491 },
6492 {
6493 .cmd = NL80211_CMD_PROBE_CLIENT,
6494 .doit = nl80211_probe_client,
6495 .policy = nl80211_policy,
6496 .flags = GENL_ADMIN_PERM,
6497 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6498 NL80211_FLAG_NEED_RTNL,
6499 },
6500 {
6501 .cmd = NL80211_CMD_REGISTER_BEACONS,
6502 .doit = nl80211_register_beacons,
6503 .policy = nl80211_policy,
6504 .flags = GENL_ADMIN_PERM,
6505 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6506 NL80211_FLAG_NEED_RTNL,
6507 },
6508 };
6509
6510 static struct genl_multicast_group nl80211_mlme_mcgrp = {
6511 .name = "mlme",
6512 };
6513
6514 /* multicast groups */
6515 static struct genl_multicast_group nl80211_config_mcgrp = {
6516 .name = "config",
6517 };
6518 static struct genl_multicast_group nl80211_scan_mcgrp = {
6519 .name = "scan",
6520 };
6521 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
6522 .name = "regulatory",
6523 };
6524
6525 /* notification functions */
6526
6527 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
6528 {
6529 struct sk_buff *msg;
6530
6531 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6532 if (!msg)
6533 return;
6534
6535 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
6536 nlmsg_free(msg);
6537 return;
6538 }
6539
6540 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6541 nl80211_config_mcgrp.id, GFP_KERNEL);
6542 }
6543
6544 static int nl80211_add_scan_req(struct sk_buff *msg,
6545 struct cfg80211_registered_device *rdev)
6546 {
6547 struct cfg80211_scan_request *req = rdev->scan_req;
6548 struct nlattr *nest;
6549 int i;
6550
6551 ASSERT_RDEV_LOCK(rdev);
6552
6553 if (WARN_ON(!req))
6554 return 0;
6555
6556 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
6557 if (!nest)
6558 goto nla_put_failure;
6559 for (i = 0; i < req->n_ssids; i++)
6560 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
6561 nla_nest_end(msg, nest);
6562
6563 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
6564 if (!nest)
6565 goto nla_put_failure;
6566 for (i = 0; i < req->n_channels; i++)
6567 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
6568 nla_nest_end(msg, nest);
6569
6570 if (req->ie)
6571 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
6572
6573 return 0;
6574 nla_put_failure:
6575 return -ENOBUFS;
6576 }
6577
6578 static int nl80211_send_scan_msg(struct sk_buff *msg,
6579 struct cfg80211_registered_device *rdev,
6580 struct net_device *netdev,
6581 u32 pid, u32 seq, int flags,
6582 u32 cmd)
6583 {
6584 void *hdr;
6585
6586 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6587 if (!hdr)
6588 return -1;
6589
6590 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6591 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6592
6593 /* ignore errors and send incomplete event anyway */
6594 nl80211_add_scan_req(msg, rdev);
6595
6596 return genlmsg_end(msg, hdr);
6597
6598 nla_put_failure:
6599 genlmsg_cancel(msg, hdr);
6600 return -EMSGSIZE;
6601 }
6602
6603 static int
6604 nl80211_send_sched_scan_msg(struct sk_buff *msg,
6605 struct cfg80211_registered_device *rdev,
6606 struct net_device *netdev,
6607 u32 pid, u32 seq, int flags, u32 cmd)
6608 {
6609 void *hdr;
6610
6611 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6612 if (!hdr)
6613 return -1;
6614
6615 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6616 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6617
6618 return genlmsg_end(msg, hdr);
6619
6620 nla_put_failure:
6621 genlmsg_cancel(msg, hdr);
6622 return -EMSGSIZE;
6623 }
6624
6625 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
6626 struct net_device *netdev)
6627 {
6628 struct sk_buff *msg;
6629
6630 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6631 if (!msg)
6632 return;
6633
6634 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6635 NL80211_CMD_TRIGGER_SCAN) < 0) {
6636 nlmsg_free(msg);
6637 return;
6638 }
6639
6640 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6641 nl80211_scan_mcgrp.id, GFP_KERNEL);
6642 }
6643
6644 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
6645 struct net_device *netdev)
6646 {
6647 struct sk_buff *msg;
6648
6649 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6650 if (!msg)
6651 return;
6652
6653 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6654 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
6655 nlmsg_free(msg);
6656 return;
6657 }
6658
6659 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6660 nl80211_scan_mcgrp.id, GFP_KERNEL);
6661 }
6662
6663 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
6664 struct net_device *netdev)
6665 {
6666 struct sk_buff *msg;
6667
6668 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6669 if (!msg)
6670 return;
6671
