mac80211: fix the support of setting non-forwarding entity in Mesh
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
79c97e97 49/* internal helper: get rdev and dev */
00918d33
JB
50static int get_rdev_dev_by_ifindex(struct net *netns, struct nlattr **attrs,
51 struct cfg80211_registered_device **rdev,
52 struct net_device **dev)
55682965
JB
53{
54 int ifindex;
55
bba95fef 56 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
57 return -EINVAL;
58
bba95fef 59 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
00918d33 60 *dev = dev_get_by_index(netns, ifindex);
55682965
JB
61 if (!*dev)
62 return -ENODEV;
63
00918d33 64 *rdev = cfg80211_get_dev_from_ifindex(netns, ifindex);
79c97e97 65 if (IS_ERR(*rdev)) {
55682965 66 dev_put(*dev);
79c97e97 67 return PTR_ERR(*rdev);
55682965
JB
68 }
69
70 return 0;
71}
72
73/* policy for the attributes */
b54452b0 74static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
75 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
76 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 77 .len = 20-1 },
31888487 78 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 79 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 80 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
81 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
82 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
83 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
84 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 85 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
86
87 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
88 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
89 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 90
e007b857
EP
91 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
92 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 93
b9454e83 94 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
95 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
96 .len = WLAN_MAX_KEY_LEN },
97 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
98 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
99 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 100 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 101 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
102
103 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
104 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
105 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
106 .len = IEEE80211_MAX_DATA_LEN },
107 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
108 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
109 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
110 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
111 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
112 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
113 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 114 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 115 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 116 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
117 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
118 .len = IEEE80211_MAX_MESH_ID_LEN },
119 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 120
b2e1b302
LR
121 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
122 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
123
9f1ba906
JM
124 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
125 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
126 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
127 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
128 .len = NL80211_MAX_SUPP_RATES },
50b12f59 129 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 130
24bdd9f4 131 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 132 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 133
6c739419 134 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
135
136 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
137 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
138 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
139 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
140 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
141
142 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
143 .len = IEEE80211_MAX_SSID_LEN },
144 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
145 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 146 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 147 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 148 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
149 [NL80211_ATTR_STA_FLAGS2] = {
150 .len = sizeof(struct nl80211_sta_flag_update),
151 },
3f77316c 152 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
153 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
154 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
155 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
156 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
157 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 158 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 159 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
160 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
161 .len = WLAN_PMKID_LEN },
9588bbd5
JM
162 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
163 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 164 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
165 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
166 .len = IEEE80211_MAX_DATA_LEN },
167 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 168 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 169 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 170 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 171 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
172 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
173 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 174 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
175 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
176 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 177 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 178 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 179 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 180 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 181 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 182 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 183 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 184 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 185 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
186 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
187 .len = IEEE80211_MAX_DATA_LEN },
188 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
189 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 190 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 191 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 192 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
193 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
194 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
195 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
196 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
197 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 198 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
199 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
200 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 201 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
202 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
203 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
204 .len = NL80211_HT_CAPABILITY_LEN
205 },
1d9d9213 206 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
55682965
JB
207};
208
e31b8213 209/* policy for the key attributes */
b54452b0 210static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 211 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
212 [NL80211_KEY_IDX] = { .type = NLA_U8 },
213 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 214 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
215 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
216 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 217 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
218 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
219};
220
221/* policy for the key default flags */
222static const struct nla_policy
223nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
224 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
225 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
226};
227
ff1b6e69
JB
228/* policy for WoWLAN attributes */
229static const struct nla_policy
230nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
231 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
232 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
233 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
234 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
235 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
236 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
237 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
238 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
239};
240
e5497d76
JB
241/* policy for GTK rekey offload attributes */
242static const struct nla_policy
243nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
244 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
245 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
246 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
247};
248
a1f1c21c
LC
249static const struct nla_policy
250nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
251 [NL80211_ATTR_SCHED_SCAN_MATCH_SSID] = { .type = NLA_BINARY,
252 .len = IEEE80211_MAX_SSID_LEN },
253};
254
a043897a
HS
255/* ifidx get helper */
256static int nl80211_get_ifidx(struct netlink_callback *cb)
257{
258 int res;
259
260 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
261 nl80211_fam.attrbuf, nl80211_fam.maxattr,
262 nl80211_policy);
263 if (res)
264 return res;
265
266 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
267 return -EINVAL;
268
269 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
270 if (!res)
271 return -EINVAL;
272 return res;
273}
274
67748893
JB
275static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
276 struct netlink_callback *cb,
277 struct cfg80211_registered_device **rdev,
278 struct net_device **dev)
279{
280 int ifidx = cb->args[0];
281 int err;
282
283 if (!ifidx)
284 ifidx = nl80211_get_ifidx(cb);
285 if (ifidx < 0)
286 return ifidx;
287
288 cb->args[0] = ifidx;
289
290 rtnl_lock();
291
292 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
293 if (!*dev) {
294 err = -ENODEV;
295 goto out_rtnl;
296 }
297
298 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
299 if (IS_ERR(*rdev)) {
300 err = PTR_ERR(*rdev);
67748893
JB
301 goto out_rtnl;
302 }
303
304 return 0;
305 out_rtnl:
306 rtnl_unlock();
307 return err;
308}
309
310static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
311{
312 cfg80211_unlock_rdev(rdev);
313 rtnl_unlock();
314}
315
f4a11bb0
JB
316/* IE validation */
317static bool is_valid_ie_attr(const struct nlattr *attr)
318{
319 const u8 *pos;
320 int len;
321
322 if (!attr)
323 return true;
324
325 pos = nla_data(attr);
326 len = nla_len(attr);
327
328 while (len) {
329 u8 elemlen;
330
331 if (len < 2)
332 return false;
333 len -= 2;
334
335 elemlen = pos[1];
336 if (elemlen > len)
337 return false;
338
339 len -= elemlen;
340 pos += 2 + elemlen;
341 }
342
343 return true;
344}
345
55682965
JB
346/* message building helper */
347static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
348 int flags, u8 cmd)
349{
350 /* since there is no private header just add the generic one */
351 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
352}
353
5dab3b8a
LR
354static int nl80211_msg_put_channel(struct sk_buff *msg,
355 struct ieee80211_channel *chan)
356{
357 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
358 chan->center_freq);
359
360 if (chan->flags & IEEE80211_CHAN_DISABLED)
361 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
362 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
363 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
364 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
365 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
366 if (chan->flags & IEEE80211_CHAN_RADAR)
367 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
368
369 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
370 DBM_TO_MBM(chan->max_power));
371
372 return 0;
373
374 nla_put_failure:
375 return -ENOBUFS;
376}
377
55682965
JB
378/* netlink command implementations */
379
b9454e83
JB
380struct key_parse {
381 struct key_params p;
382 int idx;
e31b8213 383 int type;
b9454e83 384 bool def, defmgmt;
dbd2fd65 385 bool def_uni, def_multi;
b9454e83
JB
386};
387
388static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
389{
390 struct nlattr *tb[NL80211_KEY_MAX + 1];
391 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
392 nl80211_key_policy);
393 if (err)
394 return err;
395
396 k->def = !!tb[NL80211_KEY_DEFAULT];
397 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
398
dbd2fd65
JB
399 if (k->def) {
400 k->def_uni = true;
401 k->def_multi = true;
402 }
403 if (k->defmgmt)
404 k->def_multi = true;
405
b9454e83
JB
406 if (tb[NL80211_KEY_IDX])
407 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
408
409 if (tb[NL80211_KEY_DATA]) {
410 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
411 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
412 }
413
414 if (tb[NL80211_KEY_SEQ]) {
415 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
416 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
417 }
418
419 if (tb[NL80211_KEY_CIPHER])
420 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
421
e31b8213
JB
422 if (tb[NL80211_KEY_TYPE]) {
423 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
424 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
425 return -EINVAL;
426 }
427
dbd2fd65
JB
428 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
429 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
430 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
431 tb[NL80211_KEY_DEFAULT_TYPES],
432 nl80211_key_default_policy);
dbd2fd65
JB
433 if (err)
434 return err;
435
436 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
437 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
438 }
439
b9454e83
JB
440 return 0;
441}
442
443static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
444{
445 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
446 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
447 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
448 }
449
450 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
451 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
452 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
453 }
454
455 if (info->attrs[NL80211_ATTR_KEY_IDX])
456 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
457
458 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
459 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
460
461 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
462 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
463
dbd2fd65
JB
464 if (k->def) {
465 k->def_uni = true;
466 k->def_multi = true;
467 }
468 if (k->defmgmt)
469 k->def_multi = true;
470
e31b8213
JB
471 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
472 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
473 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
474 return -EINVAL;
475 }
476
dbd2fd65
JB
477 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
478 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
479 int err = nla_parse_nested(
480 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
481 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
482 nl80211_key_default_policy);
483 if (err)
484 return err;
485
486 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
487 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
488 }
489
b9454e83
JB
490 return 0;
491}
492
493static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
494{
495 int err;
496
497 memset(k, 0, sizeof(*k));
498 k->idx = -1;
e31b8213 499 k->type = -1;
b9454e83
JB
500
501 if (info->attrs[NL80211_ATTR_KEY])
502 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
503 else
504 err = nl80211_parse_key_old(info, k);
505
506 if (err)
507 return err;
508
509 if (k->def && k->defmgmt)
510 return -EINVAL;
511
dbd2fd65
JB
512 if (k->defmgmt) {
513 if (k->def_uni || !k->def_multi)
514 return -EINVAL;
515 }
516
b9454e83
JB
517 if (k->idx != -1) {
518 if (k->defmgmt) {
519 if (k->idx < 4 || k->idx > 5)
520 return -EINVAL;
521 } else if (k->def) {
522 if (k->idx < 0 || k->idx > 3)
523 return -EINVAL;
524 } else {
525 if (k->idx < 0 || k->idx > 5)
526 return -EINVAL;
527 }
528 }
529
530 return 0;
531}
532
fffd0934
JB
533static struct cfg80211_cached_keys *
534nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
535 struct nlattr *keys)
536{
537 struct key_parse parse;
538 struct nlattr *key;
539 struct cfg80211_cached_keys *result;
540 int rem, err, def = 0;
541
542 result = kzalloc(sizeof(*result), GFP_KERNEL);
543 if (!result)
544 return ERR_PTR(-ENOMEM);
545
546 result->def = -1;
547 result->defmgmt = -1;
548
549 nla_for_each_nested(key, keys, rem) {
550 memset(&parse, 0, sizeof(parse));
551 parse.idx = -1;
552
553 err = nl80211_parse_key_new(key, &parse);
554 if (err)
555 goto error;
556 err = -EINVAL;
557 if (!parse.p.key)
558 goto error;
559 if (parse.idx < 0 || parse.idx > 4)
560 goto error;
561 if (parse.def) {
562 if (def)
563 goto error;
564 def = 1;
565 result->def = parse.idx;
dbd2fd65
JB
566 if (!parse.def_uni || !parse.def_multi)
567 goto error;
fffd0934
JB
568 } else if (parse.defmgmt)
569 goto error;
570 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 571 parse.idx, false, NULL);
fffd0934
JB
572 if (err)
573 goto error;
574 result->params[parse.idx].cipher = parse.p.cipher;
575 result->params[parse.idx].key_len = parse.p.key_len;
576 result->params[parse.idx].key = result->data[parse.idx];
577 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
578 }
579
580 return result;
581 error:
582 kfree(result);
583 return ERR_PTR(err);
584}
585
586static int nl80211_key_allowed(struct wireless_dev *wdev)
587{
588 ASSERT_WDEV_LOCK(wdev);
589
fffd0934
JB
590 switch (wdev->iftype) {
591 case NL80211_IFTYPE_AP:
592 case NL80211_IFTYPE_AP_VLAN:
074ac8df 593 case NL80211_IFTYPE_P2P_GO:
ff973af7 594 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
595 break;
596 case NL80211_IFTYPE_ADHOC:
597 if (!wdev->current_bss)
598 return -ENOLINK;
599 break;
600 case NL80211_IFTYPE_STATION:
074ac8df 601 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
602 if (wdev->sme_state != CFG80211_SME_CONNECTED)
603 return -ENOLINK;
604 break;
605 default:
606 return -EINVAL;
607 }
608
609 return 0;
610}
611
7527a782
JB
612static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
613{
614 struct nlattr *nl_modes = nla_nest_start(msg, attr);
615 int i;
616
617 if (!nl_modes)
618 goto nla_put_failure;
619
620 i = 0;
621 while (ifmodes) {
622 if (ifmodes & 1)
623 NLA_PUT_FLAG(msg, i);
624 ifmodes >>= 1;
625 i++;
626 }
627
628 nla_nest_end(msg, nl_modes);
629 return 0;
630
631nla_put_failure:
632 return -ENOBUFS;
633}
634
635static int nl80211_put_iface_combinations(struct wiphy *wiphy,
636 struct sk_buff *msg)
637{
638 struct nlattr *nl_combis;
639 int i, j;
640
641 nl_combis = nla_nest_start(msg,
642 NL80211_ATTR_INTERFACE_COMBINATIONS);
643 if (!nl_combis)
644 goto nla_put_failure;
645
646 for (i = 0; i < wiphy->n_iface_combinations; i++) {
647 const struct ieee80211_iface_combination *c;
648 struct nlattr *nl_combi, *nl_limits;
649
650 c = &wiphy->iface_combinations[i];
651
652 nl_combi = nla_nest_start(msg, i + 1);
653 if (!nl_combi)
654 goto nla_put_failure;
655
656 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
657 if (!nl_limits)
658 goto nla_put_failure;
659
660 for (j = 0; j < c->n_limits; j++) {
661 struct nlattr *nl_limit;
662
663 nl_limit = nla_nest_start(msg, j + 1);
664 if (!nl_limit)
665 goto nla_put_failure;
666 NLA_PUT_U32(msg, NL80211_IFACE_LIMIT_MAX,
667 c->limits[j].max);
668 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
669 c->limits[j].types))
670 goto nla_put_failure;
671 nla_nest_end(msg, nl_limit);
672 }
673
674 nla_nest_end(msg, nl_limits);
675
676 if (c->beacon_int_infra_match)
677 NLA_PUT_FLAG(msg,
678 NL80211_IFACE_COMB_STA_AP_BI_MATCH);
679 NLA_PUT_U32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
680 c->num_different_channels);
681 NLA_PUT_U32(msg, NL80211_IFACE_COMB_MAXNUM,
682 c->max_interfaces);
683
684 nla_nest_end(msg, nl_combi);
685 }
686
687 nla_nest_end(msg, nl_combis);
688
689 return 0;
690nla_put_failure:
691 return -ENOBUFS;
692}
693
55682965
JB
694static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
695 struct cfg80211_registered_device *dev)
696{
697 void *hdr;
ee688b00
JB
698 struct nlattr *nl_bands, *nl_band;
699 struct nlattr *nl_freqs, *nl_freq;
700 struct nlattr *nl_rates, *nl_rate;
8fdc621d 701 struct nlattr *nl_cmds;
ee688b00
JB
702 enum ieee80211_band band;
703 struct ieee80211_channel *chan;
704 struct ieee80211_rate *rate;
705 int i;
2e161f78
JB
706 const struct ieee80211_txrx_stypes *mgmt_stypes =
707 dev->wiphy.mgmt_stypes;
55682965
JB
708
709 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
710 if (!hdr)
711 return -1;
712
b5850a7a 713 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 714 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 715
f5ea9120
JB
716 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
717 cfg80211_rdev_list_generation);
718
b9a5f8ca
JM
719 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
720 dev->wiphy.retry_short);
721 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
722 dev->wiphy.retry_long);
723 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
724 dev->wiphy.frag_threshold);
725 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
726 dev->wiphy.rts_threshold);
81077e82
LT
727 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
728 dev->wiphy.coverage_class);
2a519311
JB
729 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
730 dev->wiphy.max_scan_ssids);
93b6aa69
LC
731 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
732 dev->wiphy.max_sched_scan_ssids);
18a83659
JB
733 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
734 dev->wiphy.max_scan_ie_len);
5a865bad
LC
735 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
736 dev->wiphy.max_sched_scan_ie_len);
a1f1c21c
LC
737 NLA_PUT_U8(msg, NL80211_ATTR_MAX_MATCH_SETS,
738 dev->wiphy.max_match_sets);
ee688b00 739
e31b8213
JB
740 if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
741 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
15d5dda6
JC
742 if (dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH)
743 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_MESH_AUTH);
cedb5412
EP
744 if (dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD)
745 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_AP_UAPSD);
f4b34b55
VN
746 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)
747 NLA_PUT_FLAG(msg, NL80211_ATTR_ROAM_SUPPORT);
109086ce
AN
748 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)
749 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_SUPPORT);
750 if (dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)
751 NLA_PUT_FLAG(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP);
f4b34b55 752
25e47c18
JB
753 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
754 sizeof(u32) * dev->wiphy.n_cipher_suites,
755 dev->wiphy.cipher_suites);
756
67fbb16b
SO
757 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
758 dev->wiphy.max_num_pmkids);
759
c0692b8f
JB
760 if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
761 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
762
39fd5de4
BR
763 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
764 dev->wiphy.available_antennas_tx);
765 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
766 dev->wiphy.available_antennas_rx);
767
87bbbe22
AN
768 if (dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD)
769 NLA_PUT_U32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
770 dev->wiphy.probe_resp_offload);
771
7f531e03
BR
772 if ((dev->wiphy.available_antennas_tx ||
773 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
774 u32 tx_ant = 0, rx_ant = 0;
775 int res;
776 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
777 if (!res) {
778 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
779 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
780 }
781 }
782
7527a782
JB
783 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
784 dev->wiphy.interface_modes))
f59ac048
LR
785 goto nla_put_failure;
786
ee688b00
JB
787 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
788 if (!nl_bands)
789 goto nla_put_failure;
790
791 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
792 if (!dev->wiphy.bands[band])
793 continue;
794
795 nl_band = nla_nest_start(msg, band);
796 if (!nl_band)
797 goto nla_put_failure;
798
d51626df
JB
799 /* add HT info */
800 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
801 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
802 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
803 &dev->wiphy.bands[band]->ht_cap.mcs);
804 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
805 dev->wiphy.bands[band]->ht_cap.cap);
806 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
807 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
808 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
809 dev->wiphy.bands[band]->ht_cap.ampdu_density);
810 }
811
ee688b00
JB
812 /* add frequencies */
813 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
814 if (!nl_freqs)
815 goto nla_put_failure;
816
817 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
818 nl_freq = nla_nest_start(msg, i);
819 if (!nl_freq)
820 goto nla_put_failure;
821
822 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
823
824 if (nl80211_msg_put_channel(msg, chan))
825 goto nla_put_failure;
e2f367f2 826
ee688b00
JB
827 nla_nest_end(msg, nl_freq);
828 }
829
830 nla_nest_end(msg, nl_freqs);
831
832 /* add bitrates */
833 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
834 if (!nl_rates)
835 goto nla_put_failure;
836
837 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
838 nl_rate = nla_nest_start(msg, i);
839 if (!nl_rate)
840 goto nla_put_failure;
841
842 rate = &dev->wiphy.bands[band]->bitrates[i];
843 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
844 rate->bitrate);
845 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
846 NLA_PUT_FLAG(msg,
847 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
848
849 nla_nest_end(msg, nl_rate);
850 }
851
852 nla_nest_end(msg, nl_rates);
853
854 nla_nest_end(msg, nl_band);
855 }
856 nla_nest_end(msg, nl_bands);
857
8fdc621d
JB
858 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
859 if (!nl_cmds)
860 goto nla_put_failure;
861
862 i = 0;
863#define CMD(op, n) \
864 do { \
865 if (dev->ops->op) { \
866 i++; \
867 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
868 } \
869 } while (0)
870
871 CMD(add_virtual_intf, NEW_INTERFACE);
872 CMD(change_virtual_intf, SET_INTERFACE);
873 CMD(add_key, NEW_KEY);
8860020e 874 CMD(start_ap, START_AP);
8fdc621d
JB
875 CMD(add_station, NEW_STATION);
876 CMD(add_mpath, NEW_MPATH);
24bdd9f4 877 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 878 CMD(change_bss, SET_BSS);
636a5d36
JM
879 CMD(auth, AUTHENTICATE);
880 CMD(assoc, ASSOCIATE);
881 CMD(deauth, DEAUTHENTICATE);
882 CMD(disassoc, DISASSOCIATE);
04a773ad 883 CMD(join_ibss, JOIN_IBSS);
29cbe68c 884 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
885 CMD(set_pmksa, SET_PMKSA);
886 CMD(del_pmksa, DEL_PMKSA);
887 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
888 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
889 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 890 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 891 CMD(mgmt_tx, FRAME);
f7ca38df 892 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 893 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
894 i++;
895 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
896 }
f444de05 897 CMD(set_channel, SET_CHANNEL);
e8347eba 898 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
899 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
900 CMD(tdls_mgmt, TDLS_MGMT);
901 CMD(tdls_oper, TDLS_OPER);
902 }
807f8a8c
LC
903 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
904 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 905 CMD(probe_client, PROBE_CLIENT);
1d9d9213 906 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
907 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
908 i++;
909 NLA_PUT_U32(msg, i, NL80211_CMD_REGISTER_BEACONS);
910 }
8fdc621d 911
4745fc09
KV
912#ifdef CONFIG_NL80211_TESTMODE
913 CMD(testmode_cmd, TESTMODE);
914#endif
915
8fdc621d 916#undef CMD
b23aa676 917
6829c878 918 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
919 i++;
920 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
921 }
922
6829c878 923 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
924 i++;
925 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
926 }
927
8fdc621d
JB
928 nla_nest_end(msg, nl_cmds);
929
7c4ef712
JB
930 if (dev->ops->remain_on_channel &&
931 dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
a293911d
JB
932 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
933 dev->wiphy.max_remain_on_channel_duration);
934
7c4ef712 935 if (dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)
f7ca38df
JB
936 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
937
2e161f78
JB
938 if (mgmt_stypes) {
939 u16 stypes;
940 struct nlattr *nl_ftypes, *nl_ifs;
941 enum nl80211_iftype ift;
942
943 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
944 if (!nl_ifs)
945 goto nla_put_failure;
946
947 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
948 nl_ftypes = nla_nest_start(msg, ift);
949 if (!nl_ftypes)
950 goto nla_put_failure;
951 i = 0;
952 stypes = mgmt_stypes[ift].tx;
953 while (stypes) {
954 if (stypes & 1)
955 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
956 (i << 4) | IEEE80211_FTYPE_MGMT);
957 stypes >>= 1;
958 i++;
959 }
960 nla_nest_end(msg, nl_ftypes);
961 }
962
74b70a4e
JB
963 nla_nest_end(msg, nl_ifs);
964
2e161f78
JB
965 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
966 if (!nl_ifs)
967 goto nla_put_failure;
968
969 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
970 nl_ftypes = nla_nest_start(msg, ift);
971 if (!nl_ftypes)
972 goto nla_put_failure;
973 i = 0;
974 stypes = mgmt_stypes[ift].rx;
975 while (stypes) {
976 if (stypes & 1)
977 NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
978 (i << 4) | IEEE80211_FTYPE_MGMT);
979 stypes >>= 1;
980 i++;
981 }
982 nla_nest_end(msg, nl_ftypes);
983 }
984 nla_nest_end(msg, nl_ifs);
985 }
986
ff1b6e69
JB
987 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
988 struct nlattr *nl_wowlan;
989
990 nl_wowlan = nla_nest_start(msg,
991 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
992 if (!nl_wowlan)
993 goto nla_put_failure;
994
995 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY)
996 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
997 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT)
998 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
999 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT)
1000 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
1001 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY)
1002 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED);
1003 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)
1004 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
1005 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)
1006 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
1007 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)
1008 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
1009 if (dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE)
1010 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
1011 if (dev->wiphy.wowlan.n_patterns) {
1012 struct nl80211_wowlan_pattern_support pat = {
1013 .max_patterns = dev->wiphy.wowlan.n_patterns,
1014 .min_pattern_len =
1015 dev->wiphy.wowlan.pattern_min_len,
1016 .max_pattern_len =
1017 dev->wiphy.wowlan.pattern_max_len,
1018 };
1019 NLA_PUT(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1020 sizeof(pat), &pat);
1021 }
1022
1023 nla_nest_end(msg, nl_wowlan);
1024 }
1025
7527a782
JB
1026 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1027 dev->wiphy.software_iftypes))
1028 goto nla_put_failure;
1029
1030 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1031 goto nla_put_failure;
1032
562a7480
JB
1033 if (dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME)
1034 NLA_PUT_U32(msg, NL80211_ATTR_DEVICE_AP_SME,
1035 dev->wiphy.ap_sme_capa);
1036
1f074bd8
JB
1037 NLA_PUT_U32(msg, NL80211_ATTR_FEATURE_FLAGS, dev->wiphy.features);
1038
7e7c8926
BG
1039 if (dev->wiphy.ht_capa_mod_mask)
1040 NLA_PUT(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1041 sizeof(*dev->wiphy.ht_capa_mod_mask),
1042 dev->wiphy.ht_capa_mod_mask);
1043
55682965
JB
1044 return genlmsg_end(msg, hdr);
1045
1046 nla_put_failure:
bc3ed28c
TG
1047 genlmsg_cancel(msg, hdr);
1048 return -EMSGSIZE;
55682965
JB
1049}
1050
1051static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1052{
1053 int idx = 0;
1054 int start = cb->args[0];
1055 struct cfg80211_registered_device *dev;
1056
a1794390 1057 mutex_lock(&cfg80211_mutex);
79c97e97 1058 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1059 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1060 continue;
b4637271 1061 if (++idx <= start)
55682965
JB
1062 continue;
1063 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1064 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1065 dev) < 0) {
1066 idx--;
55682965 1067 break;
b4637271 1068 }
55682965 1069 }
a1794390 1070 mutex_unlock(&cfg80211_mutex);
55682965
JB
1071
1072 cb->args[0] = idx;
1073
1074 return skb->len;
1075}
1076
1077static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1078{
1079 struct sk_buff *msg;
4c476991 1080 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1081
fd2120ca 1082 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1083 if (!msg)
4c476991 1084 return -ENOMEM;
55682965 1085
4c476991
JB
1086 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1087 nlmsg_free(msg);
1088 return -ENOBUFS;
1089 }
55682965 1090
134e6375 1091 return genlmsg_reply(msg, info);
55682965
JB
1092}
1093
31888487
JM
1094static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1095 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1096 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1097 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1098 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1099 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1100};
1101
1102static int parse_txq_params(struct nlattr *tb[],
1103 struct ieee80211_txq_params *txq_params)
1104{
1105 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
1106 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1107 !tb[NL80211_TXQ_ATTR_AIFS])
1108 return -EINVAL;
1109
1110 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
1111 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1112 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1113 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1114 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1115
1116 return 0;
1117}
1118
f444de05
JB
1119static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1120{
1121 /*
1122 * You can only set the channel explicitly for AP, mesh
1123 * and WDS type interfaces; all others have their channel
1124 * managed via their respective "establish a connection"
1125 * command (connect, join, ...)
1126 *
1127 * Monitors are special as they are normally slaved to
1128 * whatever else is going on, so they behave as though
1129 * you tried setting the wiphy channel itself.
