mac80211: fix use after free
[linux-2.6-block.git] / net / mac80211 / iface.c
CommitLineData
f0706e82 1/*
0d143fe1
JB
2 * Interface handling (except master interface)
3 *
f0706e82
JB
4 * Copyright 2002-2005, Instant802 Networks, Inc.
5 * Copyright 2005-2006, Devicescape Software, Inc.
6 * Copyright (c) 2006 Jiri Benc <jbenc@suse.cz>
75636525 7 * Copyright 2008, Johannes Berg <johannes@sipsolutions.net>
f0706e82
JB
8 *
9 * This program is free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License version 2 as
11 * published by the Free Software Foundation.
12 */
5a0e3ad6 13#include <linux/slab.h>
f0706e82
JB
14#include <linux/kernel.h>
15#include <linux/if_arp.h>
16#include <linux/netdevice.h>
17#include <linux/rtnetlink.h>
18#include <net/mac80211.h>
cf0277e7 19#include <net/ieee80211_radiotap.h>
f0706e82
JB
20#include "ieee80211_i.h"
21#include "sta_info.h"
e9f207f0 22#include "debugfs_netdev.h"
ee385855 23#include "mesh.h"
0d143fe1 24#include "led.h"
24487981 25#include "driver-ops.h"
cf0277e7 26#include "wme.h"
1be7fe8d 27#include "rate.h"
0d143fe1 28
c771c9d8
JB
29/**
30 * DOC: Interface list locking
31 *
32 * The interface list in each struct ieee80211_local is protected
33 * three-fold:
34 *
35 * (1) modifications may only be done under the RTNL
36 * (2) modifications and readers are protected against each other by
37 * the iflist_mtx.
38 * (3) modifications are done in an RCU manner so atomic readers
39 * can traverse the list in RCU-safe blocks.
40 *
41 * As a consequence, reads (traversals) of the list can be protected
42 * by either the RTNL, the iflist_mtx or RCU.
43 */
44
45
cc45ae54
JB
46static u32 ieee80211_idle_off(struct ieee80211_local *local,
47 const char *reason)
48{
49 if (!(local->hw.conf.flags & IEEE80211_CONF_IDLE))
50 return 0;
51
52 local->hw.conf.flags &= ~IEEE80211_CONF_IDLE;
53 return IEEE80211_CONF_CHANGE_IDLE;
54}
55
56static u32 ieee80211_idle_on(struct ieee80211_local *local)
57{
58 if (local->hw.conf.flags & IEEE80211_CONF_IDLE)
59 return 0;
60
61 drv_flush(local, false);
62
63 local->hw.conf.flags |= IEEE80211_CONF_IDLE;
64 return IEEE80211_CONF_CHANGE_IDLE;
65}
66
67static u32 __ieee80211_recalc_idle(struct ieee80211_local *local)
68{
69 struct ieee80211_sub_if_data *sdata;
70 int count = 0;
71 bool working = false, scanning = false;
72 unsigned int led_trig_start = 0, led_trig_stop = 0;
73 struct ieee80211_roc_work *roc;
74
75#ifdef CONFIG_PROVE_LOCKING
76 WARN_ON(debug_locks && !lockdep_rtnl_is_held() &&
77 !lockdep_is_held(&local->iflist_mtx));
78#endif
79 lockdep_assert_held(&local->mtx);
80
81 list_for_each_entry(sdata, &local->interfaces, list) {
82 if (!ieee80211_sdata_running(sdata)) {
83 sdata->vif.bss_conf.idle = true;
84 continue;
85 }
86
87 sdata->old_idle = sdata->vif.bss_conf.idle;
88
89 /* do not count disabled managed interfaces */
90 if (sdata->vif.type == NL80211_IFTYPE_STATION &&
91 !sdata->u.mgd.associated &&
92 !sdata->u.mgd.auth_data &&
93 !sdata->u.mgd.assoc_data) {
94 sdata->vif.bss_conf.idle = true;
95 continue;
96 }
97 /* do not count unused IBSS interfaces */
98 if (sdata->vif.type == NL80211_IFTYPE_ADHOC &&
99 !sdata->u.ibss.ssid_len) {
100 sdata->vif.bss_conf.idle = true;
101 continue;
102 }
103 /* count everything else */
104 sdata->vif.bss_conf.idle = false;
105 count++;
106 }
107
108 if (!local->ops->remain_on_channel) {
109 list_for_each_entry(roc, &local->roc_list, list) {
110 working = true;
111 roc->sdata->vif.bss_conf.idle = false;
112 }
113 }
114
e2fd5dbc
JB
115 sdata = rcu_dereference_protected(local->scan_sdata,
116 lockdep_is_held(&local->mtx));
117 if (sdata && !(local->hw.flags & IEEE80211_HW_SCAN_WHILE_IDLE)) {
cc45ae54 118 scanning = true;
e2fd5dbc 119 sdata->vif.bss_conf.idle = false;
cc45ae54
JB
120 }
121
122 list_for_each_entry(sdata, &local->interfaces, list) {
123 if (sdata->vif.type == NL80211_IFTYPE_MONITOR ||
124 sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
125 continue;
126 if (sdata->old_idle == sdata->vif.bss_conf.idle)
127 continue;
128 if (!ieee80211_sdata_running(sdata))
129 continue;
130 ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_IDLE);
131 }
132
133 if (working || scanning)
134 led_trig_start |= IEEE80211_TPT_LEDTRIG_FL_WORK;
135 else
136 led_trig_stop |= IEEE80211_TPT_LEDTRIG_FL_WORK;
137
138 if (count)
139 led_trig_start |= IEEE80211_TPT_LEDTRIG_FL_CONNECTED;
140 else
141 led_trig_stop |= IEEE80211_TPT_LEDTRIG_FL_CONNECTED;
142
143 ieee80211_mod_tpt_led_trig(local, led_trig_start, led_trig_stop);
144
145 if (working)
146 return ieee80211_idle_off(local, "working");
147 if (scanning)
148 return ieee80211_idle_off(local, "scanning");
149 if (!count)
150 return ieee80211_idle_on(local);
151 else
152 return ieee80211_idle_off(local, "in use");
153
154 return 0;
155}
156
157void ieee80211_recalc_idle(struct ieee80211_local *local)
158{
159 u32 chg;
160
161 mutex_lock(&local->iflist_mtx);
162 chg = __ieee80211_recalc_idle(local);
163 mutex_unlock(&local->iflist_mtx);
164 if (chg)
165 ieee80211_hw_config(local, chg);
166}
167
0d143fe1
JB
168static int ieee80211_change_mtu(struct net_device *dev, int new_mtu)
169{
170 int meshhdrlen;
171 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
172
173 meshhdrlen = (sdata->vif.type == NL80211_IFTYPE_MESH_POINT) ? 5 : 0;
174
175 /* FIX: what would be proper limits for MTU?
176 * This interface uses 802.3 frames. */
177 if (new_mtu < 256 ||
178 new_mtu > IEEE80211_MAX_DATA_LEN - 24 - 6 - meshhdrlen) {
179 return -EINVAL;
180 }
181
0d143fe1
JB
182 dev->mtu = new_mtu;
183 return 0;
184}
185
47846c9b
JB
186static int ieee80211_change_mac(struct net_device *dev, void *addr)
187{
188 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
fc5f7577 189 struct sockaddr *sa = addr;
47846c9b
JB
190 int ret;
191
9607e6b6 192 if (ieee80211_sdata_running(sdata))
47846c9b
JB
193 return -EBUSY;
194
fc5f7577 195 ret = eth_mac_addr(dev, sa);
47846c9b
JB
196
197 if (ret == 0)
fc5f7577 198 memcpy(sdata->vif.addr, sa->sa_data, ETH_ALEN);
47846c9b
JB
199
200 return ret;
201}
202
0d143fe1
JB
203static inline int identical_mac_addr_allowed(int type1, int type2)
204{
205 return type1 == NL80211_IFTYPE_MONITOR ||
206 type2 == NL80211_IFTYPE_MONITOR ||
207 (type1 == NL80211_IFTYPE_AP && type2 == NL80211_IFTYPE_WDS) ||
208 (type1 == NL80211_IFTYPE_WDS &&
209 (type2 == NL80211_IFTYPE_WDS ||
210 type2 == NL80211_IFTYPE_AP)) ||
211 (type1 == NL80211_IFTYPE_AP && type2 == NL80211_IFTYPE_AP_VLAN) ||
212 (type1 == NL80211_IFTYPE_AP_VLAN &&
213 (type2 == NL80211_IFTYPE_AP ||
214 type2 == NL80211_IFTYPE_AP_VLAN));
215}
216
87490f6d
JB
217static int ieee80211_check_concurrent_iface(struct ieee80211_sub_if_data *sdata,
218 enum nl80211_iftype iftype)
0d143fe1 219{
b4a4bf5d 220 struct ieee80211_local *local = sdata->local;
87490f6d 221 struct ieee80211_sub_if_data *nsdata;
0d143fe1 222
87490f6d 223 ASSERT_RTNL();
0d143fe1
JB
224
225 /* we hold the RTNL here so can safely walk the list */
226 list_for_each_entry(nsdata, &local->interfaces, list) {
371a255e 227 if (nsdata != sdata && ieee80211_sdata_running(nsdata)) {
0d143fe1
JB
228 /*
229 * Allow only a single IBSS interface to be up at any
230 * time. This is restricted because beacon distribution
231 * cannot work properly if both are in the same IBSS.
