mac80211: reject setting masked mac addresses
[linux-2.6-block.git] / net / mac80211 / mesh_plink.c
CommitLineData
c3896d2c 1/*
264d9b7d 2 * Copyright (c) 2008, 2009 open80211s Ltd.
c3896d2c
LCC
3 * Author: Luis Carlos Cobo <luisca@cozybit.com>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
8 */
5a0e3ad6 9#include <linux/gfp.h>
902acc78
JB
10#include <linux/kernel.h>
11#include <linux/random.h>
c3896d2c 12#include "ieee80211_i.h"
2c8dccc7 13#include "rate.h"
c3896d2c 14#include "mesh.h"
c3896d2c 15
8db09850
TP
16#define PLINK_GET_LLID(p) (p + 2)
17#define PLINK_GET_PLID(p) (p + 4)
c3896d2c
LCC
18
19#define mod_plink_timer(s, t) (mod_timer(&s->plink_timer, \
20 jiffies + HZ * t / 1000))
21
3d4f9699
AN
22/* We only need a valid sta if user configured a minimum rssi_threshold. */
23#define rssi_threshold_check(sta, sdata) \
55335137 24 (sdata->u.mesh.mshcfg.rssi_threshold == 0 ||\
3d4f9699
AN
25 (sta && (s8) -ewma_read(&sta->avg_signal) > \
26 sdata->u.mesh.mshcfg.rssi_threshold))
55335137 27
c3896d2c
LCC
28enum plink_event {
29 PLINK_UNDEFINED,
30 OPN_ACPT,
31 OPN_RJCT,
32 OPN_IGNR,
33 CNF_ACPT,
34 CNF_RJCT,
35 CNF_IGNR,
36 CLS_ACPT,
37 CLS_IGNR
38};
39
ba4a14e1
TP
40static int mesh_plink_frame_tx(struct ieee80211_sub_if_data *sdata,
41 enum ieee80211_self_protected_actioncode action,
42 u8 *da, __le16 llid, __le16 plid, __le16 reason);
43
c3896d2c 44static inline
df323818 45u32 mesh_plink_inc_estab_count(struct ieee80211_sub_if_data *sdata)
c3896d2c 46{
1258d976 47 atomic_inc(&sdata->u.mesh.estab_plinks);
df323818 48 return mesh_accept_plinks_update(sdata);
c3896d2c
LCC
49}
50
51static inline
df323818 52u32 mesh_plink_dec_estab_count(struct ieee80211_sub_if_data *sdata)
c3896d2c 53{
1258d976 54 atomic_dec(&sdata->u.mesh.estab_plinks);
df323818 55 return mesh_accept_plinks_update(sdata);
c3896d2c
LCC
56}
57
58/**
59 * mesh_plink_fsm_restart - restart a mesh peer link finite state machine
60 *
23c7a29c 61 * @sta: mesh peer link to restart
c3896d2c 62 *
07346f81 63 * Locking: this function must be called holding sta->lock
c3896d2c
LCC
64 */
65static inline void mesh_plink_fsm_restart(struct sta_info *sta)
66{
57cf8043 67 sta->plink_state = NL80211_PLINK_LISTEN;
37659ff8
LCC
68 sta->llid = sta->plid = sta->reason = 0;
69 sta->plink_retries = 0;
c3896d2c
LCC
70}
71
93e5deb1 72/*
54ab1ffb 73 * Allocate mesh sta entry and insert into station table
93e5deb1 74 */
03e4497e 75static struct sta_info *mesh_plink_alloc(struct ieee80211_sub_if_data *sdata,
54ab1ffb 76 u8 *hw_addr)
c3896d2c 77{
c3896d2c
LCC
78 struct sta_info *sta;
79
54ab1ffb 80 if (sdata->local->num_sta >= MESH_MAX_PLINKS)
73651ee6 81 return NULL;
c3896d2c 82
34e89507 83 sta = sta_info_alloc(sdata, hw_addr, GFP_KERNEL);
73651ee6
JB
84 if (!sta)
85 return NULL;
c3896d2c 86
83d5cc01
JB
87 sta_info_pre_move_state(sta, IEEE80211_STA_AUTH);
88 sta_info_pre_move_state(sta, IEEE80211_STA_ASSOC);
89 sta_info_pre_move_state(sta, IEEE80211_STA_AUTHORIZED);
d9a7ddb0 90
c2c98fde 91 set_sta_flag(sta, WLAN_STA_WME);
d9a7ddb0 92
c3896d2c
LCC
93 return sta;
94}
95
2c53040f 96/**
cbf9322e 97 * mesh_set_ht_prot_mode - set correct HT protection mode
57aac7c5 98 *
cbf9322e
AN
99 * Section 9.23.3.5 of IEEE 80211-2012 describes the protection rules for HT
100 * mesh STA in a MBSS. Three HT protection modes are supported for now, non-HT
101 * mixed mode, 20MHz-protection and no-protection mode. non-HT mixed mode is
102 * selected if any non-HT peers are present in our MBSS. 20MHz-protection mode
103 * is selected if all peers in our 20/40MHz MBSS support HT and atleast one
104 * HT20 peer is present. Otherwise no-protection mode is selected.
