cfg80211/nl80211: Optional authentication offload to userspace
[linux-block.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
2740f0cf 5 * Copyright 2013-2014 Intel Mobile Communications GmbH
66cd794e 6 * Copyright 2015-2017 Intel Deutschland GmbH
55682965
JB
7 */
8
9#include <linux/if.h>
10#include <linux/module.h>
11#include <linux/err.h>
5a0e3ad6 12#include <linux/slab.h>
55682965
JB
13#include <linux/list.h>
14#include <linux/if_ether.h>
15#include <linux/ieee80211.h>
16#include <linux/nl80211.h>
17#include <linux/rtnetlink.h>
18#include <linux/netlink.h>
2a519311 19#include <linux/etherdevice.h>
463d0183 20#include <net/net_namespace.h>
55682965
JB
21#include <net/genetlink.h>
22#include <net/cfg80211.h>
463d0183 23#include <net/sock.h>
2a0e047e 24#include <net/inet_connection_sock.h>
55682965
JB
25#include "core.h"
26#include "nl80211.h"
b2e1b302 27#include "reg.h"
e35e4d28 28#include "rdev-ops.h"
55682965 29
5fb628e9
JM
30static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
31 struct genl_info *info,
32 struct cfg80211_crypto_settings *settings,
33 int cipher_limit);
34
55682965 35/* the netlink family */
489111e5 36static struct genl_family nl80211_fam;
55682965 37
2a94fe48
JB
38/* multicast groups */
39enum nl80211_multicast_groups {
40 NL80211_MCGRP_CONFIG,
41 NL80211_MCGRP_SCAN,
42 NL80211_MCGRP_REGULATORY,
43 NL80211_MCGRP_MLME,
567ffc35 44 NL80211_MCGRP_VENDOR,
50bcd31d 45 NL80211_MCGRP_NAN,
2a94fe48
JB
46 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
47};
48
49static const struct genl_multicast_group nl80211_mcgrps[] = {
71b836ec
JB
50 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG },
51 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN },
52 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG },
53 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME },
54 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR },
50bcd31d 55 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN },
2a94fe48 56#ifdef CONFIG_NL80211_TESTMODE
71b836ec 57 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE }
2a94fe48
JB
58#endif
59};
60
89a54e48
JB
61/* returns ERR_PTR values */
62static struct wireless_dev *
63__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 64{
89a54e48
JB
65 struct cfg80211_registered_device *rdev;
66 struct wireless_dev *result = NULL;
67 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
68 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
69 u64 wdev_id;
70 int wiphy_idx = -1;
71 int ifidx = -1;
55682965 72
5fe231e8 73 ASSERT_RTNL();
55682965 74
89a54e48
JB
75 if (!have_ifidx && !have_wdev_id)
76 return ERR_PTR(-EINVAL);
55682965 77
89a54e48
JB
78 if (have_ifidx)
79 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
80 if (have_wdev_id) {
81 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
82 wiphy_idx = wdev_id >> 32;
55682965
JB
83 }
84
89a54e48
JB
85 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
86 struct wireless_dev *wdev;
87
88 if (wiphy_net(&rdev->wiphy) != netns)
89 continue;
90
91 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
92 continue;
93
53873f13 94 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
89a54e48
JB
95 if (have_ifidx && wdev->netdev &&
96 wdev->netdev->ifindex == ifidx) {
97 result = wdev;
98 break;
99 }
100 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
101 result = wdev;
102 break;
103 }
104 }
89a54e48
JB
105
106 if (result)
107 break;
108 }
109
110 if (result)
111 return result;
112 return ERR_PTR(-ENODEV);
55682965
JB
113}
114
a9455408 115static struct cfg80211_registered_device *
878d9ec7 116__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 117{
7fee4778
JB
118 struct cfg80211_registered_device *rdev = NULL, *tmp;
119 struct net_device *netdev;
a9455408 120
5fe231e8 121 ASSERT_RTNL();
a9455408 122
878d9ec7 123 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
124 !attrs[NL80211_ATTR_IFINDEX] &&
125 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
126 return ERR_PTR(-EINVAL);
127
878d9ec7 128 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 129 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 130 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 131
89a54e48
JB
132 if (attrs[NL80211_ATTR_WDEV]) {
133 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
134 struct wireless_dev *wdev;
135 bool found = false;
136
137 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
138 if (tmp) {
139 /* make sure wdev exists */
53873f13 140 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) {
89a54e48
JB
141 if (wdev->identifier != (u32)wdev_id)
142 continue;
143 found = true;
144 break;
145 }
89a54e48
JB
146
147 if (!found)
148 tmp = NULL;
149
150 if (rdev && tmp != rdev)
151 return ERR_PTR(-EINVAL);
152 rdev = tmp;
153 }
154 }
155
878d9ec7
JB
156 if (attrs[NL80211_ATTR_IFINDEX]) {
157 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
7a087e74 158
7f2b8562 159 netdev = __dev_get_by_index(netns, ifindex);
7fee4778
JB
160 if (netdev) {
161 if (netdev->ieee80211_ptr)
f26cbf40
ZG
162 tmp = wiphy_to_rdev(
163 netdev->ieee80211_ptr->wiphy);
7fee4778
JB
164 else
165 tmp = NULL;
166
7fee4778
JB
167 /* not wireless device -- return error */
168 if (!tmp)
169 return ERR_PTR(-EINVAL);
170
171 /* mismatch -- return error */
172 if (rdev && tmp != rdev)
173 return ERR_PTR(-EINVAL);
174
175 rdev = tmp;
a9455408 176 }
a9455408 177 }
a9455408 178
4f7eff10
JB
179 if (!rdev)
180 return ERR_PTR(-ENODEV);
a9455408 181
4f7eff10
JB
182 if (netns != wiphy_net(&rdev->wiphy))
183 return ERR_PTR(-ENODEV);
184
185 return rdev;
a9455408
JB
186}
187
188/*
189 * This function returns a pointer to the driver
190 * that the genl_info item that is passed refers to.
a9455408
JB
191 *
192 * The result of this can be a PTR_ERR and hence must
193 * be checked with IS_ERR() for errors.
194 */
195static struct cfg80211_registered_device *
4f7eff10 196cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 197{
5fe231e8 198 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
199}
200
55682965 201/* policy for the attributes */
8cd4d456 202static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
55682965
JB
203 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
204 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 205 .len = 20-1 },
31888487 206 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 207
72bdcf34 208 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 209 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
210 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
211 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
212 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
213
b9a5f8ca
JM
214 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
215 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
216 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
217 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 218 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
3057dbfd 219 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG },
55682965
JB
220
221 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
222 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
223 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 224
e007b857
EP
225 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
226 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 227
b9454e83 228 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
229 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
230 .len = WLAN_MAX_KEY_LEN },
231 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
232 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
233 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 234 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 235 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
236
237 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
238 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
239 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
240 .len = IEEE80211_MAX_DATA_LEN },
241 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
242 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
243 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
244 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
245 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
246 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
247 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 248 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 249 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 250 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 251 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 252 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 253 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 254
b2e1b302
LR
255 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
256 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
257
9f1ba906
JM
258 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
259 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
260 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
261 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
262 .len = NL80211_MAX_SUPP_RATES },
50b12f59 263 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 264
24bdd9f4 265 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 266 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 267
6c739419 268 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
269
270 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
271 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
272 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
273 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
274 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
275
276 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
277 .len = IEEE80211_MAX_SSID_LEN },
278 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
279 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 280 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 281 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 282 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
283 [NL80211_ATTR_STA_FLAGS2] = {
284 .len = sizeof(struct nl80211_sta_flag_update),
285 },
3f77316c 286 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
287 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
288 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
289 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
290 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
291 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 292 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 293 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
9361df14 294 [NL80211_ATTR_PMKID] = { .len = WLAN_PMKID_LEN },
9588bbd5
JM
295 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
296 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 297 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
298 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
299 .len = IEEE80211_MAX_DATA_LEN },
300 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 301 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 302 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 303 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 304 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
305 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
306 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 307 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
308 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
309 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 310 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 311 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 312 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 313 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 314 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 315 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 316 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 317 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 318 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
319 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
320 .len = IEEE80211_MAX_DATA_LEN },
321 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
322 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 323 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 324 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 325 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
326 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
327 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
328 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
329 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
330 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
31fa97c5 331 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG },
e247bd90 332 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
333 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
334 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 335 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
336 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
337 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
338 .len = NL80211_HT_CAPABILITY_LEN
339 },
1d9d9213 340 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 341 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 342 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 343 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 344 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
11b6b5a4 345 [NL80211_ATTR_AUTH_DATA] = { .type = NLA_BINARY, },
f461be3e 346 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN },
ed473771 347 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
53cabad7
JB
348 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 },
349 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 },
8feb69c7 350 [NL80211_ATTR_LOCAL_MESH_POWER_MODE] = {. type = NLA_U32 },
77765eaf
VT
351 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
352 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
353 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
354 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 355 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
356 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
357 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
358 .len = NL80211_VHT_CAPABILITY_LEN,
359 },
355199e0
JM
360 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
361 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
362 .len = IEEE80211_MAX_DATA_LEN },
5e4b6f56 363 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 },
16ef1fe2
SW
364 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
365 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
366 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
9a774c78
AO
367 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY },
368 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY },
c01fc9ad
SD
369 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY },
370 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY },
5336fa88 371 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
60f4a7b1 372 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
ad7e718c
JB
373 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
374 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
375 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
fa9ffc74
KP
376 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY,
377 .len = IEEE80211_QOS_MAP_LEN_MAX },
1df4a510
JM
378 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN },
379 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
df942e7b 380 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 },
18e5ca65 381 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG },
34d22ce2 382 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY },
bab5ab7d 383 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG },
960d01ac
JB
384 [NL80211_ATTR_TSID] = { .type = NLA_U8 },
385 [NL80211_ATTR_USER_PRIO] = { .type = NLA_U8 },
386 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 },
18998c38 387 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 },
ad2b26ab 388 [NL80211_ATTR_MAC_MASK] = { .len = ETH_ALEN },
1bdd716c 389 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG },
4b681c82 390 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 },
9c748934 391 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 },
05050753 392 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG },
34d50519 393 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG },
38de03d2 394 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED },
17b94247 395 [NL80211_ATTR_STA_SUPPORT_P2P_PS] = { .type = NLA_U8 },
c6e6a0c8
AE
396 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = {
397 .len = VHT_MUMIMO_GROUPS_DATA_LEN
398 },
399 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = { .len = ETH_ALEN },
cb3b7d87 400 [NL80211_ATTR_NAN_MASTER_PREF] = { .type = NLA_U8 },
8585989d 401 [NL80211_ATTR_BANDS] = { .type = NLA_U32 },
a442b761 402 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED },
348bd456
JM
403 [NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY,
404 .len = FILS_MAX_KEK_LEN },
405 [NL80211_ATTR_FILS_NONCES] = { .len = 2 * FILS_NONCE_LEN },
ce0ce13a 406 [NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, },
2fa436b3 407 [NL80211_ATTR_BSSID] = { .len = ETH_ALEN },
bf95ecdb 408 [NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] = { .type = NLA_S8 },
409 [NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST] = {
410 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
411 },
3093ebbe 412 [NL80211_ATTR_TIMEOUT_REASON] = { .type = NLA_U32 },
a3caf744
VK
413 [NL80211_ATTR_FILS_ERP_USERNAME] = { .type = NLA_BINARY,
414 .len = FILS_ERP_MAX_USERNAME_LEN },
415 [NL80211_ATTR_FILS_ERP_REALM] = { .type = NLA_BINARY,
416 .len = FILS_ERP_MAX_REALM_LEN },
417 [NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] = { .type = NLA_U16 },
418 [NL80211_ATTR_FILS_ERP_RRK] = { .type = NLA_BINARY,
419 .len = FILS_ERP_MAX_RRK_LEN },
420 [NL80211_ATTR_FILS_CACHE_ID] = { .len = 2 },
421 [NL80211_ATTR_PMK] = { .type = NLA_BINARY, .len = PMK_MAX_LEN },
ca986ad9 422 [NL80211_ATTR_SCHED_SCAN_MULTI] = { .type = NLA_FLAG },
40cbfa90 423 [NL80211_ATTR_EXTERNAL_AUTH_SUPPORT] = { .type = NLA_FLAG },
55682965
JB
424};
425
e31b8213 426/* policy for the key attributes */
b54452b0 427static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 428 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
429 [NL80211_KEY_IDX] = { .type = NLA_U8 },
430 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 431 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
432 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
433 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 434 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
435 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
436};
437
438/* policy for the key default flags */
439static const struct nla_policy
440nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
441 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
442 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
443};
444
f83ace3b 445#ifdef CONFIG_PM
ff1b6e69
JB
446/* policy for WoWLAN attributes */
447static const struct nla_policy
448nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
449 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
450 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
451 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
452 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
453 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
454 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
455 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
456 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e 457 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
8cd4d456 458 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED },
2a0e047e
JB
459};
460
461static const struct nla_policy
462nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
463 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
464 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
465 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN },
466 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
467 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
468 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 },
469 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
470 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
471 },
472 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
473 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
474 },
475 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
476 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 },
477 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 },
ff1b6e69 478};
f83ace3b 479#endif /* CONFIG_PM */
ff1b6e69 480
be29b99a
AK
481/* policy for coalesce rule attributes */
482static const struct nla_policy
483nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
484 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
485 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 },
486 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
487};
488
e5497d76
JB
489/* policy for GTK rekey offload attributes */
490static const struct nla_policy
491nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
492 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
493 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
494 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
495};
496
a1f1c21c
LC
497static const struct nla_policy
498nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 499 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 500 .len = IEEE80211_MAX_SSID_LEN },
3007e352 501 [NL80211_SCHED_SCAN_MATCH_ATTR_BSSID] = { .len = ETH_ALEN },
88e920b4 502 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
503};
504
3b06d277
AS
505static const struct nla_policy
506nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = {
507 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 },
508 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 },
509};
510
38de03d2
AS
511static const struct nla_policy
512nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = {
513 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG },
514 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 },
515 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = {
516 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
517 },
518};
519
a442b761
AB
520/* policy for NAN function attributes */
521static const struct nla_policy
522nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = {
523 [NL80211_NAN_FUNC_TYPE] = { .type = NLA_U8 },
0a27844c 524 [NL80211_NAN_FUNC_SERVICE_ID] = {
a442b761
AB
525 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN },
526 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 },
527 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG },
528 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG },
529 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 },
530 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 },
531 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = { .len = ETH_ALEN },
532 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG },
533 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 },
534 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY,
535 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN },
536 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED },
537 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED },
538 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED },
539 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 },
540 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 },
541};
542
543/* policy for Service Response Filter attributes */
544static const struct nla_policy
545nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = {
546 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG },
547 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY,
548 .len = NL80211_NAN_FUNC_SRF_MAX_LEN },
549 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 },
550 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED },
551};
552
ad670233
PX
553/* policy for packet pattern attributes */
554static const struct nla_policy
555nl80211_packet_pattern_policy[MAX_NL80211_PKTPAT + 1] = {
556 [NL80211_PKTPAT_MASK] = { .type = NLA_BINARY, },
557 [NL80211_PKTPAT_PATTERN] = { .type = NLA_BINARY, },
558 [NL80211_PKTPAT_OFFSET] = { .type = NLA_U32 },
559};
560
97990a06
JB
561static int nl80211_prepare_wdev_dump(struct sk_buff *skb,
562 struct netlink_callback *cb,
563 struct cfg80211_registered_device **rdev,
564 struct wireless_dev **wdev)
a043897a 565{
97990a06 566 int err;
a043897a 567
97990a06
JB
568 if (!cb->args[0]) {
569 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
c90c39da 570 genl_family_attrbuf(&nl80211_fam),
fceb6435 571 nl80211_fam.maxattr, nl80211_policy, NULL);
97990a06 572 if (err)
ea90e0dc 573 return err;
67748893 574
c90c39da
JB
575 *wdev = __cfg80211_wdev_from_attrs(
576 sock_net(skb->sk),
577 genl_family_attrbuf(&nl80211_fam));
ea90e0dc
JB
578 if (IS_ERR(*wdev))
579 return PTR_ERR(*wdev);
f26cbf40 580 *rdev = wiphy_to_rdev((*wdev)->wiphy);
c319d50b
JB
581 /* 0 is the first index - add 1 to parse only once */
582 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
583 cb->args[1] = (*wdev)->identifier;
584 } else {
c319d50b
JB
585 /* subtract the 1 again here */
586 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 587 struct wireless_dev *tmp;
67748893 588
ea90e0dc
JB
589 if (!wiphy)
590 return -ENODEV;
f26cbf40 591 *rdev = wiphy_to_rdev(wiphy);
97990a06 592 *wdev = NULL;
67748893 593
53873f13 594 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) {
97990a06
JB
595 if (tmp->identifier == cb->args[1]) {
596 *wdev = tmp;
597 break;
598 }
599 }
67748893 600
ea90e0dc
JB
601 if (!*wdev)
602 return -ENODEV;
67748893
JB
603 }
604
67748893 605 return 0;
67748893
JB
606}
607
f4a11bb0
JB
608/* IE validation */
609static bool is_valid_ie_attr(const struct nlattr *attr)
610{
611 const u8 *pos;
612 int len;
613
614 if (!attr)
615 return true;
616
617 pos = nla_data(attr);
618 len = nla_len(attr);
619
620 while (len) {
621 u8 elemlen;
622
623 if (len < 2)
624 return false;
625 len -= 2;
626
627 elemlen = pos[1];
628 if (elemlen > len)
629 return false;
630
631 len -= elemlen;
632 pos += 2 + elemlen;
633 }
634
635 return true;
636}
637
55682965 638/* message building helper */
15e47304 639static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
55682965
JB
640 int flags, u8 cmd)
641{
642 /* since there is no private header just add the generic one */
15e47304 643 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
644}
645
5dab3b8a 646static int nl80211_msg_put_channel(struct sk_buff *msg,
cdc89b97
JB
647 struct ieee80211_channel *chan,
648 bool large)
5dab3b8a 649{
ea077c1c
RL
650 /* Some channels must be completely excluded from the
651 * list to protect old user-space tools from breaking
652 */
653 if (!large && chan->flags &
654 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ))
655 return 0;
656
9360ffd1
DM
657 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
658 chan->center_freq))
659 goto nla_put_failure;
5dab3b8a 660
9360ffd1
DM
661 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
662 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
663 goto nla_put_failure;
8fe02e16
LR
664 if (chan->flags & IEEE80211_CHAN_NO_IR) {
665 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
666 goto nla_put_failure;
667 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
668 goto nla_put_failure;
669 }
cdc89b97
JB
670 if (chan->flags & IEEE80211_CHAN_RADAR) {
671 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
672 goto nla_put_failure;
673 if (large) {
674 u32 time;
675
676 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
677
678 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
679 chan->dfs_state))
680 goto nla_put_failure;
681 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
682 time))
683 goto nla_put_failure;
089027e5
JD
684 if (nla_put_u32(msg,
685 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME,
686 chan->dfs_cac_ms))
687 goto nla_put_failure;
cdc89b97
JB
688 }
689 }
5dab3b8a 690
fe1abafd
JB
691 if (large) {
692 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
693 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
694 goto nla_put_failure;
695 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
696 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
697 goto nla_put_failure;
698 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
699 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
700 goto nla_put_failure;
701 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
702 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
703 goto nla_put_failure;
570dbde1
DS
704 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) &&
705 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY))
706 goto nla_put_failure;
06f207fc
AN
707 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) &&
708 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT))
570dbde1 709 goto nla_put_failure;
ea077c1c
RL
710 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) &&
711 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ))
712 goto nla_put_failure;
713 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) &&
714 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ))
715 goto nla_put_failure;
fe1abafd
JB
716 }
717
9360ffd1
DM
718 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
719 DBM_TO_MBM(chan->max_power)))
720 goto nla_put_failure;
5dab3b8a
LR
721
722 return 0;
723
724 nla_put_failure:
725 return -ENOBUFS;
726}
727
55682965
JB
728/* netlink command implementations */
729
b9454e83
JB
730struct key_parse {
731 struct key_params p;
732 int idx;
e31b8213 733 int type;
b9454e83 734 bool def, defmgmt;
dbd2fd65 735 bool def_uni, def_multi;
b9454e83
JB
736};
737
768075eb
JB
738static int nl80211_parse_key_new(struct genl_info *info, struct nlattr *key,
739 struct key_parse *k)
b9454e83
JB
740{
741 struct nlattr *tb[NL80211_KEY_MAX + 1];
742 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
768075eb 743 nl80211_key_policy, info->extack);
b9454e83
JB
744 if (err)
745 return err;
746
747 k->def = !!tb[NL80211_KEY_DEFAULT];
748 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
749
dbd2fd65
JB
750 if (k->def) {
751 k->def_uni = true;
752 k->def_multi = true;
753 }
754 if (k->defmgmt)
755 k->def_multi = true;
756
b9454e83
JB
757 if (tb[NL80211_KEY_IDX])
758 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
759
760 if (tb[NL80211_KEY_DATA]) {
761 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
762 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
763 }
764
765 if (tb[NL80211_KEY_SEQ]) {
766 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
767 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
768 }
769
770 if (tb[NL80211_KEY_CIPHER])
771 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
772
e31b8213
JB
773 if (tb[NL80211_KEY_TYPE]) {
774 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
775 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
768075eb
JB
776 return genl_err_attr(info, -EINVAL,
777 tb[NL80211_KEY_TYPE]);
e31b8213
JB
778 }
779
dbd2fd65
JB
780 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
781 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
7a087e74 782
2da8f419
JB
783 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
784 tb[NL80211_KEY_DEFAULT_TYPES],
768075eb
JB
785 nl80211_key_default_policy,
786 info->extack);
dbd2fd65
JB
787 if (err)
788 return err;
789
790 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
791 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
792 }
793
b9454e83
JB
794 return 0;
795}
796
797static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
798{
799 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
800 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
801 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
802 }
803
804 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
805 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
806 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
807 }
808
809 if (info->attrs[NL80211_ATTR_KEY_IDX])
810 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
811
812 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
813 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
814
815 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
816 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
817
dbd2fd65
JB
818 if (k->def) {
819 k->def_uni = true;
820 k->def_multi = true;
821 }
822 if (k->defmgmt)
823 k->def_multi = true;
824
e31b8213
JB
825 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
826 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
768075eb
JB
827 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) {
828 GENL_SET_ERR_MSG(info, "key type out of range");
e31b8213 829 return -EINVAL;
768075eb 830 }
e31b8213
JB
831 }
832
dbd2fd65
JB
833 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
834 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
fceb6435
JB
835 int err = nla_parse_nested(kdt,
836 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
837 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
fe52145f
JB
838 nl80211_key_default_policy,
839 info->extack);
dbd2fd65
JB
840 if (err)
841 return err;
842
843 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
844 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
845 }
846
b9454e83
JB
847 return 0;
848}
849
850static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
851{
852 int err;
853
854 memset(k, 0, sizeof(*k));
855 k->idx = -1;
e31b8213 856 k->type = -1;
b9454e83
JB
857
858 if (info->attrs[NL80211_ATTR_KEY])
768075eb 859 err = nl80211_parse_key_new(info, info->attrs[NL80211_ATTR_KEY], k);
b9454e83
JB
860 else
861 err = nl80211_parse_key_old(info, k);
862
863 if (err)
864 return err;
865
768075eb
JB
866 if (k->def && k->defmgmt) {
867 GENL_SET_ERR_MSG(info, "key with def && defmgmt is invalid");
b9454e83 868 return -EINVAL;
768075eb 869 }
b9454e83 870
dbd2fd65 871 if (k->defmgmt) {
768075eb
JB
872 if (k->def_uni || !k->def_multi) {
873 GENL_SET_ERR_MSG(info, "defmgmt key must be mcast");
dbd2fd65 874 return -EINVAL;
768075eb 875 }
dbd2fd65
JB
876 }
877
b9454e83
JB
878 if (k->idx != -1) {
879 if (k->defmgmt) {
768075eb
JB
880 if (k->idx < 4 || k->idx > 5) {
881 GENL_SET_ERR_MSG(info,
882 "defmgmt key idx not 4 or 5");
b9454e83 883 return -EINVAL;
768075eb 884 }
b9454e83 885 } else if (k->def) {
768075eb
JB
886 if (k->idx < 0 || k->idx > 3) {
887 GENL_SET_ERR_MSG(info, "def key idx not 0-3");
b9454e83 888 return -EINVAL;
768075eb 889 }
b9454e83 890 } else {
768075eb
JB
891 if (k->idx < 0 || k->idx > 5) {
892 GENL_SET_ERR_MSG(info, "key idx not 0-5");
b9454e83 893 return -EINVAL;
768075eb 894 }
b9454e83
JB
895 }
896 }
897
898 return 0;
899}
900
fffd0934
JB
901static struct cfg80211_cached_keys *
902nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
768075eb 903 struct genl_info *info, bool *no_ht)
fffd0934 904{
768075eb 905 struct nlattr *keys = info->attrs[NL80211_ATTR_KEYS];
fffd0934
JB
906 struct key_parse parse;
907 struct nlattr *key;
908 struct cfg80211_cached_keys *result;
909 int rem, err, def = 0;
f1c1f17a
JB
910 bool have_key = false;
911
912 nla_for_each_nested(key, keys, rem) {
913 have_key = true;
914 break;
915 }
916
917 if (!have_key)
918 return NULL;
fffd0934
JB
919
920 result = kzalloc(sizeof(*result), GFP_KERNEL);
921 if (!result)
922 return ERR_PTR(-ENOMEM);
923
924 result->def = -1;
fffd0934
JB
925
926 nla_for_each_nested(key, keys, rem) {
927 memset(&parse, 0, sizeof(parse));
928 parse.idx = -1;
929
768075eb 930 err = nl80211_parse_key_new(info, key, &parse);
fffd0934
JB
931 if (err)
932 goto error;
933 err = -EINVAL;
934 if (!parse.p.key)
935 goto error;
768075eb
JB
936 if (parse.idx < 0 || parse.idx > 3) {
937 GENL_SET_ERR_MSG(info, "key index out of range [0-3]");
fffd0934 938 goto error;
768075eb 939 }
fffd0934 940 if (parse.def) {
768075eb
JB
941 if (def) {
942 GENL_SET_ERR_MSG(info,
943 "only one key can be default");
fffd0934 944 goto error;
768075eb 945 }
fffd0934
JB
946 def = 1;
947 result->def = parse.idx;
dbd2fd65
JB
948 if (!parse.def_uni || !parse.def_multi)
949 goto error;
fffd0934
JB
950 } else if (parse.defmgmt)
951 goto error;
952 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 953 parse.idx, false, NULL);
fffd0934
JB
954 if (err)
955 goto error;
386b1f27
JB
956 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 &&
957 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) {
768075eb 958 GENL_SET_ERR_MSG(info, "connect key must be WEP");
386b1f27
JB
959 err = -EINVAL;
960 goto error;
961 }
fffd0934
JB
962 result->params[parse.idx].cipher = parse.p.cipher;
963 result->params[parse.idx].key_len = parse.p.key_len;
964 result->params[parse.idx].key = result->data[parse.idx];
965 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee 966
386b1f27
JB
967 /* must be WEP key if we got here */
968 if (no_ht)
969 *no_ht = true;
fffd0934
JB
970 }
971
f1c1f17a
JB
972 if (result->def < 0) {
973 err = -EINVAL;
768075eb 974 GENL_SET_ERR_MSG(info, "need a default/TX key");
f1c1f17a
JB
975 goto error;
976 }
977
fffd0934
JB
978 return result;
979 error:
980 kfree(result);
981 return ERR_PTR(err);
982}
983
984static int nl80211_key_allowed(struct wireless_dev *wdev)
985{
986 ASSERT_WDEV_LOCK(wdev);
987
fffd0934
JB
988 switch (wdev->iftype) {
989 case NL80211_IFTYPE_AP:
990 case NL80211_IFTYPE_AP_VLAN:
074ac8df 991 case NL80211_IFTYPE_P2P_GO:
ff973af7 992 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
993 break;
994 case NL80211_IFTYPE_ADHOC:
fffd0934 995 case NL80211_IFTYPE_STATION:
074ac8df 996 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 997 if (!wdev->current_bss)
fffd0934
JB
998 return -ENOLINK;
999 break;
de4fcbad 1000 case NL80211_IFTYPE_UNSPECIFIED:
6e0bd6c3 1001 case NL80211_IFTYPE_OCB:
de4fcbad 1002 case NL80211_IFTYPE_MONITOR:
cb3b7d87 1003 case NL80211_IFTYPE_NAN:
de4fcbad
JB
1004 case NL80211_IFTYPE_P2P_DEVICE:
1005 case NL80211_IFTYPE_WDS:
1006 case NUM_NL80211_IFTYPES:
fffd0934
JB
1007 return -EINVAL;
1008 }
1009
1010 return 0;
1011}
1012
664834de
JM
1013static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
1014 struct nlattr *tb)
1015{
1016 struct ieee80211_channel *chan;
1017
1018 if (tb == NULL)
1019 return NULL;
1020 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb));
1021 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
1022 return NULL;
1023 return chan;
1024}
1025
7527a782
JB
1026static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
1027{
1028 struct nlattr *nl_modes = nla_nest_start(msg, attr);
1029 int i;
1030
1031 if (!nl_modes)
1032 goto nla_put_failure;
1033
1034 i = 0;
1035 while (ifmodes) {
9360ffd1
DM
1036 if ((ifmodes & 1) && nla_put_flag(msg, i))
1037 goto nla_put_failure;
7527a782
JB
1038 ifmodes >>= 1;
1039 i++;
1040 }
1041
1042 nla_nest_end(msg, nl_modes);
1043 return 0;
1044
1045nla_put_failure:
1046 return -ENOBUFS;
1047}
1048
1049static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
1050 struct sk_buff *msg,
1051 bool large)
7527a782
JB
1052{
1053 struct nlattr *nl_combis;
1054 int i, j;
1055
1056 nl_combis = nla_nest_start(msg,
1057 NL80211_ATTR_INTERFACE_COMBINATIONS);
1058 if (!nl_combis)
1059 goto nla_put_failure;
1060
1061 for (i = 0; i < wiphy->n_iface_combinations; i++) {
1062 const struct ieee80211_iface_combination *c;
1063 struct nlattr *nl_combi, *nl_limits;
1064
1065 c = &wiphy->iface_combinations[i];
1066
1067 nl_combi = nla_nest_start(msg, i + 1);
1068 if (!nl_combi)
1069 goto nla_put_failure;
1070
1071 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
1072 if (!nl_limits)
1073 goto nla_put_failure;
1074
1075 for (j = 0; j < c->n_limits; j++) {
1076 struct nlattr *nl_limit;
1077
1078 nl_limit = nla_nest_start(msg, j + 1);
1079 if (!nl_limit)
1080 goto nla_put_failure;
9360ffd1
DM
1081 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
1082 c->limits[j].max))
1083 goto nla_put_failure;
7527a782
JB
1084 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
1085 c->limits[j].types))
1086 goto nla_put_failure;
1087 nla_nest_end(msg, nl_limit);
1088 }
1089
1090 nla_nest_end(msg, nl_limits);
1091
9360ffd1
DM
1092 if (c->beacon_int_infra_match &&
1093 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
1094 goto nla_put_failure;
1095 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
1096 c->num_different_channels) ||
1097 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
1098 c->max_interfaces))
1099 goto nla_put_failure;
cdc89b97 1100 if (large &&
8c48b50a
FF
1101 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
1102 c->radar_detect_widths) ||
1103 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS,
1104 c->radar_detect_regions)))
cdc89b97 1105 goto nla_put_failure;
0c317a02
PK
1106 if (c->beacon_int_min_gcd &&
1107 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD,
1108 c->beacon_int_min_gcd))
1109 goto nla_put_failure;
7527a782
JB
1110
1111 nla_nest_end(msg, nl_combi);
1112 }
1113
1114 nla_nest_end(msg, nl_combis);
1115
1116 return 0;
1117nla_put_failure:
1118 return -ENOBUFS;
1119}
1120
3713b4e3 1121#ifdef CONFIG_PM
b56cf720
JB
1122static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
1123 struct sk_buff *msg)
1124{
964dc9e2 1125 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
1126 struct nlattr *nl_tcp;
1127
1128 if (!tcp)
1129 return 0;
1130
1131 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
1132 if (!nl_tcp)
1133 return -ENOBUFS;
1134
1135 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1136 tcp->data_payload_max))
1137 return -ENOBUFS;
1138
1139 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1140 tcp->data_payload_max))
1141 return -ENOBUFS;
1142
1143 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
1144 return -ENOBUFS;
1145
1146 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
1147 sizeof(*tcp->tok), tcp->tok))
1148 return -ENOBUFS;
1149
1150 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
1151 tcp->data_interval_max))
1152 return -ENOBUFS;
1153
1154 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
1155 tcp->wake_payload_max))
1156 return -ENOBUFS;
1157
1158 nla_nest_end(msg, nl_tcp);
1159 return 0;
1160}
1161
3713b4e3 1162static int nl80211_send_wowlan(struct sk_buff *msg,
1b8ec87a 1163 struct cfg80211_registered_device *rdev,
b56cf720 1164 bool large)
55682965 1165{
3713b4e3 1166 struct nlattr *nl_wowlan;
55682965 1167
1b8ec87a 1168 if (!rdev->wiphy.wowlan)
3713b4e3 1169 return 0;
55682965 1170
3713b4e3
JB
1171 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1172 if (!nl_wowlan)
1173 return -ENOBUFS;
9360ffd1 1174
1b8ec87a 1175 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 1176 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1b8ec87a 1177 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 1178 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1b8ec87a 1179 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 1180 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1b8ec87a 1181 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 1182 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1b8ec87a 1183 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 1184 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1b8ec87a 1185 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 1186 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1b8ec87a 1187 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 1188 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1b8ec87a 1189 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
1190 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1191 return -ENOBUFS;
9360ffd1 1192
1b8ec87a 1193 if (rdev->wiphy.wowlan->n_patterns) {
50ac6607 1194 struct nl80211_pattern_support pat = {
1b8ec87a
ZG
1195 .max_patterns = rdev->wiphy.wowlan->n_patterns,
1196 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len,
1197 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len,
1198 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset,
3713b4e3 1199 };
9360ffd1 1200
3713b4e3
JB
1201 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1202 sizeof(pat), &pat))
1203 return -ENOBUFS;
1204 }
9360ffd1 1205
75453ccb
LC
1206 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) &&
1207 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT,
1208 rdev->wiphy.wowlan->max_nd_match_sets))
1209 return -ENOBUFS;
1210
1b8ec87a 1211 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg))
b56cf720
JB
1212 return -ENOBUFS;
1213
3713b4e3 1214 nla_nest_end(msg, nl_wowlan);
9360ffd1 1215
3713b4e3
JB
1216 return 0;
1217}
1218#endif
9360ffd1 1219
be29b99a 1220static int nl80211_send_coalesce(struct sk_buff *msg,
1b8ec87a 1221 struct cfg80211_registered_device *rdev)
be29b99a
AK
1222{
1223 struct nl80211_coalesce_rule_support rule;
1224
1b8ec87a 1225 if (!rdev->wiphy.coalesce)
be29b99a
AK
1226 return 0;
1227
1b8ec87a
ZG
1228 rule.max_rules = rdev->wiphy.coalesce->n_rules;
1229 rule.max_delay = rdev->wiphy.coalesce->max_delay;
1230 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns;
1231 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len;
1232 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len;
1233 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset;
be29b99a
AK
1234
1235 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1236 return -ENOBUFS;
1237
1238 return 0;
1239}
1240
3713b4e3
JB
1241static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1242 struct ieee80211_supported_band *sband)
1243{
1244 struct nlattr *nl_rates, *nl_rate;
1245 struct ieee80211_rate *rate;
1246 int i;
87bbbe22 1247
3713b4e3
JB
1248 /* add HT info */
1249 if (sband->ht_cap.ht_supported &&
1250 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1251 sizeof(sband->ht_cap.mcs),
1252 &sband->ht_cap.mcs) ||
1253 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1254 sband->ht_cap.cap) ||
1255 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1256 sband->ht_cap.ampdu_factor) ||
1257 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1258 sband->ht_cap.ampdu_density)))
1259 return -ENOBUFS;
afe0cbf8 1260
3713b4e3
JB
1261 /* add VHT info */
1262 if (sband->vht_cap.vht_supported &&
1263 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1264 sizeof(sband->vht_cap.vht_mcs),
1265 &sband->vht_cap.vht_mcs) ||
1266 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1267 sband->vht_cap.cap)))
1268 return -ENOBUFS;
f59ac048 1269
3713b4e3
JB
1270 /* add bitrates */
1271 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1272 if (!nl_rates)
1273 return -ENOBUFS;
ee688b00 1274
3713b4e3
JB
1275 for (i = 0; i < sband->n_bitrates; i++) {
1276 nl_rate = nla_nest_start(msg, i);
1277 if (!nl_rate)
1278 return -ENOBUFS;
ee688b00 1279
3713b4e3
JB
1280 rate = &sband->bitrates[i];
1281 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1282 rate->bitrate))
1283 return -ENOBUFS;
1284 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1285 nla_put_flag(msg,
1286 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1287 return -ENOBUFS;
ee688b00 1288
3713b4e3
JB
1289 nla_nest_end(msg, nl_rate);
1290 }
d51626df 1291
3713b4e3 1292 nla_nest_end(msg, nl_rates);
bf0c111e 1293
3713b4e3
JB
1294 return 0;
1295}
ee688b00 1296
3713b4e3
JB
1297static int
1298nl80211_send_mgmt_stypes(struct sk_buff *msg,
1299 const struct ieee80211_txrx_stypes *mgmt_stypes)
1300{
1301 u16 stypes;
1302 struct nlattr *nl_ftypes, *nl_ifs;
1303 enum nl80211_iftype ift;
1304 int i;
ee688b00 1305
3713b4e3
JB
1306 if (!mgmt_stypes)
1307 return 0;
5dab3b8a 1308
3713b4e3
JB
1309 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1310 if (!nl_ifs)
1311 return -ENOBUFS;
e2f367f2 1312
3713b4e3
JB
1313 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1314 nl_ftypes = nla_nest_start(msg, ift);
1315 if (!nl_ftypes)
1316 return -ENOBUFS;
1317 i = 0;
1318 stypes = mgmt_stypes[ift].tx;
1319 while (stypes) {
1320 if ((stypes & 1) &&
1321 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1322 (i << 4) | IEEE80211_FTYPE_MGMT))
1323 return -ENOBUFS;
1324 stypes >>= 1;
1325 i++;
ee688b00 1326 }
3713b4e3
JB
1327 nla_nest_end(msg, nl_ftypes);
1328 }
ee688b00 1329
3713b4e3 1330 nla_nest_end(msg, nl_ifs);
ee688b00 1331
3713b4e3
JB
1332 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1333 if (!nl_ifs)
1334 return -ENOBUFS;
ee688b00 1335
3713b4e3
JB
1336 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1337 nl_ftypes = nla_nest_start(msg, ift);
1338 if (!nl_ftypes)
1339 return -ENOBUFS;
1340 i = 0;
1341 stypes = mgmt_stypes[ift].rx;
1342 while (stypes) {
1343 if ((stypes & 1) &&
1344 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1345 (i << 4) | IEEE80211_FTYPE_MGMT))
1346 return -ENOBUFS;
1347 stypes >>= 1;
1348 i++;
1349 }
1350 nla_nest_end(msg, nl_ftypes);
1351 }
1352 nla_nest_end(msg, nl_ifs);
ee688b00 1353
3713b4e3
JB
1354 return 0;
1355}
ee688b00 1356
1794899e
JB
1357#define CMD(op, n) \
1358 do { \
1359 if (rdev->ops->op) { \
1360 i++; \
1361 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1362 goto nla_put_failure; \
1363 } \
1364 } while (0)
1365
1366static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev,
1367 struct sk_buff *msg)
1368{
1369 int i = 0;
1370
1371 /*
1372 * do *NOT* add anything into this function, new things need to be
1373 * advertised only to new versions of userspace that can deal with
1374 * the split (and they can't possibly care about new features...
1375 */
1376 CMD(add_virtual_intf, NEW_INTERFACE);
1377 CMD(change_virtual_intf, SET_INTERFACE);
1378 CMD(add_key, NEW_KEY);
1379 CMD(start_ap, START_AP);
1380 CMD(add_station, NEW_STATION);
1381 CMD(add_mpath, NEW_MPATH);
1382 CMD(update_mesh_config, SET_MESH_CONFIG);
1383 CMD(change_bss, SET_BSS);
1384 CMD(auth, AUTHENTICATE);
1385 CMD(assoc, ASSOCIATE);
1386 CMD(deauth, DEAUTHENTICATE);
1387 CMD(disassoc, DISASSOCIATE);
1388 CMD(join_ibss, JOIN_IBSS);
1389 CMD(join_mesh, JOIN_MESH);
1390 CMD(set_pmksa, SET_PMKSA);
1391 CMD(del_pmksa, DEL_PMKSA);
1392 CMD(flush_pmksa, FLUSH_PMKSA);
1393 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1394 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1395 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1396 CMD(mgmt_tx, FRAME);
1397 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1398 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1399 i++;
1400 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1401 goto nla_put_failure;
1402 }
1403 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap ||
1404 rdev->ops->join_mesh) {
1405 i++;
1406 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1407 goto nla_put_failure;
1408 }
1409 CMD(set_wds_peer, SET_WDS_PEER);
1410 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1411 CMD(tdls_mgmt, TDLS_MGMT);
1412 CMD(tdls_oper, TDLS_OPER);
1413 }
ca986ad9 1414 if (rdev->wiphy.max_sched_scan_reqs)
1794899e
JB
1415 CMD(sched_scan_start, START_SCHED_SCAN);
1416 CMD(probe_client, PROBE_CLIENT);
1417 CMD(set_noack_map, SET_NOACK_MAP);
1418 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1419 i++;
1420 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1421 goto nla_put_failure;
1422 }
1423 CMD(start_p2p_device, START_P2P_DEVICE);
1424 CMD(set_mcast_rate, SET_MCAST_RATE);
1425#ifdef CONFIG_NL80211_TESTMODE
1426 CMD(testmode_cmd, TESTMODE);
1427#endif
1428
1429 if (rdev->ops->connect || rdev->ops->auth) {
1430 i++;
1431 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1432 goto nla_put_failure;
1433 }
1434
1435 if (rdev->ops->disconnect || rdev->ops->deauth) {
1436 i++;
1437 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1438 goto nla_put_failure;
1439 }
1440
1441 return i;
1442 nla_put_failure:
1443 return -ENOBUFS;
1444}
1445
86e8cf98
JB
1446struct nl80211_dump_wiphy_state {
1447 s64 filter_wiphy;
1448 long start;
019ae3a9 1449 long split_start, band_start, chan_start, capa_start;
86e8cf98
JB
1450 bool split;
1451};
1452
1b8ec87a 1453static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev,
3bb20556 1454 enum nl80211_commands cmd,
3713b4e3 1455 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 1456 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
1457{
1458 void *hdr;
1459 struct nlattr *nl_bands, *nl_band;
1460 struct nlattr *nl_freqs, *nl_freq;
1461 struct nlattr *nl_cmds;
57fbcce3 1462 enum nl80211_band band;
3713b4e3
JB
1463 struct ieee80211_channel *chan;
1464 int i;
1465 const struct ieee80211_txrx_stypes *mgmt_stypes =
1b8ec87a 1466 rdev->wiphy.mgmt_stypes;
fe1abafd 1467 u32 features;
ee688b00 1468
3bb20556 1469 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
3713b4e3
JB
1470 if (!hdr)
1471 return -ENOBUFS;
ee688b00 1472
86e8cf98
JB
1473 if (WARN_ON(!state))
1474 return -EINVAL;
ee688b00 1475
1b8ec87a 1476 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3713b4e3 1477 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1b8ec87a 1478 wiphy_name(&rdev->wiphy)) ||
3713b4e3
JB
1479 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1480 cfg80211_rdev_list_generation))
8fdc621d
JB
1481 goto nla_put_failure;
1482
3bb20556
JB
1483 if (cmd != NL80211_CMD_NEW_WIPHY)
1484 goto finish;
1485
86e8cf98 1486 switch (state->split_start) {
3713b4e3
JB
1487 case 0:
1488 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1b8ec87a 1489 rdev->wiphy.retry_short) ||
3713b4e3 1490 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1b8ec87a 1491 rdev->wiphy.retry_long) ||
3713b4e3 1492 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1b8ec87a 1493 rdev->wiphy.frag_threshold) ||
3713b4e3 1494 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1b8ec87a 1495 rdev->wiphy.rts_threshold) ||
3713b4e3 1496 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1b8ec87a 1497 rdev->wiphy.coverage_class) ||
3713b4e3 1498 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1b8ec87a 1499 rdev->wiphy.max_scan_ssids) ||
3713b4e3 1500 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1b8ec87a 1501 rdev->wiphy.max_sched_scan_ssids) ||
3713b4e3 1502 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1b8ec87a 1503 rdev->wiphy.max_scan_ie_len) ||
3713b4e3 1504 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1b8ec87a 1505 rdev->wiphy.max_sched_scan_ie_len) ||
3713b4e3 1506 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
3b06d277
AS
1507 rdev->wiphy.max_match_sets) ||
1508 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS,
1509 rdev->wiphy.max_sched_scan_plans) ||
1510 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL,
1511 rdev->wiphy.max_sched_scan_plan_interval) ||
1512 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS,
1513 rdev->wiphy.max_sched_scan_plan_iterations))
9360ffd1 1514 goto nla_put_failure;
3713b4e3 1515
1b8ec87a 1516 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
3713b4e3 1517 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1518 goto nla_put_failure;
1b8ec87a 1519 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
3713b4e3
JB
1520 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1521 goto nla_put_failure;
1b8ec87a 1522 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3713b4e3
JB
1523 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1524 goto nla_put_failure;
1b8ec87a 1525 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
3713b4e3
JB
1526 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1527 goto nla_put_failure;
1b8ec87a 1528 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
3713b4e3
JB
1529 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1530 goto nla_put_failure;
1b8ec87a 1531 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
3713b4e3 1532 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1533 goto nla_put_failure;
86e8cf98
JB
1534 state->split_start++;
1535 if (state->split)
3713b4e3
JB
1536 break;
1537 case 1:
1538 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1b8ec87a
ZG
1539 sizeof(u32) * rdev->wiphy.n_cipher_suites,
1540 rdev->wiphy.cipher_suites))
3713b4e3 1541 goto nla_put_failure;
4745fc09 1542
3713b4e3 1543 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1b8ec87a 1544 rdev->wiphy.max_num_pmkids))
3713b4e3 1545 goto nla_put_failure;
b23aa676 1546
1b8ec87a 1547 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3713b4e3 1548 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1549 goto nla_put_failure;
b23aa676 1550
3713b4e3 1551 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1b8ec87a 1552 rdev->wiphy.available_antennas_tx) ||
3713b4e3 1553 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1b8ec87a 1554 rdev->wiphy.available_antennas_rx))
9360ffd1 1555 goto nla_put_failure;
b23aa676 1556
1b8ec87a 1557 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
3713b4e3 1558 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1b8ec87a 1559 rdev->wiphy.probe_resp_offload))
3713b4e3 1560 goto nla_put_failure;
8fdc621d 1561
1b8ec87a
ZG
1562 if ((rdev->wiphy.available_antennas_tx ||
1563 rdev->wiphy.available_antennas_rx) &&
1564 rdev->ops->get_antenna) {
3713b4e3
JB
1565 u32 tx_ant = 0, rx_ant = 0;
1566 int res;
7a087e74 1567
1b8ec87a 1568 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant);
3713b4e3
JB
1569 if (!res) {
1570 if (nla_put_u32(msg,
1571 NL80211_ATTR_WIPHY_ANTENNA_TX,
1572 tx_ant) ||
1573 nla_put_u32(msg,
1574 NL80211_ATTR_WIPHY_ANTENNA_RX,
1575 rx_ant))
1576 goto nla_put_failure;
1577 }
1578 }
a293911d 1579
86e8cf98
JB
1580 state->split_start++;
1581 if (state->split)
3713b4e3
JB
1582 break;
1583 case 2:
1584 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1b8ec87a 1585 rdev->wiphy.interface_modes))
3713b4e3 1586 goto nla_put_failure;
86e8cf98
JB
1587 state->split_start++;
1588 if (state->split)
3713b4e3
JB
1589 break;
1590 case 3:
1591 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
1592 if (!nl_bands)
1593 goto nla_put_failure;
f7ca38df 1594
86e8cf98 1595 for (band = state->band_start;
57fbcce3 1596 band < NUM_NL80211_BANDS; band++) {
3713b4e3 1597 struct ieee80211_supported_band *sband;
2e161f78 1598
1b8ec87a 1599 sband = rdev->wiphy.bands[band];
2e161f78 1600
3713b4e3
JB
1601 if (!sband)
1602 continue;
1603
1604 nl_band = nla_nest_start(msg, band);
1605 if (!nl_band)
2e161f78 1606 goto nla_put_failure;
3713b4e3 1607
86e8cf98 1608 switch (state->chan_start) {
3713b4e3
JB
1609 case 0:
1610 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 1611 goto nla_put_failure;
86e8cf98
JB
1612 state->chan_start++;
1613 if (state->split)
3713b4e3
JB
1614 break;
1615 default:
1616 /* add frequencies */
1617 nl_freqs = nla_nest_start(
1618 msg, NL80211_BAND_ATTR_FREQS);
1619 if (!nl_freqs)
1620 goto nla_put_failure;
1621
86e8cf98 1622 for (i = state->chan_start - 1;
3713b4e3
JB
1623 i < sband->n_channels;
1624 i++) {
1625 nl_freq = nla_nest_start(msg, i);
1626 if (!nl_freq)
1627 goto nla_put_failure;
1628
1629 chan = &sband->channels[i];
1630
86e8cf98
JB
1631 if (nl80211_msg_put_channel(
1632 msg, chan,
1633 state->split))
3713b4e3
JB
1634 goto nla_put_failure;
1635
1636 nla_nest_end(msg, nl_freq);
86e8cf98 1637 if (state->split)
3713b4e3
JB
1638 break;
1639 }
1640 if (i < sband->n_channels)
86e8cf98 1641 state->chan_start = i + 2;
3713b4e3 1642 else
86e8cf98 1643 state->chan_start = 0;
3713b4e3
JB
1644 nla_nest_end(msg, nl_freqs);
1645 }
1646
1647 nla_nest_end(msg, nl_band);
1648
86e8cf98 1649 if (state->split) {
3713b4e3 1650 /* start again here */
86e8cf98 1651 if (state->chan_start)
3713b4e3
JB
1652 band--;
1653 break;
2e161f78 1654 }
2e161f78 1655 }
3713b4e3 1656 nla_nest_end(msg, nl_bands);
2e161f78 1657
57fbcce3 1658 if (band < NUM_NL80211_BANDS)
86e8cf98 1659 state->band_start = band + 1;
3713b4e3 1660 else
86e8cf98 1661 state->band_start = 0;
74b70a4e 1662
3713b4e3 1663 /* if bands & channels are done, continue outside */
86e8cf98
JB
1664 if (state->band_start == 0 && state->chan_start == 0)
1665 state->split_start++;
1666 if (state->split)
3713b4e3
JB
1667 break;
1668 case 4:
1669 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1670 if (!nl_cmds)
2e161f78
JB
1671 goto nla_put_failure;
1672
1794899e
JB
1673 i = nl80211_add_commands_unsplit(rdev, msg);
1674 if (i < 0)
1675 goto nla_put_failure;
86e8cf98 1676 if (state->split) {
5de17984
AS
1677 CMD(crit_proto_start, CRIT_PROTOCOL_START);
1678 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
1b8ec87a 1679 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
16ef1fe2 1680 CMD(channel_switch, CHANNEL_SWITCH);
02df00eb 1681 CMD(set_qos_map, SET_QOS_MAP);
723e73ac
JB
1682 if (rdev->wiphy.features &
1683 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)
960d01ac 1684 CMD(add_tx_ts, ADD_TX_TS);
ce0ce13a 1685 CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST);
088e8df8 1686 CMD(update_connect_params, UPDATE_CONNECT_PARAMS);
5de17984 1687 }
3713b4e3 1688#undef CMD
ff1b6e69 1689
3713b4e3 1690 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
1691 state->split_start++;
1692 if (state->split)
3713b4e3
JB
1693 break;
1694 case 5:
1b8ec87a
ZG
1695 if (rdev->ops->remain_on_channel &&
1696 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
3713b4e3
JB
1697 nla_put_u32(msg,
1698 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1b8ec87a 1699 rdev->wiphy.max_remain_on_channel_duration))
3713b4e3
JB
1700 goto nla_put_failure;
1701
1b8ec87a 1702 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
3713b4e3
JB
1703 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1704 goto nla_put_failure;
1705
1706 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
1707 goto nla_put_failure;
86e8cf98
JB
1708 state->split_start++;
1709 if (state->split)
3713b4e3
JB
1710 break;
1711 case 6:
1712#ifdef CONFIG_PM
1b8ec87a 1713 if (nl80211_send_wowlan(msg, rdev, state->split))
3713b4e3 1714 goto nla_put_failure;
86e8cf98
JB
1715 state->split_start++;
1716 if (state->split)
3713b4e3
JB
1717 break;
1718#else
86e8cf98 1719 state->split_start++;
dfb89c56 1720#endif
3713b4e3
JB
1721 case 7:
1722 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1b8ec87a 1723 rdev->wiphy.software_iftypes))
3713b4e3 1724 goto nla_put_failure;
ff1b6e69 1725
1b8ec87a 1726 if (nl80211_put_iface_combinations(&rdev->wiphy, msg,
86e8cf98 1727 state->split))
3713b4e3 1728 goto nla_put_failure;
7527a782 1729
86e8cf98
JB
1730 state->split_start++;
1731 if (state->split)
3713b4e3
JB
1732 break;
1733 case 8:
1b8ec87a 1734 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
3713b4e3 1735 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1b8ec87a 1736 rdev->wiphy.ap_sme_capa))
3713b4e3 1737 goto nla_put_failure;
7527a782 1738
1b8ec87a 1739 features = rdev->wiphy.features;
fe1abafd
JB
1740 /*
1741 * We can only add the per-channel limit information if the
1742 * dump is split, otherwise it makes it too big. Therefore
1743 * only advertise it in that case.
1744 */
86e8cf98 1745 if (state->split)
fe1abafd
JB
1746 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
1747 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 1748 goto nla_put_failure;
562a7480 1749
1b8ec87a 1750 if (rdev->wiphy.ht_capa_mod_mask &&
3713b4e3 1751 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1b8ec87a
ZG
1752 sizeof(*rdev->wiphy.ht_capa_mod_mask),
1753 rdev->wiphy.ht_capa_mod_mask))
3713b4e3 1754 goto nla_put_failure;
1f074bd8 1755
1b8ec87a
ZG
1756 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
1757 rdev->wiphy.max_acl_mac_addrs &&
3713b4e3 1758 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1b8ec87a 1759 rdev->wiphy.max_acl_mac_addrs))
3713b4e3 1760 goto nla_put_failure;
7e7c8926 1761
3713b4e3
JB
1762 /*
1763 * Any information below this point is only available to
1764 * applications that can deal with it being split. This
1765 * helps ensure that newly added capabilities don't break
1766 * older tools by overrunning their buffers.
1767 *
1768 * We still increment split_start so that in the split
1769 * case we'll continue with more data in the next round,
1770 * but break unconditionally so unsplit data stops here.
1771 */
86e8cf98 1772 state->split_start++;
3713b4e3
JB
1773 break;
1774 case 9:
1b8ec87a 1775 if (rdev->wiphy.extended_capabilities &&
fe1abafd 1776 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1b8ec87a
ZG
1777 rdev->wiphy.extended_capabilities_len,
1778 rdev->wiphy.extended_capabilities) ||
fe1abafd 1779 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1b8ec87a
ZG
1780 rdev->wiphy.extended_capabilities_len,
1781 rdev->wiphy.extended_capabilities_mask)))
fe1abafd 1782 goto nla_put_failure;
a50df0c4 1783
1b8ec87a 1784 if (rdev->wiphy.vht_capa_mod_mask &&
ee2aca34 1785 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1b8ec87a
ZG
1786 sizeof(*rdev->wiphy.vht_capa_mod_mask),
1787 rdev->wiphy.vht_capa_mod_mask))
ee2aca34
JB
1788 goto nla_put_failure;
1789
be29b99a
AK
1790 state->split_start++;
1791 break;
1792 case 10:
1b8ec87a 1793 if (nl80211_send_coalesce(msg, rdev))
be29b99a
AK
1794 goto nla_put_failure;
1795
1b8ec87a 1796 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
01e0daa4
FF
1797 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
1798 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
1799 goto nla_put_failure;
b43504cf 1800
1b8ec87a 1801 if (rdev->wiphy.max_ap_assoc_sta &&
b43504cf 1802 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
1b8ec87a 1803 rdev->wiphy.max_ap_assoc_sta))
b43504cf
JM
1804 goto nla_put_failure;
1805
ad7e718c
JB
1806 state->split_start++;
1807 break;
1808 case 11:
1b8ec87a 1809 if (rdev->wiphy.n_vendor_commands) {
567ffc35
JB
1810 const struct nl80211_vendor_cmd_info *info;
1811 struct nlattr *nested;
1812
1813 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA);
1814 if (!nested)
1815 goto nla_put_failure;
1816
1b8ec87a
ZG
1817 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
1818 info = &rdev->wiphy.vendor_commands[i].info;
567ffc35
JB
1819 if (nla_put(msg, i + 1, sizeof(*info), info))
1820 goto nla_put_failure;
1821 }
1822 nla_nest_end(msg, nested);
1823 }
1824
1b8ec87a 1825 if (rdev->wiphy.n_vendor_events) {
567ffc35
JB
1826 const struct nl80211_vendor_cmd_info *info;
1827 struct nlattr *nested;
ad7e718c 1828
567ffc35
JB
1829 nested = nla_nest_start(msg,
1830 NL80211_ATTR_VENDOR_EVENTS);
1831 if (!nested)
ad7e718c 1832 goto nla_put_failure;
567ffc35 1833
1b8ec87a
ZG
1834 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) {
1835 info = &rdev->wiphy.vendor_events[i];
567ffc35
JB
1836 if (nla_put(msg, i + 1, sizeof(*info), info))
1837 goto nla_put_failure;
1838 }
1839 nla_nest_end(msg, nested);
1840 }
9a774c78
AO
1841 state->split_start++;
1842 break;
1843 case 12:
1844 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH &&
1845 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS,
1846 rdev->wiphy.max_num_csa_counters))
1847 goto nla_put_failure;
01e0daa4 1848
1bdd716c
AN
1849 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
1850 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
1851 goto nla_put_failure;
1852
ca986ad9
AVS
1853 if (rdev->wiphy.max_sched_scan_reqs &&
1854 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_MAX_REQS,
1855 rdev->wiphy.max_sched_scan_reqs))
1856 goto nla_put_failure;
1857
d75bb06b
GKS
1858 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES,
1859 sizeof(rdev->wiphy.ext_features),
1860 rdev->wiphy.ext_features))
1861 goto nla_put_failure;
1862
38de03d2
AS
1863 if (rdev->wiphy.bss_select_support) {
1864 struct nlattr *nested;
1865 u32 bss_select_support = rdev->wiphy.bss_select_support;
1866
1867 nested = nla_nest_start(msg, NL80211_ATTR_BSS_SELECT);
1868 if (!nested)
1869 goto nla_put_failure;
1870
1871 i = 0;
1872 while (bss_select_support) {
1873 if ((bss_select_support & 1) &&
1874 nla_put_flag(msg, i))
1875 goto nla_put_failure;
1876 i++;
1877 bss_select_support >>= 1;
1878 }
1879 nla_nest_end(msg, nested);
1880 }
1881
019ae3a9
KV
1882 state->split_start++;
1883 break;
1884 case 13:
1885 if (rdev->wiphy.num_iftype_ext_capab &&
1886 rdev->wiphy.iftype_ext_capab) {
1887 struct nlattr *nested_ext_capab, *nested;
1888
1889 nested = nla_nest_start(msg,
1890 NL80211_ATTR_IFTYPE_EXT_CAPA);
1891 if (!nested)
1892 goto nla_put_failure;
1893
1894 for (i = state->capa_start;
1895 i < rdev->wiphy.num_iftype_ext_capab; i++) {
1896 const struct wiphy_iftype_ext_capab *capab;
1897
1898 capab = &rdev->wiphy.iftype_ext_capab[i];
1899
1900 nested_ext_capab = nla_nest_start(msg, i);
1901 if (!nested_ext_capab ||
1902 nla_put_u32(msg, NL80211_ATTR_IFTYPE,
1903 capab->iftype) ||
1904 nla_put(msg, NL80211_ATTR_EXT_CAPA,
1905 capab->extended_capabilities_len,
1906 capab->extended_capabilities) ||
1907 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1908 capab->extended_capabilities_len,
1909 capab->extended_capabilities_mask))
1910 goto nla_put_failure;
1911
1912 nla_nest_end(msg, nested_ext_capab);
1913 if (state->split)
1914 break;
1915 }
1916 nla_nest_end(msg, nested);
1917 if (i < rdev->wiphy.num_iftype_ext_capab) {
1918 state->capa_start = i + 1;
1919 break;
1920 }
1921 }
1922
8585989d
LC
1923 if (nla_put_u32(msg, NL80211_ATTR_BANDS,
1924 rdev->wiphy.nan_supported_bands))
1925 goto nla_put_failure;
1926
3713b4e3 1927 /* done */
86e8cf98 1928 state->split_start = 0;
3713b4e3
JB
1929 break;
1930 }
3bb20556 1931 finish:
053c095a
JB
1932 genlmsg_end(msg, hdr);
1933 return 0;
55682965
JB
1934
1935 nla_put_failure:
bc3ed28c
TG
1936 genlmsg_cancel(msg, hdr);
1937 return -EMSGSIZE;
55682965
JB
1938}
1939
86e8cf98
JB
1940static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
1941 struct netlink_callback *cb,
1942 struct nl80211_dump_wiphy_state *state)
1943{
c90c39da 1944 struct nlattr **tb = genl_family_attrbuf(&nl80211_fam);
fceb6435
JB
1945 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, tb,
1946 nl80211_fam.maxattr, nl80211_policy, NULL);
86e8cf98
JB
1947 /* ignore parse errors for backward compatibility */
1948 if (ret)
1949 return 0;
1950
1951 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
1952 if (tb[NL80211_ATTR_WIPHY])
1953 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
1954 if (tb[NL80211_ATTR_WDEV])
1955 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
1956 if (tb[NL80211_ATTR_IFINDEX]) {
1957 struct net_device *netdev;
1958 struct cfg80211_registered_device *rdev;
1959 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
1960
7f2b8562 1961 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
86e8cf98
JB
1962 if (!netdev)
1963 return -ENODEV;
1964 if (netdev->ieee80211_ptr) {
f26cbf40 1965 rdev = wiphy_to_rdev(
86e8cf98
JB
1966 netdev->ieee80211_ptr->wiphy);
1967 state->filter_wiphy = rdev->wiphy_idx;
1968 }
86e8cf98
JB
1969 }
1970
1971 return 0;
1972}
1973
55682965
JB
1974static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1975{
645e77de 1976 int idx = 0, ret;
86e8cf98 1977 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
1b8ec87a 1978 struct cfg80211_registered_device *rdev;
3a5a423b 1979
5fe231e8 1980 rtnl_lock();
86e8cf98
JB
1981 if (!state) {
1982 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
1983 if (!state) {
1984 rtnl_unlock();
86e8cf98 1985 return -ENOMEM;
3713b4e3 1986 }
86e8cf98
JB
1987 state->filter_wiphy = -1;
1988 ret = nl80211_dump_wiphy_parse(skb, cb, state);
1989 if (ret) {
1990 kfree(state);
1991 rtnl_unlock();
1992 return ret;
3713b4e3 1993 }
86e8cf98 1994 cb->args[0] = (long)state;
3713b4e3
JB
1995 }
1996
1b8ec87a
ZG
1997 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1998 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1999 continue;
86e8cf98 2000 if (++idx <= state->start)
55682965 2001 continue;
86e8cf98 2002 if (state->filter_wiphy != -1 &&
1b8ec87a 2003 state->filter_wiphy != rdev->wiphy_idx)
3713b4e3
JB
2004 continue;
2005 /* attempt to fit multiple wiphy data chunks into the skb */
2006 do {
3bb20556
JB
2007 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY,
2008 skb,
3713b4e3
JB
2009 NETLINK_CB(cb->skb).portid,
2010 cb->nlh->nlmsg_seq,
86e8cf98 2011 NLM_F_MULTI, state);
3713b4e3
JB
2012 if (ret < 0) {
2013 /*
2014 * If sending the wiphy data didn't fit (ENOBUFS
2015 * or EMSGSIZE returned), this SKB is still
2016 * empty (so it's not too big because another
2017 * wiphy dataset is already in the skb) and
2018 * we've not tried to adjust the dump allocation
2019 * yet ... then adjust the alloc size to be
2020 * bigger, and return 1 but with the empty skb.
