nl80211: don't assume wdev->netdev exists
[linux-2.6-block.git] / net / wireless / nl80211.c
CommitLineData
55682965
JB
1/*
2 * This is the new netlink-based wireless configuration interface.
3 *
026331c4 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
55682965
JB
5 */
6
7#include <linux/if.h>
8#include <linux/module.h>
9#include <linux/err.h>
5a0e3ad6 10#include <linux/slab.h>
55682965
JB
11#include <linux/list.h>
12#include <linux/if_ether.h>
13#include <linux/ieee80211.h>
14#include <linux/nl80211.h>
15#include <linux/rtnetlink.h>
16#include <linux/netlink.h>
2a519311 17#include <linux/etherdevice.h>
463d0183 18#include <net/net_namespace.h>
55682965
JB
19#include <net/genetlink.h>
20#include <net/cfg80211.h>
463d0183 21#include <net/sock.h>
55682965
JB
22#include "core.h"
23#include "nl80211.h"
b2e1b302 24#include "reg.h"
55682965 25
5fb628e9
JM
26static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type);
27static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
28 struct genl_info *info,
29 struct cfg80211_crypto_settings *settings,
30 int cipher_limit);
31
4c476991
JB
32static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
33 struct genl_info *info);
34static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
35 struct genl_info *info);
36
55682965
JB
37/* the netlink family */
38static struct genl_family nl80211_fam = {
39 .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
40 .name = "nl80211", /* have users key off the name instead */
41 .hdrsize = 0, /* no private header */
42 .version = 1, /* no particular meaning now */
43 .maxattr = NL80211_ATTR_MAX,
463d0183 44 .netnsok = true,
4c476991
JB
45 .pre_doit = nl80211_pre_doit,
46 .post_doit = nl80211_post_doit,
55682965
JB
47};
48
89a54e48
JB
49/* returns ERR_PTR values */
50static struct wireless_dev *
51__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 52{
89a54e48
JB
53 struct cfg80211_registered_device *rdev;
54 struct wireless_dev *result = NULL;
55 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
56 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
57 u64 wdev_id;
58 int wiphy_idx = -1;
59 int ifidx = -1;
55682965 60
89a54e48 61 assert_cfg80211_lock();
55682965 62
89a54e48
JB
63 if (!have_ifidx && !have_wdev_id)
64 return ERR_PTR(-EINVAL);
55682965 65
89a54e48
JB
66 if (have_ifidx)
67 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
68 if (have_wdev_id) {
69 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
70 wiphy_idx = wdev_id >> 32;
55682965
JB
71 }
72
89a54e48
JB
73 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
74 struct wireless_dev *wdev;
75
76 if (wiphy_net(&rdev->wiphy) != netns)
77 continue;
78
79 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
80 continue;
81
82 mutex_lock(&rdev->devlist_mtx);
83 list_for_each_entry(wdev, &rdev->wdev_list, list) {
84 if (have_ifidx && wdev->netdev &&
85 wdev->netdev->ifindex == ifidx) {
86 result = wdev;
87 break;
88 }
89 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
90 result = wdev;
91 break;
92 }
93 }
94 mutex_unlock(&rdev->devlist_mtx);
95
96 if (result)
97 break;
98 }
99
100 if (result)
101 return result;
102 return ERR_PTR(-ENODEV);
55682965
JB
103}
104
a9455408 105static struct cfg80211_registered_device *
878d9ec7 106__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 107{
7fee4778
JB
108 struct cfg80211_registered_device *rdev = NULL, *tmp;
109 struct net_device *netdev;
a9455408
JB
110
111 assert_cfg80211_lock();
112
878d9ec7 113 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
114 !attrs[NL80211_ATTR_IFINDEX] &&
115 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
116 return ERR_PTR(-EINVAL);
117
878d9ec7 118 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 119 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 120 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 121
89a54e48
JB
122 if (attrs[NL80211_ATTR_WDEV]) {
123 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
124 struct wireless_dev *wdev;
125 bool found = false;
126
127 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
128 if (tmp) {
129 /* make sure wdev exists */
130 mutex_lock(&tmp->devlist_mtx);
131 list_for_each_entry(wdev, &tmp->wdev_list, list) {
132 if (wdev->identifier != (u32)wdev_id)
133 continue;
134 found = true;
135 break;
136 }
137 mutex_unlock(&tmp->devlist_mtx);
138
139 if (!found)
140 tmp = NULL;
141
142 if (rdev && tmp != rdev)
143 return ERR_PTR(-EINVAL);
144 rdev = tmp;
145 }
146 }
147
878d9ec7
JB
148 if (attrs[NL80211_ATTR_IFINDEX]) {
149 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
4f7eff10 150 netdev = dev_get_by_index(netns, ifindex);
7fee4778
JB
151 if (netdev) {
152 if (netdev->ieee80211_ptr)
153 tmp = wiphy_to_dev(
154 netdev->ieee80211_ptr->wiphy);
155 else
156 tmp = NULL;
157
158 dev_put(netdev);
159
160 /* not wireless device -- return error */
161 if (!tmp)
162 return ERR_PTR(-EINVAL);
163
164 /* mismatch -- return error */
165 if (rdev && tmp != rdev)
166 return ERR_PTR(-EINVAL);
167
168 rdev = tmp;
a9455408 169 }
a9455408 170 }
a9455408 171
4f7eff10
JB
172 if (!rdev)
173 return ERR_PTR(-ENODEV);
a9455408 174
4f7eff10
JB
175 if (netns != wiphy_net(&rdev->wiphy))
176 return ERR_PTR(-ENODEV);
177
178 return rdev;
a9455408
JB
179}
180
181/*
182 * This function returns a pointer to the driver
183 * that the genl_info item that is passed refers to.
184 * If successful, it returns non-NULL and also locks
185 * the driver's mutex!
186 *
187 * This means that you need to call cfg80211_unlock_rdev()
188 * before being allowed to acquire &cfg80211_mutex!
189 *
190 * This is necessary because we need to lock the global
191 * mutex to get an item off the list safely, and then
192 * we lock the rdev mutex so it doesn't go away under us.
193 *
194 * We don't want to keep cfg80211_mutex locked
195 * for all the time in order to allow requests on
196 * other interfaces to go through at the same time.
197 *
198 * The result of this can be a PTR_ERR and hence must
199 * be checked with IS_ERR() for errors.
200 */
201static struct cfg80211_registered_device *
4f7eff10 202cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408
JB
203{
204 struct cfg80211_registered_device *rdev;
205
206 mutex_lock(&cfg80211_mutex);
878d9ec7 207 rdev = __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
208
209 /* if it is not an error we grab the lock on
210 * it to assure it won't be going away while
211 * we operate on it */
212 if (!IS_ERR(rdev))
213 mutex_lock(&rdev->mtx);
214
215 mutex_unlock(&cfg80211_mutex);
216
217 return rdev;
218}
219
55682965 220/* policy for the attributes */
b54452b0 221static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
55682965
JB
222 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
223 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 224 .len = 20-1 },
31888487 225 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
72bdcf34 226 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 227 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
b9a5f8ca
JM
228 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
229 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
230 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
231 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 232 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
55682965
JB
233
234 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
235 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
236 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 237
e007b857
EP
238 [NL80211_ATTR_MAC] = { .len = ETH_ALEN },
239 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN },
41ade00f 240
b9454e83 241 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
242 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
243 .len = WLAN_MAX_KEY_LEN },
244 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
245 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
246 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 247 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
e31b8213 248 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
ed1b6cc7
JB
249
250 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
251 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
252 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
253 .len = IEEE80211_MAX_DATA_LEN },
254 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
255 .len = IEEE80211_MAX_DATA_LEN },
5727ef1b
JB
256 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
257 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
258 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
259 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
260 .len = NL80211_MAX_SUPP_RATES },
2ec600d6 261 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
5727ef1b 262 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 263 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 264 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 265 .len = IEEE80211_MAX_MESH_ID_LEN },
2ec600d6 266 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
9f1ba906 267
b2e1b302
LR
268 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
269 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
270
9f1ba906
JM
271 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
272 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
273 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
274 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
275 .len = NL80211_MAX_SUPP_RATES },
50b12f59 276 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 277
24bdd9f4 278 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 279 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 280
6c739419 281 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN },
9aed3cc1
JM
282
283 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
284 [NL80211_ATTR_IE] = { .type = NLA_BINARY,
285 .len = IEEE80211_MAX_DATA_LEN },
2a519311
JB
286 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
287 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
288
289 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
290 .len = IEEE80211_MAX_SSID_LEN },
291 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
292 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 293 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 294 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
dc6382ce 295 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
eccb8e8f
JB
296 [NL80211_ATTR_STA_FLAGS2] = {
297 .len = sizeof(struct nl80211_sta_flag_update),
298 },
3f77316c 299 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
300 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
301 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
b23aa676
SO
302 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
303 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
304 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 305 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 306 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
67fbb16b
SO
307 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
308 .len = WLAN_PMKID_LEN },
9588bbd5
JM
309 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
310 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 311 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
312 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
313 .len = IEEE80211_MAX_DATA_LEN },
314 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ffb9eb3d 315 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
d6dc1a38 316 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 317 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 318 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
319 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
320 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 321 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
322 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
323 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 324 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 325 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 326 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 327 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
9c3990aa 328 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 },
bbe6ad6d 329 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 330 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 331 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
32e9de84 332 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 },
9946ecfb
JM
333 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY,
334 .len = IEEE80211_MAX_DATA_LEN },
335 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY,
336 .len = IEEE80211_MAX_DATA_LEN },
f4b34b55 337 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 338 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 339 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
340 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
341 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
342 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
343 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
344 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
e247bd90 345 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
346 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
347 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 348 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
349 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
350 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
351 .len = NL80211_HT_CAPABILITY_LEN
352 },
1d9d9213 353 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 354 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 355 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 356 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
55682965
JB
357};
358
e31b8213 359/* policy for the key attributes */
b54452b0 360static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 361 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
362 [NL80211_KEY_IDX] = { .type = NLA_U8 },
363 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 364 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
365 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
366 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
e31b8213 367 [NL80211_KEY_TYPE] = { .type = NLA_U32 },
dbd2fd65
JB
368 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
369};
370
371/* policy for the key default flags */
372static const struct nla_policy
373nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
374 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
375 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
376};
377
ff1b6e69
JB
378/* policy for WoWLAN attributes */
379static const struct nla_policy
380nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
381 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
382 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
383 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
384 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
385 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
386 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
387 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
388 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
ff1b6e69
JB
389};
390
e5497d76
JB
391/* policy for GTK rekey offload attributes */
392static const struct nla_policy
393nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
394 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN },
395 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN },
396 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN },
397};
398
a1f1c21c
LC
399static const struct nla_policy
400nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 401 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 402 .len = IEEE80211_MAX_SSID_LEN },
88e920b4 403 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
a1f1c21c
LC
404};
405
a043897a
HS
406/* ifidx get helper */
407static int nl80211_get_ifidx(struct netlink_callback *cb)
408{
409 int res;
410
411 res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
412 nl80211_fam.attrbuf, nl80211_fam.maxattr,
413 nl80211_policy);
414 if (res)
415 return res;
416
417 if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
418 return -EINVAL;
419
420 res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
421 if (!res)
422 return -EINVAL;
423 return res;
424}
425
67748893
JB
426static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
427 struct netlink_callback *cb,
428 struct cfg80211_registered_device **rdev,
429 struct net_device **dev)
430{
431 int ifidx = cb->args[0];
432 int err;
433
434 if (!ifidx)
435 ifidx = nl80211_get_ifidx(cb);
436 if (ifidx < 0)
437 return ifidx;
438
439 cb->args[0] = ifidx;
440
441 rtnl_lock();
442
443 *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
444 if (!*dev) {
445 err = -ENODEV;
446 goto out_rtnl;
447 }
448
449 *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
3cc25e51
FF
450 if (IS_ERR(*rdev)) {
451 err = PTR_ERR(*rdev);
67748893
JB
452 goto out_rtnl;
453 }
454
455 return 0;
456 out_rtnl:
457 rtnl_unlock();
458 return err;
459}
460
461static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
462{
463 cfg80211_unlock_rdev(rdev);
464 rtnl_unlock();
465}
466
f4a11bb0
JB
467/* IE validation */
468static bool is_valid_ie_attr(const struct nlattr *attr)
469{
470 const u8 *pos;
471 int len;
472
473 if (!attr)
474 return true;
475
476 pos = nla_data(attr);
477 len = nla_len(attr);
478
479 while (len) {
480 u8 elemlen;
481
482 if (len < 2)
483 return false;
484 len -= 2;
485
486 elemlen = pos[1];
487 if (elemlen > len)
488 return false;
489
490 len -= elemlen;
491 pos += 2 + elemlen;
492 }
493
494 return true;
495}
496
55682965
JB
497/* message building helper */
498static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
499 int flags, u8 cmd)
500{
501 /* since there is no private header just add the generic one */
502 return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
503}
504
5dab3b8a
LR
505static int nl80211_msg_put_channel(struct sk_buff *msg,
506 struct ieee80211_channel *chan)
507{
9360ffd1
DM
508 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
509 chan->center_freq))
510 goto nla_put_failure;
5dab3b8a 511
9360ffd1
DM
512 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
513 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
514 goto nla_put_failure;
515 if ((chan->flags & IEEE80211_CHAN_PASSIVE_SCAN) &&
516 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN))
517 goto nla_put_failure;
518 if ((chan->flags & IEEE80211_CHAN_NO_IBSS) &&
519 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IBSS))
520 goto nla_put_failure;
521 if ((chan->flags & IEEE80211_CHAN_RADAR) &&
522 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
523 goto nla_put_failure;
5dab3b8a 524
9360ffd1
DM
525 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
526 DBM_TO_MBM(chan->max_power)))
527 goto nla_put_failure;
5dab3b8a
LR
528
529 return 0;
530
531 nla_put_failure:
532 return -ENOBUFS;
533}
534
55682965
JB
535/* netlink command implementations */
536
b9454e83
JB
537struct key_parse {
538 struct key_params p;
539 int idx;
e31b8213 540 int type;
b9454e83 541 bool def, defmgmt;
dbd2fd65 542 bool def_uni, def_multi;
b9454e83
JB
543};
544
545static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
546{
547 struct nlattr *tb[NL80211_KEY_MAX + 1];
548 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
549 nl80211_key_policy);
550 if (err)
551 return err;
552
553 k->def = !!tb[NL80211_KEY_DEFAULT];
554 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
555
dbd2fd65
JB
556 if (k->def) {
557 k->def_uni = true;
558 k->def_multi = true;
559 }
560 if (k->defmgmt)
561 k->def_multi = true;
562
b9454e83
JB
563 if (tb[NL80211_KEY_IDX])
564 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
565
566 if (tb[NL80211_KEY_DATA]) {
567 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
568 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
569 }
570
571 if (tb[NL80211_KEY_SEQ]) {
572 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
573 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
574 }
575
576 if (tb[NL80211_KEY_CIPHER])
577 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
578
e31b8213
JB
579 if (tb[NL80211_KEY_TYPE]) {
580 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
581 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
582 return -EINVAL;
583 }
584
dbd2fd65
JB
585 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
586 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
2da8f419
JB
587 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
588 tb[NL80211_KEY_DEFAULT_TYPES],
589 nl80211_key_default_policy);
dbd2fd65
JB
590 if (err)
591 return err;
592
593 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
594 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
595 }
596
b9454e83
JB
597 return 0;
598}
599
600static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
601{
602 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
603 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
604 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
605 }
606
607 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
608 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
609 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
610 }
611
612 if (info->attrs[NL80211_ATTR_KEY_IDX])
613 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
614
615 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
616 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
617
618 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
619 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
620
dbd2fd65
JB
621 if (k->def) {
622 k->def_uni = true;
623 k->def_multi = true;
624 }
625 if (k->defmgmt)
626 k->def_multi = true;
627
e31b8213
JB
628 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
629 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
630 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
631 return -EINVAL;
632 }
633
dbd2fd65
JB
634 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
635 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
636 int err = nla_parse_nested(
637 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
638 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
639 nl80211_key_default_policy);
640 if (err)
641 return err;
642
643 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
644 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
645 }
646
b9454e83
JB
647 return 0;
648}
649
650static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
651{
652 int err;
653
654 memset(k, 0, sizeof(*k));
655 k->idx = -1;
e31b8213 656 k->type = -1;
b9454e83
JB
657
658 if (info->attrs[NL80211_ATTR_KEY])
659 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
660 else
661 err = nl80211_parse_key_old(info, k);
662
663 if (err)
664 return err;
665
666 if (k->def && k->defmgmt)
667 return -EINVAL;
668
dbd2fd65
JB
669 if (k->defmgmt) {
670 if (k->def_uni || !k->def_multi)
671 return -EINVAL;
672 }
673
b9454e83
JB
674 if (k->idx != -1) {
675 if (k->defmgmt) {
676 if (k->idx < 4 || k->idx > 5)
677 return -EINVAL;
678 } else if (k->def) {
679 if (k->idx < 0 || k->idx > 3)
680 return -EINVAL;
681 } else {
682 if (k->idx < 0 || k->idx > 5)
683 return -EINVAL;
684 }
685 }
686
687 return 0;
688}
689
fffd0934
JB
690static struct cfg80211_cached_keys *
691nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
692 struct nlattr *keys)
693{
694 struct key_parse parse;
695 struct nlattr *key;
696 struct cfg80211_cached_keys *result;
697 int rem, err, def = 0;
698
699 result = kzalloc(sizeof(*result), GFP_KERNEL);
700 if (!result)
701 return ERR_PTR(-ENOMEM);
702
703 result->def = -1;
704 result->defmgmt = -1;
705
706 nla_for_each_nested(key, keys, rem) {
707 memset(&parse, 0, sizeof(parse));
708 parse.idx = -1;
709
710 err = nl80211_parse_key_new(key, &parse);
711 if (err)
712 goto error;
713 err = -EINVAL;
714 if (!parse.p.key)
715 goto error;
716 if (parse.idx < 0 || parse.idx > 4)
717 goto error;
718 if (parse.def) {
719 if (def)
720 goto error;
721 def = 1;
722 result->def = parse.idx;
dbd2fd65
JB
723 if (!parse.def_uni || !parse.def_multi)
724 goto error;
fffd0934
JB
725 } else if (parse.defmgmt)
726 goto error;
727 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 728 parse.idx, false, NULL);
fffd0934
JB
729 if (err)
730 goto error;
731 result->params[parse.idx].cipher = parse.p.cipher;
732 result->params[parse.idx].key_len = parse.p.key_len;
733 result->params[parse.idx].key = result->data[parse.idx];
734 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
735 }
736
737 return result;
738 error:
739 kfree(result);
740 return ERR_PTR(err);
741}
742
743static int nl80211_key_allowed(struct wireless_dev *wdev)
744{
745 ASSERT_WDEV_LOCK(wdev);
746
fffd0934
JB
747 switch (wdev->iftype) {
748 case NL80211_IFTYPE_AP:
749 case NL80211_IFTYPE_AP_VLAN:
074ac8df 750 case NL80211_IFTYPE_P2P_GO:
ff973af7 751 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
752 break;
753 case NL80211_IFTYPE_ADHOC:
754 if (!wdev->current_bss)
755 return -ENOLINK;
756 break;
757 case NL80211_IFTYPE_STATION:
074ac8df 758 case NL80211_IFTYPE_P2P_CLIENT:
fffd0934
JB
759 if (wdev->sme_state != CFG80211_SME_CONNECTED)
760 return -ENOLINK;
761 break;
762 default:
763 return -EINVAL;
764 }
765
766 return 0;
767}
768
7527a782
JB
769static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
770{
771 struct nlattr *nl_modes = nla_nest_start(msg, attr);
772 int i;
773
774 if (!nl_modes)
775 goto nla_put_failure;
776
777 i = 0;
778 while (ifmodes) {
9360ffd1
DM
779 if ((ifmodes & 1) && nla_put_flag(msg, i))
780 goto nla_put_failure;
7527a782
JB
781 ifmodes >>= 1;
782 i++;
783 }
784
785 nla_nest_end(msg, nl_modes);
786 return 0;
787
788nla_put_failure:
789 return -ENOBUFS;
790}
791
792static int nl80211_put_iface_combinations(struct wiphy *wiphy,
793 struct sk_buff *msg)
794{
795 struct nlattr *nl_combis;
796 int i, j;
797
798 nl_combis = nla_nest_start(msg,
799 NL80211_ATTR_INTERFACE_COMBINATIONS);
800 if (!nl_combis)
801 goto nla_put_failure;
802
803 for (i = 0; i < wiphy->n_iface_combinations; i++) {
804 const struct ieee80211_iface_combination *c;
805 struct nlattr *nl_combi, *nl_limits;
806
807 c = &wiphy->iface_combinations[i];
808
809 nl_combi = nla_nest_start(msg, i + 1);
810 if (!nl_combi)
811 goto nla_put_failure;
812
813 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS);
814 if (!nl_limits)
815 goto nla_put_failure;
816
817 for (j = 0; j < c->n_limits; j++) {
818 struct nlattr *nl_limit;
819
820 nl_limit = nla_nest_start(msg, j + 1);
821 if (!nl_limit)
822 goto nla_put_failure;
9360ffd1
DM
823 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
824 c->limits[j].max))
825 goto nla_put_failure;
7527a782
JB
826 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
827 c->limits[j].types))
828 goto nla_put_failure;
829 nla_nest_end(msg, nl_limit);
830 }
831
832 nla_nest_end(msg, nl_limits);
833
9360ffd1
DM
834 if (c->beacon_int_infra_match &&
835 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
836 goto nla_put_failure;
837 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
838 c->num_different_channels) ||
839 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
840 c->max_interfaces))
841 goto nla_put_failure;
7527a782
JB
842
843 nla_nest_end(msg, nl_combi);
844 }
845
846 nla_nest_end(msg, nl_combis);
847
848 return 0;
849nla_put_failure:
850 return -ENOBUFS;
851}
852
55682965
JB
853static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
854 struct cfg80211_registered_device *dev)
855{
856 void *hdr;
ee688b00
JB
857 struct nlattr *nl_bands, *nl_band;
858 struct nlattr *nl_freqs, *nl_freq;
859 struct nlattr *nl_rates, *nl_rate;
8fdc621d 860 struct nlattr *nl_cmds;
ee688b00
JB
861 enum ieee80211_band band;
862 struct ieee80211_channel *chan;
863 struct ieee80211_rate *rate;
864 int i;
2e161f78
JB
865 const struct ieee80211_txrx_stypes *mgmt_stypes =
866 dev->wiphy.mgmt_stypes;
55682965
JB
867
868 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
869 if (!hdr)
870 return -1;
871
9360ffd1
DM
872 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx) ||
873 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy)) ||
874 nla_put_u32(msg, NL80211_ATTR_GENERATION,
875 cfg80211_rdev_list_generation) ||
876 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
877 dev->wiphy.retry_short) ||
878 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
879 dev->wiphy.retry_long) ||
880 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
881 dev->wiphy.frag_threshold) ||
882 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
883 dev->wiphy.rts_threshold) ||
884 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
885 dev->wiphy.coverage_class) ||
886 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
887 dev->wiphy.max_scan_ssids) ||
888 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
889 dev->wiphy.max_sched_scan_ssids) ||
890 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
891 dev->wiphy.max_scan_ie_len) ||
892 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
893 dev->wiphy.max_sched_scan_ie_len) ||
894 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
895 dev->wiphy.max_match_sets))
896 goto nla_put_failure;
897
898 if ((dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
899 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
900 goto nla_put_failure;
901 if ((dev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
902 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
903 goto nla_put_failure;
904 if ((dev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
905 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
906 goto nla_put_failure;
907 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
908 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
909 goto nla_put_failure;
910 if ((dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
911 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
912 goto nla_put_failure;
913 if ((dev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
914 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
915 goto nla_put_failure;
916
917 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
918 sizeof(u32) * dev->wiphy.n_cipher_suites,
919 dev->wiphy.cipher_suites))
920 goto nla_put_failure;
921
922 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
923 dev->wiphy.max_num_pmkids))
924 goto nla_put_failure;
925
926 if ((dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
927 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
928 goto nla_put_failure;
929
930 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
931 dev->wiphy.available_antennas_tx) ||
932 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
933 dev->wiphy.available_antennas_rx))
934 goto nla_put_failure;
935
936 if ((dev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
937 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
938 dev->wiphy.probe_resp_offload))
939 goto nla_put_failure;
87bbbe22 940
7f531e03
BR
941 if ((dev->wiphy.available_antennas_tx ||
942 dev->wiphy.available_antennas_rx) && dev->ops->get_antenna) {
afe0cbf8
BR
943 u32 tx_ant = 0, rx_ant = 0;
944 int res;
945 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
946 if (!res) {
9360ffd1
DM
947 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX,
948 tx_ant) ||
949 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX,
950 rx_ant))
951 goto nla_put_failure;
afe0cbf8
BR
952 }
953 }
954
7527a782
JB
955 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
956 dev->wiphy.interface_modes))
f59ac048
LR
957 goto nla_put_failure;
958
ee688b00
JB
959 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
960 if (!nl_bands)
961 goto nla_put_failure;
962
963 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
964 if (!dev->wiphy.bands[band])
965 continue;
966
967 nl_band = nla_nest_start(msg, band);
968 if (!nl_band)
969 goto nla_put_failure;
970
d51626df 971 /* add HT info */
9360ffd1
DM
972 if (dev->wiphy.bands[band]->ht_cap.ht_supported &&
973 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
974 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
975 &dev->wiphy.bands[band]->ht_cap.mcs) ||
976 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
977 dev->wiphy.bands[band]->ht_cap.cap) ||
978 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
979 dev->wiphy.bands[band]->ht_cap.ampdu_factor) ||
980 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
981 dev->wiphy.bands[band]->ht_cap.ampdu_density)))
982 goto nla_put_failure;
d51626df 983
bf0c111e
MP
984 /* add VHT info */
985 if (dev->wiphy.bands[band]->vht_cap.vht_supported &&
986 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
987 sizeof(dev->wiphy.bands[band]->vht_cap.vht_mcs),
988 &dev->wiphy.bands[band]->vht_cap.vht_mcs) ||
989 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
990 dev->wiphy.bands[band]->vht_cap.cap)))
991 goto nla_put_failure;
992
ee688b00
JB
993 /* add frequencies */
994 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
995 if (!nl_freqs)
996 goto nla_put_failure;
997
998 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
999 nl_freq = nla_nest_start(msg, i);
1000 if (!nl_freq)
1001 goto nla_put_failure;
1002
1003 chan = &dev->wiphy.bands[band]->channels[i];
5dab3b8a
LR
1004
1005 if (nl80211_msg_put_channel(msg, chan))
1006 goto nla_put_failure;
e2f367f2 1007
ee688b00
JB
1008 nla_nest_end(msg, nl_freq);
1009 }
1010
1011 nla_nest_end(msg, nl_freqs);
1012
1013 /* add bitrates */
1014 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
1015 if (!nl_rates)
1016 goto nla_put_failure;
1017
1018 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
1019 nl_rate = nla_nest_start(msg, i);
1020 if (!nl_rate)
1021 goto nla_put_failure;
1022
1023 rate = &dev->wiphy.bands[band]->bitrates[i];
9360ffd1
DM
1024 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1025 rate->bitrate))
1026 goto nla_put_failure;
1027 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1028 nla_put_flag(msg,
1029 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1030 goto nla_put_failure;
ee688b00
JB
1031
1032 nla_nest_end(msg, nl_rate);
1033 }
1034
1035 nla_nest_end(msg, nl_rates);
1036
1037 nla_nest_end(msg, nl_band);
1038 }
1039 nla_nest_end(msg, nl_bands);
1040
8fdc621d
JB
1041 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
1042 if (!nl_cmds)
1043 goto nla_put_failure;
1044
1045 i = 0;
1046#define CMD(op, n) \
1047 do { \
1048 if (dev->ops->op) { \
1049 i++; \
9360ffd1
DM
1050 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1051 goto nla_put_failure; \
8fdc621d
JB
1052 } \
1053 } while (0)
1054
1055 CMD(add_virtual_intf, NEW_INTERFACE);
1056 CMD(change_virtual_intf, SET_INTERFACE);
1057 CMD(add_key, NEW_KEY);
8860020e 1058 CMD(start_ap, START_AP);
8fdc621d
JB
1059 CMD(add_station, NEW_STATION);
1060 CMD(add_mpath, NEW_MPATH);
24bdd9f4 1061 CMD(update_mesh_config, SET_MESH_CONFIG);
8fdc621d 1062 CMD(change_bss, SET_BSS);
636a5d36
JM
1063 CMD(auth, AUTHENTICATE);
1064 CMD(assoc, ASSOCIATE);
1065 CMD(deauth, DEAUTHENTICATE);
1066 CMD(disassoc, DISASSOCIATE);
04a773ad 1067 CMD(join_ibss, JOIN_IBSS);
29cbe68c 1068 CMD(join_mesh, JOIN_MESH);
67fbb16b
SO
1069 CMD(set_pmksa, SET_PMKSA);
1070 CMD(del_pmksa, DEL_PMKSA);
1071 CMD(flush_pmksa, FLUSH_PMKSA);
7c4ef712
JB
1072 if (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1073 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
13ae75b1 1074 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
2e161f78 1075 CMD(mgmt_tx, FRAME);
f7ca38df 1076 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
5be83de5 1077 if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
463d0183 1078 i++;
9360ffd1
DM
1079 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1080 goto nla_put_failure;
463d0183 1081 }
e8c9bd5b 1082 if (dev->ops->set_monitor_channel || dev->ops->start_ap ||
cc1d2806 1083 dev->ops->join_mesh) {
aa430da4
JB
1084 i++;
1085 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1086 goto nla_put_failure;
1087 }
e8347eba 1088 CMD(set_wds_peer, SET_WDS_PEER);
109086ce
AN
1089 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1090 CMD(tdls_mgmt, TDLS_MGMT);
1091 CMD(tdls_oper, TDLS_OPER);
1092 }
807f8a8c
LC
1093 if (dev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN)
1094 CMD(sched_scan_start, START_SCHED_SCAN);
7f6cf311 1095 CMD(probe_client, PROBE_CLIENT);
1d9d9213 1096 CMD(set_noack_map, SET_NOACK_MAP);
5e760230
JB
1097 if (dev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1098 i++;
9360ffd1
DM
1099 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1100 goto nla_put_failure;
5e760230 1101 }
8fdc621d 1102
4745fc09
KV
1103#ifdef CONFIG_NL80211_TESTMODE
1104 CMD(testmode_cmd, TESTMODE);
1105#endif
1106
8fdc621d 1107#undef CMD
b23aa676 1108
6829c878 1109 if (dev->ops->connect || dev->ops->auth) {
b23aa676 1110 i++;
9360ffd1
DM
1111 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1112 goto nla_put_failure;
b23aa676
SO
1113 }
1114
6829c878 1115 if (dev->ops->disconnect || dev->ops->deauth) {
b23aa676 1116 i++;
9360ffd1
DM
1117 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1118 goto nla_put_failure;
b23aa676
SO
1119 }
1120
8fdc621d
JB
1121 nla_nest_end(msg, nl_cmds);
1122
7c4ef712 1123 if (dev->ops->remain_on_channel &&
9360ffd1
DM
1124 (dev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
1125 nla_put_u32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1126 dev->wiphy.max_remain_on_channel_duration))
1127 goto nla_put_failure;
a293911d 1128
9360ffd1
DM
1129 if ((dev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
1130 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
1131 goto nla_put_failure;
f7ca38df 1132
2e161f78
JB
1133 if (mgmt_stypes) {
1134 u16 stypes;
1135 struct nlattr *nl_ftypes, *nl_ifs;
1136 enum nl80211_iftype ift;
1137
1138 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
1139 if (!nl_ifs)
1140 goto nla_put_failure;
1141
1142 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1143 nl_ftypes = nla_nest_start(msg, ift);
1144 if (!nl_ftypes)
1145 goto nla_put_failure;
1146 i = 0;
1147 stypes = mgmt_stypes[ift].tx;
1148 while (stypes) {
9360ffd1
DM
1149 if ((stypes & 1) &&
1150 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1151 (i << 4) | IEEE80211_FTYPE_MGMT))
1152 goto nla_put_failure;
2e161f78
JB
1153 stypes >>= 1;
1154 i++;
1155 }
1156 nla_nest_end(msg, nl_ftypes);
1157 }
1158
74b70a4e
JB
1159 nla_nest_end(msg, nl_ifs);
1160
2e161f78
JB
1161 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
1162 if (!nl_ifs)
1163 goto nla_put_failure;
1164
1165 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
1166 nl_ftypes = nla_nest_start(msg, ift);
1167 if (!nl_ftypes)
1168 goto nla_put_failure;
1169 i = 0;
1170 stypes = mgmt_stypes[ift].rx;
1171 while (stypes) {
9360ffd1
DM
1172 if ((stypes & 1) &&
1173 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1174 (i << 4) | IEEE80211_FTYPE_MGMT))
1175 goto nla_put_failure;
2e161f78
JB
1176 stypes >>= 1;
1177 i++;
1178 }
1179 nla_nest_end(msg, nl_ftypes);
1180 }
1181 nla_nest_end(msg, nl_ifs);
1182 }
1183
dfb89c56 1184#ifdef CONFIG_PM
ff1b6e69
JB
1185 if (dev->wiphy.wowlan.flags || dev->wiphy.wowlan.n_patterns) {
1186 struct nlattr *nl_wowlan;
1187
1188 nl_wowlan = nla_nest_start(msg,
1189 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
1190 if (!nl_wowlan)
1191 goto nla_put_failure;
1192
9360ffd1
DM
1193 if (((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_ANY) &&
1194 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1195 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_DISCONNECT) &&
1196 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1197 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_MAGIC_PKT) &&
1198 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1199 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
1200 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1201 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
1202 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1203 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
1204 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1205 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
1206 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1207 ((dev->wiphy.wowlan.flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
1208 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1209 goto nla_put_failure;
ff1b6e69
JB
1210 if (dev->wiphy.wowlan.n_patterns) {
1211 struct nl80211_wowlan_pattern_support pat = {
1212 .max_patterns = dev->wiphy.wowlan.n_patterns,
1213 .min_pattern_len =
1214 dev->wiphy.wowlan.pattern_min_len,
1215 .max_pattern_len =
1216 dev->wiphy.wowlan.pattern_max_len,
1217 };
9360ffd1
DM
1218 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1219 sizeof(pat), &pat))
1220 goto nla_put_failure;
ff1b6e69
JB
1221 }
1222
1223 nla_nest_end(msg, nl_wowlan);
1224 }
dfb89c56 1225#endif
ff1b6e69 1226
7527a782
JB
1227 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1228 dev->wiphy.software_iftypes))
1229 goto nla_put_failure;
1230
1231 if (nl80211_put_iface_combinations(&dev->wiphy, msg))
1232 goto nla_put_failure;
1233
9360ffd1
DM
1234 if ((dev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
1235 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1236 dev->wiphy.ap_sme_capa))
1237 goto nla_put_failure;
562a7480 1238
9360ffd1
DM
1239 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS,
1240 dev->wiphy.features))
1241 goto nla_put_failure;
1f074bd8 1242
9360ffd1
DM
1243 if (dev->wiphy.ht_capa_mod_mask &&
1244 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1245 sizeof(*dev->wiphy.ht_capa_mod_mask),
1246 dev->wiphy.ht_capa_mod_mask))
1247 goto nla_put_failure;
7e7c8926 1248
55682965
JB
1249 return genlmsg_end(msg, hdr);
1250
1251 nla_put_failure:
bc3ed28c
TG
1252 genlmsg_cancel(msg, hdr);
1253 return -EMSGSIZE;
55682965
JB
1254}
1255
1256static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
1257{
1258 int idx = 0;
1259 int start = cb->args[0];
1260 struct cfg80211_registered_device *dev;
1261
a1794390 1262 mutex_lock(&cfg80211_mutex);
79c97e97 1263 list_for_each_entry(dev, &cfg80211_rdev_list, list) {
463d0183
JB
1264 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
1265 continue;
b4637271 1266 if (++idx <= start)
55682965
JB
1267 continue;
1268 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
1269 cb->nlh->nlmsg_seq, NLM_F_MULTI,
b4637271
JV
1270 dev) < 0) {
1271 idx--;
55682965 1272 break;
b4637271 1273 }
55682965 1274 }
a1794390 1275 mutex_unlock(&cfg80211_mutex);
55682965
JB
1276
1277 cb->args[0] = idx;
1278
1279 return skb->len;
1280}
1281
1282static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
1283{
1284 struct sk_buff *msg;
4c476991 1285 struct cfg80211_registered_device *dev = info->user_ptr[0];
55682965 1286
fd2120ca 1287 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1288 if (!msg)
4c476991 1289 return -ENOMEM;
55682965 1290
4c476991
JB
1291 if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
1292 nlmsg_free(msg);
1293 return -ENOBUFS;
1294 }
55682965 1295
134e6375 1296 return genlmsg_reply(msg, info);
55682965
JB
1297}
1298
31888487
JM
1299static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
1300 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
1301 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
1302 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
1303 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
1304 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
1305};
1306
1307static int parse_txq_params(struct nlattr *tb[],
1308 struct ieee80211_txq_params *txq_params)
1309{
a3304b0a 1310 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
1311 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
1312 !tb[NL80211_TXQ_ATTR_AIFS])
1313 return -EINVAL;
1314
a3304b0a 1315 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
1316 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
1317 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
1318 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
1319 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
1320
a3304b0a
JB
1321 if (txq_params->ac >= NL80211_NUM_ACS)
1322 return -EINVAL;
1323
31888487
JM
1324 return 0;
1325}
1326
f444de05
JB
1327static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
1328{
1329 /*
cc1d2806
JB
1330 * You can only set the channel explicitly for WDS interfaces,
1331 * all others have their channel managed via their respective
1332 * "establish a connection" command (connect, join, ...)