57aac7c5
AN
105 */
106static u32 mesh_set_ht_prot_mode(struct ieee80211_sub_if_data *sdata)
107{
108 struct ieee80211_local *local = sdata->local;
109 struct sta_info *sta;
110 u32 changed = 0;
111 u16 ht_opmode;
112 bool non_ht_sta = false, ht20_sta = false;
113
4bf88530 114 if (sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_20_NOHT)
57aac7c5
AN
115 return 0;
116
117 rcu_read_lock();
118 list_for_each_entry_rcu(sta, &local->sta_list, list) {
cbf9322e
AN
119 if (sdata != sta->sdata ||
120 sta->plink_state != NL80211_PLINK_ESTAB)
121 continue;
122
4bf88530
JB
123 switch (sta->ch_width) {
124 case NL80211_CHAN_WIDTH_20_NOHT:
bdcbd8e0
JB
125 mpl_dbg(sdata,
126 "mesh_plink %pM: nonHT sta (%pM) is present\n",
cbf9322e
AN
127 sdata->vif.addr, sta->sta.addr);
128 non_ht_sta = true;
129 goto out;
4bf88530 130 case NL80211_CHAN_WIDTH_20:
bdcbd8e0
JB
131 mpl_dbg(sdata,
132 "mesh_plink %pM: HT20 sta (%pM) is present\n",
cbf9322e
AN
133 sdata->vif.addr, sta->sta.addr);
134 ht20_sta = true;
135 default:
136 break;
57aac7c5
AN
137 }
138 }
139out:
140 rcu_read_unlock();
141
142 if (non_ht_sta)
143 ht_opmode = IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED;
466f310d 144 else if (ht20_sta &&
4bf88530 145 sdata->vif.bss_conf.chandef.width > NL80211_CHAN_WIDTH_20)
57aac7c5
AN
146 ht_opmode = IEEE80211_HT_OP_MODE_PROTECTION_20MHZ;
147 else
148 ht_opmode = IEEE80211_HT_OP_MODE_PROTECTION_NONE;
149
150 if (sdata->vif.bss_conf.ht_operation_mode != ht_opmode) {
151 sdata->vif.bss_conf.ht_operation_mode = ht_opmode;
70c33eaa 152 sdata->u.mesh.mshcfg.ht_opmode = ht_opmode;
57aac7c5 153 changed = BSS_CHANGED_HT;
bdcbd8e0
JB
154 mpl_dbg(sdata,
155 "mesh_plink %pM: protection mode changed to %d\n",
57aac7c5
AN
156 sdata->vif.addr, ht_opmode);
157 }
158
159 return changed;
160}
161
c3896d2c 162/**
c9370197 163 * __mesh_plink_deactivate - deactivate mesh peer link
c3896d2c
LCC
164 *
165 * @sta: mesh peer link to deactivate
166 *
167 * All mesh paths with this peer as next hop will be flushed
df323818 168 * Returns beacon changed flag if the beacon content changed.
c3896d2c 169 *
07346f81 170 * Locking: the caller must hold sta->lock
c3896d2c 171 */
df323818 172static u32 __mesh_plink_deactivate(struct sta_info *sta)
c3896d2c 173{
d0709a65 174 struct ieee80211_sub_if_data *sdata = sta->sdata;
df323818 175 u32 changed = 0;
d0709a65 176
df323818
MP
177 if (sta->plink_state == NL80211_PLINK_ESTAB)
178 changed = mesh_plink_dec_estab_count(sdata);
57cf8043 179 sta->plink_state = NL80211_PLINK_BLOCKED;
c3896d2c 180 mesh_path_flush_by_nexthop(sta);
c9370197 181
df323818 182 return changed;
c3896d2c
LCC
183}
184
902acc78 185/**
c9370197 186 * mesh_plink_deactivate - deactivate mesh peer link
902acc78
JB
187 *
188 * @sta: mesh peer link to deactivate
189 *
190 * All mesh paths with this peer as next hop will be flushed
191 */
192void mesh_plink_deactivate(struct sta_info *sta)
193{
c9370197 194 struct ieee80211_sub_if_data *sdata = sta->sdata;
df323818 195 u32 changed;
c9370197 196
07346f81 197 spin_lock_bh(&sta->lock);
df323818 198 changed = __mesh_plink_deactivate(sta);
ba4a14e1
TP
199 sta->reason = cpu_to_le16(WLAN_REASON_MESH_PEER_CANCELED);
200 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_CLOSE,
201 sta->sta.addr, sta->llid, sta->plid,
202 sta->reason);
07346f81 203 spin_unlock_bh(&sta->lock);
c9370197 204
df323818 205 ieee80211_bss_info_change_notify(sdata, changed);
902acc78
JB
206}
207
f698d856 208static int mesh_plink_frame_tx(struct ieee80211_sub_if_data *sdata,
54ef656b
TP
209 enum ieee80211_self_protected_actioncode action,
210 u8 *da, __le16 llid, __le16 plid, __le16 reason) {
f698d856 211 struct ieee80211_local *local = sdata->local;
3b69a9c5 212 struct sk_buff *skb;
e7570dfb 213 struct ieee80211_tx_info *info;
c3896d2c
LCC
214 struct ieee80211_mgmt *mgmt;
215 bool include_plid = false;
8db09850 216 u16 peering_proto = 0;
3b69a9c5
TP
217 u8 *pos, ie_len = 4;
218 int hdr_len = offsetof(struct ieee80211_mgmt, u.action.u.self_prot) +
219 sizeof(mgmt->u.action.u.self_prot);
f609a43d 220 int err = -ENOMEM;
3b69a9c5 221
65e8b0cc 222 skb = dev_alloc_skb(local->tx_headroom +
3b69a9c5
TP
223 hdr_len +
224 2 + /* capability info */
225 2 + /* AID */
226 2 + 8 + /* supported rates */
227 2 + (IEEE80211_MAX_SUPP_RATES - 8) +
228 2 + sdata->u.mesh.mesh_id_len +
229 2 + sizeof(struct ieee80211_meshconf_ie) +
176f3608 230 2 + sizeof(struct ieee80211_ht_cap) +
074d46d1 231 2 + sizeof(struct ieee80211_ht_operation) +
3b69a9c5
TP
232 2 + 8 + /* peering IE */
233 sdata->u.mesh.ie_len);
c3896d2c
LCC
234 if (!skb)
235 return -1;
e7570dfb 236 info = IEEE80211_SKB_CB(skb);