1130 */
1131 return !wdev ||
1132 wdev->iftype == NL80211_IFTYPE_AP ||
1133 wdev->iftype == NL80211_IFTYPE_WDS ||
1134 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1135 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1136 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1137}
1138
1139static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1140 struct wireless_dev *wdev,
1141 struct genl_info *info)
1142{
1143 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1144 u32 freq;
1145 int result;
1146
1147 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1148 return -EINVAL;
1149
1150 if (!nl80211_can_set_dev_channel(wdev))
1151 return -EOPNOTSUPP;
1152
1153 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
1154 channel_type = nla_get_u32(info->attrs[
1155 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1156 if (channel_type != NL80211_CHAN_NO_HT &&
1157 channel_type != NL80211_CHAN_HT20 &&
1158 channel_type != NL80211_CHAN_HT40PLUS &&
1159 channel_type != NL80211_CHAN_HT40MINUS)
1160 return -EINVAL;
1161 }
1162
1163 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1164
1165 mutex_lock(&rdev->devlist_mtx);
1166 if (wdev) {
1167 wdev_lock(wdev);
1168 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
1169 wdev_unlock(wdev);
1170 } else {
1171 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
1172 }
1173 mutex_unlock(&rdev->devlist_mtx);
1174
1175 return result;
1176}
1177
1178static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1179{
4c476991
JB
1180 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1181 struct net_device *netdev = info->user_ptr[1];
f444de05 1182
4c476991 1183 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1184}
1185
e8347eba
BJ
1186static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1187{
43b19952
JB
1188 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1189 struct net_device *dev = info->user_ptr[1];
1190 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1191 const u8 *bssid;
e8347eba
BJ
1192
1193 if (!info->attrs[NL80211_ATTR_MAC])
1194 return -EINVAL;
1195
43b19952
JB
1196 if (netif_running(dev))
1197 return -EBUSY;
e8347eba 1198
43b19952
JB
1199 if (!rdev->ops->set_wds_peer)
1200 return -EOPNOTSUPP;
e8347eba 1201
43b19952
JB
1202 if (wdev->iftype != NL80211_IFTYPE_WDS)
1203 return -EOPNOTSUPP;
e8347eba
BJ
1204
1205 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1206 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1207}
1208
1209
55682965
JB
1210static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1211{
1212 struct cfg80211_registered_device *rdev;
f444de05
JB
1213 struct net_device *netdev = NULL;
1214 struct wireless_dev *wdev;
a1e567c8 1215 int result = 0, rem_txq_params = 0;
31888487 1216 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1217 u32 changed;
1218 u8 retry_short = 0, retry_long = 0;
1219 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1220 u8 coverage_class = 0;
55682965 1221
f444de05
JB
1222 /*
1223 * Try to find the wiphy and netdev. Normally this
1224 * function shouldn't need the netdev, but this is
1225 * done for backward compatibility -- previously
1226 * setting the channel was done per wiphy, but now
1227 * it is per netdev. Previous userland like hostapd
1228 * also passed a netdev to set_wiphy, so that it is
1229 * possible to let that go to the right netdev!
1230 */
4bbf4d56
JB
1231 mutex_lock(&cfg80211_mutex);
1232
f444de05
JB
1233 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1234 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1235
1236 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1237 if (netdev && netdev->ieee80211_ptr) {
1238 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1239 mutex_lock(&rdev->mtx);
1240 } else
1241 netdev = NULL;
4bbf4d56
JB
1242 }
1243
f444de05
JB
1244 if (!netdev) {
1245 rdev = __cfg80211_rdev_from_info(info);
1246 if (IS_ERR(rdev)) {
1247 mutex_unlock(&cfg80211_mutex);
4c476991 1248 return PTR_ERR(rdev);
f444de05
JB
1249 }
1250 wdev = NULL;
1251 netdev = NULL;
1252 result = 0;
1253
1254 mutex_lock(&rdev->mtx);
1255 } else if (netif_running(netdev) &&
1256 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1257 wdev = netdev->ieee80211_ptr;
1258 else
1259 wdev = NULL;
1260
1261 /*
1262 * end workaround code, by now the rdev is available
1263 * and locked, and wdev may or may not be NULL.
1264 */
4bbf4d56
JB
1265
1266 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1267 result = cfg80211_dev_rename(
1268 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1269
1270 mutex_unlock(&cfg80211_mutex);
1271
1272 if (result)
1273 goto bad_res;
31888487
JM
1274
1275 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1276 struct ieee80211_txq_params txq_params;
1277 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1278
1279 if (!rdev->ops->set_txq_params) {
1280 result = -EOPNOTSUPP;
1281 goto bad_res;
1282 }
1283
f70f01c2
EP
1284 if (!netdev) {
1285 result = -EINVAL;
1286 goto bad_res;
1287 }
1288
133a3ff2
JB
1289 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1290 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1291 result = -EINVAL;
1292 goto bad_res;
1293 }
1294
31888487
JM
1295 nla_for_each_nested(nl_txq_params,
1296 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1297 rem_txq_params) {
1298 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1299 nla_data(nl_txq_params),
1300 nla_len(nl_txq_params),
1301 txq_params_policy);
1302 result = parse_txq_params(tb, &txq_params);
1303 if (result)
1304 goto bad_res;
1305
1306 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1307 netdev,
31888487
JM
1308 &txq_params);
1309 if (result)
1310 goto bad_res;
1311 }
1312 }
55682965 1313
72bdcf34 1314 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1315 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1316 if (result)
1317 goto bad_res;
1318 }
1319
98d2ff8b
JO
1320 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1321 enum nl80211_tx_power_setting type;
1322 int idx, mbm = 0;
1323
1324 if (!rdev->ops->set_tx_power) {
60ea385f 1325 result = -EOPNOTSUPP;
98d2ff8b
JO
1326 goto bad_res;
1327 }
1328
1329 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1330 type = nla_get_u32(info->attrs[idx]);
1331
1332 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1333 (type != NL80211_TX_POWER_AUTOMATIC)) {
1334 result = -EINVAL;
1335 goto bad_res;
1336 }
1337
1338 if (type != NL80211_TX_POWER_AUTOMATIC) {
1339 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1340 mbm = nla_get_u32(info->attrs[idx]);
1341 }
1342
1343 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1344 if (result)
1345 goto bad_res;
1346 }
1347
afe0cbf8
BR
1348 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1349 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1350 u32 tx_ant, rx_ant;
7f531e03
BR
1351 if ((!rdev->wiphy.available_antennas_tx &&
1352 !rdev->wiphy.available_antennas_rx) ||
1353 !rdev->ops->set_antenna) {
afe0cbf8
BR
1354 result = -EOPNOTSUPP;
1355 goto bad_res;
1356 }
1357
1358 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1359 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1360
a7ffac95 1361 /* reject antenna configurations which don't match the
7f531e03
BR
1362 * available antenna masks, except for the "all" mask */
1363 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1364 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1365 result = -EINVAL;
1366 goto bad_res;
1367 }
1368
7f531e03
BR
1369 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1370 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1371
afe0cbf8
BR
1372 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1373 if (result)
1374 goto bad_res;
1375 }
1376
b9a5f8ca
JM
1377 changed = 0;
1378
1379 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1380 retry_short = nla_get_u8(
1381 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1382 if (retry_short == 0) {
1383 result = -EINVAL;
1384 goto bad_res;
1385 }
1386 changed |= WIPHY_PARAM_RETRY_SHORT;
1387 }
1388
1389 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1390 retry_long = nla_get_u8(
1391 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1392 if (retry_long == 0) {
1393 result = -EINVAL;
1394 goto bad_res;
1395 }
1396 changed |= WIPHY_PARAM_RETRY_LONG;
1397 }
1398
1399 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1400 frag_threshold = nla_get_u32(
1401 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1402 if (frag_threshold < 256) {
1403 result = -EINVAL;
1404 goto bad_res;
1405 }
1406 if (frag_threshold != (u32) -1) {
1407 /*
1408 * Fragments (apart from the last one) are required to
1409 * have even length. Make the fragmentation code
1410 * simpler by stripping LSB should someone try to use
1411 * odd threshold value.
1412 */
1413 frag_threshold &= ~0x1;
1414 }
1415 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1416 }
1417
1418 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1419 rts_threshold = nla_get_u32(
1420 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1421 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1422 }
1423
81077e82
LT
1424 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1425 coverage_class = nla_get_u8(
1426 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1427 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1428 }
1429
b9a5f8ca
JM
1430 if (changed) {
1431 u8 old_retry_short, old_retry_long;
1432 u32 old_frag_threshold, old_rts_threshold;
81077e82 1433 u8 old_coverage_class;
b9a5f8ca
JM
1434
1435 if (!rdev->ops->set_wiphy_params) {
1436 result = -EOPNOTSUPP;
1437 goto bad_res;
1438 }
1439
1440 old_retry_short = rdev->wiphy.retry_short;
1441 old_retry_long = rdev->wiphy.retry_long;
1442 old_frag_threshold = rdev->wiphy.frag_threshold;
1443 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1444 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1445
1446 if (changed & WIPHY_PARAM_RETRY_SHORT)
1447 rdev->wiphy.retry_short = retry_short;
1448 if (changed & WIPHY_PARAM_RETRY_LONG)
1449 rdev->wiphy.retry_long = retry_long;
1450 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1451 rdev->wiphy.frag_threshold = frag_threshold;
1452 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1453 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1454 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1455 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1456
1457 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1458 if (result) {
1459 rdev->wiphy.retry_short = old_retry_short;
1460 rdev->wiphy.retry_long = old_retry_long;
1461 rdev->wiphy.frag_threshold = old_frag_threshold;
1462 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1463 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1464 }
1465 }
72bdcf34 1466
306d6112 1467 bad_res:
4bbf4d56 1468 mutex_unlock(&rdev->mtx);
f444de05
JB
1469 if (netdev)
1470 dev_put(netdev);
55682965
JB
1471 return result;
1472}
1473
1474
1475static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1476 struct cfg80211_registered_device *rdev,
55682965
JB
1477 struct net_device *dev)
1478{
1479 void *hdr;
1480
1481 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1482 if (!hdr)
1483 return -1;
1484
1485 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 1486 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 1487 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 1488 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
1489
1490 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1491 rdev->devlist_generation ^
1492 (cfg80211_rdev_list_generation << 2));
1493
55682965
JB
1494 return genlmsg_end(msg, hdr);
1495
1496 nla_put_failure:
bc3ed28c
TG
1497 genlmsg_cancel(msg, hdr);
1498 return -EMSGSIZE;
55682965
JB
1499}
1500
1501static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1502{
1503 int wp_idx = 0;
1504 int if_idx = 0;
1505 int wp_start = cb->args[0];
1506 int if_start = cb->args[1];
f5ea9120 1507 struct cfg80211_registered_device *rdev;
55682965
JB
1508 struct wireless_dev *wdev;
1509
a1794390 1510 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1511 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1512 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1513 continue;
bba95fef
JB
1514 if (wp_idx < wp_start) {
1515 wp_idx++;
55682965 1516 continue;
bba95fef 1517 }
55682965
JB
1518 if_idx = 0;
1519
f5ea9120
JB
1520 mutex_lock(&rdev->devlist_mtx);
1521 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1522 if (if_idx < if_start) {
1523 if_idx++;
55682965 1524 continue;
bba95fef 1525 }
55682965
JB
1526 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1527 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1528 rdev, wdev->netdev) < 0) {
1529 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1530 goto out;
1531 }
1532 if_idx++;
55682965 1533 }
f5ea9120 1534 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1535
1536 wp_idx++;
55682965 1537 }
bba95fef 1538 out:
a1794390 1539 mutex_unlock(&cfg80211_mutex);
55682965
JB
1540
1541 cb->args[0] = wp_idx;
1542 cb->args[1] = if_idx;
1543
1544 return skb->len;
1545}
1546
1547static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1548{
1549 struct sk_buff *msg;
4c476991
JB
1550 struct cfg80211_registered_device *dev = info->user_ptr[0];
1551 struct net_device *netdev = info->user_ptr[1];
55682965 1552
fd2120ca 1553 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1554 if (!msg)
4c476991 1555 return -ENOMEM;
55682965 1556
d726405a 1557 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
1558 dev, netdev) < 0) {
1559 nlmsg_free(msg);
1560 return -ENOBUFS;
1561 }
55682965 1562
134e6375 1563 return genlmsg_reply(msg, info);
55682965
JB
1564}
1565
66f7ac50
MW
1566static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1567 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1568 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1569 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1570 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1571 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1572};
1573
1574static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1575{
1576 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1577 int flag;
1578
1579 *mntrflags = 0;
1580
1581 if (!nla)
1582 return -EINVAL;
1583
1584 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1585 nla, mntr_flags_policy))
1586 return -EINVAL;
1587
1588 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1589 if (flags[flag])
1590 *mntrflags |= (1<<flag);
1591
1592 return 0;
1593}
1594
9bc383de 1595static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1596 struct net_device *netdev, u8 use_4addr,
1597 enum nl80211_iftype iftype)
9bc383de 1598{
ad4bb6f8 1599 if (!use_4addr) {
f350a0a8 1600 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1601 return -EBUSY;
9bc383de 1602 return 0;
ad4bb6f8 1603 }
9bc383de
JB
1604
1605 switch (iftype) {
1606 case NL80211_IFTYPE_AP_VLAN:
1607 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1608 return 0;
1609 break;
1610 case NL80211_IFTYPE_STATION:
1611 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1612 return 0;
1613 break;
1614 default:
1615 break;
1616 }
1617
1618 return -EOPNOTSUPP;
1619}
1620
55682965
JB
1621static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1622{
4c476991 1623 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1624 struct vif_params params;
e36d56b6 1625 int err;
04a773ad 1626 enum nl80211_iftype otype, ntype;
4c476991 1627 struct net_device *dev = info->user_ptr[1];
92ffe055 1628 u32 _flags, *flags = NULL;
ac7f9cfa 1629 bool change = false;
55682965 1630
2ec600d6
LCC
1631 memset(&params, 0, sizeof(params));
1632
04a773ad 1633 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1634
723b038d 1635 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1636 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1637 if (otype != ntype)
ac7f9cfa 1638 change = true;
4c476991
JB
1639 if (ntype > NL80211_IFTYPE_MAX)
1640 return -EINVAL;
723b038d
JB
1641 }
1642
92ffe055 1643 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1644 struct wireless_dev *wdev = dev->ieee80211_ptr;
1645
4c476991
JB
1646 if (ntype != NL80211_IFTYPE_MESH_POINT)
1647 return -EINVAL;
29cbe68c
JB
1648 if (netif_running(dev))
1649 return -EBUSY;
1650
1651 wdev_lock(wdev);
1652 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1653 IEEE80211_MAX_MESH_ID_LEN);
1654 wdev->mesh_id_up_len =
1655 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1656 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1657 wdev->mesh_id_up_len);
1658 wdev_unlock(wdev);
2ec600d6
LCC
1659 }
1660
8b787643
FF
1661 if (info->attrs[NL80211_ATTR_4ADDR]) {
1662 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1663 change = true;
ad4bb6f8 1664 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1665 if (err)
4c476991 1666 return err;
8b787643
FF
1667 } else {
1668 params.use_4addr = -1;
1669 }
1670
92ffe055 1671 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1672 if (ntype != NL80211_IFTYPE_MONITOR)
1673 return -EINVAL;
92ffe055
JB
1674 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1675 &_flags);
ac7f9cfa 1676 if (err)
4c476991 1677 return err;
ac7f9cfa
JB
1678
1679 flags = &_flags;
1680 change = true;
92ffe055 1681 }
3b85875a 1682
ac7f9cfa 1683 if (change)
3d54d255 1684 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1685 else
1686 err = 0;
60719ffd 1687
9bc383de
JB
1688 if (!err && params.use_4addr != -1)
1689 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1690
55682965
JB
1691 return err;
1692}
1693
1694static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1695{
4c476991 1696 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1697 struct vif_params params;
f9e10ce4 1698 struct net_device *dev;
55682965
JB
1699 int err;
1700 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1701 u32 flags;
55682965 1702
2ec600d6
LCC
1703 memset(&params, 0, sizeof(params));
1704
55682965
JB
1705 if (!info->attrs[NL80211_ATTR_IFNAME])
1706 return -EINVAL;
1707
1708 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1709 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1710 if (type > NL80211_IFTYPE_MAX)
1711 return -EINVAL;
1712 }
1713
79c97e97 1714 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1715 !(rdev->wiphy.interface_modes & (1 << type)))
1716 return -EOPNOTSUPP;
55682965 1717
9bc383de 1718 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1719 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1720 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1721 if (err)
4c476991 1722 return err;
9bc383de 1723 }
8b787643 1724
66f7ac50
MW
1725 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1726 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1727 &flags);
f9e10ce4 1728 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1729 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1730 type, err ? NULL : &flags, &params);
f9e10ce4
JB
1731 if (IS_ERR(dev))
1732 return PTR_ERR(dev);
2ec600d6 1733
29cbe68c
JB
1734 if (type == NL80211_IFTYPE_MESH_POINT &&
1735 info->attrs[NL80211_ATTR_MESH_ID]) {
1736 struct wireless_dev *wdev = dev->ieee80211_ptr;
1737
1738 wdev_lock(wdev);
1739 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1740 IEEE80211_MAX_MESH_ID_LEN);
1741 wdev->mesh_id_up_len =
1742 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1743 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1744 wdev->mesh_id_up_len);
1745 wdev_unlock(wdev);
1746 }
1747
f9e10ce4 1748 return 0;
55682965
JB
1749}
1750
1751static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1752{
4c476991
JB
1753 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1754 struct net_device *dev = info->user_ptr[1];
55682965 1755
4c476991
JB
1756 if (!rdev->ops->del_virtual_intf)
1757 return -EOPNOTSUPP;
55682965 1758
4c476991 1759 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1760}
1761
1d9d9213
SW
1762static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
1763{
1764 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1765 struct net_device *dev = info->user_ptr[1];
1766 u16 noack_map;
1767
1768 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
1769 return -EINVAL;
1770
1771 if (!rdev->ops->set_noack_map)
1772 return -EOPNOTSUPP;
1773
1774 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
1775
1776 return rdev->ops->set_noack_map(&rdev->wiphy, dev, noack_map);
1777}
1778
41ade00f
JB
1779struct get_key_cookie {
1780 struct sk_buff *msg;
1781 int error;
b9454e83 1782 int idx;
41ade00f
JB
1783};
1784
1785static void get_key_callback(void *c, struct key_params *params)
1786{
b9454e83 1787 struct nlattr *key;
41ade00f
JB
1788 struct get_key_cookie *cookie = c;
1789
1790 if (params->key)
1791 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1792 params->key_len, params->key);
1793
1794 if (params->seq)
1795 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1796 params->seq_len, params->seq);
1797
1798 if (params->cipher)
1799 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1800 params->cipher);
1801
b9454e83
JB
1802 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1803 if (!key)
1804 goto nla_put_failure;
1805
1806 if (params->key)
1807 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1808 params->key_len, params->key);
1809
1810 if (params->seq)
1811 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1812 params->seq_len, params->seq);
1813
1814 if (params->cipher)
1815 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1816 params->cipher);
1817
1818 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1819
1820 nla_nest_end(cookie->msg, key);
1821
41ade00f
JB
1822 return;
1823 nla_put_failure:
1824 cookie->error = 1;
1825}
1826
1827static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1828{
4c476991 1829 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 1830 int err;
4c476991 1831 struct net_device *dev = info->user_ptr[1];
41ade00f 1832 u8 key_idx = 0;
e31b8213
JB
1833 const u8 *mac_addr = NULL;
1834 bool pairwise;
41ade00f
JB
1835 struct get_key_cookie cookie = {
1836 .error = 0,
1837 };
1838 void *hdr;
1839 struct sk_buff *msg;
1840
1841 if (info->attrs[NL80211_ATTR_KEY_IDX])
1842 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1843
3cfcf6ac 1844 if (key_idx > 5)
41ade00f
JB
1845 return -EINVAL;
1846
1847 if (info->attrs[NL80211_ATTR_MAC])
1848 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1849
e31b8213
JB
1850 pairwise = !!mac_addr;
1851 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1852 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1853 if (kt >= NUM_NL80211_KEYTYPES)
1854 return -EINVAL;
1855 if (kt != NL80211_KEYTYPE_GROUP &&
1856 kt != NL80211_KEYTYPE_PAIRWISE)
1857 return -EINVAL;
1858 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1859 }
1860
4c476991
JB
1861 if (!rdev->ops->get_key)
1862 return -EOPNOTSUPP;
41ade00f 1863
fd2120ca 1864 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
1865 if (!msg)
1866 return -ENOMEM;
41ade00f
JB
1867
1868 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1869 NL80211_CMD_NEW_KEY);
4c476991
JB
1870 if (IS_ERR(hdr))
1871 return PTR_ERR(hdr);
41ade00f
JB
1872
1873 cookie.msg = msg;
b9454e83 1874 cookie.idx = key_idx;
41ade00f
JB
1875
1876 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1877 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1878 if (mac_addr)
1879 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1880
e31b8213
JB
1881 if (pairwise && mac_addr &&
1882 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1883 return -ENOENT;
1884
1885 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1886 mac_addr, &cookie, get_key_callback);
41ade00f
JB
1887
1888 if (err)
6c95e2a2 1889 goto free_msg;
41ade00f
JB
1890
1891 if (cookie.error)
1892 goto nla_put_failure;
1893
1894 genlmsg_end(msg, hdr);
4c476991 1895 return genlmsg_reply(msg, info);
41ade00f
JB
1896
1897 nla_put_failure:
1898 err = -ENOBUFS;
6c95e2a2 1899 free_msg:
41ade00f 1900 nlmsg_free(msg);
41ade00f
JB
1901 return err;
1902}
1903
1904static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1905{
4c476991 1906 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 1907 struct key_parse key;
41ade00f 1908 int err;
4c476991 1909 struct net_device *dev = info->user_ptr[1];
41ade00f 1910
b9454e83
JB
1911 err = nl80211_parse_key(info, &key);
1912 if (err)
1913 return err;
41ade00f 1914
b9454e83 1915 if (key.idx < 0)
41ade00f
JB
1916 return -EINVAL;
1917
b9454e83
JB
1918 /* only support setting default key */
1919 if (!key.def && !key.defmgmt)
41ade00f
JB
1920 return -EINVAL;
1921
dbd2fd65 1922 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 1923
dbd2fd65
JB
1924 if (key.def) {
1925 if (!rdev->ops->set_default_key) {
1926 err = -EOPNOTSUPP;
1927 goto out;
1928 }
41ade00f 1929
dbd2fd65
JB
1930 err = nl80211_key_allowed(dev->ieee80211_ptr);
1931 if (err)
1932 goto out;
1933
dbd2fd65
JB
1934 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1935 key.def_uni, key.def_multi);
1936
1937 if (err)
1938 goto out;
fffd0934 1939
3d23e349 1940#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
1941 dev->ieee80211_ptr->wext.default_key = key.idx;
1942#endif
1943 } else {
1944 if (key.def_uni || !key.def_multi) {
1945 err = -EINVAL;
1946 goto out;
1947 }
1948
1949 if (!rdev->ops->set_default_mgmt_key) {
1950 err = -EOPNOTSUPP;
1951 goto out;
1952 }
1953
1954 err = nl80211_key_allowed(dev->ieee80211_ptr);
1955 if (err)
1956 goto out;
1957
1958 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1959 dev, key.idx);
1960 if (err)
1961 goto out;
1962
1963#ifdef CONFIG_CFG80211_WEXT
1964 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 1965#endif
dbd2fd65
JB
1966 }
1967
1968 out:
fffd0934 1969 wdev_unlock(dev->ieee80211_ptr);
41ade00f 1970
41ade00f
JB
1971 return err;
1972}
1973
1974static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1975{
4c476991 1976 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 1977 int err;
4c476991 1978 struct net_device *dev = info->user_ptr[1];
b9454e83 1979 struct key_parse key;
e31b8213 1980 const u8 *mac_addr = NULL;
41ade00f 1981
b9454e83
JB
1982 err = nl80211_parse_key(info, &key);
1983 if (err)
1984 return err;
41ade00f 1985
b9454e83 1986 if (!key.p.key)
41ade00f
JB
1987 return -EINVAL;
1988
41ade00f
JB
1989 if (info->attrs[NL80211_ATTR_MAC])
1990 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1991
e31b8213
JB
1992 if (key.type == -1) {
1993 if (mac_addr)
1994 key.type = NL80211_KEYTYPE_PAIRWISE;
1995 else
1996 key.type = NL80211_KEYTYPE_GROUP;
1997 }
1998
1999 /* for now */
2000 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2001 key.type != NL80211_KEYTYPE_GROUP)
2002 return -EINVAL;
2003
4c476991
JB
2004 if (!rdev->ops->add_key)
2005 return -EOPNOTSUPP;
25e47c18 2006
e31b8213
JB
2007 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2008 key.type == NL80211_KEYTYPE_PAIRWISE,
2009 mac_addr))
4c476991 2010 return -EINVAL;
41ade00f 2011
fffd0934
JB
2012 wdev_lock(dev->ieee80211_ptr);
2013 err = nl80211_key_allowed(dev->ieee80211_ptr);
2014 if (!err)
2015 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 2016 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
2017 mac_addr, &key.p);
2018 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2019
41ade00f
JB
2020 return err;
2021}
2022
2023static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2024{
4c476991 2025 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2026 int err;
4c476991 2027 struct net_device *dev = info->user_ptr[1];
41ade00f 2028 u8 *mac_addr = NULL;
b9454e83 2029 struct key_parse key;
41ade00f 2030
b9454e83
JB
2031 err = nl80211_parse_key(info, &key);
2032 if (err)
2033 return err;
41ade00f
JB
2034
2035 if (info->attrs[NL80211_ATTR_MAC])
2036 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2037
e31b8213
JB
2038 if (key.type == -1) {
2039 if (mac_addr)
2040 key.type = NL80211_KEYTYPE_PAIRWISE;
2041 else
2042 key.type = NL80211_KEYTYPE_GROUP;
2043 }
2044
2045 /* for now */
2046 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2047 key.type != NL80211_KEYTYPE_GROUP)
2048 return -EINVAL;
2049
4c476991
JB
2050 if (!rdev->ops->del_key)
2051 return -EOPNOTSUPP;
41ade00f 2052
fffd0934
JB
2053 wdev_lock(dev->ieee80211_ptr);
2054 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2055
2056 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2057 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2058 err = -ENOENT;
2059
fffd0934 2060 if (!err)
e31b8213
JB
2061 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2062 key.type == NL80211_KEYTYPE_PAIRWISE,
2063 mac_addr);
41ade00f 2064
3d23e349 2065#ifdef CONFIG_CFG80211_WEXT
08645126 2066 if (!err) {
b9454e83 2067 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2068 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2069 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2070 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2071 }
2072#endif
fffd0934 2073 wdev_unlock(dev->ieee80211_ptr);
08645126 2074
41ade00f
JB
2075 return err;
2076}
2077
8860020e
JB
2078static int nl80211_parse_beacon(struct genl_info *info,
2079 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2080{
8860020e 2081 bool haveinfo = false;
ed1b6cc7 2082
9946ecfb
JM
2083 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2084 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2085 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2086 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2087 return -EINVAL;
2088
8860020e 2089 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2090
ed1b6cc7 2091 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2092 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2093 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2094 if (!bcn->head_len)
2095 return -EINVAL;
2096 haveinfo = true;
ed1b6cc7
JB
2097 }
2098
2099 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2100 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2101 bcn->tail_len =
ed1b6cc7 2102 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2103 haveinfo = true;
ed1b6cc7
JB
2104 }
2105
4c476991
JB
2106 if (!haveinfo)
2107 return -EINVAL;
3b85875a 2108
9946ecfb 2109 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2110 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2111 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2112 }
2113
2114 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2115 bcn->proberesp_ies =
9946ecfb 2116 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2117 bcn->proberesp_ies_len =
9946ecfb
JM
2118 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2119 }
2120
2121 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2122 bcn->assocresp_ies =
9946ecfb 2123 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2124 bcn->assocresp_ies_len =
9946ecfb
JM
2125 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2126 }
2127
00f740e1 2128 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2129 bcn->probe_resp =
00f740e1 2130 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2131 bcn->probe_resp_len =
00f740e1
AN
2132 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2133 }
2134
8860020e
JB
2135 return 0;
2136}
2137
2138static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2139{
2140 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2141 struct net_device *dev = info->user_ptr[1];
2142 struct wireless_dev *wdev = dev->ieee80211_ptr;
2143 struct cfg80211_ap_settings params;
2144 int err;
2145
2146 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2147 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2148 return -EOPNOTSUPP;
2149
2150 if (!rdev->ops->start_ap)
2151 return -EOPNOTSUPP;
2152
2153 if (wdev->beacon_interval)
2154 return -EALREADY;
2155
2156 memset(&params, 0, sizeof(params));
2157
2158 /* these are required for START_AP */
2159 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2160 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2161 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2162 return -EINVAL;
2163
2164 err = nl80211_parse_beacon(info, &params.beacon);
2165 if (err)
2166 return err;
2167
2168 params.beacon_interval =
2169 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2170 params.dtim_period =
2171 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2172
2173 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2174 if (err)
2175 return err;
2176
2177 /*
2178 * In theory, some of these attributes should be required here
2179 * but since they were not used when the command was originally
2180 * added, keep them optional for old user space programs to let
2181 * them continue to work with drivers that do not need the
2182 * additional information -- drivers must check!