2021 * This results in an empty message being RX'ed
2022 * in userspace, but that is ignored.
2023 *
2024 * We can then retry with the larger buffer.
2025 */
2026 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
f12cb289 2027 !skb->len && !state->split &&
3713b4e3
JB
2028 cb->min_dump_alloc < 4096) {
2029 cb->min_dump_alloc = 4096;
f12cb289 2030 state->split_start = 0;
d98cae64 2031 rtnl_unlock();
3713b4e3
JB
2032 return 1;
2033 }
2034 idx--;
2035 break;
645e77de 2036 }
86e8cf98 2037 } while (state->split_start > 0);
3713b4e3 2038 break;
55682965 2039 }
5fe231e8 2040 rtnl_unlock();
55682965 2041
86e8cf98 2042 state->start = idx;
55682965
JB
2043
2044 return skb->len;
2045}
2046
86e8cf98
JB
2047static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
2048{
2049 kfree((void *)cb->args[0]);
2050 return 0;
2051}
2052
55682965
JB
2053static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
2054{
2055 struct sk_buff *msg;
1b8ec87a 2056 struct cfg80211_registered_device *rdev = info->user_ptr[0];
86e8cf98 2057 struct nl80211_dump_wiphy_state state = {};
55682965 2058
645e77de 2059 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 2060 if (!msg)
4c476991 2061 return -ENOMEM;
55682965 2062
3bb20556
JB
2063 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg,
2064 info->snd_portid, info->snd_seq, 0,
86e8cf98 2065 &state) < 0) {
4c476991
JB
2066 nlmsg_free(msg);
2067 return -ENOBUFS;
2068 }
55682965 2069
134e6375 2070 return genlmsg_reply(msg, info);
55682965
JB
2071}
2072
31888487
JM
2073static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
2074 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
2075 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
2076 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
2077 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
2078 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
2079};
2080
2081static int parse_txq_params(struct nlattr *tb[],
2082 struct ieee80211_txq_params *txq_params)
2083{
a3304b0a 2084 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
2085 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
2086 !tb[NL80211_TXQ_ATTR_AIFS])
2087 return -EINVAL;
2088
a3304b0a 2089 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
2090 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
2091 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
2092 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
2093 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
2094
a3304b0a
JB
2095 if (txq_params->ac >= NL80211_NUM_ACS)
2096 return -EINVAL;
2097
31888487
JM
2098 return 0;
2099}
2100
f444de05
JB
2101static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
2102{
2103 /*
cc1d2806
JB
2104 * You can only set the channel explicitly for WDS interfaces,
2105 * all others have their channel managed via their respective
2106 * "establish a connection" command (connect, join, ...)
2107 *
2108 * For AP/GO and mesh mode, the channel can be set with the
2109 * channel userspace API, but is only stored and passed to the
2110 * low-level driver when the AP starts or the mesh is joined.
2111 * This is for backward compatibility, userspace can also give
2112 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
2113 *
2114 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
2115 * whatever else is going on, so they have their own special
2116 * operation to set the monitor channel if possible.
f444de05
JB
2117 */
2118 return !wdev ||
2119 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 2120 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
2121 wdev->iftype == NL80211_IFTYPE_MONITOR ||
2122 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
2123}
2124
683b6d3b
JB
2125static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
2126 struct genl_info *info,
2127 struct cfg80211_chan_def *chandef)
2128{
dbeca2ea 2129 u32 control_freq;
683b6d3b
JB
2130
2131 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
2132 return -EINVAL;
2133
2134 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
2135
2136 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
2137 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
2138 chandef->center_freq1 = control_freq;
2139 chandef->center_freq2 = 0;
683b6d3b
JB
2140
2141 /* Primary channel not allowed */
2142 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED)
2143 return -EINVAL;
2144
3d9d1d66
JB
2145 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
2146 enum nl80211_channel_type chantype;
2147
2148 chantype = nla_get_u32(
2149 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
2150
2151 switch (chantype) {
2152 case NL80211_CHAN_NO_HT:
2153 case NL80211_CHAN_HT20:
2154 case NL80211_CHAN_HT40PLUS:
2155 case NL80211_CHAN_HT40MINUS:
2156 cfg80211_chandef_create(chandef, chandef->chan,
2157 chantype);
ffa4629e
TM
2158 /* user input for center_freq is incorrect */
2159 if (info->attrs[NL80211_ATTR_CENTER_FREQ1] &&
2160 chandef->center_freq1 != nla_get_u32(
2161 info->attrs[NL80211_ATTR_CENTER_FREQ1]))
2162 return -EINVAL;
2163 /* center_freq2 must be zero */
2164 if (info->attrs[NL80211_ATTR_CENTER_FREQ2] &&
2165 nla_get_u32(info->attrs[NL80211_ATTR_CENTER_FREQ2]))
2166 return -EINVAL;
3d9d1d66
JB
2167 break;
2168 default:
2169 return -EINVAL;
2170 }
2171 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
2172 chandef->width =
2173 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]);
2174 if (info->attrs[NL80211_ATTR_CENTER_FREQ1])
2175 chandef->center_freq1 =
2176 nla_get_u32(
2177 info->attrs[NL80211_ATTR_CENTER_FREQ1]);
2178 if (info->attrs[NL80211_ATTR_CENTER_FREQ2])
2179 chandef->center_freq2 =
2180 nla_get_u32(
2181 info->attrs[NL80211_ATTR_CENTER_FREQ2]);
2182 }
2183
9f5e8f6e 2184 if (!cfg80211_chandef_valid(chandef))
3d9d1d66
JB
2185 return -EINVAL;
2186
9f5e8f6e
JB
2187 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
2188 IEEE80211_CHAN_DISABLED))
3d9d1d66
JB
2189 return -EINVAL;
2190
2f301ab2
SW
2191 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
2192 chandef->width == NL80211_CHAN_WIDTH_10) &&
2193 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ))
2194 return -EINVAL;
2195
683b6d3b
JB
2196 return 0;
2197}
2198
f444de05 2199static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
e16821bc 2200 struct net_device *dev,
f444de05
JB
2201 struct genl_info *info)
2202{
683b6d3b 2203 struct cfg80211_chan_def chandef;
f444de05 2204 int result;
e8c9bd5b 2205 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
e16821bc 2206 struct wireless_dev *wdev = NULL;
e8c9bd5b 2207
e16821bc
JM
2208 if (dev)
2209 wdev = dev->ieee80211_ptr;
f444de05
JB
2210 if (!nl80211_can_set_dev_channel(wdev))
2211 return -EOPNOTSUPP;
e16821bc
JM
2212 if (wdev)
2213 iftype = wdev->iftype;
f444de05 2214
683b6d3b
JB
2215 result = nl80211_parse_chandef(rdev, info, &chandef);
2216 if (result)
2217 return result;
f444de05 2218
e8c9bd5b 2219 switch (iftype) {
aa430da4
JB
2220 case NL80211_IFTYPE_AP:
2221 case NL80211_IFTYPE_P2P_GO:
923b352f
AN
2222 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
2223 iftype)) {
aa430da4
JB
2224 result = -EINVAL;
2225 break;
2226 }
e16821bc
JM
2227 if (wdev->beacon_interval) {
2228 if (!dev || !rdev->ops->set_ap_chanwidth ||
2229 !(rdev->wiphy.features &
2230 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) {
2231 result = -EBUSY;
2232 break;
2233 }
2234
2235 /* Only allow dynamic channel width changes */
2236 if (chandef.chan != wdev->preset_chandef.chan) {
2237 result = -EBUSY;
2238 break;
2239 }
2240 result = rdev_set_ap_chanwidth(rdev, dev, &chandef);
2241 if (result)
2242 break;
2243 }
683b6d3b 2244 wdev->preset_chandef = chandef;
aa430da4
JB
2245 result = 0;
2246 break;
cc1d2806 2247 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 2248 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 2249 break;
e8c9bd5b 2250 case NL80211_IFTYPE_MONITOR:
683b6d3b 2251 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 2252 break;
aa430da4 2253 default:
e8c9bd5b 2254 result = -EINVAL;
f444de05 2255 }
f444de05
JB
2256
2257 return result;
2258}
2259
2260static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
2261{
4c476991
JB
2262 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2263 struct net_device *netdev = info->user_ptr[1];
f444de05 2264
e16821bc 2265 return __nl80211_set_channel(rdev, netdev, info);
f444de05
JB
2266}
2267
e8347eba
BJ
2268static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
2269{
43b19952
JB
2270 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2271 struct net_device *dev = info->user_ptr[1];
2272 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 2273 const u8 *bssid;
e8347eba
BJ
2274
2275 if (!info->attrs[NL80211_ATTR_MAC])
2276 return -EINVAL;
2277
43b19952
JB
2278 if (netif_running(dev))
2279 return -EBUSY;
e8347eba 2280
43b19952
JB
2281 if (!rdev->ops->set_wds_peer)
2282 return -EOPNOTSUPP;
e8347eba 2283
43b19952
JB
2284 if (wdev->iftype != NL80211_IFTYPE_WDS)
2285 return -EOPNOTSUPP;
e8347eba
BJ
2286
2287 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 2288 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
2289}
2290
55682965
JB
2291static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
2292{
2293 struct cfg80211_registered_device *rdev;
f444de05
JB
2294 struct net_device *netdev = NULL;
2295 struct wireless_dev *wdev;
a1e567c8 2296 int result = 0, rem_txq_params = 0;
31888487 2297 struct nlattr *nl_txq_params;
b9a5f8ca
JM
2298 u32 changed;
2299 u8 retry_short = 0, retry_long = 0;
2300 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 2301 u8 coverage_class = 0;
55682965 2302
5fe231e8
JB
2303 ASSERT_RTNL();
2304
f444de05
JB
2305 /*
2306 * Try to find the wiphy and netdev. Normally this
2307 * function shouldn't need the netdev, but this is
2308 * done for backward compatibility -- previously
2309 * setting the channel was done per wiphy, but now
2310 * it is per netdev. Previous userland like hostapd
2311 * also passed a netdev to set_wiphy, so that it is
2312 * possible to let that go to the right netdev!
2313 */
4bbf4d56 2314
f444de05
JB
2315 if (info->attrs[NL80211_ATTR_IFINDEX]) {
2316 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
2317
7f2b8562 2318 netdev = __dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 2319 if (netdev && netdev->ieee80211_ptr)
f26cbf40 2320 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy);
5fe231e8 2321 else
f444de05 2322 netdev = NULL;
4bbf4d56
JB
2323 }
2324
f444de05 2325 if (!netdev) {
878d9ec7
JB
2326 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
2327 info->attrs);
5fe231e8 2328 if (IS_ERR(rdev))
4c476991 2329 return PTR_ERR(rdev);
f444de05
JB
2330 wdev = NULL;
2331 netdev = NULL;
2332 result = 0;
71fe96bf 2333 } else
f444de05 2334 wdev = netdev->ieee80211_ptr;
f444de05
JB
2335
2336 /*
2337 * end workaround code, by now the rdev is available
2338 * and locked, and wdev may or may not be NULL.
2339 */
4bbf4d56
JB
2340
2341 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
2342 result = cfg80211_dev_rename(
2343 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 2344
4bbf4d56 2345 if (result)
7f2b8562 2346 return result;
31888487
JM
2347
2348 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
2349 struct ieee80211_txq_params txq_params;
2350 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
2351
7f2b8562
YX
2352 if (!rdev->ops->set_txq_params)
2353 return -EOPNOTSUPP;
31888487 2354
7f2b8562
YX
2355 if (!netdev)
2356 return -EINVAL;
f70f01c2 2357
133a3ff2 2358 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7f2b8562
YX
2359 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2360 return -EINVAL;
133a3ff2 2361
7f2b8562
YX
2362 if (!netif_running(netdev))
2363 return -ENETDOWN;
2b5f8b0b 2364
31888487
JM
2365 nla_for_each_nested(nl_txq_params,
2366 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
2367 rem_txq_params) {
bfe2c7b1
JB
2368 result = nla_parse_nested(tb, NL80211_TXQ_ATTR_MAX,
2369 nl_txq_params,
fe52145f
JB
2370 txq_params_policy,
2371 info->extack);
ae811e21
JB
2372 if (result)
2373 return result;
31888487
JM
2374 result = parse_txq_params(tb, &txq_params);
2375 if (result)
7f2b8562 2376 return result;
31888487 2377
e35e4d28
HG
2378 result = rdev_set_txq_params(rdev, netdev,
2379 &txq_params);
31888487 2380 if (result)
7f2b8562 2381 return result;
31888487
JM
2382 }
2383 }
55682965 2384
72bdcf34 2385 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
e16821bc
JM
2386 result = __nl80211_set_channel(
2387 rdev,
2388 nl80211_can_set_dev_channel(wdev) ? netdev : NULL,
2389 info);
72bdcf34 2390 if (result)
7f2b8562 2391 return result;
72bdcf34
JM
2392 }
2393
98d2ff8b 2394 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 2395 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
2396 enum nl80211_tx_power_setting type;
2397 int idx, mbm = 0;
2398
c8442118
JB
2399 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
2400 txp_wdev = NULL;
2401
7f2b8562
YX
2402 if (!rdev->ops->set_tx_power)
2403 return -EOPNOTSUPP;
98d2ff8b
JO
2404
2405 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
2406 type = nla_get_u32(info->attrs[idx]);
2407
2408 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
7f2b8562
YX
2409 (type != NL80211_TX_POWER_AUTOMATIC))
2410 return -EINVAL;
98d2ff8b
JO
2411
2412 if (type != NL80211_TX_POWER_AUTOMATIC) {
2413 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
2414 mbm = nla_get_u32(info->attrs[idx]);
2415 }
2416
c8442118 2417 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b 2418 if (result)
7f2b8562 2419 return result;
98d2ff8b
JO
2420 }
2421
afe0cbf8
BR
2422 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
2423 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
2424 u32 tx_ant, rx_ant;
7a087e74 2425
7f531e03
BR
2426 if ((!rdev->wiphy.available_antennas_tx &&
2427 !rdev->wiphy.available_antennas_rx) ||
7f2b8562
YX
2428 !rdev->ops->set_antenna)
2429 return -EOPNOTSUPP;
afe0cbf8
BR
2430
2431 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
2432 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
2433
a7ffac95 2434 /* reject antenna configurations which don't match the
7f531e03
BR
2435 * available antenna masks, except for the "all" mask */
2436 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
7f2b8562
YX
2437 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx)))
2438 return -EINVAL;
a7ffac95 2439
7f531e03
BR
2440 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
2441 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 2442
e35e4d28 2443 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8 2444 if (result)
7f2b8562 2445 return result;
afe0cbf8
BR
2446 }
2447
b9a5f8ca
JM
2448 changed = 0;
2449
2450 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
2451 retry_short = nla_get_u8(
2452 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
7f2b8562
YX
2453 if (retry_short == 0)
2454 return -EINVAL;
2455
b9a5f8ca
JM
2456 changed |= WIPHY_PARAM_RETRY_SHORT;
2457 }
2458
2459 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2460 retry_long = nla_get_u8(
2461 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
7f2b8562
YX
2462 if (retry_long == 0)
2463 return -EINVAL;
2464
b9a5f8ca
JM
2465 changed |= WIPHY_PARAM_RETRY_LONG;
2466 }
2467
2468 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2469 frag_threshold = nla_get_u32(
2470 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
7f2b8562
YX
2471 if (frag_threshold < 256)
2472 return -EINVAL;
2473
b9a5f8ca
JM
2474 if (frag_threshold != (u32) -1) {
2475 /*
2476 * Fragments (apart from the last one) are required to
2477 * have even length. Make the fragmentation code
2478 * simpler by stripping LSB should someone try to use
2479 * odd threshold value.
2480 */
2481 frag_threshold &= ~0x1;
2482 }
2483 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2484 }
2485
2486 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2487 rts_threshold = nla_get_u32(
2488 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2489 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2490 }
2491
81077e82 2492 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
3057dbfd
LB
2493 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK])
2494 return -EINVAL;
2495
81077e82
LT
2496 coverage_class = nla_get_u8(
2497 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2498 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2499 }
2500
3057dbfd
LB
2501 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
2502 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION))
2503 return -EOPNOTSUPP;
2504
2505 changed |= WIPHY_PARAM_DYN_ACK;
81077e82
LT
2506 }
2507
b9a5f8ca
JM
2508 if (changed) {
2509 u8 old_retry_short, old_retry_long;
2510 u32 old_frag_threshold, old_rts_threshold;
81077e82 2511 u8 old_coverage_class;
b9a5f8ca 2512
7f2b8562
YX
2513 if (!rdev->ops->set_wiphy_params)
2514 return -EOPNOTSUPP;
b9a5f8ca
JM
2515
2516 old_retry_short = rdev->wiphy.retry_short;
2517 old_retry_long = rdev->wiphy.retry_long;
2518 old_frag_threshold = rdev->wiphy.frag_threshold;
2519 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 2520 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
2521
2522 if (changed & WIPHY_PARAM_RETRY_SHORT)
2523 rdev->wiphy.retry_short = retry_short;
2524 if (changed & WIPHY_PARAM_RETRY_LONG)
2525 rdev->wiphy.retry_long = retry_long;
2526 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
2527 rdev->wiphy.frag_threshold = frag_threshold;
2528 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
2529 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
2530 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
2531 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca 2532
e35e4d28 2533 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
2534 if (result) {
2535 rdev->wiphy.retry_short = old_retry_short;
2536 rdev->wiphy.retry_long = old_retry_long;
2537 rdev->wiphy.frag_threshold = old_frag_threshold;
2538 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 2539 rdev->wiphy.coverage_class = old_coverage_class;
9189ee31 2540 return result;
b9a5f8ca
JM
2541 }
2542 }
7f2b8562 2543 return 0;
55682965
JB
2544}
2545
71bbc994
JB
2546static inline u64 wdev_id(struct wireless_dev *wdev)
2547{
2548 return (u64)wdev->identifier |
f26cbf40 2549 ((u64)wiphy_to_rdev(wdev->wiphy)->wiphy_idx << 32);
71bbc994 2550}
55682965 2551
683b6d3b 2552static int nl80211_send_chandef(struct sk_buff *msg,
d2859df5 2553 const struct cfg80211_chan_def *chandef)
683b6d3b 2554{
601555cd
JB
2555 if (WARN_ON(!cfg80211_chandef_valid(chandef)))
2556 return -EINVAL;
3d9d1d66 2557
683b6d3b
JB
2558 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
2559 chandef->chan->center_freq))
2560 return -ENOBUFS;
3d9d1d66
JB
2561 switch (chandef->width) {
2562 case NL80211_CHAN_WIDTH_20_NOHT:
2563 case NL80211_CHAN_WIDTH_20:
2564 case NL80211_CHAN_WIDTH_40:
2565 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
2566 cfg80211_get_chandef_type(chandef)))
2567 return -ENOBUFS;
2568 break;
2569 default:
2570 break;
2571 }
2572 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
2573 return -ENOBUFS;
2574 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
2575 return -ENOBUFS;
2576 if (chandef->center_freq2 &&
2577 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
2578 return -ENOBUFS;
2579 return 0;
2580}
2581
15e47304 2582static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 2583 struct cfg80211_registered_device *rdev,
8f894be2 2584 struct wireless_dev *wdev, bool removal)
55682965 2585{
72fb2abc 2586 struct net_device *dev = wdev->netdev;
8f894be2 2587 u8 cmd = NL80211_CMD_NEW_INTERFACE;
55682965
JB
2588 void *hdr;
2589
8f894be2
TB
2590 if (removal)
2591 cmd = NL80211_CMD_DEL_INTERFACE;
2592
2593 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
55682965
JB
2594 if (!hdr)
2595 return -1;
2596
72fb2abc
JB
2597 if (dev &&
2598 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 2599 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
2600 goto nla_put_failure;
2601
2602 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2603 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
2dad624e
ND
2604 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
2605 NL80211_ATTR_PAD) ||
98104fde 2606 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
2607 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2608 rdev->devlist_generation ^
2609 (cfg80211_rdev_list_generation << 2)))
2610 goto nla_put_failure;
f5ea9120 2611
5b7ccaf3 2612 if (rdev->ops->get_channel) {
683b6d3b
JB
2613 int ret;
2614 struct cfg80211_chan_def chandef;
2615
2616 ret = rdev_get_channel(rdev, wdev, &chandef);
2617 if (ret == 0) {
2618 if (nl80211_send_chandef(msg, &chandef))
2619 goto nla_put_failure;
2620 }
d91df0e3
PF
2621 }
2622
d55d0d59
RM
2623 if (rdev->ops->get_tx_power) {
2624 int dbm, ret;
2625
2626 ret = rdev_get_tx_power(rdev, wdev, &dbm);
2627 if (ret == 0 &&
2628 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL,
2629 DBM_TO_MBM(dbm)))
2630 goto nla_put_failure;
2631 }
2632
44905265
JB
2633 wdev_lock(wdev);
2634 switch (wdev->iftype) {
2635 case NL80211_IFTYPE_AP:
2636 if (wdev->ssid_len &&
2637 nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
4564b187 2638 goto nla_put_failure_locked;
44905265
JB
2639 break;
2640 case NL80211_IFTYPE_STATION:
2641 case NL80211_IFTYPE_P2P_CLIENT:
2642 case NL80211_IFTYPE_ADHOC: {
2643 const u8 *ssid_ie;
2644 if (!wdev->current_bss)
2645 break;
7a94b8c2 2646 rcu_read_lock();
44905265
JB
2647 ssid_ie = ieee80211_bss_get_ie(&wdev->current_bss->pub,
2648 WLAN_EID_SSID);
7a94b8c2
DB
2649 if (ssid_ie &&
2650 nla_put(msg, NL80211_ATTR_SSID, ssid_ie[1], ssid_ie + 2))
2651 goto nla_put_failure_rcu_locked;
2652 rcu_read_unlock();
44905265
JB
2653 break;
2654 }
2655 default:
2656 /* nothing */
2657 break;
b84e7a05 2658 }
44905265 2659 wdev_unlock(wdev);
b84e7a05 2660
053c095a
JB
2661 genlmsg_end(msg, hdr);
2662 return 0;
55682965 2663
7a94b8c2
DB
2664 nla_put_failure_rcu_locked:
2665 rcu_read_unlock();
4564b187
JB
2666 nla_put_failure_locked:
2667 wdev_unlock(wdev);
55682965 2668 nla_put_failure:
bc3ed28c
TG
2669 genlmsg_cancel(msg, hdr);
2670 return -EMSGSIZE;
55682965
JB
2671}
2672
2673static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
2674{
2675 int wp_idx = 0;
2676 int if_idx = 0;
2677 int wp_start = cb->args[0];
2678 int if_start = cb->args[1];
b7fb44da 2679 int filter_wiphy = -1;
f5ea9120 2680 struct cfg80211_registered_device *rdev;
55682965 2681 struct wireless_dev *wdev;
ea90e0dc 2682 int ret;
55682965 2683
5fe231e8 2684 rtnl_lock();
b7fb44da
DK
2685 if (!cb->args[2]) {
2686 struct nl80211_dump_wiphy_state state = {
2687 .filter_wiphy = -1,
2688 };
b7fb44da
DK
2689
2690 ret = nl80211_dump_wiphy_parse(skb, cb, &state);
2691 if (ret)
ea90e0dc 2692 goto out_unlock;
b7fb44da
DK
2693
2694 filter_wiphy = state.filter_wiphy;
2695
2696 /*
2697 * if filtering, set cb->args[2] to +1 since 0 is the default
2698 * value needed to determine that parsing is necessary.
2699 */
2700 if (filter_wiphy >= 0)
2701 cb->args[2] = filter_wiphy + 1;
2702 else
2703 cb->args[2] = -1;
2704 } else if (cb->args[2] > 0) {
2705 filter_wiphy = cb->args[2] - 1;
2706 }
2707
f5ea9120
JB
2708 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2709 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2710 continue;
bba95fef
JB
2711 if (wp_idx < wp_start) {
2712 wp_idx++;
55682965 2713 continue;
bba95fef 2714 }
b7fb44da
DK
2715
2716 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx)
2717 continue;
2718
55682965
JB
2719 if_idx = 0;
2720
53873f13 2721 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
bba95fef
JB
2722 if (if_idx < if_start) {
2723 if_idx++;
55682965 2724 continue;
bba95fef 2725 }
15e47304 2726 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 2727 cb->nlh->nlmsg_seq, NLM_F_MULTI,
8f894be2 2728 rdev, wdev, false) < 0) {
bba95fef
JB
2729 goto out;
2730 }
2731 if_idx++;
55682965 2732 }
bba95fef
JB
2733
2734 wp_idx++;
55682965 2735 }
bba95fef 2736 out:
55682965
JB
2737 cb->args[0] = wp_idx;
2738 cb->args[1] = if_idx;
2739
ea90e0dc
JB
2740 ret = skb->len;
2741 out_unlock:
2742 rtnl_unlock();
2743
2744 return ret;
55682965
JB
2745}
2746
2747static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
2748{
2749 struct sk_buff *msg;
1b8ec87a 2750 struct cfg80211_registered_device *rdev = info->user_ptr[0];
72fb2abc 2751 struct wireless_dev *wdev = info->user_ptr[1];
55682965 2752
fd2120ca 2753 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 2754 if (!msg)
4c476991 2755 return -ENOMEM;
55682965 2756
15e47304 2757 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
8f894be2 2758 rdev, wdev, false) < 0) {
4c476991
JB
2759 nlmsg_free(msg);
2760 return -ENOBUFS;
2761 }
55682965 2762
134e6375 2763 return genlmsg_reply(msg, info);
55682965
JB
2764}
2765
66f7ac50
MW
2766static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
2767 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
2768 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
2769 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
2770 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
2771 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 2772 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
2773};
2774
2775static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
2776{
2777 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
2778 int flag;
2779
2780 *mntrflags = 0;
2781
2782 if (!nla)
2783 return -EINVAL;
2784
fceb6435
JB
2785 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX, nla,
2786 mntr_flags_policy, NULL))
66f7ac50
MW
2787 return -EINVAL;
2788
2789 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
2790 if (flags[flag])
2791 *mntrflags |= (1<<flag);
2792
818a986e
JB
2793 *mntrflags |= MONITOR_FLAG_CHANGED;
2794
66f7ac50
MW
2795 return 0;
2796}
2797
1db77596
JB
2798static int nl80211_parse_mon_options(struct cfg80211_registered_device *rdev,
2799 enum nl80211_iftype type,
2800 struct genl_info *info,
2801 struct vif_params *params)
2802{
2803 bool change = false;
2804 int err;
2805
2806 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
2807 if (type != NL80211_IFTYPE_MONITOR)
2808 return -EINVAL;
2809
2810 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
2811 &params->flags);
2812 if (err)
2813 return err;
2814
2815 change = true;
2816 }
2817
2818 if (params->flags & MONITOR_FLAG_ACTIVE &&
2819 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
2820 return -EOPNOTSUPP;
2821
2822 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) {
2823 const u8 *mumimo_groups;
2824 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
2825
2826 if (type != NL80211_IFTYPE_MONITOR)
2827 return -EINVAL;
2828
2829 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
2830 return -EOPNOTSUPP;
2831
2832 mumimo_groups =
2833 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]);
2834
2835 /* bits 0 and 63 are reserved and must be zero */
4954601f
JB
2836 if ((mumimo_groups[0] & BIT(0)) ||
2837 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(7)))
1db77596
JB
2838 return -EINVAL;
2839
2840 params->vht_mumimo_groups = mumimo_groups;
2841 change = true;
2842 }
2843
2844 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) {
2845 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
2846
2847 if (type != NL80211_IFTYPE_MONITOR)
2848 return -EINVAL;
2849
2850 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
2851 return -EOPNOTSUPP;
2852
2853 params->vht_mumimo_follow_addr =
2854 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]);
2855 change = true;
2856 }
2857
2858 return change ? 1 : 0;
2859}
2860
9bc383de 2861static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
2862 struct net_device *netdev, u8 use_4addr,
2863 enum nl80211_iftype iftype)
9bc383de 2864{
ad4bb6f8 2865 if (!use_4addr) {
f350a0a8 2866 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 2867 return -EBUSY;
9bc383de 2868 return 0;
ad4bb6f8 2869 }
9bc383de
JB
2870
2871 switch (iftype) {
2872 case NL80211_IFTYPE_AP_VLAN:
2873 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
2874 return 0;
2875 break;
2876 case NL80211_IFTYPE_STATION:
2877 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
2878 return 0;
2879 break;
2880 default:
2881 break;
2882 }
2883
2884 return -EOPNOTSUPP;
2885}
2886
55682965
JB
2887static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
2888{
4c476991 2889 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2890 struct vif_params params;
e36d56b6 2891 int err;
04a773ad 2892 enum nl80211_iftype otype, ntype;
4c476991 2893 struct net_device *dev = info->user_ptr[1];
ac7f9cfa 2894 bool change = false;
55682965 2895
2ec600d6
LCC
2896 memset(&params, 0, sizeof(params));
2897
04a773ad 2898 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 2899
723b038d 2900 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 2901 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 2902 if (otype != ntype)
ac7f9cfa 2903 change = true;
4c476991
JB
2904 if (ntype > NL80211_IFTYPE_MAX)
2905 return -EINVAL;
723b038d
JB
2906 }
2907
92ffe055 2908 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
2909 struct wireless_dev *wdev = dev->ieee80211_ptr;
2910
4c476991
JB
2911 if (ntype != NL80211_IFTYPE_MESH_POINT)
2912 return -EINVAL;
29cbe68c
JB
2913 if (netif_running(dev))
2914 return -EBUSY;
2915
2916 wdev_lock(wdev);
2917 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2918 IEEE80211_MAX_MESH_ID_LEN);
2919 wdev->mesh_id_up_len =
2920 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2921 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2922 wdev->mesh_id_up_len);
2923 wdev_unlock(wdev);
2ec600d6
LCC
2924 }
2925
8b787643
FF
2926 if (info->attrs[NL80211_ATTR_4ADDR]) {
2927 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
2928 change = true;
ad4bb6f8 2929 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 2930 if (err)
4c476991 2931 return err;
8b787643
FF
2932 } else {
2933 params.use_4addr = -1;
2934 }
2935
1db77596
JB
2936 err = nl80211_parse_mon_options(rdev, ntype, info, &params);
2937 if (err < 0)
2938 return err;
2939 if (err > 0)
c6e6a0c8 2940 change = true;
e057d3c3 2941
ac7f9cfa 2942 if (change)
818a986e 2943 err = cfg80211_change_iface(rdev, dev, ntype, &params);
ac7f9cfa
JB
2944 else
2945 err = 0;
60719ffd 2946
9bc383de
JB
2947 if (!err && params.use_4addr != -1)
2948 dev->ieee80211_ptr->use_4addr = params.use_4addr;
2949
55682965
JB
2950 return err;
2951}
2952
2953static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
2954{
4c476991 2955 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 2956 struct vif_params params;
84efbb84 2957 struct wireless_dev *wdev;
896ff063 2958 struct sk_buff *msg;
55682965
JB
2959 int err;
2960 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
2961
78f22b6a
JB
2962 /* to avoid failing a new interface creation due to pending removal */
2963 cfg80211_destroy_ifaces(rdev);
2964
2ec600d6
LCC
2965 memset(&params, 0, sizeof(params));
2966
55682965
JB
2967 if (!info->attrs[NL80211_ATTR_IFNAME])
2968 return -EINVAL;
2969
2970 if (info->attrs[NL80211_ATTR_IFTYPE]) {
2971 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
2972 if (type > NL80211_IFTYPE_MAX)
2973 return -EINVAL;
2974 }
2975
79c97e97 2976 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
2977 !(rdev->wiphy.interface_modes & (1 << type)))
2978 return -EOPNOTSUPP;
55682965 2979
cb3b7d87 2980 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN ||
e8f479b1
BG
2981 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) &&
2982 info->attrs[NL80211_ATTR_MAC]) {
1c18f145
AS
2983 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
2984 ETH_ALEN);
2985 if (!is_valid_ether_addr(params.macaddr))
2986 return -EADDRNOTAVAIL;
2987 }
2988
9bc383de 2989 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 2990 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 2991 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 2992 if (err)
4c476991 2993 return err;
9bc383de 2994 }
8b787643 2995
1db77596
JB
2996 err = nl80211_parse_mon_options(rdev, type, info, &params);
2997 if (err < 0)
2998 return err;
e057d3c3 2999
a18c7192
JB
3000 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3001 if (!msg)
3002 return -ENOMEM;
3003
e35e4d28
HG
3004 wdev = rdev_add_virtual_intf(rdev,
3005 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
818a986e 3006 NET_NAME_USER, type, &params);
d687cbb7
RM
3007 if (WARN_ON(!wdev)) {
3008 nlmsg_free(msg);
3009 return -EPROTO;
3010 } else if (IS_ERR(wdev)) {
1c90f9d4 3011 nlmsg_free(msg);
84efbb84 3012 return PTR_ERR(wdev);
1c90f9d4 3013 }
2ec600d6 3014
18e5ca65 3015 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
78f22b6a
JB
3016 wdev->owner_nlportid = info->snd_portid;
3017
98104fde
JB
3018 switch (type) {
3019 case NL80211_IFTYPE_MESH_POINT:
3020 if (!info->attrs[NL80211_ATTR_MESH_ID])
3021 break;
29cbe68c
JB
3022 wdev_lock(wdev);
3023 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
3024 IEEE80211_MAX_MESH_ID_LEN);
3025 wdev->mesh_id_up_len =
3026 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
3027 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
3028 wdev->mesh_id_up_len);
3029 wdev_unlock(wdev);
98104fde 3030 break;
cb3b7d87 3031 case NL80211_IFTYPE_NAN:
98104fde
JB
3032 case NL80211_IFTYPE_P2P_DEVICE:
3033 /*
cb3b7d87 3034 * P2P Device and NAN do not have a netdev, so don't go
98104fde
JB
3035 * through the netdev notifier and must be added here
3036 */
3037 mutex_init(&wdev->mtx);
3038 INIT_LIST_HEAD(&wdev->event_list);
3039 spin_lock_init(&wdev->event_lock);
3040 INIT_LIST_HEAD(&wdev->mgmt_registrations);
3041 spin_lock_init(&wdev->mgmt_registrations_lock);
3042
98104fde 3043 wdev->identifier = ++rdev->wdev_id;
53873f13 3044 list_add_rcu(&wdev->list, &rdev->wiphy.wdev_list);
98104fde 3045 rdev->devlist_generation++;
98104fde
JB
3046 break;
3047 default:
3048 break;
29cbe68c
JB
3049 }
3050
15e47304 3051 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
8f894be2 3052 rdev, wdev, false) < 0) {
1c90f9d4
JB
3053 nlmsg_free(msg);
3054 return -ENOBUFS;
3055 }
3056
896ff063
DK
3057 /*
3058 * For wdevs which have no associated netdev object (e.g. of type
3059 * NL80211_IFTYPE_P2P_DEVICE), emit the NEW_INTERFACE event here.
3060 * For all other types, the event will be generated from the
3061 * netdev notifier
3062 */
3063 if (!wdev->netdev)
3064 nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE);
8f894be2 3065
1c90f9d4 3066 return genlmsg_reply(msg, info);
55682965
JB
3067}
3068
3069static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
3070{
4c476991 3071 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 3072 struct wireless_dev *wdev = info->user_ptr[1];
55682965 3073
4c476991
JB
3074 if (!rdev->ops->del_virtual_intf)
3075 return -EOPNOTSUPP;
55682965 3076
84efbb84
JB
3077 /*
3078 * If we remove a wireless device without a netdev then clear
3079 * user_ptr[1] so that nl80211_post_doit won't dereference it
3080 * to check if it needs to do dev_put(). Otherwise it crashes
3081 * since the wdev has been freed, unlike with a netdev where
3082 * we need the dev_put() for the netdev to really be freed.
3083 */
3084 if (!wdev->netdev)
3085 info->user_ptr[1] = NULL;
3086
7f8ed01e 3087 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
3088}
3089
1d9d9213
SW
3090static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
3091{
3092 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3093 struct net_device *dev = info->user_ptr[1];
3094 u16 noack_map;
3095
3096 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
3097 return -EINVAL;
3098
3099 if (!rdev->ops->set_noack_map)
3100 return -EOPNOTSUPP;
3101
3102 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
3103
e35e4d28 3104 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
3105}
3106
41ade00f
JB
3107struct get_key_cookie {
3108 struct sk_buff *msg;
3109 int error;
b9454e83 3110 int idx;
41ade00f
JB
3111};
3112
3113static void get_key_callback(void *c, struct key_params *params)
3114{
b9454e83 3115 struct nlattr *key;
41ade00f
JB
3116 struct get_key_cookie *cookie = c;
3117
9360ffd1
DM
3118 if ((params->key &&
3119 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
3120 params->key_len, params->key)) ||
3121 (params->seq &&
3122 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
3123 params->seq_len, params->seq)) ||
3124 (params->cipher &&
3125 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
3126 params->cipher)))
3127 goto nla_put_failure;
41ade00f 3128
b9454e83
JB
3129 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
3130 if (!key)
3131 goto nla_put_failure;
3132
9360ffd1
DM
3133 if ((params->key &&
3134 nla_put(cookie->msg, NL80211_KEY_DATA,
3135 params->key_len, params->key)) ||
3136 (params->seq &&
3137 nla_put(cookie->msg, NL80211_KEY_SEQ,
3138 params->seq_len, params->seq)) ||
3139 (params->cipher &&
3140 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
3141 params->cipher)))
3142 goto nla_put_failure;
b9454e83 3143
9360ffd1
DM
3144 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
3145 goto nla_put_failure;
b9454e83
JB
3146
3147 nla_nest_end(cookie->msg, key);
3148
41ade00f
JB
3149 return;
3150 nla_put_failure:
3151 cookie->error = 1;
3152}
3153
3154static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
3155{
4c476991 3156 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3157 int err;
4c476991 3158 struct net_device *dev = info->user_ptr[1];
41ade00f 3159 u8 key_idx = 0;
e31b8213
JB
3160 const u8 *mac_addr = NULL;
3161 bool pairwise;
41ade00f
JB
3162 struct get_key_cookie cookie = {
3163 .error = 0,
3164 };
3165 void *hdr;
3166 struct sk_buff *msg;
3167
3168 if (info->attrs[NL80211_ATTR_KEY_IDX])
3169 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
3170
3cfcf6ac 3171 if (key_idx > 5)
41ade00f
JB
3172 return -EINVAL;
3173
3174 if (info->attrs[NL80211_ATTR_MAC])
3175 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3176
e31b8213
JB
3177 pairwise = !!mac_addr;
3178 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
3179 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
7a087e74 3180
e31b8213
JB
3181 if (kt >= NUM_NL80211_KEYTYPES)
3182 return -EINVAL;
3183 if (kt != NL80211_KEYTYPE_GROUP &&
3184 kt != NL80211_KEYTYPE_PAIRWISE)
3185 return -EINVAL;
3186 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
3187 }
3188
4c476991
JB
3189 if (!rdev->ops->get_key)
3190 return -EOPNOTSUPP;
41ade00f 3191
0fa7b391
JB
3192 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3193 return -ENOENT;
3194
fd2120ca 3195 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3196 if (!msg)
3197 return -ENOMEM;
41ade00f 3198
15e47304 3199 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 3200 NL80211_CMD_NEW_KEY);
cb35fba3 3201 if (!hdr)
9fe271af 3202 goto nla_put_failure;
41ade00f
JB
3203
3204 cookie.msg = msg;
b9454e83 3205 cookie.idx = key_idx;
41ade00f 3206
9360ffd1
DM
3207 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3208 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
3209 goto nla_put_failure;
3210 if (mac_addr &&
3211 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
3212 goto nla_put_failure;
41ade00f 3213
e35e4d28
HG
3214 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
3215 get_key_callback);
41ade00f
JB
3216
3217 if (err)
6c95e2a2 3218 goto free_msg;
41ade00f
JB
3219
3220 if (cookie.error)
3221 goto nla_put_failure;
3222
3223 genlmsg_end(msg, hdr);
4c476991 3224 return genlmsg_reply(msg, info);
41ade00f
JB
3225
3226 nla_put_failure:
3227 err = -ENOBUFS;
6c95e2a2 3228 free_msg:
41ade00f 3229 nlmsg_free(msg);
41ade00f
JB
3230 return err;
3231}
3232
3233static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
3234{
4c476991 3235 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 3236 struct key_parse key;
41ade00f 3237 int err;
4c476991 3238 struct net_device *dev = info->user_ptr[1];
41ade00f 3239
b9454e83
JB
3240 err = nl80211_parse_key(info, &key);
3241 if (err)
3242 return err;
41ade00f 3243
b9454e83 3244 if (key.idx < 0)
41ade00f
JB
3245 return -EINVAL;
3246
b9454e83
JB
3247 /* only support setting default key */
3248 if (!key.def && !key.defmgmt)
41ade00f
JB
3249 return -EINVAL;
3250
dbd2fd65 3251 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 3252
dbd2fd65
JB
3253 if (key.def) {
3254 if (!rdev->ops->set_default_key) {
3255 err = -EOPNOTSUPP;
3256 goto out;
3257 }
41ade00f 3258
dbd2fd65
JB
3259 err = nl80211_key_allowed(dev->ieee80211_ptr);
3260 if (err)
3261 goto out;
3262
e35e4d28 3263 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
3264 key.def_uni, key.def_multi);
3265
3266 if (err)
3267 goto out;
fffd0934 3268
3d23e349 3269#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
3270 dev->ieee80211_ptr->wext.default_key = key.idx;
3271#endif
3272 } else {
3273 if (key.def_uni || !key.def_multi) {
3274 err = -EINVAL;
3275 goto out;
3276 }
3277
3278 if (!rdev->ops->set_default_mgmt_key) {
3279 err = -EOPNOTSUPP;
3280 goto out;
3281 }
3282
3283 err = nl80211_key_allowed(dev->ieee80211_ptr);
3284 if (err)
3285 goto out;
3286
e35e4d28 3287 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
3288 if (err)
3289 goto out;
3290
3291#ifdef CONFIG_CFG80211_WEXT
3292 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 3293#endif
dbd2fd65
JB
3294 }
3295
3296 out:
fffd0934 3297 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3298
41ade00f
JB
3299 return err;
3300}
3301
3302static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
3303{
4c476991 3304 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 3305 int err;
4c476991 3306 struct net_device *dev = info->user_ptr[1];
b9454e83 3307 struct key_parse key;
e31b8213 3308 const u8 *mac_addr = NULL;
41ade00f 3309
b9454e83
JB
3310 err = nl80211_parse_key(info, &key);
3311 if (err)
3312 return err;
41ade00f 3313
b9454e83 3314 if (!key.p.key)
41ade00f
JB
3315 return -EINVAL;
3316
41ade00f
JB
3317 if (info->attrs[NL80211_ATTR_MAC])
3318 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3319
e31b8213
JB
3320 if (key.type == -1) {
3321 if (mac_addr)
3322 key.type = NL80211_KEYTYPE_PAIRWISE;
3323 else
3324 key.type = NL80211_KEYTYPE_GROUP;
3325 }
3326
3327 /* for now */
3328 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3329 key.type != NL80211_KEYTYPE_GROUP)
3330 return -EINVAL;
3331
4c476991
JB
3332 if (!rdev->ops->add_key)
3333 return -EOPNOTSUPP;
25e47c18 3334
e31b8213
JB
3335 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
3336 key.type == NL80211_KEYTYPE_PAIRWISE,
3337 mac_addr))
4c476991 3338 return -EINVAL;
41ade00f 3339
fffd0934
JB
3340 wdev_lock(dev->ieee80211_ptr);
3341 err = nl80211_key_allowed(dev->ieee80211_ptr);
3342 if (!err)
e35e4d28
HG
3343 err = rdev_add_key(rdev, dev, key.idx,
3344 key.type == NL80211_KEYTYPE_PAIRWISE,
3345 mac_addr, &key.p);
fffd0934 3346 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3347
41ade00f
JB
3348 return err;
3349}
3350
3351static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
3352{
4c476991 3353 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3354 int err;
4c476991 3355 struct net_device *dev = info->user_ptr[1];
41ade00f 3356 u8 *mac_addr = NULL;
b9454e83 3357 struct key_parse key;
41ade00f 3358
b9454e83
JB
3359 err = nl80211_parse_key(info, &key);
3360 if (err)
3361 return err;
41ade00f
JB
3362
3363 if (info->attrs[NL80211_ATTR_MAC])
3364 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3365
e31b8213
JB
3366 if (key.type == -1) {
3367 if (mac_addr)
3368 key.type = NL80211_KEYTYPE_PAIRWISE;
3369 else
3370 key.type = NL80211_KEYTYPE_GROUP;
3371 }
3372
3373 /* for now */
3374 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3375 key.type != NL80211_KEYTYPE_GROUP)
3376 return -EINVAL;
3377
4c476991
JB
3378 if (!rdev->ops->del_key)
3379 return -EOPNOTSUPP;
41ade00f 3380
fffd0934
JB
3381 wdev_lock(dev->ieee80211_ptr);
3382 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213 3383
0fa7b391 3384 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr &&
e31b8213
JB
3385 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3386 err = -ENOENT;
3387
fffd0934 3388 if (!err)
e35e4d28
HG
3389 err = rdev_del_key(rdev, dev, key.idx,
3390 key.type == NL80211_KEYTYPE_PAIRWISE,
3391 mac_addr);
41ade00f 3392
3d23e349 3393#ifdef CONFIG_CFG80211_WEXT
08645126 3394 if (!err) {
b9454e83 3395 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 3396 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 3397 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
3398 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
3399 }
3400#endif
fffd0934 3401 wdev_unlock(dev->ieee80211_ptr);
08645126 3402
41ade00f
JB
3403 return err;
3404}
3405
77765eaf
VT
3406/* This function returns an error or the number of nested attributes */
3407static int validate_acl_mac_addrs(struct nlattr *nl_attr)
3408{
3409 struct nlattr *attr;
3410 int n_entries = 0, tmp;
3411
3412 nla_for_each_nested(attr, nl_attr, tmp) {
3413 if (nla_len(attr) != ETH_ALEN)
3414 return -EINVAL;
3415
3416 n_entries++;
3417 }
3418
3419 return n_entries;
3420}
3421
3422/*
3423 * This function parses ACL information and allocates memory for ACL data.
3424 * On successful return, the calling function is responsible to free the
3425 * ACL buffer returned by this function.
3426 */
3427static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
3428 struct genl_info *info)
3429{
3430 enum nl80211_acl_policy acl_policy;
3431 struct nlattr *attr;
3432 struct cfg80211_acl_data *acl;
3433 int i = 0, n_entries, tmp;
3434
3435 if (!wiphy->max_acl_mac_addrs)
3436 return ERR_PTR(-EOPNOTSUPP);
3437
3438 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
3439 return ERR_PTR(-EINVAL);
3440
3441 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
3442 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
3443 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
3444 return ERR_PTR(-EINVAL);
3445
3446 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
3447 return ERR_PTR(-EINVAL);
3448
3449 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
3450 if (n_entries < 0)
3451 return ERR_PTR(n_entries);
3452
3453 if (n_entries > wiphy->max_acl_mac_addrs)
3454 return ERR_PTR(-ENOTSUPP);
3455
3456 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries),
3457 GFP_KERNEL);
3458 if (!acl)
3459 return ERR_PTR(-ENOMEM);
3460
3461 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
3462 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
3463 i++;
3464 }
3465
3466 acl->n_acl_entries = n_entries;
3467 acl->acl_policy = acl_policy;
3468
3469 return acl;
3470}
3471
3472static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
3473{
3474 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3475 struct net_device *dev = info->user_ptr[1];
3476 struct cfg80211_acl_data *acl;
3477 int err;
3478
3479 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3480 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3481 return -EOPNOTSUPP;
3482
3483 if (!dev->ieee80211_ptr->beacon_interval)
3484 return -EINVAL;
3485
3486 acl = parse_acl_data(&rdev->wiphy, info);
3487 if (IS_ERR(acl))
3488 return PTR_ERR(acl);
3489
3490 err = rdev_set_mac_acl(rdev, dev, acl);
3491
3492 kfree(acl);
3493
3494 return err;
3495}
3496
a7c7fbff
PK
3497static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
3498 u8 *rates, u8 rates_len)
3499{
3500 u8 i;
3501 u32 mask = 0;
3502
3503 for (i = 0; i < rates_len; i++) {
3504 int rate = (rates[i] & 0x7f) * 5;
3505 int ridx;
3506
3507 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
3508 struct ieee80211_rate *srate =
3509 &sband->bitrates[ridx];
3510 if (rate == srate->bitrate) {
3511 mask |= 1 << ridx;
3512 break;
3513 }
3514 }
3515 if (ridx == sband->n_bitrates)
3516 return 0; /* rate not found */
3517 }
3518
3519 return mask;
3520}
3521
3522static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
3523 u8 *rates, u8 rates_len,
3524 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
3525{
3526 u8 i;
3527
3528 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
3529
3530 for (i = 0; i < rates_len; i++) {
3531 int ridx, rbit;
3532
3533 ridx = rates[i] / 8;
3534 rbit = BIT(rates[i] % 8);
3535
3536 /* check validity */
3537 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
3538 return false;
3539
3540 /* check availability */
3541 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
3542 mcs[ridx] |= rbit;
3543 else
3544 return false;
3545 }
3546
3547 return true;
3548}
3549
3550static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
3551{
3552 u16 mcs_mask = 0;
3553
3554 switch (vht_mcs_map) {
3555 case IEEE80211_VHT_MCS_NOT_SUPPORTED:
3556 break;
3557 case IEEE80211_VHT_MCS_SUPPORT_0_7:
3558 mcs_mask = 0x00FF;
3559 break;
3560 case IEEE80211_VHT_MCS_SUPPORT_0_8:
3561 mcs_mask = 0x01FF;
3562 break;
3563 case IEEE80211_VHT_MCS_SUPPORT_0_9:
3564 mcs_mask = 0x03FF;
3565 break;
3566 default:
3567 break;
3568 }
3569
3570 return mcs_mask;
3571}
3572
3573static void vht_build_mcs_mask(u16 vht_mcs_map,
3574 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
3575{
3576 u8 nss;
3577
3578 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
3579 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
3580 vht_mcs_map >>= 2;
3581 }
3582}
3583
3584static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
3585 struct nl80211_txrate_vht *txrate,
3586 u16 mcs[NL80211_VHT_NSS_MAX])
3587{
3588 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
3589 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
3590 u8 i;
3591
3592 if (!sband->vht_cap.vht_supported)
3593 return false;
3594
3595 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
3596
3597 /* Build vht_mcs_mask from VHT capabilities */
3598 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
3599
3600 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
3601 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
3602 mcs[i] = txrate->mcs[i];
3603 else
3604 return false;
3605 }
3606
3607 return true;
3608}
3609
3610static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
3611 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
3612 .len = NL80211_MAX_SUPP_RATES },
3613 [NL80211_TXRATE_HT] = { .type = NLA_BINARY,
3614 .len = NL80211_MAX_SUPP_HT_RATES },
3615 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)},
3616 [NL80211_TXRATE_GI] = { .type = NLA_U8 },
3617};
3618
3619static int nl80211_parse_tx_bitrate_mask(struct genl_info *info,
3620 struct cfg80211_bitrate_mask *mask)
3621{
3622 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
3623 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3624 int rem, i;
3625 struct nlattr *tx_rates;
3626 struct ieee80211_supported_band *sband;
3627 u16 vht_tx_mcs_map;
3628
3629 memset(mask, 0, sizeof(*mask));
3630 /* Default to all rates enabled */
3631 for (i = 0; i < NUM_NL80211_BANDS; i++) {
3632 sband = rdev->wiphy.bands[i];
3633
3634 if (!sband)
3635 continue;
3636
3637 mask->control[i].legacy = (1 << sband->n_bitrates) - 1;
3638 memcpy(mask->control[i].ht_mcs,
3639 sband->ht_cap.mcs.rx_mask,
3640 sizeof(mask->control[i].ht_mcs));
3641
3642 if (!sband->vht_cap.vht_supported)
3643 continue;
3644
3645 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
3646 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs);
3647 }
3648
3649 /* if no rates are given set it back to the defaults */
3650 if (!info->attrs[NL80211_ATTR_TX_RATES])
3651 goto out;
3652
3653 /* The nested attribute uses enum nl80211_band as the index. This maps
3654 * directly to the enum nl80211_band values used in cfg80211.
3655 */
3656 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
3657 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) {
3658 enum nl80211_band band = nla_type(tx_rates);
3659 int err;
3660
3661 if (band < 0 || band >= NUM_NL80211_BANDS)
3662 return -EINVAL;
3663 sband = rdev->wiphy.bands[band];
3664 if (sband == NULL)
3665 return -EINVAL;
bfe2c7b1 3666 err = nla_parse_nested(tb, NL80211_TXRATE_MAX, tx_rates,
fe52145f 3667 nl80211_txattr_policy, info->extack);
a7c7fbff
PK
3668 if (err)
3669 return err;
3670 if (tb[NL80211_TXRATE_LEGACY]) {
3671 mask->control[band].legacy = rateset_to_mask(
3672 sband,
3673 nla_data(tb[NL80211_TXRATE_LEGACY]),
3674 nla_len(tb[NL80211_TXRATE_LEGACY]));
3675 if ((mask->control[band].legacy == 0) &&
3676 nla_len(tb[NL80211_TXRATE_LEGACY]))
3677 return -EINVAL;
3678 }
3679 if (tb[NL80211_TXRATE_HT]) {
3680 if (!ht_rateset_to_mask(
3681 sband,
3682 nla_data(tb[NL80211_TXRATE_HT]),
3683 nla_len(tb[NL80211_TXRATE_HT]),
3684 mask->control[band].ht_mcs))
3685 return -EINVAL;
3686 }
3687 if (tb[NL80211_TXRATE_VHT]) {
3688 if (!vht_set_mcs_mask(
3689 sband,
3690 nla_data(tb[NL80211_TXRATE_VHT]),
3691 mask->control[band].vht_mcs))
3692 return -EINVAL;
3693 }
3694 if (tb[NL80211_TXRATE_GI]) {
3695 mask->control[band].gi =
3696 nla_get_u8(tb[NL80211_TXRATE_GI]);
3697 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI)
3698 return -EINVAL;
3699 }
3700
3701 if (mask->control[band].legacy == 0) {
3702 /* don't allow empty legacy rates if HT or VHT
3703 * are not even supported.
3704 */
3705 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
3706 rdev->wiphy.bands[band]->vht_cap.vht_supported))
3707 return -EINVAL;
3708
3709 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
3710 if (mask->control[band].ht_mcs[i])
3711 goto out;
3712
3713 for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
3714 if (mask->control[band].vht_mcs[i])
3715 goto out;
3716
3717 /* legacy and mcs rates may not be both empty */
3718 return -EINVAL;
3719 }
3720 }
3721
3722out:
3723 return 0;
3724}
3725
8564e382
JB
3726static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev,
3727 enum nl80211_band band,
3728 struct cfg80211_bitrate_mask *beacon_rate)
a7c7fbff 3729{
8564e382
JB
3730 u32 count_ht, count_vht, i;
3731 u32 rate = beacon_rate->control[band].legacy;
a7c7fbff
PK
3732
3733 /* Allow only one rate */
3734 if (hweight32(rate) > 1)
3735 return -EINVAL;
3736
3737 count_ht = 0;
3738 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) {
8564e382 3739 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) {
a7c7fbff 3740 return -EINVAL;
8564e382 3741 } else if (beacon_rate->control[band].ht_mcs[i]) {
a7c7fbff
PK
3742 count_ht++;
3743 if (count_ht > 1)
3744 return -EINVAL;
3745 }
3746 if (count_ht && rate)
3747 return -EINVAL;
3748 }
3749
3750 count_vht = 0;
3751 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
8564e382 3752 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) {
a7c7fbff 3753 return -EINVAL;
8564e382 3754 } else if (beacon_rate->control[band].vht_mcs[i]) {
a7c7fbff
PK
3755 count_vht++;
3756 if (count_vht > 1)
3757 return -EINVAL;
3758 }
3759 if (count_vht && rate)
3760 return -EINVAL;
3761 }
3762
3763 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht))
3764 return -EINVAL;
3765
8564e382
JB
3766 if (rate &&
3767 !wiphy_ext_feature_isset(&rdev->wiphy,
3768 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY))
3769 return -EINVAL;
3770 if (count_ht &&
3771 !wiphy_ext_feature_isset(&rdev->wiphy,
3772 NL80211_EXT_FEATURE_BEACON_RATE_HT))
3773 return -EINVAL;
3774 if (count_vht &&
3775 !wiphy_ext_feature_isset(&rdev->wiphy,
3776 NL80211_EXT_FEATURE_BEACON_RATE_VHT))
3777 return -EINVAL;
3778
a7c7fbff
PK
3779 return 0;
3780}
3781
a1193be8 3782static int nl80211_parse_beacon(struct nlattr *attrs[],
8860020e 3783 struct cfg80211_beacon_data *bcn)
ed1b6cc7 3784{
8860020e 3785 bool haveinfo = false;
ed1b6cc7 3786
a1193be8
SW
3787 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) ||
3788 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) ||
3789 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
3790 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
3791 return -EINVAL;
3792
8860020e 3793 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 3794
a1193be8
SW
3795 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
3796 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
3797 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
3798 if (!bcn->head_len)
3799 return -EINVAL;
3800 haveinfo = true;
ed1b6cc7
JB
3801 }
3802
a1193be8
SW
3803 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
3804 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
3805 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 3806 haveinfo = true;
ed1b6cc7
JB
3807 }
3808
4c476991
JB
3809 if (!haveinfo)
3810 return -EINVAL;
3b85875a 3811
a1193be8
SW
3812 if (attrs[NL80211_ATTR_IE]) {
3813 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
3814 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
3815 }
3816
a1193be8 3817 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 3818 bcn->proberesp_ies =
a1193be8 3819 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 3820 bcn->proberesp_ies_len =
a1193be8 3821 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
3822 }
3823
a1193be8 3824 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 3825 bcn->assocresp_ies =
a1193be8 3826 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 3827 bcn->assocresp_ies_len =
a1193be8 3828 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
3829 }
3830
a1193be8
SW
3831 if (attrs[NL80211_ATTR_PROBE_RESP]) {
3832 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
3833 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
3834 }
3835
8860020e
JB
3836 return 0;
3837}
3838
66cd794e
JB
3839static void nl80211_check_ap_rate_selectors(struct cfg80211_ap_settings *params,
3840 const u8 *rates)
3841{
3842 int i;
3843
3844 if (!rates)
3845 return;
3846
3847 for (i = 0; i < rates[1]; i++) {
3848 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_HT_PHY)
3849 params->ht_required = true;
3850 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_VHT_PHY)
3851 params->vht_required = true;
3852 }
3853}
3854
3855/*
3856 * Since the nl80211 API didn't include, from the beginning, attributes about
3857 * HT/VHT requirements/capabilities, we parse them out of the IEs for the
3858 * benefit of drivers that rebuild IEs in the firmware.
