ath9k_htc: Handle BSSID/AID for multiple interfaces
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
4c476991
JB
26static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27 struct genl_info *info);
28static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29 struct genl_info *info);
30
55682965
JB
31/* the netlink family */
32static struct genl_family nl80211_fam = {
33 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34 .name = "nl80211", /* have users key off the name instead */
35 .hdrsize = 0, /* no private header */
36 .version = 1, /* no particular meaning now */
37 .maxattr = NL80211_ATTR_MAX,
463d0183 38 .netnsok = true,
4c476991
JB
39 .pre_doit = nl80211_pre_doit,
40 .post_doit = nl80211_post_doit,
55682965
JB
41};
42
79c97e97 43/* internal helper: get rdev and dev */
463d0183 44static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 45 struct cfg80211_registered_device **rdev,
55682965
JB
46 struct net_device **dev)
47{
463d0183 48 struct nlattr **attrs = info->attrs;
55682965
JB
49 int ifindex;
50
bba95fef 51 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
52 return -EINVAL;
53
bba95fef 54 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 55 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
56 if (!*dev)
57 return -ENODEV;
58
463d0183 59 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 60 if (IS_ERR(*rdev)) {
55682965 61 dev_put(*dev);
79c97e97 62 return PTR_ERR(*rdev);
55682965
JB
63 }
64
65 return 0;
66}
67
68/* policy for the attributes */
b54452b0 69static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
70 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 72 .len = 20-1 },
31888487 73 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 74 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 75 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
76 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 80 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
81
82 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
85
86 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 87 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 88
b9454e83 89 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
90 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91 .len = WLAN_MAX_KEY_LEN },
92 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 95 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
e31b8213 96 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
97
98 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101 .len = IEEE80211_MAX_DATA_LEN },
102 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
104 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 109 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 110 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 111 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
112 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113 .len = IEEE80211_MAX_MESH_ID_LEN },
114 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 115
b2e1b302
LR
116 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
9f1ba906
JM
119 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
122 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123 .len = NL80211_MAX_SUPP_RATES },
50b12f59 124 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 125
24bdd9f4 126 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
93da9cc1 127
36aedc90
JM
128 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
129 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
130
131 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
132 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
133 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
134 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
135 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
136
137 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
138 .len = IEEE80211_MAX_SSID_LEN },
139 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
140 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 141 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 142 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 143 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
144 [NL80211_ATTR_STA_FLAGS2] = {
145 .len = sizeof(struct nl80211_sta_flag_update),
146 },
3f77316c 147 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
148 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
149 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
150 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
151 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
152 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 153 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 154 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
155 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
156 .len = WLAN_PMKID_LEN },
9588bbd5
JM
157 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
158 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 159 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
160 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
161 .len = IEEE80211_MAX_DATA_LEN },
162 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 163 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 164 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 165 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 166 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
167 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
168 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 169 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
170 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
171 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 172 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 173 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 174 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
55682965
JB
175};
176
e31b8213 177/* policy for the key attributes */
b54452b0 178static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 179 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
180 [NL80211_KEY_IDX] = { .type = NLA_U8 },
181 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
182 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
183 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
184 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 185 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
186 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
187};
188
189/* policy for the key default flags */
190static const struct nla_policy
191nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
192 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
193 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
194};
195
a043897a
HS
196/* ifidx get helper */
197static int nl80211_get_ifidx(struct netlink_callback *cb)
198{
199 int res;
200
201 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
202 nl80211_fam.attrbuf, nl80211_fam.maxattr,
203 nl80211_policy);
204 if (res)
205 return res;
206
207 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
208 return -EINVAL;
209
210 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
211 if (!res)
212 return -EINVAL;
213 return res;
214}
215
67748893
JB
216static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
217 struct netlink_callback *cb,
218 struct cfg80211_registered_device **rdev,
219 struct net_device **dev)
220{
221 int ifidx = cb->args[0];
222 int err;
223
224 if (!ifidx)
225 ifidx = nl80211_get_ifidx(cb);
226 if (ifidx < 0)
227 return ifidx;
228
229 cb->args[0] = ifidx;
230
231 rtnl_lock();
232
233 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
234 if (!*dev) {
235 err = -ENODEV;
236 goto out_rtnl;
237 }
238
239 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
240 if (IS_ERR(*rdev)) {
241 err = PTR_ERR(*rdev);
67748893
JB
242 goto out_rtnl;
243 }
244
245 return 0;
246 out_rtnl:
247 rtnl_unlock();
248 return err;
249}
250
251static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
252{
253 cfg80211_unlock_rdev(rdev);
254 rtnl_unlock();
255}
256
f4a11bb0
JB
257/* IE validation */
258static bool is_valid_ie_attr(const struct nlattr *attr)
259{
260 const u8 *pos;
261 int len;
262
263 if (!attr)
264 return true;
265
266 pos = nla_data(attr);
267 len = nla_len(attr);
268
269 while (len) {
270 u8 elemlen;
271
272 if (len < 2)
273 return false;
274 len -= 2;
275
276 elemlen = pos[1];
277 if (elemlen > len)
278 return false;
279
280 len -= elemlen;
281 pos += 2 + elemlen;
282 }
283
284 return true;
285}
286
55682965
JB
287/* message building helper */
288static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
289 int flags, u8 cmd)
290{
291 /* since there is no private header just add the generic one */
292 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
293}
294
5dab3b8a
LR
295static int nl80211_msg_put_channel(struct sk_buff *msg,
296 struct ieee80211_channel *chan)
297{
298 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
299 chan->center_freq);
300
301 if (chan->flags & IEEE80211_CHAN_DISABLED)
302 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
303 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
304 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
305 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
306 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
307 if (chan->flags & IEEE80211_CHAN_RADAR)
308 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
309
310 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
311 DBM_TO_MBM(chan->max_power));
312
313 return 0;
314
315 nla_put_failure:
316 return -ENOBUFS;
317}
318
55682965
JB
319/* netlink command implementations */
320
b9454e83
JB
321struct key_parse {
322 struct key_params p;
323 int idx;
e31b8213 324 int type;
b9454e83 325 bool def, defmgmt;
dbd2fd65 326 bool def_uni, def_multi;
b9454e83
JB
327};
328
329static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
330{
331 struct nlattr *tb[NL80211_KEY_MAX + 1];
332 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
333 nl80211_key_policy);
334 if (err)
335 return err;
336
337 k->def = !!tb[NL80211_KEY_DEFAULT];
338 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
339
dbd2fd65
JB
340 if (k->def) {
341 k->def_uni = true;
342 k->def_multi = true;
343 }
344 if (k->defmgmt)
345 k->def_multi = true;
346
b9454e83
JB
347 if (tb[NL80211_KEY_IDX])
348 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
349
350 if (tb[NL80211_KEY_DATA]) {
351 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
352 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
353 }
354
355 if (tb[NL80211_KEY_SEQ]) {
356 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
357 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
358 }
359
360 if (tb[NL80211_KEY_CIPHER])
361 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
362
e31b8213
JB
363 if (tb[NL80211_KEY_TYPE]) {
364 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
365 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
366 return -EINVAL;
367 }
368
dbd2fd65
JB
369 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
370 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
371 int err = nla_parse_nested(kdt,
372 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
373 tb[NL80211_KEY_DEFAULT_TYPES],
374 nl80211_key_default_policy);
375 if (err)
376 return err;
377
378 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
379 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
380 }
381
b9454e83
JB
382 return 0;
383}
384
385static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
386{
387 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
388 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
389 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
390 }
391
392 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
393 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
394 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
395 }
396
397 if (info->attrs[NL80211_ATTR_KEY_IDX])
398 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
399
400 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
401 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
402
403 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
404 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
405
dbd2fd65
JB
406 if (k->def) {
407 k->def_uni = true;
408 k->def_multi = true;
409 }
410 if (k->defmgmt)
411 k->def_multi = true;
412
e31b8213
JB
413 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
414 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
415 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
416 return -EINVAL;
417 }
418
dbd2fd65
JB
419 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
420 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
421 int err = nla_parse_nested(
422 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
423 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
424 nl80211_key_default_policy);
425 if (err)
426 return err;
427
428 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
429 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
430 }
431
b9454e83
JB
432 return 0;
433}
434
435static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
436{
437 int err;
438
439 memset(k, 0, sizeof(*k));
440 k->idx = -1;
e31b8213 441 k->type = -1;
b9454e83
JB
442
443 if (info->attrs[NL80211_ATTR_KEY])
444 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
445 else
446 err = nl80211_parse_key_old(info, k);
447
448 if (err)
449 return err;
450
451 if (k->def && k->defmgmt)
452 return -EINVAL;
453
dbd2fd65
JB
454 if (k->defmgmt) {
455 if (k->def_uni || !k->def_multi)
456 return -EINVAL;
457 }
458
b9454e83
JB
459 if (k->idx != -1) {
460 if (k->defmgmt) {
461 if (k->idx < 4 || k->idx > 5)
462 return -EINVAL;
463 } else if (k->def) {
464 if (k->idx < 0 || k->idx > 3)
465 return -EINVAL;
466 } else {
467 if (k->idx < 0 || k->idx > 5)
468 return -EINVAL;
469 }
470 }
471
472 return 0;
473}
474
fffd0934
JB
475static struct cfg80211_cached_keys *
476nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
477 struct nlattr *keys)
478{
479 struct key_parse parse;
480 struct nlattr *key;
481 struct cfg80211_cached_keys *result;
482 int rem, err, def = 0;
483
484 result = kzalloc(sizeof(*result), GFP_KERNEL);
485 if (!result)
486 return ERR_PTR(-ENOMEM);
487
488 result->def = -1;
489 result->defmgmt = -1;
490
491 nla_for_each_nested(key, keys, rem) {
492 memset(&parse, 0, sizeof(parse));
493 parse.idx = -1;
494
495 err = nl80211_parse_key_new(key, &parse);
496 if (err)
497 goto error;
498 err = -EINVAL;
499 if (!parse.p.key)
500 goto error;
501 if (parse.idx < 0 || parse.idx > 4)
502 goto error;
503 if (parse.def) {
504 if (def)
505 goto error;
506 def = 1;
507 result->def = parse.idx;
dbd2fd65
JB
508 if (!parse.def_uni || !parse.def_multi)
509 goto error;
fffd0934
JB
510 } else if (parse.defmgmt)
511 goto error;
512 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 513 parse.idx, false, NULL);
fffd0934
JB
514 if (err)
515 goto error;
516 result->params[parse.idx].cipher = parse.p.cipher;
517 result->params[parse.idx].key_len = parse.p.key_len;
518 result->params[parse.idx].key = result->data[parse.idx];
519 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
520 }
521
522 return result;
523 error:
524 kfree(result);
525 return ERR_PTR(err);
526}
527
528static int nl80211_key_allowed(struct wireless_dev *wdev)
529{
530 ASSERT_WDEV_LOCK(wdev);
531
fffd0934
JB
532 switch (wdev->iftype) {
533 case NL80211_IFTYPE_AP:
534 case NL80211_IFTYPE_AP_VLAN:
074ac8df 535 case NL80211_IFTYPE_P2P_GO:
fffd0934
JB
536 break;
537 case NL80211_IFTYPE_ADHOC:
538 if (!wdev->current_bss)
539 return -ENOLINK;
540 break;
541 case NL80211_IFTYPE_STATION:
074ac8df 542 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
543 if (wdev->sme_state != CFG80211_SME_CONNECTED)
544 return -ENOLINK;
545 break;
546 default:
547 return -EINVAL;
548 }
549
550 return 0;
551}
552
55682965
JB
553static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
554 struct cfg80211_registered_device *dev)
555{
556 void *hdr;
ee688b00
JB
557 struct nlattr *nl_bands, *nl_band;
558 struct nlattr *nl_freqs, *nl_freq;
559 struct nlattr *nl_rates, *nl_rate;
f59ac048 560 struct nlattr *nl_modes;
8fdc621d 561 struct nlattr *nl_cmds;
ee688b00
JB
562 enum ieee80211_band band;
563 struct ieee80211_channel *chan;
564 struct ieee80211_rate *rate;
565 int i;
f59ac048 566 u16 ifmodes = dev->wiphy.interface_modes;
2e161f78
JB
567 const struct ieee80211_txrx_stypes *mgmt_stypes =
568 dev->wiphy.mgmt_stypes;
55682965
JB
569
570 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
571 if (!hdr)
572 return -1;
573
b5850a7a 574 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 575 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 576
f5ea9120
JB
577 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
578 cfg80211_rdev_list_generation);
579
b9a5f8ca
JM
580 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
581 dev->wiphy.retry_short);
582 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
583 dev->wiphy.retry_long);
584 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
585 dev->wiphy.frag_threshold);
586 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
587 dev->wiphy.rts_threshold);
81077e82
LT
588 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
589 dev->wiphy.coverage_class);
2a519311
JB
590 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
591 dev->wiphy.max_scan_ssids);
18a83659
JB
592 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
593 dev->wiphy.max_scan_ie_len);
ee688b00 594
e31b8213
JB
595 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
596 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
597
25e47c18
JB
598 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
599 sizeof(u32) * dev->wiphy.n_cipher_suites,
600 dev->wiphy.cipher_suites);
601
67fbb16b
SO
602 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
603 dev->wiphy.max_num_pmkids);
604
c0692b8f
JB
605 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
606 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
607
39fd5de4
BR
608 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
609 dev->wiphy.available_antennas_tx);
610 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
611 dev->wiphy.available_antennas_rx);
612
7f531e03
BR
613 if ((dev->wiphy.available_antennas_tx ||
614 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
615 u32 tx_ant = 0, rx_ant = 0;
616 int res;
617 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
618 if (!res) {
619 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
620 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
621 }
622 }
623
f59ac048
LR
624 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
625 if (!nl_modes)
626 goto nla_put_failure;
627
628 i = 0;
629 while (ifmodes) {
630 if (ifmodes & 1)
631 NLA_PUT_FLAG(msg, i);
632 ifmodes >>= 1;
633 i++;
634 }
635
636 nla_nest_end(msg, nl_modes);
637
ee688b00
JB
638 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
639 if (!nl_bands)
640 goto nla_put_failure;
641
642 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
643 if (!dev->wiphy.bands[band])
644 continue;
645
646 nl_band = nla_nest_start(msg, band);
647 if (!nl_band)
648 goto nla_put_failure;
649
d51626df
JB
650 /* add HT info */
651 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
652 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
653 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
654 &dev->wiphy.bands[band]->ht_cap.mcs);
655 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
656 dev->wiphy.bands[band]->ht_cap.cap);
657 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
658 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
659 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
660 dev->wiphy.bands[band]->ht_cap.ampdu_density);
661 }
662
ee688b00
JB
663 /* add frequencies */
664 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
665 if (!nl_freqs)
666 goto nla_put_failure;
667
668 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
669 nl_freq = nla_nest_start(msg, i);
670 if (!nl_freq)
671 goto nla_put_failure;
672
673 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
674
675 if (nl80211_msg_put_channel(msg, chan))
676 goto nla_put_failure;
e2f367f2 677
ee688b00
JB
678 nla_nest_end(msg, nl_freq);
679 }
680
681 nla_nest_end(msg, nl_freqs);
682
683 /* add bitrates */
684 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
685 if (!nl_rates)
686 goto nla_put_failure;
687
688 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
689 nl_rate = nla_nest_start(msg, i);
690 if (!nl_rate)
691 goto nla_put_failure;
692
693 rate = &dev->wiphy.bands[band]->bitrates[i];
694 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
695 rate->bitrate);
696 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
697 NLA_PUT_FLAG(msg,
698 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
699
700 nla_nest_end(msg, nl_rate);
701 }
702
703 nla_nest_end(msg, nl_rates);
704
705 nla_nest_end(msg, nl_band);
706 }
707 nla_nest_end(msg, nl_bands);
708
8fdc621d
JB
709 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
710 if (!nl_cmds)
711 goto nla_put_failure;
712
713 i = 0;
714#define CMD(op, n) \
715 do { \
716 if (dev->ops->op) { \
717 i++; \
718 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
719 } \
720 } while (0)
721
722 CMD(add_virtual_intf, NEW_INTERFACE);
723 CMD(change_virtual_intf, SET_INTERFACE);
724 CMD(add_key, NEW_KEY);
725 CMD(add_beacon, NEW_BEACON);
726 CMD(add_station, NEW_STATION);
727 CMD(add_mpath, NEW_MPATH);
24bdd9f4 728 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 729 CMD(change_bss, SET_BSS);
636a5d36
JM
730 CMD(auth, AUTHENTICATE);
731 CMD(assoc, ASSOCIATE);
732 CMD(deauth, DEAUTHENTICATE);
733 CMD(disassoc, DISASSOCIATE);
04a773ad 734 CMD(join_ibss, JOIN_IBSS);
29cbe68c 735 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
736 CMD(set_pmksa, SET_PMKSA);
737 CMD(del_pmksa, DEL_PMKSA);
738 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 739 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 740 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 741 CMD(mgmt_tx, FRAME);
f7ca38df 742 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 743 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
744 i++;
745 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
746 }
f444de05 747 CMD(set_channel, SET_CHANNEL);
e8347eba 748 CMD(set_wds_peer, SET_WDS_PEER);
8fdc621d
JB
749
750#undef CMD
b23aa676 751
6829c878 752 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
753 i++;
754 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
755 }
756
6829c878 757 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
758 i++;
759 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
760 }
761
8fdc621d
JB
762 nla_nest_end(msg, nl_cmds);
763
a293911d
JB
764 if (dev->ops->remain_on_channel)
765 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
766 dev->wiphy.max_remain_on_channel_duration);
767
f7ca38df
JB
768 /* for now at least assume all drivers have it */
769 if (dev->ops->mgmt_tx)
770 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
771
2e161f78
JB
772 if (mgmt_stypes) {
773 u16 stypes;
774 struct nlattr *nl_ftypes, *nl_ifs;
775 enum nl80211_iftype ift;
776
777 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
778 if (!nl_ifs)
779 goto nla_put_failure;
780
781 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
782 nl_ftypes = nla_nest_start(msg, ift);
783 if (!nl_ftypes)
784 goto nla_put_failure;
785 i = 0;
786 stypes = mgmt_stypes[ift].tx;
787 while (stypes) {
788 if (stypes & 1)
789 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
790 (i << 4) | IEEE80211_FTYPE_MGMT);
791 stypes >>= 1;
792 i++;
793 }
794 nla_nest_end(msg, nl_ftypes);
795 }
796
74b70a4e
JB
797 nla_nest_end(msg, nl_ifs);
798
2e161f78
JB
799 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
800 if (!nl_ifs)
801 goto nla_put_failure;
802
803 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
804 nl_ftypes = nla_nest_start(msg, ift);
805 if (!nl_ftypes)
806 goto nla_put_failure;
807 i = 0;
808 stypes = mgmt_stypes[ift].rx;
809 while (stypes) {
810 if (stypes & 1)
811 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
812 (i << 4) | IEEE80211_FTYPE_MGMT);
813 stypes >>= 1;
814 i++;
815 }
816 nla_nest_end(msg, nl_ftypes);
817 }
818 nla_nest_end(msg, nl_ifs);
819 }
820
55682965
JB
821 return genlmsg_end(msg, hdr);
822
823 nla_put_failure:
bc3ed28c
TG
824 genlmsg_cancel(msg, hdr);
825 return -EMSGSIZE;
55682965
JB
826}
827
828static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
829{
830 int idx = 0;
831 int start = cb->args[0];
832 struct cfg80211_registered_device *dev;
833
a1794390 834 mutex_lock(&cfg80211_mutex);
79c97e97 835 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
836 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
837 continue;
b4637271 838 if (++idx <= start)
55682965
JB
839 continue;
840 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
841 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
842 dev) < 0) {
843 idx--;
55682965 844 break;
b4637271 845 }
55682965 846 }
a1794390 847 mutex_unlock(&cfg80211_mutex);
55682965
JB
848
849 cb->args[0] = idx;
850
851 return skb->len;
852}
853
854static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
855{
856 struct sk_buff *msg;
4c476991 857 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 858
fd2120ca 859 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 860 if (!msg)
4c476991 861 return -ENOMEM;
55682965 862
4c476991
JB
863 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
864 nlmsg_free(msg);
865 return -ENOBUFS;
866 }
55682965 867
134e6375 868 return genlmsg_reply(msg, info);
55682965
JB
869}
870
31888487
JM
871static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
872 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
873 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
874 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
875 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
876 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
877};
878
879static int parse_txq_params(struct nlattr *tb[],
880 struct ieee80211_txq_params *txq_params)
881{
882 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
883 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
884 !tb[NL80211_TXQ_ATTR_AIFS])
885 return -EINVAL;
886
887 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
888 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
889 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
890 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
891 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
892
893 return 0;
894}
895
f444de05
JB
896static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
897{
898 /*
899 * You can only set the channel explicitly for AP, mesh
900 * and WDS type interfaces; all others have their channel
901 * managed via their respective "establish a connection"
902 * command (connect, join, ...)
903 *
904 * Monitors are special as they are normally slaved to
905 * whatever else is going on, so they behave as though
906 * you tried setting the wiphy channel itself.