1333 *
1334 * For AP/GO and mesh mode, the channel can be set with the
1335 * channel userspace API, but is only stored and passed to the
1336 * low-level driver when the AP starts or the mesh is joined.
1337 * This is for backward compatibility, userspace can also give
1338 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
1339 *
1340 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
1341 * whatever else is going on, so they have their own special
1342 * operation to set the monitor channel if possible.
f444de05
JB
1343 */
1344 return !wdev ||
1345 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 1346 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
1347 wdev->iftype == NL80211_IFTYPE_MONITOR ||
1348 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
1349}
1350
cd6c6598
JB
1351static bool nl80211_valid_channel_type(struct genl_info *info,
1352 enum nl80211_channel_type *channel_type)
1353{
1354 enum nl80211_channel_type tmp;
1355
1356 if (!info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE])
1357 return false;
1358
1359 tmp = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
1360 if (tmp != NL80211_CHAN_NO_HT &&
1361 tmp != NL80211_CHAN_HT20 &&
1362 tmp != NL80211_CHAN_HT40PLUS &&
1363 tmp != NL80211_CHAN_HT40MINUS)
1364 return false;
1365
1366 if (channel_type)
1367 *channel_type = tmp;
1368
1369 return true;
1370}
1371
f444de05
JB
1372static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
1373 struct wireless_dev *wdev,
1374 struct genl_info *info)
1375{
aa430da4 1376 struct ieee80211_channel *channel;
f444de05
JB
1377 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
1378 u32 freq;
1379 int result;
e8c9bd5b
JB
1380 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
1381
1382 if (wdev)
1383 iftype = wdev->iftype;
f444de05
JB
1384
1385 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
1386 return -EINVAL;
1387
1388 if (!nl80211_can_set_dev_channel(wdev))
1389 return -EOPNOTSUPP;
1390
cd6c6598
JB
1391 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
1392 !nl80211_valid_channel_type(info, &channel_type))
1393 return -EINVAL;
f444de05
JB
1394
1395 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
1396
1397 mutex_lock(&rdev->devlist_mtx);
e8c9bd5b 1398 switch (iftype) {
aa430da4
JB
1399 case NL80211_IFTYPE_AP:
1400 case NL80211_IFTYPE_P2P_GO:
1401 if (wdev->beacon_interval) {
1402 result = -EBUSY;
1403 break;
1404 }
1405 channel = rdev_freq_to_chan(rdev, freq, channel_type);
1406 if (!channel || !cfg80211_can_beacon_sec_chan(&rdev->wiphy,
1407 channel,
1408 channel_type)) {
1409 result = -EINVAL;
1410 break;
1411 }
1412 wdev->preset_chan = channel;
1413 wdev->preset_chantype = channel_type;
1414 result = 0;
1415 break;
cc1d2806
JB
1416 case NL80211_IFTYPE_MESH_POINT:
1417 result = cfg80211_set_mesh_freq(rdev, wdev, freq, channel_type);
1418 break;
e8c9bd5b
JB
1419 case NL80211_IFTYPE_MONITOR:
1420 result = cfg80211_set_monitor_channel(rdev, freq, channel_type);
1421 break;
aa430da4 1422 default:
e8c9bd5b 1423 result = -EINVAL;
f444de05
JB
1424 }
1425 mutex_unlock(&rdev->devlist_mtx);
1426
1427 return result;
1428}
1429
1430static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
1431{
4c476991
JB
1432 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1433 struct net_device *netdev = info->user_ptr[1];
f444de05 1434
4c476991 1435 return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
f444de05
JB
1436}
1437
e8347eba
BJ
1438static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
1439{
43b19952
JB
1440 struct cfg80211_registered_device *rdev = info->user_ptr[0];
1441 struct net_device *dev = info->user_ptr[1];
1442 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 1443 const u8 *bssid;
e8347eba
BJ
1444
1445 if (!info->attrs[NL80211_ATTR_MAC])
1446 return -EINVAL;
1447
43b19952
JB
1448 if (netif_running(dev))
1449 return -EBUSY;
e8347eba 1450
43b19952
JB
1451 if (!rdev->ops->set_wds_peer)
1452 return -EOPNOTSUPP;
e8347eba 1453
43b19952
JB
1454 if (wdev->iftype != NL80211_IFTYPE_WDS)
1455 return -EOPNOTSUPP;
e8347eba
BJ
1456
1457 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
43b19952 1458 return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
e8347eba
BJ
1459}
1460
1461
55682965
JB
1462static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
1463{
1464 struct cfg80211_registered_device *rdev;
f444de05
JB
1465 struct net_device *netdev = NULL;
1466 struct wireless_dev *wdev;
a1e567c8 1467 int result = 0, rem_txq_params = 0;
31888487 1468 struct nlattr *nl_txq_params;
b9a5f8ca
JM
1469 u32 changed;
1470 u8 retry_short = 0, retry_long = 0;
1471 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 1472 u8 coverage_class = 0;
55682965 1473
f444de05
JB
1474 /*
1475 * Try to find the wiphy and netdev. Normally this
1476 * function shouldn't need the netdev, but this is
1477 * done for backward compatibility -- previously
1478 * setting the channel was done per wiphy, but now
1479 * it is per netdev. Previous userland like hostapd
1480 * also passed a netdev to set_wiphy, so that it is
1481 * possible to let that go to the right netdev!
1482 */
4bbf4d56
JB
1483 mutex_lock(&cfg80211_mutex);
1484
f444de05
JB
1485 if (info->attrs[NL80211_ATTR_IFINDEX]) {
1486 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1487
1488 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1489 if (netdev && netdev->ieee80211_ptr) {
1490 rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1491 mutex_lock(&rdev->mtx);
1492 } else
1493 netdev = NULL;
4bbf4d56
JB
1494 }
1495
f444de05 1496 if (!netdev) {
878d9ec7
JB
1497 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
1498 info->attrs);
f444de05
JB
1499 if (IS_ERR(rdev)) {
1500 mutex_unlock(&cfg80211_mutex);
4c476991 1501 return PTR_ERR(rdev);
f444de05
JB
1502 }
1503 wdev = NULL;
1504 netdev = NULL;
1505 result = 0;
1506
1507 mutex_lock(&rdev->mtx);
cc1d2806 1508 } else if (nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
f444de05
JB
1509 wdev = netdev->ieee80211_ptr;
1510 else
1511 wdev = NULL;
1512
1513 /*
1514 * end workaround code, by now the rdev is available
1515 * and locked, and wdev may or may not be NULL.
1516 */
4bbf4d56
JB
1517
1518 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
1519 result = cfg80211_dev_rename(
1520 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56
JB
1521
1522 mutex_unlock(&cfg80211_mutex);
1523
1524 if (result)
1525 goto bad_res;
31888487
JM
1526
1527 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1528 struct ieee80211_txq_params txq_params;
1529 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1530
1531 if (!rdev->ops->set_txq_params) {
1532 result = -EOPNOTSUPP;
1533 goto bad_res;
1534 }
1535
f70f01c2
EP
1536 if (!netdev) {
1537 result = -EINVAL;
1538 goto bad_res;
1539 }
1540
133a3ff2
JB
1541 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1542 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
1543 result = -EINVAL;
1544 goto bad_res;
1545 }
1546
2b5f8b0b
JB
1547 if (!netif_running(netdev)) {
1548 result = -ENETDOWN;
1549 goto bad_res;
1550 }
1551
31888487
JM
1552 nla_for_each_nested(nl_txq_params,
1553 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1554 rem_txq_params) {
1555 nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1556 nla_data(nl_txq_params),
1557 nla_len(nl_txq_params),
1558 txq_params_policy);
1559 result = parse_txq_params(tb, &txq_params);
1560 if (result)
1561 goto bad_res;
1562
1563 result = rdev->ops->set_txq_params(&rdev->wiphy,
f70f01c2 1564 netdev,
31888487
JM
1565 &txq_params);
1566 if (result)
1567 goto bad_res;
1568 }
1569 }
55682965 1570
72bdcf34 1571 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
f444de05 1572 result = __nl80211_set_channel(rdev, wdev, info);
72bdcf34
JM
1573 if (result)
1574 goto bad_res;
1575 }
1576
98d2ff8b
JO
1577 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1578 enum nl80211_tx_power_setting type;
1579 int idx, mbm = 0;
1580
1581 if (!rdev->ops->set_tx_power) {
60ea385f 1582 result = -EOPNOTSUPP;
98d2ff8b
JO
1583 goto bad_res;
1584 }
1585
1586 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1587 type = nla_get_u32(info->attrs[idx]);
1588
1589 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1590 (type != NL80211_TX_POWER_AUTOMATIC)) {
1591 result = -EINVAL;
1592 goto bad_res;
1593 }
1594
1595 if (type != NL80211_TX_POWER_AUTOMATIC) {
1596 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1597 mbm = nla_get_u32(info->attrs[idx]);
1598 }
1599
1600 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1601 if (result)
1602 goto bad_res;
1603 }
1604
afe0cbf8
BR
1605 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1606 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1607 u32 tx_ant, rx_ant;
7f531e03
BR
1608 if ((!rdev->wiphy.available_antennas_tx &&
1609 !rdev->wiphy.available_antennas_rx) ||
1610 !rdev->ops->set_antenna) {
afe0cbf8
BR
1611 result = -EOPNOTSUPP;
1612 goto bad_res;
1613 }
1614
1615 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1616 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1617
a7ffac95 1618 /* reject antenna configurations which don't match the
7f531e03
BR
1619 * available antenna masks, except for the "all" mask */
1620 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
1621 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) {
a7ffac95
BR
1622 result = -EINVAL;
1623 goto bad_res;
1624 }
1625
7f531e03
BR
1626 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
1627 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 1628
afe0cbf8
BR
1629 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1630 if (result)
1631 goto bad_res;
1632 }
1633
b9a5f8ca
JM
1634 changed = 0;
1635
1636 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1637 retry_short = nla_get_u8(
1638 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1639 if (retry_short == 0) {
1640 result = -EINVAL;
1641 goto bad_res;
1642 }
1643 changed |= WIPHY_PARAM_RETRY_SHORT;
1644 }
1645
1646 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1647 retry_long = nla_get_u8(
1648 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1649 if (retry_long == 0) {
1650 result = -EINVAL;
1651 goto bad_res;
1652 }
1653 changed |= WIPHY_PARAM_RETRY_LONG;
1654 }
1655
1656 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1657 frag_threshold = nla_get_u32(
1658 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1659 if (frag_threshold < 256) {
1660 result = -EINVAL;
1661 goto bad_res;
1662 }
1663 if (frag_threshold != (u32) -1) {
1664 /*
1665 * Fragments (apart from the last one) are required to
1666 * have even length. Make the fragmentation code
1667 * simpler by stripping LSB should someone try to use
1668 * odd threshold value.
1669 */
1670 frag_threshold &= ~0x1;
1671 }
1672 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1673 }
1674
1675 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1676 rts_threshold = nla_get_u32(
1677 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1678 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1679 }
1680
81077e82
LT
1681 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1682 coverage_class = nla_get_u8(
1683 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1684 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1685 }
1686
b9a5f8ca
JM
1687 if (changed) {
1688 u8 old_retry_short, old_retry_long;
1689 u32 old_frag_threshold, old_rts_threshold;
81077e82 1690 u8 old_coverage_class;
b9a5f8ca
JM
1691
1692 if (!rdev->ops->set_wiphy_params) {
1693 result = -EOPNOTSUPP;
1694 goto bad_res;
1695 }
1696
1697 old_retry_short = rdev->wiphy.retry_short;
1698 old_retry_long = rdev->wiphy.retry_long;
1699 old_frag_threshold = rdev->wiphy.frag_threshold;
1700 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 1701 old_coverage_class = rdev->wiphy.coverage_class;
b9a5f8ca
JM
1702
1703 if (changed & WIPHY_PARAM_RETRY_SHORT)
1704 rdev->wiphy.retry_short = retry_short;
1705 if (changed & WIPHY_PARAM_RETRY_LONG)
1706 rdev->wiphy.retry_long = retry_long;
1707 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1708 rdev->wiphy.frag_threshold = frag_threshold;
1709 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1710 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
1711 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1712 rdev->wiphy.coverage_class = coverage_class;
b9a5f8ca
JM
1713
1714 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1715 if (result) {
1716 rdev->wiphy.retry_short = old_retry_short;
1717 rdev->wiphy.retry_long = old_retry_long;
1718 rdev->wiphy.frag_threshold = old_frag_threshold;
1719 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 1720 rdev->wiphy.coverage_class = old_coverage_class;
b9a5f8ca
JM
1721 }
1722 }
72bdcf34 1723
306d6112 1724 bad_res:
4bbf4d56 1725 mutex_unlock(&rdev->mtx);
f444de05
JB
1726 if (netdev)
1727 dev_put(netdev);
55682965
JB
1728 return result;
1729}
1730
1731
1732static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
d726405a 1733 struct cfg80211_registered_device *rdev,
72fb2abc 1734 struct wireless_dev *wdev)
55682965 1735{
72fb2abc 1736 struct net_device *dev = wdev->netdev;
55682965 1737 void *hdr;
72fb2abc 1738 u64 wdev_id = (u64)wdev->identifier |
89a54e48 1739 ((u64)rdev->wiphy_idx << 32);
55682965
JB
1740
1741 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1742 if (!hdr)
1743 return -1;
1744
72fb2abc
JB
1745 if (dev &&
1746 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
1747 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name) ||
1748 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dev->dev_addr)))
1749 goto nla_put_failure;
1750
1751 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
1752 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
89a54e48 1753 nla_put_u64(msg, NL80211_ATTR_WDEV, wdev_id) ||
9360ffd1
DM
1754 nla_put_u32(msg, NL80211_ATTR_GENERATION,
1755 rdev->devlist_generation ^
1756 (cfg80211_rdev_list_generation << 2)))
1757 goto nla_put_failure;
f5ea9120 1758
2e165b81
MK
1759 if (rdev->monitor_channel) {
1760 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
1761 rdev->monitor_channel->center_freq) ||
1762 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
1763 rdev->monitor_channel_type))
59ef43e6 1764 goto nla_put_failure;
d91df0e3
PF
1765 }
1766
55682965
JB
1767 return genlmsg_end(msg, hdr);
1768
1769 nla_put_failure:
bc3ed28c
TG
1770 genlmsg_cancel(msg, hdr);
1771 return -EMSGSIZE;
55682965
JB
1772}
1773
1774static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1775{
1776 int wp_idx = 0;
1777 int if_idx = 0;
1778 int wp_start = cb->args[0];
1779 int if_start = cb->args[1];
f5ea9120 1780 struct cfg80211_registered_device *rdev;
55682965
JB
1781 struct wireless_dev *wdev;
1782
a1794390 1783 mutex_lock(&cfg80211_mutex);
f5ea9120
JB
1784 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1785 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 1786 continue;
bba95fef
JB
1787 if (wp_idx < wp_start) {
1788 wp_idx++;
55682965 1789 continue;
bba95fef 1790 }
55682965
JB
1791 if_idx = 0;
1792
f5ea9120 1793 mutex_lock(&rdev->devlist_mtx);
89a54e48 1794 list_for_each_entry(wdev, &rdev->wdev_list, list) {
bba95fef
JB
1795 if (if_idx < if_start) {
1796 if_idx++;
55682965 1797 continue;
bba95fef 1798 }
55682965
JB
1799 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1800 cb->nlh->nlmsg_seq, NLM_F_MULTI,
72fb2abc 1801 rdev, wdev) < 0) {
f5ea9120 1802 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1803 goto out;
1804 }
1805 if_idx++;
55682965 1806 }
f5ea9120 1807 mutex_unlock(&rdev->devlist_mtx);
bba95fef
JB
1808
1809 wp_idx++;
55682965 1810 }
bba95fef 1811 out:
a1794390 1812 mutex_unlock(&cfg80211_mutex);
55682965
JB
1813
1814 cb->args[0] = wp_idx;
1815 cb->args[1] = if_idx;
1816
1817 return skb->len;
1818}
1819
1820static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1821{
1822 struct sk_buff *msg;
4c476991 1823 struct cfg80211_registered_device *dev = info->user_ptr[0];
72fb2abc 1824 struct wireless_dev *wdev = info->user_ptr[1];
55682965 1825
fd2120ca 1826 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 1827 if (!msg)
4c476991 1828 return -ENOMEM;
55682965 1829
d726405a 1830 if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
72fb2abc 1831 dev, wdev) < 0) {
4c476991
JB
1832 nlmsg_free(msg);
1833 return -ENOBUFS;
1834 }
55682965 1835
134e6375 1836 return genlmsg_reply(msg, info);
55682965
JB
1837}
1838
66f7ac50
MW
1839static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1840 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1841 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1842 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1843 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1844 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1845};
1846
1847static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1848{
1849 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1850 int flag;
1851
1852 *mntrflags = 0;
1853
1854 if (!nla)
1855 return -EINVAL;
1856
1857 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1858 nla, mntr_flags_policy))
1859 return -EINVAL;
1860
1861 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1862 if (flags[flag])
1863 *mntrflags |= (1<<flag);
1864
1865 return 0;
1866}
1867
9bc383de 1868static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
1869 struct net_device *netdev, u8 use_4addr,
1870 enum nl80211_iftype iftype)
9bc383de 1871{
ad4bb6f8 1872 if (!use_4addr) {
f350a0a8 1873 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
ad4bb6f8 1874 return -EBUSY;
9bc383de 1875 return 0;
ad4bb6f8 1876 }
9bc383de
JB
1877
1878 switch (iftype) {
1879 case NL80211_IFTYPE_AP_VLAN:
1880 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1881 return 0;
1882 break;
1883 case NL80211_IFTYPE_STATION:
1884 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1885 return 0;
1886 break;
1887 default:
1888 break;
1889 }
1890
1891 return -EOPNOTSUPP;
1892}
1893
55682965
JB
1894static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1895{
4c476991 1896 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1897 struct vif_params params;
e36d56b6 1898 int err;
04a773ad 1899 enum nl80211_iftype otype, ntype;
4c476991 1900 struct net_device *dev = info->user_ptr[1];
92ffe055 1901 u32 _flags, *flags = NULL;
ac7f9cfa 1902 bool change = false;
55682965 1903
2ec600d6
LCC
1904 memset(&params, 0, sizeof(params));
1905
04a773ad 1906 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 1907
723b038d 1908 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 1909 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 1910 if (otype != ntype)
ac7f9cfa 1911 change = true;
4c476991
JB
1912 if (ntype > NL80211_IFTYPE_MAX)
1913 return -EINVAL;
723b038d
JB
1914 }
1915
92ffe055 1916 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
1917 struct wireless_dev *wdev = dev->ieee80211_ptr;
1918
4c476991
JB
1919 if (ntype != NL80211_IFTYPE_MESH_POINT)
1920 return -EINVAL;
29cbe68c
JB
1921 if (netif_running(dev))
1922 return -EBUSY;
1923
1924 wdev_lock(wdev);
1925 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1926 IEEE80211_MAX_MESH_ID_LEN);
1927 wdev->mesh_id_up_len =
1928 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1929 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1930 wdev->mesh_id_up_len);
1931 wdev_unlock(wdev);
2ec600d6
LCC
1932 }
1933
8b787643
FF
1934 if (info->attrs[NL80211_ATTR_4ADDR]) {
1935 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1936 change = true;
ad4bb6f8 1937 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 1938 if (err)
4c476991 1939 return err;
8b787643
FF
1940 } else {
1941 params.use_4addr = -1;
1942 }
1943
92ffe055 1944 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
4c476991
JB
1945 if (ntype != NL80211_IFTYPE_MONITOR)
1946 return -EINVAL;
92ffe055
JB
1947 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1948 &_flags);
ac7f9cfa 1949 if (err)
4c476991 1950 return err;
ac7f9cfa
JB
1951
1952 flags = &_flags;
1953 change = true;
92ffe055 1954 }
3b85875a 1955
ac7f9cfa 1956 if (change)
3d54d255 1957 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
ac7f9cfa
JB
1958 else
1959 err = 0;
60719ffd 1960
9bc383de
JB
1961 if (!err && params.use_4addr != -1)
1962 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1963
55682965
JB
1964 return err;
1965}
1966
1967static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1968{
4c476991 1969 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 1970 struct vif_params params;
f9e10ce4 1971 struct net_device *dev;
55682965
JB
1972 int err;
1973 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
66f7ac50 1974 u32 flags;
55682965 1975
2ec600d6
LCC
1976 memset(&params, 0, sizeof(params));
1977
55682965
JB
1978 if (!info->attrs[NL80211_ATTR_IFNAME])
1979 return -EINVAL;
1980
1981 if (info->attrs[NL80211_ATTR_IFTYPE]) {
1982 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1983 if (type > NL80211_IFTYPE_MAX)
1984 return -EINVAL;
1985 }
1986
79c97e97 1987 if (!rdev->ops->add_virtual_intf ||
4c476991
JB
1988 !(rdev->wiphy.interface_modes & (1 << type)))
1989 return -EOPNOTSUPP;
55682965 1990
9bc383de 1991 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 1992 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 1993 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 1994 if (err)
4c476991 1995 return err;
9bc383de 1996 }
8b787643 1997
66f7ac50
MW
1998 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1999 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
2000 &flags);
f9e10ce4 2001 dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
66f7ac50 2002 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
2ec600d6 2003 type, err ? NULL : &flags, &params);
f9e10ce4
JB
2004 if (IS_ERR(dev))
2005 return PTR_ERR(dev);
2ec600d6 2006
29cbe68c
JB
2007 if (type == NL80211_IFTYPE_MESH_POINT &&
2008 info->attrs[NL80211_ATTR_MESH_ID]) {
2009 struct wireless_dev *wdev = dev->ieee80211_ptr;
2010
2011 wdev_lock(wdev);
2012 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
2013 IEEE80211_MAX_MESH_ID_LEN);
2014 wdev->mesh_id_up_len =
2015 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
2016 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
2017 wdev->mesh_id_up_len);
2018 wdev_unlock(wdev);
2019 }
2020
f9e10ce4 2021 return 0;
55682965
JB
2022}
2023
2024static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
2025{
4c476991
JB
2026 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2027 struct net_device *dev = info->user_ptr[1];
55682965 2028
4c476991
JB
2029 if (!rdev->ops->del_virtual_intf)
2030 return -EOPNOTSUPP;
55682965 2031
4c476991 2032 return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
55682965
JB
2033}
2034
1d9d9213
SW
2035static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
2036{
2037 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2038 struct net_device *dev = info->user_ptr[1];
2039 u16 noack_map;
2040
2041 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
2042 return -EINVAL;
2043
2044 if (!rdev->ops->set_noack_map)
2045 return -EOPNOTSUPP;
2046
2047 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
2048
2049 return rdev->ops->set_noack_map(&rdev->wiphy, dev, noack_map);
2050}
2051
41ade00f
JB
2052struct get_key_cookie {
2053 struct sk_buff *msg;
2054 int error;
b9454e83 2055 int idx;
41ade00f
JB
2056};
2057
2058static void get_key_callback(void *c, struct key_params *params)
2059{
b9454e83 2060 struct nlattr *key;
41ade00f
JB
2061 struct get_key_cookie *cookie = c;
2062
9360ffd1
DM
2063 if ((params->key &&
2064 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
2065 params->key_len, params->key)) ||
2066 (params->seq &&
2067 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
2068 params->seq_len, params->seq)) ||
2069 (params->cipher &&
2070 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
2071 params->cipher)))
2072 goto nla_put_failure;
41ade00f 2073
b9454e83
JB
2074 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
2075 if (!key)
2076 goto nla_put_failure;
2077
9360ffd1
DM
2078 if ((params->key &&
2079 nla_put(cookie->msg, NL80211_KEY_DATA,
2080 params->key_len, params->key)) ||
2081 (params->seq &&
2082 nla_put(cookie->msg, NL80211_KEY_SEQ,
2083 params->seq_len, params->seq)) ||
2084 (params->cipher &&
2085 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
2086 params->cipher)))
2087 goto nla_put_failure;
b9454e83 2088
9360ffd1
DM
2089 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx))
2090 goto nla_put_failure;
b9454e83
JB
2091
2092 nla_nest_end(cookie->msg, key);
2093
41ade00f
JB
2094 return;
2095 nla_put_failure:
2096 cookie->error = 1;
2097}
2098
2099static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
2100{
4c476991 2101 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2102 int err;
4c476991 2103 struct net_device *dev = info->user_ptr[1];
41ade00f 2104 u8 key_idx = 0;
e31b8213
JB
2105 const u8 *mac_addr = NULL;
2106 bool pairwise;
41ade00f
JB
2107 struct get_key_cookie cookie = {
2108 .error = 0,
2109 };
2110 void *hdr;
2111 struct sk_buff *msg;
2112
2113 if (info->attrs[NL80211_ATTR_KEY_IDX])
2114 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
2115
3cfcf6ac 2116 if (key_idx > 5)
41ade00f
JB
2117 return -EINVAL;
2118
2119 if (info->attrs[NL80211_ATTR_MAC])
2120 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2121
e31b8213
JB
2122 pairwise = !!mac_addr;
2123 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
2124 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
2125 if (kt >= NUM_NL80211_KEYTYPES)
2126 return -EINVAL;
2127 if (kt != NL80211_KEYTYPE_GROUP &&
2128 kt != NL80211_KEYTYPE_PAIRWISE)
2129 return -EINVAL;
2130 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
2131 }
2132
4c476991
JB
2133 if (!rdev->ops->get_key)
2134 return -EOPNOTSUPP;
41ade00f 2135
fd2120ca 2136 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
2137 if (!msg)
2138 return -ENOMEM;
41ade00f
JB
2139
2140 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2141 NL80211_CMD_NEW_KEY);
4c476991
JB
2142 if (IS_ERR(hdr))
2143 return PTR_ERR(hdr);
41ade00f
JB
2144
2145 cookie.msg = msg;
b9454e83 2146 cookie.idx = key_idx;
41ade00f 2147
9360ffd1
DM
2148 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2149 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
2150 goto nla_put_failure;
2151 if (mac_addr &&
2152 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
2153 goto nla_put_failure;
41ade00f 2154
e31b8213
JB
2155 if (pairwise && mac_addr &&
2156 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2157 return -ENOENT;
2158
2159 err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
2160 mac_addr, &cookie, get_key_callback);
41ade00f
JB
2161
2162 if (err)
6c95e2a2 2163 goto free_msg;
41ade00f
JB
2164
2165 if (cookie.error)
2166 goto nla_put_failure;
2167
2168 genlmsg_end(msg, hdr);
4c476991 2169 return genlmsg_reply(msg, info);
41ade00f
JB
2170
2171 nla_put_failure:
2172 err = -ENOBUFS;
6c95e2a2 2173 free_msg:
41ade00f 2174 nlmsg_free(msg);
41ade00f
JB
2175 return err;
2176}
2177
2178static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
2179{
4c476991 2180 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 2181 struct key_parse key;
41ade00f 2182 int err;
4c476991 2183 struct net_device *dev = info->user_ptr[1];
41ade00f 2184
b9454e83
JB
2185 err = nl80211_parse_key(info, &key);
2186 if (err)
2187 return err;
41ade00f 2188
b9454e83 2189 if (key.idx < 0)
41ade00f
JB
2190 return -EINVAL;
2191
b9454e83
JB
2192 /* only support setting default key */
2193 if (!key.def && !key.defmgmt)
41ade00f
JB
2194 return -EINVAL;
2195
dbd2fd65 2196 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 2197
dbd2fd65
JB
2198 if (key.def) {
2199 if (!rdev->ops->set_default_key) {
2200 err = -EOPNOTSUPP;
2201 goto out;
2202 }
41ade00f 2203
dbd2fd65
JB
2204 err = nl80211_key_allowed(dev->ieee80211_ptr);
2205 if (err)
2206 goto out;
2207
dbd2fd65
JB
2208 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
2209 key.def_uni, key.def_multi);
2210
2211 if (err)
2212 goto out;
fffd0934 2213
3d23e349 2214#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
2215 dev->ieee80211_ptr->wext.default_key = key.idx;
2216#endif
2217 } else {
2218 if (key.def_uni || !key.def_multi) {
2219 err = -EINVAL;
2220 goto out;
2221 }
2222
2223 if (!rdev->ops->set_default_mgmt_key) {
2224 err = -EOPNOTSUPP;
2225 goto out;
2226 }
2227
2228 err = nl80211_key_allowed(dev->ieee80211_ptr);
2229 if (err)
2230 goto out;
2231
2232 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
2233 dev, key.idx);
2234 if (err)
2235 goto out;
2236
2237#ifdef CONFIG_CFG80211_WEXT
2238 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 2239#endif
dbd2fd65
JB
2240 }
2241
2242 out:
fffd0934 2243 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2244
41ade00f
JB
2245 return err;
2246}
2247
2248static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
2249{
4c476991 2250 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 2251 int err;
4c476991 2252 struct net_device *dev = info->user_ptr[1];
b9454e83 2253 struct key_parse key;
e31b8213 2254 const u8 *mac_addr = NULL;
41ade00f 2255
b9454e83
JB
2256 err = nl80211_parse_key(info, &key);
2257 if (err)
2258 return err;
41ade00f 2259
b9454e83 2260 if (!key.p.key)
41ade00f
JB
2261 return -EINVAL;
2262
41ade00f
JB
2263 if (info->attrs[NL80211_ATTR_MAC])
2264 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2265
e31b8213
JB
2266 if (key.type == -1) {
2267 if (mac_addr)
2268 key.type = NL80211_KEYTYPE_PAIRWISE;
2269 else
2270 key.type = NL80211_KEYTYPE_GROUP;
2271 }
2272
2273 /* for now */
2274 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2275 key.type != NL80211_KEYTYPE_GROUP)
2276 return -EINVAL;
2277
4c476991
JB
2278 if (!rdev->ops->add_key)
2279 return -EOPNOTSUPP;
25e47c18 2280
e31b8213
JB
2281 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
2282 key.type == NL80211_KEYTYPE_PAIRWISE,
2283 mac_addr))
4c476991 2284 return -EINVAL;
41ade00f 2285
fffd0934
JB
2286 wdev_lock(dev->ieee80211_ptr);
2287 err = nl80211_key_allowed(dev->ieee80211_ptr);
2288 if (!err)
2289 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
e31b8213 2290 key.type == NL80211_KEYTYPE_PAIRWISE,
fffd0934
JB
2291 mac_addr, &key.p);
2292 wdev_unlock(dev->ieee80211_ptr);
41ade00f 2293
41ade00f
JB
2294 return err;
2295}
2296
2297static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
2298{
4c476991 2299 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 2300 int err;
4c476991 2301 struct net_device *dev = info->user_ptr[1];
41ade00f 2302 u8 *mac_addr = NULL;
b9454e83 2303 struct key_parse key;
41ade00f 2304
b9454e83
JB
2305 err = nl80211_parse_key(info, &key);
2306 if (err)
2307 return err;
41ade00f
JB
2308
2309 if (info->attrs[NL80211_ATTR_MAC])
2310 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2311
e31b8213
JB
2312 if (key.type == -1) {
2313 if (mac_addr)
2314 key.type = NL80211_KEYTYPE_PAIRWISE;
2315 else
2316 key.type = NL80211_KEYTYPE_GROUP;
2317 }
2318
2319 /* for now */
2320 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
2321 key.type != NL80211_KEYTYPE_GROUP)
2322 return -EINVAL;
2323
4c476991
JB
2324 if (!rdev->ops->del_key)
2325 return -EOPNOTSUPP;
41ade00f 2326
fffd0934
JB
2327 wdev_lock(dev->ieee80211_ptr);
2328 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213
JB
2329
2330 if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
2331 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
2332 err = -ENOENT;
2333
fffd0934 2334 if (!err)
e31b8213
JB
2335 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
2336 key.type == NL80211_KEYTYPE_PAIRWISE,
2337 mac_addr);
41ade00f 2338
3d23e349 2339#ifdef CONFIG_CFG80211_WEXT
08645126 2340 if (!err) {
b9454e83 2341 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 2342 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 2343 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
2344 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
2345 }
2346#endif
fffd0934 2347 wdev_unlock(dev->ieee80211_ptr);
08645126 2348
41ade00f
JB
2349 return err;
2350}
2351
8860020e
JB
2352static int nl80211_parse_beacon(struct genl_info *info,
2353 struct cfg80211_beacon_data *bcn)
ed1b6cc7 2354{
8860020e 2355 bool haveinfo = false;
ed1b6cc7 2356
9946ecfb
JM
2357 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]) ||
2358 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]) ||
2359 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_PROBE_RESP]) ||
2360 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]))
f4a11bb0
JB
2361 return -EINVAL;
2362
8860020e 2363 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 2364
ed1b6cc7 2365 if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
8860020e
JB
2366 bcn->head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2367 bcn->head_len = nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
2368 if (!bcn->head_len)
2369 return -EINVAL;
2370 haveinfo = true;
ed1b6cc7
JB
2371 }
2372
2373 if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
8860020e
JB
2374 bcn->tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
2375 bcn->tail_len =
ed1b6cc7 2376 nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 2377 haveinfo = true;
ed1b6cc7
JB
2378 }
2379
4c476991
JB
2380 if (!haveinfo)
2381 return -EINVAL;
3b85875a 2382
9946ecfb 2383 if (info->attrs[NL80211_ATTR_IE]) {
8860020e
JB
2384 bcn->beacon_ies = nla_data(info->attrs[NL80211_ATTR_IE]);
2385 bcn->beacon_ies_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9946ecfb
JM
2386 }
2387
2388 if (info->attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 2389 bcn->proberesp_ies =
9946ecfb 2390 nla_data(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 2391 bcn->proberesp_ies_len =
9946ecfb
JM
2392 nla_len(info->attrs[NL80211_ATTR_IE_PROBE_RESP]);
2393 }
2394
2395 if (info->attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 2396 bcn->assocresp_ies =
9946ecfb 2397 nla_data(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 2398 bcn->assocresp_ies_len =
9946ecfb
JM
2399 nla_len(info->attrs[NL80211_ATTR_IE_ASSOC_RESP]);
2400 }
2401
00f740e1 2402 if (info->attrs[NL80211_ATTR_PROBE_RESP]) {
8860020e 2403 bcn->probe_resp =
00f740e1 2404 nla_data(info->attrs[NL80211_ATTR_PROBE_RESP]);
8860020e 2405 bcn->probe_resp_len =
00f740e1
AN
2406 nla_len(info->attrs[NL80211_ATTR_PROBE_RESP]);
2407 }
2408
8860020e
JB
2409 return 0;
2410}
2411
46c1dd0c
FF
2412static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
2413 struct cfg80211_ap_settings *params)
2414{
2415 struct wireless_dev *wdev;
2416 bool ret = false;
2417
2418 mutex_lock(&rdev->devlist_mtx);
2419
89a54e48 2420 list_for_each_entry(wdev, &rdev->wdev_list, list) {
46c1dd0c
FF
2421 if (wdev->iftype != NL80211_IFTYPE_AP &&
2422 wdev->iftype != NL80211_IFTYPE_P2P_GO)
2423 continue;
2424
2425 if (!wdev->preset_chan)
2426 continue;
2427
2428 params->channel = wdev->preset_chan;
2429 params->channel_type = wdev->preset_chantype;
2430 ret = true;
2431 break;
2432 }
2433
2434 mutex_unlock(&rdev->devlist_mtx);
2435
2436 return ret;
2437}
2438
8860020e
JB
2439static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
2440{
2441 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2442 struct net_device *dev = info->user_ptr[1];
2443 struct wireless_dev *wdev = dev->ieee80211_ptr;
2444 struct cfg80211_ap_settings params;
2445 int err;
2446
2447 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2448 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2449 return -EOPNOTSUPP;
2450
2451 if (!rdev->ops->start_ap)
2452 return -EOPNOTSUPP;
2453
2454 if (wdev->beacon_interval)
2455 return -EALREADY;
2456
2457 memset(&params, 0, sizeof(params));
2458
2459 /* these are required for START_AP */
2460 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
2461 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
2462 !info->attrs[NL80211_ATTR_BEACON_HEAD])
2463 return -EINVAL;
2464
2465 err = nl80211_parse_beacon(info, &params.beacon);
2466 if (err)
2467 return err;
2468
2469 params.beacon_interval =
2470 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
2471 params.dtim_period =
2472 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
2473
2474 err = cfg80211_validate_beacon_int(rdev, params.beacon_interval);
2475 if (err)
2476 return err;
2477
2478 /*
2479 * In theory, some of these attributes should be required here
2480 * but since they were not used when the command was originally
2481 * added, keep them optional for old user space programs to let
2482 * them continue to work with drivers that do not need the
2483 * additional information -- drivers must check!