2183 */
2184 if (info->attrs[NL80211_ATTR_SSID]) {
2185 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2186 params.ssid_len =
2187 nla_len(info->attrs[NL80211_ATTR_SSID]);
2188 if (params.ssid_len == 0 ||
2189 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2190 return -EINVAL;
2191 }
2192
2193 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2194 params.hidden_ssid = nla_get_u32(
2195 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2196 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2197 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2198 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2199 return -EINVAL;
2200 }
2201
2202 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2203
2204 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2205 params.auth_type = nla_get_u32(
2206 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2207 if (!nl80211_valid_auth_type(params.auth_type))
2208 return -EINVAL;
2209 } else
2210 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2211
2212 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2213 NL80211_MAX_NR_CIPHER_SUITES);
2214 if (err)
2215 return err;
2216
2217 err = rdev->ops->start_ap(&rdev->wiphy, dev, &params);
2218 if (!err)
2219 wdev->beacon_interval = params.beacon_interval;
56d1893d 2220 return err;
ed1b6cc7
JB
2221}
2222
8860020e
JB
2223static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2224{
2225 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2226 struct net_device *dev = info->user_ptr[1];
2227 struct wireless_dev *wdev = dev->ieee80211_ptr;
2228 struct cfg80211_beacon_data params;
2229 int err;
2230
2231 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2232 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2233 return -EOPNOTSUPP;
2234
2235 if (!rdev->ops->change_beacon)
2236 return -EOPNOTSUPP;
2237
2238 if (!wdev->beacon_interval)
2239 return -EINVAL;
2240
2241 err = nl80211_parse_beacon(info, &params);
2242 if (err)
2243 return err;
2244
2245 return rdev->ops->change_beacon(&rdev->wiphy, dev, &params);
2246}
2247
2248static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2249{
4c476991
JB
2250 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2251 struct net_device *dev = info->user_ptr[1];
56d1893d
JB
2252 struct wireless_dev *wdev = dev->ieee80211_ptr;
2253 int err;
ed1b6cc7 2254
8860020e 2255 if (!rdev->ops->stop_ap)
4c476991 2256 return -EOPNOTSUPP;
ed1b6cc7 2257
074ac8df 2258 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
2259 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2260 return -EOPNOTSUPP;
3b85875a 2261
8860020e
JB
2262 if (!wdev->beacon_interval)
2263 return -ENOENT;
2264
2265 err = rdev->ops->stop_ap(&rdev->wiphy, dev);
56d1893d
JB
2266 if (!err)
2267 wdev->beacon_interval = 0;
2268 return err;
ed1b6cc7
JB
2269}
2270
5727ef1b
JB
2271static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2272 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2273 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2274 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2275 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2276 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2277 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2278};
2279
eccb8e8f 2280static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2281 enum nl80211_iftype iftype,
eccb8e8f 2282 struct station_parameters *params)
5727ef1b
JB
2283{
2284 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2285 struct nlattr *nla;
5727ef1b
JB
2286 int flag;
2287
eccb8e8f
JB
2288 /*
2289 * Try parsing the new attribute first so userspace
2290 * can specify both for older kernels.
2291 */
2292 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2293 if (nla) {
2294 struct nl80211_sta_flag_update *sta_flags;
2295
2296 sta_flags = nla_data(nla);
2297 params->sta_flags_mask = sta_flags->mask;
2298 params->sta_flags_set = sta_flags->set;
2299 if ((params->sta_flags_mask |
2300 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2301 return -EINVAL;
2302 return 0;
2303 }
2304
2305 /* if present, parse the old attribute */
5727ef1b 2306
eccb8e8f 2307 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2308 if (!nla)
2309 return 0;
2310
2311 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2312 nla, sta_flags_policy))
2313 return -EINVAL;
2314
bdd3ae3d
JB
2315 /*
2316 * Only allow certain flags for interface types so that
2317 * other attributes are silently ignored. Remember that
2318 * this is backward compatibility code with old userspace
2319 * and shouldn't be hit in other cases anyway.
2320 */
2321 switch (iftype) {
2322 case NL80211_IFTYPE_AP:
2323 case NL80211_IFTYPE_AP_VLAN:
2324 case NL80211_IFTYPE_P2P_GO:
2325 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2326 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2327 BIT(NL80211_STA_FLAG_WME) |
2328 BIT(NL80211_STA_FLAG_MFP);
2329 break;
2330 case NL80211_IFTYPE_P2P_CLIENT:
2331 case NL80211_IFTYPE_STATION:
2332 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2333 BIT(NL80211_STA_FLAG_TDLS_PEER);
2334 break;
2335 case NL80211_IFTYPE_MESH_POINT:
2336 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2337 BIT(NL80211_STA_FLAG_MFP) |
2338 BIT(NL80211_STA_FLAG_AUTHORIZED);
2339 default:
2340 return -EINVAL;
2341 }
5727ef1b
JB
2342
2343 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
2344 if (flags[flag])
eccb8e8f 2345 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
2346
2347 return 0;
2348}
2349
c8dcfd8a
FF
2350static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2351 int attr)
2352{
2353 struct nlattr *rate;
2354 u16 bitrate;
2355
2356 rate = nla_nest_start(msg, attr);
2357 if (!rate)
2358 goto nla_put_failure;
2359
2360 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2361 bitrate = cfg80211_calculate_bitrate(info);
2362 if (bitrate > 0)
2363 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2364
2365 if (info->flags & RATE_INFO_FLAGS_MCS)
2366 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS, info->mcs);
2367 if (info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2368 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2369 if (info->flags & RATE_INFO_FLAGS_SHORT_GI)
2370 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2371
2372 nla_nest_end(msg, rate);
2373 return true;
2374
2375nla_put_failure:
2376 return false;
2377}
2378
fd5b74dc
JB
2379static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
2380 int flags, struct net_device *dev,
98b62183 2381 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2382{
2383 void *hdr;
f4263c98 2384 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2385
2386 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2387 if (!hdr)
2388 return -1;
2389
2390 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2391 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
2392
f5ea9120
JB
2393 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
2394
2ec600d6
LCC
2395 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2396 if (!sinfoattr)
fd5b74dc 2397 goto nla_put_failure;
ebe27c91
MSS
2398 if (sinfo->filled & STATION_INFO_CONNECTED_TIME)
2399 NLA_PUT_U32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2400 sinfo->connected_time);
2ec600d6
LCC
2401 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
2402 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2403 sinfo->inactive_time);
2404 if (sinfo->filled & STATION_INFO_RX_BYTES)
2405 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
2406 sinfo->rx_bytes);
2407 if (sinfo->filled & STATION_INFO_TX_BYTES)
2408 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
2409 sinfo->tx_bytes);
2410 if (sinfo->filled & STATION_INFO_LLID)
2411 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
2412 sinfo->llid);
2413 if (sinfo->filled & STATION_INFO_PLID)
2414 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
2415 sinfo->plid);
2416 if (sinfo->filled & STATION_INFO_PLINK_STATE)
2417 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2418 sinfo->plink_state);
420e7fab
HR
2419 if (sinfo->filled & STATION_INFO_SIGNAL)
2420 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2421 sinfo->signal);
541a45a1
BR
2422 if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2423 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2424 sinfo->signal_avg);
420e7fab 2425 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2426 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2427 NL80211_STA_INFO_TX_BITRATE))
2428 goto nla_put_failure;
2429 }
2430 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2431 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2432 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2433 goto nla_put_failure;
420e7fab 2434 }
98c8a60a
JM
2435 if (sinfo->filled & STATION_INFO_RX_PACKETS)
2436 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2437 sinfo->rx_packets);
2438 if (sinfo->filled & STATION_INFO_TX_PACKETS)
2439 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2440 sinfo->tx_packets);
b206b4ef
BR
2441 if (sinfo->filled & STATION_INFO_TX_RETRIES)
2442 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2443 sinfo->tx_retries);
2444 if (sinfo->filled & STATION_INFO_TX_FAILED)
2445 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2446 sinfo->tx_failed);
a85e1d55
PS
2447 if (sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT)
2448 NLA_PUT_U32(msg, NL80211_STA_INFO_BEACON_LOSS,
2449 sinfo->beacon_loss_count);
f4263c98
PS
2450 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2451 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2452 if (!bss_param)
2453 goto nla_put_failure;
2454
2455 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT)
2456 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_CTS_PROT);
2457 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE)
2458 NLA_PUT_FLAG(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE);
2459 if (sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME)
2460 NLA_PUT_FLAG(msg,
2461 NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME);
2462 NLA_PUT_U8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2463 sinfo->bss_param.dtim_period);
2464 NLA_PUT_U16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2465 sinfo->bss_param.beacon_interval);
2466
2467 nla_nest_end(msg, bss_param);
2468 }
bb6e753e
HS
2469 if (sinfo->filled & STATION_INFO_STA_FLAGS)
2470 NLA_PUT(msg, NL80211_STA_INFO_STA_FLAGS,
2471 sizeof(struct nl80211_sta_flag_update),
2472 &sinfo->sta_flags);
2ec600d6 2473 nla_nest_end(msg, sinfoattr);
fd5b74dc 2474
040bdf71 2475 if (sinfo->filled & STATION_INFO_ASSOC_REQ_IES)
50d3dfb7
JM
2476 NLA_PUT(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2477 sinfo->assoc_req_ies);
2478
fd5b74dc
JB
2479 return genlmsg_end(msg, hdr);
2480
2481 nla_put_failure:
bc3ed28c
TG
2482 genlmsg_cancel(msg, hdr);
2483 return -EMSGSIZE;
fd5b74dc
JB
2484}
2485
2ec600d6 2486static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2487 struct netlink_callback *cb)
2ec600d6 2488{
2ec600d6
LCC
2489 struct station_info sinfo;
2490 struct cfg80211_registered_device *dev;
bba95fef 2491 struct net_device *netdev;
2ec600d6 2492 u8 mac_addr[ETH_ALEN];
bba95fef 2493 int sta_idx = cb->args[1];
2ec600d6 2494 int err;
2ec600d6 2495
67748893
JB
2496 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2497 if (err)
2498 return err;
bba95fef
JB
2499
2500 if (!dev->ops->dump_station) {
eec60b03 2501 err = -EOPNOTSUPP;
bba95fef
JB
2502 goto out_err;
2503 }
2504
bba95fef 2505 while (1) {
f612cedf 2506 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2507 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2508 mac_addr, &sinfo);
2509 if (err == -ENOENT)
2510 break;
2511 if (err)
3b85875a 2512 goto out_err;
bba95fef
JB
2513
2514 if (nl80211_send_station(skb,
2515 NETLINK_CB(cb->skb).pid,
2516 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2517 netdev, mac_addr,
2518 &sinfo) < 0)
2519 goto out;
2520
2521 sta_idx++;
2522 }
2523
2524
2525 out:
2526 cb->args[1] = sta_idx;
2527 err = skb->len;
bba95fef 2528 out_err:
67748893 2529 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2530
2531 return err;
2ec600d6 2532}
fd5b74dc 2533
5727ef1b
JB
2534static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2535{
4c476991
JB
2536 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2537 struct net_device *dev = info->user_ptr[1];
2ec600d6 2538 struct station_info sinfo;
fd5b74dc
JB
2539 struct sk_buff *msg;
2540 u8 *mac_addr = NULL;
4c476991 2541 int err;
fd5b74dc 2542
2ec600d6 2543 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2544
2545 if (!info->attrs[NL80211_ATTR_MAC])
2546 return -EINVAL;
2547
2548 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2549
4c476991
JB
2550 if (!rdev->ops->get_station)
2551 return -EOPNOTSUPP;
3b85875a 2552
4c476991 2553 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2554 if (err)
4c476991 2555 return err;
2ec600d6 2556
fd2120ca 2557 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2558 if (!msg)
4c476991 2559 return -ENOMEM;
fd5b74dc
JB
2560
2561 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
2562 dev, mac_addr, &sinfo) < 0) {
2563 nlmsg_free(msg);
2564 return -ENOBUFS;
2565 }
3b85875a 2566
4c476991 2567 return genlmsg_reply(msg, info);
5727ef1b
JB
2568}
2569
2570/*
c258d2de 2571 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2572 */
80b99899
JB
2573static struct net_device *get_vlan(struct genl_info *info,
2574 struct cfg80211_registered_device *rdev)
5727ef1b 2575{
463d0183 2576 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
2577 struct net_device *v;
2578 int ret;
2579
2580 if (!vlanattr)
2581 return NULL;
2582
2583 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
2584 if (!v)
2585 return ERR_PTR(-ENODEV);
2586
2587 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
2588 ret = -EINVAL;
2589 goto error;
5727ef1b 2590 }
80b99899
JB
2591
2592 if (!netif_running(v)) {
2593 ret = -ENETDOWN;
2594 goto error;
2595 }
2596
2597 return v;
2598 error:
2599 dev_put(v);
2600 return ERR_PTR(ret);
5727ef1b
JB
2601}
2602
2603static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2604{
4c476991 2605 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2606 int err;
4c476991 2607 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2608 struct station_parameters params;
2609 u8 *mac_addr = NULL;
2610
2611 memset(&params, 0, sizeof(params));
2612
2613 params.listen_interval = -1;
57cf8043 2614 params.plink_state = -1;
5727ef1b
JB
2615
2616 if (info->attrs[NL80211_ATTR_STA_AID])
2617 return -EINVAL;
2618
2619 if (!info->attrs[NL80211_ATTR_MAC])
2620 return -EINVAL;
2621
2622 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2623
2624 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2625 params.supported_rates =
2626 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2627 params.supported_rates_len =
2628 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2629 }
2630
2631 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2632 params.listen_interval =
2633 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2634
36aedc90
JM
2635 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2636 params.ht_capa =
2637 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2638
bdd90d5e
JB
2639 if (!rdev->ops->change_station)
2640 return -EOPNOTSUPP;
2641
bdd3ae3d 2642 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2643 return -EINVAL;
2644
2ec600d6
LCC
2645 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2646 params.plink_action =
2647 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2648
9c3990aa
JC
2649 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
2650 params.plink_state =
2651 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
2652
a97f4424
JB
2653 switch (dev->ieee80211_ptr->iftype) {
2654 case NL80211_IFTYPE_AP:
2655 case NL80211_IFTYPE_AP_VLAN:
074ac8df 2656 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
2657 /* disallow mesh-specific things */
2658 if (params.plink_action)
bdd90d5e
JB
2659 return -EINVAL;
2660
2661 /* TDLS can't be set, ... */
2662 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2663 return -EINVAL;
2664 /*
2665 * ... but don't bother the driver with it. This works around
2666 * a hostapd/wpa_supplicant issue -- it always includes the
2667 * TLDS_PEER flag in the mask even for AP mode.
2668 */
2669 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
2670
2671 /* accept only the listed bits */
2672 if (params.sta_flags_mask &
2673 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
2674 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2675 BIT(NL80211_STA_FLAG_WME) |
2676 BIT(NL80211_STA_FLAG_MFP)))
2677 return -EINVAL;
2678
2679 /* must be last in here for error handling */
2680 params.vlan = get_vlan(info, rdev);
2681 if (IS_ERR(params.vlan))
2682 return PTR_ERR(params.vlan);
a97f4424 2683 break;
074ac8df 2684 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 2685 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
2686 /*
2687 * Don't allow userspace to change the TDLS_PEER flag,
2688 * but silently ignore attempts to change it since we
2689 * don't have state here to verify that it doesn't try
2690 * to change the flag.
2691 */
2692 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
2693 /* fall through */
2694 case NL80211_IFTYPE_ADHOC:
2695 /* disallow things sta doesn't support */
2696 if (params.plink_action)
2697 return -EINVAL;
2698 if (params.ht_capa)
2699 return -EINVAL;
2700 if (params.listen_interval >= 0)
2701 return -EINVAL;
bdd90d5e
JB
2702 /* reject any changes other than AUTHORIZED */
2703 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2704 return -EINVAL;
a97f4424
JB
2705 break;
2706 case NL80211_IFTYPE_MESH_POINT:
2707 /* disallow things mesh doesn't support */
2708 if (params.vlan)
bdd90d5e 2709 return -EINVAL;
a97f4424 2710 if (params.ht_capa)
bdd90d5e 2711 return -EINVAL;
a97f4424 2712 if (params.listen_interval >= 0)
bdd90d5e
JB
2713 return -EINVAL;
2714 /*
2715 * No special handling for TDLS here -- the userspace
2716 * mesh code doesn't have this bug.
2717 */
b39c48fa
JC
2718 if (params.sta_flags_mask &
2719 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 2720 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 2721 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 2722 return -EINVAL;
a97f4424
JB
2723 break;
2724 default:
bdd90d5e 2725 return -EOPNOTSUPP;
034d655e
JB
2726 }
2727
bdd90d5e 2728 /* be aware of params.vlan when changing code here */
5727ef1b 2729
79c97e97 2730 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 2731
5727ef1b
JB
2732 if (params.vlan)
2733 dev_put(params.vlan);
3b85875a 2734
5727ef1b
JB
2735 return err;
2736}
2737
c75786c9
EP
2738static struct nla_policy
2739nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
2740 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
2741 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
2742};
2743
5727ef1b
JB
2744static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2745{
4c476991 2746 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2747 int err;
4c476991 2748 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2749 struct station_parameters params;
2750 u8 *mac_addr = NULL;
2751
2752 memset(&params, 0, sizeof(params));
2753
2754 if (!info->attrs[NL80211_ATTR_MAC])
2755 return -EINVAL;
2756
5727ef1b
JB
2757 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2758 return -EINVAL;
2759
2760 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2761 return -EINVAL;
2762
0e956c13
TLSC
2763 if (!info->attrs[NL80211_ATTR_STA_AID])
2764 return -EINVAL;
2765
5727ef1b
JB
2766 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2767 params.supported_rates =
2768 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2769 params.supported_rates_len =
2770 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2771 params.listen_interval =
2772 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2773
0e956c13
TLSC
2774 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2775 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2776 return -EINVAL;
51b50fbe 2777
36aedc90
JM
2778 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2779 params.ht_capa =
2780 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2781
96b78dff
JC
2782 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2783 params.plink_action =
2784 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2785
bdd90d5e
JB
2786 if (!rdev->ops->add_station)
2787 return -EOPNOTSUPP;
2788
bdd3ae3d 2789 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
2790 return -EINVAL;
2791
bdd90d5e
JB
2792 switch (dev->ieee80211_ptr->iftype) {
2793 case NL80211_IFTYPE_AP:
2794 case NL80211_IFTYPE_AP_VLAN:
2795 case NL80211_IFTYPE_P2P_GO:
2796 /* parse WME attributes if sta is WME capable */
2797 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
2798 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
2799 info->attrs[NL80211_ATTR_STA_WME]) {
2800 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
2801 struct nlattr *nla;
2802
2803 nla = info->attrs[NL80211_ATTR_STA_WME];
2804 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
2805 nl80211_sta_wme_policy);
2806 if (err)
2807 return err;
2808
2809 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
2810 params.uapsd_queues =
2811 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
2812 if (params.uapsd_queues &
2813 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
2814 return -EINVAL;
c75786c9 2815
bdd90d5e
JB
2816 if (tb[NL80211_STA_WME_MAX_SP])
2817 params.max_sp =
2818 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 2819
bdd90d5e
JB
2820 if (params.max_sp &
2821 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
2822 return -EINVAL;
4319e193 2823
bdd90d5e
JB
2824 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
2825 }
2826 /* TDLS peers cannot be added */
2827 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 2828 return -EINVAL;
bdd90d5e
JB
2829 /* but don't bother the driver with it */
2830 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 2831
bdd90d5e
JB
2832 /* must be last in here for error handling */
2833 params.vlan = get_vlan(info, rdev);
2834 if (IS_ERR(params.vlan))
2835 return PTR_ERR(params.vlan);
2836 break;
2837 case NL80211_IFTYPE_MESH_POINT:
2838 /* TDLS peers cannot be added */
2839 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
2840 return -EINVAL;
2841 break;
2842 case NL80211_IFTYPE_STATION:
2843 /* Only TDLS peers can be added */
2844 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
2845 return -EINVAL;
2846 /* Can only add if TDLS ... */
2847 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
2848 return -EOPNOTSUPP;
2849 /* ... with external setup is supported */
2850 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
2851 return -EOPNOTSUPP;
2852 break;
2853 default:
2854 return -EOPNOTSUPP;
c75786c9
EP
2855 }
2856
bdd90d5e 2857 /* be aware of params.vlan when changing code here */
5727ef1b 2858
79c97e97 2859 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 2860
5727ef1b
JB
2861 if (params.vlan)
2862 dev_put(params.vlan);
5727ef1b
JB
2863 return err;
2864}
2865
2866static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2867{
4c476991
JB
2868 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2869 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2870 u8 *mac_addr = NULL;
2871
2872 if (info->attrs[NL80211_ATTR_MAC])
2873 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2874
e80cf853 2875 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 2876 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 2877 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
2878 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2879 return -EINVAL;
5727ef1b 2880
4c476991
JB
2881 if (!rdev->ops->del_station)
2882 return -EOPNOTSUPP;
3b85875a 2883
4c476991 2884 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2885}
2886
2ec600d6
LCC
2887static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2888 int flags, struct net_device *dev,
2889 u8 *dst, u8 *next_hop,
2890 struct mpath_info *pinfo)
2891{
2892 void *hdr;
2893 struct nlattr *pinfoattr;
2894
2895 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2896 if (!hdr)
2897 return -1;
2898
2899 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2900 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2901 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2902
f5ea9120
JB
2903 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2904
2ec600d6
LCC
2905 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2906 if (!pinfoattr)
2907 goto nla_put_failure;
2908 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2909 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2910 pinfo->frame_qlen);
d19b3bf6
RP
2911 if (pinfo->filled & MPATH_INFO_SN)
2912 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2913 pinfo->sn);
2ec600d6
LCC
2914 if (pinfo->filled & MPATH_INFO_METRIC)
2915 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2916 pinfo->metric);
2917 if (pinfo->filled & MPATH_INFO_EXPTIME)
2918 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2919 pinfo->exptime);
2920 if (pinfo->filled & MPATH_INFO_FLAGS)
2921 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2922 pinfo->flags);
2923 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2924 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2925 pinfo->discovery_timeout);
2926 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2927 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2928 pinfo->discovery_retries);
2929
2930 nla_nest_end(msg, pinfoattr);
2931
2932 return genlmsg_end(msg, hdr);
2933
2934 nla_put_failure:
bc3ed28c
TG
2935 genlmsg_cancel(msg, hdr);
2936 return -EMSGSIZE;
2ec600d6
LCC
2937}
2938
2939static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2940 struct netlink_callback *cb)
2ec600d6 2941{
2ec600d6
LCC
2942 struct mpath_info pinfo;
2943 struct cfg80211_registered_device *dev;
bba95fef 2944 struct net_device *netdev;
2ec600d6
LCC
2945 u8 dst[ETH_ALEN];
2946 u8 next_hop[ETH_ALEN];
bba95fef 2947 int path_idx = cb->args[1];
2ec600d6 2948 int err;
2ec600d6 2949
67748893
JB
2950 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2951 if (err)
2952 return err;
bba95fef
JB
2953
2954 if (!dev->ops->dump_mpath) {
eec60b03 2955 err = -EOPNOTSUPP;
bba95fef
JB
2956 goto out_err;
2957 }
2958
eec60b03
JM
2959 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2960 err = -EOPNOTSUPP;
0448b5fc 2961 goto out_err;
eec60b03
JM
2962 }
2963
bba95fef
JB
2964 while (1) {
2965 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2966 dst, next_hop, &pinfo);
2967 if (err == -ENOENT)
2ec600d6 2968 break;
bba95fef 2969 if (err)
3b85875a 2970 goto out_err;
2ec600d6 2971
bba95fef
JB
2972 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2973 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2974 netdev, dst, next_hop,
2975 &pinfo) < 0)
2976 goto out;
2ec600d6 2977
bba95fef 2978 path_idx++;
2ec600d6 2979 }
2ec600d6 2980
2ec600d6 2981
bba95fef
JB
2982 out:
2983 cb->args[1] = path_idx;
2984 err = skb->len;
bba95fef 2985 out_err:
67748893 2986 nl80211_finish_netdev_dump(dev);
bba95fef 2987 return err;
2ec600d6
LCC
2988}
2989
2990static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2991{
4c476991 2992 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2993 int err;
4c476991 2994 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
2995 struct mpath_info pinfo;
2996 struct sk_buff *msg;
2997 u8 *dst = NULL;
2998 u8 next_hop[ETH_ALEN];
2999
3000 memset(&pinfo, 0, sizeof(pinfo));
3001
3002 if (!info->attrs[NL80211_ATTR_MAC])
3003 return -EINVAL;
3004
3005 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3006
4c476991
JB
3007 if (!rdev->ops->get_mpath)
3008 return -EOPNOTSUPP;
2ec600d6 3009
4c476991
JB
3010 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3011 return -EOPNOTSUPP;
eec60b03 3012
79c97e97 3013 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 3014 if (err)
4c476991 3015 return err;
2ec600d6 3016
fd2120ca 3017 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3018 if (!msg)
4c476991 3019 return -ENOMEM;
2ec600d6
LCC
3020
3021 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
3022 dev, dst, next_hop, &pinfo) < 0) {
3023 nlmsg_free(msg);
3024 return -ENOBUFS;
3025 }
3b85875a 3026
4c476991 3027 return genlmsg_reply(msg, info);
2ec600d6
LCC
3028}
3029
3030static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3031{
4c476991
JB
3032 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3033 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3034 u8 *dst = NULL;
3035 u8 *next_hop = NULL;
3036
3037 if (!info->attrs[NL80211_ATTR_MAC])
3038 return -EINVAL;
3039
3040 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3041 return -EINVAL;
3042
3043 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3044 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3045
4c476991
JB
3046 if (!rdev->ops->change_mpath)
3047 return -EOPNOTSUPP;
35a8efe1 3048
4c476991
JB
3049 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3050 return -EOPNOTSUPP;
2ec600d6 3051
4c476991 3052 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 3053}
4c476991 3054
2ec600d6
LCC
3055static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3056{
4c476991
JB
3057 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3058 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3059 u8 *dst = NULL;
3060 u8 *next_hop = NULL;
3061
3062 if (!info->attrs[NL80211_ATTR_MAC])
3063 return -EINVAL;
3064
3065 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3066 return -EINVAL;
3067
3068 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3069 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3070
4c476991
JB
3071 if (!rdev->ops->add_mpath)
3072 return -EOPNOTSUPP;
35a8efe1 3073
4c476991
JB
3074 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3075 return -EOPNOTSUPP;
2ec600d6 3076
4c476991 3077 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
3078}
3079
3080static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3081{
4c476991
JB
3082 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3083 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3084 u8 *dst = NULL;
3085
3086 if (info->attrs[NL80211_ATTR_MAC])
3087 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3088
4c476991
JB
3089 if (!rdev->ops->del_mpath)
3090 return -EOPNOTSUPP;
3b85875a 3091
4c476991 3092 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
3093}
3094
9f1ba906
JM
3095static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3096{
4c476991
JB
3097 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3098 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3099 struct bss_parameters params;
3100
3101 memset(&params, 0, sizeof(params));
3102 /* default to not changing parameters */
3103 params.use_cts_prot = -1;
3104 params.use_short_preamble = -1;
3105 params.use_short_slot_time = -1;
fd8aaaf3 3106 params.ap_isolate = -1;
50b12f59 3107 params.ht_opmode = -1;
9f1ba906
JM
3108
3109 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3110 params.use_cts_prot =
3111 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3112 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3113 params.use_short_preamble =
3114 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3115 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3116 params.use_short_slot_time =
3117 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3118 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3119 params.basic_rates =
3120 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3121 params.basic_rates_len =
3122 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3123 }
fd8aaaf3
FF
3124 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3125 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3126 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3127 params.ht_opmode =
3128 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3129
4c476991
JB
3130 if (!rdev->ops->change_bss)
3131 return -EOPNOTSUPP;
9f1ba906 3132
074ac8df 3133 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3134 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3135 return -EOPNOTSUPP;
3b85875a 3136
4c476991 3137 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
3138}
3139
b54452b0 3140static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3141 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3142 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3143 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3144 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3145 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3146 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3147};
3148
3149static int parse_reg_rule(struct nlattr *tb[],
3150 struct ieee80211_reg_rule *reg_rule)
3151{
3152 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3153 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3154
3155 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3156 return -EINVAL;
3157 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3158 return -EINVAL;
3159 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3160 return -EINVAL;
3161 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3162 return -EINVAL;
3163 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3164 return -EINVAL;
3165
3166 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3167
3168 freq_range->start_freq_khz =
3169 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3170 freq_range->end_freq_khz =
3171 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3172 freq_range->max_bandwidth_khz =
3173 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3174
3175 power_rule->max_eirp =
3176 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3177
3178 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3179 power_rule->max_antenna_gain =
3180 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3181
3182 return 0;
3183}
3184
3185static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3186{
3187 int r;
3188 char *data = NULL;
3189
80778f18
LR
3190 /*
3191 * You should only get this when cfg80211 hasn't yet initialized
3192 * completely when built-in to the kernel right between the time
3193 * window between nl80211_init() and regulatory_init(), if that is
3194 * even possible.