232 *
233 * To remove this restriction we'd have to disallow them
234 * from setting the same SSID on different IBSS interfaces
235 * belonging to the same hardware. Then, however, we're
236 * faced with having to adopt two different TSF timers...
237 */
87490f6d 238 if (iftype == NL80211_IFTYPE_ADHOC &&
0d143fe1
JB
239 nsdata->vif.type == NL80211_IFTYPE_ADHOC)
240 return -EBUSY;
241
242 /*
243 * The remaining checks are only performed for interfaces
244 * with the same MAC address.
245 */
371a255e
JB
246 if (!ether_addr_equal(sdata->vif.addr,
247 nsdata->vif.addr))
0d143fe1
JB
248 continue;
249
250 /*
251 * check whether it may have the same address
252 */
87490f6d 253 if (!identical_mac_addr_allowed(iftype,
0d143fe1
JB
254 nsdata->vif.type))
255 return -ENOTUNIQ;
256
257 /*
258 * can only add VLANs to enabled APs
259 */
87490f6d 260 if (iftype == NL80211_IFTYPE_AP_VLAN &&
0d143fe1
JB
261 nsdata->vif.type == NL80211_IFTYPE_AP)
262 sdata->bss = &nsdata->u.ap;
263 }
264 }
265
87490f6d
JB
266 return 0;
267}
268
3a25a8c8
JB
269static int ieee80211_check_queues(struct ieee80211_sub_if_data *sdata)
270{
271 int n_queues = sdata->local->hw.queues;
272 int i;
273
274 for (i = 0; i < IEEE80211_NUM_ACS; i++) {
275 if (WARN_ON_ONCE(sdata->vif.hw_queue[i] ==
276 IEEE80211_INVAL_HW_QUEUE))
277 return -EINVAL;
278 if (WARN_ON_ONCE(sdata->vif.hw_queue[i] >=
279 n_queues))
280 return -EINVAL;
281 }
282
bb3e10fb
LC
283 if ((sdata->vif.type != NL80211_IFTYPE_AP) ||
284 !(sdata->local->hw.flags & IEEE80211_HW_QUEUE_CONTROL)) {
3a25a8c8
JB
285 sdata->vif.cab_queue = IEEE80211_INVAL_HW_QUEUE;
286 return 0;
287 }
288
289 if (WARN_ON_ONCE(sdata->vif.cab_queue == IEEE80211_INVAL_HW_QUEUE))
290 return -EINVAL;
291
292 if (WARN_ON_ONCE(sdata->vif.cab_queue >= n_queues))
293 return -EINVAL;
294
295 return 0;
296}
297
85416a4f
CL
298void ieee80211_adjust_monitor_flags(struct ieee80211_sub_if_data *sdata,
299 const int offset)
300{
301 struct ieee80211_local *local = sdata->local;
302 u32 flags = sdata->u.mntr_flags;
303
304#define ADJUST(_f, _s) do { \
305 if (flags & MONITOR_FLAG_##_f) \
306 local->fif_##_s += offset; \
307 } while (0)
308
309 ADJUST(FCSFAIL, fcsfail);
310 ADJUST(PLCPFAIL, plcpfail);
311 ADJUST(CONTROL, control);
312 ADJUST(CONTROL, pspoll);
313 ADJUST(OTHER_BSS, other_bss);
314
315#undef ADJUST
316}
317
3a25a8c8
JB
318static void ieee80211_set_default_queues(struct ieee80211_sub_if_data *sdata)
319{
320 struct ieee80211_local *local = sdata->local;
321 int i;
322
323 for (i = 0; i < IEEE80211_NUM_ACS; i++) {
324 if (local->hw.flags & IEEE80211_HW_QUEUE_CONTROL)
325 sdata->vif.hw_queue[i] = IEEE80211_INVAL_HW_QUEUE;
a9d3c05c 326 else if (local->hw.queues >= IEEE80211_NUM_ACS)
3a25a8c8 327 sdata->vif.hw_queue[i] = i;
a9d3c05c
JB
328 else
329 sdata->vif.hw_queue[i] = 0;
3a25a8c8
JB
330 }
331 sdata->vif.cab_queue = IEEE80211_INVAL_HW_QUEUE;
332}
333
870d37fc 334int ieee80211_add_virtual_monitor(struct ieee80211_local *local)
4b6f1dd6
JB
335{
336 struct ieee80211_sub_if_data *sdata;
685fb72b 337 int ret = 0;
4b6f1dd6
JB
338
339 if (!(local->hw.flags & IEEE80211_HW_WANT_MONITOR_VIF))
340 return 0;
341
685fb72b
JB
342 mutex_lock(&local->iflist_mtx);
343
4b6f1dd6 344 if (local->monitor_sdata)
685fb72b 345 goto out_unlock;
4b6f1dd6
JB
346
347 sdata = kzalloc(sizeof(*sdata) + local->hw.vif_data_size, GFP_KERNEL);
685fb72b
JB
348 if (!sdata) {
349 ret = -ENOMEM;
350 goto out_unlock;
351 }
4b6f1dd6
JB
352
353 /* set up data */
354 sdata->local = local;
355 sdata->vif.type = NL80211_IFTYPE_MONITOR;
356 snprintf(sdata->name, IFNAMSIZ, "%s-monitor",
357 wiphy_name(local->hw.wiphy));
358
3a25a8c8
JB
359 ieee80211_set_default_queues(sdata);
360
4b6f1dd6
JB
361 ret = drv_add_interface(local, sdata);
362 if (WARN_ON(ret)) {
363 /* ok .. stupid driver, it asked for this! */
364 kfree(sdata);
685fb72b 365 goto out_unlock;
4b6f1dd6
JB
366 }
367
3a25a8c8
JB
368 ret = ieee80211_check_queues(sdata);
369 if (ret) {
370 kfree(sdata);
685fb72b 371 goto out_unlock;
3a25a8c8
JB
372 }
373
4b6f1dd6 374 rcu_assign_pointer(local->monitor_sdata, sdata);
685fb72b
JB
375 out_unlock:
376 mutex_unlock(&local->iflist_mtx);
377 return ret;
4b6f1dd6
JB
378}
379
870d37fc 380void ieee80211_del_virtual_monitor(struct ieee80211_local *local)
4b6f1dd6
JB
381{
382 struct ieee80211_sub_if_data *sdata;
383
384 if (!(local->hw.flags & IEEE80211_HW_WANT_MONITOR_VIF))
385 return;
386
685fb72b 387 mutex_lock(&local->iflist_mtx);
4b6f1dd6 388
685fb72b
JB
389 sdata = rcu_dereference_protected(local->monitor_sdata,
390 lockdep_is_held(&local->iflist_mtx));
4b6f1dd6 391 if (!sdata)
685fb72b 392 goto out_unlock;
4b6f1dd6
JB
393
394 rcu_assign_pointer(local->monitor_sdata, NULL);
395 synchronize_net();
396
397 drv_remove_interface(local, sdata);
398
399 kfree(sdata);
685fb72b
JB
400 out_unlock:
401 mutex_unlock(&local->iflist_mtx);
4b6f1dd6
JB
402}
403
34d4bc4d
JB
404/*
405 * NOTE: Be very careful when changing this function, it must NOT return
406 * an error on interface type changes that have been pre-checked, so most
407 * checks should be in ieee80211_check_concurrent_iface.
