cfg80211/mac80211: Update set_tx_power to use mBm instead of dBm units
[GitHub/mt8127/android_kernel_alcatel_ttab.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965
JB
25
26/* the netlink family */
27static struct genl_family nl80211_fam = {
28 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
29 .name = "nl80211", /* have users key off the name instead */
30 .hdrsize = 0, /* no private header */
31 .version = 1, /* no particular meaning now */
32 .maxattr = NL80211_ATTR_MAX,
463d0183 33 .netnsok = true,
55682965
JB
34};
35
79c97e97 36/* internal helper: get rdev and dev */
463d0183 37static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 38 struct cfg80211_registered_device **rdev,
55682965
JB
39 struct net_device **dev)
40{
463d0183 41 struct nlattr **attrs = info->attrs;
55682965
JB
42 int ifindex;
43
bba95fef 44 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
45 return -EINVAL;
46
bba95fef 47 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 48 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
49 if (!*dev)
50 return -ENODEV;
51
463d0183 52 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 53 if (IS_ERR(*rdev)) {
55682965 54 dev_put(*dev);
79c97e97 55 return PTR_ERR(*rdev);
55682965
JB
56 }
57
58 return 0;
59}
60
61/* policy for the attributes */
b54452b0 62static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
63 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
64 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 65 .len = 20-1 },
31888487 66 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 67 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 68 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
69 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
71 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
72 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 73 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
74
75 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
76 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
77 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
78
79 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 80 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 81
b9454e83 82 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
83 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
84 .len = WLAN_MAX_KEY_LEN },
85 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
86 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
87 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 88 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
89
90 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
91 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
92 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
93 .len = IEEE80211_MAX_DATA_LEN },
94 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
95 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
96 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
97 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
98 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
99 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
100 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 101 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 102 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 103 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
104 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
105 .len = IEEE80211_MAX_MESH_ID_LEN },
106 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 107
b2e1b302
LR
108 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
109 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
110
9f1ba906
JM
111 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
113 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
114 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
115 .len = NL80211_MAX_SUPP_RATES },
36aedc90 116
93da9cc1 117 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
118
36aedc90
JM
119 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
120 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
121
122 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
123 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
124 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
125 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
126 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
127
128 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
129 .len = IEEE80211_MAX_SSID_LEN },
130 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
131 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 132 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 133 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 134 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
135 [NL80211_ATTR_STA_FLAGS2] = {
136 .len = sizeof(struct nl80211_sta_flag_update),
137 },
3f77316c 138 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
139 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
140 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
141 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 142 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 143 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
144 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
145 .len = WLAN_PMKID_LEN },
9588bbd5
JM
146 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
147 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 148 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
149 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
150 .len = IEEE80211_MAX_DATA_LEN },
151 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 152 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 153 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 154 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 155 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
55682965
JB
156};
157
b9454e83 158/* policy for the attributes */
b54452b0 159static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 160 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
161 [NL80211_KEY_IDX] = { .type = NLA_U8 },
162 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
163 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
164 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
165 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
166};
167
a043897a
HS
168/* ifidx get helper */
169static int nl80211_get_ifidx(struct netlink_callback *cb)
170{
171 int res;
172
173 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
174 nl80211_fam.attrbuf, nl80211_fam.maxattr,
175 nl80211_policy);
176 if (res)
177 return res;
178
179 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
180 return -EINVAL;
181
182 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
183 if (!res)
184 return -EINVAL;
185 return res;
186}
187
f4a11bb0
JB
188/* IE validation */
189static bool is_valid_ie_attr(const struct nlattr *attr)
190{
191 const u8 *pos;
192 int len;
193
194 if (!attr)
195 return true;
196
197 pos = nla_data(attr);
198 len = nla_len(attr);
199
200 while (len) {
201 u8 elemlen;
202
203 if (len < 2)
204 return false;
205 len -= 2;
206
207 elemlen = pos[1];
208 if (elemlen > len)
209 return false;
210
211 len -= elemlen;
212 pos += 2 + elemlen;
213 }
214
215 return true;
216}
217
55682965
JB
218/* message building helper */
219static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
220 int flags, u8 cmd)
221{
222 /* since there is no private header just add the generic one */
223 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
224}
225
5dab3b8a
LR
226static int nl80211_msg_put_channel(struct sk_buff *msg,
227 struct ieee80211_channel *chan)
228{
229 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
230 chan->center_freq);
231
232 if (chan->flags & IEEE80211_CHAN_DISABLED)
233 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
234 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
235 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
236 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
237 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
238 if (chan->flags & IEEE80211_CHAN_RADAR)
239 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
240
241 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
242 DBM_TO_MBM(chan->max_power));
243
244 return 0;
245
246 nla_put_failure:
247 return -ENOBUFS;
248}
249
55682965
JB
250/* netlink command implementations */
251
b9454e83
JB
252struct key_parse {
253 struct key_params p;
254 int idx;
255 bool def, defmgmt;
256};
257
258static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
259{
260 struct nlattr *tb[NL80211_KEY_MAX + 1];
261 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
262 nl80211_key_policy);
263 if (err)
264 return err;
265
266 k->def = !!tb[NL80211_KEY_DEFAULT];
267 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
268
269 if (tb[NL80211_KEY_IDX])
270 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
271
272 if (tb[NL80211_KEY_DATA]) {
273 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
274 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
275 }
276
277 if (tb[NL80211_KEY_SEQ]) {
278 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
279 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
280 }
281
282 if (tb[NL80211_KEY_CIPHER])
283 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
284
285 return 0;
286}
287
288static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
289{
290 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
291 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
292 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
293 }
294
295 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
296 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
297 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
298 }
299
300 if (info->attrs[NL80211_ATTR_KEY_IDX])
301 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
302
303 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
304 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
305
306 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
307 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
308
309 return 0;
310}
311
312static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
313{
314 int err;
315
316 memset(k, 0, sizeof(*k));
317 k->idx = -1;
318
319 if (info->attrs[NL80211_ATTR_KEY])
320 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
321 else
322 err = nl80211_parse_key_old(info, k);
323
324 if (err)
325 return err;
326
327 if (k->def && k->defmgmt)
328 return -EINVAL;
329
330 if (k->idx != -1) {
331 if (k->defmgmt) {
332 if (k->idx < 4 || k->idx > 5)
333 return -EINVAL;
334 } else if (k->def) {
335 if (k->idx < 0 || k->idx > 3)
336 return -EINVAL;
337 } else {
338 if (k->idx < 0 || k->idx > 5)
339 return -EINVAL;
340 }
341 }
342
343 return 0;
344}
345
fffd0934
JB
346static struct cfg80211_cached_keys *
347nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
348 struct nlattr *keys)
349{
350 struct key_parse parse;
351 struct nlattr *key;
352 struct cfg80211_cached_keys *result;
353 int rem, err, def = 0;
354
355 result = kzalloc(sizeof(*result), GFP_KERNEL);
356 if (!result)
357 return ERR_PTR(-ENOMEM);
358
359 result->def = -1;
360 result->defmgmt = -1;
361
362 nla_for_each_nested(key, keys, rem) {
363 memset(&parse, 0, sizeof(parse));
364 parse.idx = -1;
365
366 err = nl80211_parse_key_new(key, &parse);
367 if (err)
368 goto error;
369 err = -EINVAL;
370 if (!parse.p.key)
371 goto error;
372 if (parse.idx < 0 || parse.idx > 4)
373 goto error;
374 if (parse.def) {
375 if (def)
376 goto error;
377 def = 1;
378 result->def = parse.idx;
379 } else if (parse.defmgmt)
380 goto error;
381 err = cfg80211_validate_key_settings(rdev, &parse.p,
382 parse.idx, NULL);
383 if (err)
384 goto error;
385 result->params[parse.idx].cipher = parse.p.cipher;
386 result->params[parse.idx].key_len = parse.p.key_len;
387 result->params[parse.idx].key = result->data[parse.idx];
388 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
389 }
390
391 return result;
392 error:
393 kfree(result);
394 return ERR_PTR(err);
395}
396
397static int nl80211_key_allowed(struct wireless_dev *wdev)
398{
399 ASSERT_WDEV_LOCK(wdev);
400
401 if (!netif_running(wdev->netdev))
402 return -ENETDOWN;
403
404 switch (wdev->iftype) {
405 case NL80211_IFTYPE_AP:
406 case NL80211_IFTYPE_AP_VLAN:
407 break;
408 case NL80211_IFTYPE_ADHOC:
409 if (!wdev->current_bss)
410 return -ENOLINK;
411 break;
412 case NL80211_IFTYPE_STATION:
413 if (wdev->sme_state != CFG80211_SME_CONNECTED)
414 return -ENOLINK;
415 break;
416 default:
417 return -EINVAL;
418 }
419
420 return 0;
421}
422
55682965
JB
423static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
424 struct cfg80211_registered_device *dev)
425{
426 void *hdr;
ee688b00
JB
427 struct nlattr *nl_bands, *nl_band;
428 struct nlattr *nl_freqs, *nl_freq;
429 struct nlattr *nl_rates, *nl_rate;
f59ac048 430 struct nlattr *nl_modes;
8fdc621d 431 struct nlattr *nl_cmds;
ee688b00
JB
432 enum ieee80211_band band;
433 struct ieee80211_channel *chan;
434 struct ieee80211_rate *rate;
435 int i;
f59ac048 436 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
437
438 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
439 if (!hdr)
440 return -1;
441
b5850a7a 442 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 443 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 444
f5ea9120
JB
445 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
446 cfg80211_rdev_list_generation);
447
b9a5f8ca
JM
448 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
449 dev->wiphy.retry_short);
450 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
451 dev->wiphy.retry_long);
452 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
453 dev->wiphy.frag_threshold);
454 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
455 dev->wiphy.rts_threshold);
81077e82
LT
456 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
457 dev->wiphy.coverage_class);
b9a5f8ca 458
2a519311
JB
459 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
460 dev->wiphy.max_scan_ssids);
18a83659
JB
461 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
462 dev->wiphy.max_scan_ie_len);
ee688b00 463
25e47c18
JB
464 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
465 sizeof(u32) * dev->wiphy.n_cipher_suites,
466 dev->wiphy.cipher_suites);
467
67fbb16b
SO
468 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
469 dev->wiphy.max_num_pmkids);
470
f59ac048
LR
471 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
472 if (!nl_modes)
473 goto nla_put_failure;
474
475 i = 0;
476 while (ifmodes) {
477 if (ifmodes & 1)
478 NLA_PUT_FLAG(msg, i);
479 ifmodes >>= 1;
480 i++;
481 }
482
483 nla_nest_end(msg, nl_modes);
484
ee688b00
JB
485 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
486 if (!nl_bands)
487 goto nla_put_failure;
488
489 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
490 if (!dev->wiphy.bands[band])
491 continue;
492
493 nl_band = nla_nest_start(msg, band);
494 if (!nl_band)
495 goto nla_put_failure;
496
d51626df
JB
497 /* add HT info */
498 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
499 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
500 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
501 &dev->wiphy.bands[band]->ht_cap.mcs);
502 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
503 dev->wiphy.bands[band]->ht_cap.cap);
504 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
505 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
506 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
507 dev->wiphy.bands[band]->ht_cap.ampdu_density);
508 }
509
ee688b00
JB
510 /* add frequencies */
511 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
512 if (!nl_freqs)
513 goto nla_put_failure;
514
515 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
516 nl_freq = nla_nest_start(msg, i);
517 if (!nl_freq)
518 goto nla_put_failure;
519
520 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
521
522 if (nl80211_msg_put_channel(msg, chan))
523 goto nla_put_failure;
e2f367f2 524
ee688b00
JB
525 nla_nest_end(msg, nl_freq);
526 }
527
528 nla_nest_end(msg, nl_freqs);
529
530 /* add bitrates */
531 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
532 if (!nl_rates)
533 goto nla_put_failure;
534
535 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
536 nl_rate = nla_nest_start(msg, i);
537 if (!nl_rate)
538 goto nla_put_failure;
539
540 rate = &dev->wiphy.bands[band]->bitrates[i];
541 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
542 rate->bitrate);
543 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
544 NLA_PUT_FLAG(msg,
545 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
546
547 nla_nest_end(msg, nl_rate);
548 }
549
550 nla_nest_end(msg, nl_rates);
551
552 nla_nest_end(msg, nl_band);
553 }
554 nla_nest_end(msg, nl_bands);
555
8fdc621d
JB
556 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
557 if (!nl_cmds)
558 goto nla_put_failure;
559
560 i = 0;
561#define CMD(op, n) \
562 do { \
563 if (dev->ops->op) { \
564 i++; \
565 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
566 } \
567 } while (0)
568
569 CMD(add_virtual_intf, NEW_INTERFACE);
570 CMD(change_virtual_intf, SET_INTERFACE);
571 CMD(add_key, NEW_KEY);
572 CMD(add_beacon, NEW_BEACON);
573 CMD(add_station, NEW_STATION);
574 CMD(add_mpath, NEW_MPATH);
575 CMD(set_mesh_params, SET_MESH_PARAMS);
576 CMD(change_bss, SET_BSS);
636a5d36
JM
577 CMD(auth, AUTHENTICATE);
578 CMD(assoc, ASSOCIATE);
579 CMD(deauth, DEAUTHENTICATE);
580 CMD(disassoc, DISASSOCIATE);
04a773ad 581 CMD(join_ibss, JOIN_IBSS);
67fbb16b
SO
582 CMD(set_pmksa, SET_PMKSA);
583 CMD(del_pmksa, DEL_PMKSA);
584 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 585 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 586 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
026331c4 587 CMD(action, ACTION);
5be83de5 588 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
589 i++;
590 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
591 }
f444de05 592 CMD(set_channel, SET_CHANNEL);
8fdc621d
JB
593
594#undef CMD
b23aa676 595
6829c878 596 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
597 i++;
598 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
599 }
600
6829c878 601 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
602 i++;
603 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
604 }
605
8fdc621d
JB
606 nla_nest_end(msg, nl_cmds);
607
55682965
JB
608 return genlmsg_end(msg, hdr);
609
610 nla_put_failure:
bc3ed28c
TG
611 genlmsg_cancel(msg, hdr);
612 return -EMSGSIZE;
55682965
JB
613}
614
615static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
616{
617 int idx = 0;
618 int start = cb->args[0];
619 struct cfg80211_registered_device *dev;
620
a1794390 621 mutex_lock(&cfg80211_mutex);
79c97e97 622 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
623 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
624 continue;
b4637271 625 if (++idx <= start)
55682965
JB
626 continue;
627 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
628 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
629 dev) < 0) {
630 idx--;
55682965 631 break;
b4637271 632 }
55682965 633 }
a1794390 634 mutex_unlock(&cfg80211_mutex);
55682965
JB
635
636 cb->args[0] = idx;
637
638 return skb->len;
639}
640
641static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
642{
643 struct sk_buff *msg;
644 struct cfg80211_registered_device *dev;
645
646 dev = cfg80211_get_dev_from_info(info);
647 if (IS_ERR(dev))
648 return PTR_ERR(dev);
649
fd2120ca 650 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
651 if (!msg)
652 goto out_err;
653
654 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
655 goto out_free;
656
4d0c8aea 657 cfg80211_unlock_rdev(dev);
55682965 658
134e6375 659 return genlmsg_reply(msg, info);
55682965
JB
660
661 out_free:
662 nlmsg_free(msg);
663 out_err:
4d0c8aea 664 cfg80211_unlock_rdev(dev);
55682965
JB
665 return -ENOBUFS;
666}
667
31888487
JM
668static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
669 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
670 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
671 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
672 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
673 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
674};
675
676static int parse_txq_params(struct nlattr *tb[],
677 struct ieee80211_txq_params *txq_params)
678{
679 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
680 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
681 !tb[NL80211_TXQ_ATTR_AIFS])
682 return -EINVAL;
683
684 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
685 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
686 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
687 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
688 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
689
690 return 0;
691}
692
f444de05
JB
693static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
694{
695 /*
696 * You can only set the channel explicitly for AP, mesh
697 * and WDS type interfaces; all others have their channel
698 * managed via their respective "establish a connection"
699 * command (connect, join, ...)
700 *
701 * Monitors are special as they are normally slaved to
702 * whatever else is going on, so they behave as though
703 * you tried setting the wiphy channel itself.
704 */
705 return !wdev ||
706 wdev->iftype == NL80211_IFTYPE_AP ||
707 wdev->iftype == NL80211_IFTYPE_WDS ||
708 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
709 wdev->iftype == NL80211_IFTYPE_MONITOR;
710}
711
712static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
713 struct wireless_dev *wdev,
714 struct genl_info *info)
715{
716 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
717 u32 freq;
718 int result;
719
720 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
721 return -EINVAL;
722
723 if (!nl80211_can_set_dev_channel(wdev))
724 return -EOPNOTSUPP;
725
726 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
727 channel_type = nla_get_u32(info->attrs[
728 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
729 if (channel_type != NL80211_CHAN_NO_HT &&
730 channel_type != NL80211_CHAN_HT20 &&
731 channel_type != NL80211_CHAN_HT40PLUS &&
732 channel_type != NL80211_CHAN_HT40MINUS)
733 return -EINVAL;
734 }
735
736 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
737
738 mutex_lock(&rdev->devlist_mtx);
739 if (wdev) {
740 wdev_lock(wdev);
741 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
742 wdev_unlock(wdev);
743 } else {
744 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
745 }
746 mutex_unlock(&rdev->devlist_mtx);
747
748 return result;
749}
750
751static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
752{
753 struct cfg80211_registered_device *rdev;
754 struct net_device *netdev;
755 int result;
756
757 rtnl_lock();
758
759 result = get_rdev_dev_by_info_ifindex(info, &rdev, &netdev);
760 if (result)
761 goto unlock;
762
763 result = __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
764
765 unlock:
766 rtnl_unlock();
767
768 return result;
769}
770
55682965
JB
771static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
772{
773 struct cfg80211_registered_device *rdev;
f444de05
JB
774 struct net_device *netdev = NULL;
775 struct wireless_dev *wdev;
776 int result, rem_txq_params = 0;
31888487 777 struct nlattr *nl_txq_params;
b9a5f8ca
JM
778 u32 changed;
779 u8 retry_short = 0, retry_long = 0;
780 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 781 u8 coverage_class = 0;
55682965 782
4bbf4d56 783 rtnl_lock();
55682965 784
f444de05
JB
785 /*
786 * Try to find the wiphy and netdev. Normally this
787 * function shouldn't need the netdev, but this is
788 * done for backward compatibility -- previously
789 * setting the channel was done per wiphy, but now
790 * it is per netdev. Previous userland like hostapd
791 * also passed a netdev to set_wiphy, so that it is
792 * possible to let that go to the right netdev!
793 */
4bbf4d56
JB
794 mutex_lock(&cfg80211_mutex);
795
f444de05
JB
796 if (info->attrs[NL80211_ATTR_IFINDEX]) {
797 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
798
799 netdev = dev_get_by_index(genl_info_net(info), ifindex);
800 if (netdev && netdev->ieee80211_ptr) {
801 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
802 mutex_lock(&rdev->mtx);
803 } else
804 netdev = NULL;
4bbf4d56
JB
805 }
806
f444de05
JB
807 if (!netdev) {
808 rdev = __cfg80211_rdev_from_info(info);
809 if (IS_ERR(rdev)) {
810 mutex_unlock(&cfg80211_mutex);
811 result = PTR_ERR(rdev);
812 goto unlock;
813 }
814 wdev = NULL;
815 netdev = NULL;
816 result = 0;
817
818 mutex_lock(&rdev->mtx);
819 } else if (netif_running(netdev) &&
820 nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
821 wdev = netdev->ieee80211_ptr;
822 else
823 wdev = NULL;
824
825 /*
826 * end workaround code, by now the rdev is available
827 * and locked, and wdev may or may not be NULL.
