cfg80211: add support for parsing OBBS_PD attributes
[linux-block.git] / net / wireless / nl80211.c
CommitLineData
457c8996 1// SPDX-License-Identifier: GPL-2.0-only
55682965
JB
2/*
3 * This is the new netlink-based wireless configuration interface.
4 *
026331c4 5 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
2740f0cf 6 * Copyright 2013-2014 Intel Mobile Communications GmbH
66cd794e 7 * Copyright 2015-2017 Intel Deutschland GmbH
55c1fdf0 8 * Copyright (C) 2018-2019 Intel Corporation
55682965
JB
9 */
10
11#include <linux/if.h>
12#include <linux/module.h>
13#include <linux/err.h>
5a0e3ad6 14#include <linux/slab.h>
55682965
JB
15#include <linux/list.h>
16#include <linux/if_ether.h>
17#include <linux/ieee80211.h>
18#include <linux/nl80211.h>
19#include <linux/rtnetlink.h>
20#include <linux/netlink.h>
259d8c1e 21#include <linux/nospec.h>
2a519311 22#include <linux/etherdevice.h>
463d0183 23#include <net/net_namespace.h>
55682965
JB
24#include <net/genetlink.h>
25#include <net/cfg80211.h>
463d0183 26#include <net/sock.h>
2a0e047e 27#include <net/inet_connection_sock.h>
55682965
JB
28#include "core.h"
29#include "nl80211.h"
b2e1b302 30#include "reg.h"
e35e4d28 31#include "rdev-ops.h"
55682965 32
5fb628e9
JM
33static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
34 struct genl_info *info,
35 struct cfg80211_crypto_settings *settings,
36 int cipher_limit);
37
55682965 38/* the netlink family */
489111e5 39static struct genl_family nl80211_fam;
55682965 40
2a94fe48
JB
41/* multicast groups */
42enum nl80211_multicast_groups {
43 NL80211_MCGRP_CONFIG,
44 NL80211_MCGRP_SCAN,
45 NL80211_MCGRP_REGULATORY,
46 NL80211_MCGRP_MLME,
567ffc35 47 NL80211_MCGRP_VENDOR,
50bcd31d 48 NL80211_MCGRP_NAN,
2a94fe48
JB
49 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
50};
51
52static const struct genl_multicast_group nl80211_mcgrps[] = {
71b836ec
JB
53 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG },
54 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN },
55 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG },
56 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME },
57 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR },
50bcd31d 58 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN },
2a94fe48 59#ifdef CONFIG_NL80211_TESTMODE
71b836ec 60 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE }
2a94fe48
JB
61#endif
62};
63
89a54e48
JB
64/* returns ERR_PTR values */
65static struct wireless_dev *
66__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 67{
89a54e48
JB
68 struct cfg80211_registered_device *rdev;
69 struct wireless_dev *result = NULL;
70 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
71 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
72 u64 wdev_id;
73 int wiphy_idx = -1;
74 int ifidx = -1;
55682965 75
5fe231e8 76 ASSERT_RTNL();
55682965 77
89a54e48
JB
78 if (!have_ifidx && !have_wdev_id)
79 return ERR_PTR(-EINVAL);
55682965 80
89a54e48
JB
81 if (have_ifidx)
82 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
83 if (have_wdev_id) {
84 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
85 wiphy_idx = wdev_id >> 32;
55682965
JB
86 }
87
89a54e48
JB
88 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
89 struct wireless_dev *wdev;
90
91 if (wiphy_net(&rdev->wiphy) != netns)
92 continue;
93
94 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
95 continue;
96
53873f13 97 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
89a54e48
JB
98 if (have_ifidx && wdev->netdev &&
99 wdev->netdev->ifindex == ifidx) {
100 result = wdev;
101 break;
102 }
103 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
104 result = wdev;
105 break;
106 }
107 }
89a54e48
JB
108
109 if (result)
110 break;
111 }
112
113 if (result)
114 return result;
115 return ERR_PTR(-ENODEV);
55682965
JB
116}
117
a9455408 118static struct cfg80211_registered_device *
878d9ec7 119__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 120{
7fee4778
JB
121 struct cfg80211_registered_device *rdev = NULL, *tmp;
122 struct net_device *netdev;
a9455408 123
5fe231e8 124 ASSERT_RTNL();
a9455408 125
878d9ec7 126 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
127 !attrs[NL80211_ATTR_IFINDEX] &&
128 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
129 return ERR_PTR(-EINVAL);
130
878d9ec7 131 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 132 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 133 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 134
89a54e48
JB
135 if (attrs[NL80211_ATTR_WDEV]) {
136 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
137 struct wireless_dev *wdev;
138 bool found = false;
139
140 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
141 if (tmp) {
142 /* make sure wdev exists */
53873f13 143 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) {
89a54e48
JB
144 if (wdev->identifier != (u32)wdev_id)
145 continue;
146 found = true;
147 break;
148 }
89a54e48
JB
149
150 if (!found)
151 tmp = NULL;
152
153 if (rdev && tmp != rdev)
154 return ERR_PTR(-EINVAL);
155 rdev = tmp;
156 }
157 }
158
878d9ec7
JB
159 if (attrs[NL80211_ATTR_IFINDEX]) {
160 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
7a087e74 161
7f2b8562 162 netdev = __dev_get_by_index(netns, ifindex);
7fee4778
JB
163 if (netdev) {
164 if (netdev->ieee80211_ptr)
f26cbf40
ZG
165 tmp = wiphy_to_rdev(
166 netdev->ieee80211_ptr->wiphy);
7fee4778
JB
167 else
168 tmp = NULL;
169
7fee4778
JB
170 /* not wireless device -- return error */
171 if (!tmp)
172 return ERR_PTR(-EINVAL);
173
174 /* mismatch -- return error */
175 if (rdev && tmp != rdev)
176 return ERR_PTR(-EINVAL);
177
178 rdev = tmp;
a9455408 179 }
a9455408 180 }
a9455408 181
4f7eff10
JB
182 if (!rdev)
183 return ERR_PTR(-ENODEV);
a9455408 184
4f7eff10
JB
185 if (netns != wiphy_net(&rdev->wiphy))
186 return ERR_PTR(-ENODEV);
187
188 return rdev;
a9455408
JB
189}
190
191/*
192 * This function returns a pointer to the driver
193 * that the genl_info item that is passed refers to.
a9455408
JB
194 *
195 * The result of this can be a PTR_ERR and hence must
196 * be checked with IS_ERR() for errors.
197 */
198static struct cfg80211_registered_device *
4f7eff10 199cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 200{
5fe231e8 201 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
202}
203
3d7af878
JB
204static int validate_ie_attr(const struct nlattr *attr,
205 struct netlink_ext_ack *extack)
206{
9f308616
JB
207 const u8 *data = nla_data(attr);
208 unsigned int len = nla_len(attr);
7388afe0 209 const struct element *elem;
3d7af878 210
9f308616
JB
211 for_each_element(elem, data, len) {
212 /* nothing */
3d7af878
JB
213 }
214
9f308616
JB
215 if (for_each_element_completed(elem, data, len))
216 return 0;
217
3d7af878
JB
218 NL_SET_ERR_MSG_ATTR(extack, attr, "malformed information elements");
219 return -EINVAL;
220}
221
55682965 222/* policy for the attributes */
81e54d08
PKC
223static const struct nla_policy
224nl80211_ftm_responder_policy[NL80211_FTM_RESP_ATTR_MAX + 1] = {
225 [NL80211_FTM_RESP_ATTR_ENABLED] = { .type = NLA_FLAG, },
226 [NL80211_FTM_RESP_ATTR_LCI] = { .type = NLA_BINARY,
227 .len = U8_MAX },
228 [NL80211_FTM_RESP_ATTR_CIVICLOC] = { .type = NLA_BINARY,
229 .len = U8_MAX },
230};
231
9bb7e0f2
JB
232static const struct nla_policy
233nl80211_pmsr_ftm_req_attr_policy[NL80211_PMSR_FTM_REQ_ATTR_MAX + 1] = {
234 [NL80211_PMSR_FTM_REQ_ATTR_ASAP] = { .type = NLA_FLAG },
235 [NL80211_PMSR_FTM_REQ_ATTR_PREAMBLE] = { .type = NLA_U32 },
236 [NL80211_PMSR_FTM_REQ_ATTR_NUM_BURSTS_EXP] =
237 NLA_POLICY_MAX(NLA_U8, 15),
238 [NL80211_PMSR_FTM_REQ_ATTR_BURST_PERIOD] = { .type = NLA_U16 },
239 [NL80211_PMSR_FTM_REQ_ATTR_BURST_DURATION] =
240 NLA_POLICY_MAX(NLA_U8, 15),
241 [NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST] =
ea18709a 242 NLA_POLICY_MAX(NLA_U8, 31),
9bb7e0f2
JB
243 [NL80211_PMSR_FTM_REQ_ATTR_NUM_FTMR_RETRIES] = { .type = NLA_U8 },
244 [NL80211_PMSR_FTM_REQ_ATTR_REQUEST_LCI] = { .type = NLA_FLAG },
245 [NL80211_PMSR_FTM_REQ_ATTR_REQUEST_CIVICLOC] = { .type = NLA_FLAG },
246};
247
248static const struct nla_policy
249nl80211_pmsr_req_data_policy[NL80211_PMSR_TYPE_MAX + 1] = {
250 [NL80211_PMSR_TYPE_FTM] =
23323289 251 NLA_POLICY_NESTED(nl80211_pmsr_ftm_req_attr_policy),
9bb7e0f2
JB
252};
253
254static const struct nla_policy
255nl80211_pmsr_req_attr_policy[NL80211_PMSR_REQ_ATTR_MAX + 1] = {
256 [NL80211_PMSR_REQ_ATTR_DATA] =
23323289 257 NLA_POLICY_NESTED(nl80211_pmsr_req_data_policy),
9bb7e0f2
JB
258 [NL80211_PMSR_REQ_ATTR_GET_AP_TSF] = { .type = NLA_FLAG },
259};
260
261static const struct nla_policy
262nl80211_psmr_peer_attr_policy[NL80211_PMSR_PEER_ATTR_MAX + 1] = {
263 [NL80211_PMSR_PEER_ATTR_ADDR] = NLA_POLICY_ETH_ADDR,
264 /*
265 * we could specify this again to be the top-level policy,
266 * but that would open us up to recursion problems ...
267 */
268 [NL80211_PMSR_PEER_ATTR_CHAN] = { .type = NLA_NESTED },
269 [NL80211_PMSR_PEER_ATTR_REQ] =
23323289 270 NLA_POLICY_NESTED(nl80211_pmsr_req_attr_policy),
9bb7e0f2
JB
271 [NL80211_PMSR_PEER_ATTR_RESP] = { .type = NLA_REJECT },
272};
273
274static const struct nla_policy
275nl80211_pmsr_attr_policy[NL80211_PMSR_ATTR_MAX + 1] = {
276 [NL80211_PMSR_ATTR_MAX_PEERS] = { .type = NLA_REJECT },
277 [NL80211_PMSR_ATTR_REPORT_AP_TSF] = { .type = NLA_REJECT },
278 [NL80211_PMSR_ATTR_RANDOMIZE_MAC_ADDR] = { .type = NLA_REJECT },
279 [NL80211_PMSR_ATTR_TYPE_CAPA] = { .type = NLA_REJECT },
280 [NL80211_PMSR_ATTR_PEERS] =
23323289 281 NLA_POLICY_NESTED_ARRAY(nl80211_psmr_peer_attr_policy),
9bb7e0f2
JB
282};
283
796e90f4
JC
284static const struct nla_policy
285he_obss_pd_policy[NL80211_HE_OBSS_PD_ATTR_MAX + 1] = {
286 [NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET] =
287 NLA_POLICY_RANGE(NLA_U8, 1, 20),
288 [NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET] =
289 NLA_POLICY_RANGE(NLA_U8, 1, 20),
290};
291
9bb7e0f2 292const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
55682965
JB
293 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
294 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 295 .len = 20-1 },
31888487 296 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 297
72bdcf34 298 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 299 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
3d9d1d66
JB
300 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
301 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
302 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
303
ab0d76f6
JB
304 [NL80211_ATTR_WIPHY_RETRY_SHORT] = NLA_POLICY_MIN(NLA_U8, 1),
305 [NL80211_ATTR_WIPHY_RETRY_LONG] = NLA_POLICY_MIN(NLA_U8, 1),
b9a5f8ca
JM
306 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
307 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 308 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
3057dbfd 309 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG },
55682965 310
ab0d76f6 311 [NL80211_ATTR_IFTYPE] = NLA_POLICY_MAX(NLA_U32, NL80211_IFTYPE_MAX),
55682965
JB
312 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
313 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 314
1a28ed21
JB
315 [NL80211_ATTR_MAC] = { .type = NLA_EXACT_LEN_WARN, .len = ETH_ALEN },
316 [NL80211_ATTR_PREV_BSSID] = {
317 .type = NLA_EXACT_LEN_WARN,
318 .len = ETH_ALEN
319 },
41ade00f 320
b9454e83 321 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
322 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
323 .len = WLAN_MAX_KEY_LEN },
ab0d76f6 324 [NL80211_ATTR_KEY_IDX] = NLA_POLICY_MAX(NLA_U8, 5),
41ade00f
JB
325 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
326 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 327 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
ab0d76f6
JB
328 [NL80211_ATTR_KEY_TYPE] =
329 NLA_POLICY_MAX(NLA_U32, NUM_NL80211_KEYTYPES),
ed1b6cc7
JB
330
331 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
332 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
333 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
334 .len = IEEE80211_MAX_DATA_LEN },
3d7af878
JB
335 [NL80211_ATTR_BEACON_TAIL] =
336 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
337 IEEE80211_MAX_DATA_LEN),
ab0d76f6
JB
338 [NL80211_ATTR_STA_AID] =
339 NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
5727ef1b
JB
340 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
341 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
342 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
343 .len = NL80211_MAX_SUPP_RATES },
ab0d76f6
JB
344 [NL80211_ATTR_STA_PLINK_ACTION] =
345 NLA_POLICY_MAX(NLA_U8, NUM_NL80211_PLINK_ACTIONS - 1),
e96d1cd2
ARN
346 [NL80211_ATTR_STA_TX_POWER_SETTING] =
347 NLA_POLICY_RANGE(NLA_U8,
348 NL80211_TX_POWER_AUTOMATIC,
349 NL80211_TX_POWER_FIXED),
350 [NL80211_ATTR_STA_TX_POWER] = { .type = NLA_S16 },
5727ef1b 351 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 352 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 353 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 354 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 355 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 356
b2e1b302
LR
357 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
358 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
359
9f1ba906
JM
360 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
361 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
362 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
363 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
364 .len = NL80211_MAX_SUPP_RATES },
50b12f59 365 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 366
24bdd9f4 367 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 368 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 369
1a28ed21
JB
370 [NL80211_ATTR_HT_CAPABILITY] = {
371 .type = NLA_EXACT_LEN_WARN,
372 .len = NL80211_HT_CAPABILITY_LEN
373 },
9aed3cc1
JM
374
375 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
3d7af878
JB
376 [NL80211_ATTR_IE] = NLA_POLICY_VALIDATE_FN(NLA_BINARY,
377 validate_ie_attr,
378 IEEE80211_MAX_DATA_LEN),
2a519311
JB
379 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
380 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
381
382 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
383 .len = IEEE80211_MAX_SSID_LEN },
384 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
385 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 386 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 387 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
ab0d76f6
JB
388 [NL80211_ATTR_USE_MFP] = NLA_POLICY_RANGE(NLA_U32,
389 NL80211_MFP_NO,
390 NL80211_MFP_OPTIONAL),
eccb8e8f
JB
391 [NL80211_ATTR_STA_FLAGS2] = {
392 .len = sizeof(struct nl80211_sta_flag_update),
393 },
3f77316c 394 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
395 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
396 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
64bf3d4b 397 [NL80211_ATTR_CONTROL_PORT_OVER_NL80211] = { .type = NLA_FLAG },
b23aa676
SO
398 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
399 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
400 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 401 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 402 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
1a28ed21
JB
403 [NL80211_ATTR_PMKID] = {
404 .type = NLA_EXACT_LEN_WARN,
405 .len = WLAN_PMKID_LEN
406 },
9588bbd5
JM
407 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
408 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 409 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
410 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
411 .len = IEEE80211_MAX_DATA_LEN },
412 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ab0d76f6
JB
413 [NL80211_ATTR_PS_STATE] = NLA_POLICY_RANGE(NLA_U32,
414 NL80211_PS_DISABLED,
415 NL80211_PS_ENABLED),
d6dc1a38 416 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 417 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 418 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
419 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
420 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 421 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
422 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
423 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 424 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 425 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 426 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 427 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
ab0d76f6
JB
428 [NL80211_ATTR_STA_PLINK_STATE] =
429 NLA_POLICY_MAX(NLA_U8, NUM_NL80211_PLINK_STATES - 1),
430 [NL80211_ATTR_MESH_PEER_AID] =
431 NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
bbe6ad6d 432 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 433 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 434 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
ab0d76f6
JB
435 [NL80211_ATTR_HIDDEN_SSID] =
436 NLA_POLICY_RANGE(NLA_U32,
437 NL80211_HIDDEN_SSID_NOT_IN_USE,
438 NL80211_HIDDEN_SSID_ZERO_CONTENTS),
3d7af878
JB
439 [NL80211_ATTR_IE_PROBE_RESP] =
440 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
441 IEEE80211_MAX_DATA_LEN),
442 [NL80211_ATTR_IE_ASSOC_RESP] =
443 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
444 IEEE80211_MAX_DATA_LEN),
f4b34b55 445 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 446 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 447 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
448 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
449 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
450 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
451 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
452 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
31fa97c5 453 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG },
e247bd90 454 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
455 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
456 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 457 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
458 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
459 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
460 .len = NL80211_HT_CAPABILITY_LEN
461 },
1d9d9213 462 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 463 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 464 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 465 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 466 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
11b6b5a4 467 [NL80211_ATTR_AUTH_DATA] = { .type = NLA_BINARY, },
1a28ed21
JB
468 [NL80211_ATTR_VHT_CAPABILITY] = {
469 .type = NLA_EXACT_LEN_WARN,
470 .len = NL80211_VHT_CAPABILITY_LEN
471 },
ed473771 472 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
ab0d76f6
JB
473 [NL80211_ATTR_P2P_CTWINDOW] = NLA_POLICY_MAX(NLA_U8, 127),
474 [NL80211_ATTR_P2P_OPPPS] = NLA_POLICY_MAX(NLA_U8, 1),
475 [NL80211_ATTR_LOCAL_MESH_POWER_MODE] =
476 NLA_POLICY_RANGE(NLA_U32,
477 NL80211_MESH_POWER_UNKNOWN + 1,
478 NL80211_MESH_POWER_MAX),
77765eaf
VT
479 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
480 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
481 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
482 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 483 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
484 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
485 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
486 .len = NL80211_VHT_CAPABILITY_LEN,
487 },
355199e0
JM
488 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
489 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
490 .len = IEEE80211_MAX_DATA_LEN },
ab0d76f6
JB
491 [NL80211_ATTR_PEER_AID] =
492 NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
16ef1fe2
SW
493 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
494 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
495 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
9a774c78
AO
496 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY },
497 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY },
c01fc9ad
SD
498 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY },
499 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY },
5336fa88 500 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
60f4a7b1 501 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
ad7e718c
JB
502 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
503 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
504 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
fa9ffc74
KP
505 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY,
506 .len = IEEE80211_QOS_MAP_LEN_MAX },
1a28ed21
JB
507 [NL80211_ATTR_MAC_HINT] = {
508 .type = NLA_EXACT_LEN_WARN,
509 .len = ETH_ALEN
510 },
1df4a510 511 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
df942e7b 512 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 },
18e5ca65 513 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG },
34d22ce2 514 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY },
bab5ab7d 515 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG },
ab0d76f6
JB
516 [NL80211_ATTR_TSID] = NLA_POLICY_MAX(NLA_U8, IEEE80211_NUM_TIDS - 1),
517 [NL80211_ATTR_USER_PRIO] =
518 NLA_POLICY_MAX(NLA_U8, IEEE80211_NUM_UPS - 1),
960d01ac 519 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 },
18998c38 520 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 },
1a28ed21
JB
521 [NL80211_ATTR_MAC_MASK] = {
522 .type = NLA_EXACT_LEN_WARN,
523 .len = ETH_ALEN
524 },
1bdd716c 525 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG },
4b681c82 526 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 },
9c748934 527 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 },
05050753 528 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG },
34d50519 529 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG },
38de03d2 530 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED },
ab0d76f6
JB
531 [NL80211_ATTR_STA_SUPPORT_P2P_PS] =
532 NLA_POLICY_MAX(NLA_U8, NUM_NL80211_P2P_PS_STATUS - 1),
c6e6a0c8
AE
533 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = {
534 .len = VHT_MUMIMO_GROUPS_DATA_LEN
535 },
1a28ed21
JB
536 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = {
537 .type = NLA_EXACT_LEN_WARN,
538 .len = ETH_ALEN
539 },
ab0d76f6 540 [NL80211_ATTR_NAN_MASTER_PREF] = NLA_POLICY_MIN(NLA_U8, 1),
8585989d 541 [NL80211_ATTR_BANDS] = { .type = NLA_U32 },
a442b761 542 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED },
348bd456
JM
543 [NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY,
544 .len = FILS_MAX_KEK_LEN },
1a28ed21
JB
545 [NL80211_ATTR_FILS_NONCES] = {
546 .type = NLA_EXACT_LEN_WARN,
547 .len = 2 * FILS_NONCE_LEN
548 },
ce0ce13a 549 [NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, },
1a28ed21 550 [NL80211_ATTR_BSSID] = { .type = NLA_EXACT_LEN_WARN, .len = ETH_ALEN },
bf95ecdb 551 [NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] = { .type = NLA_S8 },
552 [NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST] = {
553 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
554 },
3093ebbe 555 [NL80211_ATTR_TIMEOUT_REASON] = { .type = NLA_U32 },
a3caf744
VK
556 [NL80211_ATTR_FILS_ERP_USERNAME] = { .type = NLA_BINARY,
557 .len = FILS_ERP_MAX_USERNAME_LEN },
558 [NL80211_ATTR_FILS_ERP_REALM] = { .type = NLA_BINARY,
559 .len = FILS_ERP_MAX_REALM_LEN },
560 [NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] = { .type = NLA_U16 },
561 [NL80211_ATTR_FILS_ERP_RRK] = { .type = NLA_BINARY,
562 .len = FILS_ERP_MAX_RRK_LEN },
1a28ed21 563 [NL80211_ATTR_FILS_CACHE_ID] = { .type = NLA_EXACT_LEN_WARN, .len = 2 },
a3caf744 564 [NL80211_ATTR_PMK] = { .type = NLA_BINARY, .len = PMK_MAX_LEN },
ca986ad9 565 [NL80211_ATTR_SCHED_SCAN_MULTI] = { .type = NLA_FLAG },
40cbfa90 566 [NL80211_ATTR_EXTERNAL_AUTH_SUPPORT] = { .type = NLA_FLAG },
52539ca8
THJ
567
568 [NL80211_ATTR_TXQ_LIMIT] = { .type = NLA_U32 },
569 [NL80211_ATTR_TXQ_MEMORY_LIMIT] = { .type = NLA_U32 },
570 [NL80211_ATTR_TXQ_QUANTUM] = { .type = NLA_U32 },
c4cbaf79
LC
571 [NL80211_ATTR_HE_CAPABILITY] = { .type = NLA_BINARY,
572 .len = NL80211_HE_MAX_CAPABILITY_LEN },
81e54d08
PKC
573
574 [NL80211_ATTR_FTM_RESPONDER] = {
575 .type = NLA_NESTED,
576 .validation_data = nl80211_ftm_responder_policy,
577 },
9bb7e0f2
JB
578 [NL80211_ATTR_TIMEOUT] = NLA_POLICY_MIN(NLA_U32, 1),
579 [NL80211_ATTR_PEER_MEASUREMENTS] =
23323289 580 NLA_POLICY_NESTED(nl80211_pmsr_attr_policy),
36647055 581 [NL80211_ATTR_AIRTIME_WEIGHT] = NLA_POLICY_MIN(NLA_U16, 1),
26f7044e
CHH
582 [NL80211_ATTR_SAE_PASSWORD] = { .type = NLA_BINARY,
583 .len = SAE_PASSWORD_MAX_LEN },
a0de1ca3 584 [NL80211_ATTR_TWT_RESPONDER] = { .type = NLA_FLAG },
796e90f4 585 [NL80211_ATTR_HE_OBSS_PD] = NLA_POLICY_NESTED(he_obss_pd_policy),
55682965
JB
586};
587
e31b8213 588/* policy for the key attributes */
b54452b0 589static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 590 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
591 [NL80211_KEY_IDX] = { .type = NLA_U8 },
592 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 593 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
594 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
595 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
ab0d76f6 596 [NL80211_KEY_TYPE] = NLA_POLICY_MAX(NLA_U32, NUM_NL80211_KEYTYPES - 1),
dbd2fd65 597 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
6cdd3979 598 [NL80211_KEY_MODE] = NLA_POLICY_RANGE(NLA_U8, 0, NL80211_KEY_SET_TX),
dbd2fd65
JB
599};
600
601/* policy for the key default flags */
602static const struct nla_policy
603nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
604 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
605 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
606};
607
f83ace3b 608#ifdef CONFIG_PM
ff1b6e69
JB
609/* policy for WoWLAN attributes */
610static const struct nla_policy
611nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
612 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
613 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
614 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
615 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
616 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
617 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
618 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
619 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e 620 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
8cd4d456 621 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED },
2a0e047e
JB
622};
623
624static const struct nla_policy
625nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
626 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
627 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
1a28ed21
JB
628 [NL80211_WOWLAN_TCP_DST_MAC] = {
629 .type = NLA_EXACT_LEN_WARN,
630 .len = ETH_ALEN
631 },
2a0e047e
JB
632 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
633 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
1a28ed21 634 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .type = NLA_MIN_LEN, .len = 1 },
2a0e047e
JB
635 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
636 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
637 },
638 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
639 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
640 },
641 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
1a28ed21
JB
642 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .type = NLA_MIN_LEN, .len = 1 },
643 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .type = NLA_MIN_LEN, .len = 1 },
ff1b6e69 644};
f83ace3b 645#endif /* CONFIG_PM */
ff1b6e69 646
be29b99a
AK
647/* policy for coalesce rule attributes */
648static const struct nla_policy
649nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
650 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
ab0d76f6
JB
651 [NL80211_ATTR_COALESCE_RULE_CONDITION] =
652 NLA_POLICY_RANGE(NLA_U32,
653 NL80211_COALESCE_CONDITION_MATCH,
654 NL80211_COALESCE_CONDITION_NO_MATCH),
be29b99a
AK
655 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
656};
657
e5497d76
JB
658/* policy for GTK rekey offload attributes */
659static const struct nla_policy
660nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
180aa422
JB
661 [NL80211_REKEY_DATA_KEK] = {
662 .type = NLA_EXACT_LEN_WARN,
663 .len = NL80211_KEK_LEN,
664 },
665 [NL80211_REKEY_DATA_KCK] = {
666 .type = NLA_EXACT_LEN_WARN,
667 .len = NL80211_KCK_LEN,
668 },
1a28ed21
JB
669 [NL80211_REKEY_DATA_REPLAY_CTR] = {
670 .type = NLA_EXACT_LEN_WARN,
671 .len = NL80211_REPLAY_CTR_LEN
672 },
e5497d76
JB
673};
674
1e1b11b6 675static const struct nla_policy
676nl80211_match_band_rssi_policy[NUM_NL80211_BANDS] = {
677 [NL80211_BAND_2GHZ] = { .type = NLA_S32 },
678 [NL80211_BAND_5GHZ] = { .type = NLA_S32 },
679 [NL80211_BAND_60GHZ] = { .type = NLA_S32 },
680};
681
a1f1c21c
LC
682static const struct nla_policy
683nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 684 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 685 .len = IEEE80211_MAX_SSID_LEN },
1a28ed21
JB
686 [NL80211_SCHED_SCAN_MATCH_ATTR_BSSID] = {
687 .type = NLA_EXACT_LEN_WARN,
688 .len = ETH_ALEN
689 },
88e920b4 690 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
1e1b11b6 691 [NL80211_SCHED_SCAN_MATCH_PER_BAND_RSSI] =
692 NLA_POLICY_NESTED(nl80211_match_band_rssi_policy),
a1f1c21c
LC
693};
694
3b06d277
AS
695static const struct nla_policy
696nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = {
697 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 },
698 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 },
699};
700
38de03d2
AS
701static const struct nla_policy
702nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = {
703 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG },
704 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 },
705 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = {
706 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
707 },
708};
709
a442b761
AB
710/* policy for NAN function attributes */
711static const struct nla_policy
712nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = {
713 [NL80211_NAN_FUNC_TYPE] = { .type = NLA_U8 },
0a27844c 714 [NL80211_NAN_FUNC_SERVICE_ID] = {
a442b761
AB
715 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN },
716 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 },
717 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG },
718 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG },
719 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 },
720 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 },
1a28ed21
JB
721 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = {
722 .type = NLA_EXACT_LEN_WARN,
723 .len = ETH_ALEN
724 },
a442b761
AB
725 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG },
726 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 },
727 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY,
728 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN },
729 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED },
730 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED },
731 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED },
732 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 },
733 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 },
734};
735
736/* policy for Service Response Filter attributes */
737static const struct nla_policy
738nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = {
739 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG },
740 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY,
741 .len = NL80211_NAN_FUNC_SRF_MAX_LEN },
742 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 },
743 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED },
744};
745
ad670233
PX
746/* policy for packet pattern attributes */
747static const struct nla_policy
748nl80211_packet_pattern_policy[MAX_NL80211_PKTPAT + 1] = {
749 [NL80211_PKTPAT_MASK] = { .type = NLA_BINARY, },
750 [NL80211_PKTPAT_PATTERN] = { .type = NLA_BINARY, },
751 [NL80211_PKTPAT_OFFSET] = { .type = NLA_U32 },
752};
753
9bb7e0f2
JB
754int nl80211_prepare_wdev_dump(struct netlink_callback *cb,
755 struct cfg80211_registered_device **rdev,
756 struct wireless_dev **wdev)
a043897a 757{
97990a06 758 int err;
a043897a 759
97990a06 760 if (!cb->args[0]) {
50508d94
JB
761 struct nlattr **attrbuf;
762
763 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf),
764 GFP_KERNEL);
765 if (!attrbuf)
766 return -ENOMEM;
767
8cb08174
JB
768 err = nlmsg_parse_deprecated(cb->nlh,
769 GENL_HDRLEN + nl80211_fam.hdrsize,
50508d94 770 attrbuf, nl80211_fam.maxattr,
8cb08174 771 nl80211_policy, NULL);
50508d94
JB
772 if (err) {
773 kfree(attrbuf);
ea90e0dc 774 return err;
50508d94 775 }
67748893 776
50508d94
JB
777 *wdev = __cfg80211_wdev_from_attrs(sock_net(cb->skb->sk),
778 attrbuf);
779 kfree(attrbuf);
ea90e0dc
JB
780 if (IS_ERR(*wdev))
781 return PTR_ERR(*wdev);
f26cbf40 782 *rdev = wiphy_to_rdev((*wdev)->wiphy);
c319d50b
JB
783 /* 0 is the first index - add 1 to parse only once */
784 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
785 cb->args[1] = (*wdev)->identifier;
786 } else {
c319d50b
JB
787 /* subtract the 1 again here */
788 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 789 struct wireless_dev *tmp;
67748893 790
ea90e0dc
JB
791 if (!wiphy)
792 return -ENODEV;
f26cbf40 793 *rdev = wiphy_to_rdev(wiphy);
97990a06 794 *wdev = NULL;
67748893 795
53873f13 796 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) {
97990a06
JB
797 if (tmp->identifier == cb->args[1]) {
798 *wdev = tmp;
799 break;
800 }
801 }
67748893 802
ea90e0dc
JB
803 if (!*wdev)
804 return -ENODEV;
67748893
JB
805 }
806
67748893 807 return 0;
67748893
JB
808}
809
55682965 810/* message building helper */
9bb7e0f2
JB
811void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
812 int flags, u8 cmd)
55682965
JB
813{
814 /* since there is no private header just add the generic one */
15e47304 815 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
816}
817
50f32718
HD
818static int nl80211_msg_put_wmm_rules(struct sk_buff *msg,
819 const struct ieee80211_reg_rule *rule)
820{
821 int j;
822 struct nlattr *nl_wmm_rules =
ae0be8de 823 nla_nest_start_noflag(msg, NL80211_FREQUENCY_ATTR_WMM);
50f32718
HD
824
825 if (!nl_wmm_rules)
826 goto nla_put_failure;
827
828 for (j = 0; j < IEEE80211_NUM_ACS; j++) {
ae0be8de 829 struct nlattr *nl_wmm_rule = nla_nest_start_noflag(msg, j);
50f32718
HD
830
831 if (!nl_wmm_rule)
832 goto nla_put_failure;
833
834 if (nla_put_u16(msg, NL80211_WMMR_CW_MIN,
38cb87ee 835 rule->wmm_rule.client[j].cw_min) ||
50f32718 836 nla_put_u16(msg, NL80211_WMMR_CW_MAX,
38cb87ee 837 rule->wmm_rule.client[j].cw_max) ||
50f32718 838 nla_put_u8(msg, NL80211_WMMR_AIFSN,
38cb87ee 839 rule->wmm_rule.client[j].aifsn) ||
d3c89bbc
HD
840 nla_put_u16(msg, NL80211_WMMR_TXOP,
841 rule->wmm_rule.client[j].cot))
50f32718
HD
842 goto nla_put_failure;
843
844 nla_nest_end(msg, nl_wmm_rule);
845 }
846 nla_nest_end(msg, nl_wmm_rules);
847
848 return 0;
849
850nla_put_failure:
851 return -ENOBUFS;
852}
853
854static int nl80211_msg_put_channel(struct sk_buff *msg, struct wiphy *wiphy,
cdc89b97
JB
855 struct ieee80211_channel *chan,
856 bool large)
5dab3b8a 857{
ea077c1c
RL
858 /* Some channels must be completely excluded from the
859 * list to protect old user-space tools from breaking
860 */
861 if (!large && chan->flags &
862 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ))
863 return 0;
864
9360ffd1
DM
865 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
866 chan->center_freq))
867 goto nla_put_failure;
5dab3b8a 868
9360ffd1
DM
869 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
870 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
871 goto nla_put_failure;
8fe02e16
LR
872 if (chan->flags & IEEE80211_CHAN_NO_IR) {
873 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
874 goto nla_put_failure;
875 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
876 goto nla_put_failure;
877 }
cdc89b97
JB
878 if (chan->flags & IEEE80211_CHAN_RADAR) {
879 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
880 goto nla_put_failure;
881 if (large) {
882 u32 time;
883
884 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
885
886 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
887 chan->dfs_state))
888 goto nla_put_failure;
889 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
890 time))
891 goto nla_put_failure;
089027e5
JD
892 if (nla_put_u32(msg,
893 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME,
894 chan->dfs_cac_ms))
895 goto nla_put_failure;
cdc89b97
JB
896 }
897 }
5dab3b8a 898
fe1abafd
JB
899 if (large) {
900 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
901 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
902 goto nla_put_failure;
903 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
904 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
905 goto nla_put_failure;
906 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
907 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
908 goto nla_put_failure;
909 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
910 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
911 goto nla_put_failure;
570dbde1
DS
912 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) &&
913 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY))
914 goto nla_put_failure;
06f207fc
AN
915 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) &&
916 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT))
570dbde1 917 goto nla_put_failure;
ea077c1c
RL
918 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) &&
919 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ))
920 goto nla_put_failure;
921 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) &&
922 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ))
923 goto nla_put_failure;
fe1abafd
JB
924 }
925
9360ffd1
DM
926 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
927 DBM_TO_MBM(chan->max_power)))
928 goto nla_put_failure;
5dab3b8a 929
50f32718
HD
930 if (large) {
931 const struct ieee80211_reg_rule *rule =
b88d26d9 932 freq_reg_info(wiphy, MHZ_TO_KHZ(chan->center_freq));
50f32718 933
38cb87ee 934 if (!IS_ERR_OR_NULL(rule) && rule->has_wmm) {
50f32718
HD
935 if (nl80211_msg_put_wmm_rules(msg, rule))
936 goto nla_put_failure;
937 }
938 }
939
5dab3b8a
LR
940 return 0;
941
942 nla_put_failure:
943 return -ENOBUFS;
944}
945
52539ca8
THJ
946static bool nl80211_put_txq_stats(struct sk_buff *msg,
947 struct cfg80211_txq_stats *txqstats,
948 int attrtype)
949{
950 struct nlattr *txqattr;
951
952#define PUT_TXQVAL_U32(attr, memb) do { \
953 if (txqstats->filled & BIT(NL80211_TXQ_STATS_ ## attr) && \
954 nla_put_u32(msg, NL80211_TXQ_STATS_ ## attr, txqstats->memb)) \
955 return false; \
956 } while (0)
957
ae0be8de 958 txqattr = nla_nest_start_noflag(msg, attrtype);
52539ca8
THJ
959 if (!txqattr)
960 return false;
961
962 PUT_TXQVAL_U32(BACKLOG_BYTES, backlog_bytes);
963 PUT_TXQVAL_U32(BACKLOG_PACKETS, backlog_packets);
964 PUT_TXQVAL_U32(FLOWS, flows);
965 PUT_TXQVAL_U32(DROPS, drops);
966 PUT_TXQVAL_U32(ECN_MARKS, ecn_marks);
967 PUT_TXQVAL_U32(OVERLIMIT, overlimit);
968 PUT_TXQVAL_U32(OVERMEMORY, overmemory);
969 PUT_TXQVAL_U32(COLLISIONS, collisions);
970 PUT_TXQVAL_U32(TX_BYTES, tx_bytes);
971 PUT_TXQVAL_U32(TX_PACKETS, tx_packets);
972 PUT_TXQVAL_U32(MAX_FLOWS, max_flows);
973 nla_nest_end(msg, txqattr);
974
975#undef PUT_TXQVAL_U32
976 return true;
977}
978
55682965
JB
979/* netlink command implementations */
980
b9454e83
JB
981struct key_parse {
982 struct key_params p;
983 int idx;
e31b8213 984 int type;
b9454e83 985 bool def, defmgmt;
dbd2fd65 986 bool def_uni, def_multi;
b9454e83
JB
987};
988
768075eb
JB
989static int nl80211_parse_key_new(struct genl_info *info, struct nlattr *key,
990 struct key_parse *k)
b9454e83
JB
991{
992 struct nlattr *tb[NL80211_KEY_MAX + 1];
8cb08174
JB
993 int err = nla_parse_nested_deprecated(tb, NL80211_KEY_MAX, key,
994 nl80211_key_policy,
995 info->extack);
b9454e83
JB
996 if (err)
997 return err;
998
999 k->def = !!tb[NL80211_KEY_DEFAULT];
1000 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
1001
dbd2fd65
JB
1002 if (k->def) {
1003 k->def_uni = true;
1004 k->def_multi = true;
1005 }
1006 if (k->defmgmt)
1007 k->def_multi = true;
1008
b9454e83
JB
1009 if (tb[NL80211_KEY_IDX])
1010 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
1011
1012 if (tb[NL80211_KEY_DATA]) {
1013 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
1014 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
1015 }
1016
1017 if (tb[NL80211_KEY_SEQ]) {
1018 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
1019 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
1020 }
1021
1022 if (tb[NL80211_KEY_CIPHER])
1023 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
1024
ab0d76f6 1025 if (tb[NL80211_KEY_TYPE])
e31b8213 1026 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
e31b8213 1027
dbd2fd65
JB
1028 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
1029 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
7a087e74 1030
8cb08174
JB
1031 err = nla_parse_nested_deprecated(kdt,
1032 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
1033 tb[NL80211_KEY_DEFAULT_TYPES],
1034 nl80211_key_default_policy,
1035 info->extack);
dbd2fd65
JB
1036 if (err)
1037 return err;
1038
1039 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
1040 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
1041 }
1042
6cdd3979
AW
1043 if (tb[NL80211_KEY_MODE])
1044 k->p.mode = nla_get_u8(tb[NL80211_KEY_MODE]);
1045
b9454e83
JB
1046 return 0;
1047}
1048
1049static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
1050{
1051 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
1052 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
1053 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
1054 }
1055
1056 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
1057 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
1058 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
1059 }
1060
1061 if (info->attrs[NL80211_ATTR_KEY_IDX])
1062 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1063
1064 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
1065 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
1066
1067 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
1068 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
1069
dbd2fd65
JB
1070 if (k->def) {
1071 k->def_uni = true;
1072 k->def_multi = true;
1073 }
1074 if (k->defmgmt)
1075 k->def_multi = true;
1076
ab0d76f6 1077 if (info->attrs[NL80211_ATTR_KEY_TYPE])
e31b8213 1078 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
e31b8213 1079
dbd2fd65
JB
1080 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
1081 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
8cb08174
JB
1082 int err = nla_parse_nested_deprecated(kdt,
1083 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
1084 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
1085 nl80211_key_default_policy,
1086 info->extack);
dbd2fd65
JB
1087 if (err)
1088 return err;
1089
1090 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
1091 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
1092 }
1093
b9454e83
JB
1094 return 0;
1095}
1096
1097static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
1098{
1099 int err;
1100
1101 memset(k, 0, sizeof(*k));
1102 k->idx = -1;
e31b8213 1103 k->type = -1;
b9454e83
JB
1104
1105 if (info->attrs[NL80211_ATTR_KEY])
768075eb 1106 err = nl80211_parse_key_new(info, info->attrs[NL80211_ATTR_KEY], k);
b9454e83
JB
1107 else
1108 err = nl80211_parse_key_old(info, k);
1109
1110 if (err)
1111 return err;
1112
768075eb
JB
1113 if (k->def && k->defmgmt) {
1114 GENL_SET_ERR_MSG(info, "key with def && defmgmt is invalid");
b9454e83 1115 return -EINVAL;
768075eb 1116 }
b9454e83 1117
dbd2fd65 1118 if (k->defmgmt) {
768075eb
JB
1119 if (k->def_uni || !k->def_multi) {
1120 GENL_SET_ERR_MSG(info, "defmgmt key must be mcast");
dbd2fd65 1121 return -EINVAL;
768075eb 1122 }
dbd2fd65
JB
1123 }
1124
b9454e83
JB
1125 if (k->idx != -1) {
1126 if (k->defmgmt) {
768075eb
JB
1127 if (k->idx < 4 || k->idx > 5) {
1128 GENL_SET_ERR_MSG(info,
1129 "defmgmt key idx not 4 or 5");
b9454e83 1130 return -EINVAL;
768075eb 1131 }
b9454e83 1132 } else if (k->def) {
768075eb
JB
1133 if (k->idx < 0 || k->idx > 3) {
1134 GENL_SET_ERR_MSG(info, "def key idx not 0-3");
b9454e83 1135 return -EINVAL;
768075eb 1136 }
b9454e83 1137 } else {
768075eb
JB
1138 if (k->idx < 0 || k->idx > 5) {
1139 GENL_SET_ERR_MSG(info, "key idx not 0-5");
b9454e83 1140 return -EINVAL;
768075eb 1141 }
b9454e83
JB
1142 }
1143 }
1144
1145 return 0;
1146}
1147
fffd0934
JB
1148static struct cfg80211_cached_keys *
1149nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
768075eb 1150 struct genl_info *info, bool *no_ht)
fffd0934 1151{
768075eb 1152 struct nlattr *keys = info->attrs[NL80211_ATTR_KEYS];
fffd0934
JB
1153 struct key_parse parse;
1154 struct nlattr *key;
1155 struct cfg80211_cached_keys *result;
1156 int rem, err, def = 0;
f1c1f17a
JB
1157 bool have_key = false;
1158
1159 nla_for_each_nested(key, keys, rem) {
1160 have_key = true;
1161 break;
1162 }
1163
1164 if (!have_key)
1165 return NULL;
fffd0934
JB
1166
1167 result = kzalloc(sizeof(*result), GFP_KERNEL);
1168 if (!result)
1169 return ERR_PTR(-ENOMEM);
1170
1171 result->def = -1;
fffd0934
JB
1172
1173 nla_for_each_nested(key, keys, rem) {
1174 memset(&parse, 0, sizeof(parse));
1175 parse.idx = -1;
1176
768075eb 1177 err = nl80211_parse_key_new(info, key, &parse);
fffd0934
JB
1178 if (err)
1179 goto error;
1180 err = -EINVAL;
1181 if (!parse.p.key)
1182 goto error;
768075eb
JB
1183 if (parse.idx < 0 || parse.idx > 3) {
1184 GENL_SET_ERR_MSG(info, "key index out of range [0-3]");
fffd0934 1185 goto error;
768075eb 1186 }
fffd0934 1187 if (parse.def) {
768075eb
JB
1188 if (def) {
1189 GENL_SET_ERR_MSG(info,
1190 "only one key can be default");
fffd0934 1191 goto error;
768075eb 1192 }
fffd0934
JB
1193 def = 1;
1194 result->def = parse.idx;
dbd2fd65
JB
1195 if (!parse.def_uni || !parse.def_multi)
1196 goto error;
fffd0934
JB
1197 } else if (parse.defmgmt)
1198 goto error;
1199 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 1200 parse.idx, false, NULL);
fffd0934
JB
1201 if (err)
1202 goto error;
386b1f27
JB
1203 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 &&
1204 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) {
768075eb 1205 GENL_SET_ERR_MSG(info, "connect key must be WEP");
386b1f27
JB
1206 err = -EINVAL;
1207 goto error;
1208 }
fffd0934
JB
1209 result->params[parse.idx].cipher = parse.p.cipher;
1210 result->params[parse.idx].key_len = parse.p.key_len;
1211 result->params[parse.idx].key = result->data[parse.idx];
1212 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee 1213
386b1f27
JB
1214 /* must be WEP key if we got here */
1215 if (no_ht)
1216 *no_ht = true;
fffd0934
JB
1217 }
1218
f1c1f17a
JB
1219 if (result->def < 0) {
1220 err = -EINVAL;
768075eb 1221 GENL_SET_ERR_MSG(info, "need a default/TX key");
f1c1f17a
JB
1222 goto error;
1223 }
1224
fffd0934
JB
1225 return result;
1226 error:
1227 kfree(result);
1228 return ERR_PTR(err);
1229}
1230
1231static int nl80211_key_allowed(struct wireless_dev *wdev)
1232{
1233 ASSERT_WDEV_LOCK(wdev);
1234
fffd0934
JB
1235 switch (wdev->iftype) {
1236 case NL80211_IFTYPE_AP:
1237 case NL80211_IFTYPE_AP_VLAN:
074ac8df 1238 case NL80211_IFTYPE_P2P_GO:
ff973af7 1239 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
1240 break;
1241 case NL80211_IFTYPE_ADHOC:
fffd0934 1242 case NL80211_IFTYPE_STATION:
074ac8df 1243 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 1244 if (!wdev->current_bss)
fffd0934
JB
1245 return -ENOLINK;
1246 break;
de4fcbad 1247 case NL80211_IFTYPE_UNSPECIFIED:
6e0bd6c3 1248 case NL80211_IFTYPE_OCB:
de4fcbad 1249 case NL80211_IFTYPE_MONITOR:
cb3b7d87 1250 case NL80211_IFTYPE_NAN:
de4fcbad
JB
1251 case NL80211_IFTYPE_P2P_DEVICE:
1252 case NL80211_IFTYPE_WDS:
1253 case NUM_NL80211_IFTYPES:
fffd0934
JB
1254 return -EINVAL;
1255 }
1256
1257 return 0;
1258}
1259
664834de
JM
1260static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
1261 struct nlattr *tb)
1262{
1263 struct ieee80211_channel *chan;
1264
1265 if (tb == NULL)
1266 return NULL;
1267 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb));
1268 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
1269 return NULL;
1270 return chan;
1271}
1272
7527a782
JB
1273static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
1274{
ae0be8de 1275 struct nlattr *nl_modes = nla_nest_start_noflag(msg, attr);
7527a782
JB
1276 int i;
1277
1278 if (!nl_modes)
1279 goto nla_put_failure;
1280
1281 i = 0;
1282 while (ifmodes) {
9360ffd1
DM
1283 if ((ifmodes & 1) && nla_put_flag(msg, i))
1284 goto nla_put_failure;
7527a782
JB
1285 ifmodes >>= 1;
1286 i++;
1287 }
1288
1289 nla_nest_end(msg, nl_modes);
1290 return 0;
1291
1292nla_put_failure:
1293 return -ENOBUFS;
1294}
1295
1296static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
1297 struct sk_buff *msg,
1298 bool large)
7527a782
JB
1299{
1300 struct nlattr *nl_combis;
1301 int i, j;
1302
ae0be8de
MK
1303 nl_combis = nla_nest_start_noflag(msg,
1304 NL80211_ATTR_INTERFACE_COMBINATIONS);
7527a782
JB
1305 if (!nl_combis)
1306 goto nla_put_failure;
1307
1308 for (i = 0; i < wiphy->n_iface_combinations; i++) {
1309 const struct ieee80211_iface_combination *c;
1310 struct nlattr *nl_combi, *nl_limits;
1311
1312 c = &wiphy->iface_combinations[i];
1313
ae0be8de 1314 nl_combi = nla_nest_start_noflag(msg, i + 1);
7527a782
JB
1315 if (!nl_combi)
1316 goto nla_put_failure;
1317
ae0be8de
MK
1318 nl_limits = nla_nest_start_noflag(msg,
1319 NL80211_IFACE_COMB_LIMITS);
7527a782
JB
1320 if (!nl_limits)
1321 goto nla_put_failure;
1322
1323 for (j = 0; j < c->n_limits; j++) {
1324 struct nlattr *nl_limit;
1325
ae0be8de 1326 nl_limit = nla_nest_start_noflag(msg, j + 1);
7527a782
JB
1327 if (!nl_limit)
1328 goto nla_put_failure;
9360ffd1
DM
1329 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
1330 c->limits[j].max))
1331 goto nla_put_failure;
7527a782
JB
1332 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
1333 c->limits[j].types))
1334 goto nla_put_failure;
1335 nla_nest_end(msg, nl_limit);
1336 }
1337
1338 nla_nest_end(msg, nl_limits);
1339
9360ffd1
DM
1340 if (c->beacon_int_infra_match &&
1341 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
1342 goto nla_put_failure;
1343 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
1344 c->num_different_channels) ||
1345 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
1346 c->max_interfaces))
1347 goto nla_put_failure;
cdc89b97 1348 if (large &&
8c48b50a
FF
1349 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
1350 c->radar_detect_widths) ||
1351 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS,
1352 c->radar_detect_regions)))
cdc89b97 1353 goto nla_put_failure;
0c317a02
PK
1354 if (c->beacon_int_min_gcd &&
1355 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD,
1356 c->beacon_int_min_gcd))
1357 goto nla_put_failure;
7527a782
JB
1358
1359 nla_nest_end(msg, nl_combi);
1360 }
1361
1362 nla_nest_end(msg, nl_combis);
1363
1364 return 0;
1365nla_put_failure:
1366 return -ENOBUFS;
1367}
1368
3713b4e3 1369#ifdef CONFIG_PM
b56cf720
JB
1370static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
1371 struct sk_buff *msg)
1372{
964dc9e2 1373 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
1374 struct nlattr *nl_tcp;
1375
1376 if (!tcp)
1377 return 0;
1378
ae0be8de
MK
1379 nl_tcp = nla_nest_start_noflag(msg,
1380 NL80211_WOWLAN_TRIG_TCP_CONNECTION);
b56cf720
JB
1381 if (!nl_tcp)
1382 return -ENOBUFS;
1383
1384 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1385 tcp->data_payload_max))
1386 return -ENOBUFS;
1387
1388 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1389 tcp->data_payload_max))
1390 return -ENOBUFS;
1391
1392 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
1393 return -ENOBUFS;
1394
1395 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
1396 sizeof(*tcp->tok), tcp->tok))
1397 return -ENOBUFS;
1398
1399 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
1400 tcp->data_interval_max))
1401 return -ENOBUFS;
1402
1403 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
1404 tcp->wake_payload_max))
1405 return -ENOBUFS;
1406
1407 nla_nest_end(msg, nl_tcp);
1408 return 0;
1409}
1410
3713b4e3 1411static int nl80211_send_wowlan(struct sk_buff *msg,
1b8ec87a 1412 struct cfg80211_registered_device *rdev,
b56cf720 1413 bool large)
55682965 1414{
3713b4e3 1415 struct nlattr *nl_wowlan;
55682965 1416
1b8ec87a 1417 if (!rdev->wiphy.wowlan)
3713b4e3 1418 return 0;
55682965 1419
ae0be8de
MK
1420 nl_wowlan = nla_nest_start_noflag(msg,
1421 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
3713b4e3
JB
1422 if (!nl_wowlan)
1423 return -ENOBUFS;
9360ffd1 1424
1b8ec87a 1425 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 1426 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1b8ec87a 1427 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 1428 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1b8ec87a 1429 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 1430 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1b8ec87a 1431 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 1432 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1b8ec87a 1433 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 1434 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1b8ec87a 1435 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 1436 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1b8ec87a 1437 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 1438 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1b8ec87a 1439 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
1440 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1441 return -ENOBUFS;
9360ffd1 1442
1b8ec87a 1443 if (rdev->wiphy.wowlan->n_patterns) {
50ac6607 1444 struct nl80211_pattern_support pat = {
1b8ec87a
ZG
1445 .max_patterns = rdev->wiphy.wowlan->n_patterns,
1446 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len,
1447 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len,
1448 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset,
3713b4e3 1449 };
9360ffd1 1450
3713b4e3
JB
1451 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1452 sizeof(pat), &pat))
1453 return -ENOBUFS;
1454 }
9360ffd1 1455
75453ccb
LC
1456 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) &&
1457 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT,
1458 rdev->wiphy.wowlan->max_nd_match_sets))
1459 return -ENOBUFS;
1460
1b8ec87a 1461 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg))
b56cf720
JB
1462 return -ENOBUFS;
1463
3713b4e3 1464 nla_nest_end(msg, nl_wowlan);
9360ffd1 1465
3713b4e3
JB
1466 return 0;
1467}
1468#endif
9360ffd1 1469
be29b99a 1470static int nl80211_send_coalesce(struct sk_buff *msg,
1b8ec87a 1471 struct cfg80211_registered_device *rdev)
be29b99a
AK
1472{
1473 struct nl80211_coalesce_rule_support rule;
1474
1b8ec87a 1475 if (!rdev->wiphy.coalesce)
be29b99a
AK
1476 return 0;
1477
1b8ec87a
ZG
1478 rule.max_rules = rdev->wiphy.coalesce->n_rules;
1479 rule.max_delay = rdev->wiphy.coalesce->max_delay;
1480 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns;
1481 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len;
1482 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len;
1483 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset;
be29b99a
AK
1484
1485 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1486 return -ENOBUFS;
1487
1488 return 0;
1489}
1490
c4cbaf79
LC
1491static int
1492nl80211_send_iftype_data(struct sk_buff *msg,
1493 const struct ieee80211_sband_iftype_data *iftdata)
1494{
1495 const struct ieee80211_sta_he_cap *he_cap = &iftdata->he_cap;
1496
1497 if (nl80211_put_iftypes(msg, NL80211_BAND_IFTYPE_ATTR_IFTYPES,
1498 iftdata->types_mask))
1499 return -ENOBUFS;
1500
1501 if (he_cap->has_he) {
1502 if (nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_MAC,
1503 sizeof(he_cap->he_cap_elem.mac_cap_info),
1504 he_cap->he_cap_elem.mac_cap_info) ||
1505 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_PHY,
1506 sizeof(he_cap->he_cap_elem.phy_cap_info),
1507 he_cap->he_cap_elem.phy_cap_info) ||
1508 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_MCS_SET,
1509 sizeof(he_cap->he_mcs_nss_supp),
1510 &he_cap->he_mcs_nss_supp) ||
1511 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_PPE,
1512 sizeof(he_cap->ppe_thres), he_cap->ppe_thres))
1513 return -ENOBUFS;
1514 }
1515
1516 return 0;
1517}
1518
3713b4e3
JB
1519static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1520 struct ieee80211_supported_band *sband)
1521{
1522 struct nlattr *nl_rates, *nl_rate;
1523 struct ieee80211_rate *rate;
1524 int i;
87bbbe22 1525
3713b4e3
JB
1526 /* add HT info */
1527 if (sband->ht_cap.ht_supported &&
1528 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1529 sizeof(sband->ht_cap.mcs),
1530 &sband->ht_cap.mcs) ||
1531 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1532 sband->ht_cap.cap) ||
1533 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1534 sband->ht_cap.ampdu_factor) ||
1535 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1536 sband->ht_cap.ampdu_density)))
1537 return -ENOBUFS;
afe0cbf8 1538
3713b4e3
JB
1539 /* add VHT info */
1540 if (sband->vht_cap.vht_supported &&
1541 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1542 sizeof(sband->vht_cap.vht_mcs),
1543 &sband->vht_cap.vht_mcs) ||
1544 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1545 sband->vht_cap.cap)))
1546 return -ENOBUFS;
f59ac048 1547
c4cbaf79
LC
1548 if (sband->n_iftype_data) {
1549 struct nlattr *nl_iftype_data =
ae0be8de
MK
1550 nla_nest_start_noflag(msg,
1551 NL80211_BAND_ATTR_IFTYPE_DATA);
c4cbaf79
LC
1552 int err;
1553
1554 if (!nl_iftype_data)
1555 return -ENOBUFS;
1556
1557 for (i = 0; i < sband->n_iftype_data; i++) {
1558 struct nlattr *iftdata;
1559
ae0be8de 1560 iftdata = nla_nest_start_noflag(msg, i + 1);
c4cbaf79
LC
1561 if (!iftdata)
1562 return -ENOBUFS;
1563
1564 err = nl80211_send_iftype_data(msg,
1565 &sband->iftype_data[i]);
1566 if (err)
1567 return err;
1568
1569 nla_nest_end(msg, iftdata);
1570 }
1571
1572 nla_nest_end(msg, nl_iftype_data);
1573 }
1574
3713b4e3 1575 /* add bitrates */
ae0be8de 1576 nl_rates = nla_nest_start_noflag(msg, NL80211_BAND_ATTR_RATES);
3713b4e3
JB
1577 if (!nl_rates)
1578 return -ENOBUFS;
ee688b00 1579
3713b4e3 1580 for (i = 0; i < sband->n_bitrates; i++) {
ae0be8de 1581 nl_rate = nla_nest_start_noflag(msg, i);
3713b4e3
JB
1582 if (!nl_rate)
1583 return -ENOBUFS;
ee688b00 1584
3713b4e3
JB
1585 rate = &sband->bitrates[i];
1586 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1587 rate->bitrate))
1588 return -ENOBUFS;
1589 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1590 nla_put_flag(msg,
1591 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1592 return -ENOBUFS;
ee688b00 1593
3713b4e3
JB
1594 nla_nest_end(msg, nl_rate);
1595 }
d51626df 1596
3713b4e3 1597 nla_nest_end(msg, nl_rates);
bf0c111e 1598
3713b4e3
JB
1599 return 0;
1600}
ee688b00 1601
3713b4e3
JB
1602static int
1603nl80211_send_mgmt_stypes(struct sk_buff *msg,
1604 const struct ieee80211_txrx_stypes *mgmt_stypes)
1605{
1606 u16 stypes;
1607 struct nlattr *nl_ftypes, *nl_ifs;
1608 enum nl80211_iftype ift;
1609 int i;
ee688b00 1610
3713b4e3
JB
1611 if (!mgmt_stypes)
1612 return 0;
5dab3b8a 1613
ae0be8de 1614 nl_ifs = nla_nest_start_noflag(msg, NL80211_ATTR_TX_FRAME_TYPES);
3713b4e3
JB
1615 if (!nl_ifs)
1616 return -ENOBUFS;
e2f367f2 1617
3713b4e3 1618 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
ae0be8de 1619 nl_ftypes = nla_nest_start_noflag(msg, ift);
3713b4e3
JB
1620 if (!nl_ftypes)
1621 return -ENOBUFS;
1622 i = 0;
1623 stypes = mgmt_stypes[ift].tx;
1624 while (stypes) {
1625 if ((stypes & 1) &&
1626 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1627 (i << 4) | IEEE80211_FTYPE_MGMT))
1628 return -ENOBUFS;
1629 stypes >>= 1;
1630 i++;
ee688b00 1631 }
3713b4e3
JB
1632 nla_nest_end(msg, nl_ftypes);
1633 }
ee688b00 1634
3713b4e3 1635 nla_nest_end(msg, nl_ifs);
ee688b00 1636
ae0be8de 1637 nl_ifs = nla_nest_start_noflag(msg, NL80211_ATTR_RX_FRAME_TYPES);
3713b4e3
JB
1638 if (!nl_ifs)
1639 return -ENOBUFS;
ee688b00 1640
3713b4e3 1641 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
ae0be8de 1642 nl_ftypes = nla_nest_start_noflag(msg, ift);
3713b4e3
JB
1643 if (!nl_ftypes)
1644 return -ENOBUFS;
1645 i = 0;
1646 stypes = mgmt_stypes[ift].rx;
1647 while (stypes) {
1648 if ((stypes & 1) &&
1649 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1650 (i << 4) | IEEE80211_FTYPE_MGMT))
1651 return -ENOBUFS;
1652 stypes >>= 1;
1653 i++;
1654 }
1655 nla_nest_end(msg, nl_ftypes);
1656 }
1657 nla_nest_end(msg, nl_ifs);
ee688b00 1658
3713b4e3
JB
1659 return 0;
1660}
ee688b00 1661
1794899e
JB
1662#define CMD(op, n) \
1663 do { \
1664 if (rdev->ops->op) { \
1665 i++; \
1666 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1667 goto nla_put_failure; \
1668 } \
1669 } while (0)
1670
1671static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev,
1672 struct sk_buff *msg)
1673{
1674 int i = 0;
1675
1676 /*
1677 * do *NOT* add anything into this function, new things need to be
1678 * advertised only to new versions of userspace that can deal with
1679 * the split (and they can't possibly care about new features...
1680 */
1681 CMD(add_virtual_intf, NEW_INTERFACE);
1682 CMD(change_virtual_intf, SET_INTERFACE);
1683 CMD(add_key, NEW_KEY);
1684 CMD(start_ap, START_AP);
1685 CMD(add_station, NEW_STATION);
1686 CMD(add_mpath, NEW_MPATH);
1687 CMD(update_mesh_config, SET_MESH_CONFIG);
1688 CMD(change_bss, SET_BSS);
1689 CMD(auth, AUTHENTICATE);
1690 CMD(assoc, ASSOCIATE);
1691 CMD(deauth, DEAUTHENTICATE);
1692 CMD(disassoc, DISASSOCIATE);
1693 CMD(join_ibss, JOIN_IBSS);
1694 CMD(join_mesh, JOIN_MESH);
1695 CMD(set_pmksa, SET_PMKSA);
1696 CMD(del_pmksa, DEL_PMKSA);
1697 CMD(flush_pmksa, FLUSH_PMKSA);
1698 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1699 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1700 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1701 CMD(mgmt_tx, FRAME);
1702 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1703 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1704 i++;
1705 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1706 goto nla_put_failure;
1707 }
1708 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap ||
1709 rdev->ops->join_mesh) {
1710 i++;
1711 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1712 goto nla_put_failure;
1713 }
1714 CMD(set_wds_peer, SET_WDS_PEER);
1715 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1716 CMD(tdls_mgmt, TDLS_MGMT);
1717 CMD(tdls_oper, TDLS_OPER);
1718 }
ca986ad9 1719 if (rdev->wiphy.max_sched_scan_reqs)
1794899e
JB
1720 CMD(sched_scan_start, START_SCHED_SCAN);
1721 CMD(probe_client, PROBE_CLIENT);
1722 CMD(set_noack_map, SET_NOACK_MAP);
1723 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1724 i++;
1725 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1726 goto nla_put_failure;
1727 }
1728 CMD(start_p2p_device, START_P2P_DEVICE);
1729 CMD(set_mcast_rate, SET_MCAST_RATE);
1730#ifdef CONFIG_NL80211_TESTMODE
1731 CMD(testmode_cmd, TESTMODE);
1732#endif
1733
1734 if (rdev->ops->connect || rdev->ops->auth) {
1735 i++;
1736 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1737 goto nla_put_failure;
1738 }
1739
1740 if (rdev->ops->disconnect || rdev->ops->deauth) {
1741 i++;
1742 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1743 goto nla_put_failure;
1744 }
1745
1746 return i;
1747 nla_put_failure:
1748 return -ENOBUFS;
1749}
1750
9bb7e0f2
JB
1751static int
1752nl80211_send_pmsr_ftm_capa(const struct cfg80211_pmsr_capabilities *cap,
1753 struct sk_buff *msg)
1754{
1755 struct nlattr *ftm;
1756
1757 if (!cap->ftm.supported)
1758 return 0;
1759
ae0be8de 1760 ftm = nla_nest_start_noflag(msg, NL80211_PMSR_TYPE_FTM);
9bb7e0f2
JB
1761 if (!ftm)
1762 return -ENOBUFS;
1763
1764 if (cap->ftm.asap && nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_ASAP))
1765 return -ENOBUFS;
1766 if (cap->ftm.non_asap &&
1767 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_NON_ASAP))
1768 return -ENOBUFS;
1769 if (cap->ftm.request_lci &&
1770 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_REQ_LCI))
1771 return -ENOBUFS;
1772 if (cap->ftm.request_civicloc &&
1773 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_REQ_CIVICLOC))
1774 return -ENOBUFS;
1775 if (nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_PREAMBLES,
1776 cap->ftm.preambles))
1777 return -ENOBUFS;
1778 if (nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_BANDWIDTHS,
1779 cap->ftm.bandwidths))
1780 return -ENOBUFS;
1781 if (cap->ftm.max_bursts_exponent >= 0 &&
1782 nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_MAX_BURSTS_EXPONENT,
1783 cap->ftm.max_bursts_exponent))
1784 return -ENOBUFS;
1785 if (cap->ftm.max_ftms_per_burst &&
1786 nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_MAX_FTMS_PER_BURST,
1787 cap->ftm.max_ftms_per_burst))
1788 return -ENOBUFS;
1789
1790 nla_nest_end(msg, ftm);
1791 return 0;
1792}
1793
1794static int nl80211_send_pmsr_capa(struct cfg80211_registered_device *rdev,
1795 struct sk_buff *msg)
1796{
1797 const struct cfg80211_pmsr_capabilities *cap = rdev->wiphy.pmsr_capa;
1798 struct nlattr *pmsr, *caps;
1799
1800 if (!cap)
1801 return 0;
1802
1803 /*
1804 * we don't need to clean up anything here since the caller
1805 * will genlmsg_cancel() if we fail
1806 */
1807
ae0be8de 1808 pmsr = nla_nest_start_noflag(msg, NL80211_ATTR_PEER_MEASUREMENTS);
9bb7e0f2
JB
1809 if (!pmsr)
1810 return -ENOBUFS;
1811
1812 if (nla_put_u32(msg, NL80211_PMSR_ATTR_MAX_PEERS, cap->max_peers))
1813 return -ENOBUFS;
1814
1815 if (cap->report_ap_tsf &&
1816 nla_put_flag(msg, NL80211_PMSR_ATTR_REPORT_AP_TSF))
1817 return -ENOBUFS;
1818
1819 if (cap->randomize_mac_addr &&
1820 nla_put_flag(msg, NL80211_PMSR_ATTR_RANDOMIZE_MAC_ADDR))
1821 return -ENOBUFS;
1822
ae0be8de 1823 caps = nla_nest_start_noflag(msg, NL80211_PMSR_ATTR_TYPE_CAPA);
9bb7e0f2
JB
1824 if (!caps)
1825 return -ENOBUFS;
1826
1827 if (nl80211_send_pmsr_ftm_capa(cap, msg))
1828 return -ENOBUFS;
1829
1830 nla_nest_end(msg, caps);
1831 nla_nest_end(msg, pmsr);
1832
1833 return 0;
1834}
1835
86e8cf98
JB
1836struct nl80211_dump_wiphy_state {
1837 s64 filter_wiphy;
1838 long start;
019ae3a9 1839 long split_start, band_start, chan_start, capa_start;
86e8cf98
JB
1840 bool split;
1841};
1842
1b8ec87a 1843static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev,
3bb20556 1844 enum nl80211_commands cmd,
3713b4e3 1845 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 1846 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
1847{
1848 void *hdr;
1849 struct nlattr *nl_bands, *nl_band;
1850 struct nlattr *nl_freqs, *nl_freq;
1851 struct nlattr *nl_cmds;
57fbcce3 1852 enum nl80211_band band;
3713b4e3
JB
1853 struct ieee80211_channel *chan;
1854 int i;
1855 const struct ieee80211_txrx_stypes *mgmt_stypes =
1b8ec87a 1856 rdev->wiphy.mgmt_stypes;
fe1abafd 1857 u32 features;
ee688b00 1858
3bb20556 1859 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
3713b4e3
JB
1860 if (!hdr)
1861 return -ENOBUFS;
ee688b00 1862
86e8cf98
JB
1863 if (WARN_ON(!state))
1864 return -EINVAL;
ee688b00 1865
1b8ec87a 1866 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3713b4e3 1867 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1b8ec87a 1868 wiphy_name(&rdev->wiphy)) ||
3713b4e3
JB
1869 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1870 cfg80211_rdev_list_generation))
8fdc621d
JB
1871 goto nla_put_failure;
1872
3bb20556
JB
1873 if (cmd != NL80211_CMD_NEW_WIPHY)
1874 goto finish;
1875
86e8cf98 1876 switch (state->split_start) {
3713b4e3
JB
1877 case 0:
1878 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1b8ec87a 1879 rdev->wiphy.retry_short) ||
3713b4e3 1880 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1b8ec87a 1881 rdev->wiphy.retry_long) ||
3713b4e3 1882 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1b8ec87a 1883 rdev->wiphy.frag_threshold) ||
3713b4e3 1884 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1b8ec87a 1885 rdev->wiphy.rts_threshold) ||
3713b4e3 1886 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1b8ec87a 1887 rdev->wiphy.coverage_class) ||
3713b4e3 1888 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1b8ec87a 1889 rdev->wiphy.max_scan_ssids) ||
3713b4e3 1890 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1b8ec87a 1891 rdev->wiphy.max_sched_scan_ssids) ||
3713b4e3 1892 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1b8ec87a 1893 rdev->wiphy.max_scan_ie_len) ||
3713b4e3 1894 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1b8ec87a 1895 rdev->wiphy.max_sched_scan_ie_len) ||
3713b4e3 1896 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
3b06d277
AS
1897 rdev->wiphy.max_match_sets) ||
1898 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS,
1899 rdev->wiphy.max_sched_scan_plans) ||
1900 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL,
1901 rdev->wiphy.max_sched_scan_plan_interval) ||
1902 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS,
1903 rdev->wiphy.max_sched_scan_plan_iterations))
9360ffd1 1904 goto nla_put_failure;
3713b4e3 1905
1b8ec87a 1906 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
3713b4e3 1907 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 1908 goto nla_put_failure;
1b8ec87a 1909 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
3713b4e3
JB
1910 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
1911 goto nla_put_failure;
1b8ec87a 1912 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3713b4e3
JB
1913 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
1914 goto nla_put_failure;
1b8ec87a 1915 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
3713b4e3
JB
1916 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
1917 goto nla_put_failure;
1b8ec87a 1918 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
3713b4e3
JB
1919 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
1920 goto nla_put_failure;
1b8ec87a 1921 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
3713b4e3 1922 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 1923 goto nla_put_failure;
86e8cf98
JB
1924 state->split_start++;
1925 if (state->split)
3713b4e3 1926 break;
925b5978 1927 /* fall through */
3713b4e3
JB
1928 case 1:
1929 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1b8ec87a
ZG
1930 sizeof(u32) * rdev->wiphy.n_cipher_suites,
1931 rdev->wiphy.cipher_suites))
3713b4e3 1932 goto nla_put_failure;
4745fc09 1933
3713b4e3 1934 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1b8ec87a 1935 rdev->wiphy.max_num_pmkids))
3713b4e3 1936 goto nla_put_failure;
b23aa676 1937
1b8ec87a 1938 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3713b4e3 1939 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 1940 goto nla_put_failure;
b23aa676 1941
3713b4e3 1942 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1b8ec87a 1943 rdev->wiphy.available_antennas_tx) ||
3713b4e3 1944 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1b8ec87a 1945 rdev->wiphy.available_antennas_rx))
9360ffd1 1946 goto nla_put_failure;
b23aa676 1947
1b8ec87a 1948 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
3713b4e3 1949 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1b8ec87a 1950 rdev->wiphy.probe_resp_offload))
3713b4e3 1951 goto nla_put_failure;
8fdc621d 1952
1b8ec87a
ZG
1953 if ((rdev->wiphy.available_antennas_tx ||
1954 rdev->wiphy.available_antennas_rx) &&
1955 rdev->ops->get_antenna) {
3713b4e3
JB
1956 u32 tx_ant = 0, rx_ant = 0;
1957 int res;
7a087e74 1958
1b8ec87a 1959 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant);
3713b4e3
JB
1960 if (!res) {
1961 if (nla_put_u32(msg,
1962 NL80211_ATTR_WIPHY_ANTENNA_TX,
1963 tx_ant) ||
1964 nla_put_u32(msg,
1965 NL80211_ATTR_WIPHY_ANTENNA_RX,
1966 rx_ant))
1967 goto nla_put_failure;
1968 }
1969 }
a293911d 1970
86e8cf98
JB
1971 state->split_start++;
1972 if (state->split)
3713b4e3 1973 break;
925b5978 1974 /* fall through */
3713b4e3
JB
1975 case 2:
1976 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1b8ec87a 1977 rdev->wiphy.interface_modes))
3713b4e3 1978 goto nla_put_failure;
86e8cf98
JB
1979 state->split_start++;
1980 if (state->split)
3713b4e3 1981 break;
925b5978 1982 /* fall through */
3713b4e3 1983 case 3:
ae0be8de
MK
1984 nl_bands = nla_nest_start_noflag(msg,
1985 NL80211_ATTR_WIPHY_BANDS);
3713b4e3
JB
1986 if (!nl_bands)
1987 goto nla_put_failure;
f7ca38df 1988
86e8cf98 1989 for (band = state->band_start;
57fbcce3 1990 band < NUM_NL80211_BANDS; band++) {
3713b4e3 1991 struct ieee80211_supported_band *sband;
2e161f78 1992
1b8ec87a 1993 sband = rdev->wiphy.bands[band];
2e161f78 1994
3713b4e3
JB
1995 if (!sband)
1996 continue;
1997
ae0be8de 1998 nl_band = nla_nest_start_noflag(msg, band);
3713b4e3 1999 if (!nl_band)
2e161f78 2000 goto nla_put_failure;
3713b4e3 2001
86e8cf98 2002 switch (state->chan_start) {
3713b4e3
JB
2003 case 0:
2004 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 2005 goto nla_put_failure;
86e8cf98
JB
2006 state->chan_start++;
2007 if (state->split)
3713b4e3 2008 break;
925b5978 2009 /* fall through */
3713b4e3
JB
2010 default:
2011 /* add frequencies */
ae0be8de
MK
2012 nl_freqs = nla_nest_start_noflag(msg,
2013 NL80211_BAND_ATTR_FREQS);
3713b4e3
JB
2014 if (!nl_freqs)
2015 goto nla_put_failure;
2016
86e8cf98 2017 for (i = state->chan_start - 1;
3713b4e3
JB
2018 i < sband->n_channels;
2019 i++) {
ae0be8de
MK
2020 nl_freq = nla_nest_start_noflag(msg,
2021 i);
3713b4e3
JB
2022 if (!nl_freq)
2023 goto nla_put_failure;
2024
2025 chan = &sband->channels[i];
2026
86e8cf98 2027 if (nl80211_msg_put_channel(
50f32718 2028 msg, &rdev->wiphy, chan,
86e8cf98 2029 state->split))
3713b4e3
JB
2030 goto nla_put_failure;
2031
2032 nla_nest_end(msg, nl_freq);
86e8cf98 2033 if (state->split)
3713b4e3
JB
2034 break;
2035 }
2036 if (i < sband->n_channels)
86e8cf98 2037 state->chan_start = i + 2;
3713b4e3 2038 else
86e8cf98 2039 state->chan_start = 0;
3713b4e3
JB
2040 nla_nest_end(msg, nl_freqs);
2041 }
2042
2043 nla_nest_end(msg, nl_band);
2044
86e8cf98 2045 if (state->split) {
3713b4e3 2046 /* start again here */
86e8cf98 2047 if (state->chan_start)
3713b4e3
JB
2048 band--;
2049 break;
2e161f78 2050 }
2e161f78 2051 }
3713b4e3 2052 nla_nest_end(msg, nl_bands);
2e161f78 2053
57fbcce3 2054 if (band < NUM_NL80211_BANDS)
86e8cf98 2055 state->band_start = band + 1;
3713b4e3 2056 else
86e8cf98 2057 state->band_start = 0;
74b70a4e 2058
3713b4e3 2059 /* if bands & channels are done, continue outside */
86e8cf98
JB
2060 if (state->band_start == 0 && state->chan_start == 0)
2061 state->split_start++;
2062 if (state->split)
3713b4e3 2063 break;
925b5978 2064 /* fall through */
3713b4e3 2065 case 4:
ae0be8de
MK
2066 nl_cmds = nla_nest_start_noflag(msg,
2067 NL80211_ATTR_SUPPORTED_COMMANDS);
3713b4e3 2068 if (!nl_cmds)
2e161f78
JB
2069 goto nla_put_failure;
2070
1794899e
JB
2071 i = nl80211_add_commands_unsplit(rdev, msg);
2072 if (i < 0)
2073 goto nla_put_failure;
86e8cf98 2074 if (state->split) {
5de17984
AS
2075 CMD(crit_proto_start, CRIT_PROTOCOL_START);
2076 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
1b8ec87a 2077 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
16ef1fe2 2078 CMD(channel_switch, CHANNEL_SWITCH);
02df00eb 2079 CMD(set_qos_map, SET_QOS_MAP);
723e73ac
JB
2080 if (rdev->wiphy.features &
2081 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)
960d01ac 2082 CMD(add_tx_ts, ADD_TX_TS);
ce0ce13a 2083 CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST);
088e8df8 2084 CMD(update_connect_params, UPDATE_CONNECT_PARAMS);
5de17984 2085 }
3713b4e3 2086#undef CMD
ff1b6e69 2087
3713b4e3 2088 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
2089 state->split_start++;
2090 if (state->split)
3713b4e3 2091 break;
925b5978 2092 /* fall through */
3713b4e3 2093 case 5:
1b8ec87a
ZG
2094 if (rdev->ops->remain_on_channel &&
2095 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
3713b4e3
JB
2096 nla_put_u32(msg,
2097 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1b8ec87a 2098 rdev->wiphy.max_remain_on_channel_duration))
3713b4e3
JB
2099 goto nla_put_failure;
2100
1b8ec87a 2101 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
3713b4e3
JB
2102 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
2103 goto nla_put_failure;
2104
2105 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
2106 goto nla_put_failure;
86e8cf98
JB
2107 state->split_start++;
2108 if (state->split)
3713b4e3 2109 break;
925b5978 2110 /* fall through */
3713b4e3
JB
2111 case 6:
2112#ifdef CONFIG_PM
1b8ec87a 2113 if (nl80211_send_wowlan(msg, rdev, state->split))
3713b4e3 2114 goto nla_put_failure;
86e8cf98
JB
2115 state->split_start++;
2116 if (state->split)
3713b4e3
JB
2117 break;
2118#else
86e8cf98 2119 state->split_start++;
dfb89c56 2120#endif
925b5978 2121 /* fall through */
3713b4e3
JB
2122 case 7:
2123 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1b8ec87a 2124 rdev->wiphy.software_iftypes))
3713b4e3 2125 goto nla_put_failure;
ff1b6e69 2126
1b8ec87a 2127 if (nl80211_put_iface_combinations(&rdev->wiphy, msg,
86e8cf98 2128 state->split))
3713b4e3 2129 goto nla_put_failure;
7527a782 2130
86e8cf98
JB
2131 state->split_start++;
2132 if (state->split)
3713b4e3 2133 break;
925b5978 2134 /* fall through */
3713b4e3 2135 case 8:
1b8ec87a 2136 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
3713b4e3 2137 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1b8ec87a 2138 rdev->wiphy.ap_sme_capa))
3713b4e3 2139 goto nla_put_failure;
7527a782 2140
1b8ec87a 2141 features = rdev->wiphy.features;
fe1abafd
JB
2142 /*
2143 * We can only add the per-channel limit information if the
2144 * dump is split, otherwise it makes it too big. Therefore
2145 * only advertise it in that case.