408 */
409static int ieee80211_do_open(struct net_device *dev, bool coming_up)
87490f6d
JB
410{
411 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
412 struct ieee80211_local *local = sdata->local;
413 struct sta_info *sta;
414 u32 changed = 0;
415 int res;
416 u32 hw_reconf_flags = 0;
417
0d143fe1
JB
418 switch (sdata->vif.type) {
419 case NL80211_IFTYPE_WDS:
420 if (!is_valid_ether_addr(sdata->u.wds.remote_addr))
421 return -ENOLINK;
422 break;
665c93a9
JB
423 case NL80211_IFTYPE_AP_VLAN: {
424 struct ieee80211_sub_if_data *master;
425
0d143fe1
JB
426 if (!sdata->bss)
427 return -ENOLINK;
665c93a9 428
0d143fe1 429 list_add(&sdata->u.vlan.list, &sdata->bss->vlans);
665c93a9
JB
430
431 master = container_of(sdata->bss,
432 struct ieee80211_sub_if_data, u.ap);
433 sdata->control_port_protocol =
434 master->control_port_protocol;
435 sdata->control_port_no_encrypt =
436 master->control_port_no_encrypt;
0d143fe1 437 break;
665c93a9 438 }
0d143fe1
JB
439 case NL80211_IFTYPE_AP:
440 sdata->bss = &sdata->u.ap;
441 break;
442 case NL80211_IFTYPE_MESH_POINT:
0d143fe1
JB
443 case NL80211_IFTYPE_STATION:
444 case NL80211_IFTYPE_MONITOR:
445 case NL80211_IFTYPE_ADHOC:
446 /* no special treatment */
447 break;
448 case NL80211_IFTYPE_UNSPECIFIED:
2e161f78 449 case NUM_NL80211_IFTYPES:
2ca27bcf
JB
450 case NL80211_IFTYPE_P2P_CLIENT:
451 case NL80211_IFTYPE_P2P_GO:
0d143fe1
JB
452 /* cannot happen */
453 WARN_ON(1);
454 break;
455 }
456
457 if (local->open_count == 0) {
24487981 458 res = drv_start(local);
0d143fe1
JB
459 if (res)
460 goto err_del_bss;
4e6cbfd0
JL
461 if (local->ops->napi_poll)
462 napi_enable(&local->napi);
e8975581
JB
463 /* we're brought up, everything changes */
464 hw_reconf_flags = ~0;
1f87f7d3 465 ieee80211_led_radio(local, true);
67408c8c
JB
466 ieee80211_mod_tpt_led_trig(local,
467 IEEE80211_TPT_LEDTRIG_FL_RADIO, 0);
0d143fe1
JB
468 }
469
470 /*
bf533e0b
JB
471 * Copy the hopefully now-present MAC address to
472 * this interface, if it has the special null one.
0d143fe1 473 */
bf533e0b
JB
474 if (is_zero_ether_addr(dev->dev_addr)) {
475 memcpy(dev->dev_addr,
476 local->hw.wiphy->perm_addr,
477 ETH_ALEN);
478 memcpy(dev->perm_addr, dev->dev_addr, ETH_ALEN);
479
480 if (!is_valid_ether_addr(dev->dev_addr)) {
4d6c36fa
JB
481 res = -EADDRNOTAVAIL;
482 goto err_stop;
0adc23f5 483 }
0d143fe1
JB
484 }
485
0d143fe1
JB
486 switch (sdata->vif.type) {
487 case NL80211_IFTYPE_AP_VLAN:
3edaf3e6
JB
488 /* no need to tell driver, but set carrier */
489 if (rtnl_dereference(sdata->bss->beacon))
490 netif_carrier_on(dev);
491 else
492 netif_carrier_off(dev);
0d143fe1
JB
493 break;
494 case NL80211_IFTYPE_MONITOR:
495 if (sdata->u.mntr_flags & MONITOR_FLAG_COOK_FRAMES) {
496 local->cooked_mntrs++;
497 break;
498 }
499
500 /* must be before the call to ieee80211_configure_filter */
501 local->monitors++;
e8975581 502 if (local->monitors == 1) {
0869aea0
JB
503 local->hw.conf.flags |= IEEE80211_CONF_MONITOR;
504 hw_reconf_flags |= IEEE80211_CONF_CHANGE_MONITOR;
e8975581 505 }
0d143fe1 506
85416a4f 507 ieee80211_adjust_monitor_flags(sdata, 1);
0d143fe1 508 ieee80211_configure_filter(local);
53e9b1de
DG
509
510 netif_carrier_on(dev);
0d143fe1 511 break;
0d143fe1 512 default:
34d4bc4d 513 if (coming_up) {
7b7eab6f 514 res = drv_add_interface(local, sdata);
34d4bc4d
JB
515 if (res)
516 goto err_stop;
3a25a8c8
JB
517 res = ieee80211_check_queues(sdata);
518 if (res)
519 goto err_del_interface;
34d4bc4d 520 }
0d143fe1 521
29cbe68c 522 if (sdata->vif.type == NL80211_IFTYPE_AP) {
e3b90ca2 523 local->fif_pspoll++;
7be5086d 524 local->fif_probe_req++;
e3b90ca2 525
e3b90ca2 526 ieee80211_configure_filter(local);
7be5086d
JB
527 } else if (sdata->vif.type == NL80211_IFTYPE_ADHOC) {
528 local->fif_probe_req++;
a3c9aa51 529 }
e3b90ca2 530
0d143fe1
JB
531 changed |= ieee80211_reset_erp_info(sdata);
532 ieee80211_bss_info_change_notify(sdata, changed);
0d143fe1 533
86a2ea41 534 if (sdata->vif.type == NL80211_IFTYPE_STATION ||
3edaf3e6
JB
535 sdata->vif.type == NL80211_IFTYPE_ADHOC ||
536 sdata->vif.type == NL80211_IFTYPE_AP)
0d143fe1
JB
537 netif_carrier_off(dev);
538 else
539 netif_carrier_on(dev);
59034591
EP
540
541 /*
542 * set default queue parameters so drivers don't
543 * need to initialise the hardware if the hardware
544 * doesn't start up with sane defaults
545 */
3abead59 546 ieee80211_set_wmm_default(sdata, true);
0d143fe1
JB
547 }
548
2d2080c3
JB
549 set_bit(SDATA_STATE_RUNNING, &sdata->state);
550
0d143fe1
JB
551 if (sdata->vif.type == NL80211_IFTYPE_WDS) {
552 /* Create STA entry for the WDS peer */
553 sta = sta_info_alloc(sdata, sdata->u.wds.remote_addr,
554 GFP_KERNEL);
555 if (!sta) {
556 res = -ENOMEM;
557 goto err_del_interface;
558 }
559
83d5cc01
JB
560 sta_info_pre_move_state(sta, IEEE80211_STA_AUTH);
561 sta_info_pre_move_state(sta, IEEE80211_STA_ASSOC);
562 sta_info_pre_move_state(sta, IEEE80211_STA_AUTHORIZED);
0d143fe1
JB
563
564 res = sta_info_insert(sta);
565 if (res) {
566 /* STA has been freed */
567 goto err_del_interface;
568 }
1be7fe8d
BJ
569
570 rate_control_rate_init(sta);
0d143fe1
JB
571 }
572
0d143fe1
JB
573 /*
574 * set_multicast_list will be invoked by the networking core
575 * which will check whether any increments here were done in
576 * error and sync them down to the hardware as filter flags.