828 */
4bbf4d56
JB
829
830 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
831 result = cfg80211_dev_rename(
832 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
833
834 mutex_unlock(&cfg80211_mutex);
835
836 if (result)
837 goto bad_res;
31888487
JM
838
839 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
840 struct ieee80211_txq_params txq_params;
841 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
842
843 if (!rdev->ops->set_txq_params) {
844 result = -EOPNOTSUPP;
845 goto bad_res;
846 }
847
848 nla_for_each_nested(nl_txq_params,
849 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
850 rem_txq_params) {
851 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
852 nla_data(nl_txq_params),
853 nla_len(nl_txq_params),
854 txq_params_policy);
855 result = parse_txq_params(tb, &txq_params);
856 if (result)
857 goto bad_res;
858
859 result = rdev->ops->set_txq_params(&rdev->wiphy,
860 &txq_params);
861 if (result)
862 goto bad_res;
863 }
864 }
55682965 865
72bdcf34 866 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 867 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
868 if (result)
869 goto bad_res;
870 }
871
b9a5f8ca
JM
872 changed = 0;
873
874 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
875 retry_short = nla_get_u8(
876 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
877 if (retry_short == 0) {
878 result = -EINVAL;
879 goto bad_res;
880 }
881 changed |= WIPHY_PARAM_RETRY_SHORT;
882 }
883
884 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
885 retry_long = nla_get_u8(
886 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
887 if (retry_long == 0) {
888 result = -EINVAL;
889 goto bad_res;
890 }
891 changed |= WIPHY_PARAM_RETRY_LONG;
892 }
893
894 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
895 frag_threshold = nla_get_u32(
896 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
897 if (frag_threshold < 256) {
898 result = -EINVAL;
899 goto bad_res;
900 }
901 if (frag_threshold != (u32) -1) {
902 /*
903 * Fragments (apart from the last one) are required to
904 * have even length. Make the fragmentation code
905 * simpler by stripping LSB should someone try to use
906 * odd threshold value.
907 */
908 frag_threshold &= ~0x1;
909 }
910 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
911 }
912
913 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
914 rts_threshold = nla_get_u32(
915 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
916 changed |= WIPHY_PARAM_RTS_THRESHOLD;
917 }
918
81077e82
LT
919 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
920 coverage_class = nla_get_u8(
921 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
922 changed |= WIPHY_PARAM_COVERAGE_CLASS;
923 }
924
b9a5f8ca
JM
925 if (changed) {
926 u8 old_retry_short, old_retry_long;
927 u32 old_frag_threshold, old_rts_threshold;
81077e82 928 u8 old_coverage_class;
b9a5f8ca
JM
929
930 if (!rdev->ops->set_wiphy_params) {
931 result = -EOPNOTSUPP;
932 goto bad_res;
933 }
934
935 old_retry_short = rdev->wiphy.retry_short;
936 old_retry_long = rdev->wiphy.retry_long;
937 old_frag_threshold = rdev->wiphy.frag_threshold;
938 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 939 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
940
941 if (changed & WIPHY_PARAM_RETRY_SHORT)
942 rdev->wiphy.retry_short = retry_short;
943 if (changed & WIPHY_PARAM_RETRY_LONG)
944 rdev->wiphy.retry_long = retry_long;
945 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
946 rdev->wiphy.frag_threshold = frag_threshold;
947 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
948 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
949 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
950 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
951
952 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
953 if (result) {
954 rdev->wiphy.retry_short = old_retry_short;
955 rdev->wiphy.retry_long = old_retry_long;
956 rdev->wiphy.frag_threshold = old_frag_threshold;
957 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 958 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
959 }
960 }
72bdcf34 961
306d6112 962 bad_res:
4bbf4d56 963 mutex_unlock(&rdev->mtx);
f444de05
JB
964 if (netdev)
965 dev_put(netdev);
4bbf4d56
JB
966 unlock:
967 rtnl_unlock();
55682965
JB
968 return result;
969}
970
971
972static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 973 struct cfg80211_registered_device *rdev,
55682965
JB
974 struct net_device *dev)
975{
976 void *hdr;
977
978 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
979 if (!hdr)
980 return -1;
981
982 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 983 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 984 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 985 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
986
987 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
988 rdev->devlist_generation ^
989 (cfg80211_rdev_list_generation << 2));
990
55682965
JB
991 return genlmsg_end(msg, hdr);
992
993 nla_put_failure:
bc3ed28c
TG
994 genlmsg_cancel(msg, hdr);
995 return -EMSGSIZE;
55682965
JB
996}
997
998static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
999{
1000 int wp_idx = 0;
1001 int if_idx = 0;
1002 int wp_start = cb->args[0];
1003 int if_start = cb->args[1];
f5ea9120 1004 struct cfg80211_registered_device *rdev;
55682965
JB
1005 struct wireless_dev *wdev;
1006
a1794390 1007 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1008 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1009 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1010 continue;
bba95fef
JB
1011 if (wp_idx < wp_start) {
1012 wp_idx++;
55682965 1013 continue;
bba95fef 1014 }
55682965
JB
1015 if_idx = 0;
1016
f5ea9120
JB
1017 mutex_lock(&rdev->devlist_mtx);
1018 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
1019 if (if_idx < if_start) {
1020 if_idx++;
55682965 1021 continue;
bba95fef 1022 }
55682965
JB
1023 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1024 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
1025 rdev, wdev->netdev) < 0) {
1026 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1027 goto out;
1028 }
1029 if_idx++;
55682965 1030 }
f5ea9120 1031 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1032
1033 wp_idx++;
55682965 1034 }
bba95fef 1035 out:
a1794390 1036 mutex_unlock(&cfg80211_mutex);
55682965
JB
1037
1038 cb->args[0] = wp_idx;
1039 cb->args[1] = if_idx;
1040
1041 return skb->len;
1042}
1043
1044static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1045{
1046 struct sk_buff *msg;
1047 struct cfg80211_registered_device *dev;
1048 struct net_device *netdev;
1049 int err;
1050
463d0183 1051 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
1052 if (err)
1053 return err;
1054
fd2120ca 1055 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
1056 if (!msg)
1057 goto out_err;
1058
d726405a
JB
1059 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1060 dev, netdev) < 0)
55682965
JB
1061 goto out_free;
1062
1063 dev_put(netdev);
4d0c8aea 1064 cfg80211_unlock_rdev(dev);
55682965 1065
134e6375 1066 return genlmsg_reply(msg, info);
55682965
JB
1067
1068 out_free:
1069 nlmsg_free(msg);
1070 out_err:
1071 dev_put(netdev);
4d0c8aea 1072 cfg80211_unlock_rdev(dev);
55682965
JB
1073 return -ENOBUFS;
1074}
1075
66f7ac50
MW
1076static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1077 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1078 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1079 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1080 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1081 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1082};
1083
1084static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1085{
1086 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1087 int flag;
1088
1089 *mntrflags = 0;
1090
1091 if (!nla)
1092 return -EINVAL;
1093
1094 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1095 nla, mntr_flags_policy))
1096 return -EINVAL;
1097
1098 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1099 if (flags[flag])
1100 *mntrflags |= (1<<flag);
1101
1102 return 0;
1103}
1104
9bc383de 1105static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1106 struct net_device *netdev, u8 use_4addr,
1107 enum nl80211_iftype iftype)
9bc383de 1108{
ad4bb6f8
JB
1109 if (!use_4addr) {
1110 if (netdev && netdev->br_port)
1111 return -EBUSY;
9bc383de 1112 return 0;
ad4bb6f8 1113 }
9bc383de
JB
1114
1115 switch (iftype) {
1116 case NL80211_IFTYPE_AP_VLAN:
1117 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1118 return 0;
1119 break;
1120 case NL80211_IFTYPE_STATION:
1121 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1122 return 0;
1123 break;
1124 default:
1125 break;
1126 }
1127
1128 return -EOPNOTSUPP;
1129}
1130
55682965
JB
1131static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1132{
79c97e97 1133 struct cfg80211_registered_device *rdev;
2ec600d6 1134 struct vif_params params;
e36d56b6 1135 int err;
04a773ad 1136 enum nl80211_iftype otype, ntype;
55682965 1137 struct net_device *dev;
92ffe055 1138 u32 _flags, *flags = NULL;
ac7f9cfa 1139 bool change = false;
55682965 1140
2ec600d6
LCC
1141 memset(&params, 0, sizeof(params));
1142
3b85875a
JB
1143 rtnl_lock();
1144
463d0183 1145 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1146 if (err)
3b85875a
JB
1147 goto unlock_rtnl;
1148
04a773ad 1149 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1150
723b038d 1151 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1152 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1153 if (otype != ntype)
ac7f9cfa 1154 change = true;
04a773ad 1155 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 1156 err = -EINVAL;
723b038d 1157 goto unlock;
ac7f9cfa 1158 }
723b038d
JB
1159 }
1160
92ffe055 1161 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1162 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1163 err = -EINVAL;
1164 goto unlock;
1165 }
2ec600d6
LCC
1166 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1167 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1168 change = true;
2ec600d6
LCC
1169 }
1170
8b787643
FF
1171 if (info->attrs[NL80211_ATTR_4ADDR]) {
1172 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1173 change = true;
ad4bb6f8 1174 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de
JB
1175 if (err)
1176 goto unlock;
8b787643
FF
1177 } else {
1178 params.use_4addr = -1;
1179 }
1180
92ffe055 1181 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1182 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1183 err = -EINVAL;
1184 goto unlock;
1185 }
1186 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1187 &_flags);
ac7f9cfa
JB
1188 if (err)
1189 goto unlock;
1190
1191 flags = &_flags;
1192 change = true;
92ffe055 1193 }
3b85875a 1194
ac7f9cfa 1195 if (change)
3d54d255 1196 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1197 else
1198 err = 0;
60719ffd 1199
9bc383de
JB
1200 if (!err && params.use_4addr != -1)
1201 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1202
55682965 1203 unlock:
e36d56b6 1204 dev_put(dev);
79c97e97 1205 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1206 unlock_rtnl:
1207 rtnl_unlock();
55682965
JB
1208 return err;
1209}
1210
1211static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1212{
79c97e97 1213 struct cfg80211_registered_device *rdev;
2ec600d6 1214 struct vif_params params;
55682965
JB
1215 int err;
1216 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1217 u32 flags;
55682965 1218
2ec600d6
LCC
1219 memset(&params, 0, sizeof(params));
1220
55682965
JB
1221 if (!info->attrs[NL80211_ATTR_IFNAME])
1222 return -EINVAL;
1223
1224 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1225 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1226 if (type > NL80211_IFTYPE_MAX)
1227 return -EINVAL;
1228 }
1229
3b85875a
JB
1230 rtnl_lock();
1231
79c97e97
JB
1232 rdev = cfg80211_get_dev_from_info(info);
1233 if (IS_ERR(rdev)) {
1234 err = PTR_ERR(rdev);
3b85875a
JB
1235 goto unlock_rtnl;
1236 }
55682965 1237
79c97e97
JB
1238 if (!rdev->ops->add_virtual_intf ||
1239 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1240 err = -EOPNOTSUPP;
1241 goto unlock;
1242 }
1243
2ec600d6
LCC
1244 if (type == NL80211_IFTYPE_MESH_POINT &&
1245 info->attrs[NL80211_ATTR_MESH_ID]) {
1246 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1247 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1248 }
1249
9bc383de 1250 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1251 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1252 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de
JB
1253 if (err)
1254 goto unlock;
1255 }
8b787643 1256
66f7ac50
MW
1257 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1258 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1259 &flags);
79c97e97 1260 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1261 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1262 type, err ? NULL : &flags, &params);
2ec600d6 1263
55682965 1264 unlock:
79c97e97 1265 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1266 unlock_rtnl:
1267 rtnl_unlock();
55682965
JB
1268 return err;
1269}
1270
1271static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1272{
79c97e97 1273 struct cfg80211_registered_device *rdev;
463d0183 1274 int err;
55682965
JB
1275 struct net_device *dev;
1276
3b85875a
JB
1277 rtnl_lock();
1278
463d0183 1279 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1280 if (err)
3b85875a 1281 goto unlock_rtnl;
55682965 1282
79c97e97 1283 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1284 err = -EOPNOTSUPP;
1285 goto out;
1286 }
1287
463d0183 1288 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1289
1290 out:
79c97e97 1291 cfg80211_unlock_rdev(rdev);
463d0183 1292 dev_put(dev);
3b85875a
JB
1293 unlock_rtnl:
1294 rtnl_unlock();
55682965
JB
1295 return err;
1296}
1297
41ade00f
JB
1298struct get_key_cookie {
1299 struct sk_buff *msg;
1300 int error;
b9454e83 1301 int idx;
41ade00f
JB
1302};
1303
1304static void get_key_callback(void *c, struct key_params *params)
1305{
b9454e83 1306 struct nlattr *key;
41ade00f
JB
1307 struct get_key_cookie *cookie = c;
1308
1309 if (params->key)
1310 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1311 params->key_len, params->key);
1312
1313 if (params->seq)
1314 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1315 params->seq_len, params->seq);
1316
1317 if (params->cipher)
1318 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1319 params->cipher);
1320
b9454e83
JB
1321 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1322 if (!key)
1323 goto nla_put_failure;
1324
1325 if (params->key)
1326 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1327 params->key_len, params->key);
1328
1329 if (params->seq)
1330 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1331 params->seq_len, params->seq);
1332
1333 if (params->cipher)
1334 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1335 params->cipher);
1336
1337 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1338
1339 nla_nest_end(cookie->msg, key);
1340
41ade00f
JB
1341 return;
1342 nla_put_failure:
1343 cookie->error = 1;
1344}
1345
1346static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1347{
79c97e97 1348 struct cfg80211_registered_device *rdev;
41ade00f
JB
1349 int err;
1350 struct net_device *dev;
1351 u8 key_idx = 0;
1352 u8 *mac_addr = NULL;
1353 struct get_key_cookie cookie = {
1354 .error = 0,
1355 };
1356 void *hdr;
1357 struct sk_buff *msg;
1358
1359 if (info->attrs[NL80211_ATTR_KEY_IDX])
1360 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1361
3cfcf6ac 1362 if (key_idx > 5)
41ade00f
JB
1363 return -EINVAL;
1364
1365 if (info->attrs[NL80211_ATTR_MAC])
1366 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1367
3b85875a
JB
1368 rtnl_lock();
1369
463d0183 1370 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1371 if (err)
3b85875a 1372 goto unlock_rtnl;
41ade00f 1373
79c97e97 1374 if (!rdev->ops->get_key) {
41ade00f
JB
1375 err = -EOPNOTSUPP;
1376 goto out;
1377 }
1378
fd2120ca 1379 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1380 if (!msg) {
1381 err = -ENOMEM;
1382 goto out;
1383 }
1384
1385 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1386 NL80211_CMD_NEW_KEY);
1387
1388 if (IS_ERR(hdr)) {
1389 err = PTR_ERR(hdr);
6c95e2a2 1390 goto free_msg;
41ade00f
JB
1391 }
1392
1393 cookie.msg = msg;
b9454e83 1394 cookie.idx = key_idx;
41ade00f
JB
1395
1396 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1397 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1398 if (mac_addr)
1399 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1400
79c97e97 1401 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1402 &cookie, get_key_callback);
41ade00f
JB
1403
1404 if (err)
6c95e2a2 1405 goto free_msg;
41ade00f
JB
1406
1407 if (cookie.error)
1408 goto nla_put_failure;
1409
1410 genlmsg_end(msg, hdr);
134e6375 1411 err = genlmsg_reply(msg, info);
41ade00f
JB
1412 goto out;
1413
1414 nla_put_failure:
1415 err = -ENOBUFS;
6c95e2a2 1416 free_msg:
41ade00f
JB
1417 nlmsg_free(msg);
1418 out:
79c97e97 1419 cfg80211_unlock_rdev(rdev);
41ade00f 1420 dev_put(dev);
3b85875a
JB
1421 unlock_rtnl:
1422 rtnl_unlock();
1423
41ade00f
JB
1424 return err;
1425}
1426
1427static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1428{
79c97e97 1429 struct cfg80211_registered_device *rdev;
b9454e83 1430 struct key_parse key;
41ade00f
JB
1431 int err;
1432 struct net_device *dev;
3cfcf6ac
JM
1433 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1434 u8 key_index);
41ade00f 1435
b9454e83
JB
1436 err = nl80211_parse_key(info, &key);
1437 if (err)
1438 return err;
41ade00f 1439
b9454e83 1440 if (key.idx < 0)
41ade00f
JB
1441 return -EINVAL;
1442
b9454e83
JB
1443 /* only support setting default key */
1444 if (!key.def && !key.defmgmt)
41ade00f
JB
1445 return -EINVAL;
1446
3b85875a
JB
1447 rtnl_lock();
1448
463d0183 1449 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1450 if (err)
3b85875a 1451 goto unlock_rtnl;
41ade00f 1452
b9454e83 1453 if (key.def)
79c97e97 1454 func = rdev->ops->set_default_key;
3cfcf6ac 1455 else
79c97e97 1456 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1457
1458 if (!func) {
41ade00f
JB
1459 err = -EOPNOTSUPP;
1460 goto out;
1461 }
1462
fffd0934
JB
1463 wdev_lock(dev->ieee80211_ptr);
1464 err = nl80211_key_allowed(dev->ieee80211_ptr);
1465 if (!err)
1466 err = func(&rdev->wiphy, dev, key.idx);
1467
3d23e349 1468#ifdef CONFIG_CFG80211_WEXT
08645126 1469 if (!err) {
79c97e97 1470 if (func == rdev->ops->set_default_key)
b9454e83 1471 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1472 else
b9454e83 1473 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1474 }
1475#endif
fffd0934 1476 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1477
1478 out:
79c97e97 1479 cfg80211_unlock_rdev(rdev);
41ade00f 1480 dev_put(dev);
3b85875a
JB
1481
1482 unlock_rtnl:
1483 rtnl_unlock();
1484
41ade00f
JB
1485 return err;
1486}
1487
1488static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1489{
79c97e97 1490 struct cfg80211_registered_device *rdev;
fffd0934 1491 int err;
41ade00f 1492 struct net_device *dev;
b9454e83 1493 struct key_parse key;
41ade00f
JB
1494 u8 *mac_addr = NULL;
1495
b9454e83
JB
1496 err = nl80211_parse_key(info, &key);
1497 if (err)
1498 return err;
41ade00f 1499
b9454e83 1500 if (!key.p.key)
41ade00f
JB
1501 return -EINVAL;
1502
41ade00f
JB
1503 if (info->attrs[NL80211_ATTR_MAC])
1504 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1505
3b85875a
JB
1506 rtnl_lock();
1507
463d0183 1508 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1509 if (err)
3b85875a 1510 goto unlock_rtnl;
41ade00f 1511
fffd0934
JB
1512 if (!rdev->ops->add_key) {
1513 err = -EOPNOTSUPP;
25e47c18
JB
1514 goto out;
1515 }
1516
fffd0934
JB
1517 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1518 err = -EINVAL;
41ade00f
JB
1519 goto out;
1520 }
1521
fffd0934
JB
1522 wdev_lock(dev->ieee80211_ptr);
1523 err = nl80211_key_allowed(dev->ieee80211_ptr);
1524 if (!err)
1525 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1526 mac_addr, &key.p);
1527 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1528
1529 out:
79c97e97 1530 cfg80211_unlock_rdev(rdev);
41ade00f 1531 dev_put(dev);
3b85875a
JB
1532 unlock_rtnl:
1533 rtnl_unlock();
1534
41ade00f
JB
1535 return err;
1536}
1537
1538static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1539{
79c97e97 1540 struct cfg80211_registered_device *rdev;
41ade00f
JB
1541 int err;
1542 struct net_device *dev;
41ade00f 1543 u8 *mac_addr = NULL;
b9454e83 1544 struct key_parse key;
41ade00f 1545
b9454e83
JB
1546 err = nl80211_parse_key(info, &key);
1547 if (err)
1548 return err;
41ade00f
JB
1549
1550 if (info->attrs[NL80211_ATTR_MAC])
1551 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1552
3b85875a
JB
1553 rtnl_lock();
1554
463d0183 1555 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1556 if (err)
3b85875a 1557 goto unlock_rtnl;
41ade00f 1558
79c97e97 1559 if (!rdev->ops->del_key) {
41ade00f
JB
1560 err = -EOPNOTSUPP;
1561 goto out;
1562 }
1563
fffd0934
JB
1564 wdev_lock(dev->ieee80211_ptr);
1565 err = nl80211_key_allowed(dev->ieee80211_ptr);
1566 if (!err)
1567 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1568
3d23e349 1569#ifdef CONFIG_CFG80211_WEXT
08645126 1570 if (!err) {
b9454e83 1571 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1572 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1573 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1574 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1575 }
1576#endif
fffd0934 1577 wdev_unlock(dev->ieee80211_ptr);
08645126 1578
41ade00f 1579 out:
79c97e97 1580 cfg80211_unlock_rdev(rdev);
41ade00f 1581 dev_put(dev);
3b85875a
JB
1582
1583 unlock_rtnl:
1584 rtnl_unlock();
1585
41ade00f
JB
1586 return err;
1587}
1588
ed1b6cc7
JB
1589static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1590{
1591 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1592 struct beacon_parameters *info);
79c97e97 1593 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1594 int err;
1595 struct net_device *dev;
1596 struct beacon_parameters params;
1597 int haveinfo = 0;
1598
f4a11bb0
JB
1599 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1600 return -EINVAL;
1601
3b85875a
JB
1602 rtnl_lock();
1603
463d0183 1604 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1605 if (err)
3b85875a 1606 goto unlock_rtnl;
ed1b6cc7 1607
eec60b03
JM
1608 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1609 err = -EOPNOTSUPP;
1610 goto out;
1611 }
1612
ed1b6cc7
JB
1613 switch (info->genlhdr->cmd) {
1614 case NL80211_CMD_NEW_BEACON:
1615 /* these are required for NEW_BEACON */
1616 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1617 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1618 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1619 err = -EINVAL;
1620 goto out;
1621 }
1622
79c97e97 1623 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1624 break;
1625 case NL80211_CMD_SET_BEACON:
79c97e97 1626 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1627 break;
1628 default:
1629 WARN_ON(1);
1630 err = -EOPNOTSUPP;
1631 goto out;
1632 }
1633
1634 if (!call) {
1635 err = -EOPNOTSUPP;
1636 goto out;
1637 }
1638
1639 memset(&params, 0, sizeof(params));
1640
1641 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1642 params.interval =
1643 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1644 haveinfo = 1;
1645 }
1646
1647 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1648 params.dtim_period =
1649 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1650 haveinfo = 1;
1651 }
1652
1653 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1654 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1655 params.head_len =
1656 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1657 haveinfo = 1;
1658 }
1659
1660 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1661 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1662 params.tail_len =
1663 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1664 haveinfo = 1;
1665 }
1666
1667 if (!haveinfo) {
1668 err = -EINVAL;
1669 goto out;
1670 }
1671
79c97e97 1672 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1673
1674 out:
79c97e97 1675 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1676 dev_put(dev);
3b85875a
JB
1677 unlock_rtnl:
1678 rtnl_unlock();
1679
ed1b6cc7
JB
1680 return err;
1681}
1682
1683static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1684{
79c97e97 1685 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1686 int err;
1687 struct net_device *dev;
1688
3b85875a
JB
1689 rtnl_lock();
1690
463d0183 1691 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1692 if (err)
3b85875a 1693 goto unlock_rtnl;
ed1b6cc7 1694
79c97e97 1695 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1696 err = -EOPNOTSUPP;
1697 goto out;
1698 }
1699
eec60b03
JM
1700 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1701 err = -EOPNOTSUPP;
1702 goto out;
1703 }
79c97e97 1704 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1705
1706 out:
79c97e97 1707 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1708 dev_put(dev);
3b85875a
JB
1709 unlock_rtnl:
1710 rtnl_unlock();
1711
ed1b6cc7
JB
1712 return err;
1713}
1714
5727ef1b
JB
1715static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1716 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1717 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1718 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1719 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1720};
1721
eccb8e8f
JB
1722static int parse_station_flags(struct genl_info *info,
1723 struct station_parameters *params)
5727ef1b
JB
1724{
1725 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1726 struct nlattr *nla;
5727ef1b
JB
1727 int flag;
1728
eccb8e8f
JB
1729 /*
1730 * Try parsing the new attribute first so userspace
1731 * can specify both for older kernels.