3859 */
3860static void nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
3861{
3862 const struct cfg80211_beacon_data *bcn = &params->beacon;
ba83bfb1
IM
3863 size_t ies_len = bcn->tail_len;
3864 const u8 *ies = bcn->tail;
66cd794e
JB
3865 const u8 *rates;
3866 const u8 *cap;
3867
3868 rates = cfg80211_find_ie(WLAN_EID_SUPP_RATES, ies, ies_len);
3869 nl80211_check_ap_rate_selectors(params, rates);
3870
3871 rates = cfg80211_find_ie(WLAN_EID_EXT_SUPP_RATES, ies, ies_len);
3872 nl80211_check_ap_rate_selectors(params, rates);
3873
3874 cap = cfg80211_find_ie(WLAN_EID_HT_CAPABILITY, ies, ies_len);
3875 if (cap && cap[1] >= sizeof(*params->ht_cap))
3876 params->ht_cap = (void *)(cap + 2);
3877 cap = cfg80211_find_ie(WLAN_EID_VHT_CAPABILITY, ies, ies_len);
3878 if (cap && cap[1] >= sizeof(*params->vht_cap))
3879 params->vht_cap = (void *)(cap + 2);
3880}
3881
46c1dd0c
FF
3882static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
3883 struct cfg80211_ap_settings *params)
3884{
3885 struct wireless_dev *wdev;
3886 bool ret = false;
3887
53873f13 3888 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
46c1dd0c
FF
3889 if (wdev->iftype != NL80211_IFTYPE_AP &&
3890 wdev->iftype != NL80211_IFTYPE_P2P_GO)
3891 continue;
3892
683b6d3b 3893 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
3894 continue;
3895
683b6d3b 3896 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
3897 ret = true;
3898 break;
3899 }
3900
46c1dd0c
FF
3901 return ret;
3902}
3903
e39e5b5e
JM
3904static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
3905 enum nl80211_auth_type auth_type,
3906 enum nl80211_commands cmd)
3907{
3908 if (auth_type > NL80211_AUTHTYPE_MAX)
3909 return false;
3910
3911 switch (cmd) {
3912 case NL80211_CMD_AUTHENTICATE:
3913 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
3914 auth_type == NL80211_AUTHTYPE_SAE)
3915 return false;
63181060
JM
3916 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3917 NL80211_EXT_FEATURE_FILS_STA) &&
3918 (auth_type == NL80211_AUTHTYPE_FILS_SK ||
3919 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
3920 auth_type == NL80211_AUTHTYPE_FILS_PK))
3921 return false;
e39e5b5e
JM
3922 return true;
3923 case NL80211_CMD_CONNECT:
a3caf744
VK
3924 /* SAE not supported yet */
3925 if (auth_type == NL80211_AUTHTYPE_SAE)
3926 return false;
3927 /* FILS with SK PFS or PK not supported yet */
3928 if (auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
3929 auth_type == NL80211_AUTHTYPE_FILS_PK)
3930 return false;
3931 if (!wiphy_ext_feature_isset(
3932 &rdev->wiphy,
3933 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
3934 auth_type == NL80211_AUTHTYPE_FILS_SK)
3935 return false;
3936 return true;
e39e5b5e
JM
3937 case NL80211_CMD_START_AP:
3938 /* SAE not supported yet */
3939 if (auth_type == NL80211_AUTHTYPE_SAE)
3940 return false;
63181060
JM
3941 /* FILS not supported yet */
3942 if (auth_type == NL80211_AUTHTYPE_FILS_SK ||
3943 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
3944 auth_type == NL80211_AUTHTYPE_FILS_PK)
3945 return false;
e39e5b5e
JM
3946 return true;
3947 default:
3948 return false;
3949 }
3950}
3951
8860020e
JB
3952static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
3953{
3954 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3955 struct net_device *dev = info->user_ptr[1];
3956 struct wireless_dev *wdev = dev->ieee80211_ptr;
3957 struct cfg80211_ap_settings params;
3958 int err;
3959
3960 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
3961 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3962 return -EOPNOTSUPP;
3963
3964 if (!rdev->ops->start_ap)
3965 return -EOPNOTSUPP;
3966
3967 if (wdev->beacon_interval)
3968 return -EALREADY;
3969
3970 memset(&params, 0, sizeof(params));
3971
3972 /* these are required for START_AP */
3973 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
3974 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
3975 !info->attrs[NL80211_ATTR_BEACON_HEAD])
3976 return -EINVAL;
3977
a1193be8 3978 err = nl80211_parse_beacon(info->attrs, &params.beacon);
8860020e
JB
3979 if (err)
3980 return err;
3981
3982 params.beacon_interval =
3983 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3984 params.dtim_period =
3985 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
3986
0c317a02
PK
3987 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype,
3988 params.beacon_interval);
8860020e
JB
3989 if (err)
3990 return err;
3991
3992 /*
3993 * In theory, some of these attributes should be required here
3994 * but since they were not used when the command was originally
3995 * added, keep them optional for old user space programs to let
3996 * them continue to work with drivers that do not need the
3997 * additional information -- drivers must check!
3998 */
3999 if (info->attrs[NL80211_ATTR_SSID]) {
4000 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4001 params.ssid_len =
4002 nla_len(info->attrs[NL80211_ATTR_SSID]);
4003 if (params.ssid_len == 0 ||
4004 params.ssid_len > IEEE80211_MAX_SSID_LEN)
4005 return -EINVAL;
4006 }
4007
4008 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
4009 params.hidden_ssid = nla_get_u32(
4010 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
4011 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
4012 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
4013 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
4014 return -EINVAL;
4015 }
4016
4017 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4018
4019 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4020 params.auth_type = nla_get_u32(
4021 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
4022 if (!nl80211_valid_auth_type(rdev, params.auth_type,
4023 NL80211_CMD_START_AP))
8860020e
JB
4024 return -EINVAL;
4025 } else
4026 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4027
4028 err = nl80211_crypto_settings(rdev, info, &params.crypto,
4029 NL80211_MAX_NR_CIPHER_SUITES);
4030 if (err)
4031 return err;
4032
1b658f11
VT
4033 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
4034 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
4035 return -EOPNOTSUPP;
4036 params.inactivity_timeout = nla_get_u16(
4037 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
4038 }
4039
53cabad7
JB
4040 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
4041 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4042 return -EINVAL;
4043 params.p2p_ctwindow =
4044 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
4045 if (params.p2p_ctwindow > 127)
4046 return -EINVAL;
4047 if (params.p2p_ctwindow != 0 &&
4048 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
4049 return -EINVAL;
4050 }
4051
4052 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
4053 u8 tmp;
4054
4055 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4056 return -EINVAL;
4057 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
4058 if (tmp > 1)
4059 return -EINVAL;
4060 params.p2p_opp_ps = tmp;
4061 if (params.p2p_opp_ps != 0 &&
4062 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
4063 return -EINVAL;
4064 }
4065
aa430da4 4066 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
4067 err = nl80211_parse_chandef(rdev, info, &params.chandef);
4068 if (err)
4069 return err;
4070 } else if (wdev->preset_chandef.chan) {
4071 params.chandef = wdev->preset_chandef;
46c1dd0c 4072 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
4073 return -EINVAL;
4074
923b352f
AN
4075 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
4076 wdev->iftype))
aa430da4
JB
4077 return -EINVAL;
4078
a7c7fbff
PK
4079 if (info->attrs[NL80211_ATTR_TX_RATES]) {
4080 err = nl80211_parse_tx_bitrate_mask(info, &params.beacon_rate);
4081 if (err)
4082 return err;
4083
8564e382
JB
4084 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band,
4085 &params.beacon_rate);
a7c7fbff
PK
4086 if (err)
4087 return err;
4088 }
4089
18998c38
EP
4090 if (info->attrs[NL80211_ATTR_SMPS_MODE]) {
4091 params.smps_mode =
4092 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]);
4093 switch (params.smps_mode) {
4094 case NL80211_SMPS_OFF:
4095 break;
4096 case NL80211_SMPS_STATIC:
4097 if (!(rdev->wiphy.features &
4098 NL80211_FEATURE_STATIC_SMPS))
4099 return -EINVAL;
4100 break;
4101 case NL80211_SMPS_DYNAMIC:
4102 if (!(rdev->wiphy.features &
4103 NL80211_FEATURE_DYNAMIC_SMPS))
4104 return -EINVAL;
4105 break;
4106 default:
4107 return -EINVAL;
4108 }
4109 } else {
4110 params.smps_mode = NL80211_SMPS_OFF;
4111 }
4112
6e8ef842
PK
4113 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
4114 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ])
4115 return -EOPNOTSUPP;
4116
4baf6bea
OO
4117 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
4118 params.acl = parse_acl_data(&rdev->wiphy, info);
4119 if (IS_ERR(params.acl))
4120 return PTR_ERR(params.acl);
4121 }
4122
66cd794e
JB
4123 nl80211_calculate_ap_params(&params);
4124
c56589ed 4125 wdev_lock(wdev);
e35e4d28 4126 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 4127 if (!err) {
683b6d3b 4128 wdev->preset_chandef = params.chandef;
8860020e 4129 wdev->beacon_interval = params.beacon_interval;
9e0e2961 4130 wdev->chandef = params.chandef;
06e191e2
AQ
4131 wdev->ssid_len = params.ssid_len;
4132 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
46c1dd0c 4133 }
c56589ed 4134 wdev_unlock(wdev);
77765eaf
VT
4135
4136 kfree(params.acl);
4137
56d1893d 4138 return err;
ed1b6cc7
JB
4139}
4140
8860020e
JB
4141static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
4142{
4143 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4144 struct net_device *dev = info->user_ptr[1];
4145 struct wireless_dev *wdev = dev->ieee80211_ptr;
4146 struct cfg80211_beacon_data params;
4147 int err;
4148
4149 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4150 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4151 return -EOPNOTSUPP;
4152
4153 if (!rdev->ops->change_beacon)
4154 return -EOPNOTSUPP;
4155
4156 if (!wdev->beacon_interval)
4157 return -EINVAL;
4158
a1193be8 4159 err = nl80211_parse_beacon(info->attrs, &params);
8860020e
JB
4160 if (err)
4161 return err;
4162
c56589ed
SW
4163 wdev_lock(wdev);
4164 err = rdev_change_beacon(rdev, dev, &params);
4165 wdev_unlock(wdev);
4166
4167 return err;
8860020e
JB
4168}
4169
4170static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 4171{
4c476991
JB
4172 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4173 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 4174
7c8d5e03 4175 return cfg80211_stop_ap(rdev, dev, false);
ed1b6cc7
JB
4176}
4177
5727ef1b
JB
4178static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
4179 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
4180 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
4181 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 4182 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 4183 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 4184 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
4185};
4186
eccb8e8f 4187static int parse_station_flags(struct genl_info *info,
bdd3ae3d 4188 enum nl80211_iftype iftype,
eccb8e8f 4189 struct station_parameters *params)
5727ef1b
JB
4190{
4191 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 4192 struct nlattr *nla;
5727ef1b
JB
4193 int flag;
4194
eccb8e8f
JB
4195 /*
4196 * Try parsing the new attribute first so userspace
4197 * can specify both for older kernels.
4198 */
4199 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
4200 if (nla) {
4201 struct nl80211_sta_flag_update *sta_flags;
4202
4203 sta_flags = nla_data(nla);
4204 params->sta_flags_mask = sta_flags->mask;
4205 params->sta_flags_set = sta_flags->set;
77ee7c89 4206 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
4207 if ((params->sta_flags_mask |
4208 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
4209 return -EINVAL;
4210 return 0;
4211 }
4212
4213 /* if present, parse the old attribute */
5727ef1b 4214
eccb8e8f 4215 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
4216 if (!nla)
4217 return 0;
4218
fceb6435 4219 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX, nla,
fe52145f 4220 sta_flags_policy, info->extack))
5727ef1b
JB
4221 return -EINVAL;
4222
bdd3ae3d
JB
4223 /*
4224 * Only allow certain flags for interface types so that
4225 * other attributes are silently ignored. Remember that
4226 * this is backward compatibility code with old userspace
4227 * and shouldn't be hit in other cases anyway.
4228 */
4229 switch (iftype) {
4230 case NL80211_IFTYPE_AP:
4231 case NL80211_IFTYPE_AP_VLAN:
4232 case NL80211_IFTYPE_P2P_GO:
4233 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
4234 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
4235 BIT(NL80211_STA_FLAG_WME) |
4236 BIT(NL80211_STA_FLAG_MFP);
4237 break;
4238 case NL80211_IFTYPE_P2P_CLIENT:
4239 case NL80211_IFTYPE_STATION:
4240 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
4241 BIT(NL80211_STA_FLAG_TDLS_PEER);
4242 break;
4243 case NL80211_IFTYPE_MESH_POINT:
4244 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4245 BIT(NL80211_STA_FLAG_MFP) |
4246 BIT(NL80211_STA_FLAG_AUTHORIZED);
4247 default:
4248 return -EINVAL;
4249 }
5727ef1b 4250
3383b5a6
JB
4251 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
4252 if (flags[flag]) {
eccb8e8f 4253 params->sta_flags_set |= (1<<flag);
5727ef1b 4254
3383b5a6
JB
4255 /* no longer support new API additions in old API */
4256 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
4257 return -EINVAL;
4258 }
4259 }
4260
5727ef1b
JB
4261 return 0;
4262}
4263
c8dcfd8a
FF
4264static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
4265 int attr)
4266{
4267 struct nlattr *rate;
8eb41c8d
VK
4268 u32 bitrate;
4269 u16 bitrate_compat;
bbf67e45 4270 enum nl80211_rate_info rate_flg;
c8dcfd8a
FF
4271
4272 rate = nla_nest_start(msg, attr);
4273 if (!rate)
db9c64cf 4274 return false;
c8dcfd8a
FF
4275
4276 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
4277 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
4278 /* report 16-bit bitrate only if we can */
4279 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
4280 if (bitrate > 0 &&
4281 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
4282 return false;
4283 if (bitrate_compat > 0 &&
4284 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
4285 return false;
4286
b51f3bee
JB
4287 switch (info->bw) {
4288 case RATE_INFO_BW_5:
4289 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH;
4290 break;
4291 case RATE_INFO_BW_10:
4292 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH;
4293 break;
4294 default:
4295 WARN_ON(1);
4296 /* fall through */
4297 case RATE_INFO_BW_20:
4298 rate_flg = 0;
4299 break;
4300 case RATE_INFO_BW_40:
4301 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH;
4302 break;
4303 case RATE_INFO_BW_80:
4304 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH;
4305 break;
4306 case RATE_INFO_BW_160:
4307 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH;
4308 break;
4309 }
4310
4311 if (rate_flg && nla_put_flag(msg, rate_flg))
4312 return false;
4313
db9c64cf
JB
4314 if (info->flags & RATE_INFO_FLAGS_MCS) {
4315 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
4316 return false;
db9c64cf
JB
4317 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
4318 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
4319 return false;
4320 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
4321 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
4322 return false;
4323 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
4324 return false;
db9c64cf
JB
4325 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
4326 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
4327 return false;
4328 }
c8dcfd8a
FF
4329
4330 nla_nest_end(msg, rate);
4331 return true;
c8dcfd8a
FF
4332}
4333
119363c7
FF
4334static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
4335 int id)
4336{
4337 void *attr;
4338 int i = 0;
4339
4340 if (!mask)
4341 return true;
4342
4343 attr = nla_nest_start(msg, id);
4344 if (!attr)
4345 return false;
4346
4347 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
4348 if (!(mask & BIT(i)))
4349 continue;
4350
4351 if (nla_put_u8(msg, i, signal[i]))
4352 return false;
4353 }
4354
4355 nla_nest_end(msg, attr);
4356
4357 return true;
4358}
4359
cf5ead82
JB
4360static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid,
4361 u32 seq, int flags,
66266b3a
JL
4362 struct cfg80211_registered_device *rdev,
4363 struct net_device *dev,
98b62183 4364 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
4365{
4366 void *hdr;
f4263c98 4367 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 4368
cf5ead82 4369 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
fd5b74dc
JB
4370 if (!hdr)
4371 return -1;
4372
9360ffd1
DM
4373 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
4374 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
4375 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
4376 goto nla_put_failure;
f5ea9120 4377
2ec600d6
LCC
4378 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
4379 if (!sinfoattr)
fd5b74dc 4380 goto nla_put_failure;
319090bf
JB
4381
4382#define PUT_SINFO(attr, memb, type) do { \
d686b920 4383 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \
739960f1 4384 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \
319090bf
JB
4385 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \
4386 sinfo->memb)) \
4387 goto nla_put_failure; \
4388 } while (0)
d686b920
JB
4389#define PUT_SINFO_U64(attr, memb) do { \
4390 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \
4391 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \
4392 sinfo->memb, NL80211_STA_INFO_PAD)) \
4393 goto nla_put_failure; \
4394 } while (0)
319090bf
JB
4395
4396 PUT_SINFO(CONNECTED_TIME, connected_time, u32);
4397 PUT_SINFO(INACTIVE_TIME, inactive_time, u32);
4398
4399 if (sinfo->filled & (BIT(NL80211_STA_INFO_RX_BYTES) |
4400 BIT(NL80211_STA_INFO_RX_BYTES64)) &&
9360ffd1 4401 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 4402 (u32)sinfo->rx_bytes))
9360ffd1 4403 goto nla_put_failure;
319090bf
JB
4404
4405 if (sinfo->filled & (BIT(NL80211_STA_INFO_TX_BYTES) |
4406 BIT(NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 4407 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
4408 (u32)sinfo->tx_bytes))
4409 goto nla_put_failure;
319090bf 4410
d686b920
JB
4411 PUT_SINFO_U64(RX_BYTES64, rx_bytes);
4412 PUT_SINFO_U64(TX_BYTES64, tx_bytes);
319090bf
JB
4413 PUT_SINFO(LLID, llid, u16);
4414 PUT_SINFO(PLID, plid, u16);
4415 PUT_SINFO(PLINK_STATE, plink_state, u8);
d686b920 4416 PUT_SINFO_U64(RX_DURATION, rx_duration);
319090bf 4417
66266b3a
JL
4418 switch (rdev->wiphy.signal_type) {
4419 case CFG80211_SIGNAL_TYPE_MBM:
319090bf
JB
4420 PUT_SINFO(SIGNAL, signal, u8);
4421 PUT_SINFO(SIGNAL_AVG, signal_avg, u8);
66266b3a
JL
4422 break;
4423 default:
4424 break;
4425 }
319090bf 4426 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL)) {
119363c7
FF
4427 if (!nl80211_put_signal(msg, sinfo->chains,
4428 sinfo->chain_signal,
4429 NL80211_STA_INFO_CHAIN_SIGNAL))
4430 goto nla_put_failure;
4431 }
319090bf 4432 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) {
119363c7
FF
4433 if (!nl80211_put_signal(msg, sinfo->chains,
4434 sinfo->chain_signal_avg,
4435 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
4436 goto nla_put_failure;
4437 }
319090bf 4438 if (sinfo->filled & BIT(NL80211_STA_INFO_TX_BITRATE)) {
c8dcfd8a
FF
4439 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
4440 NL80211_STA_INFO_TX_BITRATE))
4441 goto nla_put_failure;
4442 }
319090bf 4443 if (sinfo->filled & BIT(NL80211_STA_INFO_RX_BITRATE)) {
c8dcfd8a
FF
4444 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
4445 NL80211_STA_INFO_RX_BITRATE))
420e7fab 4446 goto nla_put_failure;
420e7fab 4447 }
319090bf
JB
4448
4449 PUT_SINFO(RX_PACKETS, rx_packets, u32);
4450 PUT_SINFO(TX_PACKETS, tx_packets, u32);
4451 PUT_SINFO(TX_RETRIES, tx_retries, u32);
4452 PUT_SINFO(TX_FAILED, tx_failed, u32);
4453 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32);
4454 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32);
4455 PUT_SINFO(LOCAL_PM, local_pm, u32);
4456 PUT_SINFO(PEER_PM, peer_pm, u32);
4457 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32);
4458
4459 if (sinfo->filled & BIT(NL80211_STA_INFO_BSS_PARAM)) {
f4263c98
PS
4460 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
4461 if (!bss_param)
4462 goto nla_put_failure;
4463
9360ffd1
DM
4464 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
4465 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
4466 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
4467 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
4468 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
4469 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
4470 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
4471 sinfo->bss_param.dtim_period) ||
4472 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
4473 sinfo->bss_param.beacon_interval))
4474 goto nla_put_failure;
f4263c98
PS
4475
4476 nla_nest_end(msg, bss_param);
4477 }
319090bf 4478 if ((sinfo->filled & BIT(NL80211_STA_INFO_STA_FLAGS)) &&
9360ffd1
DM
4479 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
4480 sizeof(struct nl80211_sta_flag_update),
4481 &sinfo->sta_flags))
4482 goto nla_put_failure;
319090bf 4483
d686b920
JB
4484 PUT_SINFO_U64(T_OFFSET, t_offset);
4485 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc);
4486 PUT_SINFO_U64(BEACON_RX, rx_beacon);
a76b1942 4487 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8);
319090bf
JB
4488
4489#undef PUT_SINFO
d686b920 4490#undef PUT_SINFO_U64
6de39808
JB
4491
4492 if (sinfo->filled & BIT(NL80211_STA_INFO_TID_STATS)) {
4493 struct nlattr *tidsattr;
4494 int tid;
4495
4496 tidsattr = nla_nest_start(msg, NL80211_STA_INFO_TID_STATS);
4497 if (!tidsattr)
4498 goto nla_put_failure;
4499
4500 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) {
4501 struct cfg80211_tid_stats *tidstats;
4502 struct nlattr *tidattr;
4503
4504 tidstats = &sinfo->pertid[tid];
4505
4506 if (!tidstats->filled)
4507 continue;
4508
4509 tidattr = nla_nest_start(msg, tid + 1);
4510 if (!tidattr)
4511 goto nla_put_failure;
4512
d686b920 4513#define PUT_TIDVAL_U64(attr, memb) do { \
6de39808 4514 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \
d686b920
JB
4515 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \
4516 tidstats->memb, NL80211_TID_STATS_PAD)) \
6de39808
JB
4517 goto nla_put_failure; \
4518 } while (0)
4519
d686b920
JB
4520 PUT_TIDVAL_U64(RX_MSDU, rx_msdu);
4521 PUT_TIDVAL_U64(TX_MSDU, tx_msdu);
4522 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries);
4523 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed);
6de39808 4524
d686b920 4525#undef PUT_TIDVAL_U64
6de39808
JB
4526 nla_nest_end(msg, tidattr);
4527 }
4528
4529 nla_nest_end(msg, tidsattr);
4530 }
4531
2ec600d6 4532 nla_nest_end(msg, sinfoattr);
fd5b74dc 4533
319090bf 4534 if (sinfo->assoc_req_ies_len &&
9360ffd1
DM
4535 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
4536 sinfo->assoc_req_ies))
4537 goto nla_put_failure;
50d3dfb7 4538
053c095a
JB
4539 genlmsg_end(msg, hdr);
4540 return 0;
fd5b74dc
JB
4541
4542 nla_put_failure:
bc3ed28c
TG
4543 genlmsg_cancel(msg, hdr);
4544 return -EMSGSIZE;
fd5b74dc
JB
4545}
4546
2ec600d6 4547static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 4548 struct netlink_callback *cb)
2ec600d6 4549{
2ec600d6 4550 struct station_info sinfo;
1b8ec87a 4551 struct cfg80211_registered_device *rdev;
97990a06 4552 struct wireless_dev *wdev;
2ec600d6 4553 u8 mac_addr[ETH_ALEN];
97990a06 4554 int sta_idx = cb->args[2];
2ec600d6 4555 int err;
2ec600d6 4556
ea90e0dc 4557 rtnl_lock();
1b8ec87a 4558 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893 4559 if (err)
ea90e0dc 4560 goto out_err;
bba95fef 4561
97990a06
JB
4562 if (!wdev->netdev) {
4563 err = -EINVAL;
4564 goto out_err;
4565 }
4566
1b8ec87a 4567 if (!rdev->ops->dump_station) {
eec60b03 4568 err = -EOPNOTSUPP;
bba95fef
JB
4569 goto out_err;
4570 }
4571
bba95fef 4572 while (1) {
f612cedf 4573 memset(&sinfo, 0, sizeof(sinfo));
1b8ec87a 4574 err = rdev_dump_station(rdev, wdev->netdev, sta_idx,
e35e4d28 4575 mac_addr, &sinfo);
bba95fef
JB
4576 if (err == -ENOENT)
4577 break;
4578 if (err)
3b85875a 4579 goto out_err;
bba95fef 4580
cf5ead82 4581 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION,
15e47304 4582 NETLINK_CB(cb->skb).portid,
bba95fef 4583 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1b8ec87a 4584 rdev, wdev->netdev, mac_addr,
bba95fef
JB
4585 &sinfo) < 0)
4586 goto out;
4587
4588 sta_idx++;
4589 }
4590
bba95fef 4591 out:
97990a06 4592 cb->args[2] = sta_idx;
bba95fef 4593 err = skb->len;
bba95fef 4594 out_err:
ea90e0dc 4595 rtnl_unlock();
bba95fef
JB
4596
4597 return err;
2ec600d6 4598}
fd5b74dc 4599
5727ef1b
JB
4600static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
4601{
4c476991
JB
4602 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4603 struct net_device *dev = info->user_ptr[1];
2ec600d6 4604 struct station_info sinfo;
fd5b74dc
JB
4605 struct sk_buff *msg;
4606 u8 *mac_addr = NULL;
4c476991 4607 int err;
fd5b74dc 4608
2ec600d6 4609 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
4610
4611 if (!info->attrs[NL80211_ATTR_MAC])
4612 return -EINVAL;
4613
4614 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4615
4c476991
JB
4616 if (!rdev->ops->get_station)
4617 return -EOPNOTSUPP;
3b85875a 4618
e35e4d28 4619 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 4620 if (err)
4c476991 4621 return err;
2ec600d6 4622
fd2120ca 4623 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 4624 if (!msg)
4c476991 4625 return -ENOMEM;
fd5b74dc 4626
cf5ead82
JB
4627 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION,
4628 info->snd_portid, info->snd_seq, 0,
66266b3a 4629 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
4630 nlmsg_free(msg);
4631 return -ENOBUFS;
4632 }
3b85875a 4633
4c476991 4634 return genlmsg_reply(msg, info);
5727ef1b
JB
4635}
4636
77ee7c89
JB
4637int cfg80211_check_station_change(struct wiphy *wiphy,
4638 struct station_parameters *params,
4639 enum cfg80211_station_type statype)
4640{
e4208427
AB
4641 if (params->listen_interval != -1 &&
4642 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89 4643 return -EINVAL;
e4208427 4644
17b94247
AB
4645 if (params->support_p2p_ps != -1 &&
4646 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
4647 return -EINVAL;
4648
c72e1140 4649 if (params->aid &&
e4208427
AB
4650 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
4651 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89
JB
4652 return -EINVAL;
4653
4654 /* When you run into this, adjust the code below for the new flag */
4655 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
4656
4657 switch (statype) {
eef941e6
TP
4658 case CFG80211_STA_MESH_PEER_KERNEL:
4659 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
4660 /*
4661 * No ignoring the TDLS flag here -- the userspace mesh
4662 * code doesn't have the bug of including TDLS in the
4663 * mask everywhere.
4664 */
4665 if (params->sta_flags_mask &
4666 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4667 BIT(NL80211_STA_FLAG_MFP) |
4668 BIT(NL80211_STA_FLAG_AUTHORIZED)))
4669 return -EINVAL;
4670 break;
4671 case CFG80211_STA_TDLS_PEER_SETUP:
4672 case CFG80211_STA_TDLS_PEER_ACTIVE:
4673 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
4674 return -EINVAL;
4675 /* ignore since it can't change */
4676 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
4677 break;
4678 default:
4679 /* disallow mesh-specific things */
4680 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
4681 return -EINVAL;
4682 if (params->local_pm)
4683 return -EINVAL;
4684 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
4685 return -EINVAL;
4686 }
4687
4688 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
4689 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
4690 /* TDLS can't be set, ... */
4691 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4692 return -EINVAL;
4693 /*
4694 * ... but don't bother the driver with it. This works around
4695 * a hostapd/wpa_supplicant issue -- it always includes the
4696 * TLDS_PEER flag in the mask even for AP mode.
4697 */
4698 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
4699 }
4700
47edb11b
AB
4701 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
4702 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
4703 /* reject other things that can't change */
4704 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
4705 return -EINVAL;
4706 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
4707 return -EINVAL;
4708 if (params->supported_rates)
4709 return -EINVAL;
4710 if (params->ext_capab || params->ht_capa || params->vht_capa)
4711 return -EINVAL;
4712 }
4713
47edb11b
AB
4714 if (statype != CFG80211_STA_AP_CLIENT &&
4715 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
4716 if (params->vlan)
4717 return -EINVAL;
4718 }
4719
4720 switch (statype) {
4721 case CFG80211_STA_AP_MLME_CLIENT:
4722 /* Use this only for authorizing/unauthorizing a station */
4723 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
4724 return -EOPNOTSUPP;
4725 break;
4726 case CFG80211_STA_AP_CLIENT:
47edb11b 4727 case CFG80211_STA_AP_CLIENT_UNASSOC:
77ee7c89
JB
4728 /* accept only the listed bits */
4729 if (params->sta_flags_mask &
4730 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
4731 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4732 BIT(NL80211_STA_FLAG_ASSOCIATED) |
4733 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
4734 BIT(NL80211_STA_FLAG_WME) |
4735 BIT(NL80211_STA_FLAG_MFP)))
4736 return -EINVAL;
4737
4738 /* but authenticated/associated only if driver handles it */
4739 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
4740 params->sta_flags_mask &
4741 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4742 BIT(NL80211_STA_FLAG_ASSOCIATED)))
4743 return -EINVAL;
4744 break;
4745 case CFG80211_STA_IBSS:
4746 case CFG80211_STA_AP_STA:
4747 /* reject any changes other than AUTHORIZED */
4748 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
4749 return -EINVAL;
4750 break;
4751 case CFG80211_STA_TDLS_PEER_SETUP:
4752 /* reject any changes other than AUTHORIZED or WME */
4753 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
4754 BIT(NL80211_STA_FLAG_WME)))
4755 return -EINVAL;
4756 /* force (at least) rates when authorizing */
4757 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
4758 !params->supported_rates)
4759 return -EINVAL;
4760 break;
4761 case CFG80211_STA_TDLS_PEER_ACTIVE:
4762 /* reject any changes */
4763 return -EINVAL;
eef941e6 4764 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
4765 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
4766 return -EINVAL;
4767 break;
eef941e6 4768 case CFG80211_STA_MESH_PEER_USER:
42925040
CYY
4769 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION &&
4770 params->plink_action != NL80211_PLINK_ACTION_BLOCK)
77ee7c89
JB
4771 return -EINVAL;
4772 break;
4773 }
4774
06f7c88c
BL
4775 /*
4776 * Older kernel versions ignored this attribute entirely, so don't
4777 * reject attempts to update it but mark it as unused instead so the
4778 * driver won't look at the data.
4779 */
4780 if (statype != CFG80211_STA_AP_CLIENT_UNASSOC &&
4781 statype != CFG80211_STA_TDLS_PEER_SETUP)
4782 params->opmode_notif_used = false;
4783
77ee7c89
JB
4784 return 0;
4785}
4786EXPORT_SYMBOL(cfg80211_check_station_change);
4787
5727ef1b 4788/*
c258d2de 4789 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 4790 */
80b99899
JB
4791static struct net_device *get_vlan(struct genl_info *info,
4792 struct cfg80211_registered_device *rdev)
5727ef1b 4793{
463d0183 4794 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
4795 struct net_device *v;
4796 int ret;
4797
4798 if (!vlanattr)
4799 return NULL;
4800
4801 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
4802 if (!v)
4803 return ERR_PTR(-ENODEV);
4804
4805 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
4806 ret = -EINVAL;
4807 goto error;
5727ef1b 4808 }
80b99899 4809
77ee7c89
JB
4810 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4811 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4812 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
4813 ret = -EINVAL;
4814 goto error;
4815 }
4816
80b99899
JB
4817 if (!netif_running(v)) {
4818 ret = -ENETDOWN;
4819 goto error;
4820 }
4821
4822 return v;
4823 error:
4824 dev_put(v);
4825 return ERR_PTR(ret);
5727ef1b
JB
4826}
4827
94e860f1
JB
4828static const struct nla_policy
4829nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
df881293
JM
4830 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
4831 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
4832};
4833
ff276691
JB
4834static int nl80211_parse_sta_wme(struct genl_info *info,
4835 struct station_parameters *params)
df881293 4836{
df881293
JM
4837 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
4838 struct nlattr *nla;
4839 int err;
4840
df881293
JM
4841 /* parse WME attributes if present */
4842 if (!info->attrs[NL80211_ATTR_STA_WME])
4843 return 0;
4844
4845 nla = info->attrs[NL80211_ATTR_STA_WME];
4846 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
fe52145f 4847 nl80211_sta_wme_policy, info->extack);
df881293
JM
4848 if (err)
4849 return err;
4850
4851 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
4852 params->uapsd_queues = nla_get_u8(
4853 tb[NL80211_STA_WME_UAPSD_QUEUES]);
4854 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
4855 return -EINVAL;
4856
4857 if (tb[NL80211_STA_WME_MAX_SP])
4858 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
4859
4860 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
4861 return -EINVAL;
4862
4863 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
4864
4865 return 0;
4866}
4867
c01fc9ad
SD
4868static int nl80211_parse_sta_channel_info(struct genl_info *info,
4869 struct station_parameters *params)
4870{
4871 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
4872 params->supported_channels =
4873 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
4874 params->supported_channels_len =
4875 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
4876 /*
4877 * Need to include at least one (first channel, number of
4878 * channels) tuple for each subband, and must have proper
4879 * tuples for the rest of the data as well.
4880 */
4881 if (params->supported_channels_len < 2)
4882 return -EINVAL;
4883 if (params->supported_channels_len % 2)
4884 return -EINVAL;
4885 }
4886
4887 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
4888 params->supported_oper_classes =
4889 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
4890 params->supported_oper_classes_len =
4891 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
4892 /*
4893 * The value of the Length field of the Supported Operating
4894 * Classes element is between 2 and 253.
4895 */
4896 if (params->supported_oper_classes_len < 2 ||
4897 params->supported_oper_classes_len > 253)
4898 return -EINVAL;
4899 }
4900 return 0;
4901}
4902
ff276691
JB
4903static int nl80211_set_station_tdls(struct genl_info *info,
4904 struct station_parameters *params)
4905{
c01fc9ad 4906 int err;
ff276691 4907 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
4908 if (info->attrs[NL80211_ATTR_PEER_AID])
4909 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
4910 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
4911 params->ht_capa =
4912 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
4913 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
4914 params->vht_capa =
4915 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
4916
c01fc9ad
SD
4917 err = nl80211_parse_sta_channel_info(info, params);
4918 if (err)
4919 return err;
4920
ff276691
JB
4921 return nl80211_parse_sta_wme(info, params);
4922}
4923
5727ef1b
JB
4924static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
4925{
4c476991 4926 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 4927 struct net_device *dev = info->user_ptr[1];
5727ef1b 4928 struct station_parameters params;
77ee7c89
JB
4929 u8 *mac_addr;
4930 int err;
5727ef1b
JB
4931
4932 memset(&params, 0, sizeof(params));
4933
77ee7c89
JB
4934 if (!rdev->ops->change_station)
4935 return -EOPNOTSUPP;
4936
e4208427
AB
4937 /*
4938 * AID and listen_interval properties can be set only for unassociated
4939 * station. Include these parameters here and will check them in
4940 * cfg80211_check_station_change().
4941 */
a9bc31e4
AB
4942 if (info->attrs[NL80211_ATTR_STA_AID])
4943 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
e4208427
AB
4944
4945 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
4946 params.listen_interval =
4947 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
4948 else
4949 params.listen_interval = -1;
5727ef1b 4950
17b94247
AB
4951 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
4952 u8 tmp;
4953
4954 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
4955 if (tmp >= NUM_NL80211_P2P_PS_STATUS)
4956 return -EINVAL;
4957
4958 params.support_p2p_ps = tmp;
4959 } else {
4960 params.support_p2p_ps = -1;
4961 }
4962
5727ef1b
JB
4963 if (!info->attrs[NL80211_ATTR_MAC])
4964 return -EINVAL;
4965
4966 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4967
4968 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
4969 params.supported_rates =
4970 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4971 params.supported_rates_len =
4972 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
4973 }
4974
9d62a986
JM
4975 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
4976 params.capability =
4977 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
4978 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
4979 }
4980
4981 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
4982 params.ext_capab =
4983 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4984 params.ext_capab_len =
4985 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
4986 }
4987
bdd3ae3d 4988 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
4989 return -EINVAL;
4990
f8bacc21 4991 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
2ec600d6 4992 params.plink_action =
f8bacc21
JB
4993 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
4994 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
4995 return -EINVAL;
4996 }
2ec600d6 4997
f8bacc21 4998 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 4999 params.plink_state =
f8bacc21
JB
5000 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
5001 if (params.plink_state >= NUM_NL80211_PLINK_STATES)
5002 return -EINVAL;
7d27a0ba
MH
5003 if (info->attrs[NL80211_ATTR_MESH_PEER_AID]) {
5004 params.peer_aid = nla_get_u16(
5005 info->attrs[NL80211_ATTR_MESH_PEER_AID]);
5006 if (params.peer_aid > IEEE80211_MAX_AID)
5007 return -EINVAL;
5008 }
f8bacc21
JB
5009 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
5010 }
9c3990aa 5011
3b1c5a53
MP
5012 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) {
5013 enum nl80211_mesh_power_mode pm = nla_get_u32(
5014 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
5015
5016 if (pm <= NL80211_MESH_POWER_UNKNOWN ||
5017 pm > NL80211_MESH_POWER_MAX)
5018 return -EINVAL;
5019
5020 params.local_pm = pm;
5021 }
5022
06f7c88c
BL
5023 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
5024 params.opmode_notif_used = true;
5025 params.opmode_notif =
5026 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
5027 }
5028
77ee7c89
JB
5029 /* Include parameters for TDLS peer (will check later) */
5030 err = nl80211_set_station_tdls(info, &params);
5031 if (err)
5032 return err;
5033
5034 params.vlan = get_vlan(info, rdev);
5035 if (IS_ERR(params.vlan))
5036 return PTR_ERR(params.vlan);
5037
a97f4424
JB
5038 switch (dev->ieee80211_ptr->iftype) {
5039 case NL80211_IFTYPE_AP:
5040 case NL80211_IFTYPE_AP_VLAN:
074ac8df 5041 case NL80211_IFTYPE_P2P_GO:
074ac8df 5042 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 5043 case NL80211_IFTYPE_STATION:
267335d6 5044 case NL80211_IFTYPE_ADHOC:
a97f4424 5045 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
5046 break;
5047 default:
77ee7c89
JB
5048 err = -EOPNOTSUPP;
5049 goto out_put_vlan;
034d655e
JB
5050 }
5051
77ee7c89 5052 /* driver will call cfg80211_check_station_change() */
e35e4d28 5053 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 5054
77ee7c89 5055 out_put_vlan:
5727ef1b
JB
5056 if (params.vlan)
5057 dev_put(params.vlan);
3b85875a 5058
5727ef1b
JB
5059 return err;
5060}
5061
5062static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
5063{
4c476991 5064 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 5065 int err;
4c476991 5066 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
5067 struct station_parameters params;
5068 u8 *mac_addr = NULL;
bda95eb1
JB
5069 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5070 BIT(NL80211_STA_FLAG_ASSOCIATED);
5727ef1b
JB
5071
5072 memset(&params, 0, sizeof(params));
5073
984c311b
JB
5074 if (!rdev->ops->add_station)
5075 return -EOPNOTSUPP;
5076
5727ef1b
JB
5077 if (!info->attrs[NL80211_ATTR_MAC])
5078 return -EINVAL;
5079
5727ef1b
JB
5080 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
5081 return -EINVAL;
5082
5083 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
5084 return -EINVAL;
5085
5e4b6f56
JM
5086 if (!info->attrs[NL80211_ATTR_STA_AID] &&
5087 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
5088 return -EINVAL;
5089
5727ef1b
JB
5090 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5091 params.supported_rates =
5092 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
5093 params.supported_rates_len =
5094 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
5095 params.listen_interval =
5096 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 5097
17b94247
AB
5098 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
5099 u8 tmp;
5100
5101 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
5102 if (tmp >= NUM_NL80211_P2P_PS_STATUS)
5103 return -EINVAL;
5104
5105 params.support_p2p_ps = tmp;
5106 } else {
5107 /*
5108 * if not specified, assume it's supported for P2P GO interface,
5109 * and is NOT supported for AP interface
5110 */
5111 params.support_p2p_ps =
5112 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO;
5113 }
5114
3d124ea2 5115 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 5116 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
5117 else
5118 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
0e956c13
TLSC
5119 if (!params.aid || params.aid > IEEE80211_MAX_AID)
5120 return -EINVAL;
51b50fbe 5121
9d62a986
JM
5122 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
5123 params.capability =
5124 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
5125 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
5126 }
5127
5128 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
5129 params.ext_capab =
5130 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
5131 params.ext_capab_len =
5132 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
5133 }
5134
36aedc90
JM
5135 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
5136 params.ht_capa =
5137 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 5138
f461be3e
MP
5139 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
5140 params.vht_capa =
5141 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
5142
60f4a7b1
MK
5143 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
5144 params.opmode_notif_used = true;
5145 params.opmode_notif =
5146 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
5147 }
5148
f8bacc21 5149 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) {
96b78dff 5150 params.plink_action =
f8bacc21
JB
5151 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
5152 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS)
5153 return -EINVAL;
5154 }
96b78dff 5155
c01fc9ad
SD
5156 err = nl80211_parse_sta_channel_info(info, &params);
5157 if (err)
5158 return err;
5159
ff276691
JB
5160 err = nl80211_parse_sta_wme(info, &params);
5161 if (err)
5162 return err;
bdd90d5e 5163
bdd3ae3d 5164 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
5165 return -EINVAL;
5166
496fcc29
JB
5167 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT
5168 * as userspace might just pass through the capabilities from the IEs
5169 * directly, rather than enforcing this restriction and returning an
5170 * error in this case.
5171 */
5172 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) {
5173 params.ht_capa = NULL;
5174 params.vht_capa = NULL;
5175 }
5176
77ee7c89
JB
5177 /* When you run into this, adjust the code below for the new flag */
5178 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
5179
bdd90d5e
JB
5180 switch (dev->ieee80211_ptr->iftype) {
5181 case NL80211_IFTYPE_AP:
5182 case NL80211_IFTYPE_AP_VLAN:
5183 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
5184 /* ignore WME attributes if iface/sta is not capable */
5185 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
5186 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
5187 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 5188
bdd90d5e 5189 /* TDLS peers cannot be added */
3d124ea2
JM
5190 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
5191 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 5192 return -EINVAL;
bdd90d5e
JB
5193 /* but don't bother the driver with it */
5194 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 5195
d582cffb
JB
5196 /* allow authenticated/associated only if driver handles it */
5197 if (!(rdev->wiphy.features &
5198 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
bda95eb1 5199 params.sta_flags_mask & auth_assoc)
d582cffb
JB
5200 return -EINVAL;
5201
bda95eb1
JB
5202 /* Older userspace, or userspace wanting to be compatible with
5203 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth
5204 * and assoc flags in the mask, but assumes the station will be
5205 * added as associated anyway since this was the required driver
5206 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was
5207 * introduced.
5208 * In order to not bother drivers with this quirk in the API
5209 * set the flags in both the mask and set for new stations in
5210 * this case.
5211 */
5212 if (!(params.sta_flags_mask & auth_assoc)) {
5213 params.sta_flags_mask |= auth_assoc;
5214 params.sta_flags_set |= auth_assoc;
5215 }
5216
bdd90d5e
JB
5217 /* must be last in here for error handling */
5218 params.vlan = get_vlan(info, rdev);
5219 if (IS_ERR(params.vlan))
5220 return PTR_ERR(params.vlan);
5221 break;
5222 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
5223 /* ignore uAPSD data */
5224 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
5225
d582cffb
JB
5226 /* associated is disallowed */
5227 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
5228 return -EINVAL;
bdd90d5e 5229 /* TDLS peers cannot be added */
3d124ea2
JM
5230 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
5231 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
5232 return -EINVAL;
5233 break;
5234 case NL80211_IFTYPE_STATION:
93d08f0b 5235 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
5236 /* ignore uAPSD data */
5237 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
5238
77ee7c89
JB
5239 /* these are disallowed */
5240 if (params.sta_flags_mask &
5241 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
5242 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 5243 return -EINVAL;
bdd90d5e
JB
5244 /* Only TDLS peers can be added */
5245 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
5246 return -EINVAL;
5247 /* Can only add if TDLS ... */
5248 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
5249 return -EOPNOTSUPP;
5250 /* ... with external setup is supported */
5251 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
5252 return -EOPNOTSUPP;
77ee7c89
JB
5253 /*
5254 * Older wpa_supplicant versions always mark the TDLS peer
5255 * as authorized, but it shouldn't yet be.
5256 */
5257 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
5258 break;
5259 default:
5260 return -EOPNOTSUPP;
c75786c9
EP
5261 }
5262
bdd90d5e 5263 /* be aware of params.vlan when changing code here */
5727ef1b 5264
e35e4d28 5265 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 5266
5727ef1b
JB
5267 if (params.vlan)
5268 dev_put(params.vlan);
5727ef1b
JB
5269 return err;
5270}
5271
5272static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
5273{
4c476991
JB
5274 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5275 struct net_device *dev = info->user_ptr[1];
89c771e5
JM
5276 struct station_del_parameters params;
5277
5278 memset(&params, 0, sizeof(params));
5727ef1b
JB
5279
5280 if (info->attrs[NL80211_ATTR_MAC])
89c771e5 5281 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
5727ef1b 5282
e80cf853 5283 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 5284 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 5285 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
5286 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5287 return -EINVAL;
5727ef1b 5288
4c476991
JB
5289 if (!rdev->ops->del_station)
5290 return -EOPNOTSUPP;
3b85875a 5291
98856866
JM
5292 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) {
5293 params.subtype =
5294 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
5295 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 &&
5296 params.subtype != IEEE80211_STYPE_DEAUTH >> 4)
5297 return -EINVAL;
5298 } else {
5299 /* Default to Deauthentication frame */
5300 params.subtype = IEEE80211_STYPE_DEAUTH >> 4;
5301 }
5302
5303 if (info->attrs[NL80211_ATTR_REASON_CODE]) {
5304 params.reason_code =
5305 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5306 if (params.reason_code == 0)
5307 return -EINVAL; /* 0 is reserved */
5308 } else {
5309 /* Default to reason code 2 */
5310 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID;
5311 }
5312
89c771e5 5313 return rdev_del_station(rdev, dev, &params);
5727ef1b
JB
5314}
5315
15e47304 5316static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
5317 int flags, struct net_device *dev,
5318 u8 *dst, u8 *next_hop,
5319 struct mpath_info *pinfo)
5320{
5321 void *hdr;
5322 struct nlattr *pinfoattr;
5323
1ef4c850 5324 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH);
2ec600d6
LCC
5325 if (!hdr)
5326 return -1;
5327
9360ffd1
DM
5328 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5329 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
5330 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
5331 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
5332 goto nla_put_failure;
f5ea9120 5333
2ec600d6
LCC
5334 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
5335 if (!pinfoattr)
5336 goto nla_put_failure;
9360ffd1
DM
5337 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
5338 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
5339 pinfo->frame_qlen))
5340 goto nla_put_failure;
5341 if (((pinfo->filled & MPATH_INFO_SN) &&
5342 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
5343 ((pinfo->filled & MPATH_INFO_METRIC) &&
5344 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
5345 pinfo->metric)) ||
5346 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
5347 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
5348 pinfo->exptime)) ||
5349 ((pinfo->filled & MPATH_INFO_FLAGS) &&
5350 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
5351 pinfo->flags)) ||
5352 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
5353 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
5354 pinfo->discovery_timeout)) ||
5355 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
5356 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
5357 pinfo->discovery_retries)))
5358 goto nla_put_failure;
2ec600d6
LCC
5359
5360 nla_nest_end(msg, pinfoattr);
5361
053c095a
JB
5362 genlmsg_end(msg, hdr);
5363 return 0;
2ec600d6
LCC
5364
5365 nla_put_failure:
bc3ed28c
TG
5366 genlmsg_cancel(msg, hdr);
5367 return -EMSGSIZE;
2ec600d6
LCC
5368}
5369
5370static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 5371 struct netlink_callback *cb)
2ec600d6 5372{
2ec600d6 5373 struct mpath_info pinfo;
1b8ec87a 5374 struct cfg80211_registered_device *rdev;
97990a06 5375 struct wireless_dev *wdev;
2ec600d6
LCC
5376 u8 dst[ETH_ALEN];
5377 u8 next_hop[ETH_ALEN];
97990a06 5378 int path_idx = cb->args[2];
2ec600d6 5379 int err;
2ec600d6 5380
ea90e0dc 5381 rtnl_lock();
1b8ec87a 5382 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893 5383 if (err)
ea90e0dc 5384 goto out_err;
bba95fef 5385
1b8ec87a 5386 if (!rdev->ops->dump_mpath) {
eec60b03 5387 err = -EOPNOTSUPP;
bba95fef
JB
5388 goto out_err;
5389 }
5390
97990a06 5391 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 5392 err = -EOPNOTSUPP;
0448b5fc 5393 goto out_err;
eec60b03
JM
5394 }
5395
bba95fef 5396 while (1) {
1b8ec87a 5397 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst,
97990a06 5398 next_hop, &pinfo);
bba95fef 5399 if (err == -ENOENT)
2ec600d6 5400 break;
bba95fef 5401 if (err)
3b85875a 5402 goto out_err;
2ec600d6 5403
15e47304 5404 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 5405 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 5406 wdev->netdev, dst, next_hop,
bba95fef
JB
5407 &pinfo) < 0)
5408 goto out;
2ec600d6 5409
bba95fef 5410 path_idx++;
2ec600d6 5411 }
2ec600d6 5412
bba95fef 5413 out:
97990a06 5414 cb->args[2] = path_idx;
bba95fef 5415 err = skb->len;
bba95fef 5416 out_err:
ea90e0dc 5417 rtnl_unlock();
bba95fef 5418 return err;
2ec600d6
LCC
5419}
5420
5421static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
5422{
4c476991 5423 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 5424 int err;
4c476991 5425 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5426 struct mpath_info pinfo;
5427 struct sk_buff *msg;
5428 u8 *dst = NULL;
5429 u8 next_hop[ETH_ALEN];
5430
5431 memset(&pinfo, 0, sizeof(pinfo));
5432
5433 if (!info->attrs[NL80211_ATTR_MAC])
5434 return -EINVAL;
5435
5436 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5437
4c476991
JB
5438 if (!rdev->ops->get_mpath)
5439 return -EOPNOTSUPP;
2ec600d6 5440
4c476991
JB
5441 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5442 return -EOPNOTSUPP;
eec60b03 5443
e35e4d28 5444 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 5445 if (err)
4c476991 5446 return err;
2ec600d6 5447
fd2120ca 5448 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 5449 if (!msg)
4c476991 5450 return -ENOMEM;
2ec600d6 5451
15e47304 5452 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
5453 dev, dst, next_hop, &pinfo) < 0) {
5454 nlmsg_free(msg);
5455 return -ENOBUFS;
5456 }
3b85875a 5457
4c476991 5458 return genlmsg_reply(msg, info);
2ec600d6
LCC
5459}
5460
5461static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
5462{
4c476991
JB
5463 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5464 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5465 u8 *dst = NULL;
5466 u8 *next_hop = NULL;
5467
5468 if (!info->attrs[NL80211_ATTR_MAC])
5469 return -EINVAL;
5470
5471 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
5472 return -EINVAL;
5473
5474 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5475 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
5476
4c476991
JB
5477 if (!rdev->ops->change_mpath)
5478 return -EOPNOTSUPP;
35a8efe1 5479
4c476991
JB
5480 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5481 return -EOPNOTSUPP;
2ec600d6 5482
e35e4d28 5483 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 5484}
4c476991 5485
2ec600d6
LCC
5486static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
5487{
4c476991
JB
5488 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5489 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5490 u8 *dst = NULL;
5491 u8 *next_hop = NULL;
5492
5493 if (!info->attrs[NL80211_ATTR_MAC])
5494 return -EINVAL;
5495
5496 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
5497 return -EINVAL;
5498
5499 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5500 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
5501
4c476991
JB
5502 if (!rdev->ops->add_mpath)
5503 return -EOPNOTSUPP;
35a8efe1 5504
4c476991
JB
5505 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5506 return -EOPNOTSUPP;
2ec600d6 5507
e35e4d28 5508 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
5509}
5510
5511static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
5512{
4c476991
JB
5513 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5514 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
5515 u8 *dst = NULL;
5516
5517 if (info->attrs[NL80211_ATTR_MAC])
5518 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5519
4c476991
JB
5520 if (!rdev->ops->del_mpath)
5521 return -EOPNOTSUPP;
3b85875a 5522
e35e4d28 5523 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
5524}
5525
66be7d2b
HR
5526static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info)
5527{
5528 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5529 int err;
5530 struct net_device *dev = info->user_ptr[1];
5531 struct mpath_info pinfo;
5532 struct sk_buff *msg;
5533 u8 *dst = NULL;
5534 u8 mpp[ETH_ALEN];
5535
5536 memset(&pinfo, 0, sizeof(pinfo));
5537
5538 if (!info->attrs[NL80211_ATTR_MAC])
5539 return -EINVAL;
5540
5541 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
5542
5543 if (!rdev->ops->get_mpp)
5544 return -EOPNOTSUPP;
5545
5546 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
5547 return -EOPNOTSUPP;
5548
5549 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo);
5550 if (err)
5551 return err;
5552
5553 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5554 if (!msg)
5555 return -ENOMEM;
5556
5557 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
5558 dev, dst, mpp, &pinfo) < 0) {
5559 nlmsg_free(msg);
5560 return -ENOBUFS;
5561 }
5562
5563 return genlmsg_reply(msg, info);
5564}
5565
5566static int nl80211_dump_mpp(struct sk_buff *skb,
5567 struct netlink_callback *cb)
5568{
5569 struct mpath_info pinfo;
5570 struct cfg80211_registered_device *rdev;
5571 struct wireless_dev *wdev;
5572 u8 dst[ETH_ALEN];
5573 u8 mpp[ETH_ALEN];
5574 int path_idx = cb->args[2];
5575 int err;
5576
ea90e0dc 5577 rtnl_lock();
66be7d2b
HR
5578 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
5579 if (err)
ea90e0dc 5580 goto out_err;
66be7d2b
HR
5581
5582 if (!rdev->ops->dump_mpp) {
5583 err = -EOPNOTSUPP;
5584 goto out_err;
5585 }
5586
5587 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
5588 err = -EOPNOTSUPP;
5589 goto out_err;
5590 }
5591
5592 while (1) {
5593 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst,
5594 mpp, &pinfo);
5595 if (err == -ENOENT)
5596 break;
5597 if (err)
5598 goto out_err;
5599
5600 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
5601 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5602 wdev->netdev, dst, mpp,
5603 &pinfo) < 0)
5604 goto out;
5605
5606 path_idx++;
5607 }
5608
5609 out:
5610 cb->args[2] = path_idx;
5611 err = skb->len;
5612 out_err:
ea90e0dc 5613 rtnl_unlock();
66be7d2b
HR
5614 return err;
5615}
5616
9f1ba906
JM
5617static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
5618{
4c476991
JB
5619 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5620 struct net_device *dev = info->user_ptr[1];
c56589ed 5621 struct wireless_dev *wdev = dev->ieee80211_ptr;
9f1ba906 5622 struct bss_parameters params;
c56589ed 5623 int err;
9f1ba906
JM
5624
5625 memset(&params, 0, sizeof(params));
5626 /* default to not changing parameters */
5627 params.use_cts_prot = -1;
5628 params.use_short_preamble = -1;
5629 params.use_short_slot_time = -1;
fd8aaaf3 5630 params.ap_isolate = -1;
50b12f59 5631 params.ht_opmode = -1;
53cabad7
JB
5632 params.p2p_ctwindow = -1;
5633 params.p2p_opp_ps = -1;
9f1ba906
JM
5634
5635 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
5636 params.use_cts_prot =
5637 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
5638 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
5639 params.use_short_preamble =
5640 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
5641 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
5642 params.use_short_slot_time =
5643 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
5644 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5645 params.basic_rates =
5646 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5647 params.basic_rates_len =
5648 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5649 }
fd8aaaf3
FF
5650 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
5651 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
5652 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
5653 params.ht_opmode =
5654 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 5655
53cabad7
JB
5656 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
5657 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5658 return -EINVAL;
5659 params.p2p_ctwindow =
5660 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
5661 if (params.p2p_ctwindow < 0)
5662 return -EINVAL;
5663 if (params.p2p_ctwindow != 0 &&
5664 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
5665 return -EINVAL;
5666 }
5667
5668 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
5669 u8 tmp;
5670
5671 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5672 return -EINVAL;
5673 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
5674 if (tmp > 1)
5675 return -EINVAL;
5676 params.p2p_opp_ps = tmp;
5677 if (params.p2p_opp_ps &&
5678 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
5679 return -EINVAL;
5680 }
5681
4c476991
JB
5682 if (!rdev->ops->change_bss)
5683 return -EOPNOTSUPP;
9f1ba906 5684
074ac8df 5685 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
5686 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5687 return -EOPNOTSUPP;
3b85875a 5688
c56589ed
SW
5689 wdev_lock(wdev);
5690 err = rdev_change_bss(rdev, dev, &params);
5691 wdev_unlock(wdev);
5692
5693 return err;
9f1ba906
JM
5694}
5695
b2e1b302
LR
5696static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
5697{
b2e1b302 5698 char *data = NULL;
05050753 5699 bool is_indoor;
57b5ce07 5700 enum nl80211_user_reg_hint_type user_reg_hint_type;
05050753
I
5701 u32 owner_nlportid;
5702
80778f18
LR
5703 /*
5704 * You should only get this when cfg80211 hasn't yet initialized
5705 * completely when built-in to the kernel right between the time
5706 * window between nl80211_init() and regulatory_init(), if that is
5707 * even possible.