577 */
578 if (sdata->flags & IEEE80211_SDATA_ALLMULTI)
579 atomic_inc(&local->iff_allmultis);
580
581 if (sdata->flags & IEEE80211_SDATA_PROMISC)
582 atomic_inc(&local->iff_promiscs);
583
7da7cc1d 584 mutex_lock(&local->mtx);
5cff20e6 585 hw_reconf_flags |= __ieee80211_recalc_idle(local);
7da7cc1d 586 mutex_unlock(&local->mtx);
5cff20e6 587
34d4bc4d
JB
588 if (coming_up)
589 local->open_count++;
590
59034591 591 if (hw_reconf_flags)
e8975581 592 ieee80211_hw_config(local, hw_reconf_flags);
0d143fe1 593
10f644a4 594 ieee80211_recalc_ps(local, -1);
965bedad 595
8a5b33f5 596 netif_tx_start_all_queues(dev);
0d143fe1
JB
597
598 return 0;
599 err_del_interface:
7b7eab6f 600 drv_remove_interface(local, sdata);
0d143fe1 601 err_stop:
24487981
JB
602 if (!local->open_count)
603 drv_stop(local);
0d143fe1
JB
604 err_del_bss:
605 sdata->bss = NULL;
606 if (sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
607 list_del(&sdata->u.vlan.list);
4d6c36fa 608 /* might already be clear but that doesn't matter */
2d2080c3 609 clear_bit(SDATA_STATE_RUNNING, &sdata->state);
0d143fe1
JB
610 return res;
611}
612
34d4bc4d 613static int ieee80211_open(struct net_device *dev)
0d143fe1
JB
614{
615 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
34d4bc4d
JB
616 int err;
617
618 /* fail early if user set an invalid address */
2fcf2824 619 if (!is_valid_ether_addr(dev->dev_addr))
34d4bc4d
JB
620 return -EADDRNOTAVAIL;
621
622 err = ieee80211_check_concurrent_iface(sdata, sdata->vif.type);
623 if (err)
624 return err;
625
626 return ieee80211_do_open(dev, true);
627}
628
629static void ieee80211_do_stop(struct ieee80211_sub_if_data *sdata,
630 bool going_down)
631{
0d143fe1 632 struct ieee80211_local *local = sdata->local;
5061b0c2
JB
633 unsigned long flags;
634 struct sk_buff *skb, *tmp;
e8975581 635 u32 hw_reconf_flags = 0;
5061b0c2 636 int i;
2cf22b89 637 enum nl80211_channel_type orig_ct;
0d143fe1 638
c29acf20
RM
639 clear_bit(SDATA_STATE_RUNNING, &sdata->state);
640
e2fd5dbc 641 if (rcu_access_pointer(local->scan_sdata) == sdata)
352ffad6
BC
642 ieee80211_scan_cancel(local);
643
0d143fe1
JB
644 /*
645 * Stop TX on this interface first.
646 */
34d4bc4d 647 netif_tx_stop_all_queues(sdata->dev);
0d143fe1 648
2eb278e0 649 ieee80211_roc_purge(sdata);
af6b6374 650
0d143fe1
JB
651 /*
652 * Remove all stations associated with this interface.
653 *
654 * This must be done before calling ops->remove_interface()
655 * because otherwise we can later invoke ops->sta_notify()
656 * whenever the STAs are removed, and that invalidates driver
657 * assumptions about always getting a vif pointer that is valid
658 * (because if we remove a STA after ops->remove_interface()
659 * the driver will have removed the vif info already!)
660 *
b9dcf712
JB
661 * This is relevant only in AP, WDS and mesh modes, since in
662 * all other modes we've already removed all stations when
663 * disconnecting etc.
0d143fe1
JB
664 */
665 sta_info_flush(local, sdata);
666
667 /*
668 * Don't count this interface for promisc/allmulti while it
669 * is down. dev_mc_unsync() will invoke set_multicast_list
670 * on the master interface which will sync these down to the
671 * hardware as filter flags.
672 */
673 if (sdata->flags & IEEE80211_SDATA_ALLMULTI)
674 atomic_dec(&local->iff_allmultis);
675
676 if (sdata->flags & IEEE80211_SDATA_PROMISC)
677 atomic_dec(&local->iff_promiscs);
678
7be5086d 679 if (sdata->vif.type == NL80211_IFTYPE_AP) {
e3b90ca2 680 local->fif_pspoll--;
7be5086d
JB
681 local->fif_probe_req--;
682 } else if (sdata->vif.type == NL80211_IFTYPE_ADHOC) {
683 local->fif_probe_req--;
684 }
e3b90ca2 685
34d4bc4d 686 netif_addr_lock_bh(sdata->dev);
3b8d81e0 687 spin_lock_bh(&local->filter_lock);
34d4bc4d
JB
688 __hw_addr_unsync(&local->mc_list, &sdata->dev->mc,
689 sdata->dev->addr_len);
3b8d81e0 690 spin_unlock_bh(&local->filter_lock);
34d4bc4d 691 netif_addr_unlock_bh(sdata->dev);
3b8d81e0 692
3ac64bee
JB
693 ieee80211_configure_filter(local);
694
7cbf0ba5
VN
695 del_timer_sync(&local->dynamic_ps_timer);
696 cancel_work_sync(&local->dynamic_ps_enable_work);
0d143fe1
JB
697
698 /* APs need special treatment */
699 if (sdata->vif.type == NL80211_IFTYPE_AP) {
57c9fff3 700 struct ieee80211_sub_if_data *vlan, *tmpsdata;
40b275b6
JB
701 struct beacon_data *old_beacon =
702 rtnl_dereference(sdata->u.ap.beacon);
02945821
AN
703 struct sk_buff *old_probe_resp =
704 rtnl_dereference(sdata->u.ap.probe_resp);
0d143fe1 705
b9dcf712
JB
706 /* sdata_running will return false, so this will disable */
707 ieee80211_bss_info_change_notify(sdata,
708 BSS_CHANGED_BEACON_ENABLED);
709
02945821 710 /* remove beacon and probe response */
a9b3cd7f 711 RCU_INIT_POINTER(sdata->u.ap.beacon, NULL);
02945821 712 RCU_INIT_POINTER(sdata->u.ap.probe_resp, NULL);
0d143fe1
JB
713 synchronize_rcu();
714 kfree(old_beacon);
5e2e05de 715 kfree_skb(old_probe_resp);
0d143fe1
JB
716
717 /* down all dependent devices, that is VLANs */
57c9fff3 718 list_for_each_entry_safe(vlan, tmpsdata, &sdata->u.ap.vlans,
0d143fe1
JB
719 u.vlan.list)
720 dev_close(vlan->dev);
721 WARN_ON(!list_empty(&sdata->u.ap.vlans));
6f2d9335
JB
722
723 /* free all potentially still buffered bcast frames */
724 local->total_ps_buffered -= skb_queue_len(&sdata->u.ap.ps_bc_buf);
725 skb_queue_purge(&sdata->u.ap.ps_bc_buf);
afa762f6
EP
726 } else if (sdata->vif.type == NL80211_IFTYPE_STATION) {
727 ieee80211_mgd_stop(sdata);
0d143fe1
JB
728 }
729
34d4bc4d
JB
730 if (going_down)
731 local->open_count--;
0d143fe1
JB
732
733 switch (sdata->vif.type) {
734 case NL80211_IFTYPE_AP_VLAN:
735 list_del(&sdata->u.vlan.list);
736 /* no need to tell driver */
737 break;
738 case NL80211_IFTYPE_MONITOR:
739 if (sdata->u.mntr_flags & MONITOR_FLAG_COOK_FRAMES) {
740 local->cooked_mntrs--;
741 break;
742 }
743
744 local->monitors--;
e8975581 745 if (local->monitors == 0) {
0869aea0
JB
746 local->hw.conf.flags &= ~IEEE80211_CONF_MONITOR;
747 hw_reconf_flags |= IEEE80211_CONF_CHANGE_MONITOR;
e8975581 748 }
0d143fe1 749
85416a4f 750 ieee80211_adjust_monitor_flags(sdata, -1);
0d143fe1 751 ieee80211_configure_filter(local);
0d143fe1 752 break;
0d143fe1 753 default:
c1475ca9 754 flush_work(&sdata->work);
35f20c14
JB
755 /*
756 * When we get here, the interface is marked down.
757 * Call synchronize_rcu() to wait for the RX path
758 * should it be using the interface and enqueuing
759 * frames at this very time on another CPU.
760 */
761 synchronize_rcu();
762 skb_queue_purge(&sdata->skb_queue);
763
97af7432 764 /*
b9dcf712
JB
765 * Disable beaconing here for mesh only, AP and IBSS
766 * are already taken care of.
97af7432 767 */
b9dcf712 768 if (sdata->vif.type == NL80211_IFTYPE_MESH_POINT)
97af7432
BC
769 ieee80211_bss_info_change_notify(sdata,
770 BSS_CHANGED_BEACON_ENABLED);
97af7432 771
b9dcf712
JB
772 /*
773 * Free all remaining keys, there shouldn't be any,
774 * except maybe group keys in AP more or WDS?
775 */
ad0e2b5a 776 ieee80211_free_keys(sdata);
b9dcf712 777
34d4bc4d 778 if (going_down)
7b7eab6f 779 drv_remove_interface(local, sdata);
0d143fe1
JB
780 }
781
782 sdata->bss = NULL;
783
7da7cc1d 784 mutex_lock(&local->mtx);
5cff20e6 785 hw_reconf_flags |= __ieee80211_recalc_idle(local);
7da7cc1d 786 mutex_unlock(&local->mtx);
5cff20e6
JB
787
788 ieee80211_recalc_ps(local, -1);
789
0d143fe1 790 if (local->open_count == 0) {
4e6cbfd0
JL
791 if (local->ops->napi_poll)
792 napi_disable(&local->napi);
ea77f12f 793 ieee80211_clear_tx_pending(local);
84f6a01c 794 ieee80211_stop_device(local);
0d143fe1 795
e8975581
JB
796 /* no reconfiguring after stop! */
797 hw_reconf_flags = 0;
0d143fe1
JB
798 }
799
2cf22b89
BG
800 /* Re-calculate channel-type, in case there are multiple vifs
801 * on different channel types.