2484 */
2485 if (info->attrs[NL80211_ATTR_SSID]) {
2486 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
2487 params.ssid_len =
2488 nla_len(info->attrs[NL80211_ATTR_SSID]);
2489 if (params.ssid_len == 0 ||
2490 params.ssid_len > IEEE80211_MAX_SSID_LEN)
2491 return -EINVAL;
2492 }
2493
2494 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) {
2495 params.hidden_ssid = nla_get_u32(
2496 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
2497 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE &&
2498 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN &&
2499 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS)
2500 return -EINVAL;
2501 }
2502
2503 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
2504
2505 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
2506 params.auth_type = nla_get_u32(
2507 info->attrs[NL80211_ATTR_AUTH_TYPE]);
2508 if (!nl80211_valid_auth_type(params.auth_type))
2509 return -EINVAL;
2510 } else
2511 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
2512
2513 err = nl80211_crypto_settings(rdev, info, &params.crypto,
2514 NL80211_MAX_NR_CIPHER_SUITES);
2515 if (err)
2516 return err;
2517
1b658f11
VT
2518 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
2519 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
2520 return -EOPNOTSUPP;
2521 params.inactivity_timeout = nla_get_u16(
2522 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
2523 }
2524
aa430da4
JB
2525 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
2526 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
2527
2528 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
2529 !nl80211_valid_channel_type(info, &channel_type))
2530 return -EINVAL;
2531
2532 params.channel = rdev_freq_to_chan(rdev,
2533 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
2534 channel_type);
2535 if (!params.channel)
2536 return -EINVAL;
2537 params.channel_type = channel_type;
2538 } else if (wdev->preset_chan) {
2539 params.channel = wdev->preset_chan;
2540 params.channel_type = wdev->preset_chantype;
46c1dd0c 2541 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
2542 return -EINVAL;
2543
2544 if (!cfg80211_can_beacon_sec_chan(&rdev->wiphy, params.channel,
2545 params.channel_type))
2546 return -EINVAL;
2547
e4e32459
MK
2548 mutex_lock(&rdev->devlist_mtx);
2549 err = cfg80211_can_use_chan(rdev, wdev, params.channel,
2550 CHAN_MODE_SHARED);
2551 mutex_unlock(&rdev->devlist_mtx);
2552
2553 if (err)
2554 return err;
2555
8860020e 2556 err = rdev->ops->start_ap(&rdev->wiphy, dev, &params);
46c1dd0c
FF
2557 if (!err) {
2558 wdev->preset_chan = params.channel;
2559 wdev->preset_chantype = params.channel_type;
8860020e 2560 wdev->beacon_interval = params.beacon_interval;
f4489ebe 2561 wdev->channel = params.channel;
46c1dd0c 2562 }
56d1893d 2563 return err;
ed1b6cc7
JB
2564}
2565
8860020e
JB
2566static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
2567{
2568 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2569 struct net_device *dev = info->user_ptr[1];
2570 struct wireless_dev *wdev = dev->ieee80211_ptr;
2571 struct cfg80211_beacon_data params;
2572 int err;
2573
2574 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2575 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2576 return -EOPNOTSUPP;
2577
2578 if (!rdev->ops->change_beacon)
2579 return -EOPNOTSUPP;
2580
2581 if (!wdev->beacon_interval)
2582 return -EINVAL;
2583
2584 err = nl80211_parse_beacon(info, &params);
2585 if (err)
2586 return err;
2587
2588 return rdev->ops->change_beacon(&rdev->wiphy, dev, &params);
2589}
2590
2591static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 2592{
4c476991
JB
2593 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2594 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 2595
60771780 2596 return cfg80211_stop_ap(rdev, dev);
ed1b6cc7
JB
2597}
2598
5727ef1b
JB
2599static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
2600 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
2601 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
2602 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 2603 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 2604 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 2605 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
2606};
2607
eccb8e8f 2608static int parse_station_flags(struct genl_info *info,
bdd3ae3d 2609 enum nl80211_iftype iftype,
eccb8e8f 2610 struct station_parameters *params)
5727ef1b
JB
2611{
2612 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 2613 struct nlattr *nla;
5727ef1b
JB
2614 int flag;
2615
eccb8e8f
JB
2616 /*
2617 * Try parsing the new attribute first so userspace
2618 * can specify both for older kernels.
2619 */
2620 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
2621 if (nla) {
2622 struct nl80211_sta_flag_update *sta_flags;
2623
2624 sta_flags = nla_data(nla);
2625 params->sta_flags_mask = sta_flags->mask;
2626 params->sta_flags_set = sta_flags->set;
2627 if ((params->sta_flags_mask |
2628 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
2629 return -EINVAL;
2630 return 0;
2631 }
2632
2633 /* if present, parse the old attribute */
5727ef1b 2634
eccb8e8f 2635 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
2636 if (!nla)
2637 return 0;
2638
2639 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
2640 nla, sta_flags_policy))
2641 return -EINVAL;
2642
bdd3ae3d
JB
2643 /*
2644 * Only allow certain flags for interface types so that
2645 * other attributes are silently ignored. Remember that
2646 * this is backward compatibility code with old userspace
2647 * and shouldn't be hit in other cases anyway.
2648 */
2649 switch (iftype) {
2650 case NL80211_IFTYPE_AP:
2651 case NL80211_IFTYPE_AP_VLAN:
2652 case NL80211_IFTYPE_P2P_GO:
2653 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2654 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
2655 BIT(NL80211_STA_FLAG_WME) |
2656 BIT(NL80211_STA_FLAG_MFP);
2657 break;
2658 case NL80211_IFTYPE_P2P_CLIENT:
2659 case NL80211_IFTYPE_STATION:
2660 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
2661 BIT(NL80211_STA_FLAG_TDLS_PEER);
2662 break;
2663 case NL80211_IFTYPE_MESH_POINT:
2664 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
2665 BIT(NL80211_STA_FLAG_MFP) |
2666 BIT(NL80211_STA_FLAG_AUTHORIZED);
2667 default:
2668 return -EINVAL;
2669 }
5727ef1b 2670
3383b5a6
JB
2671 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
2672 if (flags[flag]) {
eccb8e8f 2673 params->sta_flags_set |= (1<<flag);
5727ef1b 2674
3383b5a6
JB
2675 /* no longer support new API additions in old API */
2676 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
2677 return -EINVAL;
2678 }
2679 }
2680
5727ef1b
JB
2681 return 0;
2682}
2683
c8dcfd8a
FF
2684static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info,
2685 int attr)
2686{
2687 struct nlattr *rate;
8eb41c8d
VK
2688 u32 bitrate;
2689 u16 bitrate_compat;
c8dcfd8a
FF
2690
2691 rate = nla_nest_start(msg, attr);
2692 if (!rate)
2693 goto nla_put_failure;
2694
2695 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2696 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
2697 /* report 16-bit bitrate only if we can */
2698 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
9360ffd1 2699 if ((bitrate > 0 &&
8eb41c8d
VK
2700 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate)) ||
2701 (bitrate_compat > 0 &&
2702 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat)) ||
9360ffd1
DM
2703 ((info->flags & RATE_INFO_FLAGS_MCS) &&
2704 nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs)) ||
2705 ((info->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) &&
2706 nla_put_flag(msg, NL80211_RATE_INFO_40_MHZ_WIDTH)) ||
2707 ((info->flags & RATE_INFO_FLAGS_SHORT_GI) &&
2708 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)))
2709 goto nla_put_failure;
c8dcfd8a
FF
2710
2711 nla_nest_end(msg, rate);
2712 return true;
2713
2714nla_put_failure:
2715 return false;
2716}
2717
fd5b74dc 2718static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
66266b3a
JL
2719 int flags,
2720 struct cfg80211_registered_device *rdev,
2721 struct net_device *dev,
98b62183 2722 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
2723{
2724 void *hdr;
f4263c98 2725 struct nlattr *sinfoattr, *bss_param;
fd5b74dc
JB
2726
2727 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2728 if (!hdr)
2729 return -1;
2730
9360ffd1
DM
2731 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
2732 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
2733 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
2734 goto nla_put_failure;
f5ea9120 2735
2ec600d6
LCC
2736 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
2737 if (!sinfoattr)
fd5b74dc 2738 goto nla_put_failure;
9360ffd1
DM
2739 if ((sinfo->filled & STATION_INFO_CONNECTED_TIME) &&
2740 nla_put_u32(msg, NL80211_STA_INFO_CONNECTED_TIME,
2741 sinfo->connected_time))
2742 goto nla_put_failure;
2743 if ((sinfo->filled & STATION_INFO_INACTIVE_TIME) &&
2744 nla_put_u32(msg, NL80211_STA_INFO_INACTIVE_TIME,
2745 sinfo->inactive_time))
2746 goto nla_put_failure;
2747 if ((sinfo->filled & STATION_INFO_RX_BYTES) &&
2748 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
2749 sinfo->rx_bytes))
2750 goto nla_put_failure;
2751 if ((sinfo->filled & STATION_INFO_TX_BYTES) &&
2752 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
2753 sinfo->tx_bytes))
2754 goto nla_put_failure;
2755 if ((sinfo->filled & STATION_INFO_LLID) &&
2756 nla_put_u16(msg, NL80211_STA_INFO_LLID, sinfo->llid))
2757 goto nla_put_failure;
2758 if ((sinfo->filled & STATION_INFO_PLID) &&
2759 nla_put_u16(msg, NL80211_STA_INFO_PLID, sinfo->plid))
2760 goto nla_put_failure;
2761 if ((sinfo->filled & STATION_INFO_PLINK_STATE) &&
2762 nla_put_u8(msg, NL80211_STA_INFO_PLINK_STATE,
2763 sinfo->plink_state))
2764 goto nla_put_failure;
66266b3a
JL
2765 switch (rdev->wiphy.signal_type) {
2766 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
2767 if ((sinfo->filled & STATION_INFO_SIGNAL) &&
2768 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL,
2769 sinfo->signal))
2770 goto nla_put_failure;
2771 if ((sinfo->filled & STATION_INFO_SIGNAL_AVG) &&
2772 nla_put_u8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2773 sinfo->signal_avg))
2774 goto nla_put_failure;
66266b3a
JL
2775 break;
2776 default:
2777 break;
2778 }
420e7fab 2779 if (sinfo->filled & STATION_INFO_TX_BITRATE) {
c8dcfd8a
FF
2780 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
2781 NL80211_STA_INFO_TX_BITRATE))
2782 goto nla_put_failure;
2783 }
2784 if (sinfo->filled & STATION_INFO_RX_BITRATE) {
2785 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
2786 NL80211_STA_INFO_RX_BITRATE))
420e7fab 2787 goto nla_put_failure;
420e7fab 2788 }
9360ffd1
DM
2789 if ((sinfo->filled & STATION_INFO_RX_PACKETS) &&
2790 nla_put_u32(msg, NL80211_STA_INFO_RX_PACKETS,
2791 sinfo->rx_packets))
2792 goto nla_put_failure;
2793 if ((sinfo->filled & STATION_INFO_TX_PACKETS) &&
2794 nla_put_u32(msg, NL80211_STA_INFO_TX_PACKETS,
2795 sinfo->tx_packets))
2796 goto nla_put_failure;
2797 if ((sinfo->filled & STATION_INFO_TX_RETRIES) &&
2798 nla_put_u32(msg, NL80211_STA_INFO_TX_RETRIES,
2799 sinfo->tx_retries))
2800 goto nla_put_failure;
2801 if ((sinfo->filled & STATION_INFO_TX_FAILED) &&
2802 nla_put_u32(msg, NL80211_STA_INFO_TX_FAILED,
2803 sinfo->tx_failed))
2804 goto nla_put_failure;
2805 if ((sinfo->filled & STATION_INFO_BEACON_LOSS_COUNT) &&
2806 nla_put_u32(msg, NL80211_STA_INFO_BEACON_LOSS,
2807 sinfo->beacon_loss_count))
2808 goto nla_put_failure;
f4263c98
PS
2809 if (sinfo->filled & STATION_INFO_BSS_PARAM) {
2810 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM);
2811 if (!bss_param)
2812 goto nla_put_failure;
2813
9360ffd1
DM
2814 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
2815 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
2816 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
2817 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
2818 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
2819 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
2820 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
2821 sinfo->bss_param.dtim_period) ||
2822 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
2823 sinfo->bss_param.beacon_interval))
2824 goto nla_put_failure;
f4263c98
PS
2825
2826 nla_nest_end(msg, bss_param);
2827 }
9360ffd1
DM
2828 if ((sinfo->filled & STATION_INFO_STA_FLAGS) &&
2829 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
2830 sizeof(struct nl80211_sta_flag_update),
2831 &sinfo->sta_flags))
2832 goto nla_put_failure;
7eab0f64
JL
2833 if ((sinfo->filled & STATION_INFO_T_OFFSET) &&
2834 nla_put_u64(msg, NL80211_STA_INFO_T_OFFSET,
2835 sinfo->t_offset))
2836 goto nla_put_failure;
2ec600d6 2837 nla_nest_end(msg, sinfoattr);
fd5b74dc 2838
9360ffd1
DM
2839 if ((sinfo->filled & STATION_INFO_ASSOC_REQ_IES) &&
2840 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
2841 sinfo->assoc_req_ies))
2842 goto nla_put_failure;
50d3dfb7 2843
fd5b74dc
JB
2844 return genlmsg_end(msg, hdr);
2845
2846 nla_put_failure:
bc3ed28c
TG
2847 genlmsg_cancel(msg, hdr);
2848 return -EMSGSIZE;
fd5b74dc
JB
2849}
2850
2ec600d6 2851static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 2852 struct netlink_callback *cb)
2ec600d6 2853{
2ec600d6
LCC
2854 struct station_info sinfo;
2855 struct cfg80211_registered_device *dev;
bba95fef 2856 struct net_device *netdev;
2ec600d6 2857 u8 mac_addr[ETH_ALEN];
bba95fef 2858 int sta_idx = cb->args[1];
2ec600d6 2859 int err;
2ec600d6 2860
67748893
JB
2861 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2862 if (err)
2863 return err;
bba95fef
JB
2864
2865 if (!dev->ops->dump_station) {
eec60b03 2866 err = -EOPNOTSUPP;
bba95fef
JB
2867 goto out_err;
2868 }
2869
bba95fef 2870 while (1) {
f612cedf 2871 memset(&sinfo, 0, sizeof(sinfo));
bba95fef
JB
2872 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2873 mac_addr, &sinfo);
2874 if (err == -ENOENT)
2875 break;
2876 if (err)
3b85875a 2877 goto out_err;
bba95fef
JB
2878
2879 if (nl80211_send_station(skb,
2880 NETLINK_CB(cb->skb).pid,
2881 cb->nlh->nlmsg_seq, NLM_F_MULTI,
66266b3a 2882 dev, netdev, mac_addr,
bba95fef
JB
2883 &sinfo) < 0)
2884 goto out;
2885
2886 sta_idx++;
2887 }
2888
2889
2890 out:
2891 cb->args[1] = sta_idx;
2892 err = skb->len;
bba95fef 2893 out_err:
67748893 2894 nl80211_finish_netdev_dump(dev);
bba95fef
JB
2895
2896 return err;
2ec600d6 2897}
fd5b74dc 2898
5727ef1b
JB
2899static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2900{
4c476991
JB
2901 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2902 struct net_device *dev = info->user_ptr[1];
2ec600d6 2903 struct station_info sinfo;
fd5b74dc
JB
2904 struct sk_buff *msg;
2905 u8 *mac_addr = NULL;
4c476991 2906 int err;
fd5b74dc 2907
2ec600d6 2908 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc
JB
2909
2910 if (!info->attrs[NL80211_ATTR_MAC])
2911 return -EINVAL;
2912
2913 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2914
4c476991
JB
2915 if (!rdev->ops->get_station)
2916 return -EOPNOTSUPP;
3b85875a 2917
4c476991 2918 err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
fd5b74dc 2919 if (err)
4c476991 2920 return err;
2ec600d6 2921
fd2120ca 2922 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
fd5b74dc 2923 if (!msg)
4c476991 2924 return -ENOMEM;
fd5b74dc
JB
2925
2926 if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
66266b3a 2927 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991
JB
2928 nlmsg_free(msg);
2929 return -ENOBUFS;
2930 }
3b85875a 2931
4c476991 2932 return genlmsg_reply(msg, info);
5727ef1b
JB
2933}
2934
2935/*
c258d2de 2936 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 2937 */
80b99899
JB
2938static struct net_device *get_vlan(struct genl_info *info,
2939 struct cfg80211_registered_device *rdev)
5727ef1b 2940{
463d0183 2941 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
2942 struct net_device *v;
2943 int ret;
2944
2945 if (!vlanattr)
2946 return NULL;
2947
2948 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
2949 if (!v)
2950 return ERR_PTR(-ENODEV);
2951
2952 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
2953 ret = -EINVAL;
2954 goto error;
5727ef1b 2955 }
80b99899
JB
2956
2957 if (!netif_running(v)) {
2958 ret = -ENETDOWN;
2959 goto error;
2960 }
2961
2962 return v;
2963 error:
2964 dev_put(v);
2965 return ERR_PTR(ret);
5727ef1b
JB
2966}
2967
2968static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2969{
4c476991 2970 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 2971 int err;
4c476991 2972 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
2973 struct station_parameters params;
2974 u8 *mac_addr = NULL;
2975
2976 memset(&params, 0, sizeof(params));
2977
2978 params.listen_interval = -1;
57cf8043 2979 params.plink_state = -1;
5727ef1b
JB
2980
2981 if (info->attrs[NL80211_ATTR_STA_AID])
2982 return -EINVAL;
2983
2984 if (!info->attrs[NL80211_ATTR_MAC])
2985 return -EINVAL;
2986
2987 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2988
2989 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2990 params.supported_rates =
2991 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2992 params.supported_rates_len =
2993 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2994 }
2995
2996 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2997 params.listen_interval =
2998 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2999
36aedc90
JM
3000 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3001 params.ht_capa =
3002 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
3003
bdd90d5e
JB
3004 if (!rdev->ops->change_station)
3005 return -EOPNOTSUPP;
3006
bdd3ae3d 3007 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3008 return -EINVAL;
3009
2ec600d6
LCC
3010 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3011 params.plink_action =
3012 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3013
9c3990aa
JC
3014 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE])
3015 params.plink_state =
3016 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
3017
a97f4424
JB
3018 switch (dev->ieee80211_ptr->iftype) {
3019 case NL80211_IFTYPE_AP:
3020 case NL80211_IFTYPE_AP_VLAN:
074ac8df 3021 case NL80211_IFTYPE_P2P_GO:
a97f4424
JB
3022 /* disallow mesh-specific things */
3023 if (params.plink_action)
bdd90d5e
JB
3024 return -EINVAL;
3025
3026 /* TDLS can't be set, ... */
3027 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3028 return -EINVAL;
3029 /*
3030 * ... but don't bother the driver with it. This works around
3031 * a hostapd/wpa_supplicant issue -- it always includes the
3032 * TLDS_PEER flag in the mask even for AP mode.
3033 */
3034 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3035
3036 /* accept only the listed bits */
3037 if (params.sta_flags_mask &
3038 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
3039 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
3040 BIT(NL80211_STA_FLAG_WME) |
3041 BIT(NL80211_STA_FLAG_MFP)))
3042 return -EINVAL;
3043
3044 /* must be last in here for error handling */
3045 params.vlan = get_vlan(info, rdev);
3046 if (IS_ERR(params.vlan))
3047 return PTR_ERR(params.vlan);
a97f4424 3048 break;
074ac8df 3049 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 3050 case NL80211_IFTYPE_STATION:
bdd90d5e
JB
3051 /*
3052 * Don't allow userspace to change the TDLS_PEER flag,
3053 * but silently ignore attempts to change it since we
3054 * don't have state here to verify that it doesn't try
3055 * to change the flag.
3056 */
3057 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
267335d6
AQ
3058 /* fall through */
3059 case NL80211_IFTYPE_ADHOC:
3060 /* disallow things sta doesn't support */
3061 if (params.plink_action)
3062 return -EINVAL;
3063 if (params.ht_capa)
3064 return -EINVAL;
3065 if (params.listen_interval >= 0)
3066 return -EINVAL;
bdd90d5e
JB
3067 /* reject any changes other than AUTHORIZED */
3068 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
3069 return -EINVAL;
a97f4424
JB
3070 break;
3071 case NL80211_IFTYPE_MESH_POINT:
3072 /* disallow things mesh doesn't support */
3073 if (params.vlan)
bdd90d5e 3074 return -EINVAL;
a97f4424 3075 if (params.ht_capa)
bdd90d5e 3076 return -EINVAL;
a97f4424 3077 if (params.listen_interval >= 0)
bdd90d5e
JB
3078 return -EINVAL;
3079 /*
3080 * No special handling for TDLS here -- the userspace
3081 * mesh code doesn't have this bug.