65e8b0cc 237 skb_reserve(skb, local->tx_headroom);
3b69a9c5
TP
238 mgmt = (struct ieee80211_mgmt *) skb_put(skb, hdr_len);
239 memset(mgmt, 0, hdr_len);
e7827a70
HH
240 mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
241 IEEE80211_STYPE_ACTION);
c3896d2c 242 memcpy(mgmt->da, da, ETH_ALEN);
47846c9b 243 memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
915b5c50 244 memcpy(mgmt->bssid, sdata->vif.addr, ETH_ALEN);
8db09850
TP
245 mgmt->u.action.category = WLAN_CATEGORY_SELF_PROTECTED;
246 mgmt->u.action.u.self_prot.action_code = action;
c3896d2c 247
8db09850 248 if (action != WLAN_SP_MESH_PEERING_CLOSE) {
55de908a
JB
249 enum ieee80211_band band = ieee80211_get_sdata_band(sdata);
250
8db09850
TP
251 /* capability info */
252 pos = skb_put(skb, 2);
253 memset(pos, 0, 2);
54ef656b 254 if (action == WLAN_SP_MESH_PEERING_CONFIRM) {
8db09850
TP
255 /* AID */
256 pos = skb_put(skb, 2);
77fa76bb 257 memcpy(pos + 2, &plid, 2);
c3896d2c 258 }
55de908a
JB
259 if (ieee80211_add_srates_ie(sdata, skb, true, band) ||
260 ieee80211_add_ext_srates_ie(sdata, skb, true, band) ||
082ebb0c
TP
261 mesh_add_rsn_ie(skb, sdata) ||
262 mesh_add_meshid_ie(skb, sdata) ||
263 mesh_add_meshconf_ie(skb, sdata))
f609a43d 264 goto free;
8db09850 265 } else { /* WLAN_SP_MESH_PEERING_CLOSE */
e7570dfb 266 info->flags |= IEEE80211_TX_CTL_NO_ACK;
8db09850 267 if (mesh_add_meshid_ie(skb, sdata))
f609a43d 268 goto free;
c3896d2c
LCC
269 }
270
8db09850 271 /* Add Mesh Peering Management element */
c3896d2c 272 switch (action) {
54ef656b 273 case WLAN_SP_MESH_PEERING_OPEN:
c3896d2c 274 break;
54ef656b 275 case WLAN_SP_MESH_PEERING_CONFIRM:
8db09850 276 ie_len += 2;
c3896d2c
LCC
277 include_plid = true;
278 break;
54ef656b 279 case WLAN_SP_MESH_PEERING_CLOSE:
8db09850
TP
280 if (plid) {
281 ie_len += 2;
c3896d2c
LCC
282 include_plid = true;
283 }
8db09850 284 ie_len += 2; /* reason code */
c3896d2c 285 break;
8db09850 286 default:
f609a43d
TP
287 err = -EINVAL;
288 goto free;
c3896d2c
LCC
289 }
290
8db09850 291 if (WARN_ON(skb_tailroom(skb) < 2 + ie_len))
f609a43d 292 goto free;
8db09850 293
c3896d2c 294 pos = skb_put(skb, 2 + ie_len);
8db09850 295 *pos++ = WLAN_EID_PEER_MGMT;
c3896d2c 296 *pos++ = ie_len;
8db09850
TP
297 memcpy(pos, &peering_proto, 2);
298 pos += 2;
c3896d2c 299 memcpy(pos, &llid, 2);
8db09850 300 pos += 2;
c3896d2c 301 if (include_plid) {
c3896d2c 302 memcpy(pos, &plid, 2);
8db09850 303 pos += 2;
c3896d2c 304 }
54ef656b 305 if (action == WLAN_SP_MESH_PEERING_CLOSE) {
c3896d2c 306 memcpy(pos, &reason, 2);
8db09850 307 pos += 2;
c3896d2c 308 }
176f3608
TP
309
310 if (action != WLAN_SP_MESH_PEERING_CLOSE) {
311 if (mesh_add_ht_cap_ie(skb, sdata) ||
074d46d1 312 mesh_add_ht_oper_ie(skb, sdata))
f609a43d 313 goto free;
176f3608
TP
314 }
315
8db09850 316 if (mesh_add_vendor_ies(skb, sdata))
f609a43d 317 goto free;
c3896d2c 318
62ae67be 319 ieee80211_tx_skb(sdata, skb);
c3896d2c 320 return 0;
f609a43d
TP
321free:
322 kfree_skb(skb);
323 return err;
c3896d2c
LCC
324}
325
2c53040f
BH
326/**
327 * mesh_peer_init - initialize new mesh peer and return resulting sta_info
54ab1ffb
TP
328 *
329 * @sdata: local meshif
330 * @addr: peer's address
54ab1ffb
TP
331 * @elems: IEs from beacon or mesh peering frame
332 *
333 * call under RCU
334 */
335static struct sta_info *mesh_peer_init(struct ieee80211_sub_if_data *sdata,
f743ff49 336 u8 *addr,
54ab1ffb 337 struct ieee802_11_elems *elems)
c3896d2c 338{
f698d856 339 struct ieee80211_local *local = sdata->local;
55de908a 340 enum ieee80211_band band = ieee80211_get_sdata_band(sdata);
54ab1ffb 341 struct ieee80211_supported_band *sband;
f743ff49 342 u32 rates, basic_rates = 0;
c3896d2c 343 struct sta_info *sta;
e87278e7 344 bool insert = false;
c3896d2c 345
f743ff49
TP
346 sband = local->hw.wiphy->bands[band];
347 rates = ieee80211_sta_get_rates(local, elems, band, &basic_rates);
d0709a65 348
54ab1ffb 349 sta = sta_info_get(sdata, addr);
c3896d2c 350 if (!sta) {
f5c56814
TP
351 /* Userspace handles peer allocation when security is enabled */
352 if (sdata->u.mesh.security & IEEE80211_MESH_SEC_AUTHED) {
353 cfg80211_notify_new_peer_candidate(sdata->dev, addr,
354 elems->ie_start,
355 elems->total_len,
356 GFP_ATOMIC);
357 return NULL;
358 }
359
54ab1ffb 360 sta = mesh_plink_alloc(sdata, addr);
34e89507 361 if (!sta)
54ab1ffb 362 return NULL;
e87278e7 363 insert = true;
c3896d2c
LCC
364 }
365
54ab1ffb 366 spin_lock_bh(&sta->lock);
c3896d2c 367 sta->last_rx = jiffies;
bae35d92
CYY
368 if (sta->plink_state == NL80211_PLINK_ESTAB) {
369 spin_unlock_bh(&sta->lock);
370 return sta;
371 }
372
f743ff49 373 sta->sta.supp_rates[band] = rates;