2146 */
86e8cf98 2147 if (state->split)
fe1abafd
JB
2148 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
2149 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 2150 goto nla_put_failure;
562a7480 2151
1b8ec87a 2152 if (rdev->wiphy.ht_capa_mod_mask &&
3713b4e3 2153 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1b8ec87a
ZG
2154 sizeof(*rdev->wiphy.ht_capa_mod_mask),
2155 rdev->wiphy.ht_capa_mod_mask))
3713b4e3 2156 goto nla_put_failure;
1f074bd8 2157
1b8ec87a
ZG
2158 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
2159 rdev->wiphy.max_acl_mac_addrs &&
3713b4e3 2160 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1b8ec87a 2161 rdev->wiphy.max_acl_mac_addrs))
3713b4e3 2162 goto nla_put_failure;
7e7c8926 2163
3713b4e3
JB
2164 /*
2165 * Any information below this point is only available to
2166 * applications that can deal with it being split. This
2167 * helps ensure that newly added capabilities don't break
2168 * older tools by overrunning their buffers.
2169 *
2170 * We still increment split_start so that in the split
2171 * case we'll continue with more data in the next round,
2172 * but break unconditionally so unsplit data stops here.
2173 */
86e8cf98 2174 state->split_start++;
3713b4e3
JB
2175 break;
2176 case 9:
1b8ec87a 2177 if (rdev->wiphy.extended_capabilities &&
fe1abafd 2178 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1b8ec87a
ZG
2179 rdev->wiphy.extended_capabilities_len,
2180 rdev->wiphy.extended_capabilities) ||
fe1abafd 2181 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1b8ec87a
ZG
2182 rdev->wiphy.extended_capabilities_len,
2183 rdev->wiphy.extended_capabilities_mask)))
fe1abafd 2184 goto nla_put_failure;
a50df0c4 2185
1b8ec87a 2186 if (rdev->wiphy.vht_capa_mod_mask &&
ee2aca34 2187 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1b8ec87a
ZG
2188 sizeof(*rdev->wiphy.vht_capa_mod_mask),
2189 rdev->wiphy.vht_capa_mod_mask))
ee2aca34
JB
2190 goto nla_put_failure;
2191
ae6fa4d5
DK
2192 if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN,
2193 rdev->wiphy.perm_addr))
2194 goto nla_put_failure;
2195
2196 if (!is_zero_ether_addr(rdev->wiphy.addr_mask) &&
2197 nla_put(msg, NL80211_ATTR_MAC_MASK, ETH_ALEN,
2198 rdev->wiphy.addr_mask))
2199 goto nla_put_failure;
2200
2201 if (rdev->wiphy.n_addresses > 1) {
2202 void *attr;
2203
2204 attr = nla_nest_start(msg, NL80211_ATTR_MAC_ADDRS);
2205 if (!attr)
2206 goto nla_put_failure;
2207
2208 for (i = 0; i < rdev->wiphy.n_addresses; i++)
2209 if (nla_put(msg, i + 1, ETH_ALEN,
2210 rdev->wiphy.addresses[i].addr))
2211 goto nla_put_failure;
2212
2213 nla_nest_end(msg, attr);
2214 }
2215
be29b99a
AK
2216 state->split_start++;
2217 break;
2218 case 10:
1b8ec87a 2219 if (nl80211_send_coalesce(msg, rdev))
be29b99a
AK
2220 goto nla_put_failure;
2221
1b8ec87a 2222 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
01e0daa4
FF
2223 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
2224 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
2225 goto nla_put_failure;
b43504cf 2226
1b8ec87a 2227 if (rdev->wiphy.max_ap_assoc_sta &&
b43504cf 2228 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
1b8ec87a 2229 rdev->wiphy.max_ap_assoc_sta))
b43504cf
JM
2230 goto nla_put_failure;
2231
ad7e718c
JB
2232 state->split_start++;
2233 break;
2234 case 11:
1b8ec87a 2235 if (rdev->wiphy.n_vendor_commands) {
567ffc35
JB
2236 const struct nl80211_vendor_cmd_info *info;
2237 struct nlattr *nested;
2238
ae0be8de
MK
2239 nested = nla_nest_start_noflag(msg,
2240 NL80211_ATTR_VENDOR_DATA);
567ffc35
JB
2241 if (!nested)
2242 goto nla_put_failure;
2243
1b8ec87a
ZG
2244 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
2245 info = &rdev->wiphy.vendor_commands[i].info;
567ffc35
JB
2246 if (nla_put(msg, i + 1, sizeof(*info), info))
2247 goto nla_put_failure;
2248 }
2249 nla_nest_end(msg, nested);
2250 }
2251
1b8ec87a 2252 if (rdev->wiphy.n_vendor_events) {
567ffc35
JB
2253 const struct nl80211_vendor_cmd_info *info;
2254 struct nlattr *nested;
ad7e718c 2255
ae0be8de
MK
2256 nested = nla_nest_start_noflag(msg,
2257 NL80211_ATTR_VENDOR_EVENTS);
567ffc35 2258 if (!nested)
ad7e718c 2259 goto nla_put_failure;
567ffc35 2260
1b8ec87a
ZG
2261 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) {
2262 info = &rdev->wiphy.vendor_events[i];
567ffc35
JB
2263 if (nla_put(msg, i + 1, sizeof(*info), info))
2264 goto nla_put_failure;
2265 }
2266 nla_nest_end(msg, nested);
2267 }
9a774c78
AO
2268 state->split_start++;
2269 break;
2270 case 12:
2271 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH &&
2272 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS,
2273 rdev->wiphy.max_num_csa_counters))
2274 goto nla_put_failure;
01e0daa4 2275
1bdd716c
AN
2276 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
2277 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
2278 goto nla_put_failure;
2279
ca986ad9
AVS
2280 if (rdev->wiphy.max_sched_scan_reqs &&
2281 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_MAX_REQS,
2282 rdev->wiphy.max_sched_scan_reqs))
2283 goto nla_put_failure;
2284
d75bb06b
GKS
2285 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES,
2286 sizeof(rdev->wiphy.ext_features),
2287 rdev->wiphy.ext_features))
2288 goto nla_put_failure;
2289
38de03d2
AS
2290 if (rdev->wiphy.bss_select_support) {
2291 struct nlattr *nested;
2292 u32 bss_select_support = rdev->wiphy.bss_select_support;
2293
ae0be8de
MK
2294 nested = nla_nest_start_noflag(msg,
2295 NL80211_ATTR_BSS_SELECT);
38de03d2
AS
2296 if (!nested)
2297 goto nla_put_failure;
2298
2299 i = 0;
2300 while (bss_select_support) {
2301 if ((bss_select_support & 1) &&
2302 nla_put_flag(msg, i))
2303 goto nla_put_failure;
2304 i++;
2305 bss_select_support >>= 1;
2306 }
2307 nla_nest_end(msg, nested);
2308 }
2309
019ae3a9
KV
2310 state->split_start++;
2311 break;
2312 case 13:
2313 if (rdev->wiphy.num_iftype_ext_capab &&
2314 rdev->wiphy.iftype_ext_capab) {
2315 struct nlattr *nested_ext_capab, *nested;
2316
ae0be8de
MK
2317 nested = nla_nest_start_noflag(msg,
2318 NL80211_ATTR_IFTYPE_EXT_CAPA);
019ae3a9
KV
2319 if (!nested)
2320 goto nla_put_failure;
2321
2322 for (i = state->capa_start;
2323 i < rdev->wiphy.num_iftype_ext_capab; i++) {
2324 const struct wiphy_iftype_ext_capab *capab;
2325
2326 capab = &rdev->wiphy.iftype_ext_capab[i];
2327
ae0be8de
MK
2328 nested_ext_capab = nla_nest_start_noflag(msg,
2329 i);
019ae3a9
KV
2330 if (!nested_ext_capab ||
2331 nla_put_u32(msg, NL80211_ATTR_IFTYPE,
2332 capab->iftype) ||
2333 nla_put(msg, NL80211_ATTR_EXT_CAPA,
2334 capab->extended_capabilities_len,
2335 capab->extended_capabilities) ||
2336 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
2337 capab->extended_capabilities_len,
2338 capab->extended_capabilities_mask))
2339 goto nla_put_failure;
2340
2341 nla_nest_end(msg, nested_ext_capab);
2342 if (state->split)
2343 break;
2344 }
2345 nla_nest_end(msg, nested);
2346 if (i < rdev->wiphy.num_iftype_ext_capab) {
2347 state->capa_start = i + 1;
2348 break;
2349 }
2350 }
2351
8585989d
LC
2352 if (nla_put_u32(msg, NL80211_ATTR_BANDS,
2353 rdev->wiphy.nan_supported_bands))
2354 goto nla_put_failure;
2355
52539ca8
THJ
2356 if (wiphy_ext_feature_isset(&rdev->wiphy,
2357 NL80211_EXT_FEATURE_TXQS)) {
2358 struct cfg80211_txq_stats txqstats = {};
2359 int res;
2360
2361 res = rdev_get_txq_stats(rdev, NULL, &txqstats);
2362 if (!res &&
2363 !nl80211_put_txq_stats(msg, &txqstats,
2364 NL80211_ATTR_TXQ_STATS))
2365 goto nla_put_failure;
2366
2367 if (nla_put_u32(msg, NL80211_ATTR_TXQ_LIMIT,
2368 rdev->wiphy.txq_limit))
2369 goto nla_put_failure;
2370 if (nla_put_u32(msg, NL80211_ATTR_TXQ_MEMORY_LIMIT,
2371 rdev->wiphy.txq_memory_limit))
2372 goto nla_put_failure;
2373 if (nla_put_u32(msg, NL80211_ATTR_TXQ_QUANTUM,
2374 rdev->wiphy.txq_quantum))
2375 goto nla_put_failure;
2376 }
2377
9bb7e0f2
JB
2378 state->split_start++;
2379 break;
2380 case 14:
2381 if (nl80211_send_pmsr_capa(rdev, msg))
2382 goto nla_put_failure;
2383
ab4dfa20
VJ
2384 state->split_start++;
2385 break;
2386 case 15:
2387 if (rdev->wiphy.akm_suites &&
2388 nla_put(msg, NL80211_ATTR_AKM_SUITES,
2389 sizeof(u32) * rdev->wiphy.n_akm_suites,
2390 rdev->wiphy.akm_suites))
2391 goto nla_put_failure;
2392
3713b4e3 2393 /* done */
86e8cf98 2394 state->split_start = 0;
3713b4e3
JB
2395 break;
2396 }
3bb20556 2397 finish:
053c095a
JB
2398 genlmsg_end(msg, hdr);
2399 return 0;
55682965
JB
2400
2401 nla_put_failure:
bc3ed28c
TG
2402 genlmsg_cancel(msg, hdr);
2403 return -EMSGSIZE;
55682965
JB
2404}
2405
86e8cf98
JB
2406static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
2407 struct netlink_callback *cb,
2408 struct nl80211_dump_wiphy_state *state)
2409{
50508d94
JB
2410 struct nlattr **tb = kcalloc(NUM_NL80211_ATTR, sizeof(*tb), GFP_KERNEL);
2411 int ret;
2412
2413 if (!tb)
2414 return -ENOMEM;
2415
2416 ret = nlmsg_parse_deprecated(cb->nlh,
2417 GENL_HDRLEN + nl80211_fam.hdrsize,
2418 tb, nl80211_fam.maxattr,
2419 nl80211_policy, NULL);
86e8cf98 2420 /* ignore parse errors for backward compatibility */
50508d94
JB
2421 if (ret) {
2422 ret = 0;
2423 goto out;
2424 }
86e8cf98
JB
2425
2426 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
2427 if (tb[NL80211_ATTR_WIPHY])
2428 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
2429 if (tb[NL80211_ATTR_WDEV])
2430 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
2431 if (tb[NL80211_ATTR_IFINDEX]) {
2432 struct net_device *netdev;
2433 struct cfg80211_registered_device *rdev;
2434 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
2435
7f2b8562 2436 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
50508d94
JB
2437 if (!netdev) {
2438 ret = -ENODEV;
2439 goto out;
2440 }
86e8cf98 2441 if (netdev->ieee80211_ptr) {
f26cbf40 2442 rdev = wiphy_to_rdev(
86e8cf98
JB
2443 netdev->ieee80211_ptr->wiphy);
2444 state->filter_wiphy = rdev->wiphy_idx;
2445 }
86e8cf98
JB
2446 }
2447
50508d94
JB
2448 ret = 0;
2449out:
2450 kfree(tb);
2451 return ret;
86e8cf98
JB
2452}
2453
55682965
JB
2454static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
2455{
645e77de 2456 int idx = 0, ret;
86e8cf98 2457 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
1b8ec87a 2458 struct cfg80211_registered_device *rdev;
3a5a423b 2459
5fe231e8 2460 rtnl_lock();
86e8cf98
JB
2461 if (!state) {
2462 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
2463 if (!state) {
2464 rtnl_unlock();
86e8cf98 2465 return -ENOMEM;
3713b4e3 2466 }
86e8cf98
JB
2467 state->filter_wiphy = -1;
2468 ret = nl80211_dump_wiphy_parse(skb, cb, state);
2469 if (ret) {
2470 kfree(state);
2471 rtnl_unlock();
2472 return ret;
3713b4e3 2473 }
86e8cf98 2474 cb->args[0] = (long)state;
3713b4e3
JB
2475 }
2476
1b8ec87a
ZG
2477 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2478 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2479 continue;
86e8cf98 2480 if (++idx <= state->start)
55682965 2481 continue;
86e8cf98 2482 if (state->filter_wiphy != -1 &&
1b8ec87a 2483 state->filter_wiphy != rdev->wiphy_idx)
3713b4e3
JB
2484 continue;
2485 /* attempt to fit multiple wiphy data chunks into the skb */
2486 do {
3bb20556
JB
2487 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY,
2488 skb,
3713b4e3
JB
2489 NETLINK_CB(cb->skb).portid,
2490 cb->nlh->nlmsg_seq,
86e8cf98 2491 NLM_F_MULTI, state);
3713b4e3
JB
2492 if (ret < 0) {
2493 /*
2494 * If sending the wiphy data didn't fit (ENOBUFS
2495 * or EMSGSIZE returned), this SKB is still
2496 * empty (so it's not too big because another
2497 * wiphy dataset is already in the skb) and
2498 * we've not tried to adjust the dump allocation
2499 * yet ... then adjust the alloc size to be
2500 * bigger, and return 1 but with the empty skb.
2501 * This results in an empty message being RX'ed
2502 * in userspace, but that is ignored.
2503 *
2504 * We can then retry with the larger buffer.
2505 */
2506 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
f12cb289 2507 !skb->len && !state->split &&
3713b4e3
JB
2508 cb->min_dump_alloc < 4096) {
2509 cb->min_dump_alloc = 4096;
f12cb289 2510 state->split_start = 0;
d98cae64 2511 rtnl_unlock();
3713b4e3
JB
2512 return 1;
2513 }
2514 idx--;
2515 break;
645e77de 2516 }
86e8cf98 2517 } while (state->split_start > 0);
3713b4e3 2518 break;
55682965 2519 }
5fe231e8 2520 rtnl_unlock();
55682965 2521
86e8cf98 2522 state->start = idx;
55682965
JB
2523
2524 return skb->len;
2525}
2526
86e8cf98
JB
2527static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
2528{
2529 kfree((void *)cb->args[0]);
2530 return 0;
2531}
2532
55682965
JB
2533static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
2534{
2535 struct sk_buff *msg;
1b8ec87a 2536 struct cfg80211_registered_device *rdev = info->user_ptr[0];
86e8cf98 2537 struct nl80211_dump_wiphy_state state = {};
55682965 2538
645e77de 2539 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 2540 if (!msg)
4c476991 2541 return -ENOMEM;
55682965 2542
3bb20556
JB
2543 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg,
2544 info->snd_portid, info->snd_seq, 0,
86e8cf98 2545 &state) < 0) {
4c476991
JB
2546 nlmsg_free(msg);
2547 return -ENOBUFS;
2548 }
55682965 2549
134e6375 2550 return genlmsg_reply(msg, info);
55682965
JB
2551}
2552
31888487
JM
2553static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
2554 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
2555 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
2556 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
2557 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
2558 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
2559};
2560
2561static int parse_txq_params(struct nlattr *tb[],
2562 struct ieee80211_txq_params *txq_params)
2563{
259d8c1e
DW
2564 u8 ac;
2565
a3304b0a 2566 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
2567 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
2568 !tb[NL80211_TXQ_ATTR_AIFS])
2569 return -EINVAL;
2570
259d8c1e 2571 ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
2572 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
2573 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
2574 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
2575 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
2576
259d8c1e 2577 if (ac >= NL80211_NUM_ACS)
a3304b0a 2578 return -EINVAL;
259d8c1e 2579 txq_params->ac = array_index_nospec(ac, NL80211_NUM_ACS);
31888487
JM
2580 return 0;
2581}
2582
f444de05
JB
2583static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
2584{
2585 /*
cc1d2806
JB
2586 * You can only set the channel explicitly for WDS interfaces,
2587 * all others have their channel managed via their respective
2588 * "establish a connection" command (connect, join, ...)
2589 *
2590 * For AP/GO and mesh mode, the channel can be set with the
2591 * channel userspace API, but is only stored and passed to the
2592 * low-level driver when the AP starts or the mesh is joined.
2593 * This is for backward compatibility, userspace can also give
2594 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
2595 *
2596 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
2597 * whatever else is going on, so they have their own special
2598 * operation to set the monitor channel if possible.
f444de05
JB
2599 */
2600 return !wdev ||
2601 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 2602 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
2603 wdev->iftype == NL80211_IFTYPE_MONITOR ||
2604 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
2605}
2606
9bb7e0f2
JB
2607int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
2608 struct genl_info *info,
2609 struct cfg80211_chan_def *chandef)
683b6d3b 2610{
49f9cf0e
JB
2611 struct netlink_ext_ack *extack = info->extack;
2612 struct nlattr **attrs = info->attrs;
dbeca2ea 2613 u32 control_freq;
683b6d3b 2614
49f9cf0e 2615 if (!attrs[NL80211_ATTR_WIPHY_FREQ])
683b6d3b
JB
2616 return -EINVAL;
2617
49f9cf0e 2618 control_freq = nla_get_u32(attrs[NL80211_ATTR_WIPHY_FREQ]);
683b6d3b
JB
2619
2620 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq);
3d9d1d66
JB
2621 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
2622 chandef->center_freq1 = control_freq;
2623 chandef->center_freq2 = 0;
683b6d3b
JB
2624
2625 /* Primary channel not allowed */
49f9cf0e
JB
2626 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED) {
2627 NL_SET_ERR_MSG_ATTR(extack, attrs[NL80211_ATTR_WIPHY_FREQ],
2628 "Channel is disabled");
683b6d3b 2629 return -EINVAL;
49f9cf0e 2630 }
683b6d3b 2631
49f9cf0e 2632 if (attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
3d9d1d66
JB
2633 enum nl80211_channel_type chantype;
2634
49f9cf0e 2635 chantype = nla_get_u32(attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
3d9d1d66
JB
2636
2637 switch (chantype) {
2638 case NL80211_CHAN_NO_HT:
2639 case NL80211_CHAN_HT20:
2640 case NL80211_CHAN_HT40PLUS:
2641 case NL80211_CHAN_HT40MINUS:
2642 cfg80211_chandef_create(chandef, chandef->chan,
2643 chantype);
ffa4629e 2644 /* user input for center_freq is incorrect */
49f9cf0e
JB
2645 if (attrs[NL80211_ATTR_CENTER_FREQ1] &&
2646 chandef->center_freq1 != nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ1])) {
2647 NL_SET_ERR_MSG_ATTR(extack,
2648 attrs[NL80211_ATTR_CENTER_FREQ1],
2649 "bad center frequency 1");
ffa4629e 2650 return -EINVAL;
49f9cf0e 2651 }
ffa4629e 2652 /* center_freq2 must be zero */
49f9cf0e
JB
2653 if (attrs[NL80211_ATTR_CENTER_FREQ2] &&
2654 nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ2])) {
2655 NL_SET_ERR_MSG_ATTR(extack,
2656 attrs[NL80211_ATTR_CENTER_FREQ2],
2657 "center frequency 2 can't be used");
ffa4629e 2658 return -EINVAL;
49f9cf0e 2659 }
3d9d1d66
JB
2660 break;
2661 default:
49f9cf0e
JB
2662 NL_SET_ERR_MSG_ATTR(extack,
2663 attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE],
2664 "invalid channel type");
3d9d1d66
JB
2665 return -EINVAL;
2666 }
49f9cf0e 2667 } else if (attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
3d9d1d66 2668 chandef->width =
49f9cf0e
JB
2669 nla_get_u32(attrs[NL80211_ATTR_CHANNEL_WIDTH]);
2670 if (attrs[NL80211_ATTR_CENTER_FREQ1])
3d9d1d66 2671 chandef->center_freq1 =
49f9cf0e
JB
2672 nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ1]);
2673 if (attrs[NL80211_ATTR_CENTER_FREQ2])
3d9d1d66 2674 chandef->center_freq2 =
49f9cf0e 2675 nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ2]);
3d9d1d66
JB
2676 }
2677
49f9cf0e
JB
2678 if (!cfg80211_chandef_valid(chandef)) {
2679 NL_SET_ERR_MSG(extack, "invalid channel definition");
3d9d1d66 2680 return -EINVAL;
49f9cf0e 2681 }
3d9d1d66 2682
9f5e8f6e 2683 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
49f9cf0e
JB
2684 IEEE80211_CHAN_DISABLED)) {
2685 NL_SET_ERR_MSG(extack, "(extension) channel is disabled");
3d9d1d66 2686 return -EINVAL;
49f9cf0e 2687 }
3d9d1d66 2688
2f301ab2
SW
2689 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
2690 chandef->width == NL80211_CHAN_WIDTH_10) &&
49f9cf0e
JB
2691 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ)) {
2692 NL_SET_ERR_MSG(extack, "5/10 MHz not supported");
2f301ab2 2693 return -EINVAL;
49f9cf0e 2694 }
2f301ab2 2695
683b6d3b
JB
2696 return 0;
2697}
2698
f444de05 2699static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
e16821bc 2700 struct net_device *dev,
f444de05
JB
2701 struct genl_info *info)
2702{
683b6d3b 2703 struct cfg80211_chan_def chandef;
f444de05 2704 int result;
e8c9bd5b 2705 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
e16821bc 2706 struct wireless_dev *wdev = NULL;
e8c9bd5b 2707
e16821bc
JM
2708 if (dev)
2709 wdev = dev->ieee80211_ptr;
f444de05
JB
2710 if (!nl80211_can_set_dev_channel(wdev))
2711 return -EOPNOTSUPP;
e16821bc
JM
2712 if (wdev)
2713 iftype = wdev->iftype;
f444de05 2714
683b6d3b
JB
2715 result = nl80211_parse_chandef(rdev, info, &chandef);
2716 if (result)
2717 return result;
f444de05 2718
e8c9bd5b 2719 switch (iftype) {
aa430da4
JB
2720 case NL80211_IFTYPE_AP:
2721 case NL80211_IFTYPE_P2P_GO:
923b352f
AN
2722 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
2723 iftype)) {
aa430da4
JB
2724 result = -EINVAL;
2725 break;
2726 }
e16821bc
JM
2727 if (wdev->beacon_interval) {
2728 if (!dev || !rdev->ops->set_ap_chanwidth ||
2729 !(rdev->wiphy.features &
2730 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) {
2731 result = -EBUSY;
2732 break;
2733 }
2734
2735 /* Only allow dynamic channel width changes */
2736 if (chandef.chan != wdev->preset_chandef.chan) {
2737 result = -EBUSY;
2738 break;
2739 }
2740 result = rdev_set_ap_chanwidth(rdev, dev, &chandef);
2741 if (result)
2742 break;
2743 }
683b6d3b 2744 wdev->preset_chandef = chandef;
aa430da4
JB
2745 result = 0;
2746 break;
cc1d2806 2747 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 2748 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 2749 break;
e8c9bd5b 2750 case NL80211_IFTYPE_MONITOR:
683b6d3b 2751 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 2752 break;
aa430da4 2753 default:
e8c9bd5b 2754 result = -EINVAL;
f444de05 2755 }
f444de05
JB
2756
2757 return result;
2758}
2759
2760static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
2761{
4c476991
JB
2762 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2763 struct net_device *netdev = info->user_ptr[1];
f444de05 2764
e16821bc 2765 return __nl80211_set_channel(rdev, netdev, info);
f444de05
JB
2766}
2767
e8347eba
BJ
2768static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
2769{
43b19952
JB
2770 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2771 struct net_device *dev = info->user_ptr[1];
2772 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 2773 const u8 *bssid;
e8347eba
BJ
2774
2775 if (!info->attrs[NL80211_ATTR_MAC])
2776 return -EINVAL;
2777
43b19952
JB
2778 if (netif_running(dev))
2779 return -EBUSY;
e8347eba 2780
43b19952
JB
2781 if (!rdev->ops->set_wds_peer)
2782 return -EOPNOTSUPP;
e8347eba 2783
43b19952
JB
2784 if (wdev->iftype != NL80211_IFTYPE_WDS)
2785 return -EOPNOTSUPP;
e8347eba
BJ
2786
2787 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 2788 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
2789}
2790
55682965
JB
2791static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
2792{
2793 struct cfg80211_registered_device *rdev;
f444de05
JB
2794 struct net_device *netdev = NULL;
2795 struct wireless_dev *wdev;
a1e567c8 2796 int result = 0, rem_txq_params = 0;
31888487 2797 struct nlattr *nl_txq_params;
b9a5f8ca
JM
2798 u32 changed;
2799 u8 retry_short = 0, retry_long = 0;
2800 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 2801 u8 coverage_class = 0;
52539ca8 2802 u32 txq_limit = 0, txq_memory_limit = 0, txq_quantum = 0;
55682965 2803
5fe231e8
JB
2804 ASSERT_RTNL();
2805
f444de05
JB
2806 /*
2807 * Try to find the wiphy and netdev. Normally this
2808 * function shouldn't need the netdev, but this is
2809 * done for backward compatibility -- previously
2810 * setting the channel was done per wiphy, but now
2811 * it is per netdev. Previous userland like hostapd
2812 * also passed a netdev to set_wiphy, so that it is
2813 * possible to let that go to the right netdev!
2814 */
4bbf4d56 2815
f444de05
JB
2816 if (info->attrs[NL80211_ATTR_IFINDEX]) {
2817 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
2818
7f2b8562 2819 netdev = __dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 2820 if (netdev && netdev->ieee80211_ptr)
f26cbf40 2821 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy);
5fe231e8 2822 else
f444de05 2823 netdev = NULL;
4bbf4d56
JB
2824 }
2825
f444de05 2826 if (!netdev) {
878d9ec7
JB
2827 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
2828 info->attrs);
5fe231e8 2829 if (IS_ERR(rdev))
4c476991 2830 return PTR_ERR(rdev);
f444de05
JB
2831 wdev = NULL;
2832 netdev = NULL;
2833 result = 0;
71fe96bf 2834 } else
f444de05 2835 wdev = netdev->ieee80211_ptr;
f444de05
JB
2836
2837 /*
2838 * end workaround code, by now the rdev is available
2839 * and locked, and wdev may or may not be NULL.
2840 */
4bbf4d56
JB
2841
2842 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
2843 result = cfg80211_dev_rename(
2844 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 2845
4bbf4d56 2846 if (result)
7f2b8562 2847 return result;
31888487
JM
2848
2849 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
2850 struct ieee80211_txq_params txq_params;
2851 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
2852
7f2b8562
YX
2853 if (!rdev->ops->set_txq_params)
2854 return -EOPNOTSUPP;
31888487 2855
7f2b8562
YX
2856 if (!netdev)
2857 return -EINVAL;
f70f01c2 2858
133a3ff2 2859 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7f2b8562
YX
2860 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2861 return -EINVAL;
133a3ff2 2862
7f2b8562
YX
2863 if (!netif_running(netdev))
2864 return -ENETDOWN;
2b5f8b0b 2865
31888487
JM
2866 nla_for_each_nested(nl_txq_params,
2867 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
2868 rem_txq_params) {
8cb08174
JB
2869 result = nla_parse_nested_deprecated(tb,
2870 NL80211_TXQ_ATTR_MAX,
2871 nl_txq_params,
2872 txq_params_policy,
2873 info->extack);
ae811e21
JB
2874 if (result)
2875 return result;
31888487
JM
2876 result = parse_txq_params(tb, &txq_params);
2877 if (result)
7f2b8562 2878 return result;
31888487 2879
e35e4d28
HG
2880 result = rdev_set_txq_params(rdev, netdev,
2881 &txq_params);
31888487 2882 if (result)
7f2b8562 2883 return result;
31888487
JM
2884 }
2885 }
55682965 2886
72bdcf34 2887 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
e16821bc
JM
2888 result = __nl80211_set_channel(
2889 rdev,
2890 nl80211_can_set_dev_channel(wdev) ? netdev : NULL,
2891 info);
72bdcf34 2892 if (result)
7f2b8562 2893 return result;
72bdcf34
JM
2894 }
2895
98d2ff8b 2896 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 2897 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
2898 enum nl80211_tx_power_setting type;
2899 int idx, mbm = 0;
2900
c8442118
JB
2901 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
2902 txp_wdev = NULL;
2903
7f2b8562
YX
2904 if (!rdev->ops->set_tx_power)
2905 return -EOPNOTSUPP;
98d2ff8b
JO
2906
2907 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
2908 type = nla_get_u32(info->attrs[idx]);
2909
2910 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
7f2b8562
YX
2911 (type != NL80211_TX_POWER_AUTOMATIC))
2912 return -EINVAL;
98d2ff8b
JO
2913
2914 if (type != NL80211_TX_POWER_AUTOMATIC) {
2915 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
2916 mbm = nla_get_u32(info->attrs[idx]);
2917 }
2918
c8442118 2919 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b 2920 if (result)
7f2b8562 2921 return result;
98d2ff8b
JO
2922 }
2923
afe0cbf8
BR
2924 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
2925 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
2926 u32 tx_ant, rx_ant;
7a087e74 2927
7f531e03
BR
2928 if ((!rdev->wiphy.available_antennas_tx &&
2929 !rdev->wiphy.available_antennas_rx) ||
7f2b8562
YX
2930 !rdev->ops->set_antenna)
2931 return -EOPNOTSUPP;
afe0cbf8
BR
2932
2933 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
2934 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
2935
a7ffac95 2936 /* reject antenna configurations which don't match the
7f531e03
BR
2937 * available antenna masks, except for the "all" mask */
2938 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
7f2b8562
YX
2939 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx)))
2940 return -EINVAL;
a7ffac95 2941
7f531e03
BR
2942 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
2943 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 2944
e35e4d28 2945 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8 2946 if (result)
7f2b8562 2947 return result;
afe0cbf8
BR
2948 }
2949
b9a5f8ca
JM
2950 changed = 0;
2951
2952 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
2953 retry_short = nla_get_u8(
2954 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
7f2b8562 2955
b9a5f8ca
JM
2956 changed |= WIPHY_PARAM_RETRY_SHORT;
2957 }
2958
2959 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
2960 retry_long = nla_get_u8(
2961 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
7f2b8562 2962
b9a5f8ca
JM
2963 changed |= WIPHY_PARAM_RETRY_LONG;
2964 }
2965
2966 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
2967 frag_threshold = nla_get_u32(
2968 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
7f2b8562
YX
2969 if (frag_threshold < 256)
2970 return -EINVAL;
2971
b9a5f8ca
JM
2972 if (frag_threshold != (u32) -1) {
2973 /*
2974 * Fragments (apart from the last one) are required to
2975 * have even length. Make the fragmentation code
2976 * simpler by stripping LSB should someone try to use
2977 * odd threshold value.
2978 */
2979 frag_threshold &= ~0x1;
2980 }
2981 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
2982 }
2983
2984 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
2985 rts_threshold = nla_get_u32(
2986 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
2987 changed |= WIPHY_PARAM_RTS_THRESHOLD;
2988 }
2989
81077e82 2990 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
3057dbfd
LB
2991 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK])
2992 return -EINVAL;
2993
81077e82
LT
2994 coverage_class = nla_get_u8(
2995 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
2996 changed |= WIPHY_PARAM_COVERAGE_CLASS;
2997 }
2998
3057dbfd
LB
2999 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
3000 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION))
3001 return -EOPNOTSUPP;
3002
3003 changed |= WIPHY_PARAM_DYN_ACK;
81077e82
LT
3004 }
3005
52539ca8
THJ
3006 if (info->attrs[NL80211_ATTR_TXQ_LIMIT]) {
3007 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3008 NL80211_EXT_FEATURE_TXQS))
3009 return -EOPNOTSUPP;
3010 txq_limit = nla_get_u32(
3011 info->attrs[NL80211_ATTR_TXQ_LIMIT]);
3012 changed |= WIPHY_PARAM_TXQ_LIMIT;
3013 }
3014
3015 if (info->attrs[NL80211_ATTR_TXQ_MEMORY_LIMIT]) {
3016 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3017 NL80211_EXT_FEATURE_TXQS))
3018 return -EOPNOTSUPP;
3019 txq_memory_limit = nla_get_u32(
3020 info->attrs[NL80211_ATTR_TXQ_MEMORY_LIMIT]);
3021 changed |= WIPHY_PARAM_TXQ_MEMORY_LIMIT;
3022 }
3023
3024 if (info->attrs[NL80211_ATTR_TXQ_QUANTUM]) {
3025 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3026 NL80211_EXT_FEATURE_TXQS))
3027 return -EOPNOTSUPP;
3028 txq_quantum = nla_get_u32(
3029 info->attrs[NL80211_ATTR_TXQ_QUANTUM]);
3030 changed |= WIPHY_PARAM_TXQ_QUANTUM;
3031 }
3032
b9a5f8ca
JM
3033 if (changed) {
3034 u8 old_retry_short, old_retry_long;
3035 u32 old_frag_threshold, old_rts_threshold;
81077e82 3036 u8 old_coverage_class;
52539ca8 3037 u32 old_txq_limit, old_txq_memory_limit, old_txq_quantum;
b9a5f8ca 3038
7f2b8562
YX
3039 if (!rdev->ops->set_wiphy_params)
3040 return -EOPNOTSUPP;
b9a5f8ca
JM
3041
3042 old_retry_short = rdev->wiphy.retry_short;
3043 old_retry_long = rdev->wiphy.retry_long;
3044 old_frag_threshold = rdev->wiphy.frag_threshold;
3045 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 3046 old_coverage_class = rdev->wiphy.coverage_class;
52539ca8
THJ
3047 old_txq_limit = rdev->wiphy.txq_limit;
3048 old_txq_memory_limit = rdev->wiphy.txq_memory_limit;
3049 old_txq_quantum = rdev->wiphy.txq_quantum;
b9a5f8ca
JM
3050
3051 if (changed & WIPHY_PARAM_RETRY_SHORT)
3052 rdev->wiphy.retry_short = retry_short;
3053 if (changed & WIPHY_PARAM_RETRY_LONG)
3054 rdev->wiphy.retry_long = retry_long;
3055 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
3056 rdev->wiphy.frag_threshold = frag_threshold;
3057 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
3058 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
3059 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
3060 rdev->wiphy.coverage_class = coverage_class;
52539ca8
THJ
3061 if (changed & WIPHY_PARAM_TXQ_LIMIT)
3062 rdev->wiphy.txq_limit = txq_limit;
3063 if (changed & WIPHY_PARAM_TXQ_MEMORY_LIMIT)
3064 rdev->wiphy.txq_memory_limit = txq_memory_limit;
3065 if (changed & WIPHY_PARAM_TXQ_QUANTUM)
3066 rdev->wiphy.txq_quantum = txq_quantum;
b9a5f8ca 3067
e35e4d28 3068 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
3069 if (result) {
3070 rdev->wiphy.retry_short = old_retry_short;
3071 rdev->wiphy.retry_long = old_retry_long;
3072 rdev->wiphy.frag_threshold = old_frag_threshold;
3073 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 3074 rdev->wiphy.coverage_class = old_coverage_class;
52539ca8
THJ
3075 rdev->wiphy.txq_limit = old_txq_limit;
3076 rdev->wiphy.txq_memory_limit = old_txq_memory_limit;
3077 rdev->wiphy.txq_quantum = old_txq_quantum;
9189ee31 3078 return result;
b9a5f8ca
JM
3079 }
3080 }
7f2b8562 3081 return 0;
55682965
JB
3082}
3083
683b6d3b 3084static int nl80211_send_chandef(struct sk_buff *msg,
d2859df5 3085 const struct cfg80211_chan_def *chandef)
683b6d3b 3086{
601555cd
JB
3087 if (WARN_ON(!cfg80211_chandef_valid(chandef)))
3088 return -EINVAL;
3d9d1d66 3089
683b6d3b
JB
3090 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
3091 chandef->chan->center_freq))
3092 return -ENOBUFS;
3d9d1d66
JB
3093 switch (chandef->width) {
3094 case NL80211_CHAN_WIDTH_20_NOHT:
3095 case NL80211_CHAN_WIDTH_20:
3096 case NL80211_CHAN_WIDTH_40:
3097 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
3098 cfg80211_get_chandef_type(chandef)))
3099 return -ENOBUFS;
3100 break;
3101 default:
3102 break;
3103 }
3104 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
3105 return -ENOBUFS;
3106 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
3107 return -ENOBUFS;
3108 if (chandef->center_freq2 &&
3109 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
3110 return -ENOBUFS;
3111 return 0;
3112}
3113
15e47304 3114static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 3115 struct cfg80211_registered_device *rdev,
3d1a5bbf
AZ
3116 struct wireless_dev *wdev,
3117 enum nl80211_commands cmd)
55682965 3118{
72fb2abc 3119 struct net_device *dev = wdev->netdev;
55682965
JB
3120 void *hdr;
3121
3d1a5bbf
AZ
3122 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE &&
3123 cmd != NL80211_CMD_DEL_INTERFACE &&
3124 cmd != NL80211_CMD_SET_INTERFACE);
8f894be2
TB
3125
3126 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
55682965
JB
3127 if (!hdr)
3128 return -1;
3129
72fb2abc
JB
3130 if (dev &&
3131 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 3132 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
3133 goto nla_put_failure;
3134
3135 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3136 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
2dad624e
ND
3137 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
3138 NL80211_ATTR_PAD) ||
98104fde 3139 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
3140 nla_put_u32(msg, NL80211_ATTR_GENERATION,
3141 rdev->devlist_generation ^
446faa15
AQ
3142 (cfg80211_rdev_list_generation << 2)) ||
3143 nla_put_u8(msg, NL80211_ATTR_4ADDR, wdev->use_4addr))
9360ffd1 3144 goto nla_put_failure;
f5ea9120 3145
5b7ccaf3 3146 if (rdev->ops->get_channel) {
683b6d3b
JB
3147 int ret;
3148 struct cfg80211_chan_def chandef;
3149
3150 ret = rdev_get_channel(rdev, wdev, &chandef);
3151 if (ret == 0) {
3152 if (nl80211_send_chandef(msg, &chandef))
3153 goto nla_put_failure;
3154 }
d91df0e3
PF
3155 }
3156
d55d0d59
RM
3157 if (rdev->ops->get_tx_power) {
3158 int dbm, ret;
3159
3160 ret = rdev_get_tx_power(rdev, wdev, &dbm);
3161 if (ret == 0 &&
3162 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL,
3163 DBM_TO_MBM(dbm)))
3164 goto nla_put_failure;
3165 }
3166
44905265
JB
3167 wdev_lock(wdev);
3168 switch (wdev->iftype) {
3169 case NL80211_IFTYPE_AP:
3170 if (wdev->ssid_len &&
3171 nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
4564b187 3172 goto nla_put_failure_locked;
44905265
JB
3173 break;
3174 case NL80211_IFTYPE_STATION:
3175 case NL80211_IFTYPE_P2P_CLIENT:
3176 case NL80211_IFTYPE_ADHOC: {
3177 const u8 *ssid_ie;
3178 if (!wdev->current_bss)
3179 break;
7a94b8c2 3180 rcu_read_lock();
44905265
JB
3181 ssid_ie = ieee80211_bss_get_ie(&wdev->current_bss->pub,
3182 WLAN_EID_SSID);
7a94b8c2
DB
3183 if (ssid_ie &&
3184 nla_put(msg, NL80211_ATTR_SSID, ssid_ie[1], ssid_ie + 2))
3185 goto nla_put_failure_rcu_locked;
3186 rcu_read_unlock();
44905265
JB
3187 break;
3188 }
3189 default:
3190 /* nothing */
3191 break;
b84e7a05 3192 }
44905265 3193 wdev_unlock(wdev);
b84e7a05 3194
52539ca8
THJ
3195 if (rdev->ops->get_txq_stats) {
3196 struct cfg80211_txq_stats txqstats = {};
3197 int ret = rdev_get_txq_stats(rdev, wdev, &txqstats);
3198
3199 if (ret == 0 &&
3200 !nl80211_put_txq_stats(msg, &txqstats,
3201 NL80211_ATTR_TXQ_STATS))
3202 goto nla_put_failure;
3203 }
3204
053c095a
JB
3205 genlmsg_end(msg, hdr);
3206 return 0;
55682965 3207
7a94b8c2
DB
3208 nla_put_failure_rcu_locked:
3209 rcu_read_unlock();
4564b187
JB
3210 nla_put_failure_locked:
3211 wdev_unlock(wdev);
55682965 3212 nla_put_failure:
bc3ed28c
TG
3213 genlmsg_cancel(msg, hdr);
3214 return -EMSGSIZE;
55682965
JB
3215}
3216
3217static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
3218{
3219 int wp_idx = 0;
3220 int if_idx = 0;
3221 int wp_start = cb->args[0];
3222 int if_start = cb->args[1];
b7fb44da 3223 int filter_wiphy = -1;
f5ea9120 3224 struct cfg80211_registered_device *rdev;
55682965 3225 struct wireless_dev *wdev;
ea90e0dc 3226 int ret;
55682965 3227
5fe231e8 3228 rtnl_lock();
b7fb44da
DK
3229 if (!cb->args[2]) {
3230 struct nl80211_dump_wiphy_state state = {
3231 .filter_wiphy = -1,
3232 };
b7fb44da
DK
3233
3234 ret = nl80211_dump_wiphy_parse(skb, cb, &state);
3235 if (ret)
ea90e0dc 3236 goto out_unlock;
b7fb44da
DK
3237
3238 filter_wiphy = state.filter_wiphy;
3239
3240 /*
3241 * if filtering, set cb->args[2] to +1 since 0 is the default
3242 * value needed to determine that parsing is necessary.
3243 */
3244 if (filter_wiphy >= 0)
3245 cb->args[2] = filter_wiphy + 1;
3246 else
3247 cb->args[2] = -1;
3248 } else if (cb->args[2] > 0) {
3249 filter_wiphy = cb->args[2] - 1;
3250 }
3251
f5ea9120
JB
3252 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
3253 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 3254 continue;
bba95fef
JB
3255 if (wp_idx < wp_start) {
3256 wp_idx++;
55682965 3257 continue;
bba95fef 3258 }
b7fb44da
DK
3259
3260 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx)
3261 continue;
3262
55682965
JB
3263 if_idx = 0;
3264
53873f13 3265 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
bba95fef
JB
3266 if (if_idx < if_start) {
3267 if_idx++;
55682965 3268 continue;
bba95fef 3269 }
15e47304 3270 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 3271 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3d1a5bbf
AZ
3272 rdev, wdev,
3273 NL80211_CMD_NEW_INTERFACE) < 0) {
bba95fef
JB
3274 goto out;
3275 }
3276 if_idx++;
55682965 3277 }
bba95fef
JB
3278
3279 wp_idx++;
55682965 3280 }
bba95fef 3281 out:
55682965
JB
3282 cb->args[0] = wp_idx;
3283 cb->args[1] = if_idx;
3284
ea90e0dc
JB
3285 ret = skb->len;
3286 out_unlock:
3287 rtnl_unlock();
3288
3289 return ret;
55682965
JB
3290}
3291
3292static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
3293{
3294 struct sk_buff *msg;
1b8ec87a 3295 struct cfg80211_registered_device *rdev = info->user_ptr[0];
72fb2abc 3296 struct wireless_dev *wdev = info->user_ptr[1];
55682965 3297
fd2120ca 3298 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 3299 if (!msg)
4c476991 3300 return -ENOMEM;
55682965 3301
15e47304 3302 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
3d1a5bbf 3303 rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
4c476991
JB
3304 nlmsg_free(msg);
3305 return -ENOBUFS;
3306 }
55682965 3307
134e6375 3308 return genlmsg_reply(msg, info);
55682965
JB
3309}
3310
66f7ac50
MW
3311static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
3312 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
3313 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
3314 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
3315 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
3316 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 3317 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
3318};
3319
3320static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
3321{
3322 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
3323 int flag;
3324
3325 *mntrflags = 0;
3326
3327 if (!nla)
3328 return -EINVAL;
3329
8cb08174 3330 if (nla_parse_nested_deprecated(flags, NL80211_MNTR_FLAG_MAX, nla, mntr_flags_policy, NULL))
66f7ac50
MW
3331 return -EINVAL;
3332
3333 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
3334 if (flags[flag])
3335 *mntrflags |= (1<<flag);
3336
818a986e
JB
3337 *mntrflags |= MONITOR_FLAG_CHANGED;
3338
66f7ac50
MW
3339 return 0;
3340}
3341
1db77596
JB
3342static int nl80211_parse_mon_options(struct cfg80211_registered_device *rdev,
3343 enum nl80211_iftype type,
3344 struct genl_info *info,
3345 struct vif_params *params)
3346{
3347 bool change = false;
3348 int err;
3349
3350 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
3351 if (type != NL80211_IFTYPE_MONITOR)
3352 return -EINVAL;
3353
3354 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
3355 &params->flags);
3356 if (err)
3357 return err;
3358
3359 change = true;
3360 }
3361
3362 if (params->flags & MONITOR_FLAG_ACTIVE &&
3363 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
3364 return -EOPNOTSUPP;
3365
3366 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) {
3367 const u8 *mumimo_groups;
3368 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
3369
3370 if (type != NL80211_IFTYPE_MONITOR)
3371 return -EINVAL;
3372
3373 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
3374 return -EOPNOTSUPP;
3375
3376 mumimo_groups =
3377 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]);
3378
3379 /* bits 0 and 63 are reserved and must be zero */
4954601f
JB
3380 if ((mumimo_groups[0] & BIT(0)) ||
3381 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(7)))
1db77596
JB
3382 return -EINVAL;
3383
3384 params->vht_mumimo_groups = mumimo_groups;
3385 change = true;
3386 }
3387
3388 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) {
3389 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
3390
3391 if (type != NL80211_IFTYPE_MONITOR)
3392 return -EINVAL;
3393
3394 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
3395 return -EOPNOTSUPP;
3396
3397 params->vht_mumimo_follow_addr =
3398 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]);
3399 change = true;
3400 }
3401
3402 return change ? 1 : 0;
3403}
3404
9bc383de 3405static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
3406 struct net_device *netdev, u8 use_4addr,
3407 enum nl80211_iftype iftype)
9bc383de 3408{
ad4bb6f8 3409 if (!use_4addr) {
f350a0a8 3410 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 3411 return -EBUSY;
9bc383de 3412 return 0;
ad4bb6f8 3413 }
9bc383de
JB
3414
3415 switch (iftype) {
3416 case NL80211_IFTYPE_AP_VLAN:
3417 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
3418 return 0;
3419 break;
3420 case NL80211_IFTYPE_STATION:
3421 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
3422 return 0;
3423 break;
3424 default:
3425 break;
3426 }
3427
3428 return -EOPNOTSUPP;
3429}
3430
55682965
JB
3431static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
3432{
4c476991 3433 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3434 struct vif_params params;
e36d56b6 3435 int err;
04a773ad 3436 enum nl80211_iftype otype, ntype;
4c476991 3437 struct net_device *dev = info->user_ptr[1];
ac7f9cfa 3438 bool change = false;
55682965 3439
2ec600d6
LCC
3440 memset(&params, 0, sizeof(params));
3441
04a773ad 3442 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 3443
723b038d 3444 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 3445 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 3446 if (otype != ntype)
ac7f9cfa 3447 change = true;
723b038d
JB
3448 }
3449
92ffe055 3450 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
3451 struct wireless_dev *wdev = dev->ieee80211_ptr;
3452
4c476991
JB
3453 if (ntype != NL80211_IFTYPE_MESH_POINT)
3454 return -EINVAL;
29cbe68c
JB
3455 if (netif_running(dev))
3456 return -EBUSY;
3457
3458 wdev_lock(wdev);
3459 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
3460 IEEE80211_MAX_MESH_ID_LEN);
3461 wdev->mesh_id_up_len =
3462 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
3463 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
3464 wdev->mesh_id_up_len);
3465 wdev_unlock(wdev);
2ec600d6
LCC
3466 }
3467
8b787643
FF
3468 if (info->attrs[NL80211_ATTR_4ADDR]) {
3469 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
3470 change = true;
ad4bb6f8 3471 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 3472 if (err)
4c476991 3473 return err;
8b787643
FF
3474 } else {
3475 params.use_4addr = -1;
3476 }
3477
1db77596
JB
3478 err = nl80211_parse_mon_options(rdev, ntype, info, &params);
3479 if (err < 0)
3480 return err;
3481 if (err > 0)
c6e6a0c8 3482 change = true;
e057d3c3 3483
ac7f9cfa 3484 if (change)
818a986e 3485 err = cfg80211_change_iface(rdev, dev, ntype, &params);
ac7f9cfa
JB
3486 else
3487 err = 0;
60719ffd 3488
9bc383de
JB
3489 if (!err && params.use_4addr != -1)
3490 dev->ieee80211_ptr->use_4addr = params.use_4addr;
3491
3d1a5bbf
AZ
3492 if (change && !err) {
3493 struct wireless_dev *wdev = dev->ieee80211_ptr;
3494
3495 nl80211_notify_iface(rdev, wdev, NL80211_CMD_SET_INTERFACE);
3496 }
3497
55682965
JB
3498 return err;
3499}
3500
3501static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
3502{
4c476991 3503 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3504 struct vif_params params;
84efbb84 3505 struct wireless_dev *wdev;
896ff063 3506 struct sk_buff *msg;
55682965
JB
3507 int err;
3508 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
3509
78f22b6a
JB
3510 /* to avoid failing a new interface creation due to pending removal */
3511 cfg80211_destroy_ifaces(rdev);
3512
2ec600d6
LCC
3513 memset(&params, 0, sizeof(params));
3514
55682965
JB
3515 if (!info->attrs[NL80211_ATTR_IFNAME])
3516 return -EINVAL;
3517
ab0d76f6 3518 if (info->attrs[NL80211_ATTR_IFTYPE])
55682965 3519 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
55682965 3520
33d915d9 3521 if (!rdev->ops->add_virtual_intf)
4c476991 3522 return -EOPNOTSUPP;
55682965 3523
cb3b7d87 3524 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN ||
e8f479b1
BG
3525 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) &&
3526 info->attrs[NL80211_ATTR_MAC]) {
1c18f145
AS
3527 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
3528 ETH_ALEN);
3529 if (!is_valid_ether_addr(params.macaddr))
3530 return -EADDRNOTAVAIL;
3531 }
3532
9bc383de 3533 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 3534 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 3535 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 3536 if (err)
4c476991 3537 return err;
9bc383de 3538 }
8b787643 3539
33d915d9
MP
3540 if (!(rdev->wiphy.interface_modes & (1 << type)) &&
3541 !(type == NL80211_IFTYPE_AP_VLAN && params.use_4addr &&
3542 rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP))
3543 return -EOPNOTSUPP;
3544
1db77596
JB
3545 err = nl80211_parse_mon_options(rdev, type, info, &params);
3546 if (err < 0)
3547 return err;
e057d3c3 3548
a18c7192
JB
3549 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3550 if (!msg)
3551 return -ENOMEM;
3552
e35e4d28
HG
3553 wdev = rdev_add_virtual_intf(rdev,
3554 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
818a986e 3555 NET_NAME_USER, type, &params);
d687cbb7
RM
3556 if (WARN_ON(!wdev)) {
3557 nlmsg_free(msg);
3558 return -EPROTO;
3559 } else if (IS_ERR(wdev)) {
1c90f9d4 3560 nlmsg_free(msg);
84efbb84 3561 return PTR_ERR(wdev);
1c90f9d4 3562 }
2ec600d6 3563
18e5ca65 3564 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
78f22b6a
JB
3565 wdev->owner_nlportid = info->snd_portid;
3566
98104fde
JB
3567 switch (type) {
3568 case NL80211_IFTYPE_MESH_POINT:
3569 if (!info->attrs[NL80211_ATTR_MESH_ID])
3570 break;
29cbe68c
JB
3571 wdev_lock(wdev);
3572 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
3573 IEEE80211_MAX_MESH_ID_LEN);
3574 wdev->mesh_id_up_len =
3575 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
3576 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
3577 wdev->mesh_id_up_len);
3578 wdev_unlock(wdev);
98104fde 3579 break;
cb3b7d87 3580 case NL80211_IFTYPE_NAN:
98104fde
JB
3581 case NL80211_IFTYPE_P2P_DEVICE:
3582 /*
cb3b7d87 3583 * P2P Device and NAN do not have a netdev, so don't go
98104fde
JB
3584 * through the netdev notifier and must be added here
3585 */
e4d4216e 3586 cfg80211_init_wdev(rdev, wdev);
98104fde
JB
3587 break;
3588 default:
3589 break;
29cbe68c
JB
3590 }
3591
15e47304 3592 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
3d1a5bbf 3593 rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
1c90f9d4
JB
3594 nlmsg_free(msg);
3595 return -ENOBUFS;
3596 }
3597
3598 return genlmsg_reply(msg, info);
55682965
JB
3599}
3600
3601static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
3602{
4c476991 3603 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 3604 struct wireless_dev *wdev = info->user_ptr[1];
55682965 3605
4c476991
JB
3606 if (!rdev->ops->del_virtual_intf)
3607 return -EOPNOTSUPP;
55682965 3608
84efbb84
JB
3609 /*
3610 * If we remove a wireless device without a netdev then clear
3611 * user_ptr[1] so that nl80211_post_doit won't dereference it
3612 * to check if it needs to do dev_put(). Otherwise it crashes
3613 * since the wdev has been freed, unlike with a netdev where
3614 * we need the dev_put() for the netdev to really be freed.
3615 */
3616 if (!wdev->netdev)
3617 info->user_ptr[1] = NULL;
3618
7f8ed01e 3619 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
3620}
3621
1d9d9213
SW
3622static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
3623{
3624 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3625 struct net_device *dev = info->user_ptr[1];
3626 u16 noack_map;
3627
3628 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
3629 return -EINVAL;
3630
3631 if (!rdev->ops->set_noack_map)
3632 return -EOPNOTSUPP;
3633
3634 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
3635
e35e4d28 3636 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
3637}
3638
41ade00f
JB
3639struct get_key_cookie {
3640 struct sk_buff *msg;
3641 int error;
b9454e83 3642 int idx;
41ade00f
JB
3643};
3644
3645static void get_key_callback(void *c, struct key_params *params)
3646{
b9454e83 3647 struct nlattr *key;
41ade00f
JB
3648 struct get_key_cookie *cookie = c;
3649
9360ffd1
DM
3650 if ((params->key &&
3651 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
3652 params->key_len, params->key)) ||
3653 (params->seq &&
3654 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
3655 params->seq_len, params->seq)) ||
3656 (params->cipher &&
3657 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
3658 params->cipher)))
3659 goto nla_put_failure;
41ade00f 3660
ae0be8de 3661 key = nla_nest_start_noflag(cookie->msg, NL80211_ATTR_KEY);
b9454e83
JB
3662 if (!key)
3663 goto nla_put_failure;
3664
9360ffd1
DM
3665 if ((params->key &&
3666 nla_put(cookie->msg, NL80211_KEY_DATA,
3667 params->key_len, params->key)) ||
3668 (params->seq &&
3669 nla_put(cookie->msg, NL80211_KEY_SEQ,
3670 params->seq_len, params->seq)) ||
3671 (params->cipher &&
3672 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
3673 params->cipher)))
3674 goto nla_put_failure;
b9454e83 3675
efdfce72 3676 if (nla_put_u8(cookie->msg, NL80211_KEY_IDX, cookie->idx))
9360ffd1 3677 goto nla_put_failure;
b9454e83
JB
3678
3679 nla_nest_end(cookie->msg, key);
3680
41ade00f
JB
3681 return;
3682 nla_put_failure:
3683 cookie->error = 1;
3684}
3685
3686static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
3687{
4c476991 3688 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3689 int err;
4c476991 3690 struct net_device *dev = info->user_ptr[1];
41ade00f 3691 u8 key_idx = 0;
e31b8213
JB
3692 const u8 *mac_addr = NULL;
3693 bool pairwise;
41ade00f
JB
3694 struct get_key_cookie cookie = {
3695 .error = 0,
3696 };
3697 void *hdr;
3698 struct sk_buff *msg;
3699
3700 if (info->attrs[NL80211_ATTR_KEY_IDX])
3701 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
3702
41ade00f
JB
3703 if (info->attrs[NL80211_ATTR_MAC])
3704 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3705
e31b8213
JB
3706 pairwise = !!mac_addr;
3707 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
3708 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
7a087e74 3709
e31b8213
JB
3710 if (kt != NL80211_KEYTYPE_GROUP &&
3711 kt != NL80211_KEYTYPE_PAIRWISE)
3712 return -EINVAL;
3713 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
3714 }
3715
4c476991
JB
3716 if (!rdev->ops->get_key)
3717 return -EOPNOTSUPP;
41ade00f 3718
0fa7b391
JB
3719 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3720 return -ENOENT;
3721
fd2120ca 3722 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3723 if (!msg)
3724 return -ENOMEM;
41ade00f 3725
15e47304 3726 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 3727 NL80211_CMD_NEW_KEY);
cb35fba3 3728 if (!hdr)
9fe271af 3729 goto nla_put_failure;
41ade00f
JB
3730
3731 cookie.msg = msg;
b9454e83 3732 cookie.idx = key_idx;
41ade00f 3733
9360ffd1
DM
3734 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3735 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
3736 goto nla_put_failure;
3737 if (mac_addr &&
3738 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
3739 goto nla_put_failure;
41ade00f 3740
e35e4d28
HG
3741 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
3742 get_key_callback);
41ade00f
JB
3743
3744 if (err)
6c95e2a2 3745 goto free_msg;
41ade00f
JB
3746
3747 if (cookie.error)
3748 goto nla_put_failure;
3749
3750 genlmsg_end(msg, hdr);
4c476991 3751 return genlmsg_reply(msg, info);
41ade00f
JB
3752
3753 nla_put_failure:
3754 err = -ENOBUFS;
6c95e2a2 3755 free_msg:
41ade00f 3756 nlmsg_free(msg);
41ade00f
JB
3757 return err;
3758}
3759
3760static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
3761{
4c476991 3762 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 3763 struct key_parse key;
41ade00f 3764 int err;
4c476991 3765 struct net_device *dev = info->user_ptr[1];
41ade00f 3766
b9454e83
JB
3767 err = nl80211_parse_key(info, &key);
3768 if (err)
3769 return err;
41ade00f 3770
b9454e83 3771 if (key.idx < 0)
41ade00f
JB
3772 return -EINVAL;
3773
6cdd3979
AW
3774 /* Only support setting default key and
3775 * Extended Key ID action NL80211_KEY_SET_TX.
3776 */
3777 if (!key.def && !key.defmgmt &&
3778 !(key.p.mode == NL80211_KEY_SET_TX))
41ade00f
JB
3779 return -EINVAL;
3780
dbd2fd65 3781 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 3782
dbd2fd65
JB
3783 if (key.def) {
3784 if (!rdev->ops->set_default_key) {
3785 err = -EOPNOTSUPP;
3786 goto out;
3787 }
41ade00f 3788
dbd2fd65
JB
3789 err = nl80211_key_allowed(dev->ieee80211_ptr);
3790 if (err)
3791 goto out;
3792
e35e4d28 3793 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
3794 key.def_uni, key.def_multi);
3795
3796 if (err)
3797 goto out;
fffd0934 3798
3d23e349 3799#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
3800 dev->ieee80211_ptr->wext.default_key = key.idx;
3801#endif
6cdd3979 3802 } else if (key.defmgmt) {
dbd2fd65
JB
3803 if (key.def_uni || !key.def_multi) {
3804 err = -EINVAL;
3805 goto out;
3806 }
3807
3808 if (!rdev->ops->set_default_mgmt_key) {
3809 err = -EOPNOTSUPP;
3810 goto out;
3811 }
3812
3813 err = nl80211_key_allowed(dev->ieee80211_ptr);
3814 if (err)
3815 goto out;
3816
e35e4d28 3817 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
3818 if (err)
3819 goto out;
3820
3821#ifdef CONFIG_CFG80211_WEXT
3822 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 3823#endif
6cdd3979
AW
3824 } else if (key.p.mode == NL80211_KEY_SET_TX &&
3825 wiphy_ext_feature_isset(&rdev->wiphy,
3826 NL80211_EXT_FEATURE_EXT_KEY_ID)) {
3827 u8 *mac_addr = NULL;
3828
3829 if (info->attrs[NL80211_ATTR_MAC])
3830 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3831
3832 if (!mac_addr || key.idx < 0 || key.idx > 1) {
3833 err = -EINVAL;
3834 goto out;
3835 }
dbd2fd65 3836
6cdd3979
AW
3837 err = rdev_add_key(rdev, dev, key.idx,
3838 NL80211_KEYTYPE_PAIRWISE,
3839 mac_addr, &key.p);
3840 } else {
3841 err = -EINVAL;
3842 }
dbd2fd65 3843 out:
fffd0934 3844 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3845
41ade00f
JB
3846 return err;
3847}
3848
3849static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
3850{
4c476991 3851 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 3852 int err;
4c476991 3853 struct net_device *dev = info->user_ptr[1];
b9454e83 3854 struct key_parse key;
e31b8213 3855 const u8 *mac_addr = NULL;
41ade00f 3856
b9454e83
JB
3857 err = nl80211_parse_key(info, &key);
3858 if (err)
3859 return err;
41ade00f 3860
b9454e83 3861 if (!key.p.key)
41ade00f
JB
3862 return -EINVAL;
3863
41ade00f
JB
3864 if (info->attrs[NL80211_ATTR_MAC])
3865 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3866
e31b8213
JB
3867 if (key.type == -1) {
3868 if (mac_addr)
3869 key.type = NL80211_KEYTYPE_PAIRWISE;
3870 else
3871 key.type = NL80211_KEYTYPE_GROUP;
3872 }
3873
3874 /* for now */
3875 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3876 key.type != NL80211_KEYTYPE_GROUP)
3877 return -EINVAL;
3878
4c476991
JB
3879 if (!rdev->ops->add_key)
3880 return -EOPNOTSUPP;
25e47c18 3881
e31b8213
JB
3882 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
3883 key.type == NL80211_KEYTYPE_PAIRWISE,
3884 mac_addr))
4c476991 3885 return -EINVAL;
41ade00f 3886
fffd0934
JB
3887 wdev_lock(dev->ieee80211_ptr);
3888 err = nl80211_key_allowed(dev->ieee80211_ptr);
3889 if (!err)
e35e4d28
HG
3890 err = rdev_add_key(rdev, dev, key.idx,
3891 key.type == NL80211_KEYTYPE_PAIRWISE,
3892 mac_addr, &key.p);
fffd0934 3893 wdev_unlock(dev->ieee80211_ptr);
41ade00f 3894
41ade00f
JB
3895 return err;
3896}
3897
3898static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
3899{
4c476991 3900 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3901 int err;
4c476991 3902 struct net_device *dev = info->user_ptr[1];
41ade00f 3903 u8 *mac_addr = NULL;
b9454e83 3904 struct key_parse key;
41ade00f 3905
b9454e83
JB
3906 err = nl80211_parse_key(info, &key);
3907 if (err)
3908 return err;
41ade00f
JB
3909
3910 if (info->attrs[NL80211_ATTR_MAC])
3911 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3912
e31b8213
JB
3913 if (key.type == -1) {
3914 if (mac_addr)
3915 key.type = NL80211_KEYTYPE_PAIRWISE;
3916 else
3917 key.type = NL80211_KEYTYPE_GROUP;
3918 }
3919
3920 /* for now */
3921 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
3922 key.type != NL80211_KEYTYPE_GROUP)
3923 return -EINVAL;
3924
4c476991
JB
3925 if (!rdev->ops->del_key)
3926 return -EOPNOTSUPP;
41ade00f 3927
fffd0934
JB
3928 wdev_lock(dev->ieee80211_ptr);
3929 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213 3930
0fa7b391 3931 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr &&
e31b8213
JB
3932 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3933 err = -ENOENT;
3934
fffd0934 3935 if (!err)
e35e4d28
HG
3936 err = rdev_del_key(rdev, dev, key.idx,
3937 key.type == NL80211_KEYTYPE_PAIRWISE,
3938 mac_addr);
41ade00f 3939
3d23e349 3940#ifdef CONFIG_CFG80211_WEXT
08645126 3941 if (!err) {
b9454e83 3942 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 3943 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 3944 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
3945 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
3946 }
3947#endif
fffd0934 3948 wdev_unlock(dev->ieee80211_ptr);
08645126 3949
41ade00f
JB
3950 return err;
3951}
3952
77765eaf
VT
3953/* This function returns an error or the number of nested attributes */
3954static int validate_acl_mac_addrs(struct nlattr *nl_attr)
3955{
3956 struct nlattr *attr;
3957 int n_entries = 0, tmp;
3958
3959 nla_for_each_nested(attr, nl_attr, tmp) {
3960 if (nla_len(attr) != ETH_ALEN)
3961 return -EINVAL;
3962
3963 n_entries++;
3964 }
3965
3966 return n_entries;
3967}
3968
3969/*
3970 * This function parses ACL information and allocates memory for ACL data.
