nl80211: add support for setting fixed HE rate/gi/ltf
[linux-block.git] / net / wireless / nl80211.c
CommitLineData
457c8996 1// SPDX-License-Identifier: GPL-2.0-only
55682965
JB
2/*
3 * This is the new netlink-based wireless configuration interface.
4 *
026331c4 5 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net>
2740f0cf 6 * Copyright 2013-2014 Intel Mobile Communications GmbH
66cd794e 7 * Copyright 2015-2017 Intel Deutschland GmbH
7e8d6f12 8 * Copyright (C) 2018-2020 Intel Corporation
55682965
JB
9 */
10
11#include <linux/if.h>
12#include <linux/module.h>
13#include <linux/err.h>
5a0e3ad6 14#include <linux/slab.h>
55682965
JB
15#include <linux/list.h>
16#include <linux/if_ether.h>
17#include <linux/ieee80211.h>
18#include <linux/nl80211.h>
19#include <linux/rtnetlink.h>
20#include <linux/netlink.h>
259d8c1e 21#include <linux/nospec.h>
2a519311 22#include <linux/etherdevice.h>
e3ae39ed 23#include <linux/if_vlan.h>
463d0183 24#include <net/net_namespace.h>
55682965
JB
25#include <net/genetlink.h>
26#include <net/cfg80211.h>
463d0183 27#include <net/sock.h>
2a0e047e 28#include <net/inet_connection_sock.h>
55682965
JB
29#include "core.h"
30#include "nl80211.h"
b2e1b302 31#include "reg.h"
e35e4d28 32#include "rdev-ops.h"
55682965 33
5fb628e9
JM
34static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
35 struct genl_info *info,
36 struct cfg80211_crypto_settings *settings,
37 int cipher_limit);
38
55682965 39/* the netlink family */
489111e5 40static struct genl_family nl80211_fam;
55682965 41
2a94fe48
JB
42/* multicast groups */
43enum nl80211_multicast_groups {
44 NL80211_MCGRP_CONFIG,
45 NL80211_MCGRP_SCAN,
46 NL80211_MCGRP_REGULATORY,
47 NL80211_MCGRP_MLME,
567ffc35 48 NL80211_MCGRP_VENDOR,
50bcd31d 49 NL80211_MCGRP_NAN,
2a94fe48
JB
50 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */
51};
52
53static const struct genl_multicast_group nl80211_mcgrps[] = {
71b836ec
JB
54 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG },
55 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN },
56 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG },
57 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME },
58 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR },
50bcd31d 59 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN },
2a94fe48 60#ifdef CONFIG_NL80211_TESTMODE
71b836ec 61 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE }
2a94fe48
JB
62#endif
63};
64
89a54e48
JB
65/* returns ERR_PTR values */
66static struct wireless_dev *
67__cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs)
55682965 68{
89a54e48
JB
69 struct cfg80211_registered_device *rdev;
70 struct wireless_dev *result = NULL;
71 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX];
72 bool have_wdev_id = attrs[NL80211_ATTR_WDEV];
73 u64 wdev_id;
74 int wiphy_idx = -1;
75 int ifidx = -1;
55682965 76
5fe231e8 77 ASSERT_RTNL();
55682965 78
89a54e48
JB
79 if (!have_ifidx && !have_wdev_id)
80 return ERR_PTR(-EINVAL);
55682965 81
89a54e48
JB
82 if (have_ifidx)
83 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
84 if (have_wdev_id) {
85 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
86 wiphy_idx = wdev_id >> 32;
55682965
JB
87 }
88
89a54e48
JB
89 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
90 struct wireless_dev *wdev;
91
92 if (wiphy_net(&rdev->wiphy) != netns)
93 continue;
94
95 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx)
96 continue;
97
53873f13 98 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
89a54e48
JB
99 if (have_ifidx && wdev->netdev &&
100 wdev->netdev->ifindex == ifidx) {
101 result = wdev;
102 break;
103 }
104 if (have_wdev_id && wdev->identifier == (u32)wdev_id) {
105 result = wdev;
106 break;
107 }
108 }
89a54e48
JB
109
110 if (result)
111 break;
112 }
113
114 if (result)
115 return result;
116 return ERR_PTR(-ENODEV);
55682965
JB
117}
118
a9455408 119static struct cfg80211_registered_device *
878d9ec7 120__cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs)
a9455408 121{
7fee4778
JB
122 struct cfg80211_registered_device *rdev = NULL, *tmp;
123 struct net_device *netdev;
a9455408 124
5fe231e8 125 ASSERT_RTNL();
a9455408 126
878d9ec7 127 if (!attrs[NL80211_ATTR_WIPHY] &&
89a54e48
JB
128 !attrs[NL80211_ATTR_IFINDEX] &&
129 !attrs[NL80211_ATTR_WDEV])
7fee4778
JB
130 return ERR_PTR(-EINVAL);
131
878d9ec7 132 if (attrs[NL80211_ATTR_WIPHY])
7fee4778 133 rdev = cfg80211_rdev_by_wiphy_idx(
878d9ec7 134 nla_get_u32(attrs[NL80211_ATTR_WIPHY]));
a9455408 135
89a54e48
JB
136 if (attrs[NL80211_ATTR_WDEV]) {
137 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]);
138 struct wireless_dev *wdev;
139 bool found = false;
140
141 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32);
142 if (tmp) {
143 /* make sure wdev exists */
53873f13 144 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) {
89a54e48
JB
145 if (wdev->identifier != (u32)wdev_id)
146 continue;
147 found = true;
148 break;
149 }
89a54e48
JB
150
151 if (!found)
152 tmp = NULL;
153
154 if (rdev && tmp != rdev)
155 return ERR_PTR(-EINVAL);
156 rdev = tmp;
157 }
158 }
159
878d9ec7
JB
160 if (attrs[NL80211_ATTR_IFINDEX]) {
161 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
7a087e74 162
7f2b8562 163 netdev = __dev_get_by_index(netns, ifindex);
7fee4778
JB
164 if (netdev) {
165 if (netdev->ieee80211_ptr)
f26cbf40
ZG
166 tmp = wiphy_to_rdev(
167 netdev->ieee80211_ptr->wiphy);
7fee4778
JB
168 else
169 tmp = NULL;
170
7fee4778
JB
171 /* not wireless device -- return error */
172 if (!tmp)
173 return ERR_PTR(-EINVAL);
174
175 /* mismatch -- return error */
176 if (rdev && tmp != rdev)
177 return ERR_PTR(-EINVAL);
178
179 rdev = tmp;
a9455408 180 }
a9455408 181 }
a9455408 182
4f7eff10
JB
183 if (!rdev)
184 return ERR_PTR(-ENODEV);
a9455408 185
4f7eff10
JB
186 if (netns != wiphy_net(&rdev->wiphy))
187 return ERR_PTR(-ENODEV);
188
189 return rdev;
a9455408
JB
190}
191
192/*
193 * This function returns a pointer to the driver
194 * that the genl_info item that is passed refers to.
a9455408
JB
195 *
196 * The result of this can be a PTR_ERR and hence must
197 * be checked with IS_ERR() for errors.
198 */
199static struct cfg80211_registered_device *
4f7eff10 200cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info)
a9455408 201{
5fe231e8 202 return __cfg80211_rdev_from_attrs(netns, info->attrs);
a9455408
JB
203}
204
f88eb7c0
JB
205static int validate_beacon_head(const struct nlattr *attr,
206 struct netlink_ext_ack *extack)
207{
208 const u8 *data = nla_data(attr);
209 unsigned int len = nla_len(attr);
210 const struct element *elem;
211 const struct ieee80211_mgmt *mgmt = (void *)data;
212 unsigned int fixedlen = offsetof(struct ieee80211_mgmt,
213 u.beacon.variable);
214
215 if (len < fixedlen)
216 goto err;
217
218 if (ieee80211_hdrlen(mgmt->frame_control) !=
219 offsetof(struct ieee80211_mgmt, u.beacon))
220 goto err;
221
222 data += fixedlen;
223 len -= fixedlen;
224
225 for_each_element(elem, data, len) {
226 /* nothing */
227 }
228
229 if (for_each_element_completed(elem, data, len))
230 return 0;
231
232err:
233 NL_SET_ERR_MSG_ATTR(extack, attr, "malformed beacon head");
234 return -EINVAL;
235}
236
3d7af878
JB
237static int validate_ie_attr(const struct nlattr *attr,
238 struct netlink_ext_ack *extack)
239{
9f308616
JB
240 const u8 *data = nla_data(attr);
241 unsigned int len = nla_len(attr);
7388afe0 242 const struct element *elem;
3d7af878 243
9f308616
JB
244 for_each_element(elem, data, len) {
245 /* nothing */
3d7af878
JB
246 }
247
9f308616
JB
248 if (for_each_element_completed(elem, data, len))
249 return 0;
250
3d7af878
JB
251 NL_SET_ERR_MSG_ATTR(extack, attr, "malformed information elements");
252 return -EINVAL;
253}
254
55682965 255/* policy for the attributes */
d15da2a2
JB
256static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR];
257
81e54d08
PKC
258static const struct nla_policy
259nl80211_ftm_responder_policy[NL80211_FTM_RESP_ATTR_MAX + 1] = {
260 [NL80211_FTM_RESP_ATTR_ENABLED] = { .type = NLA_FLAG, },
261 [NL80211_FTM_RESP_ATTR_LCI] = { .type = NLA_BINARY,
262 .len = U8_MAX },
263 [NL80211_FTM_RESP_ATTR_CIVICLOC] = { .type = NLA_BINARY,
264 .len = U8_MAX },
265};
266
9bb7e0f2
JB
267static const struct nla_policy
268nl80211_pmsr_ftm_req_attr_policy[NL80211_PMSR_FTM_REQ_ATTR_MAX + 1] = {
269 [NL80211_PMSR_FTM_REQ_ATTR_ASAP] = { .type = NLA_FLAG },
270 [NL80211_PMSR_FTM_REQ_ATTR_PREAMBLE] = { .type = NLA_U32 },
271 [NL80211_PMSR_FTM_REQ_ATTR_NUM_BURSTS_EXP] =
272 NLA_POLICY_MAX(NLA_U8, 15),
273 [NL80211_PMSR_FTM_REQ_ATTR_BURST_PERIOD] = { .type = NLA_U16 },
274 [NL80211_PMSR_FTM_REQ_ATTR_BURST_DURATION] =
275 NLA_POLICY_MAX(NLA_U8, 15),
276 [NL80211_PMSR_FTM_REQ_ATTR_FTMS_PER_BURST] =
ea18709a 277 NLA_POLICY_MAX(NLA_U8, 31),
9bb7e0f2
JB
278 [NL80211_PMSR_FTM_REQ_ATTR_NUM_FTMR_RETRIES] = { .type = NLA_U8 },
279 [NL80211_PMSR_FTM_REQ_ATTR_REQUEST_LCI] = { .type = NLA_FLAG },
280 [NL80211_PMSR_FTM_REQ_ATTR_REQUEST_CIVICLOC] = { .type = NLA_FLAG },
efb5520d
AS
281 [NL80211_PMSR_FTM_REQ_ATTR_TRIGGER_BASED] = { .type = NLA_FLAG },
282 [NL80211_PMSR_FTM_REQ_ATTR_NON_TRIGGER_BASED] = { .type = NLA_FLAG },
9bb7e0f2
JB
283};
284
285static const struct nla_policy
286nl80211_pmsr_req_data_policy[NL80211_PMSR_TYPE_MAX + 1] = {
287 [NL80211_PMSR_TYPE_FTM] =
23323289 288 NLA_POLICY_NESTED(nl80211_pmsr_ftm_req_attr_policy),
9bb7e0f2
JB
289};
290
291static const struct nla_policy
292nl80211_pmsr_req_attr_policy[NL80211_PMSR_REQ_ATTR_MAX + 1] = {
293 [NL80211_PMSR_REQ_ATTR_DATA] =
23323289 294 NLA_POLICY_NESTED(nl80211_pmsr_req_data_policy),
9bb7e0f2
JB
295 [NL80211_PMSR_REQ_ATTR_GET_AP_TSF] = { .type = NLA_FLAG },
296};
297
298static const struct nla_policy
299nl80211_psmr_peer_attr_policy[NL80211_PMSR_PEER_ATTR_MAX + 1] = {
300 [NL80211_PMSR_PEER_ATTR_ADDR] = NLA_POLICY_ETH_ADDR,
d15da2a2 301 [NL80211_PMSR_PEER_ATTR_CHAN] = NLA_POLICY_NESTED(nl80211_policy),
9bb7e0f2 302 [NL80211_PMSR_PEER_ATTR_REQ] =
23323289 303 NLA_POLICY_NESTED(nl80211_pmsr_req_attr_policy),
9bb7e0f2
JB
304 [NL80211_PMSR_PEER_ATTR_RESP] = { .type = NLA_REJECT },
305};
306
307static const struct nla_policy
308nl80211_pmsr_attr_policy[NL80211_PMSR_ATTR_MAX + 1] = {
309 [NL80211_PMSR_ATTR_MAX_PEERS] = { .type = NLA_REJECT },
310 [NL80211_PMSR_ATTR_REPORT_AP_TSF] = { .type = NLA_REJECT },
311 [NL80211_PMSR_ATTR_RANDOMIZE_MAC_ADDR] = { .type = NLA_REJECT },
312 [NL80211_PMSR_ATTR_TYPE_CAPA] = { .type = NLA_REJECT },
313 [NL80211_PMSR_ATTR_PEERS] =
23323289 314 NLA_POLICY_NESTED_ARRAY(nl80211_psmr_peer_attr_policy),
9bb7e0f2
JB
315};
316
796e90f4
JC
317static const struct nla_policy
318he_obss_pd_policy[NL80211_HE_OBSS_PD_ATTR_MAX + 1] = {
319 [NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET] =
320 NLA_POLICY_RANGE(NLA_U8, 1, 20),
321 [NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET] =
322 NLA_POLICY_RANGE(NLA_U8, 1, 20),
323};
324
5c5e52d1
JC
325static const struct nla_policy
326he_bss_color_policy[NL80211_HE_BSS_COLOR_ATTR_MAX + 1] = {
327 [NL80211_HE_BSS_COLOR_ATTR_COLOR] = NLA_POLICY_RANGE(NLA_U8, 1, 63),
328 [NL80211_HE_BSS_COLOR_ATTR_DISABLED] = { .type = NLA_FLAG },
329 [NL80211_HE_BSS_COLOR_ATTR_PARTIAL] = { .type = NLA_FLAG },
330};
331
9a5f6488
TC
332static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
333 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
334 .len = NL80211_MAX_SUPP_RATES },
335 [NL80211_TXRATE_HT] = { .type = NLA_BINARY,
336 .len = NL80211_MAX_SUPP_HT_RATES },
337 [NL80211_TXRATE_VHT] = NLA_POLICY_EXACT_LEN_WARN(sizeof(struct nl80211_txrate_vht)),
338 [NL80211_TXRATE_GI] = { .type = NLA_U8 },
eb89a6a6
MH
339 [NL80211_TXRATE_HE] = NLA_POLICY_EXACT_LEN(sizeof(struct nl80211_txrate_he)),
340 [NL80211_TXRATE_HE_GI] = NLA_POLICY_RANGE(NLA_U8,
341 NL80211_RATE_INFO_HE_GI_0_8,
342 NL80211_RATE_INFO_HE_GI_3_2),
343 [NL80211_TXRATE_HE_LTF] = NLA_POLICY_RANGE(NLA_U8,
344 NL80211_RATE_INFO_HE_1XLTF,
345 NL80211_RATE_INFO_HE_4XLTF),
9a5f6488
TC
346};
347
77f576de
T
348static const struct nla_policy
349nl80211_tid_config_attr_policy[NL80211_TID_CONFIG_ATTR_MAX + 1] = {
3710a8a6
JB
350 [NL80211_TID_CONFIG_ATTR_VIF_SUPP] = { .type = NLA_U64 },
351 [NL80211_TID_CONFIG_ATTR_PEER_SUPP] = { .type = NLA_U64 },
77f576de 352 [NL80211_TID_CONFIG_ATTR_OVERRIDE] = { .type = NLA_FLAG },
3710a8a6 353 [NL80211_TID_CONFIG_ATTR_TIDS] = NLA_POLICY_RANGE(NLA_U16, 1, 0xff),
77f576de
T
354 [NL80211_TID_CONFIG_ATTR_NOACK] =
355 NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
6a21d16c
T
356 [NL80211_TID_CONFIG_ATTR_RETRY_SHORT] = NLA_POLICY_MIN(NLA_U8, 1),
357 [NL80211_TID_CONFIG_ATTR_RETRY_LONG] = NLA_POLICY_MIN(NLA_U8, 1),
ade274b2
T
358 [NL80211_TID_CONFIG_ATTR_AMPDU_CTRL] =
359 NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
04f7d142
T
360 [NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL] =
361 NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
33462e68
SM
362 [NL80211_TID_CONFIG_ATTR_AMSDU_CTRL] =
363 NLA_POLICY_MAX(NLA_U8, NL80211_TID_CONFIG_DISABLE),
9a5f6488
TC
364 [NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE] =
365 NLA_POLICY_MAX(NLA_U8, NL80211_TX_RATE_FIXED),
366 [NL80211_TID_CONFIG_ATTR_TX_RATE] =
367 NLA_POLICY_NESTED(nl80211_txattr_policy),
77f576de
T
368};
369
d15da2a2 370static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = {
6d4dd4ef 371 [0] = { .strict_start_type = NL80211_ATTR_HE_OBSS_PD },
55682965
JB
372 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
373 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
079e24ed 374 .len = 20-1 },
31888487 375 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
3d9d1d66 376
72bdcf34 377 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
094d05dc 378 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
2a38075c
AAL
379 [NL80211_ATTR_WIPHY_EDMG_CHANNELS] = NLA_POLICY_RANGE(NLA_U8,
380 NL80211_EDMG_CHANNELS_MIN,
381 NL80211_EDMG_CHANNELS_MAX),
382 [NL80211_ATTR_WIPHY_EDMG_BW_CONFIG] = NLA_POLICY_RANGE(NLA_U8,
383 NL80211_EDMG_BW_CONFIG_MIN,
384 NL80211_EDMG_BW_CONFIG_MAX),
385
3d9d1d66
JB
386 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 },
387 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 },
942ba88b 388 [NL80211_ATTR_CENTER_FREQ1_OFFSET] = NLA_POLICY_RANGE(NLA_U32, 0, 999),
3d9d1d66
JB
389 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 },
390
ab0d76f6
JB
391 [NL80211_ATTR_WIPHY_RETRY_SHORT] = NLA_POLICY_MIN(NLA_U8, 1),
392 [NL80211_ATTR_WIPHY_RETRY_LONG] = NLA_POLICY_MIN(NLA_U8, 1),
b9a5f8ca
JM
393 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
394 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
81077e82 395 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
3057dbfd 396 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG },
55682965 397
ab0d76f6 398 [NL80211_ATTR_IFTYPE] = NLA_POLICY_MAX(NLA_U32, NL80211_IFTYPE_MAX),
55682965
JB
399 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
400 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
41ade00f 401
c7721c05
JB
402 [NL80211_ATTR_MAC] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
403 [NL80211_ATTR_PREV_BSSID] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
41ade00f 404
b9454e83 405 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
41ade00f
JB
406 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
407 .len = WLAN_MAX_KEY_LEN },
56be393f 408 [NL80211_ATTR_KEY_IDX] = NLA_POLICY_MAX(NLA_U8, 7),
41ade00f
JB
409 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
410 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
81962267 411 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
ab0d76f6
JB
412 [NL80211_ATTR_KEY_TYPE] =
413 NLA_POLICY_MAX(NLA_U32, NUM_NL80211_KEYTYPES),
ed1b6cc7
JB
414
415 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
416 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
f88eb7c0
JB
417 [NL80211_ATTR_BEACON_HEAD] =
418 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_beacon_head,
419 IEEE80211_MAX_DATA_LEN),
3d7af878
JB
420 [NL80211_ATTR_BEACON_TAIL] =
421 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
422 IEEE80211_MAX_DATA_LEN),
ab0d76f6
JB
423 [NL80211_ATTR_STA_AID] =
424 NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
5727ef1b
JB
425 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
426 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
427 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
428 .len = NL80211_MAX_SUPP_RATES },
ab0d76f6
JB
429 [NL80211_ATTR_STA_PLINK_ACTION] =
430 NLA_POLICY_MAX(NLA_U8, NUM_NL80211_PLINK_ACTIONS - 1),
e96d1cd2
ARN
431 [NL80211_ATTR_STA_TX_POWER_SETTING] =
432 NLA_POLICY_RANGE(NLA_U8,
433 NL80211_TX_POWER_AUTOMATIC,
434 NL80211_TX_POWER_FIXED),
435 [NL80211_ATTR_STA_TX_POWER] = { .type = NLA_S16 },
5727ef1b 436 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
0a9542ee 437 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
2ec600d6 438 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
a4f606ea 439 .len = IEEE80211_MAX_MESH_ID_LEN },
1fab1b89 440 [NL80211_ATTR_MPATH_NEXT_HOP] = NLA_POLICY_ETH_ADDR_COMPAT,
9f1ba906 441
b2e1b302
LR
442 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
443 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
444
9f1ba906
JM
445 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
446 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
447 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
90c97a04
JM
448 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
449 .len = NL80211_MAX_SUPP_RATES },
50b12f59 450 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
36aedc90 451
24bdd9f4 452 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
15d5dda6 453 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG },
93da9cc1 454
c7721c05 455 [NL80211_ATTR_HT_CAPABILITY] = NLA_POLICY_EXACT_LEN_WARN(NL80211_HT_CAPABILITY_LEN),
9aed3cc1
JM
456
457 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
3d7af878
JB
458 [NL80211_ATTR_IE] = NLA_POLICY_VALIDATE_FN(NLA_BINARY,
459 validate_ie_attr,
460 IEEE80211_MAX_DATA_LEN),
2a519311
JB
461 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
462 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
636a5d36
JM
463
464 [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
465 .len = IEEE80211_MAX_SSID_LEN },
466 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
467 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
04a773ad 468 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
1965c853 469 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
ab0d76f6
JB
470 [NL80211_ATTR_USE_MFP] = NLA_POLICY_RANGE(NLA_U32,
471 NL80211_MFP_NO,
472 NL80211_MFP_OPTIONAL),
eccb8e8f
JB
473 [NL80211_ATTR_STA_FLAGS2] = {
474 .len = sizeof(struct nl80211_sta_flag_update),
475 },
3f77316c 476 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
c0692b8f
JB
477 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
478 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
64bf3d4b 479 [NL80211_ATTR_CONTROL_PORT_OVER_NL80211] = { .type = NLA_FLAG },
b23aa676 480 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
ea750801 481 [NL80211_ATTR_STATUS_CODE] = { .type = NLA_U16 },
b23aa676
SO
482 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
483 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
463d0183 484 [NL80211_ATTR_PID] = { .type = NLA_U32 },
8b787643 485 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
c7721c05 486 [NL80211_ATTR_PMKID] = NLA_POLICY_EXACT_LEN_WARN(WLAN_PMKID_LEN),
9588bbd5
JM
487 [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
488 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
13ae75b1 489 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
026331c4
JM
490 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
491 .len = IEEE80211_MAX_DATA_LEN },
492 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
ab0d76f6
JB
493 [NL80211_ATTR_PS_STATE] = NLA_POLICY_RANGE(NLA_U32,
494 NL80211_PS_DISABLED,
495 NL80211_PS_ENABLED),
d6dc1a38 496 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
d5cdfacb 497 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
fd8aaaf3 498 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
98d2ff8b
JO
499 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
500 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
2e161f78 501 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
afe0cbf8
BR
502 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
503 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
885a46d0 504 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
f7ca38df 505 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
dbd2fd65 506 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
ff1b6e69 507 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED },
ab0d76f6
JB
508 [NL80211_ATTR_STA_PLINK_STATE] =
509 NLA_POLICY_MAX(NLA_U8, NUM_NL80211_PLINK_STATES - 1),
056e9375
JK
510 [NL80211_ATTR_MEASUREMENT_DURATION] = { .type = NLA_U16 },
511 [NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY] = { .type = NLA_FLAG },
ab0d76f6
JB
512 [NL80211_ATTR_MESH_PEER_AID] =
513 NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
bbe6ad6d 514 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 },
e5497d76 515 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED },
34850ab2 516 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED },
ab0d76f6
JB
517 [NL80211_ATTR_HIDDEN_SSID] =
518 NLA_POLICY_RANGE(NLA_U32,
519 NL80211_HIDDEN_SSID_NOT_IN_USE,
520 NL80211_HIDDEN_SSID_ZERO_CONTENTS),
3d7af878
JB
521 [NL80211_ATTR_IE_PROBE_RESP] =
522 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
523 IEEE80211_MAX_DATA_LEN),
524 [NL80211_ATTR_IE_ASSOC_RESP] =
525 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
526 IEEE80211_MAX_DATA_LEN),
f4b34b55 527 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG },
a1f1c21c 528 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED },
e9f935e3 529 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG },
109086ce
AN
530 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 },
531 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 },
532 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 },
533 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG },
534 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG },
31fa97c5 535 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG },
e247bd90 536 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG },
00f740e1
AN
537 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY,
538 .len = IEEE80211_MAX_DATA_LEN },
8b60b078 539 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 },
7e7c8926
BG
540 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG },
541 [NL80211_ATTR_HT_CAPABILITY_MASK] = {
542 .len = NL80211_HT_CAPABILITY_LEN
543 },
1d9d9213 544 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 },
1b658f11 545 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 },
4486ea98 546 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 },
89a54e48 547 [NL80211_ATTR_WDEV] = { .type = NLA_U64 },
57b5ce07 548 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 },
cb9abd48
JB
549
550 /* need to include at least Auth Transaction and Status Code */
551 [NL80211_ATTR_AUTH_DATA] = NLA_POLICY_MIN_LEN(4),
552
c7721c05 553 [NL80211_ATTR_VHT_CAPABILITY] = NLA_POLICY_EXACT_LEN_WARN(NL80211_VHT_CAPABILITY_LEN),
ed473771 554 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 },
ab0d76f6
JB
555 [NL80211_ATTR_P2P_CTWINDOW] = NLA_POLICY_MAX(NLA_U8, 127),
556 [NL80211_ATTR_P2P_OPPPS] = NLA_POLICY_MAX(NLA_U8, 1),
557 [NL80211_ATTR_LOCAL_MESH_POWER_MODE] =
558 NLA_POLICY_RANGE(NLA_U32,
559 NL80211_MESH_POWER_UNKNOWN + 1,
560 NL80211_MESH_POWER_MAX),
77765eaf
VT
561 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 },
562 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED },
9d62a986
JM
563 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 },
564 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, },
3713b4e3 565 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, },
ee2aca34
JB
566 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG },
567 [NL80211_ATTR_VHT_CAPABILITY_MASK] = {
568 .len = NL80211_VHT_CAPABILITY_LEN,
569 },
355199e0
JM
570 [NL80211_ATTR_MDID] = { .type = NLA_U16 },
571 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY,
572 .len = IEEE80211_MAX_DATA_LEN },
0e1a1d85 573 [NL80211_ATTR_CRIT_PROT_ID] = { .type = NLA_U16 },
cb9abd48
JB
574 [NL80211_ATTR_MAX_CRIT_PROT_DURATION] =
575 NLA_POLICY_MAX(NLA_U16, NL80211_CRIT_PROTO_MAX_DURATION),
ab0d76f6
JB
576 [NL80211_ATTR_PEER_AID] =
577 NLA_POLICY_RANGE(NLA_U16, 1, IEEE80211_MAX_AID),
16ef1fe2
SW
578 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 },
579 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG },
580 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED },
9a774c78
AO
581 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY },
582 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY },
cb9abd48 583 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = NLA_POLICY_MIN_LEN(2),
c8b82802
JB
584 /*
585 * The value of the Length field of the Supported Operating
586 * Classes element is between 2 and 253.