5708 */
458f4f9e 5709 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 5710 return -EINPROGRESS;
80778f18 5711
57b5ce07
LR
5712 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
5713 user_reg_hint_type =
5714 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
5715 else
5716 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
5717
5718 switch (user_reg_hint_type) {
5719 case NL80211_USER_REG_HINT_USER:
5720 case NL80211_USER_REG_HINT_CELL_BASE:
52616f2b
IP
5721 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
5722 return -EINVAL;
5723
5724 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
5725 return regulatory_hint_user(data, user_reg_hint_type);
5726 case NL80211_USER_REG_HINT_INDOOR:
05050753
I
5727 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
5728 owner_nlportid = info->snd_portid;
5729 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR];
5730 } else {
5731 owner_nlportid = 0;
5732 is_indoor = true;
5733 }
5734
5735 return regulatory_hint_indoor(is_indoor, owner_nlportid);
57b5ce07
LR
5736 default:
5737 return -EINVAL;
5738 }
b2e1b302
LR
5739}
5740
1ea4ff3e
JB
5741static int nl80211_reload_regdb(struct sk_buff *skb, struct genl_info *info)
5742{
5743 return reg_reload_regdb();
5744}
5745
24bdd9f4 5746static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 5747 struct genl_info *info)
93da9cc1 5748{
4c476991 5749 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 5750 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
5751 struct wireless_dev *wdev = dev->ieee80211_ptr;
5752 struct mesh_config cur_params;
5753 int err = 0;
93da9cc1 5754 void *hdr;
5755 struct nlattr *pinfoattr;
5756 struct sk_buff *msg;
5757
29cbe68c
JB
5758 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
5759 return -EOPNOTSUPP;
5760
24bdd9f4 5761 if (!rdev->ops->get_mesh_config)
4c476991 5762 return -EOPNOTSUPP;
f3f92586 5763
29cbe68c
JB
5764 wdev_lock(wdev);
5765 /* If not connected, get default parameters */
5766 if (!wdev->mesh_id_len)
5767 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
5768 else
e35e4d28 5769 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
5770 wdev_unlock(wdev);
5771
93da9cc1 5772 if (err)
4c476991 5773 return err;
93da9cc1 5774
5775 /* Draw up a netlink message to send back */
fd2120ca 5776 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5777 if (!msg)
5778 return -ENOMEM;
15e47304 5779 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 5780 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 5781 if (!hdr)
efe1cf0c 5782 goto out;
24bdd9f4 5783 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 5784 if (!pinfoattr)
5785 goto nla_put_failure;
9360ffd1
DM
5786 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5787 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
5788 cur_params.dot11MeshRetryTimeout) ||
5789 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
5790 cur_params.dot11MeshConfirmTimeout) ||
5791 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
5792 cur_params.dot11MeshHoldingTimeout) ||
5793 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
5794 cur_params.dot11MeshMaxPeerLinks) ||
5795 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
5796 cur_params.dot11MeshMaxRetries) ||
5797 nla_put_u8(msg, NL80211_MESHCONF_TTL,
5798 cur_params.dot11MeshTTL) ||
5799 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
5800 cur_params.element_ttl) ||
5801 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
5802 cur_params.auto_open_plinks) ||
7eab0f64
JL
5803 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
5804 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
5805 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
5806 cur_params.dot11MeshHWMPmaxPREQretries) ||
5807 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
5808 cur_params.path_refresh_time) ||
5809 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
5810 cur_params.min_discovery_timeout) ||
5811 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
5812 cur_params.dot11MeshHWMPactivePathTimeout) ||
5813 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
5814 cur_params.dot11MeshHWMPpreqMinInterval) ||
5815 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
5816 cur_params.dot11MeshHWMPperrMinInterval) ||
5817 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
5818 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
5819 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
5820 cur_params.dot11MeshHWMPRootMode) ||
5821 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
5822 cur_params.dot11MeshHWMPRannInterval) ||
5823 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
5824 cur_params.dot11MeshGateAnnouncementProtocol) ||
5825 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
5826 cur_params.dot11MeshForwarding) ||
335d5349 5827 nla_put_s32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
5828 cur_params.rssi_threshold) ||
5829 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
5830 cur_params.ht_opmode) ||
5831 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
5832 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
5833 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
5834 cur_params.dot11MeshHWMProotInterval) ||
5835 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
5836 cur_params.dot11MeshHWMPconfirmationInterval) ||
5837 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
5838 cur_params.power_mode) ||
5839 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
5840 cur_params.dot11MeshAwakeWindowDuration) ||
5841 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
5842 cur_params.plink_timeout))
9360ffd1 5843 goto nla_put_failure;
93da9cc1 5844 nla_nest_end(msg, pinfoattr);
5845 genlmsg_end(msg, hdr);
4c476991 5846 return genlmsg_reply(msg, info);
93da9cc1 5847
3b85875a 5848 nla_put_failure:
93da9cc1 5849 genlmsg_cancel(msg, hdr);
efe1cf0c 5850 out:
d080e275 5851 nlmsg_free(msg);
4c476991 5852 return -ENOBUFS;
93da9cc1 5853}
5854
b54452b0 5855static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 5856 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
5857 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
5858 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
5859 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
5860 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
5861 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 5862 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 5863 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 5864 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 5865 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
5866 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
5867 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
5868 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
5869 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 5870 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 5871 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 5872 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 5873 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 5874 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 5875 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
5876 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
5877 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
5878 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
5879 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 5880 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
3b1c5a53
MP
5881 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 },
5882 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 5883 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
93da9cc1 5884};
5885
c80d545d
JC
5886static const struct nla_policy
5887 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 5888 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
5889 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
5890 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 5891 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 5892 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 5893 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
581a8b0f 5894 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 5895 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 5896 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
5897};
5898
f151d9db
AB
5899static int nl80211_check_bool(const struct nlattr *nla, u8 min, u8 max, bool *out)
5900{
5901 u8 val = nla_get_u8(nla);
5902 if (val < min || val > max)
5903 return -EINVAL;
5904 *out = val;
5905 return 0;
5906}
5907
5908static int nl80211_check_u8(const struct nlattr *nla, u8 min, u8 max, u8 *out)
5909{
5910 u8 val = nla_get_u8(nla);
5911 if (val < min || val > max)
5912 return -EINVAL;
5913 *out = val;
5914 return 0;
5915}
5916
5917static int nl80211_check_u16(const struct nlattr *nla, u16 min, u16 max, u16 *out)
5918{
5919 u16 val = nla_get_u16(nla);
5920 if (val < min || val > max)
5921 return -EINVAL;
5922 *out = val;
5923 return 0;
5924}
5925
5926static int nl80211_check_u32(const struct nlattr *nla, u32 min, u32 max, u32 *out)
5927{
5928 u32 val = nla_get_u32(nla);
5929 if (val < min || val > max)
5930 return -EINVAL;
5931 *out = val;
5932 return 0;
5933}
5934
5935static int nl80211_check_s32(const struct nlattr *nla, s32 min, s32 max, s32 *out)
5936{
5937 s32 val = nla_get_s32(nla);
5938 if (val < min || val > max)
5939 return -EINVAL;
5940 *out = val;
5941 return 0;
5942}
5943
ff9a71af
JB
5944static int nl80211_check_power_mode(const struct nlattr *nla,
5945 enum nl80211_mesh_power_mode min,
5946 enum nl80211_mesh_power_mode max,
5947 enum nl80211_mesh_power_mode *out)
5948{
5949 u32 val = nla_get_u32(nla);
5950 if (val < min || val > max)
5951 return -EINVAL;
5952 *out = val;
5953 return 0;
5954}
5955
24bdd9f4 5956static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
5957 struct mesh_config *cfg,
5958 u32 *mask_out)
93da9cc1 5959{
93da9cc1 5960 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 5961 u32 mask = 0;
9757235f 5962 u16 ht_opmode;
93da9cc1 5963
ea54fba2
MP
5964#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \
5965do { \
5966 if (tb[attr]) { \
f151d9db 5967 if (fn(tb[attr], min, max, &cfg->param)) \
ea54fba2 5968 return -EINVAL; \
ea54fba2
MP
5969 mask |= (1 << (attr - 1)); \
5970 } \
5971} while (0)
bd90fdcc 5972
24bdd9f4 5973 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 5974 return -EINVAL;
5975 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 5976 info->attrs[NL80211_ATTR_MESH_CONFIG],
fe52145f 5977 nl80211_meshconf_params_policy, info->extack))
93da9cc1 5978 return -EINVAL;
5979
93da9cc1 5980 /* This makes sure that there aren't more than 32 mesh config
5981 * parameters (otherwise our bitfield scheme would not work.) */
5982 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
5983
5984 /* Fill in the params struct */
ea54fba2 5985 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255,
a4f606ea 5986 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
f151d9db 5987 nl80211_check_u16);
ea54fba2 5988 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255,
a4f606ea 5989 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
f151d9db 5990 nl80211_check_u16);
ea54fba2 5991 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255,
a4f606ea 5992 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
f151d9db 5993 nl80211_check_u16);
ea54fba2 5994 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255,
a4f606ea 5995 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
f151d9db 5996 nl80211_check_u16);
ea54fba2 5997 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16,
a4f606ea 5998 mask, NL80211_MESHCONF_MAX_RETRIES,
f151d9db 5999 nl80211_check_u8);
ea54fba2 6000 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255,
f151d9db 6001 mask, NL80211_MESHCONF_TTL, nl80211_check_u8);
ea54fba2 6002 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255,
a4f606ea 6003 mask, NL80211_MESHCONF_ELEMENT_TTL,
f151d9db 6004 nl80211_check_u8);
ea54fba2 6005 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1,
a4f606ea 6006 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
f151d9db 6007 nl80211_check_bool);
ea54fba2
MP
6008 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
6009 1, 255, mask,
a4f606ea 6010 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
f151d9db 6011 nl80211_check_u32);
ea54fba2 6012 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255,
a4f606ea 6013 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
f151d9db 6014 nl80211_check_u8);
ea54fba2 6015 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535,
a4f606ea 6016 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
f151d9db 6017 nl80211_check_u32);
ea54fba2 6018 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535,
a4f606ea 6019 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
f151d9db 6020 nl80211_check_u16);
ea54fba2
MP
6021 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
6022 1, 65535, mask,
a4f606ea 6023 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
f151d9db 6024 nl80211_check_u32);
93da9cc1 6025 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
ea54fba2
MP
6026 1, 65535, mask,
6027 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
f151d9db 6028 nl80211_check_u16);
dca7e943 6029 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
ea54fba2
MP
6030 1, 65535, mask,
6031 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
f151d9db 6032 nl80211_check_u16);
93da9cc1 6033 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
6034 dot11MeshHWMPnetDiameterTraversalTime,
6035 1, 65535, mask,
a4f606ea 6036 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
f151d9db 6037 nl80211_check_u16);
ea54fba2
MP
6038 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4,
6039 mask, NL80211_MESHCONF_HWMP_ROOTMODE,
f151d9db 6040 nl80211_check_u8);
ea54fba2
MP
6041 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535,
6042 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
f151d9db 6043 nl80211_check_u16);
63c5723b 6044 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
6045 dot11MeshGateAnnouncementProtocol, 0, 1,
6046 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
f151d9db 6047 nl80211_check_bool);
ea54fba2 6048 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1,
a4f606ea 6049 mask, NL80211_MESHCONF_FORWARDING,
f151d9db 6050 nl80211_check_bool);
83374fe9 6051 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0,
a4f606ea 6052 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
f151d9db 6053 nl80211_check_s32);
9757235f
MH
6054 /*
6055 * Check HT operation mode based on
6056 * IEEE 802.11 2012 8.4.2.59 HT Operation element.
6057 */
6058 if (tb[NL80211_MESHCONF_HT_OPMODE]) {
6059 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]);
6060
6061 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION |
6062 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
6063 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
6064 return -EINVAL;
6065
6066 if ((ht_opmode & IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT) &&
6067 (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
6068 return -EINVAL;
6069
6070 switch (ht_opmode & IEEE80211_HT_OP_MODE_PROTECTION) {
6071 case IEEE80211_HT_OP_MODE_PROTECTION_NONE:
6072 case IEEE80211_HT_OP_MODE_PROTECTION_20MHZ:
6073 if (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)
6074 return -EINVAL;
6075 break;
6076 case IEEE80211_HT_OP_MODE_PROTECTION_NONMEMBER:
6077 case IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED:
6078 if (!(ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
6079 return -EINVAL;
6080 break;
6081 }
6082 cfg->ht_opmode = ht_opmode;
fd551bac 6083 mask |= (1 << (NL80211_MESHCONF_HT_OPMODE - 1));
9757235f 6084 }
ac1073a6 6085 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
ea54fba2 6086 1, 65535, mask,
ac1073a6 6087 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
f151d9db 6088 nl80211_check_u32);
ea54fba2 6089 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535,
ac1073a6 6090 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
f151d9db 6091 nl80211_check_u16);
728b19e5 6092 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ea54fba2
MP
6093 dot11MeshHWMPconfirmationInterval,
6094 1, 65535, mask,
728b19e5 6095 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
f151d9db 6096 nl80211_check_u16);
3b1c5a53
MP
6097 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode,
6098 NL80211_MESH_POWER_ACTIVE,
6099 NL80211_MESH_POWER_MAX,
6100 mask, NL80211_MESHCONF_POWER_MODE,
ff9a71af 6101 nl80211_check_power_mode);
3b1c5a53
MP
6102 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration,
6103 0, 65535, mask,
f151d9db 6104 NL80211_MESHCONF_AWAKE_WINDOW, nl80211_check_u16);
31f909a2 6105 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 0, 0xffffffff,
8e7c0538 6106 mask, NL80211_MESHCONF_PLINK_TIMEOUT,
f151d9db 6107 nl80211_check_u32);
bd90fdcc
JB
6108 if (mask_out)
6109 *mask_out = mask;
c80d545d 6110
bd90fdcc
JB
6111 return 0;
6112
6113#undef FILL_IN_MESH_PARAM_IF_SET
6114}
6115
c80d545d
JC
6116static int nl80211_parse_mesh_setup(struct genl_info *info,
6117 struct mesh_setup *setup)
6118{
bb2798d4 6119 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
6120 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
6121
6122 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
6123 return -EINVAL;
6124 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
6125 info->attrs[NL80211_ATTR_MESH_SETUP],
fe52145f 6126 nl80211_mesh_setup_params_policy, info->extack))
c80d545d
JC
6127 return -EINVAL;
6128
d299a1f2
JC
6129 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
6130 setup->sync_method =
6131 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
6132 IEEE80211_SYNC_METHOD_VENDOR :
6133 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
6134
c80d545d
JC
6135 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
6136 setup->path_sel_proto =
6137 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
6138 IEEE80211_PATH_PROTOCOL_VENDOR :
6139 IEEE80211_PATH_PROTOCOL_HWMP;
6140
6141 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
6142 setup->path_metric =
6143 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
6144 IEEE80211_PATH_METRIC_VENDOR :
6145 IEEE80211_PATH_METRIC_AIRTIME;
6146
581a8b0f 6147 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 6148 struct nlattr *ieattr =
581a8b0f 6149 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
6150 if (!is_valid_ie_attr(ieattr))
6151 return -EINVAL;
581a8b0f
JC
6152 setup->ie = nla_data(ieattr);
6153 setup->ie_len = nla_len(ieattr);
c80d545d 6154 }
bb2798d4
TP
6155 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
6156 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
6157 return -EINVAL;
6158 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
6159 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
6160 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
6161 if (setup->is_secure)
6162 setup->user_mpm = true;
c80d545d 6163
6e16d90b
CT
6164 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
6165 if (!setup->user_mpm)
6166 return -EINVAL;
6167 setup->auth_id =
6168 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
6169 }
6170
c80d545d
JC
6171 return 0;
6172}
6173
24bdd9f4 6174static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 6175 struct genl_info *info)
bd90fdcc
JB
6176{
6177 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6178 struct net_device *dev = info->user_ptr[1];
29cbe68c 6179 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
6180 struct mesh_config cfg;
6181 u32 mask;
6182 int err;
6183
29cbe68c
JB
6184 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
6185 return -EOPNOTSUPP;
6186
24bdd9f4 6187 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
6188 return -EOPNOTSUPP;
6189
24bdd9f4 6190 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
6191 if (err)
6192 return err;
6193
29cbe68c
JB
6194 wdev_lock(wdev);
6195 if (!wdev->mesh_id_len)
6196 err = -ENOLINK;
6197
6198 if (!err)
e35e4d28 6199 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
6200
6201 wdev_unlock(wdev);
6202
6203 return err;
93da9cc1 6204}
6205
ad30ca2c
AN
6206static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom,
6207 struct sk_buff *msg)
f130347c 6208{
f130347c
LR
6209 struct nlattr *nl_reg_rules;
6210 unsigned int i;
f130347c 6211
458f4f9e
JB
6212 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
6213 (regdom->dfs_region &&
6214 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
ad30ca2c 6215 goto nla_put_failure;
458f4f9e 6216
f130347c
LR
6217 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
6218 if (!nl_reg_rules)
ad30ca2c 6219 goto nla_put_failure;
f130347c 6220
458f4f9e 6221 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
6222 struct nlattr *nl_reg_rule;
6223 const struct ieee80211_reg_rule *reg_rule;
6224 const struct ieee80211_freq_range *freq_range;
6225 const struct ieee80211_power_rule *power_rule;
97524820 6226 unsigned int max_bandwidth_khz;
f130347c 6227
458f4f9e 6228 reg_rule = &regdom->reg_rules[i];
f130347c
LR
6229 freq_range = &reg_rule->freq_range;
6230 power_rule = &reg_rule->power_rule;
6231
6232 nl_reg_rule = nla_nest_start(msg, i);
6233 if (!nl_reg_rule)
ad30ca2c 6234 goto nla_put_failure;
f130347c 6235
97524820
JD
6236 max_bandwidth_khz = freq_range->max_bandwidth_khz;
6237 if (!max_bandwidth_khz)
6238 max_bandwidth_khz = reg_get_max_bandwidth(regdom,
6239 reg_rule);
6240
9360ffd1
DM
6241 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
6242 reg_rule->flags) ||
6243 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
6244 freq_range->start_freq_khz) ||
6245 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
6246 freq_range->end_freq_khz) ||
6247 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
97524820 6248 max_bandwidth_khz) ||
9360ffd1
DM
6249 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
6250 power_rule->max_antenna_gain) ||
6251 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
089027e5
JD
6252 power_rule->max_eirp) ||
6253 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME,
6254 reg_rule->dfs_cac_ms))
ad30ca2c 6255 goto nla_put_failure;
f130347c
LR
6256
6257 nla_nest_end(msg, nl_reg_rule);
6258 }
6259
6260 nla_nest_end(msg, nl_reg_rules);
ad30ca2c
AN
6261 return 0;
6262
6263nla_put_failure:
6264 return -EMSGSIZE;
6265}
6266
6267static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info)
6268{
6269 const struct ieee80211_regdomain *regdom = NULL;
6270 struct cfg80211_registered_device *rdev;
6271 struct wiphy *wiphy = NULL;
6272 struct sk_buff *msg;
6273 void *hdr;
6274
6275 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6276 if (!msg)
6277 return -ENOBUFS;
6278
6279 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
6280 NL80211_CMD_GET_REG);
6281 if (!hdr)
6282 goto put_failure;
6283
6284 if (info->attrs[NL80211_ATTR_WIPHY]) {
1bdd716c
AN
6285 bool self_managed;
6286
ad30ca2c
AN
6287 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
6288 if (IS_ERR(rdev)) {
6289 nlmsg_free(msg);
6290 return PTR_ERR(rdev);
6291 }
6292
6293 wiphy = &rdev->wiphy;
1bdd716c
AN
6294 self_managed = wiphy->regulatory_flags &
6295 REGULATORY_WIPHY_SELF_MANAGED;
ad30ca2c
AN
6296 regdom = get_wiphy_regdom(wiphy);
6297
1bdd716c
AN
6298 /* a self-managed-reg device must have a private regdom */
6299 if (WARN_ON(!regdom && self_managed)) {
6300 nlmsg_free(msg);
6301 return -EINVAL;
6302 }
6303
ad30ca2c
AN
6304 if (regdom &&
6305 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
6306 goto nla_put_failure;
6307 }
6308
6309 if (!wiphy && reg_last_request_cell_base() &&
6310 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
6311 NL80211_USER_REG_HINT_CELL_BASE))
6312 goto nla_put_failure;
6313
6314 rcu_read_lock();
6315
6316 if (!regdom)
6317 regdom = rcu_dereference(cfg80211_regdomain);
6318
6319 if (nl80211_put_regdom(regdom, msg))
6320 goto nla_put_failure_rcu;
6321
6322 rcu_read_unlock();
f130347c
LR
6323
6324 genlmsg_end(msg, hdr);
5fe231e8 6325 return genlmsg_reply(msg, info);
f130347c 6326
458f4f9e
JB
6327nla_put_failure_rcu:
6328 rcu_read_unlock();
f130347c
LR
6329nla_put_failure:
6330 genlmsg_cancel(msg, hdr);
efe1cf0c 6331put_failure:
d080e275 6332 nlmsg_free(msg);
5fe231e8 6333 return -EMSGSIZE;
f130347c
LR
6334}
6335
ad30ca2c
AN
6336static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb,
6337 u32 seq, int flags, struct wiphy *wiphy,
6338 const struct ieee80211_regdomain *regdom)
6339{
6340 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
6341 NL80211_CMD_GET_REG);
6342
6343 if (!hdr)
6344 return -1;
6345
0a833c29 6346 genl_dump_check_consistent(cb, hdr);
ad30ca2c
AN
6347
6348 if (nl80211_put_regdom(regdom, msg))
6349 goto nla_put_failure;
6350
6351 if (!wiphy && reg_last_request_cell_base() &&
6352 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
6353 NL80211_USER_REG_HINT_CELL_BASE))
6354 goto nla_put_failure;
6355
6356 if (wiphy &&
6357 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
6358 goto nla_put_failure;
6359
1bdd716c
AN
6360 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
6361 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
6362 goto nla_put_failure;
6363
053c095a
JB
6364 genlmsg_end(msg, hdr);
6365 return 0;
ad30ca2c
AN
6366
6367nla_put_failure:
6368 genlmsg_cancel(msg, hdr);
6369 return -EMSGSIZE;
6370}
6371
6372static int nl80211_get_reg_dump(struct sk_buff *skb,
6373 struct netlink_callback *cb)
6374{
6375 const struct ieee80211_regdomain *regdom = NULL;
6376 struct cfg80211_registered_device *rdev;
6377 int err, reg_idx, start = cb->args[2];
6378
6379 rtnl_lock();
6380
6381 if (cfg80211_regdomain && start == 0) {
6382 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
6383 NLM_F_MULTI, NULL,
6384 rtnl_dereference(cfg80211_regdomain));
6385 if (err < 0)
6386 goto out_err;
6387 }
6388
6389 /* the global regdom is idx 0 */
6390 reg_idx = 1;
6391 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
6392 regdom = get_wiphy_regdom(&rdev->wiphy);
6393 if (!regdom)
6394 continue;
6395
6396 if (++reg_idx <= start)
6397 continue;
6398
6399 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
6400 NLM_F_MULTI, &rdev->wiphy, regdom);
6401 if (err < 0) {
6402 reg_idx--;
6403 break;
6404 }
6405 }
6406
6407 cb->args[2] = reg_idx;
6408 err = skb->len;
6409out_err:
6410 rtnl_unlock();
6411 return err;
6412}
6413
b6863036
JB
6414#ifdef CONFIG_CFG80211_CRDA_SUPPORT
6415static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
6416 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
6417 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
6418 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
6419 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
6420 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
6421 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
6422 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 },
6423};
6424
6425static int parse_reg_rule(struct nlattr *tb[],
6426 struct ieee80211_reg_rule *reg_rule)
6427{
6428 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
6429 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
6430
6431 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
6432 return -EINVAL;
6433 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
6434 return -EINVAL;
6435 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
6436 return -EINVAL;
6437 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
6438 return -EINVAL;
6439 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
6440 return -EINVAL;
6441
6442 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
6443
6444 freq_range->start_freq_khz =
6445 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
6446 freq_range->end_freq_khz =
6447 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
6448 freq_range->max_bandwidth_khz =
6449 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
6450
6451 power_rule->max_eirp =
6452 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
6453
6454 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
6455 power_rule->max_antenna_gain =
6456 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
6457
6458 if (tb[NL80211_ATTR_DFS_CAC_TIME])
6459 reg_rule->dfs_cac_ms =
6460 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]);
6461
6462 return 0;
6463}
6464
b2e1b302
LR
6465static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
6466{
6467 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
6468 struct nlattr *nl_reg_rule;
ea372c54
JB
6469 char *alpha2;
6470 int rem_reg_rules, r;
b2e1b302 6471 u32 num_rules = 0, rule_idx = 0, size_of_regd;
4c7d3982 6472 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
ea372c54 6473 struct ieee80211_regdomain *rd;
b2e1b302
LR
6474
6475 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
6476 return -EINVAL;
6477
6478 if (!info->attrs[NL80211_ATTR_REG_RULES])
6479 return -EINVAL;
6480
6481 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
6482
8b60b078
LR
6483 if (info->attrs[NL80211_ATTR_DFS_REGION])
6484 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
6485
b2e1b302 6486 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 6487 rem_reg_rules) {
b2e1b302
LR
6488 num_rules++;
6489 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 6490 return -EINVAL;
b2e1b302
LR
6491 }
6492
e438768f
LR
6493 if (!reg_is_valid_request(alpha2))
6494 return -EINVAL;
6495
b2e1b302 6496 size_of_regd = sizeof(struct ieee80211_regdomain) +
1a919318 6497 num_rules * sizeof(struct ieee80211_reg_rule);
b2e1b302
LR
6498
6499 rd = kzalloc(size_of_regd, GFP_KERNEL);
6913b49a
JB
6500 if (!rd)
6501 return -ENOMEM;
b2e1b302
LR
6502
6503 rd->n_reg_rules = num_rules;
6504 rd->alpha2[0] = alpha2[0];
6505 rd->alpha2[1] = alpha2[1];
6506
8b60b078
LR
6507 /*
6508 * Disable DFS master mode if the DFS region was
6509 * not supported or known on this kernel.
6510 */
6511 if (reg_supported_dfs_region(dfs_region))
6512 rd->dfs_region = dfs_region;
6513
b2e1b302 6514 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 6515 rem_reg_rules) {
bfe2c7b1 6516 r = nla_parse_nested(tb, NL80211_REG_RULE_ATTR_MAX,
fe52145f
JB
6517 nl_reg_rule, reg_rule_policy,
6518 info->extack);
ae811e21
JB
6519 if (r)
6520 goto bad_reg;
b2e1b302
LR
6521 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
6522 if (r)
6523 goto bad_reg;
6524
6525 rule_idx++;
6526
d0e18f83
LR
6527 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
6528 r = -EINVAL;
b2e1b302 6529 goto bad_reg;
d0e18f83 6530 }
b2e1b302
LR
6531 }
6532
06627990
JB
6533 /* set_regdom takes ownership of rd */
6534 return set_regdom(rd, REGD_SOURCE_CRDA);
d2372b31 6535 bad_reg:
b2e1b302 6536 kfree(rd);
d0e18f83 6537 return r;
b2e1b302 6538}
b6863036 6539#endif /* CONFIG_CFG80211_CRDA_SUPPORT */
b2e1b302 6540
83f5e2cf
JB
6541static int validate_scan_freqs(struct nlattr *freqs)
6542{
6543 struct nlattr *attr1, *attr2;
6544 int n_channels = 0, tmp1, tmp2;
6545
d7f13f74
SD
6546 nla_for_each_nested(attr1, freqs, tmp1)
6547 if (nla_len(attr1) != sizeof(u32))
6548 return 0;
6549
83f5e2cf
JB
6550 nla_for_each_nested(attr1, freqs, tmp1) {
6551 n_channels++;
6552 /*
6553 * Some hardware has a limited channel list for
6554 * scanning, and it is pretty much nonsensical
6555 * to scan for a channel twice, so disallow that
6556 * and don't require drivers to check that the
6557 * channel list they get isn't longer than what
6558 * they can scan, as long as they can scan all
6559 * the channels they registered at once.
6560 */
6561 nla_for_each_nested(attr2, freqs, tmp2)
6562 if (attr1 != attr2 &&
6563 nla_get_u32(attr1) == nla_get_u32(attr2))
6564 return 0;
6565 }
6566
6567 return n_channels;
6568}
6569
57fbcce3 6570static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b)
38de03d2 6571{
57fbcce3 6572 return b < NUM_NL80211_BANDS && wiphy->bands[b];
38de03d2
AS
6573}
6574
6575static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy,
6576 struct cfg80211_bss_selection *bss_select)
6577{
6578 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1];
6579 struct nlattr *nest;
6580 int err;
6581 bool found = false;
6582 int i;
6583
6584 /* only process one nested attribute */
6585 nest = nla_data(nla);
6586 if (!nla_ok(nest, nla_len(nest)))
6587 return -EINVAL;
6588
bfe2c7b1 6589 err = nla_parse_nested(attr, NL80211_BSS_SELECT_ATTR_MAX, nest,
fceb6435 6590 nl80211_bss_select_policy, NULL);
38de03d2
AS
6591 if (err)
6592 return err;
6593
6594 /* only one attribute may be given */
6595 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) {
6596 if (attr[i]) {
6597 if (found)
6598 return -EINVAL;
6599 found = true;
6600 }
6601 }
6602
6603 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID;
6604
6605 if (attr[NL80211_BSS_SELECT_ATTR_RSSI])
6606 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI;
6607
6608 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) {
6609 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF;
6610 bss_select->param.band_pref =
6611 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]);
6612 if (!is_band_valid(wiphy, bss_select->param.band_pref))
6613 return -EINVAL;
6614 }
6615
6616 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) {
6617 struct nl80211_bss_select_rssi_adjust *adj_param;
6618
6619 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]);
6620 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST;
6621 bss_select->param.adjust.band = adj_param->band;
6622 bss_select->param.adjust.delta = adj_param->delta;
6623 if (!is_band_valid(wiphy, bss_select->param.adjust.band))
6624 return -EINVAL;
6625 }
6626
6627 /* user-space did not provide behaviour attribute */
6628 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID)
6629 return -EINVAL;
6630
6631 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour)))
6632 return -EINVAL;
6633
6634 return 0;
6635}
6636
ad2b26ab
JB
6637static int nl80211_parse_random_mac(struct nlattr **attrs,
6638 u8 *mac_addr, u8 *mac_addr_mask)
6639{
6640 int i;
6641
6642 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) {
d2beae10
JP
6643 eth_zero_addr(mac_addr);
6644 eth_zero_addr(mac_addr_mask);
ad2b26ab
JB
6645 mac_addr[0] = 0x2;
6646 mac_addr_mask[0] = 0x3;
6647
6648 return 0;
6649 }
6650
6651 /* need both or none */
6652 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK])
6653 return -EINVAL;
6654
6655 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN);
6656 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN);
6657
6658 /* don't allow or configure an mcast address */
6659 if (!is_multicast_ether_addr(mac_addr_mask) ||
6660 is_multicast_ether_addr(mac_addr))
6661 return -EINVAL;
6662
6663 /*
6664 * allow users to pass a MAC address that has bits set outside
6665 * of the mask, but don't bother drivers with having to deal
6666 * with such bits
6667 */
6668 for (i = 0; i < ETH_ALEN; i++)
6669 mac_addr[i] &= mac_addr_mask[i];
6670
6671 return 0;
6672}
6673
34373d12
VT
6674static bool cfg80211_off_channel_oper_allowed(struct wireless_dev *wdev)
6675{
6676 ASSERT_WDEV_LOCK(wdev);
6677
6678 if (!cfg80211_beaconing_iface_active(wdev))
6679 return true;
6680
6681 if (!(wdev->chandef.chan->flags & IEEE80211_CHAN_RADAR))
6682 return true;
6683
6684 return regulatory_pre_cac_allowed(wdev->wiphy);
6685}
6686
2d23d073
RZ
6687static int
6688nl80211_check_scan_flags(struct wiphy *wiphy, struct wireless_dev *wdev,
6689 void *request, struct nlattr **attrs,
6690 bool is_sched_scan)
6691{
6692 u8 *mac_addr, *mac_addr_mask;
6693 u32 *flags;
6694 enum nl80211_feature_flags randomness_flag;
6695
6696 if (!attrs[NL80211_ATTR_SCAN_FLAGS])
6697 return 0;
6698
6699 if (is_sched_scan) {
6700 struct cfg80211_sched_scan_request *req = request;
6701
6702 randomness_flag = wdev ?
6703 NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR :
6704 NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
6705 flags = &req->flags;
6706 mac_addr = req->mac_addr;
6707 mac_addr_mask = req->mac_addr_mask;
6708 } else {
6709 struct cfg80211_scan_request *req = request;
6710
6711 randomness_flag = NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR;
6712 flags = &req->flags;
6713 mac_addr = req->mac_addr;
6714 mac_addr_mask = req->mac_addr_mask;
6715 }
6716
6717 *flags = nla_get_u32(attrs[NL80211_ATTR_SCAN_FLAGS]);
6718
5037a009
SD
6719 if (((*flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
6720 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
6721 ((*flags & NL80211_SCAN_FLAG_LOW_SPAN) &&
6722 !wiphy_ext_feature_isset(wiphy,
6723 NL80211_EXT_FEATURE_LOW_SPAN_SCAN)) ||
6724 ((*flags & NL80211_SCAN_FLAG_LOW_POWER) &&
6725 !wiphy_ext_feature_isset(wiphy,
6726 NL80211_EXT_FEATURE_LOW_POWER_SCAN)) ||
6727 ((*flags & NL80211_SCAN_FLAG_HIGH_ACCURACY) &&
6728 !wiphy_ext_feature_isset(wiphy,
6729 NL80211_EXT_FEATURE_HIGH_ACCURACY_SCAN)))
2d23d073
RZ
6730 return -EOPNOTSUPP;
6731
6732 if (*flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
6733 int err;
6734
6735 if (!(wiphy->features & randomness_flag) ||
6736 (wdev && wdev->current_bss))
6737 return -EOPNOTSUPP;
6738
6739 err = nl80211_parse_random_mac(attrs, mac_addr, mac_addr_mask);
6740 if (err)
6741 return err;
6742 }
6743
6744 if ((*flags & NL80211_SCAN_FLAG_FILS_MAX_CHANNEL_TIME) &&
6745 !wiphy_ext_feature_isset(wiphy,
6746 NL80211_EXT_FEATURE_FILS_MAX_CHANNEL_TIME))
6747 return -EOPNOTSUPP;
6748
6749 if ((*flags & NL80211_SCAN_FLAG_ACCEPT_BCAST_PROBE_RESP) &&
6750 !wiphy_ext_feature_isset(wiphy,
6751 NL80211_EXT_FEATURE_ACCEPT_BCAST_PROBE_RESP))
6752 return -EOPNOTSUPP;
6753
6754 if ((*flags & NL80211_SCAN_FLAG_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION) &&
6755 !wiphy_ext_feature_isset(wiphy,
6756 NL80211_EXT_FEATURE_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION))
6757 return -EOPNOTSUPP;
6758
6759 if ((*flags & NL80211_SCAN_FLAG_OCE_PROBE_REQ_HIGH_TX_RATE) &&
6760 !wiphy_ext_feature_isset(wiphy,
6761 NL80211_EXT_FEATURE_OCE_PROBE_REQ_HIGH_TX_RATE))
6762 return -EOPNOTSUPP;
6763
6764 return 0;
6765}
6766
2a519311
JB
6767static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
6768{
4c476991 6769 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 6770 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 6771 struct cfg80211_scan_request *request;
2a519311
JB
6772 struct nlattr *attr;
6773 struct wiphy *wiphy;
83f5e2cf 6774 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 6775 size_t ie_len;
2a519311 6776
f4a11bb0
JB
6777 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
6778 return -EINVAL;
6779
79c97e97 6780 wiphy = &rdev->wiphy;
2a519311 6781
cb3b7d87
AB
6782 if (wdev->iftype == NL80211_IFTYPE_NAN)
6783 return -EOPNOTSUPP;
6784
4c476991
JB
6785 if (!rdev->ops->scan)
6786 return -EOPNOTSUPP;
2a519311 6787
f9d15d16 6788 if (rdev->scan_req || rdev->scan_msg) {
f9f47529
JB
6789 err = -EBUSY;
6790 goto unlock;
6791 }
2a519311
JB
6792
6793 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
6794 n_channels = validate_scan_freqs(
6795 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
6796 if (!n_channels) {
6797 err = -EINVAL;
6798 goto unlock;
6799 }
2a519311 6800 } else {
bdfbec2d 6801 n_channels = ieee80211_get_num_supported_channels(wiphy);
2a519311
JB
6802 }
6803
6804 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
6805 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
6806 n_ssids++;
6807
f9f47529
JB
6808 if (n_ssids > wiphy->max_scan_ssids) {
6809 err = -EINVAL;
6810 goto unlock;
6811 }
2a519311 6812
70692ad2
JM
6813 if (info->attrs[NL80211_ATTR_IE])
6814 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
6815 else
6816 ie_len = 0;
6817
f9f47529
JB
6818 if (ie_len > wiphy->max_scan_ie_len) {
6819 err = -EINVAL;
6820 goto unlock;
6821 }
18a83659 6822
2a519311 6823 request = kzalloc(sizeof(*request)
a2cd43c5
LC
6824 + sizeof(*request->ssids) * n_ssids
6825 + sizeof(*request->channels) * n_channels
70692ad2 6826 + ie_len, GFP_KERNEL);
f9f47529
JB
6827 if (!request) {
6828 err = -ENOMEM;
6829 goto unlock;
6830 }
2a519311 6831
2a519311 6832 if (n_ssids)
5ba63533 6833 request->ssids = (void *)&request->channels[n_channels];
2a519311 6834 request->n_ssids = n_ssids;
70692ad2 6835 if (ie_len) {
13874e4b 6836 if (n_ssids)
70692ad2
JM
6837 request->ie = (void *)(request->ssids + n_ssids);
6838 else
6839 request->ie = (void *)(request->channels + n_channels);
6840 }
2a519311 6841
584991dc 6842 i = 0;
2a519311
JB
6843 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
6844 /* user specified, bail out if channel not found */
2a519311 6845 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
6846 struct ieee80211_channel *chan;
6847
6848 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
6849
6850 if (!chan) {
2a519311
JB
6851 err = -EINVAL;
6852 goto out_free;
6853 }
584991dc
JB
6854
6855 /* ignore disabled channels */
6856 if (chan->flags & IEEE80211_CHAN_DISABLED)
6857 continue;
6858
6859 request->channels[i] = chan;
2a519311
JB
6860 i++;
6861 }
6862 } else {
57fbcce3 6863 enum nl80211_band band;
34850ab2 6864
2a519311 6865 /* all channels */
57fbcce3 6866 for (band = 0; band < NUM_NL80211_BANDS; band++) {
2a519311 6867 int j;
7a087e74 6868
2a519311
JB
6869 if (!wiphy->bands[band])
6870 continue;
6871 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
6872 struct ieee80211_channel *chan;
6873
6874 chan = &wiphy->bands[band]->channels[j];
6875
6876 if (chan->flags & IEEE80211_CHAN_DISABLED)
6877 continue;
6878
6879 request->channels[i] = chan;
2a519311
JB
6880 i++;
6881 }
6882 }
6883 }
6884
584991dc
JB
6885 if (!i) {
6886 err = -EINVAL;
6887 goto out_free;
6888 }
6889
6890 request->n_channels = i;
6891
34373d12
VT
6892 wdev_lock(wdev);
6893 if (!cfg80211_off_channel_oper_allowed(wdev)) {
6894 struct ieee80211_channel *chan;
6895
6896 if (request->n_channels != 1) {
6897 wdev_unlock(wdev);
6898 err = -EBUSY;
6899 goto out_free;
6900 }
6901
6902 chan = request->channels[0];
6903 if (chan->center_freq != wdev->chandef.chan->center_freq) {
6904 wdev_unlock(wdev);
6905 err = -EBUSY;
6906 goto out_free;
6907 }
6908 }
6909 wdev_unlock(wdev);
6910
2a519311 6911 i = 0;
13874e4b 6912 if (n_ssids) {
2a519311 6913 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 6914 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
6915 err = -EINVAL;
6916 goto out_free;
6917 }
57a27e1d 6918 request->ssids[i].ssid_len = nla_len(attr);
2a519311 6919 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
6920 i++;
6921 }
6922 }
6923
70692ad2
JM
6924 if (info->attrs[NL80211_ATTR_IE]) {
6925 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
6926 memcpy((void *)request->ie,
6927 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
6928 request->ie_len);
6929 }
6930
57fbcce3 6931 for (i = 0; i < NUM_NL80211_BANDS; i++)
a401d2bb
JB
6932 if (wiphy->bands[i])
6933 request->rates[i] =
6934 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
6935
6936 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
6937 nla_for_each_nested(attr,
6938 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
6939 tmp) {
57fbcce3 6940 enum nl80211_band band = nla_type(attr);
34850ab2 6941
57fbcce3 6942 if (band < 0 || band >= NUM_NL80211_BANDS) {
34850ab2
JB
6943 err = -EINVAL;
6944 goto out_free;
6945 }
1b09cd82
FF
6946
6947 if (!wiphy->bands[band])
6948 continue;
6949
34850ab2
JB
6950 err = ieee80211_get_ratemask(wiphy->bands[band],
6951 nla_data(attr),
6952 nla_len(attr),
6953 &request->rates[band]);
6954 if (err)
6955 goto out_free;
6956 }
6957 }
6958
1d76250b
AS
6959 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) {
6960 if (!wiphy_ext_feature_isset(wiphy,
6961 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) {
6962 err = -EOPNOTSUPP;
6963 goto out_free;
6964 }
6965
6966 request->duration =
6967 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]);
6968 request->duration_mandatory =
6969 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]);
6970 }
6971
2d23d073
RZ
6972 err = nl80211_check_scan_flags(wiphy, wdev, request, info->attrs,
6973 false);
6974 if (err)
6975 goto out_free;
ed473771 6976
e9f935e3
RM
6977 request->no_cck =
6978 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6979
2fa436b3
VK
6980 /* Initial implementation used NL80211_ATTR_MAC to set the specific
6981 * BSSID to scan for. This was problematic because that same attribute
6982 * was already used for another purpose (local random MAC address). The
6983 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards
6984 * compatibility with older userspace components, also use the
6985 * NL80211_ATTR_MAC value here if it can be determined to be used for
6986 * the specific BSSID use case instead of the random MAC address
6987 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use).
6988 */
6989 if (info->attrs[NL80211_ATTR_BSSID])
6990 memcpy(request->bssid,
6991 nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN);
6992 else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) &&
6993 info->attrs[NL80211_ATTR_MAC])
818965d3
JM
6994 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]),
6995 ETH_ALEN);
6996 else
6997 eth_broadcast_addr(request->bssid);
6998
fd014284 6999 request->wdev = wdev;
79c97e97 7000 request->wiphy = &rdev->wiphy;
15d6030b 7001 request->scan_start = jiffies;
2a519311 7002
79c97e97 7003 rdev->scan_req = request;
e35e4d28 7004 err = rdev_scan(rdev, request);
2a519311 7005
463d0183 7006 if (!err) {
fd014284
JB
7007 nl80211_send_scan_start(rdev, wdev);
7008 if (wdev->netdev)
7009 dev_hold(wdev->netdev);
4c476991 7010 } else {
2a519311 7011 out_free:
79c97e97 7012 rdev->scan_req = NULL;
2a519311
JB
7013 kfree(request);
7014 }
3b85875a 7015
f9f47529 7016 unlock:
2a519311
JB
7017 return err;
7018}
7019
91d3ab46
VK
7020static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info)
7021{
7022 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7023 struct wireless_dev *wdev = info->user_ptr[1];
7024
7025 if (!rdev->ops->abort_scan)
7026 return -EOPNOTSUPP;
7027
7028 if (rdev->scan_msg)
7029 return 0;
7030
7031 if (!rdev->scan_req)
7032 return -ENOENT;
7033
7034 rdev_abort_scan(rdev, wdev);
7035 return 0;
7036}
7037
3b06d277
AS
7038static int
7039nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans,
7040 struct cfg80211_sched_scan_request *request,
7041 struct nlattr **attrs)
7042{
7043 int tmp, err, i = 0;
7044 struct nlattr *attr;
7045
7046 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
7047 u32 interval;
7048
7049 /*
7050 * If scan plans are not specified,
5a88de53 7051 * %NL80211_ATTR_SCHED_SCAN_INTERVAL will be specified. In this
3b06d277
AS
7052 * case one scan plan will be set with the specified scan
7053 * interval and infinite number of iterations.
7054 */
3b06d277
AS
7055 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
7056 if (!interval)
7057 return -EINVAL;
7058
7059 request->scan_plans[0].interval =
7060 DIV_ROUND_UP(interval, MSEC_PER_SEC);
7061 if (!request->scan_plans[0].interval)
7062 return -EINVAL;
7063
7064 if (request->scan_plans[0].interval >
7065 wiphy->max_sched_scan_plan_interval)
7066 request->scan_plans[0].interval =
7067 wiphy->max_sched_scan_plan_interval;
7068
7069 return 0;
7070 }
7071
7072 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) {
7073 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1];
7074
7075 if (WARN_ON(i >= n_plans))
7076 return -EINVAL;
7077
bfe2c7b1 7078 err = nla_parse_nested(plan, NL80211_SCHED_SCAN_PLAN_MAX,
fceb6435 7079 attr, nl80211_plan_policy, NULL);
3b06d277
AS
7080 if (err)
7081 return err;
7082
7083 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL])
7084 return -EINVAL;
7085
7086 request->scan_plans[i].interval =
7087 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]);
7088 if (!request->scan_plans[i].interval ||
7089 request->scan_plans[i].interval >
7090 wiphy->max_sched_scan_plan_interval)
7091 return -EINVAL;
7092
7093 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) {
7094 request->scan_plans[i].iterations =
7095 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]);
7096 if (!request->scan_plans[i].iterations ||
7097 (request->scan_plans[i].iterations >
7098 wiphy->max_sched_scan_plan_iterations))
7099 return -EINVAL;
7100 } else if (i < n_plans - 1) {
7101 /*
7102 * All scan plans but the last one must specify
7103 * a finite number of iterations
7104 */
7105 return -EINVAL;
7106 }
7107
7108 i++;
7109 }
7110
7111 /*
7112 * The last scan plan must not specify the number of
7113 * iterations, it is supposed to run infinitely
7114 */
7115 if (request->scan_plans[n_plans - 1].iterations)
7116 return -EINVAL;
7117
7118 return 0;
7119}
7120
256da02d 7121static struct cfg80211_sched_scan_request *
ad2b26ab 7122nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev,
aad1e812 7123 struct nlattr **attrs, int max_match_sets)
807f8a8c
LC
7124{
7125 struct cfg80211_sched_scan_request *request;
807f8a8c 7126 struct nlattr *attr;
3b06d277 7127 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0;
57fbcce3 7128 enum nl80211_band band;
807f8a8c 7129 size_t ie_len;
a1f1c21c 7130 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
ea73cbce 7131 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF;
807f8a8c 7132
256da02d
LC
7133 if (!is_valid_ie_attr(attrs[NL80211_ATTR_IE]))
7134 return ERR_PTR(-EINVAL);
807f8a8c 7135
256da02d 7136 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c 7137 n_channels = validate_scan_freqs(
256da02d 7138 attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
807f8a8c 7139 if (!n_channels)
256da02d 7140 return ERR_PTR(-EINVAL);
807f8a8c 7141 } else {
bdfbec2d 7142 n_channels = ieee80211_get_num_supported_channels(wiphy);
807f8a8c
LC
7143 }
7144
256da02d
LC
7145 if (attrs[NL80211_ATTR_SCAN_SSIDS])
7146 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c
LC
7147 tmp)
7148 n_ssids++;
7149
93b6aa69 7150 if (n_ssids > wiphy->max_sched_scan_ssids)
256da02d 7151 return ERR_PTR(-EINVAL);
807f8a8c 7152
ea73cbce
JB
7153 /*
7154 * First, count the number of 'real' matchsets. Due to an issue with
7155 * the old implementation, matchsets containing only the RSSI attribute
7156 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default'
7157 * RSSI for all matchsets, rather than their own matchset for reporting
7158 * all APs with a strong RSSI. This is needed to be compatible with
7159 * older userspace that treated a matchset with only the RSSI as the
7160 * global RSSI for all other matchsets - if there are other matchsets.
7161 */
256da02d 7162 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 7163 nla_for_each_nested(attr,
256da02d 7164 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
ea73cbce
JB
7165 tmp) {
7166 struct nlattr *rssi;
7167
bfe2c7b1
JB
7168 err = nla_parse_nested(tb,
7169 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
fceb6435
JB
7170 attr, nl80211_match_policy,
7171 NULL);
ea73cbce 7172 if (err)
256da02d 7173 return ERR_PTR(err);
3007e352
AVS
7174
7175 /* SSID and BSSID are mutually exclusive */
7176 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] &&
7177 tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID])
7178 return ERR_PTR(-EINVAL);
7179
ea73cbce 7180 /* add other standalone attributes here */
3007e352
AVS
7181 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] ||
7182 tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID]) {
ea73cbce
JB
7183 n_match_sets++;
7184 continue;
7185 }
7186 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
7187 if (rssi)
7188 default_match_rssi = nla_get_s32(rssi);
7189 }
7190 }
7191
7192 /* However, if there's no other matchset, add the RSSI one */
7193 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF)
7194 n_match_sets = 1;
a1f1c21c 7195
aad1e812 7196 if (n_match_sets > max_match_sets)
256da02d 7197 return ERR_PTR(-EINVAL);
a1f1c21c 7198
256da02d
LC
7199 if (attrs[NL80211_ATTR_IE])
7200 ie_len = nla_len(attrs[NL80211_ATTR_IE]);
807f8a8c
LC
7201 else
7202 ie_len = 0;
7203
5a865bad 7204 if (ie_len > wiphy->max_sched_scan_ie_len)
256da02d 7205 return ERR_PTR(-EINVAL);
c10841ca 7206
3b06d277
AS
7207 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
7208 /*
7209 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since
7210 * each scan plan already specifies its own interval
7211 */
7212 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
7213 return ERR_PTR(-EINVAL);
7214
7215 nla_for_each_nested(attr,
7216 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp)
7217 n_plans++;
7218 } else {
7219 /*
7220 * The scan interval attribute is kept for backward
7221 * compatibility. If no scan plans are specified and sched scan
7222 * interval is specified, one scan plan will be set with this
7223 * scan interval and infinite number of iterations.
7224 */
7225 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
7226 return ERR_PTR(-EINVAL);
7227
7228 n_plans = 1;
7229 }
7230
7231 if (!n_plans || n_plans > wiphy->max_sched_scan_plans)
7232 return ERR_PTR(-EINVAL);
7233
bf95ecdb 7234 if (!wiphy_ext_feature_isset(
7235 wiphy, NL80211_EXT_FEATURE_SCHED_SCAN_RELATIVE_RSSI) &&
7236 (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] ||
7237 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]))
7238 return ERR_PTR(-EINVAL);
7239
807f8a8c 7240 request = kzalloc(sizeof(*request)
a2cd43c5 7241 + sizeof(*request->ssids) * n_ssids
a1f1c21c 7242 + sizeof(*request->match_sets) * n_match_sets
3b06d277 7243 + sizeof(*request->scan_plans) * n_plans
a2cd43c5 7244 + sizeof(*request->channels) * n_channels
807f8a8c 7245 + ie_len, GFP_KERNEL);
256da02d
LC
7246 if (!request)
7247 return ERR_PTR(-ENOMEM);
807f8a8c
LC
7248
7249 if (n_ssids)
7250 request->ssids = (void *)&request->channels[n_channels];
7251 request->n_ssids = n_ssids;
7252 if (ie_len) {
13874e4b 7253 if (n_ssids)
807f8a8c
LC
7254 request->ie = (void *)(request->ssids + n_ssids);
7255 else
7256 request->ie = (void *)(request->channels + n_channels);
7257 }
7258
a1f1c21c
LC
7259 if (n_match_sets) {
7260 if (request->ie)
7261 request->match_sets = (void *)(request->ie + ie_len);
13874e4b 7262 else if (n_ssids)
a1f1c21c
LC
7263 request->match_sets =
7264 (void *)(request->ssids + n_ssids);
7265 else
7266 request->match_sets =
7267 (void *)(request->channels + n_channels);
7268 }
7269 request->n_match_sets = n_match_sets;
7270
3b06d277
AS
7271 if (n_match_sets)
7272 request->scan_plans = (void *)(request->match_sets +
7273 n_match_sets);
7274 else if (request->ie)
7275 request->scan_plans = (void *)(request->ie + ie_len);
7276 else if (n_ssids)
7277 request->scan_plans = (void *)(request->ssids + n_ssids);
7278 else
7279 request->scan_plans = (void *)(request->channels + n_channels);
7280
7281 request->n_scan_plans = n_plans;
7282
807f8a8c 7283 i = 0;
256da02d 7284 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c
LC
7285 /* user specified, bail out if channel not found */
7286 nla_for_each_nested(attr,
256da02d 7287 attrs[NL80211_ATTR_SCAN_FREQUENCIES],
807f8a8c
LC
7288 tmp) {
7289 struct ieee80211_channel *chan;
7290
7291 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
7292
7293 if (!chan) {
7294 err = -EINVAL;
7295 goto out_free;
7296 }
7297
7298 /* ignore disabled channels */
7299 if (chan->flags & IEEE80211_CHAN_DISABLED)
7300 continue;
7301
7302 request->channels[i] = chan;
7303 i++;
7304 }
7305 } else {
7306 /* all channels */
57fbcce3 7307 for (band = 0; band < NUM_NL80211_BANDS; band++) {
807f8a8c 7308 int j;
7a087e74 7309
807f8a8c
LC
7310 if (!wiphy->bands[band])
7311 continue;
7312 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
7313 struct ieee80211_channel *chan;
7314
7315 chan = &wiphy->bands[band]->channels[j];
7316
7317 if (chan->flags & IEEE80211_CHAN_DISABLED)
7318 continue;
7319
7320 request->channels[i] = chan;
7321 i++;
7322 }
7323 }
7324 }
7325
7326 if (!i) {
7327 err = -EINVAL;
7328 goto out_free;
7329 }
7330
7331 request->n_channels = i;
7332
7333 i = 0;
13874e4b 7334 if (n_ssids) {
256da02d 7335 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c 7336 tmp) {
57a27e1d 7337 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
7338 err = -EINVAL;
7339 goto out_free;
7340 }
57a27e1d 7341 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
7342 memcpy(request->ssids[i].ssid, nla_data(attr),
7343 nla_len(attr));
807f8a8c
LC
7344 i++;
7345 }
7346 }
7347
a1f1c21c 7348 i = 0;
256da02d 7349 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 7350 nla_for_each_nested(attr,
256da02d 7351 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
a1f1c21c 7352 tmp) {
3007e352 7353 struct nlattr *ssid, *bssid, *rssi;
a1f1c21c 7354
bfe2c7b1
JB
7355 err = nla_parse_nested(tb,
7356 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
fceb6435
JB
7357 attr, nl80211_match_policy,
7358 NULL);
ae811e21
JB
7359 if (err)
7360 goto out_free;
4a4ab0d7 7361 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
3007e352
AVS
7362 bssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID];
7363 if (ssid || bssid) {
ea73cbce
JB
7364 if (WARN_ON(i >= n_match_sets)) {
7365 /* this indicates a programming error,
7366 * the loop above should have verified
7367 * things properly
7368 */
7369 err = -EINVAL;
7370 goto out_free;
7371 }
7372
3007e352
AVS
7373 if (ssid) {
7374 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
7375 err = -EINVAL;
7376 goto out_free;
7377 }
7378 memcpy(request->match_sets[i].ssid.ssid,
7379 nla_data(ssid), nla_len(ssid));
7380 request->match_sets[i].ssid.ssid_len =
7381 nla_len(ssid);
7382 }
7383 if (bssid) {
7384 if (nla_len(bssid) != ETH_ALEN) {
7385 err = -EINVAL;
7386 goto out_free;
7387 }
7388 memcpy(request->match_sets[i].bssid,
7389 nla_data(bssid), ETH_ALEN);
a1f1c21c 7390 }
3007e352 7391
56ab364f 7392 /* special attribute - old implementation w/a */
ea73cbce
JB
7393 request->match_sets[i].rssi_thold =
7394 default_match_rssi;
7395 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
7396 if (rssi)
7397 request->match_sets[i].rssi_thold =
7398 nla_get_s32(rssi);
a1f1c21c
LC
7399 }
7400 i++;
7401 }
ea73cbce
JB
7402
7403 /* there was no other matchset, so the RSSI one is alone */
f89f46cf 7404 if (i == 0 && n_match_sets)
ea73cbce
JB
7405 request->match_sets[0].rssi_thold = default_match_rssi;
7406
7407 request->min_rssi_thold = INT_MAX;
7408 for (i = 0; i < n_match_sets; i++)
7409 request->min_rssi_thold =
7410 min(request->match_sets[i].rssi_thold,
7411 request->min_rssi_thold);
7412 } else {
7413 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
7414 }
7415
9900e484
JB
7416 if (ie_len) {
7417 request->ie_len = ie_len;
807f8a8c 7418 memcpy((void *)request->ie,
256da02d 7419 nla_data(attrs[NL80211_ATTR_IE]),
807f8a8c
LC
7420 request->ie_len);
7421 }
7422
2d23d073
RZ
7423 err = nl80211_check_scan_flags(wiphy, wdev, request, attrs, true);
7424 if (err)
7425 goto out_free;
ed473771 7426
9c748934
LC
7427 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY])
7428 request->delay =
7429 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]);
7430
bf95ecdb 7431 if (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]) {
7432 request->relative_rssi = nla_get_s8(
7433 attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]);
7434 request->relative_rssi_set = true;
7435 }
7436
7437 if (request->relative_rssi_set &&
7438 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]) {
7439 struct nl80211_bss_select_rssi_adjust *rssi_adjust;
7440
7441 rssi_adjust = nla_data(
7442 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]);
7443 request->rssi_adjust.band = rssi_adjust->band;
7444 request->rssi_adjust.delta = rssi_adjust->delta;
7445 if (!is_band_valid(wiphy, request->rssi_adjust.band)) {
7446 err = -EINVAL;
7447 goto out_free;
7448 }
7449 }
7450
3b06d277
AS
7451 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs);
7452 if (err)
7453 goto out_free;
7454
15d6030b 7455 request->scan_start = jiffies;
807f8a8c 7456
256da02d 7457 return request;
807f8a8c
LC
7458
7459out_free:
7460 kfree(request);
256da02d
LC
7461 return ERR_PTR(err);
7462}
7463
7464static int nl80211_start_sched_scan(struct sk_buff *skb,
7465 struct genl_info *info)
7466{
7467 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7468 struct net_device *dev = info->user_ptr[1];
ad2b26ab 7469 struct wireless_dev *wdev = dev->ieee80211_ptr;
31a60ed1 7470 struct cfg80211_sched_scan_request *sched_scan_req;
ca986ad9 7471 bool want_multi;
256da02d
LC
7472 int err;
7473
ca986ad9 7474 if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_start)
256da02d
LC
7475 return -EOPNOTSUPP;
7476
ca986ad9
AVS
7477 want_multi = info->attrs[NL80211_ATTR_SCHED_SCAN_MULTI];
7478 err = cfg80211_sched_scan_req_possible(rdev, want_multi);
7479 if (err)
7480 return err;
256da02d 7481
31a60ed1 7482 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev,
aad1e812
AVS
7483 info->attrs,
7484 rdev->wiphy.max_match_sets);
31a60ed1
JR
7485
7486 err = PTR_ERR_OR_ZERO(sched_scan_req);
256da02d
LC
7487 if (err)
7488 goto out_err;
7489
ca986ad9
AVS
7490 /* leave request id zero for legacy request
7491 * or if driver does not support multi-scheduled scan
7492 */
7493 if (want_multi && rdev->wiphy.max_sched_scan_reqs > 1) {
7494 while (!sched_scan_req->reqid)
7495 sched_scan_req->reqid = rdev->wiphy.cookie_counter++;
7496 }
7497
31a60ed1 7498 err = rdev_sched_scan_start(rdev, dev, sched_scan_req);
256da02d
LC
7499 if (err)
7500 goto out_free;
7501
31a60ed1
JR
7502 sched_scan_req->dev = dev;
7503 sched_scan_req->wiphy = &rdev->wiphy;
7504
93a1e86c
JR
7505 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
7506 sched_scan_req->owner_nlportid = info->snd_portid;
7507
ca986ad9 7508 cfg80211_add_sched_scan_req(rdev, sched_scan_req);
256da02d 7509
96b08fd6 7510 nl80211_send_sched_scan(sched_scan_req, NL80211_CMD_START_SCHED_SCAN);
256da02d
LC
7511 return 0;
7512
7513out_free:
31a60ed1 7514 kfree(sched_scan_req);
256da02d 7515out_err:
807f8a8c
LC
7516 return err;
7517}
7518
7519static int nl80211_stop_sched_scan(struct sk_buff *skb,
7520 struct genl_info *info)
7521{
ca986ad9 7522 struct cfg80211_sched_scan_request *req;
807f8a8c 7523 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ca986ad9 7524 u64 cookie;
807f8a8c 7525
ca986ad9 7526 if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_stop)
807f8a8c
LC
7527 return -EOPNOTSUPP;
7528
ca986ad9
AVS
7529 if (info->attrs[NL80211_ATTR_COOKIE]) {
7530 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
7531 return __cfg80211_stop_sched_scan(rdev, cookie, false);
7532 }
7533
7534 req = list_first_or_null_rcu(&rdev->sched_scan_req_list,
7535 struct cfg80211_sched_scan_request,
7536 list);
7537 if (!req || req->reqid ||
7538 (req->owner_nlportid &&
7539 req->owner_nlportid != info->snd_portid))
7540 return -ENOENT;
7541
7542 return cfg80211_stop_sched_scan_req(rdev, req, false);
807f8a8c
LC
7543}
7544
04f39047
SW
7545static int nl80211_start_radar_detection(struct sk_buff *skb,
7546 struct genl_info *info)
7547{
7548 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7549 struct net_device *dev = info->user_ptr[1];
7550 struct wireless_dev *wdev = dev->ieee80211_ptr;
7551 struct cfg80211_chan_def chandef;
55f7435c 7552 enum nl80211_dfs_regions dfs_region;
31559f35 7553 unsigned int cac_time_ms;
04f39047
SW
7554 int err;
7555
55f7435c
LR
7556 dfs_region = reg_get_dfs_region(wdev->wiphy);
7557 if (dfs_region == NL80211_DFS_UNSET)
7558 return -EINVAL;
7559
04f39047
SW
7560 err = nl80211_parse_chandef(rdev, info, &chandef);
7561 if (err)
7562 return err;
7563
ff311bc1
SW
7564 if (netif_carrier_ok(dev))
7565 return -EBUSY;
7566
04f39047
SW
7567 if (wdev->cac_started)
7568 return -EBUSY;
7569
2beb6dab 7570 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef,
00ec75fc 7571 wdev->iftype);
04f39047
SW
7572 if (err < 0)
7573 return err;
7574
7575 if (err == 0)
7576 return -EINVAL;
7577
fe7c3a1f 7578 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef))
04f39047
SW
7579 return -EINVAL;
7580
7581 if (!rdev->ops->start_radar_detection)
7582 return -EOPNOTSUPP;
7583
31559f35
JD
7584 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef);
7585 if (WARN_ON(!cac_time_ms))
7586 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
7587
a1056b1b 7588 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms);
04f39047 7589 if (!err) {
9e0e2961 7590 wdev->chandef = chandef;
04f39047
SW
7591 wdev->cac_started = true;
7592 wdev->cac_start_time = jiffies;
31559f35 7593 wdev->cac_time_ms = cac_time_ms;
04f39047 7594 }
04f39047
SW
7595 return err;
7596}
7597
16ef1fe2
SW
7598static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
7599{
7600 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7601 struct net_device *dev = info->user_ptr[1];
7602 struct wireless_dev *wdev = dev->ieee80211_ptr;
7603 struct cfg80211_csa_settings params;
7604 /* csa_attrs is defined static to avoid waste of stack size - this
7605 * function is called under RTNL lock, so this should not be a problem.
7606 */
7607 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
16ef1fe2 7608 int err;
ee4bc9e7 7609 bool need_new_beacon = false;
8d9de16f 7610 bool need_handle_dfs_flag = true;
9a774c78 7611 int len, i;
252e07ca 7612 u32 cs_count;
16ef1fe2
SW
7613
7614 if (!rdev->ops->channel_switch ||
7615 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
7616 return -EOPNOTSUPP;
7617
ee4bc9e7
SW
7618 switch (dev->ieee80211_ptr->iftype) {
7619 case NL80211_IFTYPE_AP:
7620 case NL80211_IFTYPE_P2P_GO:
7621 need_new_beacon = true;
8d9de16f
BB
7622 /* For all modes except AP the handle_dfs flag needs to be
7623 * supplied to tell the kernel that userspace will handle radar
7624 * events when they happen. Otherwise a switch to a channel
7625 * requiring DFS will be rejected.
7626 */
7627 need_handle_dfs_flag = false;
ee4bc9e7
SW
7628
7629 /* useless if AP is not running */
7630 if (!wdev->beacon_interval)
1ff79dfa 7631 return -ENOTCONN;
ee4bc9e7
SW
7632 break;
7633 case NL80211_IFTYPE_ADHOC:
1ff79dfa
JB
7634 if (!wdev->ssid_len)
7635 return -ENOTCONN;
7636 break;
c6da674a 7637 case NL80211_IFTYPE_MESH_POINT:
1ff79dfa
JB
7638 if (!wdev->mesh_id_len)
7639 return -ENOTCONN;
ee4bc9e7
SW
7640 break;
7641 default:
16ef1fe2 7642 return -EOPNOTSUPP;
ee4bc9e7 7643 }
16ef1fe2
SW
7644
7645 memset(&params, 0, sizeof(params));
7646
7647 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
7648 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
7649 return -EINVAL;
7650
7651 /* only important for AP, IBSS and mesh create IEs internally */
d0a361a5 7652 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
16ef1fe2
SW
7653 return -EINVAL;
7654
252e07ca
LC
7655 /* Even though the attribute is u32, the specification says
7656 * u8, so let's make sure we don't overflow.