3971 * On successful return, the calling function is responsible to free the
3972 * ACL buffer returned by this function.
3973 */
3974static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
3975 struct genl_info *info)
3976{
3977 enum nl80211_acl_policy acl_policy;
3978 struct nlattr *attr;
3979 struct cfg80211_acl_data *acl;
3980 int i = 0, n_entries, tmp;
3981
3982 if (!wiphy->max_acl_mac_addrs)
3983 return ERR_PTR(-EOPNOTSUPP);
3984
3985 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
3986 return ERR_PTR(-EINVAL);
3987
3988 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
3989 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
3990 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
3991 return ERR_PTR(-EINVAL);
3992
3993 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
3994 return ERR_PTR(-EINVAL);
3995
3996 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
3997 if (n_entries < 0)
3998 return ERR_PTR(n_entries);
3999
4000 if (n_entries > wiphy->max_acl_mac_addrs)
4001 return ERR_PTR(-ENOTSUPP);
4002
391d132c 4003 acl = kzalloc(struct_size(acl, mac_addrs, n_entries), GFP_KERNEL);
77765eaf
VT
4004 if (!acl)
4005 return ERR_PTR(-ENOMEM);
4006
4007 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
4008 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
4009 i++;
4010 }
4011
4012 acl->n_acl_entries = n_entries;
4013 acl->acl_policy = acl_policy;
4014
4015 return acl;
4016}
4017
4018static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
4019{
4020 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4021 struct net_device *dev = info->user_ptr[1];
4022 struct cfg80211_acl_data *acl;
4023 int err;
4024
4025 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4026 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4027 return -EOPNOTSUPP;
4028
4029 if (!dev->ieee80211_ptr->beacon_interval)
4030 return -EINVAL;
4031
4032 acl = parse_acl_data(&rdev->wiphy, info);
4033 if (IS_ERR(acl))
4034 return PTR_ERR(acl);
4035
4036 err = rdev_set_mac_acl(rdev, dev, acl);
4037
4038 kfree(acl);
4039
4040 return err;
4041}
4042
a7c7fbff
PK
4043static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4044 u8 *rates, u8 rates_len)
4045{
4046 u8 i;
4047 u32 mask = 0;
4048
4049 for (i = 0; i < rates_len; i++) {
4050 int rate = (rates[i] & 0x7f) * 5;
4051 int ridx;
4052
4053 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4054 struct ieee80211_rate *srate =
4055 &sband->bitrates[ridx];
4056 if (rate == srate->bitrate) {
4057 mask |= 1 << ridx;
4058 break;
4059 }
4060 }
4061 if (ridx == sband->n_bitrates)
4062 return 0; /* rate not found */
4063 }
4064
4065 return mask;
4066}
4067
4068static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
4069 u8 *rates, u8 rates_len,
4070 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
4071{
4072 u8 i;
4073
4074 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
4075
4076 for (i = 0; i < rates_len; i++) {
4077 int ridx, rbit;
4078
4079 ridx = rates[i] / 8;
4080 rbit = BIT(rates[i] % 8);
4081
4082 /* check validity */
4083 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
4084 return false;
4085
4086 /* check availability */
30fe6d50 4087 ridx = array_index_nospec(ridx, IEEE80211_HT_MCS_MASK_LEN);
a7c7fbff
PK
4088 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
4089 mcs[ridx] |= rbit;
4090 else
4091 return false;
4092 }
4093
4094 return true;
4095}
4096
4097static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
4098{
4099 u16 mcs_mask = 0;
4100
4101 switch (vht_mcs_map) {
4102 case IEEE80211_VHT_MCS_NOT_SUPPORTED:
4103 break;
4104 case IEEE80211_VHT_MCS_SUPPORT_0_7:
4105 mcs_mask = 0x00FF;
4106 break;
4107 case IEEE80211_VHT_MCS_SUPPORT_0_8:
4108 mcs_mask = 0x01FF;
4109 break;
4110 case IEEE80211_VHT_MCS_SUPPORT_0_9:
4111 mcs_mask = 0x03FF;
4112 break;
4113 default:
4114 break;
4115 }
4116
4117 return mcs_mask;
4118}
4119
4120static void vht_build_mcs_mask(u16 vht_mcs_map,
4121 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
4122{
4123 u8 nss;
4124
4125 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
4126 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
4127 vht_mcs_map >>= 2;
4128 }
4129}
4130
4131static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
4132 struct nl80211_txrate_vht *txrate,
4133 u16 mcs[NL80211_VHT_NSS_MAX])
4134{
4135 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
4136 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
4137 u8 i;
4138
4139 if (!sband->vht_cap.vht_supported)
4140 return false;
4141
4142 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
4143
4144 /* Build vht_mcs_mask from VHT capabilities */
4145 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
4146
4147 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
4148 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
4149 mcs[i] = txrate->mcs[i];
4150 else
4151 return false;
4152 }
4153
4154 return true;
4155}
4156
4157static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
4158 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4159 .len = NL80211_MAX_SUPP_RATES },
4160 [NL80211_TXRATE_HT] = { .type = NLA_BINARY,
4161 .len = NL80211_MAX_SUPP_HT_RATES },
180aa422
JB
4162 [NL80211_TXRATE_VHT] = {
4163 .type = NLA_EXACT_LEN_WARN,
4164 .len = sizeof(struct nl80211_txrate_vht),
4165 },
a7c7fbff
PK
4166 [NL80211_TXRATE_GI] = { .type = NLA_U8 },
4167};
4168
4169static int nl80211_parse_tx_bitrate_mask(struct genl_info *info,
4170 struct cfg80211_bitrate_mask *mask)
4171{
4172 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4173 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4174 int rem, i;
4175 struct nlattr *tx_rates;
4176 struct ieee80211_supported_band *sband;
4177 u16 vht_tx_mcs_map;
4178
4179 memset(mask, 0, sizeof(*mask));
4180 /* Default to all rates enabled */
4181 for (i = 0; i < NUM_NL80211_BANDS; i++) {
4182 sband = rdev->wiphy.bands[i];
4183
4184 if (!sband)
4185 continue;
4186
4187 mask->control[i].legacy = (1 << sband->n_bitrates) - 1;
4188 memcpy(mask->control[i].ht_mcs,
4189 sband->ht_cap.mcs.rx_mask,
4190 sizeof(mask->control[i].ht_mcs));
4191
4192 if (!sband->vht_cap.vht_supported)
4193 continue;
4194
4195 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
4196 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs);
4197 }
4198
4199 /* if no rates are given set it back to the defaults */
4200 if (!info->attrs[NL80211_ATTR_TX_RATES])
4201 goto out;
4202
4203 /* The nested attribute uses enum nl80211_band as the index. This maps
4204 * directly to the enum nl80211_band values used in cfg80211.
4205 */
4206 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
4207 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) {
4208 enum nl80211_band band = nla_type(tx_rates);
4209 int err;
4210
4211 if (band < 0 || band >= NUM_NL80211_BANDS)
4212 return -EINVAL;
4213 sband = rdev->wiphy.bands[band];
4214 if (sband == NULL)
4215 return -EINVAL;
8cb08174
JB
4216 err = nla_parse_nested_deprecated(tb, NL80211_TXRATE_MAX,
4217 tx_rates,
4218 nl80211_txattr_policy,
4219 info->extack);
a7c7fbff
PK
4220 if (err)
4221 return err;
4222 if (tb[NL80211_TXRATE_LEGACY]) {
4223 mask->control[band].legacy = rateset_to_mask(
4224 sband,
4225 nla_data(tb[NL80211_TXRATE_LEGACY]),
4226 nla_len(tb[NL80211_TXRATE_LEGACY]));
4227 if ((mask->control[band].legacy == 0) &&
4228 nla_len(tb[NL80211_TXRATE_LEGACY]))
4229 return -EINVAL;
4230 }
4231 if (tb[NL80211_TXRATE_HT]) {
4232 if (!ht_rateset_to_mask(
4233 sband,
4234 nla_data(tb[NL80211_TXRATE_HT]),
4235 nla_len(tb[NL80211_TXRATE_HT]),
4236 mask->control[band].ht_mcs))
4237 return -EINVAL;
4238 }
4239 if (tb[NL80211_TXRATE_VHT]) {
4240 if (!vht_set_mcs_mask(
4241 sband,
4242 nla_data(tb[NL80211_TXRATE_VHT]),
4243 mask->control[band].vht_mcs))
4244 return -EINVAL;
4245 }
4246 if (tb[NL80211_TXRATE_GI]) {
4247 mask->control[band].gi =
4248 nla_get_u8(tb[NL80211_TXRATE_GI]);
4249 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI)
4250 return -EINVAL;
4251 }
4252
4253 if (mask->control[band].legacy == 0) {
4254 /* don't allow empty legacy rates if HT or VHT
4255 * are not even supported.
4256 */
4257 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
4258 rdev->wiphy.bands[band]->vht_cap.vht_supported))
4259 return -EINVAL;
4260
4261 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
4262 if (mask->control[band].ht_mcs[i])
4263 goto out;
4264
4265 for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
4266 if (mask->control[band].vht_mcs[i])
4267 goto out;
4268
4269 /* legacy and mcs rates may not be both empty */
4270 return -EINVAL;
4271 }
4272 }
4273
4274out:
4275 return 0;
4276}
4277
8564e382
JB
4278static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev,
4279 enum nl80211_band band,
4280 struct cfg80211_bitrate_mask *beacon_rate)
a7c7fbff 4281{
8564e382
JB
4282 u32 count_ht, count_vht, i;
4283 u32 rate = beacon_rate->control[band].legacy;
a7c7fbff
PK
4284
4285 /* Allow only one rate */
4286 if (hweight32(rate) > 1)
4287 return -EINVAL;
4288
4289 count_ht = 0;
4290 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) {
8564e382 4291 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) {
a7c7fbff 4292 return -EINVAL;
8564e382 4293 } else if (beacon_rate->control[band].ht_mcs[i]) {
a7c7fbff
PK
4294 count_ht++;
4295 if (count_ht > 1)
4296 return -EINVAL;
4297 }
4298 if (count_ht && rate)
4299 return -EINVAL;
4300 }
4301
4302 count_vht = 0;
4303 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
8564e382 4304 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) {
a7c7fbff 4305 return -EINVAL;
8564e382 4306 } else if (beacon_rate->control[band].vht_mcs[i]) {
a7c7fbff
PK
4307 count_vht++;
4308 if (count_vht > 1)
4309 return -EINVAL;
4310 }
4311 if (count_vht && rate)
4312 return -EINVAL;
4313 }
4314
4315 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht))
4316 return -EINVAL;
4317
8564e382
JB
4318 if (rate &&
4319 !wiphy_ext_feature_isset(&rdev->wiphy,
4320 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY))
4321 return -EINVAL;
4322 if (count_ht &&
4323 !wiphy_ext_feature_isset(&rdev->wiphy,
4324 NL80211_EXT_FEATURE_BEACON_RATE_HT))
4325 return -EINVAL;
4326 if (count_vht &&
4327 !wiphy_ext_feature_isset(&rdev->wiphy,
4328 NL80211_EXT_FEATURE_BEACON_RATE_VHT))
4329 return -EINVAL;
4330
a7c7fbff
PK
4331 return 0;
4332}
4333
81e54d08
PKC
4334static int nl80211_parse_beacon(struct cfg80211_registered_device *rdev,
4335 struct nlattr *attrs[],
8860020e 4336 struct cfg80211_beacon_data *bcn)
ed1b6cc7 4337{
8860020e 4338 bool haveinfo = false;
81e54d08 4339 int err;
ed1b6cc7 4340
8860020e 4341 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 4342
a1193be8
SW
4343 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
4344 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
4345 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
4346 if (!bcn->head_len)
4347 return -EINVAL;
4348 haveinfo = true;
ed1b6cc7
JB
4349 }
4350
a1193be8
SW
4351 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
4352 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
4353 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 4354 haveinfo = true;
ed1b6cc7
JB
4355 }
4356
4c476991
JB
4357 if (!haveinfo)
4358 return -EINVAL;
3b85875a 4359
a1193be8
SW
4360 if (attrs[NL80211_ATTR_IE]) {
4361 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
4362 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
4363 }
4364
a1193be8 4365 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 4366 bcn->proberesp_ies =
a1193be8 4367 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 4368 bcn->proberesp_ies_len =
a1193be8 4369 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
4370 }
4371
a1193be8 4372 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 4373 bcn->assocresp_ies =
a1193be8 4374 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 4375 bcn->assocresp_ies_len =
a1193be8 4376 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
4377 }
4378
a1193be8
SW
4379 if (attrs[NL80211_ATTR_PROBE_RESP]) {
4380 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
4381 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
4382 }
4383
81e54d08
PKC
4384 if (attrs[NL80211_ATTR_FTM_RESPONDER]) {
4385 struct nlattr *tb[NL80211_FTM_RESP_ATTR_MAX + 1];
4386
8cb08174
JB
4387 err = nla_parse_nested_deprecated(tb,
4388 NL80211_FTM_RESP_ATTR_MAX,
4389 attrs[NL80211_ATTR_FTM_RESPONDER],
4390 NULL, NULL);
81e54d08
PKC
4391 if (err)
4392 return err;
4393
4394 if (tb[NL80211_FTM_RESP_ATTR_ENABLED] &&
4395 wiphy_ext_feature_isset(&rdev->wiphy,
4396 NL80211_EXT_FEATURE_ENABLE_FTM_RESPONDER))
4397 bcn->ftm_responder = 1;
4398 else
4399 return -EOPNOTSUPP;
4400
4401 if (tb[NL80211_FTM_RESP_ATTR_LCI]) {
4402 bcn->lci = nla_data(tb[NL80211_FTM_RESP_ATTR_LCI]);
4403 bcn->lci_len = nla_len(tb[NL80211_FTM_RESP_ATTR_LCI]);
4404 }
4405
4406 if (tb[NL80211_FTM_RESP_ATTR_CIVICLOC]) {
4407 bcn->civicloc = nla_data(tb[NL80211_FTM_RESP_ATTR_CIVICLOC]);
4408 bcn->civicloc_len = nla_len(tb[NL80211_FTM_RESP_ATTR_CIVICLOC]);
4409 }
4410 } else {
4411 bcn->ftm_responder = -1;
4412 }
4413
8860020e
JB
4414 return 0;
4415}
4416
796e90f4
JC
4417static int nl80211_parse_he_obss_pd(struct nlattr *attrs,
4418 struct ieee80211_he_obss_pd *he_obss_pd)
4419{
4420 struct nlattr *tb[NL80211_HE_OBSS_PD_ATTR_MAX + 1];
4421 int err;
4422
4423 err = nla_parse_nested(tb, NL80211_HE_OBSS_PD_ATTR_MAX, attrs,
4424 he_obss_pd_policy, NULL);
4425 if (err)
4426 return err;
4427
4428 if (!tb[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET] ||
4429 !tb[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET])
4430 return -EINVAL;
4431
4432 he_obss_pd->min_offset =
4433 nla_get_u32(tb[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET]);
4434 he_obss_pd->max_offset =
4435 nla_get_u32(tb[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET]);
4436
4437 if (he_obss_pd->min_offset >= he_obss_pd->max_offset)
4438 return -EINVAL;
4439
4440 he_obss_pd->enable = true;
4441
4442 return 0;
4443}
4444
66cd794e
JB
4445static void nl80211_check_ap_rate_selectors(struct cfg80211_ap_settings *params,
4446 const u8 *rates)
4447{
4448 int i;
4449
4450 if (!rates)
4451 return;
4452
4453 for (i = 0; i < rates[1]; i++) {
4454 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_HT_PHY)
4455 params->ht_required = true;
4456 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_VHT_PHY)
4457 params->vht_required = true;
4458 }
4459}
4460
4461/*
4462 * Since the nl80211 API didn't include, from the beginning, attributes about
4463 * HT/VHT requirements/capabilities, we parse them out of the IEs for the
4464 * benefit of drivers that rebuild IEs in the firmware.
4465 */
4466static void nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
4467{
4468 const struct cfg80211_beacon_data *bcn = &params->beacon;
ba83bfb1
IM
4469 size_t ies_len = bcn->tail_len;
4470 const u8 *ies = bcn->tail;
66cd794e
JB
4471 const u8 *rates;
4472 const u8 *cap;
4473
4474 rates = cfg80211_find_ie(WLAN_EID_SUPP_RATES, ies, ies_len);
4475 nl80211_check_ap_rate_selectors(params, rates);
4476
4477 rates = cfg80211_find_ie(WLAN_EID_EXT_SUPP_RATES, ies, ies_len);
4478 nl80211_check_ap_rate_selectors(params, rates);
4479
4480 cap = cfg80211_find_ie(WLAN_EID_HT_CAPABILITY, ies, ies_len);
4481 if (cap && cap[1] >= sizeof(*params->ht_cap))
4482 params->ht_cap = (void *)(cap + 2);
4483 cap = cfg80211_find_ie(WLAN_EID_VHT_CAPABILITY, ies, ies_len);
4484 if (cap && cap[1] >= sizeof(*params->vht_cap))
4485 params->vht_cap = (void *)(cap + 2);
244eb9ae
ST
4486 cap = cfg80211_find_ext_ie(WLAN_EID_EXT_HE_CAPABILITY, ies, ies_len);
4487 if (cap && cap[1] >= sizeof(*params->he_cap) + 1)
4488 params->he_cap = (void *)(cap + 3);
66cd794e
JB
4489}
4490
46c1dd0c
FF
4491static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
4492 struct cfg80211_ap_settings *params)
4493{
4494 struct wireless_dev *wdev;
4495 bool ret = false;
4496
53873f13 4497 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
46c1dd0c
FF
4498 if (wdev->iftype != NL80211_IFTYPE_AP &&
4499 wdev->iftype != NL80211_IFTYPE_P2P_GO)
4500 continue;
4501
683b6d3b 4502 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
4503 continue;
4504
683b6d3b 4505 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
4506 ret = true;
4507 break;
4508 }
4509
46c1dd0c
FF
4510 return ret;
4511}
4512
e39e5b5e
JM
4513static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
4514 enum nl80211_auth_type auth_type,
4515 enum nl80211_commands cmd)
4516{
4517 if (auth_type > NL80211_AUTHTYPE_MAX)
4518 return false;
4519
4520 switch (cmd) {
4521 case NL80211_CMD_AUTHENTICATE:
4522 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
4523 auth_type == NL80211_AUTHTYPE_SAE)
4524 return false;
63181060
JM
4525 if (!wiphy_ext_feature_isset(&rdev->wiphy,
4526 NL80211_EXT_FEATURE_FILS_STA) &&
4527 (auth_type == NL80211_AUTHTYPE_FILS_SK ||
4528 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
4529 auth_type == NL80211_AUTHTYPE_FILS_PK))
4530 return false;
e39e5b5e
JM
4531 return true;
4532 case NL80211_CMD_CONNECT:
10773a7c 4533 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
26f7044e
CHH
4534 !wiphy_ext_feature_isset(&rdev->wiphy,
4535 NL80211_EXT_FEATURE_SAE_OFFLOAD) &&
10773a7c 4536 auth_type == NL80211_AUTHTYPE_SAE)
a3caf744 4537 return false;
10773a7c 4538
a3caf744
VK
4539 /* FILS with SK PFS or PK not supported yet */
4540 if (auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
4541 auth_type == NL80211_AUTHTYPE_FILS_PK)
4542 return false;
4543 if (!wiphy_ext_feature_isset(
4544 &rdev->wiphy,
4545 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
4546 auth_type == NL80211_AUTHTYPE_FILS_SK)
4547 return false;
4548 return true;
e39e5b5e
JM
4549 case NL80211_CMD_START_AP:
4550 /* SAE not supported yet */
4551 if (auth_type == NL80211_AUTHTYPE_SAE)
4552 return false;
63181060
JM
4553 /* FILS not supported yet */
4554 if (auth_type == NL80211_AUTHTYPE_FILS_SK ||
4555 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
4556 auth_type == NL80211_AUTHTYPE_FILS_PK)
4557 return false;
e39e5b5e
JM
4558 return true;
4559 default:
4560 return false;
4561 }
4562}
4563
8860020e
JB
4564static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
4565{
4566 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4567 struct net_device *dev = info->user_ptr[1];
4568 struct wireless_dev *wdev = dev->ieee80211_ptr;
4569 struct cfg80211_ap_settings params;
4570 int err;
4571
4572 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4573 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4574 return -EOPNOTSUPP;
4575
4576 if (!rdev->ops->start_ap)
4577 return -EOPNOTSUPP;
4578
4579 if (wdev->beacon_interval)
4580 return -EALREADY;
4581
4582 memset(&params, 0, sizeof(params));
4583
4584 /* these are required for START_AP */
4585 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
4586 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
4587 !info->attrs[NL80211_ATTR_BEACON_HEAD])
4588 return -EINVAL;
4589
81e54d08 4590 err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon);
8860020e
JB
4591 if (err)
4592 return err;
4593
4594 params.beacon_interval =
4595 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
4596 params.dtim_period =
4597 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
4598
0c317a02
PK
4599 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype,
4600 params.beacon_interval);
8860020e
JB
4601 if (err)
4602 return err;
4603
4604 /*
4605 * In theory, some of these attributes should be required here
4606 * but since they were not used when the command was originally
4607 * added, keep them optional for old user space programs to let
4608 * them continue to work with drivers that do not need the
4609 * additional information -- drivers must check!
4610 */
4611 if (info->attrs[NL80211_ATTR_SSID]) {
4612 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4613 params.ssid_len =
4614 nla_len(info->attrs[NL80211_ATTR_SSID]);
4615 if (params.ssid_len == 0 ||
4616 params.ssid_len > IEEE80211_MAX_SSID_LEN)
4617 return -EINVAL;
4618 }
4619
ab0d76f6 4620 if (info->attrs[NL80211_ATTR_HIDDEN_SSID])
8860020e
JB
4621 params.hidden_ssid = nla_get_u32(
4622 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
8860020e
JB
4623
4624 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
4625
4626 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4627 params.auth_type = nla_get_u32(
4628 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
4629 if (!nl80211_valid_auth_type(rdev, params.auth_type,
4630 NL80211_CMD_START_AP))
8860020e
JB
4631 return -EINVAL;
4632 } else
4633 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4634
4635 err = nl80211_crypto_settings(rdev, info, &params.crypto,
4636 NL80211_MAX_NR_CIPHER_SUITES);
4637 if (err)
4638 return err;
4639
1b658f11
VT
4640 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
4641 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
4642 return -EOPNOTSUPP;
4643 params.inactivity_timeout = nla_get_u16(
4644 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
4645 }
4646
53cabad7
JB
4647 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
4648 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4649 return -EINVAL;
4650 params.p2p_ctwindow =
4651 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
53cabad7
JB
4652 if (params.p2p_ctwindow != 0 &&
4653 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
4654 return -EINVAL;
4655 }
4656
4657 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
4658 u8 tmp;
4659
4660 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4661 return -EINVAL;
4662 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
53cabad7
JB
4663 params.p2p_opp_ps = tmp;
4664 if (params.p2p_opp_ps != 0 &&
4665 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
4666 return -EINVAL;
4667 }
4668
aa430da4 4669 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
4670 err = nl80211_parse_chandef(rdev, info, &params.chandef);
4671 if (err)
4672 return err;
4673 } else if (wdev->preset_chandef.chan) {
4674 params.chandef = wdev->preset_chandef;
46c1dd0c 4675 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
4676 return -EINVAL;
4677
923b352f
AN
4678 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
4679 wdev->iftype))
aa430da4
JB
4680 return -EINVAL;
4681
a7c7fbff
PK
4682 if (info->attrs[NL80211_ATTR_TX_RATES]) {
4683 err = nl80211_parse_tx_bitrate_mask(info, &params.beacon_rate);
4684 if (err)
4685 return err;
4686
8564e382
JB
4687 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band,
4688 &params.beacon_rate);
a7c7fbff
PK
4689 if (err)
4690 return err;
4691 }
4692
18998c38
EP
4693 if (info->attrs[NL80211_ATTR_SMPS_MODE]) {
4694 params.smps_mode =
4695 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]);
4696 switch (params.smps_mode) {
4697 case NL80211_SMPS_OFF:
4698 break;
4699 case NL80211_SMPS_STATIC:
4700 if (!(rdev->wiphy.features &
4701 NL80211_FEATURE_STATIC_SMPS))
4702 return -EINVAL;
4703 break;
4704 case NL80211_SMPS_DYNAMIC:
4705 if (!(rdev->wiphy.features &
4706 NL80211_FEATURE_DYNAMIC_SMPS))
4707 return -EINVAL;
4708 break;
4709 default:
4710 return -EINVAL;
4711 }
4712 } else {
4713 params.smps_mode = NL80211_SMPS_OFF;
4714 }
4715
6e8ef842
PK
4716 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
4717 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ])
4718 return -EOPNOTSUPP;
4719
4baf6bea
OO
4720 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
4721 params.acl = parse_acl_data(&rdev->wiphy, info);
4722 if (IS_ERR(params.acl))
4723 return PTR_ERR(params.acl);
4724 }
4725
a0de1ca3
JC
4726 params.twt_responder =
4727 nla_get_flag(info->attrs[NL80211_ATTR_TWT_RESPONDER]);
4728
796e90f4
JC
4729 if (info->attrs[NL80211_ATTR_HE_OBSS_PD]) {
4730 err = nl80211_parse_he_obss_pd(
4731 info->attrs[NL80211_ATTR_HE_OBSS_PD],
4732 &params.he_obss_pd);
4733 if (err)
4734 return err;
4735 }
4736
66cd794e
JB
4737 nl80211_calculate_ap_params(&params);
4738
fe494370
SD
4739 if (info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])
4740 params.flags |= AP_SETTINGS_EXTERNAL_AUTH_SUPPORT;
4741
c56589ed 4742 wdev_lock(wdev);
e35e4d28 4743 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 4744 if (!err) {
683b6d3b 4745 wdev->preset_chandef = params.chandef;
8860020e 4746 wdev->beacon_interval = params.beacon_interval;
9e0e2961 4747 wdev->chandef = params.chandef;
06e191e2
AQ
4748 wdev->ssid_len = params.ssid_len;
4749 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
466a3061
DK
4750
4751 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
4752 wdev->conn_owner_nlportid = info->snd_portid;
46c1dd0c 4753 }
c56589ed 4754 wdev_unlock(wdev);
77765eaf
VT
4755
4756 kfree(params.acl);
4757
56d1893d 4758 return err;
ed1b6cc7
JB
4759}
4760
8860020e
JB
4761static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
4762{
4763 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4764 struct net_device *dev = info->user_ptr[1];
4765 struct wireless_dev *wdev = dev->ieee80211_ptr;
4766 struct cfg80211_beacon_data params;
4767 int err;
4768
4769 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4770 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4771 return -EOPNOTSUPP;
4772
4773 if (!rdev->ops->change_beacon)
4774 return -EOPNOTSUPP;
4775
4776 if (!wdev->beacon_interval)
4777 return -EINVAL;
4778
81e54d08 4779 err = nl80211_parse_beacon(rdev, info->attrs, &params);
8860020e
JB
4780 if (err)
4781 return err;
4782
c56589ed
SW
4783 wdev_lock(wdev);
4784 err = rdev_change_beacon(rdev, dev, &params);
4785 wdev_unlock(wdev);
4786
4787 return err;
8860020e
JB
4788}
4789
4790static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 4791{
4c476991
JB
4792 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4793 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 4794
7c8d5e03 4795 return cfg80211_stop_ap(rdev, dev, false);
ed1b6cc7
JB
4796}
4797
5727ef1b
JB
4798static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
4799 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
4800 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
4801 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 4802 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 4803 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 4804 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
4805};
4806
eccb8e8f 4807static int parse_station_flags(struct genl_info *info,
bdd3ae3d 4808 enum nl80211_iftype iftype,
eccb8e8f 4809 struct station_parameters *params)
5727ef1b
JB
4810{
4811 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 4812 struct nlattr *nla;
5727ef1b
JB
4813 int flag;
4814
eccb8e8f
JB
4815 /*
4816 * Try parsing the new attribute first so userspace
4817 * can specify both for older kernels.
4818 */
4819 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
4820 if (nla) {
4821 struct nl80211_sta_flag_update *sta_flags;
4822
4823 sta_flags = nla_data(nla);
4824 params->sta_flags_mask = sta_flags->mask;
4825 params->sta_flags_set = sta_flags->set;
77ee7c89 4826 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
4827 if ((params->sta_flags_mask |
4828 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
4829 return -EINVAL;
4830 return 0;
4831 }
4832
4833 /* if present, parse the old attribute */
5727ef1b 4834
eccb8e8f 4835 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
4836 if (!nla)
4837 return 0;
4838
8cb08174 4839 if (nla_parse_nested_deprecated(flags, NL80211_STA_FLAG_MAX, nla, sta_flags_policy, info->extack))
5727ef1b
JB
4840 return -EINVAL;
4841
bdd3ae3d
JB
4842 /*
4843 * Only allow certain flags for interface types so that
4844 * other attributes are silently ignored. Remember that
4845 * this is backward compatibility code with old userspace
4846 * and shouldn't be hit in other cases anyway.
4847 */
4848 switch (iftype) {
4849 case NL80211_IFTYPE_AP:
4850 case NL80211_IFTYPE_AP_VLAN:
4851 case NL80211_IFTYPE_P2P_GO:
4852 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
4853 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
4854 BIT(NL80211_STA_FLAG_WME) |
4855 BIT(NL80211_STA_FLAG_MFP);
4856 break;
4857 case NL80211_IFTYPE_P2P_CLIENT:
4858 case NL80211_IFTYPE_STATION:
4859 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
4860 BIT(NL80211_STA_FLAG_TDLS_PEER);
4861 break;
4862 case NL80211_IFTYPE_MESH_POINT:
4863 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
4864 BIT(NL80211_STA_FLAG_MFP) |
4865 BIT(NL80211_STA_FLAG_AUTHORIZED);
5cf3006c 4866 break;
bdd3ae3d
JB
4867 default:
4868 return -EINVAL;
4869 }
5727ef1b 4870
3383b5a6
JB
4871 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
4872 if (flags[flag]) {
eccb8e8f 4873 params->sta_flags_set |= (1<<flag);
5727ef1b 4874
3383b5a6
JB
4875 /* no longer support new API additions in old API */
4876 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
4877 return -EINVAL;
4878 }
4879 }
4880
5727ef1b
JB
4881 return 0;
4882}
4883
9bb7e0f2 4884bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, int attr)
c8dcfd8a
FF
4885{
4886 struct nlattr *rate;
8eb41c8d
VK
4887 u32 bitrate;
4888 u16 bitrate_compat;
bbf67e45 4889 enum nl80211_rate_info rate_flg;
c8dcfd8a 4890
ae0be8de 4891 rate = nla_nest_start_noflag(msg, attr);
c8dcfd8a 4892 if (!rate)
db9c64cf 4893 return false;
c8dcfd8a
FF
4894
4895 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
4896 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
4897 /* report 16-bit bitrate only if we can */
4898 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
4899 if (bitrate > 0 &&
4900 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
4901 return false;
4902 if (bitrate_compat > 0 &&
4903 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
4904 return false;
4905
b51f3bee
JB
4906 switch (info->bw) {
4907 case RATE_INFO_BW_5:
4908 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH;
4909 break;
4910 case RATE_INFO_BW_10:
4911 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH;
4912 break;
4913 default:
4914 WARN_ON(1);
4915 /* fall through */
4916 case RATE_INFO_BW_20:
4917 rate_flg = 0;
4918 break;
4919 case RATE_INFO_BW_40:
4920 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH;
4921 break;
4922 case RATE_INFO_BW_80:
4923 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH;
4924 break;
4925 case RATE_INFO_BW_160:
4926 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH;
4927 break;
c4cbaf79
LC
4928 case RATE_INFO_BW_HE_RU:
4929 rate_flg = 0;
4930 WARN_ON(!(info->flags & RATE_INFO_FLAGS_HE_MCS));
b51f3bee
JB
4931 }
4932
4933 if (rate_flg && nla_put_flag(msg, rate_flg))
4934 return false;
4935
db9c64cf
JB
4936 if (info->flags & RATE_INFO_FLAGS_MCS) {
4937 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
4938 return false;
db9c64cf
JB
4939 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
4940 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
4941 return false;
4942 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
4943 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
4944 return false;
4945 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
4946 return false;
db9c64cf
JB
4947 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
4948 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
4949 return false;
c4cbaf79
LC
4950 } else if (info->flags & RATE_INFO_FLAGS_HE_MCS) {
4951 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_MCS, info->mcs))
4952 return false;
4953 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_NSS, info->nss))
4954 return false;
4955 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_GI, info->he_gi))
4956 return false;
4957 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_DCM, info->he_dcm))
4958 return false;
4959 if (info->bw == RATE_INFO_BW_HE_RU &&
4960 nla_put_u8(msg, NL80211_RATE_INFO_HE_RU_ALLOC,
4961 info->he_ru_alloc))
4962 return false;
db9c64cf 4963 }
c8dcfd8a
FF
4964
4965 nla_nest_end(msg, rate);
4966 return true;
c8dcfd8a
FF
4967}
4968
119363c7
FF
4969static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
4970 int id)
4971{
4972 void *attr;
4973 int i = 0;
4974
4975 if (!mask)
4976 return true;
4977
ae0be8de 4978 attr = nla_nest_start_noflag(msg, id);
119363c7
FF
4979 if (!attr)
4980 return false;
4981
4982 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
4983 if (!(mask & BIT(i)))
4984 continue;
4985
4986 if (nla_put_u8(msg, i, signal[i]))
4987 return false;
4988 }
4989
4990 nla_nest_end(msg, attr);
4991
4992 return true;
4993}
4994
cf5ead82
JB
4995static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid,
4996 u32 seq, int flags,
66266b3a
JL
4997 struct cfg80211_registered_device *rdev,
4998 struct net_device *dev,
98b62183 4999 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
5000{
5001 void *hdr;
f4263c98 5002 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 5003
cf5ead82 5004 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
f77bf486
AS
5005 if (!hdr) {
5006 cfg80211_sinfo_release_content(sinfo);
fd5b74dc 5007 return -1;
f77bf486 5008 }
fd5b74dc 5009
9360ffd1
DM
5010 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5011 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
5012 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
5013 goto nla_put_failure;
f5ea9120 5014
ae0be8de 5015 sinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_STA_INFO);
2ec600d6 5016 if (!sinfoattr)
fd5b74dc 5017 goto nla_put_failure;
319090bf
JB
5018
5019#define PUT_SINFO(attr, memb, type) do { \
d686b920 5020 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \
397c657a 5021 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_ ## attr) && \
319090bf
JB
5022 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \
5023 sinfo->memb)) \
5024 goto nla_put_failure; \
5025 } while (0)
d686b920 5026#define PUT_SINFO_U64(attr, memb) do { \
397c657a 5027 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_ ## attr) && \
d686b920
JB
5028 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \
5029 sinfo->memb, NL80211_STA_INFO_PAD)) \
5030 goto nla_put_failure; \
5031 } while (0)
319090bf
JB
5032
5033 PUT_SINFO(CONNECTED_TIME, connected_time, u32);
5034 PUT_SINFO(INACTIVE_TIME, inactive_time, u32);
5035
397c657a
OE
5036 if (sinfo->filled & (BIT_ULL(NL80211_STA_INFO_RX_BYTES) |
5037 BIT_ULL(NL80211_STA_INFO_RX_BYTES64)) &&
9360ffd1 5038 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 5039 (u32)sinfo->rx_bytes))
9360ffd1 5040 goto nla_put_failure;
319090bf 5041
397c657a
OE
5042 if (sinfo->filled & (BIT_ULL(NL80211_STA_INFO_TX_BYTES) |
5043 BIT_ULL(NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 5044 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
5045 (u32)sinfo->tx_bytes))
5046 goto nla_put_failure;
319090bf 5047
d686b920
JB
5048 PUT_SINFO_U64(RX_BYTES64, rx_bytes);
5049 PUT_SINFO_U64(TX_BYTES64, tx_bytes);
319090bf
JB
5050 PUT_SINFO(LLID, llid, u16);
5051 PUT_SINFO(PLID, plid, u16);
5052 PUT_SINFO(PLINK_STATE, plink_state, u8);
d686b920 5053 PUT_SINFO_U64(RX_DURATION, rx_duration);
36647055
THJ
5054 PUT_SINFO_U64(TX_DURATION, tx_duration);
5055
5056 if (wiphy_ext_feature_isset(&rdev->wiphy,
5057 NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
5058 PUT_SINFO(AIRTIME_WEIGHT, airtime_weight, u16);
319090bf 5059
66266b3a
JL
5060 switch (rdev->wiphy.signal_type) {
5061 case CFG80211_SIGNAL_TYPE_MBM:
319090bf
JB
5062 PUT_SINFO(SIGNAL, signal, u8);
5063 PUT_SINFO(SIGNAL_AVG, signal_avg, u8);
66266b3a
JL
5064 break;
5065 default:
5066 break;
5067 }
397c657a 5068 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL)) {
119363c7
FF
5069 if (!nl80211_put_signal(msg, sinfo->chains,
5070 sinfo->chain_signal,
5071 NL80211_STA_INFO_CHAIN_SIGNAL))
5072 goto nla_put_failure;
5073 }
397c657a 5074 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) {
119363c7
FF
5075 if (!nl80211_put_signal(msg, sinfo->chains,
5076 sinfo->chain_signal_avg,
5077 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
5078 goto nla_put_failure;
5079 }
397c657a 5080 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_TX_BITRATE)) {
c8dcfd8a
FF
5081 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
5082 NL80211_STA_INFO_TX_BITRATE))
5083 goto nla_put_failure;
5084 }
397c657a 5085 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_RX_BITRATE)) {
c8dcfd8a
FF
5086 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
5087 NL80211_STA_INFO_RX_BITRATE))
420e7fab 5088 goto nla_put_failure;
420e7fab 5089 }
319090bf
JB
5090
5091 PUT_SINFO(RX_PACKETS, rx_packets, u32);
5092 PUT_SINFO(TX_PACKETS, tx_packets, u32);
5093 PUT_SINFO(TX_RETRIES, tx_retries, u32);
5094 PUT_SINFO(TX_FAILED, tx_failed, u32);
5095 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32);
ab60633c 5096 PUT_SINFO(AIRTIME_LINK_METRIC, airtime_link_metric, u32);
319090bf
JB
5097 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32);
5098 PUT_SINFO(LOCAL_PM, local_pm, u32);
5099 PUT_SINFO(PEER_PM, peer_pm, u32);
5100 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32);
dbdaee7a 5101 PUT_SINFO(CONNECTED_TO_GATE, connected_to_gate, u8);
319090bf 5102
397c657a 5103 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_BSS_PARAM)) {
ae0be8de
MK
5104 bss_param = nla_nest_start_noflag(msg,
5105 NL80211_STA_INFO_BSS_PARAM);
f4263c98
PS
5106 if (!bss_param)
5107 goto nla_put_failure;
5108
9360ffd1
DM
5109 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
5110 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
5111 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
5112 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
5113 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
5114 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
5115 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
5116 sinfo->bss_param.dtim_period) ||
5117 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
5118 sinfo->bss_param.beacon_interval))
5119 goto nla_put_failure;
f4263c98
PS
5120
5121 nla_nest_end(msg, bss_param);
5122 }
397c657a 5123 if ((sinfo->filled & BIT_ULL(NL80211_STA_INFO_STA_FLAGS)) &&
9360ffd1
DM
5124 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
5125 sizeof(struct nl80211_sta_flag_update),
5126 &sinfo->sta_flags))
5127 goto nla_put_failure;
319090bf 5128
d686b920
JB
5129 PUT_SINFO_U64(T_OFFSET, t_offset);
5130 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc);
5131 PUT_SINFO_U64(BEACON_RX, rx_beacon);
a76b1942 5132 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8);
0d4e14a3
AB
5133 PUT_SINFO(RX_MPDUS, rx_mpdu_count, u32);
5134 PUT_SINFO(FCS_ERROR_COUNT, fcs_err_count, u32);
81d5439d 5135 if (wiphy_ext_feature_isset(&rdev->wiphy,
9c06602b
BP
5136 NL80211_EXT_FEATURE_ACK_SIGNAL_SUPPORT)) {
5137 PUT_SINFO(ACK_SIGNAL, ack_signal, u8);
5138 PUT_SINFO(ACK_SIGNAL_AVG, avg_ack_signal, s8);
5139 }
319090bf
JB
5140
5141#undef PUT_SINFO
d686b920 5142#undef PUT_SINFO_U64
6de39808 5143
8689c051 5144 if (sinfo->pertid) {
6de39808
JB
5145 struct nlattr *tidsattr;
5146 int tid;
5147
ae0be8de
MK
5148 tidsattr = nla_nest_start_noflag(msg,
5149 NL80211_STA_INFO_TID_STATS);
6de39808
JB
5150 if (!tidsattr)
5151 goto nla_put_failure;
5152
5153 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) {
5154 struct cfg80211_tid_stats *tidstats;
5155 struct nlattr *tidattr;
5156
5157 tidstats = &sinfo->pertid[tid];
5158
5159 if (!tidstats->filled)
5160 continue;
5161
ae0be8de 5162 tidattr = nla_nest_start_noflag(msg, tid + 1);
6de39808
JB
5163 if (!tidattr)
5164 goto nla_put_failure;
5165
d686b920 5166#define PUT_TIDVAL_U64(attr, memb) do { \
6de39808 5167 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \
d686b920
JB
5168 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \
5169 tidstats->memb, NL80211_TID_STATS_PAD)) \
6de39808
JB
5170 goto nla_put_failure; \
5171 } while (0)
5172
d686b920
JB
5173 PUT_TIDVAL_U64(RX_MSDU, rx_msdu);
5174 PUT_TIDVAL_U64(TX_MSDU, tx_msdu);
5175 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries);
5176 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed);
6de39808 5177
d686b920 5178#undef PUT_TIDVAL_U64
52539ca8
THJ
5179 if ((tidstats->filled &
5180 BIT(NL80211_TID_STATS_TXQ_STATS)) &&
5181 !nl80211_put_txq_stats(msg, &tidstats->txq_stats,
5182 NL80211_TID_STATS_TXQ_STATS))
5183 goto nla_put_failure;
5184
6de39808
JB
5185 nla_nest_end(msg, tidattr);
5186 }
5187
5188 nla_nest_end(msg, tidsattr);
5189 }
5190
2ec600d6 5191 nla_nest_end(msg, sinfoattr);
fd5b74dc 5192
319090bf 5193 if (sinfo->assoc_req_ies_len &&
9360ffd1
DM
5194 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
5195 sinfo->assoc_req_ies))
5196 goto nla_put_failure;
50d3dfb7 5197
7ea3e110 5198 cfg80211_sinfo_release_content(sinfo);
053c095a
JB
5199 genlmsg_end(msg, hdr);
5200 return 0;
fd5b74dc
JB
5201
5202 nla_put_failure:
7ea3e110 5203 cfg80211_sinfo_release_content(sinfo);
bc3ed28c
TG
5204 genlmsg_cancel(msg, hdr);
5205 return -EMSGSIZE;
fd5b74dc
JB
5206}
5207
2ec600d6 5208static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 5209 struct netlink_callback *cb)
2ec600d6 5210{
73887fd9 5211 struct station_info sinfo;
1b8ec87a 5212 struct cfg80211_registered_device *rdev;
97990a06 5213 struct wireless_dev *wdev;
2ec600d6 5214 u8 mac_addr[ETH_ALEN];
97990a06 5215 int sta_idx = cb->args[2];
2ec600d6 5216 int err;
2ec600d6 5217
ea90e0dc 5218 rtnl_lock();
5297c65c 5219 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
67748893 5220 if (err)
ea90e0dc 5221 goto out_err;
bba95fef 5222
97990a06
JB
5223 if (!wdev->netdev) {
5224 err = -EINVAL;
5225 goto out_err;
5226 }
5227
1b8ec87a 5228 if (!rdev->ops->dump_station) {
eec60b03 5229 err = -EOPNOTSUPP;
bba95fef
JB
5230 goto out_err;
5231 }
5232
bba95fef 5233 while (1) {
73887fd9 5234 memset(&sinfo, 0, sizeof(sinfo));
1b8ec87a 5235 err = rdev_dump_station(rdev, wdev->netdev, sta_idx,
73887fd9 5236 mac_addr, &sinfo);
bba95fef
JB
5237 if (err == -ENOENT)
5238 break;
5239 if (err)
3b85875a 5240 goto out_err;
bba95fef 5241
cf5ead82 5242 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION,
15e47304 5243 NETLINK_CB(cb->skb).portid,
bba95fef 5244 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1b8ec87a 5245 rdev, wdev->netdev, mac_addr,
73887fd9 5246 &sinfo) < 0)
bba95fef
JB
5247 goto out;
5248
5249 sta_idx++;
5250 }
5251
bba95fef 5252 out:
97990a06 5253 cb->args[2] = sta_idx;
bba95fef 5254 err = skb->len;
bba95fef 5255 out_err:
ea90e0dc 5256 rtnl_unlock();
bba95fef
JB
5257
5258 return err;
2ec600d6 5259}
fd5b74dc 5260
5727ef1b
JB
5261static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
5262{
4c476991
JB
5263 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5264 struct net_device *dev = info->user_ptr[1];
73887fd9 5265 struct station_info sinfo;
fd5b74dc
JB
5266 struct sk_buff *msg;
5267 u8 *mac_addr = NULL;
4c476991 5268 int err;
fd5b74dc 5269
73887fd9 5270 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc 5271
73887fd9
JB
5272 if (!info->attrs[NL80211_ATTR_MAC])
5273 return -EINVAL;
fd5b74dc
JB
5274
5275 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5276
73887fd9
JB
5277 if (!rdev->ops->get_station)
5278 return -EOPNOTSUPP;
3b85875a 5279
73887fd9 5280 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 5281 if (err)
73887fd9 5282 return err;
2ec600d6 5283
fd2120ca 5284 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7ea3e110 5285 if (!msg) {
ba8f566a 5286 cfg80211_sinfo_release_content(&sinfo);
73887fd9 5287 return -ENOMEM;
7ea3e110 5288 }
fd5b74dc 5289
cf5ead82
JB
5290 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION,
5291 info->snd_portid, info->snd_seq, 0,
73887fd9 5292 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991 5293 nlmsg_free(msg);
73887fd9 5294 return -ENOBUFS;
4c476991 5295 }
3b85875a 5296
73887fd9 5297 return genlmsg_reply(msg, info);
5727ef1b
JB
5298}
5299
77ee7c89
JB
5300int cfg80211_check_station_change(struct wiphy *wiphy,
5301 struct station_parameters *params,
5302 enum cfg80211_station_type statype)
5303{
e4208427
AB
5304 if (params->listen_interval != -1 &&
5305 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89 5306 return -EINVAL;
e4208427 5307
17b94247
AB
5308 if (params->support_p2p_ps != -1 &&
5309 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
5310 return -EINVAL;
5311
c72e1140 5312 if (params->aid &&
e4208427
AB
5313 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
5314 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89
JB
5315 return -EINVAL;
5316
5317 /* When you run into this, adjust the code below for the new flag */
5318 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
5319
5320 switch (statype) {
eef941e6
TP
5321 case CFG80211_STA_MESH_PEER_KERNEL:
5322 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
5323 /*
5324 * No ignoring the TDLS flag here -- the userspace mesh
5325 * code doesn't have the bug of including TDLS in the
5326 * mask everywhere.
5327 */
5328 if (params->sta_flags_mask &
5329 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5330 BIT(NL80211_STA_FLAG_MFP) |
5331 BIT(NL80211_STA_FLAG_AUTHORIZED)))
5332 return -EINVAL;
5333 break;
5334 case CFG80211_STA_TDLS_PEER_SETUP:
5335 case CFG80211_STA_TDLS_PEER_ACTIVE:
5336 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
5337 return -EINVAL;
5338 /* ignore since it can't change */
5339 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
5340 break;
5341 default:
5342 /* disallow mesh-specific things */
5343 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
5344 return -EINVAL;
5345 if (params->local_pm)
5346 return -EINVAL;
5347 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
5348 return -EINVAL;
5349 }
5350
5351 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
5352 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
5353 /* TDLS can't be set, ... */
5354 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
5355 return -EINVAL;
5356 /*
5357 * ... but don't bother the driver with it. This works around
5358 * a hostapd/wpa_supplicant issue -- it always includes the
5359 * TLDS_PEER flag in the mask even for AP mode.
5360 */
5361 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
5362 }
5363
47edb11b
AB
5364 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
5365 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
5366 /* reject other things that can't change */
5367 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
5368 return -EINVAL;
5369 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
5370 return -EINVAL;
5371 if (params->supported_rates)
5372 return -EINVAL;
c4cbaf79
LC
5373 if (params->ext_capab || params->ht_capa || params->vht_capa ||
5374 params->he_capa)
77ee7c89
JB
5375 return -EINVAL;
5376 }
5377
47edb11b
AB
5378 if (statype != CFG80211_STA_AP_CLIENT &&
5379 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
5380 if (params->vlan)
5381 return -EINVAL;
5382 }
5383
5384 switch (statype) {
5385 case CFG80211_STA_AP_MLME_CLIENT:
5386 /* Use this only for authorizing/unauthorizing a station */
5387 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
5388 return -EOPNOTSUPP;
5389 break;
5390 case CFG80211_STA_AP_CLIENT:
47edb11b 5391 case CFG80211_STA_AP_CLIENT_UNASSOC:
77ee7c89
JB
5392 /* accept only the listed bits */
5393 if (params->sta_flags_mask &
5394 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
5395 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5396 BIT(NL80211_STA_FLAG_ASSOCIATED) |
5397 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
5398 BIT(NL80211_STA_FLAG_WME) |
5399 BIT(NL80211_STA_FLAG_MFP)))
5400 return -EINVAL;
5401
5402 /* but authenticated/associated only if driver handles it */
5403 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
5404 params->sta_flags_mask &
5405 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5406 BIT(NL80211_STA_FLAG_ASSOCIATED)))
5407 return -EINVAL;
5408 break;
5409 case CFG80211_STA_IBSS:
5410 case CFG80211_STA_AP_STA:
5411 /* reject any changes other than AUTHORIZED */
5412 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
5413 return -EINVAL;
5414 break;
5415 case CFG80211_STA_TDLS_PEER_SETUP:
5416 /* reject any changes other than AUTHORIZED or WME */
5417 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
5418 BIT(NL80211_STA_FLAG_WME)))
5419 return -EINVAL;
5420 /* force (at least) rates when authorizing */
5421 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
5422 !params->supported_rates)
5423 return -EINVAL;
5424 break;
5425 case CFG80211_STA_TDLS_PEER_ACTIVE:
5426 /* reject any changes */
5427 return -EINVAL;
eef941e6 5428 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
5429 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
5430 return -EINVAL;
5431 break;
eef941e6 5432 case CFG80211_STA_MESH_PEER_USER:
42925040
CYY
5433 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION &&
5434 params->plink_action != NL80211_PLINK_ACTION_BLOCK)
77ee7c89
JB
5435 return -EINVAL;
5436 break;
5437 }
5438
06f7c88c
BL
5439 /*
5440 * Older kernel versions ignored this attribute entirely, so don't
5441 * reject attempts to update it but mark it as unused instead so the
5442 * driver won't look at the data.
5443 */
5444 if (statype != CFG80211_STA_AP_CLIENT_UNASSOC &&
5445 statype != CFG80211_STA_TDLS_PEER_SETUP)
5446 params->opmode_notif_used = false;
5447
77ee7c89
JB
5448 return 0;
5449}
5450EXPORT_SYMBOL(cfg80211_check_station_change);
5451
5727ef1b 5452/*
c258d2de 5453 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 5454 */
80b99899
JB
5455static struct net_device *get_vlan(struct genl_info *info,
5456 struct cfg80211_registered_device *rdev)
5727ef1b 5457{
463d0183 5458 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
5459 struct net_device *v;
5460 int ret;
5461
5462 if (!vlanattr)
5463 return NULL;
5464
5465 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
5466 if (!v)
5467 return ERR_PTR(-ENODEV);
5468
5469 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
5470 ret = -EINVAL;
5471 goto error;
5727ef1b 5472 }
80b99899 5473
77ee7c89
JB
5474 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5475 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5476 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
5477 ret = -EINVAL;
5478 goto error;
5479 }
5480
80b99899
JB
5481 if (!netif_running(v)) {
5482 ret = -ENETDOWN;
5483 goto error;
5484 }
5485
5486 return v;
5487 error:
5488 dev_put(v);
5489 return ERR_PTR(ret);
5727ef1b
JB
5490}
5491
94e860f1
JB
5492static const struct nla_policy
5493nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
df881293
JM
5494 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
5495 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
5496};
5497
ff276691
JB
5498static int nl80211_parse_sta_wme(struct genl_info *info,
5499 struct station_parameters *params)
df881293 5500{
df881293
JM
5501 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
5502 struct nlattr *nla;
5503 int err;
5504
df881293
JM
5505 /* parse WME attributes if present */
5506 if (!info->attrs[NL80211_ATTR_STA_WME])
5507 return 0;
5508
5509 nla = info->attrs[NL80211_ATTR_STA_WME];
8cb08174
JB
5510 err = nla_parse_nested_deprecated(tb, NL80211_STA_WME_MAX, nla,
5511 nl80211_sta_wme_policy,
5512 info->extack);
df881293
JM
5513 if (err)
5514 return err;
5515
5516 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
5517 params->uapsd_queues = nla_get_u8(
5518 tb[NL80211_STA_WME_UAPSD_QUEUES]);
5519 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
5520 return -EINVAL;
5521
5522 if (tb[NL80211_STA_WME_MAX_SP])
5523 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
5524
5525 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
5526 return -EINVAL;
5527
5528 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
5529
5530 return 0;
5531}
5532
c01fc9ad
SD
5533static int nl80211_parse_sta_channel_info(struct genl_info *info,
5534 struct station_parameters *params)
5535{
5536 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
5537 params->supported_channels =
5538 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
5539 params->supported_channels_len =
5540 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
5541 /*
5542 * Need to include at least one (first channel, number of
5543 * channels) tuple for each subband, and must have proper
5544 * tuples for the rest of the data as well.
5545 */
5546 if (params->supported_channels_len < 2)
5547 return -EINVAL;
5548 if (params->supported_channels_len % 2)
5549 return -EINVAL;
5550 }
5551
5552 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
5553 params->supported_oper_classes =
5554 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
5555 params->supported_oper_classes_len =
5556 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
5557 /*
5558 * The value of the Length field of the Supported Operating
5559 * Classes element is between 2 and 253.
5560 */
5561 if (params->supported_oper_classes_len < 2 ||
5562 params->supported_oper_classes_len > 253)
5563 return -EINVAL;
5564 }
5565 return 0;
5566}
5567
ff276691
JB
5568static int nl80211_set_station_tdls(struct genl_info *info,
5569 struct station_parameters *params)
5570{
c01fc9ad 5571 int err;
ff276691 5572 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
5573 if (info->attrs[NL80211_ATTR_PEER_AID])
5574 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
5575 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
5576 params->ht_capa =
5577 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5578 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
5579 params->vht_capa =
5580 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
c4cbaf79
LC
5581 if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
5582 params->he_capa =
5583 nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
5584 params->he_capa_len =
5585 nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
5586
5587 if (params->he_capa_len < NL80211_HE_MIN_CAPABILITY_LEN)
5588 return -EINVAL;
5589 }
ff276691 5590
c01fc9ad
SD
5591 err = nl80211_parse_sta_channel_info(info, params);
5592 if (err)
5593 return err;
5594
ff276691
JB
5595 return nl80211_parse_sta_wme(info, params);
5596}
5597
e96d1cd2
ARN
5598static int nl80211_parse_sta_txpower_setting(struct genl_info *info,
5599 struct station_parameters *params)
5600{
5601 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5602 int idx;
5603
5604 if (info->attrs[NL80211_ATTR_STA_TX_POWER_SETTING]) {
5605 if (!rdev->ops->set_tx_power ||
5606 !wiphy_ext_feature_isset(&rdev->wiphy,
5607 NL80211_EXT_FEATURE_STA_TX_PWR))
5608 return -EOPNOTSUPP;
5609
5610 idx = NL80211_ATTR_STA_TX_POWER_SETTING;
5611 params->txpwr.type = nla_get_u8(info->attrs[idx]);
5612
5613 if (params->txpwr.type == NL80211_TX_POWER_LIMITED) {
5614 idx = NL80211_ATTR_STA_TX_POWER;
5615
5616 if (info->attrs[idx])
5617 params->txpwr.power =
5618 nla_get_s16(info->attrs[idx]);
5619 else
5620 return -EINVAL;
5621 }
5622 params->sta_modify_mask |= STATION_PARAM_APPLY_STA_TXPOWER;
5623 }
5624
5625 return 0;
5626}
5627
5727ef1b
JB
5628static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
5629{
4c476991 5630 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 5631 struct net_device *dev = info->user_ptr[1];
5727ef1b 5632 struct station_parameters params;
77ee7c89
JB
5633 u8 *mac_addr;
5634 int err;
5727ef1b
JB
5635
5636 memset(&params, 0, sizeof(params));
5637
77ee7c89
JB
5638 if (!rdev->ops->change_station)
5639 return -EOPNOTSUPP;
5640
e4208427
AB
5641 /*
5642 * AID and listen_interval properties can be set only for unassociated
5643 * station. Include these parameters here and will check them in
5644 * cfg80211_check_station_change().
5645 */
a9bc31e4
AB
5646 if (info->attrs[NL80211_ATTR_STA_AID])
5647 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
e4208427
AB
5648
5649 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
5650 params.listen_interval =
5651 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
5652 else
5653 params.listen_interval = -1;
5727ef1b 5654
ab0d76f6
JB
5655 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS])
5656 params.support_p2p_ps =
5657 nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
5658 else
17b94247 5659 params.support_p2p_ps = -1;
17b94247 5660
5727ef1b
JB
5661 if (!info->attrs[NL80211_ATTR_MAC])
5662 return -EINVAL;
5663
5664 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5665
5666 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
5667 params.supported_rates =
5668 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
5669 params.supported_rates_len =
5670 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
5671 }
5672
9d62a986
JM
5673 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
5674 params.capability =
5675 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
5676 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
5677 }
5678
5679 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
5680 params.ext_capab =
5681 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
5682 params.ext_capab_len =
5683 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
5684 }
5685
bdd3ae3d 5686 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
5687 return -EINVAL;
5688
ab0d76f6 5689 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2ec600d6 5690 params.plink_action =
f8bacc21 5691 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2ec600d6 5692
f8bacc21 5693 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 5694 params.plink_state =
f8bacc21 5695 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
ab0d76f6 5696 if (info->attrs[NL80211_ATTR_MESH_PEER_AID])
7d27a0ba
MH
5697 params.peer_aid = nla_get_u16(
5698 info->attrs[NL80211_ATTR_MESH_PEER_AID]);
f8bacc21
JB
5699 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
5700 }
9c3990aa 5701
ab0d76f6
JB
5702 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE])
5703 params.local_pm = nla_get_u32(
3b1c5a53
MP
5704 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
5705
06f7c88c
BL
5706 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
5707 params.opmode_notif_used = true;
5708 params.opmode_notif =
5709 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
5710 }
5711
36647055
THJ
5712 if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT])
5713 params.airtime_weight =
5714 nla_get_u16(info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]);
5715
5716 if (params.airtime_weight &&
5717 !wiphy_ext_feature_isset(&rdev->wiphy,
5718 NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
5719 return -EOPNOTSUPP;
5720
e96d1cd2
ARN
5721 err = nl80211_parse_sta_txpower_setting(info, &params);
5722 if (err)
5723 return err;
5724
77ee7c89
JB
5725 /* Include parameters for TDLS peer (will check later) */
5726 err = nl80211_set_station_tdls(info, &params);
5727 if (err)
5728 return err;
5729
5730 params.vlan = get_vlan(info, rdev);
5731 if (IS_ERR(params.vlan))
5732 return PTR_ERR(params.vlan);
5733
a97f4424
JB
5734 switch (dev->ieee80211_ptr->iftype) {
5735 case NL80211_IFTYPE_AP:
5736 case NL80211_IFTYPE_AP_VLAN:
074ac8df 5737 case NL80211_IFTYPE_P2P_GO:
074ac8df 5738 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 5739 case NL80211_IFTYPE_STATION:
267335d6 5740 case NL80211_IFTYPE_ADHOC:
a97f4424 5741 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
5742 break;
5743 default:
77ee7c89
JB
5744 err = -EOPNOTSUPP;
5745 goto out_put_vlan;
034d655e
JB
5746 }
5747
77ee7c89 5748 /* driver will call cfg80211_check_station_change() */
e35e4d28 5749 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 5750
77ee7c89 5751 out_put_vlan:
5727ef1b
JB
5752 if (params.vlan)
5753 dev_put(params.vlan);
3b85875a 5754
5727ef1b
JB
5755 return err;
5756}
5757
5758static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
5759{
4c476991 5760 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 5761 int err;
4c476991 5762 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
5763 struct station_parameters params;
5764 u8 *mac_addr = NULL;
bda95eb1
JB
5765 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5766 BIT(NL80211_STA_FLAG_ASSOCIATED);
5727ef1b
JB
5767
5768 memset(&params, 0, sizeof(params));
5769
984c311b
JB
5770 if (!rdev->ops->add_station)
5771 return -EOPNOTSUPP;
5772
5727ef1b
JB
5773 if (!info->attrs[NL80211_ATTR_MAC])
5774 return -EINVAL;
5775
5727ef1b
JB
5776 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
5777 return -EINVAL;
5778
5779 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
5780 return -EINVAL;
5781
5e4b6f56
JM
5782 if (!info->attrs[NL80211_ATTR_STA_AID] &&
5783 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
5784 return -EINVAL;
5785
5727ef1b
JB
5786 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5787 params.supported_rates =
5788 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
5789 params.supported_rates_len =
5790 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
5791 params.listen_interval =
5792 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 5793
17b94247 5794 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
ab0d76f6
JB
5795 params.support_p2p_ps =
5796 nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
17b94247
AB
5797 } else {
5798 /*
5799 * if not specified, assume it's supported for P2P GO interface,
5800 * and is NOT supported for AP interface
5801 */
5802 params.support_p2p_ps =
5803 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO;
5804 }
5805
3d124ea2 5806 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 5807 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
5808 else
5809 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
51b50fbe 5810
9d62a986
JM
5811 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
5812 params.capability =
5813 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
5814 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
5815 }
5816
5817 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
5818 params.ext_capab =
5819 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
5820 params.ext_capab_len =
5821 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
5822 }
5823
36aedc90
JM
5824 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
5825 params.ht_capa =
5826 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 5827
f461be3e
MP
5828 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
5829 params.vht_capa =
5830 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
5831
c4cbaf79
LC
5832 if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
5833 params.he_capa =
5834 nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
5835 params.he_capa_len =
5836 nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
5837
5838 /* max len is validated in nla policy */
5839 if (params.he_capa_len < NL80211_HE_MIN_CAPABILITY_LEN)
5840 return -EINVAL;
5841 }
5842
60f4a7b1
MK
5843 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
5844 params.opmode_notif_used = true;
5845 params.opmode_notif =
5846 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
5847 }
5848
ab0d76f6 5849 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
96b78dff 5850 params.plink_action =
f8bacc21 5851 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
96b78dff 5852
36647055
THJ
5853 if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT])
5854 params.airtime_weight =
5855 nla_get_u16(info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]);
5856
5857 if (params.airtime_weight &&
5858 !wiphy_ext_feature_isset(&rdev->wiphy,
5859 NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
5860 return -EOPNOTSUPP;
5861
e96d1cd2
ARN
5862 err = nl80211_parse_sta_txpower_setting(info, &params);
5863 if (err)
5864 return err;
5865
c01fc9ad
SD
5866 err = nl80211_parse_sta_channel_info(info, &params);
5867 if (err)
5868 return err;
5869
ff276691
JB
5870 err = nl80211_parse_sta_wme(info, &params);
5871 if (err)
5872 return err;
bdd90d5e 5873
bdd3ae3d 5874 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
5875 return -EINVAL;
5876
496fcc29
JB
5877 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT
5878 * as userspace might just pass through the capabilities from the IEs
5879 * directly, rather than enforcing this restriction and returning an
5880 * error in this case.
5881 */
5882 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) {
5883 params.ht_capa = NULL;
5884 params.vht_capa = NULL;
c4cbaf79
LC
5885
5886 /* HE requires WME */
5887 if (params.he_capa_len)
5888 return -EINVAL;
496fcc29
JB
5889 }
5890
77ee7c89
JB
5891 /* When you run into this, adjust the code below for the new flag */
5892 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
5893
bdd90d5e
JB
5894 switch (dev->ieee80211_ptr->iftype) {
5895 case NL80211_IFTYPE_AP:
5896 case NL80211_IFTYPE_AP_VLAN:
5897 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
5898 /* ignore WME attributes if iface/sta is not capable */
5899 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
5900 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
5901 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 5902
bdd90d5e 5903 /* TDLS peers cannot be added */
3d124ea2
JM
5904 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
5905 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 5906 return -EINVAL;
bdd90d5e
JB
5907 /* but don't bother the driver with it */
5908 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 5909
d582cffb
JB
5910 /* allow authenticated/associated only if driver handles it */
5911 if (!(rdev->wiphy.features &
5912 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
bda95eb1 5913 params.sta_flags_mask & auth_assoc)
d582cffb
JB
5914 return -EINVAL;
5915
bda95eb1
JB
5916 /* Older userspace, or userspace wanting to be compatible with
5917 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth
5918 * and assoc flags in the mask, but assumes the station will be
5919 * added as associated anyway since this was the required driver
5920 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was
5921 * introduced.
5922 * In order to not bother drivers with this quirk in the API
5923 * set the flags in both the mask and set for new stations in
5924 * this case.
5925 */
5926 if (!(params.sta_flags_mask & auth_assoc)) {
5927 params.sta_flags_mask |= auth_assoc;
5928 params.sta_flags_set |= auth_assoc;
5929 }
5930
bdd90d5e
JB
5931 /* must be last in here for error handling */
5932 params.vlan = get_vlan(info, rdev);
5933 if (IS_ERR(params.vlan))
5934 return PTR_ERR(params.vlan);
5935 break;
5936 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
5937 /* ignore uAPSD data */
5938 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
5939
d582cffb
JB
5940 /* associated is disallowed */
5941 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
5942 return -EINVAL;
bdd90d5e 5943 /* TDLS peers cannot be added */
3d124ea2
JM
5944 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
5945 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
5946 return -EINVAL;
5947 break;
5948 case NL80211_IFTYPE_STATION:
93d08f0b 5949 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
5950 /* ignore uAPSD data */
5951 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
5952
77ee7c89
JB
5953 /* these are disallowed */
5954 if (params.sta_flags_mask &
5955 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
5956 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 5957 return -EINVAL;
bdd90d5e
JB
5958 /* Only TDLS peers can be added */
5959 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
5960 return -EINVAL;
5961 /* Can only add if TDLS ... */
5962 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
5963 return -EOPNOTSUPP;
5964 /* ... with external setup is supported */
5965 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
5966 return -EOPNOTSUPP;
77ee7c89
JB
5967 /*
5968 * Older wpa_supplicant versions always mark the TDLS peer
5969 * as authorized, but it shouldn't yet be.