3195 */
3196 mutex_lock(&cfg80211_mutex);
3197 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3198 mutex_unlock(&cfg80211_mutex);
3199 return -EINPROGRESS;
80778f18 3200 }
fe33eb39 3201 mutex_unlock(&cfg80211_mutex);
80778f18 3202
fe33eb39
LR
3203 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3204 return -EINVAL;
b2e1b302
LR
3205
3206 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3207
fe33eb39
LR
3208 r = regulatory_hint_user(data);
3209
b2e1b302
LR
3210 return r;
3211}
3212
24bdd9f4 3213static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3214 struct genl_info *info)
93da9cc1 3215{
4c476991 3216 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3217 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3218 struct wireless_dev *wdev = dev->ieee80211_ptr;
3219 struct mesh_config cur_params;
3220 int err = 0;
93da9cc1 3221 void *hdr;
3222 struct nlattr *pinfoattr;
3223 struct sk_buff *msg;
3224
29cbe68c
JB
3225 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3226 return -EOPNOTSUPP;
3227
24bdd9f4 3228 if (!rdev->ops->get_mesh_config)
4c476991 3229 return -EOPNOTSUPP;
f3f92586 3230
29cbe68c
JB
3231 wdev_lock(wdev);
3232 /* If not connected, get default parameters */
3233 if (!wdev->mesh_id_len)
3234 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3235 else
24bdd9f4 3236 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3237 &cur_params);
3238 wdev_unlock(wdev);
3239
93da9cc1 3240 if (err)
4c476991 3241 return err;
93da9cc1 3242
3243 /* Draw up a netlink message to send back */
fd2120ca 3244 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3245 if (!msg)
3246 return -ENOMEM;
93da9cc1 3247 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3248 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3249 if (!hdr)
efe1cf0c 3250 goto out;
24bdd9f4 3251 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3252 if (!pinfoattr)
3253 goto nla_put_failure;
3254 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3255 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3256 cur_params.dot11MeshRetryTimeout);
3257 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3258 cur_params.dot11MeshConfirmTimeout);
3259 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3260 cur_params.dot11MeshHoldingTimeout);
3261 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3262 cur_params.dot11MeshMaxPeerLinks);
3263 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
3264 cur_params.dot11MeshMaxRetries);
3265 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
3266 cur_params.dot11MeshTTL);
45904f21
JC
3267 NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3268 cur_params.element_ttl);
93da9cc1 3269 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3270 cur_params.auto_open_plinks);
3271 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3272 cur_params.dot11MeshHWMPmaxPREQretries);
3273 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3274 cur_params.path_refresh_time);
3275 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3276 cur_params.min_discovery_timeout);
3277 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3278 cur_params.dot11MeshHWMPactivePathTimeout);
3279 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3280 cur_params.dot11MeshHWMPpreqMinInterval);
dca7e943
TP
3281 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3282 cur_params.dot11MeshHWMPperrMinInterval);
93da9cc1 3283 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3284 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
3285 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3286 cur_params.dot11MeshHWMPRootMode);
0507e159
JC
3287 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3288 cur_params.dot11MeshHWMPRannInterval);
16dd7267
JC
3289 NLA_PUT_U8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3290 cur_params.dot11MeshGateAnnouncementProtocol);
94f90656
CYY
3291 NLA_PUT_U8(msg, NL80211_MESHCONF_FORWARDING,
3292 cur_params.dot11MeshForwarding);
55335137
AN
3293 NLA_PUT_U32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
3294 cur_params.rssi_threshold);
93da9cc1 3295 nla_nest_end(msg, pinfoattr);
3296 genlmsg_end(msg, hdr);
4c476991 3297 return genlmsg_reply(msg, info);
93da9cc1 3298
3b85875a 3299 nla_put_failure:
93da9cc1 3300 genlmsg_cancel(msg, hdr);
efe1cf0c 3301 out:
d080e275 3302 nlmsg_free(msg);
4c476991 3303 return -ENOBUFS;
93da9cc1 3304}
3305
b54452b0 3306static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3307 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3308 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3309 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3310 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3311 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3312 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3313 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3314 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
3315
3316 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3317 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3318 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3319 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3320 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3321 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3322 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3323 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3324 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3325 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3326 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
55335137 3327 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32},
93da9cc1 3328};
3329
c80d545d
JC
3330static const struct nla_policy
3331 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
3332 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3333 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3334 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3335 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
c80d545d 3336 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3337 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3338};
3339
24bdd9f4 3340static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3341 struct mesh_config *cfg,
3342 u32 *mask_out)
93da9cc1 3343{
93da9cc1 3344 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3345 u32 mask = 0;
93da9cc1 3346
bd90fdcc
JB
3347#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3348do {\
3349 if (table[attr_num]) {\
3350 cfg->param = nla_fn(table[attr_num]); \
3351 mask |= (1 << (attr_num - 1)); \
3352 } \
3353} while (0);\
3354
3355
24bdd9f4 3356 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3357 return -EINVAL;
3358 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3359 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3360 nl80211_meshconf_params_policy))
93da9cc1 3361 return -EINVAL;
3362
93da9cc1 3363 /* This makes sure that there aren't more than 32 mesh config
3364 * parameters (otherwise our bitfield scheme would not work.) */
3365 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3366
3367 /* Fill in the params struct */
93da9cc1 3368 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
3369 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
3370 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
3371 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
3372 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
3373 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
3374 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
3375 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
3376 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
3377 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
3378 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
3379 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21
JC
3380 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
3381 mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
93da9cc1 3382 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
3383 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
3384 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
3385 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3386 nla_get_u8);
3387 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
3388 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
3389 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
3390 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3391 nla_get_u16);
3392 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
3393 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3394 nla_get_u32);
3395 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
3396 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3397 nla_get_u16);
dca7e943
TP
3398 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
3399 mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3400 nla_get_u16);
93da9cc1 3401 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3402 dot11MeshHWMPnetDiameterTraversalTime,
3403 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3404 nla_get_u16);
63c5723b
RP
3405 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3406 dot11MeshHWMPRootMode, mask,
3407 NL80211_MESHCONF_HWMP_ROOTMODE,
3408 nla_get_u8);
0507e159
JC
3409 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3410 dot11MeshHWMPRannInterval, mask,
3411 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3412 nla_get_u16);
16dd7267
JC
3413 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3414 dot11MeshGateAnnouncementProtocol, mask,
3415 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3416 nla_get_u8);
94f90656
CYY
3417 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
3418 mask, NL80211_MESHCONF_FORWARDING, nla_get_u8);
55335137
AN
3419 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
3420 mask, NL80211_MESHCONF_RSSI_THRESHOLD, nla_get_u32);
bd90fdcc
JB
3421 if (mask_out)
3422 *mask_out = mask;
c80d545d 3423
bd90fdcc
JB
3424 return 0;
3425
3426#undef FILL_IN_MESH_PARAM_IF_SET
3427}
3428
c80d545d
JC
3429static int nl80211_parse_mesh_setup(struct genl_info *info,
3430 struct mesh_setup *setup)
3431{
3432 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3433
3434 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3435 return -EINVAL;
3436 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3437 info->attrs[NL80211_ATTR_MESH_SETUP],
3438 nl80211_mesh_setup_params_policy))
3439 return -EINVAL;
3440
3441 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3442 setup->path_sel_proto =
3443 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3444 IEEE80211_PATH_PROTOCOL_VENDOR :
3445 IEEE80211_PATH_PROTOCOL_HWMP;
3446
3447 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3448 setup->path_metric =
3449 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3450 IEEE80211_PATH_METRIC_VENDOR :
3451 IEEE80211_PATH_METRIC_AIRTIME;
3452
581a8b0f
JC
3453
3454 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3455 struct nlattr *ieattr =
581a8b0f 3456 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3457 if (!is_valid_ie_attr(ieattr))
3458 return -EINVAL;
581a8b0f
JC
3459 setup->ie = nla_data(ieattr);
3460 setup->ie_len = nla_len(ieattr);
c80d545d 3461 }
b130e5ce
JC
3462 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3463 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3464
3465 return 0;
3466}
3467
24bdd9f4 3468static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3469 struct genl_info *info)
bd90fdcc
JB
3470{
3471 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3472 struct net_device *dev = info->user_ptr[1];
29cbe68c 3473 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3474 struct mesh_config cfg;
3475 u32 mask;
3476 int err;
3477
29cbe68c
JB
3478 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3479 return -EOPNOTSUPP;
3480
24bdd9f4 3481 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3482 return -EOPNOTSUPP;
3483
24bdd9f4 3484 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3485 if (err)
3486 return err;
3487
29cbe68c
JB
3488 wdev_lock(wdev);
3489 if (!wdev->mesh_id_len)
3490 err = -ENOLINK;
3491
3492 if (!err)
24bdd9f4 3493 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3494 mask, &cfg);
3495
3496 wdev_unlock(wdev);
3497
3498 return err;
93da9cc1 3499}
3500
f130347c
LR
3501static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3502{
3503 struct sk_buff *msg;
3504 void *hdr = NULL;
3505 struct nlattr *nl_reg_rules;
3506 unsigned int i;
3507 int err = -EINVAL;
3508
a1794390 3509 mutex_lock(&cfg80211_mutex);
f130347c
LR
3510
3511 if (!cfg80211_regdomain)
3512 goto out;
3513
fd2120ca 3514 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3515 if (!msg) {
3516 err = -ENOBUFS;
3517 goto out;
3518 }
3519
3520 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3521 NL80211_CMD_GET_REG);
3522 if (!hdr)
efe1cf0c 3523 goto put_failure;
f130347c
LR
3524
3525 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
3526 cfg80211_regdomain->alpha2);
8b60b078
LR
3527 if (cfg80211_regdomain->dfs_region)
3528 NLA_PUT_U8(msg, NL80211_ATTR_DFS_REGION,
3529 cfg80211_regdomain->dfs_region);
f130347c
LR
3530
3531 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3532 if (!nl_reg_rules)
3533 goto nla_put_failure;
3534
3535 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3536 struct nlattr *nl_reg_rule;
3537 const struct ieee80211_reg_rule *reg_rule;
3538 const struct ieee80211_freq_range *freq_range;
3539 const struct ieee80211_power_rule *power_rule;
3540
3541 reg_rule = &cfg80211_regdomain->reg_rules[i];
3542 freq_range = &reg_rule->freq_range;
3543 power_rule = &reg_rule->power_rule;
3544
3545 nl_reg_rule = nla_nest_start(msg, i);
3546 if (!nl_reg_rule)
3547 goto nla_put_failure;
3548
3549 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3550 reg_rule->flags);
3551 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
3552 freq_range->start_freq_khz);
3553 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
3554 freq_range->end_freq_khz);
3555 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3556 freq_range->max_bandwidth_khz);
3557 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3558 power_rule->max_antenna_gain);
3559 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3560 power_rule->max_eirp);
3561
3562 nla_nest_end(msg, nl_reg_rule);
3563 }
3564
3565 nla_nest_end(msg, nl_reg_rules);
3566
3567 genlmsg_end(msg, hdr);
134e6375 3568 err = genlmsg_reply(msg, info);
f130347c
LR
3569 goto out;
3570
3571nla_put_failure:
3572 genlmsg_cancel(msg, hdr);
efe1cf0c 3573put_failure:
d080e275 3574 nlmsg_free(msg);
f130347c
LR
3575 err = -EMSGSIZE;
3576out:
a1794390 3577 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3578 return err;
3579}
3580
b2e1b302
LR
3581static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3582{
3583 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3584 struct nlattr *nl_reg_rule;
3585 char *alpha2 = NULL;
3586 int rem_reg_rules = 0, r = 0;
3587 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 3588 u8 dfs_region = 0;
b2e1b302
LR
3589 struct ieee80211_regdomain *rd = NULL;
3590
3591 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3592 return -EINVAL;
3593
3594 if (!info->attrs[NL80211_ATTR_REG_RULES])
3595 return -EINVAL;
3596
3597 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3598
8b60b078
LR
3599 if (info->attrs[NL80211_ATTR_DFS_REGION])
3600 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
3601
b2e1b302
LR
3602 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3603 rem_reg_rules) {
3604 num_rules++;
3605 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 3606 return -EINVAL;
b2e1b302
LR
3607 }
3608
61405e97
LR
3609 mutex_lock(&cfg80211_mutex);
3610
d0e18f83
LR
3611 if (!reg_is_valid_request(alpha2)) {
3612 r = -EINVAL;
3613 goto bad_reg;
3614 }
b2e1b302
LR
3615
3616 size_of_regd = sizeof(struct ieee80211_regdomain) +
3617 (num_rules * sizeof(struct ieee80211_reg_rule));
3618
3619 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
3620 if (!rd) {
3621 r = -ENOMEM;
3622 goto bad_reg;
3623 }
b2e1b302
LR
3624
3625 rd->n_reg_rules = num_rules;
3626 rd->alpha2[0] = alpha2[0];
3627 rd->alpha2[1] = alpha2[1];
3628
8b60b078
LR
3629 /*
3630 * Disable DFS master mode if the DFS region was
3631 * not supported or known on this kernel.
3632 */
3633 if (reg_supported_dfs_region(dfs_region))
3634 rd->dfs_region = dfs_region;
3635
b2e1b302
LR
3636 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3637 rem_reg_rules) {
3638 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3639 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3640 reg_rule_policy);
3641 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3642 if (r)
3643 goto bad_reg;
3644
3645 rule_idx++;
3646
d0e18f83
LR
3647 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3648 r = -EINVAL;
b2e1b302 3649 goto bad_reg;
d0e18f83 3650 }
b2e1b302
LR
3651 }
3652
3653 BUG_ON(rule_idx != num_rules);
3654
b2e1b302 3655 r = set_regdom(rd);
61405e97 3656
a1794390 3657 mutex_unlock(&cfg80211_mutex);
d0e18f83 3658
b2e1b302
LR
3659 return r;
3660
d2372b31 3661 bad_reg:
61405e97 3662 mutex_unlock(&cfg80211_mutex);
b2e1b302 3663 kfree(rd);
d0e18f83 3664 return r;
b2e1b302
LR
3665}
3666
83f5e2cf
JB
3667static int validate_scan_freqs(struct nlattr *freqs)
3668{
3669 struct nlattr *attr1, *attr2;
3670 int n_channels = 0, tmp1, tmp2;
3671
3672 nla_for_each_nested(attr1, freqs, tmp1) {
3673 n_channels++;
3674 /*
3675 * Some hardware has a limited channel list for
3676 * scanning, and it is pretty much nonsensical
3677 * to scan for a channel twice, so disallow that
3678 * and don't require drivers to check that the
3679 * channel list they get isn't longer than what
3680 * they can scan, as long as they can scan all
3681 * the channels they registered at once.
3682 */
3683 nla_for_each_nested(attr2, freqs, tmp2)
3684 if (attr1 != attr2 &&
3685 nla_get_u32(attr1) == nla_get_u32(attr2))
3686 return 0;
3687 }
3688
3689 return n_channels;
3690}
3691
2a519311
JB
3692static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3693{
4c476991
JB
3694 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3695 struct net_device *dev = info->user_ptr[1];
2a519311 3696 struct cfg80211_scan_request *request;
2a519311
JB
3697 struct nlattr *attr;
3698 struct wiphy *wiphy;
83f5e2cf 3699 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 3700 size_t ie_len;
2a519311 3701
f4a11bb0
JB
3702 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3703 return -EINVAL;
3704
79c97e97 3705 wiphy = &rdev->wiphy;
2a519311 3706
4c476991
JB
3707 if (!rdev->ops->scan)
3708 return -EOPNOTSUPP;
2a519311 3709
4c476991
JB
3710 if (rdev->scan_req)
3711 return -EBUSY;
2a519311
JB
3712
3713 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3714 n_channels = validate_scan_freqs(
3715 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
3716 if (!n_channels)
3717 return -EINVAL;
2a519311 3718 } else {
34850ab2 3719 enum ieee80211_band band;
83f5e2cf
JB
3720 n_channels = 0;
3721
2a519311
JB
3722 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3723 if (wiphy->bands[band])
3724 n_channels += wiphy->bands[band]->n_channels;
3725 }
3726
3727 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3728 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3729 n_ssids++;
3730
4c476991
JB
3731 if (n_ssids > wiphy->max_scan_ssids)
3732 return -EINVAL;
2a519311 3733
70692ad2
JM
3734 if (info->attrs[NL80211_ATTR_IE])
3735 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3736 else
3737 ie_len = 0;
3738
4c476991
JB
3739 if (ie_len > wiphy->max_scan_ie_len)
3740 return -EINVAL;
18a83659 3741
2a519311 3742 request = kzalloc(sizeof(*request)
a2cd43c5
LC
3743 + sizeof(*request->ssids) * n_ssids
3744 + sizeof(*request->channels) * n_channels
70692ad2 3745 + ie_len, GFP_KERNEL);
4c476991
JB
3746 if (!request)
3747 return -ENOMEM;
2a519311 3748
2a519311 3749 if (n_ssids)
5ba63533 3750 request->ssids = (void *)&request->channels[n_channels];
2a519311 3751 request->n_ssids = n_ssids;
70692ad2
JM
3752 if (ie_len) {
3753 if (request->ssids)
3754 request->ie = (void *)(request->ssids + n_ssids);
3755 else
3756 request->ie = (void *)(request->channels + n_channels);
3757 }
2a519311 3758
584991dc 3759 i = 0;
2a519311
JB
3760 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3761 /* user specified, bail out if channel not found */
2a519311 3762 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3763 struct ieee80211_channel *chan;
3764
3765 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3766
3767 if (!chan) {
2a519311
JB
3768 err = -EINVAL;
3769 goto out_free;
3770 }
584991dc
JB
3771
3772 /* ignore disabled channels */
3773 if (chan->flags & IEEE80211_CHAN_DISABLED)
3774 continue;
3775
3776 request->channels[i] = chan;
2a519311
JB
3777 i++;
3778 }
3779 } else {
34850ab2
JB
3780 enum ieee80211_band band;
3781
2a519311 3782 /* all channels */
2a519311
JB
3783 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3784 int j;
3785 if (!wiphy->bands[band])
3786 continue;
3787 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3788 struct ieee80211_channel *chan;
3789
3790 chan = &wiphy->bands[band]->channels[j];
3791
3792 if (chan->flags & IEEE80211_CHAN_DISABLED)
3793 continue;
3794
3795 request->channels[i] = chan;
2a519311
JB
3796 i++;
3797 }
3798 }
3799 }
3800
584991dc
JB
3801 if (!i) {
3802 err = -EINVAL;
3803 goto out_free;
3804 }
3805
3806 request->n_channels = i;
3807
2a519311
JB
3808 i = 0;
3809 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3810 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 3811 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
3812 err = -EINVAL;
3813 goto out_free;
3814 }
57a27e1d 3815 request->ssids[i].ssid_len = nla_len(attr);
2a519311 3816 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
3817 i++;
3818 }
3819 }
3820
70692ad2
JM
3821 if (info->attrs[NL80211_ATTR_IE]) {
3822 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3823 memcpy((void *)request->ie,
3824 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3825 request->ie_len);
3826 }
3827
34850ab2 3828 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
3829 if (wiphy->bands[i])
3830 request->rates[i] =
3831 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
3832
3833 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
3834 nla_for_each_nested(attr,
3835 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
3836 tmp) {
3837 enum ieee80211_band band = nla_type(attr);
3838
84404623 3839 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
3840 err = -EINVAL;
3841 goto out_free;
3842 }
3843 err = ieee80211_get_ratemask(wiphy->bands[band],
3844 nla_data(attr),
3845 nla_len(attr),
3846 &request->rates[band]);
3847 if (err)
3848 goto out_free;
3849 }
3850 }
3851
e9f935e3
RM
3852 request->no_cck =
3853 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
3854
463d0183 3855 request->dev = dev;
79c97e97 3856 request->wiphy = &rdev->wiphy;
2a519311 3857
79c97e97
JB
3858 rdev->scan_req = request;
3859 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3860
463d0183 3861 if (!err) {
79c97e97 3862 nl80211_send_scan_start(rdev, dev);
463d0183 3863 dev_hold(dev);
4c476991 3864 } else {
2a519311 3865 out_free:
79c97e97 3866 rdev->scan_req = NULL;
2a519311
JB
3867 kfree(request);
3868 }
3b85875a 3869
2a519311
JB
3870 return err;
3871}
3872
807f8a8c
LC
3873static int nl80211_start_sched_scan(struct sk_buff *skb,
3874 struct genl_info *info)
3875{
3876 struct cfg80211_sched_scan_request *request;
3877 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3878 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
3879 struct nlattr *attr;
3880 struct wiphy *wiphy;
a1f1c21c 3881 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 3882 u32 interval;
807f8a8c
LC
3883 enum ieee80211_band band;
3884 size_t ie_len;
a1f1c21c 3885 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
3886
3887 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
3888 !rdev->ops->sched_scan_start)
3889 return -EOPNOTSUPP;
3890
3891 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3892 return -EINVAL;
3893
bbe6ad6d
LC
3894 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
3895 return -EINVAL;
3896
3897 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
3898 if (interval == 0)
3899 return -EINVAL;
3900
807f8a8c
LC
3901 wiphy = &rdev->wiphy;
3902
3903 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3904 n_channels = validate_scan_freqs(
3905 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3906 if (!n_channels)
3907 return -EINVAL;
3908 } else {
3909 n_channels = 0;
3910
3911 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3912 if (wiphy->bands[band])
3913 n_channels += wiphy->bands[band]->n_channels;
3914 }
3915
3916 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3917 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
3918 tmp)
3919 n_ssids++;
3920
93b6aa69 3921 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
3922 return -EINVAL;
3923
a1f1c21c
LC
3924 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
3925 nla_for_each_nested(attr,
3926 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
3927 tmp)
3928 n_match_sets++;
3929
3930 if (n_match_sets > wiphy->max_match_sets)
3931 return -EINVAL;
3932
807f8a8c
LC
3933 if (info->attrs[NL80211_ATTR_IE])
3934 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3935 else
3936 ie_len = 0;
3937
5a865bad 3938 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
3939 return -EINVAL;
3940
c10841ca
LC
3941 mutex_lock(&rdev->sched_scan_mtx);
3942
3943 if (rdev->sched_scan_req) {
3944 err = -EINPROGRESS;
3945 goto out;
3946 }
3947
807f8a8c 3948 request = kzalloc(sizeof(*request)
a2cd43c5 3949 + sizeof(*request->ssids) * n_ssids
a1f1c21c 3950 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 3951 + sizeof(*request->channels) * n_channels
807f8a8c 3952 + ie_len, GFP_KERNEL);
c10841ca
LC
3953 if (!request) {
3954 err = -ENOMEM;
3955 goto out;
3956 }
807f8a8c
LC
3957
3958 if (n_ssids)
3959 request->ssids = (void *)&request->channels[n_channels];
3960 request->n_ssids = n_ssids;
3961 if (ie_len) {
3962 if (request->ssids)
3963 request->ie = (void *)(request->ssids + n_ssids);
3964 else
3965 request->ie = (void *)(request->channels + n_channels);
3966 }
3967
a1f1c21c
LC
3968 if (n_match_sets) {
3969 if (request->ie)
3970 request->match_sets = (void *)(request->ie + ie_len);
3971 else if (request->ssids)
3972 request->match_sets =
3973 (void *)(request->ssids + n_ssids);
3974 else
3975 request->match_sets =
3976 (void *)(request->channels + n_channels);
3977 }
3978 request->n_match_sets = n_match_sets;
3979
807f8a8c
LC
3980 i = 0;
3981 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3982 /* user specified, bail out if channel not found */
3983 nla_for_each_nested(attr,
3984 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
3985 tmp) {
3986 struct ieee80211_channel *chan;
3987
3988 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3989
3990 if (!chan) {
3991 err = -EINVAL;
3992 goto out_free;
3993 }
3994
3995 /* ignore disabled channels */
3996 if (chan->flags & IEEE80211_CHAN_DISABLED)
3997 continue;
3998
3999 request->channels[i] = chan;
4000 i++;
4001 }
4002 } else {
4003 /* all channels */
4004 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4005 int j;
4006 if (!wiphy->bands[band])
4007 continue;
4008 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4009 struct ieee80211_channel *chan;
4010
4011 chan = &wiphy->bands[band]->channels[j];
4012
4013 if (chan->flags & IEEE80211_CHAN_DISABLED)
4014 continue;
4015
4016 request->channels[i] = chan;
4017 i++;
4018 }
4019 }
4020 }
4021
4022 if (!i) {
4023 err = -EINVAL;
4024 goto out_free;
4025 }
4026
4027 request->n_channels = i;
4028
4029 i = 0;
4030 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4031 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4032 tmp) {
57a27e1d 4033 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4034 err = -EINVAL;