7657 */
7658 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
7659 if (cs_count > 255)
7660 return -EINVAL;
7661
7662 params.count = cs_count;
16ef1fe2 7663
ee4bc9e7
SW
7664 if (!need_new_beacon)
7665 goto skip_beacons;
7666
16ef1fe2
SW
7667 err = nl80211_parse_beacon(info->attrs, &params.beacon_after);
7668 if (err)
7669 return err;
7670
7671 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX,
7672 info->attrs[NL80211_ATTR_CSA_IES],
fe52145f 7673 nl80211_policy, info->extack);
16ef1fe2
SW
7674 if (err)
7675 return err;
7676
7677 err = nl80211_parse_beacon(csa_attrs, &params.beacon_csa);
7678 if (err)
7679 return err;
7680
7681 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
7682 return -EINVAL;
7683
9a774c78
AO
7684 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
7685 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
7686 return -EINVAL;
7687
9a774c78
AO
7688 params.n_counter_offsets_beacon = len / sizeof(u16);
7689 if (rdev->wiphy.max_num_csa_counters &&
7690 (params.n_counter_offsets_beacon >
7691 rdev->wiphy.max_num_csa_counters))
16ef1fe2
SW
7692 return -EINVAL;
7693
9a774c78
AO
7694 params.counter_offsets_beacon =
7695 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
7696
7697 /* sanity checks - counters should fit and be the same */
7698 for (i = 0; i < params.n_counter_offsets_beacon; i++) {
7699 u16 offset = params.counter_offsets_beacon[i];
7700
7701 if (offset >= params.beacon_csa.tail_len)
7702 return -EINVAL;
7703
7704 if (params.beacon_csa.tail[offset] != params.count)
7705 return -EINVAL;
7706 }
7707
16ef1fe2 7708 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
9a774c78
AO
7709 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
7710 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
7711 return -EINVAL;
7712
9a774c78
AO
7713 params.n_counter_offsets_presp = len / sizeof(u16);
7714 if (rdev->wiphy.max_num_csa_counters &&
ad5987b4 7715 (params.n_counter_offsets_presp >
9a774c78 7716 rdev->wiphy.max_num_csa_counters))
16ef1fe2 7717 return -EINVAL;
9a774c78
AO
7718
7719 params.counter_offsets_presp =
7720 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
7721
7722 /* sanity checks - counters should fit and be the same */
7723 for (i = 0; i < params.n_counter_offsets_presp; i++) {
7724 u16 offset = params.counter_offsets_presp[i];
7725
7726 if (offset >= params.beacon_csa.probe_resp_len)
7727 return -EINVAL;
7728
7729 if (params.beacon_csa.probe_resp[offset] !=
7730 params.count)
7731 return -EINVAL;
7732 }
16ef1fe2
SW
7733 }
7734
ee4bc9e7 7735skip_beacons:
16ef1fe2
SW
7736 err = nl80211_parse_chandef(rdev, info, &params.chandef);
7737 if (err)
7738 return err;
7739
923b352f
AN
7740 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
7741 wdev->iftype))
16ef1fe2
SW
7742 return -EINVAL;
7743
2beb6dab
LC
7744 err = cfg80211_chandef_dfs_required(wdev->wiphy,
7745 &params.chandef,
7746 wdev->iftype);
7747 if (err < 0)
7748 return err;
7749
8d9de16f 7750 if (err > 0) {
2beb6dab 7751 params.radar_required = true;
8d9de16f
BB
7752 if (need_handle_dfs_flag &&
7753 !nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS])) {
7754 return -EINVAL;
7755 }
7756 }
16ef1fe2 7757
16ef1fe2
SW
7758 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
7759 params.block_tx = true;
7760
c56589ed
SW
7761 wdev_lock(wdev);
7762 err = rdev_channel_switch(rdev, dev, &params);
7763 wdev_unlock(wdev);
7764
7765 return err;
16ef1fe2
SW
7766}
7767
9720bb3a
JB
7768static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
7769 u32 seq, int flags,
2a519311 7770 struct cfg80211_registered_device *rdev,
48ab905d
JB
7771 struct wireless_dev *wdev,
7772 struct cfg80211_internal_bss *intbss)
2a519311 7773{
48ab905d 7774 struct cfg80211_bss *res = &intbss->pub;
9caf0364 7775 const struct cfg80211_bss_ies *ies;
2a519311
JB
7776 void *hdr;
7777 struct nlattr *bss;
48ab905d
JB
7778
7779 ASSERT_WDEV_LOCK(wdev);
2a519311 7780
15e47304 7781 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
7782 NL80211_CMD_NEW_SCAN_RESULTS);
7783 if (!hdr)
7784 return -1;
7785
0a833c29 7786 genl_dump_check_consistent(cb, hdr);
9720bb3a 7787
97990a06
JB
7788 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
7789 goto nla_put_failure;
7790 if (wdev->netdev &&
9360ffd1
DM
7791 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
7792 goto nla_put_failure;
2dad624e
ND
7793 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
7794 NL80211_ATTR_PAD))
97990a06 7795 goto nla_put_failure;
2a519311
JB
7796
7797 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
7798 if (!bss)
7799 goto nla_put_failure;
9360ffd1 7800 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 7801 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 7802 goto nla_put_failure;
9caf0364
JB
7803
7804 rcu_read_lock();
0e227084
JB
7805 /* indicate whether we have probe response data or not */
7806 if (rcu_access_pointer(res->proberesp_ies) &&
7807 nla_put_flag(msg, NL80211_BSS_PRESP_DATA))
7808 goto fail_unlock_rcu;
7809
7810 /* this pointer prefers to be pointed to probe response data
7811 * but is always valid
7812 */
9caf0364 7813 ies = rcu_dereference(res->ies);
8cef2c9d 7814 if (ies) {
2dad624e
ND
7815 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf,
7816 NL80211_BSS_PAD))
8cef2c9d 7817 goto fail_unlock_rcu;
8cef2c9d
JB
7818 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
7819 ies->len, ies->data))
7820 goto fail_unlock_rcu;
9caf0364 7821 }
0e227084
JB
7822
7823 /* and this pointer is always (unless driver didn't know) beacon data */
9caf0364 7824 ies = rcu_dereference(res->beacon_ies);
0e227084 7825 if (ies && ies->from_beacon) {
2dad624e
ND
7826 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf,
7827 NL80211_BSS_PAD))
8cef2c9d
JB
7828 goto fail_unlock_rcu;
7829 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
7830 ies->len, ies->data))
7831 goto fail_unlock_rcu;
9caf0364
JB
7832 }
7833 rcu_read_unlock();
7834
9360ffd1
DM
7835 if (res->beacon_interval &&
7836 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
7837 goto nla_put_failure;
7838 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
7839 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
dcd6eac1 7840 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
7841 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
7842 jiffies_to_msecs(jiffies - intbss->ts)))
7843 goto nla_put_failure;
2a519311 7844
1d76250b
AS
7845 if (intbss->parent_tsf &&
7846 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF,
7847 intbss->parent_tsf, NL80211_BSS_PAD) ||
7848 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN,
7849 intbss->parent_bssid)))
7850 goto nla_put_failure;
7851
6e19bc4b 7852 if (intbss->ts_boottime &&
2dad624e
ND
7853 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME,
7854 intbss->ts_boottime, NL80211_BSS_PAD))
6e19bc4b
DS
7855 goto nla_put_failure;
7856
983dafaa
SD
7857 if (!nl80211_put_signal(msg, intbss->pub.chains,
7858 intbss->pub.chain_signal,
7859 NL80211_BSS_CHAIN_SIGNAL))
7860 goto nla_put_failure;
7861
77965c97 7862 switch (rdev->wiphy.signal_type) {
2a519311 7863 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
7864 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
7865 goto nla_put_failure;
2a519311
JB
7866 break;
7867 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
7868 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
7869 goto nla_put_failure;
2a519311
JB
7870 break;
7871 default:
7872 break;
7873 }
7874
48ab905d 7875 switch (wdev->iftype) {
074ac8df 7876 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 7877 case NL80211_IFTYPE_STATION:
9360ffd1
DM
7878 if (intbss == wdev->current_bss &&
7879 nla_put_u32(msg, NL80211_BSS_STATUS,
7880 NL80211_BSS_STATUS_ASSOCIATED))
7881 goto nla_put_failure;
48ab905d
JB
7882 break;
7883 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
7884 if (intbss == wdev->current_bss &&
7885 nla_put_u32(msg, NL80211_BSS_STATUS,
7886 NL80211_BSS_STATUS_IBSS_JOINED))
7887 goto nla_put_failure;
48ab905d
JB
7888 break;
7889 default:
7890 break;
7891 }
7892
2a519311
JB
7893 nla_nest_end(msg, bss);
7894
053c095a
JB
7895 genlmsg_end(msg, hdr);
7896 return 0;
2a519311 7897
8cef2c9d
JB
7898 fail_unlock_rcu:
7899 rcu_read_unlock();
2a519311
JB
7900 nla_put_failure:
7901 genlmsg_cancel(msg, hdr);
7902 return -EMSGSIZE;
7903}
7904
97990a06 7905static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 7906{
48ab905d 7907 struct cfg80211_registered_device *rdev;
2a519311 7908 struct cfg80211_internal_bss *scan;
48ab905d 7909 struct wireless_dev *wdev;
97990a06 7910 int start = cb->args[2], idx = 0;
2a519311
JB
7911 int err;
7912
ea90e0dc 7913 rtnl_lock();
97990a06 7914 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
ea90e0dc
JB
7915 if (err) {
7916 rtnl_unlock();
67748893 7917 return err;
ea90e0dc 7918 }
2a519311 7919
48ab905d
JB
7920 wdev_lock(wdev);
7921 spin_lock_bh(&rdev->bss_lock);
7922 cfg80211_bss_expire(rdev);
7923
9720bb3a
JB
7924 cb->seq = rdev->bss_generation;
7925
48ab905d 7926 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
7927 if (++idx <= start)
7928 continue;
9720bb3a 7929 if (nl80211_send_bss(skb, cb,
2a519311 7930 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 7931 rdev, wdev, scan) < 0) {
2a519311 7932 idx--;
67748893 7933 break;
2a519311
JB
7934 }
7935 }
7936
48ab905d
JB
7937 spin_unlock_bh(&rdev->bss_lock);
7938 wdev_unlock(wdev);
2a519311 7939
97990a06 7940 cb->args[2] = idx;
ea90e0dc 7941 rtnl_unlock();
2a519311 7942
67748893 7943 return skb->len;
2a519311
JB
7944}
7945
15e47304 7946static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
11f78ac3
JB
7947 int flags, struct net_device *dev,
7948 bool allow_radio_stats,
7949 struct survey_info *survey)
61fa713c
HS
7950{
7951 void *hdr;
7952 struct nlattr *infoattr;
7953
11f78ac3
JB
7954 /* skip radio stats if userspace didn't request them */
7955 if (!survey->channel && !allow_radio_stats)
7956 return 0;
7957
15e47304 7958 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
7959 NL80211_CMD_NEW_SURVEY_RESULTS);
7960 if (!hdr)
7961 return -ENOMEM;
7962
9360ffd1
DM
7963 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
7964 goto nla_put_failure;
61fa713c
HS
7965
7966 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
7967 if (!infoattr)
7968 goto nla_put_failure;
7969
11f78ac3
JB
7970 if (survey->channel &&
7971 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
9360ffd1
DM
7972 survey->channel->center_freq))
7973 goto nla_put_failure;
7974
7975 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
7976 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
7977 goto nla_put_failure;
7978 if ((survey->filled & SURVEY_INFO_IN_USE) &&
7979 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
7980 goto nla_put_failure;
4ed20beb 7981 if ((survey->filled & SURVEY_INFO_TIME) &&
2dad624e
ND
7982 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME,
7983 survey->time, NL80211_SURVEY_INFO_PAD))
9360ffd1 7984 goto nla_put_failure;
4ed20beb 7985 if ((survey->filled & SURVEY_INFO_TIME_BUSY) &&
2dad624e
ND
7986 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY,
7987 survey->time_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 7988 goto nla_put_failure;
4ed20beb 7989 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) &&
2dad624e
ND
7990 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY,
7991 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 7992 goto nla_put_failure;
4ed20beb 7993 if ((survey->filled & SURVEY_INFO_TIME_RX) &&
2dad624e
ND
7994 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX,
7995 survey->time_rx, NL80211_SURVEY_INFO_PAD))
9360ffd1 7996 goto nla_put_failure;
4ed20beb 7997 if ((survey->filled & SURVEY_INFO_TIME_TX) &&
2dad624e
ND
7998 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX,
7999 survey->time_tx, NL80211_SURVEY_INFO_PAD))
9360ffd1 8000 goto nla_put_failure;
052536ab 8001 if ((survey->filled & SURVEY_INFO_TIME_SCAN) &&
2dad624e
ND
8002 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN,
8003 survey->time_scan, NL80211_SURVEY_INFO_PAD))
052536ab 8004 goto nla_put_failure;
61fa713c
HS
8005
8006 nla_nest_end(msg, infoattr);
8007
053c095a
JB
8008 genlmsg_end(msg, hdr);
8009 return 0;
61fa713c
HS
8010
8011 nla_put_failure:
8012 genlmsg_cancel(msg, hdr);
8013 return -EMSGSIZE;
8014}
8015
11f78ac3 8016static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb)
61fa713c 8017{
c90c39da 8018 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam);
61fa713c 8019 struct survey_info survey;
1b8ec87a 8020 struct cfg80211_registered_device *rdev;
97990a06
JB
8021 struct wireless_dev *wdev;
8022 int survey_idx = cb->args[2];
61fa713c 8023 int res;
11f78ac3 8024 bool radio_stats;
61fa713c 8025
ea90e0dc 8026 rtnl_lock();
1b8ec87a 8027 res = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev);
67748893 8028 if (res)
ea90e0dc 8029 goto out_err;
61fa713c 8030
11f78ac3 8031 /* prepare_wdev_dump parsed the attributes */
c90c39da 8032 radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS];
11f78ac3 8033
97990a06
JB
8034 if (!wdev->netdev) {
8035 res = -EINVAL;
8036 goto out_err;
8037 }
8038
1b8ec87a 8039 if (!rdev->ops->dump_survey) {
61fa713c
HS
8040 res = -EOPNOTSUPP;
8041 goto out_err;
8042 }
8043
8044 while (1) {
1b8ec87a 8045 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
8046 if (res == -ENOENT)
8047 break;
8048 if (res)
8049 goto out_err;
8050
11f78ac3
JB
8051 /* don't send disabled channels, but do send non-channel data */
8052 if (survey.channel &&
8053 survey.channel->flags & IEEE80211_CHAN_DISABLED) {
180cdc79
LR
8054 survey_idx++;
8055 continue;
8056 }
8057
61fa713c 8058 if (nl80211_send_survey(skb,
15e47304 8059 NETLINK_CB(cb->skb).portid,
61fa713c 8060 cb->nlh->nlmsg_seq, NLM_F_MULTI,
11f78ac3 8061 wdev->netdev, radio_stats, &survey) < 0)
61fa713c
HS
8062 goto out;
8063 survey_idx++;
8064 }
8065
8066 out:
97990a06 8067 cb->args[2] = survey_idx;
61fa713c
HS
8068 res = skb->len;
8069 out_err:
ea90e0dc 8070 rtnl_unlock();
61fa713c
HS
8071 return res;
8072}
8073
b23aa676
SO
8074static bool nl80211_valid_wpa_versions(u32 wpa_versions)
8075{
8076 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
8077 NL80211_WPA_VERSION_2));
8078}
8079
636a5d36
JM
8080static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
8081{
4c476991
JB
8082 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8083 struct net_device *dev = info->user_ptr[1];
19957bb3 8084 struct ieee80211_channel *chan;
11b6b5a4
JM
8085 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL;
8086 int err, ssid_len, ie_len = 0, auth_data_len = 0;
19957bb3 8087 enum nl80211_auth_type auth_type;
fffd0934 8088 struct key_parse key;
d5cdfacb 8089 bool local_state_change;
636a5d36 8090
f4a11bb0
JB
8091 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8092 return -EINVAL;
8093
8094 if (!info->attrs[NL80211_ATTR_MAC])
8095 return -EINVAL;
8096
1778092e
JM
8097 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
8098 return -EINVAL;
8099
19957bb3
JB
8100 if (!info->attrs[NL80211_ATTR_SSID])
8101 return -EINVAL;
8102
8103 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
8104 return -EINVAL;
8105
fffd0934
JB
8106 err = nl80211_parse_key(info, &key);
8107 if (err)
8108 return err;
8109
8110 if (key.idx >= 0) {
e31b8213
JB
8111 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
8112 return -EINVAL;
fffd0934
JB
8113 if (!key.p.key || !key.p.key_len)
8114 return -EINVAL;
8115 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
8116 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
8117 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
8118 key.p.key_len != WLAN_KEY_LEN_WEP104))
8119 return -EINVAL;
b6b5555b 8120 if (key.idx > 3)
fffd0934
JB
8121 return -EINVAL;
8122 } else {
8123 key.p.key_len = 0;
8124 key.p.key = NULL;
8125 }
8126
afea0b7a
JB
8127 if (key.idx >= 0) {
8128 int i;
8129 bool ok = false;
7a087e74 8130
afea0b7a
JB
8131 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
8132 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
8133 ok = true;
8134 break;
8135 }
8136 }
4c476991
JB
8137 if (!ok)
8138 return -EINVAL;
afea0b7a
JB
8139 }
8140
4c476991
JB
8141 if (!rdev->ops->auth)
8142 return -EOPNOTSUPP;
636a5d36 8143
074ac8df 8144 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8145 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8146 return -EOPNOTSUPP;
eec60b03 8147
19957bb3 8148 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
664834de
JM
8149 chan = nl80211_get_valid_chan(&rdev->wiphy,
8150 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
8151 if (!chan)
4c476991 8152 return -EINVAL;
636a5d36 8153
19957bb3
JB
8154 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
8155 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
8156
8157 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
8158 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8159 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8160 }
8161
19957bb3 8162 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 8163 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 8164 return -EINVAL;
636a5d36 8165
63181060
JM
8166 if ((auth_type == NL80211_AUTHTYPE_SAE ||
8167 auth_type == NL80211_AUTHTYPE_FILS_SK ||
8168 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
8169 auth_type == NL80211_AUTHTYPE_FILS_PK) &&
11b6b5a4 8170 !info->attrs[NL80211_ATTR_AUTH_DATA])
e39e5b5e
JM
8171 return -EINVAL;
8172
11b6b5a4 8173 if (info->attrs[NL80211_ATTR_AUTH_DATA]) {
63181060
JM
8174 if (auth_type != NL80211_AUTHTYPE_SAE &&
8175 auth_type != NL80211_AUTHTYPE_FILS_SK &&
8176 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS &&
8177 auth_type != NL80211_AUTHTYPE_FILS_PK)
e39e5b5e 8178 return -EINVAL;
11b6b5a4
JM
8179 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]);
8180 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]);
e39e5b5e 8181 /* need to include at least Auth Transaction and Status Code */
11b6b5a4 8182 if (auth_data_len < 4)
e39e5b5e
JM
8183 return -EINVAL;
8184 }
8185
d5cdfacb
JM
8186 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
8187
95de817b
JB
8188 /*
8189 * Since we no longer track auth state, ignore
8190 * requests to only change local state.
8191 */
8192 if (local_state_change)
8193 return 0;
8194
91bf9b26
JB
8195 wdev_lock(dev->ieee80211_ptr);
8196 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
8197 ssid, ssid_len, ie, ie_len,
8198 key.p.key, key.p.key_len, key.idx,
11b6b5a4 8199 auth_data, auth_data_len);
91bf9b26
JB
8200 wdev_unlock(dev->ieee80211_ptr);
8201 return err;
636a5d36
JM
8202}
8203
c0692b8f
JB
8204static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
8205 struct genl_info *info,
3dc27d25
JB
8206 struct cfg80211_crypto_settings *settings,
8207 int cipher_limit)
b23aa676 8208{
c0b2bbd8
JB
8209 memset(settings, 0, sizeof(*settings));
8210
b23aa676
SO
8211 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
8212
c0692b8f
JB
8213 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
8214 u16 proto;
7a087e74 8215
c0692b8f
JB
8216 proto = nla_get_u16(
8217 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
8218 settings->control_port_ethertype = cpu_to_be16(proto);
8219 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
8220 proto != ETH_P_PAE)
8221 return -EINVAL;
8222 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
8223 settings->control_port_no_encrypt = true;
8224 } else
8225 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
8226
b23aa676
SO
8227 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
8228 void *data;
8229 int len, i;
8230
8231 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
8232 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
8233 settings->n_ciphers_pairwise = len / sizeof(u32);
8234
8235 if (len % sizeof(u32))
8236 return -EINVAL;
8237
3dc27d25 8238 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
8239 return -EINVAL;
8240
8241 memcpy(settings->ciphers_pairwise, data, len);
8242
8243 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
8244 if (!cfg80211_supported_cipher_suite(
8245 &rdev->wiphy,
b23aa676
SO
8246 settings->ciphers_pairwise[i]))
8247 return -EINVAL;
8248 }
8249
8250 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
8251 settings->cipher_group =
8252 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
8253 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
8254 settings->cipher_group))
b23aa676
SO
8255 return -EINVAL;
8256 }
8257
8258 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
8259 settings->wpa_versions =
8260 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
8261 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
8262 return -EINVAL;
8263 }
8264
8265 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
8266 void *data;
6d30240e 8267 int len;
b23aa676
SO
8268
8269 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
8270 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
8271 settings->n_akm_suites = len / sizeof(u32);
8272
8273 if (len % sizeof(u32))
8274 return -EINVAL;
8275
1b9ca027
JM
8276 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
8277 return -EINVAL;
8278
b23aa676 8279 memcpy(settings->akm_suites, data, len);
b23aa676
SO
8280 }
8281
91b5ab62
EP
8282 if (info->attrs[NL80211_ATTR_PMK]) {
8283 if (nla_len(info->attrs[NL80211_ATTR_PMK]) != WLAN_PMK_LEN)
8284 return -EINVAL;
8285 if (!wiphy_ext_feature_isset(&rdev->wiphy,
8286 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_PSK))
8287 return -EINVAL;
8288 settings->psk = nla_data(info->attrs[NL80211_ATTR_PMK]);
8289 }
8290
b23aa676
SO
8291 return 0;
8292}
8293
636a5d36
JM
8294static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
8295{
4c476991
JB
8296 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8297 struct net_device *dev = info->user_ptr[1];
f444de05 8298 struct ieee80211_channel *chan;
f62fab73
JB
8299 struct cfg80211_assoc_request req = {};
8300 const u8 *bssid, *ssid;
8301 int err, ssid_len = 0;
636a5d36 8302
f4a11bb0
JB
8303 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8304 return -EINVAL;
8305
8306 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
8307 !info->attrs[NL80211_ATTR_SSID] ||
8308 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
8309 return -EINVAL;
8310
4c476991
JB
8311 if (!rdev->ops->assoc)
8312 return -EOPNOTSUPP;
636a5d36 8313
074ac8df 8314 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8315 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8316 return -EOPNOTSUPP;
eec60b03 8317
19957bb3 8318 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 8319
664834de
JM
8320 chan = nl80211_get_valid_chan(&rdev->wiphy,
8321 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
8322 if (!chan)
4c476991 8323 return -EINVAL;
636a5d36 8324
19957bb3
JB
8325 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
8326 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
8327
8328 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
8329 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8330 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8331 }
8332
dc6382ce 8333 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 8334 enum nl80211_mfp mfp =
dc6382ce 8335 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 8336 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 8337 req.use_mfp = true;
4c476991
JB
8338 else if (mfp != NL80211_MFP_NO)
8339 return -EINVAL;
dc6382ce
JM
8340 }
8341
3e5d7649 8342 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 8343 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 8344
7e7c8926 8345 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 8346 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
8347
8348 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
8349 memcpy(&req.ht_capa_mask,
8350 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
8351 sizeof(req.ht_capa_mask));
7e7c8926
BG
8352
8353 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 8354 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 8355 return -EINVAL;
f62fab73
JB
8356 memcpy(&req.ht_capa,
8357 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
8358 sizeof(req.ht_capa));
7e7c8926
BG
8359 }
8360
ee2aca34 8361 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 8362 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
8363
8364 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
8365 memcpy(&req.vht_capa_mask,
8366 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
8367 sizeof(req.vht_capa_mask));
ee2aca34
JB
8368
8369 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 8370 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 8371 return -EINVAL;
f62fab73
JB
8372 memcpy(&req.vht_capa,
8373 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
8374 sizeof(req.vht_capa));
ee2aca34
JB
8375 }
8376
bab5ab7d 8377 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
8378 if (!((rdev->wiphy.features &
8379 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
8380 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
8381 !wiphy_ext_feature_isset(&rdev->wiphy,
8382 NL80211_EXT_FEATURE_RRM))
bab5ab7d
AK
8383 return -EINVAL;
8384 req.flags |= ASSOC_REQ_USE_RRM;
8385 }
8386
348bd456
JM
8387 if (info->attrs[NL80211_ATTR_FILS_KEK]) {
8388 req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]);
8389 req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]);
8390 if (!info->attrs[NL80211_ATTR_FILS_NONCES])
8391 return -EINVAL;
8392 req.fils_nonces =
8393 nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]);
8394 }
8395
f62fab73 8396 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
8397 if (!err) {
8398 wdev_lock(dev->ieee80211_ptr);
bd2522b1 8399
f62fab73
JB
8400 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
8401 ssid, ssid_len, &req);
bd2522b1
AZ
8402
8403 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
8404 dev->ieee80211_ptr->conn_owner_nlportid =
8405 info->snd_portid;
8406 memcpy(dev->ieee80211_ptr->disconnect_bssid,
8407 bssid, ETH_ALEN);
8408 }
8409
91bf9b26
JB
8410 wdev_unlock(dev->ieee80211_ptr);
8411 }
636a5d36 8412
636a5d36
JM
8413 return err;
8414}
8415
8416static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
8417{
4c476991
JB
8418 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8419 struct net_device *dev = info->user_ptr[1];
19957bb3 8420 const u8 *ie = NULL, *bssid;
91bf9b26 8421 int ie_len = 0, err;
19957bb3 8422 u16 reason_code;
d5cdfacb 8423 bool local_state_change;
636a5d36 8424
f4a11bb0
JB
8425 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8426 return -EINVAL;
8427
8428 if (!info->attrs[NL80211_ATTR_MAC])
8429 return -EINVAL;
8430
8431 if (!info->attrs[NL80211_ATTR_REASON_CODE])
8432 return -EINVAL;
8433
4c476991
JB
8434 if (!rdev->ops->deauth)
8435 return -EOPNOTSUPP;
636a5d36 8436
074ac8df 8437 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8438 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8439 return -EOPNOTSUPP;
eec60b03 8440
19957bb3 8441 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 8442
19957bb3
JB
8443 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
8444 if (reason_code == 0) {
f4a11bb0 8445 /* Reason Code 0 is reserved */
4c476991 8446 return -EINVAL;
255e737e 8447 }
636a5d36
JM
8448
8449 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
8450 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8451 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8452 }
8453
d5cdfacb
JM
8454 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
8455
91bf9b26
JB
8456 wdev_lock(dev->ieee80211_ptr);
8457 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
8458 local_state_change);
8459 wdev_unlock(dev->ieee80211_ptr);
8460 return err;
636a5d36
JM
8461}
8462
8463static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
8464{
4c476991
JB
8465 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8466 struct net_device *dev = info->user_ptr[1];
19957bb3 8467 const u8 *ie = NULL, *bssid;
91bf9b26 8468 int ie_len = 0, err;
19957bb3 8469 u16 reason_code;
d5cdfacb 8470 bool local_state_change;
636a5d36 8471
f4a11bb0
JB
8472 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8473 return -EINVAL;
8474
8475 if (!info->attrs[NL80211_ATTR_MAC])
8476 return -EINVAL;
8477
8478 if (!info->attrs[NL80211_ATTR_REASON_CODE])
8479 return -EINVAL;
8480
4c476991
JB
8481 if (!rdev->ops->disassoc)
8482 return -EOPNOTSUPP;
636a5d36 8483
074ac8df 8484 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8485 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8486 return -EOPNOTSUPP;
eec60b03 8487
19957bb3 8488 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 8489
19957bb3
JB
8490 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
8491 if (reason_code == 0) {
f4a11bb0 8492 /* Reason Code 0 is reserved */
4c476991 8493 return -EINVAL;
255e737e 8494 }
636a5d36
JM
8495
8496 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
8497 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8498 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8499 }
8500
d5cdfacb
JM
8501 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
8502
91bf9b26
JB
8503 wdev_lock(dev->ieee80211_ptr);
8504 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
8505 local_state_change);
8506 wdev_unlock(dev->ieee80211_ptr);
8507 return err;
636a5d36
JM
8508}
8509
dd5b4cc7
FF
8510static bool
8511nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
57fbcce3 8512 int mcast_rate[NUM_NL80211_BANDS],
dd5b4cc7
FF
8513 int rateval)
8514{
8515 struct wiphy *wiphy = &rdev->wiphy;
8516 bool found = false;
8517 int band, i;
8518
57fbcce3 8519 for (band = 0; band < NUM_NL80211_BANDS; band++) {
dd5b4cc7
FF
8520 struct ieee80211_supported_band *sband;
8521
8522 sband = wiphy->bands[band];
8523 if (!sband)
8524 continue;
8525
8526 for (i = 0; i < sband->n_bitrates; i++) {
8527 if (sband->bitrates[i].bitrate == rateval) {
8528 mcast_rate[band] = i + 1;
8529 found = true;
8530 break;
8531 }
8532 }
8533 }
8534
8535 return found;
8536}
8537
04a773ad
JB
8538static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
8539{
4c476991
JB
8540 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8541 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
8542 struct cfg80211_ibss_params ibss;
8543 struct wiphy *wiphy;
fffd0934 8544 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
8545 int err;
8546
8e30bc55
JB
8547 memset(&ibss, 0, sizeof(ibss));
8548
04a773ad
JB
8549 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8550 return -EINVAL;
8551
683b6d3b 8552 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
8553 !nla_len(info->attrs[NL80211_ATTR_SSID]))
8554 return -EINVAL;
8555
8e30bc55
JB
8556 ibss.beacon_interval = 100;
8557
12d20fc9 8558 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL])
8e30bc55
JB
8559 ibss.beacon_interval =
8560 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 8561
0c317a02
PK
8562 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC,
8563 ibss.beacon_interval);
12d20fc9
PK
8564 if (err)
8565 return err;
8e30bc55 8566
4c476991
JB
8567 if (!rdev->ops->join_ibss)
8568 return -EOPNOTSUPP;
04a773ad 8569
4c476991
JB
8570 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
8571 return -EOPNOTSUPP;
04a773ad 8572
79c97e97 8573 wiphy = &rdev->wiphy;
04a773ad 8574
39193498 8575 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 8576 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
8577
8578 if (!is_valid_ether_addr(ibss.bssid))
8579 return -EINVAL;
8580 }
04a773ad
JB
8581 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
8582 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
8583
8584 if (info->attrs[NL80211_ATTR_IE]) {
8585 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8586 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
8587 }
8588
683b6d3b
JB
8589 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
8590 if (err)
8591 return err;
04a773ad 8592
174e0cd2
IP
8593 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef,
8594 NL80211_IFTYPE_ADHOC))
54858ee5
AS
8595 return -EINVAL;
8596
2f301ab2 8597 switch (ibss.chandef.width) {
bf372645
SW
8598 case NL80211_CHAN_WIDTH_5:
8599 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
8600 case NL80211_CHAN_WIDTH_20_NOHT:
8601 break;
8602 case NL80211_CHAN_WIDTH_20:
8603 case NL80211_CHAN_WIDTH_40:
ffc11991
JD
8604 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
8605 return -EINVAL;
8606 break;
8607 case NL80211_CHAN_WIDTH_80:
8608 case NL80211_CHAN_WIDTH_80P80:
8609 case NL80211_CHAN_WIDTH_160:
8610 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
8611 return -EINVAL;
8612 if (!wiphy_ext_feature_isset(&rdev->wiphy,
8613 NL80211_EXT_FEATURE_VHT_IBSS))
8614 return -EINVAL;
8615 break;
2f301ab2 8616 default:
c04d6150 8617 return -EINVAL;
2f301ab2 8618 }
db9c64cf 8619
04a773ad 8620 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
8621 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
8622
fbd2c8dc
TP
8623 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
8624 u8 *rates =
8625 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8626 int n_rates =
8627 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
8628 struct ieee80211_supported_band *sband =
683b6d3b 8629 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 8630
34850ab2
JB
8631 err = ieee80211_get_ratemask(sband, rates, n_rates,
8632 &ibss.basic_rates);
8633 if (err)
8634 return err;
fbd2c8dc 8635 }
dd5b4cc7 8636
803768f5
SW
8637 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
8638 memcpy(&ibss.ht_capa_mask,
8639 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
8640 sizeof(ibss.ht_capa_mask));
8641
8642 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
8643 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
8644 return -EINVAL;
8645 memcpy(&ibss.ht_capa,
8646 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
8647 sizeof(ibss.ht_capa));
8648 }
8649
dd5b4cc7
FF
8650 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
8651 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
8652 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
8653 return -EINVAL;
fbd2c8dc 8654
4c476991 8655 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
8656 bool no_ht = false;
8657
768075eb 8658 connkeys = nl80211_parse_connkeys(rdev, info, &no_ht);
4c476991
JB
8659 if (IS_ERR(connkeys))
8660 return PTR_ERR(connkeys);
de7044ee 8661
3d9d1d66
JB
8662 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
8663 no_ht) {
5e950a78 8664 kzfree(connkeys);
de7044ee
SM
8665 return -EINVAL;
8666 }
4c476991 8667 }
04a773ad 8668
267335d6
AQ
8669 ibss.control_port =
8670 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
8671
5336fa88
SW
8672 ibss.userspace_handles_dfs =
8673 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
8674
4c476991 8675 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934 8676 if (err)
b47f610b 8677 kzfree(connkeys);
04a773ad
JB
8678 return err;
8679}
8680
8681static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
8682{
4c476991
JB
8683 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8684 struct net_device *dev = info->user_ptr[1];
04a773ad 8685
4c476991
JB
8686 if (!rdev->ops->leave_ibss)
8687 return -EOPNOTSUPP;
04a773ad 8688
4c476991
JB
8689 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
8690 return -EOPNOTSUPP;
04a773ad 8691
4c476991 8692 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
8693}
8694
f4e583c8
AQ
8695static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
8696{
8697 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8698 struct net_device *dev = info->user_ptr[1];
57fbcce3 8699 int mcast_rate[NUM_NL80211_BANDS];
f4e583c8
AQ
8700 u32 nla_rate;
8701 int err;
8702
8703 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
876dc930
BVB
8704 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
8705 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB)
f4e583c8
AQ
8706 return -EOPNOTSUPP;
8707
8708 if (!rdev->ops->set_mcast_rate)
8709 return -EOPNOTSUPP;
8710
8711 memset(mcast_rate, 0, sizeof(mcast_rate));
8712
8713 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
8714 return -EINVAL;
8715
8716 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
8717 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
8718 return -EINVAL;
8719
a1056b1b 8720 err = rdev_set_mcast_rate(rdev, dev, mcast_rate);
f4e583c8
AQ
8721
8722 return err;
8723}
8724
ad7e718c
JB
8725static struct sk_buff *
8726__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
6c09e791
AK
8727 struct wireless_dev *wdev, int approxlen,
8728 u32 portid, u32 seq, enum nl80211_commands cmd,
567ffc35
JB
8729 enum nl80211_attrs attr,
8730 const struct nl80211_vendor_cmd_info *info,
8731 gfp_t gfp)
ad7e718c
JB
8732{
8733 struct sk_buff *skb;
8734 void *hdr;
8735 struct nlattr *data;
8736
8737 skb = nlmsg_new(approxlen + 100, gfp);
8738 if (!skb)
8739 return NULL;
8740
8741 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
8742 if (!hdr) {
8743 kfree_skb(skb);
8744 return NULL;
8745 }
8746
8747 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
8748 goto nla_put_failure;
567ffc35
JB
8749
8750 if (info) {
8751 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
8752 info->vendor_id))
8753 goto nla_put_failure;
8754 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
8755 info->subcmd))
8756 goto nla_put_failure;
8757 }
8758
6c09e791 8759 if (wdev) {
2dad624e
ND
8760 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
8761 wdev_id(wdev), NL80211_ATTR_PAD))
6c09e791
AK
8762 goto nla_put_failure;
8763 if (wdev->netdev &&
8764 nla_put_u32(skb, NL80211_ATTR_IFINDEX,
8765 wdev->netdev->ifindex))
8766 goto nla_put_failure;
8767 }
8768
ad7e718c 8769 data = nla_nest_start(skb, attr);
76e1fb4b
JB
8770 if (!data)
8771 goto nla_put_failure;
ad7e718c
JB
8772
8773 ((void **)skb->cb)[0] = rdev;
8774 ((void **)skb->cb)[1] = hdr;
8775 ((void **)skb->cb)[2] = data;
8776
8777 return skb;
8778
8779 nla_put_failure:
8780 kfree_skb(skb);
8781 return NULL;
8782}
f4e583c8 8783
e03ad6ea 8784struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
6c09e791 8785 struct wireless_dev *wdev,
e03ad6ea
JB
8786 enum nl80211_commands cmd,
8787 enum nl80211_attrs attr,
8788 int vendor_event_idx,
8789 int approxlen, gfp_t gfp)
8790{
f26cbf40 8791 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
e03ad6ea
JB
8792 const struct nl80211_vendor_cmd_info *info;
8793
8794 switch (cmd) {
8795 case NL80211_CMD_TESTMODE:
8796 if (WARN_ON(vendor_event_idx != -1))
8797 return NULL;
8798 info = NULL;
8799 break;
8800 case NL80211_CMD_VENDOR:
8801 if (WARN_ON(vendor_event_idx < 0 ||
8802 vendor_event_idx >= wiphy->n_vendor_events))
8803 return NULL;
8804 info = &wiphy->vendor_events[vendor_event_idx];
8805 break;
8806 default:
8807 WARN_ON(1);
8808 return NULL;
8809 }
8810
6c09e791 8811 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, 0, 0,
e03ad6ea
JB
8812 cmd, attr, info, gfp);
8813}
8814EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
8815
8816void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
8817{
8818 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
8819 void *hdr = ((void **)skb->cb)[1];
8820 struct nlattr *data = ((void **)skb->cb)[2];
8821 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
8822
bd8c78e7
JB
8823 /* clear CB data for netlink core to own from now on */
8824 memset(skb->cb, 0, sizeof(skb->cb));
8825
e03ad6ea
JB
8826 nla_nest_end(skb, data);
8827 genlmsg_end(skb, hdr);
8828
8829 if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
8830 mcgrp = NL80211_MCGRP_VENDOR;
8831
8832 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0,
8833 mcgrp, gfp);
8834}
8835EXPORT_SYMBOL(__cfg80211_send_event_skb);
8836
aff89a9b 8837#ifdef CONFIG_NL80211_TESTMODE
aff89a9b
JB
8838static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
8839{
4c476991 8840 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
8841 struct wireless_dev *wdev =
8842 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
8843 int err;
8844
fc73f11f
DS
8845 if (!rdev->ops->testmode_cmd)
8846 return -EOPNOTSUPP;
8847
8848 if (IS_ERR(wdev)) {
8849 err = PTR_ERR(wdev);
8850 if (err != -EINVAL)
8851 return err;
8852 wdev = NULL;
8853 } else if (wdev->wiphy != &rdev->wiphy) {
8854 return -EINVAL;
8855 }
8856
aff89a9b
JB
8857 if (!info->attrs[NL80211_ATTR_TESTDATA])
8858 return -EINVAL;
8859
ad7e718c 8860 rdev->cur_cmd_info = info;
fc73f11f 8861 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
8862 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
8863 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
ad7e718c 8864 rdev->cur_cmd_info = NULL;
aff89a9b 8865
aff89a9b
JB
8866 return err;
8867}
8868
71063f0e
WYG
8869static int nl80211_testmode_dump(struct sk_buff *skb,
8870 struct netlink_callback *cb)
8871{
00918d33 8872 struct cfg80211_registered_device *rdev;
71063f0e
WYG
8873 int err;
8874 long phy_idx;
8875 void *data = NULL;
8876 int data_len = 0;
8877
5fe231e8
JB
8878 rtnl_lock();
8879
71063f0e
WYG
8880 if (cb->args[0]) {
8881 /*
8882 * 0 is a valid index, but not valid for args[0],
8883 * so we need to offset by 1.
8884 */
8885 phy_idx = cb->args[0] - 1;
a4956dca
LC
8886
8887 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
8888 if (!rdev) {
8889 err = -ENOENT;
8890 goto out_err;
8891 }
71063f0e 8892 } else {
c90c39da
JB
8893 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam);
8894
71063f0e 8895 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
fceb6435
JB
8896 attrbuf, nl80211_fam.maxattr,
8897 nl80211_policy, NULL);
71063f0e 8898 if (err)
5fe231e8 8899 goto out_err;
00918d33 8900
c90c39da 8901 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
2bd7e35d 8902 if (IS_ERR(rdev)) {
5fe231e8
JB
8903 err = PTR_ERR(rdev);
8904 goto out_err;
00918d33 8905 }
2bd7e35d 8906 phy_idx = rdev->wiphy_idx;
2bd7e35d 8907
c90c39da
JB
8908 if (attrbuf[NL80211_ATTR_TESTDATA])
8909 cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA];
71063f0e
WYG
8910 }
8911
8912 if (cb->args[1]) {
8913 data = nla_data((void *)cb->args[1]);
8914 data_len = nla_len((void *)cb->args[1]);
8915 }
8916
00918d33 8917 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
8918 err = -EOPNOTSUPP;
8919 goto out_err;
8920 }
8921
8922 while (1) {
15e47304 8923 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
8924 cb->nlh->nlmsg_seq, NLM_F_MULTI,
8925 NL80211_CMD_TESTMODE);
8926 struct nlattr *tmdata;
8927
cb35fba3
DC
8928 if (!hdr)
8929 break;
8930
9360ffd1 8931 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
8932 genlmsg_cancel(skb, hdr);
8933 break;
8934 }
8935
8936 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
8937 if (!tmdata) {
8938 genlmsg_cancel(skb, hdr);
8939 break;
8940 }
e35e4d28 8941 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
8942 nla_nest_end(skb, tmdata);
8943
8944 if (err == -ENOBUFS || err == -ENOENT) {
8945 genlmsg_cancel(skb, hdr);
8946 break;
8947 } else if (err) {
8948 genlmsg_cancel(skb, hdr);
8949 goto out_err;
8950 }
8951
8952 genlmsg_end(skb, hdr);
8953 }
8954
8955 err = skb->len;
8956 /* see above */
8957 cb->args[0] = phy_idx + 1;
8958 out_err:
5fe231e8 8959 rtnl_unlock();
71063f0e
WYG
8960 return err;
8961}
aff89a9b
JB
8962#endif
8963
b23aa676
SO
8964static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
8965{
4c476991
JB
8966 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8967 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
8968 struct cfg80211_connect_params connect;
8969 struct wiphy *wiphy;
fffd0934 8970 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
8971 int err;
8972
8973 memset(&connect, 0, sizeof(connect));
8974
8975 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
8976 return -EINVAL;
8977
8978 if (!info->attrs[NL80211_ATTR_SSID] ||
8979 !nla_len(info->attrs[NL80211_ATTR_SSID]))
8980 return -EINVAL;
8981
8982 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
8983 connect.auth_type =
8984 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
8985 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
8986 NL80211_CMD_CONNECT))
b23aa676
SO
8987 return -EINVAL;
8988 } else
8989 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
8990
8991 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
8992
3a00df57
AS
8993 if (info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS] &&
8994 !wiphy_ext_feature_isset(&rdev->wiphy,
8995 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
8996 return -EINVAL;
8997 connect.want_1x = info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS];
8998
c0692b8f 8999 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 9000 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
9001 if (err)
9002 return err;
b23aa676 9003
074ac8df 9004 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9005 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9006 return -EOPNOTSUPP;
b23aa676 9007
79c97e97 9008 wiphy = &rdev->wiphy;
b23aa676 9009
4486ea98
BS
9010 connect.bg_scan_period = -1;
9011 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
9012 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
9013 connect.bg_scan_period =
9014 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
9015 }
9016
b23aa676
SO
9017 if (info->attrs[NL80211_ATTR_MAC])
9018 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1df4a510
JM
9019 else if (info->attrs[NL80211_ATTR_MAC_HINT])
9020 connect.bssid_hint =
9021 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
b23aa676
SO
9022 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9023 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
9024
9025 if (info->attrs[NL80211_ATTR_IE]) {
9026 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9027 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9028 }
9029
cee00a95
JM
9030 if (info->attrs[NL80211_ATTR_USE_MFP]) {
9031 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
65026002
EG
9032 if (connect.mfp == NL80211_MFP_OPTIONAL &&
9033 !wiphy_ext_feature_isset(&rdev->wiphy,
9034 NL80211_EXT_FEATURE_MFP_OPTIONAL))
9035 return -EOPNOTSUPP;
9036
cee00a95 9037 if (connect.mfp != NL80211_MFP_REQUIRED &&
65026002
EG
9038 connect.mfp != NL80211_MFP_NO &&
9039 connect.mfp != NL80211_MFP_OPTIONAL)
cee00a95
JM
9040 return -EINVAL;
9041 } else {
9042 connect.mfp = NL80211_MFP_NO;
9043 }
9044
ba6fbacf
JM
9045 if (info->attrs[NL80211_ATTR_PREV_BSSID])
9046 connect.prev_bssid =
9047 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
9048
b23aa676 9049 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
664834de
JM
9050 connect.channel = nl80211_get_valid_chan(
9051 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]);
9052 if (!connect.channel)
1df4a510
JM
9053 return -EINVAL;
9054 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
664834de
JM
9055 connect.channel_hint = nl80211_get_valid_chan(
9056 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
9057 if (!connect.channel_hint)
4c476991 9058 return -EINVAL;
b23aa676
SO
9059 }
9060
fffd0934 9061 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
768075eb 9062 connkeys = nl80211_parse_connkeys(rdev, info, NULL);
4c476991
JB
9063 if (IS_ERR(connkeys))
9064 return PTR_ERR(connkeys);
fffd0934
JB
9065 }
9066
7e7c8926
BG
9067 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
9068 connect.flags |= ASSOC_REQ_DISABLE_HT;
9069
9070 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
9071 memcpy(&connect.ht_capa_mask,
9072 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
9073 sizeof(connect.ht_capa_mask));
9074
9075 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e 9076 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
b47f610b 9077 kzfree(connkeys);
7e7c8926 9078 return -EINVAL;
b4e4f47e 9079 }
7e7c8926
BG
9080 memcpy(&connect.ht_capa,
9081 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
9082 sizeof(connect.ht_capa));
9083 }
9084
ee2aca34
JB
9085 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
9086 connect.flags |= ASSOC_REQ_DISABLE_VHT;
9087
9088 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
9089 memcpy(&connect.vht_capa_mask,
9090 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
9091 sizeof(connect.vht_capa_mask));
9092
9093 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
9094 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
b47f610b 9095 kzfree(connkeys);
ee2aca34
JB
9096 return -EINVAL;
9097 }
9098 memcpy(&connect.vht_capa,
9099 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
9100 sizeof(connect.vht_capa));
9101 }
9102
bab5ab7d 9103 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
9104 if (!((rdev->wiphy.features &
9105 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
9106 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
9107 !wiphy_ext_feature_isset(&rdev->wiphy,
9108 NL80211_EXT_FEATURE_RRM)) {
707554b4 9109 kzfree(connkeys);
bab5ab7d 9110 return -EINVAL;
707554b4 9111 }
bab5ab7d
AK
9112 connect.flags |= ASSOC_REQ_USE_RRM;
9113 }
9114
34d50519 9115 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
57fbcce3 9116 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) {
34d50519
LD
9117 kzfree(connkeys);
9118 return -EOPNOTSUPP;
9119 }
9120
38de03d2
AS
9121 if (info->attrs[NL80211_ATTR_BSS_SELECT]) {
9122 /* bss selection makes no sense if bssid is set */
9123 if (connect.bssid) {
9124 kzfree(connkeys);
9125 return -EINVAL;
9126 }
9127
9128 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT],
9129 wiphy, &connect.bss_select);
9130 if (err) {
9131 kzfree(connkeys);
9132 return err;
9133 }
9134 }
9135
a3caf744
VK
9136 if (wiphy_ext_feature_isset(&rdev->wiphy,
9137 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
9138 info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
9139 info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
9140 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
9141 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
9142 connect.fils_erp_username =
9143 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
9144 connect.fils_erp_username_len =
9145 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
9146 connect.fils_erp_realm =
9147 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
9148 connect.fils_erp_realm_len =
9149 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
9150 connect.fils_erp_next_seq_num =
9151 nla_get_u16(
9152 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
9153 connect.fils_erp_rrk =
9154 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
9155 connect.fils_erp_rrk_len =
9156 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
9157 } else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
9158 info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
9159 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
9160 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
9161 kzfree(connkeys);
9162 return -EINVAL;
9163 }
9164
40cbfa90
SD
9165 if (nla_get_flag(info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])) {
9166 if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
9167 GENL_SET_ERR_MSG(info,
9168 "external auth requires connection ownership");
9169 return -EINVAL;
9170 }
9171 connect.flags |= CONNECT_REQ_EXTERNAL_AUTH_SUPPORT;
9172 }
9173
83739b03 9174 wdev_lock(dev->ieee80211_ptr);
bd2522b1 9175
4ce2bd9c
JM
9176 err = cfg80211_connect(rdev, dev, &connect, connkeys,
9177 connect.prev_bssid);
fffd0934 9178 if (err)
b47f610b 9179 kzfree(connkeys);
bd2522b1
AZ
9180
9181 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
9182 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
9183 if (connect.bssid)
9184 memcpy(dev->ieee80211_ptr->disconnect_bssid,
9185 connect.bssid, ETH_ALEN);
9186 else
9187 memset(dev->ieee80211_ptr->disconnect_bssid,
9188 0, ETH_ALEN);
9189 }
9190
9191 wdev_unlock(dev->ieee80211_ptr);
9192
b23aa676
SO
9193 return err;
9194}
9195
088e8df8 9196static int nl80211_update_connect_params(struct sk_buff *skb,
9197 struct genl_info *info)
9198{
9199 struct cfg80211_connect_params connect = {};
9200 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9201 struct net_device *dev = info->user_ptr[1];
9202 struct wireless_dev *wdev = dev->ieee80211_ptr;
9203 u32 changed = 0;
9204 int ret;
9205
9206 if (!rdev->ops->update_connect_params)
9207 return -EOPNOTSUPP;
9208
9209 if (info->attrs[NL80211_ATTR_IE]) {
9210 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
9211 return -EINVAL;
9212 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9213 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9214 changed |= UPDATE_ASSOC_IES;
9215 }
9216
9217 wdev_lock(dev->ieee80211_ptr);
9218 if (!wdev->current_bss)
9219 ret = -ENOLINK;
9220 else
9221 ret = rdev_update_connect_params(rdev, dev, &connect, changed);
9222 wdev_unlock(dev->ieee80211_ptr);
9223
9224 return ret;
9225}
9226
b23aa676
SO
9227static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
9228{
4c476991
JB
9229 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9230 struct net_device *dev = info->user_ptr[1];
b23aa676 9231 u16 reason;
83739b03 9232 int ret;
b23aa676
SO
9233
9234 if (!info->attrs[NL80211_ATTR_REASON_CODE])
9235 reason = WLAN_REASON_DEAUTH_LEAVING;
9236 else
9237 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
9238
9239 if (reason == 0)
9240 return -EINVAL;
9241
074ac8df 9242 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9243 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9244 return -EOPNOTSUPP;
b23aa676 9245
83739b03
JB
9246 wdev_lock(dev->ieee80211_ptr);
9247 ret = cfg80211_disconnect(rdev, dev, reason, true);
9248 wdev_unlock(dev->ieee80211_ptr);
9249 return ret;
b23aa676
SO
9250}
9251
463d0183
JB
9252static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
9253{
4c476991 9254 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
9255 struct net *net;
9256 int err;
463d0183 9257
4b681c82
VK
9258 if (info->attrs[NL80211_ATTR_PID]) {
9259 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
9260
9261 net = get_net_ns_by_pid(pid);
9262 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) {
9263 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]);
463d0183 9264
4b681c82
VK
9265 net = get_net_ns_by_fd(fd);
9266 } else {
9267 return -EINVAL;
9268 }
463d0183 9269
4c476991
JB
9270 if (IS_ERR(net))
9271 return PTR_ERR(net);
463d0183
JB
9272
9273 err = 0;
9274
9275 /* check if anything to do */
4c476991
JB
9276 if (!net_eq(wiphy_net(&rdev->wiphy), net))
9277 err = cfg80211_switch_netns(rdev, net);
463d0183 9278
463d0183 9279 put_net(net);
463d0183
JB
9280 return err;
9281}
9282
67fbb16b
SO
9283static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
9284{
4c476991 9285 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
9286 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
9287 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 9288 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
9289 struct cfg80211_pmksa pmksa;
9290
9291 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
9292
67fbb16b
SO
9293 if (!info->attrs[NL80211_ATTR_PMKID])
9294 return -EINVAL;
9295
67fbb16b 9296 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
a3caf744
VK
9297
9298 if (info->attrs[NL80211_ATTR_MAC]) {
9299 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
9300 } else if (info->attrs[NL80211_ATTR_SSID] &&
9301 info->attrs[NL80211_ATTR_FILS_CACHE_ID] &&
9302 (info->genlhdr->cmd == NL80211_CMD_DEL_PMKSA ||
9303 info->attrs[NL80211_ATTR_PMK])) {
9304 pmksa.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9305 pmksa.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
9306 pmksa.cache_id =
9307 nla_data(info->attrs[NL80211_ATTR_FILS_CACHE_ID]);
9308 } else {
9309 return -EINVAL;
9310 }
9311 if (info->attrs[NL80211_ATTR_PMK]) {
9312 pmksa.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
9313 pmksa.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
9314 }
67fbb16b 9315
074ac8df 9316 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9317 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9318 return -EOPNOTSUPP;
67fbb16b
SO
9319
9320 switch (info->genlhdr->cmd) {
9321 case NL80211_CMD_SET_PMKSA:
9322 rdev_ops = rdev->ops->set_pmksa;
9323 break;
9324 case NL80211_CMD_DEL_PMKSA:
9325 rdev_ops = rdev->ops->del_pmksa;
9326 break;
9327 default:
9328 WARN_ON(1);
9329 break;
9330 }
9331
4c476991
JB
9332 if (!rdev_ops)
9333 return -EOPNOTSUPP;
67fbb16b 9334
4c476991 9335 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
9336}
9337
9338static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
9339{
4c476991
JB
9340 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9341 struct net_device *dev = info->user_ptr[1];
67fbb16b 9342
074ac8df 9343 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9344 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9345 return -EOPNOTSUPP;
67fbb16b 9346
4c476991
JB
9347 if (!rdev->ops->flush_pmksa)
9348 return -EOPNOTSUPP;
67fbb16b 9349
e35e4d28 9350 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
9351}
9352
109086ce
AN
9353static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
9354{
9355 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9356 struct net_device *dev = info->user_ptr[1];
9357 u8 action_code, dialog_token;
df942e7b 9358 u32 peer_capability = 0;
109086ce
AN
9359 u16 status_code;
9360 u8 *peer;
31fa97c5 9361 bool initiator;
109086ce
AN
9362
9363 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
9364 !rdev->ops->tdls_mgmt)
9365 return -EOPNOTSUPP;
9366
9367 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
9368 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
9369 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
9370 !info->attrs[NL80211_ATTR_IE] ||
9371 !info->attrs[NL80211_ATTR_MAC])
9372 return -EINVAL;
9373
9374 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
9375 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
9376 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
9377 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
31fa97c5 9378 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]);
df942e7b
SDU
9379 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
9380 peer_capability =
9381 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
109086ce 9382
e35e4d28 9383 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
df942e7b 9384 dialog_token, status_code, peer_capability,
31fa97c5 9385 initiator,
e35e4d28
HG
9386 nla_data(info->attrs[NL80211_ATTR_IE]),
9387 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
9388}
9389
9390static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
9391{
9392 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9393 struct net_device *dev = info->user_ptr[1];
9394 enum nl80211_tdls_operation operation;
9395 u8 *peer;
9396
9397 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
9398 !rdev->ops->tdls_oper)
9399 return -EOPNOTSUPP;
9400
9401 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
9402 !info->attrs[NL80211_ATTR_MAC])
9403 return -EINVAL;
9404
9405 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
9406 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
9407
e35e4d28 9408 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
9409}
9410
9588bbd5
JM
9411static int nl80211_remain_on_channel(struct sk_buff *skb,
9412 struct genl_info *info)
9413{
4c476991 9414 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9415 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 9416 struct cfg80211_chan_def chandef;
34373d12 9417 const struct cfg80211_chan_def *compat_chandef;
9588bbd5
JM
9418 struct sk_buff *msg;
9419 void *hdr;
9420 u64 cookie;
683b6d3b 9421 u32 duration;
9588bbd5
JM
9422 int err;
9423
9424 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
9425 !info->attrs[NL80211_ATTR_DURATION])
9426 return -EINVAL;
9427
9428 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
9429
ebf348fc
JB
9430 if (!rdev->ops->remain_on_channel ||
9431 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
9432 return -EOPNOTSUPP;
9433
9588bbd5 9434 /*
ebf348fc
JB
9435 * We should be on that channel for at least a minimum amount of
9436 * time (10ms) but no longer than the driver supports.
9588bbd5 9437 */
ebf348fc 9438 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 9439 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
9440 return -EINVAL;
9441
683b6d3b
JB
9442 err = nl80211_parse_chandef(rdev, info, &chandef);
9443 if (err)
9444 return err;
9588bbd5 9445
34373d12
VT
9446 wdev_lock(wdev);
9447 if (!cfg80211_off_channel_oper_allowed(wdev) &&
9448 !cfg80211_chandef_identical(&wdev->chandef, &chandef)) {
9449 compat_chandef = cfg80211_chandef_compatible(&wdev->chandef,
9450 &chandef);
9451 if (compat_chandef != &chandef) {
9452 wdev_unlock(wdev);
9453 return -EBUSY;
9454 }
9455 }
9456 wdev_unlock(wdev);
9457
9588bbd5 9458 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
9459 if (!msg)
9460 return -ENOMEM;
9588bbd5 9461
15e47304 9462 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 9463 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
9464 if (!hdr) {
9465 err = -ENOBUFS;
9588bbd5
JM
9466 goto free_msg;
9467 }
9468
683b6d3b
JB
9469 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
9470 duration, &cookie);
9588bbd5
JM
9471
9472 if (err)
9473 goto free_msg;
9474
2dad624e
ND
9475 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
9476 NL80211_ATTR_PAD))
9360ffd1 9477 goto nla_put_failure;
9588bbd5
JM
9478
9479 genlmsg_end(msg, hdr);
4c476991
JB
9480
9481 return genlmsg_reply(msg, info);
9588bbd5
JM
9482
9483 nla_put_failure:
9484 err = -ENOBUFS;
9485 free_msg:
9486 nlmsg_free(msg);
9588bbd5
JM
9487 return err;
9488}
9489
9490static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
9491 struct genl_info *info)
9492{
4c476991 9493 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9494 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 9495 u64 cookie;
9588bbd5
JM
9496
9497 if (!info->attrs[NL80211_ATTR_COOKIE])
9498 return -EINVAL;
9499
4c476991
JB
9500 if (!rdev->ops->cancel_remain_on_channel)
9501 return -EOPNOTSUPP;
9588bbd5 9502
9588bbd5
JM
9503 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
9504
e35e4d28 9505 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
9506}
9507
13ae75b1
JM
9508static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
9509 struct genl_info *info)
9510{
13ae75b1 9511 struct cfg80211_bitrate_mask mask;
a7c7fbff 9512 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 9513 struct net_device *dev = info->user_ptr[1];
a7c7fbff 9514 int err;
13ae75b1 9515
4c476991
JB
9516 if (!rdev->ops->set_bitrate_mask)
9517 return -EOPNOTSUPP;
13ae75b1 9518
a7c7fbff
PK
9519 err = nl80211_parse_tx_bitrate_mask(info, &mask);
9520 if (err)
9521 return err;
13ae75b1 9522
e35e4d28 9523 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
9524}
9525
2e161f78 9526static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 9527{
4c476991 9528 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9529 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 9530 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
9531
9532 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
9533 return -EINVAL;
9534
2e161f78
JB
9535 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
9536 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 9537
71bbc994
JB
9538 switch (wdev->iftype) {
9539 case NL80211_IFTYPE_STATION:
9540 case NL80211_IFTYPE_ADHOC:
9541 case NL80211_IFTYPE_P2P_CLIENT:
9542 case NL80211_IFTYPE_AP:
9543 case NL80211_IFTYPE_AP_VLAN:
9544 case NL80211_IFTYPE_MESH_POINT:
9545 case NL80211_IFTYPE_P2P_GO:
98104fde 9546 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 9547 break;
cb3b7d87 9548 case NL80211_IFTYPE_NAN:
71bbc994 9549 default:
4c476991 9550 return -EOPNOTSUPP;
71bbc994 9551 }
026331c4
JM
9552
9553 /* not much point in registering if we can't reply */
4c476991
JB
9554 if (!rdev->ops->mgmt_tx)
9555 return -EOPNOTSUPP;
026331c4 9556
15e47304 9557 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
9558 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
9559 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
9560}
9561
2e161f78 9562static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 9563{
4c476991 9564 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9565 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 9566 struct cfg80211_chan_def chandef;
026331c4 9567 int err;
d64d373f 9568 void *hdr = NULL;
026331c4 9569 u64 cookie;
e247bd90 9570 struct sk_buff *msg = NULL;
b176e629
AO
9571 struct cfg80211_mgmt_tx_params params = {
9572 .dont_wait_for_ack =
9573 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
9574 };
026331c4 9575
683b6d3b 9576 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
9577 return -EINVAL;
9578
4c476991
JB
9579 if (!rdev->ops->mgmt_tx)
9580 return -EOPNOTSUPP;
026331c4 9581
71bbc994 9582 switch (wdev->iftype) {
ea141b75
AQ
9583 case NL80211_IFTYPE_P2P_DEVICE:
9584 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
9585 return -EINVAL;
71bbc994
JB
9586 case NL80211_IFTYPE_STATION:
9587 case NL80211_IFTYPE_ADHOC:
9588 case NL80211_IFTYPE_P2P_CLIENT:
9589 case NL80211_IFTYPE_AP:
9590 case NL80211_IFTYPE_AP_VLAN:
9591 case NL80211_IFTYPE_MESH_POINT:
9592 case NL80211_IFTYPE_P2P_GO:
9593 break;
cb3b7d87 9594 case NL80211_IFTYPE_NAN:
71bbc994 9595 default:
4c476991 9596 return -EOPNOTSUPP;
71bbc994 9597 }
026331c4 9598
f7ca38df 9599 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 9600 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df 9601 return -EINVAL;
b176e629 9602 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
9603
9604 /*
9605 * We should wait on the channel for at least a minimum amount
9606 * of time (10ms) but no longer than the driver supports.
