]> bbs.cooldavid.org Git - net-next-2.6.git/blame - net/wireless/nl80211.c
ipv6: drop unused "dev" arg of icmpv6_send()
[net-next-2.6.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
08645126 4 * Copyright 2006-2009 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
55682965
JB
10#include <linux/list.h>
11#include <linux/if_ether.h>
12#include <linux/ieee80211.h>
13#include <linux/nl80211.h>
14#include <linux/rtnetlink.h>
15#include <linux/netlink.h>
2a519311 16#include <linux/etherdevice.h>
463d0183 17#include <net/net_namespace.h>
55682965
JB
18#include <net/genetlink.h>
19#include <net/cfg80211.h>
463d0183 20#include <net/sock.h>
55682965
JB
21#include "core.h"
22#include "nl80211.h"
b2e1b302 23#include "reg.h"
55682965
JB
24
25/* the netlink family */
26static struct genl_family nl80211_fam = {
27 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
28 .name = "nl80211", /* have users key off the name instead */
29 .hdrsize = 0, /* no private header */
30 .version = 1, /* no particular meaning now */
31 .maxattr = NL80211_ATTR_MAX,
463d0183 32 .netnsok = true,
55682965
JB
33};
34
79c97e97 35/* internal helper: get rdev and dev */
463d0183 36static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
79c97e97 37 struct cfg80211_registered_device **rdev,
55682965
JB
38 struct net_device **dev)
39{
463d0183 40 struct nlattr **attrs = info->attrs;
55682965
JB
41 int ifindex;
42
bba95fef 43 if (!attrs[NL80211_ATTR_IFINDEX])
55682965
JB
44 return -EINVAL;
45
bba95fef 46 ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
463d0183 47 *dev = dev_get_by_index(genl_info_net(info), ifindex);
55682965
JB
48 if (!*dev)
49 return -ENODEV;
50
463d0183 51 *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
79c97e97 52 if (IS_ERR(*rdev)) {
55682965 53 dev_put(*dev);
79c97e97 54 return PTR_ERR(*rdev);
55682965
JB
55 }
56
57 return 0;
58}
59
60/* policy for the attributes */
61static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
62 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
63 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 64 .len = 20-1 },
31888487 65 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 66 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 67 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
68 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
69 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
70 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
71 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 72 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
73
74 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
75 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
76 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f
JB
77
78 [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
3e5d7649 79 [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
41ade00f 80
b9454e83 81 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
82 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
83 .len = WLAN_MAX_KEY_LEN },
84 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
85 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
86 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
9f26a952 87 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
ed1b6cc7
JB
88
89 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
90 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
91 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
92 .len = IEEE80211_MAX_DATA_LEN },
93 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
94 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
95 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
96 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
97 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
98 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
99 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 100 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 101 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 102 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6
LCC
103 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
104 .len = IEEE80211_MAX_MESH_ID_LEN },
105 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 106
b2e1b302
LR
107 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
108 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
109
9f1ba906
JM
110 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
111 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
112 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
113 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
114 .len = NL80211_MAX_SUPP_RATES },
36aedc90 115
93da9cc1 116 [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
117
36aedc90
JM
118 [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
119 .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
120
121 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
122 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
123 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
124 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
125 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
126
127 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
128 .len = IEEE80211_MAX_SSID_LEN },
129 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
130 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 131 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 132 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 133 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
134 [NL80211_ATTR_STA_FLAGS2] = {
135 .len = sizeof(struct nl80211_sta_flag_update),
136 },
3f77316c 137 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
b23aa676
SO
138 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
139 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
140 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 141 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 142 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
143 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
144 .len = WLAN_PMKID_LEN },
9588bbd5
JM
145 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
146 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 147 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
55682965
JB
148};
149
b9454e83
JB
150/* policy for the attributes */
151static struct nla_policy
152nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
fffd0934 153 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
154 [NL80211_KEY_IDX] = { .type = NLA_U8 },
155 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
156 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
157 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
158 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
159};
160
a043897a
HS
161/* ifidx get helper */
162static int nl80211_get_ifidx(struct netlink_callback *cb)
163{
164 int res;
165
166 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
167 nl80211_fam.attrbuf, nl80211_fam.maxattr,
168 nl80211_policy);
169 if (res)
170 return res;
171
172 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
173 return -EINVAL;
174
175 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
176 if (!res)
177 return -EINVAL;
178 return res;
179}
180
f4a11bb0
JB
181/* IE validation */
182static bool is_valid_ie_attr(const struct nlattr *attr)
183{
184 const u8 *pos;
185 int len;
186
187 if (!attr)
188 return true;
189
190 pos = nla_data(attr);
191 len = nla_len(attr);
192
193 while (len) {
194 u8 elemlen;
195
196 if (len < 2)
197 return false;
198 len -= 2;
199
200 elemlen = pos[1];
201 if (elemlen > len)
202 return false;
203
204 len -= elemlen;
205 pos += 2 + elemlen;
206 }
207
208 return true;
209}
210
55682965
JB
211/* message building helper */
212static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
213 int flags, u8 cmd)
214{
215 /* since there is no private header just add the generic one */
216 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
217}
218
5dab3b8a
LR
219static int nl80211_msg_put_channel(struct sk_buff *msg,
220 struct ieee80211_channel *chan)
221{
222 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
223 chan->center_freq);
224
225 if (chan->flags & IEEE80211_CHAN_DISABLED)
226 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
227 if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
228 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
229 if (chan->flags & IEEE80211_CHAN_NO_IBSS)
230 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
231 if (chan->flags & IEEE80211_CHAN_RADAR)
232 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
233
234 NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
235 DBM_TO_MBM(chan->max_power));
236
237 return 0;
238
239 nla_put_failure:
240 return -ENOBUFS;
241}
242
55682965
JB
243/* netlink command implementations */
244
b9454e83
JB
245struct key_parse {
246 struct key_params p;
247 int idx;
248 bool def, defmgmt;
249};
250
251static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
252{
253 struct nlattr *tb[NL80211_KEY_MAX + 1];
254 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
255 nl80211_key_policy);
256 if (err)
257 return err;
258
259 k->def = !!tb[NL80211_KEY_DEFAULT];
260 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
261
262 if (tb[NL80211_KEY_IDX])
263 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
264
265 if (tb[NL80211_KEY_DATA]) {
266 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
267 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
268 }
269
270 if (tb[NL80211_KEY_SEQ]) {
271 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
272 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
273 }
274
275 if (tb[NL80211_KEY_CIPHER])
276 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
277
278 return 0;
279}
280
281static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
282{
283 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
284 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
285 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
286 }
287
288 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
289 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
290 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
291 }
292
293 if (info->attrs[NL80211_ATTR_KEY_IDX])
294 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
295
296 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
297 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
298
299 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
300 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
301
302 return 0;
303}
304
305static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
306{
307 int err;
308
309 memset(k, 0, sizeof(*k));
310 k->idx = -1;
311
312 if (info->attrs[NL80211_ATTR_KEY])
313 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
314 else
315 err = nl80211_parse_key_old(info, k);
316
317 if (err)
318 return err;
319
320 if (k->def && k->defmgmt)
321 return -EINVAL;
322
323 if (k->idx != -1) {
324 if (k->defmgmt) {
325 if (k->idx < 4 || k->idx > 5)
326 return -EINVAL;
327 } else if (k->def) {
328 if (k->idx < 0 || k->idx > 3)
329 return -EINVAL;
330 } else {
331 if (k->idx < 0 || k->idx > 5)
332 return -EINVAL;
333 }
334 }
335
336 return 0;
337}
338
fffd0934
JB
339static struct cfg80211_cached_keys *
340nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
341 struct nlattr *keys)
342{
343 struct key_parse parse;
344 struct nlattr *key;
345 struct cfg80211_cached_keys *result;
346 int rem, err, def = 0;
347
348 result = kzalloc(sizeof(*result), GFP_KERNEL);
349 if (!result)
350 return ERR_PTR(-ENOMEM);
351
352 result->def = -1;
353 result->defmgmt = -1;
354
355 nla_for_each_nested(key, keys, rem) {
356 memset(&parse, 0, sizeof(parse));
357 parse.idx = -1;
358
359 err = nl80211_parse_key_new(key, &parse);
360 if (err)
361 goto error;
362 err = -EINVAL;
363 if (!parse.p.key)
364 goto error;
365 if (parse.idx < 0 || parse.idx > 4)
366 goto error;
367 if (parse.def) {
368 if (def)
369 goto error;
370 def = 1;
371 result->def = parse.idx;
372 } else if (parse.defmgmt)
373 goto error;
374 err = cfg80211_validate_key_settings(rdev, &parse.p,
375 parse.idx, NULL);
376 if (err)
377 goto error;
378 result->params[parse.idx].cipher = parse.p.cipher;
379 result->params[parse.idx].key_len = parse.p.key_len;
380 result->params[parse.idx].key = result->data[parse.idx];
381 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
382 }
383
384 return result;
385 error:
386 kfree(result);
387 return ERR_PTR(err);
388}
389
390static int nl80211_key_allowed(struct wireless_dev *wdev)
391{
392 ASSERT_WDEV_LOCK(wdev);
393
394 if (!netif_running(wdev->netdev))
395 return -ENETDOWN;
396
397 switch (wdev->iftype) {
398 case NL80211_IFTYPE_AP:
399 case NL80211_IFTYPE_AP_VLAN:
400 break;
401 case NL80211_IFTYPE_ADHOC:
402 if (!wdev->current_bss)
403 return -ENOLINK;
404 break;
405 case NL80211_IFTYPE_STATION:
406 if (wdev->sme_state != CFG80211_SME_CONNECTED)
407 return -ENOLINK;
408 break;
409 default:
410 return -EINVAL;
411 }
412
413 return 0;
414}
415
55682965
JB
416static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
417 struct cfg80211_registered_device *dev)
418{
419 void *hdr;
ee688b00
JB
420 struct nlattr *nl_bands, *nl_band;
421 struct nlattr *nl_freqs, *nl_freq;
422 struct nlattr *nl_rates, *nl_rate;
f59ac048 423 struct nlattr *nl_modes;
8fdc621d 424 struct nlattr *nl_cmds;
ee688b00
JB
425 enum ieee80211_band band;
426 struct ieee80211_channel *chan;
427 struct ieee80211_rate *rate;
428 int i;
f59ac048 429 u16 ifmodes = dev->wiphy.interface_modes;
55682965
JB
430
431 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
432 if (!hdr)
433 return -1;
434
b5850a7a 435 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
55682965 436 NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
b9a5f8ca 437
f5ea9120
JB
438 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
439 cfg80211_rdev_list_generation);
440
b9a5f8ca
JM
441 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
442 dev->wiphy.retry_short);
443 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
444 dev->wiphy.retry_long);
445 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
446 dev->wiphy.frag_threshold);
447 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
448 dev->wiphy.rts_threshold);
81077e82
LT
449 NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
450 dev->wiphy.coverage_class);
b9a5f8ca 451
2a519311
JB
452 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
453 dev->wiphy.max_scan_ssids);
18a83659
JB
454 NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
455 dev->wiphy.max_scan_ie_len);
ee688b00 456
25e47c18
JB
457 NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
458 sizeof(u32) * dev->wiphy.n_cipher_suites,
459 dev->wiphy.cipher_suites);
460
67fbb16b
SO
461 NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
462 dev->wiphy.max_num_pmkids);
463
f59ac048
LR
464 nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
465 if (!nl_modes)
466 goto nla_put_failure;
467
468 i = 0;
469 while (ifmodes) {
470 if (ifmodes & 1)
471 NLA_PUT_FLAG(msg, i);
472 ifmodes >>= 1;
473 i++;
474 }
475
476 nla_nest_end(msg, nl_modes);
477
ee688b00
JB
478 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
479 if (!nl_bands)
480 goto nla_put_failure;
481
482 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
483 if (!dev->wiphy.bands[band])
484 continue;
485
486 nl_band = nla_nest_start(msg, band);
487 if (!nl_band)
488 goto nla_put_failure;
489
d51626df
JB
490 /* add HT info */
491 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
492 NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
493 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
494 &dev->wiphy.bands[band]->ht_cap.mcs);
495 NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
496 dev->wiphy.bands[band]->ht_cap.cap);
497 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
498 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
499 NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
500 dev->wiphy.bands[band]->ht_cap.ampdu_density);
501 }
502
ee688b00
JB
503 /* add frequencies */
504 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
505 if (!nl_freqs)
506 goto nla_put_failure;
507
508 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
509 nl_freq = nla_nest_start(msg, i);
510 if (!nl_freq)
511 goto nla_put_failure;
512
513 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
514
515 if (nl80211_msg_put_channel(msg, chan))
516 goto nla_put_failure;
e2f367f2 517
ee688b00
JB
518 nla_nest_end(msg, nl_freq);
519 }
520
521 nla_nest_end(msg, nl_freqs);
522
523 /* add bitrates */
524 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
525 if (!nl_rates)
526 goto nla_put_failure;
527
528 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
529 nl_rate = nla_nest_start(msg, i);
530 if (!nl_rate)
531 goto nla_put_failure;
532
533 rate = &dev->wiphy.bands[band]->bitrates[i];
534 NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
535 rate->bitrate);
536 if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
537 NLA_PUT_FLAG(msg,
538 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
539
540 nla_nest_end(msg, nl_rate);
541 }
542
543 nla_nest_end(msg, nl_rates);
544
545 nla_nest_end(msg, nl_band);
546 }
547 nla_nest_end(msg, nl_bands);
548
8fdc621d
JB
549 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
550 if (!nl_cmds)
551 goto nla_put_failure;
552
553 i = 0;
554#define CMD(op, n) \
555 do { \
556 if (dev->ops->op) { \
557 i++; \
558 NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
559 } \
560 } while (0)
561
562 CMD(add_virtual_intf, NEW_INTERFACE);
563 CMD(change_virtual_intf, SET_INTERFACE);
564 CMD(add_key, NEW_KEY);
565 CMD(add_beacon, NEW_BEACON);
566 CMD(add_station, NEW_STATION);
567 CMD(add_mpath, NEW_MPATH);
568 CMD(set_mesh_params, SET_MESH_PARAMS);
569 CMD(change_bss, SET_BSS);
636a5d36
JM
570 CMD(auth, AUTHENTICATE);
571 CMD(assoc, ASSOCIATE);
572 CMD(deauth, DEAUTHENTICATE);
573 CMD(disassoc, DISASSOCIATE);
04a773ad 574 CMD(join_ibss, JOIN_IBSS);
67fbb16b
SO
575 CMD(set_pmksa, SET_PMKSA);
576 CMD(del_pmksa, DEL_PMKSA);
577 CMD(flush_pmksa, FLUSH_PMKSA);
9588bbd5 578 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 579 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
5be83de5 580 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183
JB
581 i++;
582 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
583 }
8fdc621d
JB
584
585#undef CMD
b23aa676 586
6829c878 587 if (dev->ops->connect || dev->ops->auth) {
b23aa676
SO
588 i++;
589 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
590 }
591
6829c878 592 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676
SO
593 i++;
594 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
595 }
596
8fdc621d
JB
597 nla_nest_end(msg, nl_cmds);
598
55682965
JB
599 return genlmsg_end(msg, hdr);
600
601 nla_put_failure:
bc3ed28c
TG
602 genlmsg_cancel(msg, hdr);
603 return -EMSGSIZE;
55682965
JB
604}
605
606static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
607{
608 int idx = 0;
609 int start = cb->args[0];
610 struct cfg80211_registered_device *dev;
611
a1794390 612 mutex_lock(&cfg80211_mutex);
79c97e97 613 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
614 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
615 continue;
b4637271 616 if (++idx <= start)
55682965
JB
617 continue;
618 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
619 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
620 dev) < 0) {
621 idx--;
55682965 622 break;
b4637271 623 }
55682965 624 }
a1794390 625 mutex_unlock(&cfg80211_mutex);
55682965
JB
626
627 cb->args[0] = idx;
628
629 return skb->len;
630}
631
632static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
633{
634 struct sk_buff *msg;
635 struct cfg80211_registered_device *dev;
636
637 dev = cfg80211_get_dev_from_info(info);
638 if (IS_ERR(dev))
639 return PTR_ERR(dev);
640
fd2120ca 641 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
642 if (!msg)
643 goto out_err;
644
645 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
646 goto out_free;
647
4d0c8aea 648 cfg80211_unlock_rdev(dev);
55682965 649
134e6375 650 return genlmsg_reply(msg, info);
55682965
JB
651
652 out_free:
653 nlmsg_free(msg);
654 out_err:
4d0c8aea 655 cfg80211_unlock_rdev(dev);
55682965
JB
656 return -ENOBUFS;
657}
658
31888487
JM
659static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
660 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
661 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
662 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
663 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
664 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
665};
666
667static int parse_txq_params(struct nlattr *tb[],
668 struct ieee80211_txq_params *txq_params)
669{
670 if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
671 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
672 !tb[NL80211_TXQ_ATTR_AIFS])
673 return -EINVAL;
674
675 txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
676 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
677 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
678 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
679 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
680
681 return 0;
682}
683
55682965
JB
684static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
685{
686 struct cfg80211_registered_device *rdev;
31888487
JM
687 int result = 0, rem_txq_params = 0;
688 struct nlattr *nl_txq_params;
b9a5f8ca
JM
689 u32 changed;
690 u8 retry_short = 0, retry_long = 0;
691 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 692 u8 coverage_class = 0;
55682965 693
4bbf4d56 694 rtnl_lock();
55682965 695
4bbf4d56
JB
696 mutex_lock(&cfg80211_mutex);
697
79c97e97 698 rdev = __cfg80211_rdev_from_info(info);
4bbf4d56 699 if (IS_ERR(rdev)) {
1f5fc70a 700 mutex_unlock(&cfg80211_mutex);
4bbf4d56
JB
701 result = PTR_ERR(rdev);
702 goto unlock;
703 }
704
705 mutex_lock(&rdev->mtx);
706
707 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
708 result = cfg80211_dev_rename(
709 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
710
711 mutex_unlock(&cfg80211_mutex);
712
713 if (result)
714 goto bad_res;
31888487
JM
715
716 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
717 struct ieee80211_txq_params txq_params;
718 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
719
720 if (!rdev->ops->set_txq_params) {
721 result = -EOPNOTSUPP;
722 goto bad_res;
723 }
724
725 nla_for_each_nested(nl_txq_params,
726 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
727 rem_txq_params) {
728 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
729 nla_data(nl_txq_params),
730 nla_len(nl_txq_params),
731 txq_params_policy);
732 result = parse_txq_params(tb, &txq_params);
733 if (result)
734 goto bad_res;
735
736 result = rdev->ops->set_txq_params(&rdev->wiphy,
737 &txq_params);
738 if (result)
739 goto bad_res;
740 }
741 }
55682965 742
72bdcf34 743 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
094d05dc 744 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
294196ab 745 u32 freq;
72bdcf34 746
306d6112
JB
747 result = -EINVAL;
748
094d05dc
S
749 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
750 channel_type = nla_get_u32(info->attrs[
751 NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
752 if (channel_type != NL80211_CHAN_NO_HT &&
753 channel_type != NL80211_CHAN_HT20 &&
754 channel_type != NL80211_CHAN_HT40PLUS &&
755 channel_type != NL80211_CHAN_HT40MINUS)
72bdcf34 756 goto bad_res;
72bdcf34
JM
757 }
758
759 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
306d6112 760
59bbb6f7 761 mutex_lock(&rdev->devlist_mtx);
4b181144 762 result = rdev_set_freq(rdev, NULL, freq, channel_type);
59bbb6f7 763 mutex_unlock(&rdev->devlist_mtx);
72bdcf34
JM
764 if (result)
765 goto bad_res;
766 }
767
b9a5f8ca
JM
768 changed = 0;
769
770 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
771 retry_short = nla_get_u8(
772 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
773 if (retry_short == 0) {
774 result = -EINVAL;
775 goto bad_res;
776 }
777 changed |= WIPHY_PARAM_RETRY_SHORT;
778 }
779
780 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
781 retry_long = nla_get_u8(
782 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
783 if (retry_long == 0) {
784 result = -EINVAL;
785 goto bad_res;
786 }
787 changed |= WIPHY_PARAM_RETRY_LONG;
788 }
789
790 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
791 frag_threshold = nla_get_u32(
792 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
793 if (frag_threshold < 256) {
794 result = -EINVAL;
795 goto bad_res;
796 }
797 if (frag_threshold != (u32) -1) {
798 /*
799 * Fragments (apart from the last one) are required to
800 * have even length. Make the fragmentation code
801 * simpler by stripping LSB should someone try to use
802 * odd threshold value.
