mac80211: Let user space receive and send mesh auth/deauth frames
[linux-2.6-block.git] / net / mac80211 / mesh_plink.c
CommitLineData
c3896d2c 1/*
264d9b7d 2 * Copyright (c) 2008, 2009 open80211s Ltd.
c3896d2c
LCC
3 * Author: Luis Carlos Cobo <luisca@cozybit.com>
4 *
5 * This program is free software; you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License version 2 as
7 * published by the Free Software Foundation.
8 */
5a0e3ad6 9#include <linux/gfp.h>
902acc78
JB
10#include <linux/kernel.h>
11#include <linux/random.h>
c3896d2c 12#include "ieee80211_i.h"
2c8dccc7 13#include "rate.h"
c3896d2c 14#include "mesh.h"
c3896d2c
LCC
15
16#ifdef CONFIG_MAC80211_VERBOSE_MPL_DEBUG
17#define mpl_dbg(fmt, args...) printk(KERN_DEBUG fmt, ##args)
18#else
19#define mpl_dbg(fmt, args...) do { (void)(0); } while (0)
20#endif
21
0938393f
RP
22#define PLINK_GET_LLID(p) (p + 4)
23#define PLINK_GET_PLID(p) (p + 6)
c3896d2c
LCC
24
25#define mod_plink_timer(s, t) (mod_timer(&s->plink_timer, \
26 jiffies + HZ * t / 1000))
27
28/* Peer link cancel reasons, all subject to ANA approval */
29#define MESH_LINK_CANCELLED 2
30#define MESH_MAX_NEIGHBORS 3
31#define MESH_CAPABILITY_POLICY_VIOLATION 4
32#define MESH_CLOSE_RCVD 5
33#define MESH_MAX_RETRIES 6
34#define MESH_CONFIRM_TIMEOUT 7
35#define MESH_SECURITY_ROLE_NEGOTIATION_DIFFERS 8
36#define MESH_SECURITY_AUTHENTICATION_IMPOSSIBLE 9
37#define MESH_SECURITY_FAILED_VERIFICATION 10
38
472dbc45
JB
39#define dot11MeshMaxRetries(s) (s->u.mesh.mshcfg.dot11MeshMaxRetries)
40#define dot11MeshRetryTimeout(s) (s->u.mesh.mshcfg.dot11MeshRetryTimeout)
41#define dot11MeshConfirmTimeout(s) (s->u.mesh.mshcfg.dot11MeshConfirmTimeout)
42#define dot11MeshHoldingTimeout(s) (s->u.mesh.mshcfg.dot11MeshHoldingTimeout)
43#define dot11MeshMaxPeerLinks(s) (s->u.mesh.mshcfg.dot11MeshMaxPeerLinks)
c3896d2c
LCC
44
45enum plink_frame_type {
46 PLINK_OPEN = 0,
47 PLINK_CONFIRM,
48 PLINK_CLOSE
49};
50
51enum plink_event {
52 PLINK_UNDEFINED,
53 OPN_ACPT,
54 OPN_RJCT,
55 OPN_IGNR,
56 CNF_ACPT,
57 CNF_RJCT,
58 CNF_IGNR,
59 CLS_ACPT,
60 CLS_IGNR
61};
62
63static inline
64void mesh_plink_inc_estab_count(struct ieee80211_sub_if_data *sdata)
65{
472dbc45 66 atomic_inc(&sdata->u.mesh.mshstats.estab_plinks);
d0709a65 67 mesh_accept_plinks_update(sdata);
c3896d2c
LCC
68}
69
70static inline
71void mesh_plink_dec_estab_count(struct ieee80211_sub_if_data *sdata)
72{
472dbc45 73 atomic_dec(&sdata->u.mesh.mshstats.estab_plinks);
d0709a65 74 mesh_accept_plinks_update(sdata);
c3896d2c
LCC
75}
76
77/**
78 * mesh_plink_fsm_restart - restart a mesh peer link finite state machine
79 *
23c7a29c 80 * @sta: mesh peer link to restart
c3896d2c 81 *
07346f81 82 * Locking: this function must be called holding sta->lock
c3896d2c
LCC
83 */
84static inline void mesh_plink_fsm_restart(struct sta_info *sta)
85{
b4e08ea1 86 sta->plink_state = PLINK_LISTEN;
37659ff8
LCC
87 sta->llid = sta->plid = sta->reason = 0;
88 sta->plink_retries = 0;
c3896d2c
LCC
89}
90
93e5deb1
JB
91/*
92 * NOTE: This is just an alias for sta_info_alloc(), see notes
93 * on it in the lifecycle management section!