4035 goto out_free;
4036 }
57a27e1d 4037 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4038 memcpy(request->ssids[i].ssid, nla_data(attr),
4039 nla_len(attr));
807f8a8c
LC
4040 i++;
4041 }
4042 }
4043
a1f1c21c
LC
4044 i = 0;
4045 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4046 nla_for_each_nested(attr,
4047 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4048 tmp) {
4049 struct nlattr *ssid;
4050
4051 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4052 nla_data(attr), nla_len(attr),
4053 nl80211_match_policy);
4054 ssid = tb[NL80211_ATTR_SCHED_SCAN_MATCH_SSID];
4055 if (ssid) {
4056 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4057 err = -EINVAL;
4058 goto out_free;
4059 }
4060 memcpy(request->match_sets[i].ssid.ssid,
4061 nla_data(ssid), nla_len(ssid));
4062 request->match_sets[i].ssid.ssid_len =
4063 nla_len(ssid);
4064 }
4065 i++;
4066 }
4067 }
4068
807f8a8c
LC
4069 if (info->attrs[NL80211_ATTR_IE]) {
4070 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4071 memcpy((void *)request->ie,
4072 nla_data(info->attrs[NL80211_ATTR_IE]),
4073 request->ie_len);
4074 }
4075
4076 request->dev = dev;
4077 request->wiphy = &rdev->wiphy;
bbe6ad6d 4078 request->interval = interval;
807f8a8c
LC
4079
4080 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
4081 if (!err) {
4082 rdev->sched_scan_req = request;
4083 nl80211_send_sched_scan(rdev, dev,
4084 NL80211_CMD_START_SCHED_SCAN);
4085 goto out;
4086 }
4087
4088out_free:
4089 kfree(request);
4090out:
c10841ca 4091 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4092 return err;
4093}
4094
4095static int nl80211_stop_sched_scan(struct sk_buff *skb,
4096 struct genl_info *info)
4097{
4098 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4099 int err;
807f8a8c
LC
4100
4101 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4102 !rdev->ops->sched_scan_stop)
4103 return -EOPNOTSUPP;
4104
c10841ca
LC
4105 mutex_lock(&rdev->sched_scan_mtx);
4106 err = __cfg80211_stop_sched_scan(rdev, false);
4107 mutex_unlock(&rdev->sched_scan_mtx);
4108
4109 return err;
807f8a8c
LC
4110}
4111
9720bb3a
JB
4112static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4113 u32 seq, int flags,
2a519311 4114 struct cfg80211_registered_device *rdev,
48ab905d
JB
4115 struct wireless_dev *wdev,
4116 struct cfg80211_internal_bss *intbss)
2a519311 4117{
48ab905d 4118 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
4119 void *hdr;
4120 struct nlattr *bss;
48ab905d
JB
4121
4122 ASSERT_WDEV_LOCK(wdev);
2a519311 4123
9720bb3a 4124 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
4125 NL80211_CMD_NEW_SCAN_RESULTS);
4126 if (!hdr)
4127 return -1;
4128
9720bb3a
JB
4129 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4130
f5ea9120 4131 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 4132 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
4133
4134 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4135 if (!bss)
4136 goto nla_put_failure;
4137 if (!is_zero_ether_addr(res->bssid))
4138 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
4139 if (res->information_elements && res->len_information_elements)
4140 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4141 res->len_information_elements,
4142 res->information_elements);
34a6eddb
JM
4143 if (res->beacon_ies && res->len_beacon_ies &&
4144 res->beacon_ies != res->information_elements)
4145 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
4146 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
4147 if (res->tsf)
4148 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
4149 if (res->beacon_interval)
4150 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
4151 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
4152 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
4153 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
4154 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 4155
77965c97 4156 switch (rdev->wiphy.signal_type) {
2a519311
JB
4157 case CFG80211_SIGNAL_TYPE_MBM:
4158 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
4159 break;
4160 case CFG80211_SIGNAL_TYPE_UNSPEC:
4161 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
4162 break;
4163 default:
4164 break;
4165 }
4166
48ab905d 4167 switch (wdev->iftype) {
074ac8df 4168 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d
JB
4169 case NL80211_IFTYPE_STATION:
4170 if (intbss == wdev->current_bss)
4171 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4172 NL80211_BSS_STATUS_ASSOCIATED);
48ab905d
JB
4173 break;
4174 case NL80211_IFTYPE_ADHOC:
4175 if (intbss == wdev->current_bss)
4176 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
4177 NL80211_BSS_STATUS_IBSS_JOINED);
4178 break;
4179 default:
4180 break;
4181 }
4182
2a519311
JB
4183 nla_nest_end(msg, bss);
4184
4185 return genlmsg_end(msg, hdr);
4186
4187 nla_put_failure:
4188 genlmsg_cancel(msg, hdr);
4189 return -EMSGSIZE;
4190}
4191
4192static int nl80211_dump_scan(struct sk_buff *skb,
4193 struct netlink_callback *cb)
4194{
48ab905d
JB
4195 struct cfg80211_registered_device *rdev;
4196 struct net_device *dev;
2a519311 4197 struct cfg80211_internal_bss *scan;
48ab905d 4198 struct wireless_dev *wdev;
2a519311
JB
4199 int start = cb->args[1], idx = 0;
4200 int err;
4201
67748893
JB
4202 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4203 if (err)
4204 return err;
2a519311 4205
48ab905d 4206 wdev = dev->ieee80211_ptr;
2a519311 4207
48ab905d
JB
4208 wdev_lock(wdev);
4209 spin_lock_bh(&rdev->bss_lock);
4210 cfg80211_bss_expire(rdev);
4211
9720bb3a
JB
4212 cb->seq = rdev->bss_generation;
4213
48ab905d 4214 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4215 if (++idx <= start)
4216 continue;
9720bb3a 4217 if (nl80211_send_bss(skb, cb,
2a519311 4218 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4219 rdev, wdev, scan) < 0) {
2a519311 4220 idx--;
67748893 4221 break;
2a519311
JB
4222 }
4223 }
4224
48ab905d
JB
4225 spin_unlock_bh(&rdev->bss_lock);
4226 wdev_unlock(wdev);
2a519311
JB
4227
4228 cb->args[1] = idx;
67748893 4229 nl80211_finish_netdev_dump(rdev);
2a519311 4230
67748893 4231 return skb->len;
2a519311
JB
4232}
4233
61fa713c
HS
4234static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4235 int flags, struct net_device *dev,
4236 struct survey_info *survey)
4237{
4238 void *hdr;
4239 struct nlattr *infoattr;
4240
61fa713c
HS
4241 hdr = nl80211hdr_put(msg, pid, seq, flags,
4242 NL80211_CMD_NEW_SURVEY_RESULTS);
4243 if (!hdr)
4244 return -ENOMEM;
4245
4246 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
4247
4248 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4249 if (!infoattr)
4250 goto nla_put_failure;
4251
4252 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4253 survey->channel->center_freq);
4254 if (survey->filled & SURVEY_INFO_NOISE_DBM)
4255 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
4256 survey->noise);
17e5a808
FF
4257 if (survey->filled & SURVEY_INFO_IN_USE)
4258 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
8610c29a
FF
4259 if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
4260 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4261 survey->channel_time);
4262 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
4263 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4264 survey->channel_time_busy);
4265 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
4266 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4267 survey->channel_time_ext_busy);
4268 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
4269 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4270 survey->channel_time_rx);
4271 if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
4272 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4273 survey->channel_time_tx);
61fa713c
HS
4274
4275 nla_nest_end(msg, infoattr);
4276
4277 return genlmsg_end(msg, hdr);
4278
4279 nla_put_failure:
4280 genlmsg_cancel(msg, hdr);
4281 return -EMSGSIZE;
4282}
4283
4284static int nl80211_dump_survey(struct sk_buff *skb,
4285 struct netlink_callback *cb)
4286{
4287 struct survey_info survey;
4288 struct cfg80211_registered_device *dev;
4289 struct net_device *netdev;
61fa713c
HS
4290 int survey_idx = cb->args[1];
4291 int res;
4292
67748893
JB
4293 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4294 if (res)
4295 return res;
61fa713c
HS
4296
4297 if (!dev->ops->dump_survey) {
4298 res = -EOPNOTSUPP;
4299 goto out_err;
4300 }
4301
4302 while (1) {
180cdc79
LR
4303 struct ieee80211_channel *chan;
4304
61fa713c
HS
4305 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4306 &survey);
4307 if (res == -ENOENT)
4308 break;
4309 if (res)
4310 goto out_err;
4311
180cdc79
LR
4312 /* Survey without a channel doesn't make sense */
4313 if (!survey.channel) {
4314 res = -EINVAL;
4315 goto out;
4316 }
4317
4318 chan = ieee80211_get_channel(&dev->wiphy,
4319 survey.channel->center_freq);
4320 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4321 survey_idx++;
4322 continue;
4323 }
4324
61fa713c
HS
4325 if (nl80211_send_survey(skb,
4326 NETLINK_CB(cb->skb).pid,
4327 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4328 netdev,
4329 &survey) < 0)
4330 goto out;
4331 survey_idx++;
4332 }
4333
4334 out:
4335 cb->args[1] = survey_idx;
4336 res = skb->len;
4337 out_err:
67748893 4338 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4339 return res;
4340}
4341
255e737e
JM
4342static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4343{
b23aa676
SO
4344 return auth_type <= NL80211_AUTHTYPE_MAX;
4345}
4346
4347static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4348{
4349 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4350 NL80211_WPA_VERSION_2));
4351}
4352
636a5d36
JM
4353static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4354{
4c476991
JB
4355 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4356 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4357 struct ieee80211_channel *chan;
4358 const u8 *bssid, *ssid, *ie = NULL;
4359 int err, ssid_len, ie_len = 0;
4360 enum nl80211_auth_type auth_type;
fffd0934 4361 struct key_parse key;
d5cdfacb 4362 bool local_state_change;
636a5d36 4363
f4a11bb0
JB
4364 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4365 return -EINVAL;
4366
4367 if (!info->attrs[NL80211_ATTR_MAC])
4368 return -EINVAL;
4369
1778092e
JM
4370 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4371 return -EINVAL;
4372
19957bb3
JB
4373 if (!info->attrs[NL80211_ATTR_SSID])
4374 return -EINVAL;
4375
4376 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4377 return -EINVAL;
4378
fffd0934
JB
4379 err = nl80211_parse_key(info, &key);
4380 if (err)
4381 return err;
4382
4383 if (key.idx >= 0) {
e31b8213
JB
4384 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4385 return -EINVAL;
fffd0934
JB
4386 if (!key.p.key || !key.p.key_len)
4387 return -EINVAL;
4388 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4389 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4390 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4391 key.p.key_len != WLAN_KEY_LEN_WEP104))
4392 return -EINVAL;
4393 if (key.idx > 4)
4394 return -EINVAL;
4395 } else {
4396 key.p.key_len = 0;
4397 key.p.key = NULL;
4398 }
4399
afea0b7a
JB
4400 if (key.idx >= 0) {
4401 int i;
4402 bool ok = false;
4403 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4404 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4405 ok = true;
4406 break;
4407 }
4408 }
4c476991
JB
4409 if (!ok)
4410 return -EINVAL;
afea0b7a
JB
4411 }
4412
4c476991
JB
4413 if (!rdev->ops->auth)
4414 return -EOPNOTSUPP;
636a5d36 4415
074ac8df 4416 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4417 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4418 return -EOPNOTSUPP;
eec60b03 4419
19957bb3 4420 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4421 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4422 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4423 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4424 return -EINVAL;
636a5d36 4425
19957bb3
JB
4426 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4427 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4428
4429 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4430 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4431 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4432 }
4433
19957bb3 4434 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4435 if (!nl80211_valid_auth_type(auth_type))
4436 return -EINVAL;
636a5d36 4437
d5cdfacb
JM
4438 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4439
95de817b
JB
4440 /*
4441 * Since we no longer track auth state, ignore
4442 * requests to only change local state.
4443 */
4444 if (local_state_change)
4445 return 0;
4446
4c476991
JB
4447 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4448 ssid, ssid_len, ie, ie_len,
95de817b 4449 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
4450}
4451
c0692b8f
JB
4452static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4453 struct genl_info *info,
3dc27d25
JB
4454 struct cfg80211_crypto_settings *settings,
4455 int cipher_limit)
b23aa676 4456{
c0b2bbd8
JB
4457 memset(settings, 0, sizeof(*settings));
4458
b23aa676
SO
4459 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4460
c0692b8f
JB
4461 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4462 u16 proto;
4463 proto = nla_get_u16(
4464 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4465 settings->control_port_ethertype = cpu_to_be16(proto);
4466 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4467 proto != ETH_P_PAE)
4468 return -EINVAL;
4469 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4470 settings->control_port_no_encrypt = true;
4471 } else
4472 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4473
b23aa676
SO
4474 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4475 void *data;
4476 int len, i;
4477
4478 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4479 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4480 settings->n_ciphers_pairwise = len / sizeof(u32);
4481
4482 if (len % sizeof(u32))
4483 return -EINVAL;
4484
3dc27d25 4485 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4486 return -EINVAL;
4487
4488 memcpy(settings->ciphers_pairwise, data, len);
4489
4490 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4491 if (!cfg80211_supported_cipher_suite(
4492 &rdev->wiphy,
b23aa676
SO
4493 settings->ciphers_pairwise[i]))
4494 return -EINVAL;
4495 }
4496
4497 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4498 settings->cipher_group =
4499 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4500 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4501 settings->cipher_group))
b23aa676
SO
4502 return -EINVAL;
4503 }
4504
4505 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4506 settings->wpa_versions =
4507 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4508 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4509 return -EINVAL;
4510 }
4511
4512 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4513 void *data;
6d30240e 4514 int len;
b23aa676
SO
4515
4516 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4517 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4518 settings->n_akm_suites = len / sizeof(u32);
4519
4520 if (len % sizeof(u32))
4521 return -EINVAL;
4522
1b9ca027
JM
4523 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4524 return -EINVAL;
4525
b23aa676 4526 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4527 }
4528
4529 return 0;
4530}
4531
636a5d36
JM
4532static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4533{
4c476991
JB
4534 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4535 struct net_device *dev = info->user_ptr[1];
19957bb3 4536 struct cfg80211_crypto_settings crypto;
f444de05 4537 struct ieee80211_channel *chan;
3e5d7649 4538 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4539 int err, ssid_len, ie_len = 0;
4540 bool use_mfp = false;
7e7c8926
BG
4541 u32 flags = 0;
4542 struct ieee80211_ht_cap *ht_capa = NULL;
4543 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 4544
f4a11bb0
JB
4545 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4546 return -EINVAL;
4547
4548 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4549 !info->attrs[NL80211_ATTR_SSID] ||
4550 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4551 return -EINVAL;
4552
4c476991
JB
4553 if (!rdev->ops->assoc)
4554 return -EOPNOTSUPP;
636a5d36 4555
074ac8df 4556 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4557 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4558 return -EOPNOTSUPP;
eec60b03 4559
19957bb3 4560 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4561
19957bb3
JB
4562 chan = ieee80211_get_channel(&rdev->wiphy,
4563 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4564 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4565 return -EINVAL;
636a5d36 4566
19957bb3
JB
4567 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4568 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4569
4570 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4571 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4572 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4573 }
4574
dc6382ce 4575 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 4576 enum nl80211_mfp mfp =
dc6382ce 4577 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 4578 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 4579 use_mfp = true;
4c476991
JB
4580 else if (mfp != NL80211_MFP_NO)
4581 return -EINVAL;
dc6382ce
JM
4582 }
4583
3e5d7649
JB
4584 if (info->attrs[NL80211_ATTR_PREV_BSSID])
4585 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
4586
7e7c8926
BG
4587 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
4588 flags |= ASSOC_REQ_DISABLE_HT;
4589
4590 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
4591 ht_capa_mask =
4592 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
4593
4594 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
4595 if (!ht_capa_mask)
4596 return -EINVAL;
4597 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4598 }
4599
c0692b8f 4600 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 4601 if (!err)
3e5d7649
JB
4602 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
4603 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
4604 &crypto, flags, ht_capa,
4605 ht_capa_mask);
636a5d36 4606
636a5d36
JM
4607 return err;
4608}
4609
4610static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
4611{
4c476991
JB
4612 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4613 struct net_device *dev = info->user_ptr[1];
19957bb3 4614 const u8 *ie = NULL, *bssid;
4c476991 4615 int ie_len = 0;
19957bb3 4616 u16 reason_code;
d5cdfacb 4617 bool local_state_change;
636a5d36 4618
f4a11bb0
JB
4619 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4620 return -EINVAL;
4621
4622 if (!info->attrs[NL80211_ATTR_MAC])
4623 return -EINVAL;
4624
4625 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4626 return -EINVAL;
4627
4c476991
JB
4628 if (!rdev->ops->deauth)
4629 return -EOPNOTSUPP;
636a5d36 4630
074ac8df 4631 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4632 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4633 return -EOPNOTSUPP;
eec60b03 4634
19957bb3 4635 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4636
19957bb3
JB
4637 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4638 if (reason_code == 0) {
f4a11bb0 4639 /* Reason Code 0 is reserved */
4c476991 4640 return -EINVAL;
255e737e 4641 }
636a5d36
JM
4642
4643 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4644 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4645 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4646 }
4647
d5cdfacb
JM
4648 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4649
4c476991
JB
4650 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
4651 local_state_change);
636a5d36
JM
4652}
4653
4654static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
4655{
4c476991
JB
4656 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4657 struct net_device *dev = info->user_ptr[1];
19957bb3 4658 const u8 *ie = NULL, *bssid;
4c476991 4659 int ie_len = 0;
19957bb3 4660 u16 reason_code;
d5cdfacb 4661 bool local_state_change;
636a5d36 4662
f4a11bb0
JB
4663 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4664 return -EINVAL;
4665
4666 if (!info->attrs[NL80211_ATTR_MAC])
4667 return -EINVAL;
4668
4669 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4670 return -EINVAL;
4671
4c476991
JB
4672 if (!rdev->ops->disassoc)
4673 return -EOPNOTSUPP;
636a5d36 4674
074ac8df 4675 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4676 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4677 return -EOPNOTSUPP;
eec60b03 4678
19957bb3 4679 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4680
19957bb3
JB
4681 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4682 if (reason_code == 0) {
f4a11bb0 4683 /* Reason Code 0 is reserved */
4c476991 4684 return -EINVAL;
255e737e 4685 }
636a5d36
JM
4686
4687 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4688 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4689 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4690 }
4691
d5cdfacb
JM
4692 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4693
4c476991
JB
4694 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
4695 local_state_change);
636a5d36
JM
4696}
4697
dd5b4cc7
FF
4698static bool
4699nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
4700 int mcast_rate[IEEE80211_NUM_BANDS],
4701 int rateval)
4702{
4703 struct wiphy *wiphy = &rdev->wiphy;
4704 bool found = false;
4705 int band, i;
4706
4707 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4708 struct ieee80211_supported_band *sband;
4709
4710 sband = wiphy->bands[band];
4711 if (!sband)
4712 continue;
4713
4714 for (i = 0; i < sband->n_bitrates; i++) {
4715 if (sband->bitrates[i].bitrate == rateval) {
4716 mcast_rate[band] = i + 1;
4717 found = true;
4718 break;
4719 }
4720 }
4721 }
4722
4723 return found;
4724}
4725
04a773ad
JB
4726static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
4727{
4c476991
JB
4728 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4729 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
4730 struct cfg80211_ibss_params ibss;
4731 struct wiphy *wiphy;
fffd0934 4732 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
4733 int err;
4734
8e30bc55
JB
4735 memset(&ibss, 0, sizeof(ibss));
4736
04a773ad
JB
4737 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4738 return -EINVAL;
4739
4740 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4741 !info->attrs[NL80211_ATTR_SSID] ||
4742 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4743 return -EINVAL;
4744
8e30bc55
JB
4745 ibss.beacon_interval = 100;
4746
4747 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
4748 ibss.beacon_interval =
4749 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4750 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
4751 return -EINVAL;
4752 }
4753
4c476991
JB
4754 if (!rdev->ops->join_ibss)
4755 return -EOPNOTSUPP;
04a773ad 4756
4c476991
JB
4757 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4758 return -EOPNOTSUPP;
04a773ad 4759
79c97e97 4760 wiphy = &rdev->wiphy;
04a773ad 4761
39193498 4762 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 4763 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
4764
4765 if (!is_valid_ether_addr(ibss.bssid))
4766 return -EINVAL;
4767 }
04a773ad
JB
4768 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4769 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4770
4771 if (info->attrs[NL80211_ATTR_IE]) {
4772 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4773 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4774 }
4775
54858ee5
AS
4776 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4777 enum nl80211_channel_type channel_type;
4778
4779 channel_type = nla_get_u32(
4780 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4781 if (channel_type != NL80211_CHAN_NO_HT &&
4782 channel_type != NL80211_CHAN_HT20 &&
4783 channel_type != NL80211_CHAN_HT40MINUS &&
4784 channel_type != NL80211_CHAN_HT40PLUS)
4785 return -EINVAL;
4786
4787 if (channel_type != NL80211_CHAN_NO_HT &&
4788 !(wiphy->features & NL80211_FEATURE_HT_IBSS))
4789 return -EINVAL;
4790
4791 ibss.channel_type = channel_type;
4792 } else {
4793 ibss.channel_type = NL80211_CHAN_NO_HT;
4794 }
4795
4796 ibss.channel = rdev_freq_to_chan(rdev,
4797 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
4798 ibss.channel_type);
04a773ad
JB
4799 if (!ibss.channel ||
4800 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
4801 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
4802 return -EINVAL;
04a773ad 4803
54858ee5
AS
4804 /* Both channels should be able to initiate communication */
4805 if ((ibss.channel_type == NL80211_CHAN_HT40PLUS ||
4806 ibss.channel_type == NL80211_CHAN_HT40MINUS) &&
4807 !cfg80211_can_beacon_sec_chan(&rdev->wiphy, ibss.channel,
4808 ibss.channel_type))
4809 return -EINVAL;
4810
04a773ad 4811 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
4812 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4813
fbd2c8dc
TP
4814 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
4815 u8 *rates =
4816 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4817 int n_rates =
4818 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
4819 struct ieee80211_supported_band *sband =
4820 wiphy->bands[ibss.channel->band];
fbd2c8dc 4821
34850ab2
JB
4822 err = ieee80211_get_ratemask(sband, rates, n_rates,
4823 &ibss.basic_rates);
4824 if (err)
4825 return err;
fbd2c8dc 4826 }
dd5b4cc7
FF
4827
4828 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
4829 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
4830 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
4831 return -EINVAL;
fbd2c8dc 4832
4c476991
JB
4833 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4834 connkeys = nl80211_parse_connkeys(rdev,
4835 info->attrs[NL80211_ATTR_KEYS]);
4836 if (IS_ERR(connkeys))
4837 return PTR_ERR(connkeys);
4838 }
04a773ad 4839
267335d6
AQ
4840 ibss.control_port =
4841 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
4842
4c476991 4843 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
4844 if (err)
4845 kfree(connkeys);
04a773ad
JB
4846 return err;
4847}
4848
4849static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4850{
4c476991
JB
4851 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4852 struct net_device *dev = info->user_ptr[1];
04a773ad 4853
4c476991
JB
4854 if (!rdev->ops->leave_ibss)
4855 return -EOPNOTSUPP;
04a773ad 4856
4c476991
JB
4857 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
4858 return -EOPNOTSUPP;
04a773ad 4859
4c476991 4860 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4861}
4862
aff89a9b
JB
4863#ifdef CONFIG_NL80211_TESTMODE
4864static struct genl_multicast_group nl80211_testmode_mcgrp = {
4865 .name = "testmode",
4866};
4867
4868static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4869{
4c476991 4870 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
4871 int err;
4872
4873 if (!info->attrs[NL80211_ATTR_TESTDATA])
4874 return -EINVAL;
4875
aff89a9b
JB
4876 err = -EOPNOTSUPP;
4877 if (rdev->ops->testmode_cmd) {
4878 rdev->testmode_info = info;
4879 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4880 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4881 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4882 rdev->testmode_info = NULL;
4883 }
4884
aff89a9b
JB
4885 return err;
4886}
4887
71063f0e
WYG
4888static int nl80211_testmode_dump(struct sk_buff *skb,
4889 struct netlink_callback *cb)
4890{
00918d33 4891 struct cfg80211_registered_device *rdev;
71063f0e
WYG
4892 int err;
4893 long phy_idx;
4894 void *data = NULL;
4895 int data_len = 0;
4896
4897 if (cb->args[0]) {
4898 /*
4899 * 0 is a valid index, but not valid for args[0],
4900 * so we need to offset by 1.