907 */
908 return !wdev ||
909 wdev->iftype == NL80211_IFTYPE_AP ||
910 wdev->iftype == NL80211_IFTYPE_WDS ||
911 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
912 wdev->iftype == NL80211_IFTYPE_MONITOR ||
913 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
914}
915
916static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
917 struct wireless_dev *wdev,
918 struct genl_info *info)
919{
920 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
921 u32 freq;
922 int result;
923
924 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
925 return -EINVAL;
926
927 if (!nl80211_can_set_dev_channel(wdev))
928 return -EOPNOTSUPP;
929
930 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
931 channel_type = nla_get_u32(info->attrs[
932 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
933 if (channel_type != NL80211_CHAN_NO_HT &&
934 channel_type != NL80211_CHAN_HT20 &&
935 channel_type != NL80211_CHAN_HT40PLUS &&
936 channel_type != NL80211_CHAN_HT40MINUS)
937 return -EINVAL;
938 }
939
940 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
941
942 mutex_lock(&rdev->devlist_mtx);
943 if (wdev) {
944 wdev_lock(wdev);
945 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
946 wdev_unlock(wdev);
947 } else {
948 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
949 }
950 mutex_unlock(&rdev->devlist_mtx);
951
952 return result;
953}
954
955static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
956{
4c476991
JB
957 struct cfg80211_registered_device *rdev = info->user_ptr[0];
958 struct net_device *netdev = info->user_ptr[1];
f444de05 959
4c476991 960 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
961}
962
e8347eba
BJ
963static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
964{
43b19952
JB
965 struct cfg80211_registered_device *rdev = info->user_ptr[0];
966 struct net_device *dev = info->user_ptr[1];
967 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 968 const u8 *bssid;
e8347eba
BJ
969
970 if (!info->attrs[NL80211_ATTR_MAC])
971 return -EINVAL;
972
43b19952
JB
973 if (netif_running(dev))
974 return -EBUSY;
e8347eba 975
43b19952
JB
976 if (!rdev->ops->set_wds_peer)
977 return -EOPNOTSUPP;
e8347eba 978
43b19952
JB
979 if (wdev->iftype != NL80211_IFTYPE_WDS)
980 return -EOPNOTSUPP;
e8347eba
BJ
981
982 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 983 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
984}
985
986
55682965
JB
987static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
988{
989 struct cfg80211_registered_device *rdev;
f444de05
JB
990 struct net_device *netdev = NULL;
991 struct wireless_dev *wdev;
a1e567c8 992 int result = 0, rem_txq_params = 0;
31888487 993 struct nlattr *nl_txq_params;
b9a5f8ca
JM
994 u32 changed;
995 u8 retry_short = 0, retry_long = 0;
996 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 997 u8 coverage_class = 0;
55682965 998
f444de05
JB
999 /*
1000 * Try to find the wiphy and netdev. Normally this
1001 * function shouldn't need the netdev, but this is
1002 * done for backward compatibility -- previously
1003 * setting the channel was done per wiphy, but now
1004 * it is per netdev. Previous userland like hostapd
1005 * also passed a netdev to set_wiphy, so that it is
1006 * possible to let that go to the right netdev!
1007 */
4bbf4d56
JB
1008 mutex_lock(&cfg80211_mutex);
1009
f444de05
JB
1010 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1011 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1012
1013 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1014 if (netdev && netdev->ieee80211_ptr) {
1015 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1016 mutex_lock(&rdev->mtx);
1017 } else
1018 netdev = NULL;
4bbf4d56
JB
1019 }
1020
f444de05
JB
1021 if (!netdev) {
1022 rdev = __cfg80211_rdev_from_info(info);
1023 if (IS_ERR(rdev)) {
1024 mutex_unlock(&cfg80211_mutex);
4c476991 1025 return PTR_ERR(rdev);
f444de05
JB
1026 }
1027 wdev = NULL;
1028 netdev = NULL;
1029 result = 0;
1030
1031 mutex_lock(&rdev->mtx);
1032 } else if (netif_running(netdev) &&
1033 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1034 wdev = netdev->ieee80211_ptr;
1035 else
1036 wdev = NULL;
1037
1038 /*
1039 * end workaround code, by now the rdev is available
1040 * and locked, and wdev may or may not be NULL.
1041 */
4bbf4d56
JB
1042
1043 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1044 result = cfg80211_dev_rename(
1045 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1046
1047 mutex_unlock(&cfg80211_mutex);
1048
1049 if (result)
1050 goto bad_res;
31888487
JM
1051
1052 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1053 struct ieee80211_txq_params txq_params;
1054 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1055
1056 if (!rdev->ops->set_txq_params) {
1057 result = -EOPNOTSUPP;
1058 goto bad_res;
1059 }
1060
1061 nla_for_each_nested(nl_txq_params,
1062 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1063 rem_txq_params) {
1064 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1065 nla_data(nl_txq_params),
1066 nla_len(nl_txq_params),
1067 txq_params_policy);
1068 result = parse_txq_params(tb, &txq_params);
1069 if (result)
1070 goto bad_res;
1071
1072 result = rdev->ops->set_txq_params(&rdev->wiphy,
1073 &txq_params);
1074 if (result)
1075 goto bad_res;
1076 }
1077 }
55682965 1078
72bdcf34 1079 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1080 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1081 if (result)
1082 goto bad_res;
1083 }
1084
98d2ff8b
JO
1085 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1086 enum nl80211_tx_power_setting type;
1087 int idx, mbm = 0;
1088
1089 if (!rdev->ops->set_tx_power) {
60ea385f 1090 result = -EOPNOTSUPP;
98d2ff8b
JO
1091 goto bad_res;
1092 }
1093
1094 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1095 type = nla_get_u32(info->attrs[idx]);
1096
1097 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1098 (type != NL80211_TX_POWER_AUTOMATIC)) {
1099 result = -EINVAL;
1100 goto bad_res;
1101 }
1102
1103 if (type != NL80211_TX_POWER_AUTOMATIC) {
1104 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1105 mbm = nla_get_u32(info->attrs[idx]);
1106 }
1107
1108 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1109 if (result)
1110 goto bad_res;
1111 }
1112
afe0cbf8
BR
1113 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1114 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1115 u32 tx_ant, rx_ant;
7f531e03
BR
1116 if ((!rdev->wiphy.available_antennas_tx &&
1117 !rdev->wiphy.available_antennas_rx) ||
1118 !rdev->ops->set_antenna) {
afe0cbf8
BR
1119 result = -EOPNOTSUPP;
1120 goto bad_res;
1121 }
1122
1123 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1124 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1125
a7ffac95 1126 /* reject antenna configurations which don't match the
7f531e03
BR
1127 * available antenna masks, except for the "all" mask */
1128 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1129 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1130 result = -EINVAL;
1131 goto bad_res;
1132 }
1133
7f531e03
BR
1134 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1135 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1136
afe0cbf8
BR
1137 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1138 if (result)
1139 goto bad_res;
1140 }
1141
b9a5f8ca
JM
1142 changed = 0;
1143
1144 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1145 retry_short = nla_get_u8(
1146 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1147 if (retry_short == 0) {
1148 result = -EINVAL;
1149 goto bad_res;
1150 }
1151 changed |= WIPHY_PARAM_RETRY_SHORT;
1152 }
1153
1154 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1155 retry_long = nla_get_u8(
1156 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1157 if (retry_long == 0) {
1158 result = -EINVAL;
1159 goto bad_res;
1160 }
1161 changed |= WIPHY_PARAM_RETRY_LONG;
1162 }
1163
1164 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1165 frag_threshold = nla_get_u32(
1166 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1167 if (frag_threshold < 256) {
1168 result = -EINVAL;
1169 goto bad_res;
1170 }
1171 if (frag_threshold != (u32) -1) {
1172 /*
1173 * Fragments (apart from the last one) are required to
1174 * have even length. Make the fragmentation code
1175 * simpler by stripping LSB should someone try to use
1176 * odd threshold value.
1177 */
1178 frag_threshold &= ~0x1;
1179 }
1180 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1181 }
1182
1183 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1184 rts_threshold = nla_get_u32(
1185 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1186 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1187 }
1188
81077e82
LT
1189 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1190 coverage_class = nla_get_u8(
1191 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1192 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1193 }
1194
b9a5f8ca
JM
1195 if (changed) {
1196 u8 old_retry_short, old_retry_long;
1197 u32 old_frag_threshold, old_rts_threshold;
81077e82 1198 u8 old_coverage_class;
b9a5f8ca
JM
1199
1200 if (!rdev->ops->set_wiphy_params) {
1201 result = -EOPNOTSUPP;
1202 goto bad_res;
1203 }
1204
1205 old_retry_short = rdev->wiphy.retry_short;
1206 old_retry_long = rdev->wiphy.retry_long;
1207 old_frag_threshold = rdev->wiphy.frag_threshold;
1208 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1209 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1210
1211 if (changed & WIPHY_PARAM_RETRY_SHORT)
1212 rdev->wiphy.retry_short = retry_short;
1213 if (changed & WIPHY_PARAM_RETRY_LONG)
1214 rdev->wiphy.retry_long = retry_long;
1215 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1216 rdev->wiphy.frag_threshold = frag_threshold;
1217 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1218 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1219 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1220 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1221
1222 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1223 if (result) {
1224 rdev->wiphy.retry_short = old_retry_short;
1225 rdev->wiphy.retry_long = old_retry_long;
1226 rdev->wiphy.frag_threshold = old_frag_threshold;
1227 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1228 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1229 }
1230 }
72bdcf34 1231
306d6112 1232 bad_res:
4bbf4d56 1233 mutex_unlock(&rdev->mtx);
f444de05
JB
1234 if (netdev)
1235 dev_put(netdev);
55682965
JB
1236 return result;
1237}
1238
1239
1240static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1241 struct cfg80211_registered_device *rdev,
55682965
JB
1242 struct net_device *dev)
1243{
1244 void *hdr;
1245
1246 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1247 if (!hdr)
1248 return -1;
1249
1250 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1251 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1252 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1253 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1254
1255 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1256 rdev->devlist_generation ^
1257 (cfg80211_rdev_list_generation << 2));
1258
55682965
JB
1259 return genlmsg_end(msg, hdr);
1260
1261 nla_put_failure:
bc3ed28c
TG
1262 genlmsg_cancel(msg, hdr);
1263 return -EMSGSIZE;
55682965
JB
1264}
1265
1266static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1267{
1268 int wp_idx = 0;
1269 int if_idx = 0;
1270 int wp_start = cb->args[0];
1271 int if_start = cb->args[1];
f5ea9120 1272 struct cfg80211_registered_device *rdev;
55682965
JB
1273 struct wireless_dev *wdev;
1274
a1794390 1275 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1276 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1277 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1278 continue;
bba95fef
JB
1279 if (wp_idx < wp_start) {
1280 wp_idx++;
55682965 1281 continue;
bba95fef 1282 }
55682965
JB
1283 if_idx = 0;
1284
f5ea9120
JB
1285 mutex_lock(&rdev->devlist_mtx);
1286 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1287 if (if_idx < if_start) {
1288 if_idx++;
55682965 1289 continue;
bba95fef 1290 }
55682965
JB
1291 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1292 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1293 rdev, wdev->netdev) < 0) {
1294 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1295 goto out;
1296 }
1297 if_idx++;
55682965 1298 }
f5ea9120 1299 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1300
1301 wp_idx++;
55682965 1302 }
bba95fef 1303 out:
a1794390 1304 mutex_unlock(&cfg80211_mutex);
55682965
JB
1305
1306 cb->args[0] = wp_idx;
1307 cb->args[1] = if_idx;
1308
1309 return skb->len;
1310}
1311
1312static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1313{
1314 struct sk_buff *msg;
4c476991
JB
1315 struct cfg80211_registered_device *dev = info->user_ptr[0];
1316 struct net_device *netdev = info->user_ptr[1];
55682965 1317
fd2120ca 1318 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1319 if (!msg)
4c476991 1320 return -ENOMEM;
55682965 1321
d726405a 1322 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1323 dev, netdev) < 0) {
1324 nlmsg_free(msg);
1325 return -ENOBUFS;
1326 }
55682965 1327
134e6375 1328 return genlmsg_reply(msg, info);
55682965
JB
1329}
1330
66f7ac50
MW
1331static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1332 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1333 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1334 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1335 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1336 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1337};
1338
1339static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1340{
1341 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1342 int flag;
1343
1344 *mntrflags = 0;
1345
1346 if (!nla)
1347 return -EINVAL;
1348
1349 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1350 nla, mntr_flags_policy))
1351 return -EINVAL;
1352
1353 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1354 if (flags[flag])
1355 *mntrflags |= (1<<flag);
1356
1357 return 0;
1358}
1359
9bc383de 1360static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1361 struct net_device *netdev, u8 use_4addr,
1362 enum nl80211_iftype iftype)
9bc383de 1363{
ad4bb6f8 1364 if (!use_4addr) {
f350a0a8 1365 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1366 return -EBUSY;
9bc383de 1367 return 0;
ad4bb6f8 1368 }
9bc383de
JB
1369
1370 switch (iftype) {
1371 case NL80211_IFTYPE_AP_VLAN:
1372 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1373 return 0;
1374 break;
1375 case NL80211_IFTYPE_STATION:
1376 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1377 return 0;
1378 break;
1379 default:
1380 break;
1381 }
1382
1383 return -EOPNOTSUPP;
1384}
1385
55682965
JB
1386static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1387{
4c476991 1388 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1389 struct vif_params params;
e36d56b6 1390 int err;
04a773ad 1391 enum nl80211_iftype otype, ntype;
4c476991 1392 struct net_device *dev = info->user_ptr[1];
92ffe055 1393 u32 _flags, *flags = NULL;
ac7f9cfa 1394 bool change = false;
55682965 1395
2ec600d6
LCC
1396 memset(&params, 0, sizeof(params));
1397
04a773ad 1398 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1399
723b038d 1400 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1401 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1402 if (otype != ntype)
ac7f9cfa 1403 change = true;
4c476991
JB
1404 if (ntype > NL80211_IFTYPE_MAX)
1405 return -EINVAL;
723b038d
JB
1406 }
1407
92ffe055 1408 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1409 struct wireless_dev *wdev = dev->ieee80211_ptr;
1410
4c476991
JB
1411 if (ntype != NL80211_IFTYPE_MESH_POINT)
1412 return -EINVAL;
29cbe68c
JB
1413 if (netif_running(dev))
1414 return -EBUSY;
1415
1416 wdev_lock(wdev);
1417 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1418 IEEE80211_MAX_MESH_ID_LEN);
1419 wdev->mesh_id_up_len =
1420 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1421 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1422 wdev->mesh_id_up_len);
1423 wdev_unlock(wdev);
2ec600d6
LCC
1424 }
1425
8b787643
FF
1426 if (info->attrs[NL80211_ATTR_4ADDR]) {
1427 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1428 change = true;
ad4bb6f8 1429 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1430 if (err)
4c476991 1431 return err;
8b787643
FF
1432 } else {
1433 params.use_4addr = -1;
1434 }
1435
92ffe055 1436 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1437 if (ntype != NL80211_IFTYPE_MONITOR)
1438 return -EINVAL;
92ffe055
JB
1439 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1440 &_flags);
ac7f9cfa 1441 if (err)
4c476991 1442 return err;
ac7f9cfa
JB
1443
1444 flags = &_flags;
1445 change = true;
92ffe055 1446 }
3b85875a 1447
ac7f9cfa 1448 if (change)
3d54d255 1449 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1450 else
1451 err = 0;
60719ffd 1452
9bc383de
JB
1453 if (!err && params.use_4addr != -1)
1454 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1455
55682965
JB
1456 return err;
1457}
1458
1459static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1460{
4c476991 1461 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1462 struct vif_params params;
f9e10ce4 1463 struct net_device *dev;
55682965
JB
1464 int err;
1465 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1466 u32 flags;
55682965 1467
2ec600d6
LCC
1468 memset(&params, 0, sizeof(params));
1469
55682965
JB
1470 if (!info->attrs[NL80211_ATTR_IFNAME])
1471 return -EINVAL;
1472
1473 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1474 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1475 if (type > NL80211_IFTYPE_MAX)
1476 return -EINVAL;
1477 }
1478
79c97e97 1479 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1480 !(rdev->wiphy.interface_modes & (1 << type)))
1481 return -EOPNOTSUPP;
55682965 1482
9bc383de 1483 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1484 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1485 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1486 if (err)
4c476991 1487 return err;
9bc383de 1488 }
8b787643 1489
66f7ac50
MW
1490 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1491 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1492 &flags);
f9e10ce4 1493 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1494 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1495 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1496 if (IS_ERR(dev))
1497 return PTR_ERR(dev);
2ec600d6 1498
29cbe68c
JB
1499 if (type == NL80211_IFTYPE_MESH_POINT &&
1500 info->attrs[NL80211_ATTR_MESH_ID]) {
1501 struct wireless_dev *wdev = dev->ieee80211_ptr;
1502
1503 wdev_lock(wdev);
1504 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1505 IEEE80211_MAX_MESH_ID_LEN);
1506 wdev->mesh_id_up_len =
1507 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1508 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1509 wdev->mesh_id_up_len);
1510 wdev_unlock(wdev);
1511 }
1512
f9e10ce4 1513 return 0;
55682965
JB
1514}
1515
1516static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1517{
4c476991
JB
1518 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1519 struct net_device *dev = info->user_ptr[1];
55682965 1520
4c476991
JB
1521 if (!rdev->ops->del_virtual_intf)
1522 return -EOPNOTSUPP;
55682965 1523
4c476991 1524 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1525}
1526
41ade00f
JB
1527struct get_key_cookie {
1528 struct sk_buff *msg;
1529 int error;
b9454e83 1530 int idx;
41ade00f
JB
1531};
1532
1533static void get_key_callback(void *c, struct key_params *params)
1534{
b9454e83 1535 struct nlattr *key;
41ade00f
JB
1536 struct get_key_cookie *cookie = c;
1537
1538 if (params->key)
1539 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1540 params->key_len, params->key);
1541
1542 if (params->seq)
1543 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1544 params->seq_len, params->seq);
1545
1546 if (params->cipher)
1547 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1548 params->cipher);
1549
b9454e83
JB
1550 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1551 if (!key)
1552 goto nla_put_failure;
1553
1554 if (params->key)
1555 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1556 params->key_len, params->key);
1557
1558 if (params->seq)
1559 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1560 params->seq_len, params->seq);
1561
1562 if (params->cipher)
1563 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1564 params->cipher);
1565
1566 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1567
1568 nla_nest_end(cookie->msg, key);
1569
41ade00f
JB
1570 return;
1571 nla_put_failure:
1572 cookie->error = 1;
1573}
1574
1575static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1576{
4c476991 1577 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1578 int err;
4c476991 1579 struct net_device *dev = info->user_ptr[1];
41ade00f 1580 u8 key_idx = 0;
e31b8213
JB
1581 const u8 *mac_addr = NULL;
1582 bool pairwise;
41ade00f
JB
1583 struct get_key_cookie cookie = {
1584 .error = 0,
1585 };
1586 void *hdr;
1587 struct sk_buff *msg;
1588
1589 if (info->attrs[NL80211_ATTR_KEY_IDX])
1590 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1591
3cfcf6ac 1592 if (key_idx > 5)
41ade00f
JB
1593 return -EINVAL;
1594
1595 if (info->attrs[NL80211_ATTR_MAC])
1596 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1597
e31b8213
JB
1598 pairwise = !!mac_addr;
1599 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1600 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1601 if (kt >= NUM_NL80211_KEYTYPES)
1602 return -EINVAL;
1603 if (kt != NL80211_KEYTYPE_GROUP &&
1604 kt != NL80211_KEYTYPE_PAIRWISE)
1605 return -EINVAL;
1606 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1607 }
1608
4c476991
JB
1609 if (!rdev->ops->get_key)
1610 return -EOPNOTSUPP;
41ade00f 1611
fd2120ca 1612 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1613 if (!msg)
1614 return -ENOMEM;
41ade00f
JB
1615
1616 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1617 NL80211_CMD_NEW_KEY);
4c476991
JB
1618 if (IS_ERR(hdr))
1619 return PTR_ERR(hdr);
41ade00f
JB
1620
1621 cookie.msg = msg;
b9454e83 1622 cookie.idx = key_idx;
41ade00f
JB
1623
1624 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1625 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1626 if (mac_addr)
1627 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1628
e31b8213
JB
1629 if (pairwise && mac_addr &&
1630 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1631 return -ENOENT;
1632
1633 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1634 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1635
1636 if (err)
6c95e2a2 1637 goto free_msg;
41ade00f
JB
1638
1639 if (cookie.error)
1640 goto nla_put_failure;
1641
1642 genlmsg_end(msg, hdr);
4c476991 1643 return genlmsg_reply(msg, info);
41ade00f
JB
1644
1645 nla_put_failure:
1646 err = -ENOBUFS;
6c95e2a2 1647 free_msg:
41ade00f 1648 nlmsg_free(msg);
41ade00f
JB
1649 return err;
1650}
1651
1652static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1653{
4c476991 1654 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1655 struct key_parse key;
41ade00f 1656 int err;
4c476991 1657 struct net_device *dev = info->user_ptr[1];
41ade00f 1658
b9454e83
JB
1659 err = nl80211_parse_key(info, &key);
1660 if (err)
1661 return err;
41ade00f 1662
b9454e83 1663 if (key.idx < 0)
41ade00f
JB
1664 return -EINVAL;
1665
b9454e83
JB
1666 /* only support setting default key */
1667 if (!key.def && !key.defmgmt)