5970 */
5971 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
5972 break;
5973 default:
5974 return -EOPNOTSUPP;
c75786c9
EP
5975 }
5976
bdd90d5e 5977 /* be aware of params.vlan when changing code here */
5727ef1b 5978
e35e4d28 5979 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 5980
5727ef1b
JB
5981 if (params.vlan)
5982 dev_put(params.vlan);
5727ef1b
JB
5983 return err;
5984}
5985
5986static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
5987{
4c476991
JB
5988 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5989 struct net_device *dev = info->user_ptr[1];
89c771e5
JM
5990 struct station_del_parameters params;
5991
5992 memset(&params, 0, sizeof(params));
5727ef1b
JB
5993
5994 if (info->attrs[NL80211_ATTR_MAC])
89c771e5 5995 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
5727ef1b 5996
e80cf853 5997 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 5998 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 5999 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
6000 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6001 return -EINVAL;
5727ef1b 6002
4c476991
JB
6003 if (!rdev->ops->del_station)
6004 return -EOPNOTSUPP;
3b85875a 6005
98856866
JM
6006 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) {
6007 params.subtype =
6008 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
6009 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 &&
6010 params.subtype != IEEE80211_STYPE_DEAUTH >> 4)
6011 return -EINVAL;
6012 } else {
6013 /* Default to Deauthentication frame */
6014 params.subtype = IEEE80211_STYPE_DEAUTH >> 4;
6015 }
6016
6017 if (info->attrs[NL80211_ATTR_REASON_CODE]) {
6018 params.reason_code =
6019 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6020 if (params.reason_code == 0)
6021 return -EINVAL; /* 0 is reserved */
6022 } else {
6023 /* Default to reason code 2 */
6024 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID;
6025 }
6026
89c771e5 6027 return rdev_del_station(rdev, dev, &params);
5727ef1b
JB
6028}
6029
15e47304 6030static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
6031 int flags, struct net_device *dev,
6032 u8 *dst, u8 *next_hop,
6033 struct mpath_info *pinfo)
6034{
6035 void *hdr;
6036 struct nlattr *pinfoattr;
6037
1ef4c850 6038 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH);
2ec600d6
LCC
6039 if (!hdr)
6040 return -1;
6041
9360ffd1
DM
6042 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
6043 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
6044 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
6045 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
6046 goto nla_put_failure;
f5ea9120 6047
ae0be8de 6048 pinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_MPATH_INFO);
2ec600d6
LCC
6049 if (!pinfoattr)
6050 goto nla_put_failure;
9360ffd1
DM
6051 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
6052 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
6053 pinfo->frame_qlen))
6054 goto nla_put_failure;
6055 if (((pinfo->filled & MPATH_INFO_SN) &&
6056 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
6057 ((pinfo->filled & MPATH_INFO_METRIC) &&
6058 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
6059 pinfo->metric)) ||
6060 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
6061 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
6062 pinfo->exptime)) ||
6063 ((pinfo->filled & MPATH_INFO_FLAGS) &&
6064 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
6065 pinfo->flags)) ||
6066 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
6067 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
6068 pinfo->discovery_timeout)) ||
6069 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
6070 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
cc241636
JH
6071 pinfo->discovery_retries)) ||
6072 ((pinfo->filled & MPATH_INFO_HOP_COUNT) &&
6073 nla_put_u8(msg, NL80211_MPATH_INFO_HOP_COUNT,
540bbcb9
JH
6074 pinfo->hop_count)) ||
6075 ((pinfo->filled & MPATH_INFO_PATH_CHANGE) &&
6076 nla_put_u32(msg, NL80211_MPATH_INFO_PATH_CHANGE,
6077 pinfo->path_change_count)))
9360ffd1 6078 goto nla_put_failure;
2ec600d6
LCC
6079
6080 nla_nest_end(msg, pinfoattr);
6081
053c095a
JB
6082 genlmsg_end(msg, hdr);
6083 return 0;
2ec600d6
LCC
6084
6085 nla_put_failure:
bc3ed28c
TG
6086 genlmsg_cancel(msg, hdr);
6087 return -EMSGSIZE;
2ec600d6
LCC
6088}
6089
6090static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 6091 struct netlink_callback *cb)
2ec600d6 6092{
2ec600d6 6093 struct mpath_info pinfo;
1b8ec87a 6094 struct cfg80211_registered_device *rdev;
97990a06 6095 struct wireless_dev *wdev;
2ec600d6
LCC
6096 u8 dst[ETH_ALEN];
6097 u8 next_hop[ETH_ALEN];
97990a06 6098 int path_idx = cb->args[2];
2ec600d6 6099 int err;
2ec600d6 6100
ea90e0dc 6101 rtnl_lock();
5297c65c 6102 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
67748893 6103 if (err)
ea90e0dc 6104 goto out_err;
bba95fef 6105
1b8ec87a 6106 if (!rdev->ops->dump_mpath) {
eec60b03 6107 err = -EOPNOTSUPP;
bba95fef
JB
6108 goto out_err;
6109 }
6110
97990a06 6111 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 6112 err = -EOPNOTSUPP;
0448b5fc 6113 goto out_err;
eec60b03
JM
6114 }
6115
bba95fef 6116 while (1) {
1b8ec87a 6117 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst,
97990a06 6118 next_hop, &pinfo);
bba95fef 6119 if (err == -ENOENT)
2ec600d6 6120 break;
bba95fef 6121 if (err)
3b85875a 6122 goto out_err;
2ec600d6 6123
15e47304 6124 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 6125 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 6126 wdev->netdev, dst, next_hop,
bba95fef
JB
6127 &pinfo) < 0)
6128 goto out;
2ec600d6 6129
bba95fef 6130 path_idx++;
2ec600d6 6131 }
2ec600d6 6132
bba95fef 6133 out:
97990a06 6134 cb->args[2] = path_idx;
bba95fef 6135 err = skb->len;
bba95fef 6136 out_err:
ea90e0dc 6137 rtnl_unlock();
bba95fef 6138 return err;
2ec600d6
LCC
6139}
6140
6141static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
6142{
4c476991 6143 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 6144 int err;
4c476991 6145 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6146 struct mpath_info pinfo;
6147 struct sk_buff *msg;
6148 u8 *dst = NULL;
6149 u8 next_hop[ETH_ALEN];
6150
6151 memset(&pinfo, 0, sizeof(pinfo));
6152
6153 if (!info->attrs[NL80211_ATTR_MAC])
6154 return -EINVAL;
6155
6156 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6157
4c476991
JB
6158 if (!rdev->ops->get_mpath)
6159 return -EOPNOTSUPP;
2ec600d6 6160
4c476991
JB
6161 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6162 return -EOPNOTSUPP;
eec60b03 6163
e35e4d28 6164 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 6165 if (err)
4c476991 6166 return err;
2ec600d6 6167
fd2120ca 6168 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 6169 if (!msg)
4c476991 6170 return -ENOMEM;
2ec600d6 6171
15e47304 6172 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
6173 dev, dst, next_hop, &pinfo) < 0) {
6174 nlmsg_free(msg);
6175 return -ENOBUFS;
6176 }
3b85875a 6177
4c476991 6178 return genlmsg_reply(msg, info);
2ec600d6
LCC
6179}
6180
6181static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
6182{
4c476991
JB
6183 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6184 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6185 u8 *dst = NULL;
6186 u8 *next_hop = NULL;
6187
6188 if (!info->attrs[NL80211_ATTR_MAC])
6189 return -EINVAL;
6190
6191 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
6192 return -EINVAL;
6193
6194 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6195 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
6196
4c476991
JB
6197 if (!rdev->ops->change_mpath)
6198 return -EOPNOTSUPP;
35a8efe1 6199
4c476991
JB
6200 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6201 return -EOPNOTSUPP;
2ec600d6 6202
e35e4d28 6203 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 6204}
4c476991 6205
2ec600d6
LCC
6206static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
6207{
4c476991
JB
6208 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6209 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6210 u8 *dst = NULL;
6211 u8 *next_hop = NULL;
6212
6213 if (!info->attrs[NL80211_ATTR_MAC])
6214 return -EINVAL;
6215
6216 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
6217 return -EINVAL;
6218
6219 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6220 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
6221
4c476991
JB
6222 if (!rdev->ops->add_mpath)
6223 return -EOPNOTSUPP;
35a8efe1 6224
4c476991
JB
6225 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6226 return -EOPNOTSUPP;
2ec600d6 6227
e35e4d28 6228 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
6229}
6230
6231static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
6232{
4c476991
JB
6233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6234 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6235 u8 *dst = NULL;
6236
6237 if (info->attrs[NL80211_ATTR_MAC])
6238 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6239
4c476991
JB
6240 if (!rdev->ops->del_mpath)
6241 return -EOPNOTSUPP;
3b85875a 6242
e35e4d28 6243 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
6244}
6245
66be7d2b
HR
6246static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info)
6247{
6248 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6249 int err;
6250 struct net_device *dev = info->user_ptr[1];
6251 struct mpath_info pinfo;
6252 struct sk_buff *msg;
6253 u8 *dst = NULL;
6254 u8 mpp[ETH_ALEN];
6255
6256 memset(&pinfo, 0, sizeof(pinfo));
6257
6258 if (!info->attrs[NL80211_ATTR_MAC])
6259 return -EINVAL;
6260
6261 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6262
6263 if (!rdev->ops->get_mpp)
6264 return -EOPNOTSUPP;
6265
6266 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6267 return -EOPNOTSUPP;
6268
6269 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo);
6270 if (err)
6271 return err;
6272
6273 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6274 if (!msg)
6275 return -ENOMEM;
6276
6277 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
6278 dev, dst, mpp, &pinfo) < 0) {
6279 nlmsg_free(msg);
6280 return -ENOBUFS;
6281 }
6282
6283 return genlmsg_reply(msg, info);
6284}
6285
6286static int nl80211_dump_mpp(struct sk_buff *skb,
6287 struct netlink_callback *cb)
6288{
6289 struct mpath_info pinfo;
6290 struct cfg80211_registered_device *rdev;
6291 struct wireless_dev *wdev;
6292 u8 dst[ETH_ALEN];
6293 u8 mpp[ETH_ALEN];
6294 int path_idx = cb->args[2];
6295 int err;
6296
ea90e0dc 6297 rtnl_lock();
5297c65c 6298 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
66be7d2b 6299 if (err)
ea90e0dc 6300 goto out_err;
66be7d2b
HR
6301
6302 if (!rdev->ops->dump_mpp) {
6303 err = -EOPNOTSUPP;
6304 goto out_err;
6305 }
6306
6307 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
6308 err = -EOPNOTSUPP;
6309 goto out_err;
6310 }
6311
6312 while (1) {
6313 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst,
6314 mpp, &pinfo);
6315 if (err == -ENOENT)
6316 break;
6317 if (err)
6318 goto out_err;
6319
6320 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
6321 cb->nlh->nlmsg_seq, NLM_F_MULTI,
6322 wdev->netdev, dst, mpp,
6323 &pinfo) < 0)
6324 goto out;
6325
6326 path_idx++;
6327 }
6328
6329 out:
6330 cb->args[2] = path_idx;
6331 err = skb->len;
6332 out_err:
ea90e0dc 6333 rtnl_unlock();
66be7d2b
HR
6334 return err;
6335}
6336
9f1ba906
JM
6337static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
6338{
4c476991
JB
6339 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6340 struct net_device *dev = info->user_ptr[1];
c56589ed 6341 struct wireless_dev *wdev = dev->ieee80211_ptr;
9f1ba906 6342 struct bss_parameters params;
c56589ed 6343 int err;
9f1ba906
JM
6344
6345 memset(&params, 0, sizeof(params));
6346 /* default to not changing parameters */
6347 params.use_cts_prot = -1;
6348 params.use_short_preamble = -1;
6349 params.use_short_slot_time = -1;
fd8aaaf3 6350 params.ap_isolate = -1;
50b12f59 6351 params.ht_opmode = -1;
53cabad7
JB
6352 params.p2p_ctwindow = -1;
6353 params.p2p_opp_ps = -1;
9f1ba906
JM
6354
6355 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
6356 params.use_cts_prot =
6357 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
6358 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
6359 params.use_short_preamble =
6360 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
6361 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
6362 params.use_short_slot_time =
6363 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
6364 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
6365 params.basic_rates =
6366 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6367 params.basic_rates_len =
6368 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6369 }
fd8aaaf3
FF
6370 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
6371 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
6372 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
6373 params.ht_opmode =
6374 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 6375
53cabad7
JB
6376 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
6377 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6378 return -EINVAL;
6379 params.p2p_ctwindow =
ab0d76f6 6380 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
53cabad7
JB
6381 if (params.p2p_ctwindow != 0 &&
6382 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
6383 return -EINVAL;
6384 }
6385
6386 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
6387 u8 tmp;
6388
6389 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6390 return -EINVAL;
6391 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
53cabad7
JB
6392 params.p2p_opp_ps = tmp;
6393 if (params.p2p_opp_ps &&
6394 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
6395 return -EINVAL;
6396 }
6397
4c476991
JB
6398 if (!rdev->ops->change_bss)
6399 return -EOPNOTSUPP;
9f1ba906 6400
074ac8df 6401 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
6402 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6403 return -EOPNOTSUPP;
3b85875a 6404
c56589ed
SW
6405 wdev_lock(wdev);
6406 err = rdev_change_bss(rdev, dev, &params);
6407 wdev_unlock(wdev);
6408
6409 return err;
9f1ba906
JM
6410}
6411
b2e1b302
LR
6412static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
6413{
b2e1b302 6414 char *data = NULL;
05050753 6415 bool is_indoor;
57b5ce07 6416 enum nl80211_user_reg_hint_type user_reg_hint_type;
05050753
I
6417 u32 owner_nlportid;
6418
80778f18
LR
6419 /*
6420 * You should only get this when cfg80211 hasn't yet initialized
6421 * completely when built-in to the kernel right between the time
6422 * window between nl80211_init() and regulatory_init(), if that is
6423 * even possible.
6424 */
458f4f9e 6425 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 6426 return -EINPROGRESS;
80778f18 6427
57b5ce07
LR
6428 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
6429 user_reg_hint_type =
6430 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
6431 else
6432 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
6433
6434 switch (user_reg_hint_type) {
6435 case NL80211_USER_REG_HINT_USER:
6436 case NL80211_USER_REG_HINT_CELL_BASE:
52616f2b
IP
6437 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
6438 return -EINVAL;
6439
6440 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
6441 return regulatory_hint_user(data, user_reg_hint_type);
6442 case NL80211_USER_REG_HINT_INDOOR:
05050753
I
6443 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
6444 owner_nlportid = info->snd_portid;
6445 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR];
6446 } else {
6447 owner_nlportid = 0;
6448 is_indoor = true;
6449 }
6450
6451 return regulatory_hint_indoor(is_indoor, owner_nlportid);
57b5ce07
LR
6452 default:
6453 return -EINVAL;
6454 }
b2e1b302
LR
6455}
6456
1ea4ff3e
JB
6457static int nl80211_reload_regdb(struct sk_buff *skb, struct genl_info *info)
6458{
6459 return reg_reload_regdb();
6460}
6461
24bdd9f4 6462static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 6463 struct genl_info *info)
93da9cc1 6464{
4c476991 6465 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 6466 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
6467 struct wireless_dev *wdev = dev->ieee80211_ptr;
6468 struct mesh_config cur_params;
6469 int err = 0;
93da9cc1 6470 void *hdr;
6471 struct nlattr *pinfoattr;
6472 struct sk_buff *msg;
6473
29cbe68c
JB
6474 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
6475 return -EOPNOTSUPP;
6476
24bdd9f4 6477 if (!rdev->ops->get_mesh_config)
4c476991 6478 return -EOPNOTSUPP;
f3f92586 6479
29cbe68c
JB
6480 wdev_lock(wdev);
6481 /* If not connected, get default parameters */
6482 if (!wdev->mesh_id_len)
6483 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
6484 else
e35e4d28 6485 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
6486 wdev_unlock(wdev);
6487
93da9cc1 6488 if (err)
4c476991 6489 return err;
93da9cc1 6490
6491 /* Draw up a netlink message to send back */
fd2120ca 6492 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6493 if (!msg)
6494 return -ENOMEM;
15e47304 6495 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 6496 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 6497 if (!hdr)
efe1cf0c 6498 goto out;
ae0be8de 6499 pinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 6500 if (!pinfoattr)
6501 goto nla_put_failure;
9360ffd1
DM
6502 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
6503 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
6504 cur_params.dot11MeshRetryTimeout) ||
6505 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
6506 cur_params.dot11MeshConfirmTimeout) ||
6507 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
6508 cur_params.dot11MeshHoldingTimeout) ||
6509 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
6510 cur_params.dot11MeshMaxPeerLinks) ||
6511 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
6512 cur_params.dot11MeshMaxRetries) ||
6513 nla_put_u8(msg, NL80211_MESHCONF_TTL,
6514 cur_params.dot11MeshTTL) ||
6515 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
6516 cur_params.element_ttl) ||
6517 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
6518 cur_params.auto_open_plinks) ||
7eab0f64
JL
6519 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
6520 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
6521 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
6522 cur_params.dot11MeshHWMPmaxPREQretries) ||
6523 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
6524 cur_params.path_refresh_time) ||
6525 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
6526 cur_params.min_discovery_timeout) ||
6527 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
6528 cur_params.dot11MeshHWMPactivePathTimeout) ||
6529 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
6530 cur_params.dot11MeshHWMPpreqMinInterval) ||
6531 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
6532 cur_params.dot11MeshHWMPperrMinInterval) ||
6533 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
6534 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
6535 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
6536 cur_params.dot11MeshHWMPRootMode) ||
6537 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
6538 cur_params.dot11MeshHWMPRannInterval) ||
6539 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
6540 cur_params.dot11MeshGateAnnouncementProtocol) ||
6541 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
6542 cur_params.dot11MeshForwarding) ||
335d5349 6543 nla_put_s32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
6544 cur_params.rssi_threshold) ||
6545 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
6546 cur_params.ht_opmode) ||
6547 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
6548 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
6549 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
6550 cur_params.dot11MeshHWMProotInterval) ||
6551 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
6552 cur_params.dot11MeshHWMPconfirmationInterval) ||
6553 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
6554 cur_params.power_mode) ||
6555 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
6556 cur_params.dot11MeshAwakeWindowDuration) ||
6557 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
01d66fbd
BC
6558 cur_params.plink_timeout) ||
6559 nla_put_u8(msg, NL80211_MESHCONF_CONNECTED_TO_GATE,
6560 cur_params.dot11MeshConnectedToMeshGate))
9360ffd1 6561 goto nla_put_failure;
93da9cc1 6562 nla_nest_end(msg, pinfoattr);
6563 genlmsg_end(msg, hdr);
4c476991 6564 return genlmsg_reply(msg, info);
93da9cc1 6565
3b85875a 6566 nla_put_failure:
efe1cf0c 6567 out:
d080e275 6568 nlmsg_free(msg);
4c476991 6569 return -ENOBUFS;
93da9cc1 6570}
6571
ab0d76f6
JB
6572static const struct nla_policy
6573nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
6574 [NL80211_MESHCONF_RETRY_TIMEOUT] =
6575 NLA_POLICY_RANGE(NLA_U16, 1, 255),
6576 [NL80211_MESHCONF_CONFIRM_TIMEOUT] =
6577 NLA_POLICY_RANGE(NLA_U16, 1, 255),
6578 [NL80211_MESHCONF_HOLDING_TIMEOUT] =
6579 NLA_POLICY_RANGE(NLA_U16, 1, 255),
6580 [NL80211_MESHCONF_MAX_PEER_LINKS] =
6581 NLA_POLICY_RANGE(NLA_U16, 0, 255),
6582 [NL80211_MESHCONF_MAX_RETRIES] = NLA_POLICY_MAX(NLA_U8, 16),
6583 [NL80211_MESHCONF_TTL] = NLA_POLICY_MIN(NLA_U8, 1),
6584 [NL80211_MESHCONF_ELEMENT_TTL] = NLA_POLICY_MIN(NLA_U8, 1),
6585 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = NLA_POLICY_MAX(NLA_U8, 1),
6586 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] =
6587 NLA_POLICY_RANGE(NLA_U32, 1, 255),
93da9cc1 6588 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
6589 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
ab0d76f6 6590 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = NLA_POLICY_MIN(NLA_U16, 1),
93da9cc1 6591 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
ab0d76f6
JB
6592 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] =
6593 NLA_POLICY_MIN(NLA_U16, 1),
6594 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] =
6595 NLA_POLICY_MIN(NLA_U16, 1),
6596 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] =
6597 NLA_POLICY_MIN(NLA_U16, 1),
6598 [NL80211_MESHCONF_HWMP_ROOTMODE] = NLA_POLICY_MAX(NLA_U8, 4),
6599 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] =
6600 NLA_POLICY_MIN(NLA_U16, 1),
6601 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = NLA_POLICY_MAX(NLA_U8, 1),
6602 [NL80211_MESHCONF_FORWARDING] = NLA_POLICY_MAX(NLA_U8, 1),
6603 [NL80211_MESHCONF_RSSI_THRESHOLD] =
6604 NLA_POLICY_RANGE(NLA_S32, -255, 0),
a4f606ea 6605 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6 6606 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
ab0d76f6
JB
6607 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] =
6608 NLA_POLICY_MIN(NLA_U16, 1),
6609 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] =
6610 NLA_POLICY_MIN(NLA_U16, 1),
6611 [NL80211_MESHCONF_POWER_MODE] =
6612 NLA_POLICY_RANGE(NLA_U32,
6613 NL80211_MESH_POWER_ACTIVE,
6614 NL80211_MESH_POWER_MAX),
3b1c5a53 6615 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 6616 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
01d66fbd 6617 [NL80211_MESHCONF_CONNECTED_TO_GATE] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
93da9cc1 6618};
6619
c80d545d
JC
6620static const struct nla_policy
6621 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 6622 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
6623 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
6624 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 6625 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 6626 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 6627 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
3d7af878
JB
6628 [NL80211_MESH_SETUP_IE] =
6629 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
6630 IEEE80211_MAX_DATA_LEN),
b130e5ce 6631 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
6632};
6633
24bdd9f4 6634static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
6635 struct mesh_config *cfg,
6636 u32 *mask_out)
93da9cc1 6637{
93da9cc1 6638 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 6639 u32 mask = 0;
9757235f 6640 u16 ht_opmode;
93da9cc1 6641
ab0d76f6
JB
6642#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, mask, attr, fn) \
6643do { \
6644 if (tb[attr]) { \
6645 cfg->param = fn(tb[attr]); \
6646 mask |= BIT((attr) - 1); \
6647 } \
ea54fba2 6648} while (0)
bd90fdcc 6649
24bdd9f4 6650 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 6651 return -EINVAL;
8cb08174 6652 if (nla_parse_nested_deprecated(tb, NL80211_MESHCONF_ATTR_MAX, info->attrs[NL80211_ATTR_MESH_CONFIG], nl80211_meshconf_params_policy, info->extack))
93da9cc1 6653 return -EINVAL;
6654
93da9cc1 6655 /* This makes sure that there aren't more than 32 mesh config
6656 * parameters (otherwise our bitfield scheme would not work.) */
6657 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
6658
6659 /* Fill in the params struct */
ab0d76f6
JB
6660 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, mask,
6661 NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
6662 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, mask,
6663 NL80211_MESHCONF_CONFIRM_TIMEOUT,
6664 nla_get_u16);
6665 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, mask,
6666 NL80211_MESHCONF_HOLDING_TIMEOUT,
6667 nla_get_u16);
6668 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, mask,
6669 NL80211_MESHCONF_MAX_PEER_LINKS,
6670 nla_get_u16);
6671 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, mask,
6672 NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
6673 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, mask,
6674 NL80211_MESHCONF_TTL, nla_get_u8);
6675 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, mask,
6676 NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
6677 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, mask,
6678 NL80211_MESHCONF_AUTO_OPEN_PLINKS,
6679 nla_get_u8);
ea54fba2 6680 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
ab0d76f6 6681 mask,
a4f606ea 6682 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
ab0d76f6
JB
6683 nla_get_u32);
6684 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, mask,
6685 NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
6686 nla_get_u8);
6687 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, mask,
6688 NL80211_MESHCONF_PATH_REFRESH_TIME,
6689 nla_get_u32);
6690 if (mask & BIT(NL80211_MESHCONF_PATH_REFRESH_TIME) &&
6691 (cfg->path_refresh_time < 1 || cfg->path_refresh_time > 65535))
6692 return -EINVAL;
6693 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, mask,
6694 NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
6695 nla_get_u16);
ea54fba2 6696 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
ab0d76f6 6697 mask,
a4f606ea 6698 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
ab0d76f6
JB
6699 nla_get_u32);
6700 if (mask & BIT(NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT) &&
6701 (cfg->dot11MeshHWMPactivePathTimeout < 1 ||
6702 cfg->dot11MeshHWMPactivePathTimeout > 65535))
6703 return -EINVAL;
6704 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval, mask,
ea54fba2 6705 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
ab0d76f6
JB
6706 nla_get_u16);
6707 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval, mask,
ea54fba2 6708 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
ab0d76f6 6709 nla_get_u16);
93da9cc1 6710 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ab0d76f6 6711 dot11MeshHWMPnetDiameterTraversalTime, mask,
a4f606ea 6712 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
ab0d76f6
JB
6713 nla_get_u16);
6714 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
6715 NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
6716 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
6717 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
6718 nla_get_u16);
6719 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshGateAnnouncementProtocol,
ea54fba2 6720 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
ab0d76f6
JB
6721 nla_get_u8);
6722 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, mask,
6723 NL80211_MESHCONF_FORWARDING, nla_get_u8);
6724 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, mask,
6725 NL80211_MESHCONF_RSSI_THRESHOLD,
6726 nla_get_s32);
01d66fbd
BC
6727 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConnectedToMeshGate, mask,
6728 NL80211_MESHCONF_CONNECTED_TO_GATE,
6729 nla_get_u8);
9757235f
MH
6730 /*
6731 * Check HT operation mode based on
188f60ab 6732 * IEEE 802.11-2016 9.4.2.57 HT Operation element.
9757235f
MH
6733 */
6734 if (tb[NL80211_MESHCONF_HT_OPMODE]) {
6735 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]);
6736
6737 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION |
6738 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
6739 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
6740 return -EINVAL;
6741
188f60ab
BC
6742 /* NON_HT_STA bit is reserved, but some programs set it */
6743 ht_opmode &= ~IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
9757235f 6744
9757235f 6745 cfg->ht_opmode = ht_opmode;
fd551bac 6746 mask |= (1 << (NL80211_MESHCONF_HT_OPMODE - 1));
9757235f 6747 }
728b19e5 6748 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ab0d76f6
JB
6749 dot11MeshHWMPactivePathToRootTimeout, mask,
6750 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
6751 nla_get_u32);
6752 if (mask & BIT(NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT) &&
6753 (cfg->dot11MeshHWMPactivePathToRootTimeout < 1 ||
6754 cfg->dot11MeshHWMPactivePathToRootTimeout > 65535))
6755 return -EINVAL;
6756 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, mask,
6757 NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
6758 nla_get_u16);
6759 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPconfirmationInterval,
6760 mask,
728b19e5 6761 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
ab0d76f6
JB
6762 nla_get_u16);
6763 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode, mask,
6764 NL80211_MESHCONF_POWER_MODE, nla_get_u32);
6765 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration, mask,
6766 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
6767 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, mask,
6768 NL80211_MESHCONF_PLINK_TIMEOUT, nla_get_u32);
bd90fdcc
JB
6769 if (mask_out)
6770 *mask_out = mask;
c80d545d 6771
bd90fdcc
JB
6772 return 0;
6773
6774#undef FILL_IN_MESH_PARAM_IF_SET
6775}
6776
c80d545d
JC
6777static int nl80211_parse_mesh_setup(struct genl_info *info,
6778 struct mesh_setup *setup)
6779{
bb2798d4 6780 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
6781 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
6782
6783 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
6784 return -EINVAL;
8cb08174 6785 if (nla_parse_nested_deprecated(tb, NL80211_MESH_SETUP_ATTR_MAX, info->attrs[NL80211_ATTR_MESH_SETUP], nl80211_mesh_setup_params_policy, info->extack))
c80d545d
JC
6786 return -EINVAL;
6787
d299a1f2
JC
6788 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
6789 setup->sync_method =
6790 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
6791 IEEE80211_SYNC_METHOD_VENDOR :
6792 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
6793
c80d545d
JC
6794 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
6795 setup->path_sel_proto =
6796 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
6797 IEEE80211_PATH_PROTOCOL_VENDOR :
6798 IEEE80211_PATH_PROTOCOL_HWMP;
6799
6800 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
6801 setup->path_metric =
6802 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
6803 IEEE80211_PATH_METRIC_VENDOR :
6804 IEEE80211_PATH_METRIC_AIRTIME;
6805
581a8b0f 6806 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 6807 struct nlattr *ieattr =
581a8b0f 6808 tb[NL80211_MESH_SETUP_IE];
581a8b0f
JC
6809 setup->ie = nla_data(ieattr);
6810 setup->ie_len = nla_len(ieattr);
c80d545d 6811 }
bb2798d4
TP
6812 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
6813 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
6814 return -EINVAL;
6815 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
6816 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
6817 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
6818 if (setup->is_secure)
6819 setup->user_mpm = true;
c80d545d 6820
6e16d90b
CT
6821 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
6822 if (!setup->user_mpm)
6823 return -EINVAL;
6824 setup->auth_id =
6825 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
6826 }
6827
c80d545d
JC
6828 return 0;
6829}
6830
24bdd9f4 6831static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 6832 struct genl_info *info)
bd90fdcc
JB
6833{
6834 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6835 struct net_device *dev = info->user_ptr[1];
29cbe68c 6836 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
6837 struct mesh_config cfg;
6838 u32 mask;
6839 int err;
6840
29cbe68c
JB
6841 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
6842 return -EOPNOTSUPP;
6843
24bdd9f4 6844 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
6845 return -EOPNOTSUPP;
6846
24bdd9f4 6847 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
6848 if (err)
6849 return err;
6850
29cbe68c
JB
6851 wdev_lock(wdev);
6852 if (!wdev->mesh_id_len)
6853 err = -ENOLINK;
6854
6855 if (!err)
e35e4d28 6856 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
6857
6858 wdev_unlock(wdev);
6859
6860 return err;
93da9cc1 6861}
6862
ad30ca2c
AN
6863static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom,
6864 struct sk_buff *msg)
f130347c 6865{
f130347c
LR
6866 struct nlattr *nl_reg_rules;
6867 unsigned int i;
f130347c 6868
458f4f9e
JB
6869 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
6870 (regdom->dfs_region &&
6871 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
ad30ca2c 6872 goto nla_put_failure;
458f4f9e 6873
ae0be8de 6874 nl_reg_rules = nla_nest_start_noflag(msg, NL80211_ATTR_REG_RULES);
f130347c 6875 if (!nl_reg_rules)
ad30ca2c 6876 goto nla_put_failure;
f130347c 6877
458f4f9e 6878 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
6879 struct nlattr *nl_reg_rule;
6880 const struct ieee80211_reg_rule *reg_rule;
6881 const struct ieee80211_freq_range *freq_range;
6882 const struct ieee80211_power_rule *power_rule;
97524820 6883 unsigned int max_bandwidth_khz;
f130347c 6884
458f4f9e 6885 reg_rule = &regdom->reg_rules[i];
f130347c
LR
6886 freq_range = &reg_rule->freq_range;
6887 power_rule = &reg_rule->power_rule;
6888
ae0be8de 6889 nl_reg_rule = nla_nest_start_noflag(msg, i);
f130347c 6890 if (!nl_reg_rule)
ad30ca2c 6891 goto nla_put_failure;
f130347c 6892
97524820
JD
6893 max_bandwidth_khz = freq_range->max_bandwidth_khz;
6894 if (!max_bandwidth_khz)
6895 max_bandwidth_khz = reg_get_max_bandwidth(regdom,
6896 reg_rule);
6897
9360ffd1
DM
6898 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
6899 reg_rule->flags) ||
6900 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
6901 freq_range->start_freq_khz) ||
6902 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
6903 freq_range->end_freq_khz) ||
6904 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
97524820 6905 max_bandwidth_khz) ||
9360ffd1
DM
6906 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
6907 power_rule->max_antenna_gain) ||
6908 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
089027e5
JD
6909 power_rule->max_eirp) ||
6910 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME,
6911 reg_rule->dfs_cac_ms))
ad30ca2c 6912 goto nla_put_failure;
f130347c
LR
6913
6914 nla_nest_end(msg, nl_reg_rule);
6915 }
6916
6917 nla_nest_end(msg, nl_reg_rules);
ad30ca2c
AN
6918 return 0;
6919
6920nla_put_failure:
6921 return -EMSGSIZE;
6922}
6923
6924static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info)
6925{
6926 const struct ieee80211_regdomain *regdom = NULL;
6927 struct cfg80211_registered_device *rdev;
6928 struct wiphy *wiphy = NULL;
6929 struct sk_buff *msg;
6930 void *hdr;
6931
6932 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6933 if (!msg)
6934 return -ENOBUFS;
6935
6936 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
6937 NL80211_CMD_GET_REG);
6938 if (!hdr)
6939 goto put_failure;
6940
6941 if (info->attrs[NL80211_ATTR_WIPHY]) {
1bdd716c
AN
6942 bool self_managed;
6943
ad30ca2c
AN
6944 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
6945 if (IS_ERR(rdev)) {
6946 nlmsg_free(msg);
6947 return PTR_ERR(rdev);
6948 }
6949
6950 wiphy = &rdev->wiphy;
1bdd716c
AN
6951 self_managed = wiphy->regulatory_flags &
6952 REGULATORY_WIPHY_SELF_MANAGED;
ad30ca2c
AN
6953 regdom = get_wiphy_regdom(wiphy);
6954
1bdd716c
AN
6955 /* a self-managed-reg device must have a private regdom */
6956 if (WARN_ON(!regdom && self_managed)) {
6957 nlmsg_free(msg);
6958 return -EINVAL;
6959 }
6960
ad30ca2c
AN
6961 if (regdom &&
6962 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
6963 goto nla_put_failure;
6964 }
6965
6966 if (!wiphy && reg_last_request_cell_base() &&
6967 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
6968 NL80211_USER_REG_HINT_CELL_BASE))
6969 goto nla_put_failure;
6970
6971 rcu_read_lock();
6972
6973 if (!regdom)
6974 regdom = rcu_dereference(cfg80211_regdomain);
6975
6976 if (nl80211_put_regdom(regdom, msg))
6977 goto nla_put_failure_rcu;
6978
6979 rcu_read_unlock();
f130347c
LR
6980
6981 genlmsg_end(msg, hdr);
5fe231e8 6982 return genlmsg_reply(msg, info);
f130347c 6983
458f4f9e
JB
6984nla_put_failure_rcu:
6985 rcu_read_unlock();
f130347c 6986nla_put_failure:
efe1cf0c 6987put_failure:
d080e275 6988 nlmsg_free(msg);
5fe231e8 6989 return -EMSGSIZE;
f130347c
LR
6990}
6991
ad30ca2c
AN
6992static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb,
6993 u32 seq, int flags, struct wiphy *wiphy,
6994 const struct ieee80211_regdomain *regdom)
6995{
6996 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
6997 NL80211_CMD_GET_REG);
6998
6999 if (!hdr)
7000 return -1;
7001
0a833c29 7002 genl_dump_check_consistent(cb, hdr);
ad30ca2c
AN
7003
7004 if (nl80211_put_regdom(regdom, msg))
7005 goto nla_put_failure;
7006
7007 if (!wiphy && reg_last_request_cell_base() &&
7008 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
7009 NL80211_USER_REG_HINT_CELL_BASE))
7010 goto nla_put_failure;
7011
7012 if (wiphy &&
7013 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
7014 goto nla_put_failure;
7015
1bdd716c
AN
7016 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
7017 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
7018 goto nla_put_failure;
7019
053c095a
JB
7020 genlmsg_end(msg, hdr);
7021 return 0;
ad30ca2c
AN
7022
7023nla_put_failure:
7024 genlmsg_cancel(msg, hdr);
7025 return -EMSGSIZE;
7026}
7027
7028static int nl80211_get_reg_dump(struct sk_buff *skb,
7029 struct netlink_callback *cb)
7030{
7031 const struct ieee80211_regdomain *regdom = NULL;
7032 struct cfg80211_registered_device *rdev;
7033 int err, reg_idx, start = cb->args[2];
7034
7035 rtnl_lock();
7036
7037 if (cfg80211_regdomain && start == 0) {
7038 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
7039 NLM_F_MULTI, NULL,
7040 rtnl_dereference(cfg80211_regdomain));
7041 if (err < 0)
7042 goto out_err;
7043 }
7044
7045 /* the global regdom is idx 0 */
7046 reg_idx = 1;
7047 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
7048 regdom = get_wiphy_regdom(&rdev->wiphy);
7049 if (!regdom)
7050 continue;
7051
7052 if (++reg_idx <= start)
7053 continue;
7054
7055 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
7056 NLM_F_MULTI, &rdev->wiphy, regdom);
7057 if (err < 0) {
7058 reg_idx--;
7059 break;
7060 }
7061 }
7062
7063 cb->args[2] = reg_idx;
7064 err = skb->len;
7065out_err:
7066 rtnl_unlock();
7067 return err;
7068}
7069
b6863036
JB
7070#ifdef CONFIG_CFG80211_CRDA_SUPPORT
7071static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
7072 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
7073 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
7074 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
7075 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
7076 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
7077 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
7078 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 },
7079};
7080
7081static int parse_reg_rule(struct nlattr *tb[],
7082 struct ieee80211_reg_rule *reg_rule)
7083{
7084 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
7085 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
7086
7087 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
7088 return -EINVAL;
7089 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
7090 return -EINVAL;
7091 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
7092 return -EINVAL;
7093 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
7094 return -EINVAL;
7095 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
7096 return -EINVAL;
7097
7098 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
7099
7100 freq_range->start_freq_khz =
7101 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
7102 freq_range->end_freq_khz =
7103 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
7104 freq_range->max_bandwidth_khz =
7105 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
7106
7107 power_rule->max_eirp =
7108 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
7109
7110 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
7111 power_rule->max_antenna_gain =
7112 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
7113
7114 if (tb[NL80211_ATTR_DFS_CAC_TIME])
7115 reg_rule->dfs_cac_ms =
7116 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]);
7117
7118 return 0;
7119}
7120
b2e1b302
LR
7121static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
7122{
7123 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
7124 struct nlattr *nl_reg_rule;
ea372c54
JB
7125 char *alpha2;
7126 int rem_reg_rules, r;
391d132c 7127 u32 num_rules = 0, rule_idx = 0;
4c7d3982 7128 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
ea372c54 7129 struct ieee80211_regdomain *rd;
b2e1b302
LR
7130
7131 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
7132 return -EINVAL;
7133
7134 if (!info->attrs[NL80211_ATTR_REG_RULES])
7135 return -EINVAL;
7136
7137 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
7138
8b60b078
LR
7139 if (info->attrs[NL80211_ATTR_DFS_REGION])
7140 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
7141
b2e1b302 7142 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 7143 rem_reg_rules) {
b2e1b302
LR
7144 num_rules++;
7145 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 7146 return -EINVAL;
b2e1b302
LR
7147 }
7148
e438768f
LR
7149 if (!reg_is_valid_request(alpha2))
7150 return -EINVAL;
7151
391d132c 7152 rd = kzalloc(struct_size(rd, reg_rules, num_rules), GFP_KERNEL);
6913b49a
JB
7153 if (!rd)
7154 return -ENOMEM;
b2e1b302
LR
7155
7156 rd->n_reg_rules = num_rules;
7157 rd->alpha2[0] = alpha2[0];
7158 rd->alpha2[1] = alpha2[1];
7159
8b60b078
LR
7160 /*
7161 * Disable DFS master mode if the DFS region was
7162 * not supported or known on this kernel.
7163 */
7164 if (reg_supported_dfs_region(dfs_region))
7165 rd->dfs_region = dfs_region;
7166
b2e1b302 7167 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 7168 rem_reg_rules) {
8cb08174
JB
7169 r = nla_parse_nested_deprecated(tb, NL80211_REG_RULE_ATTR_MAX,
7170 nl_reg_rule, reg_rule_policy,
7171 info->extack);
ae811e21
JB
7172 if (r)
7173 goto bad_reg;
b2e1b302
LR
7174 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
7175 if (r)
7176 goto bad_reg;
7177
7178 rule_idx++;
7179
d0e18f83
LR
7180 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
7181 r = -EINVAL;
b2e1b302 7182 goto bad_reg;
d0e18f83 7183 }
b2e1b302
LR
7184 }
7185
06627990
JB
7186 /* set_regdom takes ownership of rd */
7187 return set_regdom(rd, REGD_SOURCE_CRDA);
d2372b31 7188 bad_reg:
b2e1b302 7189 kfree(rd);
d0e18f83 7190 return r;
b2e1b302 7191}
b6863036 7192#endif /* CONFIG_CFG80211_CRDA_SUPPORT */
b2e1b302 7193
83f5e2cf
JB
7194static int validate_scan_freqs(struct nlattr *freqs)
7195{
7196 struct nlattr *attr1, *attr2;
7197 int n_channels = 0, tmp1, tmp2;
7198
d7f13f74
SD
7199 nla_for_each_nested(attr1, freqs, tmp1)
7200 if (nla_len(attr1) != sizeof(u32))
7201 return 0;
7202
83f5e2cf
JB
7203 nla_for_each_nested(attr1, freqs, tmp1) {
7204 n_channels++;
7205 /*
7206 * Some hardware has a limited channel list for
7207 * scanning, and it is pretty much nonsensical
7208 * to scan for a channel twice, so disallow that
7209 * and don't require drivers to check that the
7210 * channel list they get isn't longer than what
7211 * they can scan, as long as they can scan all
7212 * the channels they registered at once.
7213 */
7214 nla_for_each_nested(attr2, freqs, tmp2)
7215 if (attr1 != attr2 &&
7216 nla_get_u32(attr1) == nla_get_u32(attr2))
7217 return 0;
7218 }
7219
7220 return n_channels;
7221}
7222
57fbcce3 7223static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b)
38de03d2 7224{
57fbcce3 7225 return b < NUM_NL80211_BANDS && wiphy->bands[b];
38de03d2
AS
7226}
7227
7228static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy,
7229 struct cfg80211_bss_selection *bss_select)
7230{
7231 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1];
7232 struct nlattr *nest;
7233 int err;
7234 bool found = false;
7235 int i;
7236
7237 /* only process one nested attribute */
7238 nest = nla_data(nla);
7239 if (!nla_ok(nest, nla_len(nest)))
7240 return -EINVAL;
7241
8cb08174
JB
7242 err = nla_parse_nested_deprecated(attr, NL80211_BSS_SELECT_ATTR_MAX,
7243 nest, nl80211_bss_select_policy,
7244 NULL);
38de03d2
AS
7245 if (err)
7246 return err;
7247
7248 /* only one attribute may be given */
7249 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) {
7250 if (attr[i]) {
7251 if (found)
7252 return -EINVAL;
7253 found = true;
7254 }
7255 }
7256
7257 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID;
7258
7259 if (attr[NL80211_BSS_SELECT_ATTR_RSSI])
7260 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI;
7261
7262 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) {
7263 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF;
7264 bss_select->param.band_pref =
7265 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]);
7266 if (!is_band_valid(wiphy, bss_select->param.band_pref))
7267 return -EINVAL;
7268 }
7269
7270 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) {
7271 struct nl80211_bss_select_rssi_adjust *adj_param;
7272
7273 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]);
7274 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST;
7275 bss_select->param.adjust.band = adj_param->band;
7276 bss_select->param.adjust.delta = adj_param->delta;
7277 if (!is_band_valid(wiphy, bss_select->param.adjust.band))
7278 return -EINVAL;
7279 }
7280
7281 /* user-space did not provide behaviour attribute */
7282 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID)
7283 return -EINVAL;
7284
7285 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour)))
7286 return -EINVAL;
7287
7288 return 0;
7289}
7290
9bb7e0f2
JB
7291int nl80211_parse_random_mac(struct nlattr **attrs,
7292 u8 *mac_addr, u8 *mac_addr_mask)
ad2b26ab
JB
7293{
7294 int i;
7295
7296 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) {
d2beae10
JP
7297 eth_zero_addr(mac_addr);
7298 eth_zero_addr(mac_addr_mask);
ad2b26ab
JB
7299 mac_addr[0] = 0x2;
7300 mac_addr_mask[0] = 0x3;
7301
7302 return 0;
7303 }
7304
7305 /* need both or none */
7306 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK])
7307 return -EINVAL;
7308
7309 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN);
7310 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN);
7311
7312 /* don't allow or configure an mcast address */
7313 if (!is_multicast_ether_addr(mac_addr_mask) ||
7314 is_multicast_ether_addr(mac_addr))
7315 return -EINVAL;
7316
7317 /*
7318 * allow users to pass a MAC address that has bits set outside
7319 * of the mask, but don't bother drivers with having to deal
7320 * with such bits
7321 */
7322 for (i = 0; i < ETH_ALEN; i++)
7323 mac_addr[i] &= mac_addr_mask[i];
7324
7325 return 0;
7326}
7327
34373d12
VT
7328static bool cfg80211_off_channel_oper_allowed(struct wireless_dev *wdev)
7329{
7330 ASSERT_WDEV_LOCK(wdev);
7331
7332 if (!cfg80211_beaconing_iface_active(wdev))
7333 return true;
7334
7335 if (!(wdev->chandef.chan->flags & IEEE80211_CHAN_RADAR))
7336 return true;
7337
7338 return regulatory_pre_cac_allowed(wdev->wiphy);
7339}
7340
db0a4ad8
JB
7341static bool nl80211_check_scan_feat(struct wiphy *wiphy, u32 flags, u32 flag,
7342 enum nl80211_ext_feature_index feat)
7343{
7344 if (!(flags & flag))
7345 return true;
7346 if (wiphy_ext_feature_isset(wiphy, feat))
7347 return true;
7348 return false;
7349}
7350
2d23d073
RZ
7351static int
7352nl80211_check_scan_flags(struct wiphy *wiphy, struct wireless_dev *wdev,
7353 void *request, struct nlattr **attrs,
7354 bool is_sched_scan)
7355{
7356 u8 *mac_addr, *mac_addr_mask;
7357 u32 *flags;
7358 enum nl80211_feature_flags randomness_flag;
7359
7360 if (!attrs[NL80211_ATTR_SCAN_FLAGS])
7361 return 0;
7362
7363 if (is_sched_scan) {
7364 struct cfg80211_sched_scan_request *req = request;
7365
7366 randomness_flag = wdev ?
7367 NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR :
7368 NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
7369 flags = &req->flags;
7370 mac_addr = req->mac_addr;
7371 mac_addr_mask = req->mac_addr_mask;
7372 } else {
7373 struct cfg80211_scan_request *req = request;
7374
7375 randomness_flag = NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR;
7376 flags = &req->flags;
7377 mac_addr = req->mac_addr;
7378 mac_addr_mask = req->mac_addr_mask;
7379 }
7380
7381 *flags = nla_get_u32(attrs[NL80211_ATTR_SCAN_FLAGS]);
7382
5037a009
SD
7383 if (((*flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
7384 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
db0a4ad8
JB
7385 !nl80211_check_scan_feat(wiphy, *flags,
7386 NL80211_SCAN_FLAG_LOW_SPAN,
7387 NL80211_EXT_FEATURE_LOW_SPAN_SCAN) ||
7388 !nl80211_check_scan_feat(wiphy, *flags,
7389 NL80211_SCAN_FLAG_LOW_POWER,
7390 NL80211_EXT_FEATURE_LOW_POWER_SCAN) ||
7391 !nl80211_check_scan_feat(wiphy, *flags,
7392 NL80211_SCAN_FLAG_HIGH_ACCURACY,
7393 NL80211_EXT_FEATURE_HIGH_ACCURACY_SCAN) ||
7394 !nl80211_check_scan_feat(wiphy, *flags,
7395 NL80211_SCAN_FLAG_FILS_MAX_CHANNEL_TIME,
7396 NL80211_EXT_FEATURE_FILS_MAX_CHANNEL_TIME) ||
7397 !nl80211_check_scan_feat(wiphy, *flags,
7398 NL80211_SCAN_FLAG_ACCEPT_BCAST_PROBE_RESP,
7399 NL80211_EXT_FEATURE_ACCEPT_BCAST_PROBE_RESP) ||
7400 !nl80211_check_scan_feat(wiphy, *flags,
7401 NL80211_SCAN_FLAG_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION,
7402 NL80211_EXT_FEATURE_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION) ||
7403 !nl80211_check_scan_feat(wiphy, *flags,
7404 NL80211_SCAN_FLAG_OCE_PROBE_REQ_HIGH_TX_RATE,
2e076f19
JB
7405 NL80211_EXT_FEATURE_OCE_PROBE_REQ_HIGH_TX_RATE) ||
7406 !nl80211_check_scan_feat(wiphy, *flags,
7407 NL80211_SCAN_FLAG_RANDOM_SN,
7408 NL80211_EXT_FEATURE_SCAN_RANDOM_SN) ||
7409 !nl80211_check_scan_feat(wiphy, *flags,
7410 NL80211_SCAN_FLAG_MIN_PREQ_CONTENT,
7411 NL80211_EXT_FEATURE_SCAN_MIN_PREQ_CONTENT))
2d23d073
RZ
7412 return -EOPNOTSUPP;
7413
7414 if (*flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
7415 int err;
7416
7417 if (!(wiphy->features & randomness_flag) ||
7418 (wdev && wdev->current_bss))
7419 return -EOPNOTSUPP;
7420
7421 err = nl80211_parse_random_mac(attrs, mac_addr, mac_addr_mask);
7422 if (err)
7423 return err;
7424 }
7425
2d23d073
RZ
7426 return 0;
7427}
7428
2a519311
JB
7429static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
7430{
4c476991 7431 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 7432 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 7433 struct cfg80211_scan_request *request;
2a519311
JB
7434 struct nlattr *attr;
7435 struct wiphy *wiphy;
83f5e2cf 7436 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 7437 size_t ie_len;
2a519311 7438
79c97e97 7439 wiphy = &rdev->wiphy;
2a519311 7440
cb3b7d87
AB
7441 if (wdev->iftype == NL80211_IFTYPE_NAN)
7442 return -EOPNOTSUPP;
7443
4c476991
JB
7444 if (!rdev->ops->scan)
7445 return -EOPNOTSUPP;
2a519311 7446
f9d15d16 7447 if (rdev->scan_req || rdev->scan_msg) {
f9f47529
JB
7448 err = -EBUSY;
7449 goto unlock;
7450 }
2a519311
JB
7451
7452 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
7453 n_channels = validate_scan_freqs(
7454 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
f9f47529
JB
7455 if (!n_channels) {
7456 err = -EINVAL;
7457 goto unlock;
7458 }
2a519311 7459 } else {
bdfbec2d 7460 n_channels = ieee80211_get_num_supported_channels(wiphy);
2a519311
JB
7461 }
7462
7463 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
7464 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
7465 n_ssids++;
7466
f9f47529
JB
7467 if (n_ssids > wiphy->max_scan_ssids) {
7468 err = -EINVAL;
7469 goto unlock;
7470 }
2a519311 7471
70692ad2
JM
7472 if (info->attrs[NL80211_ATTR_IE])
7473 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
7474 else
7475 ie_len = 0;
7476
f9f47529
JB
7477 if (ie_len > wiphy->max_scan_ie_len) {
7478 err = -EINVAL;
7479 goto unlock;
7480 }
18a83659 7481
2a519311 7482 request = kzalloc(sizeof(*request)
a2cd43c5
LC
7483 + sizeof(*request->ssids) * n_ssids
7484 + sizeof(*request->channels) * n_channels
70692ad2 7485 + ie_len, GFP_KERNEL);
f9f47529
JB
7486 if (!request) {
7487 err = -ENOMEM;
7488 goto unlock;
7489 }
2a519311 7490
2a519311 7491 if (n_ssids)
5ba63533 7492 request->ssids = (void *)&request->channels[n_channels];
2a519311 7493 request->n_ssids = n_ssids;
70692ad2 7494 if (ie_len) {
13874e4b 7495 if (n_ssids)
70692ad2
JM
7496 request->ie = (void *)(request->ssids + n_ssids);
7497 else
7498 request->ie = (void *)(request->channels + n_channels);
7499 }
2a519311 7500
584991dc 7501 i = 0;
2a519311
JB
7502 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
7503 /* user specified, bail out if channel not found */
2a519311 7504 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
7505 struct ieee80211_channel *chan;
7506
7507 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
7508
7509 if (!chan) {
2a519311
JB
7510 err = -EINVAL;
7511 goto out_free;
7512 }
584991dc
JB
7513
7514 /* ignore disabled channels */
7515 if (chan->flags & IEEE80211_CHAN_DISABLED)
7516 continue;
7517
7518 request->channels[i] = chan;
2a519311
JB
7519 i++;
7520 }
7521 } else {
57fbcce3 7522 enum nl80211_band band;
34850ab2 7523
2a519311 7524 /* all channels */
57fbcce3 7525 for (band = 0; band < NUM_NL80211_BANDS; band++) {
2a519311 7526 int j;
7a087e74 7527
2a519311
JB
7528 if (!wiphy->bands[band])
7529 continue;
7530 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
7531 struct ieee80211_channel *chan;
7532
7533 chan = &wiphy->bands[band]->channels[j];
7534
7535 if (chan->flags & IEEE80211_CHAN_DISABLED)
7536 continue;
7537
7538 request->channels[i] = chan;
2a519311
JB
7539 i++;
7540 }
7541 }
7542 }
7543
584991dc
JB
7544 if (!i) {
7545 err = -EINVAL;
7546 goto out_free;
7547 }
7548
7549 request->n_channels = i;
7550
34373d12
VT
7551 wdev_lock(wdev);
7552 if (!cfg80211_off_channel_oper_allowed(wdev)) {
7553 struct ieee80211_channel *chan;
7554
7555 if (request->n_channels != 1) {
7556 wdev_unlock(wdev);
7557 err = -EBUSY;
7558 goto out_free;
7559 }
7560
7561 chan = request->channels[0];
7562 if (chan->center_freq != wdev->chandef.chan->center_freq) {
7563 wdev_unlock(wdev);
7564 err = -EBUSY;
7565 goto out_free;
7566 }
7567 }
7568 wdev_unlock(wdev);
7569
2a519311 7570 i = 0;
13874e4b 7571 if (n_ssids) {
2a519311 7572 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 7573 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
7574 err = -EINVAL;
7575 goto out_free;
7576 }
57a27e1d 7577 request->ssids[i].ssid_len = nla_len(attr);
2a519311 7578 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
7579 i++;
7580 }
7581 }
7582
70692ad2
JM
7583 if (info->attrs[NL80211_ATTR_IE]) {
7584 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
7585 memcpy((void *)request->ie,
7586 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
7587 request->ie_len);
7588 }
7589
57fbcce3 7590 for (i = 0; i < NUM_NL80211_BANDS; i++)
a401d2bb
JB
7591 if (wiphy->bands[i])
7592 request->rates[i] =
7593 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
7594
7595 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
7596 nla_for_each_nested(attr,
7597 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
7598 tmp) {
57fbcce3 7599 enum nl80211_band band = nla_type(attr);
34850ab2 7600
57fbcce3 7601 if (band < 0 || band >= NUM_NL80211_BANDS) {
34850ab2
JB
7602 err = -EINVAL;
7603 goto out_free;
7604 }
1b09cd82
FF
7605
7606 if (!wiphy->bands[band])
7607 continue;
7608
34850ab2
JB
7609 err = ieee80211_get_ratemask(wiphy->bands[band],
7610 nla_data(attr),
7611 nla_len(attr),
7612 &request->rates[band]);
7613 if (err)
7614 goto out_free;
7615 }
7616 }
7617
1d76250b
AS
7618 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) {
7619 if (!wiphy_ext_feature_isset(wiphy,
7620 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) {
7621 err = -EOPNOTSUPP;
7622 goto out_free;
7623 }
7624
7625 request->duration =
7626 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]);
7627 request->duration_mandatory =
7628 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]);
7629 }
7630
2d23d073
RZ
7631 err = nl80211_check_scan_flags(wiphy, wdev, request, info->attrs,
7632 false);
7633 if (err)
7634 goto out_free;
ed473771 7635
e9f935e3
RM
7636 request->no_cck =
7637 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
7638
2fa436b3
VK
7639 /* Initial implementation used NL80211_ATTR_MAC to set the specific
7640 * BSSID to scan for. This was problematic because that same attribute
7641 * was already used for another purpose (local random MAC address). The
7642 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards
7643 * compatibility with older userspace components, also use the
7644 * NL80211_ATTR_MAC value here if it can be determined to be used for
7645 * the specific BSSID use case instead of the random MAC address
7646 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use).
7647 */
7648 if (info->attrs[NL80211_ATTR_BSSID])
7649 memcpy(request->bssid,
7650 nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN);
7651 else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) &&
7652 info->attrs[NL80211_ATTR_MAC])
818965d3
JM
7653 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]),
7654 ETH_ALEN);
7655 else
7656 eth_broadcast_addr(request->bssid);
7657
fd014284 7658 request->wdev = wdev;
79c97e97 7659 request->wiphy = &rdev->wiphy;
15d6030b 7660 request->scan_start = jiffies;
2a519311 7661
79c97e97 7662 rdev->scan_req = request;
e35e4d28 7663 err = rdev_scan(rdev, request);
2a519311 7664
463d0183 7665 if (!err) {
fd014284
JB
7666 nl80211_send_scan_start(rdev, wdev);
7667 if (wdev->netdev)
7668 dev_hold(wdev->netdev);
4c476991 7669 } else {
2a519311 7670 out_free:
79c97e97 7671 rdev->scan_req = NULL;
2a519311
JB
7672 kfree(request);
7673 }
3b85875a 7674
f9f47529 7675 unlock:
2a519311
JB
7676 return err;
7677}
7678
91d3ab46
VK
7679static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info)
7680{
7681 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7682 struct wireless_dev *wdev = info->user_ptr[1];
7683
7684 if (!rdev->ops->abort_scan)
7685 return -EOPNOTSUPP;
7686
7687 if (rdev->scan_msg)
7688 return 0;
7689
7690 if (!rdev->scan_req)
7691 return -ENOENT;
7692
7693 rdev_abort_scan(rdev, wdev);
7694 return 0;
7695}
7696
3b06d277
AS
7697static int
7698nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans,
7699 struct cfg80211_sched_scan_request *request,
7700 struct nlattr **attrs)
7701{
7702 int tmp, err, i = 0;
7703 struct nlattr *attr;
7704
7705 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
7706 u32 interval;
7707
7708 /*
7709 * If scan plans are not specified,
5a88de53 7710 * %NL80211_ATTR_SCHED_SCAN_INTERVAL will be specified. In this
3b06d277
AS
7711 * case one scan plan will be set with the specified scan
7712 * interval and infinite number of iterations.
7713 */
3b06d277
AS
7714 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
7715 if (!interval)
7716 return -EINVAL;
7717
7718 request->scan_plans[0].interval =
7719 DIV_ROUND_UP(interval, MSEC_PER_SEC);
7720 if (!request->scan_plans[0].interval)
7721 return -EINVAL;
7722
7723 if (request->scan_plans[0].interval >
7724 wiphy->max_sched_scan_plan_interval)
7725 request->scan_plans[0].interval =
7726 wiphy->max_sched_scan_plan_interval;
7727
7728 return 0;
7729 }
7730
7731 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) {
7732 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1];
7733
7734 if (WARN_ON(i >= n_plans))
7735 return -EINVAL;
7736
8cb08174
JB
7737 err = nla_parse_nested_deprecated(plan,
7738 NL80211_SCHED_SCAN_PLAN_MAX,
7739 attr, nl80211_plan_policy,
7740 NULL);
3b06d277
AS
7741 if (err)
7742 return err;
7743
7744 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL])
7745 return -EINVAL;
7746
7747 request->scan_plans[i].interval =
7748 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]);
7749 if (!request->scan_plans[i].interval ||
7750 request->scan_plans[i].interval >
7751 wiphy->max_sched_scan_plan_interval)
7752 return -EINVAL;
7753
7754 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) {
7755 request->scan_plans[i].iterations =
7756 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]);
7757 if (!request->scan_plans[i].iterations ||
7758 (request->scan_plans[i].iterations >
7759 wiphy->max_sched_scan_plan_iterations))
7760 return -EINVAL;
7761 } else if (i < n_plans - 1) {
7762 /*
7763 * All scan plans but the last one must specify
7764 * a finite number of iterations
7765 */
7766 return -EINVAL;
7767 }
7768
7769 i++;
7770 }
7771
7772 /*
7773 * The last scan plan must not specify the number of
7774 * iterations, it is supposed to run infinitely
7775 */
7776 if (request->scan_plans[n_plans - 1].iterations)
7777 return -EINVAL;
7778
7779 return 0;
7780}
7781
1e1b11b6 7782static int
7783nl80211_parse_sched_scan_per_band_rssi(struct wiphy *wiphy,
7784 struct cfg80211_match_set *match_sets,
7785 struct nlattr *tb_band_rssi,
7786 s32 rssi_thold)
7787{
7788 struct nlattr *attr;
7789 int i, tmp, ret = 0;
7790
7791 if (!wiphy_ext_feature_isset(wiphy,
7792 NL80211_EXT_FEATURE_SCHED_SCAN_BAND_SPECIFIC_RSSI_THOLD)) {
7793 if (tb_band_rssi)
7794 ret = -EOPNOTSUPP;
7795 else
7796 for (i = 0; i < NUM_NL80211_BANDS; i++)
7797 match_sets->per_band_rssi_thold[i] =
7798 NL80211_SCAN_RSSI_THOLD_OFF;
7799 return ret;
7800 }
7801
7802 for (i = 0; i < NUM_NL80211_BANDS; i++)
7803 match_sets->per_band_rssi_thold[i] = rssi_thold;
7804
7805 nla_for_each_nested(attr, tb_band_rssi, tmp) {
7806 enum nl80211_band band = nla_type(attr);
7807
7808 if (band < 0 || band >= NUM_NL80211_BANDS)
7809 return -EINVAL;
7810
7811 match_sets->per_band_rssi_thold[band] = nla_get_s32(attr);
7812 }
7813
7814 return 0;
7815}
7816
256da02d 7817static struct cfg80211_sched_scan_request *
ad2b26ab 7818nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev,
aad1e812 7819 struct nlattr **attrs, int max_match_sets)
807f8a8c
LC
7820{
7821 struct cfg80211_sched_scan_request *request;
807f8a8c 7822 struct nlattr *attr;
3b06d277 7823 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0;
57fbcce3 7824 enum nl80211_band band;
807f8a8c 7825 size_t ie_len;
a1f1c21c 7826 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
ea73cbce 7827 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF;
807f8a8c 7828
256da02d 7829 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c 7830 n_channels = validate_scan_freqs(
256da02d 7831 attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
807f8a8c 7832 if (!n_channels)
256da02d 7833 return ERR_PTR(-EINVAL);
807f8a8c 7834 } else {
bdfbec2d 7835 n_channels = ieee80211_get_num_supported_channels(wiphy);
807f8a8c
LC
7836 }
7837
256da02d
LC
7838 if (attrs[NL80211_ATTR_SCAN_SSIDS])
7839 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c
LC
7840 tmp)
7841 n_ssids++;
7842
93b6aa69 7843 if (n_ssids > wiphy->max_sched_scan_ssids)
256da02d 7844 return ERR_PTR(-EINVAL);
807f8a8c 7845
ea73cbce
JB
7846 /*
7847 * First, count the number of 'real' matchsets. Due to an issue with
7848 * the old implementation, matchsets containing only the RSSI attribute
7849 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default'
7850 * RSSI for all matchsets, rather than their own matchset for reporting
7851 * all APs with a strong RSSI. This is needed to be compatible with
7852 * older userspace that treated a matchset with only the RSSI as the
7853 * global RSSI for all other matchsets - if there are other matchsets.
7854 */
256da02d 7855 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 7856 nla_for_each_nested(attr,
256da02d 7857 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
ea73cbce
JB
7858 tmp) {
7859 struct nlattr *rssi;
7860
8cb08174
JB
7861 err = nla_parse_nested_deprecated(tb,
7862 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
7863 attr,
7864 nl80211_match_policy,
7865 NULL);
ea73cbce 7866 if (err)
256da02d 7867 return ERR_PTR(err);
3007e352
AVS
7868
7869 /* SSID and BSSID are mutually exclusive */
7870 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] &&
7871 tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID])
7872 return ERR_PTR(-EINVAL);
7873
ea73cbce 7874 /* add other standalone attributes here */
3007e352
AVS
7875 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] ||
7876 tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID]) {
ea73cbce
JB
7877 n_match_sets++;
7878 continue;
7879 }
7880 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
7881 if (rssi)
7882 default_match_rssi = nla_get_s32(rssi);
7883 }
7884 }
7885
7886 /* However, if there's no other matchset, add the RSSI one */
7887 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF)
7888 n_match_sets = 1;
a1f1c21c 7889
aad1e812 7890 if (n_match_sets > max_match_sets)
256da02d 7891 return ERR_PTR(-EINVAL);
a1f1c21c 7892
256da02d
LC
7893 if (attrs[NL80211_ATTR_IE])
7894 ie_len = nla_len(attrs[NL80211_ATTR_IE]);
807f8a8c
LC
7895 else
7896 ie_len = 0;
7897
5a865bad 7898 if (ie_len > wiphy->max_sched_scan_ie_len)
256da02d 7899 return ERR_PTR(-EINVAL);
c10841ca 7900
3b06d277
AS
7901 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
7902 /*
7903 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since
7904 * each scan plan already specifies its own interval
7905 */
7906 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
7907 return ERR_PTR(-EINVAL);
7908
7909 nla_for_each_nested(attr,
7910 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp)
7911 n_plans++;
7912 } else {
7913 /*
7914 * The scan interval attribute is kept for backward
7915 * compatibility. If no scan plans are specified and sched scan
7916 * interval is specified, one scan plan will be set with this
7917 * scan interval and infinite number of iterations.
7918 */
7919 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
7920 return ERR_PTR(-EINVAL);
7921
7922 n_plans = 1;
7923 }
7924
7925 if (!n_plans || n_plans > wiphy->max_sched_scan_plans)
7926 return ERR_PTR(-EINVAL);
7927
bf95ecdb 7928 if (!wiphy_ext_feature_isset(
7929 wiphy, NL80211_EXT_FEATURE_SCHED_SCAN_RELATIVE_RSSI) &&
7930 (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] ||
7931 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]))
7932 return ERR_PTR(-EINVAL);
7933
807f8a8c 7934 request = kzalloc(sizeof(*request)
a2cd43c5 7935 + sizeof(*request->ssids) * n_ssids
a1f1c21c 7936 + sizeof(*request->match_sets) * n_match_sets
3b06d277 7937 + sizeof(*request->scan_plans) * n_plans
a2cd43c5 7938 + sizeof(*request->channels) * n_channels
807f8a8c 7939 + ie_len, GFP_KERNEL);
256da02d
LC
7940 if (!request)
7941 return ERR_PTR(-ENOMEM);
807f8a8c
LC
7942
7943 if (n_ssids)
7944 request->ssids = (void *)&request->channels[n_channels];
7945 request->n_ssids = n_ssids;
7946 if (ie_len) {
13874e4b 7947 if (n_ssids)
807f8a8c
LC
7948 request->ie = (void *)(request->ssids + n_ssids);
7949 else
7950 request->ie = (void *)(request->channels + n_channels);
7951 }
7952
a1f1c21c
LC
7953 if (n_match_sets) {
7954 if (request->ie)
7955 request->match_sets = (void *)(request->ie + ie_len);
13874e4b 7956 else if (n_ssids)
a1f1c21c
LC
7957 request->match_sets =
7958 (void *)(request->ssids + n_ssids);
7959 else
7960 request->match_sets =
7961 (void *)(request->channels + n_channels);
7962 }
7963 request->n_match_sets = n_match_sets;
7964
3b06d277
AS
7965 if (n_match_sets)
7966 request->scan_plans = (void *)(request->match_sets +
7967 n_match_sets);
7968 else if (request->ie)
7969 request->scan_plans = (void *)(request->ie + ie_len);
7970 else if (n_ssids)
7971 request->scan_plans = (void *)(request->ssids + n_ssids);
7972 else
7973 request->scan_plans = (void *)(request->channels + n_channels);
7974
7975 request->n_scan_plans = n_plans;
7976
807f8a8c 7977 i = 0;
256da02d 7978 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c
LC
7979 /* user specified, bail out if channel not found */
7980 nla_for_each_nested(attr,
256da02d 7981 attrs[NL80211_ATTR_SCAN_FREQUENCIES],
807f8a8c
LC
7982 tmp) {
7983 struct ieee80211_channel *chan;
7984
7985 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
7986
7987 if (!chan) {
7988 err = -EINVAL;
7989 goto out_free;
7990 }
7991
7992 /* ignore disabled channels */
7993 if (chan->flags & IEEE80211_CHAN_DISABLED)
7994 continue;
7995
7996 request->channels[i] = chan;
7997 i++;
7998 }
7999 } else {
8000 /* all channels */
57fbcce3 8001 for (band = 0; band < NUM_NL80211_BANDS; band++) {
807f8a8c 8002 int j;
7a087e74 8003
807f8a8c
LC
8004 if (!wiphy->bands[band])
8005 continue;
8006 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
8007 struct ieee80211_channel *chan;
8008
8009 chan = &wiphy->bands[band]->channels[j];
8010
8011 if (chan->flags & IEEE80211_CHAN_DISABLED)
8012 continue;
8013
8014 request->channels[i] = chan;
8015 i++;
8016 }
8017 }
8018 }
8019
8020 if (!i) {
8021 err = -EINVAL;
8022 goto out_free;
8023 }
8024
8025 request->n_channels = i;
8026
8027 i = 0;
13874e4b 8028 if (n_ssids) {
256da02d 8029 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c 8030 tmp) {
57a27e1d 8031 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
8032 err = -EINVAL;
8033 goto out_free;
8034 }
57a27e1d 8035 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
8036 memcpy(request->ssids[i].ssid, nla_data(attr),
8037 nla_len(attr));
807f8a8c
LC
8038 i++;
8039 }
8040 }
8041
a1f1c21c 8042 i = 0;
256da02d 8043 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 8044 nla_for_each_nested(attr,
256da02d 8045 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
a1f1c21c 8046 tmp) {
3007e352 8047 struct nlattr *ssid, *bssid, *rssi;
a1f1c21c 8048
8cb08174
JB
8049 err = nla_parse_nested_deprecated(tb,
8050 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
8051 attr,
8052 nl80211_match_policy,
8053 NULL);
ae811e21
JB
8054 if (err)
8055 goto out_free;
4a4ab0d7 8056 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
3007e352 8057 bssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID];
d39f3b4f
JB
8058
8059 if (!ssid && !bssid) {
8060 i++;
8061 continue;
8062 }
8063
8064 if (WARN_ON(i >= n_match_sets)) {
8065 /* this indicates a programming error,
8066 * the loop above should have verified
8067 * things properly
8068 */
8069 err = -EINVAL;
8070 goto out_free;
8071 }
8072
8073 if (ssid) {
8074 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
ea73cbce
JB
8075 err = -EINVAL;
8076 goto out_free;
8077 }
d39f3b4f
JB
8078 memcpy(request->match_sets[i].ssid.ssid,
8079 nla_data(ssid), nla_len(ssid));
8080 request->match_sets[i].ssid.ssid_len =
8081 nla_len(ssid);
8082 }
8083 if (bssid) {
8084 if (nla_len(bssid) != ETH_ALEN) {
8085 err = -EINVAL;
8086 goto out_free;
a1f1c21c 8087 }
d39f3b4f
JB
8088 memcpy(request->match_sets[i].bssid,
8089 nla_data(bssid), ETH_ALEN);
8090 }
3007e352 8091
d39f3b4f
JB
8092 /* special attribute - old implementation w/a */
8093 request->match_sets[i].rssi_thold = default_match_rssi;
8094 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
8095 if (rssi)
ea73cbce 8096 request->match_sets[i].rssi_thold =
d39f3b4f 8097 nla_get_s32(rssi);
1e1b11b6 8098
8099 /* Parse per band RSSI attribute */
8100 err = nl80211_parse_sched_scan_per_band_rssi(wiphy,
8101 &request->match_sets[i],
8102 tb[NL80211_SCHED_SCAN_MATCH_PER_BAND_RSSI],
8103 request->match_sets[i].rssi_thold);
8104 if (err)
8105 goto out_free;
8106
a1f1c21c
LC
8107 i++;
8108 }
ea73cbce
JB
8109
8110 /* there was no other matchset, so the RSSI one is alone */
f89f46cf 8111 if (i == 0 && n_match_sets)
ea73cbce
JB
8112 request->match_sets[0].rssi_thold = default_match_rssi;
8113
8114 request->min_rssi_thold = INT_MAX;
8115 for (i = 0; i < n_match_sets; i++)
8116 request->min_rssi_thold =
8117 min(request->match_sets[i].rssi_thold,
8118 request->min_rssi_thold);
8119 } else {
8120 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
8121 }
8122
9900e484
JB
8123 if (ie_len) {
8124 request->ie_len = ie_len;
807f8a8c 8125 memcpy((void *)request->ie,
256da02d 8126 nla_data(attrs[NL80211_ATTR_IE]),
807f8a8c
LC
8127 request->ie_len);
8128 }
8129
2d23d073
RZ
8130 err = nl80211_check_scan_flags(wiphy, wdev, request, attrs, true);
8131 if (err)
8132 goto out_free;
ed473771 8133
9c748934
LC
8134 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY])
8135 request->delay =
8136 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]);
8137
bf95ecdb 8138 if (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]) {
8139 request->relative_rssi = nla_get_s8(
8140 attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]);
8141 request->relative_rssi_set = true;
8142 }
8143
8144 if (request->relative_rssi_set &&
8145 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]) {
8146 struct nl80211_bss_select_rssi_adjust *rssi_adjust;
8147
8148 rssi_adjust = nla_data(
8149 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]);
8150 request->rssi_adjust.band = rssi_adjust->band;
8151 request->rssi_adjust.delta = rssi_adjust->delta;
8152 if (!is_band_valid(wiphy, request->rssi_adjust.band)) {
8153 err = -EINVAL;
8154 goto out_free;
8155 }
8156 }
8157
3b06d277
AS
8158 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs);
8159 if (err)
8160 goto out_free;
8161
15d6030b 8162 request->scan_start = jiffies;
807f8a8c 8163
256da02d 8164 return request;
807f8a8c
LC
8165
8166out_free:
8167 kfree(request);
256da02d
LC
8168 return ERR_PTR(err);
8169}
8170
8171static int nl80211_start_sched_scan(struct sk_buff *skb,
8172 struct genl_info *info)
8173{
8174 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8175 struct net_device *dev = info->user_ptr[1];
ad2b26ab 8176 struct wireless_dev *wdev = dev->ieee80211_ptr;
31a60ed1 8177 struct cfg80211_sched_scan_request *sched_scan_req;
ca986ad9 8178 bool want_multi;
256da02d
LC
8179 int err;
8180
ca986ad9 8181 if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_start)
256da02d
LC
8182 return -EOPNOTSUPP;
8183
ca986ad9
AVS
8184 want_multi = info->attrs[NL80211_ATTR_SCHED_SCAN_MULTI];
8185 err = cfg80211_sched_scan_req_possible(rdev, want_multi);
8186 if (err)
8187 return err;
256da02d 8188
31a60ed1 8189 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev,
aad1e812
AVS
8190 info->attrs,
8191 rdev->wiphy.max_match_sets);
31a60ed1
JR
8192
8193 err = PTR_ERR_OR_ZERO(sched_scan_req);
256da02d
LC
8194 if (err)
8195 goto out_err;
8196
ca986ad9
AVS
8197 /* leave request id zero for legacy request
8198 * or if driver does not support multi-scheduled scan
8199 */
8200 if (want_multi && rdev->wiphy.max_sched_scan_reqs > 1) {
8201 while (!sched_scan_req->reqid)
b60ad348 8202 sched_scan_req->reqid = cfg80211_assign_cookie(rdev);
ca986ad9
AVS
8203 }
8204
31a60ed1 8205 err = rdev_sched_scan_start(rdev, dev, sched_scan_req);
256da02d
LC
8206 if (err)
8207 goto out_free;
8208
31a60ed1
JR
8209 sched_scan_req->dev = dev;
8210 sched_scan_req->wiphy = &rdev->wiphy;
8211
93a1e86c
JR
8212 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
8213 sched_scan_req->owner_nlportid = info->snd_portid;
8214
ca986ad9 8215 cfg80211_add_sched_scan_req(rdev, sched_scan_req);
256da02d 8216
96b08fd6 8217 nl80211_send_sched_scan(sched_scan_req, NL80211_CMD_START_SCHED_SCAN);
256da02d
LC
8218 return 0;
8219
8220out_free:
31a60ed1 8221 kfree(sched_scan_req);
256da02d 8222out_err:
807f8a8c
LC
8223 return err;
8224}
8225
8226static int nl80211_stop_sched_scan(struct sk_buff *skb,
8227 struct genl_info *info)
8228{
ca986ad9 8229 struct cfg80211_sched_scan_request *req;
807f8a8c 8230 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ca986ad9 8231 u64 cookie;
807f8a8c 8232
ca986ad9 8233 if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_stop)
807f8a8c
LC
8234 return -EOPNOTSUPP;
8235
ca986ad9
AVS
8236 if (info->attrs[NL80211_ATTR_COOKIE]) {
8237 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
8238 return __cfg80211_stop_sched_scan(rdev, cookie, false);
8239 }
8240
8241 req = list_first_or_null_rcu(&rdev->sched_scan_req_list,
8242 struct cfg80211_sched_scan_request,
8243 list);
8244 if (!req || req->reqid ||
8245 (req->owner_nlportid &&
8246 req->owner_nlportid != info->snd_portid))
8247 return -ENOENT;
8248
8249 return cfg80211_stop_sched_scan_req(rdev, req, false);
807f8a8c
LC
8250}
8251
04f39047
SW
8252static int nl80211_start_radar_detection(struct sk_buff *skb,
8253 struct genl_info *info)
8254{
8255 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8256 struct net_device *dev = info->user_ptr[1];
8257 struct wireless_dev *wdev = dev->ieee80211_ptr;
13cf6dec 8258 struct wiphy *wiphy = wdev->wiphy;
04f39047 8259 struct cfg80211_chan_def chandef;
55f7435c 8260 enum nl80211_dfs_regions dfs_region;
31559f35 8261 unsigned int cac_time_ms;
04f39047
SW
8262 int err;
8263
13cf6dec 8264 dfs_region = reg_get_dfs_region(wiphy);
55f7435c
LR
8265 if (dfs_region == NL80211_DFS_UNSET)
8266 return -EINVAL;
8267
04f39047
SW
8268 err = nl80211_parse_chandef(rdev, info, &chandef);
8269 if (err)
8270 return err;
8271
ff311bc1
SW
8272 if (netif_carrier_ok(dev))
8273 return -EBUSY;
8274
04f39047
SW
8275 if (wdev->cac_started)
8276 return -EBUSY;
8277
13cf6dec 8278 err = cfg80211_chandef_dfs_required(wiphy, &chandef, wdev->iftype);
04f39047
SW
8279 if (err < 0)
8280 return err;
8281
8282 if (err == 0)
8283 return -EINVAL;
8284
13cf6dec 8285 if (!cfg80211_chandef_dfs_usable(wiphy, &chandef))
04f39047
SW
8286 return -EINVAL;
8287
13cf6dec
DL
8288 /* CAC start is offloaded to HW and can't be started manually */
8289 if (wiphy_ext_feature_isset(wiphy, NL80211_EXT_FEATURE_DFS_OFFLOAD))
8290 return -EOPNOTSUPP;
8291
04f39047
SW
8292 if (!rdev->ops->start_radar_detection)
8293 return -EOPNOTSUPP;
8294
31559f35
JD
8295 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef);
8296 if (WARN_ON(!cac_time_ms))
8297 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
8298
a1056b1b 8299 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms);
04f39047 8300 if (!err) {
9e0e2961 8301 wdev->chandef = chandef;
04f39047
SW
8302 wdev->cac_started = true;
8303 wdev->cac_start_time = jiffies;
31559f35 8304 wdev->cac_time_ms = cac_time_ms;
04f39047 8305 }
04f39047
SW
8306 return err;
8307}
8308
30c63115
S
8309static int nl80211_notify_radar_detection(struct sk_buff *skb,
8310 struct genl_info *info)
8311{
8312 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8313 struct net_device *dev = info->user_ptr[1];
8314 struct wireless_dev *wdev = dev->ieee80211_ptr;
8315 struct wiphy *wiphy = wdev->wiphy;
8316 struct cfg80211_chan_def chandef;
8317 enum nl80211_dfs_regions dfs_region;
8318 int err;
8319
8320 dfs_region = reg_get_dfs_region(wiphy);
8321 if (dfs_region == NL80211_DFS_UNSET) {
8322 GENL_SET_ERR_MSG(info,
8323 "DFS Region is not set. Unexpected Radar indication");
8324 return -EINVAL;
8325 }
8326
8327 err = nl80211_parse_chandef(rdev, info, &chandef);
8328 if (err) {
8329 GENL_SET_ERR_MSG(info, "Unable to extract chandef info");
8330 return err;
8331 }
8332
8333 err = cfg80211_chandef_dfs_required(wiphy, &chandef, wdev->iftype);
8334 if (err < 0) {
8335 GENL_SET_ERR_MSG(info, "chandef is invalid");
8336 return err;
8337 }
8338
8339 if (err == 0) {
8340 GENL_SET_ERR_MSG(info,
8341 "Unexpected Radar indication for chandef/iftype");
8342 return -EINVAL;
8343 }
8344
8345 /* Do not process this notification if radar is already detected
8346 * by kernel on this channel, and return success.