94 */
03e4497e 95static struct sta_info *mesh_plink_alloc(struct ieee80211_sub_if_data *sdata,
881d948c 96 u8 *hw_addr, u32 rates)
c3896d2c 97{
d0709a65 98 struct ieee80211_local *local = sdata->local;
c3896d2c
LCC
99 struct sta_info *sta;
100
c3896d2c 101 if (local->num_sta >= MESH_MAX_PLINKS)
73651ee6 102 return NULL;
c3896d2c 103
34e89507 104 sta = sta_info_alloc(sdata, hw_addr, GFP_KERNEL);
73651ee6
JB
105 if (!sta)
106 return NULL;
c3896d2c 107
07346f81 108 sta->flags = WLAN_STA_AUTHORIZED;
323ce79a 109 sta->sta.supp_rates[local->hw.conf.channel->band] = rates;
b973c31a 110 rate_control_rate_init(sta);
c3896d2c
LCC
111
112 return sta;
113}
114
115/**
c9370197 116 * __mesh_plink_deactivate - deactivate mesh peer link
c3896d2c
LCC
117 *
118 * @sta: mesh peer link to deactivate
119 *
120 * All mesh paths with this peer as next hop will be flushed
121 *
07346f81 122 * Locking: the caller must hold sta->lock
c3896d2c 123 */
c9370197 124static bool __mesh_plink_deactivate(struct sta_info *sta)
c3896d2c 125{
d0709a65 126 struct ieee80211_sub_if_data *sdata = sta->sdata;
c9370197 127 bool deactivated = false;
d0709a65 128
c9370197 129 if (sta->plink_state == PLINK_ESTAB) {
c3896d2c 130 mesh_plink_dec_estab_count(sdata);
c9370197
JL
131 deactivated = true;
132 }
b4e08ea1 133 sta->plink_state = PLINK_BLOCKED;
c3896d2c 134 mesh_path_flush_by_nexthop(sta);
c9370197
JL
135
136 return deactivated;
c3896d2c
LCC
137}
138
902acc78 139/**
c9370197 140 * mesh_plink_deactivate - deactivate mesh peer link
902acc78
JB
141 *
142 * @sta: mesh peer link to deactivate
143 *
144 * All mesh paths with this peer as next hop will be flushed
145 */
146void mesh_plink_deactivate(struct sta_info *sta)
147{
c9370197
JL
148 struct ieee80211_sub_if_data *sdata = sta->sdata;
149 bool deactivated;
150
07346f81 151 spin_lock_bh(&sta->lock);
c9370197 152 deactivated = __mesh_plink_deactivate(sta);
07346f81 153 spin_unlock_bh(&sta->lock);
c9370197
JL
154
155 if (deactivated)
156 ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_BEACON);
902acc78
JB
157}
158
f698d856 159static int mesh_plink_frame_tx(struct ieee80211_sub_if_data *sdata,
c3896d2c
LCC
160 enum plink_frame_type action, u8 *da, __le16 llid, __le16 plid,
161 __le16 reason) {
f698d856 162 struct ieee80211_local *local = sdata->local;
c80d545d 163 struct sk_buff *skb = dev_alloc_skb(local->hw.extra_tx_headroom + 400 +
581a8b0f 164 sdata->u.mesh.ie_len);
c3896d2c
LCC
165 struct ieee80211_mgmt *mgmt;
166 bool include_plid = false;
0938393f 167 static const u8 meshpeeringproto[] = { 0x00, 0x0F, 0xAC, 0x2A };
c3896d2c
LCC
168 u8 *pos;
169 int ie_len;
170
171 if (!skb)
172 return -1;
173 skb_reserve(skb, local->hw.extra_tx_headroom);
174 /* 25 is the size of the common mgmt part (24) plus the size of the
175 * common action part (1)
176 */
177 mgmt = (struct ieee80211_mgmt *)
178 skb_put(skb, 25 + sizeof(mgmt->u.action.u.plink_action));
179 memset(mgmt, 0, 25 + sizeof(mgmt->u.action.u.plink_action));
e7827a70
HH
180 mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