41ade00f
JB
1668 return -EINVAL;
1669
dbd2fd65 1670 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1671
dbd2fd65
JB
1672 if (key.def) {
1673 if (!rdev->ops->set_default_key) {
1674 err = -EOPNOTSUPP;
1675 goto out;
1676 }
41ade00f 1677
dbd2fd65
JB
1678 err = nl80211_key_allowed(dev->ieee80211_ptr);
1679 if (err)
1680 goto out;
1681
1682 if (!(rdev->wiphy.flags &
1683 WIPHY_FLAG_SUPPORTS_SEPARATE_DEFAULT_KEYS)) {
1684 if (!key.def_uni || !key.def_multi) {
1685 err = -EOPNOTSUPP;
1686 goto out;
1687 }
1688 }
1689
1690 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1691 key.def_uni, key.def_multi);
1692
1693 if (err)
1694 goto out;
fffd0934 1695
3d23e349 1696#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1697 dev->ieee80211_ptr->wext.default_key = key.idx;
1698#endif
1699 } else {
1700 if (key.def_uni || !key.def_multi) {
1701 err = -EINVAL;
1702 goto out;
1703 }
1704
1705 if (!rdev->ops->set_default_mgmt_key) {
1706 err = -EOPNOTSUPP;
1707 goto out;
1708 }
1709
1710 err = nl80211_key_allowed(dev->ieee80211_ptr);
1711 if (err)
1712 goto out;
1713
1714 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1715 dev, key.idx);
1716 if (err)
1717 goto out;
1718
1719#ifdef CONFIG_CFG80211_WEXT
1720 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1721#endif
dbd2fd65
JB
1722 }
1723
1724 out:
fffd0934 1725 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1726
41ade00f
JB
1727 return err;
1728}
1729
1730static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1731{
4c476991 1732 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1733 int err;
4c476991 1734 struct net_device *dev = info->user_ptr[1];
b9454e83 1735 struct key_parse key;
e31b8213 1736 const u8 *mac_addr = NULL;
41ade00f 1737
b9454e83
JB
1738 err = nl80211_parse_key(info, &key);
1739 if (err)
1740 return err;
41ade00f 1741
b9454e83 1742 if (!key.p.key)
41ade00f
JB
1743 return -EINVAL;
1744
41ade00f
JB
1745 if (info->attrs[NL80211_ATTR_MAC])
1746 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1747
e31b8213
JB
1748 if (key.type == -1) {
1749 if (mac_addr)
1750 key.type = NL80211_KEYTYPE_PAIRWISE;
1751 else
1752 key.type = NL80211_KEYTYPE_GROUP;
1753 }
1754
1755 /* for now */
1756 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1757 key.type != NL80211_KEYTYPE_GROUP)
1758 return -EINVAL;
1759
4c476991
JB
1760 if (!rdev->ops->add_key)
1761 return -EOPNOTSUPP;
25e47c18 1762
e31b8213
JB
1763 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1764 key.type == NL80211_KEYTYPE_PAIRWISE,
1765 mac_addr))
4c476991 1766 return -EINVAL;
41ade00f 1767
fffd0934
JB
1768 wdev_lock(dev->ieee80211_ptr);
1769 err = nl80211_key_allowed(dev->ieee80211_ptr);
1770 if (!err)
1771 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 1772 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
1773 mac_addr, &key.p);
1774 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1775
41ade00f
JB
1776 return err;
1777}
1778
1779static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1780{
4c476991 1781 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1782 int err;
4c476991 1783 struct net_device *dev = info->user_ptr[1];
41ade00f 1784 u8 *mac_addr = NULL;
b9454e83 1785 struct key_parse key;
41ade00f 1786
b9454e83
JB
1787 err = nl80211_parse_key(info, &key);
1788 if (err)
1789 return err;
41ade00f
JB
1790
1791 if (info->attrs[NL80211_ATTR_MAC])
1792 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1793
e31b8213
JB
1794 if (key.type == -1) {
1795 if (mac_addr)
1796 key.type = NL80211_KEYTYPE_PAIRWISE;
1797 else
1798 key.type = NL80211_KEYTYPE_GROUP;
1799 }
1800
1801 /* for now */
1802 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1803 key.type != NL80211_KEYTYPE_GROUP)
1804 return -EINVAL;
1805
4c476991
JB
1806 if (!rdev->ops->del_key)
1807 return -EOPNOTSUPP;
41ade00f 1808
fffd0934
JB
1809 wdev_lock(dev->ieee80211_ptr);
1810 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
1811
1812 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1813 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1814 err = -ENOENT;
1815
fffd0934 1816 if (!err)
e31b8213
JB
1817 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1818 key.type == NL80211_KEYTYPE_PAIRWISE,
1819 mac_addr);
41ade00f 1820
3d23e349 1821#ifdef CONFIG_CFG80211_WEXT
08645126 1822 if (!err) {
b9454e83 1823 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1824 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1825 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1826 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1827 }
1828#endif
fffd0934 1829 wdev_unlock(dev->ieee80211_ptr);
08645126 1830
41ade00f
JB
1831 return err;
1832}
1833
ed1b6cc7
JB
1834static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1835{
1836 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1837 struct beacon_parameters *info);
4c476991
JB
1838 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1839 struct net_device *dev = info->user_ptr[1];
ed1b6cc7
JB
1840 struct beacon_parameters params;
1841 int haveinfo = 0;
1842
f4a11bb0
JB
1843 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1844 return -EINVAL;
1845
074ac8df 1846 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1847 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1848 return -EOPNOTSUPP;
eec60b03 1849
ed1b6cc7
JB
1850 switch (info->genlhdr->cmd) {
1851 case NL80211_CMD_NEW_BEACON:
1852 /* these are required for NEW_BEACON */
1853 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1854 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4c476991
JB
1855 !info->attrs[NL80211_ATTR_BEACON_HEAD])
1856 return -EINVAL;
ed1b6cc7 1857
79c97e97 1858 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1859 break;
1860 case NL80211_CMD_SET_BEACON:
79c97e97 1861 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1862 break;
1863 default:
1864 WARN_ON(1);
4c476991 1865 return -EOPNOTSUPP;
ed1b6cc7
JB
1866 }
1867
4c476991
JB
1868 if (!call)
1869 return -EOPNOTSUPP;
ed1b6cc7
JB
1870
1871 memset(&params, 0, sizeof(params));
1872
1873 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1874 params.interval =
1875 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1876 haveinfo = 1;
1877 }
1878
1879 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1880 params.dtim_period =
1881 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1882 haveinfo = 1;
1883 }
1884
1885 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1886 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1887 params.head_len =
1888 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1889 haveinfo = 1;
1890 }
1891
1892 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1893 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1894 params.tail_len =
1895 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1896 haveinfo = 1;
1897 }
1898
4c476991
JB
1899 if (!haveinfo)
1900 return -EINVAL;
3b85875a 1901
4c476991 1902 return call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1903}
1904
1905static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1906{
4c476991
JB
1907 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1908 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 1909
4c476991
JB
1910 if (!rdev->ops->del_beacon)
1911 return -EOPNOTSUPP;
ed1b6cc7 1912
074ac8df 1913 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
1914 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1915 return -EOPNOTSUPP;
3b85875a 1916
4c476991 1917 return rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1918}
1919
5727ef1b
JB
1920static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1921 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1922 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1923 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1924 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1925};
1926
eccb8e8f
JB
1927static int parse_station_flags(struct genl_info *info,
1928 struct station_parameters *params)
5727ef1b
JB
1929{
1930 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1931 struct nlattr *nla;
5727ef1b
JB
1932 int flag;
1933
eccb8e8f
JB
1934 /*
1935 * Try parsing the new attribute first so userspace
1936 * can specify both for older kernels.
1937 */
1938 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1939 if (nla) {
1940 struct nl80211_sta_flag_update *sta_flags;
1941
1942 sta_flags = nla_data(nla);
1943 params->sta_flags_mask = sta_flags->mask;
1944 params->sta_flags_set = sta_flags->set;
1945 if ((params->sta_flags_mask |
1946 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1947 return -EINVAL;
1948 return 0;
1949 }
1950
1951 /* if present, parse the old attribute */
5727ef1b 1952
eccb8e8f 1953 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1954 if (!nla)
1955 return 0;
1956
1957 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1958 nla, sta_flags_policy))
1959 return -EINVAL;
1960
eccb8e8f
JB
1961 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1962 params->sta_flags_mask &= ~1;
5727ef1b
JB
1963
1964 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1965 if (flags[flag])
eccb8e8f 1966 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1967
1968 return 0;
1969}
1970
fd5b74dc
JB
1971static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1972 int flags, struct net_device *dev,
98b62183 1973 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1974{
1975 void *hdr;
420e7fab
HR
1976 struct nlattr *sinfoattr, *txrate;
1977 u16 bitrate;
fd5b74dc
JB
1978
1979 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1980 if (!hdr)
1981 return -1;
1982
1983 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1984 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1985
f5ea9120
JB
1986 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1987
2ec600d6
LCC
1988 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1989 if (!sinfoattr)
fd5b74dc 1990 goto nla_put_failure;
2ec600d6
LCC
1991 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1992 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1993 sinfo->inactive_time);
1994 if (sinfo->filled & STATION_INFO_RX_BYTES)
1995 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1996 sinfo->rx_bytes);
1997 if (sinfo->filled & STATION_INFO_TX_BYTES)
1998 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1999 sinfo->tx_bytes);
2000 if (sinfo->filled & STATION_INFO_LLID)
2001 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2002 sinfo->llid);
2003 if (sinfo->filled & STATION_INFO_PLID)
2004 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2005 sinfo->plid);
2006 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2007 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2008 sinfo->plink_state);
420e7fab
HR
2009 if (sinfo->filled & STATION_INFO_SIGNAL)
2010 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2011 sinfo->signal);
541a45a1
BR
2012 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2013 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2014 sinfo->signal_avg);
420e7fab
HR
2015 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
2016 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
2017 if (!txrate)
2018 goto nla_put_failure;
2019
254416aa
JL
2020 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2021 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
2022 if (bitrate > 0)
2023 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 2024
420e7fab
HR
2025 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
2026 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
2027 sinfo->txrate.mcs);
2028 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2029 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2030 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
2031 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2032
2033 nla_nest_end(msg, txrate);
2034 }
98c8a60a
JM
2035 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2036 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2037 sinfo->rx_packets);
2038 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2039 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2040 sinfo->tx_packets);
b206b4ef
BR
2041 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2042 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2043 sinfo->tx_retries);
2044 if (sinfo->filled & STATION_INFO_TX_FAILED)
2045 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2046 sinfo->tx_failed);
2ec600d6 2047 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
2048
2049 return genlmsg_end(msg, hdr);
2050
2051 nla_put_failure:
bc3ed28c
TG
2052 genlmsg_cancel(msg, hdr);
2053 return -EMSGSIZE;
fd5b74dc
JB
2054}
2055
2ec600d6 2056static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2057 struct netlink_callback *cb)
2ec600d6 2058{
2ec600d6
LCC
2059 struct station_info sinfo;
2060 struct cfg80211_registered_device *dev;
bba95fef 2061 struct net_device *netdev;
2ec600d6 2062 u8 mac_addr[ETH_ALEN];
bba95fef 2063 int sta_idx = cb->args[1];
2ec600d6 2064 int err;
2ec600d6 2065
67748893
JB
2066 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2067 if (err)
2068 return err;
bba95fef
JB
2069
2070 if (!dev->ops->dump_station) {
eec60b03 2071 err = -EOPNOTSUPP;
bba95fef
JB
2072 goto out_err;
2073 }
2074
bba95fef
JB
2075 while (1) {
2076 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2077 mac_addr, &sinfo);
2078 if (err == -ENOENT)
2079 break;
2080 if (err)
3b85875a 2081 goto out_err;
bba95fef
JB
2082
2083 if (nl80211_send_station(skb,
2084 NETLINK_CB(cb->skb).pid,
2085 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2086 netdev, mac_addr,
2087 &sinfo) < 0)
2088 goto out;
2089
2090 sta_idx++;
2091 }
2092
2093
2094 out:
2095 cb->args[1] = sta_idx;
2096 err = skb->len;
bba95fef 2097 out_err:
67748893 2098 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2099
2100 return err;
2ec600d6 2101}
fd5b74dc 2102
5727ef1b
JB
2103static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2104{
4c476991
JB
2105 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2106 struct net_device *dev = info->user_ptr[1];
2ec600d6 2107 struct station_info sinfo;
fd5b74dc
JB
2108 struct sk_buff *msg;
2109 u8 *mac_addr = NULL;
4c476991 2110 int err;
fd5b74dc 2111
2ec600d6 2112 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2113
2114 if (!info->attrs[NL80211_ATTR_MAC])
2115 return -EINVAL;
2116
2117 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2118
4c476991
JB
2119 if (!rdev->ops->get_station)
2120 return -EOPNOTSUPP;
3b85875a 2121
4c476991 2122 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2123 if (err)
4c476991 2124 return err;
2ec600d6 2125
fd2120ca 2126 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2127 if (!msg)
4c476991 2128 return -ENOMEM;
fd5b74dc
JB
2129
2130 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2131 dev, mac_addr, &sinfo) < 0) {
2132 nlmsg_free(msg);
2133 return -ENOBUFS;
2134 }
3b85875a 2135
4c476991 2136 return genlmsg_reply(msg, info);
5727ef1b
JB
2137}
2138
2139/*
c258d2de 2140 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2141 */
463d0183 2142static int get_vlan(struct genl_info *info,
5727ef1b
JB
2143 struct cfg80211_registered_device *rdev,
2144 struct net_device **vlan)
2145{
463d0183 2146 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
2147 *vlan = NULL;
2148
2149 if (vlanattr) {
463d0183
JB
2150 *vlan = dev_get_by_index(genl_info_net(info),
2151 nla_get_u32(vlanattr));
5727ef1b
JB
2152 if (!*vlan)
2153 return -ENODEV;
2154 if (!(*vlan)->ieee80211_ptr)
2155 return -EINVAL;
2156 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2157 return -EINVAL;
c258d2de
FF
2158 if (!netif_running(*vlan))
2159 return -ENETDOWN;
5727ef1b
JB
2160 }
2161 return 0;
2162}
2163
2164static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2165{
4c476991 2166 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2167 int err;
4c476991 2168 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2169 struct station_parameters params;
2170 u8 *mac_addr = NULL;
2171
2172 memset(&params, 0, sizeof(params));
2173
2174 params.listen_interval = -1;
2175
2176 if (info->attrs[NL80211_ATTR_STA_AID])
2177 return -EINVAL;
2178
2179 if (!info->attrs[NL80211_ATTR_MAC])
2180 return -EINVAL;
2181
2182 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2183
2184 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2185 params.supported_rates =
2186 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2187 params.supported_rates_len =
2188 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2189 }
2190
2191 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2192 params.listen_interval =
2193 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2194
36aedc90
JM
2195 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2196 params.ht_capa =
2197 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2198
eccb8e8f 2199 if (parse_station_flags(info, &params))
5727ef1b
JB
2200 return -EINVAL;
2201
2ec600d6
LCC
2202 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2203 params.plink_action =
2204 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2205
463d0183 2206 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2207 if (err)
034d655e 2208 goto out;
a97f4424
JB
2209
2210 /* validate settings */
2211 err = 0;
2212
2213 switch (dev->ieee80211_ptr->iftype) {
2214 case NL80211_IFTYPE_AP:
2215 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2216 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2217 /* disallow mesh-specific things */
2218 if (params.plink_action)
2219 err = -EINVAL;
2220 break;
074ac8df 2221 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424
JB
2222 case NL80211_IFTYPE_STATION:
2223 /* disallow everything but AUTHORIZED flag */
2224 if (params.plink_action)
2225 err = -EINVAL;
2226 if (params.vlan)
2227 err = -EINVAL;
2228 if (params.supported_rates)
2229 err = -EINVAL;
2230 if (params.ht_capa)
2231 err = -EINVAL;
2232 if (params.listen_interval >= 0)
2233 err = -EINVAL;
2234 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2235 err = -EINVAL;
2236 break;
2237 case NL80211_IFTYPE_MESH_POINT:
2238 /* disallow things mesh doesn't support */
2239 if (params.vlan)
2240 err = -EINVAL;
2241 if (params.ht_capa)
2242 err = -EINVAL;
2243 if (params.listen_interval >= 0)
2244 err = -EINVAL;
2245 if (params.supported_rates)
2246 err = -EINVAL;
2247 if (params.sta_flags_mask)
2248 err = -EINVAL;
2249 break;
2250 default:
2251 err = -EINVAL;
034d655e
JB
2252 }
2253
5727ef1b
JB
2254 if (err)
2255 goto out;
2256
79c97e97 2257 if (!rdev->ops->change_station) {
5727ef1b
JB
2258 err = -EOPNOTSUPP;
2259 goto out;
2260 }
2261
79c97e97 2262 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2263
2264 out:
2265 if (params.vlan)
2266 dev_put(params.vlan);
3b85875a 2267
5727ef1b
JB
2268 return err;
2269}
2270
2271static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2272{
4c476991 2273 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2274 int err;
4c476991 2275 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2276 struct station_parameters params;
2277 u8 *mac_addr = NULL;
2278
2279 memset(&params, 0, sizeof(params));
2280
2281 if (!info->attrs[NL80211_ATTR_MAC])
2282 return -EINVAL;
2283
5727ef1b
JB
2284 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2285 return -EINVAL;
2286
2287 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2288 return -EINVAL;
2289
0e956c13
TLSC
2290 if (!info->attrs[NL80211_ATTR_STA_AID])
2291 return -EINVAL;
2292
5727ef1b
JB
2293 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2294 params.supported_rates =
2295 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2296 params.supported_rates_len =
2297 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2298 params.listen_interval =
2299 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2300
0e956c13
TLSC
2301 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2302 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2303 return -EINVAL;
51b50fbe 2304
36aedc90
JM
2305 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2306 params.ht_capa =
2307 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2308
eccb8e8f 2309 if (parse_station_flags(info, &params))
5727ef1b
JB
2310 return -EINVAL;
2311
0e956c13 2312 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
074ac8df 2313 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4c476991
JB
2314 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2315 return -EINVAL;
0e956c13 2316
463d0183 2317 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2318 if (err)
e80cf853 2319 goto out;
a97f4424
JB
2320
2321 /* validate settings */
2322 err = 0;
2323
79c97e97 2324 if (!rdev->ops->add_station) {
5727ef1b
JB
2325 err = -EOPNOTSUPP;
2326 goto out;
2327 }
2328
79c97e97 2329 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2330
2331 out:
2332 if (params.vlan)
2333 dev_put(params.vlan);
5727ef1b
JB
2334 return err;
2335}
2336
2337static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2338{
4c476991
JB
2339 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2340 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2341 u8 *mac_addr = NULL;
2342
2343 if (info->attrs[NL80211_ATTR_MAC])
2344 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2345
e80cf853 2346 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2347 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2348 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2349 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2350 return -EINVAL;
5727ef1b 2351
4c476991
JB
2352 if (!rdev->ops->del_station)
2353 return -EOPNOTSUPP;
3b85875a 2354
4c476991 2355 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2356}
2357
2ec600d6
LCC
2358static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2359 int flags, struct net_device *dev,
2360 u8 *dst, u8 *next_hop,
2361 struct mpath_info *pinfo)
2362{
2363 void *hdr;
2364 struct nlattr *pinfoattr;
2365
2366 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2367 if (!hdr)
2368 return -1;
2369
2370 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2371 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2372 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2373
f5ea9120
JB
2374 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2375
2ec600d6
LCC
2376 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2377 if (!pinfoattr)
2378 goto nla_put_failure;
2379 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2380 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2381 pinfo->frame_qlen);
d19b3bf6
RP
2382 if (pinfo->filled & MPATH_INFO_SN)
2383 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2384 pinfo->sn);
2ec600d6
LCC
2385 if (pinfo->filled & MPATH_INFO_METRIC)
2386 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2387 pinfo->metric);
2388 if (pinfo->filled & MPATH_INFO_EXPTIME)
2389 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2390 pinfo->exptime);
2391 if (pinfo->filled & MPATH_INFO_FLAGS)
2392 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2393 pinfo->flags);
2394 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2395 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2396 pinfo->discovery_timeout);
2397 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2398 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2399 pinfo->discovery_retries);
2400
2401 nla_nest_end(msg, pinfoattr);
2402
2403 return genlmsg_end(msg, hdr);
2404
2405 nla_put_failure:
bc3ed28c
TG
2406 genlmsg_cancel(msg, hdr);
2407 return -EMSGSIZE;
2ec600d6
LCC
2408}
2409
2410static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2411 struct netlink_callback *cb)
2ec600d6 2412{
2ec600d6
LCC