803 */
804 frag_threshold &= ~0x1;
805 }
806 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
807 }
808
809 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
810 rts_threshold = nla_get_u32(
811 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
812 changed |= WIPHY_PARAM_RTS_THRESHOLD;
813 }
814
81077e82
LT
815 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
816 coverage_class = nla_get_u8(
817 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
818 changed |= WIPHY_PARAM_COVERAGE_CLASS;
819 }
820
b9a5f8ca
JM
821 if (changed) {
822 u8 old_retry_short, old_retry_long;
823 u32 old_frag_threshold, old_rts_threshold;
81077e82 824 u8 old_coverage_class;
b9a5f8ca
JM
825
826 if (!rdev->ops->set_wiphy_params) {
827 result = -EOPNOTSUPP;
828 goto bad_res;
829 }
830
831 old_retry_short = rdev->wiphy.retry_short;
832 old_retry_long = rdev->wiphy.retry_long;
833 old_frag_threshold = rdev->wiphy.frag_threshold;
834 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 835 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
836
837 if (changed & WIPHY_PARAM_RETRY_SHORT)
838 rdev->wiphy.retry_short = retry_short;
839 if (changed & WIPHY_PARAM_RETRY_LONG)
840 rdev->wiphy.retry_long = retry_long;
841 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
842 rdev->wiphy.frag_threshold = frag_threshold;
843 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
844 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
845 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
846 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
847
848 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
849 if (result) {
850 rdev->wiphy.retry_short = old_retry_short;
851 rdev->wiphy.retry_long = old_retry_long;
852 rdev->wiphy.frag_threshold = old_frag_threshold;
853 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 854 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
855 }
856 }
72bdcf34 857
306d6112 858 bad_res:
4bbf4d56
JB
859 mutex_unlock(&rdev->mtx);
860 unlock:
861 rtnl_unlock();
55682965
JB
862 return result;
863}
864
865
866static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 867 struct cfg80211_registered_device *rdev,
55682965
JB
868 struct net_device *dev)
869{
870 void *hdr;
871
872 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
873 if (!hdr)
874 return -1;
875
876 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
d726405a 877 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
55682965 878 NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
60719ffd 879 NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
f5ea9120
JB
880
881 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
882 rdev->devlist_generation ^
883 (cfg80211_rdev_list_generation << 2));
884
55682965
JB
885 return genlmsg_end(msg, hdr);
886
887 nla_put_failure:
bc3ed28c
TG
888 genlmsg_cancel(msg, hdr);
889 return -EMSGSIZE;
55682965
JB
890}
891
892static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
893{
894 int wp_idx = 0;
895 int if_idx = 0;
896 int wp_start = cb->args[0];
897 int if_start = cb->args[1];
f5ea9120 898 struct cfg80211_registered_device *rdev;
55682965
JB
899 struct wireless_dev *wdev;
900
a1794390 901 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
902 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
903 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 904 continue;
bba95fef
JB
905 if (wp_idx < wp_start) {
906 wp_idx++;
55682965 907 continue;
bba95fef 908 }
55682965
JB
909 if_idx = 0;
910
f5ea9120
JB
911 mutex_lock(&rdev->devlist_mtx);
912 list_for_each_entry(wdev, &rdev->netdev_list, list) {
bba95fef
JB
913 if (if_idx < if_start) {
914 if_idx++;
55682965 915 continue;
bba95fef 916 }
55682965
JB
917 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
918 cb->nlh->nlmsg_seq, NLM_F_MULTI,
f5ea9120
JB
919 rdev, wdev->netdev) < 0) {
920 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
921 goto out;
922 }
923 if_idx++;
55682965 924 }
f5ea9120 925 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
926
927 wp_idx++;
55682965 928 }
bba95fef 929 out:
a1794390 930 mutex_unlock(&cfg80211_mutex);
55682965
JB
931
932 cb->args[0] = wp_idx;
933 cb->args[1] = if_idx;
934
935 return skb->len;
936}
937
938static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
939{
940 struct sk_buff *msg;
941 struct cfg80211_registered_device *dev;
942 struct net_device *netdev;
943 int err;
944
463d0183 945 err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
55682965
JB
946 if (err)
947 return err;
948
fd2120ca 949 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
950 if (!msg)
951 goto out_err;
952
d726405a
JB
953 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
954 dev, netdev) < 0)
55682965
JB
955 goto out_free;
956
957 dev_put(netdev);
4d0c8aea 958 cfg80211_unlock_rdev(dev);
55682965 959
134e6375 960 return genlmsg_reply(msg, info);
55682965
JB
961
962 out_free:
963 nlmsg_free(msg);
964 out_err:
965 dev_put(netdev);
4d0c8aea 966 cfg80211_unlock_rdev(dev);
55682965
JB
967 return -ENOBUFS;
968}
969
66f7ac50
MW
970static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
971 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
972 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
973 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
974 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
975 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
976};
977
978static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
979{
980 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
981 int flag;
982
983 *mntrflags = 0;
984
985 if (!nla)
986 return -EINVAL;
987
988 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
989 nla, mntr_flags_policy))
990 return -EINVAL;
991
992 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
993 if (flags[flag])
994 *mntrflags |= (1<<flag);
995
996 return 0;
997}
998
9bc383de 999static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1000 struct net_device *netdev, u8 use_4addr,
1001 enum nl80211_iftype iftype)
9bc383de 1002{
ad4bb6f8
JB
1003 if (!use_4addr) {
1004 if (netdev && netdev->br_port)
1005 return -EBUSY;
9bc383de 1006 return 0;
ad4bb6f8 1007 }
9bc383de
JB
1008
1009 switch (iftype) {
1010 case NL80211_IFTYPE_AP_VLAN:
1011 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1012 return 0;
1013 break;
1014 case NL80211_IFTYPE_STATION:
1015 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1016 return 0;
1017 break;
1018 default:
1019 break;
1020 }
1021
1022 return -EOPNOTSUPP;
1023}
1024
55682965
JB
1025static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1026{
79c97e97 1027 struct cfg80211_registered_device *rdev;
2ec600d6 1028 struct vif_params params;
e36d56b6 1029 int err;
04a773ad 1030 enum nl80211_iftype otype, ntype;
55682965 1031 struct net_device *dev;
92ffe055 1032 u32 _flags, *flags = NULL;
ac7f9cfa 1033 bool change = false;
55682965 1034
2ec600d6
LCC
1035 memset(&params, 0, sizeof(params));
1036
3b85875a
JB
1037 rtnl_lock();
1038
463d0183 1039 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1040 if (err)
3b85875a
JB
1041 goto unlock_rtnl;
1042
04a773ad 1043 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1044
723b038d 1045 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1046 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1047 if (otype != ntype)
ac7f9cfa 1048 change = true;
04a773ad 1049 if (ntype > NL80211_IFTYPE_MAX) {
ac7f9cfa 1050 err = -EINVAL;
723b038d 1051 goto unlock;
ac7f9cfa 1052 }
723b038d
JB
1053 }
1054
92ffe055 1055 if (info->attrs[NL80211_ATTR_MESH_ID]) {
04a773ad 1056 if (ntype != NL80211_IFTYPE_MESH_POINT) {
92ffe055
JB
1057 err = -EINVAL;
1058 goto unlock;
1059 }
2ec600d6
LCC
1060 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1061 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
ac7f9cfa 1062 change = true;
2ec600d6
LCC
1063 }
1064
8b787643
FF
1065 if (info->attrs[NL80211_ATTR_4ADDR]) {
1066 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1067 change = true;
ad4bb6f8 1068 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de
JB
1069 if (err)
1070 goto unlock;
8b787643
FF
1071 } else {
1072 params.use_4addr = -1;
1073 }
1074
92ffe055 1075 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
04a773ad 1076 if (ntype != NL80211_IFTYPE_MONITOR) {
92ffe055
JB
1077 err = -EINVAL;
1078 goto unlock;
1079 }
1080 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1081 &_flags);
ac7f9cfa
JB
1082 if (err)
1083 goto unlock;
1084
1085 flags = &_flags;
1086 change = true;
92ffe055 1087 }
3b85875a 1088
ac7f9cfa 1089 if (change)
3d54d255 1090 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1091 else
1092 err = 0;
60719ffd 1093
9bc383de
JB
1094 if (!err && params.use_4addr != -1)
1095 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1096
55682965 1097 unlock:
e36d56b6 1098 dev_put(dev);
79c97e97 1099 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1100 unlock_rtnl:
1101 rtnl_unlock();
55682965
JB
1102 return err;
1103}
1104
1105static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1106{
79c97e97 1107 struct cfg80211_registered_device *rdev;
2ec600d6 1108 struct vif_params params;
55682965
JB
1109 int err;
1110 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1111 u32 flags;
55682965 1112
2ec600d6
LCC
1113 memset(&params, 0, sizeof(params));
1114
55682965
JB
1115 if (!info->attrs[NL80211_ATTR_IFNAME])
1116 return -EINVAL;
1117
1118 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1119 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1120 if (type > NL80211_IFTYPE_MAX)
1121 return -EINVAL;
1122 }
1123
3b85875a
JB
1124 rtnl_lock();
1125
79c97e97
JB
1126 rdev = cfg80211_get_dev_from_info(info);
1127 if (IS_ERR(rdev)) {
1128 err = PTR_ERR(rdev);
3b85875a
JB
1129 goto unlock_rtnl;
1130 }
55682965 1131
79c97e97
JB
1132 if (!rdev->ops->add_virtual_intf ||
1133 !(rdev->wiphy.interface_modes & (1 << type))) {
55682965
JB
1134 err = -EOPNOTSUPP;
1135 goto unlock;
1136 }
1137
2ec600d6
LCC
1138 if (type == NL80211_IFTYPE_MESH_POINT &&
1139 info->attrs[NL80211_ATTR_MESH_ID]) {
1140 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1141 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1142 }
1143
9bc383de 1144 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1145 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1146 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de
JB
1147 if (err)
1148 goto unlock;
1149 }
8b787643 1150
66f7ac50
MW
1151 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1152 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1153 &flags);
79c97e97 1154 err = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 1155 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 1156 type, err ? NULL : &flags, &params);
2ec600d6 1157
55682965 1158 unlock:
79c97e97 1159 cfg80211_unlock_rdev(rdev);
3b85875a
JB
1160 unlock_rtnl:
1161 rtnl_unlock();
55682965
JB
1162 return err;
1163}
1164
1165static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1166{
79c97e97 1167 struct cfg80211_registered_device *rdev;
463d0183 1168 int err;
55682965
JB
1169 struct net_device *dev;
1170
3b85875a
JB
1171 rtnl_lock();
1172
463d0183 1173 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
55682965 1174 if (err)
3b85875a 1175 goto unlock_rtnl;
55682965 1176
79c97e97 1177 if (!rdev->ops->del_virtual_intf) {
55682965
JB
1178 err = -EOPNOTSUPP;
1179 goto out;
1180 }
1181
463d0183 1182 err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
1183
1184 out:
79c97e97 1185 cfg80211_unlock_rdev(rdev);
463d0183 1186 dev_put(dev);
3b85875a
JB
1187 unlock_rtnl:
1188 rtnl_unlock();
55682965
JB
1189 return err;
1190}
1191
41ade00f
JB
1192struct get_key_cookie {
1193 struct sk_buff *msg;
1194 int error;
b9454e83 1195 int idx;
41ade00f
JB
1196};
1197
1198static void get_key_callback(void *c, struct key_params *params)
1199{
b9454e83 1200 struct nlattr *key;
41ade00f
JB
1201 struct get_key_cookie *cookie = c;
1202
1203 if (params->key)
1204 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1205 params->key_len, params->key);
1206
1207 if (params->seq)
1208 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1209 params->seq_len, params->seq);
1210
1211 if (params->cipher)
1212 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1213 params->cipher);
1214
b9454e83
JB
1215 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1216 if (!key)
1217 goto nla_put_failure;
1218
1219 if (params->key)
1220 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1221 params->key_len, params->key);
1222
1223 if (params->seq)
1224 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1225 params->seq_len, params->seq);
1226
1227 if (params->cipher)
1228 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1229 params->cipher);
1230
1231 NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1232
1233 nla_nest_end(cookie->msg, key);
1234
41ade00f
JB
1235 return;
1236 nla_put_failure:
1237 cookie->error = 1;
1238}
1239
1240static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1241{
79c97e97 1242 struct cfg80211_registered_device *rdev;
41ade00f
JB
1243 int err;
1244 struct net_device *dev;
1245 u8 key_idx = 0;
1246 u8 *mac_addr = NULL;
1247 struct get_key_cookie cookie = {
1248 .error = 0,
1249 };
1250 void *hdr;
1251 struct sk_buff *msg;
1252
1253 if (info->attrs[NL80211_ATTR_KEY_IDX])
1254 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1255
3cfcf6ac 1256 if (key_idx > 5)
41ade00f
JB
1257 return -EINVAL;
1258
1259 if (info->attrs[NL80211_ATTR_MAC])
1260 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1261
3b85875a
JB
1262 rtnl_lock();
1263
463d0183 1264 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1265 if (err)
3b85875a 1266 goto unlock_rtnl;
41ade00f 1267
79c97e97 1268 if (!rdev->ops->get_key) {
41ade00f
JB
1269 err = -EOPNOTSUPP;
1270 goto out;
1271 }
1272
fd2120ca 1273 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
41ade00f
JB
1274 if (!msg) {
1275 err = -ENOMEM;
1276 goto out;
1277 }
1278
1279 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1280 NL80211_CMD_NEW_KEY);
1281
1282 if (IS_ERR(hdr)) {
1283 err = PTR_ERR(hdr);
6c95e2a2 1284 goto free_msg;
41ade00f
JB
1285 }
1286
1287 cookie.msg = msg;
b9454e83 1288 cookie.idx = key_idx;
41ade00f
JB
1289
1290 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1291 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1292 if (mac_addr)
1293 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1294
79c97e97 1295 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
41ade00f 1296 &cookie, get_key_callback);
41ade00f
JB
1297
1298 if (err)
6c95e2a2 1299 goto free_msg;
41ade00f
JB
1300
1301 if (cookie.error)
1302 goto nla_put_failure;
1303
1304 genlmsg_end(msg, hdr);
134e6375 1305 err = genlmsg_reply(msg, info);
41ade00f
JB
1306 goto out;
1307
1308 nla_put_failure:
1309 err = -ENOBUFS;
6c95e2a2 1310 free_msg:
41ade00f
JB
1311 nlmsg_free(msg);
1312 out:
79c97e97 1313 cfg80211_unlock_rdev(rdev);
41ade00f 1314 dev_put(dev);
3b85875a
JB
1315 unlock_rtnl:
1316 rtnl_unlock();
1317
41ade00f
JB
1318 return err;
1319}
1320
1321static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1322{
79c97e97 1323 struct cfg80211_registered_device *rdev;
b9454e83 1324 struct key_parse key;
41ade00f
JB
1325 int err;
1326 struct net_device *dev;
3cfcf6ac
JM
1327 int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1328 u8 key_index);
41ade00f 1329
b9454e83
JB
1330 err = nl80211_parse_key(info, &key);
1331 if (err)
1332 return err;
41ade00f 1333
b9454e83 1334 if (key.idx < 0)
41ade00f
JB
1335 return -EINVAL;
1336
b9454e83
JB
1337 /* only support setting default key */
1338 if (!key.def && !key.defmgmt)
41ade00f
JB
1339 return -EINVAL;
1340
3b85875a
JB
1341 rtnl_lock();
1342
463d0183 1343 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1344 if (err)
3b85875a 1345 goto unlock_rtnl;
41ade00f 1346
b9454e83 1347 if (key.def)
79c97e97 1348 func = rdev->ops->set_default_key;
3cfcf6ac 1349 else
79c97e97 1350 func = rdev->ops->set_default_mgmt_key;
3cfcf6ac
JM
1351
1352 if (!func) {
41ade00f
JB
1353 err = -EOPNOTSUPP;
1354 goto out;
1355 }
1356
fffd0934
JB
1357 wdev_lock(dev->ieee80211_ptr);
1358 err = nl80211_key_allowed(dev->ieee80211_ptr);
1359 if (!err)
1360 err = func(&rdev->wiphy, dev, key.idx);
1361
3d23e349 1362#ifdef CONFIG_CFG80211_WEXT
08645126 1363 if (!err) {
79c97e97 1364 if (func == rdev->ops->set_default_key)
b9454e83 1365 dev->ieee80211_ptr->wext.default_key = key.idx;
08645126 1366 else
b9454e83 1367 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126
JB
1368 }
1369#endif
fffd0934 1370 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1371
1372 out:
79c97e97 1373 cfg80211_unlock_rdev(rdev);
41ade00f 1374 dev_put(dev);
3b85875a
JB
1375
1376 unlock_rtnl:
1377 rtnl_unlock();
1378
41ade00f
JB
1379 return err;
1380}
1381
1382static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1383{
79c97e97 1384 struct cfg80211_registered_device *rdev;
fffd0934 1385 int err;
41ade00f 1386 struct net_device *dev;
b9454e83 1387 struct key_parse key;
41ade00f
JB
1388 u8 *mac_addr = NULL;
1389
b9454e83
JB
1390 err = nl80211_parse_key(info, &key);
1391 if (err)
1392 return err;
41ade00f 1393
b9454e83 1394 if (!key.p.key)
41ade00f
JB
1395 return -EINVAL;
1396
41ade00f
JB
1397 if (info->attrs[NL80211_ATTR_MAC])
1398 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1399
3b85875a
JB
1400 rtnl_lock();
1401
463d0183 1402 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1403 if (err)
3b85875a 1404 goto unlock_rtnl;
41ade00f 1405
fffd0934
JB
1406 if (!rdev->ops->add_key) {
1407 err = -EOPNOTSUPP;
25e47c18
JB
1408 goto out;
1409 }
1410
fffd0934
JB
1411 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
1412 err = -EINVAL;
41ade00f
JB
1413 goto out;
1414 }
1415
fffd0934
JB
1416 wdev_lock(dev->ieee80211_ptr);
1417 err = nl80211_key_allowed(dev->ieee80211_ptr);
1418 if (!err)
1419 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1420 mac_addr, &key.p);
1421 wdev_unlock(dev->ieee80211_ptr);
41ade00f
JB
1422
1423 out:
79c97e97 1424 cfg80211_unlock_rdev(rdev);
41ade00f 1425 dev_put(dev);
3b85875a
JB
1426 unlock_rtnl:
1427 rtnl_unlock();
1428
41ade00f
JB
1429 return err;
1430}
1431
1432static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1433{
79c97e97 1434 struct cfg80211_registered_device *rdev;
41ade00f
JB
1435 int err;
1436 struct net_device *dev;
41ade00f 1437 u8 *mac_addr = NULL;
b9454e83 1438 struct key_parse key;
41ade00f 1439
b9454e83
JB
1440 err = nl80211_parse_key(info, &key);
1441 if (err)
1442 return err;
41ade00f
JB
1443
1444 if (info->attrs[NL80211_ATTR_MAC])
1445 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1446
3b85875a
JB
1447 rtnl_lock();
1448
463d0183 1449 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
41ade00f 1450 if (err)
3b85875a 1451 goto unlock_rtnl;
41ade00f 1452
79c97e97 1453 if (!rdev->ops->del_key) {
41ade00f
JB
1454 err = -EOPNOTSUPP;
1455 goto out;
1456 }
1457
fffd0934
JB
1458 wdev_lock(dev->ieee80211_ptr);
1459 err = nl80211_key_allowed(dev->ieee80211_ptr);
1460 if (!err)
1461 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
41ade00f 1462
3d23e349 1463#ifdef CONFIG_CFG80211_WEXT
08645126 1464 if (!err) {
b9454e83 1465 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 1466 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 1467 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
1468 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1469 }
1470#endif
fffd0934 1471 wdev_unlock(dev->ieee80211_ptr);
08645126 1472
41ade00f 1473 out:
79c97e97 1474 cfg80211_unlock_rdev(rdev);
41ade00f 1475 dev_put(dev);
3b85875a
JB
1476
1477 unlock_rtnl:
1478 rtnl_unlock();
1479
41ade00f
JB
1480 return err;
1481}
1482
ed1b6cc7
JB
1483static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1484{
1485 int (*call)(struct wiphy *wiphy, struct net_device *dev,
1486 struct beacon_parameters *info);
79c97e97 1487 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1488 int err;
1489 struct net_device *dev;
1490 struct beacon_parameters params;
1491 int haveinfo = 0;
1492
f4a11bb0
JB
1493 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1494 return -EINVAL;
1495
3b85875a
JB
1496 rtnl_lock();
1497
463d0183 1498 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1499 if (err)
3b85875a 1500 goto unlock_rtnl;
ed1b6cc7 1501
eec60b03
JM
1502 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1503 err = -EOPNOTSUPP;
1504 goto out;
1505 }
1506
ed1b6cc7
JB
1507 switch (info->genlhdr->cmd) {
1508 case NL80211_CMD_NEW_BEACON:
1509 /* these are required for NEW_BEACON */
1510 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1511 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1512 !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1513 err = -EINVAL;
1514 goto out;
1515 }
1516
79c97e97 1517 call = rdev->ops->add_beacon;
ed1b6cc7
JB
1518 break;
1519 case NL80211_CMD_SET_BEACON:
79c97e97 1520 call = rdev->ops->set_beacon;
ed1b6cc7
JB
1521 break;
1522 default:
1523 WARN_ON(1);
1524 err = -EOPNOTSUPP;
1525 goto out;
1526 }
1527
1528 if (!call) {
1529 err = -EOPNOTSUPP;
1530 goto out;
1531 }
1532
1533 memset(&params, 0, sizeof(params));
1534
1535 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1536 params.interval =
1537 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1538 haveinfo = 1;
1539 }
1540
1541 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1542 params.dtim_period =
1543 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1544 haveinfo = 1;
1545 }
1546
1547 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1548 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1549 params.head_len =
1550 nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1551 haveinfo = 1;
1552 }
1553
1554 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1555 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1556 params.tail_len =
1557 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1558 haveinfo = 1;
1559 }
1560
1561 if (!haveinfo) {
1562 err = -EINVAL;
1563 goto out;
1564 }
1565
79c97e97 1566 err = call(&rdev->wiphy, dev, &params);
ed1b6cc7
JB
1567
1568 out:
79c97e97 1569 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1570 dev_put(dev);
3b85875a
JB
1571 unlock_rtnl:
1572 rtnl_unlock();
1573
ed1b6cc7
JB
1574 return err;
1575}
1576
1577static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1578{
79c97e97 1579 struct cfg80211_registered_device *rdev;
ed1b6cc7
JB
1580 int err;
1581 struct net_device *dev;
1582
3b85875a
JB
1583 rtnl_lock();
1584
463d0183 1585 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
ed1b6cc7 1586 if (err)
3b85875a 1587 goto unlock_rtnl;
ed1b6cc7 1588
79c97e97 1589 if (!rdev->ops->del_beacon) {
ed1b6cc7
JB
1590 err = -EOPNOTSUPP;
1591 goto out;
1592 }
1593
eec60b03
JM
1594 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
1595 err = -EOPNOTSUPP;
1596 goto out;
1597 }
79c97e97 1598 err = rdev->ops->del_beacon(&rdev->wiphy, dev);
ed1b6cc7
JB
1599
1600 out:
79c97e97 1601 cfg80211_unlock_rdev(rdev);
ed1b6cc7 1602 dev_put(dev);
3b85875a
JB
1603 unlock_rtnl:
1604 rtnl_unlock();
1605
ed1b6cc7
JB
1606 return err;
1607}
1608
5727ef1b
JB
1609static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1610 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1611 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1612 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 1613 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
5727ef1b
JB
1614};
1615
eccb8e8f
JB
1616static int parse_station_flags(struct genl_info *info,
1617 struct station_parameters *params)
5727ef1b
JB
1618{
1619 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 1620 struct nlattr *nla;
5727ef1b
JB
1621 int flag;
1622
eccb8e8f
JB
1623 /*
1624 * Try parsing the new attribute first so userspace
1625 * can specify both for older kernels.