587 */
588 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] =
589 NLA_POLICY_RANGE(NLA_BINARY, 2, 253),
5336fa88 590 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG },
60f4a7b1 591 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 },
ad7e718c
JB
592 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 },
593 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 },
594 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY },
c8b82802
JB
595 [NL80211_ATTR_QOS_MAP] = NLA_POLICY_RANGE(NLA_BINARY,
596 IEEE80211_QOS_MAP_LEN_MIN,
597 IEEE80211_QOS_MAP_LEN_MAX),
c7721c05 598 [NL80211_ATTR_MAC_HINT] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
1df4a510 599 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 },
df942e7b 600 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 },
18e5ca65 601 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG },
34d22ce2 602 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY },
bab5ab7d 603 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG },
ab0d76f6
JB
604 [NL80211_ATTR_TSID] = NLA_POLICY_MAX(NLA_U8, IEEE80211_NUM_TIDS - 1),
605 [NL80211_ATTR_USER_PRIO] =
606 NLA_POLICY_MAX(NLA_U8, IEEE80211_NUM_UPS - 1),
960d01ac 607 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 },
18998c38 608 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 },
5cde05c6 609 [NL80211_ATTR_OPER_CLASS] = { .type = NLA_U8 },
c7721c05 610 [NL80211_ATTR_MAC_MASK] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
1bdd716c 611 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG },
4b681c82 612 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 },
9c748934 613 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 },
05050753 614 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG },
34d50519 615 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG },
38de03d2 616 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED },
ab0d76f6
JB
617 [NL80211_ATTR_STA_SUPPORT_P2P_PS] =
618 NLA_POLICY_MAX(NLA_U8, NUM_NL80211_P2P_PS_STATUS - 1),
c6e6a0c8
AE
619 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = {
620 .len = VHT_MUMIMO_GROUPS_DATA_LEN
621 },
c7721c05 622 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
ab0d76f6 623 [NL80211_ATTR_NAN_MASTER_PREF] = NLA_POLICY_MIN(NLA_U8, 1),
8585989d 624 [NL80211_ATTR_BANDS] = { .type = NLA_U32 },
a442b761 625 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED },
348bd456
JM
626 [NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY,
627 .len = FILS_MAX_KEK_LEN },
c7721c05 628 [NL80211_ATTR_FILS_NONCES] = NLA_POLICY_EXACT_LEN_WARN(2 * FILS_NONCE_LEN),
ce0ce13a 629 [NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, },
c7721c05 630 [NL80211_ATTR_BSSID] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
bf95ecdb 631 [NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] = { .type = NLA_S8 },
632 [NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST] = {
633 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
634 },
3093ebbe 635 [NL80211_ATTR_TIMEOUT_REASON] = { .type = NLA_U32 },
a3caf744
VK
636 [NL80211_ATTR_FILS_ERP_USERNAME] = { .type = NLA_BINARY,
637 .len = FILS_ERP_MAX_USERNAME_LEN },
638 [NL80211_ATTR_FILS_ERP_REALM] = { .type = NLA_BINARY,
639 .len = FILS_ERP_MAX_REALM_LEN },
640 [NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] = { .type = NLA_U16 },
641 [NL80211_ATTR_FILS_ERP_RRK] = { .type = NLA_BINARY,
642 .len = FILS_ERP_MAX_RRK_LEN },
c7721c05 643 [NL80211_ATTR_FILS_CACHE_ID] = NLA_POLICY_EXACT_LEN_WARN(2),
a3caf744 644 [NL80211_ATTR_PMK] = { .type = NLA_BINARY, .len = PMK_MAX_LEN },
cb9abd48 645 [NL80211_ATTR_PMKR0_NAME] = NLA_POLICY_EXACT_LEN(WLAN_PMK_NAME_LEN),
ca986ad9 646 [NL80211_ATTR_SCHED_SCAN_MULTI] = { .type = NLA_FLAG },
40cbfa90 647 [NL80211_ATTR_EXTERNAL_AUTH_SUPPORT] = { .type = NLA_FLAG },
52539ca8
THJ
648
649 [NL80211_ATTR_TXQ_LIMIT] = { .type = NLA_U32 },
650 [NL80211_ATTR_TXQ_MEMORY_LIMIT] = { .type = NLA_U32 },
651 [NL80211_ATTR_TXQ_QUANTUM] = { .type = NLA_U32 },
c8b82802
JB
652 [NL80211_ATTR_HE_CAPABILITY] =
653 NLA_POLICY_RANGE(NLA_BINARY,
654 NL80211_HE_MIN_CAPABILITY_LEN,
655 NL80211_HE_MAX_CAPABILITY_LEN),
0e012b4e
JB
656 [NL80211_ATTR_FTM_RESPONDER] =
657 NLA_POLICY_NESTED(nl80211_ftm_responder_policy),
9bb7e0f2
JB
658 [NL80211_ATTR_TIMEOUT] = NLA_POLICY_MIN(NLA_U32, 1),
659 [NL80211_ATTR_PEER_MEASUREMENTS] =
23323289 660 NLA_POLICY_NESTED(nl80211_pmsr_attr_policy),
36647055 661 [NL80211_ATTR_AIRTIME_WEIGHT] = NLA_POLICY_MIN(NLA_U16, 1),
26f7044e
CHH
662 [NL80211_ATTR_SAE_PASSWORD] = { .type = NLA_BINARY,
663 .len = SAE_PASSWORD_MAX_LEN },
a0de1ca3 664 [NL80211_ATTR_TWT_RESPONDER] = { .type = NLA_FLAG },
796e90f4 665 [NL80211_ATTR_HE_OBSS_PD] = NLA_POLICY_NESTED(he_obss_pd_policy),
14f34e36 666 [NL80211_ATTR_VLAN_ID] = NLA_POLICY_RANGE(NLA_U16, 1, VLAN_N_VID - 2),
5c5e52d1 667 [NL80211_ATTR_HE_BSS_COLOR] = NLA_POLICY_NESTED(he_bss_color_policy),
77f576de
T
668 [NL80211_ATTR_TID_CONFIG] =
669 NLA_POLICY_NESTED_ARRAY(nl80211_tid_config_attr_policy),
5631d96a 670 [NL80211_ATTR_CONTROL_PORT_NO_PREAUTH] = { .type = NLA_FLAG },
7fc82af8
VJ
671 [NL80211_ATTR_PMK_LIFETIME] = NLA_POLICY_MIN(NLA_U32, 1),
672 [NL80211_ATTR_PMK_REAUTH_THRESHOLD] = NLA_POLICY_RANGE(NLA_U8, 1, 100),
9dba48a6 673 [NL80211_ATTR_RECEIVE_MULTICAST] = { .type = NLA_FLAG },
942ba88b 674 [NL80211_ATTR_WIPHY_FREQ_OFFSET] = NLA_POLICY_RANGE(NLA_U32, 0, 999),
2032f3b2 675 [NL80211_ATTR_SCAN_FREQ_KHZ] = { .type = NLA_NESTED },
8140860c
JB
676 [NL80211_ATTR_HE_6GHZ_CAPABILITY] =
677 NLA_POLICY_EXACT_LEN(sizeof(struct ieee80211_he_6ghz_capa)),
55682965
JB
678};
679
e31b8213 680/* policy for the key attributes */
b54452b0 681static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
fffd0934 682 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
b9454e83
JB
683 [NL80211_KEY_IDX] = { .type = NLA_U8 },
684 [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
81962267 685 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 },
b9454e83
JB
686 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
687 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
ab0d76f6 688 [NL80211_KEY_TYPE] = NLA_POLICY_MAX(NLA_U32, NUM_NL80211_KEYTYPES - 1),
dbd2fd65 689 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
6cdd3979 690 [NL80211_KEY_MODE] = NLA_POLICY_RANGE(NLA_U8, 0, NL80211_KEY_SET_TX),
dbd2fd65
JB
691};
692
693/* policy for the key default flags */
694static const struct nla_policy
695nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
696 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
697 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
b9454e83
JB
698};
699
f83ace3b 700#ifdef CONFIG_PM
ff1b6e69
JB
701/* policy for WoWLAN attributes */
702static const struct nla_policy
703nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = {
704 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG },
705 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG },
706 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG },
707 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED },
77dbbb13
JB
708 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG },
709 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG },
710 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG },
711 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG },
2a0e047e 712 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED },
8cd4d456 713 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED },
2a0e047e
JB
714};
715
716static const struct nla_policy
717nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = {
718 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 },
719 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 },
c7721c05 720 [NL80211_WOWLAN_TCP_DST_MAC] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
2a0e047e
JB
721 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 },
722 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 },
bc043585 723 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = NLA_POLICY_MIN_LEN(1),
2a0e047e
JB
724 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = {
725 .len = sizeof(struct nl80211_wowlan_tcp_data_seq)
726 },
727 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = {
728 .len = sizeof(struct nl80211_wowlan_tcp_data_token)
729 },
730 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 },
bc043585
JB
731 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = NLA_POLICY_MIN_LEN(1),
732 [NL80211_WOWLAN_TCP_WAKE_MASK] = NLA_POLICY_MIN_LEN(1),
ff1b6e69 733};
f83ace3b 734#endif /* CONFIG_PM */
ff1b6e69 735
be29b99a
AK
736/* policy for coalesce rule attributes */
737static const struct nla_policy
738nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = {
739 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 },
ab0d76f6
JB
740 [NL80211_ATTR_COALESCE_RULE_CONDITION] =
741 NLA_POLICY_RANGE(NLA_U32,
742 NL80211_COALESCE_CONDITION_MATCH,
743 NL80211_COALESCE_CONDITION_NO_MATCH),
be29b99a
AK
744 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED },
745};
746
e5497d76
JB
747/* policy for GTK rekey offload attributes */
748static const struct nla_policy
749nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = {
093a48d2
NE
750 [NL80211_REKEY_DATA_KEK] = {
751 .type = NLA_BINARY,
752 .len = NL80211_KEK_EXT_LEN
753 },
754 [NL80211_REKEY_DATA_KCK] = {
755 .type = NLA_BINARY,
756 .len = NL80211_KCK_EXT_LEN
757 },
cb9abd48 758 [NL80211_REKEY_DATA_REPLAY_CTR] = NLA_POLICY_EXACT_LEN(NL80211_REPLAY_CTR_LEN),
093a48d2 759 [NL80211_REKEY_DATA_AKM] = { .type = NLA_U32 },
e5497d76
JB
760};
761
1e1b11b6 762static const struct nla_policy
763nl80211_match_band_rssi_policy[NUM_NL80211_BANDS] = {
764 [NL80211_BAND_2GHZ] = { .type = NLA_S32 },
765 [NL80211_BAND_5GHZ] = { .type = NLA_S32 },
e548a1c3 766 [NL80211_BAND_6GHZ] = { .type = NLA_S32 },
1e1b11b6 767 [NL80211_BAND_60GHZ] = { .type = NLA_S32 },
768};
769
a1f1c21c
LC
770static const struct nla_policy
771nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = {
4a4ab0d7 772 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY,
a1f1c21c 773 .len = IEEE80211_MAX_SSID_LEN },
c7721c05 774 [NL80211_SCHED_SCAN_MATCH_ATTR_BSSID] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
88e920b4 775 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 },
1e1b11b6 776 [NL80211_SCHED_SCAN_MATCH_PER_BAND_RSSI] =
777 NLA_POLICY_NESTED(nl80211_match_band_rssi_policy),
a1f1c21c
LC
778};
779
3b06d277
AS
780static const struct nla_policy
781nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = {
782 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 },
783 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 },
784};
785
38de03d2
AS
786static const struct nla_policy
787nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = {
788 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG },
789 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 },
790 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = {
791 .len = sizeof(struct nl80211_bss_select_rssi_adjust)
792 },
793};
794
a442b761
AB
795/* policy for NAN function attributes */
796static const struct nla_policy
797nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = {
cb9abd48
JB
798 [NL80211_NAN_FUNC_TYPE] =
799 NLA_POLICY_MAX(NLA_U8, NL80211_NAN_FUNC_MAX_TYPE),
0a27844c 800 [NL80211_NAN_FUNC_SERVICE_ID] = {
a442b761
AB
801 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN },
802 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 },
803 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG },
804 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG },
805 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 },
806 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 },
c7721c05 807 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = NLA_POLICY_EXACT_LEN_WARN(ETH_ALEN),
a442b761
AB
808 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG },
809 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 },
810 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY,
811 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN },
812 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED },
813 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED },
814 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED },
815 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 },
816 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 },
817};
818
819/* policy for Service Response Filter attributes */
820static const struct nla_policy
821nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = {
822 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG },
823 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY,
824 .len = NL80211_NAN_FUNC_SRF_MAX_LEN },
825 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 },
826 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED },
827};
828
ad670233
PX
829/* policy for packet pattern attributes */
830static const struct nla_policy
831nl80211_packet_pattern_policy[MAX_NL80211_PKTPAT + 1] = {
832 [NL80211_PKTPAT_MASK] = { .type = NLA_BINARY, },
833 [NL80211_PKTPAT_PATTERN] = { .type = NLA_BINARY, },
834 [NL80211_PKTPAT_OFFSET] = { .type = NLA_U32 },
835};
836
9bb7e0f2
JB
837int nl80211_prepare_wdev_dump(struct netlink_callback *cb,
838 struct cfg80211_registered_device **rdev,
839 struct wireless_dev **wdev)
a043897a 840{
97990a06 841 int err;
a043897a 842
97990a06 843 if (!cb->args[0]) {
50508d94
JB
844 struct nlattr **attrbuf;
845
846 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf),
847 GFP_KERNEL);
848 if (!attrbuf)
849 return -ENOMEM;
850
8cb08174
JB
851 err = nlmsg_parse_deprecated(cb->nlh,
852 GENL_HDRLEN + nl80211_fam.hdrsize,
50508d94 853 attrbuf, nl80211_fam.maxattr,
8cb08174 854 nl80211_policy, NULL);
50508d94
JB
855 if (err) {
856 kfree(attrbuf);
ea90e0dc 857 return err;
50508d94 858 }
67748893 859
50508d94
JB
860 *wdev = __cfg80211_wdev_from_attrs(sock_net(cb->skb->sk),
861 attrbuf);
862 kfree(attrbuf);
ea90e0dc
JB
863 if (IS_ERR(*wdev))
864 return PTR_ERR(*wdev);
f26cbf40 865 *rdev = wiphy_to_rdev((*wdev)->wiphy);
c319d50b
JB
866 /* 0 is the first index - add 1 to parse only once */
867 cb->args[0] = (*rdev)->wiphy_idx + 1;
97990a06
JB
868 cb->args[1] = (*wdev)->identifier;
869 } else {
c319d50b
JB
870 /* subtract the 1 again here */
871 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
97990a06 872 struct wireless_dev *tmp;
67748893 873
ea90e0dc
JB
874 if (!wiphy)
875 return -ENODEV;
f26cbf40 876 *rdev = wiphy_to_rdev(wiphy);
97990a06 877 *wdev = NULL;
67748893 878
53873f13 879 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) {
97990a06
JB
880 if (tmp->identifier == cb->args[1]) {
881 *wdev = tmp;
882 break;
883 }
884 }
67748893 885
ea90e0dc
JB
886 if (!*wdev)
887 return -ENODEV;
67748893
JB
888 }
889
67748893 890 return 0;
67748893
JB
891}
892
55682965 893/* message building helper */
9bb7e0f2
JB
894void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq,
895 int flags, u8 cmd)
55682965
JB
896{
897 /* since there is no private header just add the generic one */
15e47304 898 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd);
55682965
JB
899}
900
50f32718
HD
901static int nl80211_msg_put_wmm_rules(struct sk_buff *msg,
902 const struct ieee80211_reg_rule *rule)
903{
904 int j;
905 struct nlattr *nl_wmm_rules =
ae0be8de 906 nla_nest_start_noflag(msg, NL80211_FREQUENCY_ATTR_WMM);
50f32718
HD
907
908 if (!nl_wmm_rules)
909 goto nla_put_failure;
910
911 for (j = 0; j < IEEE80211_NUM_ACS; j++) {
ae0be8de 912 struct nlattr *nl_wmm_rule = nla_nest_start_noflag(msg, j);
50f32718
HD
913
914 if (!nl_wmm_rule)
915 goto nla_put_failure;
916
917 if (nla_put_u16(msg, NL80211_WMMR_CW_MIN,
38cb87ee 918 rule->wmm_rule.client[j].cw_min) ||
50f32718 919 nla_put_u16(msg, NL80211_WMMR_CW_MAX,
38cb87ee 920 rule->wmm_rule.client[j].cw_max) ||
50f32718 921 nla_put_u8(msg, NL80211_WMMR_AIFSN,
38cb87ee 922 rule->wmm_rule.client[j].aifsn) ||
d3c89bbc
HD
923 nla_put_u16(msg, NL80211_WMMR_TXOP,
924 rule->wmm_rule.client[j].cot))
50f32718
HD
925 goto nla_put_failure;
926
927 nla_nest_end(msg, nl_wmm_rule);
928 }
929 nla_nest_end(msg, nl_wmm_rules);
930
931 return 0;
932
933nla_put_failure:
934 return -ENOBUFS;
935}
936
937static int nl80211_msg_put_channel(struct sk_buff *msg, struct wiphy *wiphy,
cdc89b97
JB
938 struct ieee80211_channel *chan,
939 bool large)
5dab3b8a 940{
ea077c1c
RL
941 /* Some channels must be completely excluded from the
942 * list to protect old user-space tools from breaking
943 */
944 if (!large && chan->flags &
945 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ))
946 return 0;
947
9360ffd1
DM
948 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ,
949 chan->center_freq))
950 goto nla_put_failure;
5dab3b8a 951
942ba88b
TP
952 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_OFFSET, chan->freq_offset))
953 goto nla_put_failure;
954
9360ffd1
DM
955 if ((chan->flags & IEEE80211_CHAN_DISABLED) &&
956 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED))
957 goto nla_put_failure;
8fe02e16
LR
958 if (chan->flags & IEEE80211_CHAN_NO_IR) {
959 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR))
960 goto nla_put_failure;
961 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS))
962 goto nla_put_failure;
963 }
cdc89b97
JB
964 if (chan->flags & IEEE80211_CHAN_RADAR) {
965 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR))
966 goto nla_put_failure;
967 if (large) {
968 u32 time;
969
970 time = elapsed_jiffies_msecs(chan->dfs_state_entered);
971
972 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE,
973 chan->dfs_state))
974 goto nla_put_failure;
975 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME,
976 time))
977 goto nla_put_failure;
089027e5
JD
978 if (nla_put_u32(msg,
979 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME,
980 chan->dfs_cac_ms))
981 goto nla_put_failure;
cdc89b97
JB
982 }
983 }
5dab3b8a 984
fe1abafd
JB
985 if (large) {
986 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) &&
987 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS))
988 goto nla_put_failure;
989 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) &&
990 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS))
991 goto nla_put_failure;
992 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) &&
993 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ))
994 goto nla_put_failure;
995 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) &&
996 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ))
997 goto nla_put_failure;
570dbde1
DS
998 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) &&
999 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY))
1000 goto nla_put_failure;
06f207fc
AN
1001 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) &&
1002 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT))
570dbde1 1003 goto nla_put_failure;
ea077c1c
RL
1004 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) &&
1005 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ))
1006 goto nla_put_failure;
1007 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) &&
1008 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ))
1009 goto nla_put_failure;
1e61d82c
HD
1010 if ((chan->flags & IEEE80211_CHAN_NO_HE) &&
1011 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HE))
1012 goto nla_put_failure;
fe1abafd
JB
1013 }
1014
9360ffd1
DM
1015 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
1016 DBM_TO_MBM(chan->max_power)))
1017 goto nla_put_failure;
5dab3b8a 1018
50f32718
HD
1019 if (large) {
1020 const struct ieee80211_reg_rule *rule =
b88d26d9 1021 freq_reg_info(wiphy, MHZ_TO_KHZ(chan->center_freq));
50f32718 1022
38cb87ee 1023 if (!IS_ERR_OR_NULL(rule) && rule->has_wmm) {
50f32718
HD
1024 if (nl80211_msg_put_wmm_rules(msg, rule))
1025 goto nla_put_failure;
1026 }
1027 }
1028
5dab3b8a
LR
1029 return 0;
1030
1031 nla_put_failure:
1032 return -ENOBUFS;
1033}
1034
52539ca8
THJ
1035static bool nl80211_put_txq_stats(struct sk_buff *msg,
1036 struct cfg80211_txq_stats *txqstats,
1037 int attrtype)
1038{
1039 struct nlattr *txqattr;
1040
1041#define PUT_TXQVAL_U32(attr, memb) do { \
1042 if (txqstats->filled & BIT(NL80211_TXQ_STATS_ ## attr) && \
1043 nla_put_u32(msg, NL80211_TXQ_STATS_ ## attr, txqstats->memb)) \
1044 return false; \
1045 } while (0)
1046
ae0be8de 1047 txqattr = nla_nest_start_noflag(msg, attrtype);
52539ca8
THJ
1048 if (!txqattr)
1049 return false;
1050
1051 PUT_TXQVAL_U32(BACKLOG_BYTES, backlog_bytes);
1052 PUT_TXQVAL_U32(BACKLOG_PACKETS, backlog_packets);
1053 PUT_TXQVAL_U32(FLOWS, flows);
1054 PUT_TXQVAL_U32(DROPS, drops);
1055 PUT_TXQVAL_U32(ECN_MARKS, ecn_marks);
1056 PUT_TXQVAL_U32(OVERLIMIT, overlimit);
1057 PUT_TXQVAL_U32(OVERMEMORY, overmemory);
1058 PUT_TXQVAL_U32(COLLISIONS, collisions);
1059 PUT_TXQVAL_U32(TX_BYTES, tx_bytes);
1060 PUT_TXQVAL_U32(TX_PACKETS, tx_packets);
1061 PUT_TXQVAL_U32(MAX_FLOWS, max_flows);
1062 nla_nest_end(msg, txqattr);
1063
1064#undef PUT_TXQVAL_U32
1065 return true;
1066}
1067
55682965
JB
1068/* netlink command implementations */
1069
b9454e83
JB
1070struct key_parse {
1071 struct key_params p;
1072 int idx;
e31b8213 1073 int type;
56be393f 1074 bool def, defmgmt, defbeacon;
dbd2fd65 1075 bool def_uni, def_multi;
b9454e83
JB
1076};
1077
768075eb
JB
1078static int nl80211_parse_key_new(struct genl_info *info, struct nlattr *key,
1079 struct key_parse *k)
b9454e83
JB
1080{
1081 struct nlattr *tb[NL80211_KEY_MAX + 1];
8cb08174
JB
1082 int err = nla_parse_nested_deprecated(tb, NL80211_KEY_MAX, key,
1083 nl80211_key_policy,
1084 info->extack);
b9454e83
JB
1085 if (err)
1086 return err;
1087
1088 k->def = !!tb[NL80211_KEY_DEFAULT];
1089 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
56be393f 1090 k->defbeacon = !!tb[NL80211_KEY_DEFAULT_BEACON];
b9454e83 1091
dbd2fd65
JB
1092 if (k->def) {
1093 k->def_uni = true;
1094 k->def_multi = true;
1095 }
56be393f 1096 if (k->defmgmt || k->defbeacon)
dbd2fd65
JB
1097 k->def_multi = true;
1098
b9454e83
JB
1099 if (tb[NL80211_KEY_IDX])
1100 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
1101
1102 if (tb[NL80211_KEY_DATA]) {