2413 struct mpath_info pinfo;
2414 struct cfg80211_registered_device *dev;
bba95fef 2415 struct net_device *netdev;
2ec600d6
LCC
2416 u8 dst[ETH_ALEN];
2417 u8 next_hop[ETH_ALEN];
bba95fef 2418 int path_idx = cb->args[1];
2ec600d6 2419 int err;
2ec600d6 2420
67748893
JB
2421 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2422 if (err)
2423 return err;
bba95fef
JB
2424
2425 if (!dev->ops->dump_mpath) {
eec60b03 2426 err = -EOPNOTSUPP;
bba95fef
JB
2427 goto out_err;
2428 }
2429
eec60b03
JM
2430 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2431 err = -EOPNOTSUPP;
0448b5fc 2432 goto out_err;
eec60b03
JM
2433 }
2434
bba95fef
JB
2435 while (1) {
2436 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2437 dst, next_hop, &pinfo);
2438 if (err == -ENOENT)
2ec600d6 2439 break;
bba95fef 2440 if (err)
3b85875a 2441 goto out_err;
2ec600d6 2442
bba95fef
JB
2443 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2444 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2445 netdev, dst, next_hop,
2446 &pinfo) < 0)
2447 goto out;
2ec600d6 2448
bba95fef 2449 path_idx++;
2ec600d6 2450 }
2ec600d6 2451
2ec600d6 2452
bba95fef
JB
2453 out:
2454 cb->args[1] = path_idx;
2455 err = skb->len;
bba95fef 2456 out_err:
67748893 2457 nl80211_finish_netdev_dump(dev);
bba95fef 2458 return err;
2ec600d6
LCC
2459}
2460
2461static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2462{
4c476991 2463 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2464 int err;
4c476991 2465 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2466 struct mpath_info pinfo;
2467 struct sk_buff *msg;
2468 u8 *dst = NULL;
2469 u8 next_hop[ETH_ALEN];
2470
2471 memset(&pinfo, 0, sizeof(pinfo));
2472
2473 if (!info->attrs[NL80211_ATTR_MAC])
2474 return -EINVAL;
2475
2476 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2477
4c476991
JB
2478 if (!rdev->ops->get_mpath)
2479 return -EOPNOTSUPP;
2ec600d6 2480
4c476991
JB
2481 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2482 return -EOPNOTSUPP;
eec60b03 2483
79c97e97 2484 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 2485 if (err)
4c476991 2486 return err;
2ec600d6 2487
fd2120ca 2488 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 2489 if (!msg)
4c476991 2490 return -ENOMEM;
2ec600d6
LCC
2491
2492 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2493 dev, dst, next_hop, &pinfo) < 0) {
2494 nlmsg_free(msg);
2495 return -ENOBUFS;
2496 }
3b85875a 2497
4c476991 2498 return genlmsg_reply(msg, info);
2ec600d6
LCC
2499}
2500
2501static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2502{
4c476991
JB
2503 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2504 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2505 u8 *dst = NULL;
2506 u8 *next_hop = NULL;
2507
2508 if (!info->attrs[NL80211_ATTR_MAC])
2509 return -EINVAL;
2510
2511 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2512 return -EINVAL;
2513
2514 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2515 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2516
4c476991
JB
2517 if (!rdev->ops->change_mpath)
2518 return -EOPNOTSUPP;
35a8efe1 2519
4c476991
JB
2520 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2521 return -EOPNOTSUPP;
2ec600d6 2522
4c476991 2523 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 2524}
4c476991 2525
2ec600d6
LCC
2526static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2527{
4c476991
JB
2528 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2529 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2530 u8 *dst = NULL;
2531 u8 *next_hop = NULL;
2532
2533 if (!info->attrs[NL80211_ATTR_MAC])
2534 return -EINVAL;
2535
2536 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2537 return -EINVAL;
2538
2539 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2540 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2541
4c476991
JB
2542 if (!rdev->ops->add_mpath)
2543 return -EOPNOTSUPP;
35a8efe1 2544
4c476991
JB
2545 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2546 return -EOPNOTSUPP;
2ec600d6 2547
4c476991 2548 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2549}
2550
2551static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2552{
4c476991
JB
2553 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2554 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2555 u8 *dst = NULL;
2556
2557 if (info->attrs[NL80211_ATTR_MAC])
2558 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2559
4c476991
JB
2560 if (!rdev->ops->del_mpath)
2561 return -EOPNOTSUPP;
3b85875a 2562
4c476991 2563 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2564}
2565
9f1ba906
JM
2566static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2567{
4c476991
JB
2568 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2569 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
2570 struct bss_parameters params;
2571
2572 memset(&params, 0, sizeof(params));
2573 /* default to not changing parameters */
2574 params.use_cts_prot = -1;
2575 params.use_short_preamble = -1;
2576 params.use_short_slot_time = -1;
fd8aaaf3 2577 params.ap_isolate = -1;
50b12f59 2578 params.ht_opmode = -1;
9f1ba906
JM
2579
2580 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2581 params.use_cts_prot =
2582 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2583 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2584 params.use_short_preamble =
2585 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2586 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2587 params.use_short_slot_time =
2588 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2589 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2590 params.basic_rates =
2591 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2592 params.basic_rates_len =
2593 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2594 }
fd8aaaf3
FF
2595 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2596 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
2597 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2598 params.ht_opmode =
2599 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 2600
4c476991
JB
2601 if (!rdev->ops->change_bss)
2602 return -EOPNOTSUPP;
9f1ba906 2603
074ac8df 2604 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2605 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2606 return -EOPNOTSUPP;
3b85875a 2607
4c476991 2608 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2609}
2610
b54452b0 2611static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2612 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2613 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2614 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2615 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2616 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2617 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2618};
2619
2620static int parse_reg_rule(struct nlattr *tb[],
2621 struct ieee80211_reg_rule *reg_rule)
2622{
2623 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2624 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2625
2626 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2627 return -EINVAL;
2628 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2629 return -EINVAL;
2630 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2631 return -EINVAL;
2632 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2633 return -EINVAL;
2634 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2635 return -EINVAL;
2636
2637 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2638
2639 freq_range->start_freq_khz =
2640 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2641 freq_range->end_freq_khz =
2642 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2643 freq_range->max_bandwidth_khz =
2644 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2645
2646 power_rule->max_eirp =
2647 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2648
2649 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2650 power_rule->max_antenna_gain =
2651 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2652
2653 return 0;
2654}
2655
2656static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2657{
2658 int r;
2659 char *data = NULL;
2660
80778f18
LR
2661 /*
2662 * You should only get this when cfg80211 hasn't yet initialized
2663 * completely when built-in to the kernel right between the time
2664 * window between nl80211_init() and regulatory_init(), if that is
2665 * even possible.
2666 */
2667 mutex_lock(&cfg80211_mutex);
2668 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2669 mutex_unlock(&cfg80211_mutex);
2670 return -EINPROGRESS;
80778f18 2671 }
fe33eb39 2672 mutex_unlock(&cfg80211_mutex);
80778f18 2673
fe33eb39
LR
2674 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2675 return -EINVAL;
b2e1b302
LR
2676
2677 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2678
fe33eb39
LR
2679 r = regulatory_hint_user(data);
2680
b2e1b302
LR
2681 return r;
2682}
2683
24bdd9f4 2684static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 2685 struct genl_info *info)
93da9cc1 2686{
4c476991 2687 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 2688 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
2689 struct wireless_dev *wdev = dev->ieee80211_ptr;
2690 struct mesh_config cur_params;
2691 int err = 0;
93da9cc1 2692 void *hdr;
2693 struct nlattr *pinfoattr;
2694 struct sk_buff *msg;
2695
29cbe68c
JB
2696 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2697 return -EOPNOTSUPP;
2698
24bdd9f4 2699 if (!rdev->ops->get_mesh_config)
4c476991 2700 return -EOPNOTSUPP;
f3f92586 2701
29cbe68c
JB
2702 wdev_lock(wdev);
2703 /* If not connected, get default parameters */
2704 if (!wdev->mesh_id_len)
2705 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2706 else
24bdd9f4 2707 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2708 &cur_params);
2709 wdev_unlock(wdev);
2710
93da9cc1 2711 if (err)
4c476991 2712 return err;
93da9cc1 2713
2714 /* Draw up a netlink message to send back */
fd2120ca 2715 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2716 if (!msg)
2717 return -ENOMEM;
93da9cc1 2718 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 2719 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 2720 if (!hdr)
efe1cf0c 2721 goto out;
24bdd9f4 2722 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 2723 if (!pinfoattr)
2724 goto nla_put_failure;
2725 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2726 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2727 cur_params.dot11MeshRetryTimeout);
2728 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2729 cur_params.dot11MeshConfirmTimeout);
2730 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2731 cur_params.dot11MeshHoldingTimeout);
2732 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2733 cur_params.dot11MeshMaxPeerLinks);
2734 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2735 cur_params.dot11MeshMaxRetries);
2736 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2737 cur_params.dot11MeshTTL);
45904f21
JC
2738 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2739 cur_params.element_ttl);
93da9cc1 2740 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2741 cur_params.auto_open_plinks);
2742 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2743 cur_params.dot11MeshHWMPmaxPREQretries);
2744 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2745 cur_params.path_refresh_time);
2746 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2747 cur_params.min_discovery_timeout);
2748 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2749 cur_params.dot11MeshHWMPactivePathTimeout);
2750 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2751 cur_params.dot11MeshHWMPpreqMinInterval);
2752 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2753 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2754 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2755 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2756 nla_nest_end(msg, pinfoattr);
2757 genlmsg_end(msg, hdr);
4c476991 2758 return genlmsg_reply(msg, info);
93da9cc1 2759
3b85875a 2760 nla_put_failure:
93da9cc1 2761 genlmsg_cancel(msg, hdr);
efe1cf0c 2762 out:
d080e275 2763 nlmsg_free(msg);
4c476991 2764 return -ENOBUFS;
93da9cc1 2765}
2766
b54452b0 2767static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2768 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2769 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2770 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2771 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2772 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2773 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 2774 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 2775 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2776
2777 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2778 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2779 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2780 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2781 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2782 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2783};
2784
c80d545d
JC
2785static const struct nla_policy
2786 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
2787 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
2788 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
2789 [NL80211_MESH_SETUP_VENDOR_PATH_SEL_IE] = { .type = NLA_BINARY,
2790 .len = IEEE80211_MAX_DATA_LEN },
2791};
2792
24bdd9f4 2793static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
2794 struct mesh_config *cfg,
2795 u32 *mask_out)
93da9cc1 2796{
93da9cc1 2797 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 2798 u32 mask = 0;
93da9cc1 2799
bd90fdcc
JB
2800#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2801do {\
2802 if (table[attr_num]) {\
2803 cfg->param = nla_fn(table[attr_num]); \
2804 mask |= (1 << (attr_num - 1)); \
2805 } \
2806} while (0);\
2807
2808
24bdd9f4 2809 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 2810 return -EINVAL;
2811 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 2812 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 2813 nl80211_meshconf_params_policy))
93da9cc1 2814 return -EINVAL;
2815
93da9cc1 2816 /* This makes sure that there aren't more than 32 mesh config
2817 * parameters (otherwise our bitfield scheme would not work.) */
2818 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2819
2820 /* Fill in the params struct */
93da9cc1 2821 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2822 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2823 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2824 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2825 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2826 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2827 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2828 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2829 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2830 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2831 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2832 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
2833 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2834 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 2835 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2836 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2837 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2838 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2839 nla_get_u8);
2840 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2841 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2842 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2843 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2844 nla_get_u16);
2845 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2846 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2847 nla_get_u32);
2848 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2849 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2850 nla_get_u16);
2851 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2852 dot11MeshHWMPnetDiameterTraversalTime,
2853 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2854 nla_get_u16);
63c5723b
RP
2855 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2856 dot11MeshHWMPRootMode, mask,
2857 NL80211_MESHCONF_HWMP_ROOTMODE,
2858 nla_get_u8);
bd90fdcc
JB
2859 if (mask_out)
2860 *mask_out = mask;
c80d545d 2861
bd90fdcc
JB
2862 return 0;
2863
2864#undef FILL_IN_MESH_PARAM_IF_SET
2865}
2866
c80d545d
JC
2867static int nl80211_parse_mesh_setup(struct genl_info *info,
2868 struct mesh_setup *setup)
2869{
2870 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
2871
2872 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
2873 return -EINVAL;
2874 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
2875 info->attrs[NL80211_ATTR_MESH_SETUP],
2876 nl80211_mesh_setup_params_policy))
2877 return -EINVAL;
2878
2879 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
2880 setup->path_sel_proto =
2881 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
2882 IEEE80211_PATH_PROTOCOL_VENDOR :
2883 IEEE80211_PATH_PROTOCOL_HWMP;
2884
2885 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
2886 setup->path_metric =
2887 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
2888 IEEE80211_PATH_METRIC_VENDOR :
2889 IEEE80211_PATH_METRIC_AIRTIME;
2890
2891 if (tb[NL80211_MESH_SETUP_VENDOR_PATH_SEL_IE]) {
2892 struct nlattr *ieattr =
2893 tb[NL80211_MESH_SETUP_VENDOR_PATH_SEL_IE];
2894 if (!is_valid_ie_attr(ieattr))
2895 return -EINVAL;
2896 setup->vendor_ie = nla_data(ieattr);
2897 setup->vendor_ie_len = nla_len(ieattr);
2898 }
2899
2900 return 0;
2901}
2902
24bdd9f4 2903static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 2904 struct genl_info *info)
bd90fdcc
JB
2905{
2906 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2907 struct net_device *dev = info->user_ptr[1];
29cbe68c 2908 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
2909 struct mesh_config cfg;
2910 u32 mask;
2911 int err;
2912
29cbe68c
JB
2913 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2914 return -EOPNOTSUPP;
2915
24bdd9f4 2916 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
2917 return -EOPNOTSUPP;
2918
24bdd9f4 2919 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
2920 if (err)
2921 return err;
2922
29cbe68c
JB
2923 wdev_lock(wdev);
2924 if (!wdev->mesh_id_len)
2925 err = -ENOLINK;
2926
2927 if (!err)
24bdd9f4 2928 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
2929 mask, &cfg);
2930
2931 wdev_unlock(wdev);
2932
2933 return err;
93da9cc1 2934}
2935
f130347c
LR
2936static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2937{
2938 struct sk_buff *msg;
2939 void *hdr = NULL;
2940 struct nlattr *nl_reg_rules;
2941 unsigned int i;
2942 int err = -EINVAL;
2943
a1794390 2944 mutex_lock(&cfg80211_mutex);
f130347c
LR
2945
2946 if (!cfg80211_regdomain)
2947 goto out;
2948
fd2120ca 2949 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2950 if (!msg) {
2951 err = -ENOBUFS;
2952 goto out;
2953 }
2954
2955 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2956 NL80211_CMD_GET_REG);
2957 if (!hdr)
efe1cf0c 2958 goto put_failure;
f130347c
LR
2959
2960 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2961 cfg80211_regdomain->alpha2);
2962
2963 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2964 if (!nl_reg_rules)
2965 goto nla_put_failure;
2966
2967 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2968 struct nlattr *nl_reg_rule;
2969 const struct ieee80211_reg_rule *reg_rule;
2970 const struct ieee80211_freq_range *freq_range;
2971 const struct ieee80211_power_rule *power_rule;
2972
2973 reg_rule = &cfg80211_regdomain->reg_rules[i];
2974 freq_range = &reg_rule->freq_range;
2975 power_rule = &reg_rule->power_rule;
2976
2977 nl_reg_rule = nla_nest_start(msg, i);
2978 if (!nl_reg_rule)
2979 goto nla_put_failure;
2980
2981 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2982 reg_rule->flags);
2983 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2984 freq_range->start_freq_khz);
2985 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2986 freq_range->end_freq_khz);
2987 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2988 freq_range->max_bandwidth_khz);
2989 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2990 power_rule->max_antenna_gain);
2991 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2992 power_rule->max_eirp);
2993
2994 nla_nest_end(msg, nl_reg_rule);
2995 }
2996
2997 nla_nest_end(msg, nl_reg_rules);
2998
2999 genlmsg_end(msg, hdr);
134e6375 3000 err = genlmsg_reply(msg, info);
f130347c
LR
3001 goto out;
3002
3003nla_put_failure:
3004 genlmsg_cancel(msg, hdr);
efe1cf0c 3005put_failure:
d080e275 3006 nlmsg_free(msg);
f130347c
LR
3007 err = -EMSGSIZE;
3008out:
a1794390 3009 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3010 return err;
3011}
3012
b2e1b302
LR
3013static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3014{
3015 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3016 struct nlattr *nl_reg_rule;
3017 char *alpha2 = NULL;
3018 int rem_reg_rules = 0, r = 0;
3019 u32 num_rules = 0, rule_idx = 0, size_of_regd;
3020 struct ieee80211_regdomain *rd = NULL;
3021
3022 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3023 return -EINVAL;
3024
3025 if (!info->attrs[NL80211_ATTR_REG_RULES])
3026 return -EINVAL;
3027
3028 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3029
3030 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3031 rem_reg_rules) {
3032 num_rules++;
3033 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3034 return -EINVAL;
b2e1b302
LR
3035 }
3036
61405e97
LR
3037 mutex_lock(&cfg80211_mutex);
3038
d0e18f83
LR
3039 if (!reg_is_valid_request(alpha2)) {
3040 r = -EINVAL;
3041 goto bad_reg;
3042 }
b2e1b302
LR
3043
3044 size_of_regd = sizeof(struct ieee80211_regdomain) +
3045 (num_rules * sizeof(struct ieee80211_reg_rule));
3046
3047 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3048 if (!rd) {
3049 r = -ENOMEM;
3050 goto bad_reg;
3051 }
b2e1b302
LR
3052
3053 rd->n_reg_rules = num_rules;
3054 rd->alpha2[0] = alpha2[0];
3055 rd->alpha2[1] = alpha2[1];
3056
3057 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3058 rem_reg_rules) {
3059 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3060 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3061 reg_rule_policy);
3062 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3063 if (r)
3064 goto bad_reg;
3065
3066 rule_idx++;
3067
d0e18f83
LR
3068 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3069 r = -EINVAL;
b2e1b302 3070 goto bad_reg;
d0e18f83 3071 }
b2e1b302
LR
3072 }
3073
3074 BUG_ON(rule_idx != num_rules);
3075
b2e1b302 3076 r = set_regdom(rd);
61405e97 3077
a1794390 3078 mutex_unlock(&cfg80211_mutex);
d0e18f83 3079
b2e1b302
LR
3080 return r;
3081
d2372b31 3082 bad_reg:
61405e97 3083 mutex_unlock(&cfg80211_mutex);
b2e1b302 3084 kfree(rd);
d0e18f83 3085 return r;
b2e1b302
LR
3086}
3087
83f5e2cf
JB
3088static int validate_scan_freqs(struct nlattr *freqs)
3089{
3090 struct nlattr *attr1, *attr2;
3091 int n_channels = 0, tmp1, tmp2;
3092
3093 nla_for_each_nested(attr1, freqs, tmp1) {
3094 n_channels++;
3095 /*
3096 * Some hardware has a limited channel list for
3097 * scanning, and it is pretty much nonsensical
3098 * to scan for a channel twice, so disallow that
3099 * and don't require drivers to check that the
3100 * channel list they get isn't longer than what
3101 * they can scan, as long as they can scan all
3102 * the channels they registered at once.