9607 */
b176e629
AO
9608 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
9609 params.wait > rdev->wiphy.max_remain_on_channel_duration)
ebf348fc 9610 return -EINVAL;
f7ca38df
JB
9611 }
9612
b176e629 9613 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
f7ca38df 9614
b176e629 9615 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7c4ef712
JB
9616 return -EINVAL;
9617
b176e629 9618 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
e9f935e3 9619
ea141b75
AQ
9620 /* get the channel if any has been specified, otherwise pass NULL to
9621 * the driver. The latter will use the current one
9622 */
9623 chandef.chan = NULL;
9624 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
9625 err = nl80211_parse_chandef(rdev, info, &chandef);
9626 if (err)
9627 return err;
9628 }
9629
b176e629 9630 if (!chandef.chan && params.offchan)
ea141b75 9631 return -EINVAL;
026331c4 9632
34373d12
VT
9633 wdev_lock(wdev);
9634 if (params.offchan && !cfg80211_off_channel_oper_allowed(wdev)) {
9635 wdev_unlock(wdev);
9636 return -EBUSY;
9637 }
9638 wdev_unlock(wdev);
9639
34d22ce2
AO
9640 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
9641 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
9642
9643 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) {
9644 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
9645 int i;
9646
9647 if (len % sizeof(u16))
9648 return -EINVAL;
9649
9650 params.n_csa_offsets = len / sizeof(u16);
9651 params.csa_offsets =
9652 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
9653
9654 /* check that all the offsets fit the frame */
9655 for (i = 0; i < params.n_csa_offsets; i++) {
9656 if (params.csa_offsets[i] >= params.len)
9657 return -EINVAL;
9658 }
9659 }
9660
b176e629 9661 if (!params.dont_wait_for_ack) {
e247bd90
JB
9662 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
9663 if (!msg)
9664 return -ENOMEM;
026331c4 9665
15e47304 9666 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 9667 NL80211_CMD_FRAME);
cb35fba3
DC
9668 if (!hdr) {
9669 err = -ENOBUFS;
e247bd90
JB
9670 goto free_msg;
9671 }
026331c4 9672 }
e247bd90 9673
b176e629
AO
9674 params.chan = chandef.chan;
9675 err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
026331c4
JM
9676 if (err)
9677 goto free_msg;
9678
e247bd90 9679 if (msg) {
2dad624e
ND
9680 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
9681 NL80211_ATTR_PAD))
9360ffd1 9682 goto nla_put_failure;
026331c4 9683
e247bd90
JB
9684 genlmsg_end(msg, hdr);
9685 return genlmsg_reply(msg, info);
9686 }
9687
9688 return 0;
026331c4
JM
9689
9690 nla_put_failure:
9691 err = -ENOBUFS;
9692 free_msg:
9693 nlmsg_free(msg);
026331c4
JM
9694 return err;
9695}
9696
f7ca38df
JB
9697static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
9698{
9699 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 9700 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
9701 u64 cookie;
9702
9703 if (!info->attrs[NL80211_ATTR_COOKIE])
9704 return -EINVAL;
9705
9706 if (!rdev->ops->mgmt_tx_cancel_wait)
9707 return -EOPNOTSUPP;
9708
71bbc994
JB
9709 switch (wdev->iftype) {
9710 case NL80211_IFTYPE_STATION:
9711 case NL80211_IFTYPE_ADHOC:
9712 case NL80211_IFTYPE_P2P_CLIENT:
9713 case NL80211_IFTYPE_AP:
9714 case NL80211_IFTYPE_AP_VLAN:
9715 case NL80211_IFTYPE_P2P_GO:
98104fde 9716 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 9717 break;
cb3b7d87 9718 case NL80211_IFTYPE_NAN:
71bbc994 9719 default:
f7ca38df 9720 return -EOPNOTSUPP;
71bbc994 9721 }
f7ca38df
JB
9722
9723 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
9724
e35e4d28 9725 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
9726}
9727
ffb9eb3d
KV
9728static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
9729{
4c476991 9730 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 9731 struct wireless_dev *wdev;
4c476991 9732 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
9733 u8 ps_state;
9734 bool state;
9735 int err;
9736
4c476991
JB
9737 if (!info->attrs[NL80211_ATTR_PS_STATE])
9738 return -EINVAL;
ffb9eb3d
KV
9739
9740 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
9741
4c476991
JB
9742 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
9743 return -EINVAL;
ffb9eb3d
KV
9744
9745 wdev = dev->ieee80211_ptr;
9746
4c476991
JB
9747 if (!rdev->ops->set_power_mgmt)
9748 return -EOPNOTSUPP;
ffb9eb3d
KV
9749
9750 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
9751
9752 if (state == wdev->ps)
4c476991 9753 return 0;
ffb9eb3d 9754
e35e4d28 9755 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
9756 if (!err)
9757 wdev->ps = state;
ffb9eb3d
KV
9758 return err;
9759}
9760
9761static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
9762{
4c476991 9763 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
9764 enum nl80211_ps_state ps_state;
9765 struct wireless_dev *wdev;
4c476991 9766 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
9767 struct sk_buff *msg;
9768 void *hdr;
9769 int err;
9770
ffb9eb3d
KV
9771 wdev = dev->ieee80211_ptr;
9772
4c476991
JB
9773 if (!rdev->ops->set_power_mgmt)
9774 return -EOPNOTSUPP;
ffb9eb3d
KV
9775
9776 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
9777 if (!msg)
9778 return -ENOMEM;
ffb9eb3d 9779
15e47304 9780 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
9781 NL80211_CMD_GET_POWER_SAVE);
9782 if (!hdr) {
4c476991 9783 err = -ENOBUFS;
ffb9eb3d
KV
9784 goto free_msg;
9785 }
9786
9787 if (wdev->ps)
9788 ps_state = NL80211_PS_ENABLED;
9789 else
9790 ps_state = NL80211_PS_DISABLED;
9791
9360ffd1
DM
9792 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
9793 goto nla_put_failure;
ffb9eb3d
KV
9794
9795 genlmsg_end(msg, hdr);
4c476991 9796 return genlmsg_reply(msg, info);
ffb9eb3d 9797
4c476991 9798 nla_put_failure:
ffb9eb3d 9799 err = -ENOBUFS;
4c476991 9800 free_msg:
ffb9eb3d 9801 nlmsg_free(msg);
ffb9eb3d
KV
9802 return err;
9803}
9804
94e860f1
JB
9805static const struct nla_policy
9806nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
4a4b8169 9807 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_BINARY },
d6dc1a38
JO
9808 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
9809 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
9810 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
9811 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
9812 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
bee427b8 9813 [NL80211_ATTR_CQM_RSSI_LEVEL] = { .type = NLA_S32 },
d6dc1a38
JO
9814};
9815
84f10708 9816static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 9817 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
9818{
9819 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 9820 struct net_device *dev = info->user_ptr[1];
1da5fcc8 9821 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 9822
d9d8b019 9823 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
9824 return -EINVAL;
9825
84f10708
TP
9826 if (!rdev->ops->set_cqm_txe_config)
9827 return -EOPNOTSUPP;
9828
9829 if (wdev->iftype != NL80211_IFTYPE_STATION &&
9830 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
9831 return -EOPNOTSUPP;
9832
e35e4d28 9833 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
9834}
9835
4a4b8169
AZ
9836static int cfg80211_cqm_rssi_update(struct cfg80211_registered_device *rdev,
9837 struct net_device *dev)
9838{
9839 struct wireless_dev *wdev = dev->ieee80211_ptr;
9840 s32 last, low, high;
9841 u32 hyst;
9842 int i, n;
9843 int err;
9844
9845 /* RSSI reporting disabled? */
9846 if (!wdev->cqm_config)
9847 return rdev_set_cqm_rssi_range_config(rdev, dev, 0, 0);
9848
9849 /*
9850 * Obtain current RSSI value if possible, if not and no RSSI threshold
9851 * event has been received yet, we should receive an event after a
9852 * connection is established and enough beacons received to calculate
9853 * the average.
9854 */
9855 if (!wdev->cqm_config->last_rssi_event_value && wdev->current_bss &&
9856 rdev->ops->get_station) {
5762d7d3 9857 struct station_info sinfo = {};
4a4b8169
AZ
9858 u8 *mac_addr;
9859
9860 mac_addr = wdev->current_bss->pub.bssid;
9861
9862 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
9863 if (err)
9864 return err;
9865
9866 if (sinfo.filled & BIT(NL80211_STA_INFO_BEACON_SIGNAL_AVG))
9867 wdev->cqm_config->last_rssi_event_value =
9868 (s8) sinfo.rx_beacon_signal_avg;
9869 }
9870
9871 last = wdev->cqm_config->last_rssi_event_value;
9872 hyst = wdev->cqm_config->rssi_hyst;
9873 n = wdev->cqm_config->n_rssi_thresholds;
9874
9875 for (i = 0; i < n; i++)
9876 if (last < wdev->cqm_config->rssi_thresholds[i])
9877 break;
9878
9879 low = i > 0 ?
9880 (wdev->cqm_config->rssi_thresholds[i - 1] - hyst) : S32_MIN;
9881 high = i < n ?
9882 (wdev->cqm_config->rssi_thresholds[i] + hyst - 1) : S32_MAX;
9883
9884 return rdev_set_cqm_rssi_range_config(rdev, dev, low, high);
9885}
9886
d6dc1a38 9887static int nl80211_set_cqm_rssi(struct genl_info *info,
4a4b8169
AZ
9888 const s32 *thresholds, int n_thresholds,
9889 u32 hysteresis)
d6dc1a38 9890{
4c476991 9891 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 9892 struct net_device *dev = info->user_ptr[1];
1da5fcc8 9893 struct wireless_dev *wdev = dev->ieee80211_ptr;
4a4b8169
AZ
9894 int i, err;
9895 s32 prev = S32_MIN;
d6dc1a38 9896
4a4b8169
AZ
9897 /* Check all values negative and sorted */
9898 for (i = 0; i < n_thresholds; i++) {
9899 if (thresholds[i] > 0 || thresholds[i] <= prev)
9900 return -EINVAL;
d6dc1a38 9901
4a4b8169
AZ
9902 prev = thresholds[i];
9903 }
d6dc1a38 9904
074ac8df 9905 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9906 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
9907 return -EOPNOTSUPP;
d6dc1a38 9908
4a4b8169
AZ
9909 wdev_lock(wdev);
9910 cfg80211_cqm_config_free(wdev);
9911 wdev_unlock(wdev);
9912
9913 if (n_thresholds <= 1 && rdev->ops->set_cqm_rssi_config) {
9914 if (n_thresholds == 0 || thresholds[0] == 0) /* Disabling */
9915 return rdev_set_cqm_rssi_config(rdev, dev, 0, 0);
9916
9917 return rdev_set_cqm_rssi_config(rdev, dev,
9918 thresholds[0], hysteresis);
9919 }
9920
9921 if (!wiphy_ext_feature_isset(&rdev->wiphy,
9922 NL80211_EXT_FEATURE_CQM_RSSI_LIST))
9923 return -EOPNOTSUPP;
9924
9925 if (n_thresholds == 1 && thresholds[0] == 0) /* Disabling */
9926 n_thresholds = 0;
9927
9928 wdev_lock(wdev);
9929 if (n_thresholds) {
9930 struct cfg80211_cqm_config *cqm_config;
9931
9932 cqm_config = kzalloc(sizeof(struct cfg80211_cqm_config) +
9933 n_thresholds * sizeof(s32), GFP_KERNEL);
9934 if (!cqm_config) {
9935 err = -ENOMEM;
9936 goto unlock;
9937 }
9938
9939 cqm_config->rssi_hyst = hysteresis;
9940 cqm_config->n_rssi_thresholds = n_thresholds;
9941 memcpy(cqm_config->rssi_thresholds, thresholds,
9942 n_thresholds * sizeof(s32));
9943
9944 wdev->cqm_config = cqm_config;
9945 }
9946
9947 err = cfg80211_cqm_rssi_update(rdev, dev);
9948
9949unlock:
9950 wdev_unlock(wdev);
9951
9952 return err;
d6dc1a38
JO
9953}
9954
9955static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
9956{
9957 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
9958 struct nlattr *cqm;
9959 int err;
9960
9961 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
9962 if (!cqm)
9963 return -EINVAL;
d6dc1a38
JO
9964
9965 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
fe52145f 9966 nl80211_attr_cqm_policy, info->extack);
d6dc1a38 9967 if (err)
1da5fcc8 9968 return err;
d6dc1a38
JO
9969
9970 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
9971 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4a4b8169
AZ
9972 const s32 *thresholds =
9973 nla_data(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
9974 int len = nla_len(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
1da5fcc8 9975 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 9976
4a4b8169
AZ
9977 if (len % 4)
9978 return -EINVAL;
9979
9980 return nl80211_set_cqm_rssi(info, thresholds, len / 4,
9981 hysteresis);
1da5fcc8
JB
9982 }
9983
9984 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
9985 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
9986 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
9987 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
9988 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
9989 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
9990
9991 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
9992 }
9993
9994 return -EINVAL;
d6dc1a38
JO
9995}
9996
6e0bd6c3
RL
9997static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
9998{
9999 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10000 struct net_device *dev = info->user_ptr[1];
10001 struct ocb_setup setup = {};
10002 int err;
10003
10004 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
10005 if (err)
10006 return err;
10007
10008 return cfg80211_join_ocb(rdev, dev, &setup);
10009}
10010
10011static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info)
10012{
10013 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10014 struct net_device *dev = info->user_ptr[1];
10015
10016 return cfg80211_leave_ocb(rdev, dev);
10017}
10018
29cbe68c
JB
10019static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
10020{
10021 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10022 struct net_device *dev = info->user_ptr[1];
10023 struct mesh_config cfg;
c80d545d 10024 struct mesh_setup setup;
29cbe68c
JB
10025 int err;
10026
10027 /* start with default */
10028 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 10029 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 10030
24bdd9f4 10031 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 10032 /* and parse parameters if given */
24bdd9f4 10033 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
10034 if (err)
10035 return err;
10036 }
10037
10038 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
10039 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
10040 return -EINVAL;
10041
c80d545d
JC
10042 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
10043 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
10044
4bb62344
CYY
10045 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
10046 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
10047 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
10048 return -EINVAL;
10049
9bdbf04d
MP
10050 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
10051 setup.beacon_interval =
10052 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 10053
0c317a02
PK
10054 err = cfg80211_validate_beacon_int(rdev,
10055 NL80211_IFTYPE_MESH_POINT,
10056 setup.beacon_interval);
12d20fc9
PK
10057 if (err)
10058 return err;
9bdbf04d
MP
10059 }
10060
10061 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
10062 setup.dtim_period =
10063 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
10064 if (setup.dtim_period < 1 || setup.dtim_period > 100)
10065 return -EINVAL;
10066 }
10067
c80d545d
JC
10068 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
10069 /* parse additional setup parameters if given */
10070 err = nl80211_parse_mesh_setup(info, &setup);
10071 if (err)
10072 return err;
10073 }
10074
d37bb18a
TP
10075 if (setup.user_mpm)
10076 cfg.auto_open_plinks = false;
10077
cc1d2806 10078 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
10079 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
10080 if (err)
10081 return err;
cc1d2806
JB
10082 } else {
10083 /* cfg80211_join_mesh() will sort it out */
683b6d3b 10084 setup.chandef.chan = NULL;
cc1d2806
JB
10085 }
10086
ffb3cf30
AN
10087 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
10088 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
10089 int n_rates =
10090 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
10091 struct ieee80211_supported_band *sband;
10092
10093 if (!setup.chandef.chan)
10094 return -EINVAL;
10095
10096 sband = rdev->wiphy.bands[setup.chandef.chan->band];
10097
10098 err = ieee80211_get_ratemask(sband, rates, n_rates,
10099 &setup.basic_rates);
10100 if (err)
10101 return err;
10102 }
10103
8564e382
JB
10104 if (info->attrs[NL80211_ATTR_TX_RATES]) {
10105 err = nl80211_parse_tx_bitrate_mask(info, &setup.beacon_rate);
10106 if (err)
10107 return err;
10108
265698d7
JB
10109 if (!setup.chandef.chan)
10110 return -EINVAL;
10111
8564e382
JB
10112 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band,
10113 &setup.beacon_rate);
10114 if (err)
10115 return err;
10116 }
10117
d37d49c2
BB
10118 setup.userspace_handles_dfs =
10119 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
10120
c80d545d 10121 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
10122}
10123
10124static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
10125{
10126 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10127 struct net_device *dev = info->user_ptr[1];
10128
10129 return cfg80211_leave_mesh(rdev, dev);
10130}
10131
dfb89c56 10132#ifdef CONFIG_PM
bb92d199
AK
10133static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
10134 struct cfg80211_registered_device *rdev)
10135{
6abb9cb9 10136 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
10137 struct nlattr *nl_pats, *nl_pat;
10138 int i, pat_len;
10139
6abb9cb9 10140 if (!wowlan->n_patterns)
bb92d199
AK
10141 return 0;
10142
10143 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
10144 if (!nl_pats)
10145 return -ENOBUFS;
10146
6abb9cb9 10147 for (i = 0; i < wowlan->n_patterns; i++) {
bb92d199
AK
10148 nl_pat = nla_nest_start(msg, i + 1);
10149 if (!nl_pat)
10150 return -ENOBUFS;
6abb9cb9 10151 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 10152 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 10153 wowlan->patterns[i].mask) ||
50ac6607
AK
10154 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
10155 wowlan->patterns[i].pattern) ||
10156 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 10157 wowlan->patterns[i].pkt_offset))
bb92d199
AK
10158 return -ENOBUFS;
10159 nla_nest_end(msg, nl_pat);
10160 }
10161 nla_nest_end(msg, nl_pats);
10162
10163 return 0;
10164}
10165
2a0e047e
JB
10166static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
10167 struct cfg80211_wowlan_tcp *tcp)
10168{
10169 struct nlattr *nl_tcp;
10170
10171 if (!tcp)
10172 return 0;
10173
10174 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION);
10175 if (!nl_tcp)
10176 return -ENOBUFS;
10177
930345ea
JB
10178 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
10179 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
2a0e047e
JB
10180 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
10181 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
10182 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
10183 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
10184 tcp->payload_len, tcp->payload) ||
10185 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
10186 tcp->data_interval) ||
10187 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
10188 tcp->wake_len, tcp->wake_data) ||
10189 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
10190 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
10191 return -ENOBUFS;
10192
10193 if (tcp->payload_seq.len &&
10194 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
10195 sizeof(tcp->payload_seq), &tcp->payload_seq))
10196 return -ENOBUFS;
10197
10198 if (tcp->payload_tok.len &&
10199 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
10200 sizeof(tcp->payload_tok) + tcp->tokens_size,
10201 &tcp->payload_tok))
10202 return -ENOBUFS;
10203
e248ad30
JB
10204 nla_nest_end(msg, nl_tcp);
10205
2a0e047e
JB
10206 return 0;
10207}
10208
75453ccb
LC
10209static int nl80211_send_wowlan_nd(struct sk_buff *msg,
10210 struct cfg80211_sched_scan_request *req)
10211{
3b06d277 10212 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan;
75453ccb
LC
10213 int i;
10214
10215 if (!req)
10216 return 0;
10217
10218 nd = nla_nest_start(msg, NL80211_WOWLAN_TRIG_NET_DETECT);
10219 if (!nd)
10220 return -ENOBUFS;
10221
3b06d277
AS
10222 if (req->n_scan_plans == 1 &&
10223 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL,
10224 req->scan_plans[0].interval * 1000))
75453ccb
LC
10225 return -ENOBUFS;
10226
21fea567
LC
10227 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay))
10228 return -ENOBUFS;
10229
bf95ecdb 10230 if (req->relative_rssi_set) {
10231 struct nl80211_bss_select_rssi_adjust rssi_adjust;
10232
10233 if (nla_put_s8(msg, NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI,
10234 req->relative_rssi))
10235 return -ENOBUFS;
10236
10237 rssi_adjust.band = req->rssi_adjust.band;
10238 rssi_adjust.delta = req->rssi_adjust.delta;
10239 if (nla_put(msg, NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST,
10240 sizeof(rssi_adjust), &rssi_adjust))
10241 return -ENOBUFS;
10242 }
10243
75453ccb
LC
10244 freqs = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
10245 if (!freqs)
10246 return -ENOBUFS;
10247
53b18980
JB
10248 for (i = 0; i < req->n_channels; i++) {
10249 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
10250 return -ENOBUFS;
10251 }
75453ccb
LC
10252
10253 nla_nest_end(msg, freqs);
10254
10255 if (req->n_match_sets) {
10256 matches = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_MATCH);
76e1fb4b
JB
10257 if (!matches)
10258 return -ENOBUFS;
10259
75453ccb
LC
10260 for (i = 0; i < req->n_match_sets; i++) {
10261 match = nla_nest_start(msg, i);
76e1fb4b
JB
10262 if (!match)
10263 return -ENOBUFS;
10264
53b18980
JB
10265 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID,
10266 req->match_sets[i].ssid.ssid_len,
10267 req->match_sets[i].ssid.ssid))
10268 return -ENOBUFS;
75453ccb
LC
10269 nla_nest_end(msg, match);
10270 }
10271 nla_nest_end(msg, matches);
10272 }
10273
3b06d277
AS
10274 scan_plans = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_PLANS);
10275 if (!scan_plans)
10276 return -ENOBUFS;
10277
10278 for (i = 0; i < req->n_scan_plans; i++) {
10279 scan_plan = nla_nest_start(msg, i + 1);
76e1fb4b
JB
10280 if (!scan_plan)
10281 return -ENOBUFS;
10282
3b06d277
AS
10283 if (!scan_plan ||
10284 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL,
10285 req->scan_plans[i].interval) ||
10286 (req->scan_plans[i].iterations &&
10287 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS,
10288 req->scan_plans[i].iterations)))
10289 return -ENOBUFS;
10290 nla_nest_end(msg, scan_plan);
10291 }
10292 nla_nest_end(msg, scan_plans);
10293
75453ccb
LC
10294 nla_nest_end(msg, nd);
10295
10296 return 0;
10297}
10298
ff1b6e69
JB
10299static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
10300{
10301 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10302 struct sk_buff *msg;
10303 void *hdr;
2a0e047e 10304 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 10305
964dc9e2 10306 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
10307 return -EOPNOTSUPP;
10308
6abb9cb9 10309 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 10310 /* adjust size to have room for all the data */
6abb9cb9
JB
10311 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
10312 rdev->wiphy.wowlan_config->tcp->payload_len +
10313 rdev->wiphy.wowlan_config->tcp->wake_len +
10314 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
10315 }
10316
10317 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
10318 if (!msg)
10319 return -ENOMEM;
10320
15e47304 10321 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
10322 NL80211_CMD_GET_WOWLAN);
10323 if (!hdr)
10324 goto nla_put_failure;
10325
6abb9cb9 10326 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
10327 struct nlattr *nl_wowlan;
10328
10329 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
10330 if (!nl_wowlan)
10331 goto nla_put_failure;
10332
6abb9cb9 10333 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 10334 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 10335 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 10336 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 10337 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 10338 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 10339 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 10340 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 10341 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 10342 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 10343 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 10344 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 10345 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
10346 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
10347 goto nla_put_failure;
2a0e047e 10348
bb92d199
AK
10349 if (nl80211_send_wowlan_patterns(msg, rdev))
10350 goto nla_put_failure;
2a0e047e 10351
6abb9cb9
JB
10352 if (nl80211_send_wowlan_tcp(msg,
10353 rdev->wiphy.wowlan_config->tcp))
2a0e047e 10354 goto nla_put_failure;
75453ccb
LC
10355
10356 if (nl80211_send_wowlan_nd(
10357 msg,
10358 rdev->wiphy.wowlan_config->nd_config))
10359 goto nla_put_failure;
2a0e047e 10360
ff1b6e69
JB
10361 nla_nest_end(msg, nl_wowlan);
10362 }
10363
10364 genlmsg_end(msg, hdr);
10365 return genlmsg_reply(msg, info);
10366
10367nla_put_failure:
10368 nlmsg_free(msg);
10369 return -ENOBUFS;
10370}
10371
2a0e047e
JB
10372static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
10373 struct nlattr *attr,
10374 struct cfg80211_wowlan *trig)
10375{
10376 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
10377 struct cfg80211_wowlan_tcp *cfg;
10378 struct nl80211_wowlan_tcp_data_token *tok = NULL;
10379 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
10380 u32 size;
10381 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
10382 int err, port;
10383
964dc9e2 10384 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
10385 return -EINVAL;
10386
bfe2c7b1 10387 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TCP, attr,
fceb6435 10388 nl80211_wowlan_tcp_policy, NULL);
2a0e047e
JB
10389 if (err)
10390 return err;
10391
10392 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
10393 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
10394 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
10395 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
10396 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
10397 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
10398 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
10399 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
10400 return -EINVAL;
10401
10402 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 10403 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
10404 return -EINVAL;
10405
10406 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 10407 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 10408 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
10409 return -EINVAL;
10410
10411 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 10412 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
10413 return -EINVAL;
10414
10415 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
10416 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
10417 return -EINVAL;
10418
10419 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
10420 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
10421
10422 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
10423 tokens_size = tokln - sizeof(*tok);
10424
10425 if (!tok->len || tokens_size % tok->len)
10426 return -EINVAL;
964dc9e2 10427 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 10428 return -EINVAL;
964dc9e2 10429 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 10430 return -EINVAL;
964dc9e2 10431 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 10432 return -EINVAL;
964dc9e2 10433 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
10434 return -EINVAL;
10435 if (tok->offset + tok->len > data_size)
10436 return -EINVAL;
10437 }
10438
10439 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
10440 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 10441 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
10442 return -EINVAL;
10443 if (seq->len == 0 || seq->len > 4)
10444 return -EINVAL;
10445 if (seq->len + seq->offset > data_size)
10446 return -EINVAL;
10447 }
10448
10449 size = sizeof(*cfg);
10450 size += data_size;
10451 size += wake_size + wake_mask_size;
10452 size += tokens_size;
10453
10454 cfg = kzalloc(size, GFP_KERNEL);
10455 if (!cfg)
10456 return -ENOMEM;
67b61f6c
JB
10457 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
10458 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
2a0e047e
JB
10459 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
10460 ETH_ALEN);
10461 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
10462 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
10463 else
10464 port = 0;
10465#ifdef CONFIG_INET
10466 /* allocate a socket and port for it and use it */
10467 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
10468 IPPROTO_TCP, &cfg->sock, 1);
10469 if (err) {
10470 kfree(cfg);
10471 return err;
10472 }
10473 if (inet_csk_get_port(cfg->sock->sk, port)) {
10474 sock_release(cfg->sock);
10475 kfree(cfg);
10476 return -EADDRINUSE;
10477 }
10478 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
10479#else
10480 if (!port) {
10481 kfree(cfg);
10482 return -EINVAL;
10483 }
10484 cfg->src_port = port;
10485#endif
10486
10487 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
10488 cfg->payload_len = data_size;
10489 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
10490 memcpy((void *)cfg->payload,
10491 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
10492 data_size);
10493 if (seq)
10494 cfg->payload_seq = *seq;
10495 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
10496 cfg->wake_len = wake_size;
10497 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
10498 memcpy((void *)cfg->wake_data,
10499 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
10500 wake_size);
10501 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
10502 data_size + wake_size;
10503 memcpy((void *)cfg->wake_mask,
10504 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
10505 wake_mask_size);
10506 if (tok) {
10507 cfg->tokens_size = tokens_size;
10508 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
10509 }
10510
10511 trig->tcp = cfg;
10512
10513 return 0;
10514}
10515
8cd4d456
LC
10516static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev,
10517 const struct wiphy_wowlan_support *wowlan,
10518 struct nlattr *attr,
10519 struct cfg80211_wowlan *trig)
10520{
10521 struct nlattr **tb;
10522 int err;
10523
10524 tb = kzalloc(NUM_NL80211_ATTR * sizeof(*tb), GFP_KERNEL);
10525 if (!tb)
10526 return -ENOMEM;
10527
10528 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) {
10529 err = -EOPNOTSUPP;
10530 goto out;
10531 }
10532
fceb6435
JB
10533 err = nla_parse_nested(tb, NL80211_ATTR_MAX, attr, nl80211_policy,
10534 NULL);
8cd4d456
LC
10535 if (err)
10536 goto out;
10537
aad1e812
AVS
10538 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb,
10539 wowlan->max_nd_match_sets);
8cd4d456
LC
10540 err = PTR_ERR_OR_ZERO(trig->nd_config);
10541 if (err)
10542 trig->nd_config = NULL;
10543
10544out:
10545 kfree(tb);
10546 return err;
10547}
10548
ff1b6e69
JB
10549static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
10550{
10551 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10552 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 10553 struct cfg80211_wowlan new_triggers = {};
ae33bd81 10554 struct cfg80211_wowlan *ntrig;
964dc9e2 10555 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 10556 int err, i;
6abb9cb9 10557 bool prev_enabled = rdev->wiphy.wowlan_config;
98fc4386 10558 bool regular = false;
ff1b6e69 10559
964dc9e2 10560 if (!wowlan)
ff1b6e69
JB
10561 return -EOPNOTSUPP;
10562
ae33bd81
JB
10563 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
10564 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 10565 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
10566 goto set_wakeup;
10567 }
ff1b6e69 10568
bfe2c7b1
JB
10569 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TRIG,
10570 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS],
fe52145f 10571 nl80211_wowlan_policy, info->extack);
ff1b6e69
JB
10572 if (err)
10573 return err;
10574
10575 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
10576 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
10577 return -EINVAL;
10578 new_triggers.any = true;
10579 }
10580
10581 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
10582 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
10583 return -EINVAL;
10584 new_triggers.disconnect = true;
98fc4386 10585 regular = true;
ff1b6e69
JB
10586 }
10587
10588 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
10589 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
10590 return -EINVAL;
10591 new_triggers.magic_pkt = true;
98fc4386 10592 regular = true;
ff1b6e69
JB
10593 }
10594
77dbbb13
JB
10595 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
10596 return -EINVAL;
10597
10598 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
10599 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
10600 return -EINVAL;
10601 new_triggers.gtk_rekey_failure = true;
98fc4386 10602 regular = true;
77dbbb13
JB
10603 }
10604
10605 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
10606 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
10607 return -EINVAL;
10608 new_triggers.eap_identity_req = true;
98fc4386 10609 regular = true;
77dbbb13
JB
10610 }
10611
10612 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
10613 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
10614 return -EINVAL;
10615 new_triggers.four_way_handshake = true;
98fc4386 10616 regular = true;
77dbbb13
JB
10617 }
10618
10619 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
10620 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
10621 return -EINVAL;
10622 new_triggers.rfkill_release = true;
98fc4386 10623 regular = true;
77dbbb13
JB
10624 }
10625
ff1b6e69
JB
10626 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
10627 struct nlattr *pat;
10628 int n_patterns = 0;
bb92d199 10629 int rem, pat_len, mask_len, pkt_offset;
50ac6607 10630 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69 10631
98fc4386
JB
10632 regular = true;
10633
ff1b6e69
JB
10634 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
10635 rem)
10636 n_patterns++;
10637 if (n_patterns > wowlan->n_patterns)
10638 return -EINVAL;
10639
10640 new_triggers.patterns = kcalloc(n_patterns,
10641 sizeof(new_triggers.patterns[0]),
10642 GFP_KERNEL);
10643 if (!new_triggers.patterns)
10644 return -ENOMEM;
10645
10646 new_triggers.n_patterns = n_patterns;
10647 i = 0;
10648
10649 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
10650 rem) {
922bd80f
JB
10651 u8 *mask_pat;
10652
bfe2c7b1 10653 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat,
ad670233
PX
10654 nl80211_packet_pattern_policy,
10655 info->extack);
ff1b6e69 10656 err = -EINVAL;
50ac6607
AK
10657 if (!pat_tb[NL80211_PKTPAT_MASK] ||
10658 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 10659 goto error;
50ac6607 10660 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 10661 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 10662 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
10663 goto error;
10664 if (pat_len > wowlan->pattern_max_len ||
10665 pat_len < wowlan->pattern_min_len)
10666 goto error;
10667
50ac6607 10668 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
10669 pkt_offset = 0;
10670 else
10671 pkt_offset = nla_get_u32(
50ac6607 10672 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
10673 if (pkt_offset > wowlan->max_pkt_offset)
10674 goto error;
10675 new_triggers.patterns[i].pkt_offset = pkt_offset;
10676
922bd80f
JB
10677 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
10678 if (!mask_pat) {
ff1b6e69
JB
10679 err = -ENOMEM;
10680 goto error;
10681 }
922bd80f
JB
10682 new_triggers.patterns[i].mask = mask_pat;
10683 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69 10684 mask_len);
922bd80f
JB
10685 mask_pat += mask_len;
10686 new_triggers.patterns[i].pattern = mask_pat;
ff1b6e69 10687 new_triggers.patterns[i].pattern_len = pat_len;
922bd80f 10688 memcpy(mask_pat,
50ac6607 10689 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
10690 pat_len);
10691 i++;
10692 }
10693 }
10694
2a0e047e 10695 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
98fc4386 10696 regular = true;
2a0e047e
JB
10697 err = nl80211_parse_wowlan_tcp(
10698 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
10699 &new_triggers);
10700 if (err)
10701 goto error;
10702 }
10703
8cd4d456 10704 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) {
98fc4386 10705 regular = true;
8cd4d456
LC
10706 err = nl80211_parse_wowlan_nd(
10707 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT],
10708 &new_triggers);
10709 if (err)
10710 goto error;
10711 }
10712
98fc4386
JB
10713 /* The 'any' trigger means the device continues operating more or less
10714 * as in its normal operation mode and wakes up the host on most of the
10715 * normal interrupts (like packet RX, ...)
10716 * It therefore makes little sense to combine with the more constrained
10717 * wakeup trigger modes.
10718 */
10719 if (new_triggers.any && regular) {
10720 err = -EINVAL;
10721 goto error;
10722 }
10723
ae33bd81
JB
10724 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
10725 if (!ntrig) {
10726 err = -ENOMEM;
10727 goto error;
ff1b6e69 10728 }
ae33bd81 10729 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 10730 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 10731
ae33bd81 10732 set_wakeup:
6abb9cb9
JB
10733 if (rdev->ops->set_wakeup &&
10734 prev_enabled != !!rdev->wiphy.wowlan_config)
10735 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 10736
ff1b6e69
JB
10737 return 0;
10738 error:
10739 for (i = 0; i < new_triggers.n_patterns; i++)
10740 kfree(new_triggers.patterns[i].mask);
10741 kfree(new_triggers.patterns);
2a0e047e
JB
10742 if (new_triggers.tcp && new_triggers.tcp->sock)
10743 sock_release(new_triggers.tcp->sock);
10744 kfree(new_triggers.tcp);
e5dbe070 10745 kfree(new_triggers.nd_config);
ff1b6e69
JB
10746 return err;
10747}
dfb89c56 10748#endif
ff1b6e69 10749
be29b99a
AK
10750static int nl80211_send_coalesce_rules(struct sk_buff *msg,
10751 struct cfg80211_registered_device *rdev)
10752{
10753 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
10754 int i, j, pat_len;
10755 struct cfg80211_coalesce_rules *rule;
10756
10757 if (!rdev->coalesce->n_rules)
10758 return 0;
10759
10760 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE);
10761 if (!nl_rules)
10762 return -ENOBUFS;
10763
10764 for (i = 0; i < rdev->coalesce->n_rules; i++) {
10765 nl_rule = nla_nest_start(msg, i + 1);
10766 if (!nl_rule)
10767 return -ENOBUFS;
10768
10769 rule = &rdev->coalesce->rules[i];
10770 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
10771 rule->delay))
10772 return -ENOBUFS;
10773
10774 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
10775 rule->condition))
10776 return -ENOBUFS;
10777
10778 nl_pats = nla_nest_start(msg,
10779 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
10780 if (!nl_pats)
10781 return -ENOBUFS;
10782
10783 for (j = 0; j < rule->n_patterns; j++) {
10784 nl_pat = nla_nest_start(msg, j + 1);
10785 if (!nl_pat)
10786 return -ENOBUFS;
10787 pat_len = rule->patterns[j].pattern_len;
10788 if (nla_put(msg, NL80211_PKTPAT_MASK,
10789 DIV_ROUND_UP(pat_len, 8),
10790 rule->patterns[j].mask) ||
10791 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
10792 rule->patterns[j].pattern) ||
10793 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
10794 rule->patterns[j].pkt_offset))
10795 return -ENOBUFS;
10796 nla_nest_end(msg, nl_pat);
10797 }
10798 nla_nest_end(msg, nl_pats);
10799 nla_nest_end(msg, nl_rule);
10800 }
10801 nla_nest_end(msg, nl_rules);
10802
10803 return 0;
10804}
10805
10806static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
10807{
10808 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10809 struct sk_buff *msg;
10810 void *hdr;
10811
10812 if (!rdev->wiphy.coalesce)
10813 return -EOPNOTSUPP;
10814
10815 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10816 if (!msg)
10817 return -ENOMEM;
10818
10819 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
10820 NL80211_CMD_GET_COALESCE);
10821 if (!hdr)
10822 goto nla_put_failure;
10823
10824 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
10825 goto nla_put_failure;
10826
10827 genlmsg_end(msg, hdr);
10828 return genlmsg_reply(msg, info);
10829
10830nla_put_failure:
10831 nlmsg_free(msg);
10832 return -ENOBUFS;
10833}
10834
10835void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
10836{
10837 struct cfg80211_coalesce *coalesce = rdev->coalesce;
10838 int i, j;
10839 struct cfg80211_coalesce_rules *rule;
10840
10841 if (!coalesce)
10842 return;
10843
10844 for (i = 0; i < coalesce->n_rules; i++) {
10845 rule = &coalesce->rules[i];
10846 for (j = 0; j < rule->n_patterns; j++)
10847 kfree(rule->patterns[j].mask);
10848 kfree(rule->patterns);
10849 }
10850 kfree(coalesce->rules);
10851 kfree(coalesce);
10852 rdev->coalesce = NULL;
10853}
10854
10855static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
10856 struct nlattr *rule,
10857 struct cfg80211_coalesce_rules *new_rule)
10858{
10859 int err, i;
10860 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
10861 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
10862 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
10863 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
10864
bfe2c7b1 10865 err = nla_parse_nested(tb, NL80211_ATTR_COALESCE_RULE_MAX, rule,
fceb6435 10866 nl80211_coalesce_policy, NULL);
be29b99a
AK
10867 if (err)
10868 return err;
10869
10870 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
10871 new_rule->delay =
10872 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
10873 if (new_rule->delay > coalesce->max_delay)
10874 return -EINVAL;
10875
10876 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
10877 new_rule->condition =
10878 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
10879 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH &&
10880 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH)
10881 return -EINVAL;
10882
10883 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
10884 return -EINVAL;
10885
10886 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
10887 rem)
10888 n_patterns++;
10889 if (n_patterns > coalesce->n_patterns)
10890 return -EINVAL;
10891
10892 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
10893 GFP_KERNEL);
10894 if (!new_rule->patterns)
10895 return -ENOMEM;
10896
10897 new_rule->n_patterns = n_patterns;
10898 i = 0;
10899
10900 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
10901 rem) {
922bd80f
JB
10902 u8 *mask_pat;
10903
ad670233
PX
10904 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat,
10905 nl80211_packet_pattern_policy, NULL);
be29b99a
AK
10906 if (!pat_tb[NL80211_PKTPAT_MASK] ||
10907 !pat_tb[NL80211_PKTPAT_PATTERN])
10908 return -EINVAL;
10909 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
10910 mask_len = DIV_ROUND_UP(pat_len, 8);
10911 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
10912 return -EINVAL;
10913 if (pat_len > coalesce->pattern_max_len ||
10914 pat_len < coalesce->pattern_min_len)
10915 return -EINVAL;
10916
10917 if (!pat_tb[NL80211_PKTPAT_OFFSET])
10918 pkt_offset = 0;
10919 else
10920 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
10921 if (pkt_offset > coalesce->max_pkt_offset)
10922 return -EINVAL;
10923 new_rule->patterns[i].pkt_offset = pkt_offset;
10924
922bd80f
JB
10925 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
10926 if (!mask_pat)
be29b99a 10927 return -ENOMEM;
922bd80f
JB
10928
10929 new_rule->patterns[i].mask = mask_pat;
10930 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
10931 mask_len);
10932
10933 mask_pat += mask_len;
10934 new_rule->patterns[i].pattern = mask_pat;
be29b99a 10935 new_rule->patterns[i].pattern_len = pat_len;
922bd80f
JB
10936 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
10937 pat_len);
be29b99a
AK
10938 i++;
10939 }
10940
10941 return 0;
10942}
10943
10944static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
10945{
10946 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10947 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
10948 struct cfg80211_coalesce new_coalesce = {};
10949 struct cfg80211_coalesce *n_coalesce;
10950 int err, rem_rule, n_rules = 0, i, j;
10951 struct nlattr *rule;
10952 struct cfg80211_coalesce_rules *tmp_rule;
10953
10954 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
10955 return -EOPNOTSUPP;
10956
10957 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
10958 cfg80211_rdev_free_coalesce(rdev);
a1056b1b 10959 rdev_set_coalesce(rdev, NULL);
be29b99a
AK
10960 return 0;
10961 }
10962
10963 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
10964 rem_rule)
10965 n_rules++;
10966 if (n_rules > coalesce->n_rules)
10967 return -EINVAL;
10968
10969 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
10970 GFP_KERNEL);
10971 if (!new_coalesce.rules)
10972 return -ENOMEM;
10973
10974 new_coalesce.n_rules = n_rules;
10975 i = 0;
10976
10977 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
10978 rem_rule) {
10979 err = nl80211_parse_coalesce_rule(rdev, rule,
10980 &new_coalesce.rules[i]);
10981 if (err)
10982 goto error;
10983
10984 i++;
10985 }
10986
a1056b1b 10987 err = rdev_set_coalesce(rdev, &new_coalesce);
be29b99a
AK
10988 if (err)
10989 goto error;
10990
10991 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
10992 if (!n_coalesce) {
10993 err = -ENOMEM;
10994 goto error;
10995 }
10996 cfg80211_rdev_free_coalesce(rdev);
10997 rdev->coalesce = n_coalesce;
10998
10999 return 0;
11000error:
11001 for (i = 0; i < new_coalesce.n_rules; i++) {
11002 tmp_rule = &new_coalesce.rules[i];
11003 for (j = 0; j < tmp_rule->n_patterns; j++)
11004 kfree(tmp_rule->patterns[j].mask);
11005 kfree(tmp_rule->patterns);
11006 }
11007 kfree(new_coalesce.rules);
11008
11009 return err;
11010}
11011
e5497d76
JB
11012static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
11013{
11014 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11015 struct net_device *dev = info->user_ptr[1];
11016 struct wireless_dev *wdev = dev->ieee80211_ptr;
11017 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
11018 struct cfg80211_gtk_rekey_data rekey_data;
11019 int err;
11020
11021 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
11022 return -EINVAL;
11023
bfe2c7b1
JB
11024 err = nla_parse_nested(tb, MAX_NL80211_REKEY_DATA,
11025 info->attrs[NL80211_ATTR_REKEY_DATA],
fe52145f 11026 nl80211_rekey_policy, info->extack);
e5497d76
JB
11027 if (err)
11028 return err;
11029
e785fa0a
VD
11030 if (!tb[NL80211_REKEY_DATA_REPLAY_CTR] || !tb[NL80211_REKEY_DATA_KEK] ||
11031 !tb[NL80211_REKEY_DATA_KCK])
11032 return -EINVAL;
e5497d76
JB
11033 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
11034 return -ERANGE;
11035 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
11036 return -ERANGE;
11037 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
11038 return -ERANGE;
11039
78f686ca
JB
11040 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]);
11041 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]);
11042 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]);
e5497d76
JB
11043
11044 wdev_lock(wdev);
11045 if (!wdev->current_bss) {
11046 err = -ENOTCONN;
11047 goto out;
11048 }
11049
11050 if (!rdev->ops->set_rekey_data) {
11051 err = -EOPNOTSUPP;
11052 goto out;
11053 }
11054
e35e4d28 11055 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
11056 out:
11057 wdev_unlock(wdev);
11058 return err;
11059}
11060
28946da7
JB
11061static int nl80211_register_unexpected_frame(struct sk_buff *skb,
11062 struct genl_info *info)
11063{
11064 struct net_device *dev = info->user_ptr[1];
11065 struct wireless_dev *wdev = dev->ieee80211_ptr;
11066
11067 if (wdev->iftype != NL80211_IFTYPE_AP &&
11068 wdev->iftype != NL80211_IFTYPE_P2P_GO)
11069 return -EINVAL;
11070
15e47304 11071 if (wdev->ap_unexpected_nlportid)
28946da7
JB
11072 return -EBUSY;
11073
15e47304 11074 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
11075 return 0;
11076}
11077
7f6cf311
JB
11078static int nl80211_probe_client(struct sk_buff *skb,
11079 struct genl_info *info)
11080{
11081 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11082 struct net_device *dev = info->user_ptr[1];
11083 struct wireless_dev *wdev = dev->ieee80211_ptr;
11084 struct sk_buff *msg;
11085 void *hdr;
11086 const u8 *addr;
11087 u64 cookie;
11088 int err;
11089
11090 if (wdev->iftype != NL80211_IFTYPE_AP &&
11091 wdev->iftype != NL80211_IFTYPE_P2P_GO)
11092 return -EOPNOTSUPP;
11093
11094 if (!info->attrs[NL80211_ATTR_MAC])
11095 return -EINVAL;
11096
11097 if (!rdev->ops->probe_client)
11098 return -EOPNOTSUPP;
11099
11100 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11101 if (!msg)
11102 return -ENOMEM;
11103
15e47304 11104 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 11105 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
11106 if (!hdr) {
11107 err = -ENOBUFS;
7f6cf311
JB
11108 goto free_msg;
11109 }
11110
11111 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
11112
e35e4d28 11113 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
11114 if (err)
11115 goto free_msg;
11116
2dad624e
ND
11117 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
11118 NL80211_ATTR_PAD))
9360ffd1 11119 goto nla_put_failure;
7f6cf311
JB
11120
11121 genlmsg_end(msg, hdr);
11122
11123 return genlmsg_reply(msg, info);
11124
11125 nla_put_failure:
11126 err = -ENOBUFS;
11127 free_msg:
11128 nlmsg_free(msg);
11129 return err;
11130}
11131
5e760230
JB
11132static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
11133{
11134 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
11135 struct cfg80211_beacon_registration *reg, *nreg;
11136 int rv;
5e760230
JB
11137
11138 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
11139 return -EOPNOTSUPP;
11140
37c73b5f
BG
11141 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
11142 if (!nreg)
11143 return -ENOMEM;
11144
11145 /* First, check if already registered. */
11146 spin_lock_bh(&rdev->beacon_registrations_lock);
11147 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
11148 if (reg->nlportid == info->snd_portid) {
11149 rv = -EALREADY;
11150 goto out_err;
11151 }
11152 }
11153 /* Add it to the list */
11154 nreg->nlportid = info->snd_portid;
11155 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 11156
37c73b5f 11157 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
11158
11159 return 0;
37c73b5f
BG
11160out_err:
11161 spin_unlock_bh(&rdev->beacon_registrations_lock);
11162 kfree(nreg);
11163 return rv;
5e760230
JB
11164}
11165
98104fde
JB
11166static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
11167{
11168 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11169 struct wireless_dev *wdev = info->user_ptr[1];
11170 int err;
11171
11172 if (!rdev->ops->start_p2p_device)
11173 return -EOPNOTSUPP;
11174
11175 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
11176 return -EOPNOTSUPP;
11177
73c7da3d 11178 if (wdev_running(wdev))
98104fde
JB
11179 return 0;
11180
b6a55015
LC
11181 if (rfkill_blocked(rdev->rfkill))
11182 return -ERFKILL;
98104fde 11183
eeb126e9 11184 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
11185 if (err)
11186 return err;
11187
73c7da3d 11188 wdev->is_running = true;
98104fde 11189 rdev->opencount++;
98104fde
JB
11190
11191 return 0;
11192}
11193
11194static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
11195{
11196 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11197 struct wireless_dev *wdev = info->user_ptr[1];
11198
11199 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
11200 return -EOPNOTSUPP;
11201
11202 if (!rdev->ops->stop_p2p_device)
11203 return -EOPNOTSUPP;
11204
f9f47529 11205 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
11206
11207 return 0;
11208}
11209
cb3b7d87
AB
11210static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info)
11211{
11212 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11213 struct wireless_dev *wdev = info->user_ptr[1];
11214 struct cfg80211_nan_conf conf = {};
11215 int err;
11216
11217 if (wdev->iftype != NL80211_IFTYPE_NAN)
11218 return -EOPNOTSUPP;
11219
eeb04a96 11220 if (wdev_running(wdev))
cb3b7d87
AB
11221 return -EEXIST;
11222
11223 if (rfkill_blocked(rdev->rfkill))
11224 return -ERFKILL;
11225
11226 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF])
11227 return -EINVAL;
11228
cb3b7d87
AB
11229 conf.master_pref =
11230 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
11231 if (!conf.master_pref)
11232 return -EINVAL;
11233
8585989d
LC
11234 if (info->attrs[NL80211_ATTR_BANDS]) {
11235 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
11236
11237 if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
11238 return -EOPNOTSUPP;
11239
11240 if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
11241 return -EINVAL;
11242
11243 conf.bands = bands;
11244 }
cb3b7d87
AB
11245
11246 err = rdev_start_nan(rdev, wdev, &conf);
11247 if (err)
11248 return err;
11249
73c7da3d 11250 wdev->is_running = true;
cb3b7d87
AB
11251 rdev->opencount++;
11252
11253 return 0;
11254}
11255
11256static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info)
11257{
11258 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11259 struct wireless_dev *wdev = info->user_ptr[1];
11260
11261 if (wdev->iftype != NL80211_IFTYPE_NAN)
11262 return -EOPNOTSUPP;
11263
11264 cfg80211_stop_nan(rdev, wdev);
11265
11266 return 0;
11267}
11268
a442b761
AB
11269static int validate_nan_filter(struct nlattr *filter_attr)
11270{
11271 struct nlattr *attr;
11272 int len = 0, n_entries = 0, rem;
11273
11274 nla_for_each_nested(attr, filter_attr, rem) {
11275 len += nla_len(attr);
11276 n_entries++;
11277 }
11278
11279 if (len >= U8_MAX)
11280 return -EINVAL;
11281
11282 return n_entries;
11283}
11284
11285static int handle_nan_filter(struct nlattr *attr_filter,
11286 struct cfg80211_nan_func *func,
11287 bool tx)
11288{
11289 struct nlattr *attr;
11290 int n_entries, rem, i;
11291 struct cfg80211_nan_func_filter *filter;
11292
11293 n_entries = validate_nan_filter(attr_filter);
11294 if (n_entries < 0)
11295 return n_entries;
11296
11297 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters));
11298
11299 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL);
11300 if (!filter)
11301 return -ENOMEM;
11302
11303 i = 0;
11304 nla_for_each_nested(attr, attr_filter, rem) {
b15ca182 11305 filter[i].filter = nla_memdup(attr, GFP_KERNEL);
a442b761
AB
11306 filter[i].len = nla_len(attr);
11307 i++;
11308 }
11309 if (tx) {
11310 func->num_tx_filters = n_entries;
11311 func->tx_filters = filter;
11312 } else {
11313 func->num_rx_filters = n_entries;
11314 func->rx_filters = filter;
11315 }
11316
11317 return 0;
11318}
11319
11320static int nl80211_nan_add_func(struct sk_buff *skb,
11321 struct genl_info *info)
11322{
11323 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11324 struct wireless_dev *wdev = info->user_ptr[1];
11325 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr;
11326 struct cfg80211_nan_func *func;
11327 struct sk_buff *msg = NULL;
11328 void *hdr = NULL;
11329 int err = 0;
11330
11331 if (wdev->iftype != NL80211_IFTYPE_NAN)
11332 return -EOPNOTSUPP;
11333
73c7da3d 11334 if (!wdev_running(wdev))
a442b761
AB
11335 return -ENOTCONN;
11336
11337 if (!info->attrs[NL80211_ATTR_NAN_FUNC])
11338 return -EINVAL;
11339
bfe2c7b1
JB
11340 err = nla_parse_nested(tb, NL80211_NAN_FUNC_ATTR_MAX,
11341 info->attrs[NL80211_ATTR_NAN_FUNC],
fe52145f 11342 nl80211_nan_func_policy, info->extack);
a442b761
AB
11343 if (err)
11344 return err;
11345
11346 func = kzalloc(sizeof(*func), GFP_KERNEL);
11347 if (!func)
11348 return -ENOMEM;
11349
11350 func->cookie = wdev->wiphy->cookie_counter++;
11351
11352 if (!tb[NL80211_NAN_FUNC_TYPE] ||
11353 nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]) > NL80211_NAN_FUNC_MAX_TYPE) {
11354 err = -EINVAL;
11355 goto out;
11356 }
11357
11358
11359 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]);
11360
11361 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) {
11362 err = -EINVAL;
11363 goto out;
11364 }
11365
11366 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]),
11367 sizeof(func->service_id));
11368
11369 func->close_range =
11370 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]);
11371
11372 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) {
11373 func->serv_spec_info_len =
11374 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]);
11375 func->serv_spec_info =
11376 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]),
11377 func->serv_spec_info_len,
11378 GFP_KERNEL);
11379 if (!func->serv_spec_info) {
11380 err = -ENOMEM;
11381 goto out;
11382 }
11383 }
11384
11385 if (tb[NL80211_NAN_FUNC_TTL])
11386 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]);
11387
11388 switch (func->type) {
11389 case NL80211_NAN_FUNC_PUBLISH:
11390 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) {
11391 err = -EINVAL;
11392 goto out;
11393 }
11394
11395 func->publish_type =
11396 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]);
11397 func->publish_bcast =
11398 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]);
11399
11400 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) &&
11401 func->publish_bcast) {
11402 err = -EINVAL;
11403 goto out;
11404 }
11405 break;
11406 case NL80211_NAN_FUNC_SUBSCRIBE:
11407 func->subscribe_active =
11408 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]);
11409 break;
11410 case NL80211_NAN_FUNC_FOLLOW_UP:
11411 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] ||
3ea15452
HC
11412 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] ||
11413 !tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]) {
a442b761
AB
11414 err = -EINVAL;
11415 goto out;
11416 }
11417
11418 func->followup_id =
11419 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]);
11420 func->followup_reqid =
11421 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]);
11422 memcpy(func->followup_dest.addr,
11423 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]),
11424 sizeof(func->followup_dest.addr));
11425 if (func->ttl) {
11426 err = -EINVAL;
11427 goto out;
11428 }
11429 break;
11430 default:
11431 err = -EINVAL;
11432 goto out;
11433 }
11434
11435 if (tb[NL80211_NAN_FUNC_SRF]) {
11436 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR];
11437
bfe2c7b1
JB
11438 err = nla_parse_nested(srf_tb, NL80211_NAN_SRF_ATTR_MAX,
11439 tb[NL80211_NAN_FUNC_SRF],
fe52145f 11440 nl80211_nan_srf_policy, info->extack);
a442b761
AB
11441 if (err)
11442 goto out;
11443
11444 func->srf_include =
11445 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]);
11446
11447 if (srf_tb[NL80211_NAN_SRF_BF]) {
11448 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] ||
11449 !srf_tb[NL80211_NAN_SRF_BF_IDX]) {
11450 err = -EINVAL;
11451 goto out;
11452 }
11453
11454 func->srf_bf_len =
11455 nla_len(srf_tb[NL80211_NAN_SRF_BF]);
11456 func->srf_bf =
11457 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]),
11458 func->srf_bf_len, GFP_KERNEL);
11459 if (!func->srf_bf) {
11460 err = -ENOMEM;
11461 goto out;
11462 }
11463
11464 func->srf_bf_idx =
11465 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]);
11466 } else {
11467 struct nlattr *attr, *mac_attr =
11468 srf_tb[NL80211_NAN_SRF_MAC_ADDRS];
11469 int n_entries, rem, i = 0;
11470
11471 if (!mac_attr) {
11472 err = -EINVAL;
11473 goto out;
11474 }
11475
11476 n_entries = validate_acl_mac_addrs(mac_attr);
11477 if (n_entries <= 0) {
11478 err = -EINVAL;
11479 goto out;
11480 }
11481
11482 func->srf_num_macs = n_entries;
11483 func->srf_macs =
11484 kzalloc(sizeof(*func->srf_macs) * n_entries,
11485 GFP_KERNEL);
11486 if (!func->srf_macs) {
11487 err = -ENOMEM;
11488 goto out;
11489 }
11490
11491 nla_for_each_nested(attr, mac_attr, rem)
11492 memcpy(func->srf_macs[i++].addr, nla_data(attr),
11493 sizeof(*func->srf_macs));
11494 }
11495 }
11496
11497 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) {
11498 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER],
11499 func, true);
11500 if (err)
11501 goto out;
11502 }
11503
11504 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) {
11505 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER],
11506 func, false);
11507 if (err)
11508 goto out;
11509 }
11510
11511 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11512 if (!msg) {
11513 err = -ENOMEM;
11514 goto out;
11515 }
11516
11517 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
11518 NL80211_CMD_ADD_NAN_FUNCTION);
11519 /* This can't really happen - we just allocated 4KB */
11520 if (WARN_ON(!hdr)) {
11521 err = -ENOMEM;
11522 goto out;
11523 }
11524
11525 err = rdev_add_nan_func(rdev, wdev, func);
11526out:
11527 if (err < 0) {
11528 cfg80211_free_nan_func(func);
11529 nlmsg_free(msg);
11530 return err;
11531 }
11532
11533 /* propagate the instance id and cookie to userspace */
11534 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie,
11535 NL80211_ATTR_PAD))
11536 goto nla_put_failure;
11537
11538 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC);
11539 if (!func_attr)
11540 goto nla_put_failure;
11541
11542 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID,
11543 func->instance_id))
11544 goto nla_put_failure;
11545
11546 nla_nest_end(msg, func_attr);
11547
11548 genlmsg_end(msg, hdr);
11549 return genlmsg_reply(msg, info);
11550
11551nla_put_failure:
11552 nlmsg_free(msg);
11553 return -ENOBUFS;
11554}
11555
11556static int nl80211_nan_del_func(struct sk_buff *skb,
11557 struct genl_info *info)
11558{
11559 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11560 struct wireless_dev *wdev = info->user_ptr[1];
11561 u64 cookie;
11562
11563 if (wdev->iftype != NL80211_IFTYPE_NAN)
11564 return -EOPNOTSUPP;
11565
73c7da3d 11566 if (!wdev_running(wdev))
a442b761
AB
11567 return -ENOTCONN;
11568
11569 if (!info->attrs[NL80211_ATTR_COOKIE])
11570 return -EINVAL;
11571
a442b761
AB
11572 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
11573
11574 rdev_del_nan_func(rdev, wdev, cookie);
11575
11576 return 0;
11577}
11578
a5a9dcf2
AB
11579static int nl80211_nan_change_config(struct sk_buff *skb,
11580 struct genl_info *info)
11581{
11582 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11583 struct wireless_dev *wdev = info->user_ptr[1];
11584 struct cfg80211_nan_conf conf = {};
11585 u32 changed = 0;
11586
11587 if (wdev->iftype != NL80211_IFTYPE_NAN)
11588 return -EOPNOTSUPP;
11589
73c7da3d 11590 if (!wdev_running(wdev))
a5a9dcf2
AB
11591 return -ENOTCONN;
11592
11593 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) {
11594 conf.master_pref =
11595 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
11596 if (conf.master_pref <= 1 || conf.master_pref == 255)
11597 return -EINVAL;
11598
11599 changed |= CFG80211_NAN_CONF_CHANGED_PREF;
11600 }
11601
8585989d
LC
11602 if (info->attrs[NL80211_ATTR_BANDS]) {
11603 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
11604
11605 if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
11606 return -EOPNOTSUPP;
11607
11608 if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
11609 return -EINVAL;
11610
11611 conf.bands = bands;
11612 changed |= CFG80211_NAN_CONF_CHANGED_BANDS;
a5a9dcf2
AB
11613 }
11614
11615 if (!changed)
11616 return -EINVAL;
11617
11618 return rdev_nan_change_conf(rdev, wdev, &conf, changed);
11619}
11620
50bcd31d
AB
11621void cfg80211_nan_match(struct wireless_dev *wdev,
11622 struct cfg80211_nan_match_params *match, gfp_t gfp)
11623{
11624 struct wiphy *wiphy = wdev->wiphy;
11625 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
11626 struct nlattr *match_attr, *local_func_attr, *peer_func_attr;
11627 struct sk_buff *msg;
11628 void *hdr;
11629
11630 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr))
11631 return;
11632
11633 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11634 if (!msg)
11635 return;
11636
11637 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH);
11638 if (!hdr) {
11639 nlmsg_free(msg);
11640 return;
11641 }
11642
11643 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11644 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11645 wdev->netdev->ifindex)) ||
11646 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
11647 NL80211_ATTR_PAD))
11648 goto nla_put_failure;
11649
11650 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie,
11651 NL80211_ATTR_PAD) ||
11652 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr))
11653 goto nla_put_failure;
11654
11655 match_attr = nla_nest_start(msg, NL80211_ATTR_NAN_MATCH);
11656 if (!match_attr)
11657 goto nla_put_failure;
11658
11659 local_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_LOCAL);
11660 if (!local_func_attr)
11661 goto nla_put_failure;
11662
11663 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id))
11664 goto nla_put_failure;
11665
11666 nla_nest_end(msg, local_func_attr);
11667
11668 peer_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_PEER);
11669 if (!peer_func_attr)
11670 goto nla_put_failure;
11671
11672 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) ||
11673 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id))
11674 goto nla_put_failure;
11675
11676 if (match->info && match->info_len &&
11677 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len,
11678 match->info))
11679 goto nla_put_failure;
11680
11681 nla_nest_end(msg, peer_func_attr);
11682 nla_nest_end(msg, match_attr);
11683 genlmsg_end(msg, hdr);
11684
11685 if (!wdev->owner_nlportid)
11686 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
11687 msg, 0, NL80211_MCGRP_NAN, gfp);
11688 else
11689 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
11690 wdev->owner_nlportid);
11691
11692 return;
11693
11694nla_put_failure:
11695 nlmsg_free(msg);
11696}
11697EXPORT_SYMBOL(cfg80211_nan_match);
11698
368e5a7b
AB
11699void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
11700 u8 inst_id,
11701 enum nl80211_nan_func_term_reason reason,
11702 u64 cookie, gfp_t gfp)
11703{
11704 struct wiphy *wiphy = wdev->wiphy;
11705 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
11706 struct sk_buff *msg;
11707 struct nlattr *func_attr;
11708 void *hdr;
11709