1626 */
1627 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1628 if (nla) {
1629 struct nl80211_sta_flag_update *sta_flags;
1630
1631 sta_flags = nla_data(nla);
1632 params->sta_flags_mask = sta_flags->mask;
1633 params->sta_flags_set = sta_flags->set;
1634 if ((params->sta_flags_mask |
1635 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1636 return -EINVAL;
1637 return 0;
1638 }
1639
1640 /* if present, parse the old attribute */
5727ef1b 1641
eccb8e8f 1642 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
1643 if (!nla)
1644 return 0;
1645
1646 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1647 nla, sta_flags_policy))
1648 return -EINVAL;
1649
eccb8e8f
JB
1650 params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1651 params->sta_flags_mask &= ~1;
5727ef1b
JB
1652
1653 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1654 if (flags[flag])
eccb8e8f 1655 params->sta_flags_set |= (1<<flag);
5727ef1b
JB
1656
1657 return 0;
1658}
1659
fd5b74dc
JB
1660static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1661 int flags, struct net_device *dev,
98b62183 1662 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
1663{
1664 void *hdr;
420e7fab
HR
1665 struct nlattr *sinfoattr, *txrate;
1666 u16 bitrate;
fd5b74dc
JB
1667
1668 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1669 if (!hdr)
1670 return -1;
1671
1672 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1673 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1674
f5ea9120
JB
1675 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1676
2ec600d6
LCC
1677 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1678 if (!sinfoattr)
fd5b74dc 1679 goto nla_put_failure;
2ec600d6
LCC
1680 if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1681 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1682 sinfo->inactive_time);
1683 if (sinfo->filled & STATION_INFO_RX_BYTES)
1684 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1685 sinfo->rx_bytes);
1686 if (sinfo->filled & STATION_INFO_TX_BYTES)
1687 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1688 sinfo->tx_bytes);
1689 if (sinfo->filled & STATION_INFO_LLID)
1690 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1691 sinfo->llid);
1692 if (sinfo->filled & STATION_INFO_PLID)
1693 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1694 sinfo->plid);
1695 if (sinfo->filled & STATION_INFO_PLINK_STATE)
1696 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1697 sinfo->plink_state);
420e7fab
HR
1698 if (sinfo->filled & STATION_INFO_SIGNAL)
1699 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1700 sinfo->signal);
1701 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1702 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1703 if (!txrate)
1704 goto nla_put_failure;
1705
254416aa
JL
1706 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1707 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
420e7fab
HR
1708 if (bitrate > 0)
1709 NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2ec600d6 1710
420e7fab
HR
1711 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1712 NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1713 sinfo->txrate.mcs);
1714 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1715 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1716 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1717 NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1718
1719 nla_nest_end(msg, txrate);
1720 }
98c8a60a
JM
1721 if (sinfo->filled & STATION_INFO_RX_PACKETS)
1722 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1723 sinfo->rx_packets);
1724 if (sinfo->filled & STATION_INFO_TX_PACKETS)
1725 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1726 sinfo->tx_packets);
2ec600d6 1727 nla_nest_end(msg, sinfoattr);
fd5b74dc
JB
1728
1729 return genlmsg_end(msg, hdr);
1730
1731 nla_put_failure:
bc3ed28c
TG
1732 genlmsg_cancel(msg, hdr);
1733 return -EMSGSIZE;
fd5b74dc
JB
1734}
1735
2ec600d6 1736static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 1737 struct netlink_callback *cb)
2ec600d6 1738{
2ec600d6
LCC
1739 struct station_info sinfo;
1740 struct cfg80211_registered_device *dev;
bba95fef 1741 struct net_device *netdev;
2ec600d6 1742 u8 mac_addr[ETH_ALEN];
bba95fef
JB
1743 int ifidx = cb->args[0];
1744 int sta_idx = cb->args[1];
2ec600d6 1745 int err;
2ec600d6 1746
a043897a
HS
1747 if (!ifidx)
1748 ifidx = nl80211_get_ifidx(cb);
1749 if (ifidx < 0)
1750 return ifidx;
2ec600d6 1751
3b85875a
JB
1752 rtnl_lock();
1753
463d0183 1754 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
1755 if (!netdev) {
1756 err = -ENODEV;
1757 goto out_rtnl;
1758 }
2ec600d6 1759
463d0183 1760 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
1761 if (IS_ERR(dev)) {
1762 err = PTR_ERR(dev);
3b85875a 1763 goto out_rtnl;
bba95fef
JB
1764 }
1765
1766 if (!dev->ops->dump_station) {
eec60b03 1767 err = -EOPNOTSUPP;
bba95fef
JB
1768 goto out_err;
1769 }
1770
bba95fef
JB
1771 while (1) {
1772 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1773 mac_addr, &sinfo);
1774 if (err == -ENOENT)
1775 break;
1776 if (err)
3b85875a 1777 goto out_err;
bba95fef
JB
1778
1779 if (nl80211_send_station(skb,
1780 NETLINK_CB(cb->skb).pid,
1781 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1782 netdev, mac_addr,
1783 &sinfo) < 0)
1784 goto out;
1785
1786 sta_idx++;
1787 }
1788
1789
1790 out:
1791 cb->args[1] = sta_idx;
1792 err = skb->len;
bba95fef 1793 out_err:
4d0c8aea 1794 cfg80211_unlock_rdev(dev);
3b85875a
JB
1795 out_rtnl:
1796 rtnl_unlock();
bba95fef
JB
1797
1798 return err;
2ec600d6 1799}
fd5b74dc 1800
5727ef1b
JB
1801static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1802{
79c97e97 1803 struct cfg80211_registered_device *rdev;
fd5b74dc
JB
1804 int err;
1805 struct net_device *dev;
2ec600d6 1806 struct station_info sinfo;
fd5b74dc
JB
1807 struct sk_buff *msg;
1808 u8 *mac_addr = NULL;
1809
2ec600d6 1810 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
1811
1812 if (!info->attrs[NL80211_ATTR_MAC])
1813 return -EINVAL;
1814
1815 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1816
3b85875a
JB
1817 rtnl_lock();
1818
463d0183 1819 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
fd5b74dc 1820 if (err)
3b85875a 1821 goto out_rtnl;
fd5b74dc 1822
79c97e97 1823 if (!rdev->ops->get_station) {
fd5b74dc
JB
1824 err = -EOPNOTSUPP;
1825 goto out;
1826 }
1827
79c97e97 1828 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2ec600d6
LCC
1829 if (err)
1830 goto out;
1831
fd2120ca 1832 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc
JB
1833 if (!msg)
1834 goto out;
1835
1836 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2ec600d6 1837 dev, mac_addr, &sinfo) < 0)
fd5b74dc
JB
1838 goto out_free;
1839
134e6375 1840 err = genlmsg_reply(msg, info);
fd5b74dc
JB
1841 goto out;
1842
1843 out_free:
1844 nlmsg_free(msg);
fd5b74dc 1845 out:
79c97e97 1846 cfg80211_unlock_rdev(rdev);
fd5b74dc 1847 dev_put(dev);
3b85875a
JB
1848 out_rtnl:
1849 rtnl_unlock();
1850
fd5b74dc 1851 return err;
5727ef1b
JB
1852}
1853
1854/*
c258d2de 1855 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 1856 */
463d0183 1857static int get_vlan(struct genl_info *info,
5727ef1b
JB
1858 struct cfg80211_registered_device *rdev,
1859 struct net_device **vlan)
1860{
463d0183 1861 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
5727ef1b
JB
1862 *vlan = NULL;
1863
1864 if (vlanattr) {
463d0183
JB
1865 *vlan = dev_get_by_index(genl_info_net(info),
1866 nla_get_u32(vlanattr));
5727ef1b
JB
1867 if (!*vlan)
1868 return -ENODEV;
1869 if (!(*vlan)->ieee80211_ptr)
1870 return -EINVAL;
1871 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
1872 return -EINVAL;
c258d2de
FF
1873 if (!netif_running(*vlan))
1874 return -ENETDOWN;
5727ef1b
JB
1875 }
1876 return 0;
1877}
1878
1879static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
1880{
79c97e97 1881 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1882 int err;
1883 struct net_device *dev;
1884 struct station_parameters params;
1885 u8 *mac_addr = NULL;
1886
1887 memset(&params, 0, sizeof(params));
1888
1889 params.listen_interval = -1;
1890
1891 if (info->attrs[NL80211_ATTR_STA_AID])
1892 return -EINVAL;
1893
1894 if (!info->attrs[NL80211_ATTR_MAC])
1895 return -EINVAL;
1896
1897 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1898
1899 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
1900 params.supported_rates =
1901 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1902 params.supported_rates_len =
1903 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
1904 }
1905
1906 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
1907 params.listen_interval =
1908 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1909
36aedc90
JM
1910 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
1911 params.ht_capa =
1912 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1913
eccb8e8f 1914 if (parse_station_flags(info, &params))
5727ef1b
JB
1915 return -EINVAL;
1916
2ec600d6
LCC
1917 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
1918 params.plink_action =
1919 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
1920
3b85875a
JB
1921 rtnl_lock();
1922
463d0183 1923 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 1924 if (err)
3b85875a 1925 goto out_rtnl;
5727ef1b 1926
463d0183 1927 err = get_vlan(info, rdev, &params.vlan);
a97f4424 1928 if (err)
034d655e 1929 goto out;
a97f4424
JB
1930
1931 /* validate settings */
1932 err = 0;
1933
1934 switch (dev->ieee80211_ptr->iftype) {
1935 case NL80211_IFTYPE_AP:
1936 case NL80211_IFTYPE_AP_VLAN:
1937 /* disallow mesh-specific things */
1938 if (params.plink_action)
1939 err = -EINVAL;
1940 break;
1941 case NL80211_IFTYPE_STATION:
1942 /* disallow everything but AUTHORIZED flag */
1943 if (params.plink_action)
1944 err = -EINVAL;
1945 if (params.vlan)
1946 err = -EINVAL;
1947 if (params.supported_rates)
1948 err = -EINVAL;
1949 if (params.ht_capa)
1950 err = -EINVAL;
1951 if (params.listen_interval >= 0)
1952 err = -EINVAL;
1953 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
1954 err = -EINVAL;
1955 break;
1956 case NL80211_IFTYPE_MESH_POINT:
1957 /* disallow things mesh doesn't support */
1958 if (params.vlan)
1959 err = -EINVAL;
1960 if (params.ht_capa)
1961 err = -EINVAL;
1962 if (params.listen_interval >= 0)
1963 err = -EINVAL;
1964 if (params.supported_rates)
1965 err = -EINVAL;
1966 if (params.sta_flags_mask)
1967 err = -EINVAL;
1968 break;
1969 default:
1970 err = -EINVAL;
034d655e
JB
1971 }
1972
5727ef1b
JB
1973 if (err)
1974 goto out;
1975
79c97e97 1976 if (!rdev->ops->change_station) {
5727ef1b
JB
1977 err = -EOPNOTSUPP;
1978 goto out;
1979 }
1980
79c97e97 1981 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
1982
1983 out:
1984 if (params.vlan)
1985 dev_put(params.vlan);
79c97e97 1986 cfg80211_unlock_rdev(rdev);
5727ef1b 1987 dev_put(dev);
3b85875a
JB
1988 out_rtnl:
1989 rtnl_unlock();
1990
5727ef1b
JB
1991 return err;
1992}
1993
1994static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
1995{
79c97e97 1996 struct cfg80211_registered_device *rdev;
5727ef1b
JB
1997 int err;
1998 struct net_device *dev;
1999 struct station_parameters params;
2000 u8 *mac_addr = NULL;
2001
2002 memset(&params, 0, sizeof(params));
2003
2004 if (!info->attrs[NL80211_ATTR_MAC])
2005 return -EINVAL;
2006
5727ef1b
JB
2007 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2008 return -EINVAL;
2009
2010 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2011 return -EINVAL;
2012
2013 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2014 params.supported_rates =
2015 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2016 params.supported_rates_len =
2017 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2018 params.listen_interval =
2019 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 2020
a97f4424
JB
2021 if (info->attrs[NL80211_ATTR_STA_AID]) {
2022 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2023 if (!params.aid || params.aid > IEEE80211_MAX_AID)
2024 return -EINVAL;
2025 }
51b50fbe 2026
36aedc90
JM
2027 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2028 params.ht_capa =
2029 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 2030
eccb8e8f 2031 if (parse_station_flags(info, &params))
5727ef1b
JB
2032 return -EINVAL;
2033
3b85875a
JB
2034 rtnl_lock();
2035
463d0183 2036 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2037 if (err)
3b85875a 2038 goto out_rtnl;
5727ef1b 2039
463d0183 2040 err = get_vlan(info, rdev, &params.vlan);
a97f4424 2041 if (err)
e80cf853 2042 goto out;
a97f4424
JB
2043
2044 /* validate settings */
2045 err = 0;
2046
2047 switch (dev->ieee80211_ptr->iftype) {
2048 case NL80211_IFTYPE_AP:
2049 case NL80211_IFTYPE_AP_VLAN:
2050 /* all ok but must have AID */
2051 if (!params.aid)
2052 err = -EINVAL;
2053 break;
2054 case NL80211_IFTYPE_MESH_POINT:
2055 /* disallow things mesh doesn't support */
2056 if (params.vlan)
2057 err = -EINVAL;
2058 if (params.aid)
2059 err = -EINVAL;
2060 if (params.ht_capa)
2061 err = -EINVAL;
2062 if (params.listen_interval >= 0)
2063 err = -EINVAL;
2064 if (params.supported_rates)
2065 err = -EINVAL;
2066 if (params.sta_flags_mask)
2067 err = -EINVAL;
2068 break;
2069 default:
2070 err = -EINVAL;
e80cf853
JB
2071 }
2072
5727ef1b
JB
2073 if (err)
2074 goto out;
2075
79c97e97 2076 if (!rdev->ops->add_station) {
5727ef1b
JB
2077 err = -EOPNOTSUPP;
2078 goto out;
2079 }
2080
35a8efe1
JM
2081 if (!netif_running(dev)) {
2082 err = -ENETDOWN;
2083 goto out;
2084 }
2085
79c97e97 2086 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b
JB
2087
2088 out:
2089 if (params.vlan)
2090 dev_put(params.vlan);
79c97e97 2091 cfg80211_unlock_rdev(rdev);
5727ef1b 2092 dev_put(dev);
3b85875a
JB
2093 out_rtnl:
2094 rtnl_unlock();
2095
5727ef1b
JB
2096 return err;
2097}
2098
2099static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2100{
79c97e97 2101 struct cfg80211_registered_device *rdev;
5727ef1b
JB
2102 int err;
2103 struct net_device *dev;
2104 u8 *mac_addr = NULL;
2105
2106 if (info->attrs[NL80211_ATTR_MAC])
2107 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2108
3b85875a
JB
2109 rtnl_lock();
2110
463d0183 2111 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
5727ef1b 2112 if (err)
3b85875a 2113 goto out_rtnl;
5727ef1b 2114
e80cf853 2115 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
155cc9e4
AY
2116 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2117 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
e80cf853
JB
2118 err = -EINVAL;
2119 goto out;
2120 }
2121
79c97e97 2122 if (!rdev->ops->del_station) {
5727ef1b
JB
2123 err = -EOPNOTSUPP;
2124 goto out;
2125 }
2126
79c97e97 2127 err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
2128
2129 out:
79c97e97 2130 cfg80211_unlock_rdev(rdev);
5727ef1b 2131 dev_put(dev);
3b85875a
JB
2132 out_rtnl:
2133 rtnl_unlock();
2134
5727ef1b
JB
2135 return err;
2136}
2137
2ec600d6
LCC
2138static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2139 int flags, struct net_device *dev,
2140 u8 *dst, u8 *next_hop,
2141 struct mpath_info *pinfo)
2142{
2143 void *hdr;
2144 struct nlattr *pinfoattr;
2145
2146 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2147 if (!hdr)
2148 return -1;
2149
2150 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2151 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2152 NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2153
f5ea9120
JB
2154 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2155
2ec600d6
LCC
2156 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2157 if (!pinfoattr)
2158 goto nla_put_failure;
2159 if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2160 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2161 pinfo->frame_qlen);
d19b3bf6
RP
2162 if (pinfo->filled & MPATH_INFO_SN)
2163 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2164 pinfo->sn);
2ec600d6
LCC
2165 if (pinfo->filled & MPATH_INFO_METRIC)
2166 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2167 pinfo->metric);
2168 if (pinfo->filled & MPATH_INFO_EXPTIME)
2169 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2170 pinfo->exptime);
2171 if (pinfo->filled & MPATH_INFO_FLAGS)
2172 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2173 pinfo->flags);
2174 if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2175 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2176 pinfo->discovery_timeout);
2177 if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2178 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2179 pinfo->discovery_retries);
2180
2181 nla_nest_end(msg, pinfoattr);
2182
2183 return genlmsg_end(msg, hdr);
2184
2185 nla_put_failure:
bc3ed28c
TG
2186 genlmsg_cancel(msg, hdr);
2187 return -EMSGSIZE;
2ec600d6
LCC
2188}
2189
2190static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 2191 struct netlink_callback *cb)
2ec600d6 2192{
2ec600d6
LCC
2193 struct mpath_info pinfo;
2194 struct cfg80211_registered_device *dev;
bba95fef 2195 struct net_device *netdev;
2ec600d6
LCC
2196 u8 dst[ETH_ALEN];
2197 u8 next_hop[ETH_ALEN];
bba95fef
JB
2198 int ifidx = cb->args[0];
2199 int path_idx = cb->args[1];
2ec600d6 2200 int err;
2ec600d6 2201
a043897a
HS
2202 if (!ifidx)
2203 ifidx = nl80211_get_ifidx(cb);
2204 if (ifidx < 0)
2205 return ifidx;
bba95fef 2206
3b85875a
JB
2207 rtnl_lock();
2208
463d0183 2209 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3b85875a
JB
2210 if (!netdev) {
2211 err = -ENODEV;
2212 goto out_rtnl;
2213 }
bba95fef 2214
463d0183 2215 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
bba95fef
JB
2216 if (IS_ERR(dev)) {
2217 err = PTR_ERR(dev);
3b85875a 2218 goto out_rtnl;
bba95fef
JB
2219 }
2220
2221 if (!dev->ops->dump_mpath) {
eec60b03 2222 err = -EOPNOTSUPP;
bba95fef
JB
2223 goto out_err;
2224 }
2225
eec60b03
JM
2226 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2227 err = -EOPNOTSUPP;
0448b5fc 2228 goto out_err;
eec60b03
JM
2229 }
2230
bba95fef
JB
2231 while (1) {
2232 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2233 dst, next_hop, &pinfo);
2234 if (err == -ENOENT)
2ec600d6 2235 break;
bba95fef 2236 if (err)
3b85875a 2237 goto out_err;
2ec600d6 2238
bba95fef
JB
2239 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2240 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2241 netdev, dst, next_hop,
2242 &pinfo) < 0)
2243 goto out;
2ec600d6 2244
bba95fef 2245 path_idx++;
2ec600d6 2246 }
2ec600d6 2247
2ec600d6 2248
bba95fef
JB
2249 out:
2250 cb->args[1] = path_idx;
2251 err = skb->len;
bba95fef 2252 out_err:
4d0c8aea 2253 cfg80211_unlock_rdev(dev);
3b85875a
JB
2254 out_rtnl:
2255 rtnl_unlock();
bba95fef
JB
2256
2257 return err;
2ec600d6
LCC
2258}
2259
2260static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2261{
79c97e97 2262 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2263 int err;
2264 struct net_device *dev;
2265 struct mpath_info pinfo;
2266 struct sk_buff *msg;
2267 u8 *dst = NULL;
2268 u8 next_hop[ETH_ALEN];
2269
2270 memset(&pinfo, 0, sizeof(pinfo));
2271
2272 if (!info->attrs[NL80211_ATTR_MAC])
2273 return -EINVAL;
2274
2275 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2276
3b85875a
JB
2277 rtnl_lock();
2278
463d0183 2279 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2280 if (err)
3b85875a 2281 goto out_rtnl;
2ec600d6 2282
79c97e97 2283 if (!rdev->ops->get_mpath) {
2ec600d6
LCC
2284 err = -EOPNOTSUPP;
2285 goto out;
2286 }
2287
eec60b03
JM
2288 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2289 err = -EOPNOTSUPP;
2290 goto out;
2291 }
2292
79c97e97 2293 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6
LCC
2294 if (err)
2295 goto out;
2296
fd2120ca 2297 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6
LCC
2298 if (!msg)
2299 goto out;
2300
2301 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2302 dev, dst, next_hop, &pinfo) < 0)
2303 goto out_free;
2304
134e6375 2305 err = genlmsg_reply(msg, info);
2ec600d6
LCC
2306 goto out;
2307
2308 out_free:
2309 nlmsg_free(msg);
2ec600d6 2310 out:
79c97e97 2311 cfg80211_unlock_rdev(rdev);
2ec600d6 2312 dev_put(dev);
3b85875a
JB