1732 */
1733 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1734 if (nla) {
1735 struct nl80211_sta_flag_update *sta_flags;
1736
1737 sta_flags = nla_data(nla);
1738 params->sta_flags_mask = sta_flags->mask;
1739 params->sta_flags_set = sta_flags->set;
1740 if ((params->sta_flags_mask |
1741 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1742 return -EINVAL;
1743 return 0;
1744 }
1745
1746 /* if present, parse the old attribute */
5727ef1b 1747
eccb8e8f 1748 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1749 if (!nla)
1750 return 0;
1751
1752 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1753 nla, sta_flags_policy))
1754 return -EINVAL;
1755
eccb8e8f
JB
1756 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1757 params->sta_flags_mask &= ~1;
5727ef1b
JB
1758
1759 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1760 if (flags[flag])
eccb8e8f 1761 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1762
1763 return 0;
1764}
1765
fd5b74dc
JB
1766static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1767 int flags, struct net_device *dev,
98b62183 1768 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1769{
1770 void *hdr;
420e7fab
HR
1771 struct nlattr *sinfoattr, *txrate;
1772 u16 bitrate;
fd5b74dc
JB
1773
1774 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1775 if (!hdr)
1776 return -1;
1777
1778 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1779 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1780
f5ea9120
JB
1781 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1782
2ec600d6
LCC
1783 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1784 if (!sinfoattr)
fd5b74dc 1785 goto nla_put_failure;
2ec600d6
LCC
1786 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1787 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1788 sinfo->inactive_time);
1789 if (sinfo->filled & STATION_INFO_RX_BYTES)
1790 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1791 sinfo->rx_bytes);
1792 if (sinfo->filled & STATION_INFO_TX_BYTES)
1793 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1794 sinfo->tx_bytes);
1795 if (sinfo->filled & STATION_INFO_LLID)
1796 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1797 sinfo->llid);
1798 if (sinfo->filled & STATION_INFO_PLID)
1799 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1800 sinfo->plid);
1801 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1802 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1803 sinfo->plink_state);
420e7fab
HR
1804 if (sinfo->filled & STATION_INFO_SIGNAL)
1805 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1806 sinfo->signal);
1807 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1808 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1809 if (!txrate)
1810 goto nla_put_failure;
1811
254416aa
JL
1812 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1813 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
1814 if (bitrate > 0)
1815 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1816
420e7fab
HR
1817 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1818 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1819 sinfo->txrate.mcs);
1820 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1821 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1822 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1823 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1824
1825 nla_nest_end(msg, txrate);
1826 }
98c8a60a
JM
1827 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1828 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1829 sinfo->rx_packets);
1830 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1831 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1832 sinfo->tx_packets);
2ec600d6 1833 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1834
1835 return genlmsg_end(msg, hdr);
1836
1837 nla_put_failure:
bc3ed28c
TG
1838 genlmsg_cancel(msg, hdr);
1839 return -EMSGSIZE;
fd5b74dc
JB
1840}
1841
2ec600d6 1842static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1843 struct netlink_callback *cb)
2ec600d6 1844{
2ec600d6
LCC
1845 struct station_info sinfo;
1846 struct cfg80211_registered_device *dev;
bba95fef 1847 struct net_device *netdev;
2ec600d6 1848 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1849 int ifidx = cb->args[0];
1850 int sta_idx = cb->args[1];
2ec600d6 1851 int err;
2ec600d6 1852
a043897a
HS
1853 if (!ifidx)
1854 ifidx = nl80211_get_ifidx(cb);
1855 if (ifidx < 0)
1856 return ifidx;
2ec600d6 1857
3b85875a
JB
1858 rtnl_lock();
1859
463d0183 1860 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1861 if (!netdev) {
1862 err = -ENODEV;
1863 goto out_rtnl;
1864 }
2ec600d6 1865
463d0183 1866 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1867 if (IS_ERR(dev)) {
1868 err = PTR_ERR(dev);
3b85875a 1869 goto out_rtnl;
bba95fef
JB
1870 }
1871
1872 if (!dev->ops->dump_station) {
eec60b03 1873 err = -EOPNOTSUPP;
bba95fef
JB
1874 goto out_err;
1875 }
1876
bba95fef
JB
1877 while (1) {
1878 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1879 mac_addr, &sinfo);
1880 if (err == -ENOENT)
1881 break;
1882 if (err)
3b85875a 1883 goto out_err;
bba95fef
JB
1884
1885 if (nl80211_send_station(skb,
1886 NETLINK_CB(cb->skb).pid,
1887 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1888 netdev, mac_addr,
1889 &sinfo) < 0)
1890 goto out;
1891
1892 sta_idx++;
1893 }
1894
1895
1896 out:
1897 cb->args[1] = sta_idx;
1898 err = skb->len;
bba95fef 1899 out_err:
4d0c8aea 1900 cfg80211_unlock_rdev(dev);
3b85875a
JB
1901 out_rtnl:
1902 rtnl_unlock();
bba95fef
JB
1903
1904 return err;
2ec600d6 1905}
fd5b74dc 1906
5727ef1b
JB
1907static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1908{
79c97e97 1909 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1910 int err;
1911 struct net_device *dev;
2ec600d6 1912 struct station_info sinfo;
fd5b74dc
JB
1913 struct sk_buff *msg;
1914 u8 *mac_addr = NULL;
1915
2ec600d6 1916 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1917
1918 if (!info->attrs[NL80211_ATTR_MAC])
1919 return -EINVAL;
1920
1921 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1922
3b85875a
JB
1923 rtnl_lock();
1924
463d0183 1925 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 1926 if (err)
3b85875a 1927 goto out_rtnl;
fd5b74dc 1928
79c97e97 1929 if (!rdev->ops->get_station) {
fd5b74dc
JB
1930 err = -EOPNOTSUPP;
1931 goto out;
1932 }
1933
79c97e97 1934 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1935 if (err)
1936 goto out;
1937
fd2120ca 1938 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1939 if (!msg)
1940 goto out;
1941
1942 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1943 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1944 goto out_free;
1945
134e6375 1946 err = genlmsg_reply(msg, info);
fd5b74dc
JB
1947 goto out;
1948
1949 out_free:
1950 nlmsg_free(msg);
fd5b74dc 1951 out:
79c97e97 1952 cfg80211_unlock_rdev(rdev);
fd5b74dc 1953 dev_put(dev);
3b85875a
JB
1954 out_rtnl:
1955 rtnl_unlock();
1956
fd5b74dc 1957 return err;
5727ef1b
JB
1958}
1959
1960/*
c258d2de 1961 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 1962 */
463d0183 1963static int get_vlan(struct genl_info *info,
5727ef1b
JB
1964 struct cfg80211_registered_device *rdev,
1965 struct net_device **vlan)
1966{
463d0183 1967 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
1968 *vlan = NULL;
1969
1970 if (vlanattr) {
463d0183
JB
1971 *vlan = dev_get_by_index(genl_info_net(info),
1972 nla_get_u32(vlanattr));
5727ef1b
JB
1973 if (!*vlan)
1974 return -ENODEV;
1975 if (!(*vlan)->ieee80211_ptr)
1976 return -EINVAL;
1977 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1978 return -EINVAL;
c258d2de
FF
1979 if (!netif_running(*vlan))
1980 return -ENETDOWN;
5727ef1b
JB
1981 }
1982 return 0;
1983}
1984
1985static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1986{
79c97e97 1987 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1988 int err;
1989 struct net_device *dev;
1990 struct station_parameters params;
1991 u8 *mac_addr = NULL;
1992
1993 memset(&params, 0, sizeof(params));
1994
1995 params.listen_interval = -1;
1996
1997 if (info->attrs[NL80211_ATTR_STA_AID])
1998 return -EINVAL;
1999
2000 if (!info->attrs[NL80211_ATTR_MAC])
2001 return -EINVAL;
2002
2003 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2004
2005 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2006 params.supported_rates =
2007 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2008 params.supported_rates_len =
2009 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2010 }
2011
2012 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2013 params.listen_interval =
2014 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2015
36aedc90
JM
2016 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2017 params.ht_capa =
2018 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2019
eccb8e8f 2020 if (parse_station_flags(info, &params))
5727ef1b
JB
2021 return -EINVAL;
2022
2ec600d6
LCC
2023 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2024 params.plink_action =
2025 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2026
3b85875a
JB
2027 rtnl_lock();
2028
463d0183 2029 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2030 if (err)
3b85875a 2031 goto out_rtnl;
5727ef1b 2032
463d0183 2033 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2034 if (err)
034d655e 2035 goto out;
a97f4424
JB
2036
2037 /* validate settings */
2038 err = 0;
2039
2040 switch (dev->ieee80211_ptr->iftype) {
2041 case NL80211_IFTYPE_AP:
2042 case NL80211_IFTYPE_AP_VLAN:
2043 /* disallow mesh-specific things */
2044 if (params.plink_action)
2045 err = -EINVAL;
2046 break;
2047 case NL80211_IFTYPE_STATION:
2048 /* disallow everything but AUTHORIZED flag */
2049 if (params.plink_action)
2050 err = -EINVAL;
2051 if (params.vlan)
2052 err = -EINVAL;
2053 if (params.supported_rates)
2054 err = -EINVAL;
2055 if (params.ht_capa)
2056 err = -EINVAL;
2057 if (params.listen_interval >= 0)
2058 err = -EINVAL;
2059 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2060 err = -EINVAL;
2061 break;
2062 case NL80211_IFTYPE_MESH_POINT:
2063 /* disallow things mesh doesn't support */
2064 if (params.vlan)
2065 err = -EINVAL;
2066 if (params.ht_capa)
2067 err = -EINVAL;
2068 if (params.listen_interval >= 0)
2069 err = -EINVAL;
2070 if (params.supported_rates)
2071 err = -EINVAL;
2072 if (params.sta_flags_mask)
2073 err = -EINVAL;
2074 break;
2075 default:
2076 err = -EINVAL;
034d655e
JB
2077 }
2078
5727ef1b
JB
2079 if (err)
2080 goto out;
2081
79c97e97 2082 if (!rdev->ops->change_station) {
5727ef1b
JB
2083 err = -EOPNOTSUPP;
2084 goto out;
2085 }
2086
79c97e97 2087 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2088
2089 out:
2090 if (params.vlan)
2091 dev_put(params.vlan);
79c97e97 2092 cfg80211_unlock_rdev(rdev);
5727ef1b 2093 dev_put(dev);
3b85875a
JB
2094 out_rtnl:
2095 rtnl_unlock();
2096
5727ef1b
JB
2097 return err;
2098}
2099
2100static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2101{
79c97e97 2102 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2103 int err;
2104 struct net_device *dev;
2105 struct station_parameters params;
2106 u8 *mac_addr = NULL;
2107
2108 memset(&params, 0, sizeof(params));
2109
2110 if (!info->attrs[NL80211_ATTR_MAC])
2111 return -EINVAL;
2112
5727ef1b
JB
2113 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2114 return -EINVAL;
2115
2116 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2117 return -EINVAL;
2118
0e956c13
TLSC
2119 if (!info->attrs[NL80211_ATTR_STA_AID])
2120 return -EINVAL;
2121
5727ef1b
JB
2122 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2123 params.supported_rates =
2124 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2125 params.supported_rates_len =
2126 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2127 params.listen_interval =
2128 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2129
0e956c13
TLSC
2130 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2131 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2132 return -EINVAL;
51b50fbe 2133
36aedc90
JM
2134 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2135 params.ht_capa =
2136 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2137
eccb8e8f 2138 if (parse_station_flags(info, &params))
5727ef1b
JB
2139 return -EINVAL;
2140
3b85875a
JB
2141 rtnl_lock();
2142
463d0183 2143 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2144 if (err)
3b85875a 2145 goto out_rtnl;
5727ef1b 2146
0e956c13
TLSC
2147 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2148 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN) {
2149 err = -EINVAL;
2150 goto out;
2151 }
2152
463d0183 2153 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2154 if (err)
e80cf853 2155 goto out;
a97f4424
JB
2156
2157 /* validate settings */
2158 err = 0;
2159
79c97e97 2160 if (!rdev->ops->add_station) {
5727ef1b
JB
2161 err = -EOPNOTSUPP;
2162 goto out;
2163 }
2164
35a8efe1
JM
2165 if (!netif_running(dev)) {
2166 err = -ENETDOWN;
2167 goto out;
2168 }
2169
79c97e97 2170 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2171
2172 out:
2173 if (params.vlan)
2174 dev_put(params.vlan);
79c97e97 2175 cfg80211_unlock_rdev(rdev);
5727ef1b 2176 dev_put(dev);
3b85875a
JB
2177 out_rtnl:
2178 rtnl_unlock();
2179
5727ef1b
JB
2180 return err;
2181}
2182
2183static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2184{
79c97e97 2185 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2186 int err;
2187 struct net_device *dev;
2188 u8 *mac_addr = NULL;
2189
2190 if (info->attrs[NL80211_ATTR_MAC])
2191 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2192
3b85875a
JB
2193 rtnl_lock();
2194
463d0183 2195 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2196 if (err)
3b85875a 2197 goto out_rtnl;
5727ef1b 2198
e80cf853 2199 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02
MP
2200 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2201 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2202 err = -EINVAL;
2203 goto out;
2204 }
2205
79c97e97 2206 if (!rdev->ops->del_station) {
5727ef1b
JB
2207 err = -EOPNOTSUPP;
2208 goto out;
2209 }
2210
79c97e97 2211 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2212
2213 out:
79c97e97 2214 cfg80211_unlock_rdev(rdev);
5727ef1b 2215 dev_put(dev);
3b85875a
JB
2216 out_rtnl:
2217 rtnl_unlock();
2218
5727ef1b
JB
2219 return err;
2220}
2221
2ec600d6
LCC
2222static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2223 int flags, struct net_device *dev,
2224 u8 *dst, u8 *next_hop,
2225 struct mpath_info *pinfo)
2226{
2227 void *hdr;
2228 struct nlattr *pinfoattr;
2229
2230 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2231 if (!hdr)
2232 return -1;
2233
2234 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2235 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2236 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2237
f5ea9120
JB
2238 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2239
2ec600d6
LCC
2240 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2241 if (!pinfoattr)
2242 goto nla_put_failure;
2243 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2244 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2245 pinfo->frame_qlen);
d19b3bf6
RP
2246 if (pinfo->filled & MPATH_INFO_SN)
2247 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2248 pinfo->sn);
2ec600d6
LCC
2249 if (pinfo->filled & MPATH_INFO_METRIC)
2250 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2251 pinfo->metric);
2252 if (pinfo->filled & MPATH_INFO_EXPTIME)
2253 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2254 pinfo->exptime);
2255 if (pinfo->filled & MPATH_INFO_FLAGS)
2256 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2257 pinfo->flags);
2258 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2259 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2260 pinfo->discovery_timeout);
2261 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2262 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2263 pinfo->discovery_retries);
2264
2265 nla_nest_end(msg, pinfoattr);
2266
2267 return genlmsg_end(msg, hdr);
2268
2269 nla_put_failure:
bc3ed28c
TG
2270 genlmsg_cancel(msg, hdr);
2271 return -EMSGSIZE;
2ec600d6
LCC
2272}
2273
2274static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2275 struct netlink_callback *cb)
2ec600d6 2276{
2ec600d6
LCC
2277 struct mpath_info pinfo;
2278 struct cfg80211_registered_device *dev;
bba95fef 2279 struct net_device *netdev;
2ec600d6
LCC
2280 u8 dst[ETH_ALEN];
2281 u8 next_hop[ETH_ALEN];
bba95fef
JB
2282 int ifidx = cb->args[0];
2283 int path_idx = cb->args[1];
2ec600d6 2284 int err;
2ec600d6 2285
a043897a
HS
2286 if (!ifidx)
2287 ifidx = nl80211_get_ifidx(cb);
2288 if (ifidx < 0)
2289 return ifidx;
bba95fef 2290
3b85875a
JB
2291 rtnl_lock();
2292
463d0183 2293 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2294 if (!netdev) {
2295 err = -ENODEV;
2296 goto out_rtnl;
2297 }
bba95fef 2298
463d0183 2299 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2300 if (IS_ERR(dev)) {
2301 err = PTR_ERR(dev);
3b85875a 2302 goto out_rtnl;
bba95fef
JB
2303 }
2304
2305 if (!dev->ops->dump_mpath) {
eec60b03 2306 err = -EOPNOTSUPP;
bba95fef
JB
2307 goto out_err;
2308 }
2309
eec60b03
JM
2310 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2311 err = -EOPNOTSUPP;
0448b5fc 2312 goto out_err;
eec60b03
JM
2313 }
2314
bba95fef
JB
2315 while (1) {
2316 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2317 dst, next_hop, &pinfo);
2318 if (err == -ENOENT)
2ec600d6 2319 break;
bba95fef 2320 if (err)
3b85875a 2321 goto out_err;
2ec600d6 2322
bba95fef
JB
2323 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2324 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2325 netdev, dst, next_hop,
2326 &pinfo) < 0)
2327 goto out;
2ec600d6 2328
bba95fef 2329 path_idx++;
2ec600d6 2330 }
2ec600d6 2331
2ec600d6 2332
bba95fef
JB
2333 out:
2334 cb->args[1] = path_idx;
2335 err = skb->len;
bba95fef 2336 out_err:
4d0c8aea 2337 cfg80211_unlock_rdev(dev);
3b85875a
JB
2338 out_rtnl:
2339 rtnl_unlock();
bba95fef
JB
2340
2341 return err;
2ec600d6
LCC
2342}
2343
2344static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2345{
79c97e97 2346 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2347 int err;
2348 struct net_device *dev;
2349 struct mpath_info pinfo;
2350 struct sk_buff *msg;
2351 u8 *dst = NULL;
2352 u8 next_hop[ETH_ALEN];
2353
2354 memset(&pinfo, 0, sizeof(pinfo));
2355
2356 if (!info->attrs[NL80211_ATTR_MAC])
2357 return -EINVAL;
2358
2359 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2360
3b85875a
JB
2361 rtnl_lock();
2362
463d0183 2363 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2364 if (err)
3b85875a 2365 goto out_rtnl;
2ec600d6 2366
79c97e97 2367 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2368 err = -EOPNOTSUPP;
2369 goto out;
2370 }
2371
eec60b03
JM
2372 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2373 err = -EOPNOTSUPP;
2374 goto out;
2375 }
2376
79c97e97 2377 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2378 if (err)
2379 goto out;
2380
fd2120ca 2381 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2382 if (!msg)
2383 goto out;
2384
2385 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2386 dev, dst, next_hop, &pinfo) < 0)
2387 goto out_free;
2388
134e6375 2389 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2390 goto out;
2391
2392 out_free:
2393 nlmsg_free(msg);
2ec600d6 2394 out:
79c97e97 2395 cfg80211_unlock_rdev(rdev);
2ec600d6 2396 dev_put(dev);
3b85875a
JB
2397 out_rtnl:
2398 rtnl_unlock();
2399
2ec600d6
LCC
2400 return err;
2401}
2402
2403static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2404{
79c97e97 2405 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2406 int err;
2407 struct net_device *dev;
2408 u8 *dst = NULL;
2409 u8 *next_hop = NULL;
2410