e76781e4 374 if (elems->ht_cap_elem &&
4bf88530 375 sdata->vif.bss_conf.chandef.width != NL80211_CHAN_WIDTH_20_NOHT)
54ab1ffb
TP
376 ieee80211_ht_cap_ie_to_sta_ht_cap(sdata, sband,
377 elems->ht_cap_elem,
378 &sta->sta.ht_cap);
379 else
380 memset(&sta->sta.ht_cap, 0, sizeof(sta->sta.ht_cap));
381
57aac7c5 382 if (elems->ht_operation) {
4bf88530
JB
383 struct cfg80211_chan_def chandef;
384
c7d25828
TP
385 if (!(elems->ht_operation->ht_param &
386 IEEE80211_HT_PARAM_CHAN_WIDTH_ANY))
387 sta->sta.ht_cap.cap &=
388 ~IEEE80211_HT_CAP_SUP_WIDTH_20_40;
4bf88530
JB
389 ieee80211_ht_oper_to_chandef(sdata->vif.bss_conf.chandef.chan,
390 elems->ht_operation, &chandef);
391 sta->ch_width = chandef.width;
57aac7c5 392 }
c7d25828 393
54ab1ffb
TP
394 rate_control_rate_init(sta);
395 spin_unlock_bh(&sta->lock);
396
e87278e7
TP
397 if (insert && sta_info_insert(sta))
398 return NULL;
399
54ab1ffb
TP
400 return sta;
401}
402
f743ff49
TP
403void mesh_neighbour_update(struct ieee80211_sub_if_data *sdata,
404 u8 *hw_addr,
54ab1ffb
TP
405 struct ieee802_11_elems *elems)
406{
407 struct sta_info *sta;
408
54ab1ffb 409 rcu_read_lock();
f743ff49 410 sta = mesh_peer_init(sdata, hw_addr, elems);
54ab1ffb
TP
411 if (!sta)
412 goto out;
413
1570ca59 414 if (mesh_peer_accepts_plinks(elems) &&
54ab1ffb
TP
415 sta->plink_state == NL80211_PLINK_LISTEN &&
416 sdata->u.mesh.accepting_plinks &&
417 sdata->u.mesh.mshcfg.auto_open_plinks &&
418 rssi_threshold_check(sta, sdata))
c3896d2c
LCC
419 mesh_plink_open(sta);
420
54ab1ffb 421out:
d0709a65 422 rcu_read_unlock();
c3896d2c
LCC
423}
424
425static void mesh_plink_timer(unsigned long data)
426{
427 struct sta_info *sta;
428 __le16 llid, plid, reason;
c3896d2c 429 struct ieee80211_sub_if_data *sdata;
453e66f2 430 struct mesh_config *mshcfg;
c3896d2c 431
d0709a65
JB
432 /*
433 * This STA is valid because sta_info_destroy() will
434 * del_timer_sync() this timer after having made sure
435 * it cannot be readded (by deleting the plink.)
436 */
c3896d2c
LCC
437 sta = (struct sta_info *) data;
438
5bb644a0
JB
439 if (sta->sdata->local->quiescing) {
440 sta->plink_timer_was_running = true;
441 return;
442 }
443
07346f81 444 spin_lock_bh(&sta->lock);
c3896d2c
LCC
445 if (sta->ignore_plink_timer) {
446 sta->ignore_plink_timer = false;
07346f81 447 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
448 return;
449 }
bdcbd8e0
JB
450 mpl_dbg(sta->sdata,
451 "Mesh plink timer for %pM fired on state %d\n",
0c68ae26 452 sta->sta.addr, sta->plink_state);
c3896d2c
LCC
453 reason = 0;
454 llid = sta->llid;
455 plid = sta->plid;
d0709a65 456 sdata = sta->sdata;
453e66f2 457 mshcfg = &sdata->u.mesh.mshcfg;
c3896d2c
LCC
458
459 switch (sta->plink_state) {
57cf8043
JC
460 case NL80211_PLINK_OPN_RCVD:
461 case NL80211_PLINK_OPN_SNT:
c3896d2c 462 /* retry timer */
453e66f2 463 if (sta->plink_retries < mshcfg->dot11MeshMaxRetries) {
c3896d2c 464 u32 rand;
bdcbd8e0
JB
465 mpl_dbg(sta->sdata,
466 "Mesh plink for %pM (retry, timeout): %d %d\n",
0c68ae26
JB
467 sta->sta.addr, sta->plink_retries,
468 sta->plink_timeout);
c3896d2c
LCC
469 get_random_bytes(&rand, sizeof(u32));
470 sta->plink_timeout = sta->plink_timeout +
471 rand % sta->plink_timeout;
472 ++sta->plink_retries;
d0709a65 473 mod_plink_timer(sta, sta->plink_timeout);
07346f81 474 spin_unlock_bh(&sta->lock);
54ef656b
TP
475 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_OPEN,
476 sta->sta.addr, llid, 0, 0);
c3896d2c
LCC
477 break;
478 }
54ef656b 479 reason = cpu_to_le16(WLAN_REASON_MESH_MAX_RETRIES);
c3896d2c 480 /* fall through on else */
57cf8043 481 case NL80211_PLINK_CNF_RCVD:
c3896d2c
LCC
482 /* confirm timer */
483 if (!reason)
54ef656b 484 reason = cpu_to_le16(WLAN_REASON_MESH_CONFIRM_TIMEOUT);
57cf8043 485 sta->plink_state = NL80211_PLINK_HOLDING;
453e66f2 486 mod_plink_timer(sta, mshcfg->dot11MeshHoldingTimeout);
07346f81 487 spin_unlock_bh(&sta->lock);
54ef656b
TP
488 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_CLOSE,
489 sta->sta.addr, llid, plid, reason);
c3896d2c 490 break;
57cf8043 491 case NL80211_PLINK_HOLDING:
c3896d2c 492 /* holding timer */
d0709a65 493 del_timer(&sta->plink_timer);
c3896d2c 494 mesh_plink_fsm_restart(sta);
07346f81 495 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
496 break;
497 default:
07346f81 498 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
499 break;
500 }
c3896d2c
LCC
501}
502
5bb644a0
JB
503#ifdef CONFIG_PM
504void mesh_plink_quiesce(struct sta_info *sta)
505{
506 if (del_timer_sync(&sta->plink_timer))
507 sta->plink_timer_was_running = true;
508}
509
510void mesh_plink_restart(struct sta_info *sta)
511{
512 if (sta->plink_timer_was_running) {