3082 */
b39c48fa
JC
3083 if (params.sta_flags_mask &
3084 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
8429828e 3085 BIT(NL80211_STA_FLAG_MFP) |
b39c48fa 3086 BIT(NL80211_STA_FLAG_AUTHORIZED)))
bdd90d5e 3087 return -EINVAL;
a97f4424
JB
3088 break;
3089 default:
bdd90d5e 3090 return -EOPNOTSUPP;
034d655e
JB
3091 }
3092
bdd90d5e 3093 /* be aware of params.vlan when changing code here */
5727ef1b 3094
79c97e97 3095 err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 3096
5727ef1b
JB
3097 if (params.vlan)
3098 dev_put(params.vlan);
3b85875a 3099
5727ef1b
JB
3100 return err;
3101}
3102
c75786c9
EP
3103static struct nla_policy
3104nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] __read_mostly = {
3105 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
3106 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
3107};
3108
5727ef1b
JB
3109static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
3110{
4c476991 3111 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 3112 int err;
4c476991 3113 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3114 struct station_parameters params;
3115 u8 *mac_addr = NULL;
3116
3117 memset(&params, 0, sizeof(params));
3118
3119 if (!info->attrs[NL80211_ATTR_MAC])
3120 return -EINVAL;
3121
5727ef1b
JB
3122 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
3123 return -EINVAL;
3124
3125 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
3126 return -EINVAL;
3127
0e956c13
TLSC
3128 if (!info->attrs[NL80211_ATTR_STA_AID])
3129 return -EINVAL;
3130
5727ef1b
JB
3131 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3132 params.supported_rates =
3133 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3134 params.supported_rates_len =
3135 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
3136 params.listen_interval =
3137 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 3138
0e956c13
TLSC
3139 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
3140 if (!params.aid || params.aid > IEEE80211_MAX_AID)
3141 return -EINVAL;
51b50fbe 3142
36aedc90
JM
3143 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
3144 params.ht_capa =
3145 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 3146
96b78dff
JC
3147 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
3148 params.plink_action =
3149 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
3150
bdd90d5e
JB
3151 if (!rdev->ops->add_station)
3152 return -EOPNOTSUPP;
3153
bdd3ae3d 3154 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
3155 return -EINVAL;
3156
bdd90d5e
JB
3157 switch (dev->ieee80211_ptr->iftype) {
3158 case NL80211_IFTYPE_AP:
3159 case NL80211_IFTYPE_AP_VLAN:
3160 case NL80211_IFTYPE_P2P_GO:
3161 /* parse WME attributes if sta is WME capable */
3162 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3163 (params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)) &&
3164 info->attrs[NL80211_ATTR_STA_WME]) {
3165 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
3166 struct nlattr *nla;
3167
3168 nla = info->attrs[NL80211_ATTR_STA_WME];
3169 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla,
3170 nl80211_sta_wme_policy);
3171 if (err)
3172 return err;
3173
3174 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
3175 params.uapsd_queues =
3176 nla_get_u8(tb[NL80211_STA_WME_UAPSD_QUEUES]);
3177 if (params.uapsd_queues &
3178 ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
3179 return -EINVAL;
c75786c9 3180
bdd90d5e
JB
3181 if (tb[NL80211_STA_WME_MAX_SP])
3182 params.max_sp =
3183 nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
c75786c9 3184
bdd90d5e
JB
3185 if (params.max_sp &
3186 ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
3187 return -EINVAL;
4319e193 3188
bdd90d5e
JB
3189 params.sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
3190 }
3191 /* TDLS peers cannot be added */
3192 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
4319e193 3193 return -EINVAL;
bdd90d5e
JB
3194 /* but don't bother the driver with it */
3195 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 3196
bdd90d5e
JB
3197 /* must be last in here for error handling */
3198 params.vlan = get_vlan(info, rdev);
3199 if (IS_ERR(params.vlan))
3200 return PTR_ERR(params.vlan);
3201 break;
3202 case NL80211_IFTYPE_MESH_POINT:
3203 /* TDLS peers cannot be added */
3204 if (params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
3205 return -EINVAL;
3206 break;
3207 case NL80211_IFTYPE_STATION:
3208 /* Only TDLS peers can be added */
3209 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
3210 return -EINVAL;
3211 /* Can only add if TDLS ... */
3212 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
3213 return -EOPNOTSUPP;
3214 /* ... with external setup is supported */
3215 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
3216 return -EOPNOTSUPP;
3217 break;
3218 default:
3219 return -EOPNOTSUPP;
c75786c9
EP
3220 }
3221
bdd90d5e 3222 /* be aware of params.vlan when changing code here */
5727ef1b 3223
79c97e97 3224 err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
5727ef1b 3225
5727ef1b
JB
3226 if (params.vlan)
3227 dev_put(params.vlan);
5727ef1b
JB
3228 return err;
3229}
3230
3231static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
3232{
4c476991
JB
3233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3234 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
3235 u8 *mac_addr = NULL;
3236
3237 if (info->attrs[NL80211_ATTR_MAC])
3238 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3239
e80cf853 3240 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
d5d9de02 3241 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
074ac8df 3242 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
3243 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3244 return -EINVAL;
5727ef1b 3245
4c476991
JB
3246 if (!rdev->ops->del_station)
3247 return -EOPNOTSUPP;
3b85875a 3248
4c476991 3249 return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
5727ef1b
JB
3250}
3251
2ec600d6
LCC
3252static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
3253 int flags, struct net_device *dev,
3254 u8 *dst, u8 *next_hop,
3255 struct mpath_info *pinfo)
3256{
3257 void *hdr;
3258 struct nlattr *pinfoattr;
3259
3260 hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
3261 if (!hdr)
3262 return -1;
3263
9360ffd1
DM
3264 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3265 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
3266 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
3267 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
3268 goto nla_put_failure;
f5ea9120 3269
2ec600d6
LCC
3270 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
3271 if (!pinfoattr)
3272 goto nla_put_failure;
9360ffd1
DM
3273 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
3274 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
3275 pinfo->frame_qlen))
3276 goto nla_put_failure;
3277 if (((pinfo->filled & MPATH_INFO_SN) &&
3278 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
3279 ((pinfo->filled & MPATH_INFO_METRIC) &&
3280 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
3281 pinfo->metric)) ||
3282 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
3283 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
3284 pinfo->exptime)) ||
3285 ((pinfo->filled & MPATH_INFO_FLAGS) &&
3286 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
3287 pinfo->flags)) ||
3288 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
3289 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
3290 pinfo->discovery_timeout)) ||
3291 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
3292 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
3293 pinfo->discovery_retries)))
3294 goto nla_put_failure;
2ec600d6
LCC
3295
3296 nla_nest_end(msg, pinfoattr);
3297
3298 return genlmsg_end(msg, hdr);
3299
3300 nla_put_failure:
bc3ed28c
TG
3301 genlmsg_cancel(msg, hdr);
3302 return -EMSGSIZE;
2ec600d6
LCC
3303}
3304
3305static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 3306 struct netlink_callback *cb)
2ec600d6 3307{
2ec600d6
LCC
3308 struct mpath_info pinfo;
3309 struct cfg80211_registered_device *dev;
bba95fef 3310 struct net_device *netdev;
2ec600d6
LCC
3311 u8 dst[ETH_ALEN];
3312 u8 next_hop[ETH_ALEN];
bba95fef 3313 int path_idx = cb->args[1];
2ec600d6 3314 int err;
2ec600d6 3315
67748893
JB
3316 err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3317 if (err)
3318 return err;
bba95fef
JB
3319
3320 if (!dev->ops->dump_mpath) {
eec60b03 3321 err = -EOPNOTSUPP;
bba95fef
JB
3322 goto out_err;
3323 }
3324
eec60b03
JM
3325 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
3326 err = -EOPNOTSUPP;
0448b5fc 3327 goto out_err;
eec60b03
JM
3328 }
3329
bba95fef
JB
3330 while (1) {
3331 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
3332 dst, next_hop, &pinfo);
3333 if (err == -ENOENT)
2ec600d6 3334 break;
bba95fef 3335 if (err)
3b85875a 3336 goto out_err;
2ec600d6 3337
bba95fef
JB
3338 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
3339 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3340 netdev, dst, next_hop,
3341 &pinfo) < 0)
3342 goto out;
2ec600d6 3343
bba95fef 3344 path_idx++;
2ec600d6 3345 }
2ec600d6 3346
2ec600d6 3347
bba95fef
JB
3348 out:
3349 cb->args[1] = path_idx;
3350 err = skb->len;
bba95fef 3351 out_err:
67748893 3352 nl80211_finish_netdev_dump(dev);
bba95fef 3353 return err;
2ec600d6
LCC
3354}
3355
3356static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
3357{
4c476991 3358 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3359 int err;
4c476991 3360 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3361 struct mpath_info pinfo;
3362 struct sk_buff *msg;
3363 u8 *dst = NULL;
3364 u8 next_hop[ETH_ALEN];
3365
3366 memset(&pinfo, 0, sizeof(pinfo));
3367
3368 if (!info->attrs[NL80211_ATTR_MAC])
3369 return -EINVAL;
3370
3371 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3372
4c476991
JB
3373 if (!rdev->ops->get_mpath)
3374 return -EOPNOTSUPP;
2ec600d6 3375
4c476991
JB
3376 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3377 return -EOPNOTSUPP;
eec60b03 3378
79c97e97 3379 err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2ec600d6 3380 if (err)
4c476991 3381 return err;
2ec600d6 3382
fd2120ca 3383 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 3384 if (!msg)
4c476991 3385 return -ENOMEM;
2ec600d6
LCC
3386
3387 if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
4c476991
JB
3388 dev, dst, next_hop, &pinfo) < 0) {
3389 nlmsg_free(msg);
3390 return -ENOBUFS;
3391 }
3b85875a 3392
4c476991 3393 return genlmsg_reply(msg, info);
2ec600d6
LCC
3394}
3395
3396static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
3397{
4c476991
JB
3398 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3399 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3400 u8 *dst = NULL;
3401 u8 *next_hop = NULL;
3402
3403 if (!info->attrs[NL80211_ATTR_MAC])
3404 return -EINVAL;
3405
3406 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3407 return -EINVAL;
3408
3409 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3410 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3411
4c476991
JB
3412 if (!rdev->ops->change_mpath)
3413 return -EOPNOTSUPP;
35a8efe1 3414
4c476991
JB
3415 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3416 return -EOPNOTSUPP;
2ec600d6 3417
4c476991 3418 return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6 3419}
4c476991 3420
2ec600d6
LCC
3421static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
3422{
4c476991
JB
3423 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3424 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3425 u8 *dst = NULL;
3426 u8 *next_hop = NULL;
3427
3428 if (!info->attrs[NL80211_ATTR_MAC])
3429 return -EINVAL;
3430
3431 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
3432 return -EINVAL;
3433
3434 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3435 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
3436
4c476991
JB
3437 if (!rdev->ops->add_mpath)
3438 return -EOPNOTSUPP;
35a8efe1 3439
4c476991
JB
3440 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
3441 return -EOPNOTSUPP;
2ec600d6 3442
4c476991 3443 return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2ec600d6
LCC
3444}
3445
3446static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
3447{
4c476991
JB
3448 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3449 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
3450 u8 *dst = NULL;
3451
3452 if (info->attrs[NL80211_ATTR_MAC])
3453 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
3454
4c476991
JB
3455 if (!rdev->ops->del_mpath)
3456 return -EOPNOTSUPP;
3b85875a 3457
4c476991 3458 return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2ec600d6
LCC
3459}
3460
9f1ba906
JM
3461static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
3462{
4c476991
JB
3463 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3464 struct net_device *dev = info->user_ptr[1];
9f1ba906
JM
3465 struct bss_parameters params;
3466
3467 memset(&params, 0, sizeof(params));
3468 /* default to not changing parameters */
3469 params.use_cts_prot = -1;
3470 params.use_short_preamble = -1;
3471 params.use_short_slot_time = -1;
fd8aaaf3 3472 params.ap_isolate = -1;
50b12f59 3473 params.ht_opmode = -1;
9f1ba906
JM
3474
3475 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
3476 params.use_cts_prot =
3477 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
3478 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
3479 params.use_short_preamble =
3480 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
3481 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
3482 params.use_short_slot_time =
3483 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
3484 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3485 params.basic_rates =
3486 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3487 params.basic_rates_len =
3488 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3489 }
fd8aaaf3
FF
3490 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
3491 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
3492 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
3493 params.ht_opmode =
3494 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 3495
4c476991
JB
3496 if (!rdev->ops->change_bss)
3497 return -EOPNOTSUPP;
9f1ba906 3498
074ac8df 3499 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
3500 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3501 return -EOPNOTSUPP;
3b85875a 3502
4c476991 3503 return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
9f1ba906
JM
3504}
3505
b54452b0 3506static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
b2e1b302
LR
3507 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
3508 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
3509 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
3510 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
3511 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
3512 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
3513};
3514
3515static int parse_reg_rule(struct nlattr *tb[],
3516 struct ieee80211_reg_rule *reg_rule)
3517{
3518 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
3519 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
3520
3521 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
3522 return -EINVAL;
3523 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
3524 return -EINVAL;
3525 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
3526 return -EINVAL;
3527 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
3528 return -EINVAL;
3529 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
3530 return -EINVAL;
3531
3532 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
3533
3534 freq_range->start_freq_khz =
3535 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
3536 freq_range->end_freq_khz =
3537 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
3538 freq_range->max_bandwidth_khz =
3539 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
3540
3541 power_rule->max_eirp =
3542 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
3543
3544 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
3545 power_rule->max_antenna_gain =
3546 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
3547
3548 return 0;
3549}
3550
3551static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
3552{
3553 int r;
3554 char *data = NULL;
3555
80778f18
LR
3556 /*
3557 * You should only get this when cfg80211 hasn't yet initialized
3558 * completely when built-in to the kernel right between the time
3559 * window between nl80211_init() and regulatory_init(), if that is
3560 * even possible.
3561 */
3562 mutex_lock(&cfg80211_mutex);
3563 if (unlikely(!cfg80211_regdomain)) {
fe33eb39
LR
3564 mutex_unlock(&cfg80211_mutex);
3565 return -EINPROGRESS;
80778f18 3566 }
fe33eb39 3567 mutex_unlock(&cfg80211_mutex);
80778f18 3568
fe33eb39
LR
3569 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
3570 return -EINVAL;
b2e1b302
LR
3571
3572 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
3573
fe33eb39
LR
3574 r = regulatory_hint_user(data);
3575
b2e1b302
LR
3576 return r;
3577}
3578
24bdd9f4 3579static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 3580 struct genl_info *info)
93da9cc1 3581{
4c476991 3582 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 3583 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
3584 struct wireless_dev *wdev = dev->ieee80211_ptr;
3585 struct mesh_config cur_params;
3586 int err = 0;
93da9cc1 3587 void *hdr;
3588 struct nlattr *pinfoattr;
3589 struct sk_buff *msg;
3590
29cbe68c
JB
3591 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3592 return -EOPNOTSUPP;
3593
24bdd9f4 3594 if (!rdev->ops->get_mesh_config)
4c476991 3595 return -EOPNOTSUPP;
f3f92586 3596
29cbe68c
JB
3597 wdev_lock(wdev);
3598 /* If not connected, get default parameters */
3599 if (!wdev->mesh_id_len)
3600 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
3601 else
24bdd9f4 3602 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3603 &cur_params);
3604 wdev_unlock(wdev);
3605
93da9cc1 3606 if (err)
4c476991 3607 return err;
93da9cc1 3608
3609 /* Draw up a netlink message to send back */
fd2120ca 3610 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3611 if (!msg)
3612 return -ENOMEM;
93da9cc1 3613 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
24bdd9f4 3614 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 3615 if (!hdr)
efe1cf0c 3616 goto out;
24bdd9f4 3617 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 3618 if (!pinfoattr)
3619 goto nla_put_failure;
9360ffd1
DM
3620 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3621 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
3622 cur_params.dot11MeshRetryTimeout) ||
3623 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3624 cur_params.dot11MeshConfirmTimeout) ||
3625 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
3626 cur_params.dot11MeshHoldingTimeout) ||
3627 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
3628 cur_params.dot11MeshMaxPeerLinks) ||
3629 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
3630 cur_params.dot11MeshMaxRetries) ||
3631 nla_put_u8(msg, NL80211_MESHCONF_TTL,
3632 cur_params.dot11MeshTTL) ||
3633 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
3634 cur_params.element_ttl) ||
3635 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3636 cur_params.auto_open_plinks) ||
7eab0f64
JL
3637 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3638 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
3639 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3640 cur_params.dot11MeshHWMPmaxPREQretries) ||
3641 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
3642 cur_params.path_refresh_time) ||
3643 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3644 cur_params.min_discovery_timeout) ||
3645 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3646 cur_params.dot11MeshHWMPactivePathTimeout) ||
3647 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3648 cur_params.dot11MeshHWMPpreqMinInterval) ||
3649 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3650 cur_params.dot11MeshHWMPperrMinInterval) ||
3651 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3652 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
3653 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
3654 cur_params.dot11MeshHWMPRootMode) ||
3655 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3656 cur_params.dot11MeshHWMPRannInterval) ||
3657 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3658 cur_params.dot11MeshGateAnnouncementProtocol) ||
3659 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
3660 cur_params.dot11MeshForwarding) ||
3661 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
3662 cur_params.rssi_threshold) ||
3663 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
3664 cur_params.ht_opmode) ||
3665 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
3666 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
3667 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
3668 cur_params.dot11MeshHWMProotInterval) ||
3669 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3670 cur_params.dot11MeshHWMPconfirmationInterval))
9360ffd1 3671 goto nla_put_failure;
93da9cc1 3672 nla_nest_end(msg, pinfoattr);
3673 genlmsg_end(msg, hdr);
4c476991 3674 return genlmsg_reply(msg, info);
93da9cc1 3675
3b85875a 3676 nla_put_failure:
93da9cc1 3677 genlmsg_cancel(msg, hdr);
efe1cf0c 3678 out:
d080e275 3679 nlmsg_free(msg);
4c476991 3680 return -ENOBUFS;
93da9cc1 3681}
3682
b54452b0 3683static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
93da9cc1 3684 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
3685 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
3686 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
3687 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
3688 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
3689 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
45904f21 3690 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
93da9cc1 3691 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
d299a1f2 3692 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 },
93da9cc1 3693 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
3694 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
3695 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
3696 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
3697 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
dca7e943 3698 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3699 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
699403db 3700 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 },
0507e159 3701 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 },
16dd7267 3702 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 },
94f90656 3703 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 },
a4f606ea
CYY
3704 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 },
3705 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6
CYY
3706 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
3707 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 },
728b19e5 3708 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 },
93da9cc1 3709};
3710
c80d545d
JC
3711static const struct nla_policy
3712 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 3713 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
3714 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
3715 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 3716 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
581a8b0f 3717 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY,
a4f606ea 3718 .len = IEEE80211_MAX_DATA_LEN },
b130e5ce 3719 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
3720};
3721
24bdd9f4 3722static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
3723 struct mesh_config *cfg,
3724 u32 *mask_out)
93da9cc1 3725{
93da9cc1 3726 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 3727 u32 mask = 0;
93da9cc1 3728
bd90fdcc
JB
3729#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
3730do {\
3731 if (table[attr_num]) {\
3732 cfg->param = nla_fn(table[attr_num]); \
3733 mask |= (1 << (attr_num - 1)); \
3734 } \
3735} while (0);\
3736
3737
24bdd9f4 3738 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 3739 return -EINVAL;
3740 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
24bdd9f4 3741 info->attrs[NL80211_ATTR_MESH_CONFIG],
bd90fdcc 3742 nl80211_meshconf_params_policy))
93da9cc1 3743 return -EINVAL;
3744
93da9cc1 3745 /* This makes sure that there aren't more than 32 mesh config
3746 * parameters (otherwise our bitfield scheme would not work.) */
3747 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
3748
3749 /* Fill in the params struct */
93da9cc1 3750 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
a4f606ea
CYY
3751 mask, NL80211_MESHCONF_RETRY_TIMEOUT,
3752 nla_get_u16);
93da9cc1 3753 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
a4f606ea
CYY
3754 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT,
3755 nla_get_u16);
93da9cc1 3756 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
a4f606ea
CYY
3757 mask, NL80211_MESHCONF_HOLDING_TIMEOUT,
3758 nla_get_u16);
93da9cc1 3759 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
a4f606ea
CYY
3760 mask, NL80211_MESHCONF_MAX_PEER_LINKS,
3761 nla_get_u16);
93da9cc1 3762 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
a4f606ea
CYY
3763 mask, NL80211_MESHCONF_MAX_RETRIES,
3764 nla_get_u8);
93da9cc1 3765 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
a4f606ea 3766 mask, NL80211_MESHCONF_TTL, nla_get_u8);
45904f21 3767 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
a4f606ea
CYY
3768 mask, NL80211_MESHCONF_ELEMENT_TTL,
3769 nla_get_u8);
93da9cc1 3770 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
a4f606ea
CYY
3771 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
3772 nla_get_u8);
3773 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, mask,
3774 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
3775 nla_get_u32);
93da9cc1 3776 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
a4f606ea
CYY
3777 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
3778 nla_get_u8);
93da9cc1 3779 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
a4f606ea
CYY
3780 mask, NL80211_MESHCONF_PATH_REFRESH_TIME,
3781 nla_get_u32);
93da9cc1 3782 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
a4f606ea
CYY
3783 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
3784 nla_get_u16);
3785 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, mask,
3786 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
3787 nla_get_u32);
93da9cc1 3788 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
a4f606ea
CYY
3789 mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
3790 nla_get_u16);
dca7e943 3791 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval,
a4f606ea
CYY
3792 mask, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
3793 nla_get_u16);
0507e159 3794 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
3795 dot11MeshHWMPnetDiameterTraversalTime, mask,
3796 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
3797 nla_get_u16);
3798 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
3799 NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
3800 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
3801 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
3802 nla_get_u16);
16dd7267 3803 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
a4f606ea
CYY
3804 dot11MeshGateAnnouncementProtocol, mask,
3805 NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
3806 nla_get_u8);
94f90656 3807 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding,
a4f606ea
CYY
3808 mask, NL80211_MESHCONF_FORWARDING,
3809 nla_get_u8);
55335137 3810 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold,
a4f606ea
CYY
3811 mask, NL80211_MESHCONF_RSSI_THRESHOLD,
3812 nla_get_u32);
70c33eaa 3813 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, ht_opmode,
a4f606ea 3814 mask, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
3815 nla_get_u16);
3816 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout,
3817 mask,
3818 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
3819 nla_get_u32);
3820 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval,
3821 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
3822 nla_get_u16);
3823 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
3824 dot11MeshHWMPconfirmationInterval, mask,
3825 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
a4f606ea 3826 nla_get_u16);
bd90fdcc
JB
3827 if (mask_out)
3828 *mask_out = mask;
c80d545d 3829
bd90fdcc
JB
3830 return 0;
3831
3832#undef FILL_IN_MESH_PARAM_IF_SET
3833}
3834
c80d545d
JC
3835static int nl80211_parse_mesh_setup(struct genl_info *info,
3836 struct mesh_setup *setup)
3837{
3838 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
3839
3840 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
3841 return -EINVAL;
3842 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX,
3843 info->attrs[NL80211_ATTR_MESH_SETUP],
3844 nl80211_mesh_setup_params_policy))
3845 return -EINVAL;
3846
d299a1f2
JC
3847 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
3848 setup->sync_method =
3849 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
3850 IEEE80211_SYNC_METHOD_VENDOR :
3851 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
3852
c80d545d
JC
3853 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
3854 setup->path_sel_proto =
3855 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
3856 IEEE80211_PATH_PROTOCOL_VENDOR :
3857 IEEE80211_PATH_PROTOCOL_HWMP;
3858
3859 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
3860 setup->path_metric =
3861 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
3862 IEEE80211_PATH_METRIC_VENDOR :
3863 IEEE80211_PATH_METRIC_AIRTIME;
3864
581a8b0f
JC
3865
3866 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 3867 struct nlattr *ieattr =
581a8b0f 3868 tb[NL80211_MESH_SETUP_IE];
c80d545d
JC
3869 if (!is_valid_ie_attr(ieattr))
3870 return -EINVAL;
581a8b0f
JC
3871 setup->ie = nla_data(ieattr);
3872 setup->ie_len = nla_len(ieattr);
c80d545d 3873 }
b130e5ce
JC
3874 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
3875 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
c80d545d
JC
3876
3877 return 0;
3878}
3879
24bdd9f4 3880static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 3881 struct genl_info *info)
bd90fdcc
JB
3882{
3883 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3884 struct net_device *dev = info->user_ptr[1];
29cbe68c 3885 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
3886 struct mesh_config cfg;
3887 u32 mask;
3888 int err;
3889
29cbe68c
JB
3890 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
3891 return -EOPNOTSUPP;
3892
24bdd9f4 3893 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
3894 return -EOPNOTSUPP;
3895
24bdd9f4 3896 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
3897 if (err)
3898 return err;
3899
29cbe68c
JB
3900 wdev_lock(wdev);
3901 if (!wdev->mesh_id_len)
3902 err = -ENOLINK;
3903
3904 if (!err)
24bdd9f4 3905 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
29cbe68c
JB
3906 mask, &cfg);
3907
3908 wdev_unlock(wdev);
3909
3910 return err;
93da9cc1 3911}
3912
f130347c
LR
3913static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
3914{
3915 struct sk_buff *msg;
3916 void *hdr = NULL;
3917 struct nlattr *nl_reg_rules;
3918 unsigned int i;
3919 int err = -EINVAL;
3920
a1794390 3921 mutex_lock(&cfg80211_mutex);
f130347c
LR
3922
3923 if (!cfg80211_regdomain)
3924 goto out;
3925
fd2120ca 3926 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
f130347c
LR
3927 if (!msg) {
3928 err = -ENOBUFS;
3929 goto out;
3930 }
3931
3932 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
3933 NL80211_CMD_GET_REG);
3934 if (!hdr)
efe1cf0c 3935 goto put_failure;
f130347c 3936
9360ffd1
DM
3937 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
3938 cfg80211_regdomain->alpha2) ||
3939 (cfg80211_regdomain->dfs_region &&
3940 nla_put_u8(msg, NL80211_ATTR_DFS_REGION,
3941 cfg80211_regdomain->dfs_region)))
3942 goto nla_put_failure;
f130347c
LR
3943
3944 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
3945 if (!nl_reg_rules)
3946 goto nla_put_failure;
3947
3948 for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
3949 struct nlattr *nl_reg_rule;
3950 const struct ieee80211_reg_rule *reg_rule;
3951 const struct ieee80211_freq_range *freq_range;
3952 const struct ieee80211_power_rule *power_rule;
3953
3954 reg_rule = &cfg80211_regdomain->reg_rules[i];
3955 freq_range = &reg_rule->freq_range;
3956 power_rule = &reg_rule->power_rule;
3957
3958 nl_reg_rule = nla_nest_start(msg, i);
3959 if (!nl_reg_rule)
3960 goto nla_put_failure;
3961
9360ffd1
DM
3962 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
3963 reg_rule->flags) ||
3964 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
3965 freq_range->start_freq_khz) ||
3966 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
3967 freq_range->end_freq_khz) ||
3968 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
3969 freq_range->max_bandwidth_khz) ||
3970 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
3971 power_rule->max_antenna_gain) ||
3972 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
3973 power_rule->max_eirp))
3974 goto nla_put_failure;
f130347c
LR
3975
3976 nla_nest_end(msg, nl_reg_rule);
3977 }
3978
3979 nla_nest_end(msg, nl_reg_rules);
3980
3981 genlmsg_end(msg, hdr);
134e6375 3982 err = genlmsg_reply(msg, info);
f130347c
LR
3983 goto out;
3984
3985nla_put_failure:
3986 genlmsg_cancel(msg, hdr);
efe1cf0c 3987put_failure:
d080e275 3988 nlmsg_free(msg);
f130347c
LR
3989 err = -EMSGSIZE;
3990out:
a1794390 3991 mutex_unlock(&cfg80211_mutex);
f130347c
LR
3992 return err;
3993}
3994
b2e1b302
LR
3995static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
3996{
3997 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
3998 struct nlattr *nl_reg_rule;
3999 char *alpha2 = NULL;
4000 int rem_reg_rules = 0, r = 0;
4001 u32 num_rules = 0, rule_idx = 0, size_of_regd;
8b60b078 4002 u8 dfs_region = 0;
b2e1b302
LR
4003 struct ieee80211_regdomain *rd = NULL;
4004
4005 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
4006 return -EINVAL;
4007
4008 if (!info->attrs[NL80211_ATTR_REG_RULES])
4009 return -EINVAL;
4010
4011 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
4012
8b60b078
LR
4013 if (info->attrs[NL80211_ATTR_DFS_REGION])
4014 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
4015
b2e1b302
LR
4016 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
4017 rem_reg_rules) {
4018 num_rules++;
4019 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 4020 return -EINVAL;
b2e1b302
LR
4021 }
4022
61405e97
LR
4023 mutex_lock(&cfg80211_mutex);
4024
d0e18f83
LR
4025 if (!reg_is_valid_request(alpha2)) {
4026 r = -EINVAL;
4027 goto bad_reg;
4028 }
b2e1b302
LR
4029
4030 size_of_regd = sizeof(struct ieee80211_regdomain) +
4031 (num_rules * sizeof(struct ieee80211_reg_rule));
4032
4033 rd = kzalloc(size_of_regd, GFP_KERNEL);
d0e18f83
LR
4034 if (!rd) {
4035 r = -ENOMEM;
4036 goto bad_reg;
4037 }
b2e1b302
LR
4038
4039 rd->n_reg_rules = num_rules;
4040 rd->alpha2[0] = alpha2[0];
4041 rd->alpha2[1] = alpha2[1];
4042
8b60b078
LR
4043 /*
4044 * Disable DFS master mode if the DFS region was
4045 * not supported or known on this kernel.
4046 */
4047 if (reg_supported_dfs_region(dfs_region))
4048 rd->dfs_region = dfs_region;
4049
b2e1b302
LR
4050 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
4051 rem_reg_rules) {
4052 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
4053 nla_data(nl_reg_rule), nla_len(nl_reg_rule),
4054 reg_rule_policy);
4055 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
4056 if (r)
4057 goto bad_reg;
4058
4059 rule_idx++;
4060
d0e18f83
LR
4061 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
4062 r = -EINVAL;
b2e1b302 4063 goto bad_reg;
d0e18f83 4064 }
b2e1b302
LR
4065 }
4066
4067 BUG_ON(rule_idx != num_rules);
4068
b2e1b302 4069 r = set_regdom(rd);
61405e97 4070
a1794390 4071 mutex_unlock(&cfg80211_mutex);
d0e18f83 4072
b2e1b302
LR
4073 return r;
4074
d2372b31 4075 bad_reg:
61405e97 4076 mutex_unlock(&cfg80211_mutex);
b2e1b302 4077 kfree(rd);
d0e18f83 4078 return r;
b2e1b302
LR
4079}
4080
83f5e2cf
JB
4081static int validate_scan_freqs(struct nlattr *freqs)
4082{
4083 struct nlattr *attr1, *attr2;
4084 int n_channels = 0, tmp1, tmp2;
4085
4086 nla_for_each_nested(attr1, freqs, tmp1) {
4087 n_channels++;
4088 /*
4089 * Some hardware has a limited channel list for
4090 * scanning, and it is pretty much nonsensical
4091 * to scan for a channel twice, so disallow that
4092 * and don't require drivers to check that the
4093 * channel list they get isn't longer than what
4094 * they can scan, as long as they can scan all
4095 * the channels they registered at once.