2411 if (!info->attrs[NL80211_ATTR_MAC])
2412 return -EINVAL;
2413
2414 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2415 return -EINVAL;
2416
2417 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2418 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2419
3b85875a
JB
2420 rtnl_lock();
2421
463d0183 2422 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2423 if (err)
3b85875a 2424 goto out_rtnl;
2ec600d6 2425
79c97e97 2426 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2427 err = -EOPNOTSUPP;
2428 goto out;
2429 }
2430
eec60b03
JM
2431 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2432 err = -EOPNOTSUPP;
2433 goto out;
2434 }
2435
35a8efe1
JM
2436 if (!netif_running(dev)) {
2437 err = -ENETDOWN;
2438 goto out;
2439 }
2440
79c97e97 2441 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2442
2443 out:
79c97e97 2444 cfg80211_unlock_rdev(rdev);
2ec600d6 2445 dev_put(dev);
3b85875a
JB
2446 out_rtnl:
2447 rtnl_unlock();
2448
2ec600d6
LCC
2449 return err;
2450}
2451static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2452{
79c97e97 2453 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2454 int err;
2455 struct net_device *dev;
2456 u8 *dst = NULL;
2457 u8 *next_hop = NULL;
2458
2459 if (!info->attrs[NL80211_ATTR_MAC])
2460 return -EINVAL;
2461
2462 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2463 return -EINVAL;
2464
2465 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2466 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2467
3b85875a
JB
2468 rtnl_lock();
2469
463d0183 2470 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2471 if (err)
3b85875a 2472 goto out_rtnl;
2ec600d6 2473
79c97e97 2474 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2475 err = -EOPNOTSUPP;
2476 goto out;
2477 }
2478
eec60b03
JM
2479 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2480 err = -EOPNOTSUPP;
2481 goto out;
2482 }
2483
35a8efe1
JM
2484 if (!netif_running(dev)) {
2485 err = -ENETDOWN;
2486 goto out;
2487 }
2488
79c97e97 2489 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2490
2491 out:
79c97e97 2492 cfg80211_unlock_rdev(rdev);
2ec600d6 2493 dev_put(dev);
3b85875a
JB
2494 out_rtnl:
2495 rtnl_unlock();
2496
2ec600d6
LCC
2497 return err;
2498}
2499
2500static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2501{
79c97e97 2502 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2503 int err;
2504 struct net_device *dev;
2505 u8 *dst = NULL;
2506
2507 if (info->attrs[NL80211_ATTR_MAC])
2508 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2509
3b85875a
JB
2510 rtnl_lock();
2511
463d0183 2512 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2513 if (err)
3b85875a 2514 goto out_rtnl;
2ec600d6 2515
79c97e97 2516 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2517 err = -EOPNOTSUPP;
2518 goto out;
2519 }
2520
79c97e97 2521 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2522
2523 out:
79c97e97 2524 cfg80211_unlock_rdev(rdev);
2ec600d6 2525 dev_put(dev);
3b85875a
JB
2526 out_rtnl:
2527 rtnl_unlock();
2528
2ec600d6
LCC
2529 return err;
2530}
2531
9f1ba906
JM
2532static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2533{
79c97e97 2534 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2535 int err;
2536 struct net_device *dev;
2537 struct bss_parameters params;
2538
2539 memset(&params, 0, sizeof(params));
2540 /* default to not changing parameters */
2541 params.use_cts_prot = -1;
2542 params.use_short_preamble = -1;
2543 params.use_short_slot_time = -1;
fd8aaaf3 2544 params.ap_isolate = -1;
9f1ba906
JM
2545
2546 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2547 params.use_cts_prot =
2548 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2549 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2550 params.use_short_preamble =
2551 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2552 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2553 params.use_short_slot_time =
2554 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2555 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2556 params.basic_rates =
2557 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2558 params.basic_rates_len =
2559 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2560 }
fd8aaaf3
FF
2561 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2562 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
9f1ba906 2563
3b85875a
JB
2564 rtnl_lock();
2565
463d0183 2566 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2567 if (err)
3b85875a 2568 goto out_rtnl;
9f1ba906 2569
79c97e97 2570 if (!rdev->ops->change_bss) {
9f1ba906
JM
2571 err = -EOPNOTSUPP;
2572 goto out;
2573 }
2574
eec60b03
JM
2575 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2576 err = -EOPNOTSUPP;
2577 goto out;
2578 }
2579
79c97e97 2580 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2581
2582 out:
79c97e97 2583 cfg80211_unlock_rdev(rdev);
9f1ba906 2584 dev_put(dev);
3b85875a
JB
2585 out_rtnl:
2586 rtnl_unlock();
2587
9f1ba906
JM
2588 return err;
2589}
2590
b54452b0 2591static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
2592 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2593 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2594 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2595 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2596 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2597 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2598};
2599
2600static int parse_reg_rule(struct nlattr *tb[],
2601 struct ieee80211_reg_rule *reg_rule)
2602{
2603 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2604 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2605
2606 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2607 return -EINVAL;
2608 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2609 return -EINVAL;
2610 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2611 return -EINVAL;
2612 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2613 return -EINVAL;
2614 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2615 return -EINVAL;
2616
2617 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2618
2619 freq_range->start_freq_khz =
2620 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2621 freq_range->end_freq_khz =
2622 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2623 freq_range->max_bandwidth_khz =
2624 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2625
2626 power_rule->max_eirp =
2627 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2628
2629 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2630 power_rule->max_antenna_gain =
2631 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2632
2633 return 0;
2634}
2635
2636static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2637{
2638 int r;
2639 char *data = NULL;
2640
80778f18
LR
2641 /*
2642 * You should only get this when cfg80211 hasn't yet initialized
2643 * completely when built-in to the kernel right between the time
2644 * window between nl80211_init() and regulatory_init(), if that is
2645 * even possible.
2646 */
2647 mutex_lock(&cfg80211_mutex);
2648 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2649 mutex_unlock(&cfg80211_mutex);
2650 return -EINPROGRESS;
80778f18 2651 }
fe33eb39 2652 mutex_unlock(&cfg80211_mutex);
80778f18 2653
fe33eb39
LR
2654 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2655 return -EINVAL;
b2e1b302
LR
2656
2657 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2658
fe33eb39
LR
2659 r = regulatory_hint_user(data);
2660
b2e1b302
LR
2661 return r;
2662}
2663
93da9cc1 2664static int nl80211_get_mesh_params(struct sk_buff *skb,
2665 struct genl_info *info)
2666{
79c97e97 2667 struct cfg80211_registered_device *rdev;
93da9cc1 2668 struct mesh_config cur_params;
2669 int err;
2670 struct net_device *dev;
2671 void *hdr;
2672 struct nlattr *pinfoattr;
2673 struct sk_buff *msg;
2674
3b85875a
JB
2675 rtnl_lock();
2676
93da9cc1 2677 /* Look up our device */
463d0183 2678 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2679 if (err)
3b85875a 2680 goto out_rtnl;
93da9cc1 2681
79c97e97 2682 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2683 err = -EOPNOTSUPP;
2684 goto out;
2685 }
2686
93da9cc1 2687 /* Get the mesh params */
79c97e97 2688 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2689 if (err)
2690 goto out;
2691
2692 /* Draw up a netlink message to send back */
fd2120ca 2693 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2694 if (!msg) {
2695 err = -ENOBUFS;
2696 goto out;
2697 }
2698 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2699 NL80211_CMD_GET_MESH_PARAMS);
2700 if (!hdr)
2701 goto nla_put_failure;
2702 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2703 if (!pinfoattr)
2704 goto nla_put_failure;
2705 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2706 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2707 cur_params.dot11MeshRetryTimeout);
2708 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2709 cur_params.dot11MeshConfirmTimeout);
2710 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2711 cur_params.dot11MeshHoldingTimeout);
2712 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2713 cur_params.dot11MeshMaxPeerLinks);
2714 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2715 cur_params.dot11MeshMaxRetries);
2716 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2717 cur_params.dot11MeshTTL);
2718 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2719 cur_params.auto_open_plinks);
2720 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2721 cur_params.dot11MeshHWMPmaxPREQretries);
2722 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2723 cur_params.path_refresh_time);
2724 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2725 cur_params.min_discovery_timeout);
2726 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2727 cur_params.dot11MeshHWMPactivePathTimeout);
2728 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2729 cur_params.dot11MeshHWMPpreqMinInterval);
2730 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2731 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2732 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2733 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2734 nla_nest_end(msg, pinfoattr);
2735 genlmsg_end(msg, hdr);
134e6375 2736 err = genlmsg_reply(msg, info);
93da9cc1 2737 goto out;
2738
3b85875a 2739 nla_put_failure:
93da9cc1 2740 genlmsg_cancel(msg, hdr);
2741 err = -EMSGSIZE;
3b85875a 2742 out:
93da9cc1 2743 /* Cleanup */
79c97e97 2744 cfg80211_unlock_rdev(rdev);
93da9cc1 2745 dev_put(dev);
3b85875a
JB
2746 out_rtnl:
2747 rtnl_unlock();
2748
93da9cc1 2749 return err;
2750}
2751
2752#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2753do {\
2754 if (table[attr_num]) {\
2755 cfg.param = nla_fn(table[attr_num]); \
2756 mask |= (1 << (attr_num - 1)); \
2757 } \
2758} while (0);\
2759
b54452b0 2760static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 2761 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2762 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2763 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2764 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2765 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2766 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2767 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2768
2769 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2770 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2771 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2772 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2773 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2774 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2775};
2776
2777static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2778{
2779 int err;
2780 u32 mask;
79c97e97 2781 struct cfg80211_registered_device *rdev;
93da9cc1 2782 struct net_device *dev;
2783 struct mesh_config cfg;
2784 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2785 struct nlattr *parent_attr;
2786
2787 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2788 if (!parent_attr)
2789 return -EINVAL;
2790 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2791 parent_attr, nl80211_meshconf_params_policy))
2792 return -EINVAL;
2793
3b85875a
JB
2794 rtnl_lock();
2795
463d0183 2796 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2797 if (err)
3b85875a 2798 goto out_rtnl;
93da9cc1 2799
79c97e97 2800 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2801 err = -EOPNOTSUPP;
2802 goto out;
2803 }
2804
93da9cc1 2805 /* This makes sure that there aren't more than 32 mesh config
2806 * parameters (otherwise our bitfield scheme would not work.) */
2807 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2808
2809 /* Fill in the params struct */
2810 mask = 0;
2811 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2812 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2813 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2814 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2815 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2816 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2817 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2818 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2819 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2820 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2821 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2822 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2823 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2824 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2825 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2826 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2827 nla_get_u8);
2828 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2829 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2830 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2831 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2832 nla_get_u16);
2833 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2834 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2835 nla_get_u32);
2836 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2837 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2838 nla_get_u16);
2839 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2840 dot11MeshHWMPnetDiameterTraversalTime,
2841 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2842 nla_get_u16);
63c5723b
RP
2843 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2844 dot11MeshHWMPRootMode, mask,
2845 NL80211_MESHCONF_HWMP_ROOTMODE,
2846 nla_get_u8);
93da9cc1 2847
2848 /* Apply changes */
79c97e97 2849 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2850
f3f92586 2851 out:
93da9cc1 2852 /* cleanup */
79c97e97 2853 cfg80211_unlock_rdev(rdev);
93da9cc1 2854 dev_put(dev);
3b85875a
JB
2855 out_rtnl:
2856 rtnl_unlock();
2857
93da9cc1 2858 return err;
2859}
2860
2861#undef FILL_IN_MESH_PARAM_IF_SET
2862
f130347c
LR
2863static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2864{
2865 struct sk_buff *msg;
2866 void *hdr = NULL;
2867 struct nlattr *nl_reg_rules;
2868 unsigned int i;
2869 int err = -EINVAL;
2870
a1794390 2871 mutex_lock(&cfg80211_mutex);
f130347c
LR
2872
2873 if (!cfg80211_regdomain)
2874 goto out;
2875
fd2120ca 2876 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2877 if (!msg) {
2878 err = -ENOBUFS;
2879 goto out;
2880 }
2881
2882 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2883 NL80211_CMD_GET_REG);
2884 if (!hdr)
2885 goto nla_put_failure;
2886
2887 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2888 cfg80211_regdomain->alpha2);
2889
2890 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2891 if (!nl_reg_rules)
2892 goto nla_put_failure;
2893
2894 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2895 struct nlattr *nl_reg_rule;
2896 const struct ieee80211_reg_rule *reg_rule;
2897 const struct ieee80211_freq_range *freq_range;
2898 const struct ieee80211_power_rule *power_rule;
2899
2900 reg_rule = &cfg80211_regdomain->reg_rules[i];
2901 freq_range = &reg_rule->freq_range;
2902 power_rule = &reg_rule->power_rule;
2903
2904 nl_reg_rule = nla_nest_start(msg, i);
2905 if (!nl_reg_rule)
2906 goto nla_put_failure;
2907
2908 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2909 reg_rule->flags);
2910 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2911 freq_range->start_freq_khz);
2912 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2913 freq_range->end_freq_khz);
2914 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2915 freq_range->max_bandwidth_khz);
2916 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2917 power_rule->max_antenna_gain);
2918 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2919 power_rule->max_eirp);
2920
2921 nla_nest_end(msg, nl_reg_rule);
2922 }
2923
2924 nla_nest_end(msg, nl_reg_rules);
2925
2926 genlmsg_end(msg, hdr);
134e6375 2927 err = genlmsg_reply(msg, info);
f130347c
LR
2928 goto out;
2929
2930nla_put_failure:
2931 genlmsg_cancel(msg, hdr);
2932 err = -EMSGSIZE;
2933out:
a1794390 2934 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2935 return err;
2936}
2937
b2e1b302
LR
2938static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2939{
2940 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2941 struct nlattr *nl_reg_rule;
2942 char *alpha2 = NULL;
2943 int rem_reg_rules = 0, r = 0;
2944 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2945 struct ieee80211_regdomain *rd = NULL;
2946
2947 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2948 return -EINVAL;
2949
2950 if (!info->attrs[NL80211_ATTR_REG_RULES])
2951 return -EINVAL;
2952
2953 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2954
2955 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2956 rem_reg_rules) {
2957 num_rules++;
2958 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2959 return -EINVAL;
b2e1b302
LR
2960 }
2961
61405e97
LR
2962 mutex_lock(&cfg80211_mutex);
2963
d0e18f83
LR
2964 if (!reg_is_valid_request(alpha2)) {
2965 r = -EINVAL;
2966 goto bad_reg;
2967 }
b2e1b302
LR
2968
2969 size_of_regd = sizeof(struct ieee80211_regdomain) +
2970 (num_rules * sizeof(struct ieee80211_reg_rule));
2971
2972 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2973 if (!rd) {
2974 r = -ENOMEM;
2975 goto bad_reg;
2976 }
b2e1b302
LR
2977
2978 rd->n_reg_rules = num_rules;
2979 rd->alpha2[0] = alpha2[0];
2980 rd->alpha2[1] = alpha2[1];
2981
2982 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2983 rem_reg_rules) {
2984 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2985 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2986 reg_rule_policy);
2987 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2988 if (r)
2989 goto bad_reg;
2990
2991 rule_idx++;
2992
d0e18f83
LR
2993 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2994 r = -EINVAL;
b2e1b302 2995 goto bad_reg;
d0e18f83 2996 }
b2e1b302
LR
2997 }
2998
2999 BUG_ON(rule_idx != num_rules);
3000
b2e1b302 3001 r = set_regdom(rd);
61405e97 3002
a1794390 3003 mutex_unlock(&cfg80211_mutex);
d0e18f83 3004
b2e1b302
LR
3005 return r;
3006
d2372b31 3007 bad_reg:
61405e97 3008 mutex_unlock(&cfg80211_mutex);
b2e1b302 3009 kfree(rd);
d0e18f83 3010 return r;
b2e1b302
LR
3011}
3012
83f5e2cf
JB
3013static int validate_scan_freqs(struct nlattr *freqs)
3014{
3015 struct nlattr *attr1, *attr2;
3016 int n_channels = 0, tmp1, tmp2;
3017
3018 nla_for_each_nested(attr1, freqs, tmp1) {
3019 n_channels++;
3020 /*
3021 * Some hardware has a limited channel list for
3022 * scanning, and it is pretty much nonsensical
3023 * to scan for a channel twice, so disallow that
3024 * and don't require drivers to check that the
3025 * channel list they get isn't longer than what
3026 * they can scan, as long as they can scan all
3027 * the channels they registered at once.