802 */
803 orig_ct = local->_oper_channel_type;
804 ieee80211_set_channel_type(local, NULL, NL80211_CHAN_NO_HT);
805
e8975581 806 /* do after stop to avoid reconfiguring when we stop anyway */
2cf22b89 807 if (hw_reconf_flags || (orig_ct != local->_oper_channel_type))
e8975581
JB
808 ieee80211_hw_config(local, hw_reconf_flags);
809
5061b0c2
JB
810 spin_lock_irqsave(&local->queue_stop_reason_lock, flags);
811 for (i = 0; i < IEEE80211_MAX_QUEUES; i++) {
812 skb_queue_walk_safe(&local->pending[i], skb, tmp) {
813 struct ieee80211_tx_info *info = IEEE80211_SKB_CB(skb);
814 if (info->control.vif == &sdata->vif) {
815 __skb_unlink(skb, &local->pending[i]);
816 dev_kfree_skb_irq(skb);
817 }
818 }
819 }
820 spin_unlock_irqrestore(&local->queue_stop_reason_lock, flags);
34d4bc4d
JB
821}
822
823static int ieee80211_stop(struct net_device *dev)
824{
825 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
826
827 ieee80211_do_stop(sdata, true);
5061b0c2 828
0d143fe1
JB
829 return 0;
830}
831
832static void ieee80211_set_multicast_list(struct net_device *dev)
833{
0d143fe1 834 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
b4a4bf5d 835 struct ieee80211_local *local = sdata->local;
0d143fe1
JB
836 int allmulti, promisc, sdata_allmulti, sdata_promisc;
837
838 allmulti = !!(dev->flags & IFF_ALLMULTI);
839 promisc = !!(dev->flags & IFF_PROMISC);
840 sdata_allmulti = !!(sdata->flags & IEEE80211_SDATA_ALLMULTI);
841 sdata_promisc = !!(sdata->flags & IEEE80211_SDATA_PROMISC);
842
843 if (allmulti != sdata_allmulti) {
844 if (dev->flags & IFF_ALLMULTI)
845 atomic_inc(&local->iff_allmultis);
846 else
847 atomic_dec(&local->iff_allmultis);
848 sdata->flags ^= IEEE80211_SDATA_ALLMULTI;
849 }
850
851 if (promisc != sdata_promisc) {
852 if (dev->flags & IFF_PROMISC)
853 atomic_inc(&local->iff_promiscs);
854 else
855 atomic_dec(&local->iff_promiscs);
856 sdata->flags ^= IEEE80211_SDATA_PROMISC;
857 }
3b8d81e0 858 spin_lock_bh(&local->filter_lock);
22bedad3 859 __hw_addr_sync(&local->mc_list, &dev->mc, dev->addr_len);
3b8d81e0 860 spin_unlock_bh(&local->filter_lock);
3ac64bee 861 ieee80211_queue_work(&local->hw, &local->reconfig_filter);
0d143fe1
JB
862}
863
75636525
JB
864/*
865 * Called when the netdev is removed or, by the code below, before
866 * the interface type changes.
867 */
868static void ieee80211_teardown_sdata(struct net_device *dev)
f0706e82 869{
75636525
JB
870 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
871 struct ieee80211_local *local = sdata->local;
75636525 872 int flushed;
f0706e82
JB
873 int i;
874
75636525
JB
875 /* free extra data */
876 ieee80211_free_keys(sdata);
877
aee14ceb
JM
878 ieee80211_debugfs_remove_netdev(sdata);
879
f0706e82 880 for (i = 0; i < IEEE80211_FRAGMENT_MAX; i++)
75636525
JB
881 __skb_queue_purge(&sdata->fragments[i].skb_list);
882 sdata->fragment_next = 0;
11a843b7 883
b9dcf712
JB
884 if (ieee80211_vif_is_mesh(&sdata->vif))
885 mesh_rmc_free(sdata);
75636525
JB
886
887 flushed = sta_info_flush(local, sdata);
888 WARN_ON(flushed);
f0706e82
JB
889}
890
cf0277e7
JB
891static u16 ieee80211_netdev_select_queue(struct net_device *dev,
892 struct sk_buff *skb)
893{
894 return ieee80211_select_queue(IEEE80211_DEV_TO_SUB_IF(dev), skb);
895}
896
587e729e
JB
897static const struct net_device_ops ieee80211_dataif_ops = {
898 .ndo_open = ieee80211_open,
899 .ndo_stop = ieee80211_stop,
900 .ndo_uninit = ieee80211_teardown_sdata,
901 .ndo_start_xmit = ieee80211_subif_start_xmit,
afc4b13d 902 .ndo_set_rx_mode = ieee80211_set_multicast_list,
587e729e 903 .ndo_change_mtu = ieee80211_change_mtu,
47846c9b 904 .ndo_set_mac_address = ieee80211_change_mac,
cf0277e7 905 .ndo_select_queue = ieee80211_netdev_select_queue,
587e729e
JB
906};
907
cf0277e7
JB
908static u16 ieee80211_monitor_select_queue(struct net_device *dev,
909 struct sk_buff *skb)
910{
911 struct ieee80211_sub_if_data *sdata = IEEE80211_DEV_TO_SUB_IF(dev);
912 struct ieee80211_local *local = sdata->local;
913 struct ieee80211_hdr *hdr;
914 struct ieee80211_radiotap_header *rtap = (void *)skb->data;
915
32c5057b 916 if (local->hw.queues < IEEE80211_NUM_ACS)
cf0277e7
JB
917 return 0;
918
919 if (skb->len < 4 ||
b49bb574 920 skb->len < le16_to_cpu(rtap->it_len) + 2 /* frame control */)
cf0277e7
JB
921 return 0; /* doesn't matter, frame will be dropped */
922
b49bb574 923 hdr = (void *)((u8 *)skb->data + le16_to_cpu(rtap->it_len));
cf0277e7 924
00e96dec 925 return ieee80211_select_queue_80211(sdata, skb, hdr);
cf0277e7
JB
926}
927
587e729e
JB
928static const struct net_device_ops ieee80211_monitorif_ops = {
929 .ndo_open = ieee80211_open,
930 .ndo_stop = ieee80211_stop,
931 .ndo_uninit = ieee80211_teardown_sdata,
932 .ndo_start_xmit = ieee80211_monitor_start_xmit,
afc4b13d 933 .ndo_set_rx_mode = ieee80211_set_multicast_list,
587e729e
JB
934 .ndo_change_mtu = ieee80211_change_mtu,
935 .ndo_set_mac_address = eth_mac_addr,
cf0277e7 936 .ndo_select_queue = ieee80211_monitor_select_queue,
587e729e
JB
937};
938
939static void ieee80211_if_setup(struct net_device *dev)
940{
941 ether_setup(dev);
550fd08c 942 dev->priv_flags &= ~IFF_TX_SKB_SHARING;
587e729e 943 dev->netdev_ops = &ieee80211_dataif_ops;
587e729e
JB
944 dev->destructor = free_netdev;
945}
946
1fa57d01
JB
947static void ieee80211_iface_work(struct work_struct *work)
948{
949 struct ieee80211_sub_if_data *sdata =
950 container_of(work, struct ieee80211_sub_if_data, work);
951 struct ieee80211_local *local = sdata->local;
952 struct sk_buff *skb;
344eec67 953 struct sta_info *sta;
c1475ca9 954 struct ieee80211_ra_tid *ra_tid;
1fa57d01
JB
955
956 if (!ieee80211_sdata_running(sdata))
957 return;
958
959 if (local->scanning)
960 return;
961
962 /*
963 * ieee80211_queue_work() should have picked up most cases,
964 * here we'll pick the rest.