513 add_timer(&sta->plink_timer);
514 sta->plink_timer_was_running = false;
515 }
516}
517#endif
518
c3896d2c
LCC
519static inline void mesh_plink_timer_set(struct sta_info *sta, int timeout)
520{
521 sta->plink_timer.expires = jiffies + (HZ * timeout / 1000);
522 sta->plink_timer.data = (unsigned long) sta;
523 sta->plink_timer.function = mesh_plink_timer;
524 sta->plink_timeout = timeout;
c3896d2c
LCC
525 add_timer(&sta->plink_timer);
526}
527
528int mesh_plink_open(struct sta_info *sta)
529{
530 __le16 llid;
d0709a65 531 struct ieee80211_sub_if_data *sdata = sta->sdata;
c3896d2c 532
c2c98fde 533 if (!test_sta_flag(sta, WLAN_STA_AUTH))
53e80511
JC
534 return -EPERM;
535
07346f81 536 spin_lock_bh(&sta->lock);
c3896d2c
LCC
537 get_random_bytes(&llid, 2);
538 sta->llid = llid;
9385d04f
CYY
539 if (sta->plink_state != NL80211_PLINK_LISTEN &&
540 sta->plink_state != NL80211_PLINK_BLOCKED) {
07346f81 541 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
542 return -EBUSY;
543 }
57cf8043 544 sta->plink_state = NL80211_PLINK_OPN_SNT;
453e66f2 545 mesh_plink_timer_set(sta, sdata->u.mesh.mshcfg.dot11MeshRetryTimeout);
07346f81 546 spin_unlock_bh(&sta->lock);
bdcbd8e0
JB
547 mpl_dbg(sdata,
548 "Mesh plink: starting establishment with %pM\n",
0c68ae26 549 sta->sta.addr);
c3896d2c 550
54ef656b 551 return mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_OPEN,
17741cdc 552 sta->sta.addr, llid, 0, 0);
c3896d2c
LCC
553}
554
555void mesh_plink_block(struct sta_info *sta)
556{
c9370197 557 struct ieee80211_sub_if_data *sdata = sta->sdata;
df323818 558 u32 changed;
c9370197 559
07346f81 560 spin_lock_bh(&sta->lock);
df323818 561 changed = __mesh_plink_deactivate(sta);
57cf8043 562 sta->plink_state = NL80211_PLINK_BLOCKED;
07346f81 563 spin_unlock_bh(&sta->lock);
c9370197 564
df323818 565 ieee80211_bss_info_change_notify(sdata, changed);
c3896d2c
LCC
566}
567
c3896d2c 568
f698d856 569void mesh_rx_plink_frame(struct ieee80211_sub_if_data *sdata, struct ieee80211_mgmt *mgmt,
c3896d2c
LCC
570 size_t len, struct ieee80211_rx_status *rx_status)
571{
453e66f2 572 struct mesh_config *mshcfg = &sdata->u.mesh.mshcfg;
c3896d2c
LCC
573 struct ieee802_11_elems elems;
574 struct sta_info *sta;
575 enum plink_event event;
54ef656b 576 enum ieee80211_self_protected_actioncode ftype;
c3896d2c 577 size_t baselen;
57aac7c5 578 bool matches_local = true;
c3896d2c
LCC
579 u8 ie_len;
580 u8 *baseaddr;
57aac7c5 581 u32 changed = 0;
c3896d2c 582 __le16 plid, llid, reason;
1460dd15 583 static const char *mplstates[] = {
57cf8043
JC
584 [NL80211_PLINK_LISTEN] = "LISTEN",
585 [NL80211_PLINK_OPN_SNT] = "OPN-SNT",
586 [NL80211_PLINK_OPN_RCVD] = "OPN-RCVD",
587 [NL80211_PLINK_CNF_RCVD] = "CNF_RCVD",
588 [NL80211_PLINK_ESTAB] = "ESTAB",
589 [NL80211_PLINK_HOLDING] = "HOLDING",
590 [NL80211_PLINK_BLOCKED] = "BLOCKED"
1460dd15 591 };
c3896d2c 592
9c80d3dc
JB
593 /* need action_code, aux */
594 if (len < IEEE80211_MIN_ACTION_SIZE + 3)
595 return;
596
c3896d2c 597 if (is_multicast_ether_addr(mgmt->da)) {
bdcbd8e0
JB
598 mpl_dbg(sdata,
599 "Mesh plink: ignore frame from multicast address\n");
c3896d2c
LCC
600 return;
601 }
602
8db09850
TP
603 baseaddr = mgmt->u.action.u.self_prot.variable;
604 baselen = (u8 *) mgmt->u.action.u.self_prot.variable - (u8 *) mgmt;
605 if (mgmt->u.action.u.self_prot.action_code ==
54ef656b 606 WLAN_SP_MESH_PEERING_CONFIRM) {
c3896d2c 607 baseaddr += 4;
70bdb6b2 608 baselen += 4;
c3896d2c
LCC
609 }
610 ieee802_11_parse_elems(baseaddr, len - baselen, &elems);
8db09850 611 if (!elems.peering) {
bdcbd8e0
JB
612 mpl_dbg(sdata,
613 "Mesh plink: missing necessary peer link ie\n");
c3896d2c
LCC
614 return;
615 }
b130e5ce
JC
616 if (elems.rsn_len &&
617 sdata->u.mesh.security == IEEE80211_MESH_SEC_NONE) {
bdcbd8e0
JB
618 mpl_dbg(sdata,
619 "Mesh plink: can't establish link with secure peer\n");
5cff5e01
JC
620 return;
621 }
c3896d2c 622
8db09850
TP
623 ftype = mgmt->u.action.u.self_prot.action_code;
624 ie_len = elems.peering_len;
625 if ((ftype == WLAN_SP_MESH_PEERING_OPEN && ie_len != 4) ||
626 (ftype == WLAN_SP_MESH_PEERING_CONFIRM && ie_len != 6) ||
627 (ftype == WLAN_SP_MESH_PEERING_CLOSE && ie_len != 6
628 && ie_len != 8)) {
bdcbd8e0
JB
629 mpl_dbg(sdata,
630 "Mesh plink: incorrect plink ie length %d %d\n",
631 ftype, ie_len);
c3896d2c
LCC
632 return;
633 }
634
54ef656b
TP
635 if (ftype != WLAN_SP_MESH_PEERING_CLOSE &&
636 (!elems.mesh_id || !elems.mesh_config)) {
bdcbd8e0 637 mpl_dbg(sdata, "Mesh plink: missing necessary ie\n");
c3896d2c
LCC
638 return;
639 }
640 /* Note the lines below are correct, the llid in the frame is the plid
641 * from the point of view of this host.