6672 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6673 NL80211_CMD_SCAN_ABORTED) < 0) {
6674 nlmsg_free(msg);
6675 return;
6676 }
6677
6678 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6679 nl80211_scan_mcgrp.id, GFP_KERNEL);
6680 }
6681
6682 void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
6683 struct net_device *netdev)
6684 {
6685 struct sk_buff *msg;
6686
6687 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6688 if (!msg)
6689 return;
6690
6691 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
6692 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
6693 nlmsg_free(msg);
6694 return;
6695 }
6696
6697 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6698 nl80211_scan_mcgrp.id, GFP_KERNEL);
6699 }
6700
6701 void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
6702 struct net_device *netdev, u32 cmd)
6703 {
6704 struct sk_buff *msg;
6705
6706 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6707 if (!msg)
6708 return;
6709
6710 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
6711 nlmsg_free(msg);
6712 return;
6713 }
6714
6715 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6716 nl80211_scan_mcgrp.id, GFP_KERNEL);
6717 }
6718
6719 /*
6720 * This can happen on global regulatory changes or device specific settings
6721 * based on custom world regulatory domains.
6722 */
6723 void nl80211_send_reg_change_event(struct regulatory_request *request)
6724 {
6725 struct sk_buff *msg;
6726 void *hdr;
6727
6728 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6729 if (!msg)
6730 return;
6731
6732 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
6733 if (!hdr) {
6734 nlmsg_free(msg);
6735 return;
6736 }
6737
6738 /* Userspace can always count this one always being set */
6739 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
6740
6741 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
6742 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6743 NL80211_REGDOM_TYPE_WORLD);
6744 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
6745 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6746 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
6747 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
6748 request->intersect)
6749 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6750 NL80211_REGDOM_TYPE_INTERSECTION);
6751 else {
6752 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
6753 NL80211_REGDOM_TYPE_COUNTRY);
6754 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
6755 }
6756
6757 if (wiphy_idx_valid(request->wiphy_idx))
6758 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
6759
6760 genlmsg_end(msg, hdr);
6761
6762 rcu_read_lock();
6763 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
6764 GFP_ATOMIC);
6765 rcu_read_unlock();
6766
6767 return;
6768
6769 nla_put_failure:
6770 genlmsg_cancel(msg, hdr);
6771 nlmsg_free(msg);
6772 }
6773
6774 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
6775 struct net_device *netdev,
6776 const u8 *buf, size_t len,
6777 enum nl80211_commands cmd, gfp_t gfp)
6778 {
6779 struct sk_buff *msg;
6780 void *hdr;
6781
6782 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6783 if (!msg)
6784 return;
6785
6786 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6787 if (!hdr) {
6788 nlmsg_free(msg);
6789 return;
6790 }
6791
6792 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6793 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6794 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6795
6796 genlmsg_end(msg, hdr);
6797
6798 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6799 nl80211_mlme_mcgrp.id, gfp);
6800 return;
6801
6802 nla_put_failure:
6803 genlmsg_cancel(msg, hdr);
6804 nlmsg_free(msg);
6805 }
6806
6807 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
6808 struct net_device *netdev, const u8 *buf,
6809 size_t len, gfp_t gfp)
6810 {
6811 nl80211_send_mlme_event(rdev, netdev, buf, len,
6812 NL80211_CMD_AUTHENTICATE, gfp);
6813 }
6814
6815 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
6816 struct net_device *netdev, const u8 *buf,
6817 size_t len, gfp_t gfp)
6818 {
6819 nl80211_send_mlme_event(rdev, netdev, buf, len,
6820 NL80211_CMD_ASSOCIATE, gfp);
6821 }
6822
6823 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
6824 struct net_device *netdev, const u8 *buf,
6825 size_t len, gfp_t gfp)
6826 {
6827 nl80211_send_mlme_event(rdev, netdev, buf, len,
6828 NL80211_CMD_DEAUTHENTICATE, gfp);
6829 }
6830
6831 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
6832 struct net_device *netdev, const u8 *buf,
6833 size_t len, gfp_t gfp)
6834 {
6835 nl80211_send_mlme_event(rdev, netdev, buf, len,
6836 NL80211_CMD_DISASSOCIATE, gfp);
6837 }
6838
6839 void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