8347 */
8348 if (chandef.chan->dfs_state == NL80211_DFS_UNAVAILABLE)
8349 return 0;
8350
8351 cfg80211_set_dfs_state(wiphy, &chandef, NL80211_DFS_UNAVAILABLE);
8352
8353 cfg80211_sched_dfs_chan_update(rdev);
8354
a680fe46 8355 rdev->radar_chandef = chandef;
30c63115
S
8356
8357 /* Propagate this notification to other radios as well */
8358 queue_work(cfg80211_wq, &rdev->propagate_radar_detect_wk);
8359
8360 return 0;
8361}
8362
16ef1fe2
SW
8363static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
8364{
8365 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8366 struct net_device *dev = info->user_ptr[1];
8367 struct wireless_dev *wdev = dev->ieee80211_ptr;
8368 struct cfg80211_csa_settings params;
8369 /* csa_attrs is defined static to avoid waste of stack size - this
8370 * function is called under RTNL lock, so this should not be a problem.
8371 */
8372 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
16ef1fe2 8373 int err;
ee4bc9e7 8374 bool need_new_beacon = false;
8d9de16f 8375 bool need_handle_dfs_flag = true;
9a774c78 8376 int len, i;
252e07ca 8377 u32 cs_count;
16ef1fe2
SW
8378
8379 if (!rdev->ops->channel_switch ||
8380 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
8381 return -EOPNOTSUPP;
8382
ee4bc9e7
SW
8383 switch (dev->ieee80211_ptr->iftype) {
8384 case NL80211_IFTYPE_AP:
8385 case NL80211_IFTYPE_P2P_GO:
8386 need_new_beacon = true;
8d9de16f
BB
8387 /* For all modes except AP the handle_dfs flag needs to be
8388 * supplied to tell the kernel that userspace will handle radar
8389 * events when they happen. Otherwise a switch to a channel
8390 * requiring DFS will be rejected.
8391 */
8392 need_handle_dfs_flag = false;
ee4bc9e7
SW
8393
8394 /* useless if AP is not running */
8395 if (!wdev->beacon_interval)
1ff79dfa 8396 return -ENOTCONN;
ee4bc9e7
SW
8397 break;
8398 case NL80211_IFTYPE_ADHOC:
1ff79dfa
JB
8399 if (!wdev->ssid_len)
8400 return -ENOTCONN;
8401 break;
c6da674a 8402 case NL80211_IFTYPE_MESH_POINT:
1ff79dfa
JB
8403 if (!wdev->mesh_id_len)
8404 return -ENOTCONN;
ee4bc9e7
SW
8405 break;
8406 default:
16ef1fe2 8407 return -EOPNOTSUPP;
ee4bc9e7 8408 }
16ef1fe2
SW
8409
8410 memset(&params, 0, sizeof(params));
c177db2d 8411 params.beacon_csa.ftm_responder = -1;
16ef1fe2
SW
8412
8413 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
8414 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
8415 return -EINVAL;
8416
8417 /* only important for AP, IBSS and mesh create IEs internally */
d0a361a5 8418 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
16ef1fe2
SW
8419 return -EINVAL;
8420
252e07ca
LC
8421 /* Even though the attribute is u32, the specification says
8422 * u8, so let's make sure we don't overflow.
8423 */
8424 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
8425 if (cs_count > 255)
8426 return -EINVAL;
8427
8428 params.count = cs_count;
16ef1fe2 8429
ee4bc9e7
SW
8430 if (!need_new_beacon)
8431 goto skip_beacons;
8432
81e54d08 8433 err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon_after);
16ef1fe2
SW
8434 if (err)
8435 return err;
8436
8cb08174
JB
8437 err = nla_parse_nested_deprecated(csa_attrs, NL80211_ATTR_MAX,
8438 info->attrs[NL80211_ATTR_CSA_IES],
8439 nl80211_policy, info->extack);
16ef1fe2
SW
8440 if (err)
8441 return err;
8442
81e54d08 8443 err = nl80211_parse_beacon(rdev, csa_attrs, &params.beacon_csa);
16ef1fe2
SW
8444 if (err)
8445 return err;
8446
8447 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
8448 return -EINVAL;
8449
9a774c78
AO
8450 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
8451 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
8452 return -EINVAL;
8453
9a774c78
AO
8454 params.n_counter_offsets_beacon = len / sizeof(u16);
8455 if (rdev->wiphy.max_num_csa_counters &&
8456 (params.n_counter_offsets_beacon >
8457 rdev->wiphy.max_num_csa_counters))
16ef1fe2
SW
8458 return -EINVAL;
8459
9a774c78
AO
8460 params.counter_offsets_beacon =
8461 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
8462
8463 /* sanity checks - counters should fit and be the same */
8464 for (i = 0; i < params.n_counter_offsets_beacon; i++) {
8465 u16 offset = params.counter_offsets_beacon[i];
8466
8467 if (offset >= params.beacon_csa.tail_len)
8468 return -EINVAL;
8469
8470 if (params.beacon_csa.tail[offset] != params.count)
8471 return -EINVAL;
8472 }
8473
16ef1fe2 8474 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
9a774c78
AO
8475 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
8476 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
8477 return -EINVAL;
8478
9a774c78
AO
8479 params.n_counter_offsets_presp = len / sizeof(u16);
8480 if (rdev->wiphy.max_num_csa_counters &&
ad5987b4 8481 (params.n_counter_offsets_presp >
9a774c78 8482 rdev->wiphy.max_num_csa_counters))
16ef1fe2 8483 return -EINVAL;
9a774c78
AO
8484
8485 params.counter_offsets_presp =
8486 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
8487
8488 /* sanity checks - counters should fit and be the same */
8489 for (i = 0; i < params.n_counter_offsets_presp; i++) {
8490 u16 offset = params.counter_offsets_presp[i];
8491
8492 if (offset >= params.beacon_csa.probe_resp_len)
8493 return -EINVAL;
8494
8495 if (params.beacon_csa.probe_resp[offset] !=
8496 params.count)
8497 return -EINVAL;
8498 }
16ef1fe2
SW
8499 }
8500
ee4bc9e7 8501skip_beacons:
16ef1fe2
SW
8502 err = nl80211_parse_chandef(rdev, info, &params.chandef);
8503 if (err)
8504 return err;
8505
923b352f
AN
8506 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
8507 wdev->iftype))
16ef1fe2
SW
8508 return -EINVAL;
8509
2beb6dab
LC
8510 err = cfg80211_chandef_dfs_required(wdev->wiphy,
8511 &params.chandef,
8512 wdev->iftype);
8513 if (err < 0)
8514 return err;
8515
8d9de16f 8516 if (err > 0) {
2beb6dab 8517 params.radar_required = true;
8d9de16f
BB
8518 if (need_handle_dfs_flag &&
8519 !nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS])) {
8520 return -EINVAL;
8521 }
8522 }
16ef1fe2 8523
16ef1fe2
SW
8524 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
8525 params.block_tx = true;
8526
c56589ed
SW
8527 wdev_lock(wdev);
8528 err = rdev_channel_switch(rdev, dev, &params);
8529 wdev_unlock(wdev);
8530
8531 return err;
16ef1fe2
SW
8532}
8533
9720bb3a
JB
8534static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
8535 u32 seq, int flags,
2a519311 8536 struct cfg80211_registered_device *rdev,
48ab905d
JB
8537 struct wireless_dev *wdev,
8538 struct cfg80211_internal_bss *intbss)
2a519311 8539{
48ab905d 8540 struct cfg80211_bss *res = &intbss->pub;
9caf0364 8541 const struct cfg80211_bss_ies *ies;
2a519311
JB
8542 void *hdr;
8543 struct nlattr *bss;
48ab905d
JB
8544
8545 ASSERT_WDEV_LOCK(wdev);
2a519311 8546
15e47304 8547 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
8548 NL80211_CMD_NEW_SCAN_RESULTS);
8549 if (!hdr)
8550 return -1;
8551
0a833c29 8552 genl_dump_check_consistent(cb, hdr);
9720bb3a 8553
97990a06
JB
8554 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
8555 goto nla_put_failure;
8556 if (wdev->netdev &&
9360ffd1
DM
8557 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
8558 goto nla_put_failure;
2dad624e
ND
8559 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
8560 NL80211_ATTR_PAD))
97990a06 8561 goto nla_put_failure;
2a519311 8562
ae0be8de 8563 bss = nla_nest_start_noflag(msg, NL80211_ATTR_BSS);
2a519311
JB
8564 if (!bss)
8565 goto nla_put_failure;
9360ffd1 8566 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 8567 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 8568 goto nla_put_failure;
9caf0364
JB
8569
8570 rcu_read_lock();
0e227084
JB
8571 /* indicate whether we have probe response data or not */
8572 if (rcu_access_pointer(res->proberesp_ies) &&
8573 nla_put_flag(msg, NL80211_BSS_PRESP_DATA))
8574 goto fail_unlock_rcu;
8575
8576 /* this pointer prefers to be pointed to probe response data
8577 * but is always valid
8578 */
9caf0364 8579 ies = rcu_dereference(res->ies);
8cef2c9d 8580 if (ies) {
2dad624e
ND
8581 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf,
8582 NL80211_BSS_PAD))
8cef2c9d 8583 goto fail_unlock_rcu;
8cef2c9d
JB
8584 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
8585 ies->len, ies->data))
8586 goto fail_unlock_rcu;
9caf0364 8587 }
0e227084
JB
8588
8589 /* and this pointer is always (unless driver didn't know) beacon data */
9caf0364 8590 ies = rcu_dereference(res->beacon_ies);
0e227084 8591 if (ies && ies->from_beacon) {
2dad624e
ND
8592 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf,
8593 NL80211_BSS_PAD))
8cef2c9d
JB
8594 goto fail_unlock_rcu;
8595 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
8596 ies->len, ies->data))
8597 goto fail_unlock_rcu;
9caf0364
JB
8598 }
8599 rcu_read_unlock();
8600
9360ffd1
DM
8601 if (res->beacon_interval &&
8602 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
8603 goto nla_put_failure;
8604 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
8605 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
dcd6eac1 8606 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
8607 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
8608 jiffies_to_msecs(jiffies - intbss->ts)))
8609 goto nla_put_failure;
2a519311 8610
1d76250b
AS
8611 if (intbss->parent_tsf &&
8612 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF,
8613 intbss->parent_tsf, NL80211_BSS_PAD) ||
8614 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN,
8615 intbss->parent_bssid)))
8616 goto nla_put_failure;
8617
6e19bc4b 8618 if (intbss->ts_boottime &&
2dad624e
ND
8619 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME,
8620 intbss->ts_boottime, NL80211_BSS_PAD))
6e19bc4b
DS
8621 goto nla_put_failure;
8622
983dafaa
SD
8623 if (!nl80211_put_signal(msg, intbss->pub.chains,
8624 intbss->pub.chain_signal,
8625 NL80211_BSS_CHAIN_SIGNAL))
8626 goto nla_put_failure;
8627
77965c97 8628 switch (rdev->wiphy.signal_type) {
2a519311 8629 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
8630 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
8631 goto nla_put_failure;
2a519311
JB
8632 break;
8633 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
8634 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
8635 goto nla_put_failure;
2a519311
JB
8636 break;
8637 default:
8638 break;
8639 }
8640
48ab905d 8641 switch (wdev->iftype) {
074ac8df 8642 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 8643 case NL80211_IFTYPE_STATION:
9360ffd1
DM
8644 if (intbss == wdev->current_bss &&
8645 nla_put_u32(msg, NL80211_BSS_STATUS,
8646 NL80211_BSS_STATUS_ASSOCIATED))
8647 goto nla_put_failure;
48ab905d
JB
8648 break;
8649 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
8650 if (intbss == wdev->current_bss &&
8651 nla_put_u32(msg, NL80211_BSS_STATUS,
8652 NL80211_BSS_STATUS_IBSS_JOINED))
8653 goto nla_put_failure;
48ab905d
JB
8654 break;
8655 default:
8656 break;
8657 }
8658
2a519311
JB
8659 nla_nest_end(msg, bss);
8660
053c095a
JB
8661 genlmsg_end(msg, hdr);
8662 return 0;
2a519311 8663
8cef2c9d
JB
8664 fail_unlock_rcu:
8665 rcu_read_unlock();
2a519311
JB
8666 nla_put_failure:
8667 genlmsg_cancel(msg, hdr);
8668 return -EMSGSIZE;
8669}
8670
97990a06 8671static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 8672{
48ab905d 8673 struct cfg80211_registered_device *rdev;
2a519311 8674 struct cfg80211_internal_bss *scan;
48ab905d 8675 struct wireless_dev *wdev;
97990a06 8676 int start = cb->args[2], idx = 0;
2a519311
JB
8677 int err;
8678
ea90e0dc 8679 rtnl_lock();
5297c65c 8680 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
ea90e0dc
JB
8681 if (err) {
8682 rtnl_unlock();
67748893 8683 return err;
ea90e0dc 8684 }
2a519311 8685
48ab905d
JB
8686 wdev_lock(wdev);
8687 spin_lock_bh(&rdev->bss_lock);
d1e23c94
DK
8688
8689 /*
8690 * dump_scan will be called multiple times to break up the scan results
8691 * into multiple messages. It is unlikely that any more bss-es will be
8692 * expired after the first call, so only call only call this on the
8693 * first dump_scan invocation.
8694 */
8695 if (start == 0)
8696 cfg80211_bss_expire(rdev);
48ab905d 8697
9720bb3a
JB
8698 cb->seq = rdev->bss_generation;
8699
48ab905d 8700 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
8701 if (++idx <= start)
8702 continue;
9720bb3a 8703 if (nl80211_send_bss(skb, cb,
2a519311 8704 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 8705 rdev, wdev, scan) < 0) {
2a519311 8706 idx--;
67748893 8707 break;
2a519311
JB
8708 }
8709 }
8710
48ab905d
JB
8711 spin_unlock_bh(&rdev->bss_lock);
8712 wdev_unlock(wdev);
2a519311 8713
97990a06 8714 cb->args[2] = idx;
ea90e0dc 8715 rtnl_unlock();
2a519311 8716
67748893 8717 return skb->len;
2a519311
JB
8718}
8719
15e47304 8720static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
11f78ac3
JB
8721 int flags, struct net_device *dev,
8722 bool allow_radio_stats,
8723 struct survey_info *survey)
61fa713c
HS
8724{
8725 void *hdr;
8726 struct nlattr *infoattr;
8727
11f78ac3
JB
8728 /* skip radio stats if userspace didn't request them */
8729 if (!survey->channel && !allow_radio_stats)
8730 return 0;
8731
15e47304 8732 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
8733 NL80211_CMD_NEW_SURVEY_RESULTS);
8734 if (!hdr)
8735 return -ENOMEM;
8736
9360ffd1
DM
8737 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
8738 goto nla_put_failure;
61fa713c 8739
ae0be8de 8740 infoattr = nla_nest_start_noflag(msg, NL80211_ATTR_SURVEY_INFO);
61fa713c
HS
8741 if (!infoattr)
8742 goto nla_put_failure;
8743
11f78ac3
JB
8744 if (survey->channel &&
8745 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
9360ffd1
DM
8746 survey->channel->center_freq))
8747 goto nla_put_failure;
8748
8749 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
8750 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
8751 goto nla_put_failure;
8752 if ((survey->filled & SURVEY_INFO_IN_USE) &&
8753 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
8754 goto nla_put_failure;
4ed20beb 8755 if ((survey->filled & SURVEY_INFO_TIME) &&
2dad624e
ND
8756 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME,
8757 survey->time, NL80211_SURVEY_INFO_PAD))
9360ffd1 8758 goto nla_put_failure;
4ed20beb 8759 if ((survey->filled & SURVEY_INFO_TIME_BUSY) &&
2dad624e
ND
8760 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY,
8761 survey->time_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 8762 goto nla_put_failure;
4ed20beb 8763 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) &&
2dad624e
ND
8764 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY,
8765 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 8766 goto nla_put_failure;
4ed20beb 8767 if ((survey->filled & SURVEY_INFO_TIME_RX) &&
2dad624e
ND
8768 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX,
8769 survey->time_rx, NL80211_SURVEY_INFO_PAD))
9360ffd1 8770 goto nla_put_failure;
4ed20beb 8771 if ((survey->filled & SURVEY_INFO_TIME_TX) &&
2dad624e
ND
8772 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX,
8773 survey->time_tx, NL80211_SURVEY_INFO_PAD))
9360ffd1 8774 goto nla_put_failure;
052536ab 8775 if ((survey->filled & SURVEY_INFO_TIME_SCAN) &&
2dad624e
ND
8776 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN,
8777 survey->time_scan, NL80211_SURVEY_INFO_PAD))
052536ab 8778 goto nla_put_failure;
61fa713c
HS
8779
8780 nla_nest_end(msg, infoattr);
8781
053c095a
JB
8782 genlmsg_end(msg, hdr);
8783 return 0;
61fa713c
HS
8784
8785 nla_put_failure:
8786 genlmsg_cancel(msg, hdr);
8787 return -EMSGSIZE;
8788}
8789
11f78ac3 8790static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb)
61fa713c 8791{
50508d94 8792 struct nlattr **attrbuf;
61fa713c 8793 struct survey_info survey;
1b8ec87a 8794 struct cfg80211_registered_device *rdev;
97990a06
JB
8795 struct wireless_dev *wdev;
8796 int survey_idx = cb->args[2];
61fa713c 8797 int res;
11f78ac3 8798 bool radio_stats;
61fa713c 8799
50508d94
JB
8800 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf), GFP_KERNEL);
8801 if (!attrbuf)
8802 return -ENOMEM;
8803
ea90e0dc 8804 rtnl_lock();
5297c65c 8805 res = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
67748893 8806 if (res)
ea90e0dc 8807 goto out_err;
61fa713c 8808
11f78ac3 8809 /* prepare_wdev_dump parsed the attributes */
c90c39da 8810 radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS];
11f78ac3 8811
97990a06
JB
8812 if (!wdev->netdev) {
8813 res = -EINVAL;
8814 goto out_err;
8815 }
8816
1b8ec87a 8817 if (!rdev->ops->dump_survey) {
61fa713c
HS
8818 res = -EOPNOTSUPP;
8819 goto out_err;
8820 }
8821
8822 while (1) {
1b8ec87a 8823 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
8824 if (res == -ENOENT)
8825 break;
8826 if (res)
8827 goto out_err;
8828
11f78ac3
JB
8829 /* don't send disabled channels, but do send non-channel data */
8830 if (survey.channel &&
8831 survey.channel->flags & IEEE80211_CHAN_DISABLED) {
180cdc79
LR
8832 survey_idx++;
8833 continue;
8834 }
8835
61fa713c 8836 if (nl80211_send_survey(skb,
15e47304 8837 NETLINK_CB(cb->skb).portid,
61fa713c 8838 cb->nlh->nlmsg_seq, NLM_F_MULTI,
11f78ac3 8839 wdev->netdev, radio_stats, &survey) < 0)
61fa713c
HS
8840 goto out;
8841 survey_idx++;
8842 }
8843
8844 out:
97990a06 8845 cb->args[2] = survey_idx;
61fa713c
HS
8846 res = skb->len;
8847 out_err:
50508d94 8848 kfree(attrbuf);
ea90e0dc 8849 rtnl_unlock();
61fa713c
HS
8850 return res;
8851}
8852
b23aa676
SO
8853static bool nl80211_valid_wpa_versions(u32 wpa_versions)
8854{
8855 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
cc3e14c2
CHH
8856 NL80211_WPA_VERSION_2 |
8857 NL80211_WPA_VERSION_3));
b23aa676
SO
8858}
8859
636a5d36
JM
8860static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
8861{
4c476991
JB
8862 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8863 struct net_device *dev = info->user_ptr[1];
19957bb3 8864 struct ieee80211_channel *chan;
11b6b5a4
JM
8865 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL;
8866 int err, ssid_len, ie_len = 0, auth_data_len = 0;
19957bb3 8867 enum nl80211_auth_type auth_type;
fffd0934 8868 struct key_parse key;
d5cdfacb 8869 bool local_state_change;
636a5d36 8870
f4a11bb0
JB
8871 if (!info->attrs[NL80211_ATTR_MAC])
8872 return -EINVAL;
8873
1778092e
JM
8874 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
8875 return -EINVAL;
8876
19957bb3
JB
8877 if (!info->attrs[NL80211_ATTR_SSID])
8878 return -EINVAL;
8879
8880 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
8881 return -EINVAL;
8882
fffd0934
JB
8883 err = nl80211_parse_key(info, &key);
8884 if (err)
8885 return err;
8886
8887 if (key.idx >= 0) {
e31b8213
JB
8888 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
8889 return -EINVAL;
fffd0934
JB
8890 if (!key.p.key || !key.p.key_len)
8891 return -EINVAL;
8892 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
8893 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
8894 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
8895 key.p.key_len != WLAN_KEY_LEN_WEP104))
8896 return -EINVAL;
b6b5555b 8897 if (key.idx > 3)
fffd0934
JB
8898 return -EINVAL;
8899 } else {
8900 key.p.key_len = 0;
8901 key.p.key = NULL;
8902 }
8903
afea0b7a
JB
8904 if (key.idx >= 0) {
8905 int i;
8906 bool ok = false;
7a087e74 8907
afea0b7a
JB
8908 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
8909 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
8910 ok = true;
8911 break;
8912 }
8913 }
4c476991
JB
8914 if (!ok)
8915 return -EINVAL;
afea0b7a
JB
8916 }
8917
4c476991
JB
8918 if (!rdev->ops->auth)
8919 return -EOPNOTSUPP;
636a5d36 8920
074ac8df 8921 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
8922 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
8923 return -EOPNOTSUPP;
eec60b03 8924
19957bb3 8925 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
664834de
JM
8926 chan = nl80211_get_valid_chan(&rdev->wiphy,
8927 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
8928 if (!chan)
4c476991 8929 return -EINVAL;
636a5d36 8930
19957bb3
JB
8931 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
8932 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
8933
8934 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
8935 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
8936 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
8937 }
8938
19957bb3 8939 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 8940 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 8941 return -EINVAL;
636a5d36 8942
63181060
JM
8943 if ((auth_type == NL80211_AUTHTYPE_SAE ||
8944 auth_type == NL80211_AUTHTYPE_FILS_SK ||
8945 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
8946 auth_type == NL80211_AUTHTYPE_FILS_PK) &&
11b6b5a4 8947 !info->attrs[NL80211_ATTR_AUTH_DATA])
e39e5b5e
JM
8948 return -EINVAL;
8949
11b6b5a4 8950 if (info->attrs[NL80211_ATTR_AUTH_DATA]) {
63181060
JM
8951 if (auth_type != NL80211_AUTHTYPE_SAE &&
8952 auth_type != NL80211_AUTHTYPE_FILS_SK &&
8953 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS &&
8954 auth_type != NL80211_AUTHTYPE_FILS_PK)
e39e5b5e 8955 return -EINVAL;
11b6b5a4
JM
8956 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]);
8957 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]);
e39e5b5e 8958 /* need to include at least Auth Transaction and Status Code */
11b6b5a4 8959 if (auth_data_len < 4)
e39e5b5e
JM
8960 return -EINVAL;
8961 }
8962
d5cdfacb
JM
8963 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
8964
95de817b
JB
8965 /*
8966 * Since we no longer track auth state, ignore
8967 * requests to only change local state.
8968 */
8969 if (local_state_change)
8970 return 0;
8971
91bf9b26
JB
8972 wdev_lock(dev->ieee80211_ptr);
8973 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
8974 ssid, ssid_len, ie, ie_len,
8975 key.p.key, key.p.key_len, key.idx,
11b6b5a4 8976 auth_data, auth_data_len);
91bf9b26
JB
8977 wdev_unlock(dev->ieee80211_ptr);
8978 return err;
636a5d36
JM
8979}
8980
64bf3d4b
DK
8981static int validate_pae_over_nl80211(struct cfg80211_registered_device *rdev,
8982 struct genl_info *info)
8983{
8984 if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
8985 GENL_SET_ERR_MSG(info, "SOCKET_OWNER not set");
8986 return -EINVAL;
8987 }
8988
8989 if (!rdev->ops->tx_control_port ||
8990 !wiphy_ext_feature_isset(&rdev->wiphy,
8991 NL80211_EXT_FEATURE_CONTROL_PORT_OVER_NL80211))
8992 return -EOPNOTSUPP;
8993
8994 return 0;
8995}
8996
c0692b8f
JB
8997static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
8998 struct genl_info *info,
3dc27d25
JB
8999 struct cfg80211_crypto_settings *settings,
9000 int cipher_limit)
b23aa676 9001{
c0b2bbd8
JB
9002 memset(settings, 0, sizeof(*settings));
9003
b23aa676
SO
9004 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
9005
c0692b8f
JB
9006 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
9007 u16 proto;
7a087e74 9008
c0692b8f
JB
9009 proto = nla_get_u16(
9010 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
9011 settings->control_port_ethertype = cpu_to_be16(proto);
9012 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
9013 proto != ETH_P_PAE)
9014 return -EINVAL;
9015 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
9016 settings->control_port_no_encrypt = true;
9017 } else
9018 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
9019
64bf3d4b
DK
9020 if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
9021 int r = validate_pae_over_nl80211(rdev, info);
9022
9023 if (r < 0)
9024 return r;
9025
9026 settings->control_port_over_nl80211 = true;
9027 }
9028
b23aa676
SO
9029 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
9030 void *data;
9031 int len, i;
9032
9033 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
9034 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
9035 settings->n_ciphers_pairwise = len / sizeof(u32);
9036
9037 if (len % sizeof(u32))
9038 return -EINVAL;
9039
3dc27d25 9040 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
9041 return -EINVAL;
9042
9043 memcpy(settings->ciphers_pairwise, data, len);
9044
9045 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
9046 if (!cfg80211_supported_cipher_suite(
9047 &rdev->wiphy,
b23aa676
SO
9048 settings->ciphers_pairwise[i]))
9049 return -EINVAL;
9050 }
9051
9052 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
9053 settings->cipher_group =
9054 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
9055 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
9056 settings->cipher_group))
b23aa676
SO
9057 return -EINVAL;
9058 }
9059
9060 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
9061 settings->wpa_versions =
9062 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
9063 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
9064 return -EINVAL;
9065 }
9066
9067 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
9068 void *data;
6d30240e 9069 int len;
b23aa676
SO
9070
9071 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
9072 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
9073 settings->n_akm_suites = len / sizeof(u32);
9074
9075 if (len % sizeof(u32))
9076 return -EINVAL;
9077
1b9ca027
JM
9078 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
9079 return -EINVAL;
9080
b23aa676 9081 memcpy(settings->akm_suites, data, len);
b23aa676
SO
9082 }
9083
91b5ab62
EP
9084 if (info->attrs[NL80211_ATTR_PMK]) {
9085 if (nla_len(info->attrs[NL80211_ATTR_PMK]) != WLAN_PMK_LEN)
9086 return -EINVAL;
9087 if (!wiphy_ext_feature_isset(&rdev->wiphy,
9088 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_PSK))
9089 return -EINVAL;
9090 settings->psk = nla_data(info->attrs[NL80211_ATTR_PMK]);
9091 }
9092
26f7044e
CHH
9093 if (info->attrs[NL80211_ATTR_SAE_PASSWORD]) {
9094 if (!wiphy_ext_feature_isset(&rdev->wiphy,
9095 NL80211_EXT_FEATURE_SAE_OFFLOAD))
9096 return -EINVAL;
9097 settings->sae_pwd =
9098 nla_data(info->attrs[NL80211_ATTR_SAE_PASSWORD]);
9099 settings->sae_pwd_len =
9100 nla_len(info->attrs[NL80211_ATTR_SAE_PASSWORD]);
9101 }
9102
b23aa676
SO
9103 return 0;
9104}
9105
636a5d36
JM
9106static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
9107{
4c476991
JB
9108 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9109 struct net_device *dev = info->user_ptr[1];
f444de05 9110 struct ieee80211_channel *chan;
f62fab73
JB
9111 struct cfg80211_assoc_request req = {};
9112 const u8 *bssid, *ssid;
9113 int err, ssid_len = 0;
636a5d36 9114
bad29297
AZ
9115 if (dev->ieee80211_ptr->conn_owner_nlportid &&
9116 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
9117 return -EPERM;
9118
f4a11bb0 9119 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
9120 !info->attrs[NL80211_ATTR_SSID] ||
9121 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
9122 return -EINVAL;
9123
4c476991
JB
9124 if (!rdev->ops->assoc)
9125 return -EOPNOTSUPP;
636a5d36 9126
074ac8df 9127 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9128 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9129 return -EOPNOTSUPP;
eec60b03 9130
19957bb3 9131 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 9132
664834de
JM
9133 chan = nl80211_get_valid_chan(&rdev->wiphy,
9134 info->attrs[NL80211_ATTR_WIPHY_FREQ]);
9135 if (!chan)
4c476991 9136 return -EINVAL;
636a5d36 9137
19957bb3
JB
9138 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9139 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
9140
9141 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
9142 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9143 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9144 }
9145
dc6382ce 9146 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 9147 enum nl80211_mfp mfp =
dc6382ce 9148 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 9149 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 9150 req.use_mfp = true;
4c476991
JB
9151 else if (mfp != NL80211_MFP_NO)
9152 return -EINVAL;
dc6382ce
JM
9153 }
9154
3e5d7649 9155 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 9156 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 9157
7e7c8926 9158 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 9159 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
9160
9161 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
9162 memcpy(&req.ht_capa_mask,
9163 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
9164 sizeof(req.ht_capa_mask));
7e7c8926
BG
9165
9166 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 9167 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 9168 return -EINVAL;
f62fab73
JB
9169 memcpy(&req.ht_capa,
9170 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
9171 sizeof(req.ht_capa));
7e7c8926
BG
9172 }
9173
ee2aca34 9174 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 9175 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
9176
9177 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
9178 memcpy(&req.vht_capa_mask,
9179 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
9180 sizeof(req.vht_capa_mask));
ee2aca34
JB
9181
9182 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 9183 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 9184 return -EINVAL;
f62fab73
JB
9185 memcpy(&req.vht_capa,
9186 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
9187 sizeof(req.vht_capa));
ee2aca34
JB
9188 }
9189
bab5ab7d 9190 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
9191 if (!((rdev->wiphy.features &
9192 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
9193 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
9194 !wiphy_ext_feature_isset(&rdev->wiphy,
9195 NL80211_EXT_FEATURE_RRM))
bab5ab7d
AK
9196 return -EINVAL;
9197 req.flags |= ASSOC_REQ_USE_RRM;
9198 }
9199
348bd456
JM
9200 if (info->attrs[NL80211_ATTR_FILS_KEK]) {
9201 req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]);
9202 req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]);
9203 if (!info->attrs[NL80211_ATTR_FILS_NONCES])
9204 return -EINVAL;
9205 req.fils_nonces =
9206 nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]);
9207 }
9208
f62fab73 9209 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
9210 if (!err) {
9211 wdev_lock(dev->ieee80211_ptr);
bd2522b1 9212
f62fab73
JB
9213 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
9214 ssid, ssid_len, &req);
bd2522b1
AZ
9215
9216 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
9217 dev->ieee80211_ptr->conn_owner_nlportid =
9218 info->snd_portid;
9219 memcpy(dev->ieee80211_ptr->disconnect_bssid,
9220 bssid, ETH_ALEN);
9221 }
9222
91bf9b26
JB
9223 wdev_unlock(dev->ieee80211_ptr);
9224 }
636a5d36 9225
636a5d36
JM
9226 return err;
9227}
9228
9229static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
9230{
4c476991
JB
9231 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9232 struct net_device *dev = info->user_ptr[1];
19957bb3 9233 const u8 *ie = NULL, *bssid;
91bf9b26 9234 int ie_len = 0, err;
19957bb3 9235 u16 reason_code;
d5cdfacb 9236 bool local_state_change;
636a5d36 9237
bad29297
AZ
9238 if (dev->ieee80211_ptr->conn_owner_nlportid &&
9239 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
9240 return -EPERM;
9241
f4a11bb0
JB
9242 if (!info->attrs[NL80211_ATTR_MAC])
9243 return -EINVAL;
9244
9245 if (!info->attrs[NL80211_ATTR_REASON_CODE])
9246 return -EINVAL;
9247
4c476991
JB
9248 if (!rdev->ops->deauth)
9249 return -EOPNOTSUPP;
636a5d36 9250
074ac8df 9251 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9252 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9253 return -EOPNOTSUPP;
eec60b03 9254
19957bb3 9255 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 9256
19957bb3
JB
9257 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
9258 if (reason_code == 0) {
f4a11bb0 9259 /* Reason Code 0 is reserved */
4c476991 9260 return -EINVAL;
255e737e 9261 }
636a5d36
JM
9262
9263 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
9264 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9265 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9266 }
9267
d5cdfacb
JM
9268 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
9269
91bf9b26
JB
9270 wdev_lock(dev->ieee80211_ptr);
9271 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
9272 local_state_change);
9273 wdev_unlock(dev->ieee80211_ptr);
9274 return err;
636a5d36
JM
9275}
9276
9277static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
9278{
4c476991
JB
9279 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9280 struct net_device *dev = info->user_ptr[1];
19957bb3 9281 const u8 *ie = NULL, *bssid;
91bf9b26 9282 int ie_len = 0, err;
19957bb3 9283 u16 reason_code;
d5cdfacb 9284 bool local_state_change;
636a5d36 9285
bad29297
AZ
9286 if (dev->ieee80211_ptr->conn_owner_nlportid &&
9287 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
9288 return -EPERM;
9289
f4a11bb0
JB
9290 if (!info->attrs[NL80211_ATTR_MAC])
9291 return -EINVAL;
9292
9293 if (!info->attrs[NL80211_ATTR_REASON_CODE])
9294 return -EINVAL;
9295
4c476991
JB
9296 if (!rdev->ops->disassoc)
9297 return -EOPNOTSUPP;
636a5d36 9298
074ac8df 9299 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9300 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9301 return -EOPNOTSUPP;
eec60b03 9302
19957bb3 9303 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 9304
19957bb3
JB
9305 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
9306 if (reason_code == 0) {
f4a11bb0 9307 /* Reason Code 0 is reserved */
4c476991 9308 return -EINVAL;
255e737e 9309 }
636a5d36
JM
9310
9311 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
9312 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9313 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9314 }
9315
d5cdfacb
JM
9316 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
9317
91bf9b26
JB
9318 wdev_lock(dev->ieee80211_ptr);
9319 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
9320 local_state_change);
9321 wdev_unlock(dev->ieee80211_ptr);
9322 return err;
636a5d36
JM
9323}
9324
dd5b4cc7
FF
9325static bool
9326nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
57fbcce3 9327 int mcast_rate[NUM_NL80211_BANDS],
dd5b4cc7
FF
9328 int rateval)
9329{
9330 struct wiphy *wiphy = &rdev->wiphy;
9331 bool found = false;
9332 int band, i;
9333
57fbcce3 9334 for (band = 0; band < NUM_NL80211_BANDS; band++) {
dd5b4cc7
FF
9335 struct ieee80211_supported_band *sband;
9336
9337 sband = wiphy->bands[band];
9338 if (!sband)
9339 continue;
9340
9341 for (i = 0; i < sband->n_bitrates; i++) {
9342 if (sband->bitrates[i].bitrate == rateval) {
9343 mcast_rate[band] = i + 1;
9344 found = true;
9345 break;
9346 }
9347 }
9348 }
9349
9350 return found;
9351}
9352
04a773ad
JB
9353static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
9354{
4c476991
JB
9355 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9356 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
9357 struct cfg80211_ibss_params ibss;
9358 struct wiphy *wiphy;
fffd0934 9359 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
9360 int err;
9361
8e30bc55
JB
9362 memset(&ibss, 0, sizeof(ibss));
9363
683b6d3b 9364 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
9365 !nla_len(info->attrs[NL80211_ATTR_SSID]))
9366 return -EINVAL;
9367
8e30bc55
JB
9368 ibss.beacon_interval = 100;
9369
12d20fc9 9370 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL])
8e30bc55
JB
9371 ibss.beacon_interval =
9372 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 9373
0c317a02
PK
9374 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC,
9375 ibss.beacon_interval);
12d20fc9
PK
9376 if (err)
9377 return err;
8e30bc55 9378
4c476991
JB
9379 if (!rdev->ops->join_ibss)
9380 return -EOPNOTSUPP;
04a773ad 9381
4c476991
JB
9382 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
9383 return -EOPNOTSUPP;
04a773ad 9384
79c97e97 9385 wiphy = &rdev->wiphy;
04a773ad 9386
39193498 9387 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 9388 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
9389
9390 if (!is_valid_ether_addr(ibss.bssid))
9391 return -EINVAL;
9392 }
04a773ad
JB
9393 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9394 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
9395
9396 if (info->attrs[NL80211_ATTR_IE]) {
9397 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9398 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9399 }
9400
683b6d3b
JB
9401 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
9402 if (err)
9403 return err;
04a773ad 9404
174e0cd2
IP
9405 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef,
9406 NL80211_IFTYPE_ADHOC))
54858ee5
AS
9407 return -EINVAL;
9408
2f301ab2 9409 switch (ibss.chandef.width) {
bf372645
SW
9410 case NL80211_CHAN_WIDTH_5:
9411 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
9412 case NL80211_CHAN_WIDTH_20_NOHT:
9413 break;
9414 case NL80211_CHAN_WIDTH_20:
9415 case NL80211_CHAN_WIDTH_40:
ffc11991
JD
9416 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
9417 return -EINVAL;
9418 break;
9419 case NL80211_CHAN_WIDTH_80:
9420 case NL80211_CHAN_WIDTH_80P80:
9421 case NL80211_CHAN_WIDTH_160:
9422 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
9423 return -EINVAL;
9424 if (!wiphy_ext_feature_isset(&rdev->wiphy,
9425 NL80211_EXT_FEATURE_VHT_IBSS))
9426 return -EINVAL;
9427 break;
2f301ab2 9428 default:
c04d6150 9429 return -EINVAL;
2f301ab2 9430 }
db9c64cf 9431
04a773ad 9432 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
9433 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
9434
fbd2c8dc
TP
9435 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
9436 u8 *rates =
9437 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
9438 int n_rates =
9439 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
9440 struct ieee80211_supported_band *sband =
683b6d3b 9441 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 9442
34850ab2
JB
9443 err = ieee80211_get_ratemask(sband, rates, n_rates,
9444 &ibss.basic_rates);
9445 if (err)
9446 return err;
fbd2c8dc 9447 }
dd5b4cc7 9448
803768f5
SW
9449 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
9450 memcpy(&ibss.ht_capa_mask,
9451 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
9452 sizeof(ibss.ht_capa_mask));
9453
9454 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
9455 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
9456 return -EINVAL;
9457 memcpy(&ibss.ht_capa,
9458 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
9459 sizeof(ibss.ht_capa));
9460 }
9461
dd5b4cc7
FF
9462 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
9463 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
9464 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
9465 return -EINVAL;
fbd2c8dc 9466
4c476991 9467 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
9468 bool no_ht = false;
9469
768075eb 9470 connkeys = nl80211_parse_connkeys(rdev, info, &no_ht);
4c476991
JB
9471 if (IS_ERR(connkeys))
9472 return PTR_ERR(connkeys);
de7044ee 9473
3d9d1d66
JB
9474 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
9475 no_ht) {
5e950a78 9476 kzfree(connkeys);
de7044ee
SM
9477 return -EINVAL;
9478 }
4c476991 9479 }
04a773ad 9480
267335d6
AQ
9481 ibss.control_port =
9482 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
9483
c3bfe1f6
DK
9484 if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
9485 int r = validate_pae_over_nl80211(rdev, info);
9486
d350a0f4
JB
9487 if (r < 0) {
9488 kzfree(connkeys);
c3bfe1f6 9489 return r;
d350a0f4 9490 }
c3bfe1f6
DK
9491
9492 ibss.control_port_over_nl80211 = true;
9493 }
9494
5336fa88
SW
9495 ibss.userspace_handles_dfs =
9496 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
9497
f8d16d3e
DK
9498 wdev_lock(dev->ieee80211_ptr);
9499 err = __cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934 9500 if (err)
b47f610b 9501 kzfree(connkeys);
f8d16d3e
DK
9502 else if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
9503 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
9504 wdev_unlock(dev->ieee80211_ptr);
9505
04a773ad
JB
9506 return err;
9507}
9508
9509static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
9510{
4c476991
JB
9511 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9512 struct net_device *dev = info->user_ptr[1];
04a773ad 9513
4c476991
JB
9514 if (!rdev->ops->leave_ibss)
9515 return -EOPNOTSUPP;
04a773ad 9516
4c476991
JB
9517 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
9518 return -EOPNOTSUPP;
04a773ad 9519
4c476991 9520 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
9521}
9522
f4e583c8
AQ
9523static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
9524{
9525 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9526 struct net_device *dev = info->user_ptr[1];
57fbcce3 9527 int mcast_rate[NUM_NL80211_BANDS];
f4e583c8
AQ
9528 u32 nla_rate;
9529 int err;
9530
9531 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
876dc930
BVB
9532 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
9533 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB)
f4e583c8
AQ
9534 return -EOPNOTSUPP;
9535
9536 if (!rdev->ops->set_mcast_rate)
9537 return -EOPNOTSUPP;
9538
9539 memset(mcast_rate, 0, sizeof(mcast_rate));
9540
9541 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
9542 return -EINVAL;
9543
9544 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
9545 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
9546 return -EINVAL;
9547
a1056b1b 9548 err = rdev_set_mcast_rate(rdev, dev, mcast_rate);
f4e583c8
AQ
9549
9550 return err;
9551}
9552
ad7e718c
JB
9553static struct sk_buff *
9554__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
6c09e791
AK
9555 struct wireless_dev *wdev, int approxlen,
9556 u32 portid, u32 seq, enum nl80211_commands cmd,
567ffc35
JB
9557 enum nl80211_attrs attr,
9558 const struct nl80211_vendor_cmd_info *info,
9559 gfp_t gfp)
ad7e718c
JB
9560{
9561 struct sk_buff *skb;
9562 void *hdr;
9563 struct nlattr *data;
9564
9565 skb = nlmsg_new(approxlen + 100, gfp);
9566 if (!skb)
9567 return NULL;
9568
9569 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
9570 if (!hdr) {
9571 kfree_skb(skb);
9572 return NULL;
9573 }
9574
9575 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
9576 goto nla_put_failure;
567ffc35
JB
9577
9578 if (info) {
9579 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
9580 info->vendor_id))
9581 goto nla_put_failure;
9582 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
9583 info->subcmd))
9584 goto nla_put_failure;
9585 }
9586
6c09e791 9587 if (wdev) {
2dad624e
ND
9588 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
9589 wdev_id(wdev), NL80211_ATTR_PAD))
6c09e791
AK
9590 goto nla_put_failure;
9591 if (wdev->netdev &&
9592 nla_put_u32(skb, NL80211_ATTR_IFINDEX,
9593 wdev->netdev->ifindex))
9594 goto nla_put_failure;
9595 }
9596
ae0be8de 9597 data = nla_nest_start_noflag(skb, attr);
76e1fb4b
JB
9598 if (!data)
9599 goto nla_put_failure;
ad7e718c
JB
9600
9601 ((void **)skb->cb)[0] = rdev;
9602 ((void **)skb->cb)[1] = hdr;
9603 ((void **)skb->cb)[2] = data;
9604
9605 return skb;
9606
9607 nla_put_failure:
9608 kfree_skb(skb);
9609 return NULL;
9610}
f4e583c8 9611
e03ad6ea 9612struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
6c09e791 9613 struct wireless_dev *wdev,
e03ad6ea
JB
9614 enum nl80211_commands cmd,
9615 enum nl80211_attrs attr,
55c1fdf0 9616 unsigned int portid,
e03ad6ea
JB
9617 int vendor_event_idx,
9618 int approxlen, gfp_t gfp)
9619{
f26cbf40 9620 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
e03ad6ea
JB
9621 const struct nl80211_vendor_cmd_info *info;
9622
9623 switch (cmd) {
9624 case NL80211_CMD_TESTMODE:
9625 if (WARN_ON(vendor_event_idx != -1))
9626 return NULL;
9627 info = NULL;
9628 break;
9629 case NL80211_CMD_VENDOR:
9630 if (WARN_ON(vendor_event_idx < 0 ||
9631 vendor_event_idx >= wiphy->n_vendor_events))
9632 return NULL;
9633 info = &wiphy->vendor_events[vendor_event_idx];
9634 break;
9635 default:
9636 WARN_ON(1);
9637 return NULL;
9638 }
9639
55c1fdf0 9640 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, portid, 0,
e03ad6ea
JB
9641 cmd, attr, info, gfp);
9642}
9643EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
9644
9645void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
9646{
9647 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
9648 void *hdr = ((void **)skb->cb)[1];
55c1fdf0 9649 struct nlmsghdr *nlhdr = nlmsg_hdr(skb);
e03ad6ea
JB
9650 struct nlattr *data = ((void **)skb->cb)[2];
9651 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
9652
bd8c78e7
JB
9653 /* clear CB data for netlink core to own from now on */
9654 memset(skb->cb, 0, sizeof(skb->cb));
9655
e03ad6ea
JB
9656 nla_nest_end(skb, data);
9657 genlmsg_end(skb, hdr);
9658
55c1fdf0
JB
9659 if (nlhdr->nlmsg_pid) {
9660 genlmsg_unicast(wiphy_net(&rdev->wiphy), skb,
9661 nlhdr->nlmsg_pid);
9662 } else {
9663 if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
9664 mcgrp = NL80211_MCGRP_VENDOR;
e03ad6ea 9665
55c1fdf0
JB
9666 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
9667 skb, 0, mcgrp, gfp);
9668 }
e03ad6ea
JB
9669}
9670EXPORT_SYMBOL(__cfg80211_send_event_skb);
9671
aff89a9b 9672#ifdef CONFIG_NL80211_TESTMODE
aff89a9b
JB
9673static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
9674{
4c476991 9675 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
9676 struct wireless_dev *wdev =
9677 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
9678 int err;
9679
fc73f11f
DS
9680 if (!rdev->ops->testmode_cmd)
9681 return -EOPNOTSUPP;
9682
9683 if (IS_ERR(wdev)) {
9684 err = PTR_ERR(wdev);
9685 if (err != -EINVAL)
9686 return err;
9687 wdev = NULL;
9688 } else if (wdev->wiphy != &rdev->wiphy) {
9689 return -EINVAL;
9690 }
9691
aff89a9b
JB
9692 if (!info->attrs[NL80211_ATTR_TESTDATA])
9693 return -EINVAL;
9694
ad7e718c 9695 rdev->cur_cmd_info = info;
fc73f11f 9696 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
9697 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
9698 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
ad7e718c 9699 rdev->cur_cmd_info = NULL;
aff89a9b 9700
aff89a9b
JB
9701 return err;
9702}
9703
71063f0e
WYG
9704static int nl80211_testmode_dump(struct sk_buff *skb,
9705 struct netlink_callback *cb)
9706{
00918d33 9707 struct cfg80211_registered_device *rdev;
50508d94 9708 struct nlattr **attrbuf = NULL;
71063f0e
WYG
9709 int err;
9710 long phy_idx;
9711 void *data = NULL;
9712 int data_len = 0;
9713
5fe231e8
JB
9714 rtnl_lock();
9715
71063f0e
WYG
9716 if (cb->args[0]) {
9717 /*
9718 * 0 is a valid index, but not valid for args[0],
9719 * so we need to offset by 1.
9720 */
9721 phy_idx = cb->args[0] - 1;
a4956dca
LC
9722
9723 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
9724 if (!rdev) {
9725 err = -ENOENT;
9726 goto out_err;
9727 }
71063f0e 9728 } else {
50508d94
JB
9729 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf),
9730 GFP_KERNEL);
9731 if (!attrbuf) {
9732 err = -ENOMEM;
9733 goto out_err;
9734 }
c90c39da 9735
8cb08174
JB
9736 err = nlmsg_parse_deprecated(cb->nlh,
9737 GENL_HDRLEN + nl80211_fam.hdrsize,
9738 attrbuf, nl80211_fam.maxattr,
9739 nl80211_policy, NULL);
71063f0e 9740 if (err)
5fe231e8 9741 goto out_err;
00918d33 9742
c90c39da 9743 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
2bd7e35d 9744 if (IS_ERR(rdev)) {
5fe231e8
JB
9745 err = PTR_ERR(rdev);
9746 goto out_err;
00918d33 9747 }
2bd7e35d 9748 phy_idx = rdev->wiphy_idx;
2bd7e35d 9749
c90c39da
JB
9750 if (attrbuf[NL80211_ATTR_TESTDATA])
9751 cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA];
71063f0e
WYG
9752 }
9753
9754 if (cb->args[1]) {
9755 data = nla_data((void *)cb->args[1]);
9756 data_len = nla_len((void *)cb->args[1]);
9757 }
9758
00918d33 9759 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
9760 err = -EOPNOTSUPP;
9761 goto out_err;
9762 }
9763
9764 while (1) {
15e47304 9765 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
9766 cb->nlh->nlmsg_seq, NLM_F_MULTI,
9767 NL80211_CMD_TESTMODE);
9768 struct nlattr *tmdata;
9769
cb35fba3
DC
9770 if (!hdr)
9771 break;
9772
9360ffd1 9773 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
9774 genlmsg_cancel(skb, hdr);
9775 break;
9776 }
9777
ae0be8de 9778 tmdata = nla_nest_start_noflag(skb, NL80211_ATTR_TESTDATA);
71063f0e
WYG
9779 if (!tmdata) {
9780 genlmsg_cancel(skb, hdr);
9781 break;
9782 }
e35e4d28 9783 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
9784 nla_nest_end(skb, tmdata);
9785
9786 if (err == -ENOBUFS || err == -ENOENT) {
9787 genlmsg_cancel(skb, hdr);
9788 break;
9789 } else if (err) {
9790 genlmsg_cancel(skb, hdr);
9791 goto out_err;
9792 }
9793
9794 genlmsg_end(skb, hdr);
9795 }
9796
9797 err = skb->len;
9798 /* see above */
9799 cb->args[0] = phy_idx + 1;
9800 out_err:
50508d94 9801 kfree(attrbuf);
5fe231e8 9802 rtnl_unlock();
71063f0e
WYG
9803 return err;
9804}
aff89a9b
JB
9805#endif
9806
b23aa676
SO
9807static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
9808{
4c476991
JB
9809 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9810 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
9811 struct cfg80211_connect_params connect;
9812 struct wiphy *wiphy;
fffd0934 9813 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
9814 int err;
9815
9816 memset(&connect, 0, sizeof(connect));
9817
b23aa676
SO
9818 if (!info->attrs[NL80211_ATTR_SSID] ||
9819 !nla_len(info->attrs[NL80211_ATTR_SSID]))
9820 return -EINVAL;
9821
9822 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
9823 connect.auth_type =
9824 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
9825 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
9826 NL80211_CMD_CONNECT))
b23aa676
SO
9827 return -EINVAL;
9828 } else
9829 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
9830
9831 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
9832
3a00df57
AS
9833 if (info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS] &&
9834 !wiphy_ext_feature_isset(&rdev->wiphy,
9835 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
9836 return -EINVAL;
9837 connect.want_1x = info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS];
9838
c0692b8f 9839 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 9840 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
9841 if (err)
9842 return err;
b23aa676 9843
074ac8df 9844 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9845 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9846 return -EOPNOTSUPP;
b23aa676 9847
79c97e97 9848 wiphy = &rdev->wiphy;
b23aa676 9849
4486ea98
BS
9850 connect.bg_scan_period = -1;
9851 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
9852 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
9853 connect.bg_scan_period =
9854 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
9855 }
9856
b23aa676
SO
9857 if (info->attrs[NL80211_ATTR_MAC])
9858 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1df4a510
JM
9859 else if (info->attrs[NL80211_ATTR_MAC_HINT])
9860 connect.bssid_hint =
9861 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
b23aa676
SO
9862 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9863 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
9864
9865 if (info->attrs[NL80211_ATTR_IE]) {
9866 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9867 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9868 }
9869
cee00a95
JM
9870 if (info->attrs[NL80211_ATTR_USE_MFP]) {
9871 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
65026002
EG
9872 if (connect.mfp == NL80211_MFP_OPTIONAL &&
9873 !wiphy_ext_feature_isset(&rdev->wiphy,
9874 NL80211_EXT_FEATURE_MFP_OPTIONAL))
9875 return -EOPNOTSUPP;
cee00a95
JM
9876 } else {
9877 connect.mfp = NL80211_MFP_NO;
9878 }
9879
ba6fbacf
JM
9880 if (info->attrs[NL80211_ATTR_PREV_BSSID])
9881 connect.prev_bssid =
9882 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
9883
b23aa676 9884 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
664834de
JM
9885 connect.channel = nl80211_get_valid_chan(
9886 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]);
9887 if (!connect.channel)
1df4a510
JM
9888 return -EINVAL;
9889 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
664834de
JM
9890 connect.channel_hint = nl80211_get_valid_chan(
9891 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
9892 if (!connect.channel_hint)
4c476991 9893 return -EINVAL;
b23aa676
SO
9894 }
9895
fffd0934 9896 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
768075eb 9897 connkeys = nl80211_parse_connkeys(rdev, info, NULL);
4c476991
JB
9898 if (IS_ERR(connkeys))
9899 return PTR_ERR(connkeys);
fffd0934
JB
9900 }
9901
7e7c8926
BG
9902 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
9903 connect.flags |= ASSOC_REQ_DISABLE_HT;
9904
9905 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
9906 memcpy(&connect.ht_capa_mask,
9907 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
9908 sizeof(connect.ht_capa_mask));
9909
9910 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e 9911 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
b47f610b 9912 kzfree(connkeys);
7e7c8926 9913 return -EINVAL;
b4e4f47e 9914 }
7e7c8926
BG
9915 memcpy(&connect.ht_capa,
9916 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
9917 sizeof(connect.ht_capa));
9918 }
9919
ee2aca34
JB
9920 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
9921 connect.flags |= ASSOC_REQ_DISABLE_VHT;
9922
9923 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
9924 memcpy(&connect.vht_capa_mask,
9925 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
9926 sizeof(connect.vht_capa_mask));
9927
9928 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
9929 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
b47f610b 9930 kzfree(connkeys);
ee2aca34
JB
9931 return -EINVAL;
9932 }
9933 memcpy(&connect.vht_capa,
9934 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
9935 sizeof(connect.vht_capa));
9936 }
9937
bab5ab7d 9938 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
9939 if (!((rdev->wiphy.features &
9940 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
9941 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
9942 !wiphy_ext_feature_isset(&rdev->wiphy,
9943 NL80211_EXT_FEATURE_RRM)) {
707554b4 9944 kzfree(connkeys);
bab5ab7d 9945 return -EINVAL;
707554b4 9946 }
bab5ab7d
AK
9947 connect.flags |= ASSOC_REQ_USE_RRM;
9948 }
9949
34d50519 9950 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
57fbcce3 9951 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) {
34d50519
LD
9952 kzfree(connkeys);
9953 return -EOPNOTSUPP;
9954 }
9955
38de03d2
AS
9956 if (info->attrs[NL80211_ATTR_BSS_SELECT]) {
9957 /* bss selection makes no sense if bssid is set */
9958 if (connect.bssid) {
9959 kzfree(connkeys);
9960 return -EINVAL;
9961 }
9962
9963 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT],
9964 wiphy, &connect.bss_select);
9965 if (err) {
9966 kzfree(connkeys);
9967 return err;
9968 }
9969 }
9970
a3caf744
VK
9971 if (wiphy_ext_feature_isset(&rdev->wiphy,
9972 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
9973 info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
9974 info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
9975 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
9976 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
9977 connect.fils_erp_username =
9978 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
9979 connect.fils_erp_username_len =
9980 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
9981 connect.fils_erp_realm =
9982 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
9983 connect.fils_erp_realm_len =
9984 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
9985 connect.fils_erp_next_seq_num =
9986 nla_get_u16(
9987 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
9988 connect.fils_erp_rrk =
9989 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
9990 connect.fils_erp_rrk_len =
9991 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
9992 } else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
9993 info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
9994 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
9995 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
9996 kzfree(connkeys);
9997 return -EINVAL;
9998 }
9999
40cbfa90
SD
10000 if (nla_get_flag(info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])) {
10001 if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
2f0605a6 10002 kzfree(connkeys);
40cbfa90
SD
10003 GENL_SET_ERR_MSG(info,
10004 "external auth requires connection ownership");
10005 return -EINVAL;
10006 }
10007 connect.flags |= CONNECT_REQ_EXTERNAL_AUTH_SUPPORT;
10008 }
10009
83739b03 10010 wdev_lock(dev->ieee80211_ptr);
bd2522b1 10011
4ce2bd9c
JM
10012 err = cfg80211_connect(rdev, dev, &connect, connkeys,
10013 connect.prev_bssid);
fffd0934 10014 if (err)
b47f610b 10015 kzfree(connkeys);
bd2522b1
AZ
10016
10017 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
10018 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
10019 if (connect.bssid)
10020 memcpy(dev->ieee80211_ptr->disconnect_bssid,
10021 connect.bssid, ETH_ALEN);
10022 else
10023 memset(dev->ieee80211_ptr->disconnect_bssid,
10024 0, ETH_ALEN);
10025 }
10026
10027 wdev_unlock(dev->ieee80211_ptr);
10028
b23aa676
SO
10029 return err;
10030}
10031
088e8df8 10032static int nl80211_update_connect_params(struct sk_buff *skb,
10033 struct genl_info *info)
10034{
10035 struct cfg80211_connect_params connect = {};
10036 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10037 struct net_device *dev = info->user_ptr[1];
10038 struct wireless_dev *wdev = dev->ieee80211_ptr;
7f9a3e15
VK
10039 bool fils_sk_offload;
10040 u32 auth_type;
088e8df8 10041 u32 changed = 0;
10042 int ret;
10043
10044 if (!rdev->ops->update_connect_params)
10045 return -EOPNOTSUPP;
10046
10047 if (info->attrs[NL80211_ATTR_IE]) {
088e8df8 10048 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
10049 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
10050 changed |= UPDATE_ASSOC_IES;
10051 }
10052
7f9a3e15
VK
10053 fils_sk_offload = wiphy_ext_feature_isset(&rdev->wiphy,
10054 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD);
10055
10056 /*
10057 * when driver supports fils-sk offload all attributes must be
10058 * provided. So the else covers "fils-sk-not-all" and
10059 * "no-fils-sk-any".
10060 */
10061 if (fils_sk_offload &&
10062 info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
10063 info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
10064 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
10065 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
10066 connect.fils_erp_username =
10067 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
10068 connect.fils_erp_username_len =
10069 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
10070 connect.fils_erp_realm =
10071 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
10072 connect.fils_erp_realm_len =
10073 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
10074 connect.fils_erp_next_seq_num =
10075 nla_get_u16(
10076 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
10077 connect.fils_erp_rrk =
10078 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
10079 connect.fils_erp_rrk_len =
10080 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
10081 changed |= UPDATE_FILS_ERP_INFO;
10082 } else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
10083 info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
10084 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
10085 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
10086 return -EINVAL;
10087 }
10088
10089 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
10090 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
10091 if (!nl80211_valid_auth_type(rdev, auth_type,
10092 NL80211_CMD_CONNECT))
10093 return -EINVAL;
10094
10095 if (auth_type == NL80211_AUTHTYPE_FILS_SK &&
10096 fils_sk_offload && !(changed & UPDATE_FILS_ERP_INFO))
10097 return -EINVAL;
10098
10099 connect.auth_type = auth_type;
10100 changed |= UPDATE_AUTH_TYPE;
10101 }
10102
088e8df8 10103 wdev_lock(dev->ieee80211_ptr);
10104 if (!wdev->current_bss)
10105 ret = -ENOLINK;
10106 else
10107 ret = rdev_update_connect_params(rdev, dev, &connect, changed);
10108 wdev_unlock(dev->ieee80211_ptr);
10109
10110 return ret;
10111}
10112
b23aa676
SO
10113static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
10114{
4c476991
JB
10115 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10116 struct net_device *dev = info->user_ptr[1];
b23aa676 10117 u16 reason;
83739b03 10118 int ret;
b23aa676 10119
bad29297
AZ
10120 if (dev->ieee80211_ptr->conn_owner_nlportid &&
10121 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
10122 return -EPERM;
10123
b23aa676
SO
10124 if (!info->attrs[NL80211_ATTR_REASON_CODE])
10125 reason = WLAN_REASON_DEAUTH_LEAVING;
10126 else
10127 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
10128
10129 if (reason == 0)
10130 return -EINVAL;
10131
074ac8df 10132 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
10133 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
10134 return -EOPNOTSUPP;
b23aa676 10135
83739b03
JB
10136 wdev_lock(dev->ieee80211_ptr);
10137 ret = cfg80211_disconnect(rdev, dev, reason, true);
10138 wdev_unlock(dev->ieee80211_ptr);
10139 return ret;
b23aa676
SO
10140}
10141
463d0183
JB
10142static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
10143{
4c476991 10144 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
10145 struct net *net;
10146 int err;
463d0183 10147
4b681c82
VK
10148 if (info->attrs[NL80211_ATTR_PID]) {
10149 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
10150
10151 net = get_net_ns_by_pid(pid);
10152 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) {
10153 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]);
463d0183 10154
4b681c82
VK
10155 net = get_net_ns_by_fd(fd);
10156 } else {
10157 return -EINVAL;
10158 }
463d0183 10159
4c476991
JB
10160 if (IS_ERR(net))
10161 return PTR_ERR(net);
463d0183
JB
10162
10163 err = 0;
10164
10165 /* check if anything to do */
4c476991
JB
10166 if (!net_eq(wiphy_net(&rdev->wiphy), net))
10167 err = cfg80211_switch_netns(rdev, net);
463d0183 10168
463d0183 10169 put_net(net);
463d0183
JB
10170 return err;
10171}
10172
67fbb16b
SO
10173static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
10174{
4c476991 10175 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
10176 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
10177 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 10178 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
10179 struct cfg80211_pmksa pmksa;
10180
10181 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
10182
67fbb16b
SO
10183 if (!info->attrs[NL80211_ATTR_PMKID])
10184 return -EINVAL;
10185
67fbb16b 10186 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
a3caf744
VK
10187
10188 if (info->attrs[NL80211_ATTR_MAC]) {
10189 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
10190 } else if (info->attrs[NL80211_ATTR_SSID] &&
10191 info->attrs[NL80211_ATTR_FILS_CACHE_ID] &&
10192 (info->genlhdr->cmd == NL80211_CMD_DEL_PMKSA ||
10193 info->attrs[NL80211_ATTR_PMK])) {
10194 pmksa.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
10195 pmksa.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
10196 pmksa.cache_id =
10197 nla_data(info->attrs[NL80211_ATTR_FILS_CACHE_ID]);
10198 } else {
10199 return -EINVAL;
10200 }
10201 if (info->attrs[NL80211_ATTR_PMK]) {
10202 pmksa.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
10203 pmksa.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
10204 }
67fbb16b 10205
074ac8df 10206 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
6c900360
LD
10207 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
10208 !(dev->ieee80211_ptr->iftype == NL80211_IFTYPE_AP &&
10209 wiphy_ext_feature_isset(&rdev->wiphy,
10210 NL80211_EXT_FEATURE_AP_PMKSA_CACHING)))
4c476991 10211 return -EOPNOTSUPP;
67fbb16b
SO
10212
10213 switch (info->genlhdr->cmd) {
10214 case NL80211_CMD_SET_PMKSA:
10215 rdev_ops = rdev->ops->set_pmksa;
10216 break;
10217 case NL80211_CMD_DEL_PMKSA:
10218 rdev_ops = rdev->ops->del_pmksa;
10219 break;
10220 default:
10221 WARN_ON(1);
10222 break;
10223 }
10224
4c476991
JB
10225 if (!rdev_ops)
10226 return -EOPNOTSUPP;
67fbb16b 10227
4c476991 10228 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
10229}
10230
10231static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
10232{
4c476991
JB
10233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10234 struct net_device *dev = info->user_ptr[1];
67fbb16b 10235
074ac8df 10236 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
10237 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
10238 return -EOPNOTSUPP;
67fbb16b 10239
4c476991
JB
10240 if (!rdev->ops->flush_pmksa)
10241 return -EOPNOTSUPP;
67fbb16b 10242
e35e4d28 10243 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
10244}
10245
109086ce
AN
10246static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
10247{
10248 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10249 struct net_device *dev = info->user_ptr[1];
10250 u8 action_code, dialog_token;
df942e7b 10251 u32 peer_capability = 0;
109086ce
AN
10252 u16 status_code;
10253 u8 *peer;
31fa97c5 10254 bool initiator;
109086ce
AN
10255
10256 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
10257 !rdev->ops->tdls_mgmt)
10258 return -EOPNOTSUPP;
10259
10260 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
10261 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
10262 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
10263 !info->attrs[NL80211_ATTR_IE] ||
10264 !info->attrs[NL80211_ATTR_MAC])
10265 return -EINVAL;
10266
10267 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
10268 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
10269 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
10270 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
31fa97c5 10271 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]);
df942e7b
SDU
10272 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
10273 peer_capability =
10274 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
109086ce 10275
e35e4d28 10276 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
df942e7b 10277 dialog_token, status_code, peer_capability,
31fa97c5 10278 initiator,
e35e4d28
HG
10279 nla_data(info->attrs[NL80211_ATTR_IE]),
10280 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
10281}
10282
10283static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
10284{
10285 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10286 struct net_device *dev = info->user_ptr[1];
10287 enum nl80211_tdls_operation operation;
10288 u8 *peer;
10289
10290 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
10291 !rdev->ops->tdls_oper)
10292 return -EOPNOTSUPP;
10293
10294 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
10295 !info->attrs[NL80211_ATTR_MAC])
10296 return -EINVAL;
10297
10298 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
10299 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
10300
e35e4d28 10301 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
10302}
10303
9588bbd5
JM
10304static int nl80211_remain_on_channel(struct sk_buff *skb,
10305 struct genl_info *info)
10306{
4c476991 10307 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10308 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 10309 struct cfg80211_chan_def chandef;
34373d12 10310 const struct cfg80211_chan_def *compat_chandef;
9588bbd5
JM
10311 struct sk_buff *msg;
10312 void *hdr;
10313 u64 cookie;
683b6d3b 10314 u32 duration;
9588bbd5
JM
10315 int err;
10316
10317 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
10318 !info->attrs[NL80211_ATTR_DURATION])
10319 return -EINVAL;
10320
10321 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
10322
ebf348fc
JB
10323 if (!rdev->ops->remain_on_channel ||
10324 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
10325 return -EOPNOTSUPP;
10326
9588bbd5 10327 /*
ebf348fc
JB
10328 * We should be on that channel for at least a minimum amount of
10329 * time (10ms) but no longer than the driver supports.