4096 */
4097 nla_for_each_nested(attr2, freqs, tmp2)
4098 if (attr1 != attr2 &&
4099 nla_get_u32(attr1) == nla_get_u32(attr2))
4100 return 0;
4101 }
4102
4103 return n_channels;
4104}
4105
2a519311
JB
4106static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
4107{
4c476991
JB
4108 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4109 struct net_device *dev = info->user_ptr[1];
2a519311 4110 struct cfg80211_scan_request *request;
2a519311
JB
4111 struct nlattr *attr;
4112 struct wiphy *wiphy;
83f5e2cf 4113 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 4114 size_t ie_len;
2a519311 4115
f4a11bb0
JB
4116 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4117 return -EINVAL;
4118
79c97e97 4119 wiphy = &rdev->wiphy;
2a519311 4120
4c476991
JB
4121 if (!rdev->ops->scan)
4122 return -EOPNOTSUPP;
2a519311 4123
4c476991
JB
4124 if (rdev->scan_req)
4125 return -EBUSY;
2a519311
JB
4126
4127 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
83f5e2cf
JB
4128 n_channels = validate_scan_freqs(
4129 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4c476991
JB
4130 if (!n_channels)
4131 return -EINVAL;
2a519311 4132 } else {
34850ab2 4133 enum ieee80211_band band;
83f5e2cf
JB
4134 n_channels = 0;
4135
2a519311
JB
4136 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4137 if (wiphy->bands[band])
4138 n_channels += wiphy->bands[band]->n_channels;
4139 }
4140
4141 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4142 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
4143 n_ssids++;
4144
4c476991
JB
4145 if (n_ssids > wiphy->max_scan_ssids)
4146 return -EINVAL;
2a519311 4147
70692ad2
JM
4148 if (info->attrs[NL80211_ATTR_IE])
4149 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4150 else
4151 ie_len = 0;
4152
4c476991
JB
4153 if (ie_len > wiphy->max_scan_ie_len)
4154 return -EINVAL;
18a83659 4155
2a519311 4156 request = kzalloc(sizeof(*request)
a2cd43c5
LC
4157 + sizeof(*request->ssids) * n_ssids
4158 + sizeof(*request->channels) * n_channels
70692ad2 4159 + ie_len, GFP_KERNEL);
4c476991
JB
4160 if (!request)
4161 return -ENOMEM;
2a519311 4162
2a519311 4163 if (n_ssids)
5ba63533 4164 request->ssids = (void *)&request->channels[n_channels];
2a519311 4165 request->n_ssids = n_ssids;
70692ad2
JM
4166 if (ie_len) {
4167 if (request->ssids)
4168 request->ie = (void *)(request->ssids + n_ssids);
4169 else
4170 request->ie = (void *)(request->channels + n_channels);
4171 }
2a519311 4172
584991dc 4173 i = 0;
2a519311
JB
4174 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4175 /* user specified, bail out if channel not found */
2a519311 4176 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
584991dc
JB
4177 struct ieee80211_channel *chan;
4178
4179 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4180
4181 if (!chan) {
2a519311
JB
4182 err = -EINVAL;
4183 goto out_free;
4184 }
584991dc
JB
4185
4186 /* ignore disabled channels */
4187 if (chan->flags & IEEE80211_CHAN_DISABLED)
4188 continue;
4189
4190 request->channels[i] = chan;
2a519311
JB
4191 i++;
4192 }
4193 } else {
34850ab2
JB
4194 enum ieee80211_band band;
4195
2a519311 4196 /* all channels */
2a519311
JB
4197 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4198 int j;
4199 if (!wiphy->bands[band])
4200 continue;
4201 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
4202 struct ieee80211_channel *chan;
4203
4204 chan = &wiphy->bands[band]->channels[j];
4205
4206 if (chan->flags & IEEE80211_CHAN_DISABLED)
4207 continue;
4208
4209 request->channels[i] = chan;
2a519311
JB
4210 i++;
4211 }
4212 }
4213 }
4214
584991dc
JB
4215 if (!i) {
4216 err = -EINVAL;
4217 goto out_free;
4218 }
4219
4220 request->n_channels = i;
4221
2a519311
JB
4222 i = 0;
4223 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4224 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 4225 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
4226 err = -EINVAL;
4227 goto out_free;
4228 }
57a27e1d 4229 request->ssids[i].ssid_len = nla_len(attr);
2a519311 4230 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
4231 i++;
4232 }
4233 }
4234
70692ad2
JM
4235 if (info->attrs[NL80211_ATTR_IE]) {
4236 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
4237 memcpy((void *)request->ie,
4238 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
4239 request->ie_len);
4240 }
4241
34850ab2 4242 for (i = 0; i < IEEE80211_NUM_BANDS; i++)
a401d2bb
JB
4243 if (wiphy->bands[i])
4244 request->rates[i] =
4245 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
4246
4247 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
4248 nla_for_each_nested(attr,
4249 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
4250 tmp) {
4251 enum ieee80211_band band = nla_type(attr);
4252
84404623 4253 if (band < 0 || band >= IEEE80211_NUM_BANDS) {
34850ab2
JB
4254 err = -EINVAL;
4255 goto out_free;
4256 }
4257 err = ieee80211_get_ratemask(wiphy->bands[band],
4258 nla_data(attr),
4259 nla_len(attr),
4260 &request->rates[band]);
4261 if (err)
4262 goto out_free;
4263 }
4264 }
4265
e9f935e3
RM
4266 request->no_cck =
4267 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
4268
463d0183 4269 request->dev = dev;
79c97e97 4270 request->wiphy = &rdev->wiphy;
2a519311 4271
79c97e97
JB
4272 rdev->scan_req = request;
4273 err = rdev->ops->scan(&rdev->wiphy, dev, request);
2a519311 4274
463d0183 4275 if (!err) {
79c97e97 4276 nl80211_send_scan_start(rdev, dev);
463d0183 4277 dev_hold(dev);
4c476991 4278 } else {
2a519311 4279 out_free:
79c97e97 4280 rdev->scan_req = NULL;
2a519311
JB
4281 kfree(request);
4282 }
3b85875a 4283
2a519311
JB
4284 return err;
4285}
4286
807f8a8c
LC
4287static int nl80211_start_sched_scan(struct sk_buff *skb,
4288 struct genl_info *info)
4289{
4290 struct cfg80211_sched_scan_request *request;
4291 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4292 struct net_device *dev = info->user_ptr[1];
807f8a8c
LC
4293 struct nlattr *attr;
4294 struct wiphy *wiphy;
a1f1c21c 4295 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i;
bbe6ad6d 4296 u32 interval;
807f8a8c
LC
4297 enum ieee80211_band band;
4298 size_t ie_len;
a1f1c21c 4299 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
807f8a8c
LC
4300
4301 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4302 !rdev->ops->sched_scan_start)
4303 return -EOPNOTSUPP;
4304
4305 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4306 return -EINVAL;
4307
bbe6ad6d
LC
4308 if (!info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
4309 return -EINVAL;
4310
4311 interval = nla_get_u32(info->attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
4312 if (interval == 0)
4313 return -EINVAL;
4314
807f8a8c
LC
4315 wiphy = &rdev->wiphy;
4316
4317 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4318 n_channels = validate_scan_freqs(
4319 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
4320 if (!n_channels)
4321 return -EINVAL;
4322 } else {
4323 n_channels = 0;
4324
4325 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
4326 if (wiphy->bands[band])
4327 n_channels += wiphy->bands[band]->n_channels;
4328 }
4329
4330 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
4331 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4332 tmp)
4333 n_ssids++;
4334
93b6aa69 4335 if (n_ssids > wiphy->max_sched_scan_ssids)
807f8a8c
LC
4336 return -EINVAL;
4337
a1f1c21c
LC
4338 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH])
4339 nla_for_each_nested(attr,
4340 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4341 tmp)
4342 n_match_sets++;
4343
4344 if (n_match_sets > wiphy->max_match_sets)
4345 return -EINVAL;
4346
807f8a8c
LC
4347 if (info->attrs[NL80211_ATTR_IE])
4348 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4349 else
4350 ie_len = 0;
4351
5a865bad 4352 if (ie_len > wiphy->max_sched_scan_ie_len)
807f8a8c
LC
4353 return -EINVAL;
4354
c10841ca
LC
4355 mutex_lock(&rdev->sched_scan_mtx);
4356
4357 if (rdev->sched_scan_req) {
4358 err = -EINPROGRESS;
4359 goto out;
4360 }
4361
807f8a8c 4362 request = kzalloc(sizeof(*request)
a2cd43c5 4363 + sizeof(*request->ssids) * n_ssids
a1f1c21c 4364 + sizeof(*request->match_sets) * n_match_sets
a2cd43c5 4365 + sizeof(*request->channels) * n_channels
807f8a8c 4366 + ie_len, GFP_KERNEL);
c10841ca
LC
4367 if (!request) {
4368 err = -ENOMEM;
4369 goto out;
4370 }
807f8a8c
LC
4371
4372 if (n_ssids)
4373 request->ssids = (void *)&request->channels[n_channels];
4374 request->n_ssids = n_ssids;
4375 if (ie_len) {
4376 if (request->ssids)
4377 request->ie = (void *)(request->ssids + n_ssids);
4378 else
4379 request->ie = (void *)(request->channels + n_channels);
4380 }
4381
a1f1c21c
LC
4382 if (n_match_sets) {
4383 if (request->ie)
4384 request->match_sets = (void *)(request->ie + ie_len);
4385 else if (request->ssids)
4386 request->match_sets =
4387 (void *)(request->ssids + n_ssids);
4388 else
4389 request->match_sets =
4390 (void *)(request->channels + n_channels);
4391 }
4392 request->n_match_sets = n_match_sets;
4393
807f8a8c
LC
4394 i = 0;
4395 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
4396 /* user specified, bail out if channel not found */
4397 nla_for_each_nested(attr,
4398 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES],
4399 tmp) {
4400 struct ieee80211_channel *chan;
4401
4402 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
4403
4404 if (!chan) {
4405 err = -EINVAL;
4406 goto out_free;
4407 }
4408
4409 /* ignore disabled channels */
4410 if (chan->flags & IEEE80211_CHAN_DISABLED)
4411 continue;
4412
4413 request->channels[i] = chan;
4414 i++;
4415 }
4416 } else {
4417 /* all channels */
4418 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
4419 int j;
4420 if (!wiphy->bands[band])
4421 continue;
4422 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
4423 struct ieee80211_channel *chan;
4424
4425 chan = &wiphy->bands[band]->channels[j];
4426
4427 if (chan->flags & IEEE80211_CHAN_DISABLED)
4428 continue;
4429
4430 request->channels[i] = chan;
4431 i++;
4432 }
4433 }
4434 }
4435
4436 if (!i) {
4437 err = -EINVAL;
4438 goto out_free;
4439 }
4440
4441 request->n_channels = i;
4442
4443 i = 0;
4444 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
4445 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS],
4446 tmp) {
57a27e1d 4447 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
4448 err = -EINVAL;
4449 goto out_free;
4450 }
57a27e1d 4451 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
4452 memcpy(request->ssids[i].ssid, nla_data(attr),
4453 nla_len(attr));
807f8a8c
LC
4454 i++;
4455 }
4456 }
4457
a1f1c21c
LC
4458 i = 0;
4459 if (info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
4460 nla_for_each_nested(attr,
4461 info->attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
4462 tmp) {
88e920b4 4463 struct nlattr *ssid, *rssi;
a1f1c21c
LC
4464
4465 nla_parse(tb, NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
4466 nla_data(attr), nla_len(attr),
4467 nl80211_match_policy);
4a4ab0d7 4468 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
a1f1c21c
LC
4469 if (ssid) {
4470 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) {
4471 err = -EINVAL;
4472 goto out_free;
4473 }
4474 memcpy(request->match_sets[i].ssid.ssid,
4475 nla_data(ssid), nla_len(ssid));
4476 request->match_sets[i].ssid.ssid_len =
4477 nla_len(ssid);
4478 }
88e920b4
TP
4479 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
4480 if (rssi)
4481 request->rssi_thold = nla_get_u32(rssi);
4482 else
4483 request->rssi_thold =
4484 NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
4485 i++;
4486 }
4487 }
4488
807f8a8c
LC
4489 if (info->attrs[NL80211_ATTR_IE]) {
4490 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4491 memcpy((void *)request->ie,
4492 nla_data(info->attrs[NL80211_ATTR_IE]),
4493 request->ie_len);
4494 }
4495
4496 request->dev = dev;
4497 request->wiphy = &rdev->wiphy;
bbe6ad6d 4498 request->interval = interval;
807f8a8c
LC
4499
4500 err = rdev->ops->sched_scan_start(&rdev->wiphy, dev, request);
4501 if (!err) {
4502 rdev->sched_scan_req = request;
4503 nl80211_send_sched_scan(rdev, dev,
4504 NL80211_CMD_START_SCHED_SCAN);
4505 goto out;
4506 }
4507
4508out_free:
4509 kfree(request);
4510out:
c10841ca 4511 mutex_unlock(&rdev->sched_scan_mtx);
807f8a8c
LC
4512 return err;
4513}
4514
4515static int nl80211_stop_sched_scan(struct sk_buff *skb,
4516 struct genl_info *info)
4517{
4518 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c10841ca 4519 int err;
807f8a8c
LC
4520
4521 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) ||
4522 !rdev->ops->sched_scan_stop)
4523 return -EOPNOTSUPP;
4524
c10841ca
LC
4525 mutex_lock(&rdev->sched_scan_mtx);
4526 err = __cfg80211_stop_sched_scan(rdev, false);
4527 mutex_unlock(&rdev->sched_scan_mtx);
4528
4529 return err;
807f8a8c
LC
4530}
4531
9720bb3a
JB
4532static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
4533 u32 seq, int flags,
2a519311 4534 struct cfg80211_registered_device *rdev,
48ab905d
JB
4535 struct wireless_dev *wdev,
4536 struct cfg80211_internal_bss *intbss)
2a519311 4537{
48ab905d 4538 struct cfg80211_bss *res = &intbss->pub;
2a519311
JB
4539 void *hdr;
4540 struct nlattr *bss;
48ab905d
JB
4541
4542 ASSERT_WDEV_LOCK(wdev);
2a519311 4543
9720bb3a 4544 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).pid, seq, flags,
2a519311
JB
4545 NL80211_CMD_NEW_SCAN_RESULTS);
4546 if (!hdr)
4547 return -1;
4548
9720bb3a
JB
4549 genl_dump_check_consistent(cb, hdr, &nl80211_fam);
4550
9360ffd1
DM
4551 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation) ||
4552 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
4553 goto nla_put_failure;
2a519311
JB
4554
4555 bss = nla_nest_start(msg, NL80211_ATTR_BSS);
4556 if (!bss)
4557 goto nla_put_failure;
9360ffd1
DM
4558 if ((!is_zero_ether_addr(res->bssid) &&
4559 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)) ||
4560 (res->information_elements && res->len_information_elements &&
4561 nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
4562 res->len_information_elements,
4563 res->information_elements)) ||
4564 (res->beacon_ies && res->len_beacon_ies &&
4565 res->beacon_ies != res->information_elements &&
4566 nla_put(msg, NL80211_BSS_BEACON_IES,
4567 res->len_beacon_ies, res->beacon_ies)))
4568 goto nla_put_failure;
4569 if (res->tsf &&
4570 nla_put_u64(msg, NL80211_BSS_TSF, res->tsf))
4571 goto nla_put_failure;
4572 if (res->beacon_interval &&
4573 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
4574 goto nla_put_failure;
4575 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
4576 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
4577 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
4578 jiffies_to_msecs(jiffies - intbss->ts)))
4579 goto nla_put_failure;
2a519311 4580
77965c97 4581 switch (rdev->wiphy.signal_type) {
2a519311 4582 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
4583 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
4584 goto nla_put_failure;
2a519311
JB
4585 break;
4586 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
4587 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
4588 goto nla_put_failure;
2a519311
JB
4589 break;
4590 default:
4591 break;
4592 }
4593
48ab905d 4594 switch (wdev->iftype) {
074ac8df 4595 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 4596 case NL80211_IFTYPE_STATION:
9360ffd1
DM
4597 if (intbss == wdev->current_bss &&
4598 nla_put_u32(msg, NL80211_BSS_STATUS,
4599 NL80211_BSS_STATUS_ASSOCIATED))
4600 goto nla_put_failure;
48ab905d
JB
4601 break;
4602 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
4603 if (intbss == wdev->current_bss &&
4604 nla_put_u32(msg, NL80211_BSS_STATUS,
4605 NL80211_BSS_STATUS_IBSS_JOINED))
4606 goto nla_put_failure;
48ab905d
JB
4607 break;
4608 default:
4609 break;
4610 }
4611
2a519311
JB
4612 nla_nest_end(msg, bss);
4613
4614 return genlmsg_end(msg, hdr);
4615
4616 nla_put_failure:
4617 genlmsg_cancel(msg, hdr);
4618 return -EMSGSIZE;
4619}
4620
4621static int nl80211_dump_scan(struct sk_buff *skb,
4622 struct netlink_callback *cb)
4623{
48ab905d
JB
4624 struct cfg80211_registered_device *rdev;
4625 struct net_device *dev;
2a519311 4626 struct cfg80211_internal_bss *scan;
48ab905d 4627 struct wireless_dev *wdev;
2a519311
JB
4628 int start = cb->args[1], idx = 0;
4629 int err;
4630
67748893
JB
4631 err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
4632 if (err)
4633 return err;
2a519311 4634
48ab905d 4635 wdev = dev->ieee80211_ptr;
2a519311 4636
48ab905d
JB
4637 wdev_lock(wdev);
4638 spin_lock_bh(&rdev->bss_lock);
4639 cfg80211_bss_expire(rdev);
4640
9720bb3a
JB
4641 cb->seq = rdev->bss_generation;
4642
48ab905d 4643 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
4644 if (++idx <= start)
4645 continue;
9720bb3a 4646 if (nl80211_send_bss(skb, cb,
2a519311 4647 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 4648 rdev, wdev, scan) < 0) {
2a519311 4649 idx--;
67748893 4650 break;
2a519311
JB
4651 }
4652 }
4653
48ab905d
JB
4654 spin_unlock_bh(&rdev->bss_lock);
4655 wdev_unlock(wdev);
2a519311
JB
4656
4657 cb->args[1] = idx;
67748893 4658 nl80211_finish_netdev_dump(rdev);
2a519311 4659
67748893 4660 return skb->len;
2a519311
JB
4661}
4662
61fa713c
HS
4663static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
4664 int flags, struct net_device *dev,
4665 struct survey_info *survey)
4666{
4667 void *hdr;
4668 struct nlattr *infoattr;
4669
61fa713c
HS
4670 hdr = nl80211hdr_put(msg, pid, seq, flags,
4671 NL80211_CMD_NEW_SURVEY_RESULTS);
4672 if (!hdr)
4673 return -ENOMEM;
4674
9360ffd1
DM
4675 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
4676 goto nla_put_failure;
61fa713c
HS
4677
4678 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
4679 if (!infoattr)
4680 goto nla_put_failure;
4681
9360ffd1
DM
4682 if (nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
4683 survey->channel->center_freq))
4684 goto nla_put_failure;
4685
4686 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
4687 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
4688 goto nla_put_failure;
4689 if ((survey->filled & SURVEY_INFO_IN_USE) &&
4690 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
4691 goto nla_put_failure;
4692 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME) &&
4693 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
4694 survey->channel_time))
4695 goto nla_put_failure;
4696 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY) &&
4697 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
4698 survey->channel_time_busy))
4699 goto nla_put_failure;
4700 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY) &&
4701 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
4702 survey->channel_time_ext_busy))
4703 goto nla_put_failure;
4704 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_RX) &&
4705 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
4706 survey->channel_time_rx))
4707 goto nla_put_failure;
4708 if ((survey->filled & SURVEY_INFO_CHANNEL_TIME_TX) &&
4709 nla_put_u64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
4710 survey->channel_time_tx))
4711 goto nla_put_failure;
61fa713c
HS
4712
4713 nla_nest_end(msg, infoattr);
4714
4715 return genlmsg_end(msg, hdr);
4716
4717 nla_put_failure:
4718 genlmsg_cancel(msg, hdr);
4719 return -EMSGSIZE;
4720}
4721
4722static int nl80211_dump_survey(struct sk_buff *skb,
4723 struct netlink_callback *cb)
4724{
4725 struct survey_info survey;
4726 struct cfg80211_registered_device *dev;
4727 struct net_device *netdev;
61fa713c
HS
4728 int survey_idx = cb->args[1];
4729 int res;
4730
67748893
JB
4731 res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
4732 if (res)
4733 return res;
61fa713c
HS
4734
4735 if (!dev->ops->dump_survey) {
4736 res = -EOPNOTSUPP;
4737 goto out_err;
4738 }
4739
4740 while (1) {
180cdc79
LR
4741 struct ieee80211_channel *chan;
4742
61fa713c
HS
4743 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
4744 &survey);
4745 if (res == -ENOENT)
4746 break;
4747 if (res)
4748 goto out_err;
4749
180cdc79
LR
4750 /* Survey without a channel doesn't make sense */
4751 if (!survey.channel) {
4752 res = -EINVAL;
4753 goto out;
4754 }
4755
4756 chan = ieee80211_get_channel(&dev->wiphy,
4757 survey.channel->center_freq);
4758 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) {
4759 survey_idx++;
4760 continue;
4761 }
4762
61fa713c
HS
4763 if (nl80211_send_survey(skb,
4764 NETLINK_CB(cb->skb).pid,
4765 cb->nlh->nlmsg_seq, NLM_F_MULTI,
4766 netdev,
4767 &survey) < 0)
4768 goto out;
4769 survey_idx++;
4770 }
4771
4772 out:
4773 cb->args[1] = survey_idx;
4774 res = skb->len;
4775 out_err:
67748893 4776 nl80211_finish_netdev_dump(dev);
61fa713c
HS
4777 return res;
4778}
4779
255e737e
JM
4780static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
4781{
b23aa676
SO
4782 return auth_type <= NL80211_AUTHTYPE_MAX;
4783}
4784
4785static bool nl80211_valid_wpa_versions(u32 wpa_versions)
4786{
4787 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
4788 NL80211_WPA_VERSION_2));
4789}
4790
636a5d36
JM
4791static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
4792{
4c476991
JB
4793 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4794 struct net_device *dev = info->user_ptr[1];
19957bb3
JB
4795 struct ieee80211_channel *chan;
4796 const u8 *bssid, *ssid, *ie = NULL;
4797 int err, ssid_len, ie_len = 0;
4798 enum nl80211_auth_type auth_type;
fffd0934 4799 struct key_parse key;
d5cdfacb 4800 bool local_state_change;
636a5d36 4801
f4a11bb0
JB
4802 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4803 return -EINVAL;
4804
4805 if (!info->attrs[NL80211_ATTR_MAC])
4806 return -EINVAL;
4807
1778092e
JM
4808 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
4809 return -EINVAL;
4810
19957bb3
JB
4811 if (!info->attrs[NL80211_ATTR_SSID])
4812 return -EINVAL;
4813
4814 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
4815 return -EINVAL;
4816
fffd0934
JB
4817 err = nl80211_parse_key(info, &key);
4818 if (err)
4819 return err;
4820
4821 if (key.idx >= 0) {
e31b8213
JB
4822 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
4823 return -EINVAL;
fffd0934
JB
4824 if (!key.p.key || !key.p.key_len)
4825 return -EINVAL;
4826 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
4827 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
4828 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
4829 key.p.key_len != WLAN_KEY_LEN_WEP104))
4830 return -EINVAL;
4831 if (key.idx > 4)
4832 return -EINVAL;
4833 } else {
4834 key.p.key_len = 0;
4835 key.p.key = NULL;
4836 }
4837
afea0b7a
JB
4838 if (key.idx >= 0) {
4839 int i;
4840 bool ok = false;
4841 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
4842 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
4843 ok = true;
4844 break;
4845 }
4846 }
4c476991
JB
4847 if (!ok)
4848 return -EINVAL;
afea0b7a
JB
4849 }
4850
4c476991
JB
4851 if (!rdev->ops->auth)
4852 return -EOPNOTSUPP;
636a5d36 4853
074ac8df 4854 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4855 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4856 return -EOPNOTSUPP;
eec60b03 4857
19957bb3 4858 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
79c97e97 4859 chan = ieee80211_get_channel(&rdev->wiphy,
19957bb3 4860 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
4861 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
4862 return -EINVAL;
636a5d36 4863
19957bb3
JB
4864 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4865 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
4866
4867 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
4868 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4869 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
4870 }
4871
19957bb3 4872 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4c476991
JB
4873 if (!nl80211_valid_auth_type(auth_type))
4874 return -EINVAL;
636a5d36 4875
d5cdfacb
JM
4876 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
4877
95de817b
JB
4878 /*
4879 * Since we no longer track auth state, ignore
4880 * requests to only change local state.
4881 */
4882 if (local_state_change)
4883 return 0;
4884
4c476991
JB
4885 return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
4886 ssid, ssid_len, ie, ie_len,
95de817b 4887 key.p.key, key.p.key_len, key.idx);
636a5d36
JM
4888}
4889
c0692b8f
JB
4890static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
4891 struct genl_info *info,
3dc27d25
JB
4892 struct cfg80211_crypto_settings *settings,
4893 int cipher_limit)
b23aa676 4894{
c0b2bbd8
JB
4895 memset(settings, 0, sizeof(*settings));
4896
b23aa676
SO
4897 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
4898
c0692b8f
JB
4899 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
4900 u16 proto;
4901 proto = nla_get_u16(
4902 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
4903 settings->control_port_ethertype = cpu_to_be16(proto);
4904 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
4905 proto != ETH_P_PAE)
4906 return -EINVAL;
4907 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
4908 settings->control_port_no_encrypt = true;
4909 } else
4910 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
4911
b23aa676
SO
4912 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
4913 void *data;
4914 int len, i;
4915
4916 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4917 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
4918 settings->n_ciphers_pairwise = len / sizeof(u32);
4919
4920 if (len % sizeof(u32))
4921 return -EINVAL;
4922
3dc27d25 4923 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
4924 return -EINVAL;
4925
4926 memcpy(settings->ciphers_pairwise, data, len);
4927
4928 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
4929 if (!cfg80211_supported_cipher_suite(
4930 &rdev->wiphy,
b23aa676
SO
4931 settings->ciphers_pairwise[i]))
4932 return -EINVAL;
4933 }
4934
4935 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
4936 settings->cipher_group =
4937 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
4938 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
4939 settings->cipher_group))
b23aa676
SO
4940 return -EINVAL;
4941 }
4942
4943 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
4944 settings->wpa_versions =
4945 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
4946 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
4947 return -EINVAL;
4948 }
4949
4950 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
4951 void *data;
6d30240e 4952 int len;
b23aa676
SO
4953
4954 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
4955 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
4956 settings->n_akm_suites = len / sizeof(u32);
4957
4958 if (len % sizeof(u32))
4959 return -EINVAL;
4960
1b9ca027
JM
4961 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
4962 return -EINVAL;
4963
b23aa676 4964 memcpy(settings->akm_suites, data, len);
b23aa676
SO
4965 }
4966
4967 return 0;
4968}
4969
636a5d36
JM
4970static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
4971{
4c476991
JB
4972 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4973 struct net_device *dev = info->user_ptr[1];
19957bb3 4974 struct cfg80211_crypto_settings crypto;
f444de05 4975 struct ieee80211_channel *chan;
3e5d7649 4976 const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
19957bb3
JB
4977 int err, ssid_len, ie_len = 0;
4978 bool use_mfp = false;
7e7c8926
BG
4979 u32 flags = 0;
4980 struct ieee80211_ht_cap *ht_capa = NULL;
4981 struct ieee80211_ht_cap *ht_capa_mask = NULL;
636a5d36 4982
f4a11bb0
JB
4983 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4984 return -EINVAL;
4985
4986 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
4987 !info->attrs[NL80211_ATTR_SSID] ||
4988 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
4989 return -EINVAL;
4990
4c476991
JB
4991 if (!rdev->ops->assoc)
4992 return -EOPNOTSUPP;
636a5d36 4993
074ac8df 4994 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
4995 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4996 return -EOPNOTSUPP;
eec60b03 4997
19957bb3 4998 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 4999
19957bb3
JB
5000 chan = ieee80211_get_channel(&rdev->wiphy,
5001 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4c476991
JB
5002 if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
5003 return -EINVAL;
636a5d36 5004
19957bb3
JB
5005 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5006 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
5007
5008 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5009 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5010 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5011 }
5012
dc6382ce 5013 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 5014 enum nl80211_mfp mfp =
dc6382ce 5015 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 5016 if (mfp == NL80211_MFP_REQUIRED)
19957bb3 5017 use_mfp = true;
4c476991
JB
5018 else if (mfp != NL80211_MFP_NO)
5019 return -EINVAL;
dc6382ce
JM
5020 }
5021
3e5d7649
JB
5022 if (info->attrs[NL80211_ATTR_PREV_BSSID])
5023 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
5024
7e7c8926
BG
5025 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5026 flags |= ASSOC_REQ_DISABLE_HT;
5027
5028 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5029 ht_capa_mask =
5030 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]);
5031
5032 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5033 if (!ht_capa_mask)
5034 return -EINVAL;
5035 ht_capa = nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5036 }
5037
c0692b8f 5038 err = nl80211_crypto_settings(rdev, info, &crypto, 1);
b23aa676 5039 if (!err)
3e5d7649
JB
5040 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
5041 ssid, ssid_len, ie, ie_len, use_mfp,
7e7c8926
BG
5042 &crypto, flags, ht_capa,
5043 ht_capa_mask);
636a5d36 5044
636a5d36
JM
5045 return err;
5046}
5047
5048static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
5049{
4c476991
JB
5050 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5051 struct net_device *dev = info->user_ptr[1];
19957bb3 5052 const u8 *ie = NULL, *bssid;
4c476991 5053 int ie_len = 0;
19957bb3 5054 u16 reason_code;
d5cdfacb 5055 bool local_state_change;
636a5d36 5056
f4a11bb0
JB
5057 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5058 return -EINVAL;
5059
5060 if (!info->attrs[NL80211_ATTR_MAC])
5061 return -EINVAL;
5062
5063 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5064 return -EINVAL;
5065
4c476991
JB
5066 if (!rdev->ops->deauth)
5067 return -EOPNOTSUPP;
636a5d36 5068
074ac8df 5069 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5070 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5071 return -EOPNOTSUPP;
eec60b03 5072
19957bb3 5073 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5074
19957bb3
JB
5075 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5076 if (reason_code == 0) {
f4a11bb0 5077 /* Reason Code 0 is reserved */
4c476991 5078 return -EINVAL;
255e737e 5079 }
636a5d36
JM
5080
5081 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5082 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5083 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5084 }
5085
d5cdfacb
JM
5086 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5087
4c476991
JB
5088 return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
5089 local_state_change);
636a5d36
JM
5090}
5091
5092static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
5093{
4c476991
JB
5094 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5095 struct net_device *dev = info->user_ptr[1];
19957bb3 5096 const u8 *ie = NULL, *bssid;
4c476991 5097 int ie_len = 0;
19957bb3 5098 u16 reason_code;
d5cdfacb 5099 bool local_state_change;
636a5d36 5100
f4a11bb0
JB
5101 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5102 return -EINVAL;
5103
5104 if (!info->attrs[NL80211_ATTR_MAC])
5105 return -EINVAL;
5106
5107 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5108 return -EINVAL;
5109
4c476991
JB
5110 if (!rdev->ops->disassoc)
5111 return -EOPNOTSUPP;
636a5d36 5112
074ac8df 5113 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5114 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5115 return -EOPNOTSUPP;
eec60b03 5116
19957bb3 5117 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 5118
19957bb3
JB
5119 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5120 if (reason_code == 0) {
f4a11bb0 5121 /* Reason Code 0 is reserved */
4c476991 5122 return -EINVAL;
255e737e 5123 }
636a5d36
JM
5124
5125 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
5126 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5127 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
5128 }
5129
d5cdfacb
JM
5130 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
5131
4c476991
JB
5132 return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
5133 local_state_change);
636a5d36
JM
5134}
5135
dd5b4cc7
FF
5136static bool
5137nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
5138 int mcast_rate[IEEE80211_NUM_BANDS],
5139 int rateval)
5140{
5141 struct wiphy *wiphy = &rdev->wiphy;
5142 bool found = false;
5143 int band, i;
5144
5145 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
5146 struct ieee80211_supported_band *sband;
5147
5148 sband = wiphy->bands[band];
5149 if (!sband)
5150 continue;
5151
5152 for (i = 0; i < sband->n_bitrates; i++) {
5153 if (sband->bitrates[i].bitrate == rateval) {
5154 mcast_rate[band] = i + 1;
5155 found = true;
5156 break;
5157 }
5158 }
5159 }
5160
5161 return found;
5162}
5163
04a773ad
JB
5164static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
5165{
4c476991
JB
5166 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5167 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
5168 struct cfg80211_ibss_params ibss;
5169 struct wiphy *wiphy;
fffd0934 5170 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
5171 int err;
5172
8e30bc55
JB
5173 memset(&ibss, 0, sizeof(ibss));
5174
04a773ad
JB
5175 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5176 return -EINVAL;
5177
5178 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5179 !info->attrs[NL80211_ATTR_SSID] ||
5180 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5181 return -EINVAL;
5182
8e30bc55
JB
5183 ibss.beacon_interval = 100;
5184
5185 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
5186 ibss.beacon_interval =
5187 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5188 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
5189 return -EINVAL;
5190 }
5191
4c476991
JB
5192 if (!rdev->ops->join_ibss)
5193 return -EOPNOTSUPP;
04a773ad 5194
4c476991
JB
5195 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5196 return -EOPNOTSUPP;
04a773ad 5197
79c97e97 5198 wiphy = &rdev->wiphy;
04a773ad 5199
39193498 5200 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 5201 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
5202
5203 if (!is_valid_ether_addr(ibss.bssid))
5204 return -EINVAL;
5205 }
04a773ad
JB
5206 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5207 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5208
5209 if (info->attrs[NL80211_ATTR_IE]) {
5210 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5211 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5212 }
5213
54858ee5
AS
5214 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
5215 enum nl80211_channel_type channel_type;
5216
cd6c6598 5217 if (!nl80211_valid_channel_type(info, &channel_type))
54858ee5
AS
5218 return -EINVAL;
5219
5220 if (channel_type != NL80211_CHAN_NO_HT &&
5221 !(wiphy->features & NL80211_FEATURE_HT_IBSS))
5222 return -EINVAL;
5223
5224 ibss.channel_type = channel_type;
5225 } else {
5226 ibss.channel_type = NL80211_CHAN_NO_HT;
5227 }
5228
5229 ibss.channel = rdev_freq_to_chan(rdev,
5230 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
5231 ibss.channel_type);
04a773ad
JB
5232 if (!ibss.channel ||
5233 ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
4c476991
JB
5234 ibss.channel->flags & IEEE80211_CHAN_DISABLED)
5235 return -EINVAL;
04a773ad 5236
54858ee5
AS
5237 /* Both channels should be able to initiate communication */
5238 if ((ibss.channel_type == NL80211_CHAN_HT40PLUS ||
5239 ibss.channel_type == NL80211_CHAN_HT40MINUS) &&
5240 !cfg80211_can_beacon_sec_chan(&rdev->wiphy, ibss.channel,
5241 ibss.channel_type))
5242 return -EINVAL;
5243
04a773ad 5244 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
5245 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5246
fbd2c8dc
TP
5247 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
5248 u8 *rates =
5249 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5250 int n_rates =
5251 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
5252 struct ieee80211_supported_band *sband =
5253 wiphy->bands[ibss.channel->band];
fbd2c8dc 5254
34850ab2
JB
5255 err = ieee80211_get_ratemask(sband, rates, n_rates,
5256 &ibss.basic_rates);
5257 if (err)
5258 return err;
fbd2c8dc 5259 }
dd5b4cc7
FF
5260
5261 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
5262 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
5263 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
5264 return -EINVAL;
fbd2c8dc 5265
4c476991
JB
5266 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5267 connkeys = nl80211_parse_connkeys(rdev,
5268 info->attrs[NL80211_ATTR_KEYS]);
5269 if (IS_ERR(connkeys))
5270 return PTR_ERR(connkeys);
5271 }
04a773ad 5272
267335d6
AQ
5273 ibss.control_port =
5274 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
5275
4c476991 5276 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934
JB
5277 if (err)
5278 kfree(connkeys);
04a773ad
JB
5279 return err;
5280}
5281
5282static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
5283{
4c476991
JB
5284 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5285 struct net_device *dev = info->user_ptr[1];
04a773ad 5286
4c476991
JB
5287 if (!rdev->ops->leave_ibss)
5288 return -EOPNOTSUPP;
04a773ad 5289
4c476991
JB
5290 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
5291 return -EOPNOTSUPP;
04a773ad 5292
4c476991 5293 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
5294}
5295
aff89a9b
JB
5296#ifdef CONFIG_NL80211_TESTMODE
5297static struct genl_multicast_group nl80211_testmode_mcgrp = {
5298 .name = "testmode",
5299};
5300
5301static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
5302{
4c476991 5303 struct cfg80211_registered_device *rdev = info->user_ptr[0];
aff89a9b
JB
5304 int err;
5305
5306 if (!info->attrs[NL80211_ATTR_TESTDATA])
5307 return -EINVAL;
5308
aff89a9b
JB
5309 err = -EOPNOTSUPP;
5310 if (rdev->ops->testmode_cmd) {
5311 rdev->testmode_info = info;
5312 err = rdev->ops->testmode_cmd(&rdev->wiphy,
5313 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
5314 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
5315 rdev->testmode_info = NULL;
5316 }
5317
aff89a9b
JB
5318 return err;
5319}
5320
71063f0e
WYG
5321static int nl80211_testmode_dump(struct sk_buff *skb,
5322 struct netlink_callback *cb)
5323{
00918d33 5324 struct cfg80211_registered_device *rdev;
71063f0e
WYG
5325 int err;
5326 long phy_idx;
5327 void *data = NULL;
5328 int data_len = 0;
5329
5330 if (cb->args[0]) {
5331 /*
5332 * 0 is a valid index, but not valid for args[0],
5333 * so we need to offset by 1.