965 */
966 if (WARN(local->suspended,
967 "interface work scheduled while going to suspend\n"))
968 return;
969
970 /* first process frames */
971 while ((skb = skb_dequeue(&sdata->skb_queue))) {
bed7ee6e
JB
972 struct ieee80211_mgmt *mgmt = (void *)skb->data;
973
c1475ca9
JB
974 if (skb->pkt_type == IEEE80211_SDATA_QUEUE_AGG_START) {
975 ra_tid = (void *)&skb->cb;
976 ieee80211_start_tx_ba_cb(&sdata->vif, ra_tid->ra,
977 ra_tid->tid);
978 } else if (skb->pkt_type == IEEE80211_SDATA_QUEUE_AGG_STOP) {
979 ra_tid = (void *)&skb->cb;
980 ieee80211_stop_tx_ba_cb(&sdata->vif, ra_tid->ra,
981 ra_tid->tid);
982 } else if (ieee80211_is_action(mgmt->frame_control) &&
983 mgmt->u.action.category == WLAN_CATEGORY_BACK) {
bed7ee6e 984 int len = skb->len;
bed7ee6e 985
a93e3644 986 mutex_lock(&local->sta_mtx);
875ae5f6 987 sta = sta_info_get_bss(sdata, mgmt->sa);
bed7ee6e
JB
988 if (sta) {
989 switch (mgmt->u.action.u.addba_req.action_code) {
990 case WLAN_ACTION_ADDBA_REQ:
991 ieee80211_process_addba_request(
992 local, sta, mgmt, len);
993 break;
994 case WLAN_ACTION_ADDBA_RESP:
995 ieee80211_process_addba_resp(local, sta,
996 mgmt, len);
997 break;
998 case WLAN_ACTION_DELBA:
999 ieee80211_process_delba(sdata, sta,
1000 mgmt, len);
1001 break;
1002 default:
1003 WARN_ON(1);
1004 break;
1005 }
1006 }
a93e3644 1007 mutex_unlock(&local->sta_mtx);
344eec67
JB
1008 } else if (ieee80211_is_data_qos(mgmt->frame_control)) {
1009 struct ieee80211_hdr *hdr = (void *)mgmt;
1010 /*
1011 * So the frame isn't mgmt, but frame_control
1012 * is at the right place anyway, of course, so
1013 * the if statement is correct.
1014 *
1015 * Warn if we have other data frame types here,
1016 * they must not get here.
1017 */
1018 WARN_ON(hdr->frame_control &
1019 cpu_to_le16(IEEE80211_STYPE_NULLFUNC));
1020 WARN_ON(!(hdr->seq_ctrl &
1021 cpu_to_le16(IEEE80211_SCTL_FRAG)));
1022 /*
1023 * This was a fragment of a frame, received while
1024 * a block-ack session was active. That cannot be
1025 * right, so terminate the session.
1026 */
a93e3644 1027 mutex_lock(&local->sta_mtx);
875ae5f6 1028 sta = sta_info_get_bss(sdata, mgmt->sa);
344eec67
JB
1029 if (sta) {
1030 u16 tid = *ieee80211_get_qos_ctl(hdr) &
1031 IEEE80211_QOS_CTL_TID_MASK;
1032
1033 __ieee80211_stop_rx_ba_session(
1034 sta, tid, WLAN_BACK_RECIPIENT,
53f73c09
JB
1035 WLAN_REASON_QSTA_REQUIRE_SETUP,
1036 true);
344eec67 1037 }
a93e3644 1038 mutex_unlock(&local->sta_mtx);
bed7ee6e 1039 } else switch (sdata->vif.type) {
1fa57d01
JB
1040 case NL80211_IFTYPE_STATION:
1041 ieee80211_sta_rx_queued_mgmt(sdata, skb);
1042 break;
1043 case NL80211_IFTYPE_ADHOC:
1044 ieee80211_ibss_rx_queued_mgmt(sdata, skb);
1045 break;
1046 case NL80211_IFTYPE_MESH_POINT:
1047 if (!ieee80211_vif_is_mesh(&sdata->vif))
1048 break;
1049 ieee80211_mesh_rx_queued_mgmt(sdata, skb);
1050 break;
1051 default:
1052 WARN(1, "frame for unexpected interface type");
1fa57d01
JB
1053 break;
1054 }
36b3a628
JB
1055
1056 kfree_skb(skb);
1fa57d01
JB
1057 }
1058
1059 /* then other type-dependent work */
1060 switch (sdata->vif.type) {
1061 case NL80211_IFTYPE_STATION:
1062 ieee80211_sta_work(sdata);
1063 break;
1064 case NL80211_IFTYPE_ADHOC:
1065 ieee80211_ibss_work(sdata);
1066 break;
1067 case NL80211_IFTYPE_MESH_POINT:
1068 if (!ieee80211_vif_is_mesh(&sdata->vif))
1069 break;
1070 ieee80211_mesh_work(sdata);
1071 break;
1072 default:
1073 break;
1074 }
1075}
1076
1077
75636525
JB
1078/*
1079 * Helper function to initialise an interface to a specific type.
1080 */
1081static void ieee80211_setup_sdata(struct ieee80211_sub_if_data *sdata,
05c914fe 1082 enum nl80211_iftype type)
f0706e82 1083{
75636525
JB
1084 /* clear type-dependent union */
1085 memset(&sdata->u, 0, sizeof(sdata->u));
1086
1087 /* and set some type-dependent values */
1088 sdata->vif.type = type;
2ca27bcf 1089 sdata->vif.p2p = false;
587e729e 1090 sdata->dev->netdev_ops = &ieee80211_dataif_ops;
60719ffd 1091 sdata->wdev.iftype = type;
75636525 1092
a621fa4d
JB
1093 sdata->control_port_protocol = cpu_to_be16(ETH_P_PAE);
1094 sdata->control_port_no_encrypt = false;
1095
b53be792
SW
1096 sdata->noack_map = 0;
1097
75636525
JB
1098 /* only monitor differs */
1099 sdata->dev->type = ARPHRD_ETHER;
1100
35f20c14 1101 skb_queue_head_init(&sdata->skb_queue);
1fa57d01 1102 INIT_WORK(&sdata->work, ieee80211_iface_work);
35f20c14 1103
75636525 1104 switch (type) {
2ca27bcf
JB
1105 case NL80211_IFTYPE_P2P_GO:
1106 type = NL80211_IFTYPE_AP;
1107 sdata->vif.type = type;
1108 sdata->vif.p2p = true;
1109 /* fall through */
05c914fe 1110 case NL80211_IFTYPE_AP:
75636525
JB
1111 skb_queue_head_init(&sdata->u.ap.ps_bc_buf);
1112 INIT_LIST_HEAD(&sdata->u.ap.vlans);
1113 break;
2ca27bcf
JB
1114 case NL80211_IFTYPE_P2P_CLIENT:
1115 type = NL80211_IFTYPE_STATION;
1116 sdata->vif.type = type;
1117 sdata->vif.p2p = true;
1118 /* fall through */
05c914fe 1119 case NL80211_IFTYPE_STATION:
9c6bd790 1120 ieee80211_sta_setup_sdata(sdata);
472dbc45 1121 break;
46900298
JB
1122 case NL80211_IFTYPE_ADHOC:
1123 ieee80211_ibss_setup_sdata(sdata);
1124 break;
05c914fe 1125 case NL80211_IFTYPE_MESH_POINT:
75636525
JB
1126 if (ieee80211_vif_is_mesh(&sdata->vif))
1127 ieee80211_mesh_init_sdata(sdata);
1128 break;
05c914fe 1129 case NL80211_IFTYPE_MONITOR:
75636525 1130 sdata->dev->type = ARPHRD_IEEE80211_RADIOTAP;
587e729e 1131 sdata->dev->netdev_ops = &ieee80211_monitorif_ops;
75636525
JB
1132 sdata->u.mntr_flags = MONITOR_FLAG_CONTROL |
1133 MONITOR_FLAG_OTHER_BSS;
1134 break;
05c914fe
JB
1135 case NL80211_IFTYPE_WDS:
1136 case NL80211_IFTYPE_AP_VLAN:
75636525 1137 break;
05c914fe 1138 case NL80211_IFTYPE_UNSPECIFIED:
2e161f78 1139 case NUM_NL80211_IFTYPES:
75636525
JB
1140 BUG();
1141 break;
1142 }
1143
1144 ieee80211_debugfs_add_netdev(sdata);
1145}
1146
94c514fe
AE
1147static void ieee80211_clean_sdata(struct ieee80211_sub_if_data *sdata)
1148{
1149 switch (sdata->vif.type) {
1150 case NL80211_IFTYPE_MESH_POINT:
1151 mesh_path_flush_by_iface(sdata);
1152 break;
1153
1154 default:
1155 break;
1156 }
1157}
1158
34d4bc4d
JB
1159static int ieee80211_runtime_change_iftype(struct ieee80211_sub_if_data *sdata,
1160 enum nl80211_iftype type)
1161{
1162 struct ieee80211_local *local = sdata->local;
1163 int ret, err;
2ca27bcf
JB
1164 enum nl80211_iftype internal_type = type;
1165 bool p2p = false;
34d4bc4d
JB
1166
1167 ASSERT_RTNL();
1168
1169 if (!local->ops->change_interface)
1170 return -EBUSY;
1171
1172 switch (sdata->vif.type) {
1173 case NL80211_IFTYPE_AP:
1174 case NL80211_IFTYPE_STATION:
1175 case NL80211_IFTYPE_ADHOC:
1176 /*
1177 * Could maybe also all others here?