181 IEEE80211_STYPE_ACTION);
c3896d2c 182 memcpy(mgmt->da, da, ETH_ALEN);
47846c9b 183 memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
c3896d2c 184 /* BSSID is left zeroed, wildcard value */
97ad9139 185 mgmt->u.action.category = WLAN_CATEGORY_MESH_PLINK;
c3896d2c
LCC
186 mgmt->u.action.u.plink_action.action_code = action;
187
188 if (action == PLINK_CLOSE)
189 mgmt->u.action.u.plink_action.aux = reason;
190 else {
191 mgmt->u.action.u.plink_action.aux = cpu_to_le16(0x0);
192 if (action == PLINK_CONFIRM) {
193 pos = skb_put(skb, 4);
194 /* two-byte status code followed by two-byte AID */
77fa76bb
RP
195 memset(pos, 0, 2);
196 memcpy(pos + 2, &plid, 2);
c3896d2c 197 }
f698d856 198 mesh_mgmt_ies_add(skb, sdata);
c3896d2c
LCC
199 }
200
201 /* Add Peer Link Management element */
202 switch (action) {
203 case PLINK_OPEN:
0938393f 204 ie_len = 6;
c3896d2c
LCC
205 break;
206 case PLINK_CONFIRM:
0938393f 207 ie_len = 8;
c3896d2c
LCC
208 include_plid = true;
209 break;
210 case PLINK_CLOSE:
211 default:
212 if (!plid)
0938393f 213 ie_len = 8;
c3896d2c 214 else {
0938393f 215 ie_len = 10;
c3896d2c
LCC
216 include_plid = true;
217 }
218 break;
219 }
220
221 pos = skb_put(skb, 2 + ie_len);
222 *pos++ = WLAN_EID_PEER_LINK;
223 *pos++ = ie_len;
0938393f
RP
224 memcpy(pos, meshpeeringproto, sizeof(meshpeeringproto));
225 pos += 4;
c3896d2c
LCC
226 memcpy(pos, &llid, 2);
227 if (include_plid) {
228 pos += 2;
229 memcpy(pos, &plid, 2);
230 }
231 if (action == PLINK_CLOSE) {
232 pos += 2;
233 memcpy(pos, &reason, 2);
234 }
235
62ae67be 236 ieee80211_tx_skb(sdata, skb);
c3896d2c
LCC
237 return 0;
238}
239
881d948c 240void mesh_neighbour_update(u8 *hw_addr, u32 rates, struct ieee80211_sub_if_data *sdata,
c3896d2c
LCC
241 bool peer_accepting_plinks)
242{
f698d856 243 struct ieee80211_local *local = sdata->local;
c3896d2c
LCC
244 struct sta_info *sta;
245
d0709a65
JB
246 rcu_read_lock();
247
abe60632 248 sta = sta_info_get(sdata, hw_addr);
c3896d2c 249 if (!sta) {
34e89507
JB
250 rcu_read_unlock();
251
03e4497e 252 sta = mesh_plink_alloc(sdata, hw_addr, rates);
34e89507 253 if (!sta)
73651ee6 254 return;
34e89507 255 if (sta_info_insert_rcu(sta)) {
d0709a65 256 rcu_read_unlock();
c3896d2c 257 return;
d0709a65 258 }
c3896d2c
LCC
259 }
260
261 sta->last_rx = jiffies;
323ce79a 262 sta->sta.supp_rates[local->hw.conf.channel->band] = rates;
b4e08ea1 263 if (peer_accepting_plinks && sta->plink_state == PLINK_LISTEN &&
472dbc45
JB
264 sdata->u.mesh.accepting_plinks &&
265 sdata->u.mesh.mshcfg.auto_open_plinks)
c3896d2c
LCC
266 mesh_plink_open(sta);
267
d0709a65 268 rcu_read_unlock();
c3896d2c
LCC
269}
270
271static void mesh_plink_timer(unsigned long data)
272{
273 struct sta_info *sta;
274 __le16 llid, plid, reason;
c3896d2c 275 struct ieee80211_sub_if_data *sdata;
c3896d2c 276
d0709a65
JB
277 /*
278 * This STA is valid because sta_info_destroy() will
279 * del_timer_sync() this timer after having made sure
280 * it cannot be readded (by deleting the plink.)