9588bbd5 10330 */
ebf348fc 10331 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 10332 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
10333 return -EINVAL;
10334
683b6d3b
JB
10335 err = nl80211_parse_chandef(rdev, info, &chandef);
10336 if (err)
10337 return err;
9588bbd5 10338
34373d12
VT
10339 wdev_lock(wdev);
10340 if (!cfg80211_off_channel_oper_allowed(wdev) &&
10341 !cfg80211_chandef_identical(&wdev->chandef, &chandef)) {
10342 compat_chandef = cfg80211_chandef_compatible(&wdev->chandef,
10343 &chandef);
10344 if (compat_chandef != &chandef) {
10345 wdev_unlock(wdev);
10346 return -EBUSY;
10347 }
10348 }
10349 wdev_unlock(wdev);
10350
9588bbd5 10351 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
10352 if (!msg)
10353 return -ENOMEM;
9588bbd5 10354
15e47304 10355 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 10356 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
10357 if (!hdr) {
10358 err = -ENOBUFS;
9588bbd5
JM
10359 goto free_msg;
10360 }
10361
683b6d3b
JB
10362 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
10363 duration, &cookie);
9588bbd5
JM
10364
10365 if (err)
10366 goto free_msg;
10367
2dad624e
ND
10368 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
10369 NL80211_ATTR_PAD))
9360ffd1 10370 goto nla_put_failure;
9588bbd5
JM
10371
10372 genlmsg_end(msg, hdr);
4c476991
JB
10373
10374 return genlmsg_reply(msg, info);
9588bbd5
JM
10375
10376 nla_put_failure:
10377 err = -ENOBUFS;
10378 free_msg:
10379 nlmsg_free(msg);
9588bbd5
JM
10380 return err;
10381}
10382
10383static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
10384 struct genl_info *info)
10385{
4c476991 10386 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10387 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 10388 u64 cookie;
9588bbd5
JM
10389
10390 if (!info->attrs[NL80211_ATTR_COOKIE])
10391 return -EINVAL;
10392
4c476991
JB
10393 if (!rdev->ops->cancel_remain_on_channel)
10394 return -EOPNOTSUPP;
9588bbd5 10395
9588bbd5
JM
10396 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
10397
e35e4d28 10398 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
10399}
10400
13ae75b1
JM
10401static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
10402 struct genl_info *info)
10403{
13ae75b1 10404 struct cfg80211_bitrate_mask mask;
a7c7fbff 10405 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 10406 struct net_device *dev = info->user_ptr[1];
a7c7fbff 10407 int err;
13ae75b1 10408
4c476991
JB
10409 if (!rdev->ops->set_bitrate_mask)
10410 return -EOPNOTSUPP;
13ae75b1 10411
a7c7fbff
PK
10412 err = nl80211_parse_tx_bitrate_mask(info, &mask);
10413 if (err)
10414 return err;
13ae75b1 10415
e35e4d28 10416 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
10417}
10418
2e161f78 10419static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 10420{
4c476991 10421 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10422 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 10423 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
10424
10425 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
10426 return -EINVAL;
10427
2e161f78
JB
10428 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
10429 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 10430
71bbc994
JB
10431 switch (wdev->iftype) {
10432 case NL80211_IFTYPE_STATION:
10433 case NL80211_IFTYPE_ADHOC:
10434 case NL80211_IFTYPE_P2P_CLIENT:
10435 case NL80211_IFTYPE_AP:
10436 case NL80211_IFTYPE_AP_VLAN:
10437 case NL80211_IFTYPE_MESH_POINT:
10438 case NL80211_IFTYPE_P2P_GO:
98104fde 10439 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 10440 break;
cb3b7d87 10441 case NL80211_IFTYPE_NAN:
71bbc994 10442 default:
4c476991 10443 return -EOPNOTSUPP;
71bbc994 10444 }
026331c4
JM
10445
10446 /* not much point in registering if we can't reply */
4c476991
JB
10447 if (!rdev->ops->mgmt_tx)
10448 return -EOPNOTSUPP;
026331c4 10449
15e47304 10450 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
026331c4
JM
10451 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
10452 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
10453}
10454
2e161f78 10455static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 10456{
4c476991 10457 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10458 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 10459 struct cfg80211_chan_def chandef;
026331c4 10460 int err;
d64d373f 10461 void *hdr = NULL;
026331c4 10462 u64 cookie;
e247bd90 10463 struct sk_buff *msg = NULL;
b176e629
AO
10464 struct cfg80211_mgmt_tx_params params = {
10465 .dont_wait_for_ack =
10466 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
10467 };
026331c4 10468
683b6d3b 10469 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
10470 return -EINVAL;
10471
4c476991
JB
10472 if (!rdev->ops->mgmt_tx)
10473 return -EOPNOTSUPP;
026331c4 10474
71bbc994 10475 switch (wdev->iftype) {
ea141b75
AQ
10476 case NL80211_IFTYPE_P2P_DEVICE:
10477 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
10478 return -EINVAL;
71bbc994
JB
10479 case NL80211_IFTYPE_STATION:
10480 case NL80211_IFTYPE_ADHOC:
10481 case NL80211_IFTYPE_P2P_CLIENT:
10482 case NL80211_IFTYPE_AP:
10483 case NL80211_IFTYPE_AP_VLAN:
10484 case NL80211_IFTYPE_MESH_POINT:
10485 case NL80211_IFTYPE_P2P_GO:
10486 break;
cb3b7d87 10487 case NL80211_IFTYPE_NAN:
71bbc994 10488 default:
4c476991 10489 return -EOPNOTSUPP;
71bbc994 10490 }
026331c4 10491
f7ca38df 10492 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 10493 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df 10494 return -EINVAL;
b176e629 10495 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
10496
10497 /*
10498 * We should wait on the channel for at least a minimum amount
10499 * of time (10ms) but no longer than the driver supports.
10500 */
b176e629
AO
10501 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
10502 params.wait > rdev->wiphy.max_remain_on_channel_duration)
ebf348fc 10503 return -EINVAL;
f7ca38df
JB
10504 }
10505
b176e629 10506 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
f7ca38df 10507
b176e629 10508 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7c4ef712
JB
10509 return -EINVAL;
10510
b176e629 10511 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
e9f935e3 10512
ea141b75
AQ
10513 /* get the channel if any has been specified, otherwise pass NULL to
10514 * the driver. The latter will use the current one
10515 */
10516 chandef.chan = NULL;
10517 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
10518 err = nl80211_parse_chandef(rdev, info, &chandef);
10519 if (err)
10520 return err;
10521 }
10522
b176e629 10523 if (!chandef.chan && params.offchan)
ea141b75 10524 return -EINVAL;
026331c4 10525
34373d12
VT
10526 wdev_lock(wdev);
10527 if (params.offchan && !cfg80211_off_channel_oper_allowed(wdev)) {
10528 wdev_unlock(wdev);
10529 return -EBUSY;
10530 }
10531 wdev_unlock(wdev);
10532
34d22ce2
AO
10533 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
10534 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
10535
10536 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) {
10537 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
10538 int i;
10539
10540 if (len % sizeof(u16))
10541 return -EINVAL;
10542
10543 params.n_csa_offsets = len / sizeof(u16);
10544 params.csa_offsets =
10545 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
10546
10547 /* check that all the offsets fit the frame */
10548 for (i = 0; i < params.n_csa_offsets; i++) {
10549 if (params.csa_offsets[i] >= params.len)
10550 return -EINVAL;
10551 }
10552 }
10553
b176e629 10554 if (!params.dont_wait_for_ack) {
e247bd90
JB
10555 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
10556 if (!msg)
10557 return -ENOMEM;
026331c4 10558
15e47304 10559 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 10560 NL80211_CMD_FRAME);
cb35fba3
DC
10561 if (!hdr) {
10562 err = -ENOBUFS;
e247bd90
JB
10563 goto free_msg;
10564 }
026331c4 10565 }
e247bd90 10566
b176e629
AO
10567 params.chan = chandef.chan;
10568 err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
026331c4
JM
10569 if (err)
10570 goto free_msg;
10571
e247bd90 10572 if (msg) {
2dad624e
ND
10573 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
10574 NL80211_ATTR_PAD))
9360ffd1 10575 goto nla_put_failure;
026331c4 10576
e247bd90
JB
10577 genlmsg_end(msg, hdr);
10578 return genlmsg_reply(msg, info);
10579 }
10580
10581 return 0;
026331c4
JM
10582
10583 nla_put_failure:
10584 err = -ENOBUFS;
10585 free_msg:
10586 nlmsg_free(msg);
026331c4
JM
10587 return err;
10588}
10589
f7ca38df
JB
10590static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
10591{
10592 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10593 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
10594 u64 cookie;
10595
10596 if (!info->attrs[NL80211_ATTR_COOKIE])
10597 return -EINVAL;
10598
10599 if (!rdev->ops->mgmt_tx_cancel_wait)
10600 return -EOPNOTSUPP;
10601
71bbc994
JB
10602 switch (wdev->iftype) {
10603 case NL80211_IFTYPE_STATION:
10604 case NL80211_IFTYPE_ADHOC:
10605 case NL80211_IFTYPE_P2P_CLIENT:
10606 case NL80211_IFTYPE_AP:
10607 case NL80211_IFTYPE_AP_VLAN:
10608 case NL80211_IFTYPE_P2P_GO:
98104fde 10609 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 10610 break;
cb3b7d87 10611 case NL80211_IFTYPE_NAN:
71bbc994 10612 default:
f7ca38df 10613 return -EOPNOTSUPP;
71bbc994 10614 }
f7ca38df
JB
10615
10616 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
10617
e35e4d28 10618 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
10619}
10620
ffb9eb3d
KV
10621static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
10622{
4c476991 10623 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 10624 struct wireless_dev *wdev;
4c476991 10625 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
10626 u8 ps_state;
10627 bool state;
10628 int err;
10629
4c476991
JB
10630 if (!info->attrs[NL80211_ATTR_PS_STATE])
10631 return -EINVAL;
ffb9eb3d
KV
10632
10633 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
10634
ffb9eb3d
KV
10635 wdev = dev->ieee80211_ptr;
10636
4c476991
JB
10637 if (!rdev->ops->set_power_mgmt)
10638 return -EOPNOTSUPP;
ffb9eb3d
KV
10639
10640 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
10641
10642 if (state == wdev->ps)
4c476991 10643 return 0;
ffb9eb3d 10644
e35e4d28 10645 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
10646 if (!err)
10647 wdev->ps = state;
ffb9eb3d
KV
10648 return err;
10649}
10650
10651static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
10652{
4c476991 10653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
10654 enum nl80211_ps_state ps_state;
10655 struct wireless_dev *wdev;
4c476991 10656 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
10657 struct sk_buff *msg;
10658 void *hdr;
10659 int err;
10660
ffb9eb3d
KV
10661 wdev = dev->ieee80211_ptr;
10662
4c476991
JB
10663 if (!rdev->ops->set_power_mgmt)
10664 return -EOPNOTSUPP;
ffb9eb3d
KV
10665
10666 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
10667 if (!msg)
10668 return -ENOMEM;
ffb9eb3d 10669
15e47304 10670 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
10671 NL80211_CMD_GET_POWER_SAVE);
10672 if (!hdr) {
4c476991 10673 err = -ENOBUFS;
ffb9eb3d
KV
10674 goto free_msg;
10675 }
10676
10677 if (wdev->ps)
10678 ps_state = NL80211_PS_ENABLED;
10679 else
10680 ps_state = NL80211_PS_DISABLED;
10681
9360ffd1
DM
10682 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
10683 goto nla_put_failure;
ffb9eb3d
KV
10684
10685 genlmsg_end(msg, hdr);
4c476991 10686 return genlmsg_reply(msg, info);
ffb9eb3d 10687
4c476991 10688 nla_put_failure:
ffb9eb3d 10689 err = -ENOBUFS;
4c476991 10690 free_msg:
ffb9eb3d 10691 nlmsg_free(msg);
ffb9eb3d
KV
10692 return err;
10693}
10694
94e860f1
JB
10695static const struct nla_policy
10696nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
4a4b8169 10697 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_BINARY },
d6dc1a38
JO
10698 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
10699 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
10700 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
10701 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
10702 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
bee427b8 10703 [NL80211_ATTR_CQM_RSSI_LEVEL] = { .type = NLA_S32 },
d6dc1a38
JO
10704};
10705
84f10708 10706static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 10707 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
10708{
10709 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 10710 struct net_device *dev = info->user_ptr[1];
1da5fcc8 10711 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 10712
d9d8b019 10713 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
10714 return -EINVAL;
10715
84f10708
TP
10716 if (!rdev->ops->set_cqm_txe_config)
10717 return -EOPNOTSUPP;
10718
10719 if (wdev->iftype != NL80211_IFTYPE_STATION &&
10720 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
10721 return -EOPNOTSUPP;
10722
e35e4d28 10723 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
10724}
10725
4a4b8169
AZ
10726static int cfg80211_cqm_rssi_update(struct cfg80211_registered_device *rdev,
10727 struct net_device *dev)
10728{
10729 struct wireless_dev *wdev = dev->ieee80211_ptr;
10730 s32 last, low, high;
10731 u32 hyst;
1222a160 10732 int i, n, low_index;
4a4b8169
AZ
10733 int err;
10734
10735 /* RSSI reporting disabled? */
10736 if (!wdev->cqm_config)
10737 return rdev_set_cqm_rssi_range_config(rdev, dev, 0, 0);
10738
10739 /*
10740 * Obtain current RSSI value if possible, if not and no RSSI threshold
10741 * event has been received yet, we should receive an event after a
10742 * connection is established and enough beacons received to calculate
10743 * the average.
10744 */
10745 if (!wdev->cqm_config->last_rssi_event_value && wdev->current_bss &&
10746 rdev->ops->get_station) {
73887fd9 10747 struct station_info sinfo = {};
4a4b8169
AZ
10748 u8 *mac_addr;
10749
10750 mac_addr = wdev->current_bss->pub.bssid;
10751
73887fd9
JB
10752 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
10753 if (err)
4a4b8169
AZ
10754 return err;
10755
397c657a 10756 if (sinfo.filled & BIT_ULL(NL80211_STA_INFO_BEACON_SIGNAL_AVG))
4a4b8169 10757 wdev->cqm_config->last_rssi_event_value =
73887fd9 10758 (s8) sinfo.rx_beacon_signal_avg;
4a4b8169
AZ
10759 }
10760
10761 last = wdev->cqm_config->last_rssi_event_value;
10762 hyst = wdev->cqm_config->rssi_hyst;
10763 n = wdev->cqm_config->n_rssi_thresholds;
10764
10765 for (i = 0; i < n; i++)
10766 if (last < wdev->cqm_config->rssi_thresholds[i])
10767 break;
10768
1222a160
MH
10769 low_index = i - 1;
10770 if (low_index >= 0) {
10771 low_index = array_index_nospec(low_index, n);
10772 low = wdev->cqm_config->rssi_thresholds[low_index] - hyst;
10773 } else {
10774 low = S32_MIN;
10775 }
10776 if (i < n) {
10777 i = array_index_nospec(i, n);
10778 high = wdev->cqm_config->rssi_thresholds[i] + hyst - 1;
10779 } else {
10780 high = S32_MAX;
10781 }
4a4b8169
AZ
10782
10783 return rdev_set_cqm_rssi_range_config(rdev, dev, low, high);
10784}
10785
d6dc1a38 10786static int nl80211_set_cqm_rssi(struct genl_info *info,
4a4b8169
AZ
10787 const s32 *thresholds, int n_thresholds,
10788 u32 hysteresis)
d6dc1a38 10789{
4c476991 10790 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 10791 struct net_device *dev = info->user_ptr[1];
1da5fcc8 10792 struct wireless_dev *wdev = dev->ieee80211_ptr;
4a4b8169
AZ
10793 int i, err;
10794 s32 prev = S32_MIN;
d6dc1a38 10795
4a4b8169
AZ
10796 /* Check all values negative and sorted */
10797 for (i = 0; i < n_thresholds; i++) {
10798 if (thresholds[i] > 0 || thresholds[i] <= prev)
10799 return -EINVAL;
d6dc1a38 10800
4a4b8169
AZ
10801 prev = thresholds[i];
10802 }
d6dc1a38 10803
074ac8df 10804 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
10805 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
10806 return -EOPNOTSUPP;
d6dc1a38 10807
4a4b8169
AZ
10808 wdev_lock(wdev);
10809 cfg80211_cqm_config_free(wdev);
10810 wdev_unlock(wdev);
10811
10812 if (n_thresholds <= 1 && rdev->ops->set_cqm_rssi_config) {
10813 if (n_thresholds == 0 || thresholds[0] == 0) /* Disabling */
10814 return rdev_set_cqm_rssi_config(rdev, dev, 0, 0);
10815
10816 return rdev_set_cqm_rssi_config(rdev, dev,
10817 thresholds[0], hysteresis);
10818 }
10819
10820 if (!wiphy_ext_feature_isset(&rdev->wiphy,
10821 NL80211_EXT_FEATURE_CQM_RSSI_LIST))
10822 return -EOPNOTSUPP;
10823
10824 if (n_thresholds == 1 && thresholds[0] == 0) /* Disabling */
10825 n_thresholds = 0;
10826
10827 wdev_lock(wdev);
10828 if (n_thresholds) {
10829 struct cfg80211_cqm_config *cqm_config;
10830
10831 cqm_config = kzalloc(sizeof(struct cfg80211_cqm_config) +
10832 n_thresholds * sizeof(s32), GFP_KERNEL);
10833 if (!cqm_config) {
10834 err = -ENOMEM;
10835 goto unlock;
10836 }
10837
10838 cqm_config->rssi_hyst = hysteresis;
10839 cqm_config->n_rssi_thresholds = n_thresholds;
10840 memcpy(cqm_config->rssi_thresholds, thresholds,
10841 n_thresholds * sizeof(s32));
10842
10843 wdev->cqm_config = cqm_config;
10844 }
10845
10846 err = cfg80211_cqm_rssi_update(rdev, dev);
10847
10848unlock:
10849 wdev_unlock(wdev);
10850
10851 return err;
d6dc1a38
JO
10852}
10853
10854static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
10855{
10856 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
10857 struct nlattr *cqm;
10858 int err;
10859
10860 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
10861 if (!cqm)
10862 return -EINVAL;
d6dc1a38 10863
8cb08174
JB
10864 err = nla_parse_nested_deprecated(attrs, NL80211_ATTR_CQM_MAX, cqm,
10865 nl80211_attr_cqm_policy,
10866 info->extack);
d6dc1a38 10867 if (err)
1da5fcc8 10868 return err;
d6dc1a38
JO
10869
10870 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
10871 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4a4b8169
AZ
10872 const s32 *thresholds =
10873 nla_data(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
10874 int len = nla_len(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
1da5fcc8 10875 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 10876
4a4b8169
AZ
10877 if (len % 4)
10878 return -EINVAL;
10879
10880 return nl80211_set_cqm_rssi(info, thresholds, len / 4,
10881 hysteresis);
1da5fcc8
JB
10882 }
10883
10884 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
10885 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
10886 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
10887 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
10888 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
10889 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
10890
10891 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
10892 }
10893
10894 return -EINVAL;
d6dc1a38
JO
10895}
10896
6e0bd6c3
RL
10897static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
10898{
10899 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10900 struct net_device *dev = info->user_ptr[1];
10901 struct ocb_setup setup = {};
10902 int err;
10903
10904 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
10905 if (err)
10906 return err;
10907
10908 return cfg80211_join_ocb(rdev, dev, &setup);
10909}
10910
10911static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info)
10912{
10913 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10914 struct net_device *dev = info->user_ptr[1];
10915
10916 return cfg80211_leave_ocb(rdev, dev);
10917}
10918
29cbe68c
JB
10919static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
10920{
10921 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10922 struct net_device *dev = info->user_ptr[1];
10923 struct mesh_config cfg;
c80d545d 10924 struct mesh_setup setup;
29cbe68c
JB
10925 int err;
10926
10927 /* start with default */
10928 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 10929 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 10930
24bdd9f4 10931 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 10932 /* and parse parameters if given */
24bdd9f4 10933 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
10934 if (err)
10935 return err;
10936 }
10937
10938 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
10939 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
10940 return -EINVAL;
10941
c80d545d
JC
10942 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
10943 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
10944
4bb62344
CYY
10945 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
10946 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
10947 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
10948 return -EINVAL;
10949
9bdbf04d
MP
10950 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
10951 setup.beacon_interval =
10952 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 10953
0c317a02
PK
10954 err = cfg80211_validate_beacon_int(rdev,
10955 NL80211_IFTYPE_MESH_POINT,
10956 setup.beacon_interval);
12d20fc9
PK
10957 if (err)
10958 return err;
9bdbf04d
MP
10959 }
10960
10961 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
10962 setup.dtim_period =
10963 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
10964 if (setup.dtim_period < 1 || setup.dtim_period > 100)
10965 return -EINVAL;
10966 }
10967
c80d545d
JC
10968 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
10969 /* parse additional setup parameters if given */
10970 err = nl80211_parse_mesh_setup(info, &setup);
10971 if (err)
10972 return err;
10973 }
10974
d37bb18a
TP
10975 if (setup.user_mpm)
10976 cfg.auto_open_plinks = false;
10977
cc1d2806 10978 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
10979 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
10980 if (err)
10981 return err;
cc1d2806 10982 } else {
188c1b3c 10983 /* __cfg80211_join_mesh() will sort it out */
683b6d3b 10984 setup.chandef.chan = NULL;
cc1d2806
JB
10985 }
10986
ffb3cf30
AN
10987 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
10988 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
10989 int n_rates =
10990 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
10991 struct ieee80211_supported_band *sband;
10992
10993 if (!setup.chandef.chan)
10994 return -EINVAL;
10995
10996 sband = rdev->wiphy.bands[setup.chandef.chan->band];
10997
10998 err = ieee80211_get_ratemask(sband, rates, n_rates,
10999 &setup.basic_rates);
11000 if (err)
11001 return err;
11002 }
11003
8564e382
JB
11004 if (info->attrs[NL80211_ATTR_TX_RATES]) {
11005 err = nl80211_parse_tx_bitrate_mask(info, &setup.beacon_rate);
11006 if (err)
11007 return err;
11008
265698d7
JB
11009 if (!setup.chandef.chan)
11010 return -EINVAL;
11011
8564e382
JB
11012 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band,
11013 &setup.beacon_rate);
11014 if (err)
11015 return err;
11016 }
11017
d37d49c2
BB
11018 setup.userspace_handles_dfs =
11019 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
11020
1224f583
DK
11021 if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
11022 int r = validate_pae_over_nl80211(rdev, info);
11023
11024 if (r < 0)
11025 return r;
11026
11027 setup.control_port_over_nl80211 = true;
11028 }
11029
188c1b3c
DK
11030 wdev_lock(dev->ieee80211_ptr);
11031 err = __cfg80211_join_mesh(rdev, dev, &setup, &cfg);
11032 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER])
11033 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
11034 wdev_unlock(dev->ieee80211_ptr);
11035
11036 return err;
29cbe68c
JB
11037}
11038
11039static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
11040{
11041 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11042 struct net_device *dev = info->user_ptr[1];
11043
11044 return cfg80211_leave_mesh(rdev, dev);
11045}
11046
dfb89c56 11047#ifdef CONFIG_PM
bb92d199
AK
11048static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
11049 struct cfg80211_registered_device *rdev)
11050{
6abb9cb9 11051 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
11052 struct nlattr *nl_pats, *nl_pat;
11053 int i, pat_len;
11054
6abb9cb9 11055 if (!wowlan->n_patterns)
bb92d199
AK
11056 return 0;
11057
ae0be8de 11058 nl_pats = nla_nest_start_noflag(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
bb92d199
AK
11059 if (!nl_pats)
11060 return -ENOBUFS;
11061
6abb9cb9 11062 for (i = 0; i < wowlan->n_patterns; i++) {
ae0be8de 11063 nl_pat = nla_nest_start_noflag(msg, i + 1);
bb92d199
AK
11064 if (!nl_pat)
11065 return -ENOBUFS;
6abb9cb9 11066 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 11067 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 11068 wowlan->patterns[i].mask) ||
50ac6607
AK
11069 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
11070 wowlan->patterns[i].pattern) ||
11071 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 11072 wowlan->patterns[i].pkt_offset))
bb92d199
AK
11073 return -ENOBUFS;
11074 nla_nest_end(msg, nl_pat);
11075 }
11076 nla_nest_end(msg, nl_pats);
11077
11078 return 0;
11079}
11080
2a0e047e
JB
11081static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
11082 struct cfg80211_wowlan_tcp *tcp)
11083{
11084 struct nlattr *nl_tcp;
11085
11086 if (!tcp)
11087 return 0;
11088
ae0be8de
MK
11089 nl_tcp = nla_nest_start_noflag(msg,
11090 NL80211_WOWLAN_TRIG_TCP_CONNECTION);
2a0e047e
JB
11091 if (!nl_tcp)
11092 return -ENOBUFS;
11093
930345ea
JB
11094 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
11095 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
2a0e047e
JB
11096 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
11097 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
11098 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
11099 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
11100 tcp->payload_len, tcp->payload) ||
11101 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
11102 tcp->data_interval) ||
11103 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
11104 tcp->wake_len, tcp->wake_data) ||
11105 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
11106 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
11107 return -ENOBUFS;
11108
11109 if (tcp->payload_seq.len &&
11110 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
11111 sizeof(tcp->payload_seq), &tcp->payload_seq))
11112 return -ENOBUFS;
11113
11114 if (tcp->payload_tok.len &&
11115 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
11116 sizeof(tcp->payload_tok) + tcp->tokens_size,
11117 &tcp->payload_tok))
11118 return -ENOBUFS;
11119
e248ad30
JB
11120 nla_nest_end(msg, nl_tcp);
11121
2a0e047e
JB
11122 return 0;
11123}
11124
75453ccb
LC
11125static int nl80211_send_wowlan_nd(struct sk_buff *msg,
11126 struct cfg80211_sched_scan_request *req)
11127{
3b06d277 11128 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan;
75453ccb
LC
11129 int i;
11130
11131 if (!req)
11132 return 0;
11133
ae0be8de 11134 nd = nla_nest_start_noflag(msg, NL80211_WOWLAN_TRIG_NET_DETECT);
75453ccb
LC
11135 if (!nd)
11136 return -ENOBUFS;
11137
3b06d277
AS
11138 if (req->n_scan_plans == 1 &&
11139 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL,
11140 req->scan_plans[0].interval * 1000))
75453ccb
LC
11141 return -ENOBUFS;
11142
21fea567
LC
11143 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay))
11144 return -ENOBUFS;
11145
bf95ecdb 11146 if (req->relative_rssi_set) {
11147 struct nl80211_bss_select_rssi_adjust rssi_adjust;
11148
11149 if (nla_put_s8(msg, NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI,
11150 req->relative_rssi))
11151 return -ENOBUFS;
11152
11153 rssi_adjust.band = req->rssi_adjust.band;
11154 rssi_adjust.delta = req->rssi_adjust.delta;
11155 if (nla_put(msg, NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST,
11156 sizeof(rssi_adjust), &rssi_adjust))
11157 return -ENOBUFS;
11158 }
11159
ae0be8de 11160 freqs = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_FREQUENCIES);
75453ccb
LC
11161 if (!freqs)
11162 return -ENOBUFS;
11163
53b18980
JB
11164 for (i = 0; i < req->n_channels; i++) {
11165 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
11166 return -ENOBUFS;
11167 }
75453ccb
LC
11168
11169 nla_nest_end(msg, freqs);
11170
11171 if (req->n_match_sets) {
ae0be8de
MK
11172 matches = nla_nest_start_noflag(msg,
11173 NL80211_ATTR_SCHED_SCAN_MATCH);
76e1fb4b
JB
11174 if (!matches)
11175 return -ENOBUFS;
11176
75453ccb 11177 for (i = 0; i < req->n_match_sets; i++) {
ae0be8de 11178 match = nla_nest_start_noflag(msg, i);
76e1fb4b
JB
11179 if (!match)
11180 return -ENOBUFS;
11181
53b18980
JB
11182 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID,
11183 req->match_sets[i].ssid.ssid_len,
11184 req->match_sets[i].ssid.ssid))
11185 return -ENOBUFS;
75453ccb
LC
11186 nla_nest_end(msg, match);
11187 }
11188 nla_nest_end(msg, matches);
11189 }
11190
ae0be8de 11191 scan_plans = nla_nest_start_noflag(msg, NL80211_ATTR_SCHED_SCAN_PLANS);
3b06d277
AS
11192 if (!scan_plans)
11193 return -ENOBUFS;
11194
11195 for (i = 0; i < req->n_scan_plans; i++) {
ae0be8de 11196 scan_plan = nla_nest_start_noflag(msg, i + 1);
76e1fb4b
JB
11197 if (!scan_plan)
11198 return -ENOBUFS;
11199
67626964 11200 if (nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL,
3b06d277
AS
11201 req->scan_plans[i].interval) ||
11202 (req->scan_plans[i].iterations &&
11203 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS,
11204 req->scan_plans[i].iterations)))
11205 return -ENOBUFS;
11206 nla_nest_end(msg, scan_plan);
11207 }
11208 nla_nest_end(msg, scan_plans);
11209
75453ccb
LC
11210 nla_nest_end(msg, nd);
11211
11212 return 0;
11213}
11214
ff1b6e69
JB
11215static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
11216{
11217 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11218 struct sk_buff *msg;
11219 void *hdr;
2a0e047e 11220 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 11221
964dc9e2 11222 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
11223 return -EOPNOTSUPP;
11224
6abb9cb9 11225 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 11226 /* adjust size to have room for all the data */
6abb9cb9
JB
11227 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
11228 rdev->wiphy.wowlan_config->tcp->payload_len +
11229 rdev->wiphy.wowlan_config->tcp->wake_len +
11230 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
11231 }
11232
11233 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
11234 if (!msg)
11235 return -ENOMEM;
11236
15e47304 11237 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
11238 NL80211_CMD_GET_WOWLAN);
11239 if (!hdr)
11240 goto nla_put_failure;
11241
6abb9cb9 11242 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
11243 struct nlattr *nl_wowlan;
11244
ae0be8de
MK
11245 nl_wowlan = nla_nest_start_noflag(msg,
11246 NL80211_ATTR_WOWLAN_TRIGGERS);
ff1b6e69
JB
11247 if (!nl_wowlan)
11248 goto nla_put_failure;
11249
6abb9cb9 11250 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 11251 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 11252 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 11253 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 11254 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 11255 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 11256 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 11257 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 11258 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 11259 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 11260 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 11261 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 11262 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
11263 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
11264 goto nla_put_failure;
2a0e047e 11265
bb92d199
AK
11266 if (nl80211_send_wowlan_patterns(msg, rdev))
11267 goto nla_put_failure;
2a0e047e 11268
6abb9cb9
JB
11269 if (nl80211_send_wowlan_tcp(msg,
11270 rdev->wiphy.wowlan_config->tcp))
2a0e047e 11271 goto nla_put_failure;
75453ccb
LC
11272
11273 if (nl80211_send_wowlan_nd(
11274 msg,
11275 rdev->wiphy.wowlan_config->nd_config))
11276 goto nla_put_failure;
2a0e047e 11277
ff1b6e69
JB
11278 nla_nest_end(msg, nl_wowlan);
11279 }
11280
11281 genlmsg_end(msg, hdr);
11282 return genlmsg_reply(msg, info);
11283
11284nla_put_failure:
11285 nlmsg_free(msg);
11286 return -ENOBUFS;
11287}
11288
2a0e047e
JB
11289static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
11290 struct nlattr *attr,
11291 struct cfg80211_wowlan *trig)
11292{
11293 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
11294 struct cfg80211_wowlan_tcp *cfg;
11295 struct nl80211_wowlan_tcp_data_token *tok = NULL;
11296 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
11297 u32 size;
11298 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
11299 int err, port;
11300
964dc9e2 11301 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
11302 return -EINVAL;
11303
8cb08174
JB
11304 err = nla_parse_nested_deprecated(tb, MAX_NL80211_WOWLAN_TCP, attr,
11305 nl80211_wowlan_tcp_policy, NULL);
2a0e047e
JB
11306 if (err)
11307 return err;
11308
11309 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
11310 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
11311 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
11312 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
11313 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
11314 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
11315 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
11316 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
11317 return -EINVAL;
11318
11319 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 11320 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
11321 return -EINVAL;
11322
11323 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 11324 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 11325 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
11326 return -EINVAL;
11327
11328 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 11329 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
11330 return -EINVAL;
11331
11332 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
11333 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
11334 return -EINVAL;
11335
11336 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
11337 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
11338
11339 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
11340 tokens_size = tokln - sizeof(*tok);
11341
11342 if (!tok->len || tokens_size % tok->len)
11343 return -EINVAL;
964dc9e2 11344 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 11345 return -EINVAL;
964dc9e2 11346 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 11347 return -EINVAL;
964dc9e2 11348 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 11349 return -EINVAL;
964dc9e2 11350 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
11351 return -EINVAL;
11352 if (tok->offset + tok->len > data_size)
11353 return -EINVAL;
11354 }
11355
11356 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
11357 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 11358 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
11359 return -EINVAL;
11360 if (seq->len == 0 || seq->len > 4)
11361 return -EINVAL;
11362 if (seq->len + seq->offset > data_size)
11363 return -EINVAL;
11364 }
11365
11366 size = sizeof(*cfg);
11367 size += data_size;
11368 size += wake_size + wake_mask_size;
11369 size += tokens_size;
11370
11371 cfg = kzalloc(size, GFP_KERNEL);
11372 if (!cfg)
11373 return -ENOMEM;
67b61f6c
JB
11374 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
11375 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
2a0e047e
JB
11376 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
11377 ETH_ALEN);
11378 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
11379 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
11380 else
11381 port = 0;
11382#ifdef CONFIG_INET
11383 /* allocate a socket and port for it and use it */
11384 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
11385 IPPROTO_TCP, &cfg->sock, 1);
11386 if (err) {
11387 kfree(cfg);
11388 return err;
11389 }
11390 if (inet_csk_get_port(cfg->sock->sk, port)) {
11391 sock_release(cfg->sock);
11392 kfree(cfg);
11393 return -EADDRINUSE;
11394 }
11395 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
11396#else
11397 if (!port) {
11398 kfree(cfg);
11399 return -EINVAL;
11400 }
11401 cfg->src_port = port;
11402#endif
11403
11404 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
11405 cfg->payload_len = data_size;
11406 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
11407 memcpy((void *)cfg->payload,
11408 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
11409 data_size);
11410 if (seq)
11411 cfg->payload_seq = *seq;
11412 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
11413 cfg->wake_len = wake_size;
11414 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
11415 memcpy((void *)cfg->wake_data,
11416 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
11417 wake_size);
11418 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
11419 data_size + wake_size;
11420 memcpy((void *)cfg->wake_mask,
11421 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
11422 wake_mask_size);
11423 if (tok) {
11424 cfg->tokens_size = tokens_size;
11425 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
11426 }
11427
11428 trig->tcp = cfg;
11429
11430 return 0;
11431}
11432
8cd4d456
LC
11433static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev,
11434 const struct wiphy_wowlan_support *wowlan,
11435 struct nlattr *attr,
11436 struct cfg80211_wowlan *trig)
11437{
11438 struct nlattr **tb;
11439 int err;
11440
6396bb22 11441 tb = kcalloc(NUM_NL80211_ATTR, sizeof(*tb), GFP_KERNEL);
8cd4d456
LC
11442 if (!tb)
11443 return -ENOMEM;
11444
11445 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) {
11446 err = -EOPNOTSUPP;
11447 goto out;
11448 }
11449
8cb08174
JB
11450 err = nla_parse_nested_deprecated(tb, NL80211_ATTR_MAX, attr,
11451 nl80211_policy, NULL);
8cd4d456
LC
11452 if (err)
11453 goto out;
11454
aad1e812
AVS
11455 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb,
11456 wowlan->max_nd_match_sets);
8cd4d456
LC
11457 err = PTR_ERR_OR_ZERO(trig->nd_config);
11458 if (err)
11459 trig->nd_config = NULL;
11460
11461out:
11462 kfree(tb);
11463 return err;
11464}
11465
ff1b6e69
JB
11466static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
11467{
11468 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11469 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 11470 struct cfg80211_wowlan new_triggers = {};
ae33bd81 11471 struct cfg80211_wowlan *ntrig;
964dc9e2 11472 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 11473 int err, i;
6abb9cb9 11474 bool prev_enabled = rdev->wiphy.wowlan_config;
98fc4386 11475 bool regular = false;
ff1b6e69 11476
964dc9e2 11477 if (!wowlan)
ff1b6e69
JB
11478 return -EOPNOTSUPP;
11479
ae33bd81
JB
11480 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
11481 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 11482 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
11483 goto set_wakeup;
11484 }
ff1b6e69 11485
8cb08174
JB
11486 err = nla_parse_nested_deprecated(tb, MAX_NL80211_WOWLAN_TRIG,
11487 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS],
11488 nl80211_wowlan_policy, info->extack);
ff1b6e69
JB
11489 if (err)
11490 return err;
11491
11492 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
11493 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
11494 return -EINVAL;
11495 new_triggers.any = true;
11496 }
11497
11498 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
11499 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
11500 return -EINVAL;
11501 new_triggers.disconnect = true;
98fc4386 11502 regular = true;
ff1b6e69
JB
11503 }
11504
11505 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
11506 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
11507 return -EINVAL;
11508 new_triggers.magic_pkt = true;
98fc4386 11509 regular = true;
ff1b6e69
JB
11510 }
11511
77dbbb13
JB
11512 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
11513 return -EINVAL;
11514
11515 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
11516 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
11517 return -EINVAL;
11518 new_triggers.gtk_rekey_failure = true;
98fc4386 11519 regular = true;
77dbbb13
JB
11520 }
11521
11522 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
11523 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
11524 return -EINVAL;
11525 new_triggers.eap_identity_req = true;
98fc4386 11526 regular = true;
77dbbb13
JB
11527 }
11528
11529 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
11530 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
11531 return -EINVAL;
11532 new_triggers.four_way_handshake = true;
98fc4386 11533 regular = true;
77dbbb13
JB
11534 }
11535
11536 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
11537 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
11538 return -EINVAL;
11539 new_triggers.rfkill_release = true;
98fc4386 11540 regular = true;
77dbbb13
JB
11541 }
11542
ff1b6e69
JB
11543 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
11544 struct nlattr *pat;
11545 int n_patterns = 0;
bb92d199 11546 int rem, pat_len, mask_len, pkt_offset;
50ac6607 11547 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69 11548
98fc4386
JB
11549 regular = true;
11550
ff1b6e69
JB
11551 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
11552 rem)
11553 n_patterns++;
11554 if (n_patterns > wowlan->n_patterns)
11555 return -EINVAL;
11556
11557 new_triggers.patterns = kcalloc(n_patterns,
11558 sizeof(new_triggers.patterns[0]),
11559 GFP_KERNEL);
11560 if (!new_triggers.patterns)
11561 return -ENOMEM;
11562
11563 new_triggers.n_patterns = n_patterns;
11564 i = 0;
11565
11566 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
11567 rem) {
922bd80f
JB
11568 u8 *mask_pat;
11569
8cb08174
JB
11570 err = nla_parse_nested_deprecated(pat_tb,
11571 MAX_NL80211_PKTPAT,
11572 pat,
11573 nl80211_packet_pattern_policy,
11574 info->extack);
95bca62f
JB
11575 if (err)
11576 goto error;
11577
ff1b6e69 11578 err = -EINVAL;
50ac6607
AK
11579 if (!pat_tb[NL80211_PKTPAT_MASK] ||
11580 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 11581 goto error;
50ac6607 11582 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 11583 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 11584 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
11585 goto error;
11586 if (pat_len > wowlan->pattern_max_len ||
11587 pat_len < wowlan->pattern_min_len)
11588 goto error;
11589
50ac6607 11590 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
11591 pkt_offset = 0;
11592 else
11593 pkt_offset = nla_get_u32(
50ac6607 11594 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
11595 if (pkt_offset > wowlan->max_pkt_offset)
11596 goto error;
11597 new_triggers.patterns[i].pkt_offset = pkt_offset;
11598
922bd80f
JB
11599 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
11600 if (!mask_pat) {
ff1b6e69
JB
11601 err = -ENOMEM;
11602 goto error;
11603 }
922bd80f
JB
11604 new_triggers.patterns[i].mask = mask_pat;
11605 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69 11606 mask_len);
922bd80f
JB
11607 mask_pat += mask_len;
11608 new_triggers.patterns[i].pattern = mask_pat;
ff1b6e69 11609 new_triggers.patterns[i].pattern_len = pat_len;
922bd80f 11610 memcpy(mask_pat,
50ac6607 11611 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
11612 pat_len);
11613 i++;
11614 }
11615 }
11616
2a0e047e 11617 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
98fc4386 11618 regular = true;
2a0e047e
JB
11619 err = nl80211_parse_wowlan_tcp(
11620 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
11621 &new_triggers);
11622 if (err)
11623 goto error;
11624 }
11625
8cd4d456 11626 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) {
98fc4386 11627 regular = true;
8cd4d456
LC
11628 err = nl80211_parse_wowlan_nd(
11629 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT],
11630 &new_triggers);
11631 if (err)
11632 goto error;
11633 }
11634
98fc4386
JB
11635 /* The 'any' trigger means the device continues operating more or less
11636 * as in its normal operation mode and wakes up the host on most of the
11637 * normal interrupts (like packet RX, ...)
11638 * It therefore makes little sense to combine with the more constrained
11639 * wakeup trigger modes.
11640 */
11641 if (new_triggers.any && regular) {
11642 err = -EINVAL;
11643 goto error;
11644 }
11645
ae33bd81
JB
11646 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
11647 if (!ntrig) {
11648 err = -ENOMEM;
11649 goto error;
ff1b6e69 11650 }
ae33bd81 11651 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 11652 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 11653
ae33bd81 11654 set_wakeup:
6abb9cb9
JB
11655 if (rdev->ops->set_wakeup &&
11656 prev_enabled != !!rdev->wiphy.wowlan_config)
11657 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 11658
ff1b6e69
JB
11659 return 0;
11660 error:
11661 for (i = 0; i < new_triggers.n_patterns; i++)
11662 kfree(new_triggers.patterns[i].mask);
11663 kfree(new_triggers.patterns);
2a0e047e
JB
11664 if (new_triggers.tcp && new_triggers.tcp->sock)
11665 sock_release(new_triggers.tcp->sock);
11666 kfree(new_triggers.tcp);
e5dbe070 11667 kfree(new_triggers.nd_config);
ff1b6e69
JB
11668 return err;
11669}
dfb89c56 11670#endif
ff1b6e69 11671
be29b99a
AK
11672static int nl80211_send_coalesce_rules(struct sk_buff *msg,
11673 struct cfg80211_registered_device *rdev)
11674{
11675 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
11676 int i, j, pat_len;
11677 struct cfg80211_coalesce_rules *rule;
11678
11679 if (!rdev->coalesce->n_rules)
11680 return 0;
11681
ae0be8de 11682 nl_rules = nla_nest_start_noflag(msg, NL80211_ATTR_COALESCE_RULE);
be29b99a
AK
11683 if (!nl_rules)
11684 return -ENOBUFS;
11685
11686 for (i = 0; i < rdev->coalesce->n_rules; i++) {
ae0be8de 11687 nl_rule = nla_nest_start_noflag(msg, i + 1);
be29b99a
AK
11688 if (!nl_rule)
11689 return -ENOBUFS;
11690
11691 rule = &rdev->coalesce->rules[i];
11692 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
11693 rule->delay))
11694 return -ENOBUFS;
11695
11696 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
11697 rule->condition))
11698 return -ENOBUFS;
11699
ae0be8de
MK
11700 nl_pats = nla_nest_start_noflag(msg,
11701 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
be29b99a
AK
11702 if (!nl_pats)
11703 return -ENOBUFS;
11704
11705 for (j = 0; j < rule->n_patterns; j++) {
ae0be8de 11706 nl_pat = nla_nest_start_noflag(msg, j + 1);
be29b99a
AK
11707 if (!nl_pat)
11708 return -ENOBUFS;
11709 pat_len = rule->patterns[j].pattern_len;
11710 if (nla_put(msg, NL80211_PKTPAT_MASK,
11711 DIV_ROUND_UP(pat_len, 8),
11712 rule->patterns[j].mask) ||
11713 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
11714 rule->patterns[j].pattern) ||
11715 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
11716 rule->patterns[j].pkt_offset))
11717 return -ENOBUFS;
11718 nla_nest_end(msg, nl_pat);
11719 }
11720 nla_nest_end(msg, nl_pats);
11721 nla_nest_end(msg, nl_rule);
11722 }
11723 nla_nest_end(msg, nl_rules);
11724
11725 return 0;
11726}
11727
11728static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
11729{
11730 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11731 struct sk_buff *msg;
11732 void *hdr;
11733
11734 if (!rdev->wiphy.coalesce)
11735 return -EOPNOTSUPP;
11736
11737 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11738 if (!msg)
11739 return -ENOMEM;
11740
11741 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
11742 NL80211_CMD_GET_COALESCE);
11743 if (!hdr)
11744 goto nla_put_failure;
11745
11746 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
11747 goto nla_put_failure;
11748
11749 genlmsg_end(msg, hdr);
11750 return genlmsg_reply(msg, info);
11751
11752nla_put_failure:
11753 nlmsg_free(msg);
11754 return -ENOBUFS;
11755}
11756
11757void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
11758{
11759 struct cfg80211_coalesce *coalesce = rdev->coalesce;
11760 int i, j;
11761 struct cfg80211_coalesce_rules *rule;
11762
11763 if (!coalesce)
11764 return;
11765
11766 for (i = 0; i < coalesce->n_rules; i++) {
11767 rule = &coalesce->rules[i];
11768 for (j = 0; j < rule->n_patterns; j++)
11769 kfree(rule->patterns[j].mask);
11770 kfree(rule->patterns);
11771 }
11772 kfree(coalesce->rules);
11773 kfree(coalesce);
11774 rdev->coalesce = NULL;
11775}
11776
11777static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
11778 struct nlattr *rule,
11779 struct cfg80211_coalesce_rules *new_rule)
11780{
11781 int err, i;
11782 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
11783 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
11784 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
11785 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
11786
8cb08174
JB
11787 err = nla_parse_nested_deprecated(tb, NL80211_ATTR_COALESCE_RULE_MAX,
11788 rule, nl80211_coalesce_policy, NULL);
be29b99a
AK
11789 if (err)
11790 return err;
11791
11792 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
11793 new_rule->delay =
11794 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
11795 if (new_rule->delay > coalesce->max_delay)
11796 return -EINVAL;
11797
11798 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
11799 new_rule->condition =
11800 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
be29b99a
AK
11801
11802 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
11803 return -EINVAL;
11804
11805 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
11806 rem)
11807 n_patterns++;
11808 if (n_patterns > coalesce->n_patterns)
11809 return -EINVAL;
11810
11811 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
11812 GFP_KERNEL);
11813 if (!new_rule->patterns)
11814 return -ENOMEM;
11815
11816 new_rule->n_patterns = n_patterns;
11817 i = 0;
11818
11819 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
11820 rem) {
922bd80f
JB
11821 u8 *mask_pat;
11822
8cb08174
JB
11823 err = nla_parse_nested_deprecated(pat_tb, MAX_NL80211_PKTPAT,
11824 pat,
11825 nl80211_packet_pattern_policy,
11826 NULL);
95bca62f
JB
11827 if (err)
11828 return err;
11829
be29b99a
AK
11830 if (!pat_tb[NL80211_PKTPAT_MASK] ||
11831 !pat_tb[NL80211_PKTPAT_PATTERN])
11832 return -EINVAL;
11833 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
11834 mask_len = DIV_ROUND_UP(pat_len, 8);
11835 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
11836 return -EINVAL;
11837 if (pat_len > coalesce->pattern_max_len ||
11838 pat_len < coalesce->pattern_min_len)
11839 return -EINVAL;
11840
11841 if (!pat_tb[NL80211_PKTPAT_OFFSET])
11842 pkt_offset = 0;
11843 else
11844 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
11845 if (pkt_offset > coalesce->max_pkt_offset)
11846 return -EINVAL;
11847 new_rule->patterns[i].pkt_offset = pkt_offset;
11848
922bd80f
JB
11849 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
11850 if (!mask_pat)
be29b99a 11851 return -ENOMEM;
922bd80f
JB
11852
11853 new_rule->patterns[i].mask = mask_pat;
11854 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
11855 mask_len);
11856
11857 mask_pat += mask_len;
11858 new_rule->patterns[i].pattern = mask_pat;
be29b99a 11859 new_rule->patterns[i].pattern_len = pat_len;
922bd80f
JB
11860 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
11861 pat_len);
be29b99a
AK
11862 i++;
11863 }
11864
11865 return 0;
11866}
11867
11868static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
11869{
11870 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11871 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
11872 struct cfg80211_coalesce new_coalesce = {};
11873 struct cfg80211_coalesce *n_coalesce;
11874 int err, rem_rule, n_rules = 0, i, j;
11875 struct nlattr *rule;
11876 struct cfg80211_coalesce_rules *tmp_rule;
11877
11878 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
11879 return -EOPNOTSUPP;
11880
11881 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
11882 cfg80211_rdev_free_coalesce(rdev);
a1056b1b 11883 rdev_set_coalesce(rdev, NULL);
be29b99a
AK
11884 return 0;
11885 }
11886
11887 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
11888 rem_rule)
11889 n_rules++;
11890 if (n_rules > coalesce->n_rules)
11891 return -EINVAL;
11892
11893 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
11894 GFP_KERNEL);
11895 if (!new_coalesce.rules)
11896 return -ENOMEM;
11897
11898 new_coalesce.n_rules = n_rules;
11899 i = 0;
11900
11901 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
11902 rem_rule) {
11903 err = nl80211_parse_coalesce_rule(rdev, rule,
11904 &new_coalesce.rules[i]);
11905 if (err)
11906 goto error;
11907
11908 i++;
11909 }
11910
a1056b1b 11911 err = rdev_set_coalesce(rdev, &new_coalesce);
be29b99a
AK
11912 if (err)
11913 goto error;
11914
11915 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
11916 if (!n_coalesce) {
11917 err = -ENOMEM;
11918 goto error;
11919 }
11920 cfg80211_rdev_free_coalesce(rdev);
11921 rdev->coalesce = n_coalesce;
11922
11923 return 0;
11924error:
11925 for (i = 0; i < new_coalesce.n_rules; i++) {
11926 tmp_rule = &new_coalesce.rules[i];
11927 for (j = 0; j < tmp_rule->n_patterns; j++)
11928 kfree(tmp_rule->patterns[j].mask);
11929 kfree(tmp_rule->patterns);
11930 }
11931 kfree(new_coalesce.rules);
11932
11933 return err;
11934}
11935
e5497d76
JB
11936static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
11937{
11938 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11939 struct net_device *dev = info->user_ptr[1];
11940 struct wireless_dev *wdev = dev->ieee80211_ptr;
11941 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
11942 struct cfg80211_gtk_rekey_data rekey_data;
11943 int err;
11944
11945 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
11946 return -EINVAL;
11947
8cb08174
JB
11948 err = nla_parse_nested_deprecated(tb, MAX_NL80211_REKEY_DATA,
11949 info->attrs[NL80211_ATTR_REKEY_DATA],
11950 nl80211_rekey_policy, info->extack);
e5497d76
JB
11951 if (err)
11952 return err;
11953
e785fa0a
VD
11954 if (!tb[NL80211_REKEY_DATA_REPLAY_CTR] || !tb[NL80211_REKEY_DATA_KEK] ||
11955 !tb[NL80211_REKEY_DATA_KCK])
11956 return -EINVAL;
e5497d76
JB
11957 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
11958 return -ERANGE;
11959 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
11960 return -ERANGE;
11961 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
11962 return -ERANGE;
11963
78f686ca
JB
11964 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]);
11965 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]);
11966 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]);
e5497d76
JB
11967
11968 wdev_lock(wdev);
11969 if (!wdev->current_bss) {
11970 err = -ENOTCONN;
11971 goto out;
11972 }
11973
11974 if (!rdev->ops->set_rekey_data) {
11975 err = -EOPNOTSUPP;
11976 goto out;
11977 }
11978
e35e4d28 11979 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
11980 out:
11981 wdev_unlock(wdev);
11982 return err;
11983}
11984
28946da7
JB
11985static int nl80211_register_unexpected_frame(struct sk_buff *skb,
11986 struct genl_info *info)
11987{
11988 struct net_device *dev = info->user_ptr[1];
11989 struct wireless_dev *wdev = dev->ieee80211_ptr;
11990
11991 if (wdev->iftype != NL80211_IFTYPE_AP &&
11992 wdev->iftype != NL80211_IFTYPE_P2P_GO)
11993 return -EINVAL;
11994
15e47304 11995 if (wdev->ap_unexpected_nlportid)
28946da7
JB
11996 return -EBUSY;
11997
15e47304 11998 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
11999 return 0;
12000}
12001
7f6cf311
JB
12002static int nl80211_probe_client(struct sk_buff *skb,
12003 struct genl_info *info)
12004{
12005 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12006 struct net_device *dev = info->user_ptr[1];
12007 struct wireless_dev *wdev = dev->ieee80211_ptr;
12008 struct sk_buff *msg;
12009 void *hdr;
12010 const u8 *addr;
12011 u64 cookie;
12012 int err;
12013
12014 if (wdev->iftype != NL80211_IFTYPE_AP &&
12015 wdev->iftype != NL80211_IFTYPE_P2P_GO)
12016 return -EOPNOTSUPP;
12017
12018 if (!info->attrs[NL80211_ATTR_MAC])
12019 return -EINVAL;
12020
12021 if (!rdev->ops->probe_client)
12022 return -EOPNOTSUPP;
12023
12024 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12025 if (!msg)
12026 return -ENOMEM;
12027
15e47304 12028 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 12029 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
12030 if (!hdr) {
12031 err = -ENOBUFS;
7f6cf311
JB
12032 goto free_msg;
12033 }
12034
12035 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
12036
e35e4d28 12037 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
12038 if (err)
12039 goto free_msg;
12040
2dad624e
ND
12041 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
12042 NL80211_ATTR_PAD))
9360ffd1 12043 goto nla_put_failure;
7f6cf311
JB
12044
12045 genlmsg_end(msg, hdr);
12046
12047 return genlmsg_reply(msg, info);
12048
12049 nla_put_failure:
12050 err = -ENOBUFS;
12051 free_msg:
12052 nlmsg_free(msg);
12053 return err;
12054}
12055
5e760230
JB
12056static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
12057{
12058 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
12059 struct cfg80211_beacon_registration *reg, *nreg;
12060 int rv;
5e760230
JB
12061
12062 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
12063 return -EOPNOTSUPP;
12064
37c73b5f
BG
12065 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
12066 if (!nreg)
12067 return -ENOMEM;
12068
12069 /* First, check if already registered. */
12070 spin_lock_bh(&rdev->beacon_registrations_lock);
12071 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
12072 if (reg->nlportid == info->snd_portid) {
12073 rv = -EALREADY;
12074 goto out_err;
12075 }
12076 }
12077 /* Add it to the list */
12078 nreg->nlportid = info->snd_portid;
12079 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 12080
37c73b5f 12081 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
12082
12083 return 0;
37c73b5f
BG
12084out_err:
12085 spin_unlock_bh(&rdev->beacon_registrations_lock);
12086 kfree(nreg);
12087 return rv;
5e760230
JB
12088}
12089
98104fde
JB
12090static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
12091{
12092 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12093 struct wireless_dev *wdev = info->user_ptr[1];
12094 int err;
12095
12096 if (!rdev->ops->start_p2p_device)
12097 return -EOPNOTSUPP;
12098
12099 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
12100 return -EOPNOTSUPP;
12101
73c7da3d 12102 if (wdev_running(wdev))
98104fde
JB
12103 return 0;
12104
b6a55015
LC
12105 if (rfkill_blocked(rdev->rfkill))
12106 return -ERFKILL;
98104fde 12107
eeb126e9 12108 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
12109 if (err)
12110 return err;
12111
73c7da3d 12112 wdev->is_running = true;
98104fde 12113 rdev->opencount++;
98104fde
JB
12114
12115 return 0;
12116}
12117
12118static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
12119{
12120 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12121 struct wireless_dev *wdev = info->user_ptr[1];
12122
12123 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
12124 return -EOPNOTSUPP;
12125
12126 if (!rdev->ops->stop_p2p_device)
12127 return -EOPNOTSUPP;
12128
f9f47529 12129 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
12130
12131 return 0;
12132}
12133
cb3b7d87
AB
12134static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info)
12135{
12136 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12137 struct wireless_dev *wdev = info->user_ptr[1];
12138 struct cfg80211_nan_conf conf = {};
12139 int err;
12140
12141 if (wdev->iftype != NL80211_IFTYPE_NAN)
12142 return -EOPNOTSUPP;
12143
eeb04a96 12144 if (wdev_running(wdev))
cb3b7d87
AB
12145 return -EEXIST;
12146
12147 if (rfkill_blocked(rdev->rfkill))
12148 return -ERFKILL;
12149
12150 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF])
12151 return -EINVAL;
12152
cb3b7d87
AB
12153 conf.master_pref =
12154 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
cb3b7d87 12155
8585989d
LC
12156 if (info->attrs[NL80211_ATTR_BANDS]) {
12157 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
12158
12159 if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
12160 return -EOPNOTSUPP;
12161
12162 if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
12163 return -EINVAL;
12164
12165 conf.bands = bands;
12166 }
cb3b7d87
AB
12167
12168 err = rdev_start_nan(rdev, wdev, &conf);
12169 if (err)
12170 return err;
12171
73c7da3d 12172 wdev->is_running = true;
cb3b7d87
AB
12173 rdev->opencount++;
12174
12175 return 0;
12176}
12177
12178static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info)
12179{
12180 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12181 struct wireless_dev *wdev = info->user_ptr[1];
12182
12183 if (wdev->iftype != NL80211_IFTYPE_NAN)
12184 return -EOPNOTSUPP;
12185
12186 cfg80211_stop_nan(rdev, wdev);
12187
12188 return 0;
12189}
12190
a442b761
AB
12191static int validate_nan_filter(struct nlattr *filter_attr)
12192{
12193 struct nlattr *attr;
12194 int len = 0, n_entries = 0, rem;
12195
12196 nla_for_each_nested(attr, filter_attr, rem) {
12197 len += nla_len(attr);
12198 n_entries++;
12199 }
12200
12201 if (len >= U8_MAX)
12202 return -EINVAL;
12203
12204 return n_entries;
12205}
12206
12207static int handle_nan_filter(struct nlattr *attr_filter,
12208 struct cfg80211_nan_func *func,
12209 bool tx)
12210{
12211 struct nlattr *attr;
12212 int n_entries, rem, i;
12213 struct cfg80211_nan_func_filter *filter;
12214
12215 n_entries = validate_nan_filter(attr_filter);
12216 if (n_entries < 0)
12217 return n_entries;
12218
12219 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters));
12220
12221 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL);
12222 if (!filter)
12223 return -ENOMEM;
12224
12225 i = 0;
12226 nla_for_each_nested(attr, attr_filter, rem) {
b15ca182 12227 filter[i].filter = nla_memdup(attr, GFP_KERNEL);
a442b761
AB
12228 filter[i].len = nla_len(attr);
12229 i++;
12230 }
12231 if (tx) {
12232 func->num_tx_filters = n_entries;
12233 func->tx_filters = filter;
12234 } else {
12235 func->num_rx_filters = n_entries;
12236 func->rx_filters = filter;
12237 }
12238
12239 return 0;
12240}
12241
12242static int nl80211_nan_add_func(struct sk_buff *skb,
12243 struct genl_info *info)
12244{
12245 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12246 struct wireless_dev *wdev = info->user_ptr[1];
12247 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr;
12248 struct cfg80211_nan_func *func;
12249 struct sk_buff *msg = NULL;
12250 void *hdr = NULL;
12251 int err = 0;
12252
12253 if (wdev->iftype != NL80211_IFTYPE_NAN)
12254 return -EOPNOTSUPP;
12255
73c7da3d 12256 if (!wdev_running(wdev))
a442b761
AB
12257 return -ENOTCONN;
12258
12259 if (!info->attrs[NL80211_ATTR_NAN_FUNC])
12260 return -EINVAL;
12261
8cb08174
JB
12262 err = nla_parse_nested_deprecated(tb, NL80211_NAN_FUNC_ATTR_MAX,
12263 info->attrs[NL80211_ATTR_NAN_FUNC],
12264 nl80211_nan_func_policy,
12265 info->extack);
a442b761
AB
12266 if (err)
12267 return err;
12268
12269 func = kzalloc(sizeof(*func), GFP_KERNEL);
12270 if (!func)
12271 return -ENOMEM;
12272
b60ad348 12273 func->cookie = cfg80211_assign_cookie(rdev);
a442b761
AB
12274
12275 if (!tb[NL80211_NAN_FUNC_TYPE] ||
12276 nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]) > NL80211_NAN_FUNC_MAX_TYPE) {
12277 err = -EINVAL;
12278 goto out;
12279 }
12280
12281
12282 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]);
12283
12284 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) {
12285 err = -EINVAL;
12286 goto out;
12287 }
12288
12289 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]),
12290 sizeof(func->service_id));
12291
12292 func->close_range =
12293 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]);
12294
12295 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) {
12296 func->serv_spec_info_len =
12297 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]);
12298 func->serv_spec_info =
12299 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]),
12300 func->serv_spec_info_len,
12301 GFP_KERNEL);
12302 if (!func->serv_spec_info) {
12303 err = -ENOMEM;
12304 goto out;
12305 }
12306 }
12307
12308 if (tb[NL80211_NAN_FUNC_TTL])
12309 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]);
12310
12311 switch (func->type) {
12312 case NL80211_NAN_FUNC_PUBLISH:
12313 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) {
12314 err = -EINVAL;
12315 goto out;
12316 }
12317
12318 func->publish_type =
12319 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]);
12320 func->publish_bcast =
12321 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]);
12322
12323 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) &&
12324 func->publish_bcast) {
12325 err = -EINVAL;
12326 goto out;
12327 }
12328 break;
12329 case NL80211_NAN_FUNC_SUBSCRIBE:
12330 func->subscribe_active =
12331 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]);
12332 break;
12333 case NL80211_NAN_FUNC_FOLLOW_UP:
12334 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] ||
3ea15452
HC
12335 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] ||
12336 !tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]) {
a442b761
AB
12337 err = -EINVAL;
12338 goto out;
12339 }
12340
12341 func->followup_id =
12342 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]);
12343 func->followup_reqid =
12344 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]);
12345 memcpy(func->followup_dest.addr,
12346 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]),
12347 sizeof(func->followup_dest.addr));
12348 if (func->ttl) {
12349 err = -EINVAL;
12350 goto out;
12351 }
12352 break;
12353 default:
12354 err = -EINVAL;
12355 goto out;
12356 }
12357
12358 if (tb[NL80211_NAN_FUNC_SRF]) {
12359 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR];
12360
8cb08174
JB
12361 err = nla_parse_nested_deprecated(srf_tb,
12362 NL80211_NAN_SRF_ATTR_MAX,
12363 tb[NL80211_NAN_FUNC_SRF],
12364 nl80211_nan_srf_policy,
12365 info->extack);
a442b761
AB
12366 if (err)
12367 goto out;
12368
12369 func->srf_include =
12370 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]);
12371
12372 if (srf_tb[NL80211_NAN_SRF_BF]) {
12373 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] ||
12374 !srf_tb[NL80211_NAN_SRF_BF_IDX]) {
12375 err = -EINVAL;
12376 goto out;
12377 }
12378
12379 func->srf_bf_len =
12380 nla_len(srf_tb[NL80211_NAN_SRF_BF]);
12381 func->srf_bf =
12382 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]),
12383 func->srf_bf_len, GFP_KERNEL);
12384 if (!func->srf_bf) {
12385 err = -ENOMEM;
12386 goto out;
12387 }
12388
12389 func->srf_bf_idx =
12390 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]);
12391 } else {
12392 struct nlattr *attr, *mac_attr =
12393 srf_tb[NL80211_NAN_SRF_MAC_ADDRS];
12394 int n_entries, rem, i = 0;
12395
12396 if (!mac_attr) {
12397 err = -EINVAL;
12398 goto out;
12399 }
12400
12401 n_entries = validate_acl_mac_addrs(mac_attr);
12402 if (n_entries <= 0) {
12403 err = -EINVAL;
12404 goto out;
12405 }
12406
12407 func->srf_num_macs = n_entries;
12408 func->srf_macs =
6396bb22 12409 kcalloc(n_entries, sizeof(*func->srf_macs),
a442b761
AB
12410 GFP_KERNEL);
12411 if (!func->srf_macs) {
12412 err = -ENOMEM;
12413 goto out;
12414 }
12415
12416 nla_for_each_nested(attr, mac_attr, rem)
12417 memcpy(func->srf_macs[i++].addr, nla_data(attr),
12418 sizeof(*func->srf_macs));
12419 }
12420 }
12421
12422 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) {
12423 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER],
12424 func, true);
12425 if (err)
12426 goto out;
12427 }
12428
12429 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) {
12430 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER],
12431 func, false);
12432 if (err)
12433 goto out;
12434 }
12435
12436 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12437 if (!msg) {
12438 err = -ENOMEM;
12439 goto out;
12440 }
12441
12442 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12443 NL80211_CMD_ADD_NAN_FUNCTION);
12444 /* This can't really happen - we just allocated 4KB */
12445 if (WARN_ON(!hdr)) {
12446 err = -ENOMEM;
12447 goto out;
12448 }
12449
12450 err = rdev_add_nan_func(rdev, wdev, func);
12451out:
12452 if (err < 0) {
12453 cfg80211_free_nan_func(func);
12454 nlmsg_free(msg);
12455 return err;
12456 }
12457
12458 /* propagate the instance id and cookie to userspace */
12459 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie,
12460 NL80211_ATTR_PAD))
12461 goto nla_put_failure;
12462
ae0be8de 12463 func_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_FUNC);
a442b761
AB
12464 if (!func_attr)
12465 goto nla_put_failure;
12466
12467 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID,
12468 func->instance_id))
12469 goto nla_put_failure;
12470
12471 nla_nest_end(msg, func_attr);
12472
12473 genlmsg_end(msg, hdr);
12474 return genlmsg_reply(msg, info);
12475
12476nla_put_failure:
12477 nlmsg_free(msg);
12478 return -ENOBUFS;
12479}
12480
12481static int nl80211_nan_del_func(struct sk_buff *skb,
12482 struct genl_info *info)
12483{
12484 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12485 struct wireless_dev *wdev = info->user_ptr[1];
12486 u64 cookie;
12487
12488 if (wdev->iftype != NL80211_IFTYPE_NAN)
12489 return -EOPNOTSUPP;
12490
73c7da3d 12491 if (!wdev_running(wdev))
a442b761
AB
12492 return -ENOTCONN;
12493
12494 if (!info->attrs[NL80211_ATTR_COOKIE])
12495 return -EINVAL;
12496
a442b761
AB
12497 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
12498
12499 rdev_del_nan_func(rdev, wdev, cookie);
12500
12501 return 0;
12502}
12503
a5a9dcf2
AB
12504static int nl80211_nan_change_config(struct sk_buff *skb,
12505 struct genl_info *info)
12506{
12507 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12508 struct wireless_dev *wdev = info->user_ptr[1];
12509 struct cfg80211_nan_conf conf = {};
12510 u32 changed = 0;
12511
12512 if (wdev->iftype != NL80211_IFTYPE_NAN)
12513 return -EOPNOTSUPP;
12514
73c7da3d 12515 if (!wdev_running(wdev))
a5a9dcf2
AB
12516 return -ENOTCONN;
12517
12518 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) {
12519 conf.master_pref =
12520 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
12521 if (conf.master_pref <= 1 || conf.master_pref == 255)
12522 return -EINVAL;
12523
12524 changed |= CFG80211_NAN_CONF_CHANGED_PREF;
12525 }
12526
8585989d
LC
12527 if (info->attrs[NL80211_ATTR_BANDS]) {
12528 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
12529
12530 if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
12531 return -EOPNOTSUPP;
12532
12533 if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
12534 return -EINVAL;
12535
12536 conf.bands = bands;
12537 changed |= CFG80211_NAN_CONF_CHANGED_BANDS;
a5a9dcf2
AB
12538 }
12539
12540 if (!changed)
12541 return -EINVAL;
12542
12543 return rdev_nan_change_conf(rdev, wdev, &conf, changed);
12544}
12545
50bcd31d
AB
12546void cfg80211_nan_match(struct wireless_dev *wdev,
12547 struct cfg80211_nan_match_params *match, gfp_t gfp)
12548{
12549 struct wiphy *wiphy = wdev->wiphy;
12550 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
12551 struct nlattr *match_attr, *local_func_attr, *peer_func_attr;
12552 struct sk_buff *msg;
12553 void *hdr;
12554
12555 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr))
12556 return;
12557
12558 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12559 if (!msg)
12560 return;
12561
12562 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH);
12563 if (!hdr) {
12564 nlmsg_free(msg);
12565 return;
12566 }
12567
12568 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12569 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
12570 wdev->netdev->ifindex)) ||
12571 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
12572 NL80211_ATTR_PAD))
12573 goto nla_put_failure;
12574
12575 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie,
12576 NL80211_ATTR_PAD) ||
12577 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr))
12578 goto nla_put_failure;
12579
ae0be8de 12580 match_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_MATCH);
50bcd31d
AB
12581 if (!match_attr)
12582 goto nla_put_failure;
12583
ae0be8de
MK
12584 local_func_attr = nla_nest_start_noflag(msg,
12585 NL80211_NAN_MATCH_FUNC_LOCAL);
50bcd31d
AB
12586 if (!local_func_attr)
12587 goto nla_put_failure;
12588
12589 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id))
12590 goto nla_put_failure;
12591
12592 nla_nest_end(msg, local_func_attr);
12593
ae0be8de
MK
12594 peer_func_attr = nla_nest_start_noflag(msg,
12595 NL80211_NAN_MATCH_FUNC_PEER);
50bcd31d
AB
12596 if (!peer_func_attr)
12597 goto nla_put_failure;
12598
12599 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) ||
12600 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id))
12601 goto nla_put_failure;
12602
12603 if (match->info && match->info_len &&
12604 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len,
12605 match->info))
12606 goto nla_put_failure;
12607
12608 nla_nest_end(msg, peer_func_attr);
12609 nla_nest_end(msg, match_attr);
12610 genlmsg_end(msg, hdr);
12611
12612 if (!wdev->owner_nlportid)
12613 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
12614 msg, 0, NL80211_MCGRP_NAN, gfp);
12615 else
12616 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
12617 wdev->owner_nlportid);
12618
12619 return;
12620
12621nla_put_failure:
12622 nlmsg_free(msg);
12623}
12624EXPORT_SYMBOL(cfg80211_nan_match);
12625
368e5a7b
AB
12626void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
12627 u8 inst_id,
12628 enum nl80211_nan_func_term_reason reason,
12629 u64 cookie, gfp_t gfp)
12630{
12631 struct wiphy *wiphy = wdev->wiphy;
12632 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
12633 struct sk_buff *msg;
12634 struct nlattr *func_attr;
12635 void *hdr;
12636
12637 if (WARN_ON(!inst_id))
12638 return;
12639
12640 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
12641 if (!msg)
12642 return;
12643
12644 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION);
12645 if (!hdr) {
12646 nlmsg_free(msg);
12647 return;
12648 }
12649
12650 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
12651 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
12652 wdev->netdev->ifindex)) ||
12653 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
12654 NL80211_ATTR_PAD))
12655 goto nla_put_failure;
12656
12657 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
12658 NL80211_ATTR_PAD))
12659 goto nla_put_failure;
12660
ae0be8de 12661 func_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_FUNC);
368e5a7b
AB
12662 if (!func_attr)
12663 goto nla_put_failure;
12664
12665 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) ||
12666 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason))
12667 goto nla_put_failure;
12668
12669 nla_nest_end(msg, func_attr);
12670 genlmsg_end(msg, hdr);
12671
12672 if (!wdev->owner_nlportid)
12673 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
12674 msg, 0, NL80211_MCGRP_NAN, gfp);
12675 else
12676 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
12677 wdev->owner_nlportid);
12678
12679 return;
12680
12681nla_put_failure:
12682 nlmsg_free(msg);
12683}
12684EXPORT_SYMBOL(cfg80211_nan_func_terminated);
12685
3713b4e3
JB
12686static int nl80211_get_protocol_features(struct sk_buff *skb,
12687 struct genl_info *info)
12688{
12689 void *hdr;
12690 struct sk_buff *msg;
12691
12692 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12693 if (!msg)
12694 return -ENOMEM;
12695
12696 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12697 NL80211_CMD_GET_PROTOCOL_FEATURES);
12698 if (!hdr)
12699 goto nla_put_failure;
12700
12701 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
12702 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
12703 goto nla_put_failure;
12704
12705 genlmsg_end(msg, hdr);
12706 return genlmsg_reply(msg, info);
12707
12708 nla_put_failure:
12709 kfree_skb(msg);
12710 return -ENOBUFS;
12711}
12712
355199e0
JM
12713static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
12714{
12715 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12716 struct cfg80211_update_ft_ies_params ft_params;
12717 struct net_device *dev = info->user_ptr[1];
12718
12719 if (!rdev->ops->update_ft_ies)
12720 return -EOPNOTSUPP;
12721
12722 if (!info->attrs[NL80211_ATTR_MDID] ||
3d7af878 12723 !info->attrs[NL80211_ATTR_IE])
355199e0
JM
12724 return -EINVAL;
12725
12726 memset(&ft_params, 0, sizeof(ft_params));
12727 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
12728 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
12729 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
12730
12731 return rdev_update_ft_ies(rdev, dev, &ft_params);
12732}
12733
5de17984
AS
12734static int nl80211_crit_protocol_start(struct sk_buff *skb,
12735 struct genl_info *info)
12736{
12737 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12738 struct wireless_dev *wdev = info->user_ptr[1];
12739 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
12740 u16 duration;
12741 int ret;
12742
12743 if (!rdev->ops->crit_proto_start)
12744 return -EOPNOTSUPP;
12745
12746 if (WARN_ON(!rdev->ops->crit_proto_stop))
12747 return -EINVAL;
12748
12749 if (rdev->crit_proto_nlportid)
12750 return -EBUSY;
12751
12752 /* determine protocol if provided */
12753 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
12754 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
12755
12756 if (proto >= NUM_NL80211_CRIT_PROTO)
12757 return -EINVAL;
12758
12759 /* timeout must be provided */
12760 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
12761 return -EINVAL;
12762
12763 duration =
12764 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
12765
12766 if (duration > NL80211_CRIT_PROTO_MAX_DURATION)
12767 return -ERANGE;
12768
12769 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
12770 if (!ret)
12771 rdev->crit_proto_nlportid = info->snd_portid;
12772
12773 return ret;
12774}
12775
12776static int nl80211_crit_protocol_stop(struct sk_buff *skb,
12777 struct genl_info *info)
12778{
12779 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12780 struct wireless_dev *wdev = info->user_ptr[1];
12781
12782 if (!rdev->ops->crit_proto_stop)
12783 return -EOPNOTSUPP;
12784
12785 if (rdev->crit_proto_nlportid) {
12786 rdev->crit_proto_nlportid = 0;
12787 rdev_crit_proto_stop(rdev, wdev);
12788 }
12789 return 0;
12790}
12791
901bb989
JB
12792static int nl80211_vendor_check_policy(const struct wiphy_vendor_command *vcmd,
12793 struct nlattr *attr,
12794 struct netlink_ext_ack *extack)
12795{
12796 if (vcmd->policy == VENDOR_CMD_RAW_DATA) {
12797 if (attr->nla_type & NLA_F_NESTED) {
12798 NL_SET_ERR_MSG_ATTR(extack, attr,
12799 "unexpected nested data");
12800 return -EINVAL;
12801 }
12802
12803 return 0;
12804 }
12805
12806 if (!(attr->nla_type & NLA_F_NESTED)) {
12807 NL_SET_ERR_MSG_ATTR(extack, attr, "expected nested data");
12808 return -EINVAL;
12809 }
12810
12811 return nl80211_validate_nested(attr, vcmd->maxattr, vcmd->policy,
12812 extack);
12813}
12814
ad7e718c
JB
12815static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
12816{
12817 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12818 struct wireless_dev *wdev =
12819 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
12820 int i, err;
12821 u32 vid, subcmd;
12822
12823 if (!rdev->wiphy.vendor_commands)
12824 return -EOPNOTSUPP;
12825
12826 if (IS_ERR(wdev)) {
12827 err = PTR_ERR(wdev);
12828 if (err != -EINVAL)
12829 return err;
12830 wdev = NULL;
12831 } else if (wdev->wiphy != &rdev->wiphy) {
12832 return -EINVAL;
12833 }
12834
12835 if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
12836 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
12837 return -EINVAL;
12838
12839 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
12840 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
12841 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
12842 const struct wiphy_vendor_command *vcmd;
12843 void *data = NULL;
12844 int len = 0;
12845
12846 vcmd = &rdev->wiphy.vendor_commands[i];
12847
12848 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
12849 continue;
12850
12851 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
12852 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
12853 if (!wdev)
12854 return -EINVAL;
12855 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
12856 !wdev->netdev)
12857 return -EINVAL;
12858
12859 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
73c7da3d 12860 if (!wdev_running(wdev))
ad7e718c
JB
12861 return -ENETDOWN;
12862 }
7bdbe400
JB
12863
12864 if (!vcmd->doit)
12865 return -EOPNOTSUPP;
ad7e718c
JB
12866 } else {
12867 wdev = NULL;
12868 }
12869
12870 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
12871 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
12872 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
901bb989
JB
12873
12874 err = nl80211_vendor_check_policy(vcmd,
12875 info->attrs[NL80211_ATTR_VENDOR_DATA],
12876 info->extack);
12877 if (err)
12878 return err;
ad7e718c
JB
12879 }
12880
12881 rdev->cur_cmd_info = info;
901bb989 12882 err = vcmd->doit(&rdev->wiphy, wdev, data, len);
ad7e718c
JB
12883 rdev->cur_cmd_info = NULL;
12884 return err;
12885 }
12886
12887 return -EOPNOTSUPP;
12888}
12889
7bdbe400
JB
12890static int nl80211_prepare_vendor_dump(struct sk_buff *skb,
12891 struct netlink_callback *cb,
12892 struct cfg80211_registered_device **rdev,
12893 struct wireless_dev **wdev)
12894{
50508d94 12895 struct nlattr **attrbuf;
7bdbe400
JB
12896 u32 vid, subcmd;
12897 unsigned int i;
12898 int vcmd_idx = -1;
12899 int err;
12900 void *data = NULL;
12901 unsigned int data_len = 0;
12902
7bdbe400
JB
12903 if (cb->args[0]) {
12904 /* subtract the 1 again here */
12905 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
12906 struct wireless_dev *tmp;
12907
ea90e0dc
JB
12908 if (!wiphy)
12909 return -ENODEV;
7bdbe400
JB
12910 *rdev = wiphy_to_rdev(wiphy);
12911 *wdev = NULL;
12912
12913 if (cb->args[1]) {
53873f13 12914 list_for_each_entry(tmp, &wiphy->wdev_list, list) {
7bdbe400
JB
12915 if (tmp->identifier == cb->args[1] - 1) {
12916 *wdev = tmp;
12917 break;
12918 }
12919 }
12920 }
12921
12922 /* keep rtnl locked in successful case */
12923 return 0;
12924 }
12925
50508d94
JB
12926 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf), GFP_KERNEL);
12927 if (!attrbuf)
12928 return -ENOMEM;
12929
8cb08174
JB
12930 err = nlmsg_parse_deprecated(cb->nlh,
12931 GENL_HDRLEN + nl80211_fam.hdrsize,
12932 attrbuf, nl80211_fam.maxattr,
12933 nl80211_policy, NULL);
7bdbe400 12934 if (err)
50508d94 12935 goto out;
7bdbe400 12936
c90c39da 12937 if (!attrbuf[NL80211_ATTR_VENDOR_ID] ||
50508d94
JB
12938 !attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) {
12939 err = -EINVAL;
12940 goto out;
12941 }
7bdbe400 12942
c90c39da 12943 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk), attrbuf);
7bdbe400
JB
12944 if (IS_ERR(*wdev))
12945 *wdev = NULL;
12946
c90c39da 12947 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
50508d94
JB
12948 if (IS_ERR(*rdev)) {
12949 err = PTR_ERR(*rdev);
12950 goto out;
12951 }
7bdbe400 12952
c90c39da
JB
12953 vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]);
12954 subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]);
7bdbe400
JB
12955
12956 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) {
12957 const struct wiphy_vendor_command *vcmd;
12958
12959 vcmd = &(*rdev)->wiphy.vendor_commands[i];
12960
12961 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
12962 continue;
12963
50508d94
JB
12964 if (!vcmd->dumpit) {
12965 err = -EOPNOTSUPP;
12966 goto out;
12967 }
7bdbe400
JB
12968
12969 vcmd_idx = i;
12970 break;
12971 }
12972
50508d94
JB
12973 if (vcmd_idx < 0) {
12974 err = -EOPNOTSUPP;
12975 goto out;
12976 }
7bdbe400 12977
c90c39da
JB
12978 if (attrbuf[NL80211_ATTR_VENDOR_DATA]) {
12979 data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]);
12980 data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]);
901bb989
JB
12981
12982 err = nl80211_vendor_check_policy(
12983 &(*rdev)->wiphy.vendor_commands[vcmd_idx],
12984 attrbuf[NL80211_ATTR_VENDOR_DATA],
12985 cb->extack);
12986 if (err)
50508d94 12987 goto out;
7bdbe400
JB
12988 }
12989
12990 /* 0 is the first index - add 1 to parse only once */
12991 cb->args[0] = (*rdev)->wiphy_idx + 1;
12992 /* add 1 to know if it was NULL */
12993 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0;
12994 cb->args[2] = vcmd_idx;
12995 cb->args[3] = (unsigned long)data;
12996 cb->args[4] = data_len;
12997
12998 /* keep rtnl locked in successful case */
50508d94
JB
12999 err = 0;
13000out:
13001 kfree(attrbuf);
13002 return err;
7bdbe400
JB
13003}
13004
13005static int nl80211_vendor_cmd_dump(struct sk_buff *skb,
13006 struct netlink_callback *cb)
13007{
13008 struct cfg80211_registered_device *rdev;
13009 struct wireless_dev *wdev;
13010 unsigned int vcmd_idx;
13011 const struct wiphy_vendor_command *vcmd;
13012 void *data;
13013 int data_len;
13014 int err;
13015 struct nlattr *vendor_data;
13016
ea90e0dc 13017 rtnl_lock();
7bdbe400
JB
13018 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev);
13019 if (err)
ea90e0dc 13020 goto out;
7bdbe400
JB
13021
13022 vcmd_idx = cb->args[2];
13023 data = (void *)cb->args[3];
13024 data_len = cb->args[4];
13025 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx];
13026
13027 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
13028 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
ea90e0dc
JB
13029 if (!wdev) {
13030 err = -EINVAL;
13031 goto out;
13032 }
7bdbe400 13033 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
ea90e0dc
JB
13034 !wdev->netdev) {
13035 err = -EINVAL;
13036 goto out;
13037 }
7bdbe400
JB
13038
13039 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
ea90e0dc
JB
13040 if (!wdev_running(wdev)) {
13041 err = -ENETDOWN;
13042 goto out;
13043 }
7bdbe400
JB
13044 }
13045 }
13046
13047 while (1) {
13048 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
13049 cb->nlh->nlmsg_seq, NLM_F_MULTI,
13050 NL80211_CMD_VENDOR);
13051 if (!hdr)
13052 break;
13053
13054 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
13055 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
13056 wdev_id(wdev),
13057 NL80211_ATTR_PAD))) {
7bdbe400
JB
13058 genlmsg_cancel(skb, hdr);
13059 break;
13060 }
13061
ae0be8de
MK
13062 vendor_data = nla_nest_start_noflag(skb,
13063 NL80211_ATTR_VENDOR_DATA);
7bdbe400
JB
13064 if (!vendor_data) {
13065 genlmsg_cancel(skb, hdr);
13066 break;
13067 }
13068
13069 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len,
13070 (unsigned long *)&cb->args[5]);
13071 nla_nest_end(skb, vendor_data);
13072
13073 if (err == -ENOBUFS || err == -ENOENT) {
13074 genlmsg_cancel(skb, hdr);
13075 break;
13076 } else if (err) {
13077 genlmsg_cancel(skb, hdr);
13078 goto out;
13079 }
13080
13081 genlmsg_end(skb, hdr);
13082 }
13083
13084 err = skb->len;
13085 out:
13086 rtnl_unlock();
13087 return err;
13088}
13089
ad7e718c
JB
13090struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
13091 enum nl80211_commands cmd,
13092 enum nl80211_attrs attr,
13093 int approxlen)
13094{
f26cbf40 13095 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ad7e718c
JB
13096
13097 if (WARN_ON(!rdev->cur_cmd_info))
13098 return NULL;
13099
6c09e791 13100 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen,
ad7e718c
JB
13101 rdev->cur_cmd_info->snd_portid,
13102 rdev->cur_cmd_info->snd_seq,
567ffc35 13103 cmd, attr, NULL, GFP_KERNEL);
ad7e718c
JB
13104}
13105EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
13106
13107int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
13108{
13109 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
13110 void *hdr = ((void **)skb->cb)[1];
13111 struct nlattr *data = ((void **)skb->cb)[2];
13112
bd8c78e7
JB
13113 /* clear CB data for netlink core to own from now on */
13114 memset(skb->cb, 0, sizeof(skb->cb));
13115
ad7e718c
JB
13116 if (WARN_ON(!rdev->cur_cmd_info)) {
13117 kfree_skb(skb);
13118 return -EINVAL;
13119 }
13120
13121 nla_nest_end(skb, data);
13122 genlmsg_end(skb, hdr);
13123 return genlmsg_reply(skb, rdev->cur_cmd_info);
13124}
13125EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
13126
55c1fdf0
JB
13127unsigned int cfg80211_vendor_cmd_get_sender(struct wiphy *wiphy)
13128{
13129 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
13130
13131 if (WARN_ON(!rdev->cur_cmd_info))
13132 return 0;
13133
13134 return rdev->cur_cmd_info->snd_portid;
13135}
13136EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_get_sender);
13137
fa9ffc74
KP
13138static int nl80211_set_qos_map(struct sk_buff *skb,
13139 struct genl_info *info)
13140{
13141 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13142 struct cfg80211_qos_map *qos_map = NULL;
13143 struct net_device *dev = info->user_ptr[1];
13144 u8 *pos, len, num_des, des_len, des;
13145 int ret;
13146
13147 if (!rdev->ops->set_qos_map)
13148 return -EOPNOTSUPP;
13149
13150 if (info->attrs[NL80211_ATTR_QOS_MAP]) {
13151 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
13152 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
13153
13154 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN ||
13155 len > IEEE80211_QOS_MAP_LEN_MAX)
13156 return -EINVAL;
13157
13158 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
13159 if (!qos_map)
13160 return -ENOMEM;
13161
13162 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
13163 if (num_des) {
13164 des_len = num_des *
13165 sizeof(struct cfg80211_dscp_exception);
13166 memcpy(qos_map->dscp_exception, pos, des_len);
13167 qos_map->num_des = num_des;
13168 for (des = 0; des < num_des; des++) {
13169 if (qos_map->dscp_exception[des].up > 7) {
13170 kfree(qos_map);
13171 return -EINVAL;
13172 }
13173 }
13174 pos += des_len;
13175 }
13176 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
13177 }
13178
13179 wdev_lock(dev->ieee80211_ptr);
13180 ret = nl80211_key_allowed(dev->ieee80211_ptr);
13181 if (!ret)
13182 ret = rdev_set_qos_map(rdev, dev, qos_map);
13183 wdev_unlock(dev->ieee80211_ptr);
13184
13185 kfree(qos_map);
13186 return ret;
13187}
13188
960d01ac
JB
13189static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info)
13190{
13191 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13192 struct net_device *dev = info->user_ptr[1];
13193 struct wireless_dev *wdev = dev->ieee80211_ptr;
13194 const u8 *peer;
13195 u8 tsid, up;
13196 u16 admitted_time = 0;
13197 int err;
13198
723e73ac 13199 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION))
960d01ac
JB
13200 return -EOPNOTSUPP;
13201
13202 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] ||
13203 !info->attrs[NL80211_ATTR_USER_PRIO])
13204 return -EINVAL;
13205
13206 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
960d01ac 13207 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]);
960d01ac
JB
13208
13209 /* WMM uses TIDs 0-7 even for TSPEC */
723e73ac 13210 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) {
960d01ac 13211 /* TODO: handle 802.11 TSPEC/admission control
723e73ac
JB
13212 * need more attributes for that (e.g. BA session requirement);
13213 * change the WMM adminssion test above to allow both then
960d01ac
JB
13214 */
13215 return -EINVAL;
13216 }
13217
13218 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
13219
13220 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) {
13221 admitted_time =
13222 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]);
13223 if (!admitted_time)
13224 return -EINVAL;
13225 }
13226
13227 wdev_lock(wdev);
13228 switch (wdev->iftype) {
13229 case NL80211_IFTYPE_STATION:
13230 case NL80211_IFTYPE_P2P_CLIENT:
13231 if (wdev->current_bss)
13232 break;
13233 err = -ENOTCONN;
13234 goto out;
13235 default:
13236 err = -EOPNOTSUPP;
13237 goto out;
13238 }
13239
13240 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time);
13241
13242 out:
13243 wdev_unlock(wdev);
13244 return err;
13245}
13246
13247static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info)
13248{
13249 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13250 struct net_device *dev = info->user_ptr[1];
13251 struct wireless_dev *wdev = dev->ieee80211_ptr;
13252 const u8 *peer;
13253 u8 tsid;
13254 int err;
13255
13256 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC])
13257 return -EINVAL;
13258
13259 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
13260 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
13261
13262 wdev_lock(wdev);
13263 err = rdev_del_tx_ts(rdev, dev, tsid, peer);
13264 wdev_unlock(wdev);
13265
13266 return err;
13267}
13268
1057d35e
AN
13269static int nl80211_tdls_channel_switch(struct sk_buff *skb,
13270 struct genl_info *info)
13271{
13272 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13273 struct net_device *dev = info->user_ptr[1];
13274 struct wireless_dev *wdev = dev->ieee80211_ptr;
13275 struct cfg80211_chan_def chandef = {};
13276 const u8 *addr;
13277 u8 oper_class;
13278 int err;
13279
13280 if (!rdev->ops->tdls_channel_switch ||
13281 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
13282 return -EOPNOTSUPP;
13283
13284 switch (dev->ieee80211_ptr->iftype) {
13285 case NL80211_IFTYPE_STATION:
13286 case NL80211_IFTYPE_P2P_CLIENT:
13287 break;
13288 default:
13289 return -EOPNOTSUPP;
13290 }
13291
13292 if (!info->attrs[NL80211_ATTR_MAC] ||
13293 !info->attrs[NL80211_ATTR_OPER_CLASS])
13294 return -EINVAL;
13295
13296 err = nl80211_parse_chandef(rdev, info, &chandef);
13297 if (err)
13298 return err;
13299
13300 /*
13301 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012
13302 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the
13303 * specification is not defined for them.