6840 struct net_device *netdev, const u8 *buf,
6841 size_t len, gfp_t gfp)
6842 {
6843 nl80211_send_mlme_event(rdev, netdev, buf, len,
6844 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
6845 }
6846
6847 void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
6848 struct net_device *netdev, const u8 *buf,
6849 size_t len, gfp_t gfp)
6850 {
6851 nl80211_send_mlme_event(rdev, netdev, buf, len,
6852 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
6853 }
6854
6855 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
6856 struct net_device *netdev, int cmd,
6857 const u8 *addr, gfp_t gfp)
6858 {
6859 struct sk_buff *msg;
6860 void *hdr;
6861
6862 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6863 if (!msg)
6864 return;
6865
6866 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
6867 if (!hdr) {
6868 nlmsg_free(msg);
6869 return;
6870 }
6871
6872 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6873 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6874 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
6875 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
6876
6877 genlmsg_end(msg, hdr);
6878
6879 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6880 nl80211_mlme_mcgrp.id, gfp);
6881 return;
6882
6883 nla_put_failure:
6884 genlmsg_cancel(msg, hdr);
6885 nlmsg_free(msg);
6886 }
6887
6888 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
6889 struct net_device *netdev, const u8 *addr,
6890 gfp_t gfp)
6891 {
6892 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
6893 addr, gfp);
6894 }
6895
6896 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
6897 struct net_device *netdev, const u8 *addr,
6898 gfp_t gfp)
6899 {
6900 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
6901 addr, gfp);
6902 }
6903
6904 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
6905 struct net_device *netdev, const u8 *bssid,
6906 const u8 *req_ie, size_t req_ie_len,
6907 const u8 *resp_ie, size_t resp_ie_len,
6908 u16 status, gfp_t gfp)
6909 {
6910 struct sk_buff *msg;
6911 void *hdr;
6912
6913 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6914 if (!msg)
6915 return;
6916
6917 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
6918 if (!hdr) {
6919 nlmsg_free(msg);
6920 return;
6921 }
6922
6923 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6924 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6925 if (bssid)
6926 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6927 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
6928 if (req_ie)
6929 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6930 if (resp_ie)
6931 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6932
6933 genlmsg_end(msg, hdr);
6934
6935 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6936 nl80211_mlme_mcgrp.id, gfp);
6937 return;
6938
6939 nla_put_failure:
6940 genlmsg_cancel(msg, hdr);
6941 nlmsg_free(msg);
6942
6943 }
6944
6945 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
6946 struct net_device *netdev, const u8 *bssid,
6947 const u8 *req_ie, size_t req_ie_len,
6948 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
6949 {
6950 struct sk_buff *msg;
6951 void *hdr;
6952
6953 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6954 if (!msg)
6955 return;
6956
6957 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
6958 if (!hdr) {
6959 nlmsg_free(msg);
6960 return;
6961 }
6962
6963 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6964 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6965 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
6966 if (req_ie)
6967 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
6968 if (resp_ie)
6969 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
6970
6971 genlmsg_end(msg, hdr);
6972
6973 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6974 nl80211_mlme_mcgrp.id, gfp);
6975 return;
6976
6977 nla_put_failure:
6978 genlmsg_cancel(msg, hdr);
6979 nlmsg_free(msg);
6980
6981 }
6982
6983 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
6984 struct net_device *netdev, u16 reason,
6985 const u8 *ie, size_t ie_len, bool from_ap)
6986 {
6987 struct sk_buff *msg;
6988 void *hdr;
6989
6990 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6991 if (!msg)
6992 return;
6993
6994 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
6995 if (!hdr) {
6996 nlmsg_free(msg);
6997 return;
6998 }
6999
7000 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7001 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7002 if (from_ap && reason)
7003 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
7004 if (from_ap)
7005 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
7006 if (ie)
7007 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
7008