2313 out_rtnl:
2314 rtnl_unlock();
2315
2ec600d6
LCC
2316 return err;
2317}
2318
2319static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2320{
79c97e97 2321 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2322 int err;
2323 struct net_device *dev;
2324 u8 *dst = NULL;
2325 u8 *next_hop = NULL;
2326
2327 if (!info->attrs[NL80211_ATTR_MAC])
2328 return -EINVAL;
2329
2330 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2331 return -EINVAL;
2332
2333 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2334 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2335
3b85875a
JB
2336 rtnl_lock();
2337
463d0183 2338 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2339 if (err)
3b85875a 2340 goto out_rtnl;
2ec600d6 2341
79c97e97 2342 if (!rdev->ops->change_mpath) {
2ec600d6
LCC
2343 err = -EOPNOTSUPP;
2344 goto out;
2345 }
2346
eec60b03
JM
2347 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2348 err = -EOPNOTSUPP;
2349 goto out;
2350 }
2351
35a8efe1
JM
2352 if (!netif_running(dev)) {
2353 err = -ENETDOWN;
2354 goto out;
2355 }
2356
79c97e97 2357 err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2358
2359 out:
79c97e97 2360 cfg80211_unlock_rdev(rdev);
2ec600d6 2361 dev_put(dev);
3b85875a
JB
2362 out_rtnl:
2363 rtnl_unlock();
2364
2ec600d6
LCC
2365 return err;
2366}
2367static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2368{
79c97e97 2369 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2370 int err;
2371 struct net_device *dev;
2372 u8 *dst = NULL;
2373 u8 *next_hop = NULL;
2374
2375 if (!info->attrs[NL80211_ATTR_MAC])
2376 return -EINVAL;
2377
2378 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2379 return -EINVAL;
2380
2381 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2382 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2383
3b85875a
JB
2384 rtnl_lock();
2385
463d0183 2386 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2387 if (err)
3b85875a 2388 goto out_rtnl;
2ec600d6 2389
79c97e97 2390 if (!rdev->ops->add_mpath) {
2ec600d6
LCC
2391 err = -EOPNOTSUPP;
2392 goto out;
2393 }
2394
eec60b03
JM
2395 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2396 err = -EOPNOTSUPP;
2397 goto out;
2398 }
2399
35a8efe1
JM
2400 if (!netif_running(dev)) {
2401 err = -ENETDOWN;
2402 goto out;
2403 }
2404
79c97e97 2405 err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
2406
2407 out:
79c97e97 2408 cfg80211_unlock_rdev(rdev);
2ec600d6 2409 dev_put(dev);
3b85875a
JB
2410 out_rtnl:
2411 rtnl_unlock();
2412
2ec600d6
LCC
2413 return err;
2414}
2415
2416static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2417{
79c97e97 2418 struct cfg80211_registered_device *rdev;
2ec600d6
LCC
2419 int err;
2420 struct net_device *dev;
2421 u8 *dst = NULL;
2422
2423 if (info->attrs[NL80211_ATTR_MAC])
2424 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2425
3b85875a
JB
2426 rtnl_lock();
2427
463d0183 2428 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2ec600d6 2429 if (err)
3b85875a 2430 goto out_rtnl;
2ec600d6 2431
79c97e97 2432 if (!rdev->ops->del_mpath) {
2ec600d6
LCC
2433 err = -EOPNOTSUPP;
2434 goto out;
2435 }
2436
79c97e97 2437 err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
2438
2439 out:
79c97e97 2440 cfg80211_unlock_rdev(rdev);
2ec600d6 2441 dev_put(dev);
3b85875a
JB
2442 out_rtnl:
2443 rtnl_unlock();
2444
2ec600d6
LCC
2445 return err;
2446}
2447
9f1ba906
JM
2448static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2449{
79c97e97 2450 struct cfg80211_registered_device *rdev;
9f1ba906
JM
2451 int err;
2452 struct net_device *dev;
2453 struct bss_parameters params;
2454
2455 memset(&params, 0, sizeof(params));
2456 /* default to not changing parameters */
2457 params.use_cts_prot = -1;
2458 params.use_short_preamble = -1;
2459 params.use_short_slot_time = -1;
2460
2461 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2462 params.use_cts_prot =
2463 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2464 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2465 params.use_short_preamble =
2466 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2467 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2468 params.use_short_slot_time =
2469 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
2470 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2471 params.basic_rates =
2472 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2473 params.basic_rates_len =
2474 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2475 }
9f1ba906 2476
3b85875a
JB
2477 rtnl_lock();
2478
463d0183 2479 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
9f1ba906 2480 if (err)
3b85875a 2481 goto out_rtnl;
9f1ba906 2482
79c97e97 2483 if (!rdev->ops->change_bss) {
9f1ba906
JM
2484 err = -EOPNOTSUPP;
2485 goto out;
2486 }
2487
eec60b03
JM
2488 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
2489 err = -EOPNOTSUPP;
2490 goto out;
2491 }
2492
79c97e97 2493 err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
2494
2495 out:
79c97e97 2496 cfg80211_unlock_rdev(rdev);
9f1ba906 2497 dev_put(dev);
3b85875a
JB
2498 out_rtnl:
2499 rtnl_unlock();
2500
9f1ba906
JM
2501 return err;
2502}
2503
b2e1b302
LR
2504static const struct nla_policy
2505 reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2506 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
2507 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
2508 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
2509 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
2510 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
2511 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
2512};
2513
2514static int parse_reg_rule(struct nlattr *tb[],
2515 struct ieee80211_reg_rule *reg_rule)
2516{
2517 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2518 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2519
2520 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2521 return -EINVAL;
2522 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2523 return -EINVAL;
2524 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2525 return -EINVAL;
2526 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2527 return -EINVAL;
2528 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2529 return -EINVAL;
2530
2531 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2532
2533 freq_range->start_freq_khz =
2534 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2535 freq_range->end_freq_khz =
2536 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2537 freq_range->max_bandwidth_khz =
2538 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2539
2540 power_rule->max_eirp =
2541 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2542
2543 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2544 power_rule->max_antenna_gain =
2545 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2546
2547 return 0;
2548}
2549
2550static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2551{
2552 int r;
2553 char *data = NULL;
2554
80778f18
LR
2555 /*
2556 * You should only get this when cfg80211 hasn't yet initialized
2557 * completely when built-in to the kernel right between the time
2558 * window between nl80211_init() and regulatory_init(), if that is
2559 * even possible.
2560 */
2561 mutex_lock(&cfg80211_mutex);
2562 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
2563 mutex_unlock(&cfg80211_mutex);
2564 return -EINPROGRESS;
80778f18 2565 }
fe33eb39 2566 mutex_unlock(&cfg80211_mutex);
80778f18 2567
fe33eb39
LR
2568 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2569 return -EINVAL;
b2e1b302
LR
2570
2571 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2572
fe33eb39
LR
2573 r = regulatory_hint_user(data);
2574
b2e1b302
LR
2575 return r;
2576}
2577
93da9cc1 2578static int nl80211_get_mesh_params(struct sk_buff *skb,
2579 struct genl_info *info)
2580{
79c97e97 2581 struct cfg80211_registered_device *rdev;
93da9cc1 2582 struct mesh_config cur_params;
2583 int err;
2584 struct net_device *dev;
2585 void *hdr;
2586 struct nlattr *pinfoattr;
2587 struct sk_buff *msg;
2588
3b85875a
JB
2589 rtnl_lock();
2590
93da9cc1 2591 /* Look up our device */
463d0183 2592 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2593 if (err)
3b85875a 2594 goto out_rtnl;
93da9cc1 2595
79c97e97 2596 if (!rdev->ops->get_mesh_params) {
f3f92586
JM
2597 err = -EOPNOTSUPP;
2598 goto out;
2599 }
2600
93da9cc1 2601 /* Get the mesh params */
79c97e97 2602 err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
93da9cc1 2603 if (err)
2604 goto out;
2605
2606 /* Draw up a netlink message to send back */
fd2120ca 2607 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
93da9cc1 2608 if (!msg) {
2609 err = -ENOBUFS;
2610 goto out;
2611 }
2612 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2613 NL80211_CMD_GET_MESH_PARAMS);
2614 if (!hdr)
2615 goto nla_put_failure;
2616 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2617 if (!pinfoattr)
2618 goto nla_put_failure;
2619 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2620 NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2621 cur_params.dot11MeshRetryTimeout);
2622 NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2623 cur_params.dot11MeshConfirmTimeout);
2624 NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2625 cur_params.dot11MeshHoldingTimeout);
2626 NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2627 cur_params.dot11MeshMaxPeerLinks);
2628 NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2629 cur_params.dot11MeshMaxRetries);
2630 NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2631 cur_params.dot11MeshTTL);
2632 NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2633 cur_params.auto_open_plinks);
2634 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2635 cur_params.dot11MeshHWMPmaxPREQretries);
2636 NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2637 cur_params.path_refresh_time);
2638 NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2639 cur_params.min_discovery_timeout);
2640 NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2641 cur_params.dot11MeshHWMPactivePathTimeout);
2642 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2643 cur_params.dot11MeshHWMPpreqMinInterval);
2644 NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2645 cur_params.dot11MeshHWMPnetDiameterTraversalTime);
63c5723b
RP
2646 NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2647 cur_params.dot11MeshHWMPRootMode);
93da9cc1 2648 nla_nest_end(msg, pinfoattr);
2649 genlmsg_end(msg, hdr);
134e6375 2650 err = genlmsg_reply(msg, info);
93da9cc1 2651 goto out;
2652
3b85875a 2653 nla_put_failure:
93da9cc1 2654 genlmsg_cancel(msg, hdr);
2655 err = -EMSGSIZE;
3b85875a 2656 out:
93da9cc1 2657 /* Cleanup */
79c97e97 2658 cfg80211_unlock_rdev(rdev);
93da9cc1 2659 dev_put(dev);
3b85875a
JB
2660 out_rtnl:
2661 rtnl_unlock();
2662
93da9cc1 2663 return err;
2664}
2665
2666#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2667do {\
2668 if (table[attr_num]) {\
2669 cfg.param = nla_fn(table[attr_num]); \
2670 mask |= (1 << (attr_num - 1)); \
2671 } \
2672} while (0);\
2673
2674static struct nla_policy
2675nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
2676 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2677 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2678 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2679 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2680 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2681 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2682 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2683
2684 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2685 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2686 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2687 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2688 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2689 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2690};
2691
2692static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2693{
2694 int err;
2695 u32 mask;
79c97e97 2696 struct cfg80211_registered_device *rdev;
93da9cc1 2697 struct net_device *dev;
2698 struct mesh_config cfg;
2699 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2700 struct nlattr *parent_attr;
2701
2702 parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2703 if (!parent_attr)
2704 return -EINVAL;
2705 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2706 parent_attr, nl80211_meshconf_params_policy))
2707 return -EINVAL;
2708
3b85875a
JB
2709 rtnl_lock();
2710
463d0183 2711 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
93da9cc1 2712 if (err)
3b85875a 2713 goto out_rtnl;
93da9cc1 2714
79c97e97 2715 if (!rdev->ops->set_mesh_params) {
f3f92586
JM
2716 err = -EOPNOTSUPP;
2717 goto out;
2718 }
2719
93da9cc1 2720 /* This makes sure that there aren't more than 32 mesh config
2721 * parameters (otherwise our bitfield scheme would not work.) */
2722 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2723
2724 /* Fill in the params struct */
2725 mask = 0;
2726 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2727 mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2728 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2729 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2730 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2731 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2732 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2733 mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2734 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2735 mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2736 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2737 mask, NL80211_MESHCONF_TTL, nla_get_u8);
2738 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2739 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2740 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2741 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2742 nla_get_u8);
2743 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2744 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2745 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2746 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2747 nla_get_u16);
2748 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2749 mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2750 nla_get_u32);
2751 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2752 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2753 nla_get_u16);
2754 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2755 dot11MeshHWMPnetDiameterTraversalTime,
2756 mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2757 nla_get_u16);
63c5723b
RP
2758 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2759 dot11MeshHWMPRootMode, mask,
2760 NL80211_MESHCONF_HWMP_ROOTMODE,
2761 nla_get_u8);
93da9cc1 2762
2763 /* Apply changes */
79c97e97 2764 err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
93da9cc1 2765
f3f92586 2766 out:
93da9cc1 2767 /* cleanup */
79c97e97 2768 cfg80211_unlock_rdev(rdev);
93da9cc1 2769 dev_put(dev);
3b85875a
JB
2770 out_rtnl:
2771 rtnl_unlock();
2772
93da9cc1 2773 return err;
2774}
2775
2776#undef FILL_IN_MESH_PARAM_IF_SET
2777
f130347c
LR
2778static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2779{
2780 struct sk_buff *msg;
2781 void *hdr = NULL;
2782 struct nlattr *nl_reg_rules;
2783 unsigned int i;
2784 int err = -EINVAL;
2785
a1794390 2786 mutex_lock(&cfg80211_mutex);
f130347c
LR
2787
2788 if (!cfg80211_regdomain)
2789 goto out;
2790
fd2120ca 2791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
2792 if (!msg) {
2793 err = -ENOBUFS;
2794 goto out;
2795 }
2796
2797 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2798 NL80211_CMD_GET_REG);
2799 if (!hdr)
2800 goto nla_put_failure;
2801
2802 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2803 cfg80211_regdomain->alpha2);
2804
2805 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2806 if (!nl_reg_rules)
2807 goto nla_put_failure;
2808
2809 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2810 struct nlattr *nl_reg_rule;
2811 const struct ieee80211_reg_rule *reg_rule;
2812 const struct ieee80211_freq_range *freq_range;
2813 const struct ieee80211_power_rule *power_rule;
2814
2815 reg_rule = &cfg80211_regdomain->reg_rules[i];
2816 freq_range = &reg_rule->freq_range;
2817 power_rule = &reg_rule->power_rule;
2818
2819 nl_reg_rule = nla_nest_start(msg, i);
2820 if (!nl_reg_rule)
2821 goto nla_put_failure;
2822
2823 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2824 reg_rule->flags);
2825 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2826 freq_range->start_freq_khz);
2827 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2828 freq_range->end_freq_khz);
2829 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2830 freq_range->max_bandwidth_khz);
2831 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2832 power_rule->max_antenna_gain);
2833 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2834 power_rule->max_eirp);
2835
2836 nla_nest_end(msg, nl_reg_rule);
2837 }
2838
2839 nla_nest_end(msg, nl_reg_rules);
2840
2841 genlmsg_end(msg, hdr);
134e6375 2842 err = genlmsg_reply(msg, info);
f130347c
LR
2843 goto out;
2844
2845nla_put_failure:
2846 genlmsg_cancel(msg, hdr);
2847 err = -EMSGSIZE;
2848out:
a1794390 2849 mutex_unlock(&cfg80211_mutex);
f130347c
LR
2850 return err;
2851}
2852
b2e1b302
LR
2853static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2854{
2855 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2856 struct nlattr *nl_reg_rule;
2857 char *alpha2 = NULL;
2858 int rem_reg_rules = 0, r = 0;
2859 u32 num_rules = 0, rule_idx = 0, size_of_regd;
2860 struct ieee80211_regdomain *rd = NULL;
2861
2862 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2863 return -EINVAL;
2864
2865 if (!info->attrs[NL80211_ATTR_REG_RULES])
2866 return -EINVAL;
2867
2868 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2869
2870 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2871 rem_reg_rules) {
2872 num_rules++;
2873 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 2874 return -EINVAL;
b2e1b302
LR
2875 }
2876
61405e97
LR
2877 mutex_lock(&cfg80211_mutex);
2878
d0e18f83
LR
2879 if (!reg_is_valid_request(alpha2)) {
2880 r = -EINVAL;
2881 goto bad_reg;
2882 }
b2e1b302
LR
2883
2884 size_of_regd = sizeof(struct ieee80211_regdomain) +
2885 (num_rules * sizeof(struct ieee80211_reg_rule));
2886
2887 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
2888 if (!rd) {
2889 r = -ENOMEM;
2890 goto bad_reg;
2891 }
b2e1b302
LR
2892
2893 rd->n_reg_rules = num_rules;
2894 rd->alpha2[0] = alpha2[0];
2895 rd->alpha2[1] = alpha2[1];
2896
2897 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2898 rem_reg_rules) {
2899 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2900 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2901 reg_rule_policy);
2902 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2903 if (r)
2904 goto bad_reg;
2905
2906 rule_idx++;
2907
d0e18f83
LR
2908 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2909 r = -EINVAL;
b2e1b302 2910 goto bad_reg;
d0e18f83 2911 }
b2e1b302
LR
2912 }
2913
2914 BUG_ON(rule_idx != num_rules);
2915
b2e1b302 2916 r = set_regdom(rd);
61405e97 2917
a1794390 2918 mutex_unlock(&cfg80211_mutex);
d0e18f83 2919
b2e1b302
LR
2920 return r;
2921
d2372b31 2922 bad_reg:
61405e97 2923 mutex_unlock(&cfg80211_mutex);
b2e1b302 2924 kfree(rd);
d0e18f83 2925 return r;
b2e1b302
LR
2926}
2927
83f5e2cf
JB
2928static int validate_scan_freqs(struct nlattr *freqs)
2929{
2930 struct nlattr *attr1, *attr2;
2931 int n_channels = 0, tmp1, tmp2;
2932
2933 nla_for_each_nested(attr1, freqs, tmp1) {
2934 n_channels++;
2935 /*
2936 * Some hardware has a limited channel list for
2937 * scanning, and it is pretty much nonsensical
2938 * to scan for a channel twice, so disallow that
2939 * and don't require drivers to check that the
2940 * channel list they get isn't longer than what
2941 * they can scan, as long as they can scan all
2942 * the channels they registered at once.