3103 */
3104 nla_for_each_nested(attr2, freqs, tmp2)
3105 if (attr1 != attr2 &&
3106 nla_get_u32(attr1) == nla_get_u32(attr2))
3107 return 0;
3108 }
3109
3110 return n_channels;
3111}
3112
2a519311
JB
3113static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3114{
4c476991
JB
3115 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3116 struct net_device *dev = info->user_ptr[1];
2a519311
JB
3117 struct cfg80211_scan_request *request;
3118 struct cfg80211_ssid *ssid;
3119 struct ieee80211_channel *channel;
3120 struct nlattr *attr;
3121 struct wiphy *wiphy;
83f5e2cf 3122 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3123 enum ieee80211_band band;
70692ad2 3124 size_t ie_len;
2a519311 3125
f4a11bb0
JB
3126 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3127 return -EINVAL;
3128
79c97e97 3129 wiphy = &rdev->wiphy;
2a519311 3130
4c476991
JB
3131 if (!rdev->ops->scan)
3132 return -EOPNOTSUPP;
2a519311 3133
4c476991
JB
3134 if (rdev->scan_req)
3135 return -EBUSY;
2a519311
JB
3136
3137 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3138 n_channels = validate_scan_freqs(
3139 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3140 if (!n_channels)
3141 return -EINVAL;
2a519311 3142 } else {
83f5e2cf
JB
3143 n_channels = 0;
3144
2a519311
JB
3145 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3146 if (wiphy->bands[band])
3147 n_channels += wiphy->bands[band]->n_channels;
3148 }
3149
3150 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3151 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3152 n_ssids++;
3153
4c476991
JB
3154 if (n_ssids > wiphy->max_scan_ssids)
3155 return -EINVAL;
2a519311 3156
70692ad2
JM
3157 if (info->attrs[NL80211_ATTR_IE])
3158 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3159 else
3160 ie_len = 0;
3161
4c476991
JB
3162 if (ie_len > wiphy->max_scan_ie_len)
3163 return -EINVAL;
18a83659 3164
2a519311
JB
3165 request = kzalloc(sizeof(*request)
3166 + sizeof(*ssid) * n_ssids
70692ad2
JM
3167 + sizeof(channel) * n_channels
3168 + ie_len, GFP_KERNEL);
4c476991
JB
3169 if (!request)
3170 return -ENOMEM;
2a519311 3171
2a519311 3172 if (n_ssids)
5ba63533 3173 request->ssids = (void *)&request->channels[n_channels];
2a519311 3174 request->n_ssids = n_ssids;
70692ad2
JM
3175 if (ie_len) {
3176 if (request->ssids)
3177 request->ie = (void *)(request->ssids + n_ssids);
3178 else
3179 request->ie = (void *)(request->channels + n_channels);
3180 }
2a519311 3181
584991dc 3182 i = 0;
2a519311
JB
3183 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3184 /* user specified, bail out if channel not found */
2a519311 3185 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3186 struct ieee80211_channel *chan;
3187
3188 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3189
3190 if (!chan) {
2a519311
JB
3191 err = -EINVAL;
3192 goto out_free;
3193 }
584991dc
JB
3194
3195 /* ignore disabled channels */
3196 if (chan->flags & IEEE80211_CHAN_DISABLED)
3197 continue;
3198
3199 request->channels[i] = chan;
2a519311
JB
3200 i++;
3201 }
3202 } else {
3203 /* all channels */
2a519311
JB
3204 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3205 int j;
3206 if (!wiphy->bands[band])
3207 continue;
3208 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3209 struct ieee80211_channel *chan;
3210
3211 chan = &wiphy->bands[band]->channels[j];
3212
3213 if (chan->flags & IEEE80211_CHAN_DISABLED)
3214 continue;
3215
3216 request->channels[i] = chan;
2a519311
JB
3217 i++;
3218 }
3219 }
3220 }
3221
584991dc
JB
3222 if (!i) {
3223 err = -EINVAL;
3224 goto out_free;
3225 }
3226
3227 request->n_channels = i;
3228
2a519311
JB
3229 i = 0;
3230 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3231 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3232 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3233 err = -EINVAL;
3234 goto out_free;
3235 }
3236 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3237 request->ssids[i].ssid_len = nla_len(attr);
3238 i++;
3239 }
3240 }
3241
70692ad2
JM
3242 if (info->attrs[NL80211_ATTR_IE]) {
3243 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3244 memcpy((void *)request->ie,
3245 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3246 request->ie_len);
3247 }
3248
463d0183 3249 request->dev = dev;
79c97e97 3250 request->wiphy = &rdev->wiphy;
2a519311 3251
79c97e97
JB
3252 rdev->scan_req = request;
3253 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3254
463d0183 3255 if (!err) {
79c97e97 3256 nl80211_send_scan_start(rdev, dev);
463d0183 3257 dev_hold(dev);
4c476991 3258 } else {
2a519311 3259 out_free:
79c97e97 3260 rdev->scan_req = NULL;
2a519311
JB
3261 kfree(request);
3262 }
3b85875a 3263
2a519311
JB
3264 return err;
3265}
3266
3267static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3268 struct cfg80211_registered_device *rdev,
48ab905d
JB
3269 struct wireless_dev *wdev,
3270 struct cfg80211_internal_bss *intbss)
2a519311 3271{
48ab905d 3272 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3273 void *hdr;
3274 struct nlattr *bss;
48ab905d
JB
3275 int i;
3276
3277 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3278
3279 hdr = nl80211hdr_put(msg, pid, seq, flags,
3280 NL80211_CMD_NEW_SCAN_RESULTS);
3281 if (!hdr)
3282 return -1;
3283
f5ea9120 3284 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3285 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3286
3287 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3288 if (!bss)
3289 goto nla_put_failure;
3290 if (!is_zero_ether_addr(res->bssid))
3291 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3292 if (res->information_elements && res->len_information_elements)
3293 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3294 res->len_information_elements,
3295 res->information_elements);
34a6eddb
JM
3296 if (res->beacon_ies && res->len_beacon_ies &&
3297 res->beacon_ies != res->information_elements)
3298 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3299 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3300 if (res->tsf)
3301 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3302 if (res->beacon_interval)
3303 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3304 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3305 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3306 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3307 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3308
77965c97 3309 switch (rdev->wiphy.signal_type) {
2a519311
JB
3310 case CFG80211_SIGNAL_TYPE_MBM:
3311 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3312 break;
3313 case CFG80211_SIGNAL_TYPE_UNSPEC:
3314 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3315 break;
3316 default:
3317 break;
3318 }
3319
48ab905d 3320 switch (wdev->iftype) {
074ac8df 3321 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
3322 case NL80211_IFTYPE_STATION:
3323 if (intbss == wdev->current_bss)
3324 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3325 NL80211_BSS_STATUS_ASSOCIATED);
3326 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3327 if (intbss != wdev->auth_bsses[i])
3328 continue;
3329 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3330 NL80211_BSS_STATUS_AUTHENTICATED);
3331 break;
3332 }
3333 break;
3334 case NL80211_IFTYPE_ADHOC:
3335 if (intbss == wdev->current_bss)
3336 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3337 NL80211_BSS_STATUS_IBSS_JOINED);
3338 break;
3339 default:
3340 break;
3341 }
3342
2a519311
JB
3343 nla_nest_end(msg, bss);
3344
3345 return genlmsg_end(msg, hdr);
3346
3347 nla_put_failure:
3348 genlmsg_cancel(msg, hdr);
3349 return -EMSGSIZE;
3350}
3351
3352static int nl80211_dump_scan(struct sk_buff *skb,
3353 struct netlink_callback *cb)
3354{
48ab905d
JB
3355 struct cfg80211_registered_device *rdev;
3356 struct net_device *dev;
2a519311 3357 struct cfg80211_internal_bss *scan;
48ab905d 3358 struct wireless_dev *wdev;
2a519311
JB
3359 int start = cb->args[1], idx = 0;
3360 int err;
3361
67748893
JB
3362 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3363 if (err)
3364 return err;
2a519311 3365
48ab905d 3366 wdev = dev->ieee80211_ptr;
2a519311 3367
48ab905d
JB
3368 wdev_lock(wdev);
3369 spin_lock_bh(&rdev->bss_lock);
3370 cfg80211_bss_expire(rdev);
3371
3372 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3373 if (++idx <= start)
3374 continue;
3375 if (nl80211_send_bss(skb,
3376 NETLINK_CB(cb->skb).pid,
3377 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3378 rdev, wdev, scan) < 0) {
2a519311 3379 idx--;
67748893 3380 break;
2a519311
JB
3381 }
3382 }
3383
48ab905d
JB
3384 spin_unlock_bh(&rdev->bss_lock);
3385 wdev_unlock(wdev);
2a519311
JB
3386
3387 cb->args[1] = idx;
67748893 3388 nl80211_finish_netdev_dump(rdev);
2a519311 3389
67748893 3390 return skb->len;
2a519311
JB
3391}
3392
61fa713c
HS
3393static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3394 int flags, struct net_device *dev,
3395 struct survey_info *survey)
3396{
3397 void *hdr;
3398 struct nlattr *infoattr;
3399
3400 /* Survey without a channel doesn't make sense */
3401 if (!survey->channel)
3402 return -EINVAL;
3403
3404 hdr = nl80211hdr_put(msg, pid, seq, flags,
3405 NL80211_CMD_NEW_SURVEY_RESULTS);
3406 if (!hdr)
3407 return -ENOMEM;
3408
3409 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3410
3411 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3412 if (!infoattr)
3413 goto nla_put_failure;
3414
3415 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3416 survey->channel->center_freq);
3417 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3418 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3419 survey->noise);
17e5a808
FF
3420 if (survey->filled & SURVEY_INFO_IN_USE)
3421 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
3422 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3423 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3424 survey->channel_time);
3425 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3426 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3427 survey->channel_time_busy);
3428 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3429 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3430 survey->channel_time_ext_busy);
3431 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3432 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3433 survey->channel_time_rx);
3434 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3435 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3436 survey->channel_time_tx);
61fa713c
HS
3437
3438 nla_nest_end(msg, infoattr);
3439
3440 return genlmsg_end(msg, hdr);
3441
3442 nla_put_failure:
3443 genlmsg_cancel(msg, hdr);
3444 return -EMSGSIZE;
3445}
3446
3447static int nl80211_dump_survey(struct sk_buff *skb,
3448 struct netlink_callback *cb)
3449{
3450 struct survey_info survey;
3451 struct cfg80211_registered_device *dev;
3452 struct net_device *netdev;
61fa713c
HS
3453 int survey_idx = cb->args[1];
3454 int res;
3455
67748893
JB
3456 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3457 if (res)
3458 return res;
61fa713c
HS
3459
3460 if (!dev->ops->dump_survey) {
3461 res = -EOPNOTSUPP;
3462 goto out_err;
3463 }
3464
3465 while (1) {
3466 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3467 &survey);
3468 if (res == -ENOENT)
3469 break;
3470 if (res)
3471 goto out_err;
3472
3473 if (nl80211_send_survey(skb,
3474 NETLINK_CB(cb->skb).pid,
3475 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3476 netdev,
3477 &survey) < 0)
3478 goto out;
3479 survey_idx++;
3480 }
3481
3482 out:
3483 cb->args[1] = survey_idx;
3484 res = skb->len;
3485 out_err:
67748893 3486 nl80211_finish_netdev_dump(dev);
61fa713c
HS
3487 return res;
3488}
3489
255e737e
JM
3490static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3491{
b23aa676
SO
3492 return auth_type <= NL80211_AUTHTYPE_MAX;
3493}
3494
3495static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3496{
3497 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3498 NL80211_WPA_VERSION_2));
3499}
3500
3501static bool nl80211_valid_akm_suite(u32 akm)
3502{
3503 return akm == WLAN_AKM_SUITE_8021X ||
3504 akm == WLAN_AKM_SUITE_PSK;
3505}
3506
3507static bool nl80211_valid_cipher_suite(u32 cipher)
3508{
3509 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3510 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3511 cipher == WLAN_CIPHER_SUITE_TKIP ||
3512 cipher == WLAN_CIPHER_SUITE_CCMP ||
3513 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3514}
3515
b23aa676 3516
636a5d36
JM
3517static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3518{
4c476991
JB
3519 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3520 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
3521 struct ieee80211_channel *chan;
3522 const u8 *bssid, *ssid, *ie = NULL;
3523 int err, ssid_len, ie_len = 0;
3524 enum nl80211_auth_type auth_type;
fffd0934 3525 struct key_parse key;
d5cdfacb 3526 bool local_state_change;
636a5d36 3527
f4a11bb0
JB
3528 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3529 return -EINVAL;
3530
3531 if (!info->attrs[NL80211_ATTR_MAC])
3532 return -EINVAL;
3533
1778092e
JM
3534 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3535 return -EINVAL;
3536
19957bb3
JB
3537 if (!info->attrs[NL80211_ATTR_SSID])
3538 return -EINVAL;
3539
3540 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3541 return -EINVAL;
3542
fffd0934
JB
3543 err = nl80211_parse_key(info, &key);
3544 if (err)
3545 return err;
3546
3547 if (key.idx >= 0) {
e31b8213
JB
3548 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3549 return -EINVAL;
fffd0934
JB
3550 if (!key.p.key || !key.p.key_len)
3551 return -EINVAL;
3552 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3553 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3554 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3555 key.p.key_len != WLAN_KEY_LEN_WEP104))
3556 return -EINVAL;
3557 if (key.idx > 4)
3558 return -EINVAL;
3559 } else {
3560 key.p.key_len = 0;
3561 key.p.key = NULL;
3562 }
3563
afea0b7a
JB
3564 if (key.idx >= 0) {
3565 int i;
3566 bool ok = false;
3567 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3568 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3569 ok = true;
3570 break;
3571 }
3572 }
4c476991
JB
3573 if (!ok)
3574 return -EINVAL;
afea0b7a
JB
3575 }
3576
4c476991
JB
3577 if (!rdev->ops->auth)
3578 return -EOPNOTSUPP;
636a5d36 3579
074ac8df 3580 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3581 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3582 return -EOPNOTSUPP;
eec60b03 3583
19957bb3 3584 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3585 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 3586 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3587 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3588 return -EINVAL;
636a5d36 3589
19957bb3
JB
3590 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3591 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3592
3593 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3594 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3595 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3596 }
3597
19957bb3 3598 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
3599 if (!nl80211_valid_auth_type(auth_type))
3600 return -EINVAL;
636a5d36 3601
d5cdfacb
JM
3602 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3603
4c476991
JB
3604 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3605 ssid, ssid_len, ie, ie_len,
3606 key.p.key, key.p.key_len, key.idx,
3607 local_state_change);
636a5d36
JM
3608}
3609
c0692b8f
JB
3610static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3611 struct genl_info *info,
3dc27d25
JB
3612 struct cfg80211_crypto_settings *settings,
3613 int cipher_limit)
b23aa676 3614{
c0b2bbd8
JB
3615 memset(settings, 0, sizeof(*settings));
3616
b23aa676
SO
3617 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3618
c0692b8f
JB
3619 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3620 u16 proto;
3621 proto = nla_get_u16(
3622 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3623 settings->control_port_ethertype = cpu_to_be16(proto);
3624 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3625 proto != ETH_P_PAE)
3626 return -EINVAL;
3627 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3628 settings->control_port_no_encrypt = true;
3629 } else
3630 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3631
b23aa676
SO
3632 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3633 void *data;
3634 int len, i;
3635
3636 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3637 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3638 settings->n_ciphers_pairwise = len / sizeof(u32);
3639
3640 if (len % sizeof(u32))
3641 return -EINVAL;
3642
3dc27d25 3643 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3644 return -EINVAL;
3645
3646 memcpy(settings->ciphers_pairwise, data, len);
3647
3648 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3649 if (!nl80211_valid_cipher_suite(
3650 settings->ciphers_pairwise[i]))
3651 return -EINVAL;
3652 }
3653
3654 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3655 settings->cipher_group =
3656 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3657 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3658 return -EINVAL;
3659 }
3660
3661 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3662 settings->wpa_versions =
3663 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3664 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3665 return -EINVAL;
3666 }
3667
3668 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3669 void *data;
3670 int len, i;
3671
3672 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3673 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3674 settings->n_akm_suites = len / sizeof(u32);
3675
3676 if (len % sizeof(u32))
3677 return -EINVAL;
3678
3679 memcpy(settings->akm_suites, data, len);
3680
3681 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3682 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3683 return -EINVAL;
3684 }
3685
3686 return 0;
3687}
3688
636a5d36
JM
3689static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3690{
4c476991
JB
3691 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3692 struct net_device *dev = info->user_ptr[1];
19957bb3 3693 struct cfg80211_crypto_settings crypto;
f444de05 3694 struct ieee80211_channel *chan;
3e5d7649 3695 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3696 int err, ssid_len, ie_len = 0;
3697 bool use_mfp = false;
636a5d36 3698
f4a11bb0
JB
3699 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3700 return -EINVAL;
3701
3702 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3703 !info->attrs[NL80211_ATTR_SSID] ||
3704 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3705 return -EINVAL;
3706
4c476991
JB
3707 if (!rdev->ops->assoc)
3708 return -EOPNOTSUPP;
636a5d36 3709
074ac8df 3710 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3711 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3712 return -EOPNOTSUPP;
eec60b03 3713
19957bb3 3714 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3715
19957bb3
JB
3716 chan = ieee80211_get_channel(&rdev->wiphy,
3717 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
3718 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3719 return -EINVAL;
636a5d36 3720
19957bb3
JB
3721 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3722 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3723
3724 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3725 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3726 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3727 }
3728
dc6382ce 3729 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3730 enum nl80211_mfp mfp =
dc6382ce 3731 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3732 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3733 use_mfp = true;
4c476991
JB
3734 else if (mfp != NL80211_MFP_NO)
3735 return -EINVAL;
dc6382ce
JM
3736 }
3737
3e5d7649
JB
3738 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3739 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3740
c0692b8f 3741 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 3742 if (!err)
3e5d7649
JB
3743 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3744 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3745 &crypto);
636a5d36 3746
636a5d36
JM
3747 return err;
3748}
3749
3750static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3751{
4c476991
JB
3752 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3753 struct net_device *dev = info->user_ptr[1];
19957bb3 3754 const u8 *ie = NULL, *bssid;
4c476991 3755 int ie_len = 0;
19957bb3 3756 u16 reason_code;
d5cdfacb 3757 bool local_state_change;
636a5d36 3758
f4a11bb0
JB
3759 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3760 return -EINVAL;
3761
3762 if (!info->attrs[NL80211_ATTR_MAC])
3763 return -EINVAL;
3764
3765 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3766 return -EINVAL;
3767
4c476991
JB
3768 if (!rdev->ops->deauth)
3769 return -EOPNOTSUPP;
636a5d36 3770
074ac8df 3771 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3772 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3773 return -EOPNOTSUPP;
eec60b03 3774
19957bb3 3775 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3776
19957bb3
JB
3777 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3778 if (reason_code == 0) {
f4a11bb0 3779 /* Reason Code 0 is reserved */
4c476991 3780 return -EINVAL;
255e737e 3781 }
636a5d36
JM
3782
3783 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3784 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3785 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3786 }
3787
d5cdfacb
JM
3788 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3789
4c476991
JB
3790 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3791 local_state_change);
636a5d36
JM
3792}
3793
3794static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3795{
4c476991
JB
3796 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3797 struct net_device *dev = info->user_ptr[1];
19957bb3 3798 const u8 *ie = NULL, *bssid;
4c476991 3799 int ie_len = 0;
19957bb3 3800 u16 reason_code;
d5cdfacb 3801 bool local_state_change;
636a5d36 3802
f4a11bb0
JB
3803 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3804 return -EINVAL;
3805
3806 if (!info->attrs[NL80211_ATTR_MAC])
3807 return -EINVAL;
3808
3809 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3810 return -EINVAL;
3811
4c476991
JB
3812 if (!rdev->ops->disassoc)
3813 return -EOPNOTSUPP;
636a5d36 3814
074ac8df 3815 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
3816 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3817 return -EOPNOTSUPP;
eec60b03 3818
19957bb3 3819 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3820
19957bb3
JB
3821 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3822 if (reason_code == 0) {
f4a11bb0 3823 /* Reason Code 0 is reserved */
4c476991 3824 return -EINVAL;
255e737e 3825 }
636a5d36
JM
3826
3827 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3828 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3829 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3830 }
3831
d5cdfacb
JM
3832 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3833
4c476991
JB
3834 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3835 local_state_change);
636a5d36
JM
3836}
3837
dd5b4cc7
FF
3838static bool
3839nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3840 int mcast_rate[IEEE80211_NUM_BANDS],
3841 int rateval)
3842{
3843 struct wiphy *wiphy = &rdev->wiphy;
3844 bool found = false;
3845 int band, i;
3846
3847 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3848 struct ieee80211_supported_band *sband;
3849
3850 sband = wiphy->bands[band];
3851 if (!sband)
3852 continue;
3853
3854 for (i = 0; i < sband->n_bitrates; i++) {
3855 if (sband->bitrates[i].bitrate == rateval) {
3856 mcast_rate[band] = i + 1;
3857 found = true;
3858 break;
3859 }
3860 }
3861 }
3862
3863 return found;
3864}
3865
04a773ad
JB
3866static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3867{
4c476991
JB
3868 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3869 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
3870 struct cfg80211_ibss_params ibss;
3871 struct wiphy *wiphy;
fffd0934 3872 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3873 int err;
3874
8e30bc55
JB
3875 memset(&ibss, 0, sizeof(ibss));
3876
04a773ad
JB
3877 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3878 return -EINVAL;