1103 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
1104 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
1105 }
1106
1107 if (tb[NL80211_KEY_SEQ]) {
1108 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
1109 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
1110 }
1111
1112 if (tb[NL80211_KEY_CIPHER])
1113 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
1114
ab0d76f6 1115 if (tb[NL80211_KEY_TYPE])
e31b8213 1116 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
e31b8213 1117
dbd2fd65
JB
1118 if (tb[NL80211_KEY_DEFAULT_TYPES]) {
1119 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
7a087e74 1120
8cb08174
JB
1121 err = nla_parse_nested_deprecated(kdt,
1122 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
1123 tb[NL80211_KEY_DEFAULT_TYPES],
1124 nl80211_key_default_policy,
1125 info->extack);
dbd2fd65
JB
1126 if (err)
1127 return err;
1128
1129 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
1130 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
1131 }
1132
6cdd3979
AW
1133 if (tb[NL80211_KEY_MODE])
1134 k->p.mode = nla_get_u8(tb[NL80211_KEY_MODE]);
1135
b9454e83
JB
1136 return 0;
1137}
1138
1139static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
1140{
1141 if (info->attrs[NL80211_ATTR_KEY_DATA]) {
1142 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
1143 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
1144 }
1145
1146 if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
1147 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
1148 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
1149 }
1150
1151 if (info->attrs[NL80211_ATTR_KEY_IDX])
1152 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1153
1154 if (info->attrs[NL80211_ATTR_KEY_CIPHER])
1155 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
1156
1157 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
1158 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
1159
dbd2fd65
JB
1160 if (k->def) {
1161 k->def_uni = true;
1162 k->def_multi = true;
1163 }
1164 if (k->defmgmt)
1165 k->def_multi = true;
1166
ab0d76f6 1167 if (info->attrs[NL80211_ATTR_KEY_TYPE])
e31b8213 1168 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
e31b8213 1169
dbd2fd65
JB
1170 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
1171 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
8cb08174
JB
1172 int err = nla_parse_nested_deprecated(kdt,
1173 NUM_NL80211_KEY_DEFAULT_TYPES - 1,
1174 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
1175 nl80211_key_default_policy,
1176 info->extack);
dbd2fd65
JB
1177 if (err)
1178 return err;
1179
1180 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
1181 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
1182 }
1183
b9454e83
JB
1184 return 0;
1185}
1186
1187static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
1188{
1189 int err;
1190
1191 memset(k, 0, sizeof(*k));
1192 k->idx = -1;
e31b8213 1193 k->type = -1;
b9454e83
JB
1194
1195 if (info->attrs[NL80211_ATTR_KEY])
768075eb 1196 err = nl80211_parse_key_new(info, info->attrs[NL80211_ATTR_KEY], k);
b9454e83
JB
1197 else
1198 err = nl80211_parse_key_old(info, k);
1199
1200 if (err)
1201 return err;
1202
56be393f
JM
1203 if ((k->def ? 1 : 0) + (k->defmgmt ? 1 : 0) +
1204 (k->defbeacon ? 1 : 0) > 1) {
1205 GENL_SET_ERR_MSG(info,
1206 "key with multiple default flags is invalid");
b9454e83 1207 return -EINVAL;
768075eb 1208 }
b9454e83 1209
56be393f 1210 if (k->defmgmt || k->defbeacon) {
768075eb 1211 if (k->def_uni || !k->def_multi) {
56be393f
JM
1212 GENL_SET_ERR_MSG(info,
1213 "defmgmt/defbeacon key must be mcast");
dbd2fd65 1214 return -EINVAL;
768075eb 1215 }
dbd2fd65
JB
1216 }
1217
b9454e83
JB
1218 if (k->idx != -1) {
1219 if (k->defmgmt) {
768075eb
JB
1220 if (k->idx < 4 || k->idx > 5) {
1221 GENL_SET_ERR_MSG(info,
1222 "defmgmt key idx not 4 or 5");
b9454e83 1223 return -EINVAL;
768075eb 1224 }
56be393f
JM
1225 } else if (k->defbeacon) {
1226 if (k->idx < 6 || k->idx > 7) {
1227 GENL_SET_ERR_MSG(info,
1228 "defbeacon key idx not 6 or 7");
1229 return -EINVAL;
1230 }
b9454e83 1231 } else if (k->def) {
768075eb
JB
1232 if (k->idx < 0 || k->idx > 3) {
1233 GENL_SET_ERR_MSG(info, "def key idx not 0-3");
b9454e83 1234 return -EINVAL;
768075eb 1235 }
b9454e83 1236 } else {
56be393f
JM
1237 if (k->idx < 0 || k->idx > 7) {
1238 GENL_SET_ERR_MSG(info, "key idx not 0-7");
b9454e83 1239 return -EINVAL;
768075eb 1240 }
b9454e83
JB
1241 }
1242 }
1243
1244 return 0;
1245}
1246
fffd0934
JB
1247static struct cfg80211_cached_keys *
1248nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
768075eb 1249 struct genl_info *info, bool *no_ht)
fffd0934 1250{
768075eb 1251 struct nlattr *keys = info->attrs[NL80211_ATTR_KEYS];
fffd0934
JB
1252 struct key_parse parse;
1253 struct nlattr *key;
1254 struct cfg80211_cached_keys *result;
1255 int rem, err, def = 0;
f1c1f17a
JB
1256 bool have_key = false;
1257
1258 nla_for_each_nested(key, keys, rem) {
1259 have_key = true;
1260 break;
1261 }
1262
1263 if (!have_key)
1264 return NULL;
fffd0934
JB
1265
1266 result = kzalloc(sizeof(*result), GFP_KERNEL);
1267 if (!result)
1268 return ERR_PTR(-ENOMEM);
1269
1270 result->def = -1;
fffd0934
JB
1271
1272 nla_for_each_nested(key, keys, rem) {
1273 memset(&parse, 0, sizeof(parse));
1274 parse.idx = -1;
1275
768075eb 1276 err = nl80211_parse_key_new(info, key, &parse);
fffd0934
JB
1277 if (err)
1278 goto error;
1279 err = -EINVAL;
1280 if (!parse.p.key)
1281 goto error;
768075eb
JB
1282 if (parse.idx < 0 || parse.idx > 3) {
1283 GENL_SET_ERR_MSG(info, "key index out of range [0-3]");
fffd0934 1284 goto error;
768075eb 1285 }
fffd0934 1286 if (parse.def) {
768075eb
JB
1287 if (def) {
1288 GENL_SET_ERR_MSG(info,
1289 "only one key can be default");
fffd0934 1290 goto error;
768075eb 1291 }
fffd0934
JB
1292 def = 1;
1293 result->def = parse.idx;
dbd2fd65
JB
1294 if (!parse.def_uni || !parse.def_multi)
1295 goto error;
fffd0934
JB
1296 } else if (parse.defmgmt)
1297 goto error;
1298 err = cfg80211_validate_key_settings(rdev, &parse.p,
e31b8213 1299 parse.idx, false, NULL);
fffd0934
JB
1300 if (err)
1301 goto error;
386b1f27
JB
1302 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 &&
1303 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) {
768075eb 1304 GENL_SET_ERR_MSG(info, "connect key must be WEP");
386b1f27
JB
1305 err = -EINVAL;
1306 goto error;
1307 }
fffd0934
JB
1308 result->params[parse.idx].cipher = parse.p.cipher;
1309 result->params[parse.idx].key_len = parse.p.key_len;
1310 result->params[parse.idx].key = result->data[parse.idx];
1311 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
de7044ee 1312
386b1f27
JB
1313 /* must be WEP key if we got here */
1314 if (no_ht)
1315 *no_ht = true;
fffd0934
JB
1316 }
1317
f1c1f17a
JB
1318 if (result->def < 0) {
1319 err = -EINVAL;
768075eb 1320 GENL_SET_ERR_MSG(info, "need a default/TX key");
f1c1f17a
JB
1321 goto error;
1322 }
1323
fffd0934
JB
1324 return result;
1325 error:
1326 kfree(result);
1327 return ERR_PTR(err);
1328}
1329
1330static int nl80211_key_allowed(struct wireless_dev *wdev)
1331{
1332 ASSERT_WDEV_LOCK(wdev);
1333
fffd0934
JB
1334 switch (wdev->iftype) {
1335 case NL80211_IFTYPE_AP:
1336 case NL80211_IFTYPE_AP_VLAN:
074ac8df 1337 case NL80211_IFTYPE_P2P_GO:
ff973af7 1338 case NL80211_IFTYPE_MESH_POINT:
fffd0934
JB
1339 break;
1340 case NL80211_IFTYPE_ADHOC:
fffd0934 1341 case NL80211_IFTYPE_STATION:
074ac8df 1342 case NL80211_IFTYPE_P2P_CLIENT:
ceca7b71 1343 if (!wdev->current_bss)
fffd0934
JB
1344 return -ENOLINK;
1345 break;
de4fcbad 1346 case NL80211_IFTYPE_UNSPECIFIED:
6e0bd6c3 1347 case NL80211_IFTYPE_OCB:
de4fcbad 1348 case NL80211_IFTYPE_MONITOR:
cb3b7d87 1349 case NL80211_IFTYPE_NAN:
de4fcbad
JB
1350 case NL80211_IFTYPE_P2P_DEVICE:
1351 case NL80211_IFTYPE_WDS:
1352 case NUM_NL80211_IFTYPES:
fffd0934
JB
1353 return -EINVAL;
1354 }
1355
1356 return 0;
1357}
1358
664834de 1359static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy,
942ba88b 1360 u32 freq)
664834de
JM
1361{
1362 struct ieee80211_channel *chan;
1363
942ba88b 1364 chan = ieee80211_get_channel_khz(wiphy, freq);
664834de
JM
1365 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED)
1366 return NULL;
1367 return chan;
1368}
1369
7527a782
JB
1370static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes)
1371{
ae0be8de 1372 struct nlattr *nl_modes = nla_nest_start_noflag(msg, attr);
7527a782
JB
1373 int i;
1374
1375 if (!nl_modes)
1376 goto nla_put_failure;
1377
1378 i = 0;
1379 while (ifmodes) {
9360ffd1
DM
1380 if ((ifmodes & 1) && nla_put_flag(msg, i))
1381 goto nla_put_failure;
7527a782
JB
1382 ifmodes >>= 1;
1383 i++;
1384 }
1385
1386 nla_nest_end(msg, nl_modes);
1387 return 0;
1388
1389nla_put_failure:
1390 return -ENOBUFS;
1391}
1392
1393static int nl80211_put_iface_combinations(struct wiphy *wiphy,
cdc89b97
JB
1394 struct sk_buff *msg,
1395 bool large)
7527a782
JB
1396{
1397 struct nlattr *nl_combis;
1398 int i, j;
1399
ae0be8de
MK
1400 nl_combis = nla_nest_start_noflag(msg,
1401 NL80211_ATTR_INTERFACE_COMBINATIONS);
7527a782
JB
1402 if (!nl_combis)
1403 goto nla_put_failure;
1404
1405 for (i = 0; i < wiphy->n_iface_combinations; i++) {
1406 const struct ieee80211_iface_combination *c;
1407 struct nlattr *nl_combi, *nl_limits;
1408
1409 c = &wiphy->iface_combinations[i];
1410
ae0be8de 1411 nl_combi = nla_nest_start_noflag(msg, i + 1);
7527a782
JB
1412 if (!nl_combi)
1413 goto nla_put_failure;
1414
ae0be8de
MK
1415 nl_limits = nla_nest_start_noflag(msg,
1416 NL80211_IFACE_COMB_LIMITS);
7527a782
JB
1417 if (!nl_limits)
1418 goto nla_put_failure;
1419
1420 for (j = 0; j < c->n_limits; j++) {
1421 struct nlattr *nl_limit;
1422
ae0be8de 1423 nl_limit = nla_nest_start_noflag(msg, j + 1);
7527a782
JB
1424 if (!nl_limit)
1425 goto nla_put_failure;
9360ffd1
DM
1426 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX,
1427 c->limits[j].max))
1428 goto nla_put_failure;
7527a782
JB
1429 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES,
1430 c->limits[j].types))
1431 goto nla_put_failure;
1432 nla_nest_end(msg, nl_limit);
1433 }
1434
1435 nla_nest_end(msg, nl_limits);
1436
9360ffd1
DM
1437 if (c->beacon_int_infra_match &&
1438 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH))
1439 goto nla_put_failure;
1440 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS,
1441 c->num_different_channels) ||
1442 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM,
1443 c->max_interfaces))
1444 goto nla_put_failure;
cdc89b97 1445 if (large &&
8c48b50a
FF
1446 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS,
1447 c->radar_detect_widths) ||
1448 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS,
1449 c->radar_detect_regions)))
cdc89b97 1450 goto nla_put_failure;
0c317a02
PK
1451 if (c->beacon_int_min_gcd &&
1452 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD,
1453 c->beacon_int_min_gcd))
1454 goto nla_put_failure;
7527a782
JB
1455
1456 nla_nest_end(msg, nl_combi);
1457 }
1458
1459 nla_nest_end(msg, nl_combis);
1460
1461 return 0;
1462nla_put_failure:
1463 return -ENOBUFS;
1464}
1465
3713b4e3 1466#ifdef CONFIG_PM
b56cf720
JB
1467static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev,
1468 struct sk_buff *msg)
1469{
964dc9e2 1470 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp;
b56cf720
JB
1471 struct nlattr *nl_tcp;
1472
1473 if (!tcp)
1474 return 0;
1475
ae0be8de
MK
1476 nl_tcp = nla_nest_start_noflag(msg,
1477 NL80211_WOWLAN_TRIG_TCP_CONNECTION);
b56cf720
JB
1478 if (!nl_tcp)
1479 return -ENOBUFS;
1480
1481 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1482 tcp->data_payload_max))
1483 return -ENOBUFS;
1484
1485 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
1486 tcp->data_payload_max))
1487 return -ENOBUFS;
1488
1489 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ))
1490 return -ENOBUFS;
1491
1492 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
1493 sizeof(*tcp->tok), tcp->tok))
1494 return -ENOBUFS;
1495
1496 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
1497 tcp->data_interval_max))
1498 return -ENOBUFS;
1499
1500 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
1501 tcp->wake_payload_max))
1502 return -ENOBUFS;
1503
1504 nla_nest_end(msg, nl_tcp);
1505 return 0;
1506}
1507
3713b4e3 1508static int nl80211_send_wowlan(struct sk_buff *msg,
1b8ec87a 1509 struct cfg80211_registered_device *rdev,
b56cf720 1510 bool large)
55682965 1511{
3713b4e3 1512 struct nlattr *nl_wowlan;
55682965 1513
1b8ec87a 1514 if (!rdev->wiphy.wowlan)
3713b4e3 1515 return 0;
55682965 1516
ae0be8de
MK
1517 nl_wowlan = nla_nest_start_noflag(msg,
1518 NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED);
3713b4e3
JB
1519 if (!nl_wowlan)
1520 return -ENOBUFS;
9360ffd1 1521
1b8ec87a 1522 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) &&
3713b4e3 1523 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
1b8ec87a 1524 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) &&
3713b4e3 1525 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
1b8ec87a 1526 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) &&
3713b4e3 1527 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
1b8ec87a 1528 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) &&
3713b4e3 1529 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) ||
1b8ec87a 1530 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) &&
3713b4e3 1531 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
1b8ec87a 1532 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) &&
3713b4e3 1533 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
1b8ec87a 1534 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) &&
3713b4e3 1535 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
1b8ec87a 1536 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) &&
3713b4e3
JB
1537 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
1538 return -ENOBUFS;
9360ffd1 1539
1b8ec87a 1540 if (rdev->wiphy.wowlan->n_patterns) {
50ac6607 1541 struct nl80211_pattern_support pat = {
1b8ec87a
ZG
1542 .max_patterns = rdev->wiphy.wowlan->n_patterns,
1543 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len,
1544 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len,
1545 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset,
3713b4e3 1546 };
9360ffd1 1547
3713b4e3
JB
1548 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
1549 sizeof(pat), &pat))
1550 return -ENOBUFS;
1551 }
9360ffd1 1552
75453ccb
LC
1553 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) &&
1554 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT,
1555 rdev->wiphy.wowlan->max_nd_match_sets))
1556 return -ENOBUFS;
1557
1b8ec87a 1558 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg))
b56cf720
JB
1559 return -ENOBUFS;
1560
3713b4e3 1561 nla_nest_end(msg, nl_wowlan);
9360ffd1 1562
3713b4e3
JB
1563 return 0;
1564}
1565#endif
9360ffd1 1566
be29b99a 1567static int nl80211_send_coalesce(struct sk_buff *msg,
1b8ec87a 1568 struct cfg80211_registered_device *rdev)
be29b99a
AK
1569{
1570 struct nl80211_coalesce_rule_support rule;
1571
1b8ec87a 1572 if (!rdev->wiphy.coalesce)
be29b99a
AK
1573 return 0;
1574
1b8ec87a
ZG
1575 rule.max_rules = rdev->wiphy.coalesce->n_rules;
1576 rule.max_delay = rdev->wiphy.coalesce->max_delay;
1577 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns;
1578 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len;
1579 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len;
1580 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset;
be29b99a
AK
1581
1582 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule))
1583 return -ENOBUFS;
1584
1585 return 0;
1586}
1587
c4cbaf79
LC
1588static int
1589nl80211_send_iftype_data(struct sk_buff *msg,
22395217 1590 const struct ieee80211_supported_band *sband,
c4cbaf79
LC
1591 const struct ieee80211_sband_iftype_data *iftdata)
1592{
1593 const struct ieee80211_sta_he_cap *he_cap = &iftdata->he_cap;
1594
1595 if (nl80211_put_iftypes(msg, NL80211_BAND_IFTYPE_ATTR_IFTYPES,
1596 iftdata->types_mask))
1597 return -ENOBUFS;
1598
1599 if (he_cap->has_he) {
1600 if (nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_MAC,
1601 sizeof(he_cap->he_cap_elem.mac_cap_info),
1602 he_cap->he_cap_elem.mac_cap_info) ||
1603 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_PHY,
1604 sizeof(he_cap->he_cap_elem.phy_cap_info),
1605 he_cap->he_cap_elem.phy_cap_info) ||
1606 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_MCS_SET,
1607 sizeof(he_cap->he_mcs_nss_supp),
1608 &he_cap->he_mcs_nss_supp) ||
1609 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_CAP_PPE,
1610 sizeof(he_cap->ppe_thres), he_cap->ppe_thres))
1611 return -ENOBUFS;
1612 }
1613
22395217
JB
1614 if (sband->band == NL80211_BAND_6GHZ &&
1615 nla_put(msg, NL80211_BAND_IFTYPE_ATTR_HE_6GHZ_CAPA,
1616 sizeof(iftdata->he_6ghz_capa),
1617 &iftdata->he_6ghz_capa))
1618 return -ENOBUFS;
1619
c4cbaf79
LC
1620 return 0;
1621}
1622
3713b4e3
JB
1623static int nl80211_send_band_rateinfo(struct sk_buff *msg,
1624 struct ieee80211_supported_band *sband)
1625{
1626 struct nlattr *nl_rates, *nl_rate;
1627 struct ieee80211_rate *rate;
1628 int i;
87bbbe22 1629
3713b4e3
JB
1630 /* add HT info */
1631 if (sband->ht_cap.ht_supported &&
1632 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET,
1633 sizeof(sband->ht_cap.mcs),
1634 &sband->ht_cap.mcs) ||
1635 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA,
1636 sband->ht_cap.cap) ||
1637 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
1638 sband->ht_cap.ampdu_factor) ||
1639 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
1640 sband->ht_cap.ampdu_density)))
1641 return -ENOBUFS;
afe0cbf8 1642
3713b4e3
JB
1643 /* add VHT info */
1644 if (sband->vht_cap.vht_supported &&
1645 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET,
1646 sizeof(sband->vht_cap.vht_mcs),
1647 &sband->vht_cap.vht_mcs) ||
1648 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA,
1649 sband->vht_cap.cap)))
1650 return -ENOBUFS;
f59ac048 1651
c4cbaf79
LC
1652 if (sband->n_iftype_data) {
1653 struct nlattr *nl_iftype_data =
ae0be8de
MK
1654 nla_nest_start_noflag(msg,
1655 NL80211_BAND_ATTR_IFTYPE_DATA);
c4cbaf79
LC
1656 int err;
1657
1658 if (!nl_iftype_data)
1659 return -ENOBUFS;
1660
1661 for (i = 0; i < sband->n_iftype_data; i++) {
1662 struct nlattr *iftdata;
1663
ae0be8de 1664 iftdata = nla_nest_start_noflag(msg, i + 1);
c4cbaf79
LC
1665 if (!iftdata)
1666 return -ENOBUFS;
1667
22395217 1668 err = nl80211_send_iftype_data(msg, sband,
c4cbaf79
LC
1669 &sband->iftype_data[i]);
1670 if (err)
1671 return err;
1672
1673 nla_nest_end(msg, iftdata);
1674 }
1675
1676 nla_nest_end(msg, nl_iftype_data);
1677 }
1678
2a38075c
AAL
1679 /* add EDMG info */
1680 if (sband->edmg_cap.channels &&
1681 (nla_put_u8(msg, NL80211_BAND_ATTR_EDMG_CHANNELS,
1682 sband->edmg_cap.channels) ||
1683 nla_put_u8(msg, NL80211_BAND_ATTR_EDMG_BW_CONFIG,
1684 sband->edmg_cap.bw_config)))
1685
1686 return -ENOBUFS;
1687
3713b4e3 1688 /* add bitrates */
ae0be8de 1689 nl_rates = nla_nest_start_noflag(msg, NL80211_BAND_ATTR_RATES);
3713b4e3
JB
1690 if (!nl_rates)
1691 return -ENOBUFS;
ee688b00 1692
3713b4e3 1693 for (i = 0; i < sband->n_bitrates; i++) {
ae0be8de 1694 nl_rate = nla_nest_start_noflag(msg, i);
3713b4e3
JB
1695 if (!nl_rate)
1696 return -ENOBUFS;
ee688b00 1697
3713b4e3
JB
1698 rate = &sband->bitrates[i];
1699 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE,
1700 rate->bitrate))
1701 return -ENOBUFS;
1702 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) &&
1703 nla_put_flag(msg,
1704 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE))
1705 return -ENOBUFS;
ee688b00 1706
3713b4e3
JB
1707 nla_nest_end(msg, nl_rate);
1708 }
d51626df 1709
3713b4e3 1710 nla_nest_end(msg, nl_rates);
bf0c111e 1711
3713b4e3
JB
1712 return 0;
1713}
ee688b00 1714
3713b4e3
JB
1715static int
1716nl80211_send_mgmt_stypes(struct sk_buff *msg,
1717 const struct ieee80211_txrx_stypes *mgmt_stypes)
1718{
1719 u16 stypes;
1720 struct nlattr *nl_ftypes, *nl_ifs;
1721 enum nl80211_iftype ift;
1722 int i;
ee688b00 1723
3713b4e3
JB
1724 if (!mgmt_stypes)
1725 return 0;
5dab3b8a 1726
ae0be8de 1727 nl_ifs = nla_nest_start_noflag(msg, NL80211_ATTR_TX_FRAME_TYPES);
3713b4e3
JB
1728 if (!nl_ifs)
1729 return -ENOBUFS;
e2f367f2 1730
3713b4e3 1731 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
ae0be8de 1732 nl_ftypes = nla_nest_start_noflag(msg, ift);
3713b4e3
JB
1733 if (!nl_ftypes)
1734 return -ENOBUFS;
1735 i = 0;
1736 stypes = mgmt_stypes[ift].tx;
1737 while (stypes) {
1738 if ((stypes & 1) &&
1739 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1740 (i << 4) | IEEE80211_FTYPE_MGMT))
1741 return -ENOBUFS;
1742 stypes >>= 1;
1743 i++;
ee688b00 1744 }
3713b4e3
JB
1745 nla_nest_end(msg, nl_ftypes);
1746 }
ee688b00 1747
3713b4e3 1748 nla_nest_end(msg, nl_ifs);
ee688b00 1749
ae0be8de 1750 nl_ifs = nla_nest_start_noflag(msg, NL80211_ATTR_RX_FRAME_TYPES);
3713b4e3
JB
1751 if (!nl_ifs)
1752 return -ENOBUFS;
ee688b00 1753
3713b4e3 1754 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
ae0be8de 1755 nl_ftypes = nla_nest_start_noflag(msg, ift);
3713b4e3
JB
1756 if (!nl_ftypes)
1757 return -ENOBUFS;
1758 i = 0;
1759 stypes = mgmt_stypes[ift].rx;
1760 while (stypes) {
1761 if ((stypes & 1) &&
1762 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE,
1763 (i << 4) | IEEE80211_FTYPE_MGMT))
1764 return -ENOBUFS;
1765 stypes >>= 1;
1766 i++;
1767 }
1768 nla_nest_end(msg, nl_ftypes);
1769 }
1770 nla_nest_end(msg, nl_ifs);
ee688b00 1771
3713b4e3
JB
1772 return 0;
1773}
ee688b00 1774
1794899e
JB
1775#define CMD(op, n) \
1776 do { \
1777 if (rdev->ops->op) { \
1778 i++; \
1779 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \
1780 goto nla_put_failure; \
1781 } \
1782 } while (0)
1783
1784static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev,
1785 struct sk_buff *msg)
1786{
1787 int i = 0;
1788
1789 /*
1790 * do *NOT* add anything into this function, new things need to be
1791 * advertised only to new versions of userspace that can deal with
1792 * the split (and they can't possibly care about new features...