4901 */
4902 phy_idx = cb->args[0] - 1;
4903 } else {
4904 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
4905 nl80211_fam.attrbuf, nl80211_fam.maxattr,
4906 nl80211_policy);
4907 if (err)
4908 return err;
00918d33
JB
4909 if (nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]) {
4910 phy_idx = nla_get_u32(
4911 nl80211_fam.attrbuf[NL80211_ATTR_WIPHY]);
4912 } else {
4913 struct net_device *netdev;
4914
4915 err = get_rdev_dev_by_ifindex(sock_net(skb->sk),
4916 nl80211_fam.attrbuf,
4917 &rdev, &netdev);
4918 if (err)
4919 return err;
4920 dev_put(netdev);
4921 phy_idx = rdev->wiphy_idx;
4922 cfg80211_unlock_rdev(rdev);
4923 }
71063f0e
WYG
4924 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
4925 cb->args[1] =
4926 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
4927 }
4928
4929 if (cb->args[1]) {
4930 data = nla_data((void *)cb->args[1]);
4931 data_len = nla_len((void *)cb->args[1]);
4932 }
4933
4934 mutex_lock(&cfg80211_mutex);
00918d33
JB
4935 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
4936 if (!rdev) {
71063f0e
WYG
4937 mutex_unlock(&cfg80211_mutex);
4938 return -ENOENT;
4939 }
00918d33 4940 cfg80211_lock_rdev(rdev);
71063f0e
WYG
4941 mutex_unlock(&cfg80211_mutex);
4942
00918d33 4943 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
4944 err = -EOPNOTSUPP;
4945 goto out_err;
4946 }
4947
4948 while (1) {
4949 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
4950 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4951 NL80211_CMD_TESTMODE);
4952 struct nlattr *tmdata;
4953
00918d33 4954 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx) < 0) {
71063f0e
WYG
4955 genlmsg_cancel(skb, hdr);
4956 break;
4957 }
4958
4959 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4960 if (!tmdata) {
4961 genlmsg_cancel(skb, hdr);
4962 break;
4963 }
00918d33
JB
4964 err = rdev->ops->testmode_dump(&rdev->wiphy, skb, cb,
4965 data, data_len);
71063f0e
WYG
4966 nla_nest_end(skb, tmdata);
4967
4968 if (err == -ENOBUFS || err == -ENOENT) {
4969 genlmsg_cancel(skb, hdr);
4970 break;
4971 } else if (err) {
4972 genlmsg_cancel(skb, hdr);
4973 goto out_err;
4974 }
4975
4976 genlmsg_end(skb, hdr);
4977 }
4978
4979 err = skb->len;
4980 /* see above */
4981 cb->args[0] = phy_idx + 1;
4982 out_err:
00918d33 4983 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
4984 return err;
4985}
4986
aff89a9b
JB
4987static struct sk_buff *
4988__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4989 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4990{
4991 struct sk_buff *skb;
4992 void *hdr;
4993 struct nlattr *data;
4994
4995 skb = nlmsg_new(approxlen + 100, gfp);
4996 if (!skb)
4997 return NULL;
4998
4999 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
5000 if (!hdr) {
5001 kfree_skb(skb);
5002 return NULL;
5003 }
5004
5005 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5006 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5007
5008 ((void **)skb->cb)[0] = rdev;
5009 ((void **)skb->cb)[1] = hdr;
5010 ((void **)skb->cb)[2] = data;
5011
5012 return skb;
5013
5014 nla_put_failure:
5015 kfree_skb(skb);
5016 return NULL;
5017}
5018
5019struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5020 int approxlen)
5021{
5022 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5023
5024 if (WARN_ON(!rdev->testmode_info))
5025 return NULL;
5026
5027 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
5028 rdev->testmode_info->snd_pid,
5029 rdev->testmode_info->snd_seq,
5030 GFP_KERNEL);
5031}
5032EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5033
5034int cfg80211_testmode_reply(struct sk_buff *skb)
5035{
5036 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5037 void *hdr = ((void **)skb->cb)[1];
5038 struct nlattr *data = ((void **)skb->cb)[2];
5039
5040 if (WARN_ON(!rdev->testmode_info)) {
5041 kfree_skb(skb);
5042 return -EINVAL;
5043 }
5044
5045 nla_nest_end(skb, data);
5046 genlmsg_end(skb, hdr);
5047 return genlmsg_reply(skb, rdev->testmode_info);
5048}
5049EXPORT_SYMBOL(cfg80211_testmode_reply);
5050
5051struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5052 int approxlen, gfp_t gfp)
5053{
5054 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5055
5056 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5057}
5058EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5059
5060void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5061{
5062 void *hdr = ((void **)skb->cb)[1];
5063 struct nlattr *data = ((void **)skb->cb)[2];
5064
5065 nla_nest_end(skb, data);
5066 genlmsg_end(skb, hdr);
5067 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5068}
5069EXPORT_SYMBOL(cfg80211_testmode_event);
5070#endif
5071
b23aa676
SO
5072static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5073{
4c476991
JB
5074 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5075 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5076 struct cfg80211_connect_params connect;
5077 struct wiphy *wiphy;
fffd0934 5078 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5079 int err;
5080
5081 memset(&connect, 0, sizeof(connect));
5082
5083 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5084 return -EINVAL;
5085
5086 if (!info->attrs[NL80211_ATTR_SSID] ||
5087 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5088 return -EINVAL;
5089
5090 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5091 connect.auth_type =
5092 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
5093 if (!nl80211_valid_auth_type(connect.auth_type))
5094 return -EINVAL;
5095 } else
5096 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5097
5098 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5099
c0692b8f 5100 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5101 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5102 if (err)
5103 return err;
b23aa676 5104
074ac8df 5105 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5106 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5107 return -EOPNOTSUPP;
b23aa676 5108
79c97e97 5109 wiphy = &rdev->wiphy;
b23aa676 5110
b23aa676
SO
5111 if (info->attrs[NL80211_ATTR_MAC])
5112 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5113 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5114 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5115
5116 if (info->attrs[NL80211_ATTR_IE]) {
5117 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5118 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5119 }
5120
5121 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5122 connect.channel =
5123 ieee80211_get_channel(wiphy,
5124 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5125 if (!connect.channel ||
4c476991
JB
5126 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5127 return -EINVAL;
b23aa676
SO
5128 }
5129
fffd0934
JB
5130 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5131 connkeys = nl80211_parse_connkeys(rdev,
5132 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
5133 if (IS_ERR(connkeys))
5134 return PTR_ERR(connkeys);
fffd0934
JB
5135 }
5136
7e7c8926
BG
5137 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5138 connect.flags |= ASSOC_REQ_DISABLE_HT;
5139
5140 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5141 memcpy(&connect.ht_capa_mask,
5142 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5143 sizeof(connect.ht_capa_mask));
5144
5145 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5146 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5147 return -EINVAL;
5148 memcpy(&connect.ht_capa,
5149 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5150 sizeof(connect.ht_capa));
5151 }
5152
fffd0934 5153 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5154 if (err)
5155 kfree(connkeys);
b23aa676
SO
5156 return err;
5157}
5158
5159static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5160{
4c476991
JB
5161 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5162 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5163 u16 reason;
5164
5165 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5166 reason = WLAN_REASON_DEAUTH_LEAVING;
5167 else
5168 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5169
5170 if (reason == 0)
5171 return -EINVAL;
5172
074ac8df 5173 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5174 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5175 return -EOPNOTSUPP;
b23aa676 5176
4c476991 5177 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
5178}
5179
463d0183
JB
5180static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5181{
4c476991 5182 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
5183 struct net *net;
5184 int err;
5185 u32 pid;
5186
5187 if (!info->attrs[NL80211_ATTR_PID])
5188 return -EINVAL;
5189
5190 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5191
463d0183 5192 net = get_net_ns_by_pid(pid);
4c476991
JB
5193 if (IS_ERR(net))
5194 return PTR_ERR(net);
463d0183
JB
5195
5196 err = 0;
5197
5198 /* check if anything to do */
4c476991
JB
5199 if (!net_eq(wiphy_net(&rdev->wiphy), net))
5200 err = cfg80211_switch_netns(rdev, net);
463d0183 5201
463d0183 5202 put_net(net);
463d0183
JB
5203 return err;
5204}
5205
67fbb16b
SO
5206static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5207{
4c476991 5208 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
5209 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5210 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 5211 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
5212 struct cfg80211_pmksa pmksa;
5213
5214 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5215
5216 if (!info->attrs[NL80211_ATTR_MAC])
5217 return -EINVAL;
5218
5219 if (!info->attrs[NL80211_ATTR_PMKID])
5220 return -EINVAL;
5221
67fbb16b
SO
5222 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5223 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5224
074ac8df 5225 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5226 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5227 return -EOPNOTSUPP;
67fbb16b
SO
5228
5229 switch (info->genlhdr->cmd) {
5230 case NL80211_CMD_SET_PMKSA:
5231 rdev_ops = rdev->ops->set_pmksa;
5232 break;
5233 case NL80211_CMD_DEL_PMKSA:
5234 rdev_ops = rdev->ops->del_pmksa;
5235 break;
5236 default:
5237 WARN_ON(1);
5238 break;
5239 }
5240
4c476991
JB
5241 if (!rdev_ops)
5242 return -EOPNOTSUPP;
67fbb16b 5243
4c476991 5244 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
5245}
5246
5247static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5248{
4c476991
JB
5249 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5250 struct net_device *dev = info->user_ptr[1];
67fbb16b 5251
074ac8df 5252 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5253 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5254 return -EOPNOTSUPP;
67fbb16b 5255
4c476991
JB
5256 if (!rdev->ops->flush_pmksa)
5257 return -EOPNOTSUPP;
67fbb16b 5258
4c476991 5259 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5260}
5261
109086ce
AN
5262static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5263{
5264 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5265 struct net_device *dev = info->user_ptr[1];
5266 u8 action_code, dialog_token;
5267 u16 status_code;
5268 u8 *peer;
5269
5270 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5271 !rdev->ops->tdls_mgmt)
5272 return -EOPNOTSUPP;
5273
5274 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5275 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5276 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5277 !info->attrs[NL80211_ATTR_IE] ||
5278 !info->attrs[NL80211_ATTR_MAC])
5279 return -EINVAL;
5280
5281 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5282 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5283 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5284 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5285
5286 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5287 dialog_token, status_code,
5288 nla_data(info->attrs[NL80211_ATTR_IE]),
5289 nla_len(info->attrs[NL80211_ATTR_IE]));
5290}
5291
5292static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5293{
5294 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5295 struct net_device *dev = info->user_ptr[1];
5296 enum nl80211_tdls_operation operation;
5297 u8 *peer;
5298
5299 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5300 !rdev->ops->tdls_oper)
5301 return -EOPNOTSUPP;
5302
5303 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5304 !info->attrs[NL80211_ATTR_MAC])
5305 return -EINVAL;
5306
5307 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5308 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5309
5310 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5311}
5312
9588bbd5
JM
5313static int nl80211_remain_on_channel(struct sk_buff *skb,
5314 struct genl_info *info)
5315{
4c476991
JB
5316 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5317 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5318 struct ieee80211_channel *chan;
5319 struct sk_buff *msg;
5320 void *hdr;
5321 u64 cookie;
5322 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5323 u32 freq, duration;
5324 int err;
5325
5326 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5327 !info->attrs[NL80211_ATTR_DURATION])
5328 return -EINVAL;
5329
5330 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5331
5332 /*
5333 * We should be on that channel for at least one jiffie,
5334 * and more than 5 seconds seems excessive.
5335 */
a293911d
JB
5336 if (!duration || !msecs_to_jiffies(duration) ||
5337 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5338 return -EINVAL;
5339
7c4ef712
JB
5340 if (!rdev->ops->remain_on_channel ||
5341 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
4c476991 5342 return -EOPNOTSUPP;
9588bbd5 5343
9588bbd5
JM
5344 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5345 channel_type = nla_get_u32(
5346 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5347 if (channel_type != NL80211_CHAN_NO_HT &&
5348 channel_type != NL80211_CHAN_HT20 &&
5349 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5350 channel_type != NL80211_CHAN_HT40MINUS)
5351 return -EINVAL;
9588bbd5
JM
5352 }
5353
5354 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5355 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5356 if (chan == NULL)
5357 return -EINVAL;
9588bbd5
JM
5358
5359 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5360 if (!msg)
5361 return -ENOMEM;
9588bbd5
JM
5362
5363 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5364 NL80211_CMD_REMAIN_ON_CHANNEL);
5365
5366 if (IS_ERR(hdr)) {
5367 err = PTR_ERR(hdr);
5368 goto free_msg;
5369 }
5370
5371 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5372 channel_type, duration, &cookie);
5373
5374 if (err)
5375 goto free_msg;
5376
5377 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5378
5379 genlmsg_end(msg, hdr);
4c476991
JB
5380
5381 return genlmsg_reply(msg, info);
9588bbd5
JM
5382
5383 nla_put_failure:
5384 err = -ENOBUFS;
5385 free_msg:
5386 nlmsg_free(msg);
9588bbd5
JM
5387 return err;
5388}
5389
5390static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5391 struct genl_info *info)
5392{
4c476991
JB
5393 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5394 struct net_device *dev = info->user_ptr[1];
9588bbd5 5395 u64 cookie;
9588bbd5
JM
5396
5397 if (!info->attrs[NL80211_ATTR_COOKIE])
5398 return -EINVAL;
5399
4c476991
JB
5400 if (!rdev->ops->cancel_remain_on_channel)
5401 return -EOPNOTSUPP;
9588bbd5 5402
9588bbd5
JM
5403 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5404
4c476991 5405 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5406}
5407
13ae75b1
JM
5408static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5409 u8 *rates, u8 rates_len)
5410{
5411 u8 i;
5412 u32 mask = 0;
5413
5414 for (i = 0; i < rates_len; i++) {
5415 int rate = (rates[i] & 0x7f) * 5;
5416 int ridx;
5417 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5418 struct ieee80211_rate *srate =
5419 &sband->bitrates[ridx];
5420 if (rate == srate->bitrate) {
5421 mask |= 1 << ridx;
5422 break;
5423 }
5424 }
5425 if (ridx == sband->n_bitrates)
5426 return 0; /* rate not found */
5427 }
5428
5429 return mask;
5430}
5431
24db78c0
SW
5432static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
5433 u8 *rates, u8 rates_len,
5434 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
5435{
5436 u8 i;
5437
5438 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
5439
5440 for (i = 0; i < rates_len; i++) {
5441 int ridx, rbit;
5442
5443 ridx = rates[i] / 8;
5444 rbit = BIT(rates[i] % 8);
5445
5446 /* check validity */
910570b5 5447 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
5448 return false;
5449
5450 /* check availability */
5451 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5452 mcs[ridx] |= rbit;
5453 else
5454 return false;
5455 }
5456
5457 return true;
5458}
5459
b54452b0 5460static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5461 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5462 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
5463 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
5464 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
5465};
5466
5467static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5468 struct genl_info *info)
5469{
5470 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5471 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5472 struct cfg80211_bitrate_mask mask;
4c476991
JB
5473 int rem, i;
5474 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5475 struct nlattr *tx_rates;
5476 struct ieee80211_supported_band *sband;
5477
5478 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5479 return -EINVAL;
5480
4c476991
JB
5481 if (!rdev->ops->set_bitrate_mask)
5482 return -EOPNOTSUPP;
13ae75b1
JM
5483
5484 memset(&mask, 0, sizeof(mask));
5485 /* Default to all rates enabled */
5486 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5487 sband = rdev->wiphy.bands[i];
5488 mask.control[i].legacy =
5489 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
5490 if (sband)
5491 memcpy(mask.control[i].mcs,
5492 sband->ht_cap.mcs.rx_mask,
5493 sizeof(mask.control[i].mcs));
5494 else
5495 memset(mask.control[i].mcs, 0,
5496 sizeof(mask.control[i].mcs));
13ae75b1
JM
5497 }
5498
5499 /*
5500 * The nested attribute uses enum nl80211_band as the index. This maps
5501 * directly to the enum ieee80211_band values used in cfg80211.
5502 */
24db78c0 5503 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
5504 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5505 {
5506 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5507 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5508 return -EINVAL;
13ae75b1 5509 sband = rdev->wiphy.bands[band];
4c476991
JB
5510 if (sband == NULL)
5511 return -EINVAL;
13ae75b1
JM
5512 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5513 nla_len(tx_rates), nl80211_txattr_policy);
5514 if (tb[NL80211_TXRATE_LEGACY]) {
5515 mask.control[band].legacy = rateset_to_mask(
5516 sband,
5517 nla_data(tb[NL80211_TXRATE_LEGACY]),
5518 nla_len(tb[NL80211_TXRATE_LEGACY]));
24db78c0
SW
5519 }
5520 if (tb[NL80211_TXRATE_MCS]) {
5521 if (!ht_rateset_to_mask(
5522 sband,
5523 nla_data(tb[NL80211_TXRATE_MCS]),
5524 nla_len(tb[NL80211_TXRATE_MCS]),
5525 mask.control[band].mcs))
5526 return -EINVAL;
5527 }
5528
5529 if (mask.control[band].legacy == 0) {
5530 /* don't allow empty legacy rates if HT
5531 * is not even supported. */
5532 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
5533 return -EINVAL;
5534
5535 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5536 if (mask.control[band].mcs[i])
5537 break;
5538
5539 /* legacy and mcs rates may not be both empty */
5540 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 5541 return -EINVAL;
13ae75b1
JM
5542 }
5543 }
5544
4c476991 5545 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5546}
5547
2e161f78 5548static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5549{
4c476991
JB
5550 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5551 struct net_device *dev = info->user_ptr[1];
2e161f78 5552 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5553
5554 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5555 return -EINVAL;
5556
2e161f78
JB
5557 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5558 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5559
9d38d85d 5560 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5561 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5562 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5563 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5564 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5565 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5566 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5567 return -EOPNOTSUPP;
026331c4
JM
5568
5569 /* not much point in registering if we can't reply */
4c476991
JB
5570 if (!rdev->ops->mgmt_tx)
5571 return -EOPNOTSUPP;
026331c4 5572
4c476991 5573 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 5574 frame_type,
026331c4
JM
5575 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
5576 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
5577}
5578
2e161f78 5579static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5580{
4c476991
JB
5581 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5582 struct net_device *dev = info->user_ptr[1];
026331c4
JM
5583 struct ieee80211_channel *chan;
5584 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 5585 bool channel_type_valid = false;
026331c4
JM
5586 u32 freq;
5587 int err;
d64d373f 5588 void *hdr = NULL;
026331c4 5589 u64 cookie;
e247bd90 5590 struct sk_buff *msg = NULL;
f7ca38df 5591 unsigned int wait = 0;
e247bd90
JB
5592 bool offchan, no_cck, dont_wait_for_ack;
5593
5594 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4
JM
5595
5596 if (!info->attrs[NL80211_ATTR_FRAME] ||
5597 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
5598 return -EINVAL;
5599
4c476991
JB
5600 if (!rdev->ops->mgmt_tx)
5601 return -EOPNOTSUPP;
026331c4 5602
9d38d85d 5603 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5604 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5605 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5606 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5607 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 5608 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5609 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5610 return -EOPNOTSUPP;
026331c4 5611
f7ca38df 5612 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 5613 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
5614 return -EINVAL;
5615 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5616 }
5617
026331c4
JM
5618 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5619 channel_type = nla_get_u32(
5620 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
5621 if (channel_type != NL80211_CHAN_NO_HT &&
5622 channel_type != NL80211_CHAN_HT20 &&
5623 channel_type != NL80211_CHAN_HT40PLUS &&
4c476991
JB
5624 channel_type != NL80211_CHAN_HT40MINUS)
5625 return -EINVAL;
252aa631 5626 channel_type_valid = true;
026331c4
JM
5627 }
5628
f7ca38df
JB
5629 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
5630
7c4ef712
JB
5631 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
5632 return -EINVAL;
5633
e9f935e3
RM
5634 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
5635
026331c4
JM
5636 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5637 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5638 if (chan == NULL)
5639 return -EINVAL;
026331c4 5640
e247bd90
JB
5641 if (!dont_wait_for_ack) {
5642 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5643 if (!msg)
5644 return -ENOMEM;
026331c4 5645
e247bd90
JB
5646 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5647 NL80211_CMD_FRAME);
026331c4 5648
e247bd90
JB
5649 if (IS_ERR(hdr)) {
5650 err = PTR_ERR(hdr);
5651 goto free_msg;
5652 }
026331c4 5653 }
e247bd90 5654
f7ca38df
JB
5655 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
5656 channel_type_valid, wait,
2e161f78
JB
5657 nla_data(info->attrs[NL80211_ATTR_FRAME]),
5658 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 5659 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
5660 if (err)
5661 goto free_msg;
5662
e247bd90
JB
5663 if (msg) {
5664 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
026331c4 5665
e247bd90
JB
5666 genlmsg_end(msg, hdr);
5667 return genlmsg_reply(msg, info);
5668 }
5669
5670 return 0;
026331c4
JM
5671
5672 nla_put_failure:
5673 err = -ENOBUFS;
5674 free_msg:
5675 nlmsg_free(msg);
026331c4
JM
5676 return err;
5677}
5678
f7ca38df
JB
5679static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
5680{
5681 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5682 struct net_device *dev = info->user_ptr[1];
5683 u64 cookie;
5684
5685 if (!info->attrs[NL80211_ATTR_COOKIE])
5686 return -EINVAL;
5687
5688 if (!rdev->ops->mgmt_tx_cancel_wait)
5689 return -EOPNOTSUPP;
5690
5691 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
5692 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
5693 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5694 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5695 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5696 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5697 return -EOPNOTSUPP;
5698
5699 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5700
5701 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
5702}
5703
ffb9eb3d
KV
5704static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
5705{
4c476991 5706 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 5707 struct wireless_dev *wdev;
4c476991 5708 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5709 u8 ps_state;
5710 bool state;
5711 int err;
5712
4c476991
JB
5713 if (!info->attrs[NL80211_ATTR_PS_STATE])
5714 return -EINVAL;
ffb9eb3d
KV
5715
5716 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
5717
4c476991
JB
5718 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
5719 return -EINVAL;
ffb9eb3d
KV
5720
5721 wdev = dev->ieee80211_ptr;
5722
4c476991
JB
5723 if (!rdev->ops->set_power_mgmt)
5724 return -EOPNOTSUPP;
ffb9eb3d
KV
5725
5726 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
5727
5728 if (state == wdev->ps)
4c476991 5729 return 0;
ffb9eb3d 5730
4c476991
JB
5731 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
5732 wdev->ps_timeout);
5733 if (!err)
5734 wdev->ps = state;
ffb9eb3d
KV
5735 return err;
5736}
5737
5738static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
5739{
4c476991 5740 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
5741 enum nl80211_ps_state ps_state;
5742 struct wireless_dev *wdev;
4c476991 5743 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
5744 struct sk_buff *msg;
5745 void *hdr;
5746 int err;
5747
ffb9eb3d
KV
5748 wdev = dev->ieee80211_ptr;
5749
4c476991
JB
5750 if (!rdev->ops->set_power_mgmt)
5751 return -EOPNOTSUPP;
ffb9eb3d
KV
5752
5753 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5754 if (!msg)
5755 return -ENOMEM;
ffb9eb3d
KV
5756
5757 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5758 NL80211_CMD_GET_POWER_SAVE);
5759 if (!hdr) {
4c476991 5760 err = -ENOBUFS;
ffb9eb3d
KV
5761 goto free_msg;
5762 }
5763
5764 if (wdev->ps)
5765 ps_state = NL80211_PS_ENABLED;
5766 else
5767 ps_state = NL80211_PS_DISABLED;
5768
5769 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
5770
5771 genlmsg_end(msg, hdr);
4c476991 5772 return genlmsg_reply(msg, info);
ffb9eb3d 5773
4c476991 5774 nla_put_failure:
ffb9eb3d 5775 err = -ENOBUFS;
4c476991 5776 free_msg:
ffb9eb3d 5777 nlmsg_free(msg);
ffb9eb3d
KV
5778 return err;
5779}
5780
d6dc1a38
JO
5781static struct nla_policy
5782nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
5783 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
5784 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
5785 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
5786};
5787
5788static int nl80211_set_cqm_rssi(struct genl_info *info,
5789 s32 threshold, u32 hysteresis)
5790{
4c476991 5791 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 5792 struct wireless_dev *wdev;
4c476991 5793 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
5794
5795 if (threshold > 0)
5796 return -EINVAL;
5797
d6dc1a38
JO
5798 wdev = dev->ieee80211_ptr;
5799
4c476991
JB
5800 if (!rdev->ops->set_cqm_rssi_config)
5801 return -EOPNOTSUPP;
d6dc1a38 5802
074ac8df 5803 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5804 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
5805 return -EOPNOTSUPP;
d6dc1a38 5806
4c476991
JB
5807 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
5808 threshold, hysteresis);
d6dc1a38
JO
5809}
5810
5811static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
5812{
5813 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
5814 struct nlattr *cqm;
5815 int err;
5816
5817 cqm = info->attrs[NL80211_ATTR_CQM];
5818 if (!cqm) {
5819 err = -EINVAL;
5820 goto out;
5821 }
5822
5823 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5824 nl80211_attr_cqm_policy);
5825 if (err)
5826 goto out;
5827
5828 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5829 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5830 s32 threshold;
5831 u32 hysteresis;
5832 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5833 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5834 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5835 } else
5836 err = -EINVAL;
5837
5838out:
5839 return err;
5840}
5841
29cbe68c
JB
5842static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
5843{
5844 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5845 struct net_device *dev = info->user_ptr[1];
5846 struct mesh_config cfg;
c80d545d 5847 struct mesh_setup setup;
29cbe68c
JB
5848 int err;
5849
5850 /* start with default */
5851 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 5852 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 5853
24bdd9f4 5854 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 5855 /* and parse parameters if given */
24bdd9f4 5856 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
5857 if (err)
5858 return err;
5859 }
5860
5861 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
5862 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
5863 return -EINVAL;
5864
c80d545d
JC
5865 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
5866 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
5867
4bb62344
CYY
5868 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5869 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
5870 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5871 return -EINVAL;
5872
c80d545d
JC
5873 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
5874 /* parse additional setup parameters if given */
5875 err = nl80211_parse_mesh_setup(info, &setup);
5876 if (err)
5877 return err;
5878 }
5879
5880 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
5881}
5882
5883static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
5884{
5885 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5886 struct net_device *dev = info->user_ptr[1];
5887
5888 return cfg80211_leave_mesh(rdev, dev);
5889}
5890
ff1b6e69
JB
5891static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
5892{
5893 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5894 struct sk_buff *msg;
5895 void *hdr;
5896
5897 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5898 return -EOPNOTSUPP;
5899
5900 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5901 if (!msg)
5902 return -ENOMEM;
5903
5904 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5905 NL80211_CMD_GET_WOWLAN);
5906 if (!hdr)
5907 goto nla_put_failure;
5908
5909 if (rdev->wowlan) {
5910 struct nlattr *nl_wowlan;
5911
5912 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
5913 if (!nl_wowlan)
5914 goto nla_put_failure;
5915
5916 if (rdev->wowlan->any)
5917 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_ANY);
5918 if (rdev->wowlan->disconnect)
5919 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_DISCONNECT);
5920 if (rdev->wowlan->magic_pkt)
5921 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT);
77dbbb13
JB
5922 if (rdev->wowlan->gtk_rekey_failure)
5923 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE);
5924 if (rdev->wowlan->eap_identity_req)
5925 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST);
5926 if (rdev->wowlan->four_way_handshake)
5927 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE);
5928 if (rdev->wowlan->rfkill_release)
5929 NLA_PUT_FLAG(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE);
ff1b6e69
JB
5930 if (rdev->wowlan->n_patterns) {
5931 struct nlattr *nl_pats, *nl_pat;
5932 int i, pat_len;
5933
5934 nl_pats = nla_nest_start(msg,
5935 NL80211_WOWLAN_TRIG_PKT_PATTERN);
5936 if (!nl_pats)
5937 goto nla_put_failure;
5938
5939 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
5940 nl_pat = nla_nest_start(msg, i + 1);
5941 if (!nl_pat)
5942 goto nla_put_failure;
5943 pat_len = rdev->wowlan->patterns[i].pattern_len;
5944 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_MASK,
5945 DIV_ROUND_UP(pat_len, 8),
5946 rdev->wowlan->patterns[i].mask);
5947 NLA_PUT(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
5948 pat_len,
5949 rdev->wowlan->patterns[i].pattern);
5950 nla_nest_end(msg, nl_pat);
5951 }
5952 nla_nest_end(msg, nl_pats);
5953 }
5954
5955 nla_nest_end(msg, nl_wowlan);
5956 }
5957
5958 genlmsg_end(msg, hdr);
5959 return genlmsg_reply(msg, info);
5960
5961nla_put_failure:
5962 nlmsg_free(msg);
5963 return -ENOBUFS;
5964}
5965
5966static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
5967{