5334 */
5335 phy_idx = cb->args[0] - 1;
5336 } else {
5337 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
5338 nl80211_fam.attrbuf, nl80211_fam.maxattr,
5339 nl80211_policy);
5340 if (err)
5341 return err;
00918d33 5342
2bd7e35d
JB
5343 mutex_lock(&cfg80211_mutex);
5344 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk),
5345 nl80211_fam.attrbuf);
5346 if (IS_ERR(rdev)) {
5347 mutex_unlock(&cfg80211_mutex);
5348 return PTR_ERR(rdev);
00918d33 5349 }
2bd7e35d
JB
5350 phy_idx = rdev->wiphy_idx;
5351 rdev = NULL;
5352 mutex_unlock(&cfg80211_mutex);
5353
71063f0e
WYG
5354 if (nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA])
5355 cb->args[1] =
5356 (long)nl80211_fam.attrbuf[NL80211_ATTR_TESTDATA];
5357 }
5358
5359 if (cb->args[1]) {
5360 data = nla_data((void *)cb->args[1]);
5361 data_len = nla_len((void *)cb->args[1]);
5362 }
5363
5364 mutex_lock(&cfg80211_mutex);
00918d33
JB
5365 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
5366 if (!rdev) {
71063f0e
WYG
5367 mutex_unlock(&cfg80211_mutex);
5368 return -ENOENT;
5369 }
00918d33 5370 cfg80211_lock_rdev(rdev);
71063f0e
WYG
5371 mutex_unlock(&cfg80211_mutex);
5372
00918d33 5373 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
5374 err = -EOPNOTSUPP;
5375 goto out_err;
5376 }
5377
5378 while (1) {
5379 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).pid,
5380 cb->nlh->nlmsg_seq, NLM_F_MULTI,
5381 NL80211_CMD_TESTMODE);
5382 struct nlattr *tmdata;
5383
9360ffd1 5384 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
5385 genlmsg_cancel(skb, hdr);
5386 break;
5387 }
5388
5389 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5390 if (!tmdata) {
5391 genlmsg_cancel(skb, hdr);
5392 break;
5393 }
00918d33
JB
5394 err = rdev->ops->testmode_dump(&rdev->wiphy, skb, cb,
5395 data, data_len);
71063f0e
WYG
5396 nla_nest_end(skb, tmdata);
5397
5398 if (err == -ENOBUFS || err == -ENOENT) {
5399 genlmsg_cancel(skb, hdr);
5400 break;
5401 } else if (err) {
5402 genlmsg_cancel(skb, hdr);
5403 goto out_err;
5404 }
5405
5406 genlmsg_end(skb, hdr);
5407 }
5408
5409 err = skb->len;
5410 /* see above */
5411 cb->args[0] = phy_idx + 1;
5412 out_err:
00918d33 5413 cfg80211_unlock_rdev(rdev);
71063f0e
WYG
5414 return err;
5415}
5416
aff89a9b
JB
5417static struct sk_buff *
5418__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
5419 int approxlen, u32 pid, u32 seq, gfp_t gfp)
5420{
5421 struct sk_buff *skb;
5422 void *hdr;
5423 struct nlattr *data;
5424
5425 skb = nlmsg_new(approxlen + 100, gfp);
5426 if (!skb)
5427 return NULL;
5428
5429 hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
5430 if (!hdr) {
5431 kfree_skb(skb);
5432 return NULL;
5433 }
5434
9360ffd1
DM
5435 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
5436 goto nla_put_failure;
aff89a9b
JB
5437 data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
5438
5439 ((void **)skb->cb)[0] = rdev;
5440 ((void **)skb->cb)[1] = hdr;
5441 ((void **)skb->cb)[2] = data;
5442
5443 return skb;
5444
5445 nla_put_failure:
5446 kfree_skb(skb);
5447 return NULL;
5448}
5449
5450struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
5451 int approxlen)
5452{
5453 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5454
5455 if (WARN_ON(!rdev->testmode_info))
5456 return NULL;
5457
5458 return __cfg80211_testmode_alloc_skb(rdev, approxlen,
5459 rdev->testmode_info->snd_pid,
5460 rdev->testmode_info->snd_seq,
5461 GFP_KERNEL);
5462}
5463EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
5464
5465int cfg80211_testmode_reply(struct sk_buff *skb)
5466{
5467 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
5468 void *hdr = ((void **)skb->cb)[1];
5469 struct nlattr *data = ((void **)skb->cb)[2];
5470
5471 if (WARN_ON(!rdev->testmode_info)) {
5472 kfree_skb(skb);
5473 return -EINVAL;
5474 }
5475
5476 nla_nest_end(skb, data);
5477 genlmsg_end(skb, hdr);
5478 return genlmsg_reply(skb, rdev->testmode_info);
5479}
5480EXPORT_SYMBOL(cfg80211_testmode_reply);
5481
5482struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
5483 int approxlen, gfp_t gfp)
5484{
5485 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
5486
5487 return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
5488}
5489EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
5490
5491void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
5492{
5493 void *hdr = ((void **)skb->cb)[1];
5494 struct nlattr *data = ((void **)skb->cb)[2];
5495
5496 nla_nest_end(skb, data);
5497 genlmsg_end(skb, hdr);
5498 genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
5499}
5500EXPORT_SYMBOL(cfg80211_testmode_event);
5501#endif
5502
b23aa676
SO
5503static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
5504{
4c476991
JB
5505 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5506 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5507 struct cfg80211_connect_params connect;
5508 struct wiphy *wiphy;
fffd0934 5509 struct cfg80211_cached_keys *connkeys = NULL;
b23aa676
SO
5510 int err;
5511
5512 memset(&connect, 0, sizeof(connect));
5513
5514 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
5515 return -EINVAL;
5516
5517 if (!info->attrs[NL80211_ATTR_SSID] ||
5518 !nla_len(info->attrs[NL80211_ATTR_SSID]))
5519 return -EINVAL;
5520
5521 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5522 connect.auth_type =
5523 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
5524 if (!nl80211_valid_auth_type(connect.auth_type))
5525 return -EINVAL;
5526 } else
5527 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5528
5529 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
5530
c0692b8f 5531 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 5532 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
5533 if (err)
5534 return err;
b23aa676 5535
074ac8df 5536 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5537 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5538 return -EOPNOTSUPP;
b23aa676 5539
79c97e97 5540 wiphy = &rdev->wiphy;
b23aa676 5541
4486ea98
BS
5542 connect.bg_scan_period = -1;
5543 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
5544 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
5545 connect.bg_scan_period =
5546 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
5547 }
5548
b23aa676
SO
5549 if (info->attrs[NL80211_ATTR_MAC])
5550 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5551 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5552 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
5553
5554 if (info->attrs[NL80211_ATTR_IE]) {
5555 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
5556 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
5557 }
5558
5559 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
5560 connect.channel =
5561 ieee80211_get_channel(wiphy,
5562 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
5563 if (!connect.channel ||
4c476991
JB
5564 connect.channel->flags & IEEE80211_CHAN_DISABLED)
5565 return -EINVAL;
b23aa676
SO
5566 }
5567
fffd0934
JB
5568 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
5569 connkeys = nl80211_parse_connkeys(rdev,
5570 info->attrs[NL80211_ATTR_KEYS]);
4c476991
JB
5571 if (IS_ERR(connkeys))
5572 return PTR_ERR(connkeys);
fffd0934
JB
5573 }
5574
7e7c8926
BG
5575 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
5576 connect.flags |= ASSOC_REQ_DISABLE_HT;
5577
5578 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5579 memcpy(&connect.ht_capa_mask,
5580 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
5581 sizeof(connect.ht_capa_mask));
5582
5583 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
5584 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
5585 return -EINVAL;
5586 memcpy(&connect.ht_capa,
5587 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
5588 sizeof(connect.ht_capa));
5589 }
5590
fffd0934 5591 err = cfg80211_connect(rdev, dev, &connect, connkeys);
fffd0934
JB
5592 if (err)
5593 kfree(connkeys);
b23aa676
SO
5594 return err;
5595}
5596
5597static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
5598{
4c476991
JB
5599 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5600 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
5601 u16 reason;
5602
5603 if (!info->attrs[NL80211_ATTR_REASON_CODE])
5604 reason = WLAN_REASON_DEAUTH_LEAVING;
5605 else
5606 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
5607
5608 if (reason == 0)
5609 return -EINVAL;
5610
074ac8df 5611 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5612 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5613 return -EOPNOTSUPP;
b23aa676 5614
4c476991 5615 return cfg80211_disconnect(rdev, dev, reason, true);
b23aa676
SO
5616}
5617
463d0183
JB
5618static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
5619{
4c476991 5620 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
5621 struct net *net;
5622 int err;
5623 u32 pid;
5624
5625 if (!info->attrs[NL80211_ATTR_PID])
5626 return -EINVAL;
5627
5628 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
5629
463d0183 5630 net = get_net_ns_by_pid(pid);
4c476991
JB
5631 if (IS_ERR(net))
5632 return PTR_ERR(net);
463d0183
JB
5633
5634 err = 0;
5635
5636 /* check if anything to do */
4c476991
JB
5637 if (!net_eq(wiphy_net(&rdev->wiphy), net))
5638 err = cfg80211_switch_netns(rdev, net);
463d0183 5639
463d0183 5640 put_net(net);
463d0183
JB
5641 return err;
5642}
5643
67fbb16b
SO
5644static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
5645{
4c476991 5646 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
5647 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
5648 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 5649 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
5650 struct cfg80211_pmksa pmksa;
5651
5652 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
5653
5654 if (!info->attrs[NL80211_ATTR_MAC])
5655 return -EINVAL;
5656
5657 if (!info->attrs[NL80211_ATTR_PMKID])
5658 return -EINVAL;
5659
67fbb16b
SO
5660 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
5661 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
5662
074ac8df 5663 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5664 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5665 return -EOPNOTSUPP;
67fbb16b
SO
5666
5667 switch (info->genlhdr->cmd) {
5668 case NL80211_CMD_SET_PMKSA:
5669 rdev_ops = rdev->ops->set_pmksa;
5670 break;
5671 case NL80211_CMD_DEL_PMKSA:
5672 rdev_ops = rdev->ops->del_pmksa;
5673 break;
5674 default:
5675 WARN_ON(1);
5676 break;
5677 }
5678
4c476991
JB
5679 if (!rdev_ops)
5680 return -EOPNOTSUPP;
67fbb16b 5681
4c476991 5682 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
5683}
5684
5685static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
5686{
4c476991
JB
5687 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5688 struct net_device *dev = info->user_ptr[1];
67fbb16b 5689
074ac8df 5690 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
5691 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
5692 return -EOPNOTSUPP;
67fbb16b 5693
4c476991
JB
5694 if (!rdev->ops->flush_pmksa)
5695 return -EOPNOTSUPP;
67fbb16b 5696
4c476991 5697 return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
67fbb16b
SO
5698}
5699
109086ce
AN
5700static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
5701{
5702 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5703 struct net_device *dev = info->user_ptr[1];
5704 u8 action_code, dialog_token;
5705 u16 status_code;
5706 u8 *peer;
5707
5708 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5709 !rdev->ops->tdls_mgmt)
5710 return -EOPNOTSUPP;
5711
5712 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
5713 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
5714 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
5715 !info->attrs[NL80211_ATTR_IE] ||
5716 !info->attrs[NL80211_ATTR_MAC])
5717 return -EINVAL;
5718
5719 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5720 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
5721 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
5722 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
5723
5724 return rdev->ops->tdls_mgmt(&rdev->wiphy, dev, peer, action_code,
5725 dialog_token, status_code,
5726 nla_data(info->attrs[NL80211_ATTR_IE]),
5727 nla_len(info->attrs[NL80211_ATTR_IE]));
5728}
5729
5730static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
5731{
5732 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5733 struct net_device *dev = info->user_ptr[1];
5734 enum nl80211_tdls_operation operation;
5735 u8 *peer;
5736
5737 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
5738 !rdev->ops->tdls_oper)
5739 return -EOPNOTSUPP;
5740
5741 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
5742 !info->attrs[NL80211_ATTR_MAC])
5743 return -EINVAL;
5744
5745 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
5746 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
5747
5748 return rdev->ops->tdls_oper(&rdev->wiphy, dev, peer, operation);
5749}
5750
9588bbd5
JM
5751static int nl80211_remain_on_channel(struct sk_buff *skb,
5752 struct genl_info *info)
5753{
4c476991
JB
5754 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5755 struct net_device *dev = info->user_ptr[1];
9588bbd5
JM
5756 struct ieee80211_channel *chan;
5757 struct sk_buff *msg;
5758 void *hdr;
5759 u64 cookie;
5760 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
5761 u32 freq, duration;
5762 int err;
5763
5764 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
5765 !info->attrs[NL80211_ATTR_DURATION])
5766 return -EINVAL;
5767
5768 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
5769
ebf348fc
JB
5770 if (!rdev->ops->remain_on_channel ||
5771 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
5772 return -EOPNOTSUPP;
5773
9588bbd5 5774 /*
ebf348fc
JB
5775 * We should be on that channel for at least a minimum amount of
5776 * time (10ms) but no longer than the driver supports.
9588bbd5 5777 */
ebf348fc 5778 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 5779 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
5780 return -EINVAL;
5781
cd6c6598
JB
5782 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
5783 !nl80211_valid_channel_type(info, &channel_type))
5784 return -EINVAL;
9588bbd5
JM
5785
5786 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
5787 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
5788 if (chan == NULL)
5789 return -EINVAL;
9588bbd5
JM
5790
5791 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
5792 if (!msg)
5793 return -ENOMEM;
9588bbd5
JM
5794
5795 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
5796 NL80211_CMD_REMAIN_ON_CHANNEL);
5797
5798 if (IS_ERR(hdr)) {
5799 err = PTR_ERR(hdr);
5800 goto free_msg;
5801 }
5802
5803 err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
5804 channel_type, duration, &cookie);
5805
5806 if (err)
5807 goto free_msg;
5808
9360ffd1
DM
5809 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
5810 goto nla_put_failure;
9588bbd5
JM
5811
5812 genlmsg_end(msg, hdr);
4c476991
JB
5813
5814 return genlmsg_reply(msg, info);
9588bbd5
JM
5815
5816 nla_put_failure:
5817 err = -ENOBUFS;
5818 free_msg:
5819 nlmsg_free(msg);
9588bbd5
JM
5820 return err;
5821}
5822
5823static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
5824 struct genl_info *info)
5825{
4c476991
JB
5826 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5827 struct net_device *dev = info->user_ptr[1];
9588bbd5 5828 u64 cookie;
9588bbd5
JM
5829
5830 if (!info->attrs[NL80211_ATTR_COOKIE])
5831 return -EINVAL;
5832
4c476991
JB
5833 if (!rdev->ops->cancel_remain_on_channel)
5834 return -EOPNOTSUPP;
9588bbd5 5835
9588bbd5
JM
5836 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
5837
4c476991 5838 return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
9588bbd5
JM
5839}
5840
13ae75b1
JM
5841static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
5842 u8 *rates, u8 rates_len)
5843{
5844 u8 i;
5845 u32 mask = 0;
5846
5847 for (i = 0; i < rates_len; i++) {
5848 int rate = (rates[i] & 0x7f) * 5;
5849 int ridx;
5850 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
5851 struct ieee80211_rate *srate =
5852 &sband->bitrates[ridx];
5853 if (rate == srate->bitrate) {
5854 mask |= 1 << ridx;
5855 break;
5856 }
5857 }
5858 if (ridx == sband->n_bitrates)
5859 return 0; /* rate not found */
5860 }
5861
5862 return mask;
5863}
5864
24db78c0
SW
5865static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
5866 u8 *rates, u8 rates_len,
5867 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
5868{
5869 u8 i;
5870
5871 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
5872
5873 for (i = 0; i < rates_len; i++) {
5874 int ridx, rbit;
5875
5876 ridx = rates[i] / 8;
5877 rbit = BIT(rates[i] % 8);
5878
5879 /* check validity */
910570b5 5880 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
24db78c0
SW
5881 return false;
5882
5883 /* check availability */
5884 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
5885 mcs[ridx] |= rbit;
5886 else
5887 return false;
5888 }
5889
5890 return true;
5891}
5892
b54452b0 5893static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
13ae75b1
JM
5894 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
5895 .len = NL80211_MAX_SUPP_RATES },
24db78c0
SW
5896 [NL80211_TXRATE_MCS] = { .type = NLA_BINARY,
5897 .len = NL80211_MAX_SUPP_HT_RATES },
13ae75b1
JM
5898};
5899
5900static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
5901 struct genl_info *info)
5902{
5903 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4c476991 5904 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13ae75b1 5905 struct cfg80211_bitrate_mask mask;
4c476991
JB
5906 int rem, i;
5907 struct net_device *dev = info->user_ptr[1];
13ae75b1
JM
5908 struct nlattr *tx_rates;
5909 struct ieee80211_supported_band *sband;
5910
5911 if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
5912 return -EINVAL;
5913
4c476991
JB
5914 if (!rdev->ops->set_bitrate_mask)
5915 return -EOPNOTSUPP;
13ae75b1
JM
5916
5917 memset(&mask, 0, sizeof(mask));
5918 /* Default to all rates enabled */
5919 for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
5920 sband = rdev->wiphy.bands[i];
5921 mask.control[i].legacy =
5922 sband ? (1 << sband->n_bitrates) - 1 : 0;
24db78c0
SW
5923 if (sband)
5924 memcpy(mask.control[i].mcs,
5925 sband->ht_cap.mcs.rx_mask,
5926 sizeof(mask.control[i].mcs));
5927 else
5928 memset(mask.control[i].mcs, 0,
5929 sizeof(mask.control[i].mcs));
13ae75b1
JM
5930 }
5931
5932 /*
5933 * The nested attribute uses enum nl80211_band as the index. This maps
5934 * directly to the enum ieee80211_band values used in cfg80211.
5935 */
24db78c0 5936 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
13ae75b1
JM
5937 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
5938 {
5939 enum ieee80211_band band = nla_type(tx_rates);
4c476991
JB
5940 if (band < 0 || band >= IEEE80211_NUM_BANDS)
5941 return -EINVAL;
13ae75b1 5942 sband = rdev->wiphy.bands[band];
4c476991
JB
5943 if (sband == NULL)
5944 return -EINVAL;
13ae75b1
JM
5945 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
5946 nla_len(tx_rates), nl80211_txattr_policy);
5947 if (tb[NL80211_TXRATE_LEGACY]) {
5948 mask.control[band].legacy = rateset_to_mask(
5949 sband,
5950 nla_data(tb[NL80211_TXRATE_LEGACY]),
5951 nla_len(tb[NL80211_TXRATE_LEGACY]));
218d2e26
BS
5952 if ((mask.control[band].legacy == 0) &&
5953 nla_len(tb[NL80211_TXRATE_LEGACY]))
5954 return -EINVAL;
24db78c0
SW
5955 }
5956 if (tb[NL80211_TXRATE_MCS]) {
5957 if (!ht_rateset_to_mask(
5958 sband,
5959 nla_data(tb[NL80211_TXRATE_MCS]),
5960 nla_len(tb[NL80211_TXRATE_MCS]),
5961 mask.control[band].mcs))
5962 return -EINVAL;
5963 }
5964
5965 if (mask.control[band].legacy == 0) {
5966 /* don't allow empty legacy rates if HT
5967 * is not even supported. */
5968 if (!rdev->wiphy.bands[band]->ht_cap.ht_supported)
5969 return -EINVAL;
5970
5971 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
5972 if (mask.control[band].mcs[i])
5973 break;
5974
5975 /* legacy and mcs rates may not be both empty */
5976 if (i == IEEE80211_HT_MCS_MASK_LEN)
4c476991 5977 return -EINVAL;
13ae75b1
JM
5978 }
5979 }
5980
4c476991 5981 return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
13ae75b1
JM
5982}
5983
2e161f78 5984static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 5985{
4c476991
JB
5986 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5987 struct net_device *dev = info->user_ptr[1];
2e161f78 5988 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
5989
5990 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
5991 return -EINVAL;
5992
2e161f78
JB
5993 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
5994 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 5995
9d38d85d 5996 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 5997 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
5998 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
5999 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
6000 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 6001 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
6002 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6003 return -EOPNOTSUPP;
026331c4
JM
6004
6005 /* not much point in registering if we can't reply */
4c476991
JB
6006 if (!rdev->ops->mgmt_tx)
6007 return -EOPNOTSUPP;
026331c4 6008
4c476991 6009 return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
2e161f78 6010 frame_type,
026331c4
JM
6011 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
6012 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
026331c4
JM
6013}
6014
2e161f78 6015static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 6016{
4c476991
JB
6017 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6018 struct net_device *dev = info->user_ptr[1];
026331c4
JM
6019 struct ieee80211_channel *chan;
6020 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
252aa631 6021 bool channel_type_valid = false;
026331c4
JM
6022 u32 freq;
6023 int err;
d64d373f 6024 void *hdr = NULL;
026331c4 6025 u64 cookie;
e247bd90 6026 struct sk_buff *msg = NULL;
f7ca38df 6027 unsigned int wait = 0;
e247bd90
JB
6028 bool offchan, no_cck, dont_wait_for_ack;
6029
6030 dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
026331c4
JM
6031
6032 if (!info->attrs[NL80211_ATTR_FRAME] ||
6033 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
6034 return -EINVAL;
6035
4c476991
JB
6036 if (!rdev->ops->mgmt_tx)
6037 return -EOPNOTSUPP;
026331c4 6038
9d38d85d 6039 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
074ac8df 6040 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
663fcafd
JB
6041 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
6042 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
6043 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
c7108a71 6044 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
4c476991
JB
6045 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6046 return -EOPNOTSUPP;
026331c4 6047
f7ca38df 6048 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 6049 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df
JB
6050 return -EINVAL;
6051 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
6052
6053 /*
6054 * We should wait on the channel for at least a minimum amount
6055 * of time (10ms) but no longer than the driver supports.
6056 */
6057 if (wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
6058 wait > rdev->wiphy.max_remain_on_channel_duration)
6059 return -EINVAL;
6060
f7ca38df
JB
6061 }
6062
026331c4 6063 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
cd6c6598 6064 if (!nl80211_valid_channel_type(info, &channel_type))
4c476991 6065 return -EINVAL;
252aa631 6066 channel_type_valid = true;
026331c4
JM
6067 }
6068
f7ca38df
JB
6069 offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
6070
7c4ef712
JB
6071 if (offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
6072 return -EINVAL;
6073
e9f935e3
RM
6074 no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
6075
026331c4
JM
6076 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
6077 chan = rdev_freq_to_chan(rdev, freq, channel_type);
4c476991
JB
6078 if (chan == NULL)
6079 return -EINVAL;
026331c4 6080
e247bd90
JB
6081 if (!dont_wait_for_ack) {
6082 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6083 if (!msg)
6084 return -ENOMEM;
026331c4 6085
e247bd90
JB
6086 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6087 NL80211_CMD_FRAME);
026331c4 6088
e247bd90
JB
6089 if (IS_ERR(hdr)) {
6090 err = PTR_ERR(hdr);
6091 goto free_msg;
6092 }
026331c4 6093 }
e247bd90 6094
f7ca38df
JB
6095 err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
6096 channel_type_valid, wait,
2e161f78
JB
6097 nla_data(info->attrs[NL80211_ATTR_FRAME]),
6098 nla_len(info->attrs[NL80211_ATTR_FRAME]),
e247bd90 6099 no_cck, dont_wait_for_ack, &cookie);
026331c4
JM
6100 if (err)
6101 goto free_msg;
6102
e247bd90 6103 if (msg) {
9360ffd1
DM
6104 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6105 goto nla_put_failure;
026331c4 6106
e247bd90
JB
6107 genlmsg_end(msg, hdr);
6108 return genlmsg_reply(msg, info);
6109 }
6110
6111 return 0;
026331c4
JM
6112
6113 nla_put_failure:
6114 err = -ENOBUFS;
6115 free_msg:
6116 nlmsg_free(msg);
026331c4
JM
6117 return err;
6118}
6119
f7ca38df
JB
6120static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
6121{
6122 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6123 struct net_device *dev = info->user_ptr[1];
6124 u64 cookie;
6125
6126 if (!info->attrs[NL80211_ATTR_COOKIE])
6127 return -EINVAL;
6128
6129 if (!rdev->ops->mgmt_tx_cancel_wait)
6130 return -EOPNOTSUPP;
6131
6132 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
6133 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
6134 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
6135 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
6136 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
6137 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6138 return -EOPNOTSUPP;
6139
6140 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
6141
6142 return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
6143}
6144
ffb9eb3d
KV
6145static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
6146{
4c476991 6147 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 6148 struct wireless_dev *wdev;
4c476991 6149 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6150 u8 ps_state;
6151 bool state;
6152 int err;
6153
4c476991
JB
6154 if (!info->attrs[NL80211_ATTR_PS_STATE])
6155 return -EINVAL;
ffb9eb3d
KV
6156
6157 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
6158
4c476991
JB
6159 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
6160 return -EINVAL;
ffb9eb3d
KV
6161
6162 wdev = dev->ieee80211_ptr;
6163
4c476991
JB
6164 if (!rdev->ops->set_power_mgmt)
6165 return -EOPNOTSUPP;
ffb9eb3d
KV
6166
6167 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
6168
6169 if (state == wdev->ps)
4c476991 6170 return 0;
ffb9eb3d 6171
4c476991
JB
6172 err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
6173 wdev->ps_timeout);
6174 if (!err)
6175 wdev->ps = state;
ffb9eb3d
KV
6176 return err;
6177}
6178
6179static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
6180{
4c476991 6181 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
6182 enum nl80211_ps_state ps_state;
6183 struct wireless_dev *wdev;
4c476991 6184 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
6185 struct sk_buff *msg;
6186 void *hdr;
6187 int err;
6188
ffb9eb3d
KV
6189 wdev = dev->ieee80211_ptr;
6190
4c476991
JB
6191 if (!rdev->ops->set_power_mgmt)
6192 return -EOPNOTSUPP;
ffb9eb3d
KV
6193
6194 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6195 if (!msg)
6196 return -ENOMEM;
ffb9eb3d
KV
6197
6198 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6199 NL80211_CMD_GET_POWER_SAVE);
6200 if (!hdr) {
4c476991 6201 err = -ENOBUFS;
ffb9eb3d
KV
6202 goto free_msg;
6203 }
6204
6205 if (wdev->ps)
6206 ps_state = NL80211_PS_ENABLED;
6207 else
6208 ps_state = NL80211_PS_DISABLED;
6209
9360ffd1
DM
6210 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
6211 goto nla_put_failure;
ffb9eb3d
KV
6212
6213 genlmsg_end(msg, hdr);
4c476991 6214 return genlmsg_reply(msg, info);
ffb9eb3d 6215
4c476991 6216 nla_put_failure:
ffb9eb3d 6217 err = -ENOBUFS;
4c476991 6218 free_msg:
ffb9eb3d 6219 nlmsg_free(msg);
ffb9eb3d
KV
6220 return err;
6221}
6222
d6dc1a38
JO
6223static struct nla_policy
6224nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
6225 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
6226 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
6227 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
6228};
6229
6230static int nl80211_set_cqm_rssi(struct genl_info *info,
6231 s32 threshold, u32 hysteresis)
6232{
4c476991 6233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
d6dc1a38 6234 struct wireless_dev *wdev;
4c476991 6235 struct net_device *dev = info->user_ptr[1];
d6dc1a38
JO
6236
6237 if (threshold > 0)
6238 return -EINVAL;
6239
d6dc1a38
JO
6240 wdev = dev->ieee80211_ptr;
6241
4c476991
JB
6242 if (!rdev->ops->set_cqm_rssi_config)
6243 return -EOPNOTSUPP;
d6dc1a38 6244
074ac8df 6245 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
6246 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
6247 return -EOPNOTSUPP;
d6dc1a38 6248
4c476991
JB
6249 return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
6250 threshold, hysteresis);
d6dc1a38
JO
6251}
6252
6253static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
6254{
6255 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
6256 struct nlattr *cqm;
6257 int err;
6258
6259 cqm = info->attrs[NL80211_ATTR_CQM];
6260 if (!cqm) {
6261 err = -EINVAL;
6262 goto out;
6263 }
6264
6265 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
6266 nl80211_attr_cqm_policy);
6267 if (err)
6268 goto out;
6269
6270 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
6271 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
6272 s32 threshold;
6273 u32 hysteresis;
6274 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
6275 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
6276 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
6277 } else
6278 err = -EINVAL;
6279
6280out:
6281 return err;
6282}
6283
29cbe68c
JB
6284static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
6285{
6286 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6287 struct net_device *dev = info->user_ptr[1];
6288 struct mesh_config cfg;
c80d545d 6289 struct mesh_setup setup;
29cbe68c
JB
6290 int err;
6291
6292 /* start with default */
6293 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 6294 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 6295
24bdd9f4 6296 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 6297 /* and parse parameters if given */
24bdd9f4 6298 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
6299 if (err)
6300 return err;
6301 }
6302
6303 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
6304 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
6305 return -EINVAL;
6306
c80d545d
JC
6307 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
6308 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
6309
4bb62344
CYY
6310 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
6311 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
6312 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
6313 return -EINVAL;
6314
c80d545d
JC
6315 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
6316 /* parse additional setup parameters if given */
6317 err = nl80211_parse_mesh_setup(info, &setup);
6318 if (err)
6319 return err;
6320 }
6321
cc1d2806
JB
6322 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
6323 enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
6324
6325 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE] &&
6326 !nl80211_valid_channel_type(info, &channel_type))
6327 return -EINVAL;
6328
6329 setup.channel = rdev_freq_to_chan(rdev,
6330 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]),
6331 channel_type);
6332 if (!setup.channel)
6333 return -EINVAL;
6334 setup.channel_type = channel_type;
6335 } else {
6336 /* cfg80211_join_mesh() will sort it out */
6337 setup.channel = NULL;
6338 }
6339
c80d545d 6340 return cfg80211_join_mesh(rdev, dev, &setup, &cfg);
29cbe68c
JB
6341}
6342
6343static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
6344{
6345 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6346 struct net_device *dev = info->user_ptr[1];
6347
6348 return cfg80211_leave_mesh(rdev, dev);
6349}
6350
dfb89c56 6351#ifdef CONFIG_PM
ff1b6e69
JB
6352static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
6353{
6354 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6355 struct sk_buff *msg;
6356 void *hdr;
6357
6358 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6359 return -EOPNOTSUPP;
6360
6361 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6362 if (!msg)
6363 return -ENOMEM;
6364
6365 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6366 NL80211_CMD_GET_WOWLAN);
6367 if (!hdr)
6368 goto nla_put_failure;
6369
6370 if (rdev->wowlan) {
6371 struct nlattr *nl_wowlan;
6372
6373 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS);
6374 if (!nl_wowlan)
6375 goto nla_put_failure;
6376
9360ffd1
DM
6377 if ((rdev->wowlan->any &&
6378 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6379 (rdev->wowlan->disconnect &&
6380 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6381 (rdev->wowlan->magic_pkt &&
6382 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6383 (rdev->wowlan->gtk_rekey_failure &&
6384 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6385 (rdev->wowlan->eap_identity_req &&
6386 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6387 (rdev->wowlan->four_way_handshake &&
6388 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6389 (rdev->wowlan->rfkill_release &&
6390 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
6391 goto nla_put_failure;
ff1b6e69
JB
6392 if (rdev->wowlan->n_patterns) {
6393 struct nlattr *nl_pats, *nl_pat;
6394 int i, pat_len;
6395
6396 nl_pats = nla_nest_start(msg,
6397 NL80211_WOWLAN_TRIG_PKT_PATTERN);
6398 if (!nl_pats)
6399 goto nla_put_failure;
6400
6401 for (i = 0; i < rdev->wowlan->n_patterns; i++) {
6402 nl_pat = nla_nest_start(msg, i + 1);
6403 if (!nl_pat)
6404 goto nla_put_failure;
6405 pat_len = rdev->wowlan->patterns[i].pattern_len;
9360ffd1
DM
6406 if (nla_put(msg, NL80211_WOWLAN_PKTPAT_MASK,
6407 DIV_ROUND_UP(pat_len, 8),
6408 rdev->wowlan->patterns[i].mask) ||
6409 nla_put(msg, NL80211_WOWLAN_PKTPAT_PATTERN,
6410 pat_len,
6411 rdev->wowlan->patterns[i].pattern))
6412 goto nla_put_failure;
ff1b6e69
JB
6413 nla_nest_end(msg, nl_pat);
6414 }
6415 nla_nest_end(msg, nl_pats);
6416 }
6417
6418 nla_nest_end(msg, nl_wowlan);
6419 }
6420
6421 genlmsg_end(msg, hdr);
6422 return genlmsg_reply(msg, info);
6423
6424nla_put_failure:
6425 nlmsg_free(msg);
6426 return -ENOBUFS;
6427}
6428
6429static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
6430{
6431 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6432 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
6433 struct cfg80211_wowlan no_triggers = {};
6434 struct cfg80211_wowlan new_triggers = {};
6435 struct wiphy_wowlan_support *wowlan = &rdev->wiphy.wowlan;
6436 int err, i;