281 */
c3896d2c
LCC
282 sta = (struct sta_info *) data;
283
5bb644a0
JB
284 if (sta->sdata->local->quiescing) {
285 sta->plink_timer_was_running = true;
286 return;
287 }
288
07346f81 289 spin_lock_bh(&sta->lock);
c3896d2c
LCC
290 if (sta->ignore_plink_timer) {
291 sta->ignore_plink_timer = false;
07346f81 292 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
293 return;
294 }
0c68ae26
JB
295 mpl_dbg("Mesh plink timer for %pM fired on state %d\n",
296 sta->sta.addr, sta->plink_state);
c3896d2c
LCC
297 reason = 0;
298 llid = sta->llid;
299 plid = sta->plid;
d0709a65 300 sdata = sta->sdata;
c3896d2c
LCC
301
302 switch (sta->plink_state) {
b4e08ea1
LCC
303 case PLINK_OPN_RCVD:
304 case PLINK_OPN_SNT:
c3896d2c
LCC
305 /* retry timer */
306 if (sta->plink_retries < dot11MeshMaxRetries(sdata)) {
307 u32 rand;
0c68ae26
JB
308 mpl_dbg("Mesh plink for %pM (retry, timeout): %d %d\n",
309 sta->sta.addr, sta->plink_retries,
310 sta->plink_timeout);
c3896d2c
LCC
311 get_random_bytes(&rand, sizeof(u32));
312 sta->plink_timeout = sta->plink_timeout +
313 rand % sta->plink_timeout;
314 ++sta->plink_retries;
d0709a65 315 mod_plink_timer(sta, sta->plink_timeout);
07346f81 316 spin_unlock_bh(&sta->lock);
17741cdc 317 mesh_plink_frame_tx(sdata, PLINK_OPEN, sta->sta.addr, llid,
c3896d2c
LCC
318 0, 0);
319 break;
320 }
321 reason = cpu_to_le16(MESH_MAX_RETRIES);
322 /* fall through on else */
b4e08ea1 323 case PLINK_CNF_RCVD:
c3896d2c
LCC
324 /* confirm timer */
325 if (!reason)
326 reason = cpu_to_le16(MESH_CONFIRM_TIMEOUT);
b4e08ea1 327 sta->plink_state = PLINK_HOLDING;
d0709a65 328 mod_plink_timer(sta, dot11MeshHoldingTimeout(sdata));
07346f81 329 spin_unlock_bh(&sta->lock);
17741cdc 330 mesh_plink_frame_tx(sdata, PLINK_CLOSE, sta->sta.addr, llid, plid,
c3896d2c
LCC
331 reason);
332 break;
b4e08ea1 333 case PLINK_HOLDING:
c3896d2c 334 /* holding timer */
d0709a65 335 del_timer(&sta->plink_timer);
c3896d2c 336 mesh_plink_fsm_restart(sta);
07346f81 337 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
338 break;
339 default:
07346f81 340 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
341 break;
342 }
c3896d2c
LCC
343}
344
5bb644a0
JB
345#ifdef CONFIG_PM
346void mesh_plink_quiesce(struct sta_info *sta)
347{
348 if (del_timer_sync(&sta->plink_timer))
349 sta->plink_timer_was_running = true;
350}
351
352void mesh_plink_restart(struct sta_info *sta)
353{
354 if (sta->plink_timer_was_running) {
355 add_timer(&sta->plink_timer);
356 sta->plink_timer_was_running = false;
357 }
358}
359#endif
360
c3896d2c
LCC
361static inline void mesh_plink_timer_set(struct sta_info *sta, int timeout)
362{
363 sta->plink_timer.expires = jiffies + (HZ * timeout / 1000);
364 sta->plink_timer.data = (unsigned long) sta;
365 sta->plink_timer.function = mesh_plink_timer;
366 sta->plink_timeout = timeout;
c3896d2c
LCC
367 add_timer(&sta->plink_timer);
368}
369
370int mesh_plink_open(struct sta_info *sta)
371{
372 __le16 llid;
d0709a65 373 struct ieee80211_sub_if_data *sdata = sta->sdata;
c3896d2c 374
07346f81 375 spin_lock_bh(&sta->lock);
c3896d2c
LCC
376 get_random_bytes(&llid, 2);
377 sta->llid = llid;
b4e08ea1 378 if (sta->plink_state != PLINK_LISTEN) {
07346f81 379 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