642 */
8db09850 643 memcpy(&plid, PLINK_GET_LLID(elems.peering), 2);
54ef656b 644 if (ftype == WLAN_SP_MESH_PEERING_CONFIRM ||
8db09850
TP
645 (ftype == WLAN_SP_MESH_PEERING_CLOSE && ie_len == 8))
646 memcpy(&llid, PLINK_GET_PLID(elems.peering), 2);
c3896d2c 647
d0709a65
JB
648 rcu_read_lock();
649
abe60632 650 sta = sta_info_get(sdata, mgmt->sa);
54ef656b 651 if (!sta && ftype != WLAN_SP_MESH_PEERING_OPEN) {
bdcbd8e0 652 mpl_dbg(sdata, "Mesh plink: cls or cnf from unknown peer\n");
d0709a65 653 rcu_read_unlock();
c3896d2c
LCC
654 return;
655 }
656
55335137 657 if (ftype == WLAN_SP_MESH_PEERING_OPEN &&
3d4f9699 658 !rssi_threshold_check(sta, sdata)) {
bdcbd8e0 659 mpl_dbg(sdata, "Mesh plink: %pM does not meet rssi threshold\n",
3d4f9699 660 mgmt->sa);
55335137
AN
661 rcu_read_unlock();
662 return;
663 }
664
c2c98fde 665 if (sta && !test_sta_flag(sta, WLAN_STA_AUTH)) {
bdcbd8e0 666 mpl_dbg(sdata, "Mesh plink: Action frame from non-authed peer\n");
53e80511
JC
667 rcu_read_unlock();
668 return;
669 }
670
57cf8043 671 if (sta && sta->plink_state == NL80211_PLINK_BLOCKED) {
d0709a65 672 rcu_read_unlock();
c3896d2c
LCC
673 return;
674 }
675
676 /* Now we will figure out the appropriate event... */
677 event = PLINK_UNDEFINED;
54ef656b 678 if (ftype != WLAN_SP_MESH_PEERING_CLOSE &&
f743ff49 679 !mesh_matches_local(sdata, &elems)) {
d12c7452 680 matches_local = false;
c3896d2c 681 switch (ftype) {
54ef656b 682 case WLAN_SP_MESH_PEERING_OPEN:
c3896d2c
LCC
683 event = OPN_RJCT;
684 break;
54ef656b 685 case WLAN_SP_MESH_PEERING_CONFIRM:
c3896d2c
LCC
686 event = CNF_RJCT;
687 break;
54ef656b 688 default:
c3896d2c
LCC
689 break;
690 }
d12c7452
CL
691 }
692
693 if (!sta && !matches_local) {
694 rcu_read_unlock();
54ef656b 695 reason = cpu_to_le16(WLAN_REASON_MESH_CONFIG);
d12c7452 696 llid = 0;
54ef656b
TP
697 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_CLOSE,
698 mgmt->sa, llid, plid, reason);
d12c7452 699 return;
c3896d2c 700 } else if (!sta) {
54ef656b 701 /* ftype == WLAN_SP_MESH_PEERING_OPEN */
c3896d2c 702 if (!mesh_plink_free_count(sdata)) {
bdcbd8e0 703 mpl_dbg(sdata, "Mesh plink error: no more free plinks\n");
73651ee6
JB
704 rcu_read_unlock();
705 return;
706 }
c3896d2c 707 event = OPN_ACPT;
d12c7452 708 } else if (matches_local) {
c3896d2c 709 switch (ftype) {
54ef656b 710 case WLAN_SP_MESH_PEERING_OPEN:
c3896d2c 711 if (!mesh_plink_free_count(sdata) ||
d0709a65 712 (sta->plid && sta->plid != plid))
c3896d2c
LCC
713 event = OPN_IGNR;
714 else
715 event = OPN_ACPT;
716 break;
54ef656b 717 case WLAN_SP_MESH_PEERING_CONFIRM:
c3896d2c 718 if (!mesh_plink_free_count(sdata) ||
d0709a65 719 (sta->llid != llid || sta->plid != plid))
c3896d2c
LCC
720 event = CNF_IGNR;
721 else
722 event = CNF_ACPT;
723 break;
54ef656b 724 case WLAN_SP_MESH_PEERING_CLOSE:
57cf8043 725 if (sta->plink_state == NL80211_PLINK_ESTAB)
c3896d2c
LCC
726 /* Do not check for llid or plid. This does not
727 * follow the standard but since multiple plinks
728 * per sta are not supported, it is necessary in
729 * order to avoid a livelock when MP A sees an
730 * establish peer link to MP B but MP B does not
731 * see it. This can be caused by a timeout in
732 * B's peer link establishment or B beign
733 * restarted.