11710 if (WARN_ON(!inst_id))
11711 return;
11712
11713 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
11714 if (!msg)
11715 return;
11716
11717 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION);
11718 if (!hdr) {
11719 nlmsg_free(msg);
11720 return;
11721 }
11722
11723 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
11724 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
11725 wdev->netdev->ifindex)) ||
11726 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
11727 NL80211_ATTR_PAD))
11728 goto nla_put_failure;
11729
11730 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
11731 NL80211_ATTR_PAD))
11732 goto nla_put_failure;
11733
11734 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC);
11735 if (!func_attr)
11736 goto nla_put_failure;
11737
11738 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) ||
11739 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason))
11740 goto nla_put_failure;
11741
11742 nla_nest_end(msg, func_attr);
11743 genlmsg_end(msg, hdr);
11744
11745 if (!wdev->owner_nlportid)
11746 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
11747 msg, 0, NL80211_MCGRP_NAN, gfp);
11748 else
11749 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
11750 wdev->owner_nlportid);
11751
11752 return;
11753
11754nla_put_failure:
11755 nlmsg_free(msg);
11756}
11757EXPORT_SYMBOL(cfg80211_nan_func_terminated);
11758
3713b4e3
JB
11759static int nl80211_get_protocol_features(struct sk_buff *skb,
11760 struct genl_info *info)
11761{
11762 void *hdr;
11763 struct sk_buff *msg;
11764
11765 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11766 if (!msg)
11767 return -ENOMEM;
11768
11769 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
11770 NL80211_CMD_GET_PROTOCOL_FEATURES);
11771 if (!hdr)
11772 goto nla_put_failure;
11773
11774 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
11775 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
11776 goto nla_put_failure;
11777
11778 genlmsg_end(msg, hdr);
11779 return genlmsg_reply(msg, info);
11780
11781 nla_put_failure:
11782 kfree_skb(msg);
11783 return -ENOBUFS;
11784}
11785
355199e0
JM
11786static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
11787{
11788 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11789 struct cfg80211_update_ft_ies_params ft_params;
11790 struct net_device *dev = info->user_ptr[1];
11791
11792 if (!rdev->ops->update_ft_ies)
11793 return -EOPNOTSUPP;
11794
11795 if (!info->attrs[NL80211_ATTR_MDID] ||
11796 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
11797 return -EINVAL;
11798
11799 memset(&ft_params, 0, sizeof(ft_params));
11800 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
11801 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
11802 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
11803
11804 return rdev_update_ft_ies(rdev, dev, &ft_params);
11805}
11806
5de17984
AS
11807static int nl80211_crit_protocol_start(struct sk_buff *skb,
11808 struct genl_info *info)
11809{
11810 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11811 struct wireless_dev *wdev = info->user_ptr[1];
11812 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
11813 u16 duration;
11814 int ret;
11815
11816 if (!rdev->ops->crit_proto_start)
11817 return -EOPNOTSUPP;
11818
11819 if (WARN_ON(!rdev->ops->crit_proto_stop))
11820 return -EINVAL;
11821
11822 if (rdev->crit_proto_nlportid)
11823 return -EBUSY;
11824
11825 /* determine protocol if provided */
11826 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
11827 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
11828
11829 if (proto >= NUM_NL80211_CRIT_PROTO)
11830 return -EINVAL;
11831
11832 /* timeout must be provided */
11833 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
11834 return -EINVAL;
11835
11836 duration =
11837 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
11838
11839 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
11840 return -ERANGE;
11841
11842 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
11843 if (!ret)
11844 rdev->crit_proto_nlportid = info->snd_portid;
11845
11846 return ret;
11847}
11848
11849static int nl80211_crit_protocol_stop(struct sk_buff *skb,
11850 struct genl_info *info)
11851{
11852 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11853 struct wireless_dev *wdev = info->user_ptr[1];
11854
11855 if (!rdev->ops->crit_proto_stop)
11856 return -EOPNOTSUPP;
11857
11858 if (rdev->crit_proto_nlportid) {
11859 rdev->crit_proto_nlportid = 0;
11860 rdev_crit_proto_stop(rdev, wdev);
11861 }
11862 return 0;
11863}
11864
ad7e718c
JB
11865static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
11866{
11867 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11868 struct wireless_dev *wdev =
11869 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
11870 int i, err;
11871 u32 vid, subcmd;
11872
11873 if (!rdev->wiphy.vendor_commands)
11874 return -EOPNOTSUPP;
11875
11876 if (IS_ERR(wdev)) {
11877 err = PTR_ERR(wdev);
11878 if (err != -EINVAL)
11879 return err;
11880 wdev = NULL;
11881 } else if (wdev->wiphy != &rdev->wiphy) {
11882 return -EINVAL;
11883 }
11884
11885 if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
11886 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
11887 return -EINVAL;
11888
11889 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
11890 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
11891 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
11892 const struct wiphy_vendor_command *vcmd;
11893 void *data = NULL;
11894 int len = 0;
11895
11896 vcmd = &rdev->wiphy.vendor_commands[i];
11897
11898 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
11899 continue;
11900
11901 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
11902 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
11903 if (!wdev)
11904 return -EINVAL;
11905 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
11906 !wdev->netdev)
11907 return -EINVAL;
11908
11909 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
73c7da3d 11910 if (!wdev_running(wdev))
ad7e718c
JB
11911 return -ENETDOWN;
11912 }
7bdbe400
JB
11913
11914 if (!vcmd->doit)
11915 return -EOPNOTSUPP;
ad7e718c
JB
11916 } else {
11917 wdev = NULL;
11918 }
11919
11920 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
11921 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
11922 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
11923 }
11924
11925 rdev->cur_cmd_info = info;
11926 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev,
11927 data, len);
11928 rdev->cur_cmd_info = NULL;
11929 return err;
11930 }
11931
11932 return -EOPNOTSUPP;
11933}
11934
7bdbe400
JB
11935static int nl80211_prepare_vendor_dump(struct sk_buff *skb,
11936 struct netlink_callback *cb,
11937 struct cfg80211_registered_device **rdev,
11938 struct wireless_dev **wdev)
11939{
c90c39da 11940 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam);
7bdbe400
JB
11941 u32 vid, subcmd;
11942 unsigned int i;
11943 int vcmd_idx = -1;
11944 int err;
11945 void *data = NULL;
11946 unsigned int data_len = 0;
11947
7bdbe400
JB
11948 if (cb->args[0]) {
11949 /* subtract the 1 again here */
11950 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
11951 struct wireless_dev *tmp;
11952
ea90e0dc
JB
11953 if (!wiphy)
11954 return -ENODEV;
7bdbe400
JB
11955 *rdev = wiphy_to_rdev(wiphy);
11956 *wdev = NULL;
11957
11958 if (cb->args[1]) {
53873f13 11959 list_for_each_entry(tmp, &wiphy->wdev_list, list) {
7bdbe400
JB
11960 if (tmp->identifier == cb->args[1] - 1) {
11961 *wdev = tmp;
11962 break;
11963 }
11964 }
11965 }
11966
11967 /* keep rtnl locked in successful case */
11968 return 0;
11969 }
11970
fceb6435
JB
11971 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, attrbuf,
11972 nl80211_fam.maxattr, nl80211_policy, NULL);
7bdbe400 11973 if (err)
ea90e0dc 11974 return err;
7bdbe400 11975
c90c39da 11976 if (!attrbuf[NL80211_ATTR_VENDOR_ID] ||
ea90e0dc
JB
11977 !attrbuf[NL80211_ATTR_VENDOR_SUBCMD])
11978 return -EINVAL;
7bdbe400 11979
c90c39da 11980 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk), attrbuf);
7bdbe400
JB
11981 if (IS_ERR(*wdev))
11982 *wdev = NULL;
11983
c90c39da 11984 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
ea90e0dc
JB
11985 if (IS_ERR(*rdev))
11986 return PTR_ERR(*rdev);
7bdbe400 11987
c90c39da
JB
11988 vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]);
11989 subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]);
7bdbe400
JB
11990
11991 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) {
11992 const struct wiphy_vendor_command *vcmd;
11993
11994 vcmd = &(*rdev)->wiphy.vendor_commands[i];
11995
11996 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
11997 continue;
11998
ea90e0dc
JB
11999 if (!vcmd->dumpit)
12000 return -EOPNOTSUPP;
7bdbe400
JB
12001
12002 vcmd_idx = i;
12003 break;
12004 }
12005
ea90e0dc
JB
12006 if (vcmd_idx < 0)
12007 return -EOPNOTSUPP;
7bdbe400 12008
c90c39da
JB
12009 if (attrbuf[NL80211_ATTR_VENDOR_DATA]) {
12010 data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]);
12011 data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]);
7bdbe400
JB
12012 }
12013
12014 /* 0 is the first index - add 1 to parse only once */
12015 cb->args[0] = (*rdev)->wiphy_idx + 1;
12016 /* add 1 to know if it was NULL */
12017 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0;
12018 cb->args[2] = vcmd_idx;
12019 cb->args[3] = (unsigned long)data;
12020 cb->args[4] = data_len;
12021
12022 /* keep rtnl locked in successful case */
12023 return 0;
7bdbe400
JB
12024}
12025
12026static int nl80211_vendor_cmd_dump(struct sk_buff *skb,
12027 struct netlink_callback *cb)
12028{
12029 struct cfg80211_registered_device *rdev;
12030 struct wireless_dev *wdev;
12031 unsigned int vcmd_idx;
12032 const struct wiphy_vendor_command *vcmd;
12033 void *data;
12034 int data_len;
12035 int err;
12036 struct nlattr *vendor_data;
12037
ea90e0dc 12038 rtnl_lock();
7bdbe400
JB
12039 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev);
12040 if (err)
ea90e0dc 12041 goto out;
7bdbe400
JB
12042
12043 vcmd_idx = cb->args[2];
12044 data = (void *)cb->args[3];
12045 data_len = cb->args[4];
12046 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx];
12047
12048 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
12049 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
ea90e0dc
JB
12050 if (!wdev) {
12051 err = -EINVAL;
12052 goto out;
12053 }
7bdbe400 12054 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
ea90e0dc
JB
12055 !wdev->netdev) {
12056 err = -EINVAL;
12057 goto out;
12058 }
7bdbe400
JB
12059
12060 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
ea90e0dc
JB
12061 if (!wdev_running(wdev)) {
12062 err = -ENETDOWN;
12063 goto out;
12064 }
7bdbe400
JB
12065 }
12066 }
12067
12068 while (1) {
12069 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
12070 cb->nlh->nlmsg_seq, NLM_F_MULTI,
12071 NL80211_CMD_VENDOR);
12072 if (!hdr)
12073 break;
12074
12075 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
12076 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
12077 wdev_id(wdev),
12078 NL80211_ATTR_PAD))) {
7bdbe400
JB
12079 genlmsg_cancel(skb, hdr);
12080 break;
12081 }
12082
12083 vendor_data = nla_nest_start(skb, NL80211_ATTR_VENDOR_DATA);
12084 if (!vendor_data) {
12085 genlmsg_cancel(skb, hdr);
12086 break;
12087 }
12088
12089 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len,
12090 (unsigned long *)&cb->args[5]);
12091 nla_nest_end(skb, vendor_data);
12092
12093 if (err == -ENOBUFS || err == -ENOENT) {
12094 genlmsg_cancel(skb, hdr);
12095 break;
12096 } else if (err) {
12097 genlmsg_cancel(skb, hdr);
12098 goto out;
12099 }
12100
12101 genlmsg_end(skb, hdr);
12102 }
12103
12104 err = skb->len;
12105 out:
12106 rtnl_unlock();
12107 return err;
12108}
12109
ad7e718c
JB
12110struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
12111 enum nl80211_commands cmd,
12112 enum nl80211_attrs attr,
12113 int approxlen)
12114{
f26cbf40 12115 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ad7e718c
JB
12116
12117 if (WARN_ON(!rdev->cur_cmd_info))
12118 return NULL;
12119
6c09e791 12120 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen,
ad7e718c
JB
12121 rdev->cur_cmd_info->snd_portid,
12122 rdev->cur_cmd_info->snd_seq,
567ffc35 12123 cmd, attr, NULL, GFP_KERNEL);
ad7e718c
JB
12124}
12125EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
12126
12127int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
12128{
12129 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
12130 void *hdr = ((void **)skb->cb)[1];
12131 struct nlattr *data = ((void **)skb->cb)[2];
12132
bd8c78e7
JB
12133 /* clear CB data for netlink core to own from now on */
12134 memset(skb->cb, 0, sizeof(skb->cb));
12135
ad7e718c
JB
12136 if (WARN_ON(!rdev->cur_cmd_info)) {
12137 kfree_skb(skb);
12138 return -EINVAL;
12139 }
12140
12141 nla_nest_end(skb, data);
12142 genlmsg_end(skb, hdr);
12143 return genlmsg_reply(skb, rdev->cur_cmd_info);
12144}
12145EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
12146
fa9ffc74
KP
12147static int nl80211_set_qos_map(struct sk_buff *skb,
12148 struct genl_info *info)
12149{
12150 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12151 struct cfg80211_qos_map *qos_map = NULL;
12152 struct net_device *dev = info->user_ptr[1];
12153 u8 *pos, len, num_des, des_len, des;
12154 int ret;
12155
12156 if (!rdev->ops->set_qos_map)
12157 return -EOPNOTSUPP;
12158
12159 if (info->attrs[NL80211_ATTR_QOS_MAP]) {
12160 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
12161 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
12162
12163 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN ||
12164 len > IEEE80211_QOS_MAP_LEN_MAX)
12165 return -EINVAL;
12166
12167 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
12168 if (!qos_map)
12169 return -ENOMEM;
12170
12171 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
12172 if (num_des) {
12173 des_len = num_des *
12174 sizeof(struct cfg80211_dscp_exception);
12175 memcpy(qos_map->dscp_exception, pos, des_len);
12176 qos_map->num_des = num_des;
12177 for (des = 0; des < num_des; des++) {
12178 if (qos_map->dscp_exception[des].up > 7) {
12179 kfree(qos_map);
12180 return -EINVAL;
12181 }
12182 }
12183 pos += des_len;
12184 }
12185 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
12186 }
12187
12188 wdev_lock(dev->ieee80211_ptr);
12189 ret = nl80211_key_allowed(dev->ieee80211_ptr);
12190 if (!ret)
12191 ret = rdev_set_qos_map(rdev, dev, qos_map);
12192 wdev_unlock(dev->ieee80211_ptr);
12193
12194 kfree(qos_map);
12195 return ret;
12196}
12197
960d01ac
JB
12198static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info)
12199{
12200 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12201 struct net_device *dev = info->user_ptr[1];
12202 struct wireless_dev *wdev = dev->ieee80211_ptr;
12203 const u8 *peer;
12204 u8 tsid, up;
12205 u16 admitted_time = 0;
12206 int err;
12207
723e73ac 12208 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION))
960d01ac
JB
12209 return -EOPNOTSUPP;
12210
12211 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] ||
12212 !info->attrs[NL80211_ATTR_USER_PRIO])
12213 return -EINVAL;
12214
12215 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
12216 if (tsid >= IEEE80211_NUM_TIDS)
12217 return -EINVAL;
12218
12219 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]);
12220 if (up >= IEEE80211_NUM_UPS)
12221 return -EINVAL;
12222
12223 /* WMM uses TIDs 0-7 even for TSPEC */
723e73ac 12224 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) {
960d01ac 12225 /* TODO: handle 802.11 TSPEC/admission control
723e73ac
JB
12226 * need more attributes for that (e.g. BA session requirement);
12227 * change the WMM adminssion test above to allow both then
960d01ac
JB
12228 */
12229 return -EINVAL;
12230 }
12231
12232 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
12233
12234 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) {
12235 admitted_time =
12236 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]);
12237 if (!admitted_time)
12238 return -EINVAL;
12239 }
12240
12241 wdev_lock(wdev);
12242 switch (wdev->iftype) {
12243 case NL80211_IFTYPE_STATION:
12244 case NL80211_IFTYPE_P2P_CLIENT:
12245 if (wdev->current_bss)
12246 break;
12247 err = -ENOTCONN;
12248 goto out;
12249 default:
12250 err = -EOPNOTSUPP;
12251 goto out;
12252 }
12253
12254 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time);
12255
12256 out:
12257 wdev_unlock(wdev);
12258 return err;
12259}
12260
12261static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info)
12262{
12263 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12264 struct net_device *dev = info->user_ptr[1];
12265 struct wireless_dev *wdev = dev->ieee80211_ptr;
12266 const u8 *peer;
12267 u8 tsid;
12268 int err;
12269
12270 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC])
12271 return -EINVAL;
12272
12273 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
12274 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
12275
12276 wdev_lock(wdev);
12277 err = rdev_del_tx_ts(rdev, dev, tsid, peer);
12278 wdev_unlock(wdev);
12279
12280 return err;
12281}
12282
1057d35e
AN
12283static int nl80211_tdls_channel_switch(struct sk_buff *skb,
12284 struct genl_info *info)
12285{
12286 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12287 struct net_device *dev = info->user_ptr[1];
12288 struct wireless_dev *wdev = dev->ieee80211_ptr;
12289 struct cfg80211_chan_def chandef = {};
12290 const u8 *addr;
12291 u8 oper_class;
12292 int err;
12293
12294 if (!rdev->ops->tdls_channel_switch ||
12295 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
12296 return -EOPNOTSUPP;
12297
12298 switch (dev->ieee80211_ptr->iftype) {
12299 case NL80211_IFTYPE_STATION:
12300 case NL80211_IFTYPE_P2P_CLIENT:
12301 break;
12302 default:
12303 return -EOPNOTSUPP;
12304 }
12305
12306 if (!info->attrs[NL80211_ATTR_MAC] ||
12307 !info->attrs[NL80211_ATTR_OPER_CLASS])
12308 return -EINVAL;
12309
12310 err = nl80211_parse_chandef(rdev, info, &chandef);
12311 if (err)
12312 return err;
12313
12314 /*
12315 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012
12316 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the
12317 * specification is not defined for them.
12318 */
57fbcce3 12319 if (chandef.chan->band == NL80211_BAND_2GHZ &&
1057d35e
AN
12320 chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
12321 chandef.width != NL80211_CHAN_WIDTH_20)
12322 return -EINVAL;
12323
12324 /* we will be active on the TDLS link */
923b352f
AN
12325 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
12326 wdev->iftype))
1057d35e
AN
12327 return -EINVAL;
12328
12329 /* don't allow switching to DFS channels */
12330 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype))
12331 return -EINVAL;
12332
12333 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
12334 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]);
12335
12336 wdev_lock(wdev);
12337 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef);
12338 wdev_unlock(wdev);
12339
12340 return err;
12341}
12342
12343static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb,
12344 struct genl_info *info)
12345{
12346 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12347 struct net_device *dev = info->user_ptr[1];
12348 struct wireless_dev *wdev = dev->ieee80211_ptr;
12349 const u8 *addr;
12350
12351 if (!rdev->ops->tdls_channel_switch ||
12352 !rdev->ops->tdls_cancel_channel_switch ||
12353 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
12354 return -EOPNOTSUPP;
12355
12356 switch (dev->ieee80211_ptr->iftype) {
12357 case NL80211_IFTYPE_STATION:
12358 case NL80211_IFTYPE_P2P_CLIENT:
12359 break;
12360 default:
12361 return -EOPNOTSUPP;
12362 }
12363
12364 if (!info->attrs[NL80211_ATTR_MAC])
12365 return -EINVAL;
12366
12367 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
12368
12369 wdev_lock(wdev);
12370 rdev_tdls_cancel_channel_switch(rdev, dev, addr);
12371 wdev_unlock(wdev);
12372
12373 return 0;
12374}
12375
ce0ce13a
MB
12376static int nl80211_set_multicast_to_unicast(struct sk_buff *skb,
12377 struct genl_info *info)
12378{
12379 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12380 struct net_device *dev = info->user_ptr[1];
12381 struct wireless_dev *wdev = dev->ieee80211_ptr;
12382 const struct nlattr *nla;
12383 bool enabled;
12384
ce0ce13a
MB
12385 if (!rdev->ops->set_multicast_to_unicast)
12386 return -EOPNOTSUPP;
12387
12388 if (wdev->iftype != NL80211_IFTYPE_AP &&
12389 wdev->iftype != NL80211_IFTYPE_P2P_GO)
12390 return -EOPNOTSUPP;
12391
12392 nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED];
12393 enabled = nla_get_flag(nla);
12394
12395 return rdev_set_multicast_to_unicast(rdev, dev, enabled);
12396}
12397
3a00df57
AS
12398static int nl80211_set_pmk(struct sk_buff *skb, struct genl_info *info)
12399{
12400 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12401 struct net_device *dev = info->user_ptr[1];
12402 struct wireless_dev *wdev = dev->ieee80211_ptr;
12403 struct cfg80211_pmk_conf pmk_conf = {};
12404 int ret;
12405
12406 if (wdev->iftype != NL80211_IFTYPE_STATION &&
12407 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
12408 return -EOPNOTSUPP;
12409
12410 if (!wiphy_ext_feature_isset(&rdev->wiphy,
12411 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
12412 return -EOPNOTSUPP;
12413
12414 if (!info->attrs[NL80211_ATTR_MAC] || !info->attrs[NL80211_ATTR_PMK])
12415 return -EINVAL;
12416
12417 wdev_lock(wdev);
12418 if (!wdev->current_bss) {
12419 ret = -ENOTCONN;
12420 goto out;
12421 }
12422
12423 pmk_conf.aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
12424 if (memcmp(pmk_conf.aa, wdev->current_bss->pub.bssid, ETH_ALEN)) {
12425 ret = -EINVAL;
12426 goto out;
12427 }
12428
12429 pmk_conf.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
12430 pmk_conf.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
12431 if (pmk_conf.pmk_len != WLAN_PMK_LEN &&
12432 pmk_conf.pmk_len != WLAN_PMK_LEN_SUITE_B_192) {
12433 ret = -EINVAL;
12434 goto out;
12435 }
12436
12437 if (info->attrs[NL80211_ATTR_PMKR0_NAME]) {
12438 int r0_name_len = nla_len(info->attrs[NL80211_ATTR_PMKR0_NAME]);
12439
12440 if (r0_name_len != WLAN_PMK_NAME_LEN) {
12441 ret = -EINVAL;
12442 goto out;
12443 }
12444
12445 pmk_conf.pmk_r0_name =
12446 nla_data(info->attrs[NL80211_ATTR_PMKR0_NAME]);
12447 }
12448
12449 ret = rdev_set_pmk(rdev, dev, &pmk_conf);
12450out:
12451 wdev_unlock(wdev);
12452 return ret;
12453}
12454
12455static int nl80211_del_pmk(struct sk_buff *skb, struct genl_info *info)
12456{
12457 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12458 struct net_device *dev = info->user_ptr[1];
12459 struct wireless_dev *wdev = dev->ieee80211_ptr;
12460 const u8 *aa;
12461 int ret;
12462
12463 if (wdev->iftype != NL80211_IFTYPE_STATION &&
12464 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
12465 return -EOPNOTSUPP;
12466
12467 if (!wiphy_ext_feature_isset(&rdev->wiphy,
12468 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
12469 return -EOPNOTSUPP;
12470
12471 if (!info->attrs[NL80211_ATTR_MAC])
12472 return -EINVAL;
12473
12474 wdev_lock(wdev);
12475 aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
12476 ret = rdev_del_pmk(rdev, dev, aa);
12477 wdev_unlock(wdev);
12478
12479 return ret;
12480}
12481
40cbfa90
SD
12482static int nl80211_external_auth(struct sk_buff *skb, struct genl_info *info)
12483{
12484 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12485 struct net_device *dev = info->user_ptr[1];
12486 struct cfg80211_external_auth_params params;
12487
12488 if (rdev->ops->external_auth)
12489 return -EOPNOTSUPP;
12490
12491 if (!info->attrs[NL80211_ATTR_SSID])
12492 return -EINVAL;
12493
12494 if (!info->attrs[NL80211_ATTR_BSSID])
12495 return -EINVAL;
12496
12497 if (!info->attrs[NL80211_ATTR_STATUS_CODE])
12498 return -EINVAL;
12499
12500 memset(&params, 0, sizeof(params));
12501
12502 params.ssid.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
12503 if (params.ssid.ssid_len == 0 ||
12504 params.ssid.ssid_len > IEEE80211_MAX_SSID_LEN)
12505 return -EINVAL;
12506 memcpy(params.ssid.ssid, nla_data(info->attrs[NL80211_ATTR_SSID]),
12507 params.ssid.ssid_len);
12508
12509 memcpy(params.bssid, nla_data(info->attrs[NL80211_ATTR_BSSID]),
12510 ETH_ALEN);
12511
12512 params.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
12513
12514 return rdev_external_auth(rdev, dev, &params);
12515}
12516
4c476991
JB
12517#define NL80211_FLAG_NEED_WIPHY 0x01
12518#define NL80211_FLAG_NEED_NETDEV 0x02
12519#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
12520#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
12521#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
12522 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 12523#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 12524/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
12525#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
12526 NL80211_FLAG_CHECK_NETDEV_UP)
5393b917 12527#define NL80211_FLAG_CLEAR_SKB 0x20
4c476991 12528
f84f771d 12529static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
12530 struct genl_info *info)
12531{
12532 struct cfg80211_registered_device *rdev;
89a54e48 12533 struct wireless_dev *wdev;
4c476991 12534 struct net_device *dev;
4c476991
JB
12535 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
12536
12537 if (rtnl)
12538 rtnl_lock();
12539
12540 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 12541 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
12542 if (IS_ERR(rdev)) {
12543 if (rtnl)
12544 rtnl_unlock();
12545 return PTR_ERR(rdev);
12546 }
12547 info->user_ptr[0] = rdev;
1bf614ef
JB
12548 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
12549 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
12550 ASSERT_RTNL();
12551
89a54e48
JB
12552 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
12553 info->attrs);
12554 if (IS_ERR(wdev)) {
4c476991
JB
12555 if (rtnl)
12556 rtnl_unlock();
89a54e48 12557 return PTR_ERR(wdev);
4c476991 12558 }
89a54e48 12559
89a54e48 12560 dev = wdev->netdev;
f26cbf40 12561 rdev = wiphy_to_rdev(wdev->wiphy);
89a54e48 12562
1bf614ef
JB
12563 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
12564 if (!dev) {
1bf614ef
JB
12565 if (rtnl)
12566 rtnl_unlock();
12567 return -EINVAL;
12568 }
12569
12570 info->user_ptr[1] = dev;
12571 } else {
12572 info->user_ptr[1] = wdev;
41265714 12573 }
1bf614ef 12574
73c7da3d
AVS
12575 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
12576 !wdev_running(wdev)) {
12577 if (rtnl)
12578 rtnl_unlock();
12579 return -ENETDOWN;
12580 }
1bf614ef 12581
73c7da3d 12582 if (dev)
1bf614ef 12583 dev_hold(dev);
89a54e48 12584
4c476991 12585 info->user_ptr[0] = rdev;
4c476991
JB
12586 }
12587
12588 return 0;
12589}
12590
f84f771d 12591static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
12592 struct genl_info *info)
12593{
1bf614ef
JB
12594 if (info->user_ptr[1]) {
12595 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
12596 struct wireless_dev *wdev = info->user_ptr[1];
12597
12598 if (wdev->netdev)
12599 dev_put(wdev->netdev);
12600 } else {
12601 dev_put(info->user_ptr[1]);
12602 }
12603 }
5393b917 12604
4c476991
JB
12605 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
12606 rtnl_unlock();
5393b917
JB
12607
12608 /* If needed, clear the netlink message payload from the SKB
12609 * as it might contain key data that shouldn't stick around on
12610 * the heap after the SKB is freed. The netlink message header
12611 * is still needed for further processing, so leave it intact.
12612 */
12613 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) {
12614 struct nlmsghdr *nlh = nlmsg_hdr(skb);
12615
12616 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh));
12617 }
4c476991
JB
12618}
12619
4534de83 12620static const struct genl_ops nl80211_ops[] = {
55682965
JB
12621 {
12622 .cmd = NL80211_CMD_GET_WIPHY,
12623 .doit = nl80211_get_wiphy,
12624 .dumpit = nl80211_dump_wiphy,
86e8cf98 12625 .done = nl80211_dump_wiphy_done,
55682965
JB
12626 .policy = nl80211_policy,
12627 /* can be retrieved by unprivileged users */
5fe231e8
JB
12628 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12629 NL80211_FLAG_NEED_RTNL,
55682965
JB
12630 },
12631 {
12632 .cmd = NL80211_CMD_SET_WIPHY,
12633 .doit = nl80211_set_wiphy,
12634 .policy = nl80211_policy,
5617c6cd 12635 .flags = GENL_UNS_ADMIN_PERM,
4c476991 12636 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
12637 },
12638 {
12639 .cmd = NL80211_CMD_GET_INTERFACE,
12640 .doit = nl80211_get_interface,
12641 .dumpit = nl80211_dump_interface,
12642 .policy = nl80211_policy,
12643 /* can be retrieved by unprivileged users */
5fe231e8
JB
12644 .internal_flags = NL80211_FLAG_NEED_WDEV |
12645 NL80211_FLAG_NEED_RTNL,
55682965
JB
12646 },
12647 {
12648 .cmd = NL80211_CMD_SET_INTERFACE,
12649 .doit = nl80211_set_interface,
12650 .policy = nl80211_policy,
5617c6cd 12651 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12652 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12653 NL80211_FLAG_NEED_RTNL,
55682965
JB
12654 },
12655 {
12656 .cmd = NL80211_CMD_NEW_INTERFACE,
12657 .doit = nl80211_new_interface,
12658 .policy = nl80211_policy,
5617c6cd 12659 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12660 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12661 NL80211_FLAG_NEED_RTNL,
55682965
JB
12662 },
12663 {
12664 .cmd = NL80211_CMD_DEL_INTERFACE,
12665 .doit = nl80211_del_interface,
12666 .policy = nl80211_policy,
5617c6cd 12667 .flags = GENL_UNS_ADMIN_PERM,
84efbb84 12668 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 12669 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
12670 },
12671 {
12672 .cmd = NL80211_CMD_GET_KEY,
12673 .doit = nl80211_get_key,
12674 .policy = nl80211_policy,
5617c6cd 12675 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12676 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12677 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
12678 },
12679 {
12680 .cmd = NL80211_CMD_SET_KEY,
12681 .doit = nl80211_set_key,
12682 .policy = nl80211_policy,
5617c6cd 12683 .flags = GENL_UNS_ADMIN_PERM,
41265714 12684 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
12685 NL80211_FLAG_NEED_RTNL |
12686 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
12687 },
12688 {
12689 .cmd = NL80211_CMD_NEW_KEY,
12690 .doit = nl80211_new_key,
12691 .policy = nl80211_policy,
5617c6cd 12692 .flags = GENL_UNS_ADMIN_PERM,
41265714 12693 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
12694 NL80211_FLAG_NEED_RTNL |
12695 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
12696 },
12697 {
12698 .cmd = NL80211_CMD_DEL_KEY,
12699 .doit = nl80211_del_key,
12700 .policy = nl80211_policy,
5617c6cd 12701 .flags = GENL_UNS_ADMIN_PERM,
41265714 12702 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12703 NL80211_FLAG_NEED_RTNL,
55682965 12704 },
ed1b6cc7
JB
12705 {
12706 .cmd = NL80211_CMD_SET_BEACON,
12707 .policy = nl80211_policy,
5617c6cd 12708 .flags = GENL_UNS_ADMIN_PERM,
8860020e 12709 .doit = nl80211_set_beacon,
2b5f8b0b 12710 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12711 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
12712 },
12713 {
8860020e 12714 .cmd = NL80211_CMD_START_AP,
ed1b6cc7 12715 .policy = nl80211_policy,
5617c6cd 12716 .flags = GENL_UNS_ADMIN_PERM,
8860020e 12717 .doit = nl80211_start_ap,
2b5f8b0b 12718 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12719 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
12720 },
12721 {
8860020e 12722 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7 12723 .policy = nl80211_policy,
5617c6cd 12724 .flags = GENL_UNS_ADMIN_PERM,
8860020e 12725 .doit = nl80211_stop_ap,
2b5f8b0b 12726 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12727 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 12728 },
5727ef1b
JB
12729 {
12730 .cmd = NL80211_CMD_GET_STATION,
12731 .doit = nl80211_get_station,
2ec600d6 12732 .dumpit = nl80211_dump_station,
5727ef1b 12733 .policy = nl80211_policy,
4c476991
JB
12734 .internal_flags = NL80211_FLAG_NEED_NETDEV |
12735 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
12736 },
12737 {
12738 .cmd = NL80211_CMD_SET_STATION,
12739 .doit = nl80211_set_station,
12740 .policy = nl80211_policy,
5617c6cd 12741 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12742 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12743 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
12744 },
12745 {
12746 .cmd = NL80211_CMD_NEW_STATION,
12747 .doit = nl80211_new_station,
12748 .policy = nl80211_policy,
5617c6cd 12749 .flags = GENL_UNS_ADMIN_PERM,
41265714 12750 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12751 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
12752 },
12753 {
12754 .cmd = NL80211_CMD_DEL_STATION,
12755 .doit = nl80211_del_station,
12756 .policy = nl80211_policy,
5617c6cd 12757 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12758 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12759 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
12760 },
12761 {
12762 .cmd = NL80211_CMD_GET_MPATH,
12763 .doit = nl80211_get_mpath,
12764 .dumpit = nl80211_dump_mpath,
12765 .policy = nl80211_policy,
5617c6cd 12766 .flags = GENL_UNS_ADMIN_PERM,
41265714 12767 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12768 NL80211_FLAG_NEED_RTNL,
2ec600d6 12769 },
66be7d2b
HR
12770 {
12771 .cmd = NL80211_CMD_GET_MPP,
12772 .doit = nl80211_get_mpp,
12773 .dumpit = nl80211_dump_mpp,
12774 .policy = nl80211_policy,
5617c6cd 12775 .flags = GENL_UNS_ADMIN_PERM,
66be7d2b
HR
12776 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12777 NL80211_FLAG_NEED_RTNL,
12778 },
2ec600d6
LCC
12779 {
12780 .cmd = NL80211_CMD_SET_MPATH,
12781 .doit = nl80211_set_mpath,
12782 .policy = nl80211_policy,
5617c6cd 12783 .flags = GENL_UNS_ADMIN_PERM,
41265714 12784 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12785 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
12786 },
12787 {
12788 .cmd = NL80211_CMD_NEW_MPATH,
12789 .doit = nl80211_new_mpath,
12790 .policy = nl80211_policy,
5617c6cd 12791 .flags = GENL_UNS_ADMIN_PERM,
41265714 12792 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12793 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
12794 },
12795 {
12796 .cmd = NL80211_CMD_DEL_MPATH,
12797 .doit = nl80211_del_mpath,
12798 .policy = nl80211_policy,
5617c6cd 12799 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12800 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12801 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
12802 },
12803 {
12804 .cmd = NL80211_CMD_SET_BSS,
12805 .doit = nl80211_set_bss,
12806 .policy = nl80211_policy,
5617c6cd 12807 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12808 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12809 NL80211_FLAG_NEED_RTNL,
b2e1b302 12810 },
f130347c
LR
12811 {
12812 .cmd = NL80211_CMD_GET_REG,
ad30ca2c
AN
12813 .doit = nl80211_get_reg_do,
12814 .dumpit = nl80211_get_reg_dump,
f130347c 12815 .policy = nl80211_policy,
5fe231e8 12816 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
12817 /* can be retrieved by unprivileged users */
12818 },
b6863036 12819#ifdef CONFIG_CFG80211_CRDA_SUPPORT
b2e1b302
LR
12820 {
12821 .cmd = NL80211_CMD_SET_REG,
12822 .doit = nl80211_set_reg,
12823 .policy = nl80211_policy,
12824 .flags = GENL_ADMIN_PERM,
5fe231e8 12825 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302 12826 },
b6863036 12827#endif
b2e1b302
LR
12828 {
12829 .cmd = NL80211_CMD_REQ_SET_REG,
12830 .doit = nl80211_req_set_reg,
12831 .policy = nl80211_policy,
93da9cc1 12832 .flags = GENL_ADMIN_PERM,
12833 },
1ea4ff3e
JB
12834 {
12835 .cmd = NL80211_CMD_RELOAD_REGDB,
12836 .doit = nl80211_reload_regdb,
12837 .policy = nl80211_policy,
12838 .flags = GENL_ADMIN_PERM,
12839 },
93da9cc1 12840 {
24bdd9f4
JC
12841 .cmd = NL80211_CMD_GET_MESH_CONFIG,
12842 .doit = nl80211_get_mesh_config,
93da9cc1 12843 .policy = nl80211_policy,
12844 /* can be retrieved by unprivileged users */
2b5f8b0b 12845 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12846 NL80211_FLAG_NEED_RTNL,
93da9cc1 12847 },
12848 {
24bdd9f4
JC
12849 .cmd = NL80211_CMD_SET_MESH_CONFIG,
12850 .doit = nl80211_update_mesh_config,
93da9cc1 12851 .policy = nl80211_policy,
5617c6cd 12852 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c 12853 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12854 NL80211_FLAG_NEED_RTNL,
9aed3cc1 12855 },
2a519311
JB
12856 {
12857 .cmd = NL80211_CMD_TRIGGER_SCAN,
12858 .doit = nl80211_trigger_scan,
12859 .policy = nl80211_policy,
5617c6cd 12860 .flags = GENL_UNS_ADMIN_PERM,
fd014284 12861 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 12862 NL80211_FLAG_NEED_RTNL,
2a519311 12863 },
91d3ab46
VK
12864 {
12865 .cmd = NL80211_CMD_ABORT_SCAN,
12866 .doit = nl80211_abort_scan,
12867 .policy = nl80211_policy,
5617c6cd 12868 .flags = GENL_UNS_ADMIN_PERM,
91d3ab46
VK
12869 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
12870 NL80211_FLAG_NEED_RTNL,
12871 },
2a519311
JB
12872 {
12873 .cmd = NL80211_CMD_GET_SCAN,
12874 .policy = nl80211_policy,
12875 .dumpit = nl80211_dump_scan,
12876 },
807f8a8c
LC
12877 {
12878 .cmd = NL80211_CMD_START_SCHED_SCAN,
12879 .doit = nl80211_start_sched_scan,
12880 .policy = nl80211_policy,
5617c6cd 12881 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
12882 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12883 NL80211_FLAG_NEED_RTNL,
12884 },
12885 {
12886 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
12887 .doit = nl80211_stop_sched_scan,
12888 .policy = nl80211_policy,
5617c6cd 12889 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
12890 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12891 NL80211_FLAG_NEED_RTNL,
12892 },
636a5d36
JM
12893 {
12894 .cmd = NL80211_CMD_AUTHENTICATE,
12895 .doit = nl80211_authenticate,
12896 .policy = nl80211_policy,
5617c6cd 12897 .flags = GENL_UNS_ADMIN_PERM,
41265714 12898 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
12899 NL80211_FLAG_NEED_RTNL |
12900 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
12901 },
12902 {
12903 .cmd = NL80211_CMD_ASSOCIATE,
12904 .doit = nl80211_associate,
12905 .policy = nl80211_policy,
5617c6cd 12906 .flags = GENL_UNS_ADMIN_PERM,
41265714 12907 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12908 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
12909 },
12910 {
12911 .cmd = NL80211_CMD_DEAUTHENTICATE,
12912 .doit = nl80211_deauthenticate,
12913 .policy = nl80211_policy,
5617c6cd 12914 .flags = GENL_UNS_ADMIN_PERM,
41265714 12915 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12916 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
12917 },
12918 {
12919 .cmd = NL80211_CMD_DISASSOCIATE,
12920 .doit = nl80211_disassociate,
12921 .policy = nl80211_policy,
5617c6cd 12922 .flags = GENL_UNS_ADMIN_PERM,
41265714 12923 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12924 NL80211_FLAG_NEED_RTNL,
636a5d36 12925 },
04a773ad
JB
12926 {
12927 .cmd = NL80211_CMD_JOIN_IBSS,
12928 .doit = nl80211_join_ibss,
12929 .policy = nl80211_policy,
5617c6cd 12930 .flags = GENL_UNS_ADMIN_PERM,
41265714 12931 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12932 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
12933 },
12934 {
12935 .cmd = NL80211_CMD_LEAVE_IBSS,
12936 .doit = nl80211_leave_ibss,
12937 .policy = nl80211_policy,
5617c6cd 12938 .flags = GENL_UNS_ADMIN_PERM,
41265714 12939 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12940 NL80211_FLAG_NEED_RTNL,
04a773ad 12941 },
aff89a9b
JB
12942#ifdef CONFIG_NL80211_TESTMODE
12943 {
12944 .cmd = NL80211_CMD_TESTMODE,
12945 .doit = nl80211_testmode_do,
71063f0e 12946 .dumpit = nl80211_testmode_dump,
aff89a9b 12947 .policy = nl80211_policy,
5617c6cd 12948 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12949 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12950 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
12951 },
12952#endif
b23aa676
SO
12953 {
12954 .cmd = NL80211_CMD_CONNECT,
12955 .doit = nl80211_connect,
12956 .policy = nl80211_policy,
5617c6cd 12957 .flags = GENL_UNS_ADMIN_PERM,
41265714 12958 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12959 NL80211_FLAG_NEED_RTNL,
b23aa676 12960 },
088e8df8 12961 {
12962 .cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS,
12963 .doit = nl80211_update_connect_params,
12964 .policy = nl80211_policy,
12965 .flags = GENL_ADMIN_PERM,
12966 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
12967 NL80211_FLAG_NEED_RTNL,
12968 },
b23aa676
SO
12969 {
12970 .cmd = NL80211_CMD_DISCONNECT,
12971 .doit = nl80211_disconnect,
12972 .policy = nl80211_policy,
5617c6cd 12973 .flags = GENL_UNS_ADMIN_PERM,
41265714 12974 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12975 NL80211_FLAG_NEED_RTNL,
b23aa676 12976 },
463d0183
JB
12977 {
12978 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
12979 .doit = nl80211_wiphy_netns,
12980 .policy = nl80211_policy,
5617c6cd 12981 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
12982 .internal_flags = NL80211_FLAG_NEED_WIPHY |
12983 NL80211_FLAG_NEED_RTNL,
463d0183 12984 },
61fa713c
HS
12985 {
12986 .cmd = NL80211_CMD_GET_SURVEY,
12987 .policy = nl80211_policy,
12988 .dumpit = nl80211_dump_survey,
12989 },
67fbb16b
SO
12990 {
12991 .cmd = NL80211_CMD_SET_PMKSA,
12992 .doit = nl80211_setdel_pmksa,
12993 .policy = nl80211_policy,
5617c6cd 12994 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 12995 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 12996 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
12997 },
12998 {
12999 .cmd = NL80211_CMD_DEL_PMKSA,
13000 .doit = nl80211_setdel_pmksa,
13001 .policy = nl80211_policy,
5617c6cd 13002 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13003 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13004 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
13005 },
13006 {
13007 .cmd = NL80211_CMD_FLUSH_PMKSA,
13008 .doit = nl80211_flush_pmksa,
13009 .policy = nl80211_policy,
5617c6cd 13010 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13011 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13012 NL80211_FLAG_NEED_RTNL,
67fbb16b 13013 },
9588bbd5
JM
13014 {
13015 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
13016 .doit = nl80211_remain_on_channel,
13017 .policy = nl80211_policy,
5617c6cd 13018 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 13019 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 13020 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
13021 },
13022 {
13023 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
13024 .doit = nl80211_cancel_remain_on_channel,
13025 .policy = nl80211_policy,
5617c6cd 13026 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 13027 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 13028 NL80211_FLAG_NEED_RTNL,
9588bbd5 13029 },
13ae75b1
JM
13030 {
13031 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
13032 .doit = nl80211_set_tx_bitrate_mask,
13033 .policy = nl80211_policy,
5617c6cd 13034 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
13035 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13036 NL80211_FLAG_NEED_RTNL,
13ae75b1 13037 },
026331c4 13038 {
2e161f78
JB
13039 .cmd = NL80211_CMD_REGISTER_FRAME,
13040 .doit = nl80211_register_mgmt,
026331c4 13041 .policy = nl80211_policy,
5617c6cd 13042 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 13043 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 13044 NL80211_FLAG_NEED_RTNL,
026331c4
JM
13045 },
13046 {
2e161f78
JB
13047 .cmd = NL80211_CMD_FRAME,
13048 .doit = nl80211_tx_mgmt,
026331c4 13049 .policy = nl80211_policy,
5617c6cd 13050 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 13051 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
13052 NL80211_FLAG_NEED_RTNL,
13053 },
13054 {
13055 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
13056 .doit = nl80211_tx_mgmt_cancel_wait,
13057 .policy = nl80211_policy,
5617c6cd 13058 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 13059 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 13060 NL80211_FLAG_NEED_RTNL,
026331c4 13061 },
ffb9eb3d
KV
13062 {
13063 .cmd = NL80211_CMD_SET_POWER_SAVE,
13064 .doit = nl80211_set_power_save,
13065 .policy = nl80211_policy,
5617c6cd 13066 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
13067 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13068 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
13069 },
13070 {
13071 .cmd = NL80211_CMD_GET_POWER_SAVE,
13072 .doit = nl80211_get_power_save,
13073 .policy = nl80211_policy,
13074 /* can be retrieved by unprivileged users */
4c476991
JB
13075 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13076 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 13077 },
d6dc1a38
JO
13078 {
13079 .cmd = NL80211_CMD_SET_CQM,
13080 .doit = nl80211_set_cqm,
13081 .policy = nl80211_policy,
5617c6cd 13082 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
13083 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13084 NL80211_FLAG_NEED_RTNL,
d6dc1a38 13085 },
f444de05
JB
13086 {
13087 .cmd = NL80211_CMD_SET_CHANNEL,
13088 .doit = nl80211_set_channel,
13089 .policy = nl80211_policy,
5617c6cd 13090 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
13091 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13092 NL80211_FLAG_NEED_RTNL,
f444de05 13093 },
e8347eba
BJ
13094 {
13095 .cmd = NL80211_CMD_SET_WDS_PEER,
13096 .doit = nl80211_set_wds_peer,
13097 .policy = nl80211_policy,
5617c6cd 13098 .flags = GENL_UNS_ADMIN_PERM,
43b19952
JB
13099 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13100 NL80211_FLAG_NEED_RTNL,
e8347eba 13101 },
29cbe68c
JB
13102 {
13103 .cmd = NL80211_CMD_JOIN_MESH,
13104 .doit = nl80211_join_mesh,
13105 .policy = nl80211_policy,
5617c6cd 13106 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
13107 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13108 NL80211_FLAG_NEED_RTNL,
13109 },
13110 {
13111 .cmd = NL80211_CMD_LEAVE_MESH,
13112 .doit = nl80211_leave_mesh,
13113 .policy = nl80211_policy,
5617c6cd 13114 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
13115 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13116 NL80211_FLAG_NEED_RTNL,
13117 },
6e0bd6c3
RL
13118 {
13119 .cmd = NL80211_CMD_JOIN_OCB,
13120 .doit = nl80211_join_ocb,
13121 .policy = nl80211_policy,
5617c6cd 13122 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
13123 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13124 NL80211_FLAG_NEED_RTNL,
13125 },
13126 {
13127 .cmd = NL80211_CMD_LEAVE_OCB,
13128 .doit = nl80211_leave_ocb,
13129 .policy = nl80211_policy,
5617c6cd 13130 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
13131 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13132 NL80211_FLAG_NEED_RTNL,
13133 },
dfb89c56 13134#ifdef CONFIG_PM
ff1b6e69
JB
13135 {
13136 .cmd = NL80211_CMD_GET_WOWLAN,
13137 .doit = nl80211_get_wowlan,
13138 .policy = nl80211_policy,
13139 /* can be retrieved by unprivileged users */
13140 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13141 NL80211_FLAG_NEED_RTNL,
13142 },
13143 {
13144 .cmd = NL80211_CMD_SET_WOWLAN,
13145 .doit = nl80211_set_wowlan,
13146 .policy = nl80211_policy,
5617c6cd 13147 .flags = GENL_UNS_ADMIN_PERM,
ff1b6e69
JB
13148 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13149 NL80211_FLAG_NEED_RTNL,
13150 },
dfb89c56 13151#endif
e5497d76
JB
13152 {
13153 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
13154 .doit = nl80211_set_rekey_data,
13155 .policy = nl80211_policy,
5617c6cd 13156 .flags = GENL_UNS_ADMIN_PERM,
e5497d76 13157 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
13158 NL80211_FLAG_NEED_RTNL |
13159 NL80211_FLAG_CLEAR_SKB,
e5497d76 13160 },
109086ce
AN
13161 {
13162 .cmd = NL80211_CMD_TDLS_MGMT,
13163 .doit = nl80211_tdls_mgmt,
13164 .policy = nl80211_policy,
5617c6cd 13165 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
13166 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13167 NL80211_FLAG_NEED_RTNL,
13168 },
13169 {
13170 .cmd = NL80211_CMD_TDLS_OPER,
13171 .doit = nl80211_tdls_oper,
13172 .policy = nl80211_policy,
5617c6cd 13173 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
13174 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13175 NL80211_FLAG_NEED_RTNL,
13176 },
28946da7
JB
13177 {
13178 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
13179 .doit = nl80211_register_unexpected_frame,
13180 .policy = nl80211_policy,
5617c6cd 13181 .flags = GENL_UNS_ADMIN_PERM,
28946da7
JB
13182 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13183 NL80211_FLAG_NEED_RTNL,
13184 },
7f6cf311
JB
13185 {
13186 .cmd = NL80211_CMD_PROBE_CLIENT,
13187 .doit = nl80211_probe_client,
13188 .policy = nl80211_policy,
5617c6cd 13189 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13190 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
13191 NL80211_FLAG_NEED_RTNL,
13192 },
5e760230
JB
13193 {
13194 .cmd = NL80211_CMD_REGISTER_BEACONS,
13195 .doit = nl80211_register_beacons,
13196 .policy = nl80211_policy,
5617c6cd 13197 .flags = GENL_UNS_ADMIN_PERM,
5e760230
JB
13198 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13199 NL80211_FLAG_NEED_RTNL,
13200 },
1d9d9213
SW
13201 {
13202 .cmd = NL80211_CMD_SET_NOACK_MAP,
13203 .doit = nl80211_set_noack_map,
13204 .policy = nl80211_policy,
5617c6cd 13205 .flags = GENL_UNS_ADMIN_PERM,
1d9d9213
SW
13206 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13207 NL80211_FLAG_NEED_RTNL,
13208 },
98104fde
JB
13209 {
13210 .cmd = NL80211_CMD_START_P2P_DEVICE,
13211 .doit = nl80211_start_p2p_device,
13212 .policy = nl80211_policy,
5617c6cd 13213 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
13214 .internal_flags = NL80211_FLAG_NEED_WDEV |
13215 NL80211_FLAG_NEED_RTNL,
13216 },
13217 {
13218 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
13219 .doit = nl80211_stop_p2p_device,
13220 .policy = nl80211_policy,
5617c6cd 13221 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
13222 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13223 NL80211_FLAG_NEED_RTNL,
cb3b7d87
AB
13224 },
13225 {
13226 .cmd = NL80211_CMD_START_NAN,
13227 .doit = nl80211_start_nan,
13228 .policy = nl80211_policy,
13229 .flags = GENL_ADMIN_PERM,
13230 .internal_flags = NL80211_FLAG_NEED_WDEV |
13231 NL80211_FLAG_NEED_RTNL,
13232 },
13233 {
13234 .cmd = NL80211_CMD_STOP_NAN,
13235 .doit = nl80211_stop_nan,
13236 .policy = nl80211_policy,
13237 .flags = GENL_ADMIN_PERM,
13238 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13239 NL80211_FLAG_NEED_RTNL,
a442b761
AB
13240 },
13241 {
13242 .cmd = NL80211_CMD_ADD_NAN_FUNCTION,
13243 .doit = nl80211_nan_add_func,
13244 .policy = nl80211_policy,
13245 .flags = GENL_ADMIN_PERM,
13246 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13247 NL80211_FLAG_NEED_RTNL,
13248 },
13249 {
13250 .cmd = NL80211_CMD_DEL_NAN_FUNCTION,
13251 .doit = nl80211_nan_del_func,
13252 .policy = nl80211_policy,
13253 .flags = GENL_ADMIN_PERM,
13254 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13255 NL80211_FLAG_NEED_RTNL,
a5a9dcf2
AB
13256 },
13257 {
13258 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG,
13259 .doit = nl80211_nan_change_config,
13260 .policy = nl80211_policy,
13261 .flags = GENL_ADMIN_PERM,
13262 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13263 NL80211_FLAG_NEED_RTNL,
98104fde 13264 },
f4e583c8
AQ
13265 {
13266 .cmd = NL80211_CMD_SET_MCAST_RATE,
13267 .doit = nl80211_set_mcast_rate,
77765eaf 13268 .policy = nl80211_policy,
5617c6cd 13269 .flags = GENL_UNS_ADMIN_PERM,
77765eaf
VT
13270 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13271 NL80211_FLAG_NEED_RTNL,
13272 },
13273 {
13274 .cmd = NL80211_CMD_SET_MAC_ACL,
13275 .doit = nl80211_set_mac_acl,
f4e583c8 13276 .policy = nl80211_policy,
5617c6cd 13277 .flags = GENL_UNS_ADMIN_PERM,
f4e583c8
AQ
13278 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13279 NL80211_FLAG_NEED_RTNL,
13280 },
04f39047
SW
13281 {
13282 .cmd = NL80211_CMD_RADAR_DETECT,
13283 .doit = nl80211_start_radar_detection,
13284 .policy = nl80211_policy,
5617c6cd 13285 .flags = GENL_UNS_ADMIN_PERM,
04f39047
SW
13286 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13287 NL80211_FLAG_NEED_RTNL,
13288 },
3713b4e3
JB
13289 {
13290 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
13291 .doit = nl80211_get_protocol_features,
13292 .policy = nl80211_policy,
13293 },
355199e0
JM
13294 {
13295 .cmd = NL80211_CMD_UPDATE_FT_IES,
13296 .doit = nl80211_update_ft_ies,
13297 .policy = nl80211_policy,
5617c6cd 13298 .flags = GENL_UNS_ADMIN_PERM,
355199e0
JM
13299 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13300 NL80211_FLAG_NEED_RTNL,
13301 },
5de17984
AS
13302 {
13303 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
13304 .doit = nl80211_crit_protocol_start,
13305 .policy = nl80211_policy,
5617c6cd 13306 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
13307 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13308 NL80211_FLAG_NEED_RTNL,
13309 },
13310 {
13311 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
13312 .doit = nl80211_crit_protocol_stop,
13313 .policy = nl80211_policy,
5617c6cd 13314 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
13315 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
13316 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
13317 },
13318 {
13319 .cmd = NL80211_CMD_GET_COALESCE,
13320 .doit = nl80211_get_coalesce,
13321 .policy = nl80211_policy,
13322 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13323 NL80211_FLAG_NEED_RTNL,
13324 },
13325 {
13326 .cmd = NL80211_CMD_SET_COALESCE,
13327 .doit = nl80211_set_coalesce,
13328 .policy = nl80211_policy,
5617c6cd 13329 .flags = GENL_UNS_ADMIN_PERM,
be29b99a
AK
13330 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13331 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
13332 },
13333 {
13334 .cmd = NL80211_CMD_CHANNEL_SWITCH,
13335 .doit = nl80211_channel_switch,
13336 .policy = nl80211_policy,
5617c6cd 13337 .flags = GENL_UNS_ADMIN_PERM,
16ef1fe2
SW
13338 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13339 NL80211_FLAG_NEED_RTNL,
13340 },
ad7e718c
JB
13341 {
13342 .cmd = NL80211_CMD_VENDOR,
13343 .doit = nl80211_vendor_cmd,
7bdbe400 13344 .dumpit = nl80211_vendor_cmd_dump,
ad7e718c 13345 .policy = nl80211_policy,
5617c6cd 13346 .flags = GENL_UNS_ADMIN_PERM,
ad7e718c
JB
13347 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13348 NL80211_FLAG_NEED_RTNL,
13349 },
fa9ffc74
KP
13350 {
13351 .cmd = NL80211_CMD_SET_QOS_MAP,
13352 .doit = nl80211_set_qos_map,
13353 .policy = nl80211_policy,
5617c6cd 13354 .flags = GENL_UNS_ADMIN_PERM,
fa9ffc74
KP
13355 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13356 NL80211_FLAG_NEED_RTNL,
13357 },
960d01ac
JB
13358 {
13359 .cmd = NL80211_CMD_ADD_TX_TS,
13360 .doit = nl80211_add_tx_ts,
13361 .policy = nl80211_policy,
5617c6cd 13362 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
13363 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13364 NL80211_FLAG_NEED_RTNL,
13365 },
13366 {
13367 .cmd = NL80211_CMD_DEL_TX_TS,
13368 .doit = nl80211_del_tx_ts,
13369 .policy = nl80211_policy,
5617c6cd 13370 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
13371 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13372 NL80211_FLAG_NEED_RTNL,
13373 },
1057d35e
AN
13374 {
13375 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH,
13376 .doit = nl80211_tdls_channel_switch,
13377 .policy = nl80211_policy,
5617c6cd 13378 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
13379 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13380 NL80211_FLAG_NEED_RTNL,
13381 },
13382 {
13383 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH,
13384 .doit = nl80211_tdls_cancel_channel_switch,
13385 .policy = nl80211_policy,
5617c6cd 13386 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
13387 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13388 NL80211_FLAG_NEED_RTNL,
13389 },
ce0ce13a
MB
13390 {
13391 .cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST,
13392 .doit = nl80211_set_multicast_to_unicast,
13393 .policy = nl80211_policy,
13394 .flags = GENL_UNS_ADMIN_PERM,
13395 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13396 NL80211_FLAG_NEED_RTNL,
13397 },
3a00df57
AS
13398 {
13399 .cmd = NL80211_CMD_SET_PMK,
13400 .doit = nl80211_set_pmk,
13401 .policy = nl80211_policy,
13402 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13403 NL80211_FLAG_NEED_RTNL,
13404 },
13405 {
13406 .cmd = NL80211_CMD_DEL_PMK,
13407 .doit = nl80211_del_pmk,
13408 .policy = nl80211_policy,
13409 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13410 NL80211_FLAG_NEED_RTNL,
13411 },
40cbfa90
SD
13412 {
13413 .cmd = NL80211_CMD_EXTERNAL_AUTH,
13414 .doit = nl80211_external_auth,
13415 .policy = nl80211_policy,
13416 .flags = GENL_ADMIN_PERM,
13417 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13418 NL80211_FLAG_NEED_RTNL,
13419 },
3a00df57 13420
55682965 13421};
9588bbd5 13422
56989f6d 13423static struct genl_family nl80211_fam __ro_after_init = {
489111e5
JB
13424 .name = NL80211_GENL_NAME, /* have users key off the name instead */
13425 .hdrsize = 0, /* no private header */
13426 .version = 1, /* no particular meaning now */
13427 .maxattr = NL80211_ATTR_MAX,
13428 .netnsok = true,
13429 .pre_doit = nl80211_pre_doit,
13430 .post_doit = nl80211_post_doit,
13431 .module = THIS_MODULE,
13432 .ops = nl80211_ops,
13433 .n_ops = ARRAY_SIZE(nl80211_ops),
13434 .mcgrps = nl80211_mcgrps,
13435 .n_mcgrps = ARRAY_SIZE(nl80211_mcgrps),
13436};
13437
55682965
JB
13438/* notification functions */
13439
3bb20556
JB
13440void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev,
13441 enum nl80211_commands cmd)
55682965
JB
13442{
13443 struct sk_buff *msg;
86e8cf98 13444 struct nl80211_dump_wiphy_state state = {};
55682965 13445
3bb20556
JB
13446 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY &&
13447 cmd != NL80211_CMD_DEL_WIPHY);
13448
fd2120ca 13449 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
13450 if (!msg)
13451 return;
13452
3bb20556 13453 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) {
55682965
JB
13454 nlmsg_free(msg);
13455 return;
13456 }
13457
68eb5503 13458 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13459 NL80211_MCGRP_CONFIG, GFP_KERNEL);
55682965
JB
13460}
13461
896ff063
DK
13462void nl80211_notify_iface(struct cfg80211_registered_device *rdev,
13463 struct wireless_dev *wdev,
13464 enum nl80211_commands cmd)
13465{
13466 struct sk_buff *msg;
13467
13468 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE &&
13469 cmd != NL80211_CMD_DEL_INTERFACE);
13470
13471 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13472 if (!msg)
13473 return;
13474
13475 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev,
13476 cmd == NL80211_CMD_DEL_INTERFACE) < 0) {
13477 nlmsg_free(msg);
13478 return;
13479 }
13480
13481 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
13482 NL80211_MCGRP_CONFIG, GFP_KERNEL);
13483}
13484
362a415d
JB
13485static int nl80211_add_scan_req(struct sk_buff *msg,
13486 struct cfg80211_registered_device *rdev)
13487{
13488 struct cfg80211_scan_request *req = rdev->scan_req;
13489 struct nlattr *nest;
13490 int i;
13491
13492 if (WARN_ON(!req))
13493 return 0;
13494
13495 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
13496 if (!nest)
13497 goto nla_put_failure;
9360ffd1
DM
13498 for (i = 0; i < req->n_ssids; i++) {
13499 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
13500 goto nla_put_failure;
13501 }
362a415d
JB
13502 nla_nest_end(msg, nest);
13503
13504 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
13505 if (!nest)
13506 goto nla_put_failure;
9360ffd1
DM
13507 for (i = 0; i < req->n_channels; i++) {
13508 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
13509 goto nla_put_failure;
13510 }
362a415d
JB
13511 nla_nest_end(msg, nest);
13512
9360ffd1
DM
13513 if (req->ie &&
13514 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
13515 goto nla_put_failure;
362a415d 13516
ae917c9f
JB
13517 if (req->flags &&
13518 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
13519 goto nla_put_failure;
ed473771 13520
1d76250b
AS
13521 if (req->info.scan_start_tsf &&
13522 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF,
13523 req->info.scan_start_tsf, NL80211_BSS_PAD) ||
13524 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN,
13525 req->info.tsf_bssid)))
13526 goto nla_put_failure;
13527
362a415d
JB
13528 return 0;
13529 nla_put_failure:
13530 return -ENOBUFS;
13531}
13532
505a2e88 13533static int nl80211_prep_scan_msg(struct sk_buff *msg,
a538e2d5 13534 struct cfg80211_registered_device *rdev,
fd014284 13535 struct wireless_dev *wdev,
15e47304 13536 u32 portid, u32 seq, int flags,
a538e2d5 13537 u32 cmd)
2a519311
JB
13538{
13539 void *hdr;
13540
15e47304 13541 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
13542 if (!hdr)
13543 return -1;
13544
9360ffd1 13545 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
13546 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
13547 wdev->netdev->ifindex)) ||
2dad624e
ND
13548 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
13549 NL80211_ATTR_PAD))
9360ffd1 13550 goto nla_put_failure;
2a519311 13551
362a415d
JB
13552 /* ignore errors and send incomplete event anyway */
13553 nl80211_add_scan_req(msg, rdev);
2a519311 13554
053c095a
JB
13555 genlmsg_end(msg, hdr);
13556 return 0;
2a519311
JB
13557
13558 nla_put_failure:
13559 genlmsg_cancel(msg, hdr);
13560 return -EMSGSIZE;
13561}
13562
807f8a8c 13563static int
505a2e88 13564nl80211_prep_sched_scan_msg(struct sk_buff *msg,
96b08fd6 13565 struct cfg80211_sched_scan_request *req, u32 cmd)
807f8a8c
LC
13566{
13567 void *hdr;
13568
96b08fd6 13569 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
807f8a8c
LC
13570 if (!hdr)
13571 return -1;
13572
96b08fd6
AVS
13573 if (nla_put_u32(msg, NL80211_ATTR_WIPHY,
13574 wiphy_to_rdev(req->wiphy)->wiphy_idx) ||
13575 nla_put_u32(msg, NL80211_ATTR_IFINDEX, req->dev->ifindex) ||
13576 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, req->reqid,
13577 NL80211_ATTR_PAD))
9360ffd1 13578 goto nla_put_failure;
807f8a8c 13579
053c095a
JB
13580 genlmsg_end(msg, hdr);
13581 return 0;
807f8a8c
LC
13582
13583 nla_put_failure:
13584 genlmsg_cancel(msg, hdr);
13585 return -EMSGSIZE;
13586}
13587
a538e2d5 13588void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 13589 struct wireless_dev *wdev)
a538e2d5
JB
13590{
13591 struct sk_buff *msg;
13592
58050fce 13593 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
13594 if (!msg)
13595 return;
13596
505a2e88 13597 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
13598 NL80211_CMD_TRIGGER_SCAN) < 0) {
13599 nlmsg_free(msg);
13600 return;
13601 }
13602
68eb5503 13603 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13604 NL80211_MCGRP_SCAN, GFP_KERNEL);
a538e2d5
JB
13605}
13606
f9d15d16
JB
13607struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev,
13608 struct wireless_dev *wdev, bool aborted)
2a519311
JB
13609{
13610 struct sk_buff *msg;
13611
fd2120ca 13612 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311 13613 if (!msg)
f9d15d16 13614 return NULL;
2a519311 13615
505a2e88 13616 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
f9d15d16
JB
13617 aborted ? NL80211_CMD_SCAN_ABORTED :
13618 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311 13619 nlmsg_free(msg);
f9d15d16 13620 return NULL;
2a519311
JB
13621 }
13622
f9d15d16 13623 return msg;
2a519311
JB
13624}
13625
505a2e88
AVS
13626/* send message created by nl80211_build_scan_msg() */
13627void nl80211_send_scan_msg(struct cfg80211_registered_device *rdev,
13628 struct sk_buff *msg)
807f8a8c 13629{
807f8a8c
LC
13630 if (!msg)
13631 return;
13632
68eb5503 13633 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13634 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
13635}
13636
96b08fd6 13637void nl80211_send_sched_scan(struct cfg80211_sched_scan_request *req, u32 cmd)
807f8a8c
LC
13638{
13639 struct sk_buff *msg;
13640
58050fce 13641 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
13642 if (!msg)
13643 return;
13644
96b08fd6 13645 if (nl80211_prep_sched_scan_msg(msg, req, cmd) < 0) {
807f8a8c
LC
13646 nlmsg_free(msg);
13647 return;
13648 }
13649
96b08fd6 13650 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(req->wiphy), msg, 0,
2a94fe48 13651 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
13652}
13653
b0d7aa59
JD
13654static bool nl80211_reg_change_event_fill(struct sk_buff *msg,
13655 struct regulatory_request *request)
73d54c9e 13656{
73d54c9e 13657 /* Userspace can always count this one always being set */
9360ffd1
DM
13658 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
13659 goto nla_put_failure;
13660
13661 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
13662 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
13663 NL80211_REGDOM_TYPE_WORLD))
13664 goto nla_put_failure;
13665 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
13666 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
13667 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
13668 goto nla_put_failure;
13669 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
13670 request->intersect) {
13671 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
13672 NL80211_REGDOM_TYPE_INTERSECTION))
13673 goto nla_put_failure;
13674 } else {
13675 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
13676 NL80211_REGDOM_TYPE_COUNTRY) ||
13677 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
13678 request->alpha2))
13679 goto nla_put_failure;
13680 }
13681
ad30ca2c
AN
13682 if (request->wiphy_idx != WIPHY_IDX_INVALID) {
13683 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx);
13684
13685 if (wiphy &&
13686 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
13687 goto nla_put_failure;
1bdd716c
AN
13688
13689 if (wiphy &&
13690 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
13691 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
13692 goto nla_put_failure;
ad30ca2c 13693 }
73d54c9e 13694
b0d7aa59
JD
13695 return true;
13696
13697nla_put_failure:
13698 return false;
13699}
13700
13701/*
13702 * This can happen on global regulatory changes or device specific settings
13703 * based on custom regulatory domains.