5968 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5969 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
5970 struct cfg80211_wowlan no_triggers = {};
5971 struct cfg80211_wowlan new_triggers = {};
5972 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
5973 int err, i;
5974
5975 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
5976 return -EOPNOTSUPP;
5977
5978 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
5979 goto no_triggers;
5980
5981 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
5982 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5983 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
5984 nl80211_wowlan_policy);
5985 if (err)
5986 return err;
5987
5988 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
5989 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
5990 return -EINVAL;
5991 new_triggers.any = true;
5992 }
5993
5994 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
5995 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
5996 return -EINVAL;
5997 new_triggers.disconnect = true;
5998 }
5999
6000 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6001 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6002 return -EINVAL;
6003 new_triggers.magic_pkt = true;
6004 }
6005
77dbbb13
JB
6006 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6007 return -EINVAL;
6008
6009 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6010 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6011 return -EINVAL;
6012 new_triggers.gtk_rekey_failure = true;
6013 }
6014
6015 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6016 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6017 return -EINVAL;
6018 new_triggers.eap_identity_req = true;
6019 }
6020
6021 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6022 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6023 return -EINVAL;
6024 new_triggers.four_way_handshake = true;
6025 }
6026
6027 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6028 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6029 return -EINVAL;
6030 new_triggers.rfkill_release = true;
6031 }
6032
ff1b6e69
JB
6033 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6034 struct nlattr *pat;
6035 int n_patterns = 0;
6036 int rem, pat_len, mask_len;
6037 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6038
6039 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6040 rem)
6041 n_patterns++;
6042 if (n_patterns > wowlan->n_patterns)
6043 return -EINVAL;
6044
6045 new_triggers.patterns = kcalloc(n_patterns,
6046 sizeof(new_triggers.patterns[0]),
6047 GFP_KERNEL);
6048 if (!new_triggers.patterns)
6049 return -ENOMEM;
6050
6051 new_triggers.n_patterns = n_patterns;
6052 i = 0;
6053
6054 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6055 rem) {
6056 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6057 nla_data(pat), nla_len(pat), NULL);
6058 err = -EINVAL;
6059 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6060 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6061 goto error;
6062 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6063 mask_len = DIV_ROUND_UP(pat_len, 8);
6064 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6065 mask_len)
6066 goto error;
6067 if (pat_len > wowlan->pattern_max_len ||
6068 pat_len < wowlan->pattern_min_len)
6069 goto error;
6070
6071 new_triggers.patterns[i].mask =
6072 kmalloc(mask_len + pat_len, GFP_KERNEL);
6073 if (!new_triggers.patterns[i].mask) {
6074 err = -ENOMEM;
6075 goto error;
6076 }
6077 new_triggers.patterns[i].pattern =
6078 new_triggers.patterns[i].mask + mask_len;
6079 memcpy(new_triggers.patterns[i].mask,
6080 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6081 mask_len);
6082 new_triggers.patterns[i].pattern_len = pat_len;
6083 memcpy(new_triggers.patterns[i].pattern,
6084 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6085 pat_len);
6086 i++;
6087 }
6088 }
6089
6090 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
6091 struct cfg80211_wowlan *ntrig;
6092 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
6093 GFP_KERNEL);
6094 if (!ntrig) {
6095 err = -ENOMEM;
6096 goto error;
6097 }
6098 cfg80211_rdev_free_wowlan(rdev);
6099 rdev->wowlan = ntrig;
6100 } else {
6101 no_triggers:
6102 cfg80211_rdev_free_wowlan(rdev);
6103 rdev->wowlan = NULL;
6104 }
6105
6106 return 0;
6107 error:
6108 for (i = 0; i < new_triggers.n_patterns; i++)
6109 kfree(new_triggers.patterns[i].mask);
6110 kfree(new_triggers.patterns);
6111 return err;
6112}
6113
e5497d76
JB
6114static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6115{
6116 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6117 struct net_device *dev = info->user_ptr[1];
6118 struct wireless_dev *wdev = dev->ieee80211_ptr;
6119 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6120 struct cfg80211_gtk_rekey_data rekey_data;
6121 int err;
6122
6123 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6124 return -EINVAL;
6125
6126 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6127 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6128 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6129 nl80211_rekey_policy);
6130 if (err)
6131 return err;
6132
6133 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6134 return -ERANGE;
6135 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6136 return -ERANGE;
6137 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6138 return -ERANGE;
6139
6140 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6141 NL80211_KEK_LEN);
6142 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6143 NL80211_KCK_LEN);
6144 memcpy(rekey_data.replay_ctr,
6145 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6146 NL80211_REPLAY_CTR_LEN);
6147
6148 wdev_lock(wdev);
6149 if (!wdev->current_bss) {
6150 err = -ENOTCONN;
6151 goto out;
6152 }
6153
6154 if (!rdev->ops->set_rekey_data) {
6155 err = -EOPNOTSUPP;
6156 goto out;
6157 }
6158
6159 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
6160 out:
6161 wdev_unlock(wdev);
6162 return err;
6163}
6164
28946da7
JB
6165static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6166 struct genl_info *info)
6167{
6168 struct net_device *dev = info->user_ptr[1];
6169 struct wireless_dev *wdev = dev->ieee80211_ptr;
6170
6171 if (wdev->iftype != NL80211_IFTYPE_AP &&
6172 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6173 return -EINVAL;
6174
6175 if (wdev->ap_unexpected_nlpid)
6176 return -EBUSY;
6177
6178 wdev->ap_unexpected_nlpid = info->snd_pid;
6179 return 0;
6180}
6181
7f6cf311
JB
6182static int nl80211_probe_client(struct sk_buff *skb,
6183 struct genl_info *info)
6184{
6185 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6186 struct net_device *dev = info->user_ptr[1];
6187 struct wireless_dev *wdev = dev->ieee80211_ptr;
6188 struct sk_buff *msg;
6189 void *hdr;
6190 const u8 *addr;
6191 u64 cookie;
6192 int err;
6193
6194 if (wdev->iftype != NL80211_IFTYPE_AP &&
6195 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6196 return -EOPNOTSUPP;
6197
6198 if (!info->attrs[NL80211_ATTR_MAC])
6199 return -EINVAL;
6200
6201 if (!rdev->ops->probe_client)
6202 return -EOPNOTSUPP;
6203
6204 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6205 if (!msg)
6206 return -ENOMEM;
6207
6208 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6209 NL80211_CMD_PROBE_CLIENT);
6210
6211 if (IS_ERR(hdr)) {
6212 err = PTR_ERR(hdr);
6213 goto free_msg;
6214 }
6215
6216 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6217
6218 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
6219 if (err)
6220 goto free_msg;
6221
6222 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6223
6224 genlmsg_end(msg, hdr);
6225
6226 return genlmsg_reply(msg, info);
6227
6228 nla_put_failure:
6229 err = -ENOBUFS;
6230 free_msg:
6231 nlmsg_free(msg);
6232 return err;
6233}
6234
5e760230
JB
6235static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
6236{
6237 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6238
6239 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
6240 return -EOPNOTSUPP;
6241
6242 if (rdev->ap_beacons_nlpid)
6243 return -EBUSY;
6244
6245 rdev->ap_beacons_nlpid = info->snd_pid;
6246
6247 return 0;
6248}
6249
4c476991
JB
6250#define NL80211_FLAG_NEED_WIPHY 0x01
6251#define NL80211_FLAG_NEED_NETDEV 0x02
6252#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
6253#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
6254#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
6255 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
6256
6257static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
6258 struct genl_info *info)
6259{
6260 struct cfg80211_registered_device *rdev;
6261 struct net_device *dev;
6262 int err;
6263 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
6264
6265 if (rtnl)
6266 rtnl_lock();
6267
6268 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
6269 rdev = cfg80211_get_dev_from_info(info);
6270 if (IS_ERR(rdev)) {
6271 if (rtnl)
6272 rtnl_unlock();
6273 return PTR_ERR(rdev);
6274 }
6275 info->user_ptr[0] = rdev;
6276 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
00918d33
JB
6277 err = get_rdev_dev_by_ifindex(genl_info_net(info), info->attrs,
6278 &rdev, &dev);
4c476991
JB
6279 if (err) {
6280 if (rtnl)
6281 rtnl_unlock();
6282 return err;
6283 }
41265714
JB
6284 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
6285 !netif_running(dev)) {
d537f5fd
JB
6286 cfg80211_unlock_rdev(rdev);
6287 dev_put(dev);
41265714
JB
6288 if (rtnl)
6289 rtnl_unlock();
6290 return -ENETDOWN;
6291 }
4c476991
JB
6292 info->user_ptr[0] = rdev;
6293 info->user_ptr[1] = dev;
6294 }
6295
6296 return 0;
6297}
6298
6299static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
6300 struct genl_info *info)
6301{
6302 if (info->user_ptr[0])
6303 cfg80211_unlock_rdev(info->user_ptr[0]);
6304 if (info->user_ptr[1])
6305 dev_put(info->user_ptr[1]);
6306 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
6307 rtnl_unlock();
6308}
6309
55682965
JB
6310static struct genl_ops nl80211_ops[] = {
6311 {
6312 .cmd = NL80211_CMD_GET_WIPHY,
6313 .doit = nl80211_get_wiphy,
6314 .dumpit = nl80211_dump_wiphy,
6315 .policy = nl80211_policy,
6316 /* can be retrieved by unprivileged users */
4c476991 6317 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
6318 },
6319 {
6320 .cmd = NL80211_CMD_SET_WIPHY,
6321 .doit = nl80211_set_wiphy,
6322 .policy = nl80211_policy,
6323 .flags = GENL_ADMIN_PERM,
4c476991 6324 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
6325 },
6326 {
6327 .cmd = NL80211_CMD_GET_INTERFACE,
6328 .doit = nl80211_get_interface,
6329 .dumpit = nl80211_dump_interface,
6330 .policy = nl80211_policy,
6331 /* can be retrieved by unprivileged users */
4c476991 6332 .internal_flags = NL80211_FLAG_NEED_NETDEV,
55682965
JB
6333 },
6334 {
6335 .cmd = NL80211_CMD_SET_INTERFACE,
6336 .doit = nl80211_set_interface,
6337 .policy = nl80211_policy,
6338 .flags = GENL_ADMIN_PERM,
4c476991
JB
6339 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6340 NL80211_FLAG_NEED_RTNL,
55682965
JB
6341 },
6342 {
6343 .cmd = NL80211_CMD_NEW_INTERFACE,
6344 .doit = nl80211_new_interface,
6345 .policy = nl80211_policy,
6346 .flags = GENL_ADMIN_PERM,
4c476991
JB
6347 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6348 NL80211_FLAG_NEED_RTNL,
55682965
JB
6349 },
6350 {
6351 .cmd = NL80211_CMD_DEL_INTERFACE,
6352 .doit = nl80211_del_interface,
6353 .policy = nl80211_policy,
41ade00f 6354 .flags = GENL_ADMIN_PERM,
4c476991
JB
6355 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6356 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6357 },
6358 {
6359 .cmd = NL80211_CMD_GET_KEY,
6360 .doit = nl80211_get_key,
6361 .policy = nl80211_policy,
6362 .flags = GENL_ADMIN_PERM,
4c476991
JB
6363 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6364 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6365 },
6366 {
6367 .cmd = NL80211_CMD_SET_KEY,
6368 .doit = nl80211_set_key,
6369 .policy = nl80211_policy,
6370 .flags = GENL_ADMIN_PERM,
41265714 6371 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6372 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6373 },
6374 {
6375 .cmd = NL80211_CMD_NEW_KEY,
6376 .doit = nl80211_new_key,
6377 .policy = nl80211_policy,
6378 .flags = GENL_ADMIN_PERM,
41265714 6379 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6380 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6381 },
6382 {
6383 .cmd = NL80211_CMD_DEL_KEY,
6384 .doit = nl80211_del_key,
6385 .policy = nl80211_policy,
55682965 6386 .flags = GENL_ADMIN_PERM,
41265714 6387 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6388 NL80211_FLAG_NEED_RTNL,
55682965 6389 },
ed1b6cc7
JB
6390 {
6391 .cmd = NL80211_CMD_SET_BEACON,
6392 .policy = nl80211_policy,
6393 .flags = GENL_ADMIN_PERM,
8860020e 6394 .doit = nl80211_set_beacon,
4c476991
JB
6395 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6396 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6397 },
6398 {
8860020e 6399 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
6400 .policy = nl80211_policy,
6401 .flags = GENL_ADMIN_PERM,
8860020e 6402 .doit = nl80211_start_ap,
4c476991
JB
6403 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6404 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6405 },
6406 {
8860020e 6407 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
6408 .policy = nl80211_policy,
6409 .flags = GENL_ADMIN_PERM,
8860020e 6410 .doit = nl80211_stop_ap,
4c476991
JB
6411 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6412 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6413 },
5727ef1b
JB
6414 {
6415 .cmd = NL80211_CMD_GET_STATION,
6416 .doit = nl80211_get_station,
2ec600d6 6417 .dumpit = nl80211_dump_station,
5727ef1b 6418 .policy = nl80211_policy,
4c476991
JB
6419 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6420 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6421 },
6422 {
6423 .cmd = NL80211_CMD_SET_STATION,
6424 .doit = nl80211_set_station,
6425 .policy = nl80211_policy,
6426 .flags = GENL_ADMIN_PERM,
4c476991
JB
6427 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6428 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6429 },
6430 {
6431 .cmd = NL80211_CMD_NEW_STATION,
6432 .doit = nl80211_new_station,
6433 .policy = nl80211_policy,
6434 .flags = GENL_ADMIN_PERM,
41265714 6435 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6436 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6437 },
6438 {
6439 .cmd = NL80211_CMD_DEL_STATION,
6440 .doit = nl80211_del_station,
6441 .policy = nl80211_policy,
2ec600d6 6442 .flags = GENL_ADMIN_PERM,
4c476991
JB
6443 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6444 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6445 },
6446 {
6447 .cmd = NL80211_CMD_GET_MPATH,
6448 .doit = nl80211_get_mpath,
6449 .dumpit = nl80211_dump_mpath,
6450 .policy = nl80211_policy,
6451 .flags = GENL_ADMIN_PERM,
41265714 6452 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6453 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6454 },
6455 {
6456 .cmd = NL80211_CMD_SET_MPATH,
6457 .doit = nl80211_set_mpath,
6458 .policy = nl80211_policy,
6459 .flags = GENL_ADMIN_PERM,
41265714 6460 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6461 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6462 },
6463 {
6464 .cmd = NL80211_CMD_NEW_MPATH,
6465 .doit = nl80211_new_mpath,
6466 .policy = nl80211_policy,
6467 .flags = GENL_ADMIN_PERM,
41265714 6468 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6469 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6470 },
6471 {
6472 .cmd = NL80211_CMD_DEL_MPATH,
6473 .doit = nl80211_del_mpath,
6474 .policy = nl80211_policy,
9f1ba906 6475 .flags = GENL_ADMIN_PERM,
4c476991
JB
6476 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6477 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6478 },
6479 {
6480 .cmd = NL80211_CMD_SET_BSS,
6481 .doit = nl80211_set_bss,
6482 .policy = nl80211_policy,
b2e1b302 6483 .flags = GENL_ADMIN_PERM,
4c476991
JB
6484 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6485 NL80211_FLAG_NEED_RTNL,
b2e1b302 6486 },
f130347c
LR
6487 {
6488 .cmd = NL80211_CMD_GET_REG,
6489 .doit = nl80211_get_reg,
6490 .policy = nl80211_policy,
6491 /* can be retrieved by unprivileged users */
6492 },
b2e1b302
LR
6493 {
6494 .cmd = NL80211_CMD_SET_REG,
6495 .doit = nl80211_set_reg,
6496 .policy = nl80211_policy,
6497 .flags = GENL_ADMIN_PERM,
6498 },
6499 {
6500 .cmd = NL80211_CMD_REQ_SET_REG,
6501 .doit = nl80211_req_set_reg,
6502 .policy = nl80211_policy,
93da9cc1 6503 .flags = GENL_ADMIN_PERM,
6504 },
6505 {
24bdd9f4
JC
6506 .cmd = NL80211_CMD_GET_MESH_CONFIG,
6507 .doit = nl80211_get_mesh_config,
93da9cc1 6508 .policy = nl80211_policy,
6509 /* can be retrieved by unprivileged users */
4c476991
JB
6510 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6511 NL80211_FLAG_NEED_RTNL,
93da9cc1 6512 },
6513 {
24bdd9f4
JC
6514 .cmd = NL80211_CMD_SET_MESH_CONFIG,
6515 .doit = nl80211_update_mesh_config,
93da9cc1 6516 .policy = nl80211_policy,
9aed3cc1 6517 .flags = GENL_ADMIN_PERM,
29cbe68c 6518 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6519 NL80211_FLAG_NEED_RTNL,
9aed3cc1 6520 },
2a519311
JB
6521 {
6522 .cmd = NL80211_CMD_TRIGGER_SCAN,
6523 .doit = nl80211_trigger_scan,
6524 .policy = nl80211_policy,
6525 .flags = GENL_ADMIN_PERM,
41265714 6526 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6527 NL80211_FLAG_NEED_RTNL,
2a519311
JB
6528 },
6529 {
6530 .cmd = NL80211_CMD_GET_SCAN,
6531 .policy = nl80211_policy,
6532 .dumpit = nl80211_dump_scan,
6533 },
807f8a8c
LC
6534 {
6535 .cmd = NL80211_CMD_START_SCHED_SCAN,
6536 .doit = nl80211_start_sched_scan,
6537 .policy = nl80211_policy,
6538 .flags = GENL_ADMIN_PERM,
6539 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6540 NL80211_FLAG_NEED_RTNL,
6541 },
6542 {
6543 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
6544 .doit = nl80211_stop_sched_scan,
6545 .policy = nl80211_policy,
6546 .flags = GENL_ADMIN_PERM,
6547 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6548 NL80211_FLAG_NEED_RTNL,
6549 },
636a5d36
JM
6550 {
6551 .cmd = NL80211_CMD_AUTHENTICATE,
6552 .doit = nl80211_authenticate,
6553 .policy = nl80211_policy,
6554 .flags = GENL_ADMIN_PERM,
41265714 6555 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6556 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6557 },
6558 {
6559 .cmd = NL80211_CMD_ASSOCIATE,
6560 .doit = nl80211_associate,
6561 .policy = nl80211_policy,
6562 .flags = GENL_ADMIN_PERM,
41265714 6563 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6564 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6565 },
6566 {
6567 .cmd = NL80211_CMD_DEAUTHENTICATE,
6568 .doit = nl80211_deauthenticate,
6569 .policy = nl80211_policy,
6570 .flags = GENL_ADMIN_PERM,
41265714 6571 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6572 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
6573 },
6574 {
6575 .cmd = NL80211_CMD_DISASSOCIATE,
6576 .doit = nl80211_disassociate,
6577 .policy = nl80211_policy,
6578 .flags = GENL_ADMIN_PERM,
41265714 6579 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6580 NL80211_FLAG_NEED_RTNL,
636a5d36 6581 },
04a773ad
JB
6582 {
6583 .cmd = NL80211_CMD_JOIN_IBSS,
6584 .doit = nl80211_join_ibss,
6585 .policy = nl80211_policy,
6586 .flags = GENL_ADMIN_PERM,
41265714 6587 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6588 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
6589 },
6590 {
6591 .cmd = NL80211_CMD_LEAVE_IBSS,
6592 .doit = nl80211_leave_ibss,
6593 .policy = nl80211_policy,
6594 .flags = GENL_ADMIN_PERM,
41265714 6595 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6596 NL80211_FLAG_NEED_RTNL,
04a773ad 6597 },
aff89a9b
JB
6598#ifdef CONFIG_NL80211_TESTMODE
6599 {
6600 .cmd = NL80211_CMD_TESTMODE,
6601 .doit = nl80211_testmode_do,
71063f0e 6602 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
6603 .policy = nl80211_policy,
6604 .flags = GENL_ADMIN_PERM,
4c476991
JB
6605 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6606 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
6607 },
6608#endif
b23aa676
SO
6609 {
6610 .cmd = NL80211_CMD_CONNECT,
6611 .doit = nl80211_connect,
6612 .policy = nl80211_policy,
6613 .flags = GENL_ADMIN_PERM,
41265714 6614 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6615 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
6616 },
6617 {
6618 .cmd = NL80211_CMD_DISCONNECT,
6619 .doit = nl80211_disconnect,
6620 .policy = nl80211_policy,
6621 .flags = GENL_ADMIN_PERM,
41265714 6622 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6623 NL80211_FLAG_NEED_RTNL,
b23aa676 6624 },
463d0183
JB
6625 {
6626 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
6627 .doit = nl80211_wiphy_netns,
6628 .policy = nl80211_policy,
6629 .flags = GENL_ADMIN_PERM,
4c476991
JB
6630 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6631 NL80211_FLAG_NEED_RTNL,
463d0183 6632 },
61fa713c
HS
6633 {
6634 .cmd = NL80211_CMD_GET_SURVEY,
6635 .policy = nl80211_policy,
6636 .dumpit = nl80211_dump_survey,
6637 },
67fbb16b
SO
6638 {
6639 .cmd = NL80211_CMD_SET_PMKSA,
6640 .doit = nl80211_setdel_pmksa,
6641 .policy = nl80211_policy,
6642 .flags = GENL_ADMIN_PERM,
4c476991
JB
6643 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6644 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6645 },
6646 {
6647 .cmd = NL80211_CMD_DEL_PMKSA,
6648 .doit = nl80211_setdel_pmksa,
6649 .policy = nl80211_policy,
6650 .flags = GENL_ADMIN_PERM,
4c476991
JB
6651 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6652 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
6653 },
6654 {
6655 .cmd = NL80211_CMD_FLUSH_PMKSA,
6656 .doit = nl80211_flush_pmksa,
6657 .policy = nl80211_policy,
6658 .flags = GENL_ADMIN_PERM,
4c476991
JB
6659 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6660 NL80211_FLAG_NEED_RTNL,
67fbb16b 6661 },
9588bbd5
JM
6662 {
6663 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
6664 .doit = nl80211_remain_on_channel,
6665 .policy = nl80211_policy,
6666 .flags = GENL_ADMIN_PERM,
41265714 6667 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6668 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
6669 },
6670 {
6671 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
6672 .doit = nl80211_cancel_remain_on_channel,
6673 .policy = nl80211_policy,
6674 .flags = GENL_ADMIN_PERM,
41265714 6675 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6676 NL80211_FLAG_NEED_RTNL,
9588bbd5 6677 },
13ae75b1
JM
6678 {
6679 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
6680 .doit = nl80211_set_tx_bitrate_mask,
6681 .policy = nl80211_policy,
6682 .flags = GENL_ADMIN_PERM,
4c476991
JB
6683 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6684 NL80211_FLAG_NEED_RTNL,
13ae75b1 6685 },
026331c4 6686 {
2e161f78
JB
6687 .cmd = NL80211_CMD_REGISTER_FRAME,
6688 .doit = nl80211_register_mgmt,
026331c4
JM
6689 .policy = nl80211_policy,
6690 .flags = GENL_ADMIN_PERM,
4c476991
JB
6691 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6692 NL80211_FLAG_NEED_RTNL,
026331c4
JM
6693 },
6694 {
2e161f78
JB
6695 .cmd = NL80211_CMD_FRAME,
6696 .doit = nl80211_tx_mgmt,
026331c4 6697 .policy = nl80211_policy,
f7ca38df
JB
6698 .flags = GENL_ADMIN_PERM,
6699 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6700 NL80211_FLAG_NEED_RTNL,
6701 },
6702 {
6703 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
6704 .doit = nl80211_tx_mgmt_cancel_wait,
6705 .policy = nl80211_policy,
026331c4 6706 .flags = GENL_ADMIN_PERM,
41265714 6707 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6708 NL80211_FLAG_NEED_RTNL,
026331c4 6709 },
ffb9eb3d
KV
6710 {
6711 .cmd = NL80211_CMD_SET_POWER_SAVE,
6712 .doit = nl80211_set_power_save,
6713 .policy = nl80211_policy,
6714 .flags = GENL_ADMIN_PERM,
4c476991
JB
6715 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6716 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
6717 },
6718 {
6719 .cmd = NL80211_CMD_GET_POWER_SAVE,
6720 .doit = nl80211_get_power_save,
6721 .policy = nl80211_policy,
6722 /* can be retrieved by unprivileged users */
4c476991
JB
6723 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6724 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 6725 },
d6dc1a38
JO
6726 {
6727 .cmd = NL80211_CMD_SET_CQM,
6728 .doit = nl80211_set_cqm,
6729 .policy = nl80211_policy,
6730 .flags = GENL_ADMIN_PERM,
4c476991
JB
6731 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6732 NL80211_FLAG_NEED_RTNL,
d6dc1a38 6733 },
f444de05
JB
6734 {
6735 .cmd = NL80211_CMD_SET_CHANNEL,
6736 .doit = nl80211_set_channel,
6737 .policy = nl80211_policy,
6738 .flags = GENL_ADMIN_PERM,
4c476991
JB
6739 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6740 NL80211_FLAG_NEED_RTNL,
f444de05 6741 },
e8347eba
BJ
6742 {
6743 .cmd = NL80211_CMD_SET_WDS_PEER,
6744 .doit = nl80211_set_wds_peer,
6745 .policy = nl80211_policy,
6746 .flags = GENL_ADMIN_PERM,
43b19952
JB
6747 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6748 NL80211_FLAG_NEED_RTNL,
e8347eba 6749 },
29cbe68c
JB
6750 {
6751 .cmd = NL80211_CMD_JOIN_MESH,
6752 .doit = nl80211_join_mesh,
6753 .policy = nl80211_policy,
6754 .flags = GENL_ADMIN_PERM,
6755 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6756 NL80211_FLAG_NEED_RTNL,
6757 },
6758 {
6759 .cmd = NL80211_CMD_LEAVE_MESH,
6760 .doit = nl80211_leave_mesh,
6761 .policy = nl80211_policy,
6762 .flags = GENL_ADMIN_PERM,
6763 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6764 NL80211_FLAG_NEED_RTNL,
6765 },
ff1b6e69
JB
6766 {
6767 .cmd = NL80211_CMD_GET_WOWLAN,
6768 .doit = nl80211_get_wowlan,
6769 .policy = nl80211_policy,
6770 /* can be retrieved by unprivileged users */
6771 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6772 NL80211_FLAG_NEED_RTNL,
6773 },
6774 {
6775 .cmd = NL80211_CMD_SET_WOWLAN,
6776 .doit = nl80211_set_wowlan,
6777 .policy = nl80211_policy,
6778 .flags = GENL_ADMIN_PERM,
6779 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6780 NL80211_FLAG_NEED_RTNL,
6781 },
e5497d76
JB
6782 {
6783 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
6784 .doit = nl80211_set_rekey_data,
6785 .policy = nl80211_policy,
6786 .flags = GENL_ADMIN_PERM,
6787 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6788 NL80211_FLAG_NEED_RTNL,
6789 },
109086ce
AN
6790 {
6791 .cmd = NL80211_CMD_TDLS_MGMT,
6792 .doit = nl80211_tdls_mgmt,
6793 .policy = nl80211_policy,
6794 .flags = GENL_ADMIN_PERM,
6795 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6796 NL80211_FLAG_NEED_RTNL,
6797 },
6798 {
6799 .cmd = NL80211_CMD_TDLS_OPER,
6800 .doit = nl80211_tdls_oper,
6801 .policy = nl80211_policy,
6802 .flags = GENL_ADMIN_PERM,
6803 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
6804 NL80211_FLAG_NEED_RTNL,
6805 },
28946da7
JB
6806 {
6807 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
6808 .doit = nl80211_register_unexpected_frame,
6809 .policy = nl80211_policy,
6810 .flags = GENL_ADMIN_PERM,
6811 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6812 NL80211_FLAG_NEED_RTNL,
6813 },
7f6cf311
JB
6814 {
6815 .cmd = NL80211_CMD_PROBE_CLIENT,
6816 .doit = nl80211_probe_client,
6817 .policy = nl80211_policy,
6818 .flags = GENL_ADMIN_PERM,
6819 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6820 NL80211_FLAG_NEED_RTNL,
6821 },
5e760230
JB
6822 {
6823 .cmd = NL80211_CMD_REGISTER_BEACONS,
6824 .doit = nl80211_register_beacons,
6825 .policy = nl80211_policy,
6826 .flags = GENL_ADMIN_PERM,
6827 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6828 NL80211_FLAG_NEED_RTNL,
6829 },
1d9d9213
SW
6830 {
6831 .cmd = NL80211_CMD_SET_NOACK_MAP,
6832 .doit = nl80211_set_noack_map,
6833 .policy = nl80211_policy,
6834 .flags = GENL_ADMIN_PERM,
6835 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6836 NL80211_FLAG_NEED_RTNL,
6837 },
6838
55682965 6839};
9588bbd5 6840
6039f6d2
JM
6841static struct genl_multicast_group nl80211_mlme_mcgrp = {
6842 .name = "mlme",
6843};
55682965
JB
6844
6845/* multicast groups */
6846static struct genl_multicast_group nl80211_config_mcgrp = {
6847 .name = "config",
6848};
2a519311
JB
6849static struct genl_multicast_group nl80211_scan_mcgrp = {
6850 .name = "scan",
6851};
73d54c9e
LR
6852static struct genl_multicast_group nl80211_regulatory_mcgrp = {
6853 .name = "regulatory",
6854};
55682965
JB
6855
6856/* notification functions */
6857
6858void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
6859{
6860 struct sk_buff *msg;
6861
fd2120ca 6862 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
6863 if (!msg)
6864 return;
6865
6866 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
6867 nlmsg_free(msg);
6868 return;
6869 }
6870
463d0183
JB
6871 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6872 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
6873}
6874
362a415d
JB
6875static int nl80211_add_scan_req(struct sk_buff *msg,
6876 struct cfg80211_registered_device *rdev)
6877{
6878 struct cfg80211_scan_request *req = rdev->scan_req;
6879 struct nlattr *nest;
6880 int i;
6881
667503dd
JB
6882 ASSERT_RDEV_LOCK(rdev);
6883
362a415d
JB
6884 if (WARN_ON(!req))
6885 return 0;
6886
6887 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
6888 if (!nest)
6889 goto nla_put_failure;
6890 for (i = 0; i < req->n_ssids; i++)
6891 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
6892 nla_nest_end(msg, nest);
6893
6894 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
6895 if (!nest)
6896 goto nla_put_failure;
6897 for (i = 0; i < req->n_channels; i++)
6898 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
6899 nla_nest_end(msg, nest);
6900
6901 if (req->ie)
6902 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
6903
6904 return 0;
6905 nla_put_failure:
6906 return -ENOBUFS;
6907}
6908
a538e2d5
JB
6909static int nl80211_send_scan_msg(struct sk_buff *msg,
6910 struct cfg80211_registered_device *rdev,
6911 struct net_device *netdev,
6912 u32 pid, u32 seq, int flags,
6913 u32 cmd)
2a519311
JB
6914{
6915 void *hdr;
6916
6917 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6918 if (!hdr)
6919 return -1;
6920
b5850a7a 6921 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
6922 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6923
362a415d
JB
6924 /* ignore errors and send incomplete event anyway */
6925 nl80211_add_scan_req(msg, rdev);
2a519311
JB
6926
6927 return genlmsg_end(msg, hdr);
6928
6929 nla_put_failure:
6930 genlmsg_cancel(msg, hdr);
6931 return -EMSGSIZE;
6932}
6933
807f8a8c
LC
6934static int
6935nl80211_send_sched_scan_msg(struct sk_buff *msg,
6936 struct cfg80211_registered_device *rdev,
6937 struct net_device *netdev,
6938 u32 pid, u32 seq, int flags, u32 cmd)
6939{
6940 void *hdr;
6941
6942 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
6943 if (!hdr)
6944 return -1;
6945
6946 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6947 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6948
6949 return genlmsg_end(msg, hdr);
6950
6951 nla_put_failure:
6952 genlmsg_cancel(msg, hdr);
6953 return -EMSGSIZE;
6954}
6955
a538e2d5
JB
6956void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
6957 struct net_device *netdev)
6958{
6959 struct sk_buff *msg;
6960
6961 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
6962 if (!msg)
6963 return;
6964
6965 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6966 NL80211_CMD_TRIGGER_SCAN) < 0) {
6967 nlmsg_free(msg);
6968 return;
6969 }
6970
463d0183
JB
6971 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6972 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
6973}
6974
2a519311
JB
6975void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
6976 struct net_device *netdev)
6977{
6978 struct sk_buff *msg;
6979
fd2120ca 6980 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
6981 if (!msg)
6982 return;
6983
a538e2d5
JB
6984 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
6985 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
6986 nlmsg_free(msg);
6987 return;
6988 }
6989
463d0183
JB
6990 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6991 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
6992}
6993
6994void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
6995 struct net_device *netdev)
6996{
6997 struct sk_buff *msg;
6998
fd2120ca 6999 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7000 if (!msg)
7001 return;
7002
a538e2d5
JB
7003 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7004 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
7005 nlmsg_free(msg);
7006 return;
7007 }
7008
463d0183
JB
7009 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7010 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7011}
7012
807f8a8c
LC
7013void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7014 struct net_device *netdev)
7015{
7016 struct sk_buff *msg;
7017
7018 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7019 if (!msg)
7020 return;
7021
7022 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7023 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
7024 nlmsg_free(msg);
7025 return;
7026 }
7027
7028 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7029 nl80211_scan_mcgrp.id, GFP_KERNEL);
7030}
7031
7032void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
7033 struct net_device *netdev, u32 cmd)
7034{
7035 struct sk_buff *msg;
7036
7037 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7038 if (!msg)
7039 return;
7040
7041 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
7042 nlmsg_free(msg);
7043 return;
7044 }
7045
7046 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7047 nl80211_scan_mcgrp.id, GFP_KERNEL);
7048}
7049
73d54c9e
LR
7050/*
7051 * This can happen on global regulatory changes or device specific settings
7052 * based on custom world regulatory domains.