2943 */
2944 nla_for_each_nested(attr2, freqs, tmp2)
2945 if (attr1 != attr2 &&
2946 nla_get_u32(attr1) == nla_get_u32(attr2))
2947 return 0;
2948 }
2949
2950 return n_channels;
2951}
2952
2a519311
JB
2953static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2954{
79c97e97 2955 struct cfg80211_registered_device *rdev;
2a519311
JB
2956 struct net_device *dev;
2957 struct cfg80211_scan_request *request;
2958 struct cfg80211_ssid *ssid;
2959 struct ieee80211_channel *channel;
2960 struct nlattr *attr;
2961 struct wiphy *wiphy;
83f5e2cf 2962 int err, tmp, n_ssids = 0, n_channels, i;
2a519311 2963 enum ieee80211_band band;
70692ad2 2964 size_t ie_len;
2a519311 2965
f4a11bb0
JB
2966 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2967 return -EINVAL;
2968
3b85875a
JB
2969 rtnl_lock();
2970
463d0183 2971 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2a519311 2972 if (err)
3b85875a 2973 goto out_rtnl;
2a519311 2974
79c97e97 2975 wiphy = &rdev->wiphy;
2a519311 2976
79c97e97 2977 if (!rdev->ops->scan) {
2a519311
JB
2978 err = -EOPNOTSUPP;
2979 goto out;
2980 }
2981
35a8efe1
JM
2982 if (!netif_running(dev)) {
2983 err = -ENETDOWN;
2984 goto out;
2985 }
2986
79c97e97 2987 if (rdev->scan_req) {
2a519311 2988 err = -EBUSY;
3b85875a 2989 goto out;
2a519311
JB
2990 }
2991
2992 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
2993 n_channels = validate_scan_freqs(
2994 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2a519311
JB
2995 if (!n_channels) {
2996 err = -EINVAL;
3b85875a 2997 goto out;
2a519311
JB
2998 }
2999 } else {
83f5e2cf
JB
3000 n_channels = 0;
3001
2a519311
JB
3002 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3003 if (wiphy->bands[band])
3004 n_channels += wiphy->bands[band]->n_channels;
3005 }
3006
3007 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3008 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3009 n_ssids++;
3010
3011 if (n_ssids > wiphy->max_scan_ssids) {
3012 err = -EINVAL;
3b85875a 3013 goto out;
2a519311
JB
3014 }
3015
70692ad2
JM
3016 if (info->attrs[NL80211_ATTR_IE])
3017 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3018 else
3019 ie_len = 0;
3020
18a83659
JB
3021 if (ie_len > wiphy->max_scan_ie_len) {
3022 err = -EINVAL;
3023 goto out;
3024 }
3025
2a519311
JB
3026 request = kzalloc(sizeof(*request)
3027 + sizeof(*ssid) * n_ssids
70692ad2
JM
3028 + sizeof(channel) * n_channels
3029 + ie_len, GFP_KERNEL);
2a519311
JB
3030 if (!request) {
3031 err = -ENOMEM;
3b85875a 3032 goto out;
2a519311
JB
3033 }
3034
2a519311 3035 if (n_ssids)
5ba63533 3036 request->ssids = (void *)&request->channels[n_channels];
2a519311 3037 request->n_ssids = n_ssids;
70692ad2
JM
3038 if (ie_len) {
3039 if (request->ssids)
3040 request->ie = (void *)(request->ssids + n_ssids);
3041 else
3042 request->ie = (void *)(request->channels + n_channels);
3043 }
2a519311 3044
584991dc 3045 i = 0;
2a519311
JB
3046 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3047 /* user specified, bail out if channel not found */
2a519311 3048 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
3049 struct ieee80211_channel *chan;
3050
3051 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3052
3053 if (!chan) {
2a519311
JB
3054 err = -EINVAL;
3055 goto out_free;
3056 }
584991dc
JB
3057
3058 /* ignore disabled channels */
3059 if (chan->flags & IEEE80211_CHAN_DISABLED)
3060 continue;
3061
3062 request->channels[i] = chan;
2a519311
JB
3063 i++;
3064 }
3065 } else {
3066 /* all channels */
2a519311
JB
3067 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3068 int j;
3069 if (!wiphy->bands[band])
3070 continue;
3071 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
3072 struct ieee80211_channel *chan;
3073
3074 chan = &wiphy->bands[band]->channels[j];
3075
3076 if (chan->flags & IEEE80211_CHAN_DISABLED)
3077 continue;
3078
3079 request->channels[i] = chan;
2a519311
JB
3080 i++;
3081 }
3082 }
3083 }
3084
584991dc
JB
3085 if (!i) {
3086 err = -EINVAL;
3087 goto out_free;
3088 }
3089
3090 request->n_channels = i;
3091
2a519311
JB
3092 i = 0;
3093 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3094 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3095 if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3096 err = -EINVAL;
3097 goto out_free;
3098 }
3099 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3100 request->ssids[i].ssid_len = nla_len(attr);
3101 i++;
3102 }
3103 }
3104
70692ad2
JM
3105 if (info->attrs[NL80211_ATTR_IE]) {
3106 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
3107 memcpy((void *)request->ie,
3108 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
3109 request->ie_len);
3110 }
3111
463d0183 3112 request->dev = dev;
79c97e97 3113 request->wiphy = &rdev->wiphy;
2a519311 3114
79c97e97
JB
3115 rdev->scan_req = request;
3116 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 3117
463d0183 3118 if (!err) {
79c97e97 3119 nl80211_send_scan_start(rdev, dev);
463d0183
JB
3120 dev_hold(dev);
3121 }
a538e2d5 3122
2a519311
JB
3123 out_free:
3124 if (err) {
79c97e97 3125 rdev->scan_req = NULL;
2a519311
JB
3126 kfree(request);
3127 }
2a519311 3128 out:
79c97e97 3129 cfg80211_unlock_rdev(rdev);
2a519311 3130 dev_put(dev);
3b85875a
JB
3131 out_rtnl:
3132 rtnl_unlock();
3133
2a519311
JB
3134 return err;
3135}
3136
3137static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3138 struct cfg80211_registered_device *rdev,
48ab905d
JB
3139 struct wireless_dev *wdev,
3140 struct cfg80211_internal_bss *intbss)
2a519311 3141{
48ab905d 3142 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
3143 void *hdr;
3144 struct nlattr *bss;
48ab905d
JB
3145 int i;
3146
3147 ASSERT_WDEV_LOCK(wdev);
2a519311
JB
3148
3149 hdr = nl80211hdr_put(msg, pid, seq, flags,
3150 NL80211_CMD_NEW_SCAN_RESULTS);
3151 if (!hdr)
3152 return -1;
3153
f5ea9120 3154 NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
48ab905d 3155 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
2a519311
JB
3156
3157 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3158 if (!bss)
3159 goto nla_put_failure;
3160 if (!is_zero_ether_addr(res->bssid))
3161 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3162 if (res->information_elements && res->len_information_elements)
3163 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3164 res->len_information_elements,
3165 res->information_elements);
34a6eddb
JM
3166 if (res->beacon_ies && res->len_beacon_ies &&
3167 res->beacon_ies != res->information_elements)
3168 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3169 res->len_beacon_ies, res->beacon_ies);
2a519311
JB
3170 if (res->tsf)
3171 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3172 if (res->beacon_interval)
3173 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3174 NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3175 NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
7c89606e
HS
3176 NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3177 jiffies_to_msecs(jiffies - intbss->ts));
2a519311 3178
77965c97 3179 switch (rdev->wiphy.signal_type) {
2a519311
JB
3180 case CFG80211_SIGNAL_TYPE_MBM:
3181 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3182 break;
3183 case CFG80211_SIGNAL_TYPE_UNSPEC:
3184 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3185 break;
3186 default:
3187 break;
3188 }
3189
48ab905d
JB
3190 switch (wdev->iftype) {
3191 case NL80211_IFTYPE_STATION:
3192 if (intbss == wdev->current_bss)
3193 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3194 NL80211_BSS_STATUS_ASSOCIATED);
3195 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3196 if (intbss != wdev->auth_bsses[i])
3197 continue;
3198 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3199 NL80211_BSS_STATUS_AUTHENTICATED);
3200 break;
3201 }
3202 break;
3203 case NL80211_IFTYPE_ADHOC:
3204 if (intbss == wdev->current_bss)
3205 NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3206 NL80211_BSS_STATUS_IBSS_JOINED);
3207 break;
3208 default:
3209 break;
3210 }
3211
2a519311
JB
3212 nla_nest_end(msg, bss);
3213
3214 return genlmsg_end(msg, hdr);
3215
3216 nla_put_failure:
3217 genlmsg_cancel(msg, hdr);
3218 return -EMSGSIZE;
3219}
3220
3221static int nl80211_dump_scan(struct sk_buff *skb,
3222 struct netlink_callback *cb)
3223{
48ab905d
JB
3224 struct cfg80211_registered_device *rdev;
3225 struct net_device *dev;
2a519311 3226 struct cfg80211_internal_bss *scan;
48ab905d 3227 struct wireless_dev *wdev;
2a519311
JB
3228 int ifidx = cb->args[0];
3229 int start = cb->args[1], idx = 0;
3230 int err;
3231
a043897a
HS
3232 if (!ifidx)
3233 ifidx = nl80211_get_ifidx(cb);
3234 if (ifidx < 0)
3235 return ifidx;
3236 cb->args[0] = ifidx;
2a519311 3237
463d0183 3238 dev = dev_get_by_index(sock_net(skb->sk), ifidx);
48ab905d 3239 if (!dev)
2a519311
JB
3240 return -ENODEV;
3241
463d0183 3242 rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
48ab905d
JB
3243 if (IS_ERR(rdev)) {
3244 err = PTR_ERR(rdev);
2a519311
JB
3245 goto out_put_netdev;
3246 }
3247
48ab905d 3248 wdev = dev->ieee80211_ptr;
2a519311 3249
48ab905d
JB
3250 wdev_lock(wdev);
3251 spin_lock_bh(&rdev->bss_lock);
3252 cfg80211_bss_expire(rdev);
3253
3254 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
3255 if (++idx <= start)
3256 continue;
3257 if (nl80211_send_bss(skb,
3258 NETLINK_CB(cb->skb).pid,
3259 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 3260 rdev, wdev, scan) < 0) {
2a519311
JB
3261 idx--;
3262 goto out;
3263 }
3264 }
3265
3266 out:
48ab905d
JB
3267 spin_unlock_bh(&rdev->bss_lock);
3268 wdev_unlock(wdev);
2a519311
JB
3269
3270 cb->args[1] = idx;
3271 err = skb->len;
48ab905d 3272 cfg80211_unlock_rdev(rdev);
2a519311 3273 out_put_netdev:
48ab905d 3274 dev_put(dev);
2a519311
JB
3275
3276 return err;
3277}
3278
61fa713c
HS
3279static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3280 int flags, struct net_device *dev,
3281 struct survey_info *survey)
3282{
3283 void *hdr;
3284 struct nlattr *infoattr;
3285
3286 /* Survey without a channel doesn't make sense */
3287 if (!survey->channel)
3288 return -EINVAL;
3289
3290 hdr = nl80211hdr_put(msg, pid, seq, flags,
3291 NL80211_CMD_NEW_SURVEY_RESULTS);
3292 if (!hdr)
3293 return -ENOMEM;
3294
3295 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3296
3297 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3298 if (!infoattr)
3299 goto nla_put_failure;
3300
3301 NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3302 survey->channel->center_freq);
3303 if (survey->filled & SURVEY_INFO_NOISE_DBM)
3304 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3305 survey->noise);
3306
3307 nla_nest_end(msg, infoattr);
3308
3309 return genlmsg_end(msg, hdr);
3310
3311 nla_put_failure:
3312 genlmsg_cancel(msg, hdr);
3313 return -EMSGSIZE;
3314}
3315
3316static int nl80211_dump_survey(struct sk_buff *skb,
3317 struct netlink_callback *cb)
3318{
3319 struct survey_info survey;
3320 struct cfg80211_registered_device *dev;
3321 struct net_device *netdev;
3322 int ifidx = cb->args[0];
3323 int survey_idx = cb->args[1];
3324 int res;
3325
3326 if (!ifidx)
3327 ifidx = nl80211_get_ifidx(cb);
3328 if (ifidx < 0)
3329 return ifidx;
3330 cb->args[0] = ifidx;
3331
3332 rtnl_lock();
3333
3334 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
3335 if (!netdev) {
3336 res = -ENODEV;
3337 goto out_rtnl;
3338 }
3339
3340 dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3341 if (IS_ERR(dev)) {
3342 res = PTR_ERR(dev);
3343 goto out_rtnl;
3344 }
3345
3346 if (!dev->ops->dump_survey) {
3347 res = -EOPNOTSUPP;
3348 goto out_err;
3349 }
3350
3351 while (1) {
3352 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3353 &survey);
3354 if (res == -ENOENT)
3355 break;
3356 if (res)
3357 goto out_err;
3358
3359 if (nl80211_send_survey(skb,
3360 NETLINK_CB(cb->skb).pid,
3361 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3362 netdev,
3363 &survey) < 0)
3364 goto out;
3365 survey_idx++;
3366 }
3367
3368 out:
3369 cb->args[1] = survey_idx;
3370 res = skb->len;
3371 out_err:
3372 cfg80211_unlock_rdev(dev);
3373 out_rtnl:
3374 rtnl_unlock();
3375
3376 return res;
3377}
3378
255e737e
JM
3379static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3380{
b23aa676
SO
3381 return auth_type <= NL80211_AUTHTYPE_MAX;
3382}
3383
3384static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3385{
3386 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3387 NL80211_WPA_VERSION_2));
3388}
3389
3390static bool nl80211_valid_akm_suite(u32 akm)
3391{
3392 return akm == WLAN_AKM_SUITE_8021X ||
3393 akm == WLAN_AKM_SUITE_PSK;
3394}
3395
3396static bool nl80211_valid_cipher_suite(u32 cipher)
3397{
3398 return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3399 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3400 cipher == WLAN_CIPHER_SUITE_TKIP ||
3401 cipher == WLAN_CIPHER_SUITE_CCMP ||
3402 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
255e737e
JM
3403}
3404
b23aa676 3405
636a5d36
JM
3406static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3407{
79c97e97 3408 struct cfg80211_registered_device *rdev;
636a5d36 3409 struct net_device *dev;
19957bb3
JB
3410 struct ieee80211_channel *chan;
3411 const u8 *bssid, *ssid, *ie = NULL;
3412 int err, ssid_len, ie_len = 0;
3413 enum nl80211_auth_type auth_type;
fffd0934 3414 struct key_parse key;
636a5d36 3415
f4a11bb0
JB
3416 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3417 return -EINVAL;
3418
3419 if (!info->attrs[NL80211_ATTR_MAC])
3420 return -EINVAL;
3421
1778092e
JM
3422 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3423 return -EINVAL;
3424
19957bb3
JB
3425 if (!info->attrs[NL80211_ATTR_SSID])
3426 return -EINVAL;
3427
3428 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3429 return -EINVAL;
3430
fffd0934
JB
3431 err = nl80211_parse_key(info, &key);
3432 if (err)
3433 return err;
3434
3435 if (key.idx >= 0) {
3436 if (!key.p.key || !key.p.key_len)
3437 return -EINVAL;
3438 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3439 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3440 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3441 key.p.key_len != WLAN_KEY_LEN_WEP104))
3442 return -EINVAL;
3443 if (key.idx > 4)
3444 return -EINVAL;
3445 } else {
3446 key.p.key_len = 0;
3447 key.p.key = NULL;
3448 }
3449
636a5d36
JM
3450 rtnl_lock();
3451
463d0183 3452 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3453 if (err)
3454 goto unlock_rtnl;
3455
79c97e97 3456 if (!rdev->ops->auth) {
636a5d36
JM
3457 err = -EOPNOTSUPP;
3458 goto out;
3459 }
3460
eec60b03
JM
3461 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3462 err = -EOPNOTSUPP;
3463 goto out;
3464 }
3465
35a8efe1
JM
3466 if (!netif_running(dev)) {
3467 err = -ENETDOWN;
3468 goto out;
3469 }
3470
19957bb3 3471 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 3472 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3
JB
3473 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3474 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3475 err = -EINVAL;
3476 goto out;
636a5d36
JM
3477 }
3478
19957bb3
JB
3479 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3480 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3481
3482 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3483 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3484 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3485 }
3486
19957bb3
JB
3487 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3488 if (!nl80211_valid_auth_type(auth_type)) {
1778092e
JM
3489 err = -EINVAL;
3490 goto out;
636a5d36
JM
3491 }
3492
79c97e97 3493 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
fffd0934
JB
3494 ssid, ssid_len, ie, ie_len,
3495 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
3496
3497out:
79c97e97 3498 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3499 dev_put(dev);
3500unlock_rtnl:
3501 rtnl_unlock();
3502 return err;
3503}
3504
b23aa676 3505static int nl80211_crypto_settings(struct genl_info *info,
3dc27d25
JB
3506 struct cfg80211_crypto_settings *settings,
3507 int cipher_limit)
b23aa676 3508{
c0b2bbd8
JB
3509 memset(settings, 0, sizeof(*settings));
3510
b23aa676
SO
3511 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3512
3513 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3514 void *data;
3515 int len, i;
3516
3517 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3518 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3519 settings->n_ciphers_pairwise = len / sizeof(u32);
3520
3521 if (len % sizeof(u32))
3522 return -EINVAL;
3523
3dc27d25 3524 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
3525 return -EINVAL;
3526
3527 memcpy(settings->ciphers_pairwise, data, len);
3528
3529 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3530 if (!nl80211_valid_cipher_suite(
3531 settings->ciphers_pairwise[i]))
3532 return -EINVAL;
3533 }
3534
3535 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3536 settings->cipher_group =
3537 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3538 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3539 return -EINVAL;
3540 }
3541
3542 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3543 settings->wpa_versions =
3544 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3545 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3546 return -EINVAL;
3547 }
3548
3549 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3550 void *data;
3551 int len, i;
3552
3553 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3554 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3555 settings->n_akm_suites = len / sizeof(u32);
3556
3557 if (len % sizeof(u32))
3558 return -EINVAL;
3559
3560 memcpy(settings->akm_suites, data, len);
3561
3562 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3563 if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3564 return -EINVAL;
3565 }
3566
3567 return 0;
3568}
3569
636a5d36
JM
3570static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3571{
19957bb3 3572 struct cfg80211_registered_device *rdev;
636a5d36 3573 struct net_device *dev;
27e310c9 3574 struct wireless_dev *wdev;
19957bb3 3575 struct cfg80211_crypto_settings crypto;
59bbb6f7 3576 struct ieee80211_channel *chan, *fixedchan;
3e5d7649 3577 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
3578 int err, ssid_len, ie_len = 0;
3579 bool use_mfp = false;
636a5d36 3580
f4a11bb0
JB
3581 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3582 return -EINVAL;
3583
3584 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
3585 !info->attrs[NL80211_ATTR_SSID] ||
3586 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
3587 return -EINVAL;
3588
636a5d36
JM
3589 rtnl_lock();
3590
463d0183 3591 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3592 if (err)
3593 goto unlock_rtnl;
3594
19957bb3 3595 if (!rdev->ops->assoc) {
636a5d36
JM
3596 err = -EOPNOTSUPP;
3597 goto out;
3598 }
3599
eec60b03
JM
3600 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3601 err = -EOPNOTSUPP;
3602 goto out;
3603 }
3604
35a8efe1
JM
3605 if (!netif_running(dev)) {
3606 err = -ENETDOWN;
3607 goto out;
3608 }
3609
19957bb3 3610 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3611
19957bb3
JB
3612 chan = ieee80211_get_channel(&rdev->wiphy,
3613 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3614 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