3028 */
3029 nla_for_each_nested(attr2, freqs, tmp2)
3030 if (attr1 != attr2 &&
3031 nla_get_u32(attr1) == nla_get_u32(attr2))
3032 return 0;
3033 }
3034
3035 return n_channels;
3036}
3037
2a519311
JB
3038static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3039{
79c97e97 3040 struct cfg80211_registered_device *rdev;
2a519311
JB
3041 struct net_device *dev;
3042 struct cfg80211_scan_request *request;
3043 struct cfg80211_ssid *ssid;
3044 struct ieee80211_channel *channel;
3045 struct nlattr *attr;
3046 struct wiphy *wiphy;
83f5e2cf 3047 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 3048 enum ieee80211_band band;
70692ad2 3049 size_t ie_len;
2a519311 3050
f4a11bb0
JB
3051 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3052 return -EINVAL;
3053
3b85875a
JB
3054 rtnl_lock();
3055
463d0183 3056 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 3057 if (err)
3b85875a 3058 goto out_rtnl;
2a519311 3059
79c97e97 3060 wiphy = &rdev->wiphy;
2a519311 3061
79c97e97 3062 if (!rdev->ops->scan) {
2a519311
JB
3063 err = -EOPNOTSUPP;
3064 goto out;
3065 }
3066
35a8efe1
JM
3067 if (!netif_running(dev)) {
3068 err = -ENETDOWN;
3069 goto out;
3070 }
3071
79c97e97 3072 if (rdev->scan_req) {
2a519311 3073 err = -EBUSY;
3b85875a 3074 goto out;
2a519311
JB
3075 }
3076
3077 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
3078 n_channels = validate_scan_freqs(
3079 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
3080 if (!n_channels) {
3081 err = -EINVAL;
3b85875a 3082 goto out;
2a519311
JB
3083 }
3084 } else {
83f5e2cf
JB
3085 n_channels = 0;
3086
2a519311
JB
3087 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3088 if (wiphy->bands[band])
3089 n_channels += wiphy->bands[band]->n_channels;
3090 }
3091
3092 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3093 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3094 n_ssids++;
3095
3096 if (n_ssids > wiphy->max_scan_ssids) {
3097 err = -EINVAL;
3b85875a 3098 goto out;
2a519311
JB
3099 }
3100
70692ad2
JM
3101 if (info->attrs[NL80211_ATTR_IE])
3102 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3103 else
3104 ie_len = 0;
3105
18a83659
JB
3106 if (ie_len > wiphy->max_scan_ie_len) {
3107 err = -EINVAL;
3108 goto out;
3109 }
3110
2a519311
JB
3111 request = kzalloc(sizeof(*request)
3112 + sizeof(*ssid) * n_ssids
70692ad2
JM
3113 + sizeof(channel) * n_channels
3114 + ie_len, GFP_KERNEL);
2a519311
JB
3115 if (!request) {
3116 err = -ENOMEM;
3b85875a 3117 goto out;
2a519311
JB
3118 }
3119
2a519311 3120 if (n_ssids)
5ba63533 3121 request->ssids = (void *)&request->channels[n_channels];
2a519311 3122 request->n_ssids = n_ssids;
70692ad2
JM
3123 if (ie_len) {
3124 if (request->ssids)
3125 request->ie = (void *)(request->ssids + n_ssids);
3126 else
3127 request->ie = (void *)(request->channels + n_channels);
3128 }
2a519311 3129
584991dc 3130 i = 0;
2a519311
JB
3131 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3132 /* user specified, bail out if channel not found */
2a519311 3133 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3134 struct ieee80211_channel *chan;
3135
3136 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3137
3138 if (!chan) {
2a519311
JB
3139 err = -EINVAL;
3140 goto out_free;
3141 }
584991dc
JB
3142
3143 /* ignore disabled channels */
3144 if (chan->flags & IEEE80211_CHAN_DISABLED)
3145 continue;
3146
3147 request->channels[i] = chan;
2a519311
JB
3148 i++;
3149 }
3150 } else {
3151 /* all channels */
2a519311
JB
3152 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3153 int j;
3154 if (!wiphy->bands[band])
3155 continue;
3156 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3157 struct ieee80211_channel *chan;
3158
3159 chan = &wiphy->bands[band]->channels[j];
3160
3161 if (chan->flags & IEEE80211_CHAN_DISABLED)
3162 continue;
3163
3164 request->channels[i] = chan;
2a519311
JB
3165 i++;
3166 }
3167 }
3168 }
3169
584991dc
JB
3170 if (!i) {
3171 err = -EINVAL;
3172 goto out_free;
3173 }
3174
3175 request->n_channels = i;
3176
2a519311
JB
3177 i = 0;
3178 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3179 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3180 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3181 err = -EINVAL;
3182 goto out_free;
3183 }
3184 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3185 request->ssids[i].ssid_len = nla_len(attr);
3186 i++;
3187 }
3188 }
3189
70692ad2
JM
3190 if (info->attrs[NL80211_ATTR_IE]) {
3191 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3192 memcpy((void *)request->ie,
3193 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3194 request->ie_len);
3195 }
3196
463d0183 3197 request->dev = dev;
79c97e97 3198 request->wiphy = &rdev->wiphy;
2a519311 3199
79c97e97
JB
3200 rdev->scan_req = request;
3201 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3202
463d0183 3203 if (!err) {
79c97e97 3204 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3205 dev_hold(dev);
3206 }
a538e2d5 3207
2a519311
JB
3208 out_free:
3209 if (err) {
79c97e97 3210 rdev->scan_req = NULL;
2a519311
JB
3211 kfree(request);
3212 }
2a519311 3213 out:
79c97e97 3214 cfg80211_unlock_rdev(rdev);
2a519311 3215 dev_put(dev);
3b85875a
JB
3216 out_rtnl:
3217 rtnl_unlock();
3218
2a519311
JB
3219 return err;
3220}
3221
3222static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3223 struct cfg80211_registered_device *rdev,
48ab905d
JB
3224 struct wireless_dev *wdev,
3225 struct cfg80211_internal_bss *intbss)
2a519311 3226{
48ab905d 3227 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3228 void *hdr;
3229 struct nlattr *bss;
48ab905d
JB
3230 int i;
3231
3232 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3233
3234 hdr = nl80211hdr_put(msg, pid, seq, flags,
3235 NL80211_CMD_NEW_SCAN_RESULTS);
3236 if (!hdr)
3237 return -1;
3238
f5ea9120 3239 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3240 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3241
3242 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3243 if (!bss)
3244 goto nla_put_failure;
3245 if (!is_zero_ether_addr(res->bssid))
3246 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3247 if (res->information_elements && res->len_information_elements)
3248 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3249 res->len_information_elements,
3250 res->information_elements);
34a6eddb
JM
3251 if (res->beacon_ies && res->len_beacon_ies &&
3252 res->beacon_ies != res->information_elements)
3253 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3254 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3255 if (res->tsf)
3256 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3257 if (res->beacon_interval)
3258 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3259 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3260 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3261 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3262 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3263
77965c97 3264 switch (rdev->wiphy.signal_type) {
2a519311
JB
3265 case CFG80211_SIGNAL_TYPE_MBM:
3266 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3267 break;
3268 case CFG80211_SIGNAL_TYPE_UNSPEC:
3269 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3270 break;
3271 default:
3272 break;
3273 }
3274
48ab905d
JB
3275 switch (wdev->iftype) {
3276 case NL80211_IFTYPE_STATION:
3277 if (intbss == wdev->current_bss)
3278 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3279 NL80211_BSS_STATUS_ASSOCIATED);
3280 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3281 if (intbss != wdev->auth_bsses[i])
3282 continue;
3283 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3284 NL80211_BSS_STATUS_AUTHENTICATED);
3285 break;
3286 }
3287 break;
3288 case NL80211_IFTYPE_ADHOC:
3289 if (intbss == wdev->current_bss)
3290 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3291 NL80211_BSS_STATUS_IBSS_JOINED);
3292 break;
3293 default:
3294 break;
3295 }
3296
2a519311
JB
3297 nla_nest_end(msg, bss);
3298
3299 return genlmsg_end(msg, hdr);
3300
3301 nla_put_failure:
3302 genlmsg_cancel(msg, hdr);
3303 return -EMSGSIZE;
3304}
3305
3306static int nl80211_dump_scan(struct sk_buff *skb,
3307 struct netlink_callback *cb)
3308{
48ab905d
JB
3309 struct cfg80211_registered_device *rdev;
3310 struct net_device *dev;
2a519311 3311 struct cfg80211_internal_bss *scan;
48ab905d 3312 struct wireless_dev *wdev;
2a519311
JB
3313 int ifidx = cb->args[0];
3314 int start = cb->args[1], idx = 0;
3315 int err;
3316
a043897a
HS
3317 if (!ifidx)
3318 ifidx = nl80211_get_ifidx(cb);
3319 if (ifidx < 0)
3320 return ifidx;
3321 cb->args[0] = ifidx;
2a519311 3322
463d0183 3323 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3324 if (!dev)
2a519311
JB
3325 return -ENODEV;
3326
463d0183 3327 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3328 if (IS_ERR(rdev)) {
3329 err = PTR_ERR(rdev);
2a519311
JB
3330 goto out_put_netdev;
3331 }
3332
48ab905d 3333 wdev = dev->ieee80211_ptr;
2a519311 3334
48ab905d
JB
3335 wdev_lock(wdev);
3336 spin_lock_bh(&rdev->bss_lock);
3337 cfg80211_bss_expire(rdev);
3338
3339 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3340 if (++idx <= start)
3341 continue;
3342 if (nl80211_send_bss(skb,
3343 NETLINK_CB(cb->skb).pid,
3344 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3345 rdev, wdev, scan) < 0) {
2a519311
JB
3346 idx--;
3347 goto out;
3348 }
3349 }
3350
3351 out:
48ab905d
JB
3352 spin_unlock_bh(&rdev->bss_lock);
3353 wdev_unlock(wdev);
2a519311
JB
3354
3355 cb->args[1] = idx;
3356 err = skb->len;
48ab905d 3357 cfg80211_unlock_rdev(rdev);
2a519311 3358 out_put_netdev:
48ab905d 3359 dev_put(dev);
2a519311
JB
3360
3361 return err;
3362}
3363
61fa713c
HS
3364static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3365 int flags, struct net_device *dev,
3366 struct survey_info *survey)
3367{
3368 void *hdr;
3369 struct nlattr *infoattr;
3370
3371 /* Survey without a channel doesn't make sense */
3372 if (!survey->channel)
3373 return -EINVAL;
3374
3375 hdr = nl80211hdr_put(msg, pid, seq, flags,
3376 NL80211_CMD_NEW_SURVEY_RESULTS);
3377 if (!hdr)
3378 return -ENOMEM;
3379
3380 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3381
3382 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3383 if (!infoattr)
3384 goto nla_put_failure;
3385
3386 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3387 survey->channel->center_freq);
3388 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3389 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3390 survey->noise);
3391
3392 nla_nest_end(msg, infoattr);
3393
3394 return genlmsg_end(msg, hdr);
3395
3396 nla_put_failure:
3397 genlmsg_cancel(msg, hdr);
3398 return -EMSGSIZE;
3399}
3400
3401static int nl80211_dump_survey(struct sk_buff *skb,
3402 struct netlink_callback *cb)
3403{
3404 struct survey_info survey;
3405 struct cfg80211_registered_device *dev;
3406 struct net_device *netdev;
3407 int ifidx = cb->args[0];
3408 int survey_idx = cb->args[1];
3409 int res;
3410
3411 if (!ifidx)
3412 ifidx = nl80211_get_ifidx(cb);
3413 if (ifidx < 0)
3414 return ifidx;
3415 cb->args[0] = ifidx;
3416
3417 rtnl_lock();
3418
3419 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3420 if (!netdev) {
3421 res = -ENODEV;
3422 goto out_rtnl;
3423 }
3424
3425 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3426 if (IS_ERR(dev)) {
3427 res = PTR_ERR(dev);
3428 goto out_rtnl;
3429 }
3430
3431 if (!dev->ops->dump_survey) {
3432 res = -EOPNOTSUPP;
3433 goto out_err;
3434 }
3435
3436 while (1) {
3437 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3438 &survey);
3439 if (res == -ENOENT)
3440 break;
3441 if (res)
3442 goto out_err;
3443
3444 if (nl80211_send_survey(skb,
3445 NETLINK_CB(cb->skb).pid,
3446 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3447 netdev,
3448 &survey) < 0)
3449 goto out;
3450 survey_idx++;
3451 }
3452
3453 out:
3454 cb->args[1] = survey_idx;
3455 res = skb->len;
3456 out_err:
3457 cfg80211_unlock_rdev(dev);
3458 out_rtnl:
3459 rtnl_unlock();
3460
3461 return res;
3462}
3463
255e737e
JM
3464static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3465{
b23aa676
SO
3466 return auth_type <= NL80211_AUTHTYPE_MAX;
3467}
3468
3469static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3470{
3471 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3472 NL80211_WPA_VERSION_2));
3473}
3474
3475static bool nl80211_valid_akm_suite(u32 akm)
3476{
3477 return akm == WLAN_AKM_SUITE_8021X ||
3478 akm == WLAN_AKM_SUITE_PSK;
3479}
3480
3481static bool nl80211_valid_cipher_suite(u32 cipher)
3482{
3483 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3484 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3485 cipher == WLAN_CIPHER_SUITE_TKIP ||
3486 cipher == WLAN_CIPHER_SUITE_CCMP ||
3487 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3488}
3489
b23aa676 3490
636a5d36
JM
3491static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3492{
79c97e97 3493 struct cfg80211_registered_device *rdev;
636a5d36 3494 struct net_device *dev;
19957bb3
JB
3495 struct ieee80211_channel *chan;
3496 const u8 *bssid, *ssid, *ie = NULL;
3497 int err, ssid_len, ie_len = 0;
3498 enum nl80211_auth_type auth_type;
fffd0934 3499 struct key_parse key;
d5cdfacb 3500 bool local_state_change;
636a5d36 3501
f4a11bb0
JB
3502 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3503 return -EINVAL;
3504
3505 if (!info->attrs[NL80211_ATTR_MAC])
3506 return -EINVAL;
3507
1778092e
JM
3508 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3509 return -EINVAL;
3510
19957bb3
JB
3511 if (!info->attrs[NL80211_ATTR_SSID])
3512 return -EINVAL;
3513
3514 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3515 return -EINVAL;
3516
fffd0934
JB
3517 err = nl80211_parse_key(info, &key);
3518 if (err)
3519 return err;
3520
3521 if (key.idx >= 0) {
3522 if (!key.p.key || !key.p.key_len)
3523 return -EINVAL;
3524 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3525 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3526 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3527 key.p.key_len != WLAN_KEY_LEN_WEP104))
3528 return -EINVAL;
3529 if (key.idx > 4)
3530 return -EINVAL;
3531 } else {
3532 key.p.key_len = 0;
3533 key.p.key = NULL;
3534 }
3535
636a5d36
JM
3536 rtnl_lock();
3537
463d0183 3538 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3539 if (err)
3540 goto unlock_rtnl;
3541
79c97e97 3542 if (!rdev->ops->auth) {
636a5d36
JM
3543 err = -EOPNOTSUPP;
3544 goto out;
3545 }
3546
eec60b03
JM
3547 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3548 err = -EOPNOTSUPP;
3549 goto out;
3550 }
3551
35a8efe1
JM
3552 if (!netif_running(dev)) {
3553 err = -ENETDOWN;
3554 goto out;
3555 }
3556
19957bb3 3557 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3558 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3559 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3560 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3561 err = -EINVAL;
3562 goto out;
636a5d36
JM
3563 }
3564
19957bb3
JB
3565 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3566 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3567
3568 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3569 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3570 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3571 }
3572
19957bb3
JB
3573 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3574 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3575 err = -EINVAL;
3576 goto out;
636a5d36
JM
3577 }
3578
d5cdfacb
JM
3579 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3580
79c97e97 3581 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934 3582 ssid, ssid_len, ie, ie_len,
d5cdfacb
JM
3583 key.p.key, key.p.key_len, key.idx,
3584 local_state_change);
636a5d36
JM
3585
3586out:
79c97e97 3587 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3588 dev_put(dev);
3589unlock_rtnl:
3590 rtnl_unlock();
3591 return err;
3592}
3593
b23aa676 3594static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3595 struct cfg80211_crypto_settings *settings,
3596 int cipher_limit)
b23aa676 3597{
c0b2bbd8
JB
3598 memset(settings, 0, sizeof(*settings));
3599
b23aa676
SO
3600 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3601
3602 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3603 void *data;
3604 int len, i;
3605
3606 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3607 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3608 settings->n_ciphers_pairwise = len / sizeof(u32);
3609
3610 if (len % sizeof(u32))
3611 return -EINVAL;
3612
3dc27d25 3613 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3614 return -EINVAL;
3615
3616 memcpy(settings->ciphers_pairwise, data, len);
3617
3618 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3619 if (!nl80211_valid_cipher_suite(
3620 settings->ciphers_pairwise[i]))
3621 return -EINVAL;
3622 }
3623
3624 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3625 settings->cipher_group =
3626 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3627 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3628 return -EINVAL;
3629 }
3630
3631 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3632 settings->wpa_versions =
3633 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3634 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3635 return -EINVAL;
3636 }
3637
3638 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3639 void *data;
3640 int len, i;
3641
3642 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3643 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3644 settings->n_akm_suites = len / sizeof(u32);
3645
3646 if (len % sizeof(u32))
3647 return -EINVAL;
3648
3649 memcpy(settings->akm_suites, data, len);
3650
3651 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3652 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3653 return -EINVAL;
3654 }
3655
3656 return 0;
3657}
3658
636a5d36
JM
3659static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3660{
19957bb3 3661 struct cfg80211_registered_device *rdev;
636a5d36 3662 struct net_device *dev;
19957bb3 3663 struct cfg80211_crypto_settings crypto;
f444de05 3664 struct ieee80211_channel *chan;
3e5d7649 3665 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3666 int err, ssid_len, ie_len = 0;
3667 bool use_mfp = false;
636a5d36 3668
f4a11bb0
JB
3669 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3670 return -EINVAL;
3671
3672 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3673 !info->attrs[NL80211_ATTR_SSID] ||
3674 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3675 return -EINVAL;
3676
636a5d36
JM
3677 rtnl_lock();
3678
463d0183 3679 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3680 if (err)
3681 goto unlock_rtnl;
3682
19957bb3 3683 if (!rdev->ops->assoc) {
636a5d36
JM
3684 err = -EOPNOTSUPP;
3685 goto out;
3686 }
3687
eec60b03
JM
3688 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3689 err = -EOPNOTSUPP;
3690 goto out;
3691 }
3692
35a8efe1
JM
3693 if (!netif_running(dev)) {
3694 err = -ENETDOWN;
3695 goto out;
3696 }
3697
19957bb3 3698 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3699
19957bb3
JB
3700 chan = ieee80211_get_channel(&rdev->wiphy,
3701 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3702 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3703 err = -EINVAL;
3704 goto out;
636a5d36
JM
3705 }
3706
19957bb3
JB
3707 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3708 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3709
3710 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3711 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3712 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3713 }
3714
dc6382ce 3715 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3716 enum nl80211_mfp mfp =
dc6382ce 3717 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3718 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3719 use_mfp = true;
4f5dadce 3720 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3721 err = -EINVAL;
3722 goto out;
3723 }
3724 }
3725
3e5d7649
JB
3726 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3727 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3728
3dc27d25 3729 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3730 if (!err)
3e5d7649
JB
3731 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3732 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3733 &crypto);
636a5d36
JM
3734
3735out:
4d0c8aea 3736 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3737 dev_put(dev);
3738unlock_rtnl:
3739 rtnl_unlock();
3740 return err;
3741}
3742
3743static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3744{
79c97e97 3745 struct cfg80211_registered_device *rdev;
636a5d36 3746 struct net_device *dev;
19957bb3
JB
3747 const u8 *ie = NULL, *bssid;
3748 int err, ie_len = 0;
3749 u16 reason_code;
d5cdfacb 3750 bool local_state_change;
636a5d36 3751
f4a11bb0
JB
3752 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3753 return -EINVAL;
3754
3755 if (!info->attrs[NL80211_ATTR_MAC])
3756 return -EINVAL;
3757
3758 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3759 return -EINVAL;
3760
636a5d36
JM
3761 rtnl_lock();
3762
463d0183 3763 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3764 if (err)
3765 goto unlock_rtnl;
3766
79c97e97 3767 if (!rdev->ops->deauth) {
636a5d36
JM
3768 err = -EOPNOTSUPP;
3769 goto out;
3770 }
3771
eec60b03
JM
3772 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3773 err = -EOPNOTSUPP;
3774 goto out;
3775 }
3776
35a8efe1
JM
3777 if (!netif_running(dev)) {
3778 err = -ENETDOWN;
3779 goto out;
3780 }
3781
19957bb3 3782 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3783
19957bb3
JB
3784 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3785 if (reason_code == 0) {
f4a11bb0
JB
3786 /* Reason Code 0 is reserved */
3787 err = -EINVAL;
3788 goto out;
255e737e 3789 }
636a5d36
JM
3790
3791 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3792 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3793 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3794 }
3795
d5cdfacb
JM
3796 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3797
3798 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3799 local_state_change);
636a5d36
JM
3800
3801out:
79c97e97 3802 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3803 dev_put(dev);
3804unlock_rtnl:
3805 rtnl_unlock();
3806 return err;
3807}
3808
3809static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3810{
79c97e97 3811 struct cfg80211_registered_device *rdev;
636a5d36 3812 struct net_device *dev;
19957bb3
JB
3813 const u8 *ie = NULL, *bssid;
3814 int err, ie_len = 0;
3815 u16 reason_code;
d5cdfacb 3816 bool local_state_change;
636a5d36 3817
f4a11bb0
JB
3818 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3819 return -EINVAL;
3820
3821 if (!info->attrs[NL80211_ATTR_MAC])
3822 return -EINVAL;
3823
3824 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3825 return -EINVAL;
3826
636a5d36
JM
3827 rtnl_lock();
3828
463d0183 3829 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3830 if (err)
3831 goto unlock_rtnl;
3832
79c97e97 3833 if (!rdev->ops->disassoc) {
636a5d36
JM
3834 err = -EOPNOTSUPP;
3835 goto out;
3836 }
3837
eec60b03
JM
3838 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3839 err = -EOPNOTSUPP;
3840 goto out;
3841 }
3842
35a8efe1
JM
3843 if (!netif_running(dev)) {
3844 err = -ENETDOWN;
3845 goto out;
3846 }
3847
19957bb3 3848 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3849
19957bb3
JB
3850 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3851 if (reason_code == 0) {
f4a11bb0
JB
3852 /* Reason Code 0 is reserved */
3853 err = -EINVAL;
3854 goto out;
255e737e 3855 }
636a5d36
JM
3856
3857 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3858 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3859 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3860 }
3861
d5cdfacb
JM
3862 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3863
3864 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3865 local_state_change);
636a5d36
JM
3866
3867out:
79c97e97 3868 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3869 dev_put(dev);
3870unlock_rtnl:
3871 rtnl_unlock();
3872 return err;
3873}
3874
04a773ad
JB
3875static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3876{
79c97e97 3877 struct cfg80211_registered_device *rdev;
04a773ad
JB
3878 struct net_device *dev;
3879 struct cfg80211_ibss_params ibss;
3880 struct wiphy *wiphy;
fffd0934 3881 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3882 int err;
3883
8e30bc55
JB
3884 memset(&ibss, 0, sizeof(ibss));
3885
04a773ad
JB
3886 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3887 return -EINVAL;
3888
3889 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3890 !info->attrs[NL80211_ATTR_SSID] ||
3891 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3892 return -EINVAL;
3893
8e30bc55
JB
3894 ibss.beacon_interval = 100;
3895
3896 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3897 ibss.beacon_interval =
3898 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3899 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3900 return -EINVAL;
3901 }
3902
04a773ad
JB
3903 rtnl_lock();
3904
463d0183 3905 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3906 if (err)
3907 goto unlock_rtnl;
3908
79c97e97 3909 if (!rdev->ops->join_ibss) {
04a773ad
JB
3910 err = -EOPNOTSUPP;
3911 goto out;
3912 }
3913
3914 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3915 err = -EOPNOTSUPP;
3916 goto out;
3917 }
3918
3919 if (!netif_running(dev)) {
3920 err = -ENETDOWN;
3921 goto out;
3922 }
3923
79c97e97 3924 wiphy = &rdev->wiphy;
04a773ad
JB
3925
3926 if (info->attrs[NL80211_ATTR_MAC])
3927 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3928 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3929 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3930
3931 if (info->attrs[NL80211_ATTR_IE]) {
3932 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3933 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3934 }
3935
3936 ibss.channel = ieee80211_get_channel(wiphy,
3937 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3938 if (!ibss.channel ||
3939 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3940 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3941 err = -EINVAL;
3942 goto out;
3943 }
3944
3945 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3946 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3947
3948 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3949 connkeys = nl80211_parse_connkeys(rdev,
3950 info->attrs[NL80211_ATTR_KEYS]);
3951 if (IS_ERR(connkeys)) {
3952 err = PTR_ERR(connkeys);
3953 connkeys = NULL;
3954 goto out;
3955 }
3956 }
04a773ad 3957
fbd2c8dc
TP
3958 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3959 u8 *rates =
3960 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3961 int n_rates =
3962 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3963 struct ieee80211_supported_band *sband =
3964 wiphy->bands[ibss.channel->band];
3965 int i, j;
3966
3967 if (n_rates == 0) {
3968 err = -EINVAL;
3969 goto out;
3970 }
3971
3972 for (i = 0; i < n_rates; i++) {
3973 int rate = (rates[i] & 0x7f) * 5;
3974 bool found = false;
3975
3976 for (j = 0; j < sband->n_bitrates; j++) {
3977 if (sband->bitrates[j].bitrate == rate) {
3978 found = true;
3979 ibss.basic_rates |= BIT(j);
3980 break;
3981 }
3982 }
3983 if (!found) {
3984 err = -EINVAL;
3985 goto out;
3986 }
3987 }
3988 } else {
3989 /*
3990 * If no rates were explicitly configured,
3991 * use the mandatory rate set for 11b or
3992 * 11a for maximum compatibility.