7009 genlmsg_end(msg, hdr);
7010
7011 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7012 nl80211_mlme_mcgrp.id, GFP_KERNEL);
7013 return;
7014
7015 nla_put_failure:
7016 genlmsg_cancel(msg, hdr);
7017 nlmsg_free(msg);
7018
7019 }
7020
7021 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7022 struct net_device *netdev, const u8 *bssid,
7023 gfp_t gfp)
7024 {
7025 struct sk_buff *msg;
7026 void *hdr;
7027
7028 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7029 if (!msg)
7030 return;
7031
7032 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7033 if (!hdr) {
7034 nlmsg_free(msg);
7035 return;
7036 }
7037
7038 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7039 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7040 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7041
7042 genlmsg_end(msg, hdr);
7043
7044 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7045 nl80211_mlme_mcgrp.id, gfp);
7046 return;
7047
7048 nla_put_failure:
7049 genlmsg_cancel(msg, hdr);
7050 nlmsg_free(msg);
7051 }
7052
7053 void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7054 struct net_device *netdev,
7055 const u8 *macaddr, const u8* ie, u8 ie_len,
7056 gfp_t gfp)
7057 {
7058 struct sk_buff *msg;
7059 void *hdr;
7060
7061 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7062 if (!msg)
7063 return;
7064
7065 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7066 if (!hdr) {
7067 nlmsg_free(msg);
7068 return;
7069 }
7070
7071 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7072 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7073 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
7074 if (ie_len && ie)
7075 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
7076
7077 genlmsg_end(msg, hdr);
7078
7079 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7080 nl80211_mlme_mcgrp.id, gfp);
7081 return;
7082
7083 nla_put_failure:
7084 genlmsg_cancel(msg, hdr);
7085 nlmsg_free(msg);
7086 }
7087
7088 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7089 struct net_device *netdev, const u8 *addr,
7090 enum nl80211_key_type key_type, int key_id,
7091 const u8 *tsc, gfp_t gfp)
7092 {
7093 struct sk_buff *msg;
7094 void *hdr;
7095
7096 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7097 if (!msg)
7098 return;
7099
7100 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7101 if (!hdr) {
7102 nlmsg_free(msg);
7103 return;
7104 }
7105
7106 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7107 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7108 if (addr)
7109 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7110 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
7111 if (key_id != -1)
7112 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
7113 if (tsc)
7114 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
7115
7116 genlmsg_end(msg, hdr);
7117
7118 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7119 nl80211_mlme_mcgrp.id, gfp);
7120 return;
7121
7122 nla_put_failure:
7123 genlmsg_cancel(msg, hdr);
7124 nlmsg_free(msg);
7125 }
7126
7127 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7128 struct ieee80211_channel *channel_before,
7129 struct ieee80211_channel *channel_after)
7130 {
7131 struct sk_buff *msg;
7132 void *hdr;
7133 struct nlattr *nl_freq;
7134
7135 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
7136 if (!msg)
7137 return;
7138
7139 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7140 if (!hdr) {
7141 nlmsg_free(msg);
7142 return;
7143 }
7144
7145 /*
7146 * Since we are applying the beacon hint to a wiphy we know its
7147 * wiphy_idx is valid
7148 */
7149 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
7150
7151 /* Before */
7152 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7153 if (!nl_freq)
7154 goto nla_put_failure;
7155 if (nl80211_msg_put_channel(msg, channel_before))
7156 goto nla_put_failure;
7157 nla_nest_end(msg, nl_freq);
7158
7159 /* After */
7160 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7161 if (!nl_freq)
7162 goto nla_put_failure;
7163 if (nl80211_msg_put_channel(msg, channel_after))
7164 goto nla_put_failure;
7165 nla_nest_end(msg, nl_freq);
7166
7167 genlmsg_end(msg, hdr);
7168
7169 rcu_read_lock();
7170 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7171 GFP_ATOMIC);
7172 rcu_read_unlock();
7173
7174 return;
7175
7176 nla_put_failure:
7177 genlmsg_cancel(msg, hdr);
7178 nlmsg_free(msg);
7179 }
7180
7181 static void nl80211_send_remain_on_chan_event(
7182 int cmd, struct cfg80211_registered_device *rdev,
7183 struct net_device *netdev, u64 cookie,
7184 struct ieee80211_channel *chan,
7185 enum nl80211_channel_type channel_type,
7186 unsigned int duration, gfp_t gfp)
7187 {
7188 struct sk_buff *msg;