1793 */
1794 CMD(add_virtual_intf, NEW_INTERFACE);
1795 CMD(change_virtual_intf, SET_INTERFACE);
1796 CMD(add_key, NEW_KEY);
1797 CMD(start_ap, START_AP);
1798 CMD(add_station, NEW_STATION);
1799 CMD(add_mpath, NEW_MPATH);
1800 CMD(update_mesh_config, SET_MESH_CONFIG);
1801 CMD(change_bss, SET_BSS);
1802 CMD(auth, AUTHENTICATE);
1803 CMD(assoc, ASSOCIATE);
1804 CMD(deauth, DEAUTHENTICATE);
1805 CMD(disassoc, DISASSOCIATE);
1806 CMD(join_ibss, JOIN_IBSS);
1807 CMD(join_mesh, JOIN_MESH);
1808 CMD(set_pmksa, SET_PMKSA);
1809 CMD(del_pmksa, DEL_PMKSA);
1810 CMD(flush_pmksa, FLUSH_PMKSA);
1811 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)
1812 CMD(remain_on_channel, REMAIN_ON_CHANNEL);
1813 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
1814 CMD(mgmt_tx, FRAME);
1815 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
1816 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
1817 i++;
1818 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS))
1819 goto nla_put_failure;
1820 }
1821 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap ||
1822 rdev->ops->join_mesh) {
1823 i++;
1824 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL))
1825 goto nla_put_failure;
1826 }
1827 CMD(set_wds_peer, SET_WDS_PEER);
1828 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) {
1829 CMD(tdls_mgmt, TDLS_MGMT);
1830 CMD(tdls_oper, TDLS_OPER);
1831 }
ca986ad9 1832 if (rdev->wiphy.max_sched_scan_reqs)
1794899e
JB
1833 CMD(sched_scan_start, START_SCHED_SCAN);
1834 CMD(probe_client, PROBE_CLIENT);
1835 CMD(set_noack_map, SET_NOACK_MAP);
1836 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) {
1837 i++;
1838 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS))
1839 goto nla_put_failure;
1840 }
1841 CMD(start_p2p_device, START_P2P_DEVICE);
1842 CMD(set_mcast_rate, SET_MCAST_RATE);
1843#ifdef CONFIG_NL80211_TESTMODE
1844 CMD(testmode_cmd, TESTMODE);
1845#endif
1846
1847 if (rdev->ops->connect || rdev->ops->auth) {
1848 i++;
1849 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT))
1850 goto nla_put_failure;
1851 }
1852
1853 if (rdev->ops->disconnect || rdev->ops->deauth) {
1854 i++;
1855 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT))
1856 goto nla_put_failure;
1857 }
1858
1859 return i;
1860 nla_put_failure:
1861 return -ENOBUFS;
1862}
1863
9bb7e0f2
JB
1864static int
1865nl80211_send_pmsr_ftm_capa(const struct cfg80211_pmsr_capabilities *cap,
1866 struct sk_buff *msg)
1867{
1868 struct nlattr *ftm;
1869
1870 if (!cap->ftm.supported)
1871 return 0;
1872
ae0be8de 1873 ftm = nla_nest_start_noflag(msg, NL80211_PMSR_TYPE_FTM);
9bb7e0f2
JB
1874 if (!ftm)
1875 return -ENOBUFS;
1876
1877 if (cap->ftm.asap && nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_ASAP))
1878 return -ENOBUFS;
1879 if (cap->ftm.non_asap &&
1880 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_NON_ASAP))
1881 return -ENOBUFS;
1882 if (cap->ftm.request_lci &&
1883 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_REQ_LCI))
1884 return -ENOBUFS;
1885 if (cap->ftm.request_civicloc &&
1886 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_REQ_CIVICLOC))
1887 return -ENOBUFS;
1888 if (nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_PREAMBLES,
1889 cap->ftm.preambles))
1890 return -ENOBUFS;
1891 if (nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_BANDWIDTHS,
1892 cap->ftm.bandwidths))
1893 return -ENOBUFS;
1894 if (cap->ftm.max_bursts_exponent >= 0 &&
1895 nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_MAX_BURSTS_EXPONENT,
1896 cap->ftm.max_bursts_exponent))
1897 return -ENOBUFS;
1898 if (cap->ftm.max_ftms_per_burst &&
1899 nla_put_u32(msg, NL80211_PMSR_FTM_CAPA_ATTR_MAX_FTMS_PER_BURST,
1900 cap->ftm.max_ftms_per_burst))
1901 return -ENOBUFS;
efb5520d
AS
1902 if (cap->ftm.trigger_based &&
1903 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_TRIGGER_BASED))
1904 return -ENOBUFS;
1905 if (cap->ftm.non_trigger_based &&
1906 nla_put_flag(msg, NL80211_PMSR_FTM_CAPA_ATTR_NON_TRIGGER_BASED))
1907 return -ENOBUFS;
9bb7e0f2
JB
1908
1909 nla_nest_end(msg, ftm);
1910 return 0;
1911}
1912
1913static int nl80211_send_pmsr_capa(struct cfg80211_registered_device *rdev,
1914 struct sk_buff *msg)
1915{
1916 const struct cfg80211_pmsr_capabilities *cap = rdev->wiphy.pmsr_capa;
1917 struct nlattr *pmsr, *caps;
1918
1919 if (!cap)
1920 return 0;
1921
1922 /*
1923 * we don't need to clean up anything here since the caller
1924 * will genlmsg_cancel() if we fail
1925 */
1926
ae0be8de 1927 pmsr = nla_nest_start_noflag(msg, NL80211_ATTR_PEER_MEASUREMENTS);
9bb7e0f2
JB
1928 if (!pmsr)
1929 return -ENOBUFS;
1930
1931 if (nla_put_u32(msg, NL80211_PMSR_ATTR_MAX_PEERS, cap->max_peers))
1932 return -ENOBUFS;
1933
1934 if (cap->report_ap_tsf &&
1935 nla_put_flag(msg, NL80211_PMSR_ATTR_REPORT_AP_TSF))
1936 return -ENOBUFS;
1937
1938 if (cap->randomize_mac_addr &&
1939 nla_put_flag(msg, NL80211_PMSR_ATTR_RANDOMIZE_MAC_ADDR))
1940 return -ENOBUFS;
1941
ae0be8de 1942 caps = nla_nest_start_noflag(msg, NL80211_PMSR_ATTR_TYPE_CAPA);
9bb7e0f2
JB
1943 if (!caps)
1944 return -ENOBUFS;
1945
1946 if (nl80211_send_pmsr_ftm_capa(cap, msg))
1947 return -ENOBUFS;
1948
1949 nla_nest_end(msg, caps);
1950 nla_nest_end(msg, pmsr);
1951
1952 return 0;
1953}
1954
d6039a34
VJ
1955static int
1956nl80211_put_iftype_akm_suites(struct cfg80211_registered_device *rdev,
1957 struct sk_buff *msg)
1958{
1959 int i;
1960 struct nlattr *nested, *nested_akms;
1961 const struct wiphy_iftype_akm_suites *iftype_akms;
1962
1963 if (!rdev->wiphy.num_iftype_akm_suites ||
1964 !rdev->wiphy.iftype_akm_suites)
1965 return 0;
1966
1967 nested = nla_nest_start(msg, NL80211_ATTR_IFTYPE_AKM_SUITES);
1968 if (!nested)
1969 return -ENOBUFS;
1970
1971 for (i = 0; i < rdev->wiphy.num_iftype_akm_suites; i++) {
1972 nested_akms = nla_nest_start(msg, i + 1);
1973 if (!nested_akms)
1974 return -ENOBUFS;
1975
1976 iftype_akms = &rdev->wiphy.iftype_akm_suites[i];
1977
1978 if (nl80211_put_iftypes(msg, NL80211_IFTYPE_AKM_ATTR_IFTYPES,
1979 iftype_akms->iftypes_mask))
1980 return -ENOBUFS;
1981
1982 if (nla_put(msg, NL80211_IFTYPE_AKM_ATTR_SUITES,
1983 sizeof(u32) * iftype_akms->n_akm_suites,
1984 iftype_akms->akm_suites)) {
1985 return -ENOBUFS;
1986 }
1987 nla_nest_end(msg, nested_akms);
1988 }
1989
1990 nla_nest_end(msg, nested);
1991
1992 return 0;
1993}
1994
3710a8a6
JB
1995static int
1996nl80211_put_tid_config_support(struct cfg80211_registered_device *rdev,
1997 struct sk_buff *msg)
1998{
1999 struct nlattr *supp;
2000
2001 if (!rdev->wiphy.tid_config_support.vif &&
2002 !rdev->wiphy.tid_config_support.peer)
2003 return 0;
2004
2005 supp = nla_nest_start(msg, NL80211_ATTR_TID_CONFIG);
2006 if (!supp)
2007 return -ENOSPC;
2008
2009 if (rdev->wiphy.tid_config_support.vif &&
2010 nla_put_u64_64bit(msg, NL80211_TID_CONFIG_ATTR_VIF_SUPP,
2011 rdev->wiphy.tid_config_support.vif,
2012 NL80211_TID_CONFIG_ATTR_PAD))
2013 goto fail;
2014
2015 if (rdev->wiphy.tid_config_support.peer &&
2016 nla_put_u64_64bit(msg, NL80211_TID_CONFIG_ATTR_PEER_SUPP,
2017 rdev->wiphy.tid_config_support.peer,
2018 NL80211_TID_CONFIG_ATTR_PAD))
2019 goto fail;
2020
6a21d16c
T
2021 /* for now we just use the same value ... makes more sense */
2022 if (nla_put_u8(msg, NL80211_TID_CONFIG_ATTR_RETRY_SHORT,
2023 rdev->wiphy.tid_config_support.max_retry))
2024 goto fail;
2025 if (nla_put_u8(msg, NL80211_TID_CONFIG_ATTR_RETRY_LONG,
2026 rdev->wiphy.tid_config_support.max_retry))
2027 goto fail;
2028
3710a8a6
JB
2029 nla_nest_end(msg, supp);
2030
2031 return 0;
2032fail:
2033 nla_nest_cancel(msg, supp);
2034 return -ENOBUFS;
2035}
2036
86e8cf98
JB
2037struct nl80211_dump_wiphy_state {
2038 s64 filter_wiphy;
2039 long start;
019ae3a9 2040 long split_start, band_start, chan_start, capa_start;
86e8cf98
JB
2041 bool split;
2042};
2043
1b8ec87a 2044static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev,
3bb20556 2045 enum nl80211_commands cmd,
3713b4e3 2046 struct sk_buff *msg, u32 portid, u32 seq,
86e8cf98 2047 int flags, struct nl80211_dump_wiphy_state *state)
3713b4e3
JB
2048{
2049 void *hdr;
2050 struct nlattr *nl_bands, *nl_band;
2051 struct nlattr *nl_freqs, *nl_freq;
2052 struct nlattr *nl_cmds;
57fbcce3 2053 enum nl80211_band band;
3713b4e3
JB
2054 struct ieee80211_channel *chan;
2055 int i;
2056 const struct ieee80211_txrx_stypes *mgmt_stypes =
1b8ec87a 2057 rdev->wiphy.mgmt_stypes;
fe1abafd 2058 u32 features;
ee688b00 2059
3bb20556 2060 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
3713b4e3
JB
2061 if (!hdr)
2062 return -ENOBUFS;
ee688b00 2063
86e8cf98
JB
2064 if (WARN_ON(!state))
2065 return -EINVAL;
ee688b00 2066
1b8ec87a 2067 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3713b4e3 2068 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME,
1b8ec87a 2069 wiphy_name(&rdev->wiphy)) ||
3713b4e3
JB
2070 nla_put_u32(msg, NL80211_ATTR_GENERATION,
2071 cfg80211_rdev_list_generation))
8fdc621d
JB
2072 goto nla_put_failure;
2073
3bb20556
JB
2074 if (cmd != NL80211_CMD_NEW_WIPHY)
2075 goto finish;
2076
86e8cf98 2077 switch (state->split_start) {
3713b4e3
JB
2078 case 0:
2079 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
1b8ec87a 2080 rdev->wiphy.retry_short) ||
3713b4e3 2081 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
1b8ec87a 2082 rdev->wiphy.retry_long) ||
3713b4e3 2083 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
1b8ec87a 2084 rdev->wiphy.frag_threshold) ||
3713b4e3 2085 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
1b8ec87a 2086 rdev->wiphy.rts_threshold) ||
3713b4e3 2087 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
1b8ec87a 2088 rdev->wiphy.coverage_class) ||
3713b4e3 2089 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
1b8ec87a 2090 rdev->wiphy.max_scan_ssids) ||
3713b4e3 2091 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS,
1b8ec87a 2092 rdev->wiphy.max_sched_scan_ssids) ||
3713b4e3 2093 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
1b8ec87a 2094 rdev->wiphy.max_scan_ie_len) ||
3713b4e3 2095 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN,
1b8ec87a 2096 rdev->wiphy.max_sched_scan_ie_len) ||
3713b4e3 2097 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS,
3b06d277
AS
2098 rdev->wiphy.max_match_sets) ||
2099 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS,
2100 rdev->wiphy.max_sched_scan_plans) ||
2101 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL,
2102 rdev->wiphy.max_sched_scan_plan_interval) ||
2103 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS,
2104 rdev->wiphy.max_sched_scan_plan_iterations))
9360ffd1 2105 goto nla_put_failure;
3713b4e3 2106
1b8ec87a 2107 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) &&
3713b4e3 2108 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN))
aa430da4 2109 goto nla_put_failure;
1b8ec87a 2110 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) &&
3713b4e3
JB
2111 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH))
2112 goto nla_put_failure;
1b8ec87a 2113 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) &&
3713b4e3
JB
2114 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD))
2115 goto nla_put_failure;
1b8ec87a 2116 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) &&
3713b4e3
JB
2117 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT))
2118 goto nla_put_failure;
1b8ec87a 2119 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) &&
3713b4e3
JB
2120 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT))
2121 goto nla_put_failure;
1b8ec87a 2122 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) &&
3713b4e3 2123 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP))
9360ffd1 2124 goto nla_put_failure;
86e8cf98
JB
2125 state->split_start++;
2126 if (state->split)
3713b4e3 2127 break;
7b506ff6 2128 fallthrough;
3713b4e3
JB
2129 case 1:
2130 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES,
1b8ec87a
ZG
2131 sizeof(u32) * rdev->wiphy.n_cipher_suites,
2132 rdev->wiphy.cipher_suites))
3713b4e3 2133 goto nla_put_failure;
4745fc09 2134
3713b4e3 2135 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
1b8ec87a 2136 rdev->wiphy.max_num_pmkids))
3713b4e3 2137 goto nla_put_failure;
b23aa676 2138
1b8ec87a 2139 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3713b4e3 2140 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE))
9360ffd1 2141 goto nla_put_failure;
b23aa676 2142
3713b4e3 2143 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX,
1b8ec87a 2144 rdev->wiphy.available_antennas_tx) ||
3713b4e3 2145 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX,
1b8ec87a 2146 rdev->wiphy.available_antennas_rx))
9360ffd1 2147 goto nla_put_failure;
b23aa676 2148
1b8ec87a 2149 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) &&
3713b4e3 2150 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD,
1b8ec87a 2151 rdev->wiphy.probe_resp_offload))
3713b4e3 2152 goto nla_put_failure;
8fdc621d 2153
1b8ec87a
ZG
2154 if ((rdev->wiphy.available_antennas_tx ||
2155 rdev->wiphy.available_antennas_rx) &&
2156 rdev->ops->get_antenna) {
3713b4e3
JB
2157 u32 tx_ant = 0, rx_ant = 0;
2158 int res;
7a087e74 2159
1b8ec87a 2160 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant);
3713b4e3
JB
2161 if (!res) {
2162 if (nla_put_u32(msg,
2163 NL80211_ATTR_WIPHY_ANTENNA_TX,
2164 tx_ant) ||
2165 nla_put_u32(msg,
2166 NL80211_ATTR_WIPHY_ANTENNA_RX,
2167 rx_ant))
2168 goto nla_put_failure;
2169 }
2170 }
a293911d 2171
86e8cf98
JB
2172 state->split_start++;
2173 if (state->split)
3713b4e3 2174 break;
7b506ff6 2175 fallthrough;
3713b4e3
JB
2176 case 2:
2177 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES,
1b8ec87a 2178 rdev->wiphy.interface_modes))
3713b4e3 2179 goto nla_put_failure;
86e8cf98
JB
2180 state->split_start++;
2181 if (state->split)
3713b4e3 2182 break;
7b506ff6 2183 fallthrough;
3713b4e3 2184 case 3:
ae0be8de
MK
2185 nl_bands = nla_nest_start_noflag(msg,
2186 NL80211_ATTR_WIPHY_BANDS);
3713b4e3
JB
2187 if (!nl_bands)
2188 goto nla_put_failure;
f7ca38df 2189
86e8cf98 2190 for (band = state->band_start;
57fbcce3 2191 band < NUM_NL80211_BANDS; band++) {
3713b4e3 2192 struct ieee80211_supported_band *sband;
2e161f78 2193
1b8ec87a 2194 sband = rdev->wiphy.bands[band];
2e161f78 2195
3713b4e3
JB
2196 if (!sband)
2197 continue;
2198
ae0be8de 2199 nl_band = nla_nest_start_noflag(msg, band);
3713b4e3 2200 if (!nl_band)
2e161f78 2201 goto nla_put_failure;
3713b4e3 2202
86e8cf98 2203 switch (state->chan_start) {
3713b4e3
JB
2204 case 0:
2205 if (nl80211_send_band_rateinfo(msg, sband))
9360ffd1 2206 goto nla_put_failure;
86e8cf98
JB
2207 state->chan_start++;
2208 if (state->split)
3713b4e3 2209 break;
7b506ff6 2210 fallthrough;
3713b4e3
JB
2211 default:
2212 /* add frequencies */
ae0be8de
MK
2213 nl_freqs = nla_nest_start_noflag(msg,
2214 NL80211_BAND_ATTR_FREQS);
3713b4e3
JB
2215 if (!nl_freqs)
2216 goto nla_put_failure;
2217
86e8cf98 2218 for (i = state->chan_start - 1;
3713b4e3
JB
2219 i < sband->n_channels;
2220 i++) {
ae0be8de
MK
2221 nl_freq = nla_nest_start_noflag(msg,
2222 i);
3713b4e3
JB
2223 if (!nl_freq)
2224 goto nla_put_failure;
2225
2226 chan = &sband->channels[i];
2227
86e8cf98 2228 if (nl80211_msg_put_channel(
50f32718 2229 msg, &rdev->wiphy, chan,
86e8cf98 2230 state->split))
3713b4e3
JB
2231 goto nla_put_failure;
2232
2233 nla_nest_end(msg, nl_freq);
86e8cf98 2234 if (state->split)
3713b4e3
JB
2235 break;
2236 }
2237 if (i < sband->n_channels)
86e8cf98 2238 state->chan_start = i + 2;
3713b4e3 2239 else
86e8cf98 2240 state->chan_start = 0;
3713b4e3
JB
2241 nla_nest_end(msg, nl_freqs);
2242 }
2243
2244 nla_nest_end(msg, nl_band);
2245
86e8cf98 2246 if (state->split) {
3713b4e3 2247 /* start again here */
86e8cf98 2248 if (state->chan_start)
3713b4e3
JB
2249 band--;
2250 break;
2e161f78 2251 }
2e161f78 2252 }
3713b4e3 2253 nla_nest_end(msg, nl_bands);
2e161f78 2254
57fbcce3 2255 if (band < NUM_NL80211_BANDS)
86e8cf98 2256 state->band_start = band + 1;
3713b4e3 2257 else
86e8cf98 2258 state->band_start = 0;
74b70a4e 2259
3713b4e3 2260 /* if bands & channels are done, continue outside */
86e8cf98
JB
2261 if (state->band_start == 0 && state->chan_start == 0)
2262 state->split_start++;
2263 if (state->split)
3713b4e3 2264 break;
7b506ff6 2265 fallthrough;
3713b4e3 2266 case 4:
ae0be8de
MK
2267 nl_cmds = nla_nest_start_noflag(msg,
2268 NL80211_ATTR_SUPPORTED_COMMANDS);
3713b4e3 2269 if (!nl_cmds)
2e161f78
JB
2270 goto nla_put_failure;
2271
1794899e
JB
2272 i = nl80211_add_commands_unsplit(rdev, msg);
2273 if (i < 0)
2274 goto nla_put_failure;
86e8cf98 2275 if (state->split) {
5de17984
AS
2276 CMD(crit_proto_start, CRIT_PROTOCOL_START);
2277 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP);
1b8ec87a 2278 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)
16ef1fe2 2279 CMD(channel_switch, CHANNEL_SWITCH);
02df00eb 2280 CMD(set_qos_map, SET_QOS_MAP);
723e73ac
JB
2281 if (rdev->wiphy.features &
2282 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)
960d01ac 2283 CMD(add_tx_ts, ADD_TX_TS);
ce0ce13a 2284 CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST);
088e8df8 2285 CMD(update_connect_params, UPDATE_CONNECT_PARAMS);
7010998c 2286 CMD(update_ft_ies, UPDATE_FT_IES);
5de17984 2287 }
3713b4e3 2288#undef CMD
ff1b6e69 2289
3713b4e3 2290 nla_nest_end(msg, nl_cmds);
86e8cf98
JB
2291 state->split_start++;
2292 if (state->split)
3713b4e3 2293 break;
7b506ff6 2294 fallthrough;
3713b4e3 2295 case 5:
1b8ec87a
ZG
2296 if (rdev->ops->remain_on_channel &&
2297 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) &&
3713b4e3
JB
2298 nla_put_u32(msg,
2299 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
1b8ec87a 2300 rdev->wiphy.max_remain_on_channel_duration))
3713b4e3
JB
2301 goto nla_put_failure;
2302
1b8ec87a 2303 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) &&
3713b4e3
JB
2304 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK))
2305 goto nla_put_failure;
2306
2307 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes))
2308 goto nla_put_failure;
86e8cf98
JB
2309 state->split_start++;
2310 if (state->split)
3713b4e3 2311 break;
7b506ff6 2312 fallthrough;
3713b4e3
JB
2313 case 6:
2314#ifdef CONFIG_PM
1b8ec87a 2315 if (nl80211_send_wowlan(msg, rdev, state->split))
3713b4e3 2316 goto nla_put_failure;
86e8cf98
JB
2317 state->split_start++;
2318 if (state->split)
3713b4e3
JB
2319 break;
2320#else
86e8cf98 2321 state->split_start++;
dfb89c56 2322#endif
7b506ff6 2323 fallthrough;
3713b4e3
JB
2324 case 7:
2325 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES,
1b8ec87a 2326 rdev->wiphy.software_iftypes))
3713b4e3 2327 goto nla_put_failure;
ff1b6e69 2328
1b8ec87a 2329 if (nl80211_put_iface_combinations(&rdev->wiphy, msg,
86e8cf98 2330 state->split))
3713b4e3 2331 goto nla_put_failure;
7527a782 2332
86e8cf98
JB
2333 state->split_start++;
2334 if (state->split)
3713b4e3 2335 break;
7b506ff6 2336 fallthrough;
3713b4e3 2337 case 8:
1b8ec87a 2338 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) &&
3713b4e3 2339 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME,
1b8ec87a 2340 rdev->wiphy.ap_sme_capa))
3713b4e3 2341 goto nla_put_failure;
7527a782 2342
1b8ec87a 2343 features = rdev->wiphy.features;
fe1abafd
JB
2344 /*
2345 * We can only add the per-channel limit information if the
2346 * dump is split, otherwise it makes it too big. Therefore
2347 * only advertise it in that case.
2348 */
86e8cf98 2349 if (state->split)
fe1abafd
JB
2350 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS;
2351 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features))
3713b4e3 2352 goto nla_put_failure;
562a7480 2353
1b8ec87a 2354 if (rdev->wiphy.ht_capa_mod_mask &&
3713b4e3 2355 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK,
1b8ec87a
ZG
2356 sizeof(*rdev->wiphy.ht_capa_mod_mask),
2357 rdev->wiphy.ht_capa_mod_mask))
3713b4e3 2358 goto nla_put_failure;
1f074bd8 2359
1b8ec87a
ZG
2360 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME &&
2361 rdev->wiphy.max_acl_mac_addrs &&
3713b4e3 2362 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX,
1b8ec87a 2363 rdev->wiphy.max_acl_mac_addrs))
3713b4e3 2364 goto nla_put_failure;
7e7c8926 2365
3713b4e3
JB
2366 /*
2367 * Any information below this point is only available to
2368 * applications that can deal with it being split. This
2369 * helps ensure that newly added capabilities don't break
2370 * older tools by overrunning their buffers.
2371 *
2372 * We still increment split_start so that in the split
2373 * case we'll continue with more data in the next round,
2374 * but break unconditionally so unsplit data stops here.