3879
3880 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3881 !info->attrs[NL80211_ATTR_SSID] ||
3882 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3883 return -EINVAL;
3884
8e30bc55
JB
3885 ibss.beacon_interval = 100;
3886
3887 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3888 ibss.beacon_interval =
3889 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3890 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3891 return -EINVAL;
3892 }
3893
4c476991
JB
3894 if (!rdev->ops->join_ibss)
3895 return -EOPNOTSUPP;
04a773ad 3896
4c476991
JB
3897 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3898 return -EOPNOTSUPP;
04a773ad 3899
79c97e97 3900 wiphy = &rdev->wiphy;
04a773ad
JB
3901
3902 if (info->attrs[NL80211_ATTR_MAC])
3903 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3904 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3905 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3906
3907 if (info->attrs[NL80211_ATTR_IE]) {
3908 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3909 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3910 }
3911
3912 ibss.channel = ieee80211_get_channel(wiphy,
3913 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3914 if (!ibss.channel ||
3915 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
3916 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
3917 return -EINVAL;
04a773ad
JB
3918
3919 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3920 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3921
fbd2c8dc
TP
3922 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3923 u8 *rates =
3924 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3925 int n_rates =
3926 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3927 struct ieee80211_supported_band *sband =
3928 wiphy->bands[ibss.channel->band];
3929 int i, j;
3930
4c476991
JB
3931 if (n_rates == 0)
3932 return -EINVAL;
fbd2c8dc
TP
3933
3934 for (i = 0; i < n_rates; i++) {
3935 int rate = (rates[i] & 0x7f) * 5;
3936 bool found = false;
3937
3938 for (j = 0; j < sband->n_bitrates; j++) {
3939 if (sband->bitrates[j].bitrate == rate) {
3940 found = true;
3941 ibss.basic_rates |= BIT(j);
3942 break;
3943 }
3944 }
4c476991
JB
3945 if (!found)
3946 return -EINVAL;
fbd2c8dc 3947 }
fbd2c8dc 3948 }
dd5b4cc7
FF
3949
3950 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
3951 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
3952 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
3953 return -EINVAL;
fbd2c8dc 3954
4c476991
JB
3955 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3956 connkeys = nl80211_parse_connkeys(rdev,
3957 info->attrs[NL80211_ATTR_KEYS]);
3958 if (IS_ERR(connkeys))
3959 return PTR_ERR(connkeys);
3960 }
04a773ad 3961
4c476991 3962 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
3963 if (err)
3964 kfree(connkeys);
04a773ad
JB
3965 return err;
3966}
3967
3968static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3969{
4c476991
JB
3970 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3971 struct net_device *dev = info->user_ptr[1];
04a773ad 3972
4c476991
JB
3973 if (!rdev->ops->leave_ibss)
3974 return -EOPNOTSUPP;
04a773ad 3975
4c476991
JB
3976 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3977 return -EOPNOTSUPP;
04a773ad 3978
4c476991 3979 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3980}
3981
aff89a9b
JB
3982#ifdef CONFIG_NL80211_TESTMODE
3983static struct genl_multicast_group nl80211_testmode_mcgrp = {
3984 .name = "testmode",
3985};
3986
3987static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3988{
4c476991 3989 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
3990 int err;
3991
3992 if (!info->attrs[NL80211_ATTR_TESTDATA])
3993 return -EINVAL;
3994
aff89a9b
JB
3995 err = -EOPNOTSUPP;
3996 if (rdev->ops->testmode_cmd) {
3997 rdev->testmode_info = info;
3998 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3999 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4000 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4001 rdev->testmode_info = NULL;
4002 }
4003
aff89a9b
JB
4004 return err;
4005}
4006
4007static struct sk_buff *
4008__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4009 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4010{
4011 struct sk_buff *skb;
4012 void *hdr;
4013 struct nlattr *data;
4014
4015 skb = nlmsg_new(approxlen + 100, gfp);
4016 if (!skb)
4017 return NULL;
4018
4019 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4020 if (!hdr) {
4021 kfree_skb(skb);
4022 return NULL;
4023 }
4024
4025 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4026 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4027
4028 ((void **)skb->cb)[0] = rdev;
4029 ((void **)skb->cb)[1] = hdr;
4030 ((void **)skb->cb)[2] = data;
4031
4032 return skb;
4033
4034 nla_put_failure:
4035 kfree_skb(skb);
4036 return NULL;
4037}
4038
4039struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4040 int approxlen)
4041{
4042 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4043
4044 if (WARN_ON(!rdev->testmode_info))
4045 return NULL;
4046
4047 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4048 rdev->testmode_info->snd_pid,
4049 rdev->testmode_info->snd_seq,
4050 GFP_KERNEL);
4051}
4052EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4053
4054int cfg80211_testmode_reply(struct sk_buff *skb)
4055{
4056 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4057 void *hdr = ((void **)skb->cb)[1];
4058 struct nlattr *data = ((void **)skb->cb)[2];
4059
4060 if (WARN_ON(!rdev->testmode_info)) {
4061 kfree_skb(skb);
4062 return -EINVAL;
4063 }
4064
4065 nla_nest_end(skb, data);
4066 genlmsg_end(skb, hdr);
4067 return genlmsg_reply(skb, rdev->testmode_info);
4068}
4069EXPORT_SYMBOL(cfg80211_testmode_reply);
4070
4071struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4072 int approxlen, gfp_t gfp)
4073{
4074 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4075
4076 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4077}
4078EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4079
4080void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4081{
4082 void *hdr = ((void **)skb->cb)[1];
4083 struct nlattr *data = ((void **)skb->cb)[2];
4084
4085 nla_nest_end(skb, data);
4086 genlmsg_end(skb, hdr);
4087 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4088}
4089EXPORT_SYMBOL(cfg80211_testmode_event);
4090#endif
4091
b23aa676
SO
4092static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4093{
4c476991
JB
4094 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4095 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4096 struct cfg80211_connect_params connect;
4097 struct wiphy *wiphy;
fffd0934 4098 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4099 int err;
4100
4101 memset(&connect, 0, sizeof(connect));
4102
4103 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4104 return -EINVAL;
4105
4106 if (!info->attrs[NL80211_ATTR_SSID] ||
4107 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4108 return -EINVAL;
4109
4110 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4111 connect.auth_type =
4112 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4113 if (!nl80211_valid_auth_type(connect.auth_type))
4114 return -EINVAL;
4115 } else
4116 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4117
4118 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4119
c0692b8f 4120 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 4121 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4122 if (err)
4123 return err;
b23aa676 4124
074ac8df 4125 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4126 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4127 return -EOPNOTSUPP;
b23aa676 4128
79c97e97 4129 wiphy = &rdev->wiphy;
b23aa676 4130
b23aa676
SO
4131 if (info->attrs[NL80211_ATTR_MAC])
4132 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4133 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4134 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4135
4136 if (info->attrs[NL80211_ATTR_IE]) {
4137 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4138 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4139 }
4140
4141 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4142 connect.channel =
4143 ieee80211_get_channel(wiphy,
4144 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4145 if (!connect.channel ||
4c476991
JB
4146 connect.channel->flags & IEEE80211_CHAN_DISABLED)
4147 return -EINVAL;
b23aa676
SO
4148 }
4149
fffd0934
JB
4150 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4151 connkeys = nl80211_parse_connkeys(rdev,
4152 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
4153 if (IS_ERR(connkeys))
4154 return PTR_ERR(connkeys);
fffd0934
JB
4155 }
4156
4157 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
4158 if (err)
4159 kfree(connkeys);
b23aa676
SO
4160 return err;
4161}
4162
4163static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4164{
4c476991
JB
4165 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4166 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
4167 u16 reason;
4168
4169 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4170 reason = WLAN_REASON_DEAUTH_LEAVING;
4171 else
4172 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4173
4174 if (reason == 0)
4175 return -EINVAL;
4176
074ac8df 4177 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4178 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4179 return -EOPNOTSUPP;
b23aa676 4180
4c476991 4181 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4182}
4183
463d0183
JB
4184static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4185{
4c476991 4186 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
4187 struct net *net;
4188 int err;
4189 u32 pid;
4190
4191 if (!info->attrs[NL80211_ATTR_PID])
4192 return -EINVAL;
4193
4194 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4195
463d0183 4196 net = get_net_ns_by_pid(pid);
4c476991
JB
4197 if (IS_ERR(net))
4198 return PTR_ERR(net);
463d0183
JB
4199
4200 err = 0;
4201
4202 /* check if anything to do */
4c476991
JB
4203 if (!net_eq(wiphy_net(&rdev->wiphy), net))
4204 err = cfg80211_switch_netns(rdev, net);
463d0183 4205
463d0183 4206 put_net(net);
463d0183
JB
4207 return err;
4208}
4209
67fbb16b
SO
4210static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4211{
4c476991 4212 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
4213 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4214 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 4215 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
4216 struct cfg80211_pmksa pmksa;
4217
4218 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4219
4220 if (!info->attrs[NL80211_ATTR_MAC])
4221 return -EINVAL;
4222
4223 if (!info->attrs[NL80211_ATTR_PMKID])
4224 return -EINVAL;
4225
67fbb16b
SO
4226 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4227 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4228
074ac8df 4229 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4230 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4231 return -EOPNOTSUPP;
67fbb16b
SO
4232
4233 switch (info->genlhdr->cmd) {
4234 case NL80211_CMD_SET_PMKSA:
4235 rdev_ops = rdev->ops->set_pmksa;
4236 break;
4237 case NL80211_CMD_DEL_PMKSA:
4238 rdev_ops = rdev->ops->del_pmksa;
4239 break;
4240 default:
4241 WARN_ON(1);
4242 break;
4243 }
4244
4c476991
JB
4245 if (!rdev_ops)
4246 return -EOPNOTSUPP;
67fbb16b 4247
4c476991 4248 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
4249}
4250
4251static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4252{
4c476991
JB
4253 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4254 struct net_device *dev = info->user_ptr[1];
67fbb16b 4255
074ac8df 4256 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4257 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4258 return -EOPNOTSUPP;
67fbb16b 4259
4c476991
JB
4260 if (!rdev->ops->flush_pmksa)
4261 return -EOPNOTSUPP;
67fbb16b 4262
4c476991 4263 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
4264}
4265
9588bbd5
JM
4266static int nl80211_remain_on_channel(struct sk_buff *skb,
4267 struct genl_info *info)
4268{
4c476991
JB
4269 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4270 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
4271 struct ieee80211_channel *chan;
4272 struct sk_buff *msg;
4273 void *hdr;
4274 u64 cookie;
4275 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4276 u32 freq, duration;
4277 int err;
4278
4279 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4280 !info->attrs[NL80211_ATTR_DURATION])
4281 return -EINVAL;
4282
4283 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4284
4285 /*
4286 * We should be on that channel for at least one jiffie,
4287 * and more than 5 seconds seems excessive.
4288 */
a293911d
JB
4289 if (!duration || !msecs_to_jiffies(duration) ||
4290 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
4291 return -EINVAL;
4292
4c476991
JB
4293 if (!rdev->ops->remain_on_channel)
4294 return -EOPNOTSUPP;
9588bbd5 4295
9588bbd5
JM
4296 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4297 channel_type = nla_get_u32(
4298 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4299 if (channel_type != NL80211_CHAN_NO_HT &&
4300 channel_type != NL80211_CHAN_HT20 &&
4301 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4302 channel_type != NL80211_CHAN_HT40MINUS)
4303 return -EINVAL;
9588bbd5
JM
4304 }
4305
4306 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4307 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4308 if (chan == NULL)
4309 return -EINVAL;
9588bbd5
JM
4310
4311 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4312 if (!msg)
4313 return -ENOMEM;
9588bbd5
JM
4314
4315 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4316 NL80211_CMD_REMAIN_ON_CHANNEL);
4317
4318 if (IS_ERR(hdr)) {
4319 err = PTR_ERR(hdr);
4320 goto free_msg;
4321 }
4322
4323 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4324 channel_type, duration, &cookie);
4325
4326 if (err)
4327 goto free_msg;
4328
4329 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4330
4331 genlmsg_end(msg, hdr);
4c476991
JB
4332
4333 return genlmsg_reply(msg, info);
9588bbd5
JM
4334
4335 nla_put_failure:
4336 err = -ENOBUFS;
4337 free_msg:
4338 nlmsg_free(msg);
9588bbd5
JM
4339 return err;
4340}
4341
4342static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4343 struct genl_info *info)
4344{
4c476991
JB
4345 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4346 struct net_device *dev = info->user_ptr[1];
9588bbd5 4347 u64 cookie;
9588bbd5
JM
4348
4349 if (!info->attrs[NL80211_ATTR_COOKIE])
4350 return -EINVAL;
4351
4c476991
JB
4352 if (!rdev->ops->cancel_remain_on_channel)
4353 return -EOPNOTSUPP;
9588bbd5 4354
9588bbd5
JM
4355 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4356
4c476991 4357 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
4358}
4359
13ae75b1
JM
4360static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4361 u8 *rates, u8 rates_len)
4362{
4363 u8 i;
4364 u32 mask = 0;
4365
4366 for (i = 0; i < rates_len; i++) {
4367 int rate = (rates[i] & 0x7f) * 5;
4368 int ridx;
4369 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4370 struct ieee80211_rate *srate =
4371 &sband->bitrates[ridx];
4372 if (rate == srate->bitrate) {
4373 mask |= 1 << ridx;
4374 break;
4375 }
4376 }
4377 if (ridx == sband->n_bitrates)
4378 return 0; /* rate not found */
4379 }
4380
4381 return mask;
4382}
4383
b54452b0 4384static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4385 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4386 .len = NL80211_MAX_SUPP_RATES },
4387};
4388
4389static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4390 struct genl_info *info)
4391{
4392 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 4393 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 4394 struct cfg80211_bitrate_mask mask;
4c476991
JB
4395 int rem, i;
4396 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
4397 struct nlattr *tx_rates;
4398 struct ieee80211_supported_band *sband;
4399
4400 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4401 return -EINVAL;
4402
4c476991
JB
4403 if (!rdev->ops->set_bitrate_mask)
4404 return -EOPNOTSUPP;
13ae75b1
JM
4405
4406 memset(&mask, 0, sizeof(mask));
4407 /* Default to all rates enabled */
4408 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4409 sband = rdev->wiphy.bands[i];
4410 mask.control[i].legacy =
4411 sband ? (1 << sband->n_bitrates) - 1 : 0;
4412 }
4413
4414 /*
4415 * The nested attribute uses enum nl80211_band as the index. This maps
4416 * directly to the enum ieee80211_band values used in cfg80211.
4417 */
4418 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4419 {
4420 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
4421 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4422 return -EINVAL;
13ae75b1 4423 sband = rdev->wiphy.bands[band];
4c476991
JB
4424 if (sband == NULL)
4425 return -EINVAL;
13ae75b1
JM
4426 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4427 nla_len(tx_rates), nl80211_txattr_policy);
4428 if (tb[NL80211_TXRATE_LEGACY]) {
4429 mask.control[band].legacy = rateset_to_mask(
4430 sband,
4431 nla_data(tb[NL80211_TXRATE_LEGACY]),
4432 nla_len(tb[NL80211_TXRATE_LEGACY]));
4c476991
JB
4433 if (mask.control[band].legacy == 0)
4434 return -EINVAL;
13ae75b1
JM
4435 }
4436 }
4437
4c476991 4438 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
4439}
4440
2e161f78 4441static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4442{
4c476991
JB
4443 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4444 struct net_device *dev = info->user_ptr[1];
2e161f78 4445 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
4446
4447 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4448 return -EINVAL;
4449
2e161f78
JB
4450 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4451 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 4452
9d38d85d 4453 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4454 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4455 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4456 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4457 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4458 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4459 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4460 return -EOPNOTSUPP;
026331c4
JM
4461
4462 /* not much point in registering if we can't reply */
4c476991
JB
4463 if (!rdev->ops->mgmt_tx)
4464 return -EOPNOTSUPP;
026331c4 4465
4c476991 4466 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 4467 frame_type,
026331c4
JM
4468 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4469 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
4470}
4471
2e161f78 4472static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 4473{
4c476991
JB
4474 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4475 struct net_device *dev = info->user_ptr[1];
026331c4
JM
4476 struct ieee80211_channel *chan;
4477 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4478 bool channel_type_valid = false;
026331c4
JM
4479 u32 freq;
4480 int err;
4481 void *hdr;
4482 u64 cookie;
4483 struct sk_buff *msg;
f7ca38df
JB
4484 unsigned int wait = 0;
4485 bool offchan;
026331c4
JM
4486
4487 if (!info->attrs[NL80211_ATTR_FRAME] ||
4488 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4489 return -EINVAL;
4490
4c476991
JB
4491 if (!rdev->ops->mgmt_tx)
4492 return -EOPNOTSUPP;
026331c4 4493
9d38d85d 4494 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 4495 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
4496 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4497 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4498 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 4499 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
4500 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4501 return -EOPNOTSUPP;
026331c4 4502
f7ca38df
JB
4503 if (info->attrs[NL80211_ATTR_DURATION]) {
4504 if (!rdev->ops->mgmt_tx_cancel_wait)
4505 return -EINVAL;
4506 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4507 }
4508
026331c4
JM
4509 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4510 channel_type = nla_get_u32(
4511 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4512 if (channel_type != NL80211_CHAN_NO_HT &&
4513 channel_type != NL80211_CHAN_HT20 &&
4514 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
4515 channel_type != NL80211_CHAN_HT40MINUS)
4516 return -EINVAL;
252aa631 4517 channel_type_valid = true;
026331c4
JM
4518 }
4519
f7ca38df
JB
4520 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4521
026331c4
JM
4522 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4523 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
4524 if (chan == NULL)
4525 return -EINVAL;
026331c4
JM
4526
4527 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4528 if (!msg)
4529 return -ENOMEM;
026331c4
JM
4530
4531 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2e161f78 4532 NL80211_CMD_FRAME);
026331c4
JM
4533
4534 if (IS_ERR(hdr)) {
4535 err = PTR_ERR(hdr);
4536 goto free_msg;
4537 }
f7ca38df
JB
4538 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4539 channel_type_valid, wait,
2e161f78
JB
4540 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4541 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4542 &cookie);
026331c4
JM
4543 if (err)
4544 goto free_msg;
4545
4546 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4547
4548 genlmsg_end(msg, hdr);
4c476991 4549 return genlmsg_reply(msg, info);
026331c4
JM
4550
4551 nla_put_failure:
4552 err = -ENOBUFS;
4553 free_msg:
4554 nlmsg_free(msg);
026331c4
JM
4555 return err;
4556}
4557
f7ca38df
JB
4558static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4559{
4560 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4561 struct net_device *dev = info->user_ptr[1];
4562 u64 cookie;
4563
4564 if (!info->attrs[NL80211_ATTR_COOKIE])
4565 return -EINVAL;
4566
4567 if (!rdev->ops->mgmt_tx_cancel_wait)
4568 return -EOPNOTSUPP;
4569
4570 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4571 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4572 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4573 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4574 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4575 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4576 return -EOPNOTSUPP;
4577
4578 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4579
4580 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4581}
4582
ffb9eb3d
KV
4583static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4584{
4c476991 4585 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 4586 struct wireless_dev *wdev;
4c476991 4587 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4588 u8 ps_state;
4589 bool state;
4590 int err;
4591
4c476991
JB
4592 if (!info->attrs[NL80211_ATTR_PS_STATE])
4593 return -EINVAL;
ffb9eb3d
KV
4594
4595 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4596
4c476991
JB
4597 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4598 return -EINVAL;
ffb9eb3d
KV
4599
4600 wdev = dev->ieee80211_ptr;
4601
4c476991
JB
4602 if (!rdev->ops->set_power_mgmt)
4603 return -EOPNOTSUPP;
ffb9eb3d
KV
4604
4605 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4606
4607 if (state == wdev->ps)
4c476991 4608 return 0;
ffb9eb3d 4609
4c476991
JB
4610 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4611 wdev->ps_timeout);
4612 if (!err)
4613 wdev->ps = state;
ffb9eb3d
KV
4614 return err;
4615}
4616
4617static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4618{
4c476991 4619 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
4620 enum nl80211_ps_state ps_state;
4621 struct wireless_dev *wdev;
4c476991 4622 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
4623 struct sk_buff *msg;
4624 void *hdr;
4625 int err;
4626
ffb9eb3d
KV
4627 wdev = dev->ieee80211_ptr;
4628
4c476991
JB
4629 if (!rdev->ops->set_power_mgmt)
4630 return -EOPNOTSUPP;
ffb9eb3d
KV
4631
4632 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
4633 if (!msg)
4634 return -ENOMEM;
ffb9eb3d
KV
4635
4636 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4637 NL80211_CMD_GET_POWER_SAVE);
4638 if (!hdr) {
4c476991 4639 err = -ENOBUFS;
ffb9eb3d
KV
4640 goto free_msg;
4641 }
4642
4643 if (wdev->ps)
4644 ps_state = NL80211_PS_ENABLED;
4645 else
4646 ps_state = NL80211_PS_DISABLED;
4647
4648 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4649