3993 */
3994 struct ieee80211_supported_band *sband =
3995 wiphy->bands[ibss.channel->band];
3996 int j;
3997 u32 flag = ibss.channel->band == IEEE80211_BAND_5GHZ ?
3998 IEEE80211_RATE_MANDATORY_A :
3999 IEEE80211_RATE_MANDATORY_B;
4000
4001 for (j = 0; j < sband->n_bitrates; j++) {
4002 if (sband->bitrates[j].flags & flag)
4003 ibss.basic_rates |= BIT(j);
4004 }
4005 }
4006
fffd0934 4007 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
4008
4009out:
79c97e97 4010 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4011 dev_put(dev);
4012unlock_rtnl:
fffd0934
JB
4013 if (err)
4014 kfree(connkeys);
04a773ad
JB
4015 rtnl_unlock();
4016 return err;
4017}
4018
4019static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
4020{
79c97e97 4021 struct cfg80211_registered_device *rdev;
04a773ad
JB
4022 struct net_device *dev;
4023 int err;
4024
4025 rtnl_lock();
4026
463d0183 4027 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
4028 if (err)
4029 goto unlock_rtnl;
4030
79c97e97 4031 if (!rdev->ops->leave_ibss) {
04a773ad
JB
4032 err = -EOPNOTSUPP;
4033 goto out;
4034 }
4035
4036 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
4037 err = -EOPNOTSUPP;
4038 goto out;
4039 }
4040
4041 if (!netif_running(dev)) {
4042 err = -ENETDOWN;
4043 goto out;
4044 }
4045
79c97e97 4046 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
4047
4048out:
79c97e97 4049 cfg80211_unlock_rdev(rdev);
04a773ad
JB
4050 dev_put(dev);
4051unlock_rtnl:
4052 rtnl_unlock();
4053 return err;
4054}
4055
aff89a9b
JB
4056#ifdef CONFIG_NL80211_TESTMODE
4057static struct genl_multicast_group nl80211_testmode_mcgrp = {
4058 .name = "testmode",
4059};
4060
4061static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
4062{
4063 struct cfg80211_registered_device *rdev;
4064 int err;
4065
4066 if (!info->attrs[NL80211_ATTR_TESTDATA])
4067 return -EINVAL;
4068
4069 rtnl_lock();
4070
4071 rdev = cfg80211_get_dev_from_info(info);
4072 if (IS_ERR(rdev)) {
4073 err = PTR_ERR(rdev);
4074 goto unlock_rtnl;
4075 }
4076
4077 err = -EOPNOTSUPP;
4078 if (rdev->ops->testmode_cmd) {
4079 rdev->testmode_info = info;
4080 err = rdev->ops->testmode_cmd(&rdev->wiphy,
4081 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
4082 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
4083 rdev->testmode_info = NULL;
4084 }
4085
4d0c8aea 4086 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
4087
4088 unlock_rtnl:
4089 rtnl_unlock();
4090 return err;
4091}
4092
4093static struct sk_buff *
4094__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
4095 int approxlen, u32 pid, u32 seq, gfp_t gfp)
4096{
4097 struct sk_buff *skb;
4098 void *hdr;
4099 struct nlattr *data;
4100
4101 skb = nlmsg_new(approxlen + 100, gfp);
4102 if (!skb)
4103 return NULL;
4104
4105 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
4106 if (!hdr) {
4107 kfree_skb(skb);
4108 return NULL;
4109 }
4110
4111 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4112 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
4113
4114 ((void **)skb->cb)[0] = rdev;
4115 ((void **)skb->cb)[1] = hdr;
4116 ((void **)skb->cb)[2] = data;
4117
4118 return skb;
4119
4120 nla_put_failure:
4121 kfree_skb(skb);
4122 return NULL;
4123}
4124
4125struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
4126 int approxlen)
4127{
4128 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4129
4130 if (WARN_ON(!rdev->testmode_info))
4131 return NULL;
4132
4133 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
4134 rdev->testmode_info->snd_pid,
4135 rdev->testmode_info->snd_seq,
4136 GFP_KERNEL);
4137}
4138EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4139
4140int cfg80211_testmode_reply(struct sk_buff *skb)
4141{
4142 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4143 void *hdr = ((void **)skb->cb)[1];
4144 struct nlattr *data = ((void **)skb->cb)[2];
4145
4146 if (WARN_ON(!rdev->testmode_info)) {
4147 kfree_skb(skb);
4148 return -EINVAL;
4149 }
4150
4151 nla_nest_end(skb, data);
4152 genlmsg_end(skb, hdr);
4153 return genlmsg_reply(skb, rdev->testmode_info);
4154}
4155EXPORT_SYMBOL(cfg80211_testmode_reply);
4156
4157struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4158 int approxlen, gfp_t gfp)
4159{
4160 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4161
4162 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4163}
4164EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4165
4166void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4167{
4168 void *hdr = ((void **)skb->cb)[1];
4169 struct nlattr *data = ((void **)skb->cb)[2];
4170
4171 nla_nest_end(skb, data);
4172 genlmsg_end(skb, hdr);
4173 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4174}
4175EXPORT_SYMBOL(cfg80211_testmode_event);
4176#endif
4177
b23aa676
SO
4178static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4179{
79c97e97 4180 struct cfg80211_registered_device *rdev;
b23aa676
SO
4181 struct net_device *dev;
4182 struct cfg80211_connect_params connect;
4183 struct wiphy *wiphy;
fffd0934 4184 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4185 int err;
4186
4187 memset(&connect, 0, sizeof(connect));
4188
4189 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4190 return -EINVAL;
4191
4192 if (!info->attrs[NL80211_ATTR_SSID] ||
4193 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4194 return -EINVAL;
4195
4196 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4197 connect.auth_type =
4198 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4199 if (!nl80211_valid_auth_type(connect.auth_type))
4200 return -EINVAL;
4201 } else
4202 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4203
4204 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4205
3dc27d25
JB
4206 err = nl80211_crypto_settings(info, &connect.crypto,
4207 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4208 if (err)
4209 return err;
4210 rtnl_lock();
4211
463d0183 4212 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4213 if (err)
4214 goto unlock_rtnl;
4215
4216 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4217 err = -EOPNOTSUPP;
4218 goto out;
4219 }
4220
4221 if (!netif_running(dev)) {
4222 err = -ENETDOWN;
4223 goto out;
4224 }
4225
79c97e97 4226 wiphy = &rdev->wiphy;
b23aa676 4227
b23aa676
SO
4228 if (info->attrs[NL80211_ATTR_MAC])
4229 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4230 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4231 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4232
4233 if (info->attrs[NL80211_ATTR_IE]) {
4234 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4235 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4236 }
4237
4238 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4239 connect.channel =
4240 ieee80211_get_channel(wiphy,
4241 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4242 if (!connect.channel ||
4243 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4244 err = -EINVAL;
4245 goto out;
4246 }
4247 }
4248
fffd0934
JB
4249 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4250 connkeys = nl80211_parse_connkeys(rdev,
4251 info->attrs[NL80211_ATTR_KEYS]);
4252 if (IS_ERR(connkeys)) {
4253 err = PTR_ERR(connkeys);
4254 connkeys = NULL;
4255 goto out;
4256 }
4257 }
4258
4259 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
4260
4261out:
79c97e97 4262 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4263 dev_put(dev);
4264unlock_rtnl:
fffd0934
JB
4265 if (err)
4266 kfree(connkeys);
b23aa676
SO
4267 rtnl_unlock();
4268 return err;
4269}
4270
4271static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4272{
79c97e97 4273 struct cfg80211_registered_device *rdev;
b23aa676
SO
4274 struct net_device *dev;
4275 int err;
4276 u16 reason;
4277
4278 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4279 reason = WLAN_REASON_DEAUTH_LEAVING;
4280 else
4281 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4282
4283 if (reason == 0)
4284 return -EINVAL;
4285
4286 rtnl_lock();
4287
463d0183 4288 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4289 if (err)
4290 goto unlock_rtnl;
4291
4292 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4293 err = -EOPNOTSUPP;
4294 goto out;
4295 }
4296
4297 if (!netif_running(dev)) {
4298 err = -ENETDOWN;
4299 goto out;
4300 }
4301
79c97e97 4302 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4303
4304out:
79c97e97 4305 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4306 dev_put(dev);
4307unlock_rtnl:
4308 rtnl_unlock();
4309 return err;
4310}
4311
463d0183
JB
4312static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4313{
4314 struct cfg80211_registered_device *rdev;
4315 struct net *net;
4316 int err;
4317 u32 pid;
4318
4319 if (!info->attrs[NL80211_ATTR_PID])
4320 return -EINVAL;
4321
4322 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4323
4324 rtnl_lock();
4325
4326 rdev = cfg80211_get_dev_from_info(info);
4327 if (IS_ERR(rdev)) {
4328 err = PTR_ERR(rdev);
8a8e05e5 4329 goto out_rtnl;
463d0183
JB
4330 }
4331
4332 net = get_net_ns_by_pid(pid);
4333 if (IS_ERR(net)) {
4334 err = PTR_ERR(net);
4335 goto out;
4336 }
4337
4338 err = 0;
4339
4340 /* check if anything to do */
4341 if (net_eq(wiphy_net(&rdev->wiphy), net))
4342 goto out_put_net;
4343
4344 err = cfg80211_switch_netns(rdev, net);
4345 out_put_net:
4346 put_net(net);
4347 out:
4348 cfg80211_unlock_rdev(rdev);
8a8e05e5 4349 out_rtnl:
463d0183
JB
4350 rtnl_unlock();
4351 return err;
4352}
4353
67fbb16b
SO
4354static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4355{
4356 struct cfg80211_registered_device *rdev;
4357 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4358 struct cfg80211_pmksa *pmksa) = NULL;
4359 int err;
4360 struct net_device *dev;
4361 struct cfg80211_pmksa pmksa;
4362
4363 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4364
4365 if (!info->attrs[NL80211_ATTR_MAC])
4366 return -EINVAL;
4367
4368 if (!info->attrs[NL80211_ATTR_PMKID])
4369 return -EINVAL;
4370
4371 rtnl_lock();
4372
4373 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4374 if (err)
4375 goto out_rtnl;
4376
4377 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4378 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4379
4380 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4381 err = -EOPNOTSUPP;
4382 goto out;
4383 }
4384
4385 switch (info->genlhdr->cmd) {
4386 case NL80211_CMD_SET_PMKSA:
4387 rdev_ops = rdev->ops->set_pmksa;
4388 break;
4389 case NL80211_CMD_DEL_PMKSA:
4390 rdev_ops = rdev->ops->del_pmksa;
4391 break;
4392 default:
4393 WARN_ON(1);
4394 break;
4395 }
4396
4397 if (!rdev_ops) {
4398 err = -EOPNOTSUPP;
4399 goto out;
4400 }
4401
4402 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4403
4404 out:
4405 cfg80211_unlock_rdev(rdev);
4406 dev_put(dev);
4407 out_rtnl:
4408 rtnl_unlock();
4409
4410 return err;
4411}
4412
4413static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4414{
4415 struct cfg80211_registered_device *rdev;
4416 int err;
4417 struct net_device *dev;
4418
4419 rtnl_lock();
4420
4421 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4422 if (err)
4423 goto out_rtnl;
4424
4425 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4426 err = -EOPNOTSUPP;
4427 goto out;
4428 }
4429
4430 if (!rdev->ops->flush_pmksa) {
4431 err = -EOPNOTSUPP;
4432 goto out;
4433 }
4434
4435 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4436
4437 out:
4438 cfg80211_unlock_rdev(rdev);
4439 dev_put(dev);
4440 out_rtnl:
4441 rtnl_unlock();
4442
4443 return err;
4444
4445}
4446
9588bbd5
JM
4447static int nl80211_remain_on_channel(struct sk_buff *skb,
4448 struct genl_info *info)
4449{
4450 struct cfg80211_registered_device *rdev;
4451 struct net_device *dev;
4452 struct ieee80211_channel *chan;
4453 struct sk_buff *msg;
4454 void *hdr;
4455 u64 cookie;
4456 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4457 u32 freq, duration;
4458 int err;
4459
4460 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4461 !info->attrs[NL80211_ATTR_DURATION])
4462 return -EINVAL;
4463
4464 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4465
4466 /*
4467 * We should be on that channel for at least one jiffie,
4468 * and more than 5 seconds seems excessive.
4469 */
4470 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4471 return -EINVAL;
4472
4473 rtnl_lock();
4474
4475 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4476 if (err)
4477 goto unlock_rtnl;
4478
4479 if (!rdev->ops->remain_on_channel) {
4480 err = -EOPNOTSUPP;
4481 goto out;
4482 }
4483
4484 if (!netif_running(dev)) {
4485 err = -ENETDOWN;
4486 goto out;
4487 }
4488
4489 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4490 channel_type = nla_get_u32(
4491 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4492 if (channel_type != NL80211_CHAN_NO_HT &&
4493 channel_type != NL80211_CHAN_HT20 &&
4494 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4495 channel_type != NL80211_CHAN_HT40MINUS) {
9588bbd5
JM
4496 err = -EINVAL;
4497 goto out;
579d7534 4498 }
9588bbd5
JM
4499 }
4500
4501 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4502 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4503 if (chan == NULL) {
4504 err = -EINVAL;
4505 goto out;
4506 }
4507
4508 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4509 if (!msg) {
4510 err = -ENOMEM;
4511 goto out;
4512 }
4513
4514 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4515 NL80211_CMD_REMAIN_ON_CHANNEL);
4516
4517 if (IS_ERR(hdr)) {
4518 err = PTR_ERR(hdr);
4519 goto free_msg;
4520 }
4521
4522 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4523 channel_type, duration, &cookie);
4524
4525 if (err)
4526 goto free_msg;
4527
4528 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4529
4530 genlmsg_end(msg, hdr);
4531 err = genlmsg_reply(msg, info);
4532 goto out;
4533
4534 nla_put_failure:
4535 err = -ENOBUFS;
4536 free_msg:
4537 nlmsg_free(msg);
4538 out:
4539 cfg80211_unlock_rdev(rdev);
4540 dev_put(dev);
4541 unlock_rtnl:
4542 rtnl_unlock();
4543 return err;
4544}
4545
4546static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4547 struct genl_info *info)
4548{
4549 struct cfg80211_registered_device *rdev;
4550 struct net_device *dev;
4551 u64 cookie;
4552 int err;
4553
4554 if (!info->attrs[NL80211_ATTR_COOKIE])
4555 return -EINVAL;
4556
4557 rtnl_lock();
4558
4559 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4560 if (err)
4561 goto unlock_rtnl;
4562
4563 if (!rdev->ops->cancel_remain_on_channel) {
4564 err = -EOPNOTSUPP;
4565 goto out;
4566 }
4567
4568 if (!netif_running(dev)) {
4569 err = -ENETDOWN;
4570 goto out;
4571 }
4572
4573 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4574
4575 err = rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4576
4577 out:
4578 cfg80211_unlock_rdev(rdev);
4579 dev_put(dev);
4580 unlock_rtnl:
4581 rtnl_unlock();
4582 return err;
4583}
4584
13ae75b1
JM
4585static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4586 u8 *rates, u8 rates_len)
4587{
4588 u8 i;
4589 u32 mask = 0;
4590
4591 for (i = 0; i < rates_len; i++) {
4592 int rate = (rates[i] & 0x7f) * 5;
4593 int ridx;
4594 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4595 struct ieee80211_rate *srate =
4596 &sband->bitrates[ridx];
4597 if (rate == srate->bitrate) {
4598 mask |= 1 << ridx;
4599 break;
4600 }
4601 }
4602 if (ridx == sband->n_bitrates)
4603 return 0; /* rate not found */
4604 }
4605
4606 return mask;
4607}
4608
b54452b0 4609static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
4610 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4611 .len = NL80211_MAX_SUPP_RATES },
4612};
4613
4614static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4615 struct genl_info *info)
4616{
4617 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4618 struct cfg80211_registered_device *rdev;
4619 struct cfg80211_bitrate_mask mask;
4620 int err, rem, i;
4621 struct net_device *dev;
4622 struct nlattr *tx_rates;
4623 struct ieee80211_supported_band *sband;
4624
4625 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4626 return -EINVAL;
4627
4628 rtnl_lock();
4629
4630 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4631 if (err)
4632 goto unlock_rtnl;
4633
4634 if (!rdev->ops->set_bitrate_mask) {
4635 err = -EOPNOTSUPP;
4636 goto unlock;
4637 }
4638
4639 memset(&mask, 0, sizeof(mask));
4640 /* Default to all rates enabled */
4641 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4642 sband = rdev->wiphy.bands[i];
4643 mask.control[i].legacy =
4644 sband ? (1 << sband->n_bitrates) - 1 : 0;
4645 }
4646
4647 /*
4648 * The nested attribute uses enum nl80211_band as the index. This maps
4649 * directly to the enum ieee80211_band values used in cfg80211.