2375 */
86e8cf98 2376 state->split_start++;
3713b4e3
JB
2377 break;
2378 case 9:
1b8ec87a 2379 if (rdev->wiphy.extended_capabilities &&
fe1abafd 2380 (nla_put(msg, NL80211_ATTR_EXT_CAPA,
1b8ec87a
ZG
2381 rdev->wiphy.extended_capabilities_len,
2382 rdev->wiphy.extended_capabilities) ||
fe1abafd 2383 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
1b8ec87a
ZG
2384 rdev->wiphy.extended_capabilities_len,
2385 rdev->wiphy.extended_capabilities_mask)))
fe1abafd 2386 goto nla_put_failure;
a50df0c4 2387
1b8ec87a 2388 if (rdev->wiphy.vht_capa_mod_mask &&
ee2aca34 2389 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK,
1b8ec87a
ZG
2390 sizeof(*rdev->wiphy.vht_capa_mod_mask),
2391 rdev->wiphy.vht_capa_mod_mask))
ee2aca34
JB
2392 goto nla_put_failure;
2393
ae6fa4d5
DK
2394 if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN,
2395 rdev->wiphy.perm_addr))
2396 goto nla_put_failure;
2397
2398 if (!is_zero_ether_addr(rdev->wiphy.addr_mask) &&
2399 nla_put(msg, NL80211_ATTR_MAC_MASK, ETH_ALEN,
2400 rdev->wiphy.addr_mask))
2401 goto nla_put_failure;
2402
2403 if (rdev->wiphy.n_addresses > 1) {
2404 void *attr;
2405
2406 attr = nla_nest_start(msg, NL80211_ATTR_MAC_ADDRS);
2407 if (!attr)
2408 goto nla_put_failure;
2409
2410 for (i = 0; i < rdev->wiphy.n_addresses; i++)
2411 if (nla_put(msg, i + 1, ETH_ALEN,
2412 rdev->wiphy.addresses[i].addr))
2413 goto nla_put_failure;
2414
2415 nla_nest_end(msg, attr);
2416 }
2417
be29b99a
AK
2418 state->split_start++;
2419 break;
2420 case 10:
1b8ec87a 2421 if (nl80211_send_coalesce(msg, rdev))
be29b99a
AK
2422 goto nla_put_failure;
2423
1b8ec87a 2424 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) &&
01e0daa4
FF
2425 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) ||
2426 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ)))
2427 goto nla_put_failure;
b43504cf 2428
1b8ec87a 2429 if (rdev->wiphy.max_ap_assoc_sta &&
b43504cf 2430 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA,
1b8ec87a 2431 rdev->wiphy.max_ap_assoc_sta))
b43504cf
JM
2432 goto nla_put_failure;
2433
ad7e718c
JB
2434 state->split_start++;
2435 break;
2436 case 11:
1b8ec87a 2437 if (rdev->wiphy.n_vendor_commands) {
567ffc35
JB
2438 const struct nl80211_vendor_cmd_info *info;
2439 struct nlattr *nested;
2440
ae0be8de
MK
2441 nested = nla_nest_start_noflag(msg,
2442 NL80211_ATTR_VENDOR_DATA);
567ffc35
JB
2443 if (!nested)
2444 goto nla_put_failure;
2445
1b8ec87a
ZG
2446 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
2447 info = &rdev->wiphy.vendor_commands[i].info;
567ffc35
JB
2448 if (nla_put(msg, i + 1, sizeof(*info), info))
2449 goto nla_put_failure;
2450 }
2451 nla_nest_end(msg, nested);
2452 }
2453
1b8ec87a 2454 if (rdev->wiphy.n_vendor_events) {
567ffc35
JB
2455 const struct nl80211_vendor_cmd_info *info;
2456 struct nlattr *nested;
ad7e718c 2457
ae0be8de
MK
2458 nested = nla_nest_start_noflag(msg,
2459 NL80211_ATTR_VENDOR_EVENTS);
567ffc35 2460 if (!nested)
ad7e718c 2461 goto nla_put_failure;
567ffc35 2462
1b8ec87a
ZG
2463 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) {
2464 info = &rdev->wiphy.vendor_events[i];
567ffc35
JB
2465 if (nla_put(msg, i + 1, sizeof(*info), info))
2466 goto nla_put_failure;
2467 }
2468 nla_nest_end(msg, nested);
2469 }
9a774c78
AO
2470 state->split_start++;
2471 break;
2472 case 12:
2473 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH &&
2474 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS,
2475 rdev->wiphy.max_num_csa_counters))
2476 goto nla_put_failure;
01e0daa4 2477
1bdd716c
AN
2478 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
2479 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
2480 goto nla_put_failure;
2481
ca986ad9
AVS
2482 if (rdev->wiphy.max_sched_scan_reqs &&
2483 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_MAX_REQS,
2484 rdev->wiphy.max_sched_scan_reqs))
2485 goto nla_put_failure;
2486
d75bb06b
GKS
2487 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES,
2488 sizeof(rdev->wiphy.ext_features),
2489 rdev->wiphy.ext_features))
2490 goto nla_put_failure;
2491
38de03d2
AS
2492 if (rdev->wiphy.bss_select_support) {
2493 struct nlattr *nested;
2494 u32 bss_select_support = rdev->wiphy.bss_select_support;
2495
ae0be8de
MK
2496 nested = nla_nest_start_noflag(msg,
2497 NL80211_ATTR_BSS_SELECT);
38de03d2
AS
2498 if (!nested)
2499 goto nla_put_failure;
2500
2501 i = 0;
2502 while (bss_select_support) {
2503 if ((bss_select_support & 1) &&
2504 nla_put_flag(msg, i))
2505 goto nla_put_failure;
2506 i++;
2507 bss_select_support >>= 1;
2508 }
2509 nla_nest_end(msg, nested);
2510 }
2511
019ae3a9
KV
2512 state->split_start++;
2513 break;
2514 case 13:
2515 if (rdev->wiphy.num_iftype_ext_capab &&
2516 rdev->wiphy.iftype_ext_capab) {
2517 struct nlattr *nested_ext_capab, *nested;
2518
ae0be8de
MK
2519 nested = nla_nest_start_noflag(msg,
2520 NL80211_ATTR_IFTYPE_EXT_CAPA);
019ae3a9
KV
2521 if (!nested)
2522 goto nla_put_failure;
2523
2524 for (i = state->capa_start;
2525 i < rdev->wiphy.num_iftype_ext_capab; i++) {
2526 const struct wiphy_iftype_ext_capab *capab;
2527
2528 capab = &rdev->wiphy.iftype_ext_capab[i];
2529
ae0be8de
MK
2530 nested_ext_capab = nla_nest_start_noflag(msg,
2531 i);
019ae3a9
KV
2532 if (!nested_ext_capab ||
2533 nla_put_u32(msg, NL80211_ATTR_IFTYPE,
2534 capab->iftype) ||
2535 nla_put(msg, NL80211_ATTR_EXT_CAPA,
2536 capab->extended_capabilities_len,
2537 capab->extended_capabilities) ||
2538 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK,
2539 capab->extended_capabilities_len,
2540 capab->extended_capabilities_mask))
2541 goto nla_put_failure;
2542
2543 nla_nest_end(msg, nested_ext_capab);
2544 if (state->split)
2545 break;
2546 }
2547 nla_nest_end(msg, nested);
2548 if (i < rdev->wiphy.num_iftype_ext_capab) {
2549 state->capa_start = i + 1;
2550 break;
2551 }
2552 }
2553
8585989d
LC
2554 if (nla_put_u32(msg, NL80211_ATTR_BANDS,
2555 rdev->wiphy.nan_supported_bands))
2556 goto nla_put_failure;
2557
52539ca8
THJ
2558 if (wiphy_ext_feature_isset(&rdev->wiphy,
2559 NL80211_EXT_FEATURE_TXQS)) {
2560 struct cfg80211_txq_stats txqstats = {};
2561 int res;
2562
2563 res = rdev_get_txq_stats(rdev, NULL, &txqstats);
2564 if (!res &&
2565 !nl80211_put_txq_stats(msg, &txqstats,
2566 NL80211_ATTR_TXQ_STATS))
2567 goto nla_put_failure;
2568
2569 if (nla_put_u32(msg, NL80211_ATTR_TXQ_LIMIT,
2570 rdev->wiphy.txq_limit))
2571 goto nla_put_failure;
2572 if (nla_put_u32(msg, NL80211_ATTR_TXQ_MEMORY_LIMIT,
2573 rdev->wiphy.txq_memory_limit))
2574 goto nla_put_failure;
2575 if (nla_put_u32(msg, NL80211_ATTR_TXQ_QUANTUM,
2576 rdev->wiphy.txq_quantum))
2577 goto nla_put_failure;
2578 }
2579
9bb7e0f2
JB
2580 state->split_start++;
2581 break;
2582 case 14:
2583 if (nl80211_send_pmsr_capa(rdev, msg))
2584 goto nla_put_failure;
2585
ab4dfa20
VJ
2586 state->split_start++;
2587 break;
2588 case 15:
2589 if (rdev->wiphy.akm_suites &&
2590 nla_put(msg, NL80211_ATTR_AKM_SUITES,
2591 sizeof(u32) * rdev->wiphy.n_akm_suites,
2592 rdev->wiphy.akm_suites))
2593 goto nla_put_failure;
2594
d6039a34
VJ
2595 if (nl80211_put_iftype_akm_suites(rdev, msg))
2596 goto nla_put_failure;
2597
3710a8a6
JB
2598 if (nl80211_put_tid_config_support(rdev, msg))
2599 goto nla_put_failure;
2600
3713b4e3 2601 /* done */
86e8cf98 2602 state->split_start = 0;
3713b4e3
JB
2603 break;
2604 }
3bb20556 2605 finish:
053c095a
JB
2606 genlmsg_end(msg, hdr);
2607 return 0;
55682965
JB
2608
2609 nla_put_failure:
bc3ed28c
TG
2610 genlmsg_cancel(msg, hdr);
2611 return -EMSGSIZE;
55682965
JB
2612}
2613
86e8cf98
JB
2614static int nl80211_dump_wiphy_parse(struct sk_buff *skb,
2615 struct netlink_callback *cb,
2616 struct nl80211_dump_wiphy_state *state)
2617{
50508d94
JB
2618 struct nlattr **tb = kcalloc(NUM_NL80211_ATTR, sizeof(*tb), GFP_KERNEL);
2619 int ret;
2620
2621 if (!tb)
2622 return -ENOMEM;
2623
2624 ret = nlmsg_parse_deprecated(cb->nlh,
2625 GENL_HDRLEN + nl80211_fam.hdrsize,
2626 tb, nl80211_fam.maxattr,
2627 nl80211_policy, NULL);
86e8cf98 2628 /* ignore parse errors for backward compatibility */
50508d94
JB
2629 if (ret) {
2630 ret = 0;
2631 goto out;
2632 }
86e8cf98
JB
2633
2634 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP];
2635 if (tb[NL80211_ATTR_WIPHY])
2636 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]);
2637 if (tb[NL80211_ATTR_WDEV])
2638 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32;
2639 if (tb[NL80211_ATTR_IFINDEX]) {
2640 struct net_device *netdev;
2641 struct cfg80211_registered_device *rdev;
2642 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]);
2643
7f2b8562 2644 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
50508d94
JB
2645 if (!netdev) {
2646 ret = -ENODEV;
2647 goto out;
2648 }
86e8cf98 2649 if (netdev->ieee80211_ptr) {
f26cbf40 2650 rdev = wiphy_to_rdev(
86e8cf98
JB
2651 netdev->ieee80211_ptr->wiphy);
2652 state->filter_wiphy = rdev->wiphy_idx;
2653 }
86e8cf98
JB
2654 }
2655
50508d94
JB
2656 ret = 0;
2657out:
2658 kfree(tb);
2659 return ret;
86e8cf98
JB
2660}
2661
55682965
JB
2662static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
2663{
645e77de 2664 int idx = 0, ret;
86e8cf98 2665 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0];
1b8ec87a 2666 struct cfg80211_registered_device *rdev;
3a5a423b 2667
5fe231e8 2668 rtnl_lock();
86e8cf98
JB
2669 if (!state) {
2670 state = kzalloc(sizeof(*state), GFP_KERNEL);
57ed5cd6
JL
2671 if (!state) {
2672 rtnl_unlock();
86e8cf98 2673 return -ENOMEM;
3713b4e3 2674 }
86e8cf98
JB
2675 state->filter_wiphy = -1;
2676 ret = nl80211_dump_wiphy_parse(skb, cb, state);
2677 if (ret) {
2678 kfree(state);
2679 rtnl_unlock();
2680 return ret;
3713b4e3 2681 }
86e8cf98 2682 cb->args[0] = (long)state;
3713b4e3
JB
2683 }
2684
1b8ec87a
ZG
2685 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
2686 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 2687 continue;
86e8cf98 2688 if (++idx <= state->start)
55682965 2689 continue;
86e8cf98 2690 if (state->filter_wiphy != -1 &&
1b8ec87a 2691 state->filter_wiphy != rdev->wiphy_idx)
3713b4e3
JB
2692 continue;
2693 /* attempt to fit multiple wiphy data chunks into the skb */
2694 do {
3bb20556
JB
2695 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY,
2696 skb,
3713b4e3
JB
2697 NETLINK_CB(cb->skb).portid,
2698 cb->nlh->nlmsg_seq,
86e8cf98 2699 NLM_F_MULTI, state);
3713b4e3
JB
2700 if (ret < 0) {
2701 /*
2702 * If sending the wiphy data didn't fit (ENOBUFS
2703 * or EMSGSIZE returned), this SKB is still
2704 * empty (so it's not too big because another
2705 * wiphy dataset is already in the skb) and
2706 * we've not tried to adjust the dump allocation
2707 * yet ... then adjust the alloc size to be
2708 * bigger, and return 1 but with the empty skb.
2709 * This results in an empty message being RX'ed
2710 * in userspace, but that is ignored.
2711 *
2712 * We can then retry with the larger buffer.
2713 */
2714 if ((ret == -ENOBUFS || ret == -EMSGSIZE) &&
f12cb289 2715 !skb->len && !state->split &&
3713b4e3
JB
2716 cb->min_dump_alloc < 4096) {
2717 cb->min_dump_alloc = 4096;
f12cb289 2718 state->split_start = 0;
d98cae64 2719 rtnl_unlock();
3713b4e3
JB
2720 return 1;
2721 }
2722 idx--;
2723 break;
645e77de 2724 }
86e8cf98 2725 } while (state->split_start > 0);
3713b4e3 2726 break;
55682965 2727 }
5fe231e8 2728 rtnl_unlock();
55682965 2729
86e8cf98 2730 state->start = idx;
55682965
JB
2731
2732 return skb->len;
2733}
2734
86e8cf98
JB
2735static int nl80211_dump_wiphy_done(struct netlink_callback *cb)
2736{
2737 kfree((void *)cb->args[0]);
2738 return 0;
2739}
2740
55682965
JB
2741static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
2742{
2743 struct sk_buff *msg;
1b8ec87a 2744 struct cfg80211_registered_device *rdev = info->user_ptr[0];
86e8cf98 2745 struct nl80211_dump_wiphy_state state = {};
55682965 2746
645e77de 2747 msg = nlmsg_new(4096, GFP_KERNEL);
55682965 2748 if (!msg)
4c476991 2749 return -ENOMEM;
55682965 2750
3bb20556
JB
2751 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg,
2752 info->snd_portid, info->snd_seq, 0,
86e8cf98 2753 &state) < 0) {
4c476991
JB
2754 nlmsg_free(msg);
2755 return -ENOBUFS;
2756 }
55682965 2757
134e6375 2758 return genlmsg_reply(msg, info);
55682965
JB
2759}
2760
31888487
JM
2761static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
2762 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 },
2763 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 },
2764 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 },
2765 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 },
2766 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 },
2767};
2768
2769static int parse_txq_params(struct nlattr *tb[],
2770 struct ieee80211_txq_params *txq_params)
2771{
259d8c1e
DW
2772 u8 ac;
2773
a3304b0a 2774 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] ||
31888487
JM
2775 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
2776 !tb[NL80211_TXQ_ATTR_AIFS])
2777 return -EINVAL;
2778
259d8c1e 2779 ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]);
31888487
JM
2780 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
2781 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
2782 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
2783 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
2784
259d8c1e 2785 if (ac >= NL80211_NUM_ACS)
a3304b0a 2786 return -EINVAL;
259d8c1e 2787 txq_params->ac = array_index_nospec(ac, NL80211_NUM_ACS);
31888487
JM
2788 return 0;
2789}
2790
f444de05
JB
2791static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
2792{
2793 /*
cc1d2806
JB
2794 * You can only set the channel explicitly for WDS interfaces,
2795 * all others have their channel managed via their respective
2796 * "establish a connection" command (connect, join, ...)
2797 *
2798 * For AP/GO and mesh mode, the channel can be set with the
2799 * channel userspace API, but is only stored and passed to the
2800 * low-level driver when the AP starts or the mesh is joined.
2801 * This is for backward compatibility, userspace can also give
2802 * the channel in the start-ap or join-mesh commands instead.
f444de05
JB
2803 *
2804 * Monitors are special as they are normally slaved to
e8c9bd5b
JB
2805 * whatever else is going on, so they have their own special
2806 * operation to set the monitor channel if possible.
f444de05
JB
2807 */
2808 return !wdev ||
2809 wdev->iftype == NL80211_IFTYPE_AP ||
f444de05 2810 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
074ac8df
JB
2811 wdev->iftype == NL80211_IFTYPE_MONITOR ||
2812 wdev->iftype == NL80211_IFTYPE_P2P_GO;
f444de05
JB
2813}
2814
9bb7e0f2
JB
2815int nl80211_parse_chandef(struct cfg80211_registered_device *rdev,
2816 struct genl_info *info,
2817 struct cfg80211_chan_def *chandef)
683b6d3b 2818{
49f9cf0e
JB
2819 struct netlink_ext_ack *extack = info->extack;
2820 struct nlattr **attrs = info->attrs;
dbeca2ea 2821 u32 control_freq;
683b6d3b 2822
49f9cf0e 2823 if (!attrs[NL80211_ATTR_WIPHY_FREQ])
683b6d3b
JB
2824 return -EINVAL;
2825
942ba88b
TP
2826 control_freq = MHZ_TO_KHZ(
2827 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
2828 if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
2829 control_freq +=
2830 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
683b6d3b 2831
f43e5210 2832 memset(chandef, 0, sizeof(*chandef));
942ba88b 2833 chandef->chan = ieee80211_get_channel_khz(&rdev->wiphy, control_freq);
3d9d1d66 2834 chandef->width = NL80211_CHAN_WIDTH_20_NOHT;
942ba88b
TP
2835 chandef->center_freq1 = KHZ_TO_MHZ(control_freq);
2836 chandef->freq1_offset = control_freq % 1000;
3d9d1d66 2837 chandef->center_freq2 = 0;
683b6d3b
JB
2838
2839 /* Primary channel not allowed */
49f9cf0e
JB
2840 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED) {
2841 NL_SET_ERR_MSG_ATTR(extack, attrs[NL80211_ATTR_WIPHY_FREQ],
2842 "Channel is disabled");
683b6d3b 2843 return -EINVAL;
49f9cf0e 2844 }
683b6d3b 2845
49f9cf0e 2846 if (attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
3d9d1d66
JB
2847 enum nl80211_channel_type chantype;
2848
49f9cf0e 2849 chantype = nla_get_u32(attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
3d9d1d66
JB
2850
2851 switch (chantype) {
2852 case NL80211_CHAN_NO_HT:
2853 case NL80211_CHAN_HT20:
2854 case NL80211_CHAN_HT40PLUS:
2855 case NL80211_CHAN_HT40MINUS:
2856 cfg80211_chandef_create(chandef, chandef->chan,
2857 chantype);
ffa4629e 2858 /* user input for center_freq is incorrect */
49f9cf0e
JB
2859 if (attrs[NL80211_ATTR_CENTER_FREQ1] &&
2860 chandef->center_freq1 != nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ1])) {
2861 NL_SET_ERR_MSG_ATTR(extack,
2862 attrs[NL80211_ATTR_CENTER_FREQ1],
2863 "bad center frequency 1");
ffa4629e 2864 return -EINVAL;
49f9cf0e 2865 }
ffa4629e 2866 /* center_freq2 must be zero */
49f9cf0e
JB
2867 if (attrs[NL80211_ATTR_CENTER_FREQ2] &&
2868 nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ2])) {
2869 NL_SET_ERR_MSG_ATTR(extack,
2870 attrs[NL80211_ATTR_CENTER_FREQ2],
2871 "center frequency 2 can't be used");
ffa4629e 2872 return -EINVAL;
49f9cf0e 2873 }
3d9d1d66
JB
2874 break;
2875 default:
49f9cf0e
JB
2876 NL_SET_ERR_MSG_ATTR(extack,
2877 attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE],
2878 "invalid channel type");
3d9d1d66
JB
2879 return -EINVAL;
2880 }
49f9cf0e 2881 } else if (attrs[NL80211_ATTR_CHANNEL_WIDTH]) {
3d9d1d66 2882 chandef->width =
49f9cf0e 2883 nla_get_u32(attrs[NL80211_ATTR_CHANNEL_WIDTH]);
942ba88b 2884 if (attrs[NL80211_ATTR_CENTER_FREQ1]) {
3d9d1d66 2885 chandef->center_freq1 =
49f9cf0e 2886 nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ1]);
942ba88b
TP
2887 if (attrs[NL80211_ATTR_CENTER_FREQ1_OFFSET])
2888 chandef->freq1_offset = nla_get_u32(
2889 attrs[NL80211_ATTR_CENTER_FREQ1_OFFSET]);
2890 else
2891 chandef->freq1_offset = 0;
2892 }
49f9cf0e 2893 if (attrs[NL80211_ATTR_CENTER_FREQ2])
3d9d1d66 2894 chandef->center_freq2 =
49f9cf0e 2895 nla_get_u32(attrs[NL80211_ATTR_CENTER_FREQ2]);
3d9d1d66
JB
2896 }
2897
2a38075c
AAL
2898 if (info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]) {
2899 chandef->edmg.channels =
2900 nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]);
2901
2902 if (info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG])
2903 chandef->edmg.bw_config =
2904 nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG]);
2905 } else {
2906 chandef->edmg.bw_config = 0;
2907 chandef->edmg.channels = 0;
2908 }
2909
49f9cf0e
JB
2910 if (!cfg80211_chandef_valid(chandef)) {
2911 NL_SET_ERR_MSG(extack, "invalid channel definition");
3d9d1d66 2912 return -EINVAL;
49f9cf0e 2913 }
3d9d1d66 2914
9f5e8f6e 2915 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef,
49f9cf0e
JB
2916 IEEE80211_CHAN_DISABLED)) {
2917 NL_SET_ERR_MSG(extack, "(extension) channel is disabled");
3d9d1d66 2918 return -EINVAL;
49f9cf0e 2919 }
3d9d1d66 2920
2f301ab2
SW
2921 if ((chandef->width == NL80211_CHAN_WIDTH_5 ||
2922 chandef->width == NL80211_CHAN_WIDTH_10) &&
49f9cf0e
JB
2923 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ)) {
2924 NL_SET_ERR_MSG(extack, "5/10 MHz not supported");
2f301ab2 2925 return -EINVAL;
49f9cf0e 2926 }
2f301ab2 2927
683b6d3b
JB
2928 return 0;
2929}
2930
f444de05 2931static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
e16821bc 2932 struct net_device *dev,
f444de05
JB
2933 struct genl_info *info)
2934{
683b6d3b 2935 struct cfg80211_chan_def chandef;
f444de05 2936 int result;
e8c9bd5b 2937 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR;
e16821bc 2938 struct wireless_dev *wdev = NULL;
e8c9bd5b 2939
e16821bc
JM
2940 if (dev)
2941 wdev = dev->ieee80211_ptr;
f444de05
JB
2942 if (!nl80211_can_set_dev_channel(wdev))
2943 return -EOPNOTSUPP;
e16821bc
JM
2944 if (wdev)
2945 iftype = wdev->iftype;
f444de05 2946
683b6d3b
JB
2947 result = nl80211_parse_chandef(rdev, info, &chandef);
2948 if (result)
2949 return result;
f444de05 2950
e8c9bd5b 2951 switch (iftype) {
aa430da4
JB
2952 case NL80211_IFTYPE_AP:
2953 case NL80211_IFTYPE_P2P_GO:
923b352f
AN
2954 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
2955 iftype)) {
aa430da4
JB
2956 result = -EINVAL;
2957 break;
2958 }
e16821bc
JM
2959 if (wdev->beacon_interval) {
2960 if (!dev || !rdev->ops->set_ap_chanwidth ||
2961 !(rdev->wiphy.features &
2962 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) {
2963 result = -EBUSY;
2964 break;
2965 }
2966
2967 /* Only allow dynamic channel width changes */
2968 if (chandef.chan != wdev->preset_chandef.chan) {
2969 result = -EBUSY;
2970 break;
2971 }
2972 result = rdev_set_ap_chanwidth(rdev, dev, &chandef);
2973 if (result)
2974 break;
2975 }
683b6d3b 2976 wdev->preset_chandef = chandef;
aa430da4
JB
2977 result = 0;
2978 break;
cc1d2806 2979 case NL80211_IFTYPE_MESH_POINT:
683b6d3b 2980 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef);
cc1d2806 2981 break;
e8c9bd5b 2982 case NL80211_IFTYPE_MONITOR:
683b6d3b 2983 result = cfg80211_set_monitor_channel(rdev, &chandef);
e8c9bd5b 2984 break;
aa430da4 2985 default:
e8c9bd5b 2986 result = -EINVAL;
f444de05 2987 }
f444de05
JB
2988
2989 return result;
2990}
2991
2992static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
2993{
4c476991
JB
2994 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2995 struct net_device *netdev = info->user_ptr[1];
f444de05 2996
e16821bc 2997 return __nl80211_set_channel(rdev, netdev, info);
f444de05
JB
2998}
2999
e8347eba
BJ
3000static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
3001{
43b19952
JB
3002 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3003 struct net_device *dev = info->user_ptr[1];
3004 struct wireless_dev *wdev = dev->ieee80211_ptr;
388ac775 3005 const u8 *bssid;
e8347eba
BJ
3006
3007 if (!info->attrs[NL80211_ATTR_MAC])
3008 return -EINVAL;
3009
43b19952
JB
3010 if (netif_running(dev))
3011 return -EBUSY;
e8347eba 3012
43b19952
JB
3013 if (!rdev->ops->set_wds_peer)
3014 return -EOPNOTSUPP;
e8347eba 3015
43b19952
JB
3016 if (wdev->iftype != NL80211_IFTYPE_WDS)
3017 return -EOPNOTSUPP;
e8347eba
BJ
3018
3019 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
e35e4d28 3020 return rdev_set_wds_peer(rdev, dev, bssid);
e8347eba
BJ
3021}
3022
55682965
JB
3023static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
3024{
3025 struct cfg80211_registered_device *rdev;
f444de05
JB
3026 struct net_device *netdev = NULL;
3027 struct wireless_dev *wdev;
a1e567c8 3028 int result = 0, rem_txq_params = 0;
31888487 3029 struct nlattr *nl_txq_params;
b9a5f8ca
JM
3030 u32 changed;
3031 u8 retry_short = 0, retry_long = 0;
3032 u32 frag_threshold = 0, rts_threshold = 0;
81077e82 3033 u8 coverage_class = 0;
52539ca8 3034 u32 txq_limit = 0, txq_memory_limit = 0, txq_quantum = 0;
55682965 3035
5fe231e8
JB
3036 ASSERT_RTNL();
3037
f444de05
JB
3038 /*
3039 * Try to find the wiphy and netdev. Normally this
3040 * function shouldn't need the netdev, but this is
3041 * done for backward compatibility -- previously
3042 * setting the channel was done per wiphy, but now
3043 * it is per netdev. Previous userland like hostapd
3044 * also passed a netdev to set_wiphy, so that it is
3045 * possible to let that go to the right netdev!