3615 err = -EINVAL;
3616 goto out;
636a5d36
JM
3617 }
3618
59bbb6f7 3619 mutex_lock(&rdev->devlist_mtx);
27e310c9
JM
3620 wdev = dev->ieee80211_ptr;
3621 fixedchan = rdev_fixed_channel(rdev, wdev);
59bbb6f7
JB
3622 if (fixedchan && chan != fixedchan) {
3623 err = -EBUSY;
3624 mutex_unlock(&rdev->devlist_mtx);
3625 goto out;
3626 }
3627 mutex_unlock(&rdev->devlist_mtx);
3628
19957bb3
JB
3629 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3630 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
3631
3632 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3633 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3634 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3635 }
3636
dc6382ce 3637 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 3638 enum nl80211_mfp mfp =
dc6382ce 3639 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 3640 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 3641 use_mfp = true;
4f5dadce 3642 else if (mfp != NL80211_MFP_NO) {
dc6382ce
JM
3643 err = -EINVAL;
3644 goto out;
3645 }
3646 }
3647
3e5d7649
JB
3648 if (info->attrs[NL80211_ATTR_PREV_BSSID])
3649 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3650
3dc27d25 3651 err = nl80211_crypto_settings(info, &crypto, 1);
b23aa676 3652 if (!err)
3e5d7649
JB
3653 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3654 ssid, ssid_len, ie, ie_len, use_mfp,
19957bb3 3655 &crypto);
636a5d36
JM
3656
3657out:
4d0c8aea 3658 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3659 dev_put(dev);
3660unlock_rtnl:
3661 rtnl_unlock();
3662 return err;
3663}
3664
3665static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3666{
79c97e97 3667 struct cfg80211_registered_device *rdev;
636a5d36 3668 struct net_device *dev;
19957bb3
JB
3669 const u8 *ie = NULL, *bssid;
3670 int err, ie_len = 0;
3671 u16 reason_code;
636a5d36 3672
f4a11bb0
JB
3673 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3674 return -EINVAL;
3675
3676 if (!info->attrs[NL80211_ATTR_MAC])
3677 return -EINVAL;
3678
3679 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3680 return -EINVAL;
3681
636a5d36
JM
3682 rtnl_lock();
3683
463d0183 3684 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3685 if (err)
3686 goto unlock_rtnl;
3687
79c97e97 3688 if (!rdev->ops->deauth) {
636a5d36
JM
3689 err = -EOPNOTSUPP;
3690 goto out;
3691 }
3692
eec60b03
JM
3693 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3694 err = -EOPNOTSUPP;
3695 goto out;
3696 }
3697
35a8efe1
JM
3698 if (!netif_running(dev)) {
3699 err = -ENETDOWN;
3700 goto out;
3701 }
3702
19957bb3 3703 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3704
19957bb3
JB
3705 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3706 if (reason_code == 0) {
f4a11bb0
JB
3707 /* Reason Code 0 is reserved */
3708 err = -EINVAL;
3709 goto out;
255e737e 3710 }
636a5d36
JM
3711
3712 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3713 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3714 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3715 }
3716
79c97e97 3717 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3718
3719out:
79c97e97 3720 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3721 dev_put(dev);
3722unlock_rtnl:
3723 rtnl_unlock();
3724 return err;
3725}
3726
3727static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3728{
79c97e97 3729 struct cfg80211_registered_device *rdev;
636a5d36 3730 struct net_device *dev;
19957bb3
JB
3731 const u8 *ie = NULL, *bssid;
3732 int err, ie_len = 0;
3733 u16 reason_code;
636a5d36 3734
f4a11bb0
JB
3735 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3736 return -EINVAL;
3737
3738 if (!info->attrs[NL80211_ATTR_MAC])
3739 return -EINVAL;
3740
3741 if (!info->attrs[NL80211_ATTR_REASON_CODE])
3742 return -EINVAL;
3743
636a5d36
JM
3744 rtnl_lock();
3745
463d0183 3746 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
636a5d36
JM
3747 if (err)
3748 goto unlock_rtnl;
3749
79c97e97 3750 if (!rdev->ops->disassoc) {
636a5d36
JM
3751 err = -EOPNOTSUPP;
3752 goto out;
3753 }
3754
eec60b03
JM
3755 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
3756 err = -EOPNOTSUPP;
3757 goto out;
3758 }
3759
35a8efe1
JM
3760 if (!netif_running(dev)) {
3761 err = -ENETDOWN;
3762 goto out;
3763 }
3764
19957bb3 3765 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 3766
19957bb3
JB
3767 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3768 if (reason_code == 0) {
f4a11bb0
JB
3769 /* Reason Code 0 is reserved */
3770 err = -EINVAL;
3771 goto out;
255e737e 3772 }
636a5d36
JM
3773
3774 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
3775 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3776 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
3777 }
3778
79c97e97 3779 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
636a5d36
JM
3780
3781out:
79c97e97 3782 cfg80211_unlock_rdev(rdev);
636a5d36
JM
3783 dev_put(dev);
3784unlock_rtnl:
3785 rtnl_unlock();
3786 return err;
3787}
3788
04a773ad
JB
3789static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3790{
79c97e97 3791 struct cfg80211_registered_device *rdev;
04a773ad
JB
3792 struct net_device *dev;
3793 struct cfg80211_ibss_params ibss;
3794 struct wiphy *wiphy;
fffd0934 3795 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
3796 int err;
3797
8e30bc55
JB
3798 memset(&ibss, 0, sizeof(ibss));
3799
04a773ad
JB
3800 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3801 return -EINVAL;
3802
3803 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3804 !info->attrs[NL80211_ATTR_SSID] ||
3805 !nla_len(info->attrs[NL80211_ATTR_SSID]))
3806 return -EINVAL;
3807
8e30bc55
JB
3808 ibss.beacon_interval = 100;
3809
3810 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3811 ibss.beacon_interval =
3812 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3813 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3814 return -EINVAL;
3815 }
3816
04a773ad
JB
3817 rtnl_lock();
3818
463d0183 3819 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3820 if (err)
3821 goto unlock_rtnl;
3822
79c97e97 3823 if (!rdev->ops->join_ibss) {
04a773ad
JB
3824 err = -EOPNOTSUPP;
3825 goto out;
3826 }
3827
3828 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3829 err = -EOPNOTSUPP;
3830 goto out;
3831 }
3832
3833 if (!netif_running(dev)) {
3834 err = -ENETDOWN;
3835 goto out;
3836 }
3837
79c97e97 3838 wiphy = &rdev->wiphy;
04a773ad
JB
3839
3840 if (info->attrs[NL80211_ATTR_MAC])
3841 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3842 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3843 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3844
3845 if (info->attrs[NL80211_ATTR_IE]) {
3846 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3847 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3848 }
3849
3850 ibss.channel = ieee80211_get_channel(wiphy,
3851 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3852 if (!ibss.channel ||
3853 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3854 ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
3855 err = -EINVAL;
3856 goto out;
3857 }
3858
3859 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
3860 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3861
3862 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3863 connkeys = nl80211_parse_connkeys(rdev,
3864 info->attrs[NL80211_ATTR_KEYS]);
3865 if (IS_ERR(connkeys)) {
3866 err = PTR_ERR(connkeys);
3867 connkeys = NULL;
3868 goto out;
3869 }
3870 }
04a773ad 3871
fffd0934 3872 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
04a773ad
JB
3873
3874out:
79c97e97 3875 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3876 dev_put(dev);
3877unlock_rtnl:
fffd0934
JB
3878 if (err)
3879 kfree(connkeys);
04a773ad
JB
3880 rtnl_unlock();
3881 return err;
3882}
3883
3884static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3885{
79c97e97 3886 struct cfg80211_registered_device *rdev;
04a773ad
JB
3887 struct net_device *dev;
3888 int err;
3889
3890 rtnl_lock();
3891
463d0183 3892 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
04a773ad
JB
3893 if (err)
3894 goto unlock_rtnl;
3895
79c97e97 3896 if (!rdev->ops->leave_ibss) {
04a773ad
JB
3897 err = -EOPNOTSUPP;
3898 goto out;
3899 }
3900
3901 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
3902 err = -EOPNOTSUPP;
3903 goto out;
3904 }
3905
3906 if (!netif_running(dev)) {
3907 err = -ENETDOWN;
3908 goto out;
3909 }
3910
79c97e97 3911 err = cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
3912
3913out:
79c97e97 3914 cfg80211_unlock_rdev(rdev);
04a773ad
JB
3915 dev_put(dev);
3916unlock_rtnl:
3917 rtnl_unlock();
3918 return err;
3919}
3920
aff89a9b
JB
3921#ifdef CONFIG_NL80211_TESTMODE
3922static struct genl_multicast_group nl80211_testmode_mcgrp = {
3923 .name = "testmode",
3924};
3925
3926static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3927{
3928 struct cfg80211_registered_device *rdev;
3929 int err;
3930
3931 if (!info->attrs[NL80211_ATTR_TESTDATA])
3932 return -EINVAL;
3933
3934 rtnl_lock();
3935
3936 rdev = cfg80211_get_dev_from_info(info);
3937 if (IS_ERR(rdev)) {
3938 err = PTR_ERR(rdev);
3939 goto unlock_rtnl;
3940 }
3941
3942 err = -EOPNOTSUPP;
3943 if (rdev->ops->testmode_cmd) {
3944 rdev->testmode_info = info;
3945 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3946 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3947 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3948 rdev->testmode_info = NULL;
3949 }
3950
4d0c8aea 3951 cfg80211_unlock_rdev(rdev);
aff89a9b
JB
3952
3953 unlock_rtnl:
3954 rtnl_unlock();
3955 return err;
3956}
3957
3958static struct sk_buff *
3959__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3960 int approxlen, u32 pid, u32 seq, gfp_t gfp)
3961{
3962 struct sk_buff *skb;
3963 void *hdr;
3964 struct nlattr *data;
3965
3966 skb = nlmsg_new(approxlen + 100, gfp);
3967 if (!skb)
3968 return NULL;
3969
3970 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3971 if (!hdr) {
3972 kfree_skb(skb);
3973 return NULL;
3974 }
3975
3976 NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3977 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3978
3979 ((void **)skb->cb)[0] = rdev;
3980 ((void **)skb->cb)[1] = hdr;
3981 ((void **)skb->cb)[2] = data;
3982
3983 return skb;
3984
3985 nla_put_failure:
3986 kfree_skb(skb);
3987 return NULL;
3988}
3989
3990struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3991 int approxlen)
3992{
3993 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3994
3995 if (WARN_ON(!rdev->testmode_info))
3996 return NULL;
3997
3998 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3999 rdev->testmode_info->snd_pid,
4000 rdev->testmode_info->snd_seq,
4001 GFP_KERNEL);
4002}
4003EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
4004
4005int cfg80211_testmode_reply(struct sk_buff *skb)
4006{
4007 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4008 void *hdr = ((void **)skb->cb)[1];
4009 struct nlattr *data = ((void **)skb->cb)[2];
4010
4011 if (WARN_ON(!rdev->testmode_info)) {
4012 kfree_skb(skb);
4013 return -EINVAL;
4014 }
4015
4016 nla_nest_end(skb, data);
4017 genlmsg_end(skb, hdr);
4018 return genlmsg_reply(skb, rdev->testmode_info);
4019}
4020EXPORT_SYMBOL(cfg80211_testmode_reply);
4021
4022struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4023 int approxlen, gfp_t gfp)
4024{
4025 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4026
4027 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4028}
4029EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4030
4031void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4032{
4033 void *hdr = ((void **)skb->cb)[1];
4034 struct nlattr *data = ((void **)skb->cb)[2];
4035
4036 nla_nest_end(skb, data);
4037 genlmsg_end(skb, hdr);
4038 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4039}
4040EXPORT_SYMBOL(cfg80211_testmode_event);
4041#endif
4042
b23aa676
SO
4043static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4044{
79c97e97 4045 struct cfg80211_registered_device *rdev;
b23aa676
SO
4046 struct net_device *dev;
4047 struct cfg80211_connect_params connect;
4048 struct wiphy *wiphy;
fffd0934 4049 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
4050 int err;
4051
4052 memset(&connect, 0, sizeof(connect));
4053
4054 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4055 return -EINVAL;
4056
4057 if (!info->attrs[NL80211_ATTR_SSID] ||
4058 !nla_len(info->attrs[NL80211_ATTR_SSID]))
4059 return -EINVAL;
4060
4061 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4062 connect.auth_type =
4063 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4064 if (!nl80211_valid_auth_type(connect.auth_type))
4065 return -EINVAL;
4066 } else
4067 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4068
4069 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4070
3dc27d25
JB
4071 err = nl80211_crypto_settings(info, &connect.crypto,
4072 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
4073 if (err)
4074 return err;
4075 rtnl_lock();
4076
463d0183 4077 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4078 if (err)
4079 goto unlock_rtnl;
4080
4081 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4082 err = -EOPNOTSUPP;
4083 goto out;
4084 }
4085
4086 if (!netif_running(dev)) {
4087 err = -ENETDOWN;
4088 goto out;
4089 }
4090
79c97e97 4091 wiphy = &rdev->wiphy;
b23aa676 4092
b23aa676
SO
4093 if (info->attrs[NL80211_ATTR_MAC])
4094 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4095 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4096 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4097
4098 if (info->attrs[NL80211_ATTR_IE]) {
4099 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4100 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4101 }
4102
4103 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4104 connect.channel =
4105 ieee80211_get_channel(wiphy,
4106 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4107 if (!connect.channel ||
4108 connect.channel->flags & IEEE80211_CHAN_DISABLED) {
4109 err = -EINVAL;
4110 goto out;
4111 }
4112 }
4113
fffd0934
JB
4114 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4115 connkeys = nl80211_parse_connkeys(rdev,
4116 info->attrs[NL80211_ATTR_KEYS]);
4117 if (IS_ERR(connkeys)) {
4118 err = PTR_ERR(connkeys);
4119 connkeys = NULL;
4120 goto out;
4121 }
4122 }
4123
4124 err = cfg80211_connect(rdev, dev, &connect, connkeys);
b23aa676
SO
4125
4126out:
79c97e97 4127 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4128 dev_put(dev);
4129unlock_rtnl:
fffd0934
JB
4130 if (err)
4131 kfree(connkeys);
b23aa676
SO
4132 rtnl_unlock();
4133 return err;
4134}
4135
4136static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4137{
79c97e97 4138 struct cfg80211_registered_device *rdev;
b23aa676
SO
4139 struct net_device *dev;
4140 int err;
4141 u16 reason;
4142
4143 if (!info->attrs[NL80211_ATTR_REASON_CODE])
4144 reason = WLAN_REASON_DEAUTH_LEAVING;
4145 else
4146 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4147
4148 if (reason == 0)
4149 return -EINVAL;
4150
4151 rtnl_lock();
4152
463d0183 4153 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
b23aa676
SO
4154 if (err)
4155 goto unlock_rtnl;
4156
4157 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4158 err = -EOPNOTSUPP;
4159 goto out;
4160 }
4161
4162 if (!netif_running(dev)) {
4163 err = -ENETDOWN;
4164 goto out;
4165 }
4166
79c97e97 4167 err = cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
4168
4169out:
79c97e97 4170 cfg80211_unlock_rdev(rdev);
b23aa676
SO
4171 dev_put(dev);
4172unlock_rtnl:
4173 rtnl_unlock();
4174 return err;
4175}
4176
463d0183
JB
4177static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4178{
4179 struct cfg80211_registered_device *rdev;
4180 struct net *net;
4181 int err;
4182 u32 pid;
4183
4184 if (!info->attrs[NL80211_ATTR_PID])
4185 return -EINVAL;
4186
4187 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4188
4189 rtnl_lock();
4190
4191 rdev = cfg80211_get_dev_from_info(info);
4192 if (IS_ERR(rdev)) {
4193 err = PTR_ERR(rdev);
8a8e05e5 4194 goto out_rtnl;
463d0183
JB
4195 }
4196
4197 net = get_net_ns_by_pid(pid);
4198 if (IS_ERR(net)) {
4199 err = PTR_ERR(net);
4200 goto out;
4201 }
4202
4203 err = 0;
4204
4205 /* check if anything to do */
4206 if (net_eq(wiphy_net(&rdev->wiphy), net))
4207 goto out_put_net;
4208
4209 err = cfg80211_switch_netns(rdev, net);
4210 out_put_net:
4211 put_net(net);
4212 out:
4213 cfg80211_unlock_rdev(rdev);
8a8e05e5 4214 out_rtnl:
463d0183
JB
4215 rtnl_unlock();
4216 return err;
4217}
4218
67fbb16b
SO
4219static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4220{
4221 struct cfg80211_registered_device *rdev;
4222 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4223 struct cfg80211_pmksa *pmksa) = NULL;
4224 int err;
4225 struct net_device *dev;
4226 struct cfg80211_pmksa pmksa;
4227
4228 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4229
4230 if (!info->attrs[NL80211_ATTR_MAC])
4231 return -EINVAL;
4232
4233 if (!info->attrs[NL80211_ATTR_PMKID])
4234 return -EINVAL;
4235
4236 rtnl_lock();
4237
4238 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4239 if (err)
4240 goto out_rtnl;
4241
4242 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4243 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4244
4245 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4246 err = -EOPNOTSUPP;
4247 goto out;
4248 }
4249
4250 switch (info->genlhdr->cmd) {
4251 case NL80211_CMD_SET_PMKSA:
4252 rdev_ops = rdev->ops->set_pmksa;
4253 break;
4254 case NL80211_CMD_DEL_PMKSA:
4255 rdev_ops = rdev->ops->del_pmksa;
4256 break;
4257 default:
4258 WARN_ON(1);
4259 break;
4260 }
4261
4262 if (!rdev_ops) {
4263 err = -EOPNOTSUPP;
4264 goto out;
4265 }
4266
4267 err = rdev_ops(&rdev->wiphy, dev, &pmksa);
4268
4269 out:
4270 cfg80211_unlock_rdev(rdev);
4271 dev_put(dev);
4272 out_rtnl:
4273 rtnl_unlock();
4274
4275 return err;
4276}
4277
4278static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4279{
4280 struct cfg80211_registered_device *rdev;
4281 int err;
4282 struct net_device *dev;
4283
4284 rtnl_lock();
4285
4286 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4287 if (err)
4288 goto out_rtnl;
4289
4290 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
4291 err = -EOPNOTSUPP;
4292 goto out;
4293 }
4294
4295 if (!rdev->ops->flush_pmksa) {
4296 err = -EOPNOTSUPP;
4297 goto out;
4298 }
4299
4300 err = rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4301
4302 out:
4303 cfg80211_unlock_rdev(rdev);
4304 dev_put(dev);
4305 out_rtnl:
4306 rtnl_unlock();
4307
4308 return err;
4309
4310}
4311
9588bbd5
JM
4312static int nl80211_remain_on_channel(struct sk_buff *skb,
4313 struct genl_info *info)
4314{
4315 struct cfg80211_registered_device *rdev;
4316 struct net_device *dev;
4317 struct ieee80211_channel *chan;
4318 struct sk_buff *msg;
4319 void *hdr;
4320 u64 cookie;
4321 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4322 u32 freq, duration;
4323 int err;
4324
4325 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4326 !info->attrs[NL80211_ATTR_DURATION])
4327 return -EINVAL;
4328
4329 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4330
4331 /*
4332 * We should be on that channel for at least one jiffie,
4333 * and more than 5 seconds seems excessive.