4650 genlmsg_end(msg, hdr);
4c476991 4651 return genlmsg_reply(msg, info);
ffb9eb3d 4652
4c476991 4653 nla_put_failure:
ffb9eb3d 4654 err = -ENOBUFS;
4c476991 4655 free_msg:
ffb9eb3d 4656 nlmsg_free(msg);
ffb9eb3d
KV
4657 return err;
4658}
4659
d6dc1a38
JO
4660static struct nla_policy
4661nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4662 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4663 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4664 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4665};
4666
4667static int nl80211_set_cqm_rssi(struct genl_info *info,
4668 s32 threshold, u32 hysteresis)
4669{
4c476991 4670 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 4671 struct wireless_dev *wdev;
4c476991 4672 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
4673
4674 if (threshold > 0)
4675 return -EINVAL;
4676
d6dc1a38
JO
4677 wdev = dev->ieee80211_ptr;
4678
4c476991
JB
4679 if (!rdev->ops->set_cqm_rssi_config)
4680 return -EOPNOTSUPP;
d6dc1a38 4681
074ac8df 4682 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4683 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4684 return -EOPNOTSUPP;
d6dc1a38 4685
4c476991
JB
4686 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4687 threshold, hysteresis);
d6dc1a38
JO
4688}
4689
4690static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4691{
4692 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4693 struct nlattr *cqm;
4694 int err;
4695
4696 cqm = info->attrs[NL80211_ATTR_CQM];
4697 if (!cqm) {
4698 err = -EINVAL;
4699 goto out;
4700 }
4701
4702 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4703 nl80211_attr_cqm_policy);
4704 if (err)
4705 goto out;
4706
4707 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4708 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4709 s32 threshold;
4710 u32 hysteresis;
4711 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4712 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4713 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4714 } else
4715 err = -EINVAL;
4716
4717out:
4718 return err;
4719}
4720
29cbe68c
JB
4721static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
4722{
4723 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4724 struct net_device *dev = info->user_ptr[1];
4725 struct mesh_config cfg;
c80d545d 4726 struct mesh_setup setup;
29cbe68c
JB
4727 int err;
4728
4729 /* start with default */
4730 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 4731 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 4732
24bdd9f4 4733 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 4734 /* and parse parameters if given */
24bdd9f4 4735 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
4736 if (err)
4737 return err;
4738 }
4739
4740 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
4741 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
4742 return -EINVAL;
4743
c80d545d
JC
4744 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
4745 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
4746
4747 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
4748 /* parse additional setup parameters if given */
4749 err = nl80211_parse_mesh_setup(info, &setup);
4750 if (err)
4751 return err;
4752 }
4753
4754 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
4755}
4756
4757static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
4758{
4759 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4760 struct net_device *dev = info->user_ptr[1];
4761
4762 return cfg80211_leave_mesh(rdev, dev);
4763}
4764
4c476991
JB
4765#define NL80211_FLAG_NEED_WIPHY 0x01
4766#define NL80211_FLAG_NEED_NETDEV 0x02
4767#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
4768#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
4769#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
4770 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
4771
4772static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
4773 struct genl_info *info)
4774{
4775 struct cfg80211_registered_device *rdev;
4776 struct net_device *dev;
4777 int err;
4778 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
4779
4780 if (rtnl)
4781 rtnl_lock();
4782
4783 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4784 rdev = cfg80211_get_dev_from_info(info);
4785 if (IS_ERR(rdev)) {
4786 if (rtnl)
4787 rtnl_unlock();
4788 return PTR_ERR(rdev);
4789 }
4790 info->user_ptr[0] = rdev;
4791 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
4792 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4793 if (err) {
4794 if (rtnl)
4795 rtnl_unlock();
4796 return err;
4797 }
41265714
JB
4798 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
4799 !netif_running(dev)) {
d537f5fd
JB
4800 cfg80211_unlock_rdev(rdev);
4801 dev_put(dev);
41265714
JB
4802 if (rtnl)
4803 rtnl_unlock();
4804 return -ENETDOWN;
4805 }
4c476991
JB
4806 info->user_ptr[0] = rdev;
4807 info->user_ptr[1] = dev;
4808 }
4809
4810 return 0;
4811}
4812
4813static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
4814 struct genl_info *info)
4815{
4816 if (info->user_ptr[0])
4817 cfg80211_unlock_rdev(info->user_ptr[0]);
4818 if (info->user_ptr[1])
4819 dev_put(info->user_ptr[1]);
4820 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
4821 rtnl_unlock();
4822}
4823
55682965
JB
4824static struct genl_ops nl80211_ops[] = {
4825 {
4826 .cmd = NL80211_CMD_GET_WIPHY,
4827 .doit = nl80211_get_wiphy,
4828 .dumpit = nl80211_dump_wiphy,
4829 .policy = nl80211_policy,
4830 /* can be retrieved by unprivileged users */
4c476991 4831 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
4832 },
4833 {
4834 .cmd = NL80211_CMD_SET_WIPHY,
4835 .doit = nl80211_set_wiphy,
4836 .policy = nl80211_policy,
4837 .flags = GENL_ADMIN_PERM,
4c476991 4838 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
4839 },
4840 {
4841 .cmd = NL80211_CMD_GET_INTERFACE,
4842 .doit = nl80211_get_interface,
4843 .dumpit = nl80211_dump_interface,
4844 .policy = nl80211_policy,
4845 /* can be retrieved by unprivileged users */
4c476991 4846 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
4847 },
4848 {
4849 .cmd = NL80211_CMD_SET_INTERFACE,
4850 .doit = nl80211_set_interface,
4851 .policy = nl80211_policy,
4852 .flags = GENL_ADMIN_PERM,
4c476991
JB
4853 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4854 NL80211_FLAG_NEED_RTNL,
55682965
JB
4855 },
4856 {
4857 .cmd = NL80211_CMD_NEW_INTERFACE,
4858 .doit = nl80211_new_interface,
4859 .policy = nl80211_policy,
4860 .flags = GENL_ADMIN_PERM,
4c476991
JB
4861 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4862 NL80211_FLAG_NEED_RTNL,
55682965
JB
4863 },
4864 {
4865 .cmd = NL80211_CMD_DEL_INTERFACE,
4866 .doit = nl80211_del_interface,
4867 .policy = nl80211_policy,
41ade00f 4868 .flags = GENL_ADMIN_PERM,
4c476991
JB
4869 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4870 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4871 },
4872 {
4873 .cmd = NL80211_CMD_GET_KEY,
4874 .doit = nl80211_get_key,
4875 .policy = nl80211_policy,
4876 .flags = GENL_ADMIN_PERM,
4c476991
JB
4877 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4878 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4879 },
4880 {
4881 .cmd = NL80211_CMD_SET_KEY,
4882 .doit = nl80211_set_key,
4883 .policy = nl80211_policy,
4884 .flags = GENL_ADMIN_PERM,
41265714 4885 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4886 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4887 },
4888 {
4889 .cmd = NL80211_CMD_NEW_KEY,
4890 .doit = nl80211_new_key,
4891 .policy = nl80211_policy,
4892 .flags = GENL_ADMIN_PERM,
41265714 4893 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4894 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
4895 },
4896 {
4897 .cmd = NL80211_CMD_DEL_KEY,
4898 .doit = nl80211_del_key,
4899 .policy = nl80211_policy,
55682965 4900 .flags = GENL_ADMIN_PERM,
41265714 4901 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4902 NL80211_FLAG_NEED_RTNL,
55682965 4903 },
ed1b6cc7
JB
4904 {
4905 .cmd = NL80211_CMD_SET_BEACON,
4906 .policy = nl80211_policy,
4907 .flags = GENL_ADMIN_PERM,
4908 .doit = nl80211_addset_beacon,
4c476991
JB
4909 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4910 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4911 },
4912 {
4913 .cmd = NL80211_CMD_NEW_BEACON,
4914 .policy = nl80211_policy,
4915 .flags = GENL_ADMIN_PERM,
4916 .doit = nl80211_addset_beacon,
4c476991
JB
4917 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4918 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
4919 },
4920 {
4921 .cmd = NL80211_CMD_DEL_BEACON,
4922 .policy = nl80211_policy,
4923 .flags = GENL_ADMIN_PERM,
4924 .doit = nl80211_del_beacon,
4c476991
JB
4925 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4926 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 4927 },
5727ef1b
JB
4928 {
4929 .cmd = NL80211_CMD_GET_STATION,
4930 .doit = nl80211_get_station,
2ec600d6 4931 .dumpit = nl80211_dump_station,
5727ef1b 4932 .policy = nl80211_policy,
4c476991
JB
4933 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4934 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4935 },
4936 {
4937 .cmd = NL80211_CMD_SET_STATION,
4938 .doit = nl80211_set_station,
4939 .policy = nl80211_policy,
4940 .flags = GENL_ADMIN_PERM,
4c476991
JB
4941 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4942 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4943 },
4944 {
4945 .cmd = NL80211_CMD_NEW_STATION,
4946 .doit = nl80211_new_station,
4947 .policy = nl80211_policy,
4948 .flags = GENL_ADMIN_PERM,
41265714 4949 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4950 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
4951 },
4952 {
4953 .cmd = NL80211_CMD_DEL_STATION,
4954 .doit = nl80211_del_station,
4955 .policy = nl80211_policy,
2ec600d6 4956 .flags = GENL_ADMIN_PERM,
4c476991
JB
4957 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4958 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4959 },
4960 {
4961 .cmd = NL80211_CMD_GET_MPATH,
4962 .doit = nl80211_get_mpath,
4963 .dumpit = nl80211_dump_mpath,
4964 .policy = nl80211_policy,
4965 .flags = GENL_ADMIN_PERM,
41265714 4966 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4967 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4968 },
4969 {
4970 .cmd = NL80211_CMD_SET_MPATH,
4971 .doit = nl80211_set_mpath,
4972 .policy = nl80211_policy,
4973 .flags = GENL_ADMIN_PERM,
41265714 4974 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4975 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4976 },
4977 {
4978 .cmd = NL80211_CMD_NEW_MPATH,
4979 .doit = nl80211_new_mpath,
4980 .policy = nl80211_policy,
4981 .flags = GENL_ADMIN_PERM,
41265714 4982 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 4983 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
4984 },
4985 {
4986 .cmd = NL80211_CMD_DEL_MPATH,
4987 .doit = nl80211_del_mpath,
4988 .policy = nl80211_policy,
9f1ba906 4989 .flags = GENL_ADMIN_PERM,
4c476991
JB
4990 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4991 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
4992 },
4993 {
4994 .cmd = NL80211_CMD_SET_BSS,
4995 .doit = nl80211_set_bss,
4996 .policy = nl80211_policy,
b2e1b302 4997 .flags = GENL_ADMIN_PERM,
4c476991
JB
4998 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4999 NL80211_FLAG_NEED_RTNL,
b2e1b302 5000 },
f130347c
LR
5001 {
5002 .cmd = NL80211_CMD_GET_REG,
5003 .doit = nl80211_get_reg,
5004 .policy = nl80211_policy,
5005 /* can be retrieved by unprivileged users */
5006 },
b2e1b302
LR
5007 {
5008 .cmd = NL80211_CMD_SET_REG,
5009 .doit = nl80211_set_reg,
5010 .policy = nl80211_policy,
5011 .flags = GENL_ADMIN_PERM,
5012 },
5013 {
5014 .cmd = NL80211_CMD_REQ_SET_REG,
5015 .doit = nl80211_req_set_reg,
5016 .policy = nl80211_policy,
93da9cc1 5017 .flags = GENL_ADMIN_PERM,
5018 },
5019 {
24bdd9f4
JC
5020 .cmd = NL80211_CMD_GET_MESH_CONFIG,
5021 .doit = nl80211_get_mesh_config,
93da9cc1 5022 .policy = nl80211_policy,
5023 /* can be retrieved by unprivileged users */
4c476991
JB
5024 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5025 NL80211_FLAG_NEED_RTNL,
93da9cc1 5026 },
5027 {
24bdd9f4
JC
5028 .cmd = NL80211_CMD_SET_MESH_CONFIG,
5029 .doit = nl80211_update_mesh_config,
93da9cc1 5030 .policy = nl80211_policy,
9aed3cc1 5031 .flags = GENL_ADMIN_PERM,
29cbe68c 5032 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5033 NL80211_FLAG_NEED_RTNL,
9aed3cc1 5034 },
2a519311
JB
5035 {
5036 .cmd = NL80211_CMD_TRIGGER_SCAN,
5037 .doit = nl80211_trigger_scan,
5038 .policy = nl80211_policy,
5039 .flags = GENL_ADMIN_PERM,
41265714 5040 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5041 NL80211_FLAG_NEED_RTNL,
2a519311
JB
5042 },
5043 {
5044 .cmd = NL80211_CMD_GET_SCAN,
5045 .policy = nl80211_policy,
5046 .dumpit = nl80211_dump_scan,
5047 },
636a5d36
JM
5048 {
5049 .cmd = NL80211_CMD_AUTHENTICATE,
5050 .doit = nl80211_authenticate,
5051 .policy = nl80211_policy,
5052 .flags = GENL_ADMIN_PERM,
41265714 5053 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5054 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5055 },
5056 {
5057 .cmd = NL80211_CMD_ASSOCIATE,
5058 .doit = nl80211_associate,
5059 .policy = nl80211_policy,
5060 .flags = GENL_ADMIN_PERM,
41265714 5061 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5062 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5063 },
5064 {
5065 .cmd = NL80211_CMD_DEAUTHENTICATE,
5066 .doit = nl80211_deauthenticate,
5067 .policy = nl80211_policy,
5068 .flags = GENL_ADMIN_PERM,
41265714 5069 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5070 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
5071 },
5072 {
5073 .cmd = NL80211_CMD_DISASSOCIATE,
5074 .doit = nl80211_disassociate,
5075 .policy = nl80211_policy,
5076 .flags = GENL_ADMIN_PERM,
41265714 5077 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5078 NL80211_FLAG_NEED_RTNL,
636a5d36 5079 },
04a773ad
JB
5080 {
5081 .cmd = NL80211_CMD_JOIN_IBSS,
5082 .doit = nl80211_join_ibss,
5083 .policy = nl80211_policy,
5084 .flags = GENL_ADMIN_PERM,
41265714 5085 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5086 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
5087 },
5088 {
5089 .cmd = NL80211_CMD_LEAVE_IBSS,
5090 .doit = nl80211_leave_ibss,
5091 .policy = nl80211_policy,
5092 .flags = GENL_ADMIN_PERM,
41265714 5093 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5094 NL80211_FLAG_NEED_RTNL,
04a773ad 5095 },
aff89a9b
JB
5096#ifdef CONFIG_NL80211_TESTMODE
5097 {
5098 .cmd = NL80211_CMD_TESTMODE,
5099 .doit = nl80211_testmode_do,
5100 .policy = nl80211_policy,
5101 .flags = GENL_ADMIN_PERM,
4c476991
JB
5102 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5103 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
5104 },
5105#endif
b23aa676
SO
5106 {
5107 .cmd = NL80211_CMD_CONNECT,
5108 .doit = nl80211_connect,
5109 .policy = nl80211_policy,
5110 .flags = GENL_ADMIN_PERM,
41265714 5111 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5112 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
5113 },
5114 {
5115 .cmd = NL80211_CMD_DISCONNECT,
5116 .doit = nl80211_disconnect,
5117 .policy = nl80211_policy,
5118 .flags = GENL_ADMIN_PERM,
41265714 5119 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5120 NL80211_FLAG_NEED_RTNL,
b23aa676 5121 },
463d0183
JB
5122 {
5123 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5124 .doit = nl80211_wiphy_netns,
5125 .policy = nl80211_policy,
5126 .flags = GENL_ADMIN_PERM,
4c476991
JB
5127 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5128 NL80211_FLAG_NEED_RTNL,
463d0183 5129 },
61fa713c
HS
5130 {
5131 .cmd = NL80211_CMD_GET_SURVEY,
5132 .policy = nl80211_policy,
5133 .dumpit = nl80211_dump_survey,
5134 },
67fbb16b
SO
5135 {
5136 .cmd = NL80211_CMD_SET_PMKSA,
5137 .doit = nl80211_setdel_pmksa,
5138 .policy = nl80211_policy,
5139 .flags = GENL_ADMIN_PERM,
4c476991
JB
5140 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5141 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5142 },
5143 {
5144 .cmd = NL80211_CMD_DEL_PMKSA,
5145 .doit = nl80211_setdel_pmksa,
5146 .policy = nl80211_policy,
5147 .flags = GENL_ADMIN_PERM,
4c476991
JB
5148 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5149 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
5150 },
5151 {
5152 .cmd = NL80211_CMD_FLUSH_PMKSA,
5153 .doit = nl80211_flush_pmksa,
5154 .policy = nl80211_policy,
5155 .flags = GENL_ADMIN_PERM,
4c476991
JB
5156 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5157 NL80211_FLAG_NEED_RTNL,
67fbb16b 5158 },
9588bbd5
JM
5159 {
5160 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5161 .doit = nl80211_remain_on_channel,
5162 .policy = nl80211_policy,
5163 .flags = GENL_ADMIN_PERM,
41265714 5164 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5165 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
5166 },
5167 {
5168 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5169 .doit = nl80211_cancel_remain_on_channel,
5170 .policy = nl80211_policy,
5171 .flags = GENL_ADMIN_PERM,
41265714 5172 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5173 NL80211_FLAG_NEED_RTNL,
9588bbd5 5174 },
13ae75b1
JM
5175 {
5176 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5177 .doit = nl80211_set_tx_bitrate_mask,
5178 .policy = nl80211_policy,
5179 .flags = GENL_ADMIN_PERM,
4c476991
JB
5180 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5181 NL80211_FLAG_NEED_RTNL,
13ae75b1 5182 },
026331c4 5183 {
2e161f78
JB
5184 .cmd = NL80211_CMD_REGISTER_FRAME,
5185 .doit = nl80211_register_mgmt,
026331c4
JM
5186 .policy = nl80211_policy,
5187 .flags = GENL_ADMIN_PERM,
4c476991
JB
5188 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5189 NL80211_FLAG_NEED_RTNL,
026331c4
JM
5190 },
5191 {
2e161f78
JB
5192 .cmd = NL80211_CMD_FRAME,
5193 .doit = nl80211_tx_mgmt,
026331c4 5194 .policy = nl80211_policy,
f7ca38df
JB
5195 .flags = GENL_ADMIN_PERM,
5196 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5197 NL80211_FLAG_NEED_RTNL,
5198 },
5199 {
5200 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5201 .doit = nl80211_tx_mgmt_cancel_wait,
5202 .policy = nl80211_policy,
026331c4 5203 .flags = GENL_ADMIN_PERM,
41265714 5204 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 5205 NL80211_FLAG_NEED_RTNL,
026331c4 5206 },
ffb9eb3d
KV
5207 {
5208 .cmd = NL80211_CMD_SET_POWER_SAVE,
5209 .doit = nl80211_set_power_save,
5210 .policy = nl80211_policy,
5211 .flags = GENL_ADMIN_PERM,
4c476991
JB
5212 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5213 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
5214 },
5215 {
5216 .cmd = NL80211_CMD_GET_POWER_SAVE,
5217 .doit = nl80211_get_power_save,
5218 .policy = nl80211_policy,
5219 /* can be retrieved by unprivileged users */
4c476991
JB
5220 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5221 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 5222 },
d6dc1a38
JO
5223 {
5224 .cmd = NL80211_CMD_SET_CQM,
5225 .doit = nl80211_set_cqm,
5226 .policy = nl80211_policy,
5227 .flags = GENL_ADMIN_PERM,
4c476991
JB
5228 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5229 NL80211_FLAG_NEED_RTNL,
d6dc1a38 5230 },
f444de05
JB
5231 {
5232 .cmd = NL80211_CMD_SET_CHANNEL,
5233 .doit = nl80211_set_channel,
5234 .policy = nl80211_policy,
5235 .flags = GENL_ADMIN_PERM,
4c476991
JB
5236 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5237 NL80211_FLAG_NEED_RTNL,
f444de05 5238 },
e8347eba
BJ
5239 {
5240 .cmd = NL80211_CMD_SET_WDS_PEER,
5241 .doit = nl80211_set_wds_peer,
5242 .policy = nl80211_policy,
5243 .flags = GENL_ADMIN_PERM,
43b19952
JB
5244 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5245 NL80211_FLAG_NEED_RTNL,
e8347eba 5246 },
29cbe68c
JB
5247 {
5248 .cmd = NL80211_CMD_JOIN_MESH,
5249 .doit = nl80211_join_mesh,
5250 .policy = nl80211_policy,
5251 .flags = GENL_ADMIN_PERM,
5252 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5253 NL80211_FLAG_NEED_RTNL,
5254 },
5255 {
5256 .cmd = NL80211_CMD_LEAVE_MESH,
5257 .doit = nl80211_leave_mesh,
5258 .policy = nl80211_policy,
5259 .flags = GENL_ADMIN_PERM,
5260 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5261 NL80211_FLAG_NEED_RTNL,
5262 },
55682965 5263};
9588bbd5 5264
6039f6d2
JM
5265static struct genl_multicast_group nl80211_mlme_mcgrp = {
5266 .name = "mlme",
5267};
55682965
JB
5268
5269/* multicast groups */
5270static struct genl_multicast_group nl80211_config_mcgrp = {
5271 .name = "config",
5272};
2a519311
JB
5273static struct genl_multicast_group nl80211_scan_mcgrp = {
5274 .name = "scan",
5275};
73d54c9e
LR
5276static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5277 .name = "regulatory",
5278};
55682965
JB
5279
5280/* notification functions */
5281
5282void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5283{
5284 struct sk_buff *msg;
5285
fd2120ca 5286 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5287 if (!msg)
5288 return;
5289
5290 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5291 nlmsg_free(msg);
5292 return;
5293 }
5294
463d0183
JB
5295 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5296 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5297}
5298
362a415d
JB
5299static int nl80211_add_scan_req(struct sk_buff *msg,
5300 struct cfg80211_registered_device *rdev)
5301{
5302 struct cfg80211_scan_request *req = rdev->scan_req;
5303 struct nlattr *nest;
5304 int i;
5305
667503dd
JB
5306 ASSERT_RDEV_LOCK(rdev);
5307
362a415d
JB
5308 if (WARN_ON(!req))
5309 return 0;
5310
5311 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5312 if (!nest)
5313 goto nla_put_failure;
5314 for (i = 0; i < req->n_ssids; i++)
5315 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5316 nla_nest_end(msg, nest);
5317
5318 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5319 if (!nest)
5320 goto nla_put_failure;
5321 for (i = 0; i < req->n_channels; i++)
5322 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5323 nla_nest_end(msg, nest);
5324
5325 if (req->ie)
5326 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5327
5328 return 0;
5329 nla_put_failure:
5330 return -ENOBUFS;
5331}
5332
a538e2d5
JB
5333static int nl80211_send_scan_msg(struct sk_buff *msg,
5334 struct cfg80211_registered_device *rdev,
5335 struct net_device *netdev,
5336 u32 pid, u32 seq, int flags,
5337 u32 cmd)
2a519311
JB
5338{
5339 void *hdr;
5340
5341 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5342 if (!hdr)
5343 return -1;
5344
b5850a7a 5345 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5346 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5347
362a415d
JB
5348 /* ignore errors and send incomplete event anyway */
5349 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5350
5351 return genlmsg_end(msg, hdr);
5352
5353 nla_put_failure:
5354 genlmsg_cancel(msg, hdr);
5355 return -EMSGSIZE;
5356}
5357
a538e2d5
JB
5358void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5359 struct net_device *netdev)
5360{
5361 struct sk_buff *msg;
5362
5363 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5364 if (!msg)
5365 return;
5366
5367 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5368 NL80211_CMD_TRIGGER_SCAN) < 0) {
5369 nlmsg_free(msg);
5370 return;
5371 }
5372
463d0183
JB
5373 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5374 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5375}
5376
2a519311
JB
5377void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5378 struct net_device *netdev)
5379{
5380 struct sk_buff *msg;
5381
fd2120ca 5382 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5383 if (!msg)
5384 return;
5385
a538e2d5
JB
5386 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5387 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5388 nlmsg_free(msg);
5389 return;
5390 }
5391
463d0183
JB
5392 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5393 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5394}
5395
5396void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5397 struct net_device *netdev)
5398{
5399 struct sk_buff *msg;
5400
fd2120ca 5401 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5402 if (!msg)
5403 return;
5404
a538e2d5
JB
5405 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5406 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5407 nlmsg_free(msg);
5408 return;
5409 }
5410
463d0183
JB
5411 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5412 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5413}
5414
73d54c9e
LR
5415/*
5416 * This can happen on global regulatory changes or device specific settings
5417 * based on custom world regulatory domains.