3046 */
4bbf4d56 3047
f444de05
JB
3048 if (info->attrs[NL80211_ATTR_IFINDEX]) {
3049 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
3050
7f2b8562 3051 netdev = __dev_get_by_index(genl_info_net(info), ifindex);
5fe231e8 3052 if (netdev && netdev->ieee80211_ptr)
f26cbf40 3053 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy);
5fe231e8 3054 else
f444de05 3055 netdev = NULL;
4bbf4d56
JB
3056 }
3057
f444de05 3058 if (!netdev) {
878d9ec7
JB
3059 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info),
3060 info->attrs);
5fe231e8 3061 if (IS_ERR(rdev))
4c476991 3062 return PTR_ERR(rdev);
f444de05
JB
3063 wdev = NULL;
3064 netdev = NULL;
3065 result = 0;
71fe96bf 3066 } else
f444de05 3067 wdev = netdev->ieee80211_ptr;
f444de05
JB
3068
3069 /*
3070 * end workaround code, by now the rdev is available
3071 * and locked, and wdev may or may not be NULL.
3072 */
4bbf4d56
JB
3073
3074 if (info->attrs[NL80211_ATTR_WIPHY_NAME])
31888487
JM
3075 result = cfg80211_dev_rename(
3076 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
4bbf4d56 3077
4bbf4d56 3078 if (result)
7f2b8562 3079 return result;
31888487
JM
3080
3081 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
3082 struct ieee80211_txq_params txq_params;
3083 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
3084
7f2b8562
YX
3085 if (!rdev->ops->set_txq_params)
3086 return -EOPNOTSUPP;
31888487 3087
7f2b8562
YX
3088 if (!netdev)
3089 return -EINVAL;
f70f01c2 3090
133a3ff2 3091 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
7f2b8562
YX
3092 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
3093 return -EINVAL;
133a3ff2 3094
7f2b8562
YX
3095 if (!netif_running(netdev))
3096 return -ENETDOWN;
2b5f8b0b 3097
31888487
JM
3098 nla_for_each_nested(nl_txq_params,
3099 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
3100 rem_txq_params) {
8cb08174
JB
3101 result = nla_parse_nested_deprecated(tb,
3102 NL80211_TXQ_ATTR_MAX,
3103 nl_txq_params,
3104 txq_params_policy,
3105 info->extack);
ae811e21
JB
3106 if (result)
3107 return result;
31888487
JM
3108 result = parse_txq_params(tb, &txq_params);
3109 if (result)
7f2b8562 3110 return result;
31888487 3111
e35e4d28
HG
3112 result = rdev_set_txq_params(rdev, netdev,
3113 &txq_params);
31888487 3114 if (result)
7f2b8562 3115 return result;
31888487
JM
3116 }
3117 }
55682965 3118
72bdcf34 3119 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
e16821bc
JM
3120 result = __nl80211_set_channel(
3121 rdev,
3122 nl80211_can_set_dev_channel(wdev) ? netdev : NULL,
3123 info);
72bdcf34 3124 if (result)
7f2b8562 3125 return result;
72bdcf34
JM
3126 }
3127
98d2ff8b 3128 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
c8442118 3129 struct wireless_dev *txp_wdev = wdev;
98d2ff8b
JO
3130 enum nl80211_tx_power_setting type;
3131 int idx, mbm = 0;
3132
c8442118
JB
3133 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER))
3134 txp_wdev = NULL;
3135
7f2b8562
YX
3136 if (!rdev->ops->set_tx_power)
3137 return -EOPNOTSUPP;
98d2ff8b
JO
3138
3139 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
3140 type = nla_get_u32(info->attrs[idx]);
3141
3142 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
7f2b8562
YX
3143 (type != NL80211_TX_POWER_AUTOMATIC))
3144 return -EINVAL;
98d2ff8b
JO
3145
3146 if (type != NL80211_TX_POWER_AUTOMATIC) {
3147 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
3148 mbm = nla_get_u32(info->attrs[idx]);
3149 }
3150
c8442118 3151 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm);
98d2ff8b 3152 if (result)
7f2b8562 3153 return result;
98d2ff8b
JO
3154 }
3155
afe0cbf8
BR
3156 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
3157 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
3158 u32 tx_ant, rx_ant;
7a087e74 3159
7f531e03
BR
3160 if ((!rdev->wiphy.available_antennas_tx &&
3161 !rdev->wiphy.available_antennas_rx) ||
7f2b8562
YX
3162 !rdev->ops->set_antenna)
3163 return -EOPNOTSUPP;
afe0cbf8
BR
3164
3165 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
3166 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
3167
a7ffac95 3168 /* reject antenna configurations which don't match the
7f531e03
BR
3169 * available antenna masks, except for the "all" mask */
3170 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) ||
7f2b8562
YX
3171 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx)))
3172 return -EINVAL;
a7ffac95 3173
7f531e03
BR
3174 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx;
3175 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx;
a7ffac95 3176
e35e4d28 3177 result = rdev_set_antenna(rdev, tx_ant, rx_ant);
afe0cbf8 3178 if (result)
7f2b8562 3179 return result;
afe0cbf8
BR
3180 }
3181
b9a5f8ca
JM
3182 changed = 0;
3183
3184 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
3185 retry_short = nla_get_u8(
3186 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
7f2b8562 3187
b9a5f8ca
JM
3188 changed |= WIPHY_PARAM_RETRY_SHORT;
3189 }
3190
3191 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
3192 retry_long = nla_get_u8(
3193 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
7f2b8562 3194
b9a5f8ca
JM
3195 changed |= WIPHY_PARAM_RETRY_LONG;
3196 }
3197
3198 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
3199 frag_threshold = nla_get_u32(
3200 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
7f2b8562
YX
3201 if (frag_threshold < 256)
3202 return -EINVAL;
3203
b9a5f8ca
JM
3204 if (frag_threshold != (u32) -1) {
3205 /*
3206 * Fragments (apart from the last one) are required to
3207 * have even length. Make the fragmentation code
3208 * simpler by stripping LSB should someone try to use
3209 * odd threshold value.
3210 */
3211 frag_threshold &= ~0x1;
3212 }
3213 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
3214 }
3215
3216 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
3217 rts_threshold = nla_get_u32(
3218 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
3219 changed |= WIPHY_PARAM_RTS_THRESHOLD;
3220 }
3221
81077e82 3222 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
3057dbfd
LB
3223 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK])
3224 return -EINVAL;
3225
81077e82
LT
3226 coverage_class = nla_get_u8(
3227 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
3228 changed |= WIPHY_PARAM_COVERAGE_CLASS;
3229 }
3230
3057dbfd
LB
3231 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) {
3232 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION))
3233 return -EOPNOTSUPP;
3234
3235 changed |= WIPHY_PARAM_DYN_ACK;
81077e82
LT
3236 }
3237
52539ca8
THJ
3238 if (info->attrs[NL80211_ATTR_TXQ_LIMIT]) {
3239 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3240 NL80211_EXT_FEATURE_TXQS))
3241 return -EOPNOTSUPP;
3242 txq_limit = nla_get_u32(
3243 info->attrs[NL80211_ATTR_TXQ_LIMIT]);
3244 changed |= WIPHY_PARAM_TXQ_LIMIT;
3245 }
3246
3247 if (info->attrs[NL80211_ATTR_TXQ_MEMORY_LIMIT]) {
3248 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3249 NL80211_EXT_FEATURE_TXQS))
3250 return -EOPNOTSUPP;
3251 txq_memory_limit = nla_get_u32(
3252 info->attrs[NL80211_ATTR_TXQ_MEMORY_LIMIT]);
3253 changed |= WIPHY_PARAM_TXQ_MEMORY_LIMIT;
3254 }
3255
3256 if (info->attrs[NL80211_ATTR_TXQ_QUANTUM]) {
3257 if (!wiphy_ext_feature_isset(&rdev->wiphy,
3258 NL80211_EXT_FEATURE_TXQS))
3259 return -EOPNOTSUPP;
3260 txq_quantum = nla_get_u32(
3261 info->attrs[NL80211_ATTR_TXQ_QUANTUM]);
3262 changed |= WIPHY_PARAM_TXQ_QUANTUM;
3263 }
3264
b9a5f8ca
JM
3265 if (changed) {
3266 u8 old_retry_short, old_retry_long;
3267 u32 old_frag_threshold, old_rts_threshold;
81077e82 3268 u8 old_coverage_class;
52539ca8 3269 u32 old_txq_limit, old_txq_memory_limit, old_txq_quantum;
b9a5f8ca 3270
7f2b8562
YX
3271 if (!rdev->ops->set_wiphy_params)
3272 return -EOPNOTSUPP;
b9a5f8ca
JM
3273
3274 old_retry_short = rdev->wiphy.retry_short;
3275 old_retry_long = rdev->wiphy.retry_long;
3276 old_frag_threshold = rdev->wiphy.frag_threshold;
3277 old_rts_threshold = rdev->wiphy.rts_threshold;
81077e82 3278 old_coverage_class = rdev->wiphy.coverage_class;
52539ca8
THJ
3279 old_txq_limit = rdev->wiphy.txq_limit;
3280 old_txq_memory_limit = rdev->wiphy.txq_memory_limit;
3281 old_txq_quantum = rdev->wiphy.txq_quantum;
b9a5f8ca
JM
3282
3283 if (changed & WIPHY_PARAM_RETRY_SHORT)
3284 rdev->wiphy.retry_short = retry_short;
3285 if (changed & WIPHY_PARAM_RETRY_LONG)
3286 rdev->wiphy.retry_long = retry_long;
3287 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
3288 rdev->wiphy.frag_threshold = frag_threshold;
3289 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
3290 rdev->wiphy.rts_threshold = rts_threshold;
81077e82
LT
3291 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
3292 rdev->wiphy.coverage_class = coverage_class;
52539ca8
THJ
3293 if (changed & WIPHY_PARAM_TXQ_LIMIT)
3294 rdev->wiphy.txq_limit = txq_limit;
3295 if (changed & WIPHY_PARAM_TXQ_MEMORY_LIMIT)
3296 rdev->wiphy.txq_memory_limit = txq_memory_limit;
3297 if (changed & WIPHY_PARAM_TXQ_QUANTUM)
3298 rdev->wiphy.txq_quantum = txq_quantum;
b9a5f8ca 3299
e35e4d28 3300 result = rdev_set_wiphy_params(rdev, changed);
b9a5f8ca
JM
3301 if (result) {
3302 rdev->wiphy.retry_short = old_retry_short;
3303 rdev->wiphy.retry_long = old_retry_long;
3304 rdev->wiphy.frag_threshold = old_frag_threshold;
3305 rdev->wiphy.rts_threshold = old_rts_threshold;
81077e82 3306 rdev->wiphy.coverage_class = old_coverage_class;
52539ca8
THJ
3307 rdev->wiphy.txq_limit = old_txq_limit;
3308 rdev->wiphy.txq_memory_limit = old_txq_memory_limit;
3309 rdev->wiphy.txq_quantum = old_txq_quantum;
9189ee31 3310 return result;
b9a5f8ca
JM
3311 }
3312 }
7f2b8562 3313 return 0;
55682965
JB
3314}
3315
683b6d3b 3316static int nl80211_send_chandef(struct sk_buff *msg,
d2859df5 3317 const struct cfg80211_chan_def *chandef)
683b6d3b 3318{
601555cd
JB
3319 if (WARN_ON(!cfg80211_chandef_valid(chandef)))
3320 return -EINVAL;
3d9d1d66 3321
683b6d3b
JB
3322 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
3323 chandef->chan->center_freq))
3324 return -ENOBUFS;
942ba88b
TP
3325 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_OFFSET,
3326 chandef->chan->freq_offset))
3327 return -ENOBUFS;
3d9d1d66
JB
3328 switch (chandef->width) {
3329 case NL80211_CHAN_WIDTH_20_NOHT:
3330 case NL80211_CHAN_WIDTH_20:
3331 case NL80211_CHAN_WIDTH_40:
3332 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
3333 cfg80211_get_chandef_type(chandef)))
3334 return -ENOBUFS;
3335 break;
3336 default:
3337 break;
3338 }
3339 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width))
3340 return -ENOBUFS;
3341 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1))
3342 return -ENOBUFS;
3343 if (chandef->center_freq2 &&
3344 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2))
683b6d3b
JB
3345 return -ENOBUFS;
3346 return 0;
3347}
3348
15e47304 3349static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags,
d726405a 3350 struct cfg80211_registered_device *rdev,
3d1a5bbf
AZ
3351 struct wireless_dev *wdev,
3352 enum nl80211_commands cmd)
55682965 3353{
72fb2abc 3354 struct net_device *dev = wdev->netdev;
55682965
JB
3355 void *hdr;
3356
3d1a5bbf
AZ
3357 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE &&
3358 cmd != NL80211_CMD_DEL_INTERFACE &&
3359 cmd != NL80211_CMD_SET_INTERFACE);
8f894be2
TB
3360
3361 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
55682965
JB
3362 if (!hdr)
3363 return -1;
3364
72fb2abc
JB
3365 if (dev &&
3366 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
98104fde 3367 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name)))
72fb2abc
JB
3368 goto nla_put_failure;
3369
3370 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
3371 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) ||
2dad624e
ND
3372 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
3373 NL80211_ATTR_PAD) ||
98104fde 3374 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) ||
9360ffd1
DM
3375 nla_put_u32(msg, NL80211_ATTR_GENERATION,
3376 rdev->devlist_generation ^
446faa15
AQ
3377 (cfg80211_rdev_list_generation << 2)) ||
3378 nla_put_u8(msg, NL80211_ATTR_4ADDR, wdev->use_4addr))
9360ffd1 3379 goto nla_put_failure;
f5ea9120 3380
5b7ccaf3 3381 if (rdev->ops->get_channel) {
683b6d3b 3382 int ret;
f43e5210 3383 struct cfg80211_chan_def chandef = {};
683b6d3b
JB
3384
3385 ret = rdev_get_channel(rdev, wdev, &chandef);
3386 if (ret == 0) {
3387 if (nl80211_send_chandef(msg, &chandef))
3388 goto nla_put_failure;
3389 }
d91df0e3
PF
3390 }
3391
d55d0d59
RM
3392 if (rdev->ops->get_tx_power) {
3393 int dbm, ret;
3394
3395 ret = rdev_get_tx_power(rdev, wdev, &dbm);
3396 if (ret == 0 &&
3397 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL,
3398 DBM_TO_MBM(dbm)))
3399 goto nla_put_failure;
3400 }
3401
44905265
JB
3402 wdev_lock(wdev);
3403 switch (wdev->iftype) {
3404 case NL80211_IFTYPE_AP:
3405 if (wdev->ssid_len &&
3406 nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid))
4564b187 3407 goto nla_put_failure_locked;
44905265
JB
3408 break;
3409 case NL80211_IFTYPE_STATION:
3410 case NL80211_IFTYPE_P2P_CLIENT:
3411 case NL80211_IFTYPE_ADHOC: {
3412 const u8 *ssid_ie;
3413 if (!wdev->current_bss)
3414 break;
7a94b8c2 3415 rcu_read_lock();
44905265
JB
3416 ssid_ie = ieee80211_bss_get_ie(&wdev->current_bss->pub,
3417 WLAN_EID_SSID);
7a94b8c2
DB
3418 if (ssid_ie &&
3419 nla_put(msg, NL80211_ATTR_SSID, ssid_ie[1], ssid_ie + 2))
3420 goto nla_put_failure_rcu_locked;
3421 rcu_read_unlock();
44905265
JB
3422 break;
3423 }
3424 default:
3425 /* nothing */
3426 break;
b84e7a05 3427 }
44905265 3428 wdev_unlock(wdev);
b84e7a05 3429
52539ca8
THJ
3430 if (rdev->ops->get_txq_stats) {
3431 struct cfg80211_txq_stats txqstats = {};
3432 int ret = rdev_get_txq_stats(rdev, wdev, &txqstats);
3433
3434 if (ret == 0 &&
3435 !nl80211_put_txq_stats(msg, &txqstats,
3436 NL80211_ATTR_TXQ_STATS))
3437 goto nla_put_failure;
3438 }
3439
053c095a
JB
3440 genlmsg_end(msg, hdr);
3441 return 0;
55682965 3442
7a94b8c2
DB
3443 nla_put_failure_rcu_locked:
3444 rcu_read_unlock();
4564b187
JB
3445 nla_put_failure_locked:
3446 wdev_unlock(wdev);
55682965 3447 nla_put_failure:
bc3ed28c
TG
3448 genlmsg_cancel(msg, hdr);
3449 return -EMSGSIZE;
55682965
JB
3450}
3451
3452static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
3453{
3454 int wp_idx = 0;
3455 int if_idx = 0;
3456 int wp_start = cb->args[0];
3457 int if_start = cb->args[1];
b7fb44da 3458 int filter_wiphy = -1;
f5ea9120 3459 struct cfg80211_registered_device *rdev;
55682965 3460 struct wireless_dev *wdev;
ea90e0dc 3461 int ret;
55682965 3462
5fe231e8 3463 rtnl_lock();
b7fb44da
DK
3464 if (!cb->args[2]) {
3465 struct nl80211_dump_wiphy_state state = {
3466 .filter_wiphy = -1,
3467 };
b7fb44da
DK
3468
3469 ret = nl80211_dump_wiphy_parse(skb, cb, &state);
3470 if (ret)
ea90e0dc 3471 goto out_unlock;
b7fb44da
DK
3472
3473 filter_wiphy = state.filter_wiphy;
3474
3475 /*
3476 * if filtering, set cb->args[2] to +1 since 0 is the default
3477 * value needed to determine that parsing is necessary.
3478 */
3479 if (filter_wiphy >= 0)
3480 cb->args[2] = filter_wiphy + 1;
3481 else
3482 cb->args[2] = -1;
3483 } else if (cb->args[2] > 0) {
3484 filter_wiphy = cb->args[2] - 1;
3485 }
3486
f5ea9120
JB
3487 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
3488 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
463d0183 3489 continue;
bba95fef
JB
3490 if (wp_idx < wp_start) {
3491 wp_idx++;
55682965 3492 continue;
bba95fef 3493 }
b7fb44da
DK
3494
3495 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx)
3496 continue;
3497
55682965
JB
3498 if_idx = 0;
3499
53873f13 3500 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
bba95fef
JB
3501 if (if_idx < if_start) {
3502 if_idx++;
55682965 3503 continue;
bba95fef 3504 }
15e47304 3505 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid,
55682965 3506 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3d1a5bbf
AZ
3507 rdev, wdev,
3508 NL80211_CMD_NEW_INTERFACE) < 0) {
bba95fef
JB
3509 goto out;
3510 }
3511 if_idx++;
55682965 3512 }
bba95fef
JB
3513
3514 wp_idx++;
55682965 3515 }
bba95fef 3516 out:
55682965
JB
3517 cb->args[0] = wp_idx;
3518 cb->args[1] = if_idx;
3519
ea90e0dc
JB
3520 ret = skb->len;
3521 out_unlock:
3522 rtnl_unlock();
3523
3524 return ret;
55682965
JB
3525}
3526
3527static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
3528{
3529 struct sk_buff *msg;
1b8ec87a 3530 struct cfg80211_registered_device *rdev = info->user_ptr[0];
72fb2abc 3531 struct wireless_dev *wdev = info->user_ptr[1];
55682965 3532
fd2120ca 3533 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965 3534 if (!msg)
4c476991 3535 return -ENOMEM;
55682965 3536
15e47304 3537 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
3d1a5bbf 3538 rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
4c476991
JB
3539 nlmsg_free(msg);
3540 return -ENOBUFS;
3541 }
55682965 3542
134e6375 3543 return genlmsg_reply(msg, info);
55682965
JB
3544}
3545
66f7ac50
MW
3546static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
3547 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
3548 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
3549 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
3550 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
3551 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
e057d3c3 3552 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG },
66f7ac50
MW
3553};
3554
3555static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
3556{
3557 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
3558 int flag;
3559
3560 *mntrflags = 0;
3561
3562 if (!nla)
3563 return -EINVAL;
3564
8cb08174 3565 if (nla_parse_nested_deprecated(flags, NL80211_MNTR_FLAG_MAX, nla, mntr_flags_policy, NULL))
66f7ac50
MW
3566 return -EINVAL;
3567
3568 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
3569 if (flags[flag])
3570 *mntrflags |= (1<<flag);
3571
818a986e
JB
3572 *mntrflags |= MONITOR_FLAG_CHANGED;
3573
66f7ac50
MW
3574 return 0;
3575}
3576
1db77596
JB
3577static int nl80211_parse_mon_options(struct cfg80211_registered_device *rdev,
3578 enum nl80211_iftype type,
3579 struct genl_info *info,
3580 struct vif_params *params)
3581{
3582 bool change = false;
3583 int err;
3584
3585 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
3586 if (type != NL80211_IFTYPE_MONITOR)
3587 return -EINVAL;
3588
3589 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
3590 &params->flags);
3591 if (err)
3592 return err;
3593
3594 change = true;
3595 }
3596
3597 if (params->flags & MONITOR_FLAG_ACTIVE &&
3598 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR))
3599 return -EOPNOTSUPP;
3600
3601 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) {
3602 const u8 *mumimo_groups;
3603 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
3604
3605 if (type != NL80211_IFTYPE_MONITOR)
3606 return -EINVAL;
3607
3608 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
3609 return -EOPNOTSUPP;
3610
3611 mumimo_groups =
3612 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]);
3613
3614 /* bits 0 and 63 are reserved and must be zero */
4954601f
JB
3615 if ((mumimo_groups[0] & BIT(0)) ||
3616 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(7)))
1db77596
JB
3617 return -EINVAL;
3618
3619 params->vht_mumimo_groups = mumimo_groups;
3620 change = true;
3621 }
3622
3623 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) {
3624 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER;
3625
3626 if (type != NL80211_IFTYPE_MONITOR)
3627 return -EINVAL;
3628
3629 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag))
3630 return -EOPNOTSUPP;
3631
3632 params->vht_mumimo_follow_addr =
3633 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]);
3634 change = true;
3635 }
3636
3637 return change ? 1 : 0;
3638}
3639
9bc383de 3640static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
ad4bb6f8
JB
3641 struct net_device *netdev, u8 use_4addr,
3642 enum nl80211_iftype iftype)
9bc383de 3643{
ad4bb6f8 3644 if (!use_4addr) {
2e92a2d0 3645 if (netdev && netif_is_bridge_port(netdev))
ad4bb6f8 3646 return -EBUSY;
9bc383de 3647 return 0;
ad4bb6f8 3648 }
9bc383de
JB
3649
3650 switch (iftype) {
3651 case NL80211_IFTYPE_AP_VLAN:
3652 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
3653 return 0;
3654 break;
3655 case NL80211_IFTYPE_STATION:
3656 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
3657 return 0;
3658 break;
3659 default:
3660 break;
3661 }
3662
3663 return -EOPNOTSUPP;
3664}
3665
55682965
JB
3666static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
3667{
4c476991 3668 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3669 struct vif_params params;
e36d56b6 3670 int err;
04a773ad 3671 enum nl80211_iftype otype, ntype;
4c476991 3672 struct net_device *dev = info->user_ptr[1];
ac7f9cfa 3673 bool change = false;
55682965 3674
2ec600d6
LCC
3675 memset(&params, 0, sizeof(params));
3676
04a773ad 3677 otype = ntype = dev->ieee80211_ptr->iftype;
55682965 3678
723b038d 3679 if (info->attrs[NL80211_ATTR_IFTYPE]) {
ac7f9cfa 3680 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
04a773ad 3681 if (otype != ntype)
ac7f9cfa 3682 change = true;
723b038d
JB
3683 }
3684
92ffe055 3685 if (info->attrs[NL80211_ATTR_MESH_ID]) {
29cbe68c
JB
3686 struct wireless_dev *wdev = dev->ieee80211_ptr;
3687
4c476991
JB
3688 if (ntype != NL80211_IFTYPE_MESH_POINT)
3689 return -EINVAL;
29cbe68c
JB
3690 if (netif_running(dev))
3691 return -EBUSY;
3692
3693 wdev_lock(wdev);
3694 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
3695 IEEE80211_MAX_MESH_ID_LEN);
3696 wdev->mesh_id_up_len =
3697 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
3698 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
3699 wdev->mesh_id_up_len);
3700 wdev_unlock(wdev);
2ec600d6
LCC
3701 }
3702
8b787643
FF
3703 if (info->attrs[NL80211_ATTR_4ADDR]) {
3704 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
3705 change = true;
ad4bb6f8 3706 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
9bc383de 3707 if (err)
4c476991 3708 return err;
8b787643
FF
3709 } else {
3710 params.use_4addr = -1;
3711 }
3712
1db77596
JB
3713 err = nl80211_parse_mon_options(rdev, ntype, info, &params);
3714 if (err < 0)
3715 return err;
3716 if (err > 0)
c6e6a0c8 3717 change = true;
e057d3c3 3718
ac7f9cfa 3719 if (change)
818a986e 3720 err = cfg80211_change_iface(rdev, dev, ntype, &params);
ac7f9cfa
JB
3721 else
3722 err = 0;
60719ffd 3723
9bc383de
JB
3724 if (!err && params.use_4addr != -1)
3725 dev->ieee80211_ptr->use_4addr = params.use_4addr;
3726
3d1a5bbf
AZ
3727 if (change && !err) {
3728 struct wireless_dev *wdev = dev->ieee80211_ptr;
3729
3730 nl80211_notify_iface(rdev, wdev, NL80211_CMD_SET_INTERFACE);
3731 }
3732
55682965
JB
3733 return err;
3734}
3735
3736static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
3737{
4c476991 3738 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 3739 struct vif_params params;
84efbb84 3740 struct wireless_dev *wdev;
896ff063 3741 struct sk_buff *msg;
55682965
JB
3742 int err;
3743 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
3744
78f22b6a
JB
3745 /* to avoid failing a new interface creation due to pending removal */
3746 cfg80211_destroy_ifaces(rdev);
3747
2ec600d6
LCC
3748 memset(&params, 0, sizeof(params));
3749
55682965
JB
3750 if (!info->attrs[NL80211_ATTR_IFNAME])
3751 return -EINVAL;
3752
ab0d76f6 3753 if (info->attrs[NL80211_ATTR_IFTYPE])
55682965 3754 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
55682965 3755
33d915d9 3756 if (!rdev->ops->add_virtual_intf)
4c476991 3757 return -EOPNOTSUPP;
55682965 3758
cb3b7d87 3759 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN ||
e8f479b1
BG
3760 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) &&
3761 info->attrs[NL80211_ATTR_MAC]) {
1c18f145
AS
3762 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC],
3763 ETH_ALEN);
3764 if (!is_valid_ether_addr(params.macaddr))
3765 return -EADDRNOTAVAIL;
3766 }
3767
9bc383de 3768 if (info->attrs[NL80211_ATTR_4ADDR]) {
8b787643 3769 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
ad4bb6f8 3770 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
9bc383de 3771 if (err)
4c476991 3772 return err;
9bc383de 3773 }
8b787643 3774
e6f40511 3775 if (!cfg80211_iftype_allowed(&rdev->wiphy, type, params.use_4addr, 0))
33d915d9
MP
3776 return -EOPNOTSUPP;
3777
1db77596
JB
3778 err = nl80211_parse_mon_options(rdev, type, info, &params);
3779 if (err < 0)
3780 return err;
e057d3c3 3781
a18c7192
JB
3782 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
3783 if (!msg)
3784 return -ENOMEM;
3785
e35e4d28
HG
3786 wdev = rdev_add_virtual_intf(rdev,
3787 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
818a986e 3788 NET_NAME_USER, type, &params);
d687cbb7
RM
3789 if (WARN_ON(!wdev)) {
3790 nlmsg_free(msg);
3791 return -EPROTO;
3792 } else if (IS_ERR(wdev)) {
1c90f9d4 3793 nlmsg_free(msg);
84efbb84 3794 return PTR_ERR(wdev);
1c90f9d4 3795 }
2ec600d6 3796
18e5ca65 3797 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
78f22b6a
JB
3798 wdev->owner_nlportid = info->snd_portid;
3799
98104fde
JB
3800 switch (type) {
3801 case NL80211_IFTYPE_MESH_POINT:
3802 if (!info->attrs[NL80211_ATTR_MESH_ID])
3803 break;
29cbe68c
JB
3804 wdev_lock(wdev);
3805 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
3806 IEEE80211_MAX_MESH_ID_LEN);
3807 wdev->mesh_id_up_len =
3808 nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
3809 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
3810 wdev->mesh_id_up_len);
3811 wdev_unlock(wdev);
98104fde 3812 break;
cb3b7d87 3813 case NL80211_IFTYPE_NAN:
98104fde
JB
3814 case NL80211_IFTYPE_P2P_DEVICE:
3815 /*
cb3b7d87 3816 * P2P Device and NAN do not have a netdev, so don't go
98104fde
JB
3817 * through the netdev notifier and must be added here
3818 */
e4d4216e 3819 cfg80211_init_wdev(rdev, wdev);
98104fde
JB
3820 break;
3821 default:
3822 break;
29cbe68c
JB
3823 }
3824
15e47304 3825 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0,
3d1a5bbf 3826 rdev, wdev, NL80211_CMD_NEW_INTERFACE) < 0) {
1c90f9d4
JB
3827 nlmsg_free(msg);
3828 return -ENOBUFS;
3829 }
3830
3831 return genlmsg_reply(msg, info);
55682965
JB
3832}
3833
3834static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
3835{
4c476991 3836 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84efbb84 3837 struct wireless_dev *wdev = info->user_ptr[1];
55682965 3838
4c476991
JB
3839 if (!rdev->ops->del_virtual_intf)
3840 return -EOPNOTSUPP;
55682965 3841
84efbb84
JB
3842 /*
3843 * If we remove a wireless device without a netdev then clear
3844 * user_ptr[1] so that nl80211_post_doit won't dereference it
3845 * to check if it needs to do dev_put(). Otherwise it crashes
3846 * since the wdev has been freed, unlike with a netdev where
3847 * we need the dev_put() for the netdev to really be freed.