734 */
735 event = CLS_ACPT;
736 else if (sta->plid != plid)
737 event = CLS_IGNR;
738 else if (ie_len == 7 && sta->llid != llid)
739 event = CLS_IGNR;
740 else
741 event = CLS_ACPT;
742 break;
743 default:
bdcbd8e0 744 mpl_dbg(sdata, "Mesh plink: unknown frame subtype\n");
d0709a65 745 rcu_read_unlock();
c3896d2c
LCC
746 return;
747 }
54ab1ffb
TP
748 }
749
750 if (event == OPN_ACPT) {
751 /* allocate sta entry if necessary and update info */
f743ff49 752 sta = mesh_peer_init(sdata, mgmt->sa, &elems);
54ab1ffb 753 if (!sta) {
bdcbd8e0 754 mpl_dbg(sdata, "Mesh plink: failed to init peer!\n");
54ab1ffb
TP
755 rcu_read_unlock();
756 return;
757 }
c3896d2c
LCC
758 }
759
bdcbd8e0
JB
760 mpl_dbg(sdata,
761 "Mesh plink (peer, state, llid, plid, event): %pM %s %d %d %d\n",
1460dd15 762 mgmt->sa, mplstates[sta->plink_state],
0c68ae26
JB
763 le16_to_cpu(sta->llid), le16_to_cpu(sta->plid),
764 event);
c3896d2c 765 reason = 0;
54ab1ffb 766 spin_lock_bh(&sta->lock);
c3896d2c
LCC
767 switch (sta->plink_state) {
768 /* spin_unlock as soon as state is updated at each case */
57cf8043 769 case NL80211_PLINK_LISTEN:
c3896d2c
LCC
770 switch (event) {
771 case CLS_ACPT:
772 mesh_plink_fsm_restart(sta);
07346f81 773 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
774 break;
775 case OPN_ACPT:
57cf8043 776 sta->plink_state = NL80211_PLINK_OPN_RCVD;
c3896d2c
LCC
777 sta->plid = plid;
778 get_random_bytes(&llid, 2);
779 sta->llid = llid;
453e66f2
MP
780 mesh_plink_timer_set(sta,
781 mshcfg->dot11MeshRetryTimeout);
07346f81 782 spin_unlock_bh(&sta->lock);
54ef656b
TP
783 mesh_plink_frame_tx(sdata,
784 WLAN_SP_MESH_PEERING_OPEN,
785 sta->sta.addr, llid, 0, 0);
786 mesh_plink_frame_tx(sdata,
787 WLAN_SP_MESH_PEERING_CONFIRM,
788 sta->sta.addr, llid, plid, 0);
c3896d2c
LCC
789 break;
790 default:
07346f81 791 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
792 break;
793 }
794 break;
795
57cf8043 796 case NL80211_PLINK_OPN_SNT:
c3896d2c
LCC
797 switch (event) {
798 case OPN_RJCT:
799 case CNF_RJCT:
54ef656b 800 reason = cpu_to_le16(WLAN_REASON_MESH_CONFIG);
c3896d2c
LCC
801 case CLS_ACPT:
802 if (!reason)
54ef656b 803 reason = cpu_to_le16(WLAN_REASON_MESH_CLOSE);
c3896d2c 804 sta->reason = reason;
57cf8043 805 sta->plink_state = NL80211_PLINK_HOLDING;
c3896d2c 806 if (!mod_plink_timer(sta,
453e66f2 807 mshcfg->dot11MeshHoldingTimeout))
c3896d2c
LCC
808 sta->ignore_plink_timer = true;
809
810 llid = sta->llid;
07346f81 811 spin_unlock_bh(&sta->lock);
54ef656b
TP
812 mesh_plink_frame_tx(sdata,
813 WLAN_SP_MESH_PEERING_CLOSE,
814 sta->sta.addr, llid, plid, reason);
c3896d2c
LCC
815 break;
816 case OPN_ACPT:
817 /* retry timer is left untouched */
57cf8043 818 sta->plink_state = NL80211_PLINK_OPN_RCVD;
c3896d2c
LCC
819 sta->plid = plid;
820 llid = sta->llid;
07346f81 821 spin_unlock_bh(&sta->lock);
54ef656b
TP
822 mesh_plink_frame_tx(sdata,
823 WLAN_SP_MESH_PEERING_CONFIRM,
824 sta->sta.addr, llid, plid, 0);
c3896d2c
LCC
825 break;
826 case CNF_ACPT:
57cf8043 827 sta->plink_state = NL80211_PLINK_CNF_RCVD;
c3896d2c 828 if (!mod_plink_timer(sta,
453e66f2 829 mshcfg->dot11MeshConfirmTimeout))
c3896d2c
LCC
830 sta->ignore_plink_timer = true;
831
07346f81 832 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
833 break;
834 default:
07346f81 835 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
836 break;
837 }
838 break;
839
57cf8043 840 case NL80211_PLINK_OPN_RCVD:
c3896d2c
LCC
841 switch (event) {
842 case OPN_RJCT:
843 case CNF_RJCT:
54ef656b 844 reason = cpu_to_le16(WLAN_REASON_MESH_CONFIG);
c3896d2c
LCC
845 case CLS_ACPT:
846 if (!reason)
54ef656b 847 reason = cpu_to_le16(WLAN_REASON_MESH_CLOSE);
c3896d2c 848 sta->reason = reason;
57cf8043 849 sta->plink_state = NL80211_PLINK_HOLDING;
c3896d2c 850 if (!mod_plink_timer(sta,
453e66f2 851 mshcfg->dot11MeshHoldingTimeout))
c3896d2c
LCC
852 sta->ignore_plink_timer = true;
853
854 llid = sta->llid;
07346f81 855 spin_unlock_bh(&sta->lock);
54ef656b
TP
856 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_CLOSE,
857 sta->sta.addr, llid, plid, reason);
c3896d2c
LCC