13704 */
13705void nl80211_common_reg_change_event(enum nl80211_commands cmd_id,
13706 struct regulatory_request *request)
13707{
13708 struct sk_buff *msg;
13709 void *hdr;
13710
13711 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13712 if (!msg)
13713 return;
13714
13715 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id);
13716 if (!hdr) {
13717 nlmsg_free(msg);
13718 return;
13719 }
13720
13721 if (nl80211_reg_change_event_fill(msg, request) == false)
13722 goto nla_put_failure;
13723
3b7b72ee 13724 genlmsg_end(msg, hdr);
73d54c9e 13725
bc43b28c 13726 rcu_read_lock();
68eb5503 13727 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 13728 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
bc43b28c 13729 rcu_read_unlock();
73d54c9e
LR
13730
13731 return;
13732
13733nla_put_failure:
13734 genlmsg_cancel(msg, hdr);
13735 nlmsg_free(msg);
13736}
13737
6039f6d2
JM
13738static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
13739 struct net_device *netdev,
13740 const u8 *buf, size_t len,
b0b6aa2c
EP
13741 enum nl80211_commands cmd, gfp_t gfp,
13742 int uapsd_queues)
6039f6d2
JM
13743{
13744 struct sk_buff *msg;
13745 void *hdr;
13746
4ef8c1c9 13747 msg = nlmsg_new(100 + len, gfp);
6039f6d2
JM
13748 if (!msg)
13749 return;
13750
13751 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
13752 if (!hdr) {
13753 nlmsg_free(msg);
13754 return;
13755 }
13756
9360ffd1
DM
13757 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13758 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13759 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
13760 goto nla_put_failure;
6039f6d2 13761
b0b6aa2c
EP
13762 if (uapsd_queues >= 0) {
13763 struct nlattr *nla_wmm =
13764 nla_nest_start(msg, NL80211_ATTR_STA_WME);
13765 if (!nla_wmm)
13766 goto nla_put_failure;
13767
13768 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
13769 uapsd_queues))
13770 goto nla_put_failure;
13771
13772 nla_nest_end(msg, nla_wmm);
13773 }
13774
3b7b72ee 13775 genlmsg_end(msg, hdr);
6039f6d2 13776
68eb5503 13777 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13778 NL80211_MCGRP_MLME, gfp);
6039f6d2
JM
13779 return;
13780
13781 nla_put_failure:
13782 genlmsg_cancel(msg, hdr);
13783 nlmsg_free(msg);
13784}
13785
13786void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13787 struct net_device *netdev, const u8 *buf,
13788 size_t len, gfp_t gfp)
6039f6d2
JM
13789{
13790 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 13791 NL80211_CMD_AUTHENTICATE, gfp, -1);
6039f6d2
JM
13792}
13793
13794void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
13795 struct net_device *netdev, const u8 *buf,
b0b6aa2c 13796 size_t len, gfp_t gfp, int uapsd_queues)
6039f6d2 13797{
e6d6e342 13798 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 13799 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues);
6039f6d2
JM
13800}
13801
53b46b84 13802void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13803 struct net_device *netdev, const u8 *buf,
13804 size_t len, gfp_t gfp)
6039f6d2
JM
13805{
13806 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 13807 NL80211_CMD_DEAUTHENTICATE, gfp, -1);
6039f6d2
JM
13808}
13809
53b46b84
JM
13810void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
13811 struct net_device *netdev, const u8 *buf,
e6d6e342 13812 size_t len, gfp_t gfp)
6039f6d2
JM
13813{
13814 nl80211_send_mlme_event(rdev, netdev, buf, len,
b0b6aa2c 13815 NL80211_CMD_DISASSOCIATE, gfp, -1);
6039f6d2
JM
13816}
13817
6ff57cf8
JB
13818void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
13819 size_t len)
cf4e594e 13820{
947add36
JB
13821 struct wireless_dev *wdev = dev->ieee80211_ptr;
13822 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 13823 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
6ff57cf8
JB
13824 const struct ieee80211_mgmt *mgmt = (void *)buf;
13825 u32 cmd;
947add36 13826
6ff57cf8
JB
13827 if (WARN_ON(len < 2))
13828 return;
cf4e594e 13829
6ff57cf8
JB
13830 if (ieee80211_is_deauth(mgmt->frame_control))
13831 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
13832 else
13833 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 13834
6ff57cf8 13835 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
b0b6aa2c 13836 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1);
cf4e594e 13837}
6ff57cf8 13838EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 13839
1b06bb40
LR
13840static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
13841 struct net_device *netdev, int cmd,
e6d6e342 13842 const u8 *addr, gfp_t gfp)
1965c853
JM
13843{
13844 struct sk_buff *msg;
13845 void *hdr;
13846
e6d6e342 13847 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
13848 if (!msg)
13849 return;
13850
13851 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
13852 if (!hdr) {
13853 nlmsg_free(msg);
13854 return;
13855 }
13856
9360ffd1
DM
13857 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13858 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13859 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
13860 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
13861 goto nla_put_failure;
1965c853 13862
3b7b72ee 13863 genlmsg_end(msg, hdr);
1965c853 13864
68eb5503 13865 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13866 NL80211_MCGRP_MLME, gfp);
1965c853
JM
13867 return;
13868
13869 nla_put_failure:
13870 genlmsg_cancel(msg, hdr);
13871 nlmsg_free(msg);
13872}
13873
13874void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13875 struct net_device *netdev, const u8 *addr,
13876 gfp_t gfp)
1965c853
JM
13877{
13878 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 13879 addr, gfp);
1965c853
JM
13880}
13881
13882void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
13883 struct net_device *netdev, const u8 *addr,
13884 gfp_t gfp)
1965c853 13885{
e6d6e342
JB
13886 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
13887 addr, gfp);
1965c853
JM
13888}
13889
b23aa676 13890void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5349a0f7
VK
13891 struct net_device *netdev,
13892 struct cfg80211_connect_resp_params *cr,
3093ebbe 13893 gfp_t gfp)
b23aa676
SO
13894{
13895 struct sk_buff *msg;
13896 void *hdr;
13897
a3caf744
VK
13898 msg = nlmsg_new(100 + cr->req_ie_len + cr->resp_ie_len +
13899 cr->fils_kek_len + cr->pmk_len +
13900 (cr->pmkid ? WLAN_PMKID_LEN : 0), gfp);
b23aa676
SO
13901 if (!msg)
13902 return;
13903
13904 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
13905 if (!hdr) {
13906 nlmsg_free(msg);
13907 return;
13908 }
13909
9360ffd1
DM
13910 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13911 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
5349a0f7
VK
13912 (cr->bssid &&
13913 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, cr->bssid)) ||
bf1ecd21 13914 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE,
5349a0f7
VK
13915 cr->status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE :
13916 cr->status) ||
13917 (cr->status < 0 &&
3093ebbe 13918 (nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
5349a0f7
VK
13919 nla_put_u32(msg, NL80211_ATTR_TIMEOUT_REASON,
13920 cr->timeout_reason))) ||
13921 (cr->req_ie &&
13922 nla_put(msg, NL80211_ATTR_REQ_IE, cr->req_ie_len, cr->req_ie)) ||
13923 (cr->resp_ie &&
13924 nla_put(msg, NL80211_ATTR_RESP_IE, cr->resp_ie_len,
a3caf744
VK
13925 cr->resp_ie)) ||
13926 (cr->update_erp_next_seq_num &&
13927 nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
13928 cr->fils_erp_next_seq_num)) ||
13929 (cr->status == WLAN_STATUS_SUCCESS &&
13930 ((cr->fils_kek &&
13931 nla_put(msg, NL80211_ATTR_FILS_KEK, cr->fils_kek_len,
13932 cr->fils_kek)) ||
13933 (cr->pmk &&
13934 nla_put(msg, NL80211_ATTR_PMK, cr->pmk_len, cr->pmk)) ||
13935 (cr->pmkid &&
13936 nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, cr->pmkid)))))
9360ffd1 13937 goto nla_put_failure;
b23aa676 13938
3b7b72ee 13939 genlmsg_end(msg, hdr);
b23aa676 13940
68eb5503 13941 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13942 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
13943 return;
13944
13945 nla_put_failure:
13946 genlmsg_cancel(msg, hdr);
13947 nlmsg_free(msg);
b23aa676
SO
13948}
13949
13950void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
29ce6ecb
AS
13951 struct net_device *netdev,
13952 struct cfg80211_roam_info *info, gfp_t gfp)
b23aa676
SO
13953{
13954 struct sk_buff *msg;
13955 void *hdr;
29ce6ecb 13956 const u8 *bssid = info->bss ? info->bss->bssid : info->bssid;
b23aa676 13957
29ce6ecb 13958 msg = nlmsg_new(100 + info->req_ie_len + info->resp_ie_len, gfp);
b23aa676
SO
13959 if (!msg)
13960 return;
13961
13962 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
13963 if (!hdr) {
13964 nlmsg_free(msg);
13965 return;
13966 }
13967
9360ffd1
DM
13968 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13969 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
13970 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
29ce6ecb
AS
13971 (info->req_ie &&
13972 nla_put(msg, NL80211_ATTR_REQ_IE, info->req_ie_len,
13973 info->req_ie)) ||
13974 (info->resp_ie &&
13975 nla_put(msg, NL80211_ATTR_RESP_IE, info->resp_ie_len,
503c1fb9 13976 info->resp_ie)))
9360ffd1 13977 goto nla_put_failure;
b23aa676 13978
3b7b72ee 13979 genlmsg_end(msg, hdr);
b23aa676 13980
68eb5503 13981 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 13982 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
13983 return;
13984
503c1fb9
AS
13985 nla_put_failure:
13986 genlmsg_cancel(msg, hdr);
13987 nlmsg_free(msg);
13988}
13989
13990void nl80211_send_port_authorized(struct cfg80211_registered_device *rdev,
13991 struct net_device *netdev, const u8 *bssid)
13992{
13993 struct sk_buff *msg;
13994 void *hdr;
13995
13996 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13997 if (!msg)
13998 return;
13999
14000 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PORT_AUTHORIZED);
14001 if (!hdr) {
14002 nlmsg_free(msg);
14003 return;
14004 }
14005
14006 if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
14007 goto nla_put_failure;
14008
14009 genlmsg_end(msg, hdr);
14010
14011 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
14012 NL80211_MCGRP_MLME, GFP_KERNEL);
14013 return;
14014
b23aa676
SO
14015 nla_put_failure:
14016 genlmsg_cancel(msg, hdr);
14017 nlmsg_free(msg);
b23aa676
SO
14018}
14019
14020void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
14021 struct net_device *netdev, u16 reason,
667503dd 14022 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
14023{
14024 struct sk_buff *msg;
14025 void *hdr;
14026
4ef8c1c9 14027 msg = nlmsg_new(100 + ie_len, GFP_KERNEL);
b23aa676
SO
14028 if (!msg)
14029 return;
14030
14031 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
14032 if (!hdr) {
14033 nlmsg_free(msg);
14034 return;
14035 }
14036
9360ffd1
DM
14037 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14038 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
86b6c465 14039 (reason &&
9360ffd1
DM
14040 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
14041 (from_ap &&
14042 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
14043 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
14044 goto nla_put_failure;
b23aa676 14045
3b7b72ee 14046 genlmsg_end(msg, hdr);
b23aa676 14047
68eb5503 14048 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14049 NL80211_MCGRP_MLME, GFP_KERNEL);
b23aa676
SO
14050 return;
14051
14052 nla_put_failure:
14053 genlmsg_cancel(msg, hdr);
14054 nlmsg_free(msg);
b23aa676
SO
14055}
14056
04a773ad
JB
14057void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
14058 struct net_device *netdev, const u8 *bssid,
14059 gfp_t gfp)
14060{
14061 struct sk_buff *msg;
14062 void *hdr;
14063
fd2120ca 14064 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
14065 if (!msg)
14066 return;
14067
14068 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
14069 if (!hdr) {
14070 nlmsg_free(msg);
14071 return;
14072 }
14073
9360ffd1
DM
14074 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14075 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
14076 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
14077 goto nla_put_failure;
04a773ad 14078
3b7b72ee 14079 genlmsg_end(msg, hdr);
04a773ad 14080
68eb5503 14081 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14082 NL80211_MCGRP_MLME, gfp);
04a773ad
JB
14083 return;
14084
14085 nla_put_failure:
14086 genlmsg_cancel(msg, hdr);
14087 nlmsg_free(msg);
14088}
14089
947add36
JB
14090void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
14091 const u8* ie, u8 ie_len, gfp_t gfp)
c93b5e71 14092{
947add36 14093 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 14094 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
c93b5e71
JC
14095 struct sk_buff *msg;
14096 void *hdr;
14097
947add36
JB
14098 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
14099 return;
14100
14101 trace_cfg80211_notify_new_peer_candidate(dev, addr);
14102
4ef8c1c9 14103 msg = nlmsg_new(100 + ie_len, gfp);
c93b5e71
JC
14104 if (!msg)
14105 return;
14106
14107 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
14108 if (!hdr) {
14109 nlmsg_free(msg);
14110 return;
14111 }
14112
9360ffd1 14113 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
14114 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
14115 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1
DM
14116 (ie_len && ie &&
14117 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
14118 goto nla_put_failure;
c93b5e71 14119
3b7b72ee 14120 genlmsg_end(msg, hdr);
c93b5e71 14121
68eb5503 14122 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14123 NL80211_MCGRP_MLME, gfp);
c93b5e71
JC
14124 return;
14125
14126 nla_put_failure:
14127 genlmsg_cancel(msg, hdr);
14128 nlmsg_free(msg);
14129}
947add36 14130EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 14131
a3b8b056
JM
14132void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
14133 struct net_device *netdev, const u8 *addr,
14134 enum nl80211_key_type key_type, int key_id,
e6d6e342 14135 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
14136{
14137 struct sk_buff *msg;
14138 void *hdr;
14139
e6d6e342 14140 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
14141 if (!msg)
14142 return;
14143
14144 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
14145 if (!hdr) {
14146 nlmsg_free(msg);
14147 return;
14148 }
14149
9360ffd1
DM
14150 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14151 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
14152 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
14153 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
14154 (key_id != -1 &&
14155 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
14156 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
14157 goto nla_put_failure;
a3b8b056 14158
3b7b72ee 14159 genlmsg_end(msg, hdr);
a3b8b056 14160
68eb5503 14161 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14162 NL80211_MCGRP_MLME, gfp);
a3b8b056
JM
14163 return;
14164
14165 nla_put_failure:
14166 genlmsg_cancel(msg, hdr);
14167 nlmsg_free(msg);
14168}
14169
6bad8766
LR
14170void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
14171 struct ieee80211_channel *channel_before,
14172 struct ieee80211_channel *channel_after)
14173{
14174 struct sk_buff *msg;
14175 void *hdr;
14176 struct nlattr *nl_freq;
14177
fd2120ca 14178 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
14179 if (!msg)
14180 return;
14181
14182 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
14183 if (!hdr) {
14184 nlmsg_free(msg);
14185 return;
14186 }
14187
14188 /*
14189 * Since we are applying the beacon hint to a wiphy we know its
14190 * wiphy_idx is valid
14191 */
9360ffd1
DM
14192 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
14193 goto nla_put_failure;
6bad8766
LR
14194
14195 /* Before */
14196 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
14197 if (!nl_freq)
14198 goto nla_put_failure;
cdc89b97 14199 if (nl80211_msg_put_channel(msg, channel_before, false))
6bad8766
LR
14200 goto nla_put_failure;
14201 nla_nest_end(msg, nl_freq);
14202
14203 /* After */
14204 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
14205 if (!nl_freq)
14206 goto nla_put_failure;
cdc89b97 14207 if (nl80211_msg_put_channel(msg, channel_after, false))
6bad8766
LR
14208 goto nla_put_failure;
14209 nla_nest_end(msg, nl_freq);
14210
3b7b72ee 14211 genlmsg_end(msg, hdr);
6bad8766 14212
463d0183 14213 rcu_read_lock();
68eb5503 14214 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 14215 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
463d0183 14216 rcu_read_unlock();
6bad8766
LR
14217
14218 return;
14219
14220nla_put_failure:
14221 genlmsg_cancel(msg, hdr);
14222 nlmsg_free(msg);
14223}
14224
9588bbd5
JM
14225static void nl80211_send_remain_on_chan_event(
14226 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 14227 struct wireless_dev *wdev, u64 cookie,
9588bbd5 14228 struct ieee80211_channel *chan,
9588bbd5
JM
14229 unsigned int duration, gfp_t gfp)
14230{
14231 struct sk_buff *msg;
14232 void *hdr;
14233
14234 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14235 if (!msg)
14236 return;
14237
14238 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
14239 if (!hdr) {
14240 nlmsg_free(msg);
14241 return;
14242 }
14243
9360ffd1 14244 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
14245 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14246 wdev->netdev->ifindex)) ||
2dad624e
ND
14247 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14248 NL80211_ATTR_PAD) ||
9360ffd1 14249 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
14250 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
14251 NL80211_CHAN_NO_HT) ||
2dad624e
ND
14252 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
14253 NL80211_ATTR_PAD))
9360ffd1 14254 goto nla_put_failure;
9588bbd5 14255
9360ffd1
DM
14256 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
14257 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
14258 goto nla_put_failure;
9588bbd5 14259
3b7b72ee 14260 genlmsg_end(msg, hdr);
9588bbd5 14261
68eb5503 14262 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14263 NL80211_MCGRP_MLME, gfp);
9588bbd5
JM
14264 return;
14265
14266 nla_put_failure:
14267 genlmsg_cancel(msg, hdr);
14268 nlmsg_free(msg);
14269}
14270
947add36
JB
14271void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
14272 struct ieee80211_channel *chan,
14273 unsigned int duration, gfp_t gfp)
9588bbd5 14274{
947add36 14275 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14276 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
14277
14278 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 14279 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 14280 rdev, wdev, cookie, chan,
42d97a59 14281 duration, gfp);
9588bbd5 14282}
947add36 14283EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 14284
947add36
JB
14285void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
14286 struct ieee80211_channel *chan,
14287 gfp_t gfp)
9588bbd5 14288{
947add36 14289 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14290 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
14291
14292 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 14293 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 14294 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 14295}
947add36 14296EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 14297
947add36
JB
14298void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
14299 struct station_info *sinfo, gfp_t gfp)
98b62183 14300{
947add36 14301 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 14302 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
98b62183
JB
14303 struct sk_buff *msg;
14304
947add36
JB
14305 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
14306
58050fce 14307 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
14308 if (!msg)
14309 return;
14310
cf5ead82 14311 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0,
66266b3a 14312 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
14313 nlmsg_free(msg);
14314 return;
14315 }
14316
68eb5503 14317 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14318 NL80211_MCGRP_MLME, gfp);
98b62183 14319}
947add36 14320EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 14321
cf5ead82
JB
14322void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr,
14323 struct station_info *sinfo, gfp_t gfp)
ec15e68b 14324{
947add36 14325 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 14326 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ec15e68b 14327 struct sk_buff *msg;
cf5ead82
JB
14328 struct station_info empty_sinfo = {};
14329
14330 if (!sinfo)
14331 sinfo = &empty_sinfo;
ec15e68b 14332
947add36
JB
14333 trace_cfg80211_del_sta(dev, mac_addr);
14334
58050fce 14335 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
ec15e68b
JM
14336 if (!msg)
14337 return;
14338
cf5ead82 14339 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0,
57007121 14340 rdev, dev, mac_addr, sinfo) < 0) {
ec15e68b
JM
14341 nlmsg_free(msg);
14342 return;
14343 }
14344
68eb5503 14345 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14346 NL80211_MCGRP_MLME, gfp);
ec15e68b 14347}
cf5ead82 14348EXPORT_SYMBOL(cfg80211_del_sta_sinfo);
ec15e68b 14349
947add36
JB
14350void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
14351 enum nl80211_connect_failed_reason reason,
14352 gfp_t gfp)
ed44a951 14353{
947add36 14354 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 14355 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ed44a951
PP
14356 struct sk_buff *msg;
14357 void *hdr;
14358
14359 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
14360 if (!msg)
14361 return;
14362
14363 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
14364 if (!hdr) {
14365 nlmsg_free(msg);
14366 return;
14367 }
14368
14369 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
14370 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
14371 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
14372 goto nla_put_failure;
14373
14374 genlmsg_end(msg, hdr);
14375
68eb5503 14376 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14377 NL80211_MCGRP_MLME, gfp);
ed44a951
PP
14378 return;
14379
14380 nla_put_failure:
14381 genlmsg_cancel(msg, hdr);
14382 nlmsg_free(msg);
14383}
947add36 14384EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 14385
b92ab5d8
JB
14386static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
14387 const u8 *addr, gfp_t gfp)
28946da7
JB
14388{
14389 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 14390 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
28946da7
JB
14391 struct sk_buff *msg;
14392 void *hdr;
6aa7de05 14393 u32 nlportid = READ_ONCE(wdev->ap_unexpected_nlportid);
28946da7 14394
15e47304 14395 if (!nlportid)
28946da7
JB
14396 return false;
14397
14398 msg = nlmsg_new(100, gfp);
14399 if (!msg)
14400 return true;
14401
b92ab5d8 14402 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
14403 if (!hdr) {
14404 nlmsg_free(msg);
14405 return true;
14406 }
14407
9360ffd1
DM
14408 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14409 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
14410 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
14411 goto nla_put_failure;
28946da7 14412
9c90a9f6 14413 genlmsg_end(msg, hdr);
15e47304 14414 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
14415 return true;
14416
14417 nla_put_failure:
14418 genlmsg_cancel(msg, hdr);
14419 nlmsg_free(msg);
14420 return true;
14421}
14422
947add36
JB
14423bool cfg80211_rx_spurious_frame(struct net_device *dev,
14424 const u8 *addr, gfp_t gfp)
b92ab5d8 14425{
947add36
JB
14426 struct wireless_dev *wdev = dev->ieee80211_ptr;
14427 bool ret;
14428
14429 trace_cfg80211_rx_spurious_frame(dev, addr);
14430
14431 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
14432 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
14433 trace_cfg80211_return_bool(false);
14434 return false;
14435 }
14436 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
14437 addr, gfp);
14438 trace_cfg80211_return_bool(ret);
14439 return ret;
b92ab5d8 14440}
947add36 14441EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 14442
947add36
JB
14443bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
14444 const u8 *addr, gfp_t gfp)
b92ab5d8 14445{
947add36
JB
14446 struct wireless_dev *wdev = dev->ieee80211_ptr;
14447 bool ret;
14448
14449 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
14450
14451 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
14452 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
14453 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
14454 trace_cfg80211_return_bool(false);
14455 return false;
14456 }
14457 ret = __nl80211_unexpected_frame(dev,
14458 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
14459 addr, gfp);
14460 trace_cfg80211_return_bool(ret);
14461 return ret;
b92ab5d8 14462}
947add36 14463EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 14464
2e161f78 14465int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 14466 struct wireless_dev *wdev, u32 nlportid,
804483e9 14467 int freq, int sig_dbm,
19504cf5 14468 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 14469{
71bbc994 14470 struct net_device *netdev = wdev->netdev;
026331c4
JM
14471 struct sk_buff *msg;
14472 void *hdr;
026331c4 14473
4ef8c1c9 14474 msg = nlmsg_new(100 + len, gfp);
026331c4
JM
14475 if (!msg)
14476 return -ENOMEM;
14477
2e161f78 14478 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
14479 if (!hdr) {
14480 nlmsg_free(msg);
14481 return -ENOMEM;
14482 }
14483
9360ffd1 14484 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
14485 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14486 netdev->ifindex)) ||
2dad624e
ND
14487 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14488 NL80211_ATTR_PAD) ||
9360ffd1
DM
14489 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
14490 (sig_dbm &&
14491 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
14492 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
14493 (flags &&
14494 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 14495 goto nla_put_failure;
026331c4 14496
3b7b72ee 14497 genlmsg_end(msg, hdr);
026331c4 14498
15e47304 14499 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
14500
14501 nla_put_failure:
14502 genlmsg_cancel(msg, hdr);
14503 nlmsg_free(msg);
14504 return -ENOBUFS;
14505}
14506
947add36
JB
14507void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
14508 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 14509{
947add36 14510 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14511 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
71bbc994 14512 struct net_device *netdev = wdev->netdev;
026331c4
JM
14513 struct sk_buff *msg;
14514 void *hdr;
14515
947add36
JB
14516 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
14517
4ef8c1c9 14518 msg = nlmsg_new(100 + len, gfp);
026331c4
JM
14519 if (!msg)
14520 return;
14521
2e161f78 14522 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
14523 if (!hdr) {
14524 nlmsg_free(msg);
14525 return;
14526 }
14527
9360ffd1 14528 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
14529 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14530 netdev->ifindex)) ||
2dad624e
ND
14531 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14532 NL80211_ATTR_PAD) ||
9360ffd1 14533 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
2dad624e
ND
14534 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
14535 NL80211_ATTR_PAD) ||
9360ffd1
DM
14536 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
14537 goto nla_put_failure;
026331c4 14538
3b7b72ee 14539 genlmsg_end(msg, hdr);
026331c4 14540
68eb5503 14541 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14542 NL80211_MCGRP_MLME, gfp);
026331c4
JM
14543 return;
14544
14545 nla_put_failure:
14546 genlmsg_cancel(msg, hdr);
14547 nlmsg_free(msg);
14548}
947add36 14549EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 14550
5b97f49d
JB
14551static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev,
14552 const char *mac, gfp_t gfp)
d6dc1a38 14553{
947add36 14554 struct wireless_dev *wdev = dev->ieee80211_ptr;
5b97f49d
JB
14555 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
14556 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14557 void **cb;
947add36 14558
d6dc1a38 14559 if (!msg)
5b97f49d 14560 return NULL;
d6dc1a38 14561
5b97f49d
JB
14562 cb = (void **)msg->cb;
14563
14564 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
14565 if (!cb[0]) {
d6dc1a38 14566 nlmsg_free(msg);
5b97f49d 14567 return NULL;
d6dc1a38
JO
14568 }
14569
9360ffd1 14570 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 14571 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 14572 goto nla_put_failure;
d6dc1a38 14573
5b97f49d 14574 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
d6dc1a38
JO
14575 goto nla_put_failure;
14576
5b97f49d
JB
14577 cb[1] = nla_nest_start(msg, NL80211_ATTR_CQM);
14578 if (!cb[1])
9360ffd1 14579 goto nla_put_failure;
d6dc1a38 14580
5b97f49d 14581 cb[2] = rdev;
d6dc1a38 14582
5b97f49d
JB
14583 return msg;
14584 nla_put_failure:
14585 nlmsg_free(msg);
14586 return NULL;
14587}
14588
14589static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp)
14590{
14591 void **cb = (void **)msg->cb;
14592 struct cfg80211_registered_device *rdev = cb[2];
14593
14594 nla_nest_end(msg, cb[1]);
14595 genlmsg_end(msg, cb[0]);
14596
14597 memset(msg->cb, 0, sizeof(msg->cb));
d6dc1a38 14598
68eb5503 14599 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14600 NL80211_MCGRP_MLME, gfp);
5b97f49d
JB
14601}
14602
14603void cfg80211_cqm_rssi_notify(struct net_device *dev,
14604 enum nl80211_cqm_rssi_threshold_event rssi_event,
bee427b8 14605 s32 rssi_level, gfp_t gfp)
5b97f49d
JB
14606{
14607 struct sk_buff *msg;
4a4b8169
AZ
14608 struct wireless_dev *wdev = dev->ieee80211_ptr;
14609 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
5b97f49d 14610
bee427b8 14611 trace_cfg80211_cqm_rssi_notify(dev, rssi_event, rssi_level);
5b97f49d 14612
98f03342
JB
14613 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW &&
14614 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH))
14615 return;
14616
4a4b8169
AZ
14617 if (wdev->cqm_config) {
14618 wdev->cqm_config->last_rssi_event_value = rssi_level;
14619
14620 cfg80211_cqm_rssi_update(rdev, dev);
14621
14622 if (rssi_level == 0)
14623 rssi_level = wdev->cqm_config->last_rssi_event_value;
14624 }
14625
5b97f49d
JB
14626 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
14627 if (!msg)
14628 return;
14629
14630 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
14631 rssi_event))
14632 goto nla_put_failure;
14633
bee427b8
AZ
14634 if (rssi_level && nla_put_s32(msg, NL80211_ATTR_CQM_RSSI_LEVEL,
14635 rssi_level))
14636 goto nla_put_failure;
14637
5b97f49d
JB
14638 cfg80211_send_cqm(msg, gfp);
14639
d6dc1a38
JO
14640 return;
14641
14642 nla_put_failure:
d6dc1a38
JO
14643 nlmsg_free(msg);
14644}
947add36 14645EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 14646
5b97f49d
JB
14647void cfg80211_cqm_txe_notify(struct net_device *dev,
14648 const u8 *peer, u32 num_packets,
14649 u32 rate, u32 intvl, gfp_t gfp)
14650{
14651 struct sk_buff *msg;
14652
14653 msg = cfg80211_prepare_cqm(dev, peer, gfp);
14654 if (!msg)
14655 return;
14656
14657 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
14658 goto nla_put_failure;
14659
14660 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
14661 goto nla_put_failure;
14662
14663 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
14664 goto nla_put_failure;
14665
14666 cfg80211_send_cqm(msg, gfp);
14667 return;
14668
14669 nla_put_failure:
14670 nlmsg_free(msg);
14671}
14672EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
14673
14674void cfg80211_cqm_pktloss_notify(struct net_device *dev,
14675 const u8 *peer, u32 num_packets, gfp_t gfp)
14676{
14677 struct sk_buff *msg;
14678
14679 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
14680
14681 msg = cfg80211_prepare_cqm(dev, peer, gfp);
14682 if (!msg)
14683 return;
14684
14685 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
14686 goto nla_put_failure;
14687
14688 cfg80211_send_cqm(msg, gfp);
14689 return;
14690
14691 nla_put_failure:
14692 nlmsg_free(msg);
14693}
14694EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
14695
98f03342
JB
14696void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp)
14697{
14698 struct sk_buff *msg;
14699
14700 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
14701 if (!msg)
14702 return;
14703
14704 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT))
14705 goto nla_put_failure;
14706
14707 cfg80211_send_cqm(msg, gfp);
14708 return;
14709
14710 nla_put_failure:
14711 nlmsg_free(msg);
14712}
14713EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify);
14714
947add36
JB
14715static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
14716 struct net_device *netdev, const u8 *bssid,
14717 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
14718{
14719 struct sk_buff *msg;
14720 struct nlattr *rekey_attr;
14721 void *hdr;
14722
58050fce 14723 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
14724 if (!msg)
14725 return;
14726
14727 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
14728 if (!hdr) {
14729 nlmsg_free(msg);
14730 return;
14731 }
14732
9360ffd1
DM
14733 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14734 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
14735 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
14736 goto nla_put_failure;
e5497d76
JB
14737
14738 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
14739 if (!rekey_attr)
14740 goto nla_put_failure;
14741
9360ffd1
DM
14742 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
14743 NL80211_REPLAY_CTR_LEN, replay_ctr))
14744 goto nla_put_failure;
e5497d76
JB
14745
14746 nla_nest_end(msg, rekey_attr);
14747
3b7b72ee 14748 genlmsg_end(msg, hdr);
e5497d76 14749
68eb5503 14750 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14751 NL80211_MCGRP_MLME, gfp);
e5497d76
JB
14752 return;
14753
14754 nla_put_failure:
14755 genlmsg_cancel(msg, hdr);
14756 nlmsg_free(msg);
14757}
14758
947add36
JB
14759void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
14760 const u8 *replay_ctr, gfp_t gfp)
14761{
14762 struct wireless_dev *wdev = dev->ieee80211_ptr;
14763 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14764 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
14765
14766 trace_cfg80211_gtk_rekey_notify(dev, bssid);
14767 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
14768}
14769EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
14770
14771static void
14772nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
14773 struct net_device *netdev, int index,
14774 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
14775{
14776 struct sk_buff *msg;
14777 struct nlattr *attr;
14778 void *hdr;
14779
58050fce 14780 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
14781 if (!msg)
14782 return;
14783
14784 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
14785 if (!hdr) {
14786 nlmsg_free(msg);
14787 return;
14788 }
14789
9360ffd1
DM
14790 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14791 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
14792 goto nla_put_failure;
c9df56b4
JM
14793
14794 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
14795 if (!attr)
14796 goto nla_put_failure;
14797
9360ffd1
DM
14798 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
14799 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
14800 (preauth &&
14801 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
14802 goto nla_put_failure;
c9df56b4
JM
14803
14804 nla_nest_end(msg, attr);
14805
3b7b72ee 14806 genlmsg_end(msg, hdr);
c9df56b4 14807
68eb5503 14808 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14809 NL80211_MCGRP_MLME, gfp);
c9df56b4
JM
14810 return;
14811
14812 nla_put_failure:
14813 genlmsg_cancel(msg, hdr);
14814 nlmsg_free(msg);
14815}
14816
947add36
JB
14817void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
14818 const u8 *bssid, bool preauth, gfp_t gfp)
14819{
14820 struct wireless_dev *wdev = dev->ieee80211_ptr;
14821 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14822 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
14823
14824 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
14825 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
14826}
14827EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
14828
14829static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
14830 struct net_device *netdev,
14831 struct cfg80211_chan_def *chandef,
f8d7552e
LC
14832 gfp_t gfp,
14833 enum nl80211_commands notif,
14834 u8 count)
5314526b
TP
14835{
14836 struct sk_buff *msg;
14837 void *hdr;
14838
58050fce 14839 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
14840 if (!msg)
14841 return;
14842
f8d7552e 14843 hdr = nl80211hdr_put(msg, 0, 0, 0, notif);
5314526b
TP
14844 if (!hdr) {
14845 nlmsg_free(msg);
14846 return;
14847 }
14848
683b6d3b
JB
14849 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
14850 goto nla_put_failure;
14851
14852 if (nl80211_send_chandef(msg, chandef))
7eab0f64 14853 goto nla_put_failure;
5314526b 14854
f8d7552e
LC
14855 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) &&
14856 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count)))
14857 goto nla_put_failure;
14858
5314526b
TP
14859 genlmsg_end(msg, hdr);
14860
68eb5503 14861 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14862 NL80211_MCGRP_MLME, gfp);
5314526b
TP
14863 return;
14864
14865 nla_put_failure:
14866 genlmsg_cancel(msg, hdr);
14867 nlmsg_free(msg);
14868}
14869
947add36
JB
14870void cfg80211_ch_switch_notify(struct net_device *dev,
14871 struct cfg80211_chan_def *chandef)
84f10708 14872{
947add36
JB
14873 struct wireless_dev *wdev = dev->ieee80211_ptr;
14874 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 14875 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36 14876
e487eaeb 14877 ASSERT_WDEV_LOCK(wdev);
947add36 14878
e487eaeb 14879 trace_cfg80211_ch_switch_notify(dev, chandef);
947add36 14880
9e0e2961 14881 wdev->chandef = *chandef;
96f55f12 14882 wdev->preset_chandef = *chandef;
f8d7552e
LC
14883 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
14884 NL80211_CMD_CH_SWITCH_NOTIFY, 0);
947add36
JB
14885}
14886EXPORT_SYMBOL(cfg80211_ch_switch_notify);
14887
f8d7552e
LC
14888void cfg80211_ch_switch_started_notify(struct net_device *dev,
14889 struct cfg80211_chan_def *chandef,
14890 u8 count)
14891{
14892 struct wireless_dev *wdev = dev->ieee80211_ptr;
14893 struct wiphy *wiphy = wdev->wiphy;
14894 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
14895
14896 trace_cfg80211_ch_switch_started_notify(dev, chandef);
14897
14898 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
14899 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count);
14900}
14901EXPORT_SYMBOL(cfg80211_ch_switch_started_notify);
14902
04f39047
SW
14903void
14904nl80211_radar_notify(struct cfg80211_registered_device *rdev,
d2859df5 14905 const struct cfg80211_chan_def *chandef,
04f39047
SW
14906 enum nl80211_radar_event event,
14907 struct net_device *netdev, gfp_t gfp)
14908{
14909 struct sk_buff *msg;
14910 void *hdr;
14911
14912 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
14913 if (!msg)
14914 return;
14915
14916 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
14917 if (!hdr) {
14918 nlmsg_free(msg);
14919 return;
14920 }
14921
14922 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
14923 goto nla_put_failure;
14924
14925 /* NOP and radar events don't need a netdev parameter */
14926 if (netdev) {
14927 struct wireless_dev *wdev = netdev->ieee80211_ptr;
14928
14929 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
2dad624e
ND
14930 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14931 NL80211_ATTR_PAD))
04f39047
SW
14932 goto nla_put_failure;
14933 }
14934
14935 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
14936 goto nla_put_failure;
14937
14938 if (nl80211_send_chandef(msg, chandef))
14939 goto nla_put_failure;
14940
9c90a9f6 14941 genlmsg_end(msg, hdr);
04f39047 14942
68eb5503 14943 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14944 NL80211_MCGRP_MLME, gfp);
04f39047
SW
14945 return;
14946
14947 nla_put_failure:
14948 genlmsg_cancel(msg, hdr);
14949 nlmsg_free(msg);
14950}
14951
7f6cf311
JB
14952void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
14953 u64 cookie, bool acked, gfp_t gfp)
14954{
14955 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 14956 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
7f6cf311
JB
14957 struct sk_buff *msg;
14958 void *hdr;
7f6cf311 14959
4ee3e063
BL
14960 trace_cfg80211_probe_status(dev, addr, cookie, acked);
14961
58050fce 14962 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 14963
7f6cf311
JB
14964 if (!msg)
14965 return;
14966
14967 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
14968 if (!hdr) {
14969 nlmsg_free(msg);
14970 return;
14971 }
14972
9360ffd1
DM
14973 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14974 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
14975 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
2dad624e
ND
14976 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
14977 NL80211_ATTR_PAD) ||
9360ffd1
DM
14978 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
14979 goto nla_put_failure;
7f6cf311 14980
9c90a9f6 14981 genlmsg_end(msg, hdr);
7f6cf311 14982
68eb5503 14983 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14984 NL80211_MCGRP_MLME, gfp);
7f6cf311
JB
14985 return;
14986
14987 nla_put_failure:
14988 genlmsg_cancel(msg, hdr);
14989 nlmsg_free(msg);
14990}
14991EXPORT_SYMBOL(cfg80211_probe_status);
14992
5e760230
JB
14993void cfg80211_report_obss_beacon(struct wiphy *wiphy,
14994 const u8 *frame, size_t len,
37c73b5f 14995 int freq, int sig_dbm)
5e760230 14996{
f26cbf40 14997 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
5e760230
JB
14998 struct sk_buff *msg;
14999 void *hdr;
37c73b5f 15000 struct cfg80211_beacon_registration *reg;
5e760230 15001
4ee3e063
BL
15002 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
15003
37c73b5f
BG
15004 spin_lock_bh(&rdev->beacon_registrations_lock);
15005 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
15006 msg = nlmsg_new(len + 100, GFP_ATOMIC);
15007 if (!msg) {
15008 spin_unlock_bh(&rdev->beacon_registrations_lock);
15009 return;
15010 }
5e760230 15011
37c73b5f
BG
15012 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
15013 if (!hdr)
15014 goto nla_put_failure;
5e760230 15015
37c73b5f
BG
15016 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15017 (freq &&
15018 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
15019 (sig_dbm &&
15020 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
15021 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
15022 goto nla_put_failure;
5e760230 15023
37c73b5f 15024 genlmsg_end(msg, hdr);
5e760230 15025
37c73b5f
BG
15026 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
15027 }
15028 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
15029 return;
15030
15031 nla_put_failure:
37c73b5f
BG
15032 spin_unlock_bh(&rdev->beacon_registrations_lock);
15033 if (hdr)
15034 genlmsg_cancel(msg, hdr);
5e760230
JB
15035 nlmsg_free(msg);
15036}
15037EXPORT_SYMBOL(cfg80211_report_obss_beacon);
15038
cd8f7cb4 15039#ifdef CONFIG_PM
8cd4d456
LC
15040static int cfg80211_net_detect_results(struct sk_buff *msg,
15041 struct cfg80211_wowlan_wakeup *wakeup)
15042{
15043 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect;
15044 struct nlattr *nl_results, *nl_match, *nl_freqs;
15045 int i, j;
15046
15047 nl_results = nla_nest_start(
15048 msg, NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS);
15049 if (!nl_results)
15050 return -EMSGSIZE;
15051
15052 for (i = 0; i < nd->n_matches; i++) {
15053 struct cfg80211_wowlan_nd_match *match = nd->matches[i];
15054
15055 nl_match = nla_nest_start(msg, i);
15056 if (!nl_match)
15057 break;
15058
15059 /* The SSID attribute is optional in nl80211, but for
15060 * simplicity reasons it's always present in the
15061 * cfg80211 structure. If a driver can't pass the
15062 * SSID, that needs to be changed. A zero length SSID
15063 * is still a valid SSID (wildcard), so it cannot be
15064 * used for this purpose.
15065 */
15066 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len,
15067 match->ssid.ssid)) {
15068 nla_nest_cancel(msg, nl_match);
15069 goto out;
15070 }
15071
15072 if (match->n_channels) {
15073 nl_freqs = nla_nest_start(
15074 msg, NL80211_ATTR_SCAN_FREQUENCIES);
15075 if (!nl_freqs) {
15076 nla_nest_cancel(msg, nl_match);
15077 goto out;
15078 }
15079
15080 for (j = 0; j < match->n_channels; j++) {
5528fae8 15081 if (nla_put_u32(msg, j, match->channels[j])) {
8cd4d456
LC
15082 nla_nest_cancel(msg, nl_freqs);
15083 nla_nest_cancel(msg, nl_match);
15084 goto out;
15085 }
15086 }
15087
15088 nla_nest_end(msg, nl_freqs);
15089 }
15090
15091 nla_nest_end(msg, nl_match);
15092 }
15093
15094out:
15095 nla_nest_end(msg, nl_results);
15096 return 0;
15097}
15098
cd8f7cb4
JB
15099void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
15100 struct cfg80211_wowlan_wakeup *wakeup,
15101 gfp_t gfp)
15102{
f26cbf40 15103 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
cd8f7cb4
JB
15104 struct sk_buff *msg;
15105 void *hdr;
9c90a9f6 15106 int size = 200;
cd8f7cb4
JB
15107
15108 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
15109
15110 if (wakeup)
15111 size += wakeup->packet_present_len;
15112
15113 msg = nlmsg_new(size, gfp);
15114 if (!msg)
15115 return;
15116
15117 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
15118 if (!hdr)
15119 goto free_msg;
15120
15121 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
15122 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15123 NL80211_ATTR_PAD))
cd8f7cb4
JB
15124 goto free_msg;
15125
15126 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
15127 wdev->netdev->ifindex))
15128 goto free_msg;
15129
15130 if (wakeup) {
15131 struct nlattr *reasons;
15132
15133 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
7fa322c8
JB
15134 if (!reasons)
15135 goto free_msg;
cd8f7cb4
JB
15136
15137 if (wakeup->disconnect &&
15138 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
15139 goto free_msg;
15140 if (wakeup->magic_pkt &&
15141 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
15142 goto free_msg;
15143 if (wakeup->gtk_rekey_failure &&
15144 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
15145 goto free_msg;
15146 if (wakeup->eap_identity_req &&
15147 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
15148 goto free_msg;
15149 if (wakeup->four_way_handshake &&
15150 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
15151 goto free_msg;
15152 if (wakeup->rfkill_release &&
15153 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
15154 goto free_msg;
15155
15156 if (wakeup->pattern_idx >= 0 &&
15157 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
15158 wakeup->pattern_idx))
15159 goto free_msg;
15160
ae917c9f
JB
15161 if (wakeup->tcp_match &&
15162 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
15163 goto free_msg;
2a0e047e 15164
ae917c9f
JB
15165 if (wakeup->tcp_connlost &&
15166 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
15167 goto free_msg;
2a0e047e 15168
ae917c9f
JB
15169 if (wakeup->tcp_nomoretokens &&
15170 nla_put_flag(msg,
15171 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
15172 goto free_msg;
2a0e047e 15173
cd8f7cb4
JB
15174 if (wakeup->packet) {
15175 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
15176 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
15177
15178 if (!wakeup->packet_80211) {
15179 pkt_attr =
15180 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
15181 len_attr =
15182 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
15183 }
15184
15185 if (wakeup->packet_len &&
15186 nla_put_u32(msg, len_attr, wakeup->packet_len))
15187 goto free_msg;
15188
15189 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
15190 wakeup->packet))
15191 goto free_msg;
15192 }
15193
8cd4d456
LC
15194 if (wakeup->net_detect &&
15195 cfg80211_net_detect_results(msg, wakeup))
15196 goto free_msg;
15197
cd8f7cb4
JB
15198 nla_nest_end(msg, reasons);
15199 }
15200
9c90a9f6 15201 genlmsg_end(msg, hdr);
cd8f7cb4 15202
68eb5503 15203 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15204 NL80211_MCGRP_MLME, gfp);
cd8f7cb4
JB
15205 return;
15206
15207 free_msg:
15208 nlmsg_free(msg);
15209}
15210EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
15211#endif
15212
3475b094
JM
15213void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
15214 enum nl80211_tdls_operation oper,
15215 u16 reason_code, gfp_t gfp)
15216{
15217 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 15218 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
3475b094
JM
15219 struct sk_buff *msg;
15220 void *hdr;
3475b094
JM
15221
15222 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
15223 reason_code);
15224
15225 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
15226 if (!msg)
15227 return;
15228
15229 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
15230 if (!hdr) {
15231 nlmsg_free(msg);
15232 return;
15233 }
15234
15235 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15236 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
15237 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
15238 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
15239 (reason_code > 0 &&
15240 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
15241 goto nla_put_failure;
15242
9c90a9f6 15243 genlmsg_end(msg, hdr);
3475b094 15244
68eb5503 15245 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15246 NL80211_MCGRP_MLME, gfp);
3475b094
JM
15247 return;
15248
15249 nla_put_failure:
15250 genlmsg_cancel(msg, hdr);
15251 nlmsg_free(msg);
15252}
15253EXPORT_SYMBOL(cfg80211_tdls_oper_request);
15254
026331c4
JM
15255static int nl80211_netlink_notify(struct notifier_block * nb,
15256 unsigned long state,
15257 void *_notify)
15258{
15259 struct netlink_notify *notify = _notify;
15260 struct cfg80211_registered_device *rdev;
15261 struct wireless_dev *wdev;
37c73b5f 15262 struct cfg80211_beacon_registration *reg, *tmp;
026331c4 15263
8f815cdd 15264 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
026331c4
JM
15265 return NOTIFY_DONE;
15266
15267 rcu_read_lock();
15268
5e760230 15269 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
ca986ad9 15270 struct cfg80211_sched_scan_request *sched_scan_req;
753aacfd 15271
ca986ad9
AVS
15272 list_for_each_entry_rcu(sched_scan_req,
15273 &rdev->sched_scan_req_list,
15274 list) {
15275 if (sched_scan_req->owner_nlportid == notify->portid) {
15276 sched_scan_req->nl_owner_dead = true;
753aacfd 15277 schedule_work(&rdev->sched_scan_stop_wk);
ca986ad9 15278 }
753aacfd 15279 }
78f22b6a 15280
53873f13 15281 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) {
15e47304 15282 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f 15283
ab81007a
JB
15284 if (wdev->owner_nlportid == notify->portid) {
15285 wdev->nl_owner_dead = true;
15286 schedule_work(&rdev->destroy_work);
15287 } else if (wdev->conn_owner_nlportid == notify->portid) {
bd2522b1 15288 schedule_work(&wdev->disconnect_wk);
ab81007a 15289 }
78f22b6a
JB
15290 }
15291
37c73b5f
BG
15292 spin_lock_bh(&rdev->beacon_registrations_lock);
15293 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
15294 list) {
15295 if (reg->nlportid == notify->portid) {
15296 list_del(&reg->list);
15297 kfree(reg);
15298 break;
15299 }
15300 }
15301 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 15302 }
026331c4
JM
15303
15304 rcu_read_unlock();
15305
05050753
I
15306 /*
15307 * It is possible that the user space process that is controlling the
15308 * indoor setting disappeared, so notify the regulatory core.
15309 */
15310 regulatory_netlink_notify(notify->portid);
6784c7db 15311 return NOTIFY_OK;
026331c4
JM
15312}
15313
15314static struct notifier_block nl80211_netlink_notifier = {
15315 .notifier_call = nl80211_netlink_notify,
15316};
15317
355199e0
JM
15318void cfg80211_ft_event(struct net_device *netdev,
15319 struct cfg80211_ft_event_params *ft_event)
15320{
15321 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
f26cbf40 15322 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
355199e0
JM
15323 struct sk_buff *msg;
15324 void *hdr;
355199e0
JM
15325
15326 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
15327
15328 if (!ft_event->target_ap)
15329 return;
15330
4ef8c1c9 15331 msg = nlmsg_new(100 + ft_event->ric_ies_len, GFP_KERNEL);
355199e0
JM
15332 if (!msg)
15333 return;
15334
15335 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
ae917c9f
JB
15336 if (!hdr)
15337 goto out;
355199e0 15338
ae917c9f
JB
15339 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15340 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15341 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
15342 goto out;
355199e0 15343
ae917c9f
JB
15344 if (ft_event->ies &&
15345 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
15346 goto out;
15347 if (ft_event->ric_ies &&
15348 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
15349 ft_event->ric_ies))
15350 goto out;
355199e0 15351
9c90a9f6 15352 genlmsg_end(msg, hdr);
355199e0 15353
68eb5503 15354 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15355 NL80211_MCGRP_MLME, GFP_KERNEL);
ae917c9f
JB
15356 return;
15357 out:
15358 nlmsg_free(msg);
355199e0
JM
15359}
15360EXPORT_SYMBOL(cfg80211_ft_event);
15361
5de17984
AS
15362void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
15363{
15364 struct cfg80211_registered_device *rdev;
15365 struct sk_buff *msg;
15366 void *hdr;
15367 u32 nlportid;
15368
f26cbf40 15369 rdev = wiphy_to_rdev(wdev->wiphy);
5de17984
AS
15370 if (!rdev->crit_proto_nlportid)
15371 return;
15372
15373 nlportid = rdev->crit_proto_nlportid;
15374 rdev->crit_proto_nlportid = 0;
15375
15376 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
15377 if (!msg)
15378 return;
15379
15380 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
15381 if (!hdr)
15382 goto nla_put_failure;
15383
15384 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
15385 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15386 NL80211_ATTR_PAD))
5de17984
AS
15387 goto nla_put_failure;
15388
15389 genlmsg_end(msg, hdr);
15390
15391 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
15392 return;
15393
15394 nla_put_failure:
15395 if (hdr)
15396 genlmsg_cancel(msg, hdr);
15397 nlmsg_free(msg);
5de17984
AS
15398}
15399EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
15400
348baf0e
JB
15401void nl80211_send_ap_stopped(struct wireless_dev *wdev)
15402{
15403 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 15404 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
348baf0e
JB
15405 struct sk_buff *msg;
15406 void *hdr;
15407
15408 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
15409 if (!msg)
15410 return;
15411
15412 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP);
15413 if (!hdr)
15414 goto out;
15415
15416 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15417 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
2dad624e
ND
15418 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15419 NL80211_ATTR_PAD))
348baf0e
JB
15420 goto out;
15421
15422 genlmsg_end(msg, hdr);
15423
15424 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
15425 NL80211_MCGRP_MLME, GFP_KERNEL);
15426 return;
15427 out:
15428 nlmsg_free(msg);
15429}
15430
40cbfa90
SD
15431int cfg80211_external_auth_request(struct net_device *dev,
15432 struct cfg80211_external_auth_params *params,
15433 gfp_t gfp)
15434{
15435 struct wireless_dev *wdev = dev->ieee80211_ptr;
15436 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
15437 struct sk_buff *msg;
15438 void *hdr;
15439
15440 if (!wdev->conn_owner_nlportid)
15441 return -EINVAL;
15442
15443 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
15444 if (!msg)
15445 return -ENOMEM;
15446
15447 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_EXTERNAL_AUTH);
15448 if (!hdr)
15449 goto nla_put_failure;
15450
15451 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15452 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
15453 nla_put_u32(msg, NL80211_ATTR_AKM_SUITES, params->key_mgmt_suite) ||
15454 nla_put_u32(msg, NL80211_ATTR_EXTERNAL_AUTH_ACTION,
15455 params->action) ||
15456 nla_put(msg, NL80211_ATTR_BSSID, ETH_ALEN, params->bssid) ||
15457 nla_put(msg, NL80211_ATTR_SSID, params->ssid.ssid_len,
15458 params->ssid.ssid))
15459 goto nla_put_failure;
15460
15461 genlmsg_end(msg, hdr);
15462 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
15463 wdev->conn_owner_nlportid);
15464 return 0;
15465
15466 nla_put_failure:
15467 nlmsg_free(msg);
15468 return -ENOBUFS;
15469}
15470EXPORT_SYMBOL(cfg80211_external_auth_request);
15471
55682965
JB
15472/* initialisation/exit functions */
15473
56989f6d 15474int __init nl80211_init(void)
55682965 15475{
0d63cbb5 15476 int err;
55682965 15477
489111e5 15478 err = genl_register_family(&nl80211_fam);
55682965
JB
15479 if (err)
15480 return err;
15481
026331c4
JM
15482 err = netlink_register_notifier(&nl80211_netlink_notifier);
15483 if (err)
15484 goto err_out;
15485
55682965
JB
15486 return 0;
15487 err_out:
15488 genl_unregister_family(&nl80211_fam);
15489 return err;
15490}
15491
15492void nl80211_exit(void)
15493{
026331c4 15494 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
15495 genl_unregister_family(&nl80211_fam);
15496}