380 return -EBUSY;
381 }
b4e08ea1 382 sta->plink_state = PLINK_OPN_SNT;
c3896d2c 383 mesh_plink_timer_set(sta, dot11MeshRetryTimeout(sdata));
07346f81 384 spin_unlock_bh(&sta->lock);
0c68ae26
JB
385 mpl_dbg("Mesh plink: starting establishment with %pM\n",
386 sta->sta.addr);
c3896d2c 387
f698d856 388 return mesh_plink_frame_tx(sdata, PLINK_OPEN,
17741cdc 389 sta->sta.addr, llid, 0, 0);
c3896d2c
LCC
390}
391
392void mesh_plink_block(struct sta_info *sta)
393{
c9370197
JL
394 struct ieee80211_sub_if_data *sdata = sta->sdata;
395 bool deactivated;
396
07346f81 397 spin_lock_bh(&sta->lock);
c9370197 398 deactivated = __mesh_plink_deactivate(sta);
b4e08ea1 399 sta->plink_state = PLINK_BLOCKED;
07346f81 400 spin_unlock_bh(&sta->lock);
c9370197
JL
401
402 if (deactivated)
403 ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_BEACON);
c3896d2c
LCC
404}
405
c3896d2c 406
f698d856 407void mesh_rx_plink_frame(struct ieee80211_sub_if_data *sdata, struct ieee80211_mgmt *mgmt,
c3896d2c
LCC
408 size_t len, struct ieee80211_rx_status *rx_status)
409{
d0709a65 410 struct ieee80211_local *local = sdata->local;
c3896d2c
LCC
411 struct ieee802_11_elems elems;
412 struct sta_info *sta;
413 enum plink_event event;
414 enum plink_frame_type ftype;
415 size_t baselen;
d12c7452 416 bool deactivated, matches_local = true;
c3896d2c
LCC
417 u8 ie_len;
418 u8 *baseaddr;
419 __le16 plid, llid, reason;
1460dd15
RP
420#ifdef CONFIG_MAC80211_VERBOSE_MPL_DEBUG
421 static const char *mplstates[] = {
422 [PLINK_LISTEN] = "LISTEN",
423 [PLINK_OPN_SNT] = "OPN-SNT",
424 [PLINK_OPN_RCVD] = "OPN-RCVD",
425 [PLINK_CNF_RCVD] = "CNF_RCVD",
426 [PLINK_ESTAB] = "ESTAB",
427 [PLINK_HOLDING] = "HOLDING",
428 [PLINK_BLOCKED] = "BLOCKED"
429 };
430#endif
c3896d2c 431
9c80d3dc
JB
432 /* need action_code, aux */
433 if (len < IEEE80211_MIN_ACTION_SIZE + 3)
434 return;
435
c3896d2c
LCC
436 if (is_multicast_ether_addr(mgmt->da)) {
437 mpl_dbg("Mesh plink: ignore frame from multicast address");
438 return;
439 }
440
441 baseaddr = mgmt->u.action.u.plink_action.variable;
442 baselen = (u8 *) mgmt->u.action.u.plink_action.variable - (u8 *) mgmt;
443 if (mgmt->u.action.u.plink_action.action_code == PLINK_CONFIRM) {
444 baseaddr += 4;
70bdb6b2 445 baselen += 4;
c3896d2c
LCC
446 }
447 ieee802_11_parse_elems(baseaddr, len - baselen, &elems);
448 if (!elems.peer_link) {
449 mpl_dbg("Mesh plink: missing necessary peer link ie\n");
450 return;
451 }
5cff5e01
JC
452 if (elems.rsn_len && !sdata->u.mesh.is_secure) {
453 mpl_dbg("Mesh plink: can't establish link with secure peer\n");
454 return;
455 }
c3896d2c 456
0938393f 457 ftype = mgmt->u.action.u.plink_action.action_code;
c3896d2c 458 ie_len = elems.peer_link_len;
0938393f
RP
459 if ((ftype == PLINK_OPEN && ie_len != 6) ||
460 (ftype == PLINK_CONFIRM && ie_len != 8) ||
461 (ftype == PLINK_CLOSE && ie_len != 8 && ie_len != 10)) {
462 mpl_dbg("Mesh plink: incorrect plink ie length %d %d\n",
463 ftype, ie_len);
c3896d2c
LCC
464 return;
465 }
466
467 if (ftype != PLINK_CLOSE && (!elems.mesh_id || !elems.mesh_config)) {
468 mpl_dbg("Mesh plink: missing necessary ie\n");
469 return;
470 }
471 /* Note the lines below are correct, the llid in the frame is the plid
472 * from the point of view of this host.