13304 */
57fbcce3 13305 if (chandef.chan->band == NL80211_BAND_2GHZ &&
1057d35e
AN
13306 chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
13307 chandef.width != NL80211_CHAN_WIDTH_20)
13308 return -EINVAL;
13309
13310 /* we will be active on the TDLS link */
923b352f
AN
13311 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
13312 wdev->iftype))
1057d35e
AN
13313 return -EINVAL;
13314
13315 /* don't allow switching to DFS channels */
13316 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype))
13317 return -EINVAL;
13318
13319 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
13320 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]);
13321
13322 wdev_lock(wdev);
13323 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef);
13324 wdev_unlock(wdev);
13325
13326 return err;
13327}
13328
13329static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb,
13330 struct genl_info *info)
13331{
13332 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13333 struct net_device *dev = info->user_ptr[1];
13334 struct wireless_dev *wdev = dev->ieee80211_ptr;
13335 const u8 *addr;
13336
13337 if (!rdev->ops->tdls_channel_switch ||
13338 !rdev->ops->tdls_cancel_channel_switch ||
13339 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
13340 return -EOPNOTSUPP;
13341
13342 switch (dev->ieee80211_ptr->iftype) {
13343 case NL80211_IFTYPE_STATION:
13344 case NL80211_IFTYPE_P2P_CLIENT:
13345 break;
13346 default:
13347 return -EOPNOTSUPP;
13348 }
13349
13350 if (!info->attrs[NL80211_ATTR_MAC])
13351 return -EINVAL;
13352
13353 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
13354
13355 wdev_lock(wdev);
13356 rdev_tdls_cancel_channel_switch(rdev, dev, addr);
13357 wdev_unlock(wdev);
13358
13359 return 0;
13360}
13361
ce0ce13a
MB
13362static int nl80211_set_multicast_to_unicast(struct sk_buff *skb,
13363 struct genl_info *info)
13364{
13365 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13366 struct net_device *dev = info->user_ptr[1];
13367 struct wireless_dev *wdev = dev->ieee80211_ptr;
13368 const struct nlattr *nla;
13369 bool enabled;
13370
ce0ce13a
MB
13371 if (!rdev->ops->set_multicast_to_unicast)
13372 return -EOPNOTSUPP;
13373
13374 if (wdev->iftype != NL80211_IFTYPE_AP &&
13375 wdev->iftype != NL80211_IFTYPE_P2P_GO)
13376 return -EOPNOTSUPP;
13377
13378 nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED];
13379 enabled = nla_get_flag(nla);
13380
13381 return rdev_set_multicast_to_unicast(rdev, dev, enabled);
13382}
13383
3a00df57
AS
13384static int nl80211_set_pmk(struct sk_buff *skb, struct genl_info *info)
13385{
13386 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13387 struct net_device *dev = info->user_ptr[1];
13388 struct wireless_dev *wdev = dev->ieee80211_ptr;
13389 struct cfg80211_pmk_conf pmk_conf = {};
13390 int ret;
13391
13392 if (wdev->iftype != NL80211_IFTYPE_STATION &&
13393 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
13394 return -EOPNOTSUPP;
13395
13396 if (!wiphy_ext_feature_isset(&rdev->wiphy,
13397 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
13398 return -EOPNOTSUPP;
13399
13400 if (!info->attrs[NL80211_ATTR_MAC] || !info->attrs[NL80211_ATTR_PMK])
13401 return -EINVAL;
13402
13403 wdev_lock(wdev);
13404 if (!wdev->current_bss) {
13405 ret = -ENOTCONN;
13406 goto out;
13407 }
13408
13409 pmk_conf.aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
13410 if (memcmp(pmk_conf.aa, wdev->current_bss->pub.bssid, ETH_ALEN)) {
13411 ret = -EINVAL;
13412 goto out;
13413 }
13414
13415 pmk_conf.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
13416 pmk_conf.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
13417 if (pmk_conf.pmk_len != WLAN_PMK_LEN &&
13418 pmk_conf.pmk_len != WLAN_PMK_LEN_SUITE_B_192) {
13419 ret = -EINVAL;
13420 goto out;
13421 }
13422
13423 if (info->attrs[NL80211_ATTR_PMKR0_NAME]) {
13424 int r0_name_len = nla_len(info->attrs[NL80211_ATTR_PMKR0_NAME]);
13425
13426 if (r0_name_len != WLAN_PMK_NAME_LEN) {
13427 ret = -EINVAL;
13428 goto out;
13429 }
13430
13431 pmk_conf.pmk_r0_name =
13432 nla_data(info->attrs[NL80211_ATTR_PMKR0_NAME]);
13433 }
13434
13435 ret = rdev_set_pmk(rdev, dev, &pmk_conf);
13436out:
13437 wdev_unlock(wdev);
13438 return ret;
13439}
13440
13441static int nl80211_del_pmk(struct sk_buff *skb, struct genl_info *info)
13442{
13443 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13444 struct net_device *dev = info->user_ptr[1];
13445 struct wireless_dev *wdev = dev->ieee80211_ptr;
13446 const u8 *aa;
13447 int ret;
13448
13449 if (wdev->iftype != NL80211_IFTYPE_STATION &&
13450 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
13451 return -EOPNOTSUPP;
13452
13453 if (!wiphy_ext_feature_isset(&rdev->wiphy,
13454 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
13455 return -EOPNOTSUPP;
13456
13457 if (!info->attrs[NL80211_ATTR_MAC])
13458 return -EINVAL;
13459
13460 wdev_lock(wdev);
13461 aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
13462 ret = rdev_del_pmk(rdev, dev, aa);
13463 wdev_unlock(wdev);
13464
13465 return ret;
13466}
13467
40cbfa90
SD
13468static int nl80211_external_auth(struct sk_buff *skb, struct genl_info *info)
13469{
13470 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13471 struct net_device *dev = info->user_ptr[1];
13472 struct cfg80211_external_auth_params params;
13473
db8d93a7 13474 if (!rdev->ops->external_auth)
40cbfa90
SD
13475 return -EOPNOTSUPP;
13476
fe494370
SD
13477 if (!info->attrs[NL80211_ATTR_SSID] &&
13478 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
13479 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
40cbfa90
SD
13480 return -EINVAL;
13481
13482 if (!info->attrs[NL80211_ATTR_BSSID])
13483 return -EINVAL;
13484
13485 if (!info->attrs[NL80211_ATTR_STATUS_CODE])
13486 return -EINVAL;
13487
13488 memset(&params, 0, sizeof(params));
13489
fe494370
SD
13490 if (info->attrs[NL80211_ATTR_SSID]) {
13491 params.ssid.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
13492 if (params.ssid.ssid_len == 0 ||
13493 params.ssid.ssid_len > IEEE80211_MAX_SSID_LEN)
13494 return -EINVAL;
13495 memcpy(params.ssid.ssid,
13496 nla_data(info->attrs[NL80211_ATTR_SSID]),
13497 params.ssid.ssid_len);
13498 }
40cbfa90
SD
13499
13500 memcpy(params.bssid, nla_data(info->attrs[NL80211_ATTR_BSSID]),
13501 ETH_ALEN);
13502
13503 params.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
13504
fe494370
SD
13505 if (info->attrs[NL80211_ATTR_PMKID])
13506 params.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
13507
40cbfa90
SD
13508 return rdev_external_auth(rdev, dev, &params);
13509}
13510
2576a9ac
DK
13511static int nl80211_tx_control_port(struct sk_buff *skb, struct genl_info *info)
13512{
13513 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13514 struct net_device *dev = info->user_ptr[1];
13515 struct wireless_dev *wdev = dev->ieee80211_ptr;
13516 const u8 *buf;
13517 size_t len;
13518 u8 *dest;
13519 u16 proto;
13520 bool noencrypt;
13521 int err;
13522
13523 if (!wiphy_ext_feature_isset(&rdev->wiphy,
13524 NL80211_EXT_FEATURE_CONTROL_PORT_OVER_NL80211))
13525 return -EOPNOTSUPP;
13526
13527 if (!rdev->ops->tx_control_port)
13528 return -EOPNOTSUPP;
13529
13530 if (!info->attrs[NL80211_ATTR_FRAME] ||
13531 !info->attrs[NL80211_ATTR_MAC] ||
13532 !info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
13533 GENL_SET_ERR_MSG(info, "Frame, MAC or ethertype missing");
13534 return -EINVAL;
13535 }
13536
13537 wdev_lock(wdev);
13538
13539 switch (wdev->iftype) {
13540 case NL80211_IFTYPE_AP:
13541 case NL80211_IFTYPE_P2P_GO:
13542 case NL80211_IFTYPE_MESH_POINT:
13543 break;
13544 case NL80211_IFTYPE_ADHOC:
13545 case NL80211_IFTYPE_STATION:
13546 case NL80211_IFTYPE_P2P_CLIENT:
13547 if (wdev->current_bss)
13548 break;
13549 err = -ENOTCONN;
13550 goto out;
13551 default:
13552 err = -EOPNOTSUPP;
13553 goto out;
13554 }
13555
13556 wdev_unlock(wdev);
13557
13558 buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
13559 len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
13560 dest = nla_data(info->attrs[NL80211_ATTR_MAC]);
13561 proto = nla_get_u16(info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
13562 noencrypt =
13563 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT]);
13564
13565 return rdev_tx_control_port(rdev, dev, buf, len,
13566 dest, cpu_to_be16(proto), noencrypt);
13567
13568 out:
13569 wdev_unlock(wdev);
13570 return err;
13571}
13572
81e54d08
PKC
13573static int nl80211_get_ftm_responder_stats(struct sk_buff *skb,
13574 struct genl_info *info)
13575{
13576 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13577 struct net_device *dev = info->user_ptr[1];
13578 struct wireless_dev *wdev = dev->ieee80211_ptr;
13579 struct cfg80211_ftm_responder_stats ftm_stats = {};
13580 struct sk_buff *msg;
13581 void *hdr;
13582 struct nlattr *ftm_stats_attr;
13583 int err;
13584
13585 if (wdev->iftype != NL80211_IFTYPE_AP || !wdev->beacon_interval)
13586 return -EOPNOTSUPP;
13587
13588 err = rdev_get_ftm_responder_stats(rdev, dev, &ftm_stats);
13589 if (err)
13590 return err;
13591
13592 if (!ftm_stats.filled)
13593 return -ENODATA;
13594
13595 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13596 if (!msg)
13597 return -ENOMEM;
13598
13599 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
13600 NL80211_CMD_GET_FTM_RESPONDER_STATS);
13601 if (!hdr)
13602 return -ENOBUFS;
13603
13604 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
13605 goto nla_put_failure;
13606
ae0be8de
MK
13607 ftm_stats_attr = nla_nest_start_noflag(msg,
13608 NL80211_ATTR_FTM_RESPONDER_STATS);
81e54d08
PKC
13609 if (!ftm_stats_attr)
13610 goto nla_put_failure;
13611
13612#define SET_FTM(field, name, type) \
13613 do { if ((ftm_stats.filled & BIT(NL80211_FTM_STATS_ ## name)) && \
13614 nla_put_ ## type(msg, NL80211_FTM_STATS_ ## name, \
13615 ftm_stats.field)) \
13616 goto nla_put_failure; } while (0)
13617#define SET_FTM_U64(field, name) \
13618 do { if ((ftm_stats.filled & BIT(NL80211_FTM_STATS_ ## name)) && \
13619 nla_put_u64_64bit(msg, NL80211_FTM_STATS_ ## name, \
13620 ftm_stats.field, NL80211_FTM_STATS_PAD)) \
13621 goto nla_put_failure; } while (0)
13622
13623 SET_FTM(success_num, SUCCESS_NUM, u32);
13624 SET_FTM(partial_num, PARTIAL_NUM, u32);
13625 SET_FTM(failed_num, FAILED_NUM, u32);
13626 SET_FTM(asap_num, ASAP_NUM, u32);
13627 SET_FTM(non_asap_num, NON_ASAP_NUM, u32);
13628 SET_FTM_U64(total_duration_ms, TOTAL_DURATION_MSEC);
13629 SET_FTM(unknown_triggers_num, UNKNOWN_TRIGGERS_NUM, u32);
13630 SET_FTM(reschedule_requests_num, RESCHEDULE_REQUESTS_NUM, u32);
13631 SET_FTM(out_of_window_triggers_num, OUT_OF_WINDOW_TRIGGERS_NUM, u32);
13632#undef SET_FTM
13633
13634 nla_nest_end(msg, ftm_stats_attr);
13635
13636 genlmsg_end(msg, hdr);
13637 return genlmsg_reply(msg, info);
13638
13639nla_put_failure:
13640 nlmsg_free(msg);
13641 return -ENOBUFS;
13642}
13643
cb74e977
SD
13644static int nl80211_update_owe_info(struct sk_buff *skb, struct genl_info *info)
13645{
13646 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13647 struct cfg80211_update_owe_info owe_info;
13648 struct net_device *dev = info->user_ptr[1];
13649
13650 if (!rdev->ops->update_owe_info)
13651 return -EOPNOTSUPP;
13652
13653 if (!info->attrs[NL80211_ATTR_STATUS_CODE] ||
13654 !info->attrs[NL80211_ATTR_MAC])
13655 return -EINVAL;
13656
13657 memset(&owe_info, 0, sizeof(owe_info));
13658 owe_info.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
13659 nla_memcpy(owe_info.peer, info->attrs[NL80211_ATTR_MAC], ETH_ALEN);
13660
13661 if (info->attrs[NL80211_ATTR_IE]) {
13662 owe_info.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
13663 owe_info.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
13664 }
13665
13666 return rdev_update_owe_info(rdev, dev, &owe_info);
13667}
13668
5ab92e7f
RM
13669static int nl80211_probe_mesh_link(struct sk_buff *skb, struct genl_info *info)
13670{
13671 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13672 struct net_device *dev = info->user_ptr[1];
13673 struct wireless_dev *wdev = dev->ieee80211_ptr;
13674 struct station_info sinfo = {};
13675 const u8 *buf;
13676 size_t len;
13677 u8 *dest;
13678 int err;
13679
13680 if (!rdev->ops->probe_mesh_link || !rdev->ops->get_station)
13681 return -EOPNOTSUPP;
13682
13683 if (!info->attrs[NL80211_ATTR_MAC] ||
13684 !info->attrs[NL80211_ATTR_FRAME]) {
13685 GENL_SET_ERR_MSG(info, "Frame or MAC missing");
13686 return -EINVAL;
13687 }
13688
13689 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
13690 return -EOPNOTSUPP;
13691
13692 dest = nla_data(info->attrs[NL80211_ATTR_MAC]);
13693 buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
13694 len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
13695
13696 if (len < sizeof(struct ethhdr))
13697 return -EINVAL;
13698
13699 if (!ether_addr_equal(buf, dest) || is_multicast_ether_addr(buf) ||
13700 !ether_addr_equal(buf + ETH_ALEN, dev->dev_addr))
13701 return -EINVAL;
13702
13703 err = rdev_get_station(rdev, dev, dest, &sinfo);
13704 if (err)
13705 return err;
13706
13707 return rdev_probe_mesh_link(rdev, dev, dest, buf, len);
13708}
13709
4c476991
JB
13710#define NL80211_FLAG_NEED_WIPHY 0x01
13711#define NL80211_FLAG_NEED_NETDEV 0x02
13712#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
13713#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
13714#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
13715 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 13716#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 13717/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
13718#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
13719 NL80211_FLAG_CHECK_NETDEV_UP)
5393b917 13720#define NL80211_FLAG_CLEAR_SKB 0x20
4c476991 13721
f84f771d 13722static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
13723 struct genl_info *info)
13724{
13725 struct cfg80211_registered_device *rdev;
89a54e48 13726 struct wireless_dev *wdev;
4c476991 13727 struct net_device *dev;
4c476991
JB
13728 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
13729
13730 if (rtnl)
13731 rtnl_lock();
13732
13733 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 13734 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
13735 if (IS_ERR(rdev)) {
13736 if (rtnl)
13737 rtnl_unlock();
13738 return PTR_ERR(rdev);
13739 }
13740 info->user_ptr[0] = rdev;
1bf614ef
JB
13741 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
13742 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
13743 ASSERT_RTNL();
13744
89a54e48
JB
13745 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
13746 info->attrs);
13747 if (IS_ERR(wdev)) {
4c476991
JB
13748 if (rtnl)
13749 rtnl_unlock();
89a54e48 13750 return PTR_ERR(wdev);
4c476991 13751 }
89a54e48 13752
89a54e48 13753 dev = wdev->netdev;
f26cbf40 13754 rdev = wiphy_to_rdev(wdev->wiphy);
89a54e48 13755
1bf614ef
JB
13756 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
13757 if (!dev) {
1bf614ef
JB
13758 if (rtnl)
13759 rtnl_unlock();
13760 return -EINVAL;
13761 }
13762
13763 info->user_ptr[1] = dev;
13764 } else {
13765 info->user_ptr[1] = wdev;
41265714 13766 }
1bf614ef 13767
73c7da3d
AVS
13768 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
13769 !wdev_running(wdev)) {
13770 if (rtnl)
13771 rtnl_unlock();
13772 return -ENETDOWN;
13773 }
1bf614ef 13774
73c7da3d 13775 if (dev)
1bf614ef 13776 dev_hold(dev);
89a54e48 13777
4c476991 13778 info->user_ptr[0] = rdev;
4c476991
JB
13779 }
13780
13781 return 0;
13782}
13783
f84f771d 13784static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
13785 struct genl_info *info)
13786{
1bf614ef
JB
13787 if (info->user_ptr[1]) {
13788 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
13789 struct wireless_dev *wdev = info->user_ptr[1];
13790
13791 if (wdev->netdev)
13792 dev_put(wdev->netdev);
13793 } else {
13794 dev_put(info->user_ptr[1]);
13795 }
13796 }
5393b917 13797
4c476991
JB
13798 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
13799 rtnl_unlock();
5393b917
JB
13800
13801 /* If needed, clear the netlink message payload from the SKB
13802 * as it might contain key data that shouldn't stick around on
13803 * the heap after the SKB is freed. The netlink message header
13804 * is still needed for further processing, so leave it intact.
13805 */
13806 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) {
13807 struct nlmsghdr *nlh = nlmsg_hdr(skb);
13808
13809 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh));
13810 }
4c476991
JB
13811}
13812
4534de83 13813static const struct genl_ops nl80211_ops[] = {
55682965
JB
13814 {
13815 .cmd = NL80211_CMD_GET_WIPHY,
ef6243ac 13816 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965
JB
13817 .doit = nl80211_get_wiphy,
13818 .dumpit = nl80211_dump_wiphy,
86e8cf98 13819 .done = nl80211_dump_wiphy_done,
55682965 13820 /* can be retrieved by unprivileged users */
5fe231e8
JB
13821 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13822 NL80211_FLAG_NEED_RTNL,
55682965
JB
13823 },
13824 {
13825 .cmd = NL80211_CMD_SET_WIPHY,
ef6243ac 13826 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 13827 .doit = nl80211_set_wiphy,
5617c6cd 13828 .flags = GENL_UNS_ADMIN_PERM,
4c476991 13829 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
13830 },
13831 {
13832 .cmd = NL80211_CMD_GET_INTERFACE,
ef6243ac 13833 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965
JB
13834 .doit = nl80211_get_interface,
13835 .dumpit = nl80211_dump_interface,
55682965 13836 /* can be retrieved by unprivileged users */
5fe231e8
JB
13837 .internal_flags = NL80211_FLAG_NEED_WDEV |
13838 NL80211_FLAG_NEED_RTNL,
55682965
JB
13839 },
13840 {
13841 .cmd = NL80211_CMD_SET_INTERFACE,
ef6243ac 13842 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 13843 .doit = nl80211_set_interface,
5617c6cd 13844 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
13845 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13846 NL80211_FLAG_NEED_RTNL,
55682965
JB
13847 },
13848 {
13849 .cmd = NL80211_CMD_NEW_INTERFACE,
ef6243ac 13850 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 13851 .doit = nl80211_new_interface,
5617c6cd 13852 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
13853 .internal_flags = NL80211_FLAG_NEED_WIPHY |
13854 NL80211_FLAG_NEED_RTNL,
55682965
JB
13855 },
13856 {
13857 .cmd = NL80211_CMD_DEL_INTERFACE,
ef6243ac 13858 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 13859 .doit = nl80211_del_interface,
5617c6cd 13860 .flags = GENL_UNS_ADMIN_PERM,
84efbb84 13861 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 13862 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
13863 },
13864 {
13865 .cmd = NL80211_CMD_GET_KEY,
ef6243ac 13866 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 13867 .doit = nl80211_get_key,
5617c6cd 13868 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13869 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13870 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
13871 },
13872 {
13873 .cmd = NL80211_CMD_SET_KEY,
ef6243ac 13874 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 13875 .doit = nl80211_set_key,
5617c6cd 13876 .flags = GENL_UNS_ADMIN_PERM,
41265714 13877 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
13878 NL80211_FLAG_NEED_RTNL |
13879 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
13880 },
13881 {
13882 .cmd = NL80211_CMD_NEW_KEY,
ef6243ac 13883 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 13884 .doit = nl80211_new_key,
5617c6cd 13885 .flags = GENL_UNS_ADMIN_PERM,
41265714 13886 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
13887 NL80211_FLAG_NEED_RTNL |
13888 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
13889 },
13890 {
13891 .cmd = NL80211_CMD_DEL_KEY,
ef6243ac 13892 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 13893 .doit = nl80211_del_key,
5617c6cd 13894 .flags = GENL_UNS_ADMIN_PERM,
41265714 13895 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13896 NL80211_FLAG_NEED_RTNL,
55682965 13897 },
ed1b6cc7
JB
13898 {
13899 .cmd = NL80211_CMD_SET_BEACON,
ef6243ac 13900 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5617c6cd 13901 .flags = GENL_UNS_ADMIN_PERM,
8860020e 13902 .doit = nl80211_set_beacon,
2b5f8b0b 13903 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13904 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
13905 },
13906 {
8860020e 13907 .cmd = NL80211_CMD_START_AP,
ef6243ac 13908 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5617c6cd 13909 .flags = GENL_UNS_ADMIN_PERM,
8860020e 13910 .doit = nl80211_start_ap,
2b5f8b0b 13911 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13912 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
13913 },
13914 {
8860020e 13915 .cmd = NL80211_CMD_STOP_AP,
ef6243ac 13916 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5617c6cd 13917 .flags = GENL_UNS_ADMIN_PERM,
8860020e 13918 .doit = nl80211_stop_ap,
2b5f8b0b 13919 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13920 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 13921 },
5727ef1b
JB
13922 {
13923 .cmd = NL80211_CMD_GET_STATION,
ef6243ac 13924 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 13925 .doit = nl80211_get_station,
2ec600d6 13926 .dumpit = nl80211_dump_station,
4c476991
JB
13927 .internal_flags = NL80211_FLAG_NEED_NETDEV |
13928 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
13929 },
13930 {
13931 .cmd = NL80211_CMD_SET_STATION,
ef6243ac 13932 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 13933 .doit = nl80211_set_station,
5617c6cd 13934 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13935 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13936 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
13937 },
13938 {
13939 .cmd = NL80211_CMD_NEW_STATION,
ef6243ac 13940 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 13941 .doit = nl80211_new_station,
5617c6cd 13942 .flags = GENL_UNS_ADMIN_PERM,
41265714 13943 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13944 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
13945 },
13946 {
13947 .cmd = NL80211_CMD_DEL_STATION,
ef6243ac 13948 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 13949 .doit = nl80211_del_station,
5617c6cd 13950 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13951 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13952 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
13953 },
13954 {
13955 .cmd = NL80211_CMD_GET_MPATH,
ef6243ac 13956 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6
LCC
13957 .doit = nl80211_get_mpath,
13958 .dumpit = nl80211_dump_mpath,
5617c6cd 13959 .flags = GENL_UNS_ADMIN_PERM,
41265714 13960 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13961 NL80211_FLAG_NEED_RTNL,
2ec600d6 13962 },
66be7d2b
HR
13963 {
13964 .cmd = NL80211_CMD_GET_MPP,
ef6243ac 13965 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
66be7d2b
HR
13966 .doit = nl80211_get_mpp,
13967 .dumpit = nl80211_dump_mpp,
5617c6cd 13968 .flags = GENL_UNS_ADMIN_PERM,
66be7d2b
HR
13969 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
13970 NL80211_FLAG_NEED_RTNL,
13971 },
2ec600d6
LCC
13972 {
13973 .cmd = NL80211_CMD_SET_MPATH,
ef6243ac 13974 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6 13975 .doit = nl80211_set_mpath,
5617c6cd 13976 .flags = GENL_UNS_ADMIN_PERM,
41265714 13977 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13978 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
13979 },
13980 {
13981 .cmd = NL80211_CMD_NEW_MPATH,
ef6243ac 13982 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6 13983 .doit = nl80211_new_mpath,
5617c6cd 13984 .flags = GENL_UNS_ADMIN_PERM,
41265714 13985 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13986 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
13987 },
13988 {
13989 .cmd = NL80211_CMD_DEL_MPATH,
ef6243ac 13990 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6 13991 .doit = nl80211_del_mpath,
5617c6cd 13992 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 13993 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 13994 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
13995 },
13996 {
13997 .cmd = NL80211_CMD_SET_BSS,
ef6243ac 13998 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9f1ba906 13999 .doit = nl80211_set_bss,
5617c6cd 14000 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14001 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14002 NL80211_FLAG_NEED_RTNL,
b2e1b302 14003 },
f130347c
LR
14004 {
14005 .cmd = NL80211_CMD_GET_REG,
ef6243ac 14006 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ad30ca2c
AN
14007 .doit = nl80211_get_reg_do,
14008 .dumpit = nl80211_get_reg_dump,
5fe231e8 14009 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
14010 /* can be retrieved by unprivileged users */
14011 },
b6863036 14012#ifdef CONFIG_CFG80211_CRDA_SUPPORT
b2e1b302
LR
14013 {
14014 .cmd = NL80211_CMD_SET_REG,
ef6243ac 14015 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b2e1b302 14016 .doit = nl80211_set_reg,
b2e1b302 14017 .flags = GENL_ADMIN_PERM,
5fe231e8 14018 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302 14019 },
b6863036 14020#endif
b2e1b302
LR
14021 {
14022 .cmd = NL80211_CMD_REQ_SET_REG,
ef6243ac 14023 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b2e1b302 14024 .doit = nl80211_req_set_reg,
93da9cc1 14025 .flags = GENL_ADMIN_PERM,
14026 },
1ea4ff3e
JB
14027 {
14028 .cmd = NL80211_CMD_RELOAD_REGDB,
ef6243ac 14029 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1ea4ff3e 14030 .doit = nl80211_reload_regdb,
1ea4ff3e
JB
14031 .flags = GENL_ADMIN_PERM,
14032 },
93da9cc1 14033 {
24bdd9f4 14034 .cmd = NL80211_CMD_GET_MESH_CONFIG,
ef6243ac 14035 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
24bdd9f4 14036 .doit = nl80211_get_mesh_config,
93da9cc1 14037 /* can be retrieved by unprivileged users */
2b5f8b0b 14038 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14039 NL80211_FLAG_NEED_RTNL,
93da9cc1 14040 },
14041 {
24bdd9f4 14042 .cmd = NL80211_CMD_SET_MESH_CONFIG,
ef6243ac 14043 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
24bdd9f4 14044 .doit = nl80211_update_mesh_config,
5617c6cd 14045 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c 14046 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14047 NL80211_FLAG_NEED_RTNL,
9aed3cc1 14048 },
2a519311
JB
14049 {
14050 .cmd = NL80211_CMD_TRIGGER_SCAN,
ef6243ac 14051 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2a519311 14052 .doit = nl80211_trigger_scan,
5617c6cd 14053 .flags = GENL_UNS_ADMIN_PERM,
fd014284 14054 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14055 NL80211_FLAG_NEED_RTNL,
2a519311 14056 },
91d3ab46
VK
14057 {
14058 .cmd = NL80211_CMD_ABORT_SCAN,
ef6243ac 14059 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
91d3ab46 14060 .doit = nl80211_abort_scan,
5617c6cd 14061 .flags = GENL_UNS_ADMIN_PERM,
91d3ab46
VK
14062 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14063 NL80211_FLAG_NEED_RTNL,
14064 },
2a519311
JB
14065 {
14066 .cmd = NL80211_CMD_GET_SCAN,
ef6243ac 14067 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2a519311
JB
14068 .dumpit = nl80211_dump_scan,
14069 },
807f8a8c
LC
14070 {
14071 .cmd = NL80211_CMD_START_SCHED_SCAN,
ef6243ac 14072 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
807f8a8c 14073 .doit = nl80211_start_sched_scan,
5617c6cd 14074 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
14075 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14076 NL80211_FLAG_NEED_RTNL,
14077 },
14078 {
14079 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
ef6243ac 14080 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
807f8a8c 14081 .doit = nl80211_stop_sched_scan,
5617c6cd 14082 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
14083 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14084 NL80211_FLAG_NEED_RTNL,
14085 },
636a5d36
JM
14086 {
14087 .cmd = NL80211_CMD_AUTHENTICATE,
ef6243ac 14088 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14089 .doit = nl80211_authenticate,
5617c6cd 14090 .flags = GENL_UNS_ADMIN_PERM,
41265714 14091 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
14092 NL80211_FLAG_NEED_RTNL |
14093 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
14094 },
14095 {
14096 .cmd = NL80211_CMD_ASSOCIATE,
ef6243ac 14097 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14098 .doit = nl80211_associate,
5617c6cd 14099 .flags = GENL_UNS_ADMIN_PERM,
41265714 14100 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14101 NL80211_FLAG_NEED_RTNL |
14102 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
14103 },
14104 {
14105 .cmd = NL80211_CMD_DEAUTHENTICATE,
ef6243ac 14106 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14107 .doit = nl80211_deauthenticate,
5617c6cd 14108 .flags = GENL_UNS_ADMIN_PERM,
41265714 14109 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14110 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
14111 },
14112 {
14113 .cmd = NL80211_CMD_DISASSOCIATE,
ef6243ac 14114 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14115 .doit = nl80211_disassociate,
5617c6cd 14116 .flags = GENL_UNS_ADMIN_PERM,
41265714 14117 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14118 NL80211_FLAG_NEED_RTNL,
636a5d36 14119 },
04a773ad
JB
14120 {
14121 .cmd = NL80211_CMD_JOIN_IBSS,
ef6243ac 14122 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
04a773ad 14123 .doit = nl80211_join_ibss,
5617c6cd 14124 .flags = GENL_UNS_ADMIN_PERM,
41265714 14125 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14126 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
14127 },
14128 {
14129 .cmd = NL80211_CMD_LEAVE_IBSS,
ef6243ac 14130 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
04a773ad 14131 .doit = nl80211_leave_ibss,
5617c6cd 14132 .flags = GENL_UNS_ADMIN_PERM,
41265714 14133 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14134 NL80211_FLAG_NEED_RTNL,
04a773ad 14135 },
aff89a9b
JB
14136#ifdef CONFIG_NL80211_TESTMODE
14137 {
14138 .cmd = NL80211_CMD_TESTMODE,
ef6243ac 14139 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
aff89a9b 14140 .doit = nl80211_testmode_do,
71063f0e 14141 .dumpit = nl80211_testmode_dump,
5617c6cd 14142 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14143 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14144 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
14145 },
14146#endif
b23aa676
SO
14147 {
14148 .cmd = NL80211_CMD_CONNECT,
ef6243ac 14149 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b23aa676 14150 .doit = nl80211_connect,
5617c6cd 14151 .flags = GENL_UNS_ADMIN_PERM,
41265714 14152 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14153 NL80211_FLAG_NEED_RTNL |
14154 NL80211_FLAG_CLEAR_SKB,
b23aa676 14155 },
088e8df8 14156 {
14157 .cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS,
ef6243ac 14158 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
088e8df8 14159 .doit = nl80211_update_connect_params,
088e8df8 14160 .flags = GENL_ADMIN_PERM,
14161 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14162 NL80211_FLAG_NEED_RTNL |
14163 NL80211_FLAG_CLEAR_SKB,
088e8df8 14164 },
b23aa676
SO
14165 {
14166 .cmd = NL80211_CMD_DISCONNECT,
ef6243ac 14167 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b23aa676 14168 .doit = nl80211_disconnect,
5617c6cd 14169 .flags = GENL_UNS_ADMIN_PERM,
41265714 14170 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14171 NL80211_FLAG_NEED_RTNL,
b23aa676 14172 },
463d0183
JB
14173 {
14174 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
ef6243ac 14175 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
463d0183 14176 .doit = nl80211_wiphy_netns,
5617c6cd 14177 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14178 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14179 NL80211_FLAG_NEED_RTNL,
463d0183 14180 },
61fa713c
HS
14181 {
14182 .cmd = NL80211_CMD_GET_SURVEY,
ef6243ac 14183 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
61fa713c
HS
14184 .dumpit = nl80211_dump_survey,
14185 },
67fbb16b
SO
14186 {
14187 .cmd = NL80211_CMD_SET_PMKSA,
ef6243ac 14188 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
67fbb16b 14189 .doit = nl80211_setdel_pmksa,
5617c6cd 14190 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14191 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14192 NL80211_FLAG_NEED_RTNL |
14193 NL80211_FLAG_CLEAR_SKB,
67fbb16b
SO
14194 },
14195 {
14196 .cmd = NL80211_CMD_DEL_PMKSA,
ef6243ac 14197 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
67fbb16b 14198 .doit = nl80211_setdel_pmksa,
5617c6cd 14199 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14200 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14201 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
14202 },
14203 {
14204 .cmd = NL80211_CMD_FLUSH_PMKSA,
ef6243ac 14205 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
67fbb16b 14206 .doit = nl80211_flush_pmksa,
5617c6cd 14207 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14208 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14209 NL80211_FLAG_NEED_RTNL,
67fbb16b 14210 },
9588bbd5
JM
14211 {
14212 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
ef6243ac 14213 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9588bbd5 14214 .doit = nl80211_remain_on_channel,
5617c6cd 14215 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14216 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14217 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
14218 },
14219 {
14220 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
ef6243ac 14221 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9588bbd5 14222 .doit = nl80211_cancel_remain_on_channel,
5617c6cd 14223 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14224 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14225 NL80211_FLAG_NEED_RTNL,
9588bbd5 14226 },
13ae75b1
JM
14227 {
14228 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
ef6243ac 14229 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
13ae75b1 14230 .doit = nl80211_set_tx_bitrate_mask,
5617c6cd 14231 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14232 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14233 NL80211_FLAG_NEED_RTNL,
13ae75b1 14234 },
026331c4 14235 {
2e161f78 14236 .cmd = NL80211_CMD_REGISTER_FRAME,
ef6243ac 14237 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2e161f78 14238 .doit = nl80211_register_mgmt,
5617c6cd 14239 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14240 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 14241 NL80211_FLAG_NEED_RTNL,
026331c4
JM
14242 },
14243 {
2e161f78 14244 .cmd = NL80211_CMD_FRAME,
ef6243ac 14245 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2e161f78 14246 .doit = nl80211_tx_mgmt,
5617c6cd 14247 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14248 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
14249 NL80211_FLAG_NEED_RTNL,
14250 },
14251 {
14252 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
ef6243ac 14253 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
f7ca38df 14254 .doit = nl80211_tx_mgmt_cancel_wait,
5617c6cd 14255 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14256 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14257 NL80211_FLAG_NEED_RTNL,
026331c4 14258 },
ffb9eb3d
KV
14259 {
14260 .cmd = NL80211_CMD_SET_POWER_SAVE,
ef6243ac 14261 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ffb9eb3d 14262 .doit = nl80211_set_power_save,
5617c6cd 14263 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14264 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14265 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
14266 },
14267 {
14268 .cmd = NL80211_CMD_GET_POWER_SAVE,
ef6243ac 14269 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ffb9eb3d 14270 .doit = nl80211_get_power_save,
ffb9eb3d 14271 /* can be retrieved by unprivileged users */
4c476991
JB
14272 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14273 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 14274 },
d6dc1a38
JO
14275 {
14276 .cmd = NL80211_CMD_SET_CQM,
ef6243ac 14277 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
d6dc1a38 14278 .doit = nl80211_set_cqm,
5617c6cd 14279 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14280 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14281 NL80211_FLAG_NEED_RTNL,
d6dc1a38 14282 },
f444de05
JB
14283 {
14284 .cmd = NL80211_CMD_SET_CHANNEL,
ef6243ac 14285 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
f444de05 14286 .doit = nl80211_set_channel,
5617c6cd 14287 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14288 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14289 NL80211_FLAG_NEED_RTNL,
f444de05 14290 },
e8347eba
BJ
14291 {
14292 .cmd = NL80211_CMD_SET_WDS_PEER,
ef6243ac 14293 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
e8347eba 14294 .doit = nl80211_set_wds_peer,
5617c6cd 14295 .flags = GENL_UNS_ADMIN_PERM,
43b19952
JB
14296 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14297 NL80211_FLAG_NEED_RTNL,
e8347eba 14298 },
29cbe68c
JB
14299 {
14300 .cmd = NL80211_CMD_JOIN_MESH,
ef6243ac 14301 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
29cbe68c 14302 .doit = nl80211_join_mesh,
5617c6cd 14303 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
14304 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14305 NL80211_FLAG_NEED_RTNL,
14306 },
14307 {
14308 .cmd = NL80211_CMD_LEAVE_MESH,
ef6243ac 14309 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
29cbe68c 14310 .doit = nl80211_leave_mesh,
5617c6cd 14311 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
14312 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14313 NL80211_FLAG_NEED_RTNL,
14314 },
6e0bd6c3
RL
14315 {
14316 .cmd = NL80211_CMD_JOIN_OCB,
ef6243ac 14317 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
6e0bd6c3 14318 .doit = nl80211_join_ocb,
5617c6cd 14319 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
14320 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14321 NL80211_FLAG_NEED_RTNL,
14322 },
14323 {
14324 .cmd = NL80211_CMD_LEAVE_OCB,
ef6243ac 14325 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
6e0bd6c3 14326 .doit = nl80211_leave_ocb,
5617c6cd 14327 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
14328 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14329 NL80211_FLAG_NEED_RTNL,
14330 },
dfb89c56 14331#ifdef CONFIG_PM
ff1b6e69
JB
14332 {
14333 .cmd = NL80211_CMD_GET_WOWLAN,
ef6243ac 14334 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ff1b6e69 14335 .doit = nl80211_get_wowlan,
ff1b6e69
JB
14336 /* can be retrieved by unprivileged users */
14337 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14338 NL80211_FLAG_NEED_RTNL,
14339 },
14340 {
14341 .cmd = NL80211_CMD_SET_WOWLAN,
ef6243ac 14342 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ff1b6e69 14343 .doit = nl80211_set_wowlan,
5617c6cd 14344 .flags = GENL_UNS_ADMIN_PERM,
ff1b6e69
JB
14345 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14346 NL80211_FLAG_NEED_RTNL,
14347 },
dfb89c56 14348#endif
e5497d76
JB
14349 {
14350 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
ef6243ac 14351 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
e5497d76 14352 .doit = nl80211_set_rekey_data,
5617c6cd 14353 .flags = GENL_UNS_ADMIN_PERM,
e5497d76 14354 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
14355 NL80211_FLAG_NEED_RTNL |
14356 NL80211_FLAG_CLEAR_SKB,
e5497d76 14357 },
109086ce
AN
14358 {
14359 .cmd = NL80211_CMD_TDLS_MGMT,
ef6243ac 14360 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
109086ce 14361 .doit = nl80211_tdls_mgmt,
5617c6cd 14362 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
14363 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14364 NL80211_FLAG_NEED_RTNL,
14365 },
14366 {
14367 .cmd = NL80211_CMD_TDLS_OPER,
ef6243ac 14368 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
109086ce 14369 .doit = nl80211_tdls_oper,
5617c6cd 14370 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
14371 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14372 NL80211_FLAG_NEED_RTNL,
14373 },
28946da7
JB
14374 {
14375 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
ef6243ac 14376 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
28946da7 14377 .doit = nl80211_register_unexpected_frame,
5617c6cd 14378 .flags = GENL_UNS_ADMIN_PERM,
28946da7
JB
14379 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14380 NL80211_FLAG_NEED_RTNL,
14381 },
7f6cf311
JB
14382 {
14383 .cmd = NL80211_CMD_PROBE_CLIENT,
ef6243ac 14384 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
7f6cf311 14385 .doit = nl80211_probe_client,
5617c6cd 14386 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14387 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
14388 NL80211_FLAG_NEED_RTNL,
14389 },
5e760230
JB
14390 {
14391 .cmd = NL80211_CMD_REGISTER_BEACONS,
ef6243ac 14392 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5e760230 14393 .doit = nl80211_register_beacons,
5617c6cd 14394 .flags = GENL_UNS_ADMIN_PERM,
5e760230
JB
14395 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14396 NL80211_FLAG_NEED_RTNL,
14397 },
1d9d9213
SW
14398 {
14399 .cmd = NL80211_CMD_SET_NOACK_MAP,
ef6243ac 14400 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1d9d9213 14401 .doit = nl80211_set_noack_map,
5617c6cd 14402 .flags = GENL_UNS_ADMIN_PERM,
1d9d9213
SW
14403 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14404 NL80211_FLAG_NEED_RTNL,
14405 },
98104fde
JB
14406 {
14407 .cmd = NL80211_CMD_START_P2P_DEVICE,
ef6243ac 14408 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
98104fde 14409 .doit = nl80211_start_p2p_device,
5617c6cd 14410 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
14411 .internal_flags = NL80211_FLAG_NEED_WDEV |
14412 NL80211_FLAG_NEED_RTNL,
14413 },
14414 {
14415 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
ef6243ac 14416 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
98104fde 14417 .doit = nl80211_stop_p2p_device,
5617c6cd 14418 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
14419 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14420 NL80211_FLAG_NEED_RTNL,
cb3b7d87
AB
14421 },
14422 {
14423 .cmd = NL80211_CMD_START_NAN,
ef6243ac 14424 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
cb3b7d87 14425 .doit = nl80211_start_nan,
cb3b7d87
AB
14426 .flags = GENL_ADMIN_PERM,
14427 .internal_flags = NL80211_FLAG_NEED_WDEV |
14428 NL80211_FLAG_NEED_RTNL,
14429 },
14430 {
14431 .cmd = NL80211_CMD_STOP_NAN,
ef6243ac 14432 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
cb3b7d87 14433 .doit = nl80211_stop_nan,
cb3b7d87
AB
14434 .flags = GENL_ADMIN_PERM,
14435 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14436 NL80211_FLAG_NEED_RTNL,
a442b761
AB
14437 },
14438 {
14439 .cmd = NL80211_CMD_ADD_NAN_FUNCTION,
ef6243ac 14440 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
a442b761 14441 .doit = nl80211_nan_add_func,
a442b761
AB
14442 .flags = GENL_ADMIN_PERM,
14443 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14444 NL80211_FLAG_NEED_RTNL,
14445 },
14446 {
14447 .cmd = NL80211_CMD_DEL_NAN_FUNCTION,
ef6243ac 14448 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
a442b761 14449 .doit = nl80211_nan_del_func,
a442b761
AB
14450 .flags = GENL_ADMIN_PERM,
14451 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14452 NL80211_FLAG_NEED_RTNL,
a5a9dcf2
AB
14453 },
14454 {
14455 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG,
ef6243ac 14456 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
a5a9dcf2 14457 .doit = nl80211_nan_change_config,
a5a9dcf2
AB
14458 .flags = GENL_ADMIN_PERM,
14459 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14460 NL80211_FLAG_NEED_RTNL,
98104fde 14461 },
f4e583c8
AQ
14462 {
14463 .cmd = NL80211_CMD_SET_MCAST_RATE,
ef6243ac 14464 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
f4e583c8 14465 .doit = nl80211_set_mcast_rate,
5617c6cd 14466 .flags = GENL_UNS_ADMIN_PERM,
77765eaf
VT
14467 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14468 NL80211_FLAG_NEED_RTNL,
14469 },
14470 {
14471 .cmd = NL80211_CMD_SET_MAC_ACL,
ef6243ac 14472 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
77765eaf 14473 .doit = nl80211_set_mac_acl,
5617c6cd 14474 .flags = GENL_UNS_ADMIN_PERM,
f4e583c8
AQ
14475 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14476 NL80211_FLAG_NEED_RTNL,
14477 },
04f39047
SW
14478 {
14479 .cmd = NL80211_CMD_RADAR_DETECT,
ef6243ac 14480 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
04f39047 14481 .doit = nl80211_start_radar_detection,
5617c6cd 14482 .flags = GENL_UNS_ADMIN_PERM,
04f39047
SW
14483 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14484 NL80211_FLAG_NEED_RTNL,
14485 },
3713b4e3
JB
14486 {
14487 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
ef6243ac 14488 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
3713b4e3 14489 .doit = nl80211_get_protocol_features,
3713b4e3 14490 },
355199e0
JM
14491 {
14492 .cmd = NL80211_CMD_UPDATE_FT_IES,
ef6243ac 14493 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
355199e0 14494 .doit = nl80211_update_ft_ies,
5617c6cd 14495 .flags = GENL_UNS_ADMIN_PERM,
355199e0
JM
14496 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14497 NL80211_FLAG_NEED_RTNL,
14498 },
5de17984
AS
14499 {
14500 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
ef6243ac 14501 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5de17984 14502 .doit = nl80211_crit_protocol_start,
5617c6cd 14503 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
14504 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14505 NL80211_FLAG_NEED_RTNL,
14506 },
14507 {
14508 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
ef6243ac 14509 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5de17984 14510 .doit = nl80211_crit_protocol_stop,
5617c6cd 14511 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
14512 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14513 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
14514 },
14515 {
14516 .cmd = NL80211_CMD_GET_COALESCE,
ef6243ac 14517 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
be29b99a 14518 .doit = nl80211_get_coalesce,
be29b99a
AK
14519 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14520 NL80211_FLAG_NEED_RTNL,
14521 },
14522 {
14523 .cmd = NL80211_CMD_SET_COALESCE,
ef6243ac 14524 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
be29b99a 14525 .doit = nl80211_set_coalesce,
5617c6cd 14526 .flags = GENL_UNS_ADMIN_PERM,
be29b99a
AK
14527 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14528 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
14529 },
14530 {
14531 .cmd = NL80211_CMD_CHANNEL_SWITCH,
ef6243ac 14532 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16ef1fe2 14533 .doit = nl80211_channel_switch,
5617c6cd 14534 .flags = GENL_UNS_ADMIN_PERM,
16ef1fe2
SW
14535 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14536 NL80211_FLAG_NEED_RTNL,
14537 },
ad7e718c
JB
14538 {
14539 .cmd = NL80211_CMD_VENDOR,
ef6243ac 14540 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ad7e718c 14541 .doit = nl80211_vendor_cmd,
7bdbe400 14542 .dumpit = nl80211_vendor_cmd_dump,
5617c6cd 14543 .flags = GENL_UNS_ADMIN_PERM,
ad7e718c 14544 .internal_flags = NL80211_FLAG_NEED_WIPHY |
d6db02a8
SD
14545 NL80211_FLAG_NEED_RTNL |
14546 NL80211_FLAG_CLEAR_SKB,
ad7e718c 14547 },
fa9ffc74
KP
14548 {
14549 .cmd = NL80211_CMD_SET_QOS_MAP,
ef6243ac 14550 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
fa9ffc74 14551 .doit = nl80211_set_qos_map,
5617c6cd 14552 .flags = GENL_UNS_ADMIN_PERM,
fa9ffc74
KP
14553 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14554 NL80211_FLAG_NEED_RTNL,
14555 },
960d01ac
JB
14556 {
14557 .cmd = NL80211_CMD_ADD_TX_TS,
ef6243ac 14558 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
960d01ac 14559 .doit = nl80211_add_tx_ts,
5617c6cd 14560 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
14561 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14562 NL80211_FLAG_NEED_RTNL,
14563 },
14564 {
14565 .cmd = NL80211_CMD_DEL_TX_TS,
ef6243ac 14566 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
960d01ac 14567 .doit = nl80211_del_tx_ts,
5617c6cd 14568 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
14569 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14570 NL80211_FLAG_NEED_RTNL,
14571 },
1057d35e
AN
14572 {
14573 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH,
ef6243ac 14574 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1057d35e 14575 .doit = nl80211_tdls_channel_switch,
5617c6cd 14576 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
14577 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14578 NL80211_FLAG_NEED_RTNL,
14579 },
14580 {
14581 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH,
ef6243ac 14582 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1057d35e 14583 .doit = nl80211_tdls_cancel_channel_switch,
5617c6cd 14584 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
14585 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14586 NL80211_FLAG_NEED_RTNL,
14587 },
ce0ce13a
MB
14588 {
14589 .cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST,
ef6243ac 14590 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ce0ce13a 14591 .doit = nl80211_set_multicast_to_unicast,
ce0ce13a
MB
14592 .flags = GENL_UNS_ADMIN_PERM,
14593 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14594 NL80211_FLAG_NEED_RTNL,
14595 },
3a00df57
AS
14596 {
14597 .cmd = NL80211_CMD_SET_PMK,
ef6243ac 14598 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
3a00df57 14599 .doit = nl80211_set_pmk,
3a00df57 14600 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14601 NL80211_FLAG_NEED_RTNL |
14602 NL80211_FLAG_CLEAR_SKB,
3a00df57
AS
14603 },
14604 {
14605 .cmd = NL80211_CMD_DEL_PMK,
ef6243ac 14606 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
3a00df57 14607 .doit = nl80211_del_pmk,
3a00df57
AS
14608 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14609 NL80211_FLAG_NEED_RTNL,
14610 },
40cbfa90
SD
14611 {
14612 .cmd = NL80211_CMD_EXTERNAL_AUTH,
ef6243ac 14613 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
40cbfa90 14614 .doit = nl80211_external_auth,
40cbfa90
SD
14615 .flags = GENL_ADMIN_PERM,
14616 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14617 NL80211_FLAG_NEED_RTNL,
14618 },
2576a9ac
DK
14619 {
14620 .cmd = NL80211_CMD_CONTROL_PORT_FRAME,
ef6243ac 14621 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2576a9ac 14622 .doit = nl80211_tx_control_port,
2576a9ac
DK
14623 .flags = GENL_UNS_ADMIN_PERM,
14624 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14625 NL80211_FLAG_NEED_RTNL,
14626 },
81e54d08
PKC
14627 {
14628 .cmd = NL80211_CMD_GET_FTM_RESPONDER_STATS,
ef6243ac 14629 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
81e54d08 14630 .doit = nl80211_get_ftm_responder_stats,
81e54d08
PKC
14631 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14632 NL80211_FLAG_NEED_RTNL,
14633 },
9bb7e0f2
JB
14634 {
14635 .cmd = NL80211_CMD_PEER_MEASUREMENT_START,
ef6243ac 14636 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9bb7e0f2 14637 .doit = nl80211_pmsr_start,
9bb7e0f2
JB
14638 .flags = GENL_UNS_ADMIN_PERM,
14639 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14640 NL80211_FLAG_NEED_RTNL,
14641 },
30c63115
S
14642 {
14643 .cmd = NL80211_CMD_NOTIFY_RADAR,
ef6243ac 14644 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
30c63115 14645 .doit = nl80211_notify_radar_detection,
30c63115
S
14646 .flags = GENL_UNS_ADMIN_PERM,
14647 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14648 NL80211_FLAG_NEED_RTNL,
14649 },
cb74e977
SD
14650 {
14651 .cmd = NL80211_CMD_UPDATE_OWE_INFO,
14652 .doit = nl80211_update_owe_info,
14653 .flags = GENL_ADMIN_PERM,
5ab92e7f
RM
14654 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14655 NL80211_FLAG_NEED_RTNL,
14656 },
14657 {
14658 .cmd = NL80211_CMD_PROBE_MESH_LINK,
14659 .doit = nl80211_probe_mesh_link,
14660 .flags = GENL_UNS_ADMIN_PERM,
cb74e977
SD
14661 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14662 NL80211_FLAG_NEED_RTNL,
14663 },
55682965 14664};
9588bbd5 14665
56989f6d 14666static struct genl_family nl80211_fam __ro_after_init = {
489111e5
JB
14667 .name = NL80211_GENL_NAME, /* have users key off the name instead */
14668 .hdrsize = 0, /* no private header */
14669 .version = 1, /* no particular meaning now */
14670 .maxattr = NL80211_ATTR_MAX,
3b0f31f2 14671 .policy = nl80211_policy,
489111e5
JB
14672 .netnsok = true,
14673 .pre_doit = nl80211_pre_doit,
14674 .post_doit = nl80211_post_doit,
14675 .module = THIS_MODULE,
14676 .ops = nl80211_ops,
14677 .n_ops = ARRAY_SIZE(nl80211_ops),
14678 .mcgrps = nl80211_mcgrps,
14679 .n_mcgrps = ARRAY_SIZE(nl80211_mcgrps),
50508d94 14680 .parallel_ops = true,
489111e5
JB
14681};
14682
55682965
JB
14683/* notification functions */
14684
3bb20556
JB
14685void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev,
14686 enum nl80211_commands cmd)
55682965
JB
14687{
14688 struct sk_buff *msg;
86e8cf98 14689 struct nl80211_dump_wiphy_state state = {};
55682965 14690
3bb20556
JB
14691 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY &&
14692 cmd != NL80211_CMD_DEL_WIPHY);
14693
fd2120ca 14694 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
14695 if (!msg)
14696 return;
14697
3bb20556 14698 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) {
55682965
JB
14699 nlmsg_free(msg);
14700 return;
14701 }
14702
68eb5503 14703 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14704 NL80211_MCGRP_CONFIG, GFP_KERNEL);
55682965
JB
14705}
14706
896ff063
DK
14707void nl80211_notify_iface(struct cfg80211_registered_device *rdev,
14708 struct wireless_dev *wdev,
14709 enum nl80211_commands cmd)
14710{
14711 struct sk_buff *msg;
14712
896ff063
DK
14713 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14714 if (!msg)
14715 return;
14716
3d1a5bbf 14717 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, cmd) < 0) {
896ff063
DK
14718 nlmsg_free(msg);
14719 return;
14720 }
14721
14722 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
14723 NL80211_MCGRP_CONFIG, GFP_KERNEL);
14724}
14725
362a415d
JB
14726static int nl80211_add_scan_req(struct sk_buff *msg,
14727 struct cfg80211_registered_device *rdev)
14728{
14729 struct cfg80211_scan_request *req = rdev->scan_req;
14730 struct nlattr *nest;
14731 int i;
14732
14733 if (WARN_ON(!req))
14734 return 0;
14735
ae0be8de 14736 nest = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_SSIDS);
362a415d
JB
14737 if (!nest)
14738 goto nla_put_failure;
9360ffd1
DM
14739 for (i = 0; i < req->n_ssids; i++) {
14740 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
14741 goto nla_put_failure;
14742 }
362a415d
JB
14743 nla_nest_end(msg, nest);
14744
ae0be8de 14745 nest = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_FREQUENCIES);
362a415d
JB
14746 if (!nest)
14747 goto nla_put_failure;
9360ffd1
DM
14748 for (i = 0; i < req->n_channels; i++) {
14749 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
14750 goto nla_put_failure;
14751 }
362a415d
JB
14752 nla_nest_end(msg, nest);
14753
9360ffd1
DM
14754 if (req->ie &&
14755 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
14756 goto nla_put_failure;
362a415d 14757
ae917c9f
JB
14758 if (req->flags &&
14759 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
14760 goto nla_put_failure;
ed473771 14761
1d76250b
AS
14762 if (req->info.scan_start_tsf &&
14763 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF,
14764 req->info.scan_start_tsf, NL80211_BSS_PAD) ||
14765 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN,
14766 req->info.tsf_bssid)))
14767 goto nla_put_failure;
14768
362a415d
JB
14769 return 0;
14770 nla_put_failure:
14771 return -ENOBUFS;
14772}
14773
505a2e88 14774static int nl80211_prep_scan_msg(struct sk_buff *msg,
a538e2d5 14775 struct cfg80211_registered_device *rdev,
fd014284 14776 struct wireless_dev *wdev,
15e47304 14777 u32 portid, u32 seq, int flags,
a538e2d5 14778 u32 cmd)
2a519311
JB
14779{
14780 void *hdr;
14781
15e47304 14782 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
14783 if (!hdr)
14784 return -1;
14785
9360ffd1 14786 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
14787 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
14788 wdev->netdev->ifindex)) ||
2dad624e
ND
14789 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
14790 NL80211_ATTR_PAD))
9360ffd1 14791 goto nla_put_failure;
2a519311 14792
362a415d
JB
14793 /* ignore errors and send incomplete event anyway */
14794 nl80211_add_scan_req(msg, rdev);
2a519311 14795
053c095a
JB
14796 genlmsg_end(msg, hdr);
14797 return 0;
2a519311
JB
14798
14799 nla_put_failure:
14800 genlmsg_cancel(msg, hdr);
14801 return -EMSGSIZE;
14802}
14803
807f8a8c 14804static int
505a2e88 14805nl80211_prep_sched_scan_msg(struct sk_buff *msg,
96b08fd6 14806 struct cfg80211_sched_scan_request *req, u32 cmd)
807f8a8c
LC
14807{
14808 void *hdr;
14809
96b08fd6 14810 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
807f8a8c
LC
14811 if (!hdr)
14812 return -1;
14813
96b08fd6
AVS
14814 if (nla_put_u32(msg, NL80211_ATTR_WIPHY,
14815 wiphy_to_rdev(req->wiphy)->wiphy_idx) ||
14816 nla_put_u32(msg, NL80211_ATTR_IFINDEX, req->dev->ifindex) ||
14817 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, req->reqid,
14818 NL80211_ATTR_PAD))
9360ffd1 14819 goto nla_put_failure;
807f8a8c 14820
053c095a
JB
14821 genlmsg_end(msg, hdr);
14822 return 0;
807f8a8c
LC
14823
14824 nla_put_failure:
14825 genlmsg_cancel(msg, hdr);
14826 return -EMSGSIZE;
14827}
14828
a538e2d5 14829void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 14830 struct wireless_dev *wdev)
a538e2d5
JB
14831{
14832 struct sk_buff *msg;
14833
58050fce 14834 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
14835 if (!msg)
14836 return;
14837
505a2e88 14838 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
14839 NL80211_CMD_TRIGGER_SCAN) < 0) {
14840 nlmsg_free(msg);
14841 return;
14842 }
14843
68eb5503 14844 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14845 NL80211_MCGRP_SCAN, GFP_KERNEL);
a538e2d5
JB
14846}
14847
f9d15d16
JB
14848struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev,
14849 struct wireless_dev *wdev, bool aborted)
2a519311
JB
14850{
14851 struct sk_buff *msg;
14852
fd2120ca 14853 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311 14854 if (!msg)
f9d15d16 14855 return NULL;
2a519311 14856
505a2e88 14857 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
f9d15d16
JB
14858 aborted ? NL80211_CMD_SCAN_ABORTED :
14859 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311 14860 nlmsg_free(msg);
f9d15d16 14861 return NULL;
2a519311
JB
14862 }
14863
f9d15d16 14864 return msg;
2a519311
JB
14865}
14866
505a2e88
AVS
14867/* send message created by nl80211_build_scan_msg() */
14868void nl80211_send_scan_msg(struct cfg80211_registered_device *rdev,
14869 struct sk_buff *msg)
807f8a8c 14870{
807f8a8c
LC
14871 if (!msg)
14872 return;
14873
68eb5503 14874 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 14875 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
14876}
14877
96b08fd6 14878void nl80211_send_sched_scan(struct cfg80211_sched_scan_request *req, u32 cmd)
807f8a8c
LC
14879{
14880 struct sk_buff *msg;
14881
58050fce 14882 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
14883 if (!msg)
14884 return;
14885
96b08fd6 14886 if (nl80211_prep_sched_scan_msg(msg, req, cmd) < 0) {
807f8a8c
LC
14887 nlmsg_free(msg);
14888 return;
14889 }
14890
96b08fd6 14891 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(req->wiphy), msg, 0,
2a94fe48 14892 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
14893}
14894
b0d7aa59
JD
14895static bool nl80211_reg_change_event_fill(struct sk_buff *msg,
14896 struct regulatory_request *request)
73d54c9e 14897{
73d54c9e 14898 /* Userspace can always count this one always being set */
9360ffd1
DM
14899 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
14900 goto nla_put_failure;
14901
14902 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
14903 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
14904 NL80211_REGDOM_TYPE_WORLD))
14905 goto nla_put_failure;
14906 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
14907 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
14908 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
14909 goto nla_put_failure;
14910 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
14911 request->intersect) {
14912 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
14913 NL80211_REGDOM_TYPE_INTERSECTION))
14914 goto nla_put_failure;
14915 } else {
14916 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
14917 NL80211_REGDOM_TYPE_COUNTRY) ||
14918 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
14919 request->alpha2))
14920 goto nla_put_failure;
14921 }
14922
ad30ca2c
AN
14923 if (request->wiphy_idx != WIPHY_IDX_INVALID) {
14924 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx);
14925
14926 if (wiphy &&
14927 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
14928 goto nla_put_failure;
1bdd716c
AN
14929
14930 if (wiphy &&
14931 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
14932 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
14933 goto nla_put_failure;
ad30ca2c 14934 }
73d54c9e 14935
b0d7aa59
JD
14936 return true;
14937
14938nla_put_failure:
14939 return false;
14940}
14941
14942/*
14943 * This can happen on global regulatory changes or device specific settings
14944 * based on custom regulatory domains.