7053 */
7054void nl80211_send_reg_change_event(struct regulatory_request *request)
7055{
7056 struct sk_buff *msg;
7057 void *hdr;
7058
fd2120ca 7059 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
7060 if (!msg)
7061 return;
7062
7063 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
7064 if (!hdr) {
7065 nlmsg_free(msg);
7066 return;
7067 }
7068
7069 /* Userspace can always count this one always being set */
7070 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
7071
7072 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
7073 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7074 NL80211_REGDOM_TYPE_WORLD);
7075 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
7076 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7077 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
7078 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
7079 request->intersect)
7080 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7081 NL80211_REGDOM_TYPE_INTERSECTION);
7082 else {
7083 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
7084 NL80211_REGDOM_TYPE_COUNTRY);
7085 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
7086 }
7087
7088 if (wiphy_idx_valid(request->wiphy_idx))
7089 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
7090
3b7b72ee 7091 genlmsg_end(msg, hdr);
73d54c9e 7092
bc43b28c 7093 rcu_read_lock();
463d0183 7094 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
7095 GFP_ATOMIC);
7096 rcu_read_unlock();
73d54c9e
LR
7097
7098 return;
7099
7100nla_put_failure:
7101 genlmsg_cancel(msg, hdr);
7102 nlmsg_free(msg);
7103}
7104
6039f6d2
JM
7105static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
7106 struct net_device *netdev,
7107 const u8 *buf, size_t len,
e6d6e342 7108 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
7109{
7110 struct sk_buff *msg;
7111 void *hdr;
7112
e6d6e342 7113 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
7114 if (!msg)
7115 return;
7116
7117 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7118 if (!hdr) {
7119 nlmsg_free(msg);
7120 return;
7121 }
7122
7123 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7124 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7125 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7126
3b7b72ee 7127 genlmsg_end(msg, hdr);
6039f6d2 7128
463d0183
JB
7129 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7130 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
7131 return;
7132
7133 nla_put_failure:
7134 genlmsg_cancel(msg, hdr);
7135 nlmsg_free(msg);
7136}
7137
7138void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7139 struct net_device *netdev, const u8 *buf,
7140 size_t len, gfp_t gfp)
6039f6d2
JM
7141{
7142 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7143 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
7144}
7145
7146void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
7147 struct net_device *netdev, const u8 *buf,
e6d6e342 7148 size_t len, gfp_t gfp)
6039f6d2 7149{
e6d6e342
JB
7150 nl80211_send_mlme_event(rdev, netdev, buf, len,
7151 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
7152}
7153
53b46b84 7154void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7155 struct net_device *netdev, const u8 *buf,
7156 size_t len, gfp_t gfp)
6039f6d2
JM
7157{
7158 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7159 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
7160}
7161
53b46b84
JM
7162void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
7163 struct net_device *netdev, const u8 *buf,
e6d6e342 7164 size_t len, gfp_t gfp)
6039f6d2
JM
7165{
7166 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7167 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
7168}
7169
cf4e594e
JM
7170void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
7171 struct net_device *netdev, const u8 *buf,
7172 size_t len, gfp_t gfp)
7173{
7174 nl80211_send_mlme_event(rdev, netdev, buf, len,
7175 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
7176}
7177
7178void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
7179 struct net_device *netdev, const u8 *buf,
7180 size_t len, gfp_t gfp)
7181{
7182 nl80211_send_mlme_event(rdev, netdev, buf, len,
7183 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
7184}
7185
1b06bb40
LR
7186static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
7187 struct net_device *netdev, int cmd,
e6d6e342 7188 const u8 *addr, gfp_t gfp)
1965c853
JM
7189{
7190 struct sk_buff *msg;
7191 void *hdr;
7192
e6d6e342 7193 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
7194 if (!msg)
7195 return;
7196
7197 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7198 if (!hdr) {
7199 nlmsg_free(msg);
7200 return;
7201 }
7202
7203 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7204 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7205 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
7206 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7207
3b7b72ee 7208 genlmsg_end(msg, hdr);
1965c853 7209
463d0183
JB
7210 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7211 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
7212 return;
7213
7214 nla_put_failure:
7215 genlmsg_cancel(msg, hdr);
7216 nlmsg_free(msg);
7217}
7218
7219void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7220 struct net_device *netdev, const u8 *addr,
7221 gfp_t gfp)
1965c853
JM
7222{
7223 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 7224 addr, gfp);
1965c853
JM
7225}
7226
7227void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7228 struct net_device *netdev, const u8 *addr,
7229 gfp_t gfp)
1965c853 7230{
e6d6e342
JB
7231 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
7232 addr, gfp);
1965c853
JM
7233}
7234
b23aa676
SO
7235void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
7236 struct net_device *netdev, const u8 *bssid,
7237 const u8 *req_ie, size_t req_ie_len,
7238 const u8 *resp_ie, size_t resp_ie_len,
7239 u16 status, gfp_t gfp)
7240{
7241 struct sk_buff *msg;
7242 void *hdr;
7243
7244 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7245 if (!msg)
7246 return;
7247
7248 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
7249 if (!hdr) {
7250 nlmsg_free(msg);
7251 return;
7252 }
7253
7254 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7255 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7256 if (bssid)
7257 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7258 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
7259 if (req_ie)
7260 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
7261 if (resp_ie)
7262 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
7263
3b7b72ee 7264 genlmsg_end(msg, hdr);
b23aa676 7265
463d0183
JB
7266 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7267 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7268 return;
7269
7270 nla_put_failure:
7271 genlmsg_cancel(msg, hdr);
7272 nlmsg_free(msg);
7273
7274}
7275
7276void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
7277 struct net_device *netdev, const u8 *bssid,
7278 const u8 *req_ie, size_t req_ie_len,
7279 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
7280{
7281 struct sk_buff *msg;
7282 void *hdr;
7283
7284 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7285 if (!msg)
7286 return;
7287
7288 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
7289 if (!hdr) {
7290 nlmsg_free(msg);
7291 return;
7292 }
7293
7294 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7295 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7296 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7297 if (req_ie)
7298 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
7299 if (resp_ie)
7300 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
7301
3b7b72ee 7302 genlmsg_end(msg, hdr);
b23aa676 7303
463d0183
JB
7304 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7305 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7306 return;
7307
7308 nla_put_failure:
7309 genlmsg_cancel(msg, hdr);
7310 nlmsg_free(msg);
7311
7312}
7313
7314void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
7315 struct net_device *netdev, u16 reason,
667503dd 7316 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
7317{
7318 struct sk_buff *msg;
7319 void *hdr;
7320
667503dd 7321 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
7322 if (!msg)
7323 return;
7324
7325 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
7326 if (!hdr) {
7327 nlmsg_free(msg);
7328 return;
7329 }
7330
7331 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7332 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7333 if (from_ap && reason)
7334 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
7335 if (from_ap)
7336 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
7337 if (ie)
7338 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
7339
3b7b72ee 7340 genlmsg_end(msg, hdr);
b23aa676 7341
463d0183
JB
7342 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7343 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
7344 return;
7345
7346 nla_put_failure:
7347 genlmsg_cancel(msg, hdr);
7348 nlmsg_free(msg);
7349
7350}
7351
04a773ad
JB
7352void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7353 struct net_device *netdev, const u8 *bssid,
7354 gfp_t gfp)
7355{
7356 struct sk_buff *msg;
7357 void *hdr;
7358
fd2120ca 7359 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7360 if (!msg)
7361 return;
7362
7363 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7364 if (!hdr) {
7365 nlmsg_free(msg);
7366 return;
7367 }
7368
7369 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7370 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7371 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7372
3b7b72ee 7373 genlmsg_end(msg, hdr);
04a773ad 7374
463d0183
JB
7375 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7376 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7377 return;
7378
7379 nla_put_failure:
7380 genlmsg_cancel(msg, hdr);
7381 nlmsg_free(msg);
7382}
7383
c93b5e71
JC
7384void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7385 struct net_device *netdev,
7386 const u8 *macaddr, const u8* ie, u8 ie_len,
7387 gfp_t gfp)
7388{
7389 struct sk_buff *msg;
7390 void *hdr;
7391
7392 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7393 if (!msg)
7394 return;
7395
7396 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7397 if (!hdr) {
7398 nlmsg_free(msg);
7399 return;
7400 }
7401
7402 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7403 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7404 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr);
7405 if (ie_len && ie)
7406 NLA_PUT(msg, NL80211_ATTR_IE, ie_len , ie);
7407
3b7b72ee 7408 genlmsg_end(msg, hdr);
c93b5e71
JC
7409
7410 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7411 nl80211_mlme_mcgrp.id, gfp);
7412 return;
7413
7414 nla_put_failure:
7415 genlmsg_cancel(msg, hdr);
7416 nlmsg_free(msg);
7417}
7418
a3b8b056
JM
7419void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7420 struct net_device *netdev, const u8 *addr,
7421 enum nl80211_key_type key_type, int key_id,
e6d6e342 7422 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7423{
7424 struct sk_buff *msg;
7425 void *hdr;
7426
e6d6e342 7427 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7428 if (!msg)
7429 return;
7430
7431 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7432 if (!hdr) {
7433 nlmsg_free(msg);
7434 return;
7435 }
7436
7437 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7438 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7439 if (addr)
7440 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7441 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
a66b98db
AN
7442 if (key_id != -1)
7443 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
a3b8b056
JM
7444 if (tsc)
7445 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
7446
3b7b72ee 7447 genlmsg_end(msg, hdr);
a3b8b056 7448
463d0183
JB
7449 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7450 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7451 return;
7452
7453 nla_put_failure:
7454 genlmsg_cancel(msg, hdr);
7455 nlmsg_free(msg);
7456}
7457
6bad8766
LR
7458void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7459 struct ieee80211_channel *channel_before,
7460 struct ieee80211_channel *channel_after)
7461{
7462 struct sk_buff *msg;
7463 void *hdr;
7464 struct nlattr *nl_freq;
7465
fd2120ca 7466 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7467 if (!msg)
7468 return;
7469
7470 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7471 if (!hdr) {
7472 nlmsg_free(msg);
7473 return;
7474 }
7475
7476 /*
7477 * Since we are applying the beacon hint to a wiphy we know its
7478 * wiphy_idx is valid
7479 */
7480 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
7481
7482 /* Before */
7483 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
7484 if (!nl_freq)
7485 goto nla_put_failure;
7486 if (nl80211_msg_put_channel(msg, channel_before))
7487 goto nla_put_failure;
7488 nla_nest_end(msg, nl_freq);
7489
7490 /* After */
7491 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
7492 if (!nl_freq)
7493 goto nla_put_failure;
7494 if (nl80211_msg_put_channel(msg, channel_after))
7495 goto nla_put_failure;
7496 nla_nest_end(msg, nl_freq);
7497
3b7b72ee 7498 genlmsg_end(msg, hdr);
6bad8766 7499
463d0183
JB
7500 rcu_read_lock();
7501 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
7502 GFP_ATOMIC);
7503 rcu_read_unlock();
6bad8766
LR
7504
7505 return;
7506
7507nla_put_failure:
7508 genlmsg_cancel(msg, hdr);
7509 nlmsg_free(msg);
7510}
7511
9588bbd5
JM
7512static void nl80211_send_remain_on_chan_event(
7513 int cmd, struct cfg80211_registered_device *rdev,
7514 struct net_device *netdev, u64 cookie,
7515 struct ieee80211_channel *chan,
7516 enum nl80211_channel_type channel_type,
7517 unsigned int duration, gfp_t gfp)
7518{
7519 struct sk_buff *msg;
7520 void *hdr;
7521
7522 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7523 if (!msg)
7524 return;
7525
7526 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7527 if (!hdr) {
7528 nlmsg_free(msg);
7529 return;
7530 }
7531
7532 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7533 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7534 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
7535 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
7536 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7537
7538 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
7539 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
7540
3b7b72ee 7541 genlmsg_end(msg, hdr);
9588bbd5
JM
7542
7543 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7544 nl80211_mlme_mcgrp.id, gfp);
7545 return;
7546
7547 nla_put_failure:
7548 genlmsg_cancel(msg, hdr);
7549 nlmsg_free(msg);
7550}
7551
7552void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
7553 struct net_device *netdev, u64 cookie,
7554 struct ieee80211_channel *chan,
7555 enum nl80211_channel_type channel_type,
7556 unsigned int duration, gfp_t gfp)
7557{
7558 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
7559 rdev, netdev, cookie, chan,
7560 channel_type, duration, gfp);
7561}
7562
7563void nl80211_send_remain_on_channel_cancel(
7564 struct cfg80211_registered_device *rdev, struct net_device *netdev,
7565 u64 cookie, struct ieee80211_channel *chan,
7566 enum nl80211_channel_type channel_type, gfp_t gfp)
7567{
7568 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7569 rdev, netdev, cookie, chan,
7570 channel_type, 0, gfp);
7571}
7572
98b62183
JB
7573void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
7574 struct net_device *dev, const u8 *mac_addr,
7575 struct station_info *sinfo, gfp_t gfp)
7576{
7577 struct sk_buff *msg;
7578
7579 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7580 if (!msg)
7581 return;
7582
7583 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
7584 nlmsg_free(msg);
7585 return;
7586 }
7587
7588 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7589 nl80211_mlme_mcgrp.id, gfp);
7590}
7591
ec15e68b
JM
7592void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
7593 struct net_device *dev, const u8 *mac_addr,
7594 gfp_t gfp)
7595{
7596 struct sk_buff *msg;
7597 void *hdr;
7598
7599 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7600 if (!msg)
7601 return;
7602
7603 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
7604 if (!hdr) {
7605 nlmsg_free(msg);
7606 return;
7607 }
7608
7609 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7610 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
7611
3b7b72ee 7612 genlmsg_end(msg, hdr);
ec15e68b
JM
7613
7614 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7615 nl80211_mlme_mcgrp.id, gfp);
7616 return;
7617
7618 nla_put_failure:
7619 genlmsg_cancel(msg, hdr);
7620 nlmsg_free(msg);
7621}
7622
b92ab5d8
JB
7623static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
7624 const u8 *addr, gfp_t gfp)
28946da7
JB
7625{
7626 struct wireless_dev *wdev = dev->ieee80211_ptr;
7627 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7628 struct sk_buff *msg;
7629 void *hdr;
7630 int err;
7631 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
7632
7633 if (!nlpid)
7634 return false;
7635
7636 msg = nlmsg_new(100, gfp);
7637 if (!msg)
7638 return true;
7639
b92ab5d8 7640 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
7641 if (!hdr) {
7642 nlmsg_free(msg);
7643 return true;
7644 }
7645
7646 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7647 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7648 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7649
7650 err = genlmsg_end(msg, hdr);
7651 if (err < 0) {
7652 nlmsg_free(msg);
7653 return true;
7654 }
7655
7656 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7657 return true;
7658
7659 nla_put_failure:
7660 genlmsg_cancel(msg, hdr);
7661 nlmsg_free(msg);
7662 return true;
7663}
7664
b92ab5d8
JB
7665bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
7666{
7667 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
7668 addr, gfp);
7669}
7670
7671bool nl80211_unexpected_4addr_frame(struct net_device *dev,
7672 const u8 *addr, gfp_t gfp)
7673{
7674 return __nl80211_unexpected_frame(dev,
7675 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
7676 addr, gfp);
7677}
7678
2e161f78
JB
7679int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
7680 struct net_device *netdev, u32 nlpid,
7681 int freq, const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
7682{
7683 struct sk_buff *msg;
7684 void *hdr;
026331c4
JM
7685
7686 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7687 if (!msg)
7688 return -ENOMEM;
7689
2e161f78 7690 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
7691 if (!hdr) {
7692 nlmsg_free(msg);
7693 return -ENOMEM;
7694 }
7695
7696 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7697 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7698 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7699 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7700
3b7b72ee 7701 genlmsg_end(msg, hdr);
026331c4 7702
3b7b72ee 7703 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
7704
7705 nla_put_failure:
7706 genlmsg_cancel(msg, hdr);
7707 nlmsg_free(msg);
7708 return -ENOBUFS;
7709}
7710
2e161f78
JB
7711void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
7712 struct net_device *netdev, u64 cookie,
7713 const u8 *buf, size_t len, bool ack,
7714 gfp_t gfp)
026331c4
JM
7715{
7716 struct sk_buff *msg;
7717 void *hdr;
7718
7719 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7720 if (!msg)
7721 return;
7722
2e161f78 7723 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
7724 if (!hdr) {
7725 nlmsg_free(msg);
7726 return;
7727 }
7728
7729 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7730 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7731 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
7732 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7733 if (ack)
7734 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7735
3b7b72ee 7736 genlmsg_end(msg, hdr);
026331c4
JM
7737
7738 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
7739 return;
7740
7741 nla_put_failure:
7742 genlmsg_cancel(msg, hdr);
7743 nlmsg_free(msg);
7744}
7745
d6dc1a38
JO
7746void
7747nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
7748 struct net_device *netdev,
7749 enum nl80211_cqm_rssi_threshold_event rssi_event,
7750 gfp_t gfp)
7751{
7752 struct sk_buff *msg;
7753 struct nlattr *pinfoattr;
7754 void *hdr;
7755
7756 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7757 if (!msg)
7758 return;
7759
7760 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7761 if (!hdr) {
7762 nlmsg_free(msg);
7763 return;
7764 }
7765
7766 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7767 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7768
7769 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7770 if (!pinfoattr)
7771 goto nla_put_failure;
7772
7773 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
7774 rssi_event);
7775
7776 nla_nest_end(msg, pinfoattr);
7777
3b7b72ee 7778 genlmsg_end(msg, hdr);
d6dc1a38
JO
7779
7780 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7781 nl80211_mlme_mcgrp.id, gfp);
7782 return;
7783
7784 nla_put_failure:
7785 genlmsg_cancel(msg, hdr);
7786 nlmsg_free(msg);
7787}
7788
e5497d76
JB
7789void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
7790 struct net_device *netdev, const u8 *bssid,
7791 const u8 *replay_ctr, gfp_t gfp)
7792{
7793 struct sk_buff *msg;
7794 struct nlattr *rekey_attr;
7795 void *hdr;
7796
7797 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7798 if (!msg)
7799 return;
7800
7801 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
7802 if (!hdr) {
7803 nlmsg_free(msg);
7804 return;
7805 }
7806
7807 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7808 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7809 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
7810
7811 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
7812 if (!rekey_attr)
7813 goto nla_put_failure;
7814
7815 NLA_PUT(msg, NL80211_REKEY_DATA_REPLAY_CTR,
7816 NL80211_REPLAY_CTR_LEN, replay_ctr);
7817
7818 nla_nest_end(msg, rekey_attr);
7819
3b7b72ee 7820 genlmsg_end(msg, hdr);
e5497d76
JB
7821
7822 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7823 nl80211_mlme_mcgrp.id, gfp);
7824 return;
7825
7826 nla_put_failure:
7827 genlmsg_cancel(msg, hdr);
7828 nlmsg_free(msg);
7829}
7830
c9df56b4
JM
7831void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
7832 struct net_device *netdev, int index,
7833 const u8 *bssid, bool preauth, gfp_t gfp)
7834{
7835 struct sk_buff *msg;
7836 struct nlattr *attr;
7837 void *hdr;
7838
7839 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7840 if (!msg)
7841 return;
7842
7843 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
7844 if (!hdr) {
7845 nlmsg_free(msg);
7846 return;
7847 }
7848
7849 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7850 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7851
7852 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
7853 if (!attr)
7854 goto nla_put_failure;
7855
7856 NLA_PUT_U32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index);
7857 NLA_PUT(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid);
7858 if (preauth)
7859 NLA_PUT_FLAG(msg, NL80211_PMKSA_CANDIDATE_PREAUTH);
7860
7861 nla_nest_end(msg, attr);
7862
3b7b72ee 7863 genlmsg_end(msg, hdr);
c9df56b4
JM
7864
7865 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7866 nl80211_mlme_mcgrp.id, gfp);
7867 return;
7868
7869 nla_put_failure:
7870 genlmsg_cancel(msg, hdr);
7871 nlmsg_free(msg);
7872}
7873
c063dbf5
JB
7874void
7875nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
7876 struct net_device *netdev, const u8 *peer,
7877 u32 num_packets, gfp_t gfp)
7878{
7879 struct sk_buff *msg;
7880 struct nlattr *pinfoattr;
7881 void *hdr;
7882
7883 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7884 if (!msg)
7885 return;
7886
7887 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
7888 if (!hdr) {
7889 nlmsg_free(msg);
7890 return;
7891 }
7892
7893 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7894 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
7895 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
7896
7897 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
7898 if (!pinfoattr)
7899 goto nla_put_failure;
7900
7901 NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
7902
7903 nla_nest_end(msg, pinfoattr);
7904
3b7b72ee 7905 genlmsg_end(msg, hdr);
c063dbf5
JB
7906
7907 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7908 nl80211_mlme_mcgrp.id, gfp);
7909 return;
7910
7911 nla_put_failure:
7912 genlmsg_cancel(msg, hdr);
7913 nlmsg_free(msg);
7914}
7915
7f6cf311
JB
7916void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
7917 u64 cookie, bool acked, gfp_t gfp)
7918{
7919 struct wireless_dev *wdev = dev->ieee80211_ptr;
7920 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
7921 struct sk_buff *msg;
7922 void *hdr;
7923 int err;
7924
7925 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7926 if (!msg)
7927 return;
7928
7929 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
7930 if (!hdr) {
7931 nlmsg_free(msg);
7932 return;
7933 }
7934
7935 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7936 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
7937 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
7938 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
7939 if (acked)
7940 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
7941
7942 err = genlmsg_end(msg, hdr);
7943 if (err < 0) {
7944 nlmsg_free(msg);
7945 return;
7946 }
7947
7948 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7949 nl80211_mlme_mcgrp.id, gfp);
7950 return;
7951
7952 nla_put_failure:
7953 genlmsg_cancel(msg, hdr);
7954 nlmsg_free(msg);
7955}
7956EXPORT_SYMBOL(cfg80211_probe_status);
7957
5e760230
JB
7958void cfg80211_report_obss_beacon(struct wiphy *wiphy,
7959 const u8 *frame, size_t len,
7960 int freq, gfp_t gfp)
7961{
7962 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
7963 struct sk_buff *msg;
7964 void *hdr;
7965 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
7966
7967 if (!nlpid)
7968 return;
7969
7970 msg = nlmsg_new(len + 100, gfp);
7971 if (!msg)
7972 return;
7973
7974 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
7975 if (!hdr) {
7976 nlmsg_free(msg);
7977 return;
7978 }
7979
7980 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
7981 if (freq)
7982 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
7983 NLA_PUT(msg, NL80211_ATTR_FRAME, len, frame);
7984
7985 genlmsg_end(msg, hdr);
7986
7987 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
7988 return;
7989
7990 nla_put_failure:
7991 genlmsg_cancel(msg, hdr);
7992 nlmsg_free(msg);
7993}
7994EXPORT_SYMBOL(cfg80211_report_obss_beacon);
7995
026331c4
JM
7996static int nl80211_netlink_notify(struct notifier_block * nb,
7997 unsigned long state,
7998 void *_notify)
7999{
8000 struct netlink_notify *notify = _notify;
8001 struct cfg80211_registered_device *rdev;
8002 struct wireless_dev *wdev;
8003
8004 if (state != NETLINK_URELEASE)
8005 return NOTIFY_DONE;
8006
8007 rcu_read_lock();
8008
5e760230 8009 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
026331c4 8010 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
2e161f78 8011 cfg80211_mlme_unregister_socket(wdev, notify->pid);
5e760230
JB
8012 if (rdev->ap_beacons_nlpid == notify->pid)
8013 rdev->ap_beacons_nlpid = 0;
8014 }
026331c4
JM
8015
8016 rcu_read_unlock();
8017
8018 return NOTIFY_DONE;
8019}
8020
8021static struct notifier_block nl80211_netlink_notifier = {
8022 .notifier_call = nl80211_netlink_notify,
8023};
8024
55682965
JB
8025/* initialisation/exit functions */
8026
8027int nl80211_init(void)
8028{
0d63cbb5 8029 int err;
55682965 8030
0d63cbb5
MM
8031 err = genl_register_family_with_ops(&nl80211_fam,
8032 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
8033 if (err)
8034 return err;
8035
55682965
JB
8036 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
8037 if (err)
8038 goto err_out;
8039
2a519311
JB
8040 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
8041 if (err)
8042 goto err_out;
8043
73d54c9e
LR
8044 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
8045 if (err)
8046 goto err_out;
8047
6039f6d2
JM
8048 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
8049 if (err)
8050 goto err_out;
8051
aff89a9b
JB
8052#ifdef CONFIG_NL80211_TESTMODE
8053 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
8054 if (err)
8055 goto err_out;
8056#endif
8057
026331c4
JM
8058 err = netlink_register_notifier(&nl80211_netlink_notifier);
8059 if (err)
8060 goto err_out;
8061
55682965
JB
8062 return 0;
8063 err_out:
8064 genl_unregister_family(&nl80211_fam);
8065 return err;
8066}
8067
8068void nl80211_exit(void)
8069{
026331c4 8070 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
8071 genl_unregister_family(&nl80211_fam);
8072}