4650 */
4651 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4652 {
4653 enum ieee80211_band band = nla_type(tx_rates);
4654 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
4655 err = -EINVAL;
4656 goto unlock;
4657 }
4658 sband = rdev->wiphy.bands[band];
4659 if (sband == NULL) {
4660 err = -EINVAL;
4661 goto unlock;
4662 }
4663 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4664 nla_len(tx_rates), nl80211_txattr_policy);
4665 if (tb[NL80211_TXRATE_LEGACY]) {
4666 mask.control[band].legacy = rateset_to_mask(
4667 sband,
4668 nla_data(tb[NL80211_TXRATE_LEGACY]),
4669 nla_len(tb[NL80211_TXRATE_LEGACY]));
4670 if (mask.control[band].legacy == 0) {
4671 err = -EINVAL;
4672 goto unlock;
4673 }
4674 }
4675 }
4676
4677 err = rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4678
4679 unlock:
4680 dev_put(dev);
4681 cfg80211_unlock_rdev(rdev);
4682 unlock_rtnl:
4683 rtnl_unlock();
4684 return err;
4685}
4686
026331c4
JM
4687static int nl80211_register_action(struct sk_buff *skb, struct genl_info *info)
4688{
4689 struct cfg80211_registered_device *rdev;
4690 struct net_device *dev;
4691 int err;
4692
4693 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4694 return -EINVAL;
4695
4696 if (nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]) < 1)
4697 return -EINVAL;
4698
4699 rtnl_lock();
4700
4701 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4702 if (err)
4703 goto unlock_rtnl;
4704
9d38d85d
JB
4705 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4706 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
026331c4
JM
4707 err = -EOPNOTSUPP;
4708 goto out;
4709 }
4710
4711 /* not much point in registering if we can't reply */
4712 if (!rdev->ops->action) {
4713 err = -EOPNOTSUPP;
4714 goto out;
4715 }
4716
4717 err = cfg80211_mlme_register_action(dev->ieee80211_ptr, info->snd_pid,
4718 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4719 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4720 out:
4721 cfg80211_unlock_rdev(rdev);
4722 dev_put(dev);
4723 unlock_rtnl:
4724 rtnl_unlock();
4725 return err;
4726}
4727
4728static int nl80211_action(struct sk_buff *skb, struct genl_info *info)
4729{
4730 struct cfg80211_registered_device *rdev;
4731 struct net_device *dev;
4732 struct ieee80211_channel *chan;
4733 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 4734 bool channel_type_valid = false;
026331c4
JM
4735 u32 freq;
4736 int err;
4737 void *hdr;
4738 u64 cookie;
4739 struct sk_buff *msg;
4740
4741 if (!info->attrs[NL80211_ATTR_FRAME] ||
4742 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4743 return -EINVAL;
4744
4745 rtnl_lock();
4746
4747 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4748 if (err)
4749 goto unlock_rtnl;
4750
4751 if (!rdev->ops->action) {
4752 err = -EOPNOTSUPP;
4753 goto out;
4754 }
4755
9d38d85d
JB
4756 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4757 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
026331c4
JM
4758 err = -EOPNOTSUPP;
4759 goto out;
4760 }
4761
4762 if (!netif_running(dev)) {
4763 err = -ENETDOWN;
4764 goto out;
4765 }
4766
4767 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4768 channel_type = nla_get_u32(
4769 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4770 if (channel_type != NL80211_CHAN_NO_HT &&
4771 channel_type != NL80211_CHAN_HT20 &&
4772 channel_type != NL80211_CHAN_HT40PLUS &&
579d7534 4773 channel_type != NL80211_CHAN_HT40MINUS) {
026331c4
JM
4774 err = -EINVAL;
4775 goto out;
579d7534 4776 }
252aa631 4777 channel_type_valid = true;
026331c4
JM
4778 }
4779
4780 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4781 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4782 if (chan == NULL) {
4783 err = -EINVAL;
4784 goto out;
4785 }
4786
4787 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4788 if (!msg) {
4789 err = -ENOMEM;
4790 goto out;
4791 }
4792
4793 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4794 NL80211_CMD_ACTION);
4795
4796 if (IS_ERR(hdr)) {
4797 err = PTR_ERR(hdr);
4798 goto free_msg;
4799 }
4800 err = cfg80211_mlme_action(rdev, dev, chan, channel_type,
252aa631 4801 channel_type_valid,
026331c4
JM
4802 nla_data(info->attrs[NL80211_ATTR_FRAME]),
4803 nla_len(info->attrs[NL80211_ATTR_FRAME]),
4804 &cookie);
4805 if (err)
4806 goto free_msg;
4807
4808 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4809
4810 genlmsg_end(msg, hdr);
4811 err = genlmsg_reply(msg, info);
4812 goto out;
4813
4814 nla_put_failure:
4815 err = -ENOBUFS;
4816 free_msg:
4817 nlmsg_free(msg);
4818 out:
4819 cfg80211_unlock_rdev(rdev);
4820 dev_put(dev);
4821unlock_rtnl:
4822 rtnl_unlock();
4823 return err;
4824}
4825
ffb9eb3d
KV
4826static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4827{
4828 struct cfg80211_registered_device *rdev;
4829 struct wireless_dev *wdev;
4830 struct net_device *dev;
4831 u8 ps_state;
4832 bool state;
4833 int err;
4834
4835 if (!info->attrs[NL80211_ATTR_PS_STATE]) {
4836 err = -EINVAL;
4837 goto out;
4838 }
4839
4840 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4841
4842 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) {
4843 err = -EINVAL;
4844 goto out;
4845 }
4846
4847 rtnl_lock();
4848
4849 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4850 if (err)
4851 goto unlock_rdev;
4852
4853 wdev = dev->ieee80211_ptr;
4854
4855 if (!rdev->ops->set_power_mgmt) {
4856 err = -EOPNOTSUPP;
4857 goto unlock_rdev;
4858 }
4859
4860 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4861
4862 if (state == wdev->ps)
4863 goto unlock_rdev;
4864
4865 wdev->ps = state;
4866
4867 if (rdev->ops->set_power_mgmt(wdev->wiphy, dev, wdev->ps,
4868 wdev->ps_timeout))
4869 /* assume this means it's off */
4870 wdev->ps = false;
4871
4872unlock_rdev:
4873 cfg80211_unlock_rdev(rdev);
4874 dev_put(dev);
4875 rtnl_unlock();
4876
4877out:
4878 return err;
4879}
4880
4881static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4882{
4883 struct cfg80211_registered_device *rdev;
4884 enum nl80211_ps_state ps_state;
4885 struct wireless_dev *wdev;
4886 struct net_device *dev;
4887 struct sk_buff *msg;
4888 void *hdr;
4889 int err;
4890
4891 rtnl_lock();
4892
4893 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4894 if (err)
4895 goto unlock_rtnl;
4896
4897 wdev = dev->ieee80211_ptr;
4898
4899 if (!rdev->ops->set_power_mgmt) {
4900 err = -EOPNOTSUPP;
4901 goto out;
4902 }
4903
4904 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4905 if (!msg) {
4906 err = -ENOMEM;
4907 goto out;
4908 }
4909
4910 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4911 NL80211_CMD_GET_POWER_SAVE);
4912 if (!hdr) {
4913 err = -ENOMEM;
4914 goto free_msg;
4915 }
4916
4917 if (wdev->ps)
4918 ps_state = NL80211_PS_ENABLED;
4919 else
4920 ps_state = NL80211_PS_DISABLED;
4921
4922 NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4923
4924 genlmsg_end(msg, hdr);
4925 err = genlmsg_reply(msg, info);
4926 goto out;
4927
4928nla_put_failure:
4929 err = -ENOBUFS;
4930
4931free_msg:
4932 nlmsg_free(msg);
4933
4934out:
4935 cfg80211_unlock_rdev(rdev);
4936 dev_put(dev);
4937
4938unlock_rtnl:
4939 rtnl_unlock();
4940
4941 return err;
4942}
4943
d6dc1a38
JO
4944static struct nla_policy
4945nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4946 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4947 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4948 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4949};
4950
4951static int nl80211_set_cqm_rssi(struct genl_info *info,
4952 s32 threshold, u32 hysteresis)
4953{
4954 struct cfg80211_registered_device *rdev;
4955 struct wireless_dev *wdev;
4956 struct net_device *dev;
4957 int err;
4958
4959 if (threshold > 0)
4960 return -EINVAL;
4961
4962 rtnl_lock();
4963
4964 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4965 if (err)
4966 goto unlock_rdev;
4967
4968 wdev = dev->ieee80211_ptr;
4969
4970 if (!rdev->ops->set_cqm_rssi_config) {
4971 err = -EOPNOTSUPP;
4972 goto unlock_rdev;
4973 }
4974
4975 if (wdev->iftype != NL80211_IFTYPE_STATION) {
4976 err = -EOPNOTSUPP;
4977 goto unlock_rdev;
4978 }
4979
4980 err = rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4981 threshold, hysteresis);
4982
4983unlock_rdev:
4984 cfg80211_unlock_rdev(rdev);
4985 dev_put(dev);
4986 rtnl_unlock();
4987
4988 return err;
4989}
4990
4991static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4992{
4993 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4994 struct nlattr *cqm;
4995 int err;
4996
4997 cqm = info->attrs[NL80211_ATTR_CQM];
4998 if (!cqm) {
4999 err = -EINVAL;
5000 goto out;
5001 }
5002
5003 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
5004 nl80211_attr_cqm_policy);
5005 if (err)
5006 goto out;
5007
5008 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
5009 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
5010 s32 threshold;
5011 u32 hysteresis;
5012 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
5013 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
5014 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
5015 } else
5016 err = -EINVAL;
5017
5018out:
5019 return err;
5020}
5021
55682965
JB
5022static struct genl_ops nl80211_ops[] = {
5023 {
5024 .cmd = NL80211_CMD_GET_WIPHY,
5025 .doit = nl80211_get_wiphy,
5026 .dumpit = nl80211_dump_wiphy,
5027 .policy = nl80211_policy,
5028 /* can be retrieved by unprivileged users */
5029 },
5030 {
5031 .cmd = NL80211_CMD_SET_WIPHY,
5032 .doit = nl80211_set_wiphy,
5033 .policy = nl80211_policy,
5034 .flags = GENL_ADMIN_PERM,
5035 },
5036 {
5037 .cmd = NL80211_CMD_GET_INTERFACE,
5038 .doit = nl80211_get_interface,
5039 .dumpit = nl80211_dump_interface,
5040 .policy = nl80211_policy,
5041 /* can be retrieved by unprivileged users */
5042 },
5043 {
5044 .cmd = NL80211_CMD_SET_INTERFACE,
5045 .doit = nl80211_set_interface,
5046 .policy = nl80211_policy,
5047 .flags = GENL_ADMIN_PERM,
5048 },
5049 {
5050 .cmd = NL80211_CMD_NEW_INTERFACE,
5051 .doit = nl80211_new_interface,
5052 .policy = nl80211_policy,
5053 .flags = GENL_ADMIN_PERM,
5054 },
5055 {
5056 .cmd = NL80211_CMD_DEL_INTERFACE,
5057 .doit = nl80211_del_interface,
5058 .policy = nl80211_policy,
41ade00f
JB
5059 .flags = GENL_ADMIN_PERM,
5060 },
5061 {
5062 .cmd = NL80211_CMD_GET_KEY,
5063 .doit = nl80211_get_key,
5064 .policy = nl80211_policy,
5065 .flags = GENL_ADMIN_PERM,
5066 },
5067 {
5068 .cmd = NL80211_CMD_SET_KEY,
5069 .doit = nl80211_set_key,
5070 .policy = nl80211_policy,
5071 .flags = GENL_ADMIN_PERM,
5072 },
5073 {
5074 .cmd = NL80211_CMD_NEW_KEY,
5075 .doit = nl80211_new_key,
5076 .policy = nl80211_policy,
5077 .flags = GENL_ADMIN_PERM,
5078 },
5079 {
5080 .cmd = NL80211_CMD_DEL_KEY,
5081 .doit = nl80211_del_key,
5082 .policy = nl80211_policy,
55682965
JB
5083 .flags = GENL_ADMIN_PERM,
5084 },
ed1b6cc7
JB
5085 {
5086 .cmd = NL80211_CMD_SET_BEACON,
5087 .policy = nl80211_policy,
5088 .flags = GENL_ADMIN_PERM,
5089 .doit = nl80211_addset_beacon,
5090 },
5091 {
5092 .cmd = NL80211_CMD_NEW_BEACON,
5093 .policy = nl80211_policy,
5094 .flags = GENL_ADMIN_PERM,
5095 .doit = nl80211_addset_beacon,
5096 },
5097 {
5098 .cmd = NL80211_CMD_DEL_BEACON,
5099 .policy = nl80211_policy,
5100 .flags = GENL_ADMIN_PERM,
5101 .doit = nl80211_del_beacon,
5102 },
5727ef1b
JB
5103 {
5104 .cmd = NL80211_CMD_GET_STATION,
5105 .doit = nl80211_get_station,
2ec600d6 5106 .dumpit = nl80211_dump_station,
5727ef1b 5107 .policy = nl80211_policy,
5727ef1b
JB
5108 },
5109 {
5110 .cmd = NL80211_CMD_SET_STATION,
5111 .doit = nl80211_set_station,
5112 .policy = nl80211_policy,
5113 .flags = GENL_ADMIN_PERM,
5114 },
5115 {
5116 .cmd = NL80211_CMD_NEW_STATION,
5117 .doit = nl80211_new_station,
5118 .policy = nl80211_policy,
5119 .flags = GENL_ADMIN_PERM,
5120 },
5121 {
5122 .cmd = NL80211_CMD_DEL_STATION,
5123 .doit = nl80211_del_station,
5124 .policy = nl80211_policy,
2ec600d6
LCC
5125 .flags = GENL_ADMIN_PERM,
5126 },
5127 {
5128 .cmd = NL80211_CMD_GET_MPATH,
5129 .doit = nl80211_get_mpath,
5130 .dumpit = nl80211_dump_mpath,
5131 .policy = nl80211_policy,
5132 .flags = GENL_ADMIN_PERM,
5133 },
5134 {
5135 .cmd = NL80211_CMD_SET_MPATH,
5136 .doit = nl80211_set_mpath,
5137 .policy = nl80211_policy,
5138 .flags = GENL_ADMIN_PERM,
5139 },
5140 {
5141 .cmd = NL80211_CMD_NEW_MPATH,
5142 .doit = nl80211_new_mpath,
5143 .policy = nl80211_policy,
5144 .flags = GENL_ADMIN_PERM,
5145 },
5146 {
5147 .cmd = NL80211_CMD_DEL_MPATH,
5148 .doit = nl80211_del_mpath,
5149 .policy = nl80211_policy,
9f1ba906
JM
5150 .flags = GENL_ADMIN_PERM,
5151 },
5152 {
5153 .cmd = NL80211_CMD_SET_BSS,
5154 .doit = nl80211_set_bss,
5155 .policy = nl80211_policy,
b2e1b302
LR
5156 .flags = GENL_ADMIN_PERM,
5157 },
f130347c
LR
5158 {
5159 .cmd = NL80211_CMD_GET_REG,
5160 .doit = nl80211_get_reg,
5161 .policy = nl80211_policy,
5162 /* can be retrieved by unprivileged users */
5163 },
b2e1b302
LR
5164 {
5165 .cmd = NL80211_CMD_SET_REG,
5166 .doit = nl80211_set_reg,
5167 .policy = nl80211_policy,
5168 .flags = GENL_ADMIN_PERM,
5169 },
5170 {
5171 .cmd = NL80211_CMD_REQ_SET_REG,
5172 .doit = nl80211_req_set_reg,
5173 .policy = nl80211_policy,
93da9cc1 5174 .flags = GENL_ADMIN_PERM,
5175 },
5176 {
5177 .cmd = NL80211_CMD_GET_MESH_PARAMS,
5178 .doit = nl80211_get_mesh_params,
5179 .policy = nl80211_policy,
5180 /* can be retrieved by unprivileged users */
5181 },
5182 {
5183 .cmd = NL80211_CMD_SET_MESH_PARAMS,
5184 .doit = nl80211_set_mesh_params,
5185 .policy = nl80211_policy,
9aed3cc1
JM
5186 .flags = GENL_ADMIN_PERM,
5187 },
2a519311
JB
5188 {
5189 .cmd = NL80211_CMD_TRIGGER_SCAN,
5190 .doit = nl80211_trigger_scan,
5191 .policy = nl80211_policy,
5192 .flags = GENL_ADMIN_PERM,
5193 },
5194 {
5195 .cmd = NL80211_CMD_GET_SCAN,
5196 .policy = nl80211_policy,
5197 .dumpit = nl80211_dump_scan,
5198 },
636a5d36
JM
5199 {
5200 .cmd = NL80211_CMD_AUTHENTICATE,
5201 .doit = nl80211_authenticate,
5202 .policy = nl80211_policy,
5203 .flags = GENL_ADMIN_PERM,
5204 },
5205 {
5206 .cmd = NL80211_CMD_ASSOCIATE,
5207 .doit = nl80211_associate,
5208 .policy = nl80211_policy,
5209 .flags = GENL_ADMIN_PERM,
5210 },
5211 {
5212 .cmd = NL80211_CMD_DEAUTHENTICATE,
5213 .doit = nl80211_deauthenticate,
5214 .policy = nl80211_policy,
5215 .flags = GENL_ADMIN_PERM,
5216 },
5217 {
5218 .cmd = NL80211_CMD_DISASSOCIATE,
5219 .doit = nl80211_disassociate,
5220 .policy = nl80211_policy,
5221 .flags = GENL_ADMIN_PERM,
5222 },
04a773ad
JB
5223 {
5224 .cmd = NL80211_CMD_JOIN_IBSS,
5225 .doit = nl80211_join_ibss,
5226 .policy = nl80211_policy,
5227 .flags = GENL_ADMIN_PERM,
5228 },
5229 {
5230 .cmd = NL80211_CMD_LEAVE_IBSS,
5231 .doit = nl80211_leave_ibss,
5232 .policy = nl80211_policy,
5233 .flags = GENL_ADMIN_PERM,
5234 },
aff89a9b
JB
5235#ifdef CONFIG_NL80211_TESTMODE
5236 {
5237 .cmd = NL80211_CMD_TESTMODE,
5238 .doit = nl80211_testmode_do,
5239 .policy = nl80211_policy,
5240 .flags = GENL_ADMIN_PERM,
5241 },
5242#endif
b23aa676
SO
5243 {
5244 .cmd = NL80211_CMD_CONNECT,
5245 .doit = nl80211_connect,
5246 .policy = nl80211_policy,
5247 .flags = GENL_ADMIN_PERM,
5248 },
5249 {
5250 .cmd = NL80211_CMD_DISCONNECT,
5251 .doit = nl80211_disconnect,
5252 .policy = nl80211_policy,
5253 .flags = GENL_ADMIN_PERM,
5254 },
463d0183
JB
5255 {
5256 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5257 .doit = nl80211_wiphy_netns,
5258 .policy = nl80211_policy,
5259 .flags = GENL_ADMIN_PERM,
5260 },
61fa713c
HS
5261 {
5262 .cmd = NL80211_CMD_GET_SURVEY,
5263 .policy = nl80211_policy,
5264 .dumpit = nl80211_dump_survey,
5265 },
67fbb16b
SO
5266 {
5267 .cmd = NL80211_CMD_SET_PMKSA,
5268 .doit = nl80211_setdel_pmksa,
5269 .policy = nl80211_policy,
5270 .flags = GENL_ADMIN_PERM,
5271 },
5272 {
5273 .cmd = NL80211_CMD_DEL_PMKSA,
5274 .doit = nl80211_setdel_pmksa,
5275 .policy = nl80211_policy,
5276 .flags = GENL_ADMIN_PERM,
5277 },
5278 {
5279 .cmd = NL80211_CMD_FLUSH_PMKSA,
5280 .doit = nl80211_flush_pmksa,
5281 .policy = nl80211_policy,
5282 .flags = GENL_ADMIN_PERM,
5283 },
9588bbd5
JM
5284 {
5285 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5286 .doit = nl80211_remain_on_channel,
5287 .policy = nl80211_policy,
5288 .flags = GENL_ADMIN_PERM,
5289 },
5290 {
5291 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5292 .doit = nl80211_cancel_remain_on_channel,
5293 .policy = nl80211_policy,
5294 .flags = GENL_ADMIN_PERM,
5295 },
13ae75b1
JM
5296 {
5297 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5298 .doit = nl80211_set_tx_bitrate_mask,
5299 .policy = nl80211_policy,
5300 .flags = GENL_ADMIN_PERM,
5301 },
026331c4
JM
5302 {
5303 .cmd = NL80211_CMD_REGISTER_ACTION,
5304 .doit = nl80211_register_action,
5305 .policy = nl80211_policy,
5306 .flags = GENL_ADMIN_PERM,
5307 },
5308 {
5309 .cmd = NL80211_CMD_ACTION,
5310 .doit = nl80211_action,
5311 .policy = nl80211_policy,
5312 .flags = GENL_ADMIN_PERM,
5313 },
ffb9eb3d
KV
5314 {
5315 .cmd = NL80211_CMD_SET_POWER_SAVE,
5316 .doit = nl80211_set_power_save,
5317 .policy = nl80211_policy,
5318 .flags = GENL_ADMIN_PERM,
5319 },
5320 {
5321 .cmd = NL80211_CMD_GET_POWER_SAVE,
5322 .doit = nl80211_get_power_save,
5323 .policy = nl80211_policy,
5324 /* can be retrieved by unprivileged users */
5325 },
d6dc1a38
JO
5326 {
5327 .cmd = NL80211_CMD_SET_CQM,
5328 .doit = nl80211_set_cqm,
5329 .policy = nl80211_policy,
5330 .flags = GENL_ADMIN_PERM,
5331 },
f444de05
JB
5332 {
5333 .cmd = NL80211_CMD_SET_CHANNEL,
5334 .doit = nl80211_set_channel,
5335 .policy = nl80211_policy,
5336 .flags = GENL_ADMIN_PERM,
5337 },
55682965 5338};
9588bbd5 5339
6039f6d2
JM
5340static struct genl_multicast_group nl80211_mlme_mcgrp = {
5341 .name = "mlme",
5342};
55682965
JB
5343
5344/* multicast groups */
5345static struct genl_multicast_group nl80211_config_mcgrp = {
5346 .name = "config",
5347};
2a519311
JB
5348static struct genl_multicast_group nl80211_scan_mcgrp = {
5349 .name = "scan",
5350};
73d54c9e
LR
5351static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5352 .name = "regulatory",
5353};
55682965
JB
5354
5355/* notification functions */
5356
5357void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5358{
5359 struct sk_buff *msg;
5360
fd2120ca 5361 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
5362 if (!msg)
5363 return;
5364
5365 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5366 nlmsg_free(msg);
5367 return;
5368 }
5369
463d0183
JB
5370 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5371 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
5372}
5373
362a415d
JB
5374static int nl80211_add_scan_req(struct sk_buff *msg,
5375 struct cfg80211_registered_device *rdev)
5376{
5377 struct cfg80211_scan_request *req = rdev->scan_req;
5378 struct nlattr *nest;
5379 int i;
5380
667503dd
JB
5381 ASSERT_RDEV_LOCK(rdev);
5382
362a415d
JB
5383 if (WARN_ON(!req))
5384 return 0;
5385
5386 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5387 if (!nest)
5388 goto nla_put_failure;
5389 for (i = 0; i < req->n_ssids; i++)
5390 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5391 nla_nest_end(msg, nest);
5392
5393 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5394 if (!nest)
5395 goto nla_put_failure;
5396 for (i = 0; i < req->n_channels; i++)
5397 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5398 nla_nest_end(msg, nest);
5399
5400 if (req->ie)
5401 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5402
5403 return 0;
5404 nla_put_failure:
5405 return -ENOBUFS;
5406}
5407
a538e2d5
JB
5408static int nl80211_send_scan_msg(struct sk_buff *msg,
5409 struct cfg80211_registered_device *rdev,
5410 struct net_device *netdev,
5411 u32 pid, u32 seq, int flags,
5412 u32 cmd)
2a519311
JB
5413{
5414 void *hdr;
5415
5416 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5417 if (!hdr)
5418 return -1;
5419
b5850a7a 5420 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
5421 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5422
362a415d
JB
5423 /* ignore errors and send incomplete event anyway */
5424 nl80211_add_scan_req(msg, rdev);
2a519311
JB
5425
5426 return genlmsg_end(msg, hdr);
5427
5428 nla_put_failure:
5429 genlmsg_cancel(msg, hdr);
5430 return -EMSGSIZE;
5431}
5432
a538e2d5
JB
5433void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5434 struct net_device *netdev)
5435{
5436 struct sk_buff *msg;
5437
5438 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5439 if (!msg)
5440 return;
5441
5442 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5443 NL80211_CMD_TRIGGER_SCAN) < 0) {
5444 nlmsg_free(msg);
5445 return;
5446 }
5447
463d0183
JB
5448 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5449 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
5450}
5451
2a519311
JB
5452void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5453 struct net_device *netdev)
5454{
5455 struct sk_buff *msg;
5456
fd2120ca 5457 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5458 if (!msg)
5459 return;
5460
a538e2d5
JB
5461 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5462 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
5463 nlmsg_free(msg);
5464 return;
5465 }
5466
463d0183
JB
5467 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5468 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5469}
5470
5471void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5472 struct net_device *netdev)
5473{
5474 struct sk_buff *msg;
5475
fd2120ca 5476 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
5477 if (!msg)
5478 return;
5479
a538e2d5
JB
5480 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5481 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
5482 nlmsg_free(msg);
5483 return;
5484 }
5485
463d0183
JB
5486 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5487 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
5488}
5489
73d54c9e
LR
5490/*
5491 * This can happen on global regulatory changes or device specific settings
5492 * based on custom world regulatory domains.