473 */
474 memcpy(&plid, PLINK_GET_LLID(elems.peer_link), 2);
0938393f 475 if (ftype == PLINK_CONFIRM || (ftype == PLINK_CLOSE && ie_len == 10))
c3896d2c
LCC
476 memcpy(&llid, PLINK_GET_PLID(elems.peer_link), 2);
477
d0709a65
JB
478 rcu_read_lock();
479
abe60632 480 sta = sta_info_get(sdata, mgmt->sa);
c3896d2c
LCC
481 if (!sta && ftype != PLINK_OPEN) {
482 mpl_dbg("Mesh plink: cls or cnf from unknown peer\n");
d0709a65 483 rcu_read_unlock();
c3896d2c
LCC
484 return;
485 }
486
b4e08ea1 487 if (sta && sta->plink_state == PLINK_BLOCKED) {
d0709a65 488 rcu_read_unlock();
c3896d2c
LCC
489 return;
490 }
491
492 /* Now we will figure out the appropriate event... */
493 event = PLINK_UNDEFINED;
f698d856 494 if (ftype != PLINK_CLOSE && (!mesh_matches_local(&elems, sdata))) {
d12c7452 495 matches_local = false;
c3896d2c
LCC
496 switch (ftype) {
497 case PLINK_OPEN:
498 event = OPN_RJCT;
499 break;
500 case PLINK_CONFIRM:
501 event = CNF_RJCT;
502 break;
503 case PLINK_CLOSE:
504 /* avoid warning */
505 break;
506 }
d12c7452
CL
507 }
508
509 if (!sta && !matches_local) {
510 rcu_read_unlock();
511 reason = cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION);
512 llid = 0;
513 mesh_plink_frame_tx(sdata, PLINK_CLOSE, mgmt->sa, llid,
514 plid, reason);
515 return;
c3896d2c
LCC
516 } else if (!sta) {
517 /* ftype == PLINK_OPEN */
881d948c 518 u32 rates;
34e89507
JB
519
520 rcu_read_unlock();
521
c3896d2c
LCC
522 if (!mesh_plink_free_count(sdata)) {
523 mpl_dbg("Mesh plink error: no more free plinks\n");
524 return;
525 }
526
527 rates = ieee80211_sta_get_rates(local, &elems, rx_status->band);
03e4497e 528 sta = mesh_plink_alloc(sdata, mgmt->sa, rates);
73651ee6 529 if (!sta) {
c3896d2c
LCC
530 mpl_dbg("Mesh plink error: plink table full\n");
531 return;
532 }
34e89507 533 if (sta_info_insert_rcu(sta)) {
73651ee6
JB
534 rcu_read_unlock();
535 return;
536 }
c3896d2c 537 event = OPN_ACPT;
07346f81 538 spin_lock_bh(&sta->lock);
d12c7452 539 } else if (matches_local) {
07346f81 540 spin_lock_bh(&sta->lock);
c3896d2c
LCC
541 switch (ftype) {
542 case PLINK_OPEN:
543 if (!mesh_plink_free_count(sdata) ||
d0709a65 544 (sta->plid && sta->plid != plid))
c3896d2c
LCC
545 event = OPN_IGNR;
546 else
547 event = OPN_ACPT;
548 break;
549 case PLINK_CONFIRM:
550 if (!mesh_plink_free_count(sdata) ||
d0709a65 551 (sta->llid != llid || sta->plid != plid))
c3896d2c
LCC
552 event = CNF_IGNR;
553 else
554 event = CNF_ACPT;
555 break;
556 case PLINK_CLOSE:
b4e08ea1 557 if (sta->plink_state == PLINK_ESTAB)
c3896d2c
LCC
558 /* Do not check for llid or plid. This does not
559 * follow the standard but since multiple plinks
560 * per sta are not supported, it is necessary in
561 * order to avoid a livelock when MP A sees an
562 * establish peer link to MP B but MP B does not
563 * see it. This can be caused by a timeout in
564 * B's peer link establishment or B beign
565 * restarted.