4334 */
4335 if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4336 return -EINVAL;
4337
4338 rtnl_lock();
4339
4340 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4341 if (err)
4342 goto unlock_rtnl;
4343
4344 if (!rdev->ops->remain_on_channel) {
4345 err = -EOPNOTSUPP;
4346 goto out;
4347 }
4348
4349 if (!netif_running(dev)) {
4350 err = -ENETDOWN;
4351 goto out;
4352 }
4353
4354 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4355 channel_type = nla_get_u32(
4356 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4357 if (channel_type != NL80211_CHAN_NO_HT &&
4358 channel_type != NL80211_CHAN_HT20 &&
4359 channel_type != NL80211_CHAN_HT40PLUS &&
4360 channel_type != NL80211_CHAN_HT40MINUS)
4361 err = -EINVAL;
4362 goto out;
4363 }
4364
4365 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4366 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4367 if (chan == NULL) {
4368 err = -EINVAL;
4369 goto out;
4370 }
4371
4372 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4373 if (!msg) {
4374 err = -ENOMEM;
4375 goto out;
4376 }
4377
4378 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4379 NL80211_CMD_REMAIN_ON_CHANNEL);
4380
4381 if (IS_ERR(hdr)) {
4382 err = PTR_ERR(hdr);
4383 goto free_msg;
4384 }
4385
4386 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4387 channel_type, duration, &cookie);
4388
4389 if (err)
4390 goto free_msg;
4391
4392 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4393
4394 genlmsg_end(msg, hdr);
4395 err = genlmsg_reply(msg, info);
4396 goto out;
4397
4398 nla_put_failure:
4399 err = -ENOBUFS;
4400 free_msg:
4401 nlmsg_free(msg);
4402 out:
4403 cfg80211_unlock_rdev(rdev);
4404 dev_put(dev);
4405 unlock_rtnl:
4406 rtnl_unlock();
4407 return err;
4408}
4409
4410static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4411 struct genl_info *info)
4412{
4413 struct cfg80211_registered_device *rdev;
4414 struct net_device *dev;
4415 u64 cookie;
4416 int err;
4417
4418 if (!info->attrs[NL80211_ATTR_COOKIE])
4419 return -EINVAL;
4420
4421 rtnl_lock();
4422
4423 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4424 if (err)
4425 goto unlock_rtnl;
4426
4427 if (!rdev->ops->cancel_remain_on_channel) {
4428 err = -EOPNOTSUPP;
4429 goto out;
4430 }
4431
4432 if (!netif_running(dev)) {
4433 err = -ENETDOWN;
4434 goto out;
4435 }
4436
4437 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4438
4439 err = rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4440
4441 out:
4442 cfg80211_unlock_rdev(rdev);
4443 dev_put(dev);
4444 unlock_rtnl:
4445 rtnl_unlock();
4446 return err;
4447}
4448
13ae75b1
JM
4449static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4450 u8 *rates, u8 rates_len)
4451{
4452 u8 i;
4453 u32 mask = 0;
4454
4455 for (i = 0; i < rates_len; i++) {
4456 int rate = (rates[i] & 0x7f) * 5;
4457 int ridx;
4458 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4459 struct ieee80211_rate *srate =
4460 &sband->bitrates[ridx];
4461 if (rate == srate->bitrate) {
4462 mask |= 1 << ridx;
4463 break;
4464 }
4465 }
4466 if (ridx == sband->n_bitrates)
4467 return 0; /* rate not found */
4468 }
4469
4470 return mask;
4471}
4472
4473static struct nla_policy
4474nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] __read_mostly = {
4475 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4476 .len = NL80211_MAX_SUPP_RATES },
4477};
4478
4479static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4480 struct genl_info *info)
4481{
4482 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4483 struct cfg80211_registered_device *rdev;
4484 struct cfg80211_bitrate_mask mask;
4485 int err, rem, i;
4486 struct net_device *dev;
4487 struct nlattr *tx_rates;
4488 struct ieee80211_supported_band *sband;
4489
4490 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4491 return -EINVAL;
4492
4493 rtnl_lock();
4494
4495 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4496 if (err)
4497 goto unlock_rtnl;
4498
4499 if (!rdev->ops->set_bitrate_mask) {
4500 err = -EOPNOTSUPP;
4501 goto unlock;
4502 }
4503
4504 memset(&mask, 0, sizeof(mask));
4505 /* Default to all rates enabled */
4506 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4507 sband = rdev->wiphy.bands[i];
4508 mask.control[i].legacy =
4509 sband ? (1 << sband->n_bitrates) - 1 : 0;
4510 }
4511
4512 /*
4513 * The nested attribute uses enum nl80211_band as the index. This maps
4514 * directly to the enum ieee80211_band values used in cfg80211.
4515 */
4516 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4517 {
4518 enum ieee80211_band band = nla_type(tx_rates);
4519 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
4520 err = -EINVAL;
4521 goto unlock;
4522 }
4523 sband = rdev->wiphy.bands[band];
4524 if (sband == NULL) {
4525 err = -EINVAL;
4526 goto unlock;
4527 }
4528 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4529 nla_len(tx_rates), nl80211_txattr_policy);
4530 if (tb[NL80211_TXRATE_LEGACY]) {
4531 mask.control[band].legacy = rateset_to_mask(
4532 sband,
4533 nla_data(tb[NL80211_TXRATE_LEGACY]),
4534 nla_len(tb[NL80211_TXRATE_LEGACY]));
4535 if (mask.control[band].legacy == 0) {
4536 err = -EINVAL;
4537 goto unlock;
4538 }
4539 }
4540 }
4541
4542 err = rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4543
4544 unlock:
4545 dev_put(dev);
4546 cfg80211_unlock_rdev(rdev);
4547 unlock_rtnl:
4548 rtnl_unlock();
4549 return err;
4550}
4551
55682965
JB
4552static struct genl_ops nl80211_ops[] = {
4553 {
4554 .cmd = NL80211_CMD_GET_WIPHY,
4555 .doit = nl80211_get_wiphy,
4556 .dumpit = nl80211_dump_wiphy,
4557 .policy = nl80211_policy,
4558 /* can be retrieved by unprivileged users */
4559 },
4560 {
4561 .cmd = NL80211_CMD_SET_WIPHY,
4562 .doit = nl80211_set_wiphy,
4563 .policy = nl80211_policy,
4564 .flags = GENL_ADMIN_PERM,
4565 },
4566 {
4567 .cmd = NL80211_CMD_GET_INTERFACE,
4568 .doit = nl80211_get_interface,
4569 .dumpit = nl80211_dump_interface,
4570 .policy = nl80211_policy,
4571 /* can be retrieved by unprivileged users */
4572 },
4573 {
4574 .cmd = NL80211_CMD_SET_INTERFACE,
4575 .doit = nl80211_set_interface,
4576 .policy = nl80211_policy,
4577 .flags = GENL_ADMIN_PERM,
4578 },
4579 {
4580 .cmd = NL80211_CMD_NEW_INTERFACE,
4581 .doit = nl80211_new_interface,
4582 .policy = nl80211_policy,
4583 .flags = GENL_ADMIN_PERM,
4584 },
4585 {
4586 .cmd = NL80211_CMD_DEL_INTERFACE,
4587 .doit = nl80211_del_interface,
4588 .policy = nl80211_policy,
41ade00f
JB
4589 .flags = GENL_ADMIN_PERM,
4590 },
4591 {
4592 .cmd = NL80211_CMD_GET_KEY,
4593 .doit = nl80211_get_key,
4594 .policy = nl80211_policy,
4595 .flags = GENL_ADMIN_PERM,
4596 },
4597 {
4598 .cmd = NL80211_CMD_SET_KEY,
4599 .doit = nl80211_set_key,
4600 .policy = nl80211_policy,
4601 .flags = GENL_ADMIN_PERM,
4602 },
4603 {
4604 .cmd = NL80211_CMD_NEW_KEY,
4605 .doit = nl80211_new_key,
4606 .policy = nl80211_policy,
4607 .flags = GENL_ADMIN_PERM,
4608 },
4609 {
4610 .cmd = NL80211_CMD_DEL_KEY,
4611 .doit = nl80211_del_key,
4612 .policy = nl80211_policy,
55682965
JB
4613 .flags = GENL_ADMIN_PERM,
4614 },
ed1b6cc7
JB
4615 {
4616 .cmd = NL80211_CMD_SET_BEACON,
4617 .policy = nl80211_policy,
4618 .flags = GENL_ADMIN_PERM,
4619 .doit = nl80211_addset_beacon,
4620 },
4621 {
4622 .cmd = NL80211_CMD_NEW_BEACON,
4623 .policy = nl80211_policy,
4624 .flags = GENL_ADMIN_PERM,
4625 .doit = nl80211_addset_beacon,
4626 },
4627 {
4628 .cmd = NL80211_CMD_DEL_BEACON,
4629 .policy = nl80211_policy,
4630 .flags = GENL_ADMIN_PERM,
4631 .doit = nl80211_del_beacon,
4632 },
5727ef1b
JB
4633 {
4634 .cmd = NL80211_CMD_GET_STATION,
4635 .doit = nl80211_get_station,
2ec600d6 4636 .dumpit = nl80211_dump_station,
5727ef1b 4637 .policy = nl80211_policy,
5727ef1b
JB
4638 },
4639 {
4640 .cmd = NL80211_CMD_SET_STATION,
4641 .doit = nl80211_set_station,
4642 .policy = nl80211_policy,
4643 .flags = GENL_ADMIN_PERM,
4644 },
4645 {
4646 .cmd = NL80211_CMD_NEW_STATION,
4647 .doit = nl80211_new_station,
4648 .policy = nl80211_policy,
4649 .flags = GENL_ADMIN_PERM,
4650 },
4651 {
4652 .cmd = NL80211_CMD_DEL_STATION,
4653 .doit = nl80211_del_station,
4654 .policy = nl80211_policy,
2ec600d6
LCC
4655 .flags = GENL_ADMIN_PERM,
4656 },
4657 {
4658 .cmd = NL80211_CMD_GET_MPATH,
4659 .doit = nl80211_get_mpath,
4660 .dumpit = nl80211_dump_mpath,
4661 .policy = nl80211_policy,
4662 .flags = GENL_ADMIN_PERM,
4663 },
4664 {
4665 .cmd = NL80211_CMD_SET_MPATH,
4666 .doit = nl80211_set_mpath,
4667 .policy = nl80211_policy,
4668 .flags = GENL_ADMIN_PERM,
4669 },
4670 {
4671 .cmd = NL80211_CMD_NEW_MPATH,
4672 .doit = nl80211_new_mpath,
4673 .policy = nl80211_policy,
4674 .flags = GENL_ADMIN_PERM,
4675 },
4676 {
4677 .cmd = NL80211_CMD_DEL_MPATH,
4678 .doit = nl80211_del_mpath,
4679 .policy = nl80211_policy,
9f1ba906
JM
4680 .flags = GENL_ADMIN_PERM,
4681 },
4682 {
4683 .cmd = NL80211_CMD_SET_BSS,
4684 .doit = nl80211_set_bss,
4685 .policy = nl80211_policy,
b2e1b302
LR
4686 .flags = GENL_ADMIN_PERM,
4687 },
f130347c
LR
4688 {
4689 .cmd = NL80211_CMD_GET_REG,
4690 .doit = nl80211_get_reg,
4691 .policy = nl80211_policy,
4692 /* can be retrieved by unprivileged users */
4693 },
b2e1b302
LR
4694 {
4695 .cmd = NL80211_CMD_SET_REG,
4696 .doit = nl80211_set_reg,
4697 .policy = nl80211_policy,
4698 .flags = GENL_ADMIN_PERM,
4699 },
4700 {
4701 .cmd = NL80211_CMD_REQ_SET_REG,
4702 .doit = nl80211_req_set_reg,
4703 .policy = nl80211_policy,
93da9cc1 4704 .flags = GENL_ADMIN_PERM,
4705 },
4706 {
4707 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4708 .doit = nl80211_get_mesh_params,
4709 .policy = nl80211_policy,
4710 /* can be retrieved by unprivileged users */
4711 },
4712 {
4713 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4714 .doit = nl80211_set_mesh_params,
4715 .policy = nl80211_policy,
9aed3cc1
JM
4716 .flags = GENL_ADMIN_PERM,
4717 },
2a519311
JB
4718 {
4719 .cmd = NL80211_CMD_TRIGGER_SCAN,
4720 .doit = nl80211_trigger_scan,
4721 .policy = nl80211_policy,
4722 .flags = GENL_ADMIN_PERM,
4723 },
4724 {
4725 .cmd = NL80211_CMD_GET_SCAN,
4726 .policy = nl80211_policy,
4727 .dumpit = nl80211_dump_scan,
4728 },
636a5d36
JM
4729 {
4730 .cmd = NL80211_CMD_AUTHENTICATE,
4731 .doit = nl80211_authenticate,
4732 .policy = nl80211_policy,
4733 .flags = GENL_ADMIN_PERM,
4734 },
4735 {
4736 .cmd = NL80211_CMD_ASSOCIATE,
4737 .doit = nl80211_associate,
4738 .policy = nl80211_policy,
4739 .flags = GENL_ADMIN_PERM,
4740 },
4741 {
4742 .cmd = NL80211_CMD_DEAUTHENTICATE,
4743 .doit = nl80211_deauthenticate,
4744 .policy = nl80211_policy,
4745 .flags = GENL_ADMIN_PERM,
4746 },
4747 {
4748 .cmd = NL80211_CMD_DISASSOCIATE,
4749 .doit = nl80211_disassociate,
4750 .policy = nl80211_policy,
4751 .flags = GENL_ADMIN_PERM,
4752 },
04a773ad
JB
4753 {
4754 .cmd = NL80211_CMD_JOIN_IBSS,
4755 .doit = nl80211_join_ibss,
4756 .policy = nl80211_policy,
4757 .flags = GENL_ADMIN_PERM,
4758 },
4759 {
4760 .cmd = NL80211_CMD_LEAVE_IBSS,
4761 .doit = nl80211_leave_ibss,
4762 .policy = nl80211_policy,
4763 .flags = GENL_ADMIN_PERM,
4764 },
aff89a9b
JB
4765#ifdef CONFIG_NL80211_TESTMODE
4766 {
4767 .cmd = NL80211_CMD_TESTMODE,
4768 .doit = nl80211_testmode_do,
4769 .policy = nl80211_policy,
4770 .flags = GENL_ADMIN_PERM,
4771 },
4772#endif
b23aa676
SO
4773 {
4774 .cmd = NL80211_CMD_CONNECT,
4775 .doit = nl80211_connect,
4776 .policy = nl80211_policy,
4777 .flags = GENL_ADMIN_PERM,
4778 },
4779 {
4780 .cmd = NL80211_CMD_DISCONNECT,
4781 .doit = nl80211_disconnect,
4782 .policy = nl80211_policy,
4783 .flags = GENL_ADMIN_PERM,
4784 },
463d0183
JB
4785 {
4786 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4787 .doit = nl80211_wiphy_netns,
4788 .policy = nl80211_policy,
4789 .flags = GENL_ADMIN_PERM,
4790 },
61fa713c
HS
4791 {
4792 .cmd = NL80211_CMD_GET_SURVEY,
4793 .policy = nl80211_policy,
4794 .dumpit = nl80211_dump_survey,
4795 },
67fbb16b
SO
4796 {
4797 .cmd = NL80211_CMD_SET_PMKSA,
4798 .doit = nl80211_setdel_pmksa,
4799 .policy = nl80211_policy,
4800 .flags = GENL_ADMIN_PERM,
4801 },
4802 {
4803 .cmd = NL80211_CMD_DEL_PMKSA,
4804 .doit = nl80211_setdel_pmksa,
4805 .policy = nl80211_policy,
4806 .flags = GENL_ADMIN_PERM,
4807 },
4808 {
4809 .cmd = NL80211_CMD_FLUSH_PMKSA,
4810 .doit = nl80211_flush_pmksa,
4811 .policy = nl80211_policy,
4812 .flags = GENL_ADMIN_PERM,
4813 },
9588bbd5
JM
4814 {
4815 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
4816 .doit = nl80211_remain_on_channel,
4817 .policy = nl80211_policy,
4818 .flags = GENL_ADMIN_PERM,
4819 },
4820 {
4821 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
4822 .doit = nl80211_cancel_remain_on_channel,
4823 .policy = nl80211_policy,
4824 .flags = GENL_ADMIN_PERM,
4825 },
13ae75b1
JM
4826 {
4827 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
4828 .doit = nl80211_set_tx_bitrate_mask,
4829 .policy = nl80211_policy,
4830 .flags = GENL_ADMIN_PERM,
4831 },
55682965 4832};
9588bbd5 4833
6039f6d2
JM
4834static struct genl_multicast_group nl80211_mlme_mcgrp = {
4835 .name = "mlme",
4836};
55682965
JB
4837
4838/* multicast groups */
4839static struct genl_multicast_group nl80211_config_mcgrp = {
4840 .name = "config",
4841};
2a519311
JB
4842static struct genl_multicast_group nl80211_scan_mcgrp = {
4843 .name = "scan",
4844};
73d54c9e
LR
4845static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4846 .name = "regulatory",
4847};
55682965
JB
4848
4849/* notification functions */
4850
4851void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4852{
4853 struct sk_buff *msg;
4854
fd2120ca 4855 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
4856 if (!msg)
4857 return;
4858
4859 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
4860 nlmsg_free(msg);
4861 return;
4862 }
4863
463d0183
JB
4864 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4865 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
4866}
4867
362a415d
JB
4868static int nl80211_add_scan_req(struct sk_buff *msg,
4869 struct cfg80211_registered_device *rdev)
4870{
4871 struct cfg80211_scan_request *req = rdev->scan_req;
4872 struct nlattr *nest;
4873 int i;
4874
667503dd
JB
4875 ASSERT_RDEV_LOCK(rdev);
4876
362a415d
JB
4877 if (WARN_ON(!req))
4878 return 0;
4879
4880 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
4881 if (!nest)
4882 goto nla_put_failure;
4883 for (i = 0; i < req->n_ssids; i++)
4884 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
4885 nla_nest_end(msg, nest);
4886
4887 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
4888 if (!nest)
4889 goto nla_put_failure;
4890 for (i = 0; i < req->n_channels; i++)
4891 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
4892 nla_nest_end(msg, nest);
4893
4894 if (req->ie)
4895 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
4896
4897 return 0;
4898 nla_put_failure:
4899 return -ENOBUFS;
4900}
4901
a538e2d5
JB
4902static int nl80211_send_scan_msg(struct sk_buff *msg,
4903 struct cfg80211_registered_device *rdev,
4904 struct net_device *netdev,
4905 u32 pid, u32 seq, int flags,
4906 u32 cmd)
2a519311
JB
4907{
4908 void *hdr;
4909
4910 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
4911 if (!hdr)
4912 return -1;
4913
b5850a7a 4914 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
2a519311
JB
4915 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
4916
362a415d
JB
4917 /* ignore errors and send incomplete event anyway */
4918 nl80211_add_scan_req(msg, rdev);
2a519311
JB
4919
4920 return genlmsg_end(msg, hdr);
4921
4922 nla_put_failure:
4923 genlmsg_cancel(msg, hdr);
4924 return -EMSGSIZE;
4925}
4926
a538e2d5
JB
4927void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
4928 struct net_device *netdev)
4929{
4930 struct sk_buff *msg;
4931
4932 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
4933 if (!msg)
4934 return;
4935
4936 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4937 NL80211_CMD_TRIGGER_SCAN) < 0) {
4938 nlmsg_free(msg);
4939 return;
4940 }
4941
463d0183
JB
4942 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4943 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
4944}
4945
2a519311
JB
4946void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
4947 struct net_device *netdev)
4948{
4949 struct sk_buff *msg;
4950
fd2120ca 4951 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4952 if (!msg)
4953 return;
4954
a538e2d5
JB
4955 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4956 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
4957 nlmsg_free(msg);
4958 return;
4959 }
4960
463d0183
JB
4961 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4962 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4963}
4964
4965void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