14945 */
14946void nl80211_common_reg_change_event(enum nl80211_commands cmd_id,
14947 struct regulatory_request *request)
14948{
14949 struct sk_buff *msg;
14950 void *hdr;
14951
14952 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14953 if (!msg)
14954 return;
14955
14956 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id);
14957 if (!hdr) {
14958 nlmsg_free(msg);
14959 return;
14960 }
14961
14962 if (nl80211_reg_change_event_fill(msg, request) == false)
14963 goto nla_put_failure;
14964
3b7b72ee 14965 genlmsg_end(msg, hdr);
73d54c9e 14966
bc43b28c 14967 rcu_read_lock();
68eb5503 14968 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 14969 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
bc43b28c 14970 rcu_read_unlock();
73d54c9e
LR
14971
14972 return;
14973
14974nla_put_failure:
73d54c9e
LR
14975 nlmsg_free(msg);
14976}
14977
6039f6d2
JM
14978static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
14979 struct net_device *netdev,
14980 const u8 *buf, size_t len,
b0b6aa2c 14981 enum nl80211_commands cmd, gfp_t gfp,
4d9ec73d
JM
14982 int uapsd_queues, const u8 *req_ies,
14983 size_t req_ies_len)
6039f6d2
JM
14984{
14985 struct sk_buff *msg;
14986 void *hdr;
14987
4d9ec73d 14988 msg = nlmsg_new(100 + len + req_ies_len, gfp);
6039f6d2
JM
14989 if (!msg)
14990 return;
14991
14992 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
14993 if (!hdr) {
14994 nlmsg_free(msg);
14995 return;
14996 }
14997
9360ffd1
DM
14998 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
14999 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
4d9ec73d
JM
15000 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
15001 (req_ies &&
15002 nla_put(msg, NL80211_ATTR_REQ_IE, req_ies_len, req_ies)))
9360ffd1 15003 goto nla_put_failure;
6039f6d2 15004
b0b6aa2c
EP
15005 if (uapsd_queues >= 0) {
15006 struct nlattr *nla_wmm =
ae0be8de 15007 nla_nest_start_noflag(msg, NL80211_ATTR_STA_WME);
b0b6aa2c
EP
15008 if (!nla_wmm)
15009 goto nla_put_failure;
15010
15011 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
15012 uapsd_queues))
15013 goto nla_put_failure;
15014
15015 nla_nest_end(msg, nla_wmm);
15016 }
15017
3b7b72ee 15018 genlmsg_end(msg, hdr);
6039f6d2 15019
68eb5503 15020 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15021 NL80211_MCGRP_MLME, gfp);
6039f6d2
JM
15022 return;
15023
15024 nla_put_failure:
6039f6d2
JM
15025 nlmsg_free(msg);
15026}
15027
15028void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15029 struct net_device *netdev, const u8 *buf,
15030 size_t len, gfp_t gfp)
6039f6d2
JM
15031{
15032 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d 15033 NL80211_CMD_AUTHENTICATE, gfp, -1, NULL, 0);
6039f6d2
JM
15034}
15035
15036void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
15037 struct net_device *netdev, const u8 *buf,
4d9ec73d
JM
15038 size_t len, gfp_t gfp, int uapsd_queues,
15039 const u8 *req_ies, size_t req_ies_len)
6039f6d2 15040{
e6d6e342 15041 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d
JM
15042 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues,
15043 req_ies, req_ies_len);
6039f6d2
JM
15044}
15045
53b46b84 15046void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15047 struct net_device *netdev, const u8 *buf,
15048 size_t len, gfp_t gfp)
6039f6d2
JM
15049{
15050 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d 15051 NL80211_CMD_DEAUTHENTICATE, gfp, -1, NULL, 0);
6039f6d2
JM
15052}
15053
53b46b84
JM
15054void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
15055 struct net_device *netdev, const u8 *buf,
e6d6e342 15056 size_t len, gfp_t gfp)
6039f6d2
JM
15057{
15058 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d 15059 NL80211_CMD_DISASSOCIATE, gfp, -1, NULL, 0);
6039f6d2
JM
15060}
15061
6ff57cf8
JB
15062void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
15063 size_t len)
cf4e594e 15064{
947add36
JB
15065 struct wireless_dev *wdev = dev->ieee80211_ptr;
15066 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 15067 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
6ff57cf8
JB
15068 const struct ieee80211_mgmt *mgmt = (void *)buf;
15069 u32 cmd;
947add36 15070
6ff57cf8
JB
15071 if (WARN_ON(len < 2))
15072 return;
cf4e594e 15073
6ff57cf8
JB
15074 if (ieee80211_is_deauth(mgmt->frame_control))
15075 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
15076 else
15077 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
947add36 15078
6ff57cf8 15079 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
4d9ec73d
JM
15080 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1,
15081 NULL, 0);
cf4e594e 15082}
6ff57cf8 15083EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 15084
1b06bb40
LR
15085static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
15086 struct net_device *netdev, int cmd,
e6d6e342 15087 const u8 *addr, gfp_t gfp)
1965c853
JM
15088{
15089 struct sk_buff *msg;
15090 void *hdr;
15091
e6d6e342 15092 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
15093 if (!msg)
15094 return;
15095
15096 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
15097 if (!hdr) {
15098 nlmsg_free(msg);
15099 return;
15100 }
15101
9360ffd1
DM
15102 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15103 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15104 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
15105 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
15106 goto nla_put_failure;
1965c853 15107
3b7b72ee 15108 genlmsg_end(msg, hdr);
1965c853 15109
68eb5503 15110 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15111 NL80211_MCGRP_MLME, gfp);
1965c853
JM
15112 return;
15113
15114 nla_put_failure:
1965c853
JM
15115 nlmsg_free(msg);
15116}
15117
15118void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15119 struct net_device *netdev, const u8 *addr,
15120 gfp_t gfp)
1965c853
JM
15121{
15122 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 15123 addr, gfp);
1965c853
JM
15124}
15125
15126void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15127 struct net_device *netdev, const u8 *addr,
15128 gfp_t gfp)
1965c853 15129{
e6d6e342
JB
15130 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
15131 addr, gfp);
1965c853
JM
15132}
15133
b23aa676 15134void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5349a0f7
VK
15135 struct net_device *netdev,
15136 struct cfg80211_connect_resp_params *cr,
3093ebbe 15137 gfp_t gfp)
b23aa676
SO
15138{
15139 struct sk_buff *msg;
15140 void *hdr;
15141
a3caf744 15142 msg = nlmsg_new(100 + cr->req_ie_len + cr->resp_ie_len +
76804d28
AVS
15143 cr->fils.kek_len + cr->fils.pmk_len +
15144 (cr->fils.pmkid ? WLAN_PMKID_LEN : 0), gfp);
b23aa676
SO
15145 if (!msg)
15146 return;
15147
15148 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
15149 if (!hdr) {
15150 nlmsg_free(msg);
15151 return;
15152 }
15153
9360ffd1
DM
15154 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15155 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
5349a0f7
VK
15156 (cr->bssid &&
15157 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, cr->bssid)) ||
bf1ecd21 15158 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE,
5349a0f7
VK
15159 cr->status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE :
15160 cr->status) ||
15161 (cr->status < 0 &&
3093ebbe 15162 (nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
5349a0f7
VK
15163 nla_put_u32(msg, NL80211_ATTR_TIMEOUT_REASON,
15164 cr->timeout_reason))) ||
15165 (cr->req_ie &&
15166 nla_put(msg, NL80211_ATTR_REQ_IE, cr->req_ie_len, cr->req_ie)) ||
15167 (cr->resp_ie &&
15168 nla_put(msg, NL80211_ATTR_RESP_IE, cr->resp_ie_len,
a3caf744 15169 cr->resp_ie)) ||
76804d28 15170 (cr->fils.update_erp_next_seq_num &&
a3caf744 15171 nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
76804d28 15172 cr->fils.erp_next_seq_num)) ||
a3caf744 15173 (cr->status == WLAN_STATUS_SUCCESS &&
76804d28
AVS
15174 ((cr->fils.kek &&
15175 nla_put(msg, NL80211_ATTR_FILS_KEK, cr->fils.kek_len,
15176 cr->fils.kek)) ||
15177 (cr->fils.pmk &&
15178 nla_put(msg, NL80211_ATTR_PMK, cr->fils.pmk_len, cr->fils.pmk)) ||
15179 (cr->fils.pmkid &&
15180 nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, cr->fils.pmkid)))))
9360ffd1 15181 goto nla_put_failure;
b23aa676 15182
3b7b72ee 15183 genlmsg_end(msg, hdr);
b23aa676 15184
68eb5503 15185 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15186 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
15187 return;
15188
15189 nla_put_failure:
b23aa676 15190 nlmsg_free(msg);
b23aa676
SO
15191}
15192
15193void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
29ce6ecb
AS
15194 struct net_device *netdev,
15195 struct cfg80211_roam_info *info, gfp_t gfp)
b23aa676
SO
15196{
15197 struct sk_buff *msg;
15198 void *hdr;
29ce6ecb 15199 const u8 *bssid = info->bss ? info->bss->bssid : info->bssid;
b23aa676 15200
e841b7b1
AVS
15201 msg = nlmsg_new(100 + info->req_ie_len + info->resp_ie_len +
15202 info->fils.kek_len + info->fils.pmk_len +
15203 (info->fils.pmkid ? WLAN_PMKID_LEN : 0), gfp);
b23aa676
SO
15204 if (!msg)
15205 return;
15206
15207 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
15208 if (!hdr) {
15209 nlmsg_free(msg);
15210 return;
15211 }
15212
9360ffd1
DM
15213 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15214 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15215 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
29ce6ecb
AS
15216 (info->req_ie &&
15217 nla_put(msg, NL80211_ATTR_REQ_IE, info->req_ie_len,
15218 info->req_ie)) ||
15219 (info->resp_ie &&
15220 nla_put(msg, NL80211_ATTR_RESP_IE, info->resp_ie_len,
e841b7b1
AVS
15221 info->resp_ie)) ||
15222 (info->fils.update_erp_next_seq_num &&
15223 nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
15224 info->fils.erp_next_seq_num)) ||
15225 (info->fils.kek &&
15226 nla_put(msg, NL80211_ATTR_FILS_KEK, info->fils.kek_len,
15227 info->fils.kek)) ||
15228 (info->fils.pmk &&
15229 nla_put(msg, NL80211_ATTR_PMK, info->fils.pmk_len, info->fils.pmk)) ||
15230 (info->fils.pmkid &&
15231 nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, info->fils.pmkid)))
9360ffd1 15232 goto nla_put_failure;
b23aa676 15233
3b7b72ee 15234 genlmsg_end(msg, hdr);
b23aa676 15235
68eb5503 15236 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15237 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
15238 return;
15239
503c1fb9 15240 nla_put_failure:
503c1fb9
AS
15241 nlmsg_free(msg);
15242}
15243
15244void nl80211_send_port_authorized(struct cfg80211_registered_device *rdev,
15245 struct net_device *netdev, const u8 *bssid)
15246{
15247 struct sk_buff *msg;
15248 void *hdr;
15249
15250 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
15251 if (!msg)
15252 return;
15253
15254 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PORT_AUTHORIZED);
15255 if (!hdr) {
15256 nlmsg_free(msg);
15257 return;
15258 }
15259
f4d75993
CHH
15260 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15261 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15262 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
503c1fb9
AS
15263 goto nla_put_failure;
15264
15265 genlmsg_end(msg, hdr);
15266
15267 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
15268 NL80211_MCGRP_MLME, GFP_KERNEL);
15269 return;
15270
b23aa676 15271 nla_put_failure:
b23aa676 15272 nlmsg_free(msg);
b23aa676
SO
15273}
15274
15275void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
15276 struct net_device *netdev, u16 reason,
667503dd 15277 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
15278{
15279 struct sk_buff *msg;
15280 void *hdr;
15281
4ef8c1c9 15282 msg = nlmsg_new(100 + ie_len, GFP_KERNEL);
b23aa676
SO
15283 if (!msg)
15284 return;
15285
15286 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
15287 if (!hdr) {
15288 nlmsg_free(msg);
15289 return;
15290 }
15291
9360ffd1
DM
15292 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15293 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
86b6c465 15294 (reason &&
9360ffd1
DM
15295 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
15296 (from_ap &&
15297 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
15298 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
15299 goto nla_put_failure;
b23aa676 15300
3b7b72ee 15301 genlmsg_end(msg, hdr);
b23aa676 15302
68eb5503 15303 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15304 NL80211_MCGRP_MLME, GFP_KERNEL);
b23aa676
SO
15305 return;
15306
15307 nla_put_failure:
b23aa676 15308 nlmsg_free(msg);
b23aa676
SO
15309}
15310
04a773ad
JB
15311void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
15312 struct net_device *netdev, const u8 *bssid,
15313 gfp_t gfp)
15314{
15315 struct sk_buff *msg;
15316 void *hdr;
15317
fd2120ca 15318 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
15319 if (!msg)
15320 return;
15321
15322 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
15323 if (!hdr) {
15324 nlmsg_free(msg);
15325 return;
15326 }
15327
9360ffd1
DM
15328 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15329 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15330 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
15331 goto nla_put_failure;
04a773ad 15332
3b7b72ee 15333 genlmsg_end(msg, hdr);
04a773ad 15334
68eb5503 15335 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15336 NL80211_MCGRP_MLME, gfp);
04a773ad
JB
15337 return;
15338
15339 nla_put_failure:
04a773ad
JB
15340 nlmsg_free(msg);
15341}
15342
947add36 15343void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
ecbc12ad
BC
15344 const u8 *ie, u8 ie_len,
15345 int sig_dbm, gfp_t gfp)
c93b5e71 15346{
947add36 15347 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 15348 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
c93b5e71
JC
15349 struct sk_buff *msg;
15350 void *hdr;
15351
947add36
JB
15352 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
15353 return;
15354
15355 trace_cfg80211_notify_new_peer_candidate(dev, addr);
15356
4ef8c1c9 15357 msg = nlmsg_new(100 + ie_len, gfp);
c93b5e71
JC
15358 if (!msg)
15359 return;
15360
15361 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
15362 if (!hdr) {
15363 nlmsg_free(msg);
15364 return;
15365 }
15366
9360ffd1 15367 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
15368 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
15369 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1 15370 (ie_len && ie &&
ecbc12ad
BC
15371 nla_put(msg, NL80211_ATTR_IE, ie_len, ie)) ||
15372 (sig_dbm &&
15373 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)))
9360ffd1 15374 goto nla_put_failure;
c93b5e71 15375
3b7b72ee 15376 genlmsg_end(msg, hdr);
c93b5e71 15377
68eb5503 15378 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15379 NL80211_MCGRP_MLME, gfp);
c93b5e71
JC
15380 return;
15381
15382 nla_put_failure:
c93b5e71
JC
15383 nlmsg_free(msg);
15384}
947add36 15385EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 15386
a3b8b056
JM
15387void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
15388 struct net_device *netdev, const u8 *addr,
15389 enum nl80211_key_type key_type, int key_id,
e6d6e342 15390 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
15391{
15392 struct sk_buff *msg;
15393 void *hdr;
15394
e6d6e342 15395 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
15396 if (!msg)
15397 return;
15398
15399 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
15400 if (!hdr) {
15401 nlmsg_free(msg);
15402 return;
15403 }
15404
9360ffd1
DM
15405 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15406 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15407 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
15408 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
15409 (key_id != -1 &&
15410 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
15411 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
15412 goto nla_put_failure;
a3b8b056 15413
3b7b72ee 15414 genlmsg_end(msg, hdr);
a3b8b056 15415
68eb5503 15416 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15417 NL80211_MCGRP_MLME, gfp);
a3b8b056
JM
15418 return;
15419
15420 nla_put_failure:
a3b8b056
JM
15421 nlmsg_free(msg);
15422}
15423
6bad8766
LR
15424void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
15425 struct ieee80211_channel *channel_before,
15426 struct ieee80211_channel *channel_after)
15427{
15428 struct sk_buff *msg;
15429 void *hdr;
15430 struct nlattr *nl_freq;
15431
fd2120ca 15432 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
15433 if (!msg)
15434 return;
15435
15436 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
15437 if (!hdr) {
15438 nlmsg_free(msg);
15439 return;
15440 }
15441
15442 /*
15443 * Since we are applying the beacon hint to a wiphy we know its
15444 * wiphy_idx is valid
15445 */
9360ffd1
DM
15446 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
15447 goto nla_put_failure;
6bad8766
LR
15448
15449 /* Before */
ae0be8de 15450 nl_freq = nla_nest_start_noflag(msg, NL80211_ATTR_FREQ_BEFORE);
6bad8766
LR
15451 if (!nl_freq)
15452 goto nla_put_failure;
50f32718
HD
15453
15454 if (nl80211_msg_put_channel(msg, wiphy, channel_before, false))
6bad8766
LR
15455 goto nla_put_failure;
15456 nla_nest_end(msg, nl_freq);
15457
15458 /* After */
ae0be8de 15459 nl_freq = nla_nest_start_noflag(msg, NL80211_ATTR_FREQ_AFTER);
6bad8766
LR
15460 if (!nl_freq)
15461 goto nla_put_failure;
50f32718
HD
15462
15463 if (nl80211_msg_put_channel(msg, wiphy, channel_after, false))
6bad8766
LR
15464 goto nla_put_failure;
15465 nla_nest_end(msg, nl_freq);
15466
3b7b72ee 15467 genlmsg_end(msg, hdr);
6bad8766 15468
463d0183 15469 rcu_read_lock();
68eb5503 15470 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 15471 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
463d0183 15472 rcu_read_unlock();
6bad8766
LR
15473
15474 return;
15475
15476nla_put_failure:
6bad8766
LR
15477 nlmsg_free(msg);
15478}
15479
9588bbd5
JM
15480static void nl80211_send_remain_on_chan_event(
15481 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 15482 struct wireless_dev *wdev, u64 cookie,
9588bbd5 15483 struct ieee80211_channel *chan,
9588bbd5
JM
15484 unsigned int duration, gfp_t gfp)
15485{
15486 struct sk_buff *msg;
15487 void *hdr;
15488
15489 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
15490 if (!msg)
15491 return;
15492
15493 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
15494 if (!hdr) {
15495 nlmsg_free(msg);
15496 return;
15497 }
15498
9360ffd1 15499 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
15500 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
15501 wdev->netdev->ifindex)) ||
2dad624e
ND
15502 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15503 NL80211_ATTR_PAD) ||
9360ffd1 15504 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
15505 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
15506 NL80211_CHAN_NO_HT) ||
2dad624e
ND
15507 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
15508 NL80211_ATTR_PAD))
9360ffd1 15509 goto nla_put_failure;
9588bbd5 15510
9360ffd1
DM
15511 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
15512 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
15513 goto nla_put_failure;
9588bbd5 15514
3b7b72ee 15515 genlmsg_end(msg, hdr);
9588bbd5 15516
68eb5503 15517 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15518 NL80211_MCGRP_MLME, gfp);
9588bbd5
JM
15519 return;
15520
15521 nla_put_failure:
9588bbd5
JM
15522 nlmsg_free(msg);
15523}
15524
947add36
JB
15525void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
15526 struct ieee80211_channel *chan,
15527 unsigned int duration, gfp_t gfp)
9588bbd5 15528{
947add36 15529 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 15530 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
15531
15532 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 15533 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 15534 rdev, wdev, cookie, chan,
42d97a59 15535 duration, gfp);
9588bbd5 15536}
947add36 15537EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 15538
947add36
JB
15539void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
15540 struct ieee80211_channel *chan,
15541 gfp_t gfp)
9588bbd5 15542{
947add36 15543 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 15544 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
15545
15546 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 15547 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 15548 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 15549}
947add36 15550EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 15551
1c38c7f2
JP
15552void cfg80211_tx_mgmt_expired(struct wireless_dev *wdev, u64 cookie,
15553 struct ieee80211_channel *chan,
15554 gfp_t gfp)
15555{
15556 struct wiphy *wiphy = wdev->wiphy;
15557 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
15558
15559 trace_cfg80211_tx_mgmt_expired(wdev, cookie, chan);
15560 nl80211_send_remain_on_chan_event(NL80211_CMD_FRAME_WAIT_CANCEL,
15561 rdev, wdev, cookie, chan, 0, gfp);
15562}
15563EXPORT_SYMBOL(cfg80211_tx_mgmt_expired);
15564
947add36
JB
15565void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
15566 struct station_info *sinfo, gfp_t gfp)
98b62183 15567{
947add36 15568 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 15569 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
98b62183
JB
15570 struct sk_buff *msg;
15571
947add36
JB
15572 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
15573
58050fce 15574 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
15575 if (!msg)
15576 return;
15577
cf5ead82 15578 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0,
66266b3a 15579 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
15580 nlmsg_free(msg);
15581 return;
15582 }
15583
68eb5503 15584 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15585 NL80211_MCGRP_MLME, gfp);
98b62183 15586}
947add36 15587EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 15588
cf5ead82
JB
15589void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr,
15590 struct station_info *sinfo, gfp_t gfp)
ec15e68b 15591{
947add36 15592 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 15593 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ec15e68b 15594 struct sk_buff *msg;
73887fd9 15595 struct station_info empty_sinfo = {};
cf5ead82 15596
73887fd9
JB
15597 if (!sinfo)
15598 sinfo = &empty_sinfo;
ec15e68b 15599
947add36
JB
15600 trace_cfg80211_del_sta(dev, mac_addr);
15601
58050fce 15602 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7ea3e110
JB
15603 if (!msg) {
15604 cfg80211_sinfo_release_content(sinfo);
73887fd9 15605 return;
7ea3e110 15606 }
ec15e68b 15607
cf5ead82 15608 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0,
57007121 15609 rdev, dev, mac_addr, sinfo) < 0) {
ec15e68b 15610 nlmsg_free(msg);
73887fd9 15611 return;
ec15e68b
JM
15612 }
15613
68eb5503 15614 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15615 NL80211_MCGRP_MLME, gfp);
ec15e68b 15616}
cf5ead82 15617EXPORT_SYMBOL(cfg80211_del_sta_sinfo);
ec15e68b 15618
947add36
JB
15619void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
15620 enum nl80211_connect_failed_reason reason,
15621 gfp_t gfp)
ed44a951 15622{
947add36 15623 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 15624 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ed44a951
PP
15625 struct sk_buff *msg;
15626 void *hdr;
15627
15628 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
15629 if (!msg)
15630 return;
15631
15632 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
15633 if (!hdr) {
15634 nlmsg_free(msg);
15635 return;
15636 }
15637
15638 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
15639 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
15640 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
15641 goto nla_put_failure;
15642
15643 genlmsg_end(msg, hdr);
15644
68eb5503 15645 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15646 NL80211_MCGRP_MLME, gfp);
ed44a951
PP
15647 return;
15648
15649 nla_put_failure:
ed44a951
PP
15650 nlmsg_free(msg);
15651}
947add36 15652EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 15653
b92ab5d8
JB
15654static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
15655 const u8 *addr, gfp_t gfp)
28946da7
JB
15656{
15657 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 15658 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
28946da7
JB
15659 struct sk_buff *msg;
15660 void *hdr;
6aa7de05 15661 u32 nlportid = READ_ONCE(wdev->ap_unexpected_nlportid);
28946da7 15662
15e47304 15663 if (!nlportid)
28946da7
JB
15664 return false;
15665
15666 msg = nlmsg_new(100, gfp);
15667 if (!msg)
15668 return true;
15669
b92ab5d8 15670 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
15671 if (!hdr) {
15672 nlmsg_free(msg);
15673 return true;
15674 }
15675
9360ffd1
DM
15676 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15677 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
15678 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
15679 goto nla_put_failure;
28946da7 15680
9c90a9f6 15681 genlmsg_end(msg, hdr);
15e47304 15682 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
15683 return true;
15684
15685 nla_put_failure:
28946da7
JB
15686 nlmsg_free(msg);
15687 return true;
15688}
15689
947add36
JB
15690bool cfg80211_rx_spurious_frame(struct net_device *dev,
15691 const u8 *addr, gfp_t gfp)
b92ab5d8 15692{
947add36
JB
15693 struct wireless_dev *wdev = dev->ieee80211_ptr;
15694 bool ret;
15695
15696 trace_cfg80211_rx_spurious_frame(dev, addr);
15697
15698 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
15699 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
15700 trace_cfg80211_return_bool(false);
15701 return false;
15702 }
15703 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
15704 addr, gfp);
15705 trace_cfg80211_return_bool(ret);
15706 return ret;
b92ab5d8 15707}
947add36 15708EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 15709
947add36
JB
15710bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
15711 const u8 *addr, gfp_t gfp)
b92ab5d8 15712{
947add36
JB
15713 struct wireless_dev *wdev = dev->ieee80211_ptr;
15714 bool ret;
15715
15716 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
15717
15718 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
15719 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
15720 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
15721 trace_cfg80211_return_bool(false);
15722 return false;
15723 }
15724 ret = __nl80211_unexpected_frame(dev,
15725 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
15726 addr, gfp);
15727 trace_cfg80211_return_bool(ret);
15728 return ret;
b92ab5d8 15729}
947add36 15730EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 15731
2e161f78 15732int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 15733 struct wireless_dev *wdev, u32 nlportid,
804483e9 15734 int freq, int sig_dbm,
19504cf5 15735 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 15736{
71bbc994 15737 struct net_device *netdev = wdev->netdev;
026331c4
JM
15738 struct sk_buff *msg;
15739 void *hdr;
026331c4 15740
4ef8c1c9 15741 msg = nlmsg_new(100 + len, gfp);
026331c4
JM
15742 if (!msg)
15743 return -ENOMEM;
15744
2e161f78 15745 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
15746 if (!hdr) {
15747 nlmsg_free(msg);
15748 return -ENOMEM;
15749 }
15750
9360ffd1 15751 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
15752 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
15753 netdev->ifindex)) ||
2dad624e
ND
15754 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15755 NL80211_ATTR_PAD) ||
9360ffd1
DM
15756 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
15757 (sig_dbm &&
15758 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
15759 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
15760 (flags &&
15761 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 15762 goto nla_put_failure;
026331c4 15763
3b7b72ee 15764 genlmsg_end(msg, hdr);
026331c4 15765
15e47304 15766 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
15767
15768 nla_put_failure:
026331c4
JM
15769 nlmsg_free(msg);
15770 return -ENOBUFS;
15771}
15772
947add36
JB
15773void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
15774 const u8 *buf, size_t len, bool ack, gfp_t gfp)
026331c4 15775{
947add36 15776 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 15777 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
71bbc994 15778 struct net_device *netdev = wdev->netdev;
026331c4
JM
15779 struct sk_buff *msg;
15780 void *hdr;
15781
947add36
JB
15782 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
15783
4ef8c1c9 15784 msg = nlmsg_new(100 + len, gfp);
026331c4
JM
15785 if (!msg)
15786 return;
15787
2e161f78 15788 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
15789 if (!hdr) {
15790 nlmsg_free(msg);
15791 return;
15792 }
15793
9360ffd1 15794 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
15795 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
15796 netdev->ifindex)) ||
2dad624e
ND
15797 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15798 NL80211_ATTR_PAD) ||
9360ffd1 15799 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
2dad624e
ND
15800 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
15801 NL80211_ATTR_PAD) ||
9360ffd1
DM
15802 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
15803 goto nla_put_failure;
026331c4 15804
3b7b72ee 15805 genlmsg_end(msg, hdr);
026331c4 15806
68eb5503 15807 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15808 NL80211_MCGRP_MLME, gfp);
026331c4
JM
15809 return;
15810
15811 nla_put_failure:
026331c4
JM
15812 nlmsg_free(msg);
15813}
947add36 15814EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 15815
6a671a50 15816static int __nl80211_rx_control_port(struct net_device *dev,
a948f713 15817 struct sk_buff *skb,
6a671a50
DK
15818 bool unencrypted, gfp_t gfp)
15819{
15820 struct wireless_dev *wdev = dev->ieee80211_ptr;
15821 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
a948f713
DK
15822 struct ethhdr *ehdr = eth_hdr(skb);
15823 const u8 *addr = ehdr->h_source;
15824 u16 proto = be16_to_cpu(skb->protocol);
6a671a50
DK
15825 struct sk_buff *msg;
15826 void *hdr;
a948f713
DK
15827 struct nlattr *frame;
15828
6a671a50
DK
15829 u32 nlportid = READ_ONCE(wdev->conn_owner_nlportid);
15830
15831 if (!nlportid)
15832 return -ENOENT;
15833
a948f713 15834 msg = nlmsg_new(100 + skb->len, gfp);
6a671a50
DK
15835 if (!msg)
15836 return -ENOMEM;
15837
15838 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONTROL_PORT_FRAME);
15839 if (!hdr) {
15840 nlmsg_free(msg);
15841 return -ENOBUFS;
15842 }
15843
15844 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15845 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
15846 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15847 NL80211_ATTR_PAD) ||
6a671a50
DK
15848 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
15849 nla_put_u16(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE, proto) ||
15850 (unencrypted && nla_put_flag(msg,
15851 NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT)))
15852 goto nla_put_failure;
15853
a948f713
DK
15854 frame = nla_reserve(msg, NL80211_ATTR_FRAME, skb->len);
15855 if (!frame)
15856 goto nla_put_failure;
15857
15858 skb_copy_bits(skb, 0, nla_data(frame), skb->len);
6a671a50
DK
15859 genlmsg_end(msg, hdr);
15860
15861 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
15862
15863 nla_put_failure:
15864 nlmsg_free(msg);
15865 return -ENOBUFS;
15866}
15867
15868bool cfg80211_rx_control_port(struct net_device *dev,
a948f713 15869 struct sk_buff *skb, bool unencrypted)
6a671a50
DK
15870{
15871 int ret;
15872
a948f713
DK
15873 trace_cfg80211_rx_control_port(dev, skb, unencrypted);
15874 ret = __nl80211_rx_control_port(dev, skb, unencrypted, GFP_ATOMIC);
6a671a50
DK
15875 trace_cfg80211_return_bool(ret == 0);
15876 return ret == 0;
15877}
15878EXPORT_SYMBOL(cfg80211_rx_control_port);
15879
5b97f49d
JB
15880static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev,
15881 const char *mac, gfp_t gfp)
d6dc1a38 15882{
947add36 15883 struct wireless_dev *wdev = dev->ieee80211_ptr;
5b97f49d
JB
15884 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
15885 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
15886 void **cb;
947add36 15887
d6dc1a38 15888 if (!msg)
5b97f49d 15889 return NULL;
d6dc1a38 15890
5b97f49d
JB
15891 cb = (void **)msg->cb;
15892
15893 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
15894 if (!cb[0]) {
d6dc1a38 15895 nlmsg_free(msg);
5b97f49d 15896 return NULL;
d6dc1a38
JO
15897 }
15898
9360ffd1 15899 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 15900 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 15901 goto nla_put_failure;
d6dc1a38 15902
5b97f49d 15903 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
d6dc1a38
JO
15904 goto nla_put_failure;
15905
ae0be8de 15906 cb[1] = nla_nest_start_noflag(msg, NL80211_ATTR_CQM);
5b97f49d 15907 if (!cb[1])
9360ffd1 15908 goto nla_put_failure;
d6dc1a38 15909
5b97f49d 15910 cb[2] = rdev;
d6dc1a38 15911
5b97f49d
JB
15912 return msg;
15913 nla_put_failure:
15914 nlmsg_free(msg);
15915 return NULL;
15916}
15917
15918static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp)
15919{
15920 void **cb = (void **)msg->cb;
15921 struct cfg80211_registered_device *rdev = cb[2];
15922
15923 nla_nest_end(msg, cb[1]);
15924 genlmsg_end(msg, cb[0]);
15925
15926 memset(msg->cb, 0, sizeof(msg->cb));
d6dc1a38 15927
68eb5503 15928 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15929 NL80211_MCGRP_MLME, gfp);
5b97f49d
JB
15930}
15931
15932void cfg80211_cqm_rssi_notify(struct net_device *dev,
15933 enum nl80211_cqm_rssi_threshold_event rssi_event,
bee427b8 15934 s32 rssi_level, gfp_t gfp)
5b97f49d
JB
15935{
15936 struct sk_buff *msg;
4a4b8169
AZ
15937 struct wireless_dev *wdev = dev->ieee80211_ptr;
15938 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
5b97f49d 15939
bee427b8 15940 trace_cfg80211_cqm_rssi_notify(dev, rssi_event, rssi_level);
5b97f49d 15941
98f03342
JB
15942 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW &&
15943 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH))
15944 return;
15945
4a4b8169
AZ
15946 if (wdev->cqm_config) {
15947 wdev->cqm_config->last_rssi_event_value = rssi_level;
15948
15949 cfg80211_cqm_rssi_update(rdev, dev);
15950
15951 if (rssi_level == 0)
15952 rssi_level = wdev->cqm_config->last_rssi_event_value;
15953 }
15954
5b97f49d
JB
15955 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
15956 if (!msg)
15957 return;
15958
15959 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
15960 rssi_event))
15961 goto nla_put_failure;
15962
bee427b8
AZ
15963 if (rssi_level && nla_put_s32(msg, NL80211_ATTR_CQM_RSSI_LEVEL,
15964 rssi_level))
15965 goto nla_put_failure;
15966
5b97f49d
JB
15967 cfg80211_send_cqm(msg, gfp);
15968
d6dc1a38
JO
15969 return;
15970
15971 nla_put_failure:
d6dc1a38
JO
15972 nlmsg_free(msg);
15973}
947add36 15974EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 15975
5b97f49d
JB
15976void cfg80211_cqm_txe_notify(struct net_device *dev,
15977 const u8 *peer, u32 num_packets,
15978 u32 rate, u32 intvl, gfp_t gfp)
15979{
15980 struct sk_buff *msg;
15981
15982 msg = cfg80211_prepare_cqm(dev, peer, gfp);
15983 if (!msg)
15984 return;
15985
15986 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
15987 goto nla_put_failure;
15988
15989 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
15990 goto nla_put_failure;
15991
15992 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
15993 goto nla_put_failure;
15994
15995 cfg80211_send_cqm(msg, gfp);
15996 return;
15997
15998 nla_put_failure:
15999 nlmsg_free(msg);
16000}
16001EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
16002
16003void cfg80211_cqm_pktloss_notify(struct net_device *dev,
16004 const u8 *peer, u32 num_packets, gfp_t gfp)
16005{
16006 struct sk_buff *msg;
16007
16008 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
16009
16010 msg = cfg80211_prepare_cqm(dev, peer, gfp);
16011 if (!msg)
16012 return;
16013
16014 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
16015 goto nla_put_failure;
16016
16017 cfg80211_send_cqm(msg, gfp);
16018 return;
16019
16020 nla_put_failure:
16021 nlmsg_free(msg);
16022}
16023EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
16024
98f03342
JB
16025void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp)
16026{
16027 struct sk_buff *msg;
16028
16029 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
16030 if (!msg)
16031 return;
16032
16033 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT))
16034 goto nla_put_failure;
16035
16036 cfg80211_send_cqm(msg, gfp);
16037 return;
16038
16039 nla_put_failure:
16040 nlmsg_free(msg);
16041}
16042EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify);
16043
947add36
JB
16044static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
16045 struct net_device *netdev, const u8 *bssid,
16046 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
16047{
16048 struct sk_buff *msg;
16049 struct nlattr *rekey_attr;
16050 void *hdr;
16051
58050fce 16052 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
16053 if (!msg)
16054 return;
16055
16056 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
16057 if (!hdr) {
16058 nlmsg_free(msg);
16059 return;
16060 }
16061
9360ffd1
DM
16062 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16063 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
16064 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
16065 goto nla_put_failure;
e5497d76 16066
ae0be8de 16067 rekey_attr = nla_nest_start_noflag(msg, NL80211_ATTR_REKEY_DATA);
e5497d76
JB
16068 if (!rekey_attr)
16069 goto nla_put_failure;
16070
9360ffd1
DM
16071 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
16072 NL80211_REPLAY_CTR_LEN, replay_ctr))
16073 goto nla_put_failure;
e5497d76
JB
16074
16075 nla_nest_end(msg, rekey_attr);
16076
3b7b72ee 16077 genlmsg_end(msg, hdr);
e5497d76 16078
68eb5503 16079 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16080 NL80211_MCGRP_MLME, gfp);
e5497d76
JB
16081 return;
16082
16083 nla_put_failure:
e5497d76
JB
16084 nlmsg_free(msg);
16085}
16086
947add36
JB
16087void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
16088 const u8 *replay_ctr, gfp_t gfp)
16089{
16090 struct wireless_dev *wdev = dev->ieee80211_ptr;
16091 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16092 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
16093
16094 trace_cfg80211_gtk_rekey_notify(dev, bssid);
16095 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
16096}
16097EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
16098
16099static void
16100nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
16101 struct net_device *netdev, int index,
16102 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
16103{
16104 struct sk_buff *msg;
16105 struct nlattr *attr;
16106 void *hdr;
16107
58050fce 16108 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
16109 if (!msg)
16110 return;
16111
16112 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
16113 if (!hdr) {
16114 nlmsg_free(msg);
16115 return;
16116 }
16117
9360ffd1
DM
16118 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16119 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
16120 goto nla_put_failure;
c9df56b4 16121
ae0be8de 16122 attr = nla_nest_start_noflag(msg, NL80211_ATTR_PMKSA_CANDIDATE);
c9df56b4
JM
16123 if (!attr)
16124 goto nla_put_failure;
16125
9360ffd1
DM
16126 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
16127 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
16128 (preauth &&
16129 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
16130 goto nla_put_failure;
c9df56b4
JM
16131
16132 nla_nest_end(msg, attr);
16133
3b7b72ee 16134 genlmsg_end(msg, hdr);
c9df56b4 16135
68eb5503 16136 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16137 NL80211_MCGRP_MLME, gfp);
c9df56b4
JM
16138 return;
16139
16140 nla_put_failure:
c9df56b4
JM
16141 nlmsg_free(msg);
16142}
16143
947add36
JB
16144void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
16145 const u8 *bssid, bool preauth, gfp_t gfp)
16146{
16147 struct wireless_dev *wdev = dev->ieee80211_ptr;
16148 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16149 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
16150
16151 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
16152 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
16153}
16154EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
16155
16156static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
16157 struct net_device *netdev,
16158 struct cfg80211_chan_def *chandef,
f8d7552e
LC
16159 gfp_t gfp,
16160 enum nl80211_commands notif,
16161 u8 count)
5314526b
TP
16162{
16163 struct sk_buff *msg;
16164 void *hdr;
16165
58050fce 16166 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
16167 if (!msg)
16168 return;
16169
f8d7552e 16170 hdr = nl80211hdr_put(msg, 0, 0, 0, notif);
5314526b
TP
16171 if (!hdr) {
16172 nlmsg_free(msg);
16173 return;
16174 }
16175
683b6d3b
JB
16176 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
16177 goto nla_put_failure;
16178
16179 if (nl80211_send_chandef(msg, chandef))
7eab0f64 16180 goto nla_put_failure;
5314526b 16181
f8d7552e
LC
16182 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) &&
16183 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count)))
16184 goto nla_put_failure;
16185
5314526b
TP
16186 genlmsg_end(msg, hdr);
16187
68eb5503 16188 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16189 NL80211_MCGRP_MLME, gfp);
5314526b
TP
16190 return;
16191
16192 nla_put_failure:
5314526b
TP
16193 nlmsg_free(msg);
16194}
16195
947add36
JB
16196void cfg80211_ch_switch_notify(struct net_device *dev,
16197 struct cfg80211_chan_def *chandef)
84f10708 16198{
947add36
JB
16199 struct wireless_dev *wdev = dev->ieee80211_ptr;
16200 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16201 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36 16202
e487eaeb 16203 ASSERT_WDEV_LOCK(wdev);
947add36 16204
e487eaeb 16205 trace_cfg80211_ch_switch_notify(dev, chandef);
947add36 16206
9e0e2961 16207 wdev->chandef = *chandef;
96f55f12 16208 wdev->preset_chandef = *chandef;
5dc8cdce
SM
16209
16210 if (wdev->iftype == NL80211_IFTYPE_STATION &&
16211 !WARN_ON(!wdev->current_bss))
0afd425b 16212 cfg80211_update_assoc_bss_entry(wdev, chandef->chan);
5dc8cdce 16213
d34990bb
MV
16214 cfg80211_sched_dfs_chan_update(rdev);
16215
f8d7552e
LC
16216 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
16217 NL80211_CMD_CH_SWITCH_NOTIFY, 0);
947add36
JB
16218}
16219EXPORT_SYMBOL(cfg80211_ch_switch_notify);
16220
f8d7552e
LC
16221void cfg80211_ch_switch_started_notify(struct net_device *dev,
16222 struct cfg80211_chan_def *chandef,
16223 u8 count)
16224{
16225 struct wireless_dev *wdev = dev->ieee80211_ptr;
16226 struct wiphy *wiphy = wdev->wiphy;
16227 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
16228
16229 trace_cfg80211_ch_switch_started_notify(dev, chandef);
16230
16231 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
16232 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count);
16233}
16234EXPORT_SYMBOL(cfg80211_ch_switch_started_notify);
16235
04f39047
SW
16236void
16237nl80211_radar_notify(struct cfg80211_registered_device *rdev,
d2859df5 16238 const struct cfg80211_chan_def *chandef,
04f39047
SW
16239 enum nl80211_radar_event event,
16240 struct net_device *netdev, gfp_t gfp)
16241{
16242 struct sk_buff *msg;
16243 void *hdr;
16244
16245 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16246 if (!msg)
16247 return;
16248
16249 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
16250 if (!hdr) {
16251 nlmsg_free(msg);
16252 return;
16253 }
16254
16255 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
16256 goto nla_put_failure;
16257
16258 /* NOP and radar events don't need a netdev parameter */
16259 if (netdev) {
16260 struct wireless_dev *wdev = netdev->ieee80211_ptr;
16261
16262 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
2dad624e
ND
16263 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16264 NL80211_ATTR_PAD))
04f39047
SW
16265 goto nla_put_failure;
16266 }
16267
16268 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
16269 goto nla_put_failure;
16270
16271 if (nl80211_send_chandef(msg, chandef))
16272 goto nla_put_failure;
16273
9c90a9f6 16274 genlmsg_end(msg, hdr);
04f39047 16275
68eb5503 16276 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16277 NL80211_MCGRP_MLME, gfp);
04f39047
SW
16278 return;
16279
16280 nla_put_failure:
04f39047
SW
16281 nlmsg_free(msg);
16282}
16283
466b9936 16284void cfg80211_sta_opmode_change_notify(struct net_device *dev, const u8 *mac,
16285 struct sta_opmode_info *sta_opmode,
16286 gfp_t gfp)
16287{
16288 struct sk_buff *msg;
16289 struct wireless_dev *wdev = dev->ieee80211_ptr;
16290 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
16291 void *hdr;
16292
16293 if (WARN_ON(!mac))
16294 return;
16295
16296 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16297 if (!msg)
16298 return;
16299
16300 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STA_OPMODE_CHANGED);
16301 if (!hdr) {
16302 nlmsg_free(msg);
16303 return;
16304 }
16305
16306 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
16307 goto nla_put_failure;
16308
16309 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
16310 goto nla_put_failure;
16311
16312 if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
16313 goto nla_put_failure;
16314
16315 if ((sta_opmode->changed & STA_OPMODE_SMPS_MODE_CHANGED) &&
16316 nla_put_u8(msg, NL80211_ATTR_SMPS_MODE, sta_opmode->smps_mode))
16317 goto nla_put_failure;
16318
16319 if ((sta_opmode->changed & STA_OPMODE_MAX_BW_CHANGED) &&
16320 nla_put_u8(msg, NL80211_ATTR_CHANNEL_WIDTH, sta_opmode->bw))
16321 goto nla_put_failure;
16322
16323 if ((sta_opmode->changed & STA_OPMODE_N_SS_CHANGED) &&
16324 nla_put_u8(msg, NL80211_ATTR_NSS, sta_opmode->rx_nss))
16325 goto nla_put_failure;
16326
16327 genlmsg_end(msg, hdr);
16328
16329 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
16330 NL80211_MCGRP_MLME, gfp);
16331
16332 return;
16333
16334nla_put_failure:
16335 nlmsg_free(msg);
16336}
16337EXPORT_SYMBOL(cfg80211_sta_opmode_change_notify);
16338
7f6cf311 16339void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
c4b50cd3
VN
16340 u64 cookie, bool acked, s32 ack_signal,
16341 bool is_valid_ack_signal, gfp_t gfp)
7f6cf311
JB
16342{
16343 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 16344 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
7f6cf311
JB
16345 struct sk_buff *msg;
16346 void *hdr;
7f6cf311 16347
4ee3e063
BL
16348 trace_cfg80211_probe_status(dev, addr, cookie, acked);
16349
58050fce 16350 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 16351
7f6cf311
JB
16352 if (!msg)
16353 return;
16354
16355 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
16356 if (!hdr) {
16357 nlmsg_free(msg);
16358 return;
16359 }
16360
9360ffd1
DM
16361 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16362 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16363 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
2dad624e
ND
16364 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
16365 NL80211_ATTR_PAD) ||
c4b50cd3
VN
16366 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)) ||
16367 (is_valid_ack_signal && nla_put_s32(msg, NL80211_ATTR_ACK_SIGNAL,
16368 ack_signal)))
9360ffd1 16369 goto nla_put_failure;
7f6cf311 16370
9c90a9f6 16371 genlmsg_end(msg, hdr);
7f6cf311 16372
68eb5503 16373 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16374 NL80211_MCGRP_MLME, gfp);
7f6cf311
JB
16375 return;
16376
16377 nla_put_failure:
7f6cf311
JB
16378 nlmsg_free(msg);
16379}
16380EXPORT_SYMBOL(cfg80211_probe_status);
16381
5e760230
JB
16382void cfg80211_report_obss_beacon(struct wiphy *wiphy,
16383 const u8 *frame, size_t len,
37c73b5f 16384 int freq, int sig_dbm)
5e760230 16385{
f26cbf40 16386 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
5e760230
JB
16387 struct sk_buff *msg;
16388 void *hdr;
37c73b5f 16389 struct cfg80211_beacon_registration *reg;
5e760230 16390
4ee3e063
BL
16391 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
16392
37c73b5f
BG
16393 spin_lock_bh(&rdev->beacon_registrations_lock);
16394 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
16395 msg = nlmsg_new(len + 100, GFP_ATOMIC);
16396 if (!msg) {
16397 spin_unlock_bh(&rdev->beacon_registrations_lock);
16398 return;
16399 }
5e760230 16400
37c73b5f
BG
16401 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
16402 if (!hdr)
16403 goto nla_put_failure;
5e760230 16404
37c73b5f
BG
16405 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16406 (freq &&
16407 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
16408 (sig_dbm &&
16409 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
16410 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
16411 goto nla_put_failure;
5e760230 16412
37c73b5f 16413 genlmsg_end(msg, hdr);
5e760230 16414
37c73b5f
BG
16415 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
16416 }
16417 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
16418 return;
16419
16420 nla_put_failure:
37c73b5f 16421 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
16422 nlmsg_free(msg);
16423}
16424EXPORT_SYMBOL(cfg80211_report_obss_beacon);
16425
cd8f7cb4 16426#ifdef CONFIG_PM
8cd4d456
LC
16427static int cfg80211_net_detect_results(struct sk_buff *msg,
16428 struct cfg80211_wowlan_wakeup *wakeup)
16429{
16430 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect;
16431 struct nlattr *nl_results, *nl_match, *nl_freqs;
16432 int i, j;
16433
ae0be8de
MK
16434 nl_results = nla_nest_start_noflag(msg,
16435 NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS);
8cd4d456
LC
16436 if (!nl_results)
16437 return -EMSGSIZE;
16438
16439 for (i = 0; i < nd->n_matches; i++) {
16440 struct cfg80211_wowlan_nd_match *match = nd->matches[i];
16441
ae0be8de 16442 nl_match = nla_nest_start_noflag(msg, i);
8cd4d456
LC
16443 if (!nl_match)
16444 break;
16445
16446 /* The SSID attribute is optional in nl80211, but for
16447 * simplicity reasons it's always present in the
16448 * cfg80211 structure. If a driver can't pass the
16449 * SSID, that needs to be changed. A zero length SSID
16450 * is still a valid SSID (wildcard), so it cannot be
16451 * used for this purpose.
16452 */
16453 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len,
16454 match->ssid.ssid)) {
16455 nla_nest_cancel(msg, nl_match);
16456 goto out;
16457 }
16458
16459 if (match->n_channels) {
ae0be8de
MK
16460 nl_freqs = nla_nest_start_noflag(msg,
16461 NL80211_ATTR_SCAN_FREQUENCIES);
8cd4d456
LC
16462 if (!nl_freqs) {
16463 nla_nest_cancel(msg, nl_match);
16464 goto out;
16465 }
16466
16467 for (j = 0; j < match->n_channels; j++) {
5528fae8 16468 if (nla_put_u32(msg, j, match->channels[j])) {
8cd4d456
LC
16469 nla_nest_cancel(msg, nl_freqs);
16470 nla_nest_cancel(msg, nl_match);
16471 goto out;
16472 }
16473 }
16474
16475 nla_nest_end(msg, nl_freqs);
16476 }
16477
16478 nla_nest_end(msg, nl_match);
16479 }
16480
16481out:
16482 nla_nest_end(msg, nl_results);
16483 return 0;
16484}
16485
cd8f7cb4
JB
16486void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
16487 struct cfg80211_wowlan_wakeup *wakeup,
16488 gfp_t gfp)
16489{
f26cbf40 16490 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
cd8f7cb4
JB
16491 struct sk_buff *msg;
16492 void *hdr;
9c90a9f6 16493 int size = 200;
cd8f7cb4
JB
16494
16495 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
16496
16497 if (wakeup)
16498 size += wakeup->packet_present_len;
16499
16500 msg = nlmsg_new(size, gfp);
16501 if (!msg)
16502 return;
16503
16504 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
16505 if (!hdr)
16506 goto free_msg;
16507
16508 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
16509 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16510 NL80211_ATTR_PAD))
cd8f7cb4
JB
16511 goto free_msg;
16512
16513 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
16514 wdev->netdev->ifindex))
16515 goto free_msg;
16516
16517 if (wakeup) {
16518 struct nlattr *reasons;
16519
ae0be8de
MK
16520 reasons = nla_nest_start_noflag(msg,
16521 NL80211_ATTR_WOWLAN_TRIGGERS);
7fa322c8
JB
16522 if (!reasons)
16523 goto free_msg;
cd8f7cb4
JB
16524
16525 if (wakeup->disconnect &&
16526 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
16527 goto free_msg;
16528 if (wakeup->magic_pkt &&
16529 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
16530 goto free_msg;
16531 if (wakeup->gtk_rekey_failure &&
16532 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
16533 goto free_msg;
16534 if (wakeup->eap_identity_req &&
16535 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
16536 goto free_msg;
16537 if (wakeup->four_way_handshake &&
16538 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
16539 goto free_msg;
16540 if (wakeup->rfkill_release &&
16541 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
16542 goto free_msg;
16543
16544 if (wakeup->pattern_idx >= 0 &&
16545 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
16546 wakeup->pattern_idx))
16547 goto free_msg;
16548
ae917c9f
JB
16549 if (wakeup->tcp_match &&
16550 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
16551 goto free_msg;
2a0e047e 16552
ae917c9f
JB
16553 if (wakeup->tcp_connlost &&
16554 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
16555 goto free_msg;
2a0e047e 16556
ae917c9f
JB
16557 if (wakeup->tcp_nomoretokens &&
16558 nla_put_flag(msg,
16559 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
16560 goto free_msg;
2a0e047e 16561
cd8f7cb4
JB
16562 if (wakeup->packet) {
16563 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
16564 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
16565
16566 if (!wakeup->packet_80211) {
16567 pkt_attr =
16568 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
16569 len_attr =
16570 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
16571 }
16572
16573 if (wakeup->packet_len &&
16574 nla_put_u32(msg, len_attr, wakeup->packet_len))
16575 goto free_msg;
16576
16577 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
16578 wakeup->packet))
16579 goto free_msg;
16580 }
16581
8cd4d456
LC
16582 if (wakeup->net_detect &&
16583 cfg80211_net_detect_results(msg, wakeup))
16584 goto free_msg;
16585
cd8f7cb4
JB
16586 nla_nest_end(msg, reasons);
16587 }
16588
9c90a9f6 16589 genlmsg_end(msg, hdr);
cd8f7cb4 16590
68eb5503 16591 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16592 NL80211_MCGRP_MLME, gfp);
cd8f7cb4
JB
16593 return;
16594
16595 free_msg:
16596 nlmsg_free(msg);
16597}
16598EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
16599#endif
16600
3475b094
JM
16601void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
16602 enum nl80211_tdls_operation oper,
16603 u16 reason_code, gfp_t gfp)
16604{
16605 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 16606 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
3475b094
JM
16607 struct sk_buff *msg;
16608 void *hdr;
3475b094
JM
16609
16610 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
16611 reason_code);
16612
16613 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16614 if (!msg)
16615 return;
16616
16617 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
16618 if (!hdr) {
16619 nlmsg_free(msg);
16620 return;
16621 }
16622
16623 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16624 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16625 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
16626 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
16627 (reason_code > 0 &&
16628 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
16629 goto nla_put_failure;
16630
9c90a9f6 16631 genlmsg_end(msg, hdr);
3475b094 16632
68eb5503 16633 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16634 NL80211_MCGRP_MLME, gfp);
3475b094
JM
16635 return;
16636
16637 nla_put_failure:
3475b094
JM
16638 nlmsg_free(msg);
16639}
16640EXPORT_SYMBOL(cfg80211_tdls_oper_request);
16641
026331c4
JM
16642static int nl80211_netlink_notify(struct notifier_block * nb,
16643 unsigned long state,
16644 void *_notify)
16645{
16646 struct netlink_notify *notify = _notify;
16647 struct cfg80211_registered_device *rdev;
16648 struct wireless_dev *wdev;
37c73b5f 16649 struct cfg80211_beacon_registration *reg, *tmp;
026331c4 16650
8f815cdd 16651 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
026331c4
JM
16652 return NOTIFY_DONE;
16653
16654 rcu_read_lock();
16655
5e760230 16656 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
ca986ad9 16657 struct cfg80211_sched_scan_request *sched_scan_req;
753aacfd 16658
ca986ad9
AVS
16659 list_for_each_entry_rcu(sched_scan_req,
16660 &rdev->sched_scan_req_list,
16661 list) {
16662 if (sched_scan_req->owner_nlportid == notify->portid) {
16663 sched_scan_req->nl_owner_dead = true;
753aacfd 16664 schedule_work(&rdev->sched_scan_stop_wk);
ca986ad9 16665 }
753aacfd 16666 }
78f22b6a 16667
53873f13 16668 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) {
15e47304 16669 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f 16670
ab81007a
JB
16671 if (wdev->owner_nlportid == notify->portid) {
16672 wdev->nl_owner_dead = true;
16673 schedule_work(&rdev->destroy_work);
16674 } else if (wdev->conn_owner_nlportid == notify->portid) {
bd2522b1 16675 schedule_work(&wdev->disconnect_wk);
ab81007a 16676 }
9bb7e0f2
JB
16677
16678 cfg80211_release_pmsr(wdev, notify->portid);
78f22b6a
JB
16679 }
16680
37c73b5f
BG
16681 spin_lock_bh(&rdev->beacon_registrations_lock);
16682 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
16683 list) {
16684 if (reg->nlportid == notify->portid) {
16685 list_del(&reg->list);
16686 kfree(reg);
16687 break;
16688 }
16689 }
16690 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 16691 }
026331c4
JM
16692
16693 rcu_read_unlock();
16694
05050753
I
16695 /*
16696 * It is possible that the user space process that is controlling the
16697 * indoor setting disappeared, so notify the regulatory core.
16698 */
16699 regulatory_netlink_notify(notify->portid);
6784c7db 16700 return NOTIFY_OK;
026331c4
JM
16701}
16702
16703static struct notifier_block nl80211_netlink_notifier = {
16704 .notifier_call = nl80211_netlink_notify,
16705};
16706
355199e0
JM
16707void cfg80211_ft_event(struct net_device *netdev,
16708 struct cfg80211_ft_event_params *ft_event)
16709{
16710 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
f26cbf40 16711 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
355199e0
JM
16712 struct sk_buff *msg;
16713 void *hdr;
355199e0
JM
16714
16715 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
16716
16717 if (!ft_event->target_ap)
16718 return;
16719
1039d081
DL
16720 msg = nlmsg_new(100 + ft_event->ies_len + ft_event->ric_ies_len,
16721 GFP_KERNEL);
355199e0
JM
16722 if (!msg)
16723 return;
16724
16725 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
ae917c9f
JB
16726 if (!hdr)
16727 goto out;
355199e0 16728
ae917c9f
JB
16729 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16730 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
16731 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
16732 goto out;
355199e0 16733
ae917c9f
JB
16734 if (ft_event->ies &&
16735 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
16736 goto out;
16737 if (ft_event->ric_ies &&
16738 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
16739 ft_event->ric_ies))
16740 goto out;
355199e0 16741
9c90a9f6 16742 genlmsg_end(msg, hdr);
355199e0 16743
68eb5503 16744 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16745 NL80211_MCGRP_MLME, GFP_KERNEL);
ae917c9f
JB
16746 return;
16747 out:
16748 nlmsg_free(msg);
355199e0
JM
16749}
16750EXPORT_SYMBOL(cfg80211_ft_event);
16751
5de17984
AS
16752void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
16753{
16754 struct cfg80211_registered_device *rdev;
16755 struct sk_buff *msg;
16756 void *hdr;
16757 u32 nlportid;
16758
f26cbf40 16759 rdev = wiphy_to_rdev(wdev->wiphy);
5de17984
AS
16760 if (!rdev->crit_proto_nlportid)
16761 return;
16762
16763 nlportid = rdev->crit_proto_nlportid;
16764 rdev->crit_proto_nlportid = 0;
16765
16766 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16767 if (!msg)
16768 return;
16769
16770 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
16771 if (!hdr)
16772 goto nla_put_failure;
16773
16774 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
16775 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16776 NL80211_ATTR_PAD))
5de17984
AS
16777 goto nla_put_failure;
16778
16779 genlmsg_end(msg, hdr);
16780
16781 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
16782 return;
16783
16784 nla_put_failure:
5de17984 16785 nlmsg_free(msg);
5de17984
AS
16786}
16787EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
16788
348baf0e
JB
16789void nl80211_send_ap_stopped(struct wireless_dev *wdev)
16790{
16791 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16792 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
348baf0e
JB
16793 struct sk_buff *msg;
16794 void *hdr;
16795
16796 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
16797 if (!msg)
16798 return;
16799
16800 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP);
16801 if (!hdr)
16802 goto out;
16803
16804 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16805 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
2dad624e
ND
16806 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16807 NL80211_ATTR_PAD))
348baf0e
JB
16808 goto out;
16809
16810 genlmsg_end(msg, hdr);
16811
16812 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
16813 NL80211_MCGRP_MLME, GFP_KERNEL);
16814 return;
16815 out:
16816 nlmsg_free(msg);
16817}
16818
40cbfa90
SD
16819int cfg80211_external_auth_request(struct net_device *dev,
16820 struct cfg80211_external_auth_params *params,
16821 gfp_t gfp)
16822{
16823 struct wireless_dev *wdev = dev->ieee80211_ptr;
16824 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
16825 struct sk_buff *msg;
16826 void *hdr;
16827
16828 if (!wdev->conn_owner_nlportid)
16829 return -EINVAL;
16830
16831 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16832 if (!msg)
16833 return -ENOMEM;
16834
16835 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_EXTERNAL_AUTH);
16836 if (!hdr)
16837 goto nla_put_failure;
16838
16839 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16840 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16841 nla_put_u32(msg, NL80211_ATTR_AKM_SUITES, params->key_mgmt_suite) ||
16842 nla_put_u32(msg, NL80211_ATTR_EXTERNAL_AUTH_ACTION,
16843 params->action) ||
16844 nla_put(msg, NL80211_ATTR_BSSID, ETH_ALEN, params->bssid) ||
16845 nla_put(msg, NL80211_ATTR_SSID, params->ssid.ssid_len,
16846 params->ssid.ssid))
16847 goto nla_put_failure;
16848
16849 genlmsg_end(msg, hdr);
16850 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
16851 wdev->conn_owner_nlportid);
16852 return 0;
16853
16854 nla_put_failure:
16855 nlmsg_free(msg);
16856 return -ENOBUFS;
16857}
16858EXPORT_SYMBOL(cfg80211_external_auth_request);
16859
cb74e977
SD
16860void cfg80211_update_owe_info_event(struct net_device *netdev,
16861 struct cfg80211_update_owe_info *owe_info,
16862 gfp_t gfp)
16863{
16864 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
16865 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
16866 struct sk_buff *msg;
16867 void *hdr;
16868
16869 trace_cfg80211_update_owe_info_event(wiphy, netdev, owe_info);
16870
16871 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16872 if (!msg)
16873 return;
16874
16875 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_UPDATE_OWE_INFO);
16876 if (!hdr)
16877 goto nla_put_failure;
16878
16879 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16880 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
16881 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, owe_info->peer))
16882 goto nla_put_failure;
16883
16884 if (!owe_info->ie_len ||
16885 nla_put(msg, NL80211_ATTR_IE, owe_info->ie_len, owe_info->ie))
16886 goto nla_put_failure;
16887
16888 genlmsg_end(msg, hdr);
16889
16890 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
16891 NL80211_MCGRP_MLME, gfp);
16892 return;
16893
16894nla_put_failure:
16895 genlmsg_cancel(msg, hdr);
16896 nlmsg_free(msg);
16897}
16898EXPORT_SYMBOL(cfg80211_update_owe_info_event);
16899
55682965
JB
16900/* initialisation/exit functions */
16901
56989f6d 16902int __init nl80211_init(void)
55682965 16903{
0d63cbb5 16904 int err;
55682965 16905
489111e5 16906 err = genl_register_family(&nl80211_fam);
55682965
JB
16907 if (err)
16908 return err;
16909
026331c4
JM
16910 err = netlink_register_notifier(&nl80211_netlink_notifier);
16911 if (err)
16912 goto err_out;
16913
55682965
JB
16914 return 0;
16915 err_out:
16916 genl_unregister_family(&nl80211_fam);
16917 return err;
16918}
16919
16920void nl80211_exit(void)
16921{
026331c4 16922 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
16923 genl_unregister_family(&nl80211_fam);
16924}