3848 */
3849 if (!wdev->netdev)
3850 info->user_ptr[1] = NULL;
3851
7f8ed01e 3852 return rdev_del_virtual_intf(rdev, wdev);
55682965
JB
3853}
3854
1d9d9213
SW
3855static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info)
3856{
3857 struct cfg80211_registered_device *rdev = info->user_ptr[0];
3858 struct net_device *dev = info->user_ptr[1];
3859 u16 noack_map;
3860
3861 if (!info->attrs[NL80211_ATTR_NOACK_MAP])
3862 return -EINVAL;
3863
3864 if (!rdev->ops->set_noack_map)
3865 return -EOPNOTSUPP;
3866
3867 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]);
3868
e35e4d28 3869 return rdev_set_noack_map(rdev, dev, noack_map);
1d9d9213
SW
3870}
3871
41ade00f
JB
3872struct get_key_cookie {
3873 struct sk_buff *msg;
3874 int error;
b9454e83 3875 int idx;
41ade00f
JB
3876};
3877
3878static void get_key_callback(void *c, struct key_params *params)
3879{
b9454e83 3880 struct nlattr *key;
41ade00f
JB
3881 struct get_key_cookie *cookie = c;
3882
9360ffd1
DM
3883 if ((params->key &&
3884 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA,
3885 params->key_len, params->key)) ||
3886 (params->seq &&
3887 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ,
3888 params->seq_len, params->seq)) ||
3889 (params->cipher &&
3890 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
3891 params->cipher)))
3892 goto nla_put_failure;
41ade00f 3893
ae0be8de 3894 key = nla_nest_start_noflag(cookie->msg, NL80211_ATTR_KEY);
b9454e83
JB
3895 if (!key)
3896 goto nla_put_failure;
3897
9360ffd1
DM
3898 if ((params->key &&
3899 nla_put(cookie->msg, NL80211_KEY_DATA,
3900 params->key_len, params->key)) ||
3901 (params->seq &&
3902 nla_put(cookie->msg, NL80211_KEY_SEQ,
3903 params->seq_len, params->seq)) ||
3904 (params->cipher &&
3905 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER,
3906 params->cipher)))
3907 goto nla_put_failure;
b9454e83 3908
efdfce72 3909 if (nla_put_u8(cookie->msg, NL80211_KEY_IDX, cookie->idx))
9360ffd1 3910 goto nla_put_failure;
b9454e83
JB
3911
3912 nla_nest_end(cookie->msg, key);
3913
41ade00f
JB
3914 return;
3915 nla_put_failure:
3916 cookie->error = 1;
3917}
3918
3919static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
3920{
4c476991 3921 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 3922 int err;
4c476991 3923 struct net_device *dev = info->user_ptr[1];
41ade00f 3924 u8 key_idx = 0;
e31b8213
JB
3925 const u8 *mac_addr = NULL;
3926 bool pairwise;
41ade00f
JB
3927 struct get_key_cookie cookie = {
3928 .error = 0,
3929 };
3930 void *hdr;
3931 struct sk_buff *msg;
155d7c73
JB
3932 bool bigtk_support = false;
3933
3934 if (wiphy_ext_feature_isset(&rdev->wiphy,
3935 NL80211_EXT_FEATURE_BEACON_PROTECTION))
3936 bigtk_support = true;
3937
3938 if ((dev->ieee80211_ptr->iftype == NL80211_IFTYPE_STATION ||
3939 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_CLIENT) &&
3940 wiphy_ext_feature_isset(&rdev->wiphy,
3941 NL80211_EXT_FEATURE_BEACON_PROTECTION_CLIENT))
3942 bigtk_support = true;
41ade00f 3943
56be393f 3944 if (info->attrs[NL80211_ATTR_KEY_IDX]) {
41ade00f 3945 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
155d7c73
JB
3946
3947 if (key_idx >= 6 && key_idx <= 7 && !bigtk_support) {
3948 GENL_SET_ERR_MSG(info, "BIGTK not supported");
56be393f 3949 return -EINVAL;
155d7c73 3950 }
56be393f 3951 }
41ade00f 3952
41ade00f
JB
3953 if (info->attrs[NL80211_ATTR_MAC])
3954 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
3955
e31b8213
JB
3956 pairwise = !!mac_addr;
3957 if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
3958 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
7a087e74 3959
e31b8213
JB
3960 if (kt != NL80211_KEYTYPE_GROUP &&
3961 kt != NL80211_KEYTYPE_PAIRWISE)
3962 return -EINVAL;
3963 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
3964 }
3965
4c476991
JB
3966 if (!rdev->ops->get_key)
3967 return -EOPNOTSUPP;
41ade00f 3968
0fa7b391
JB
3969 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
3970 return -ENOENT;
3971
fd2120ca 3972 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
3973 if (!msg)
3974 return -ENOMEM;
41ade00f 3975
15e47304 3976 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
41ade00f 3977 NL80211_CMD_NEW_KEY);
cb35fba3 3978 if (!hdr)
9fe271af 3979 goto nla_put_failure;
41ade00f
JB
3980
3981 cookie.msg = msg;
b9454e83 3982 cookie.idx = key_idx;
41ade00f 3983
9360ffd1
DM
3984 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
3985 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx))
3986 goto nla_put_failure;
3987 if (mac_addr &&
3988 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr))
3989 goto nla_put_failure;
41ade00f 3990
e35e4d28
HG
3991 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie,
3992 get_key_callback);
41ade00f
JB
3993
3994 if (err)
6c95e2a2 3995 goto free_msg;
41ade00f
JB
3996
3997 if (cookie.error)
3998 goto nla_put_failure;
3999
4000 genlmsg_end(msg, hdr);
4c476991 4001 return genlmsg_reply(msg, info);
41ade00f
JB
4002
4003 nla_put_failure:
4004 err = -ENOBUFS;
6c95e2a2 4005 free_msg:
41ade00f 4006 nlmsg_free(msg);
41ade00f
JB
4007 return err;
4008}
4009
4010static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
4011{
4c476991 4012 struct cfg80211_registered_device *rdev = info->user_ptr[0];
b9454e83 4013 struct key_parse key;
41ade00f 4014 int err;
4c476991 4015 struct net_device *dev = info->user_ptr[1];
41ade00f 4016
b9454e83
JB
4017 err = nl80211_parse_key(info, &key);
4018 if (err)
4019 return err;
41ade00f 4020
b9454e83 4021 if (key.idx < 0)
41ade00f
JB
4022 return -EINVAL;
4023
6cdd3979
AW
4024 /* Only support setting default key and
4025 * Extended Key ID action NL80211_KEY_SET_TX.
4026 */
56be393f 4027 if (!key.def && !key.defmgmt && !key.defbeacon &&
6cdd3979 4028 !(key.p.mode == NL80211_KEY_SET_TX))
41ade00f
JB
4029 return -EINVAL;
4030
dbd2fd65 4031 wdev_lock(dev->ieee80211_ptr);
3cfcf6ac 4032
dbd2fd65
JB
4033 if (key.def) {
4034 if (!rdev->ops->set_default_key) {
4035 err = -EOPNOTSUPP;
4036 goto out;
4037 }
41ade00f 4038
dbd2fd65
JB
4039 err = nl80211_key_allowed(dev->ieee80211_ptr);
4040 if (err)
4041 goto out;
4042
e35e4d28 4043 err = rdev_set_default_key(rdev, dev, key.idx,
dbd2fd65
JB
4044 key.def_uni, key.def_multi);
4045
4046 if (err)
4047 goto out;
fffd0934 4048
3d23e349 4049#ifdef CONFIG_CFG80211_WEXT
dbd2fd65
JB
4050 dev->ieee80211_ptr->wext.default_key = key.idx;
4051#endif
6cdd3979 4052 } else if (key.defmgmt) {
dbd2fd65
JB
4053 if (key.def_uni || !key.def_multi) {
4054 err = -EINVAL;
4055 goto out;
4056 }
4057
4058 if (!rdev->ops->set_default_mgmt_key) {
4059 err = -EOPNOTSUPP;
4060 goto out;
4061 }
4062
4063 err = nl80211_key_allowed(dev->ieee80211_ptr);
4064 if (err)
4065 goto out;
4066
e35e4d28 4067 err = rdev_set_default_mgmt_key(rdev, dev, key.idx);
dbd2fd65
JB
4068 if (err)
4069 goto out;
4070
4071#ifdef CONFIG_CFG80211_WEXT
4072 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
08645126 4073#endif
56be393f
JM
4074 } else if (key.defbeacon) {
4075 if (key.def_uni || !key.def_multi) {
4076 err = -EINVAL;
4077 goto out;
4078 }
4079
4080 if (!rdev->ops->set_default_beacon_key) {
4081 err = -EOPNOTSUPP;
4082 goto out;
4083 }
4084
4085 err = nl80211_key_allowed(dev->ieee80211_ptr);
4086 if (err)
4087 goto out;
4088
4089 err = rdev_set_default_beacon_key(rdev, dev, key.idx);
4090 if (err)
4091 goto out;
6cdd3979
AW
4092 } else if (key.p.mode == NL80211_KEY_SET_TX &&
4093 wiphy_ext_feature_isset(&rdev->wiphy,
4094 NL80211_EXT_FEATURE_EXT_KEY_ID)) {
4095 u8 *mac_addr = NULL;
4096
4097 if (info->attrs[NL80211_ATTR_MAC])
4098 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4099
4100 if (!mac_addr || key.idx < 0 || key.idx > 1) {
4101 err = -EINVAL;
4102 goto out;
4103 }
dbd2fd65 4104
6cdd3979
AW
4105 err = rdev_add_key(rdev, dev, key.idx,
4106 NL80211_KEYTYPE_PAIRWISE,
4107 mac_addr, &key.p);
4108 } else {
4109 err = -EINVAL;
4110 }
dbd2fd65 4111 out:
fffd0934 4112 wdev_unlock(dev->ieee80211_ptr);
41ade00f 4113
41ade00f
JB
4114 return err;
4115}
4116
4117static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
4118{
4c476991 4119 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fffd0934 4120 int err;
4c476991 4121 struct net_device *dev = info->user_ptr[1];
b9454e83 4122 struct key_parse key;
e31b8213 4123 const u8 *mac_addr = NULL;
41ade00f 4124
b9454e83
JB
4125 err = nl80211_parse_key(info, &key);
4126 if (err)
4127 return err;
41ade00f 4128
f8af764b
JM
4129 if (!key.p.key) {
4130 GENL_SET_ERR_MSG(info, "no key");
41ade00f 4131 return -EINVAL;
f8af764b 4132 }
41ade00f 4133
41ade00f
JB
4134 if (info->attrs[NL80211_ATTR_MAC])
4135 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4136
e31b8213
JB
4137 if (key.type == -1) {
4138 if (mac_addr)
4139 key.type = NL80211_KEYTYPE_PAIRWISE;
4140 else
4141 key.type = NL80211_KEYTYPE_GROUP;
4142 }
4143
4144 /* for now */
4145 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
f8af764b
JM
4146 key.type != NL80211_KEYTYPE_GROUP) {
4147 GENL_SET_ERR_MSG(info, "key type not pairwise or group");
e31b8213 4148 return -EINVAL;
f8af764b 4149 }
e31b8213 4150
14f34e36
GG
4151 if (key.type == NL80211_KEYTYPE_GROUP &&
4152 info->attrs[NL80211_ATTR_VLAN_ID])
4153 key.p.vlan_id = nla_get_u16(info->attrs[NL80211_ATTR_VLAN_ID]);
4154
4c476991
JB
4155 if (!rdev->ops->add_key)
4156 return -EOPNOTSUPP;
25e47c18 4157
e31b8213
JB
4158 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
4159 key.type == NL80211_KEYTYPE_PAIRWISE,
f8af764b
JM
4160 mac_addr)) {
4161 GENL_SET_ERR_MSG(info, "key setting validation failed");
4c476991 4162 return -EINVAL;
f8af764b 4163 }
41ade00f 4164
fffd0934
JB
4165 wdev_lock(dev->ieee80211_ptr);
4166 err = nl80211_key_allowed(dev->ieee80211_ptr);
f8af764b
JM
4167 if (err)
4168 GENL_SET_ERR_MSG(info, "key not allowed");
4169 if (!err) {
e35e4d28
HG
4170 err = rdev_add_key(rdev, dev, key.idx,
4171 key.type == NL80211_KEYTYPE_PAIRWISE,
4172 mac_addr, &key.p);
f8af764b
JM
4173 if (err)
4174 GENL_SET_ERR_MSG(info, "key addition failed");
4175 }
fffd0934 4176 wdev_unlock(dev->ieee80211_ptr);
41ade00f 4177
41ade00f
JB
4178 return err;
4179}
4180
4181static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
4182{
4c476991 4183 struct cfg80211_registered_device *rdev = info->user_ptr[0];
41ade00f 4184 int err;
4c476991 4185 struct net_device *dev = info->user_ptr[1];
41ade00f 4186 u8 *mac_addr = NULL;
b9454e83 4187 struct key_parse key;
41ade00f 4188
b9454e83
JB
4189 err = nl80211_parse_key(info, &key);
4190 if (err)
4191 return err;
41ade00f
JB
4192
4193 if (info->attrs[NL80211_ATTR_MAC])
4194 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
4195
e31b8213
JB
4196 if (key.type == -1) {
4197 if (mac_addr)
4198 key.type = NL80211_KEYTYPE_PAIRWISE;
4199 else
4200 key.type = NL80211_KEYTYPE_GROUP;
4201 }
4202
4203 /* for now */
4204 if (key.type != NL80211_KEYTYPE_PAIRWISE &&
4205 key.type != NL80211_KEYTYPE_GROUP)
4206 return -EINVAL;
4207
4c476991
JB
4208 if (!rdev->ops->del_key)
4209 return -EOPNOTSUPP;
41ade00f 4210
fffd0934
JB
4211 wdev_lock(dev->ieee80211_ptr);
4212 err = nl80211_key_allowed(dev->ieee80211_ptr);
e31b8213 4213
0fa7b391 4214 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr &&
e31b8213
JB
4215 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
4216 err = -ENOENT;
4217
fffd0934 4218 if (!err)
e35e4d28
HG
4219 err = rdev_del_key(rdev, dev, key.idx,
4220 key.type == NL80211_KEYTYPE_PAIRWISE,
4221 mac_addr);
41ade00f 4222
3d23e349 4223#ifdef CONFIG_CFG80211_WEXT
08645126 4224 if (!err) {
b9454e83 4225 if (key.idx == dev->ieee80211_ptr->wext.default_key)
08645126 4226 dev->ieee80211_ptr->wext.default_key = -1;
b9454e83 4227 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
08645126
JB
4228 dev->ieee80211_ptr->wext.default_mgmt_key = -1;
4229 }
4230#endif
fffd0934 4231 wdev_unlock(dev->ieee80211_ptr);
08645126 4232
41ade00f
JB
4233 return err;
4234}
4235
77765eaf
VT
4236/* This function returns an error or the number of nested attributes */
4237static int validate_acl_mac_addrs(struct nlattr *nl_attr)
4238{
4239 struct nlattr *attr;
4240 int n_entries = 0, tmp;
4241
4242 nla_for_each_nested(attr, nl_attr, tmp) {
4243 if (nla_len(attr) != ETH_ALEN)
4244 return -EINVAL;
4245
4246 n_entries++;
4247 }
4248
4249 return n_entries;
4250}
4251
4252/*
4253 * This function parses ACL information and allocates memory for ACL data.
4254 * On successful return, the calling function is responsible to free the
4255 * ACL buffer returned by this function.
4256 */
4257static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy,
4258 struct genl_info *info)
4259{
4260 enum nl80211_acl_policy acl_policy;
4261 struct nlattr *attr;
4262 struct cfg80211_acl_data *acl;
4263 int i = 0, n_entries, tmp;
4264
4265 if (!wiphy->max_acl_mac_addrs)
4266 return ERR_PTR(-EOPNOTSUPP);
4267
4268 if (!info->attrs[NL80211_ATTR_ACL_POLICY])
4269 return ERR_PTR(-EINVAL);
4270
4271 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]);
4272 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED &&
4273 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED)
4274 return ERR_PTR(-EINVAL);
4275
4276 if (!info->attrs[NL80211_ATTR_MAC_ADDRS])
4277 return ERR_PTR(-EINVAL);
4278
4279 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]);
4280 if (n_entries < 0)
4281 return ERR_PTR(n_entries);
4282
4283 if (n_entries > wiphy->max_acl_mac_addrs)
4284 return ERR_PTR(-ENOTSUPP);
4285
391d132c 4286 acl = kzalloc(struct_size(acl, mac_addrs, n_entries), GFP_KERNEL);
77765eaf
VT
4287 if (!acl)
4288 return ERR_PTR(-ENOMEM);
4289
4290 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) {
4291 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN);
4292 i++;
4293 }
4294
4295 acl->n_acl_entries = n_entries;
4296 acl->acl_policy = acl_policy;
4297
4298 return acl;
4299}
4300
4301static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info)
4302{
4303 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4304 struct net_device *dev = info->user_ptr[1];
4305 struct cfg80211_acl_data *acl;
4306 int err;
4307
4308 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4309 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4310 return -EOPNOTSUPP;
4311
4312 if (!dev->ieee80211_ptr->beacon_interval)
4313 return -EINVAL;
4314
4315 acl = parse_acl_data(&rdev->wiphy, info);
4316 if (IS_ERR(acl))
4317 return PTR_ERR(acl);
4318
4319 err = rdev_set_mac_acl(rdev, dev, acl);
4320
4321 kfree(acl);
4322
4323 return err;
4324}
4325
a7c7fbff
PK
4326static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4327 u8 *rates, u8 rates_len)
4328{
4329 u8 i;
4330 u32 mask = 0;
4331
4332 for (i = 0; i < rates_len; i++) {
4333 int rate = (rates[i] & 0x7f) * 5;
4334 int ridx;
4335
4336 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4337 struct ieee80211_rate *srate =
4338 &sband->bitrates[ridx];
4339 if (rate == srate->bitrate) {
4340 mask |= 1 << ridx;
4341 break;
4342 }
4343 }
4344 if (ridx == sband->n_bitrates)
4345 return 0; /* rate not found */
4346 }
4347
4348 return mask;
4349}
4350
4351static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband,
4352 u8 *rates, u8 rates_len,
4353 u8 mcs[IEEE80211_HT_MCS_MASK_LEN])
4354{
4355 u8 i;
4356
4357 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN);
4358
4359 for (i = 0; i < rates_len; i++) {
4360 int ridx, rbit;
4361
4362 ridx = rates[i] / 8;
4363 rbit = BIT(rates[i] % 8);
4364
4365 /* check validity */
4366 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN))
4367 return false;
4368
4369 /* check availability */
30fe6d50 4370 ridx = array_index_nospec(ridx, IEEE80211_HT_MCS_MASK_LEN);
a7c7fbff
PK
4371 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit)
4372 mcs[ridx] |= rbit;
4373 else
4374 return false;
4375 }
4376
4377 return true;
4378}
4379
4380static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map)
4381{
4382 u16 mcs_mask = 0;
4383
4384 switch (vht_mcs_map) {
4385 case IEEE80211_VHT_MCS_NOT_SUPPORTED:
4386 break;
4387 case IEEE80211_VHT_MCS_SUPPORT_0_7:
4388 mcs_mask = 0x00FF;
4389 break;
4390 case IEEE80211_VHT_MCS_SUPPORT_0_8:
4391 mcs_mask = 0x01FF;
4392 break;
4393 case IEEE80211_VHT_MCS_SUPPORT_0_9:
4394 mcs_mask = 0x03FF;
4395 break;
4396 default:
4397 break;
4398 }
4399
4400 return mcs_mask;
4401}
4402
4403static void vht_build_mcs_mask(u16 vht_mcs_map,
4404 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX])
4405{
4406 u8 nss;
4407
4408 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) {
4409 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03);
4410 vht_mcs_map >>= 2;
4411 }
4412}
4413
4414static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband,
4415 struct nl80211_txrate_vht *txrate,
4416 u16 mcs[NL80211_VHT_NSS_MAX])
4417{
4418 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
4419 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {};
4420 u8 i;
4421
4422 if (!sband->vht_cap.vht_supported)
4423 return false;
4424
4425 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX);
4426
4427 /* Build vht_mcs_mask from VHT capabilities */
4428 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
4429
4430 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
4431 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
4432 mcs[i] = txrate->mcs[i];
4433 else
4434 return false;
4435 }
4436
4437 return true;
4438}
4439
eb89a6a6
MH
4440static u16 he_mcs_map_to_mcs_mask(u8 he_mcs_map)
4441{
4442 switch (he_mcs_map) {
4443 case IEEE80211_HE_MCS_NOT_SUPPORTED:
4444 return 0;
4445 case IEEE80211_HE_MCS_SUPPORT_0_7:
4446 return 0x00FF;
4447 case IEEE80211_HE_MCS_SUPPORT_0_9:
4448 return 0x03FF;
4449 case IEEE80211_HE_MCS_SUPPORT_0_11:
4450 return 0xFFF;
4451 default:
4452 break;
4453 }
4454 return 0;
4455}
4456
4457static void he_build_mcs_mask(u16 he_mcs_map,
4458 u16 he_mcs_mask[NL80211_HE_NSS_MAX])
4459{
4460 u8 nss;
4461
4462 for (nss = 0; nss < NL80211_HE_NSS_MAX; nss++) {
4463 he_mcs_mask[nss] = he_mcs_map_to_mcs_mask(he_mcs_map & 0x03);
4464 he_mcs_map >>= 2;
4465 }
4466}
4467
4468static u16 he_get_txmcsmap(struct genl_info *info,
4469 const struct ieee80211_sta_he_cap *he_cap)
4470{
4471 struct net_device *dev = info->user_ptr[1];
4472 struct wireless_dev *wdev = dev->ieee80211_ptr;
4473 __le16 tx_mcs;
4474
4475 switch (wdev->chandef.width) {
4476 case NL80211_CHAN_WIDTH_80P80:
4477 tx_mcs = he_cap->he_mcs_nss_supp.tx_mcs_80p80;
4478 break;
4479 case NL80211_CHAN_WIDTH_160:
4480 tx_mcs = he_cap->he_mcs_nss_supp.tx_mcs_160;
4481 break;
4482 default:
4483 tx_mcs = he_cap->he_mcs_nss_supp.tx_mcs_80;
4484 break;
4485 }
4486 return le16_to_cpu(tx_mcs);
4487}
4488
4489static bool he_set_mcs_mask(struct genl_info *info,
4490 struct wireless_dev *wdev,
4491 struct ieee80211_supported_band *sband,
4492 struct nl80211_txrate_he *txrate,
4493 u16 mcs[NL80211_HE_NSS_MAX])
4494{
4495 const struct ieee80211_sta_he_cap *he_cap;
4496 u16 tx_mcs_mask[NL80211_HE_NSS_MAX] = {};
4497 u16 tx_mcs_map = 0;
4498 u8 i;
4499
4500 he_cap = ieee80211_get_he_iftype_cap(sband, wdev->iftype);
4501 if (!he_cap)
4502 return false;
4503
4504 memset(mcs, 0, sizeof(u16) * NL80211_HE_NSS_MAX);
4505
4506 tx_mcs_map = he_get_txmcsmap(info, he_cap);
4507
4508 /* Build he_mcs_mask from HE capabilities */
4509 he_build_mcs_mask(tx_mcs_map, tx_mcs_mask);
4510
4511 for (i = 0; i < NL80211_HE_NSS_MAX; i++) {
4512 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i])
4513 mcs[i] = txrate->mcs[i];
4514 else
4515 return false;
4516 }
4517
4518 return true;
4519}
4520
a7c7fbff 4521static int nl80211_parse_tx_bitrate_mask(struct genl_info *info,
9a5f6488
TC
4522 struct nlattr *attrs[],
4523 enum nl80211_attrs attr,
eb89a6a6
MH
4524 struct cfg80211_bitrate_mask *mask,
4525 struct net_device *dev)
a7c7fbff
PK
4526{
4527 struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4528 struct cfg80211_registered_device *rdev = info->user_ptr[0];
eb89a6a6 4529 struct wireless_dev *wdev = dev->ieee80211_ptr;
a7c7fbff
PK
4530 int rem, i;
4531 struct nlattr *tx_rates;
4532 struct ieee80211_supported_band *sband;
eb89a6a6 4533 u16 vht_tx_mcs_map, he_tx_mcs_map;
a7c7fbff
PK
4534
4535 memset(mask, 0, sizeof(*mask));
4536 /* Default to all rates enabled */
4537 for (i = 0; i < NUM_NL80211_BANDS; i++) {
eb89a6a6
MH
4538 const struct ieee80211_sta_he_cap *he_cap;
4539
a7c7fbff
PK
4540 sband = rdev->wiphy.bands[i];
4541
4542 if (!sband)
4543 continue;
4544
4545 mask->control[i].legacy = (1 << sband->n_bitrates) - 1;
4546 memcpy(mask->control[i].ht_mcs,
4547 sband->ht_cap.mcs.rx_mask,
4548 sizeof(mask->control[i].ht_mcs));
4549
4550 if (!sband->vht_cap.vht_supported)
4551 continue;
4552
4553 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map);
4554 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs);
eb89a6a6
MH
4555
4556 he_cap = ieee80211_get_he_iftype_cap(sband, wdev->iftype);
4557 if (!he_cap)
4558 continue;
4559
4560 he_tx_mcs_map = he_get_txmcsmap(info, he_cap);
4561 he_build_mcs_mask(he_tx_mcs_map, mask->control[i].he_mcs);
4562
4563 mask->control[i].he_gi = 0xFF;
4564 mask->control[i].he_ltf = 0xFF;
a7c7fbff
PK
4565 }
4566
4567 /* if no rates are given set it back to the defaults */
9a5f6488 4568 if (!attrs[attr])
a7c7fbff
PK
4569 goto out;
4570
4571 /* The nested attribute uses enum nl80211_band as the index. This maps
4572 * directly to the enum nl80211_band values used in cfg80211.