566 */
567 event = CLS_ACPT;
568 else if (sta->plid != plid)
569 event = CLS_IGNR;
570 else if (ie_len == 7 && sta->llid != llid)
571 event = CLS_IGNR;
572 else
573 event = CLS_ACPT;
574 break;
575 default:
576 mpl_dbg("Mesh plink: unknown frame subtype\n");
07346f81 577 spin_unlock_bh(&sta->lock);
d0709a65 578 rcu_read_unlock();
c3896d2c
LCC
579 return;
580 }
d12c7452
CL
581 } else {
582 spin_lock_bh(&sta->lock);
c3896d2c
LCC
583 }
584
1460dd15
RP
585 mpl_dbg("Mesh plink (peer, state, llid, plid, event): %pM %s %d %d %d\n",
586 mgmt->sa, mplstates[sta->plink_state],
0c68ae26
JB
587 le16_to_cpu(sta->llid), le16_to_cpu(sta->plid),
588 event);
c3896d2c
LCC
589 reason = 0;
590 switch (sta->plink_state) {
591 /* spin_unlock as soon as state is updated at each case */
b4e08ea1 592 case PLINK_LISTEN:
c3896d2c
LCC
593 switch (event) {
594 case CLS_ACPT:
595 mesh_plink_fsm_restart(sta);
07346f81 596 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
597 break;
598 case OPN_ACPT:
b4e08ea1 599 sta->plink_state = PLINK_OPN_RCVD;
c3896d2c
LCC
600 sta->plid = plid;
601 get_random_bytes(&llid, 2);
602 sta->llid = llid;
603 mesh_plink_timer_set(sta, dot11MeshRetryTimeout(sdata));
07346f81 604 spin_unlock_bh(&sta->lock);
17741cdc 605 mesh_plink_frame_tx(sdata, PLINK_OPEN, sta->sta.addr, llid,
c3896d2c 606 0, 0);
17741cdc 607 mesh_plink_frame_tx(sdata, PLINK_CONFIRM, sta->sta.addr,
c3896d2c
LCC
608 llid, plid, 0);
609 break;
610 default:
07346f81 611 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
612 break;
613 }
614 break;
615
b4e08ea1 616 case PLINK_OPN_SNT:
c3896d2c
LCC
617 switch (event) {
618 case OPN_RJCT:
619 case CNF_RJCT:
620 reason = cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION);
621 case CLS_ACPT:
622 if (!reason)
623 reason = cpu_to_le16(MESH_CLOSE_RCVD);
624 sta->reason = reason;
b4e08ea1 625 sta->plink_state = PLINK_HOLDING;
c3896d2c
LCC
626 if (!mod_plink_timer(sta,
627 dot11MeshHoldingTimeout(sdata)))
628 sta->ignore_plink_timer = true;
629
630 llid = sta->llid;
07346f81 631 spin_unlock_bh(&sta->lock);
17741cdc 632 mesh_plink_frame_tx(sdata, PLINK_CLOSE, sta->sta.addr, llid,
c3896d2c
LCC
633 plid, reason);
634 break;
635 case OPN_ACPT:
636 /* retry timer is left untouched */
b4e08ea1 637 sta->plink_state = PLINK_OPN_RCVD;
c3896d2c
LCC
638 sta->plid = plid;
639 llid = sta->llid;
07346f81 640 spin_unlock_bh(&sta->lock);
17741cdc 641 mesh_plink_frame_tx(sdata, PLINK_CONFIRM, sta->sta.addr, llid,
c3896d2c
LCC
642 plid, 0);
643 break;
644 case CNF_ACPT:
b4e08ea1 645 sta->plink_state = PLINK_CNF_RCVD;
c3896d2c
LCC
646 if (!mod_plink_timer(sta,
647 dot11MeshConfirmTimeout(sdata)))
648 sta->ignore_plink_timer = true;
649
07346f81 650 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
651 break;
652 default:
07346f81 653 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
654 break;
655 }
656 break;
657
b4e08ea1 658 case PLINK_OPN_RCVD:
c3896d2c
LCC
659 switch (event) {
660 case OPN_RJCT:
661 case CNF_RJCT:
662 reason = cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION);
663 case CLS_ACPT:
664 if (!reason)
665 reason = cpu_to_le16(MESH_CLOSE_RCVD);
666 sta->reason = reason;
b4e08ea1 667 sta->plink_state = PLINK_HOLDING;
c3896d2c
LCC
668 if (!mod_plink_timer(sta,
669 dot11MeshHoldingTimeout(sdata)))
670 sta->ignore_plink_timer = true;
671
672 llid = sta->llid;
07346f81 673 spin_unlock_bh(&sta->lock);
17741cdc 674 mesh_plink_frame_tx(sdata, PLINK_CLOSE, sta->sta.addr, llid,
c3896d2c
LCC
675 plid, reason);
676 break;
677 case OPN_ACPT:
678 llid = sta->llid;
07346f81 679 spin_unlock_bh(&sta->lock);