7189 void *hdr;
7190
7191 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7192 if (!msg)
7193 return;
7194
7195 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7196 if (!hdr) {
7197 nlmsg_free(msg);
7198 return;
7199 }
7200
7201 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7202 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7203 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
7204 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
7205 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7206
7207 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
7208 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
7209
7210 genlmsg_end(msg, hdr);
7211
7212 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7213 nl80211_mlme_mcgrp.id, gfp);
7214 return;
7215
7216 nla_put_failure:
7217 genlmsg_cancel(msg, hdr);
7218 nlmsg_free(msg);
7219 }
7220
7221 void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7222 struct net_device *netdev, u64 cookie,
7223 struct ieee80211_channel *chan,
7224 enum nl80211_channel_type channel_type,
7225 unsigned int duration, gfp_t gfp)
7226 {
7227 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7228 rdev, netdev, cookie, chan,
7229 channel_type, duration, gfp);
7230 }
7231
7232 void nl80211_send_remain_on_channel_cancel(
7233 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7234 u64 cookie, struct ieee80211_channel *chan,
7235 enum nl80211_channel_type channel_type, gfp_t gfp)
7236 {
7237 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7238 rdev, netdev, cookie, chan,
7239 channel_type, 0, gfp);
7240 }
7241
7242 void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7243 struct net_device *dev, const u8 *mac_addr,
7244 struct station_info *sinfo, gfp_t gfp)
7245 {
7246 struct sk_buff *msg;
7247
7248 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7249 if (!msg)
7250 return;
7251
7252 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
7253 nlmsg_free(msg);
7254 return;
7255 }
7256
7257 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7258 nl80211_mlme_mcgrp.id, gfp);
7259 }
7260
7261 void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7262 struct net_device *dev, const u8 *mac_addr,
7263 gfp_t gfp)
7264 {
7265 struct sk_buff *msg;
7266 void *hdr;
7267
7268 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7269 if (!msg)
7270 return;
7271
7272 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7273 if (!hdr) {
7274 nlmsg_free(msg);
7275 return;
7276 }
7277
7278 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7279 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
7280
7281 genlmsg_end(msg, hdr);
7282
7283 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7284 nl80211_mlme_mcgrp.id, gfp);
7285 return;
7286
7287 nla_put_failure:
7288 genlmsg_cancel(msg, hdr);
7289 nlmsg_free(msg);
7290 }
7291
7292 bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7293 {
7294 struct wireless_dev *wdev = dev->ieee80211_ptr;
7295 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7296 struct sk_buff *msg;
7297 void *hdr;
7298 int err;
7299 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7300
7301 if (!nlpid)
7302 return false;
7303
7304 msg = nlmsg_new(100, gfp);
7305 if (!msg)
7306 return true;
7307
7308 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_UNEXPECTED_FRAME);
7309 if (!hdr) {
7310 nlmsg_free(msg);
7311 return true;
7312 }
7313
7314 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7315 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7316 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7317
7318 err = genlmsg_end(msg, hdr);
7319 if (err < 0) {
7320 nlmsg_free(msg);
7321 return true;
7322 }
7323
7324 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7325 return true;
7326
7327 nla_put_failure:
7328 genlmsg_cancel(msg, hdr);
7329 nlmsg_free(msg);
7330 return true;
7331 }
7332
7333 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7334 struct net_device *netdev, u32 nlpid,
7335 int freq, const u8 *buf, size_t len, gfp_t gfp)
7336 {
7337 struct sk_buff *msg;
7338 void *hdr;
7339
7340 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7341 if (!msg)
7342 return -ENOMEM;
7343
7344 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
7345 if (!hdr) {
7346 nlmsg_free(msg);
7347 return -ENOMEM;
7348 }
7349
7350 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7351 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7352 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7353 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7354
7355 genlmsg_end(msg, hdr);
7356
7357 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7358
7359 nla_put_failure:
7360 genlmsg_cancel(msg, hdr);
7361 nlmsg_free(msg);