6d52563f 6437 bool prev_enabled = rdev->wowlan;
ff1b6e69
JB
6438
6439 if (!rdev->wiphy.wowlan.flags && !rdev->wiphy.wowlan.n_patterns)
6440 return -EOPNOTSUPP;
6441
6442 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS])
6443 goto no_triggers;
6444
6445 err = nla_parse(tb, MAX_NL80211_WOWLAN_TRIG,
6446 nla_data(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6447 nla_len(info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]),
6448 nl80211_wowlan_policy);
6449 if (err)
6450 return err;
6451
6452 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
6453 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
6454 return -EINVAL;
6455 new_triggers.any = true;
6456 }
6457
6458 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
6459 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
6460 return -EINVAL;
6461 new_triggers.disconnect = true;
6462 }
6463
6464 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
6465 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
6466 return -EINVAL;
6467 new_triggers.magic_pkt = true;
6468 }
6469
77dbbb13
JB
6470 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
6471 return -EINVAL;
6472
6473 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
6474 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
6475 return -EINVAL;
6476 new_triggers.gtk_rekey_failure = true;
6477 }
6478
6479 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
6480 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
6481 return -EINVAL;
6482 new_triggers.eap_identity_req = true;
6483 }
6484
6485 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
6486 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
6487 return -EINVAL;
6488 new_triggers.four_way_handshake = true;
6489 }
6490
6491 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
6492 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
6493 return -EINVAL;
6494 new_triggers.rfkill_release = true;
6495 }
6496
ff1b6e69
JB
6497 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
6498 struct nlattr *pat;
6499 int n_patterns = 0;
6500 int rem, pat_len, mask_len;
6501 struct nlattr *pat_tb[NUM_NL80211_WOWLAN_PKTPAT];
6502
6503 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6504 rem)
6505 n_patterns++;
6506 if (n_patterns > wowlan->n_patterns)
6507 return -EINVAL;
6508
6509 new_triggers.patterns = kcalloc(n_patterns,
6510 sizeof(new_triggers.patterns[0]),
6511 GFP_KERNEL);
6512 if (!new_triggers.patterns)
6513 return -ENOMEM;
6514
6515 new_triggers.n_patterns = n_patterns;
6516 i = 0;
6517
6518 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
6519 rem) {
6520 nla_parse(pat_tb, MAX_NL80211_WOWLAN_PKTPAT,
6521 nla_data(pat), nla_len(pat), NULL);
6522 err = -EINVAL;
6523 if (!pat_tb[NL80211_WOWLAN_PKTPAT_MASK] ||
6524 !pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN])
6525 goto error;
6526 pat_len = nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]);
6527 mask_len = DIV_ROUND_UP(pat_len, 8);
6528 if (nla_len(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]) !=
6529 mask_len)
6530 goto error;
6531 if (pat_len > wowlan->pattern_max_len ||
6532 pat_len < wowlan->pattern_min_len)
6533 goto error;
6534
6535 new_triggers.patterns[i].mask =
6536 kmalloc(mask_len + pat_len, GFP_KERNEL);
6537 if (!new_triggers.patterns[i].mask) {
6538 err = -ENOMEM;
6539 goto error;
6540 }
6541 new_triggers.patterns[i].pattern =
6542 new_triggers.patterns[i].mask + mask_len;
6543 memcpy(new_triggers.patterns[i].mask,
6544 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_MASK]),
6545 mask_len);
6546 new_triggers.patterns[i].pattern_len = pat_len;
6547 memcpy(new_triggers.patterns[i].pattern,
6548 nla_data(pat_tb[NL80211_WOWLAN_PKTPAT_PATTERN]),
6549 pat_len);
6550 i++;
6551 }
6552 }
6553
6554 if (memcmp(&new_triggers, &no_triggers, sizeof(new_triggers))) {
6555 struct cfg80211_wowlan *ntrig;
6556 ntrig = kmemdup(&new_triggers, sizeof(new_triggers),
6557 GFP_KERNEL);
6558 if (!ntrig) {
6559 err = -ENOMEM;
6560 goto error;
6561 }
6562 cfg80211_rdev_free_wowlan(rdev);
6563 rdev->wowlan = ntrig;
6564 } else {
6565 no_triggers:
6566 cfg80211_rdev_free_wowlan(rdev);
6567 rdev->wowlan = NULL;
6568 }
6569
6d52563f
JB
6570 if (rdev->ops->set_wakeup && prev_enabled != !!rdev->wowlan)
6571 rdev->ops->set_wakeup(&rdev->wiphy, rdev->wowlan);
6572
ff1b6e69
JB
6573 return 0;
6574 error:
6575 for (i = 0; i < new_triggers.n_patterns; i++)
6576 kfree(new_triggers.patterns[i].mask);
6577 kfree(new_triggers.patterns);
6578 return err;
6579}
dfb89c56 6580#endif
ff1b6e69 6581
e5497d76
JB
6582static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
6583{
6584 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6585 struct net_device *dev = info->user_ptr[1];
6586 struct wireless_dev *wdev = dev->ieee80211_ptr;
6587 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
6588 struct cfg80211_gtk_rekey_data rekey_data;
6589 int err;
6590
6591 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
6592 return -EINVAL;
6593
6594 err = nla_parse(tb, MAX_NL80211_REKEY_DATA,
6595 nla_data(info->attrs[NL80211_ATTR_REKEY_DATA]),
6596 nla_len(info->attrs[NL80211_ATTR_REKEY_DATA]),
6597 nl80211_rekey_policy);
6598 if (err)
6599 return err;
6600
6601 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN)
6602 return -ERANGE;
6603 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN)
6604 return -ERANGE;
6605 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN)
6606 return -ERANGE;
6607
6608 memcpy(rekey_data.kek, nla_data(tb[NL80211_REKEY_DATA_KEK]),
6609 NL80211_KEK_LEN);
6610 memcpy(rekey_data.kck, nla_data(tb[NL80211_REKEY_DATA_KCK]),
6611 NL80211_KCK_LEN);
6612 memcpy(rekey_data.replay_ctr,
6613 nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]),
6614 NL80211_REPLAY_CTR_LEN);
6615
6616 wdev_lock(wdev);
6617 if (!wdev->current_bss) {
6618 err = -ENOTCONN;
6619 goto out;
6620 }
6621
6622 if (!rdev->ops->set_rekey_data) {
6623 err = -EOPNOTSUPP;
6624 goto out;
6625 }
6626
6627 err = rdev->ops->set_rekey_data(&rdev->wiphy, dev, &rekey_data);
6628 out:
6629 wdev_unlock(wdev);
6630 return err;
6631}
6632
28946da7
JB
6633static int nl80211_register_unexpected_frame(struct sk_buff *skb,
6634 struct genl_info *info)
6635{
6636 struct net_device *dev = info->user_ptr[1];
6637 struct wireless_dev *wdev = dev->ieee80211_ptr;
6638
6639 if (wdev->iftype != NL80211_IFTYPE_AP &&
6640 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6641 return -EINVAL;
6642
6643 if (wdev->ap_unexpected_nlpid)
6644 return -EBUSY;
6645
6646 wdev->ap_unexpected_nlpid = info->snd_pid;
6647 return 0;
6648}
6649
7f6cf311
JB
6650static int nl80211_probe_client(struct sk_buff *skb,
6651 struct genl_info *info)
6652{
6653 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6654 struct net_device *dev = info->user_ptr[1];
6655 struct wireless_dev *wdev = dev->ieee80211_ptr;
6656 struct sk_buff *msg;
6657 void *hdr;
6658 const u8 *addr;
6659 u64 cookie;
6660 int err;
6661
6662 if (wdev->iftype != NL80211_IFTYPE_AP &&
6663 wdev->iftype != NL80211_IFTYPE_P2P_GO)
6664 return -EOPNOTSUPP;
6665
6666 if (!info->attrs[NL80211_ATTR_MAC])
6667 return -EINVAL;
6668
6669 if (!rdev->ops->probe_client)
6670 return -EOPNOTSUPP;
6671
6672 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6673 if (!msg)
6674 return -ENOMEM;
6675
6676 hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
6677 NL80211_CMD_PROBE_CLIENT);
6678
6679 if (IS_ERR(hdr)) {
6680 err = PTR_ERR(hdr);
6681 goto free_msg;
6682 }
6683
6684 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6685
6686 err = rdev->ops->probe_client(&rdev->wiphy, dev, addr, &cookie);
6687 if (err)
6688 goto free_msg;
6689
9360ffd1
DM
6690 if (nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
6691 goto nla_put_failure;
7f6cf311
JB
6692
6693 genlmsg_end(msg, hdr);
6694
6695 return genlmsg_reply(msg, info);
6696
6697 nla_put_failure:
6698 err = -ENOBUFS;
6699 free_msg:
6700 nlmsg_free(msg);
6701 return err;
6702}
6703
5e760230
JB
6704static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
6705{
6706 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6707
6708 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
6709 return -EOPNOTSUPP;
6710
6711 if (rdev->ap_beacons_nlpid)
6712 return -EBUSY;
6713
6714 rdev->ap_beacons_nlpid = info->snd_pid;
6715
6716 return 0;
6717}
6718
4c476991
JB
6719#define NL80211_FLAG_NEED_WIPHY 0x01
6720#define NL80211_FLAG_NEED_NETDEV 0x02
6721#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
6722#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
6723#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
6724 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef
JB
6725#define NL80211_FLAG_NEED_WDEV 0x10
6726/* If a netdev is associated, it must be UP */
6727#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
6728 NL80211_FLAG_CHECK_NETDEV_UP)
4c476991
JB
6729
6730static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
6731 struct genl_info *info)
6732{
6733 struct cfg80211_registered_device *rdev;
89a54e48 6734 struct wireless_dev *wdev;
4c476991 6735 struct net_device *dev;
4c476991
JB
6736 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
6737
6738 if (rtnl)
6739 rtnl_lock();
6740
6741 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 6742 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
6743 if (IS_ERR(rdev)) {
6744 if (rtnl)
6745 rtnl_unlock();
6746 return PTR_ERR(rdev);
6747 }
6748 info->user_ptr[0] = rdev;
1bf614ef
JB
6749 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
6750 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
89a54e48
JB
6751 mutex_lock(&cfg80211_mutex);
6752 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
6753 info->attrs);
6754 if (IS_ERR(wdev)) {
6755 mutex_unlock(&cfg80211_mutex);
4c476991
JB
6756 if (rtnl)
6757 rtnl_unlock();
89a54e48 6758 return PTR_ERR(wdev);
4c476991 6759 }
89a54e48 6760
89a54e48
JB
6761 dev = wdev->netdev;
6762 rdev = wiphy_to_dev(wdev->wiphy);
6763
1bf614ef
JB
6764 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
6765 if (!dev) {
6766 mutex_unlock(&cfg80211_mutex);
6767 if (rtnl)
6768 rtnl_unlock();
6769 return -EINVAL;
6770 }
6771
6772 info->user_ptr[1] = dev;
6773 } else {
6774 info->user_ptr[1] = wdev;
6775 }
6776
6777 if (dev) {
6778 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
6779 !netif_running(dev)) {
6780 mutex_unlock(&cfg80211_mutex);
6781 if (rtnl)
6782 rtnl_unlock();
6783 return -ENETDOWN;
6784 }
6785
6786 dev_hold(dev);
41265714 6787 }
89a54e48 6788
89a54e48
JB
6789 cfg80211_lock_rdev(rdev);
6790
6791 mutex_unlock(&cfg80211_mutex);
6792
4c476991 6793 info->user_ptr[0] = rdev;
4c476991
JB
6794 }
6795
6796 return 0;
6797}
6798
6799static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
6800 struct genl_info *info)
6801{
6802 if (info->user_ptr[0])
6803 cfg80211_unlock_rdev(info->user_ptr[0]);
1bf614ef
JB
6804 if (info->user_ptr[1]) {
6805 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
6806 struct wireless_dev *wdev = info->user_ptr[1];
6807
6808 if (wdev->netdev)
6809 dev_put(wdev->netdev);
6810 } else {
6811 dev_put(info->user_ptr[1]);
6812 }
6813 }
4c476991
JB
6814 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
6815 rtnl_unlock();
6816}
6817
55682965
JB
6818static struct genl_ops nl80211_ops[] = {
6819 {
6820 .cmd = NL80211_CMD_GET_WIPHY,
6821 .doit = nl80211_get_wiphy,
6822 .dumpit = nl80211_dump_wiphy,
6823 .policy = nl80211_policy,
6824 /* can be retrieved by unprivileged users */
4c476991 6825 .internal_flags = NL80211_FLAG_NEED_WIPHY,
55682965
JB
6826 },
6827 {
6828 .cmd = NL80211_CMD_SET_WIPHY,
6829 .doit = nl80211_set_wiphy,
6830 .policy = nl80211_policy,
6831 .flags = GENL_ADMIN_PERM,
4c476991 6832 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
6833 },
6834 {
6835 .cmd = NL80211_CMD_GET_INTERFACE,
6836 .doit = nl80211_get_interface,
6837 .dumpit = nl80211_dump_interface,
6838 .policy = nl80211_policy,
6839 /* can be retrieved by unprivileged users */
72fb2abc 6840 .internal_flags = NL80211_FLAG_NEED_WDEV,
55682965
JB
6841 },
6842 {
6843 .cmd = NL80211_CMD_SET_INTERFACE,
6844 .doit = nl80211_set_interface,
6845 .policy = nl80211_policy,
6846 .flags = GENL_ADMIN_PERM,
4c476991
JB
6847 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6848 NL80211_FLAG_NEED_RTNL,
55682965
JB
6849 },
6850 {
6851 .cmd = NL80211_CMD_NEW_INTERFACE,
6852 .doit = nl80211_new_interface,
6853 .policy = nl80211_policy,
6854 .flags = GENL_ADMIN_PERM,
4c476991
JB
6855 .internal_flags = NL80211_FLAG_NEED_WIPHY |
6856 NL80211_FLAG_NEED_RTNL,
55682965
JB
6857 },
6858 {
6859 .cmd = NL80211_CMD_DEL_INTERFACE,
6860 .doit = nl80211_del_interface,
6861 .policy = nl80211_policy,
41ade00f 6862 .flags = GENL_ADMIN_PERM,
4c476991
JB
6863 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6864 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6865 },
6866 {
6867 .cmd = NL80211_CMD_GET_KEY,
6868 .doit = nl80211_get_key,
6869 .policy = nl80211_policy,
6870 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6871 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6872 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6873 },
6874 {
6875 .cmd = NL80211_CMD_SET_KEY,
6876 .doit = nl80211_set_key,
6877 .policy = nl80211_policy,
6878 .flags = GENL_ADMIN_PERM,
41265714 6879 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6880 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6881 },
6882 {
6883 .cmd = NL80211_CMD_NEW_KEY,
6884 .doit = nl80211_new_key,
6885 .policy = nl80211_policy,
6886 .flags = GENL_ADMIN_PERM,
41265714 6887 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6888 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
6889 },
6890 {
6891 .cmd = NL80211_CMD_DEL_KEY,
6892 .doit = nl80211_del_key,
6893 .policy = nl80211_policy,
55682965 6894 .flags = GENL_ADMIN_PERM,
41265714 6895 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6896 NL80211_FLAG_NEED_RTNL,
55682965 6897 },
ed1b6cc7
JB
6898 {
6899 .cmd = NL80211_CMD_SET_BEACON,
6900 .policy = nl80211_policy,
6901 .flags = GENL_ADMIN_PERM,
8860020e 6902 .doit = nl80211_set_beacon,
2b5f8b0b 6903 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6904 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6905 },
6906 {
8860020e 6907 .cmd = NL80211_CMD_START_AP,
ed1b6cc7
JB
6908 .policy = nl80211_policy,
6909 .flags = GENL_ADMIN_PERM,
8860020e 6910 .doit = nl80211_start_ap,
2b5f8b0b 6911 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6912 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
6913 },
6914 {
8860020e 6915 .cmd = NL80211_CMD_STOP_AP,
ed1b6cc7
JB
6916 .policy = nl80211_policy,
6917 .flags = GENL_ADMIN_PERM,
8860020e 6918 .doit = nl80211_stop_ap,
2b5f8b0b 6919 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6920 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 6921 },
5727ef1b
JB
6922 {
6923 .cmd = NL80211_CMD_GET_STATION,
6924 .doit = nl80211_get_station,
2ec600d6 6925 .dumpit = nl80211_dump_station,
5727ef1b 6926 .policy = nl80211_policy,
4c476991
JB
6927 .internal_flags = NL80211_FLAG_NEED_NETDEV |
6928 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6929 },
6930 {
6931 .cmd = NL80211_CMD_SET_STATION,
6932 .doit = nl80211_set_station,
6933 .policy = nl80211_policy,
6934 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6935 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6936 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6937 },
6938 {
6939 .cmd = NL80211_CMD_NEW_STATION,
6940 .doit = nl80211_new_station,
6941 .policy = nl80211_policy,
6942 .flags = GENL_ADMIN_PERM,
41265714 6943 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6944 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
6945 },
6946 {
6947 .cmd = NL80211_CMD_DEL_STATION,
6948 .doit = nl80211_del_station,
6949 .policy = nl80211_policy,
2ec600d6 6950 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6951 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6952 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6953 },
6954 {
6955 .cmd = NL80211_CMD_GET_MPATH,
6956 .doit = nl80211_get_mpath,
6957 .dumpit = nl80211_dump_mpath,
6958 .policy = nl80211_policy,
6959 .flags = GENL_ADMIN_PERM,
41265714 6960 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6961 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6962 },
6963 {
6964 .cmd = NL80211_CMD_SET_MPATH,
6965 .doit = nl80211_set_mpath,
6966 .policy = nl80211_policy,
6967 .flags = GENL_ADMIN_PERM,
41265714 6968 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6969 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6970 },
6971 {
6972 .cmd = NL80211_CMD_NEW_MPATH,
6973 .doit = nl80211_new_mpath,
6974 .policy = nl80211_policy,
6975 .flags = GENL_ADMIN_PERM,
41265714 6976 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6977 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
6978 },
6979 {
6980 .cmd = NL80211_CMD_DEL_MPATH,
6981 .doit = nl80211_del_mpath,
6982 .policy = nl80211_policy,
9f1ba906 6983 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6984 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6985 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
6986 },
6987 {
6988 .cmd = NL80211_CMD_SET_BSS,
6989 .doit = nl80211_set_bss,
6990 .policy = nl80211_policy,
b2e1b302 6991 .flags = GENL_ADMIN_PERM,
2b5f8b0b 6992 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 6993 NL80211_FLAG_NEED_RTNL,
b2e1b302 6994 },
f130347c
LR
6995 {
6996 .cmd = NL80211_CMD_GET_REG,
6997 .doit = nl80211_get_reg,
6998 .policy = nl80211_policy,
6999 /* can be retrieved by unprivileged users */
7000 },
b2e1b302
LR
7001 {
7002 .cmd = NL80211_CMD_SET_REG,
7003 .doit = nl80211_set_reg,
7004 .policy = nl80211_policy,
7005 .flags = GENL_ADMIN_PERM,
7006 },
7007 {
7008 .cmd = NL80211_CMD_REQ_SET_REG,
7009 .doit = nl80211_req_set_reg,
7010 .policy = nl80211_policy,
93da9cc1 7011 .flags = GENL_ADMIN_PERM,
7012 },
7013 {
24bdd9f4
JC
7014 .cmd = NL80211_CMD_GET_MESH_CONFIG,
7015 .doit = nl80211_get_mesh_config,
93da9cc1 7016 .policy = nl80211_policy,
7017 /* can be retrieved by unprivileged users */
2b5f8b0b 7018 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7019 NL80211_FLAG_NEED_RTNL,
93da9cc1 7020 },
7021 {
24bdd9f4
JC
7022 .cmd = NL80211_CMD_SET_MESH_CONFIG,
7023 .doit = nl80211_update_mesh_config,
93da9cc1 7024 .policy = nl80211_policy,
9aed3cc1 7025 .flags = GENL_ADMIN_PERM,
29cbe68c 7026 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7027 NL80211_FLAG_NEED_RTNL,
9aed3cc1 7028 },
2a519311
JB
7029 {
7030 .cmd = NL80211_CMD_TRIGGER_SCAN,
7031 .doit = nl80211_trigger_scan,
7032 .policy = nl80211_policy,
7033 .flags = GENL_ADMIN_PERM,
41265714 7034 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7035 NL80211_FLAG_NEED_RTNL,
2a519311
JB
7036 },
7037 {
7038 .cmd = NL80211_CMD_GET_SCAN,
7039 .policy = nl80211_policy,
7040 .dumpit = nl80211_dump_scan,
7041 },
807f8a8c
LC
7042 {
7043 .cmd = NL80211_CMD_START_SCHED_SCAN,
7044 .doit = nl80211_start_sched_scan,
7045 .policy = nl80211_policy,
7046 .flags = GENL_ADMIN_PERM,
7047 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7048 NL80211_FLAG_NEED_RTNL,
7049 },
7050 {
7051 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
7052 .doit = nl80211_stop_sched_scan,
7053 .policy = nl80211_policy,
7054 .flags = GENL_ADMIN_PERM,
7055 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7056 NL80211_FLAG_NEED_RTNL,
7057 },
636a5d36
JM
7058 {
7059 .cmd = NL80211_CMD_AUTHENTICATE,
7060 .doit = nl80211_authenticate,
7061 .policy = nl80211_policy,
7062 .flags = GENL_ADMIN_PERM,
41265714 7063 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7064 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7065 },
7066 {
7067 .cmd = NL80211_CMD_ASSOCIATE,
7068 .doit = nl80211_associate,
7069 .policy = nl80211_policy,
7070 .flags = GENL_ADMIN_PERM,
41265714 7071 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7072 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7073 },
7074 {
7075 .cmd = NL80211_CMD_DEAUTHENTICATE,
7076 .doit = nl80211_deauthenticate,
7077 .policy = nl80211_policy,
7078 .flags = GENL_ADMIN_PERM,
41265714 7079 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7080 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
7081 },
7082 {
7083 .cmd = NL80211_CMD_DISASSOCIATE,
7084 .doit = nl80211_disassociate,
7085 .policy = nl80211_policy,
7086 .flags = GENL_ADMIN_PERM,
41265714 7087 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7088 NL80211_FLAG_NEED_RTNL,
636a5d36 7089 },
04a773ad
JB
7090 {
7091 .cmd = NL80211_CMD_JOIN_IBSS,
7092 .doit = nl80211_join_ibss,
7093 .policy = nl80211_policy,
7094 .flags = GENL_ADMIN_PERM,
41265714 7095 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7096 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
7097 },
7098 {
7099 .cmd = NL80211_CMD_LEAVE_IBSS,
7100 .doit = nl80211_leave_ibss,
7101 .policy = nl80211_policy,
7102 .flags = GENL_ADMIN_PERM,
41265714 7103 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7104 NL80211_FLAG_NEED_RTNL,
04a773ad 7105 },
aff89a9b
JB
7106#ifdef CONFIG_NL80211_TESTMODE
7107 {
7108 .cmd = NL80211_CMD_TESTMODE,
7109 .doit = nl80211_testmode_do,
71063f0e 7110 .dumpit = nl80211_testmode_dump,
aff89a9b
JB
7111 .policy = nl80211_policy,
7112 .flags = GENL_ADMIN_PERM,
4c476991
JB
7113 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7114 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
7115 },
7116#endif
b23aa676
SO
7117 {
7118 .cmd = NL80211_CMD_CONNECT,
7119 .doit = nl80211_connect,
7120 .policy = nl80211_policy,
7121 .flags = GENL_ADMIN_PERM,
41265714 7122 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7123 NL80211_FLAG_NEED_RTNL,
b23aa676
SO
7124 },
7125 {
7126 .cmd = NL80211_CMD_DISCONNECT,
7127 .doit = nl80211_disconnect,
7128 .policy = nl80211_policy,
7129 .flags = GENL_ADMIN_PERM,
41265714 7130 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7131 NL80211_FLAG_NEED_RTNL,
b23aa676 7132 },
463d0183
JB
7133 {
7134 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
7135 .doit = nl80211_wiphy_netns,
7136 .policy = nl80211_policy,
7137 .flags = GENL_ADMIN_PERM,
4c476991
JB
7138 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7139 NL80211_FLAG_NEED_RTNL,
463d0183 7140 },
61fa713c
HS
7141 {
7142 .cmd = NL80211_CMD_GET_SURVEY,
7143 .policy = nl80211_policy,
7144 .dumpit = nl80211_dump_survey,
7145 },
67fbb16b
SO
7146 {
7147 .cmd = NL80211_CMD_SET_PMKSA,
7148 .doit = nl80211_setdel_pmksa,
7149 .policy = nl80211_policy,
7150 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7151 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7152 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7153 },
7154 {
7155 .cmd = NL80211_CMD_DEL_PMKSA,
7156 .doit = nl80211_setdel_pmksa,
7157 .policy = nl80211_policy,
7158 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7159 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7160 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
7161 },
7162 {
7163 .cmd = NL80211_CMD_FLUSH_PMKSA,
7164 .doit = nl80211_flush_pmksa,
7165 .policy = nl80211_policy,
7166 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7167 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7168 NL80211_FLAG_NEED_RTNL,
67fbb16b 7169 },
9588bbd5
JM
7170 {
7171 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
7172 .doit = nl80211_remain_on_channel,
7173 .policy = nl80211_policy,
7174 .flags = GENL_ADMIN_PERM,
41265714 7175 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7176 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
7177 },
7178 {
7179 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
7180 .doit = nl80211_cancel_remain_on_channel,
7181 .policy = nl80211_policy,
7182 .flags = GENL_ADMIN_PERM,
41265714 7183 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7184 NL80211_FLAG_NEED_RTNL,
9588bbd5 7185 },
13ae75b1
JM
7186 {
7187 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
7188 .doit = nl80211_set_tx_bitrate_mask,
7189 .policy = nl80211_policy,
7190 .flags = GENL_ADMIN_PERM,
4c476991
JB
7191 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7192 NL80211_FLAG_NEED_RTNL,
13ae75b1 7193 },
026331c4 7194 {
2e161f78
JB
7195 .cmd = NL80211_CMD_REGISTER_FRAME,
7196 .doit = nl80211_register_mgmt,
026331c4
JM
7197 .policy = nl80211_policy,
7198 .flags = GENL_ADMIN_PERM,
4c476991
JB
7199 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7200 NL80211_FLAG_NEED_RTNL,
026331c4
JM
7201 },
7202 {
2e161f78
JB
7203 .cmd = NL80211_CMD_FRAME,
7204 .doit = nl80211_tx_mgmt,
026331c4 7205 .policy = nl80211_policy,
f7ca38df
JB
7206 .flags = GENL_ADMIN_PERM,
7207 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7208 NL80211_FLAG_NEED_RTNL,
7209 },
7210 {
7211 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
7212 .doit = nl80211_tx_mgmt_cancel_wait,
7213 .policy = nl80211_policy,
026331c4 7214 .flags = GENL_ADMIN_PERM,
41265714 7215 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 7216 NL80211_FLAG_NEED_RTNL,
026331c4 7217 },
ffb9eb3d
KV
7218 {
7219 .cmd = NL80211_CMD_SET_POWER_SAVE,
7220 .doit = nl80211_set_power_save,
7221 .policy = nl80211_policy,
7222 .flags = GENL_ADMIN_PERM,
4c476991
JB
7223 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7224 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
7225 },
7226 {
7227 .cmd = NL80211_CMD_GET_POWER_SAVE,
7228 .doit = nl80211_get_power_save,
7229 .policy = nl80211_policy,
7230 /* can be retrieved by unprivileged users */
4c476991
JB
7231 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7232 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 7233 },
d6dc1a38
JO
7234 {
7235 .cmd = NL80211_CMD_SET_CQM,
7236 .doit = nl80211_set_cqm,
7237 .policy = nl80211_policy,
7238 .flags = GENL_ADMIN_PERM,
4c476991
JB
7239 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7240 NL80211_FLAG_NEED_RTNL,
d6dc1a38 7241 },
f444de05
JB
7242 {
7243 .cmd = NL80211_CMD_SET_CHANNEL,
7244 .doit = nl80211_set_channel,
7245 .policy = nl80211_policy,
7246 .flags = GENL_ADMIN_PERM,
4c476991
JB
7247 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7248 NL80211_FLAG_NEED_RTNL,
f444de05 7249 },
e8347eba
BJ
7250 {
7251 .cmd = NL80211_CMD_SET_WDS_PEER,
7252 .doit = nl80211_set_wds_peer,
7253 .policy = nl80211_policy,
7254 .flags = GENL_ADMIN_PERM,
43b19952
JB
7255 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7256 NL80211_FLAG_NEED_RTNL,
e8347eba 7257 },
29cbe68c
JB
7258 {
7259 .cmd = NL80211_CMD_JOIN_MESH,
7260 .doit = nl80211_join_mesh,
7261 .policy = nl80211_policy,
7262 .flags = GENL_ADMIN_PERM,
7263 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7264 NL80211_FLAG_NEED_RTNL,
7265 },
7266 {
7267 .cmd = NL80211_CMD_LEAVE_MESH,
7268 .doit = nl80211_leave_mesh,
7269 .policy = nl80211_policy,
7270 .flags = GENL_ADMIN_PERM,
7271 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7272 NL80211_FLAG_NEED_RTNL,
7273 },
dfb89c56 7274#ifdef CONFIG_PM
ff1b6e69
JB
7275 {
7276 .cmd = NL80211_CMD_GET_WOWLAN,
7277 .doit = nl80211_get_wowlan,
7278 .policy = nl80211_policy,
7279 /* can be retrieved by unprivileged users */
7280 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7281 NL80211_FLAG_NEED_RTNL,
7282 },
7283 {
7284 .cmd = NL80211_CMD_SET_WOWLAN,
7285 .doit = nl80211_set_wowlan,
7286 .policy = nl80211_policy,
7287 .flags = GENL_ADMIN_PERM,
7288 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7289 NL80211_FLAG_NEED_RTNL,
7290 },
dfb89c56 7291#endif
e5497d76
JB
7292 {
7293 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
7294 .doit = nl80211_set_rekey_data,
7295 .policy = nl80211_policy,
7296 .flags = GENL_ADMIN_PERM,
7297 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7298 NL80211_FLAG_NEED_RTNL,
7299 },
109086ce
AN
7300 {
7301 .cmd = NL80211_CMD_TDLS_MGMT,
7302 .doit = nl80211_tdls_mgmt,
7303 .policy = nl80211_policy,
7304 .flags = GENL_ADMIN_PERM,
7305 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7306 NL80211_FLAG_NEED_RTNL,
7307 },
7308 {
7309 .cmd = NL80211_CMD_TDLS_OPER,
7310 .doit = nl80211_tdls_oper,
7311 .policy = nl80211_policy,
7312 .flags = GENL_ADMIN_PERM,
7313 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7314 NL80211_FLAG_NEED_RTNL,
7315 },
28946da7
JB
7316 {
7317 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
7318 .doit = nl80211_register_unexpected_frame,
7319 .policy = nl80211_policy,
7320 .flags = GENL_ADMIN_PERM,
7321 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7322 NL80211_FLAG_NEED_RTNL,
7323 },
7f6cf311
JB
7324 {
7325 .cmd = NL80211_CMD_PROBE_CLIENT,
7326 .doit = nl80211_probe_client,
7327 .policy = nl80211_policy,
7328 .flags = GENL_ADMIN_PERM,
2b5f8b0b 7329 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
7330 NL80211_FLAG_NEED_RTNL,
7331 },
5e760230
JB
7332 {
7333 .cmd = NL80211_CMD_REGISTER_BEACONS,
7334 .doit = nl80211_register_beacons,
7335 .policy = nl80211_policy,
7336 .flags = GENL_ADMIN_PERM,
7337 .internal_flags = NL80211_FLAG_NEED_WIPHY |
7338 NL80211_FLAG_NEED_RTNL,
7339 },
1d9d9213
SW
7340 {
7341 .cmd = NL80211_CMD_SET_NOACK_MAP,
7342 .doit = nl80211_set_noack_map,
7343 .policy = nl80211_policy,
7344 .flags = GENL_ADMIN_PERM,
7345 .internal_flags = NL80211_FLAG_NEED_NETDEV |
7346 NL80211_FLAG_NEED_RTNL,
7347 },
7348
55682965 7349};
9588bbd5 7350
6039f6d2
JM
7351static struct genl_multicast_group nl80211_mlme_mcgrp = {
7352 .name = "mlme",
7353};
55682965
JB
7354
7355/* multicast groups */
7356static struct genl_multicast_group nl80211_config_mcgrp = {
7357 .name = "config",
7358};
2a519311
JB
7359static struct genl_multicast_group nl80211_scan_mcgrp = {
7360 .name = "scan",
7361};
73d54c9e
LR
7362static struct genl_multicast_group nl80211_regulatory_mcgrp = {
7363 .name = "regulatory",
7364};
55682965
JB
7365
7366/* notification functions */
7367
7368void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
7369{
7370 struct sk_buff *msg;
7371
fd2120ca 7372 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
7373 if (!msg)
7374 return;
7375
7376 if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
7377 nlmsg_free(msg);
7378 return;
7379 }
7380
463d0183
JB
7381 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7382 nl80211_config_mcgrp.id, GFP_KERNEL);
55682965
JB
7383}
7384
362a415d
JB
7385static int nl80211_add_scan_req(struct sk_buff *msg,
7386 struct cfg80211_registered_device *rdev)
7387{
7388 struct cfg80211_scan_request *req = rdev->scan_req;
7389 struct nlattr *nest;
7390 int i;
7391
667503dd
JB
7392 ASSERT_RDEV_LOCK(rdev);
7393
362a415d
JB
7394 if (WARN_ON(!req))
7395 return 0;
7396
7397 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
7398 if (!nest)
7399 goto nla_put_failure;
9360ffd1
DM
7400 for (i = 0; i < req->n_ssids; i++) {
7401 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
7402 goto nla_put_failure;
7403 }
362a415d
JB
7404 nla_nest_end(msg, nest);
7405
7406 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
7407 if (!nest)
7408 goto nla_put_failure;
9360ffd1
DM
7409 for (i = 0; i < req->n_channels; i++) {
7410 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
7411 goto nla_put_failure;
7412 }
362a415d
JB
7413 nla_nest_end(msg, nest);
7414
9360ffd1
DM
7415 if (req->ie &&
7416 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
7417 goto nla_put_failure;
362a415d
JB
7418
7419 return 0;
7420 nla_put_failure:
7421 return -ENOBUFS;
7422}
7423
a538e2d5
JB
7424static int nl80211_send_scan_msg(struct sk_buff *msg,
7425 struct cfg80211_registered_device *rdev,
7426 struct net_device *netdev,
7427 u32 pid, u32 seq, int flags,
7428 u32 cmd)
2a519311
JB
7429{
7430 void *hdr;
7431
7432 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
7433 if (!hdr)
7434 return -1;
7435
9360ffd1
DM
7436 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7437 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7438 goto nla_put_failure;
2a519311 7439
362a415d
JB
7440 /* ignore errors and send incomplete event anyway */
7441 nl80211_add_scan_req(msg, rdev);
2a519311
JB
7442
7443 return genlmsg_end(msg, hdr);
7444
7445 nla_put_failure:
7446 genlmsg_cancel(msg, hdr);
7447 return -EMSGSIZE;
7448}
7449
807f8a8c
LC
7450static int
7451nl80211_send_sched_scan_msg(struct sk_buff *msg,
7452 struct cfg80211_registered_device *rdev,
7453 struct net_device *netdev,
7454 u32 pid, u32 seq, int flags, u32 cmd)
7455{
7456 void *hdr;
7457
7458 hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
7459 if (!hdr)
7460 return -1;
7461
9360ffd1
DM
7462 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7463 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
7464 goto nla_put_failure;
807f8a8c
LC
7465
7466 return genlmsg_end(msg, hdr);
7467
7468 nla_put_failure:
7469 genlmsg_cancel(msg, hdr);
7470 return -EMSGSIZE;
7471}
7472
a538e2d5
JB
7473void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
7474 struct net_device *netdev)
7475{
7476 struct sk_buff *msg;
7477
7478 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7479 if (!msg)
7480 return;
7481
7482 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7483 NL80211_CMD_TRIGGER_SCAN) < 0) {
7484 nlmsg_free(msg);
7485 return;
7486 }
7487
463d0183
JB
7488 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7489 nl80211_scan_mcgrp.id, GFP_KERNEL);
a538e2d5
JB
7490}
7491
2a519311
JB
7492void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
7493 struct net_device *netdev)
7494{
7495 struct sk_buff *msg;
7496
fd2120ca 7497 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7498 if (!msg)
7499 return;
7500
a538e2d5
JB
7501 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7502 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311
JB
7503 nlmsg_free(msg);
7504 return;
7505 }
7506
463d0183
JB
7507 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7508 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7509}
7510
7511void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
7512 struct net_device *netdev)
7513{
7514 struct sk_buff *msg;
7515
fd2120ca 7516 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311
JB
7517 if (!msg)
7518 return;
7519
a538e2d5
JB
7520 if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
7521 NL80211_CMD_SCAN_ABORTED) < 0) {
2a519311
JB
7522 nlmsg_free(msg);
7523 return;
7524 }
7525
463d0183
JB
7526 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7527 nl80211_scan_mcgrp.id, GFP_KERNEL);
2a519311
JB
7528}
7529
807f8a8c
LC
7530void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev,
7531 struct net_device *netdev)
7532{
7533 struct sk_buff *msg;
7534
7535 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7536 if (!msg)
7537 return;
7538
7539 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0,
7540 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) {
7541 nlmsg_free(msg);
7542 return;
7543 }
7544
7545 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7546 nl80211_scan_mcgrp.id, GFP_KERNEL);
7547}
7548
7549void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev,
7550 struct net_device *netdev, u32 cmd)
7551{
7552 struct sk_buff *msg;
7553
7554 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
7555 if (!msg)
7556 return;
7557
7558 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) {
7559 nlmsg_free(msg);
7560 return;
7561 }
7562
7563 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7564 nl80211_scan_mcgrp.id, GFP_KERNEL);
7565}
7566
73d54c9e
LR
7567/*
7568 * This can happen on global regulatory changes or device specific settings
7569 * based on custom world regulatory domains.