1178 * Just not sure how that interacts
1179 * with the RX/config path e.g. for
1180 * mesh.
1181 */
1182 break;
1183 default:
1184 return -EBUSY;
1185 }
1186
1187 switch (type) {
1188 case NL80211_IFTYPE_AP:
1189 case NL80211_IFTYPE_STATION:
1190 case NL80211_IFTYPE_ADHOC:
1191 /*
1192 * Could probably support everything
1193 * but WDS here (WDS do_open can fail
1194 * under memory pressure, which this
1195 * code isn't prepared to handle).
1196 */
1197 break;
2ca27bcf
JB
1198 case NL80211_IFTYPE_P2P_CLIENT:
1199 p2p = true;
1200 internal_type = NL80211_IFTYPE_STATION;
1201 break;
1202 case NL80211_IFTYPE_P2P_GO:
1203 p2p = true;
1204 internal_type = NL80211_IFTYPE_AP;
1205 break;
34d4bc4d
JB
1206 default:
1207 return -EBUSY;
1208 }
1209
2ca27bcf 1210 ret = ieee80211_check_concurrent_iface(sdata, internal_type);
34d4bc4d
JB
1211 if (ret)
1212 return ret;
1213
1214 ieee80211_do_stop(sdata, false);
1215
1216 ieee80211_teardown_sdata(sdata->dev);
1217
2ca27bcf 1218 ret = drv_change_interface(local, sdata, internal_type, p2p);
34d4bc4d
JB
1219 if (ret)
1220 type = sdata->vif.type;
1221
3a25a8c8
JB
1222 /*
1223 * Ignore return value here, there's not much we can do since
1224 * the driver changed the interface type internally already.
1225 * The warnings will hopefully make driver authors fix it :-)
1226 */
1227 ieee80211_check_queues(sdata);
1228
34d4bc4d
JB
1229 ieee80211_setup_sdata(sdata, type);
1230
1231 err = ieee80211_do_open(sdata->dev, false);
1232 WARN(err, "type change: do_open returned %d", err);
1233
1234 return ret;
1235}
1236
f3947e2d 1237int ieee80211_if_change_type(struct ieee80211_sub_if_data *sdata,
05c914fe 1238 enum nl80211_iftype type)
75636525 1239{
34d4bc4d
JB
1240 int ret;
1241
f3947e2d
JB
1242 ASSERT_RTNL();
1243
2ca27bcf 1244 if (type == ieee80211_vif_type_p2p(&sdata->vif))
f3947e2d
JB
1245 return 0;
1246
e60c7744 1247 /* Setting ad-hoc mode on non-IBSS channel is not supported. */
dcebf45c
PR
1248 if (sdata->local->oper_channel->flags & IEEE80211_CHAN_NO_IBSS &&
1249 type == NL80211_IFTYPE_ADHOC)
e60c7744
JB
1250 return -EOPNOTSUPP;
1251
34d4bc4d
JB
1252 if (ieee80211_sdata_running(sdata)) {
1253 ret = ieee80211_runtime_change_iftype(sdata, type);
1254 if (ret)
1255 return ret;
1256 } else {
1257 /* Purge and reset type-dependent state. */
1258 ieee80211_teardown_sdata(sdata->dev);
1259 ieee80211_setup_sdata(sdata, type);
1260 }
75636525
JB
1261
1262 /* reset some values that shouldn't be kept across type changes */
bda3933a 1263 sdata->vif.bss_conf.basic_rates =
96dd22ac
JB
1264 ieee80211_mandatory_rates(sdata->local,
1265 sdata->local->hw.conf.channel->band);
75636525 1266 sdata->drop_unencrypted = 0;
9bc383de
JB
1267 if (type == NL80211_IFTYPE_STATION)
1268 sdata->u.mgd.use_4addr = false;
f3947e2d
JB
1269
1270 return 0;
f0706e82
JB
1271}
1272
fa9029f8
JB
1273static void ieee80211_assign_perm_addr(struct ieee80211_local *local,
1274 struct net_device *dev,
1275 enum nl80211_iftype type)
1276{
1277 struct ieee80211_sub_if_data *sdata;
1278 u64 mask, start, addr, val, inc;
1279 u8 *m;
1280 u8 tmp_addr[ETH_ALEN];
1281 int i;
1282
1283 /* default ... something at least */
1284 memcpy(dev->perm_addr, local->hw.wiphy->perm_addr, ETH_ALEN);
1285
1286 if (is_zero_ether_addr(local->hw.wiphy->addr_mask) &&
1287 local->hw.wiphy->n_addresses <= 1)
1288 return;
1289
1290
1291 mutex_lock(&local->iflist_mtx);
1292
1293 switch (type) {
1294 case NL80211_IFTYPE_MONITOR:
1295 /* doesn't matter */
1296 break;
1297 case NL80211_IFTYPE_WDS:
1298 case NL80211_IFTYPE_AP_VLAN:
1299 /* match up with an AP interface */
1300 list_for_each_entry(sdata, &local->interfaces, list) {
1301 if (sdata->vif.type != NL80211_IFTYPE_AP)
1302 continue;
1303 memcpy(dev->perm_addr, sdata->vif.addr, ETH_ALEN);
1304 break;
1305 }
1306 /* keep default if no AP interface present */
1307 break;
1308 default:
1309 /* assign a new address if possible -- try n_addresses first */
1310 for (i = 0; i < local->hw.wiphy->n_addresses; i++) {
1311 bool used = false;
1312
1313 list_for_each_entry(sdata, &local->interfaces, list) {
1314 if (memcmp(local->hw.wiphy->addresses[i].addr,
1315 sdata->vif.addr, ETH_ALEN) == 0) {
1316 used = true;
1317 break;
1318 }
1319 }
1320
1321 if (!used) {
1322 memcpy(dev->perm_addr,
1323 local->hw.wiphy->addresses[i].addr,
1324 ETH_ALEN);
1325 break;
1326 }
1327 }
1328
1329 /* try mask if available */
1330 if (is_zero_ether_addr(local->hw.wiphy->addr_mask))
1331 break;
1332
1333 m = local->hw.wiphy->addr_mask;
1334 mask = ((u64)m[0] << 5*8) | ((u64)m[1] << 4*8) |
1335 ((u64)m[2] << 3*8) | ((u64)m[3] << 2*8) |
1336 ((u64)m[4] << 1*8) | ((u64)m[5] << 0*8);
1337
1338 if (__ffs64(mask) + hweight64(mask) != fls64(mask)) {
1339 /* not a contiguous mask ... not handled now! */
bdcbd8e0 1340 pr_info("not contiguous\n");
fa9029f8
JB
1341 break;
1342 }
1343
1344 m = local->hw.wiphy->perm_addr;
1345 start = ((u64)m[0] << 5*8) | ((u64)m[1] << 4*8) |
1346 ((u64)m[2] << 3*8) | ((u64)m[3] << 2*8) |
1347 ((u64)m[4] << 1*8) | ((u64)m[5] << 0*8);
1348
1349 inc = 1ULL<<__ffs64(mask);
1350 val = (start & mask);
1351 addr = (start & ~mask) | (val & mask);
1352 do {
1353 bool used = false;
1354
1355 tmp_addr[5] = addr >> 0*8;
1356 tmp_addr[4] = addr >> 1*8;
1357 tmp_addr[3] = addr >> 2*8;
1358 tmp_addr[2] = addr >> 3*8;
1359 tmp_addr[1] = addr >> 4*8;
1360 tmp_addr[0] = addr >> 5*8;
1361
1362 val += inc;
1363
1364 list_for_each_entry(sdata, &local->interfaces, list) {
1365 if (memcmp(tmp_addr, sdata->vif.addr,
1366 ETH_ALEN) == 0) {
1367 used = true;
1368 break;
1369 }
1370 }
1371
1372 if (!used) {
1373 memcpy(dev->perm_addr, tmp_addr, ETH_ALEN);
1374 break;
1375 }
1376 addr = (start & ~mask) | (val & mask);
1377 } while (addr != start);
1378
1379 break;
1380 }
1381
1382 mutex_unlock(&local->iflist_mtx);
1383}
1384