7362 return -ENOBUFS;
7363 }
7364
7365 void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7366 struct net_device *netdev, u64 cookie,
7367 const u8 *buf, size_t len, bool ack,
7368 gfp_t gfp)
7369 {
7370 struct sk_buff *msg;
7371 void *hdr;
7372
7373 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7374 if (!msg)
7375 return;
7376
7377 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
7378 if (!hdr) {
7379 nlmsg_free(msg);
7380 return;
7381 }
7382
7383 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7384 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7385 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7386 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7387 if (ack)
7388 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7389
7390 genlmsg_end(msg, hdr);
7391
7392 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
7393 return;
7394
7395 nla_put_failure:
7396 genlmsg_cancel(msg, hdr);
7397 nlmsg_free(msg);
7398 }
7399
7400 void
7401 nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
7402 struct net_device *netdev,
7403 enum nl80211_cqm_rssi_threshold_event rssi_event,
7404 gfp_t gfp)
7405 {
7406 struct sk_buff *msg;
7407 struct nlattr *pinfoattr;
7408 void *hdr;
7409
7410 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7411 if (!msg)
7412 return;
7413
7414 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7415 if (!hdr) {
7416 nlmsg_free(msg);
7417 return;
7418 }
7419
7420 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7421 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7422
7423 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7424 if (!pinfoattr)
7425 goto nla_put_failure;
7426
7427 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
7428 rssi_event);
7429
7430 nla_nest_end(msg, pinfoattr);
7431
7432 genlmsg_end(msg, hdr);
7433
7434 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7435 nl80211_mlme_mcgrp.id, gfp);
7436 return;
7437
7438 nla_put_failure:
7439 genlmsg_cancel(msg, hdr);
7440 nlmsg_free(msg);
7441 }
7442
7443 void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
7444 struct net_device *netdev, const u8 *bssid,
7445 const u8 *replay_ctr, gfp_t gfp)
7446 {
7447 struct sk_buff *msg;
7448 struct nlattr *rekey_attr;
7449 void *hdr;
7450
7451 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7452 if (!msg)
7453 return;
7454
7455 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
7456 if (!hdr) {
7457 nlmsg_free(msg);
7458 return;
7459 }
7460
7461 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7462 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7463 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7464
7465 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
7466 if (!rekey_attr)
7467 goto nla_put_failure;
7468
7469 NLA_PUT(msg, NL80211_REKEY_DATA_REPLAY_CTR,
7470 NL80211_REPLAY_CTR_LEN, replay_ctr);
7471
7472 nla_nest_end(msg, rekey_attr);
7473
7474 genlmsg_end(msg, hdr);
7475
7476 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7477 nl80211_mlme_mcgrp.id, gfp);
7478 return;
7479
7480 nla_put_failure:
7481 genlmsg_cancel(msg, hdr);
7482 nlmsg_free(msg);
7483 }
7484
7485 void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
7486 struct net_device *netdev, int index,
7487 const u8 *bssid, bool preauth, gfp_t gfp)
7488 {
7489 struct sk_buff *msg;
7490 struct nlattr *attr;
7491 void *hdr;
7492
7493 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7494 if (!msg)
7495 return;
7496
7497 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
7498 if (!hdr) {
7499 nlmsg_free(msg);
7500 return;
7501 }
7502
7503 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7504 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7505
7506 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
7507 if (!attr)
7508 goto nla_put_failure;
7509
7510 NLA_PUT_U32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index);
7511 NLA_PUT(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid);
7512 if (preauth)
7513 NLA_PUT_FLAG(msg, NL80211_PMKSA_CANDIDATE_PREAUTH);
7514
7515 nla_nest_end(msg, attr);
7516
7517 genlmsg_end(msg, hdr);
7518
7519 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7520 nl80211_mlme_mcgrp.id, gfp);
7521 return;
7522
7523 nla_put_failure:
7524 genlmsg_cancel(msg, hdr);
7525 nlmsg_free(msg);
7526 }
7527
7528 void
7529 nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
7530 struct net_device *netdev, const u8 *peer,
7531 u32 num_packets, gfp_t gfp)
7532 {
7533 struct sk_buff *msg;
7534 struct nlattr *pinfoattr;
7535 void *hdr;
7536
7537 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7538 if (!msg)
7539 return;
7540
7541 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7542 if (!hdr) {
7543 nlmsg_free(msg);