7570 */
7571void nl80211_send_reg_change_event(struct regulatory_request *request)
7572{
7573 struct sk_buff *msg;
7574 void *hdr;
7575
fd2120ca 7576 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
73d54c9e
LR
7577 if (!msg)
7578 return;
7579
7580 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
7581 if (!hdr) {
7582 nlmsg_free(msg);
7583 return;
7584 }
7585
7586 /* Userspace can always count this one always being set */
9360ffd1
DM
7587 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
7588 goto nla_put_failure;
7589
7590 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
7591 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7592 NL80211_REGDOM_TYPE_WORLD))
7593 goto nla_put_failure;
7594 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
7595 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7596 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
7597 goto nla_put_failure;
7598 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
7599 request->intersect) {
7600 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7601 NL80211_REGDOM_TYPE_INTERSECTION))
7602 goto nla_put_failure;
7603 } else {
7604 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
7605 NL80211_REGDOM_TYPE_COUNTRY) ||
7606 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
7607 request->alpha2))
7608 goto nla_put_failure;
7609 }
7610
7611 if (wiphy_idx_valid(request->wiphy_idx) &&
7612 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
7613 goto nla_put_failure;
73d54c9e 7614
3b7b72ee 7615 genlmsg_end(msg, hdr);
73d54c9e 7616
bc43b28c 7617 rcu_read_lock();
463d0183 7618 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
bc43b28c
JB
7619 GFP_ATOMIC);
7620 rcu_read_unlock();
73d54c9e
LR
7621
7622 return;
7623
7624nla_put_failure:
7625 genlmsg_cancel(msg, hdr);
7626 nlmsg_free(msg);
7627}
7628
6039f6d2
JM
7629static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
7630 struct net_device *netdev,
7631 const u8 *buf, size_t len,
e6d6e342 7632 enum nl80211_commands cmd, gfp_t gfp)
6039f6d2
JM
7633{
7634 struct sk_buff *msg;
7635 void *hdr;
7636
e6d6e342 7637 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
6039f6d2
JM
7638 if (!msg)
7639 return;
7640
7641 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7642 if (!hdr) {
7643 nlmsg_free(msg);
7644 return;
7645 }
7646
9360ffd1
DM
7647 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7648 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7649 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
7650 goto nla_put_failure;
6039f6d2 7651
3b7b72ee 7652 genlmsg_end(msg, hdr);
6039f6d2 7653
463d0183
JB
7654 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7655 nl80211_mlme_mcgrp.id, gfp);
6039f6d2
JM
7656 return;
7657
7658 nla_put_failure:
7659 genlmsg_cancel(msg, hdr);
7660 nlmsg_free(msg);
7661}
7662
7663void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7664 struct net_device *netdev, const u8 *buf,
7665 size_t len, gfp_t gfp)
6039f6d2
JM
7666{
7667 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7668 NL80211_CMD_AUTHENTICATE, gfp);
6039f6d2
JM
7669}
7670
7671void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
7672 struct net_device *netdev, const u8 *buf,
e6d6e342 7673 size_t len, gfp_t gfp)
6039f6d2 7674{
e6d6e342
JB
7675 nl80211_send_mlme_event(rdev, netdev, buf, len,
7676 NL80211_CMD_ASSOCIATE, gfp);
6039f6d2
JM
7677}
7678
53b46b84 7679void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7680 struct net_device *netdev, const u8 *buf,
7681 size_t len, gfp_t gfp)
6039f6d2
JM
7682{
7683 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7684 NL80211_CMD_DEAUTHENTICATE, gfp);
6039f6d2
JM
7685}
7686
53b46b84
JM
7687void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
7688 struct net_device *netdev, const u8 *buf,
e6d6e342 7689 size_t len, gfp_t gfp)
6039f6d2
JM
7690{
7691 nl80211_send_mlme_event(rdev, netdev, buf, len,
e6d6e342 7692 NL80211_CMD_DISASSOCIATE, gfp);
6039f6d2
JM
7693}
7694
cf4e594e
JM
7695void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
7696 struct net_device *netdev, const u8 *buf,
7697 size_t len, gfp_t gfp)
7698{
7699 nl80211_send_mlme_event(rdev, netdev, buf, len,
7700 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
7701}
7702
7703void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
7704 struct net_device *netdev, const u8 *buf,
7705 size_t len, gfp_t gfp)
7706{
7707 nl80211_send_mlme_event(rdev, netdev, buf, len,
7708 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
7709}
7710
1b06bb40
LR
7711static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
7712 struct net_device *netdev, int cmd,
e6d6e342 7713 const u8 *addr, gfp_t gfp)
1965c853
JM
7714{
7715 struct sk_buff *msg;
7716 void *hdr;
7717
e6d6e342 7718 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
7719 if (!msg)
7720 return;
7721
7722 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
7723 if (!hdr) {
7724 nlmsg_free(msg);
7725 return;
7726 }
7727
9360ffd1
DM
7728 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7729 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7730 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
7731 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
7732 goto nla_put_failure;
1965c853 7733
3b7b72ee 7734 genlmsg_end(msg, hdr);
1965c853 7735
463d0183
JB
7736 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7737 nl80211_mlme_mcgrp.id, gfp);
1965c853
JM
7738 return;
7739
7740 nla_put_failure:
7741 genlmsg_cancel(msg, hdr);
7742 nlmsg_free(msg);
7743}
7744
7745void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7746 struct net_device *netdev, const u8 *addr,
7747 gfp_t gfp)
1965c853
JM
7748{
7749 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 7750 addr, gfp);
1965c853
JM
7751}
7752
7753void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
7754 struct net_device *netdev, const u8 *addr,
7755 gfp_t gfp)
1965c853 7756{
e6d6e342
JB
7757 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
7758 addr, gfp);
1965c853
JM
7759}
7760
b23aa676
SO
7761void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
7762 struct net_device *netdev, const u8 *bssid,
7763 const u8 *req_ie, size_t req_ie_len,
7764 const u8 *resp_ie, size_t resp_ie_len,
7765 u16 status, gfp_t gfp)
7766{
7767 struct sk_buff *msg;
7768 void *hdr;
7769
7770 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7771 if (!msg)
7772 return;
7773
7774 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
7775 if (!hdr) {
7776 nlmsg_free(msg);
7777 return;
7778 }
7779
9360ffd1
DM
7780 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7781 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7782 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) ||
7783 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, status) ||
7784 (req_ie &&
7785 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
7786 (resp_ie &&
7787 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
7788 goto nla_put_failure;
b23aa676 7789
3b7b72ee 7790 genlmsg_end(msg, hdr);
b23aa676 7791
463d0183
JB
7792 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7793 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7794 return;
7795
7796 nla_put_failure:
7797 genlmsg_cancel(msg, hdr);
7798 nlmsg_free(msg);
7799
7800}
7801
7802void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
7803 struct net_device *netdev, const u8 *bssid,
7804 const u8 *req_ie, size_t req_ie_len,
7805 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
7806{
7807 struct sk_buff *msg;
7808 void *hdr;
7809
7810 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
7811 if (!msg)
7812 return;
7813
7814 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
7815 if (!hdr) {
7816 nlmsg_free(msg);
7817 return;
7818 }
7819
9360ffd1
DM
7820 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7821 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7822 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
7823 (req_ie &&
7824 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) ||
7825 (resp_ie &&
7826 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie)))
7827 goto nla_put_failure;
b23aa676 7828
3b7b72ee 7829 genlmsg_end(msg, hdr);
b23aa676 7830
463d0183
JB
7831 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7832 nl80211_mlme_mcgrp.id, gfp);
b23aa676
SO
7833 return;
7834
7835 nla_put_failure:
7836 genlmsg_cancel(msg, hdr);
7837 nlmsg_free(msg);
7838
7839}
7840
7841void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
7842 struct net_device *netdev, u16 reason,
667503dd 7843 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
7844{
7845 struct sk_buff *msg;
7846 void *hdr;
7847
667503dd 7848 msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
b23aa676
SO
7849 if (!msg)
7850 return;
7851
7852 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
7853 if (!hdr) {
7854 nlmsg_free(msg);
7855 return;
7856 }
7857
9360ffd1
DM
7858 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7859 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7860 (from_ap && reason &&
7861 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
7862 (from_ap &&
7863 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
7864 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
7865 goto nla_put_failure;
b23aa676 7866
3b7b72ee 7867 genlmsg_end(msg, hdr);
b23aa676 7868
463d0183
JB
7869 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7870 nl80211_mlme_mcgrp.id, GFP_KERNEL);
b23aa676
SO
7871 return;
7872
7873 nla_put_failure:
7874 genlmsg_cancel(msg, hdr);
7875 nlmsg_free(msg);
7876
7877}
7878
04a773ad
JB
7879void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
7880 struct net_device *netdev, const u8 *bssid,
7881 gfp_t gfp)
7882{
7883 struct sk_buff *msg;
7884 void *hdr;
7885
fd2120ca 7886 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
7887 if (!msg)
7888 return;
7889
7890 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
7891 if (!hdr) {
7892 nlmsg_free(msg);
7893 return;
7894 }
7895
9360ffd1
DM
7896 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7897 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7898 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
7899 goto nla_put_failure;
04a773ad 7900
3b7b72ee 7901 genlmsg_end(msg, hdr);
04a773ad 7902
463d0183
JB
7903 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7904 nl80211_mlme_mcgrp.id, gfp);
04a773ad
JB
7905 return;
7906
7907 nla_put_failure:
7908 genlmsg_cancel(msg, hdr);
7909 nlmsg_free(msg);
7910}
7911
c93b5e71
JC
7912void nl80211_send_new_peer_candidate(struct cfg80211_registered_device *rdev,
7913 struct net_device *netdev,
7914 const u8 *macaddr, const u8* ie, u8 ie_len,
7915 gfp_t gfp)
7916{
7917 struct sk_buff *msg;
7918 void *hdr;
7919
7920 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7921 if (!msg)
7922 return;
7923
7924 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
7925 if (!hdr) {
7926 nlmsg_free(msg);
7927 return;
7928 }
7929
9360ffd1
DM
7930 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7931 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7932 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, macaddr) ||
7933 (ie_len && ie &&
7934 nla_put(msg, NL80211_ATTR_IE, ie_len , ie)))
7935 goto nla_put_failure;
c93b5e71 7936
3b7b72ee 7937 genlmsg_end(msg, hdr);
c93b5e71
JC
7938
7939 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7940 nl80211_mlme_mcgrp.id, gfp);
7941 return;
7942
7943 nla_put_failure:
7944 genlmsg_cancel(msg, hdr);
7945 nlmsg_free(msg);
7946}
7947
a3b8b056
JM
7948void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
7949 struct net_device *netdev, const u8 *addr,
7950 enum nl80211_key_type key_type, int key_id,
e6d6e342 7951 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
7952{
7953 struct sk_buff *msg;
7954 void *hdr;
7955
e6d6e342 7956 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
7957 if (!msg)
7958 return;
7959
7960 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
7961 if (!hdr) {
7962 nlmsg_free(msg);
7963 return;
7964 }
7965
9360ffd1
DM
7966 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
7967 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
7968 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
7969 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
7970 (key_id != -1 &&
7971 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
7972 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
7973 goto nla_put_failure;
a3b8b056 7974
3b7b72ee 7975 genlmsg_end(msg, hdr);
a3b8b056 7976
463d0183
JB
7977 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
7978 nl80211_mlme_mcgrp.id, gfp);
a3b8b056
JM
7979 return;
7980
7981 nla_put_failure:
7982 genlmsg_cancel(msg, hdr);
7983 nlmsg_free(msg);
7984}
7985
6bad8766
LR
7986void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
7987 struct ieee80211_channel *channel_before,
7988 struct ieee80211_channel *channel_after)
7989{
7990 struct sk_buff *msg;
7991 void *hdr;
7992 struct nlattr *nl_freq;
7993
fd2120ca 7994 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
7995 if (!msg)
7996 return;
7997
7998 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
7999 if (!hdr) {
8000 nlmsg_free(msg);
8001 return;
8002 }
8003
8004 /*
8005 * Since we are applying the beacon hint to a wiphy we know its
8006 * wiphy_idx is valid
8007 */
9360ffd1
DM
8008 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
8009 goto nla_put_failure;
6bad8766
LR
8010
8011 /* Before */
8012 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
8013 if (!nl_freq)
8014 goto nla_put_failure;
8015 if (nl80211_msg_put_channel(msg, channel_before))
8016 goto nla_put_failure;
8017 nla_nest_end(msg, nl_freq);
8018
8019 /* After */
8020 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
8021 if (!nl_freq)
8022 goto nla_put_failure;
8023 if (nl80211_msg_put_channel(msg, channel_after))
8024 goto nla_put_failure;
8025 nla_nest_end(msg, nl_freq);
8026
3b7b72ee 8027 genlmsg_end(msg, hdr);
6bad8766 8028
463d0183
JB
8029 rcu_read_lock();
8030 genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
8031 GFP_ATOMIC);
8032 rcu_read_unlock();
6bad8766
LR
8033
8034 return;
8035
8036nla_put_failure:
8037 genlmsg_cancel(msg, hdr);
8038 nlmsg_free(msg);
8039}
8040
9588bbd5
JM
8041static void nl80211_send_remain_on_chan_event(
8042 int cmd, struct cfg80211_registered_device *rdev,
8043 struct net_device *netdev, u64 cookie,
8044 struct ieee80211_channel *chan,
8045 enum nl80211_channel_type channel_type,
8046 unsigned int duration, gfp_t gfp)
8047{
8048 struct sk_buff *msg;
8049 void *hdr;
8050
8051 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8052 if (!msg)
8053 return;
8054
8055 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
8056 if (!hdr) {
8057 nlmsg_free(msg);
8058 return;
8059 }
8060
9360ffd1
DM
8061 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8062 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8063 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
8064 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type) ||
8065 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie))
8066 goto nla_put_failure;
9588bbd5 8067
9360ffd1
DM
8068 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
8069 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
8070 goto nla_put_failure;
9588bbd5 8071
3b7b72ee 8072 genlmsg_end(msg, hdr);
9588bbd5
JM
8073
8074 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8075 nl80211_mlme_mcgrp.id, gfp);
8076 return;
8077
8078 nla_put_failure:
8079 genlmsg_cancel(msg, hdr);
8080 nlmsg_free(msg);
8081}
8082
8083void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
8084 struct net_device *netdev, u64 cookie,
8085 struct ieee80211_channel *chan,
8086 enum nl80211_channel_type channel_type,
8087 unsigned int duration, gfp_t gfp)
8088{
8089 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
8090 rdev, netdev, cookie, chan,
8091 channel_type, duration, gfp);
8092}
8093
8094void nl80211_send_remain_on_channel_cancel(
8095 struct cfg80211_registered_device *rdev, struct net_device *netdev,
8096 u64 cookie, struct ieee80211_channel *chan,
8097 enum nl80211_channel_type channel_type, gfp_t gfp)
8098{
8099 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
8100 rdev, netdev, cookie, chan,
8101 channel_type, 0, gfp);
8102}
8103
98b62183
JB
8104void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
8105 struct net_device *dev, const u8 *mac_addr,
8106 struct station_info *sinfo, gfp_t gfp)
8107{
8108 struct sk_buff *msg;
8109
8110 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8111 if (!msg)
8112 return;
8113
66266b3a
JL
8114 if (nl80211_send_station(msg, 0, 0, 0,
8115 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
8116 nlmsg_free(msg);
8117 return;
8118 }
8119
8120 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8121 nl80211_mlme_mcgrp.id, gfp);
8122}
8123
ec15e68b
JM
8124void nl80211_send_sta_del_event(struct cfg80211_registered_device *rdev,
8125 struct net_device *dev, const u8 *mac_addr,
8126 gfp_t gfp)
8127{
8128 struct sk_buff *msg;
8129 void *hdr;
8130
8131 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8132 if (!msg)
8133 return;
8134
8135 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_STATION);
8136 if (!hdr) {
8137 nlmsg_free(msg);
8138 return;
8139 }
8140
9360ffd1
DM
8141 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8142 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
8143 goto nla_put_failure;
ec15e68b 8144
3b7b72ee 8145 genlmsg_end(msg, hdr);
ec15e68b
JM
8146
8147 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8148 nl80211_mlme_mcgrp.id, gfp);
8149 return;
8150
8151 nla_put_failure:
8152 genlmsg_cancel(msg, hdr);
8153 nlmsg_free(msg);
8154}
8155
b92ab5d8
JB
8156static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
8157 const u8 *addr, gfp_t gfp)
28946da7
JB
8158{
8159 struct wireless_dev *wdev = dev->ieee80211_ptr;
8160 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8161 struct sk_buff *msg;
8162 void *hdr;
8163 int err;
8164 u32 nlpid = ACCESS_ONCE(wdev->ap_unexpected_nlpid);
8165
8166 if (!nlpid)
8167 return false;
8168
8169 msg = nlmsg_new(100, gfp);
8170 if (!msg)
8171 return true;
8172
b92ab5d8 8173 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
8174 if (!hdr) {
8175 nlmsg_free(msg);
8176 return true;
8177 }
8178
9360ffd1
DM
8179 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8180 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8181 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
8182 goto nla_put_failure;
28946da7
JB
8183
8184 err = genlmsg_end(msg, hdr);
8185 if (err < 0) {
8186 nlmsg_free(msg);
8187 return true;
8188 }
8189
8190 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
8191 return true;
8192
8193 nla_put_failure:
8194 genlmsg_cancel(msg, hdr);
8195 nlmsg_free(msg);
8196 return true;
8197}
8198
b92ab5d8
JB
8199bool nl80211_unexpected_frame(struct net_device *dev, const u8 *addr, gfp_t gfp)
8200{
8201 return __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
8202 addr, gfp);
8203}
8204
8205bool nl80211_unexpected_4addr_frame(struct net_device *dev,
8206 const u8 *addr, gfp_t gfp)
8207{
8208 return __nl80211_unexpected_frame(dev,
8209 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
8210 addr, gfp);
8211}
8212
2e161f78
JB
8213int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
8214 struct net_device *netdev, u32 nlpid,
804483e9
JB
8215 int freq, int sig_dbm,
8216 const u8 *buf, size_t len, gfp_t gfp)
026331c4
JM
8217{
8218 struct sk_buff *msg;
8219 void *hdr;
026331c4
JM
8220
8221 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8222 if (!msg)
8223 return -ENOMEM;
8224
2e161f78 8225 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
8226 if (!hdr) {
8227 nlmsg_free(msg);
8228 return -ENOMEM;
8229 }
8230
9360ffd1
DM
8231 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8232 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8233 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8234 (sig_dbm &&
8235 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8236 nla_put(msg, NL80211_ATTR_FRAME, len, buf))
8237 goto nla_put_failure;
026331c4 8238
3b7b72ee 8239 genlmsg_end(msg, hdr);
026331c4 8240
3b7b72ee 8241 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
026331c4
JM
8242
8243 nla_put_failure:
8244 genlmsg_cancel(msg, hdr);
8245 nlmsg_free(msg);
8246 return -ENOBUFS;
8247}
8248
2e161f78
JB
8249void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
8250 struct net_device *netdev, u64 cookie,
8251 const u8 *buf, size_t len, bool ack,
8252 gfp_t gfp)
026331c4
JM
8253{
8254 struct sk_buff *msg;
8255 void *hdr;
8256
8257 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
8258 if (!msg)
8259 return;
8260
2e161f78 8261 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
026331c4
JM
8262 if (!hdr) {
8263 nlmsg_free(msg);
8264 return;
8265 }
8266
9360ffd1
DM
8267 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8268 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8269 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
8270 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8271 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
8272 goto nla_put_failure;
026331c4 8273
3b7b72ee 8274 genlmsg_end(msg, hdr);
026331c4
JM
8275
8276 genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
8277 return;
8278
8279 nla_put_failure:
8280 genlmsg_cancel(msg, hdr);
8281 nlmsg_free(msg);
8282}
8283
d6dc1a38
JO
8284void
8285nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
8286 struct net_device *netdev,
8287 enum nl80211_cqm_rssi_threshold_event rssi_event,
8288 gfp_t gfp)
8289{
8290 struct sk_buff *msg;
8291 struct nlattr *pinfoattr;
8292 void *hdr;
8293
8294 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8295 if (!msg)
8296 return;
8297
8298 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8299 if (!hdr) {
8300 nlmsg_free(msg);
8301 return;
8302 }
8303
9360ffd1
DM
8304 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8305 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8306 goto nla_put_failure;
d6dc1a38
JO
8307
8308 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8309 if (!pinfoattr)
8310 goto nla_put_failure;
8311
9360ffd1
DM
8312 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
8313 rssi_event))
8314 goto nla_put_failure;
d6dc1a38
JO
8315
8316 nla_nest_end(msg, pinfoattr);
8317
3b7b72ee 8318 genlmsg_end(msg, hdr);
d6dc1a38
JO
8319
8320 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8321 nl80211_mlme_mcgrp.id, gfp);
8322 return;
8323
8324 nla_put_failure:
8325 genlmsg_cancel(msg, hdr);
8326 nlmsg_free(msg);
8327}
8328
e5497d76
JB
8329void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
8330 struct net_device *netdev, const u8 *bssid,
8331 const u8 *replay_ctr, gfp_t gfp)
8332{
8333 struct sk_buff *msg;
8334 struct nlattr *rekey_attr;
8335 void *hdr;
8336
8337 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8338 if (!msg)
8339 return;
8340
8341 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
8342 if (!hdr) {
8343 nlmsg_free(msg);
8344 return;
8345 }
8346
9360ffd1
DM
8347 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8348 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8349 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
8350 goto nla_put_failure;
e5497d76
JB
8351
8352 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA);
8353 if (!rekey_attr)
8354 goto nla_put_failure;
8355
9360ffd1
DM
8356 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
8357 NL80211_REPLAY_CTR_LEN, replay_ctr))
8358 goto nla_put_failure;
e5497d76
JB
8359
8360 nla_nest_end(msg, rekey_attr);
8361
3b7b72ee 8362 genlmsg_end(msg, hdr);
e5497d76
JB
8363
8364 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8365 nl80211_mlme_mcgrp.id, gfp);
8366 return;
8367
8368 nla_put_failure:
8369 genlmsg_cancel(msg, hdr);
8370 nlmsg_free(msg);
8371}
8372
c9df56b4
JM
8373void nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
8374 struct net_device *netdev, int index,
8375 const u8 *bssid, bool preauth, gfp_t gfp)
8376{
8377 struct sk_buff *msg;
8378 struct nlattr *attr;
8379 void *hdr;
8380
8381 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8382 if (!msg)
8383 return;
8384
8385 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
8386 if (!hdr) {
8387 nlmsg_free(msg);
8388 return;
8389 }
8390
9360ffd1
DM
8391 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8392 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
8393 goto nla_put_failure;
c9df56b4
JM
8394
8395 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE);
8396 if (!attr)
8397 goto nla_put_failure;
8398
9360ffd1
DM
8399 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
8400 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
8401 (preauth &&
8402 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
8403 goto nla_put_failure;
c9df56b4
JM
8404
8405 nla_nest_end(msg, attr);
8406
3b7b72ee 8407 genlmsg_end(msg, hdr);
c9df56b4
JM
8408
8409 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8410 nl80211_mlme_mcgrp.id, gfp);
8411 return;
8412
8413 nla_put_failure:
8414 genlmsg_cancel(msg, hdr);
8415 nlmsg_free(msg);
8416}
8417
5314526b
TP
8418void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
8419 struct net_device *netdev, int freq,
8420 enum nl80211_channel_type type, gfp_t gfp)
8421{
8422 struct sk_buff *msg;
8423 void *hdr;
8424
8425 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8426 if (!msg)
8427 return;
8428
8429 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CH_SWITCH_NOTIFY);
8430 if (!hdr) {
8431 nlmsg_free(msg);
8432 return;
8433 }
8434
7eab0f64
JL
8435 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8436 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) ||
8437 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, type))
8438 goto nla_put_failure;
5314526b
TP
8439
8440 genlmsg_end(msg, hdr);
8441
8442 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8443 nl80211_mlme_mcgrp.id, gfp);
8444 return;
8445
8446 nla_put_failure:
8447 genlmsg_cancel(msg, hdr);
8448 nlmsg_free(msg);
8449}
8450
c063dbf5
JB
8451void
8452nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
8453 struct net_device *netdev, const u8 *peer,
8454 u32 num_packets, gfp_t gfp)
8455{
8456 struct sk_buff *msg;
8457 struct nlattr *pinfoattr;
8458 void *hdr;
8459
8460 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8461 if (!msg)
8462 return;
8463
8464 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
8465 if (!hdr) {
8466 nlmsg_free(msg);
8467 return;
8468 }
8469
9360ffd1
DM
8470 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8471 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
8472 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer))
8473 goto nla_put_failure;
c063dbf5
JB
8474
8475 pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
8476 if (!pinfoattr)
8477 goto nla_put_failure;
8478
9360ffd1
DM
8479 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
8480 goto nla_put_failure;
c063dbf5
JB
8481
8482 nla_nest_end(msg, pinfoattr);
8483
3b7b72ee 8484 genlmsg_end(msg, hdr);
c063dbf5
JB
8485
8486 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8487 nl80211_mlme_mcgrp.id, gfp);
8488 return;
8489
8490 nla_put_failure:
8491 genlmsg_cancel(msg, hdr);
8492 nlmsg_free(msg);
8493}
8494
7f6cf311
JB
8495void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
8496 u64 cookie, bool acked, gfp_t gfp)
8497{
8498 struct wireless_dev *wdev = dev->ieee80211_ptr;
8499 struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
8500 struct sk_buff *msg;
8501 void *hdr;
8502 int err;
8503
8504 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
8505 if (!msg)
8506 return;
8507
8508 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
8509 if (!hdr) {
8510 nlmsg_free(msg);
8511 return;
8512 }
8513
9360ffd1
DM
8514 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8515 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
8516 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
8517 nla_put_u64(msg, NL80211_ATTR_COOKIE, cookie) ||
8518 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)))
8519 goto nla_put_failure;
7f6cf311
JB
8520
8521 err = genlmsg_end(msg, hdr);
8522 if (err < 0) {
8523 nlmsg_free(msg);
8524 return;
8525 }
8526
8527 genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
8528 nl80211_mlme_mcgrp.id, gfp);
8529 return;
8530
8531 nla_put_failure:
8532 genlmsg_cancel(msg, hdr);
8533 nlmsg_free(msg);
8534}
8535EXPORT_SYMBOL(cfg80211_probe_status);
8536
5e760230
JB
8537void cfg80211_report_obss_beacon(struct wiphy *wiphy,
8538 const u8 *frame, size_t len,
804483e9 8539 int freq, int sig_dbm, gfp_t gfp)
5e760230
JB
8540{
8541 struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
8542 struct sk_buff *msg;
8543 void *hdr;
8544 u32 nlpid = ACCESS_ONCE(rdev->ap_beacons_nlpid);
8545
8546 if (!nlpid)
8547 return;
8548
8549 msg = nlmsg_new(len + 100, gfp);
8550 if (!msg)
8551 return;
8552
8553 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
8554 if (!hdr) {
8555 nlmsg_free(msg);
8556 return;
8557 }
8558
9360ffd1
DM
8559 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
8560 (freq &&
8561 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) ||
8562 (sig_dbm &&
8563 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
8564 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
8565 goto nla_put_failure;
5e760230
JB
8566
8567 genlmsg_end(msg, hdr);
8568
8569 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
8570 return;
8571
8572 nla_put_failure:
8573 genlmsg_cancel(msg, hdr);
8574 nlmsg_free(msg);
8575}
8576EXPORT_SYMBOL(cfg80211_report_obss_beacon);
8577
026331c4
JM
8578static int nl80211_netlink_notify(struct notifier_block * nb,
8579 unsigned long state,
8580 void *_notify)
8581{
8582 struct netlink_notify *notify = _notify;
8583 struct cfg80211_registered_device *rdev;
8584 struct wireless_dev *wdev;
8585
8586 if (state != NETLINK_URELEASE)
8587 return NOTIFY_DONE;
8588
8589 rcu_read_lock();
8590
5e760230 8591 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
89a54e48 8592 list_for_each_entry_rcu(wdev, &rdev->wdev_list, list)
2e161f78 8593 cfg80211_mlme_unregister_socket(wdev, notify->pid);
5e760230
JB
8594 if (rdev->ap_beacons_nlpid == notify->pid)
8595 rdev->ap_beacons_nlpid = 0;
8596 }
026331c4
JM
8597
8598 rcu_read_unlock();
8599
8600 return NOTIFY_DONE;
8601}
8602
8603static struct notifier_block nl80211_netlink_notifier = {
8604 .notifier_call = nl80211_netlink_notify,
8605};
8606
55682965
JB
8607/* initialisation/exit functions */
8608
8609int nl80211_init(void)
8610{
0d63cbb5 8611 int err;
55682965 8612
0d63cbb5
MM
8613 err = genl_register_family_with_ops(&nl80211_fam,
8614 nl80211_ops, ARRAY_SIZE(nl80211_ops));
55682965
JB
8615 if (err)
8616 return err;
8617
55682965
JB
8618 err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
8619 if (err)
8620 goto err_out;
8621
2a519311
JB
8622 err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
8623 if (err)
8624 goto err_out;
8625
73d54c9e
LR
8626 err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
8627 if (err)
8628 goto err_out;
8629
6039f6d2
JM
8630 err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
8631 if (err)
8632 goto err_out;
8633
aff89a9b
JB
8634#ifdef CONFIG_NL80211_TESTMODE
8635 err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
8636 if (err)
8637 goto err_out;
8638#endif
8639
026331c4
JM
8640 err = netlink_register_notifier(&nl80211_netlink_notifier);
8641 if (err)
8642 goto err_out;
8643
55682965
JB
8644 return 0;
8645 err_out:
8646 genl_unregister_family(&nl80211_fam);
8647 return err;
8648}
8649
8650void nl80211_exit(void)
8651{
026331c4 8652 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
8653 genl_unregister_family(&nl80211_fam);
8654}