4966 struct net_device *netdev)
4967{
4968 struct sk_buff *msg;
4969
fd2120ca 4970 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
4971 if (!msg)
4972 return;
4973
a538e2d5
JB
4974 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
4975 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
4976 nlmsg_free(msg);
4977 return;
4978 }
4979
463d0183
JB
4980 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
4981 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
4982}
4983
73d54c9e
LR
4984/*
4985 * This can happen on global regulatory changes or device specific settings
4986 * based on custom world regulatory domains.
4987 */
4988void nl80211_send_reg_change_event(struct regulatory_request *request)
4989{
4990 struct sk_buff *msg;
4991 void *hdr;
4992
fd2120ca 4993 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
4994 if (!msg)
4995 return;
4996
4997 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
4998 if (!hdr) {
4999 nlmsg_free(msg);
5000 return;
5001 }
5002
5003 /* Userspace can always count this one always being set */
5004 NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5005
5006 if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5007 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5008 NL80211_REGDOM_TYPE_WORLD);
5009 else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5010 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5011 NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5012 else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5013 request->intersect)
5014 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5015 NL80211_REGDOM_TYPE_INTERSECTION);
5016 else {
5017 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5018 NL80211_REGDOM_TYPE_COUNTRY);
5019 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5020 }
5021
5022 if (wiphy_idx_valid(request->wiphy_idx))
5023 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5024
5025 if (genlmsg_end(msg, hdr) < 0) {
5026 nlmsg_free(msg);
5027 return;
5028 }
5029
bc43b28c 5030 rcu_read_lock();
463d0183 5031 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
5032 GFP_ATOMIC);
5033 rcu_read_unlock();
73d54c9e
LR
5034
5035 return;
5036
5037nla_put_failure:
5038 genlmsg_cancel(msg, hdr);
5039 nlmsg_free(msg);
5040}
5041
6039f6d2
JM
5042static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5043 struct net_device *netdev,
5044 const u8 *buf, size_t len,
e6d6e342 5045 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
5046{
5047 struct sk_buff *msg;
5048 void *hdr;
5049
e6d6e342 5050 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
5051 if (!msg)
5052 return;
5053
5054 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5055 if (!hdr) {
5056 nlmsg_free(msg);
5057 return;
5058 }
5059
5060 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5061 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5062 NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5063
5064 if (genlmsg_end(msg, hdr) < 0) {
5065 nlmsg_free(msg);
5066 return;
5067 }
5068
463d0183
JB
5069 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5070 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
5071 return;
5072
5073 nla_put_failure:
5074 genlmsg_cancel(msg, hdr);
5075 nlmsg_free(msg);
5076}
5077
5078void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5079 struct net_device *netdev, const u8 *buf,
5080 size_t len, gfp_t gfp)
6039f6d2
JM
5081{
5082 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5083 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
5084}
5085
5086void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5087 struct net_device *netdev, const u8 *buf,
e6d6e342 5088 size_t len, gfp_t gfp)
6039f6d2 5089{
e6d6e342
JB
5090 nl80211_send_mlme_event(rdev, netdev, buf, len,
5091 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
5092}
5093
53b46b84 5094void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5095 struct net_device *netdev, const u8 *buf,
5096 size_t len, gfp_t gfp)
6039f6d2
JM
5097{
5098 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5099 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
5100}
5101
53b46b84
JM
5102void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5103 struct net_device *netdev, const u8 *buf,
e6d6e342 5104 size_t len, gfp_t gfp)
6039f6d2
JM
5105{
5106 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 5107 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
5108}
5109
1b06bb40
LR
5110static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5111 struct net_device *netdev, int cmd,
e6d6e342 5112 const u8 *addr, gfp_t gfp)
1965c853
JM
5113{
5114 struct sk_buff *msg;
5115 void *hdr;
5116
e6d6e342 5117 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
5118 if (!msg)
5119 return;
5120
5121 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5122 if (!hdr) {
5123 nlmsg_free(msg);
5124 return;
5125 }
5126
5127 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5128 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5129 NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5130 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5131
5132 if (genlmsg_end(msg, hdr) < 0) {
5133 nlmsg_free(msg);
5134 return;
5135 }
5136
463d0183
JB
5137 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5138 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
5139 return;
5140
5141 nla_put_failure:
5142 genlmsg_cancel(msg, hdr);
5143 nlmsg_free(msg);
5144}
5145
5146void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5147 struct net_device *netdev, const u8 *addr,
5148 gfp_t gfp)
1965c853
JM
5149{
5150 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 5151 addr, gfp);
1965c853
JM
5152}
5153
5154void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
5155 struct net_device *netdev, const u8 *addr,
5156 gfp_t gfp)
1965c853 5157{
e6d6e342
JB
5158 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5159 addr, gfp);
1965c853
JM
5160}
5161
b23aa676
SO
5162void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5163 struct net_device *netdev, const u8 *bssid,
5164 const u8 *req_ie, size_t req_ie_len,
5165 const u8 *resp_ie, size_t resp_ie_len,
5166 u16 status, gfp_t gfp)
5167{
5168 struct sk_buff *msg;
5169 void *hdr;
5170
5171 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5172 if (!msg)
5173 return;
5174
5175 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5176 if (!hdr) {
5177 nlmsg_free(msg);
5178 return;
5179 }
5180
5181 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5182 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5183 if (bssid)
5184 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5185 NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5186 if (req_ie)
5187 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5188 if (resp_ie)
5189 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5190
5191 if (genlmsg_end(msg, hdr) < 0) {
5192 nlmsg_free(msg);
5193 return;
5194 }
5195
463d0183
JB
5196 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5197 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5198 return;
5199
5200 nla_put_failure:
5201 genlmsg_cancel(msg, hdr);
5202 nlmsg_free(msg);
5203
5204}
5205
5206void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5207 struct net_device *netdev, const u8 *bssid,
5208 const u8 *req_ie, size_t req_ie_len,
5209 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5210{
5211 struct sk_buff *msg;
5212 void *hdr;
5213
5214 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5215 if (!msg)
5216 return;
5217
5218 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5219 if (!hdr) {
5220 nlmsg_free(msg);
5221 return;
5222 }
5223
5224 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5225 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5226 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5227 if (req_ie)
5228 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5229 if (resp_ie)
5230 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5231
5232 if (genlmsg_end(msg, hdr) < 0) {
5233 nlmsg_free(msg);
5234 return;
5235 }
5236
463d0183
JB
5237 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5238 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
5239 return;
5240
5241 nla_put_failure:
5242 genlmsg_cancel(msg, hdr);
5243 nlmsg_free(msg);
5244
5245}
5246
5247void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5248 struct net_device *netdev, u16 reason,
667503dd 5249 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
5250{
5251 struct sk_buff *msg;
5252 void *hdr;
5253
667503dd 5254 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
5255 if (!msg)
5256 return;
5257
5258 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5259 if (!hdr) {
5260 nlmsg_free(msg);
5261 return;
5262 }
5263
5264 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5265 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5266 if (from_ap && reason)
5267 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5268 if (from_ap)
5269 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5270 if (ie)
5271 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5272
5273 if (genlmsg_end(msg, hdr) < 0) {
5274 nlmsg_free(msg);
5275 return;
5276 }
5277
463d0183
JB
5278 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5279 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
5280 return;
5281
5282 nla_put_failure:
5283 genlmsg_cancel(msg, hdr);
5284 nlmsg_free(msg);
5285
5286}
5287
04a773ad
JB
5288void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5289 struct net_device *netdev, const u8 *bssid,
5290 gfp_t gfp)
5291{
5292 struct sk_buff *msg;
5293 void *hdr;
5294
fd2120ca 5295 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
5296 if (!msg)
5297 return;
5298
5299 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5300 if (!hdr) {
5301 nlmsg_free(msg);
5302 return;
5303 }
5304
5305 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5306 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5307 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5308
5309 if (genlmsg_end(msg, hdr) < 0) {
5310 nlmsg_free(msg);
5311 return;
5312 }
5313
463d0183
JB
5314 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5315 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
5316 return;
5317
5318 nla_put_failure:
5319 genlmsg_cancel(msg, hdr);
5320 nlmsg_free(msg);
5321}
5322
a3b8b056
JM
5323void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5324 struct net_device *netdev, const u8 *addr,
5325 enum nl80211_key_type key_type, int key_id,
e6d6e342 5326 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
5327{
5328 struct sk_buff *msg;
5329 void *hdr;
5330
e6d6e342 5331 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
5332 if (!msg)
5333 return;
5334
5335 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5336 if (!hdr) {
5337 nlmsg_free(msg);
5338 return;
5339 }
5340
5341 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5342 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5343 if (addr)
5344 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5345 NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5346 NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5347 if (tsc)
5348 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5349
5350 if (genlmsg_end(msg, hdr) < 0) {
5351 nlmsg_free(msg);
5352 return;
5353 }
5354
463d0183
JB
5355 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5356 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
5357 return;
5358
5359 nla_put_failure:
5360 genlmsg_cancel(msg, hdr);
5361 nlmsg_free(msg);
5362}
5363
6bad8766
LR
5364void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5365 struct ieee80211_channel *channel_before,
5366 struct ieee80211_channel *channel_after)
5367{
5368 struct sk_buff *msg;
5369 void *hdr;
5370 struct nlattr *nl_freq;
5371
fd2120ca 5372 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
5373 if (!msg)
5374 return;
5375
5376 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5377 if (!hdr) {
5378 nlmsg_free(msg);
5379 return;
5380 }
5381
5382 /*
5383 * Since we are applying the beacon hint to a wiphy we know its
5384 * wiphy_idx is valid
5385 */
5386 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5387
5388 /* Before */
5389 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5390 if (!nl_freq)
5391 goto nla_put_failure;
5392 if (nl80211_msg_put_channel(msg, channel_before))
5393 goto nla_put_failure;
5394 nla_nest_end(msg, nl_freq);
5395
5396 /* After */
5397 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5398 if (!nl_freq)
5399 goto nla_put_failure;
5400 if (nl80211_msg_put_channel(msg, channel_after))
5401 goto nla_put_failure;
5402 nla_nest_end(msg, nl_freq);
5403
5404 if (genlmsg_end(msg, hdr) < 0) {
5405 nlmsg_free(msg);
5406 return;
5407 }
5408
463d0183
JB
5409 rcu_read_lock();
5410 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5411 GFP_ATOMIC);
5412 rcu_read_unlock();
6bad8766
LR
5413
5414 return;
5415
5416nla_put_failure:
5417 genlmsg_cancel(msg, hdr);
5418 nlmsg_free(msg);
5419}
5420
9588bbd5
JM
5421static void nl80211_send_remain_on_chan_event(
5422 int cmd, struct cfg80211_registered_device *rdev,
5423 struct net_device *netdev, u64 cookie,
5424 struct ieee80211_channel *chan,
5425 enum nl80211_channel_type channel_type,
5426 unsigned int duration, gfp_t gfp)
5427{
5428 struct sk_buff *msg;
5429 void *hdr;
5430
5431 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5432 if (!msg)
5433 return;
5434
5435 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5436 if (!hdr) {
5437 nlmsg_free(msg);
5438 return;
5439 }
5440
5441 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5442 NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5443 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5444 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5445 NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5446
5447 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5448 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5449
5450 if (genlmsg_end(msg, hdr) < 0) {
5451 nlmsg_free(msg);
5452 return;
5453 }
5454
5455 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5456 nl80211_mlme_mcgrp.id, gfp);
5457 return;
5458
5459 nla_put_failure:
5460 genlmsg_cancel(msg, hdr);
5461 nlmsg_free(msg);
5462}
5463
5464void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5465 struct net_device *netdev, u64 cookie,
5466 struct ieee80211_channel *chan,
5467 enum nl80211_channel_type channel_type,
5468 unsigned int duration, gfp_t gfp)
5469{
5470 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5471 rdev, netdev, cookie, chan,
5472 channel_type, duration, gfp);
5473}
5474
5475void nl80211_send_remain_on_channel_cancel(
5476 struct cfg80211_registered_device *rdev, struct net_device *netdev,
5477 u64 cookie, struct ieee80211_channel *chan,
5478 enum nl80211_channel_type channel_type, gfp_t gfp)
5479{
5480 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5481 rdev, netdev, cookie, chan,
5482 channel_type, 0, gfp);
5483}
5484
98b62183
JB
5485void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5486 struct net_device *dev, const u8 *mac_addr,
5487 struct station_info *sinfo, gfp_t gfp)
5488{
5489 struct sk_buff *msg;
5490
5491 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5492 if (!msg)
5493 return;
5494
5495 if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5496 nlmsg_free(msg);
5497 return;
5498 }
5499
5500 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5501 nl80211_mlme_mcgrp.id, gfp);
5502}
5503
55682965
JB
5504/* initialisation/exit functions */
5505
5506int nl80211_init(void)
5507{
0d63cbb5 5508 int err;
55682965 5509
0d63cbb5
MM
5510 err = genl_register_family_with_ops(&nl80211_fam,
5511 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
5512 if (err)
5513 return err;
5514
55682965
JB
5515 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
5516 if (err)
5517 goto err_out;
5518
2a519311
JB
5519 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
5520 if (err)
5521 goto err_out;
5522
73d54c9e
LR
5523 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
5524 if (err)
5525 goto err_out;
5526
6039f6d2
JM
5527 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
5528 if (err)
5529 goto err_out;
5530
aff89a9b
JB
5531#ifdef CONFIG_NL80211_TESTMODE
5532 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
5533 if (err)
5534 goto err_out;
5535#endif
5536
55682965
JB
5537 return 0;
5538 err_out:
5539 genl_unregister_family(&nl80211_fam);
5540 return err;
5541}
5542
5543void nl80211_exit(void)
5544{
5545 genl_unregister_family(&nl80211_fam);
5546}