7544 return;
7545 }
7546
7547 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7548 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7549 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
7550
7551 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7552 if (!pinfoattr)
7553 goto nla_put_failure;
7554
7555 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
7556
7557 nla_nest_end(msg, pinfoattr);
7558
7559 genlmsg_end(msg, hdr);
7560
7561 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7562 nl80211_mlme_mcgrp.id, gfp);
7563 return;
7564
7565 nla_put_failure:
7566 genlmsg_cancel(msg, hdr);
7567 nlmsg_free(msg);
7568 }
7569
7570 void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
7571 u64 cookie, bool acked, gfp_t gfp)
7572 {
7573 struct wireless_dev *wdev = dev->ieee80211_ptr;
7574 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7575 struct sk_buff *msg;
7576 void *hdr;
7577 int err;
7578
7579 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7580 if (!msg)
7581 return;
7582
7583 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
7584 if (!hdr) {
7585 nlmsg_free(msg);
7586 return;
7587 }
7588
7589 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7590 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7591 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7592 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7593 if (acked)
7594 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7595
7596 err = genlmsg_end(msg, hdr);
7597 if (err < 0) {
7598 nlmsg_free(msg);
7599 return;
7600 }
7601
7602 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7603 nl80211_mlme_mcgrp.id, gfp);
7604 return;
7605
7606 nla_put_failure:
7607 genlmsg_cancel(msg, hdr);
7608 nlmsg_free(msg);
7609 }
7610 EXPORT_SYMBOL(cfg80211_probe_status);
7611
7612 void cfg80211_report_obss_beacon(struct wiphy *wiphy,
7613 const u8 *frame, size_t len,
7614 int freq, gfp_t gfp)
7615 {
7616 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
7617 struct sk_buff *msg;
7618 void *hdr;
7619 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
7620
7621 if (!nlpid)
7622 return;
7623
7624 msg = nlmsg_new(len + 100, gfp);
7625 if (!msg)
7626 return;
7627
7628 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
7629 if (!hdr) {
7630 nlmsg_free(msg);
7631 return;
7632 }
7633
7634 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7635 if (freq)
7636 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7637 NLA_PUT(msg, NL80211_ATTR_FRAME, len, frame);
7638
7639 genlmsg_end(msg, hdr);
7640
7641 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7642 return;
7643
7644 nla_put_failure:
7645 genlmsg_cancel(msg, hdr);
7646 nlmsg_free(msg);
7647 }
7648 EXPORT_SYMBOL(cfg80211_report_obss_beacon);
7649
7650 static int nl80211_netlink_notify(struct notifier_block * nb,
7651 unsigned long state,
7652 void *_notify)
7653 {
7654 struct netlink_notify *notify = _notify;
7655 struct cfg80211_registered_device *rdev;
7656 struct wireless_dev *wdev;
7657
7658 if (state != NETLINK_URELEASE)
7659 return NOTIFY_DONE;
7660
7661 rcu_read_lock();
7662
7663 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
7664 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
7665 cfg80211_mlme_unregister_socket(wdev, notify->pid);
7666 if (rdev->ap_beacons_nlpid == notify->pid)
7667 rdev->ap_beacons_nlpid = 0;
7668 }
7669
7670 rcu_read_unlock();
7671
7672 return NOTIFY_DONE;
7673 }
7674
7675 static struct notifier_block nl80211_netlink_notifier = {
7676 .notifier_call = nl80211_netlink_notify,
7677 };
7678
7679 /* initialisation/exit functions */
7680
7681 int nl80211_init(void)
7682 {
7683 int err;
7684
7685 err = genl_register_family_with_ops(&nl80211_fam,
7686 nl80211_ops, ARRAY_SIZE(nl80211_ops));
7687 if (err)
7688 return err;
7689
7690 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
7691 if (err)
7692 goto err_out;
7693
7694 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
7695 if (err)
7696 goto err_out;
7697
7698 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
7699 if (err)
7700 goto err_out;
7701
7702 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
7703 if (err)
7704 goto err_out;
7705
7706 #ifdef CONFIG_NL80211_TESTMODE
7707 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
7708 if (err)
7709 goto err_out;
7710 #endif
7711
7712 err = netlink_register_notifier(&nl80211_netlink_notifier);
7713 if (err)
7714 goto err_out;
7715
7716 return 0;
7717 err_out:
7718 genl_unregister_family(&nl80211_fam);
7719 return err;
7720 }
7721
7722 void nl80211_exit(void)
7723 {
7724 netlink_unregister_notifier(&nl80211_netlink_notifier);
7725 genl_unregister_family(&nl80211_fam);
7726 }
This page took 0.218097 seconds and 5 git commands to generate.