3e122be0 1385int ieee80211_if_add(struct ieee80211_local *local, const char *name,
84efbb84 1386 struct wireless_dev **new_wdev, enum nl80211_iftype type,
ee385855 1387 struct vif_params *params)
f0706e82
JB
1388{
1389 struct net_device *ndev;
f0706e82 1390 struct ieee80211_sub_if_data *sdata = NULL;
75636525 1391 int ret, i;
ded81f6b 1392 int txqs = 1;
f0706e82
JB
1393
1394 ASSERT_RTNL();
75636525 1395
ded81f6b
JB
1396 if (local->hw.queues >= IEEE80211_NUM_ACS)
1397 txqs = IEEE80211_NUM_ACS;
1398
55d99059 1399 ndev = alloc_netdev_mqs(sizeof(*sdata) + local->hw.vif_data_size,
ded81f6b 1400 name, ieee80211_if_setup, txqs, 1);
f0706e82
JB
1401 if (!ndev)
1402 return -ENOMEM;
a272a720 1403 dev_net_set(ndev, wiphy_net(local->hw.wiphy));
f0706e82 1404
f3994ece
JB
1405 ndev->needed_headroom = local->tx_headroom +
1406 4*6 /* four MAC addresses */
1407 + 2 + 2 + 2 + 2 /* ctl, dur, seq, qos */
1408 + 6 /* mesh */
1409 + 8 /* rfc1042/bridge tunnel */
1410 - ETH_HLEN /* ethernet hard_header_len */
1411 + IEEE80211_ENCRYPT_HEADROOM;
1412 ndev->needed_tailroom = IEEE80211_ENCRYPT_TAILROOM;
1413
59e7e707
TLSC
1414 ret = dev_alloc_name(ndev, ndev->name);
1415 if (ret < 0)
1416 goto fail;
1417
fa9029f8
JB
1418 ieee80211_assign_perm_addr(local, ndev, type);
1419 memcpy(ndev->dev_addr, ndev->perm_addr, ETH_ALEN);
f0706e82
JB
1420 SET_NETDEV_DEV(ndev, wiphy_dev(local->hw.wiphy));
1421
3e122be0
JB
1422 /* don't use IEEE80211_DEV_TO_SUB_IF because it checks too much */
1423 sdata = netdev_priv(ndev);
f0706e82 1424 ndev->ieee80211_ptr = &sdata->wdev;
47846c9b
JB
1425 memcpy(sdata->vif.addr, ndev->dev_addr, ETH_ALEN);
1426 memcpy(sdata->name, ndev->name, IFNAMSIZ);
75636525
JB
1427
1428 /* initialise type-independent data */
f0706e82 1429 sdata->wdev.wiphy = local->hw.wiphy;
f0706e82 1430 sdata->local = local;
75636525 1431 sdata->dev = ndev;
68542962
JO
1432#ifdef CONFIG_INET
1433 sdata->arp_filter_state = true;
1434#endif
75636525
JB
1435
1436 for (i = 0; i < IEEE80211_FRAGMENT_MAX; i++)
1437 skb_queue_head_init(&sdata->fragments[i].skb_list);
1438
1439 INIT_LIST_HEAD(&sdata->key_list);
1440
37eb0b16
JM
1441 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
1442 struct ieee80211_supported_band *sband;
1443 sband = local->hw.wiphy->bands[i];
1444 sdata->rc_rateidx_mask[i] =
1445 sband ? (1 << sband->n_bitrates) - 1 : 0;
19468413
SW
1446 if (sband)
1447 memcpy(sdata->rc_rateidx_mcs_mask[i],
1448 sband->ht_cap.mcs.rx_mask,
1449 sizeof(sdata->rc_rateidx_mcs_mask[i]));
1450 else
1451 memset(sdata->rc_rateidx_mcs_mask[i], 0,
1452 sizeof(sdata->rc_rateidx_mcs_mask[i]));
37eb0b16 1453 }
75636525 1454
3a25a8c8
JB
1455 ieee80211_set_default_queues(sdata);
1456
75636525
JB
1457 /* setup type-dependent data */
1458 ieee80211_setup_sdata(sdata, type);
f0706e82 1459
9bc383de
JB
1460 if (params) {
1461 ndev->ieee80211_ptr->use_4addr = params->use_4addr;
1462 if (type == NL80211_IFTYPE_STATION)
1463 sdata->u.mgd.use_4addr = params->use_4addr;
1464 }
1465
72d78728
AN
1466 ndev->features |= local->hw.netdev_features;
1467
f0706e82
JB
1468 ret = register_netdevice(ndev);
1469 if (ret)
1470 goto fail;
1471
c771c9d8 1472 mutex_lock(&local->iflist_mtx);
79010420 1473 list_add_tail_rcu(&sdata->list, &local->interfaces);
c771c9d8 1474 mutex_unlock(&local->iflist_mtx);
79010420 1475
84efbb84
JB
1476 if (new_wdev)
1477 *new_wdev = &sdata->wdev;
f0706e82 1478
f0706e82
JB
1479 return 0;
1480
75636525 1481 fail:
f0706e82
JB
1482 free_netdev(ndev);
1483 return ret;
1484}
1485
f698d856 1486void ieee80211_if_remove(struct ieee80211_sub_if_data *sdata)
f0706e82 1487{
f0706e82 1488 ASSERT_RTNL();
11a843b7 1489
c771c9d8 1490 mutex_lock(&sdata->local->iflist_mtx);
75636525 1491 list_del_rcu(&sdata->list);
c771c9d8
JB
1492 mutex_unlock(&sdata->local->iflist_mtx);
1493
94c514fe
AE
1494 /* clean up type-dependent data */
1495 ieee80211_clean_sdata(sdata);
ece1a2e7 1496
75636525 1497 synchronize_rcu();
f698d856 1498 unregister_netdevice(sdata->dev);
f0706e82
JB
1499}
1500
75636525
JB
1501/*
1502 * Remove all interfaces, may only be called at hardware unregistration
1503 * time because it doesn't do RCU-safe list removals.
1504 */
1505void ieee80211_remove_interfaces(struct ieee80211_local *local)
f0706e82 1506{
75636525 1507 struct ieee80211_sub_if_data *sdata, *tmp;
efe117ab 1508 LIST_HEAD(unreg_list);
f0706e82
JB
1509
1510 ASSERT_RTNL();
1511
efe117ab 1512 mutex_lock(&local->iflist_mtx);
75636525
JB
1513 list_for_each_entry_safe(sdata, tmp, &local->interfaces, list) {
1514 list_del(&sdata->list);
c771c9d8 1515
94c514fe 1516 ieee80211_clean_sdata(sdata);
ece1a2e7 1517
efe117ab 1518 unregister_netdevice_queue(sdata->dev, &unreg_list);
f0706e82 1519 }
efe117ab
ED
1520 mutex_unlock(&local->iflist_mtx);
1521 unregister_netdevice_many(&unreg_list);
5f04d506 1522 list_del(&unreg_list);
f0706e82 1523}
5cff20e6 1524
47846c9b
JB
1525static int netdev_notify(struct notifier_block *nb,
1526 unsigned long state,
1527 void *ndev)
1528{
1529 struct net_device *dev = ndev;
1530 struct ieee80211_sub_if_data *sdata;
1531
1532 if (state != NETDEV_CHANGENAME)
1533 return 0;
1534
1535 if (!dev->ieee80211_ptr || !dev->ieee80211_ptr->wiphy)
1536 return 0;
1537
1538 if (dev->ieee80211_ptr->wiphy->privid != mac80211_wiphy_privid)
1539 return 0;
1540
1541 sdata = IEEE80211_DEV_TO_SUB_IF(dev);
1542
2f5265e6 1543 memcpy(sdata->name, dev->name, IFNAMSIZ);
47846c9b
JB
1544
1545 ieee80211_debugfs_rename_netdev(sdata);
1546 return 0;
1547}
1548
1549static struct notifier_block mac80211_netdev_notifier = {
1550 .notifier_call = netdev_notify,
1551};
1552
1553int ieee80211_iface_init(void)
1554{
1555 return register_netdevice_notifier(&mac80211_netdev_notifier);
1556}
1557
1558void ieee80211_iface_exit(void)
1559{
1560 unregister_netdevice_notifier(&mac80211_netdev_notifier);
1561}