5418 */
5419void nl80211_send_reg_change_event(struct regulatory_request *request)
5420{
5421 struct sk_buff *msg;
5422 void *hdr;
5423
fd2120ca 5424 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5425 if (!msg)
5426 return;
5427
5428 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5429 if (!hdr) {
5430 nlmsg_free(msg);
5431 return;
5432 }
5433
5434 /* Userspace can always count this one always being set */
5435 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5436
5437 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5438 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5439 NL80211_REGDOM_TYPE_WORLD);
5440 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5441 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5442 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5443 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5444 request->intersect)
5445 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5446 NL80211_REGDOM_TYPE_INTERSECTION);
5447 else {
5448 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5449 NL80211_REGDOM_TYPE_COUNTRY);
5450 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5451 }
5452
5453 if (wiphy_idx_valid(request->wiphy_idx))
5454 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5455
5456 if (genlmsg_end(msg, hdr) < 0) {
5457 nlmsg_free(msg);
5458 return;
5459 }
5460
bc43b28c 5461 rcu_read_lock();
463d0183 5462 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5463 GFP_ATOMIC);
5464 rcu_read_unlock();
73d54c9e
LR
5465
5466 return;
5467
5468nla_put_failure:
5469 genlmsg_cancel(msg, hdr);
5470 nlmsg_free(msg);
5471}
5472
6039f6d2
JM
5473static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5474 struct net_device *netdev,
5475 const u8 *buf, size_t len,
e6d6e342 5476 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5477{
5478 struct sk_buff *msg;
5479 void *hdr;
5480
e6d6e342 5481 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5482 if (!msg)
5483 return;
5484
5485 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5486 if (!hdr) {
5487 nlmsg_free(msg);
5488 return;
5489 }
5490
5491 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5492 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5493 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5494
5495 if (genlmsg_end(msg, hdr) < 0) {
5496 nlmsg_free(msg);
5497 return;
5498 }
5499
463d0183
JB
5500 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5501 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5502 return;
5503
5504 nla_put_failure:
5505 genlmsg_cancel(msg, hdr);
5506 nlmsg_free(msg);
5507}
5508
5509void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5510 struct net_device *netdev, const u8 *buf,
5511 size_t len, gfp_t gfp)
6039f6d2
JM
5512{
5513 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5514 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5515}
5516
5517void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5518 struct net_device *netdev, const u8 *buf,
e6d6e342 5519 size_t len, gfp_t gfp)
6039f6d2 5520{
e6d6e342
JB
5521 nl80211_send_mlme_event(rdev, netdev, buf, len,
5522 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5523}
5524
53b46b84 5525void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5526 struct net_device *netdev, const u8 *buf,
5527 size_t len, gfp_t gfp)
6039f6d2
JM
5528{
5529 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5530 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5531}
5532
53b46b84
JM
5533void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5534 struct net_device *netdev, const u8 *buf,
e6d6e342 5535 size_t len, gfp_t gfp)
6039f6d2
JM
5536{
5537 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5538 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5539}
5540
cf4e594e
JM
5541void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
5542 struct net_device *netdev, const u8 *buf,
5543 size_t len, gfp_t gfp)
5544{
5545 nl80211_send_mlme_event(rdev, netdev, buf, len,
5546 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
5547}
5548
5549void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
5550 struct net_device *netdev, const u8 *buf,
5551 size_t len, gfp_t gfp)
5552{
5553 nl80211_send_mlme_event(rdev, netdev, buf, len,
5554 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
5555}
5556
1b06bb40
LR
5557static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5558 struct net_device *netdev, int cmd,
e6d6e342 5559 const u8 *addr, gfp_t gfp)
1965c853
JM
5560{
5561 struct sk_buff *msg;
5562 void *hdr;
5563
e6d6e342 5564 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5565 if (!msg)
5566 return;
5567
5568 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5569 if (!hdr) {
5570 nlmsg_free(msg);
5571 return;
5572 }
5573
5574 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5575 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5576 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5577 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5578
5579 if (genlmsg_end(msg, hdr) < 0) {
5580 nlmsg_free(msg);
5581 return;
5582 }
5583
463d0183
JB
5584 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5585 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5586 return;
5587
5588 nla_put_failure:
5589 genlmsg_cancel(msg, hdr);
5590 nlmsg_free(msg);
5591}
5592
5593void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5594 struct net_device *netdev, const u8 *addr,
5595 gfp_t gfp)
1965c853
JM
5596{
5597 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5598 addr, gfp);
1965c853
JM
5599}
5600
5601void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5602 struct net_device *netdev, const u8 *addr,
5603 gfp_t gfp)
1965c853 5604{
e6d6e342
JB
5605 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5606 addr, gfp);
1965c853
JM
5607}
5608
b23aa676
SO
5609void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5610 struct net_device *netdev, const u8 *bssid,
5611 const u8 *req_ie, size_t req_ie_len,
5612 const u8 *resp_ie, size_t resp_ie_len,
5613 u16 status, gfp_t gfp)
5614{
5615 struct sk_buff *msg;
5616 void *hdr;
5617
5618 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5619 if (!msg)
5620 return;
5621
5622 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5623 if (!hdr) {
5624 nlmsg_free(msg);
5625 return;
5626 }
5627
5628 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5629 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5630 if (bssid)
5631 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5632 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5633 if (req_ie)
5634 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5635 if (resp_ie)
5636 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5637
5638 if (genlmsg_end(msg, hdr) < 0) {
5639 nlmsg_free(msg);
5640 return;
5641 }
5642
463d0183
JB
5643 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5644 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5645 return;
5646
5647 nla_put_failure:
5648 genlmsg_cancel(msg, hdr);
5649 nlmsg_free(msg);
5650
5651}
5652
5653void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5654 struct net_device *netdev, const u8 *bssid,
5655 const u8 *req_ie, size_t req_ie_len,
5656 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5657{
5658 struct sk_buff *msg;
5659 void *hdr;
5660
5661 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5662 if (!msg)
5663 return;
5664
5665 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5666 if (!hdr) {
5667 nlmsg_free(msg);
5668 return;
5669 }
5670
5671 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5672 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5673 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5674 if (req_ie)
5675 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5676 if (resp_ie)
5677 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5678
5679 if (genlmsg_end(msg, hdr) < 0) {
5680 nlmsg_free(msg);
5681 return;
5682 }
5683
463d0183
JB
5684 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5685 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5686 return;
5687
5688 nla_put_failure:
5689 genlmsg_cancel(msg, hdr);
5690 nlmsg_free(msg);
5691
5692}
5693
5694void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5695 struct net_device *netdev, u16 reason,
667503dd 5696 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5697{
5698 struct sk_buff *msg;
5699 void *hdr;
5700
667503dd 5701 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5702 if (!msg)
5703 return;
5704
5705 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5706 if (!hdr) {
5707 nlmsg_free(msg);
5708 return;
5709 }
5710
5711 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5712 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5713 if (from_ap && reason)
5714 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5715 if (from_ap)
5716 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5717 if (ie)
5718 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5719
5720 if (genlmsg_end(msg, hdr) < 0) {
5721 nlmsg_free(msg);
5722 return;
5723 }
5724
463d0183
JB
5725 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5726 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5727 return;
5728
5729 nla_put_failure:
5730 genlmsg_cancel(msg, hdr);
5731 nlmsg_free(msg);
5732
5733}
5734
04a773ad
JB
5735void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5736 struct net_device *netdev, const u8 *bssid,
5737 gfp_t gfp)
5738{
5739 struct sk_buff *msg;
5740 void *hdr;
5741
fd2120ca 5742 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5743 if (!msg)
5744 return;
5745
5746 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5747 if (!hdr) {
5748 nlmsg_free(msg);
5749 return;
5750 }
5751
5752 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5753 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5754 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5755
5756 if (genlmsg_end(msg, hdr) < 0) {
5757 nlmsg_free(msg);
5758 return;
5759 }
5760
463d0183
JB
5761 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5762 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5763 return;
5764
5765 nla_put_failure:
5766 genlmsg_cancel(msg, hdr);
5767 nlmsg_free(msg);
5768}
5769
a3b8b056
JM
5770void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5771 struct net_device *netdev, const u8 *addr,
5772 enum nl80211_key_type key_type, int key_id,
e6d6e342 5773 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5774{
5775 struct sk_buff *msg;
5776 void *hdr;
5777
e6d6e342 5778 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5779 if (!msg)
5780 return;
5781
5782 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5783 if (!hdr) {
5784 nlmsg_free(msg);
5785 return;
5786 }
5787
5788 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5789 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5790 if (addr)
5791 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5792 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5793 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5794 if (tsc)
5795 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5796
5797 if (genlmsg_end(msg, hdr) < 0) {
5798 nlmsg_free(msg);
5799 return;
5800 }
5801
463d0183
JB
5802 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5803 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5804 return;
5805
5806 nla_put_failure:
5807 genlmsg_cancel(msg, hdr);
5808 nlmsg_free(msg);
5809}
5810
6bad8766
LR
5811void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5812 struct ieee80211_channel *channel_before,
5813 struct ieee80211_channel *channel_after)
5814{
5815 struct sk_buff *msg;
5816 void *hdr;
5817 struct nlattr *nl_freq;
5818
fd2120ca 5819 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5820 if (!msg)
5821 return;
5822
5823 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5824 if (!hdr) {
5825 nlmsg_free(msg);
5826 return;
5827 }
5828
5829 /*
5830 * Since we are applying the beacon hint to a wiphy we know its
5831 * wiphy_idx is valid
5832 */
5833 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5834
5835 /* Before */
5836 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5837 if (!nl_freq)
5838 goto nla_put_failure;
5839 if (nl80211_msg_put_channel(msg, channel_before))
5840 goto nla_put_failure;
5841 nla_nest_end(msg, nl_freq);
5842
5843 /* After */
5844 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5845 if (!nl_freq)
5846 goto nla_put_failure;
5847 if (nl80211_msg_put_channel(msg, channel_after))
5848 goto nla_put_failure;
5849 nla_nest_end(msg, nl_freq);
5850
5851 if (genlmsg_end(msg, hdr) < 0) {
5852 nlmsg_free(msg);
5853 return;
5854 }
5855
463d0183
JB
5856 rcu_read_lock();
5857 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5858 GFP_ATOMIC);
5859 rcu_read_unlock();
6bad8766
LR
5860
5861 return;
5862
5863nla_put_failure:
5864 genlmsg_cancel(msg, hdr);
5865 nlmsg_free(msg);
5866}
5867
9588bbd5
JM
5868static void nl80211_send_remain_on_chan_event(
5869 int cmd, struct cfg80211_registered_device *rdev,
5870 struct net_device *netdev, u64 cookie,
5871 struct ieee80211_channel *chan,
5872 enum nl80211_channel_type channel_type,
5873 unsigned int duration, gfp_t gfp)
5874{
5875 struct sk_buff *msg;
5876 void *hdr;
5877
5878 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5879 if (!msg)
5880 return;
5881
5882 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5883 if (!hdr) {
5884 nlmsg_free(msg);
5885 return;
5886 }
5887
5888 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5889 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5890 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5891 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5892 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5893
5894 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5895 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5896
5897 if (genlmsg_end(msg, hdr) < 0) {
5898 nlmsg_free(msg);
5899 return;
5900 }
5901
5902 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5903 nl80211_mlme_mcgrp.id, gfp);
5904 return;
5905
5906 nla_put_failure:
5907 genlmsg_cancel(msg, hdr);
5908 nlmsg_free(msg);
5909}
5910
5911void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5912 struct net_device *netdev, u64 cookie,
5913 struct ieee80211_channel *chan,
5914 enum nl80211_channel_type channel_type,
5915 unsigned int duration, gfp_t gfp)
5916{
5917 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5918 rdev, netdev, cookie, chan,
5919 channel_type, duration, gfp);
5920}
5921
5922void nl80211_send_remain_on_channel_cancel(
5923 struct cfg80211_registered_device *rdev, struct net_device *netdev,
5924 u64 cookie, struct ieee80211_channel *chan,
5925 enum nl80211_channel_type channel_type, gfp_t gfp)
5926{
5927 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5928 rdev, netdev, cookie, chan,
5929 channel_type, 0, gfp);
5930}
5931
98b62183
JB
5932void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5933 struct net_device *dev, const u8 *mac_addr,
5934 struct station_info *sinfo, gfp_t gfp)
5935{
5936 struct sk_buff *msg;
5937
5938 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5939 if (!msg)
5940 return;
5941
5942 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5943 nlmsg_free(msg);
5944 return;
5945 }
5946
5947 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5948 nl80211_mlme_mcgrp.id, gfp);
5949}
5950
2e161f78
JB
5951int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
5952 struct net_device *netdev, u32 nlpid,
5953 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
5954{
5955 struct sk_buff *msg;
5956 void *hdr;
5957 int err;
5958
5959 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5960 if (!msg)
5961 return -ENOMEM;
5962
2e161f78 5963 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
5964 if (!hdr) {
5965 nlmsg_free(msg);
5966 return -ENOMEM;
5967 }
5968
5969 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5970 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5971 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
5972 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5973
5974 err = genlmsg_end(msg, hdr);
5975 if (err < 0) {
5976 nlmsg_free(msg);
5977 return err;
5978 }
5979
5980 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
5981 if (err < 0)
5982 return err;
5983 return 0;
5984
5985 nla_put_failure:
5986 genlmsg_cancel(msg, hdr);
5987 nlmsg_free(msg);
5988 return -ENOBUFS;
5989}
5990
2e161f78
JB
5991void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
5992 struct net_device *netdev, u64 cookie,
5993 const u8 *buf, size_t len, bool ack,
5994 gfp_t gfp)
026331c4
JM
5995{
5996 struct sk_buff *msg;
5997 void *hdr;
5998
5999 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6000 if (!msg)
6001 return;
6002
2e161f78 6003 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
6004 if (!hdr) {
6005 nlmsg_free(msg);
6006 return;
6007 }
6008
6009 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6010 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6011 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6012 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6013 if (ack)
6014 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6015
6016 if (genlmsg_end(msg, hdr) < 0) {
6017 nlmsg_free(msg);
6018 return;
6019 }
6020
6021 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6022 return;
6023
6024 nla_put_failure:
6025 genlmsg_cancel(msg, hdr);
6026 nlmsg_free(msg);
6027}
6028
d6dc1a38
JO
6029void
6030nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6031 struct net_device *netdev,
6032 enum nl80211_cqm_rssi_threshold_event rssi_event,
6033 gfp_t gfp)
6034{
6035 struct sk_buff *msg;
6036 struct nlattr *pinfoattr;
6037 void *hdr;
6038
6039 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6040 if (!msg)
6041 return;
6042
6043 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6044 if (!hdr) {
6045 nlmsg_free(msg);
6046 return;
6047 }
6048
6049 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6050 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6051
6052 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6053 if (!pinfoattr)
6054 goto nla_put_failure;
6055
6056 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6057 rssi_event);
6058
6059 nla_nest_end(msg, pinfoattr);
6060
6061 if (genlmsg_end(msg, hdr) < 0) {
6062 nlmsg_free(msg);
6063 return;
6064 }
6065
6066 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6067 nl80211_mlme_mcgrp.id, gfp);
6068 return;
6069
6070 nla_put_failure:
6071 genlmsg_cancel(msg, hdr);
6072 nlmsg_free(msg);
6073}
6074
c063dbf5
JB
6075void
6076nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6077 struct net_device *netdev, const u8 *peer,
6078 u32 num_packets, gfp_t gfp)
6079{
6080 struct sk_buff *msg;
6081 struct nlattr *pinfoattr;
6082 void *hdr;
6083
6084 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6085 if (!msg)
6086 return;
6087
6088 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6089 if (!hdr) {
6090 nlmsg_free(msg);
6091 return;
6092 }
6093
6094 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6095 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6096 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6097
6098 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6099 if (!pinfoattr)
6100 goto nla_put_failure;
6101
6102 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6103
6104 nla_nest_end(msg, pinfoattr);
6105
6106 if (genlmsg_end(msg, hdr) < 0) {
6107 nlmsg_free(msg);
6108 return;
6109 }
6110
6111 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6112 nl80211_mlme_mcgrp.id, gfp);
6113 return;
6114
6115 nla_put_failure:
6116 genlmsg_cancel(msg, hdr);
6117 nlmsg_free(msg);
6118}
6119
026331c4
JM
6120static int nl80211_netlink_notify(struct notifier_block * nb,
6121 unsigned long state,
6122 void *_notify)
6123{
6124 struct netlink_notify *notify = _notify;
6125 struct cfg80211_registered_device *rdev;
6126 struct wireless_dev *wdev;
6127
6128 if (state != NETLINK_URELEASE)
6129 return NOTIFY_DONE;
6130
6131 rcu_read_lock();
6132
6133 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6134 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 6135 cfg80211_mlme_unregister_socket(wdev, notify->pid);
026331c4
JM
6136
6137 rcu_read_unlock();
6138
6139 return NOTIFY_DONE;
6140}
6141
6142static struct notifier_block nl80211_netlink_notifier = {
6143 .notifier_call = nl80211_netlink_notify,
6144};
6145
55682965
JB
6146/* initialisation/exit functions */
6147
6148int nl80211_init(void)
6149{
0d63cbb5 6150 int err;
55682965 6151
0d63cbb5
MM
6152 err = genl_register_family_with_ops(&nl80211_fam,
6153 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6154 if (err)
6155 return err;
6156
55682965
JB
6157 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6158 if (err)
6159 goto err_out;
6160
2a519311
JB
6161 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6162 if (err)
6163 goto err_out;
6164
73d54c9e
LR
6165 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6166 if (err)
6167 goto err_out;
6168
6039f6d2
JM
6169 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6170 if (err)
6171 goto err_out;
6172
aff89a9b
JB
6173#ifdef CONFIG_NL80211_TESTMODE
6174 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6175 if (err)
6176 goto err_out;
6177#endif
6178
026331c4
JM
6179 err = netlink_register_notifier(&nl80211_netlink_notifier);
6180 if (err)
6181 goto err_out;
6182
55682965
JB
6183 return 0;
6184 err_out:
6185 genl_unregister_family(&nl80211_fam);
6186 return err;
6187}
6188
6189void nl80211_exit(void)
6190{
026331c4 6191 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6192 genl_unregister_family(&nl80211_fam);
6193}