5493 */
5494void nl80211_send_reg_change_event(struct regulatory_request *request)
5495{
5496 struct sk_buff *msg;
5497 void *hdr;
5498
fd2120ca 5499 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
5500 if (!msg)
5501 return;
5502
5503 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5504 if (!hdr) {
5505 nlmsg_free(msg);
5506 return;
5507 }
5508
5509 /* Userspace can always count this one always being set */
5510 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5511
5512 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5513 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5514 NL80211_REGDOM_TYPE_WORLD);
5515 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5516 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5517 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5518 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5519 request->intersect)
5520 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5521 NL80211_REGDOM_TYPE_INTERSECTION);
5522 else {
5523 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5524 NL80211_REGDOM_TYPE_COUNTRY);
5525 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5526 }
5527
5528 if (wiphy_idx_valid(request->wiphy_idx))
5529 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5530
5531 if (genlmsg_end(msg, hdr) < 0) {
5532 nlmsg_free(msg);
5533 return;
5534 }
5535
bc43b28c 5536 rcu_read_lock();
463d0183 5537 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5538 GFP_ATOMIC);
5539 rcu_read_unlock();
73d54c9e
LR
5540
5541 return;
5542
5543nla_put_failure:
5544 genlmsg_cancel(msg, hdr);
5545 nlmsg_free(msg);
5546}
5547
6039f6d2
JM
5548static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5549 struct net_device *netdev,
5550 const u8 *buf, size_t len,
e6d6e342 5551 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5552{
5553 struct sk_buff *msg;
5554 void *hdr;
5555
e6d6e342 5556 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5557 if (!msg)
5558 return;
5559
5560 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5561 if (!hdr) {
5562 nlmsg_free(msg);
5563 return;
5564 }
5565
5566 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5567 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5568 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5569
5570 if (genlmsg_end(msg, hdr) < 0) {
5571 nlmsg_free(msg);
5572 return;
5573 }
5574
463d0183
JB
5575 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5576 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5577 return;
5578
5579 nla_put_failure:
5580 genlmsg_cancel(msg, hdr);
5581 nlmsg_free(msg);
5582}
5583
5584void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5585 struct net_device *netdev, const u8 *buf,
5586 size_t len, gfp_t gfp)
6039f6d2
JM
5587{
5588 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5589 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5590}
5591
5592void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5593 struct net_device *netdev, const u8 *buf,
e6d6e342 5594 size_t len, gfp_t gfp)
6039f6d2 5595{
e6d6e342
JB
5596 nl80211_send_mlme_event(rdev, netdev, buf, len,
5597 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5598}
5599
53b46b84 5600void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5601 struct net_device *netdev, const u8 *buf,
5602 size_t len, gfp_t gfp)
6039f6d2
JM
5603{
5604 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5605 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5606}
5607
53b46b84
JM
5608void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5609 struct net_device *netdev, const u8 *buf,
e6d6e342 5610 size_t len, gfp_t gfp)
6039f6d2
JM
5611{
5612 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5613 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5614}
5615
1b06bb40
LR
5616static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5617 struct net_device *netdev, int cmd,
e6d6e342 5618 const u8 *addr, gfp_t gfp)
1965c853
JM
5619{
5620 struct sk_buff *msg;
5621 void *hdr;
5622
e6d6e342 5623 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5624 if (!msg)
5625 return;
5626
5627 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5628 if (!hdr) {
5629 nlmsg_free(msg);
5630 return;
5631 }
5632
5633 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5634 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5635 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5636 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5637
5638 if (genlmsg_end(msg, hdr) < 0) {
5639 nlmsg_free(msg);
5640 return;
5641 }
5642
463d0183
JB
5643 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5644 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5645 return;
5646
5647 nla_put_failure:
5648 genlmsg_cancel(msg, hdr);
5649 nlmsg_free(msg);
5650}
5651
5652void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5653 struct net_device *netdev, const u8 *addr,
5654 gfp_t gfp)
1965c853
JM
5655{
5656 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5657 addr, gfp);
1965c853
JM
5658}
5659
5660void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5661 struct net_device *netdev, const u8 *addr,
5662 gfp_t gfp)
1965c853 5663{
e6d6e342
JB
5664 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5665 addr, gfp);
1965c853
JM
5666}
5667
b23aa676
SO
5668void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5669 struct net_device *netdev, const u8 *bssid,
5670 const u8 *req_ie, size_t req_ie_len,
5671 const u8 *resp_ie, size_t resp_ie_len,
5672 u16 status, gfp_t gfp)
5673{
5674 struct sk_buff *msg;
5675 void *hdr;
5676
5677 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5678 if (!msg)
5679 return;
5680
5681 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5682 if (!hdr) {
5683 nlmsg_free(msg);
5684 return;
5685 }
5686
5687 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5688 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5689 if (bssid)
5690 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5691 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5692 if (req_ie)
5693 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5694 if (resp_ie)
5695 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5696
5697 if (genlmsg_end(msg, hdr) < 0) {
5698 nlmsg_free(msg);
5699 return;
5700 }
5701
463d0183
JB
5702 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5703 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5704 return;
5705
5706 nla_put_failure:
5707 genlmsg_cancel(msg, hdr);
5708 nlmsg_free(msg);
5709
5710}
5711
5712void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5713 struct net_device *netdev, const u8 *bssid,
5714 const u8 *req_ie, size_t req_ie_len,
5715 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5716{
5717 struct sk_buff *msg;
5718 void *hdr;
5719
5720 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5721 if (!msg)
5722 return;
5723
5724 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5725 if (!hdr) {
5726 nlmsg_free(msg);
5727 return;
5728 }
5729
5730 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5731 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5732 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5733 if (req_ie)
5734 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5735 if (resp_ie)
5736 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5737
5738 if (genlmsg_end(msg, hdr) < 0) {
5739 nlmsg_free(msg);
5740 return;
5741 }
5742
463d0183
JB
5743 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5744 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5745 return;
5746
5747 nla_put_failure:
5748 genlmsg_cancel(msg, hdr);
5749 nlmsg_free(msg);
5750
5751}
5752
5753void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5754 struct net_device *netdev, u16 reason,
667503dd 5755 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5756{
5757 struct sk_buff *msg;
5758 void *hdr;
5759
667503dd 5760 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5761 if (!msg)
5762 return;
5763
5764 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5765 if (!hdr) {
5766 nlmsg_free(msg);
5767 return;
5768 }
5769
5770 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5771 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5772 if (from_ap && reason)
5773 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5774 if (from_ap)
5775 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5776 if (ie)
5777 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5778
5779 if (genlmsg_end(msg, hdr) < 0) {
5780 nlmsg_free(msg);
5781 return;
5782 }
5783
463d0183
JB
5784 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5785 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5786 return;
5787
5788 nla_put_failure:
5789 genlmsg_cancel(msg, hdr);
5790 nlmsg_free(msg);
5791
5792}
5793
04a773ad
JB
5794void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5795 struct net_device *netdev, const u8 *bssid,
5796 gfp_t gfp)
5797{
5798 struct sk_buff *msg;
5799 void *hdr;
5800
fd2120ca 5801 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5802 if (!msg)
5803 return;
5804
5805 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5806 if (!hdr) {
5807 nlmsg_free(msg);
5808 return;
5809 }
5810
5811 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5812 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5813 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5814
5815 if (genlmsg_end(msg, hdr) < 0) {
5816 nlmsg_free(msg);
5817 return;
5818 }
5819
463d0183
JB
5820 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5821 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5822 return;
5823
5824 nla_put_failure:
5825 genlmsg_cancel(msg, hdr);
5826 nlmsg_free(msg);
5827}
5828
a3b8b056
JM
5829void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5830 struct net_device *netdev, const u8 *addr,
5831 enum nl80211_key_type key_type, int key_id,
e6d6e342 5832 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5833{
5834 struct sk_buff *msg;
5835 void *hdr;
5836
e6d6e342 5837 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5838 if (!msg)
5839 return;
5840
5841 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5842 if (!hdr) {
5843 nlmsg_free(msg);
5844 return;
5845 }
5846
5847 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5848 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5849 if (addr)
5850 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5851 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5852 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5853 if (tsc)
5854 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5855
5856 if (genlmsg_end(msg, hdr) < 0) {
5857 nlmsg_free(msg);
5858 return;
5859 }
5860
463d0183
JB
5861 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5862 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5863 return;
5864
5865 nla_put_failure:
5866 genlmsg_cancel(msg, hdr);
5867 nlmsg_free(msg);
5868}
5869
6bad8766
LR
5870void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5871 struct ieee80211_channel *channel_before,
5872 struct ieee80211_channel *channel_after)
5873{
5874 struct sk_buff *msg;
5875 void *hdr;
5876 struct nlattr *nl_freq;
5877
fd2120ca 5878 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5879 if (!msg)
5880 return;
5881
5882 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5883 if (!hdr) {
5884 nlmsg_free(msg);
5885 return;
5886 }
5887
5888 /*
5889 * Since we are applying the beacon hint to a wiphy we know its
5890 * wiphy_idx is valid
5891 */
5892 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5893
5894 /* Before */
5895 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5896 if (!nl_freq)
5897 goto nla_put_failure;
5898 if (nl80211_msg_put_channel(msg, channel_before))
5899 goto nla_put_failure;
5900 nla_nest_end(msg, nl_freq);
5901
5902 /* After */
5903 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5904 if (!nl_freq)
5905 goto nla_put_failure;
5906 if (nl80211_msg_put_channel(msg, channel_after))
5907 goto nla_put_failure;
5908 nla_nest_end(msg, nl_freq);
5909
5910 if (genlmsg_end(msg, hdr) < 0) {
5911 nlmsg_free(msg);
5912 return;
5913 }
5914
463d0183
JB
5915 rcu_read_lock();
5916 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5917 GFP_ATOMIC);
5918 rcu_read_unlock();
6bad8766
LR
5919
5920 return;
5921
5922nla_put_failure:
5923 genlmsg_cancel(msg, hdr);
5924 nlmsg_free(msg);
5925}
5926
9588bbd5
JM
5927static void nl80211_send_remain_on_chan_event(
5928 int cmd, struct cfg80211_registered_device *rdev,
5929 struct net_device *netdev, u64 cookie,
5930 struct ieee80211_channel *chan,
5931 enum nl80211_channel_type channel_type,
5932 unsigned int duration, gfp_t gfp)
5933{
5934 struct sk_buff *msg;
5935 void *hdr;
5936
5937 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5938 if (!msg)
5939 return;
5940
5941 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5942 if (!hdr) {
5943 nlmsg_free(msg);
5944 return;
5945 }
5946
5947 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5948 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5949 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5950 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5951 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5952
5953 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5954 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5955
5956 if (genlmsg_end(msg, hdr) < 0) {
5957 nlmsg_free(msg);
5958 return;
5959 }
5960
5961 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5962 nl80211_mlme_mcgrp.id, gfp);
5963 return;
5964
5965 nla_put_failure:
5966 genlmsg_cancel(msg, hdr);
5967 nlmsg_free(msg);
5968}
5969
5970void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5971 struct net_device *netdev, u64 cookie,
5972 struct ieee80211_channel *chan,
5973 enum nl80211_channel_type channel_type,
5974 unsigned int duration, gfp_t gfp)
5975{
5976 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5977 rdev, netdev, cookie, chan,
5978 channel_type, duration, gfp);
5979}
5980
5981void nl80211_send_remain_on_channel_cancel(
5982 struct cfg80211_registered_device *rdev, struct net_device *netdev,
5983 u64 cookie, struct ieee80211_channel *chan,
5984 enum nl80211_channel_type channel_type, gfp_t gfp)
5985{
5986 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5987 rdev, netdev, cookie, chan,
5988 channel_type, 0, gfp);
5989}
5990
98b62183
JB
5991void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5992 struct net_device *dev, const u8 *mac_addr,
5993 struct station_info *sinfo, gfp_t gfp)
5994{
5995 struct sk_buff *msg;
5996
5997 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5998 if (!msg)
5999 return;
6000
6001 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
6002 nlmsg_free(msg);
6003 return;
6004 }
6005
6006 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6007 nl80211_mlme_mcgrp.id, gfp);
6008}
6009
026331c4
JM
6010int nl80211_send_action(struct cfg80211_registered_device *rdev,
6011 struct net_device *netdev, u32 nlpid,
6012 int freq, const u8 *buf, size_t len, gfp_t gfp)
6013{
6014 struct sk_buff *msg;
6015 void *hdr;
6016 int err;
6017
6018 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6019 if (!msg)
6020 return -ENOMEM;
6021
6022 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ACTION);
6023 if (!hdr) {
6024 nlmsg_free(msg);
6025 return -ENOMEM;
6026 }
6027
6028 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6029 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6030 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
6031 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6032
6033 err = genlmsg_end(msg, hdr);
6034 if (err < 0) {
6035 nlmsg_free(msg);
6036 return err;
6037 }
6038
6039 err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
6040 if (err < 0)
6041 return err;
6042 return 0;
6043
6044 nla_put_failure:
6045 genlmsg_cancel(msg, hdr);
6046 nlmsg_free(msg);
6047 return -ENOBUFS;
6048}
6049
6050void nl80211_send_action_tx_status(struct cfg80211_registered_device *rdev,
6051 struct net_device *netdev, u64 cookie,
6052 const u8 *buf, size_t len, bool ack,
6053 gfp_t gfp)
6054{
6055 struct sk_buff *msg;
6056 void *hdr;
6057
6058 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6059 if (!msg)
6060 return;
6061
6062 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ACTION_TX_STATUS);
6063 if (!hdr) {
6064 nlmsg_free(msg);
6065 return;
6066 }
6067
6068 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6069 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6070 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
6071 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
6072 if (ack)
6073 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
6074
6075 if (genlmsg_end(msg, hdr) < 0) {
6076 nlmsg_free(msg);
6077 return;
6078 }
6079
6080 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
6081 return;
6082
6083 nla_put_failure:
6084 genlmsg_cancel(msg, hdr);
6085 nlmsg_free(msg);
6086}
6087
d6dc1a38
JO
6088void
6089nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
6090 struct net_device *netdev,
6091 enum nl80211_cqm_rssi_threshold_event rssi_event,
6092 gfp_t gfp)
6093{
6094 struct sk_buff *msg;
6095 struct nlattr *pinfoattr;
6096 void *hdr;
6097
6098 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6099 if (!msg)
6100 return;
6101
6102 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6103 if (!hdr) {
6104 nlmsg_free(msg);
6105 return;
6106 }
6107
6108 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6109 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6110
6111 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6112 if (!pinfoattr)
6113 goto nla_put_failure;
6114
6115 NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
6116 rssi_event);
6117
6118 nla_nest_end(msg, pinfoattr);
6119
6120 if (genlmsg_end(msg, hdr) < 0) {
6121 nlmsg_free(msg);
6122 return;
6123 }
6124
6125 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6126 nl80211_mlme_mcgrp.id, gfp);
6127 return;
6128
6129 nla_put_failure:
6130 genlmsg_cancel(msg, hdr);
6131 nlmsg_free(msg);
6132}
6133
026331c4
JM
6134static int nl80211_netlink_notify(struct notifier_block * nb,
6135 unsigned long state,
6136 void *_notify)
6137{
6138 struct netlink_notify *notify = _notify;
6139 struct cfg80211_registered_device *rdev;
6140 struct wireless_dev *wdev;
6141
6142 if (state != NETLINK_URELEASE)
6143 return NOTIFY_DONE;
6144
6145 rcu_read_lock();
6146
6147 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6148 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
6149 cfg80211_mlme_unregister_actions(wdev, notify->pid);
6150
6151 rcu_read_unlock();
6152
6153 return NOTIFY_DONE;
6154}
6155
6156static struct notifier_block nl80211_netlink_notifier = {
6157 .notifier_call = nl80211_netlink_notify,
6158};
6159
55682965
JB
6160/* initialisation/exit functions */
6161
6162int nl80211_init(void)
6163{
0d63cbb5 6164 int err;
55682965 6165
0d63cbb5
MM
6166 err = genl_register_family_with_ops(&nl80211_fam,
6167 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
6168 if (err)
6169 return err;
6170
55682965
JB
6171 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6172 if (err)
6173 goto err_out;
6174
2a519311
JB
6175 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6176 if (err)
6177 goto err_out;
6178
73d54c9e
LR
6179 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6180 if (err)
6181 goto err_out;
6182
6039f6d2
JM
6183 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6184 if (err)
6185 goto err_out;
6186
aff89a9b
JB
6187#ifdef CONFIG_NL80211_TESTMODE
6188 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6189 if (err)
6190 goto err_out;
6191#endif
6192
026331c4
JM
6193 err = netlink_register_notifier(&nl80211_netlink_notifier);
6194 if (err)
6195 goto err_out;
6196
55682965
JB
6197 return 0;
6198 err_out:
6199 genl_unregister_family(&nl80211_fam);
6200 return err;
6201}
6202
6203void nl80211_exit(void)
6204{
026331c4 6205 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
6206 genl_unregister_family(&nl80211_fam);
6207}