17741cdc 680 mesh_plink_frame_tx(sdata, PLINK_CONFIRM, sta->sta.addr, llid,
c3896d2c
LCC
681 plid, 0);
682 break;
683 case CNF_ACPT:
d0709a65 684 del_timer(&sta->plink_timer);
b4e08ea1 685 sta->plink_state = PLINK_ESTAB;
07346f81 686 spin_unlock_bh(&sta->lock);
c9370197
JL
687 mesh_plink_inc_estab_count(sdata);
688 ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_BEACON);
0c68ae26
JB
689 mpl_dbg("Mesh plink with %pM ESTABLISHED\n",
690 sta->sta.addr);
c3896d2c
LCC
691 break;
692 default:
07346f81 693 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
694 break;
695 }
696 break;
697
b4e08ea1 698 case PLINK_CNF_RCVD:
c3896d2c
LCC
699 switch (event) {
700 case OPN_RJCT:
701 case CNF_RJCT:
702 reason = cpu_to_le16(MESH_CAPABILITY_POLICY_VIOLATION);
703 case CLS_ACPT:
704 if (!reason)
705 reason = cpu_to_le16(MESH_CLOSE_RCVD);
706 sta->reason = reason;
b4e08ea1 707 sta->plink_state = PLINK_HOLDING;
c3896d2c
LCC
708 if (!mod_plink_timer(sta,
709 dot11MeshHoldingTimeout(sdata)))
710 sta->ignore_plink_timer = true;
711
712 llid = sta->llid;
07346f81 713 spin_unlock_bh(&sta->lock);
17741cdc 714 mesh_plink_frame_tx(sdata, PLINK_CLOSE, sta->sta.addr, llid,
c3896d2c 715 plid, reason);
ff59dc76 716 break;
c3896d2c 717 case OPN_ACPT:
d0709a65 718 del_timer(&sta->plink_timer);
b4e08ea1 719 sta->plink_state = PLINK_ESTAB;
07346f81 720 spin_unlock_bh(&sta->lock);
c9370197
JL
721 mesh_plink_inc_estab_count(sdata);
722 ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_BEACON);
0c68ae26
JB
723 mpl_dbg("Mesh plink with %pM ESTABLISHED\n",
724 sta->sta.addr);
17741cdc 725 mesh_plink_frame_tx(sdata, PLINK_CONFIRM, sta->sta.addr, llid,
c3896d2c
LCC
726 plid, 0);
727 break;
728 default:
07346f81 729 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
730 break;
731 }
732 break;
733
b4e08ea1 734 case PLINK_ESTAB:
c3896d2c
LCC
735 switch (event) {
736 case CLS_ACPT:
737 reason = cpu_to_le16(MESH_CLOSE_RCVD);
738 sta->reason = reason;
c9370197 739 deactivated = __mesh_plink_deactivate(sta);
b4e08ea1 740 sta->plink_state = PLINK_HOLDING;
c3896d2c 741 llid = sta->llid;
d0709a65 742 mod_plink_timer(sta, dot11MeshHoldingTimeout(sdata));
07346f81 743 spin_unlock_bh(&sta->lock);
c9370197
JL
744 if (deactivated)
745 ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_BEACON);
17741cdc 746 mesh_plink_frame_tx(sdata, PLINK_CLOSE, sta->sta.addr, llid,
c3896d2c
LCC
747 plid, reason);
748 break;
749 case OPN_ACPT:
750 llid = sta->llid;
07346f81 751 spin_unlock_bh(&sta->lock);
17741cdc 752 mesh_plink_frame_tx(sdata, PLINK_CONFIRM, sta->sta.addr, llid,
c3896d2c
LCC
753 plid, 0);
754 break;
755 default:
07346f81 756 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
757 break;
758 }
759 break;
b4e08ea1 760 case PLINK_HOLDING:
c3896d2c
LCC
761 switch (event) {
762 case CLS_ACPT:
d0709a65 763 if (del_timer(&sta->plink_timer))
c3896d2c 764 sta->ignore_plink_timer = 1;
c3896d2c 765 mesh_plink_fsm_restart(sta);
07346f81 766 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
767 break;
768 case OPN_ACPT:
769 case CNF_ACPT:
770 case OPN_RJCT:
771 case CNF_RJCT:
772 llid = sta->llid;
773 reason = sta->reason;
07346f81 774 spin_unlock_bh(&sta->lock);
17741cdc
JB
775 mesh_plink_frame_tx(sdata, PLINK_CLOSE, sta->sta.addr,
776 llid, plid, reason);
c3896d2c
LCC
777 break;
778 default:
07346f81 779 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
780 }
781 break;
782 default:
b4e08ea1 783 /* should not get here, PLINK_BLOCKED is dealt with at the
3ad2f3fb 784 * beginning of the function
c3896d2c 785 */
07346f81 786 spin_unlock_bh(&sta->lock);
c3896d2c
LCC
787 break;
788 }
d0709a65
JB
789
790 rcu_read_unlock();
c3896d2c 791}