858 break;
859 case OPN_ACPT:
860 llid = sta->llid;
07346f81 861 spin_unlock_bh(&sta->lock);
54ef656b
TP
862 mesh_plink_frame_tx(sdata,
863 WLAN_SP_MESH_PEERING_CONFIRM,
864 sta->sta.addr, llid, plid, 0);
c3896d2c
LCC
865 break;
866 case CNF_ACPT:
d0709a65 867 del_timer(&sta->plink_timer);
57cf8043 868 sta->plink_state = NL80211_PLINK_ESTAB;
07346f81 869 spin_unlock_bh(&sta->lock);
df323818 870 changed |= mesh_plink_inc_estab_count(sdata);
57aac7c5 871 changed |= mesh_set_ht_prot_mode(sdata);
bdcbd8e0 872 mpl_dbg(sdata, "Mesh plink with %pM ESTABLISHED\n",
0c68ae26 873 sta->sta.addr);
c3896d2c
LCC
874 break;
875 default:
07346f81 876 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
877 break;
878 }
879 break;
880
57cf8043 881 case NL80211_PLINK_CNF_RCVD:
c3896d2c
LCC
882 switch (event) {
883 case OPN_RJCT:
884 case CNF_RJCT:
54ef656b 885 reason = cpu_to_le16(WLAN_REASON_MESH_CONFIG);
c3896d2c
LCC
886 case CLS_ACPT:
887 if (!reason)
54ef656b 888 reason = cpu_to_le16(WLAN_REASON_MESH_CLOSE);
c3896d2c 889 sta->reason = reason;
57cf8043 890 sta->plink_state = NL80211_PLINK_HOLDING;
c3896d2c 891 if (!mod_plink_timer(sta,
453e66f2 892 mshcfg->dot11MeshHoldingTimeout))
c3896d2c
LCC
893 sta->ignore_plink_timer = true;
894
895 llid = sta->llid;
07346f81 896 spin_unlock_bh(&sta->lock);
54ef656b
TP
897 mesh_plink_frame_tx(sdata,
898 WLAN_SP_MESH_PEERING_CLOSE,
899 sta->sta.addr, llid, plid, reason);
ff59dc76 900 break;
c3896d2c 901 case OPN_ACPT:
d0709a65 902 del_timer(&sta->plink_timer);
57cf8043 903 sta->plink_state = NL80211_PLINK_ESTAB;
07346f81 904 spin_unlock_bh(&sta->lock);
df323818 905 changed |= mesh_plink_inc_estab_count(sdata);
57aac7c5 906 changed |= mesh_set_ht_prot_mode(sdata);
bdcbd8e0 907 mpl_dbg(sdata, "Mesh plink with %pM ESTABLISHED\n",
0c68ae26 908 sta->sta.addr);
54ef656b
TP
909 mesh_plink_frame_tx(sdata,
910 WLAN_SP_MESH_PEERING_CONFIRM,
911 sta->sta.addr, llid, plid, 0);
c3896d2c
LCC
912 break;
913 default:
07346f81 914 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
915 break;
916 }
917 break;
918
57cf8043 919 case NL80211_PLINK_ESTAB:
c3896d2c
LCC
920 switch (event) {
921 case CLS_ACPT:
54ef656b 922 reason = cpu_to_le16(WLAN_REASON_MESH_CLOSE);
c3896d2c 923 sta->reason = reason;
df323818 924 changed |= __mesh_plink_deactivate(sta);
57cf8043 925 sta->plink_state = NL80211_PLINK_HOLDING;
c3896d2c 926 llid = sta->llid;
453e66f2 927 mod_plink_timer(sta, mshcfg->dot11MeshHoldingTimeout);
07346f81 928 spin_unlock_bh(&sta->lock);
57aac7c5 929 changed |= mesh_set_ht_prot_mode(sdata);
54ef656b
TP
930 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_CLOSE,
931 sta->sta.addr, llid, plid, reason);
c3896d2c
LCC
932 break;
933 case OPN_ACPT:
934 llid = sta->llid;
07346f81 935 spin_unlock_bh(&sta->lock);
54ef656b
TP
936 mesh_plink_frame_tx(sdata,
937 WLAN_SP_MESH_PEERING_CONFIRM,
938 sta->sta.addr, llid, plid, 0);
c3896d2c
LCC
939 break;
940 default:
07346f81 941 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
942 break;
943 }
944 break;
57cf8043 945 case NL80211_PLINK_HOLDING:
c3896d2c
LCC
946 switch (event) {
947 case CLS_ACPT:
d0709a65 948 if (del_timer(&sta->plink_timer))
c3896d2c 949 sta->ignore_plink_timer = 1;
c3896d2c 950 mesh_plink_fsm_restart(sta);
07346f81 951 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
952 break;
953 case OPN_ACPT:
954 case CNF_ACPT:
955 case OPN_RJCT:
956 case CNF_RJCT:
957 llid = sta->llid;
958 reason = sta->reason;
07346f81 959 spin_unlock_bh(&sta->lock);
54ef656b
TP
960 mesh_plink_frame_tx(sdata, WLAN_SP_MESH_PEERING_CLOSE,
961 sta->sta.addr, llid, plid, reason);
c3896d2c
LCC
962 break;
963 default:
07346f81 964 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
965 }
966 break;
967 default:
b4e08ea1 968 /* should not get here, PLINK_BLOCKED is dealt with at the
3ad2f3fb 969 * beginning of the function
c3896d2c 970 */
07346f81 971 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
972 break;
973 }
d0709a65
JB
974
975 rcu_read_unlock();
57aac7c5
AN
976
977 if (changed)
978 ieee80211_bss_info_change_notify(sdata, changed);
c3896d2c 979}