4573 */
4574 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8);
9a5f6488 4575 nla_for_each_nested(tx_rates, attrs[attr], rem) {
a7c7fbff
PK
4576 enum nl80211_band band = nla_type(tx_rates);
4577 int err;
4578
4579 if (band < 0 || band >= NUM_NL80211_BANDS)
4580 return -EINVAL;
4581 sband = rdev->wiphy.bands[band];
4582 if (sband == NULL)
4583 return -EINVAL;
8cb08174
JB
4584 err = nla_parse_nested_deprecated(tb, NL80211_TXRATE_MAX,
4585 tx_rates,
4586 nl80211_txattr_policy,
4587 info->extack);
a7c7fbff
PK
4588 if (err)
4589 return err;
4590 if (tb[NL80211_TXRATE_LEGACY]) {
4591 mask->control[band].legacy = rateset_to_mask(
4592 sband,
4593 nla_data(tb[NL80211_TXRATE_LEGACY]),
4594 nla_len(tb[NL80211_TXRATE_LEGACY]));
4595 if ((mask->control[band].legacy == 0) &&
4596 nla_len(tb[NL80211_TXRATE_LEGACY]))
4597 return -EINVAL;
4598 }
4599 if (tb[NL80211_TXRATE_HT]) {
4600 if (!ht_rateset_to_mask(
4601 sband,
4602 nla_data(tb[NL80211_TXRATE_HT]),
4603 nla_len(tb[NL80211_TXRATE_HT]),
4604 mask->control[band].ht_mcs))
4605 return -EINVAL;
4606 }
4607 if (tb[NL80211_TXRATE_VHT]) {
4608 if (!vht_set_mcs_mask(
4609 sband,
4610 nla_data(tb[NL80211_TXRATE_VHT]),
4611 mask->control[band].vht_mcs))
4612 return -EINVAL;
4613 }
4614 if (tb[NL80211_TXRATE_GI]) {
4615 mask->control[band].gi =
4616 nla_get_u8(tb[NL80211_TXRATE_GI]);
4617 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI)
4618 return -EINVAL;
4619 }
eb89a6a6
MH
4620 if (tb[NL80211_TXRATE_HE] &&
4621 !he_set_mcs_mask(info, wdev, sband,
4622 nla_data(tb[NL80211_TXRATE_HE]),
4623 mask->control[band].he_mcs))
4624 return -EINVAL;
4625 if (tb[NL80211_TXRATE_HE_GI])
4626 mask->control[band].he_gi =
4627 nla_get_u8(tb[NL80211_TXRATE_HE_GI]);
4628 if (tb[NL80211_TXRATE_HE_LTF])
4629 mask->control[band].he_ltf =
4630 nla_get_u8(tb[NL80211_TXRATE_HE_LTF]);
a7c7fbff
PK
4631
4632 if (mask->control[band].legacy == 0) {
eb89a6a6 4633 /* don't allow empty legacy rates if HT, VHT or HE
a7c7fbff
PK
4634 * are not even supported.
4635 */
4636 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported ||
eb89a6a6
MH
4637 rdev->wiphy.bands[band]->vht_cap.vht_supported ||
4638 ieee80211_get_he_iftype_cap(sband, wdev->iftype)))
a7c7fbff
PK
4639 return -EINVAL;
4640
4641 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++)
4642 if (mask->control[band].ht_mcs[i])
4643 goto out;
4644
4645 for (i = 0; i < NL80211_VHT_NSS_MAX; i++)
4646 if (mask->control[band].vht_mcs[i])
4647 goto out;
4648
eb89a6a6
MH
4649 for (i = 0; i < NL80211_HE_NSS_MAX; i++)
4650 if (mask->control[band].he_mcs[i])
4651 goto out;
4652
a7c7fbff
PK
4653 /* legacy and mcs rates may not be both empty */
4654 return -EINVAL;
4655 }
4656 }
4657
4658out:
4659 return 0;
4660}
4661
8564e382
JB
4662static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev,
4663 enum nl80211_band band,
4664 struct cfg80211_bitrate_mask *beacon_rate)
a7c7fbff 4665{
8564e382
JB
4666 u32 count_ht, count_vht, i;
4667 u32 rate = beacon_rate->control[band].legacy;
a7c7fbff
PK
4668
4669 /* Allow only one rate */
4670 if (hweight32(rate) > 1)
4671 return -EINVAL;
4672
4673 count_ht = 0;
4674 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) {
8564e382 4675 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) {
a7c7fbff 4676 return -EINVAL;
8564e382 4677 } else if (beacon_rate->control[band].ht_mcs[i]) {
a7c7fbff
PK
4678 count_ht++;
4679 if (count_ht > 1)
4680 return -EINVAL;
4681 }
4682 if (count_ht && rate)
4683 return -EINVAL;
4684 }
4685
4686 count_vht = 0;
4687 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) {
8564e382 4688 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) {
a7c7fbff 4689 return -EINVAL;
8564e382 4690 } else if (beacon_rate->control[band].vht_mcs[i]) {
a7c7fbff
PK
4691 count_vht++;
4692 if (count_vht > 1)
4693 return -EINVAL;
4694 }
4695 if (count_vht && rate)
4696 return -EINVAL;
4697 }
4698
4699 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht))
4700 return -EINVAL;
4701
8564e382
JB
4702 if (rate &&
4703 !wiphy_ext_feature_isset(&rdev->wiphy,
4704 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY))
4705 return -EINVAL;
4706 if (count_ht &&
4707 !wiphy_ext_feature_isset(&rdev->wiphy,
4708 NL80211_EXT_FEATURE_BEACON_RATE_HT))
4709 return -EINVAL;
4710 if (count_vht &&
4711 !wiphy_ext_feature_isset(&rdev->wiphy,
4712 NL80211_EXT_FEATURE_BEACON_RATE_VHT))
4713 return -EINVAL;
4714
a7c7fbff
PK
4715 return 0;
4716}
4717
81e54d08
PKC
4718static int nl80211_parse_beacon(struct cfg80211_registered_device *rdev,
4719 struct nlattr *attrs[],
8860020e 4720 struct cfg80211_beacon_data *bcn)
ed1b6cc7 4721{
8860020e 4722 bool haveinfo = false;
81e54d08 4723 int err;
ed1b6cc7 4724
8860020e 4725 memset(bcn, 0, sizeof(*bcn));
ed1b6cc7 4726
a1193be8
SW
4727 if (attrs[NL80211_ATTR_BEACON_HEAD]) {
4728 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]);
4729 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]);
8860020e
JB
4730 if (!bcn->head_len)
4731 return -EINVAL;
4732 haveinfo = true;
ed1b6cc7
JB
4733 }
4734
a1193be8
SW
4735 if (attrs[NL80211_ATTR_BEACON_TAIL]) {
4736 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]);
4737 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]);
8860020e 4738 haveinfo = true;
ed1b6cc7
JB
4739 }
4740
4c476991
JB
4741 if (!haveinfo)
4742 return -EINVAL;
3b85875a 4743
a1193be8
SW
4744 if (attrs[NL80211_ATTR_IE]) {
4745 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]);
4746 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]);
9946ecfb
JM
4747 }
4748
a1193be8 4749 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) {
8860020e 4750 bcn->proberesp_ies =
a1193be8 4751 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]);
8860020e 4752 bcn->proberesp_ies_len =
a1193be8 4753 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]);
9946ecfb
JM
4754 }
4755
a1193be8 4756 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) {
8860020e 4757 bcn->assocresp_ies =
a1193be8 4758 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
8860020e 4759 bcn->assocresp_ies_len =
a1193be8 4760 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]);
9946ecfb
JM
4761 }
4762
a1193be8
SW
4763 if (attrs[NL80211_ATTR_PROBE_RESP]) {
4764 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]);
4765 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]);
00f740e1
AN
4766 }
4767
81e54d08
PKC
4768 if (attrs[NL80211_ATTR_FTM_RESPONDER]) {
4769 struct nlattr *tb[NL80211_FTM_RESP_ATTR_MAX + 1];
4770
8cb08174
JB
4771 err = nla_parse_nested_deprecated(tb,
4772 NL80211_FTM_RESP_ATTR_MAX,
4773 attrs[NL80211_ATTR_FTM_RESPONDER],
4774 NULL, NULL);
81e54d08
PKC
4775 if (err)
4776 return err;
4777
4778 if (tb[NL80211_FTM_RESP_ATTR_ENABLED] &&
4779 wiphy_ext_feature_isset(&rdev->wiphy,
4780 NL80211_EXT_FEATURE_ENABLE_FTM_RESPONDER))
4781 bcn->ftm_responder = 1;
4782 else
4783 return -EOPNOTSUPP;
4784
4785 if (tb[NL80211_FTM_RESP_ATTR_LCI]) {
4786 bcn->lci = nla_data(tb[NL80211_FTM_RESP_ATTR_LCI]);
4787 bcn->lci_len = nla_len(tb[NL80211_FTM_RESP_ATTR_LCI]);
4788 }
4789
4790 if (tb[NL80211_FTM_RESP_ATTR_CIVICLOC]) {
4791 bcn->civicloc = nla_data(tb[NL80211_FTM_RESP_ATTR_CIVICLOC]);
4792 bcn->civicloc_len = nla_len(tb[NL80211_FTM_RESP_ATTR_CIVICLOC]);
4793 }
4794 } else {
4795 bcn->ftm_responder = -1;
4796 }
4797
8860020e
JB
4798 return 0;
4799}
4800
796e90f4
JC
4801static int nl80211_parse_he_obss_pd(struct nlattr *attrs,
4802 struct ieee80211_he_obss_pd *he_obss_pd)
4803{
4804 struct nlattr *tb[NL80211_HE_OBSS_PD_ATTR_MAX + 1];
4805 int err;
4806
4807 err = nla_parse_nested(tb, NL80211_HE_OBSS_PD_ATTR_MAX, attrs,
4808 he_obss_pd_policy, NULL);
4809 if (err)
4810 return err;
4811
4812 if (!tb[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET] ||
4813 !tb[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET])
4814 return -EINVAL;
4815
4816 he_obss_pd->min_offset =
4817 nla_get_u32(tb[NL80211_HE_OBSS_PD_ATTR_MIN_OFFSET]);
4818 he_obss_pd->max_offset =
4819 nla_get_u32(tb[NL80211_HE_OBSS_PD_ATTR_MAX_OFFSET]);
4820
4821 if (he_obss_pd->min_offset >= he_obss_pd->max_offset)
4822 return -EINVAL;
4823
4824 he_obss_pd->enable = true;
4825
4826 return 0;
4827}
4828
5c5e52d1
JC
4829static int nl80211_parse_he_bss_color(struct nlattr *attrs,
4830 struct cfg80211_he_bss_color *he_bss_color)
4831{
4832 struct nlattr *tb[NL80211_HE_BSS_COLOR_ATTR_MAX + 1];
4833 int err;
4834
4835 err = nla_parse_nested(tb, NL80211_HE_BSS_COLOR_ATTR_MAX, attrs,
4836 he_bss_color_policy, NULL);
4837 if (err)
4838 return err;
4839
4840 if (!tb[NL80211_HE_BSS_COLOR_ATTR_COLOR])
4841 return -EINVAL;
4842
4843 he_bss_color->color =
4844 nla_get_u8(tb[NL80211_HE_BSS_COLOR_ATTR_COLOR]);
75e6b594
JB
4845 he_bss_color->enabled =
4846 !nla_get_flag(tb[NL80211_HE_BSS_COLOR_ATTR_DISABLED]);
5c5e52d1
JC
4847 he_bss_color->partial =
4848 nla_get_flag(tb[NL80211_HE_BSS_COLOR_ATTR_PARTIAL]);
4849
4850 return 0;
4851}
4852
66cd794e
JB
4853static void nl80211_check_ap_rate_selectors(struct cfg80211_ap_settings *params,
4854 const u8 *rates)
4855{
4856 int i;
4857
4858 if (!rates)
4859 return;
4860
4861 for (i = 0; i < rates[1]; i++) {
4862 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_HT_PHY)
4863 params->ht_required = true;
4864 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_VHT_PHY)
4865 params->vht_required = true;
2a392596
IP
4866 if (rates[2 + i] == BSS_MEMBERSHIP_SELECTOR_HE_PHY)
4867 params->he_required = true;
66cd794e
JB
4868 }
4869}
4870
4871/*
4872 * Since the nl80211 API didn't include, from the beginning, attributes about
4873 * HT/VHT requirements/capabilities, we parse them out of the IEs for the
4874 * benefit of drivers that rebuild IEs in the firmware.
4875 */
4876static void nl80211_calculate_ap_params(struct cfg80211_ap_settings *params)
4877{
4878 const struct cfg80211_beacon_data *bcn = &params->beacon;
ba83bfb1
IM
4879 size_t ies_len = bcn->tail_len;
4880 const u8 *ies = bcn->tail;
66cd794e
JB
4881 const u8 *rates;
4882 const u8 *cap;
4883
4884 rates = cfg80211_find_ie(WLAN_EID_SUPP_RATES, ies, ies_len);
4885 nl80211_check_ap_rate_selectors(params, rates);
4886
4887 rates = cfg80211_find_ie(WLAN_EID_EXT_SUPP_RATES, ies, ies_len);
4888 nl80211_check_ap_rate_selectors(params, rates);
4889
4890 cap = cfg80211_find_ie(WLAN_EID_HT_CAPABILITY, ies, ies_len);
4891 if (cap && cap[1] >= sizeof(*params->ht_cap))
4892 params->ht_cap = (void *)(cap + 2);
4893 cap = cfg80211_find_ie(WLAN_EID_VHT_CAPABILITY, ies, ies_len);
4894 if (cap && cap[1] >= sizeof(*params->vht_cap))
4895 params->vht_cap = (void *)(cap + 2);
244eb9ae
ST
4896 cap = cfg80211_find_ext_ie(WLAN_EID_EXT_HE_CAPABILITY, ies, ies_len);
4897 if (cap && cap[1] >= sizeof(*params->he_cap) + 1)
4898 params->he_cap = (void *)(cap + 3);
7e8d6f12
ST
4899 cap = cfg80211_find_ext_ie(WLAN_EID_EXT_HE_OPERATION, ies, ies_len);
4900 if (cap && cap[1] >= sizeof(*params->he_oper) + 1)
4901 params->he_oper = (void *)(cap + 3);
66cd794e
JB
4902}
4903
46c1dd0c
FF
4904static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev,
4905 struct cfg80211_ap_settings *params)
4906{
4907 struct wireless_dev *wdev;
4908 bool ret = false;
4909
53873f13 4910 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) {
46c1dd0c
FF
4911 if (wdev->iftype != NL80211_IFTYPE_AP &&
4912 wdev->iftype != NL80211_IFTYPE_P2P_GO)
4913 continue;
4914
683b6d3b 4915 if (!wdev->preset_chandef.chan)
46c1dd0c
FF
4916 continue;
4917
683b6d3b 4918 params->chandef = wdev->preset_chandef;
46c1dd0c
FF
4919 ret = true;
4920 break;
4921 }
4922
46c1dd0c
FF
4923 return ret;
4924}
4925
e39e5b5e
JM
4926static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev,
4927 enum nl80211_auth_type auth_type,
4928 enum nl80211_commands cmd)
4929{
4930 if (auth_type > NL80211_AUTHTYPE_MAX)
4931 return false;
4932
4933 switch (cmd) {
4934 case NL80211_CMD_AUTHENTICATE:
4935 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
4936 auth_type == NL80211_AUTHTYPE_SAE)
4937 return false;
63181060
JM
4938 if (!wiphy_ext_feature_isset(&rdev->wiphy,
4939 NL80211_EXT_FEATURE_FILS_STA) &&
4940 (auth_type == NL80211_AUTHTYPE_FILS_SK ||
4941 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
4942 auth_type == NL80211_AUTHTYPE_FILS_PK))
4943 return false;
e39e5b5e
JM
4944 return true;
4945 case NL80211_CMD_CONNECT:
10773a7c 4946 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) &&
26f7044e
CHH
4947 !wiphy_ext_feature_isset(&rdev->wiphy,
4948 NL80211_EXT_FEATURE_SAE_OFFLOAD) &&
10773a7c 4949 auth_type == NL80211_AUTHTYPE_SAE)
a3caf744 4950 return false;
10773a7c 4951
a3caf744
VK
4952 /* FILS with SK PFS or PK not supported yet */
4953 if (auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
4954 auth_type == NL80211_AUTHTYPE_FILS_PK)
4955 return false;
4956 if (!wiphy_ext_feature_isset(
4957 &rdev->wiphy,
4958 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
4959 auth_type == NL80211_AUTHTYPE_FILS_SK)
4960 return false;
4961 return true;
e39e5b5e
JM
4962 case NL80211_CMD_START_AP:
4963 /* SAE not supported yet */
4964 if (auth_type == NL80211_AUTHTYPE_SAE)
4965 return false;
63181060
JM
4966 /* FILS not supported yet */
4967 if (auth_type == NL80211_AUTHTYPE_FILS_SK ||
4968 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
4969 auth_type == NL80211_AUTHTYPE_FILS_PK)
4970 return false;
e39e5b5e
JM
4971 return true;
4972 default:
4973 return false;
4974 }
4975}
4976
8860020e
JB
4977static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info)
4978{
4979 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4980 struct net_device *dev = info->user_ptr[1];
4981 struct wireless_dev *wdev = dev->ieee80211_ptr;
4982 struct cfg80211_ap_settings params;
4983 int err;
4984
4985 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4986 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4987 return -EOPNOTSUPP;
4988
4989 if (!rdev->ops->start_ap)
4990 return -EOPNOTSUPP;
4991
4992 if (wdev->beacon_interval)
4993 return -EALREADY;
4994
4995 memset(&params, 0, sizeof(params));
4996
4997 /* these are required for START_AP */
4998 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
4999 !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
5000 !info->attrs[NL80211_ATTR_BEACON_HEAD])
5001 return -EINVAL;
5002
81e54d08 5003 err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon);
8860020e
JB
5004 if (err)
5005 return err;
5006
5007 params.beacon_interval =
5008 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
5009 params.dtim_period =
5010 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
5011
0c317a02
PK
5012 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype,
5013 params.beacon_interval);
8860020e
JB
5014 if (err)
5015 return err;
5016
5017 /*
5018 * In theory, some of these attributes should be required here
5019 * but since they were not used when the command was originally
5020 * added, keep them optional for old user space programs to let
5021 * them continue to work with drivers that do not need the
5022 * additional information -- drivers must check!
5023 */
5024 if (info->attrs[NL80211_ATTR_SSID]) {
5025 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
5026 params.ssid_len =
5027 nla_len(info->attrs[NL80211_ATTR_SSID]);
cb9abd48 5028 if (params.ssid_len == 0)
8860020e
JB
5029 return -EINVAL;
5030 }
5031
ab0d76f6 5032 if (info->attrs[NL80211_ATTR_HIDDEN_SSID])
8860020e
JB
5033 params.hidden_ssid = nla_get_u32(
5034 info->attrs[NL80211_ATTR_HIDDEN_SSID]);
8860020e
JB
5035
5036 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
5037
5038 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
5039 params.auth_type = nla_get_u32(
5040 info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
5041 if (!nl80211_valid_auth_type(rdev, params.auth_type,
5042 NL80211_CMD_START_AP))
8860020e
JB
5043 return -EINVAL;
5044 } else
5045 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
5046
5047 err = nl80211_crypto_settings(rdev, info, &params.crypto,
5048 NL80211_MAX_NR_CIPHER_SUITES);
5049 if (err)
5050 return err;
5051
1b658f11
VT
5052 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) {
5053 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER))
5054 return -EOPNOTSUPP;
5055 params.inactivity_timeout = nla_get_u16(
5056 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]);
5057 }
5058
53cabad7
JB
5059 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
5060 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5061 return -EINVAL;
5062 params.p2p_ctwindow =
5063 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
53cabad7
JB
5064 if (params.p2p_ctwindow != 0 &&
5065 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
5066 return -EINVAL;
5067 }
5068
5069 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
5070 u8 tmp;
5071
5072 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5073 return -EINVAL;
5074 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
53cabad7
JB
5075 params.p2p_opp_ps = tmp;
5076 if (params.p2p_opp_ps != 0 &&
5077 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
5078 return -EINVAL;
5079 }
5080
aa430da4 5081 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
5082 err = nl80211_parse_chandef(rdev, info, &params.chandef);
5083 if (err)
5084 return err;
5085 } else if (wdev->preset_chandef.chan) {
5086 params.chandef = wdev->preset_chandef;
46c1dd0c 5087 } else if (!nl80211_get_ap_channel(rdev, &params))
aa430da4
JB
5088 return -EINVAL;
5089
923b352f
AN
5090 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
5091 wdev->iftype))
aa430da4
JB
5092 return -EINVAL;
5093
a7c7fbff 5094 if (info->attrs[NL80211_ATTR_TX_RATES]) {
9a5f6488
TC
5095 err = nl80211_parse_tx_bitrate_mask(info, info->attrs,
5096 NL80211_ATTR_TX_RATES,
eb89a6a6
MH
5097 &params.beacon_rate,
5098 dev);
a7c7fbff
PK
5099 if (err)
5100 return err;
5101
8564e382
JB
5102 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band,
5103 &params.beacon_rate);
a7c7fbff
PK
5104 if (err)
5105 return err;
5106 }
5107
18998c38
EP
5108 if (info->attrs[NL80211_ATTR_SMPS_MODE]) {
5109 params.smps_mode =
5110 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]);
5111 switch (params.smps_mode) {
5112 case NL80211_SMPS_OFF:
5113 break;
5114 case NL80211_SMPS_STATIC:
5115 if (!(rdev->wiphy.features &
5116 NL80211_FEATURE_STATIC_SMPS))
5117 return -EINVAL;
5118 break;
5119 case NL80211_SMPS_DYNAMIC:
5120 if (!(rdev->wiphy.features &
5121 NL80211_FEATURE_DYNAMIC_SMPS))
5122 return -EINVAL;
5123 break;
5124 default:
5125 return -EINVAL;
5126 }
5127 } else {
5128 params.smps_mode = NL80211_SMPS_OFF;
5129 }
5130
6e8ef842
PK
5131 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
5132 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ])
5133 return -EOPNOTSUPP;
5134
4baf6bea
OO
5135 if (info->attrs[NL80211_ATTR_ACL_POLICY]) {
5136 params.acl = parse_acl_data(&rdev->wiphy, info);
5137 if (IS_ERR(params.acl))
5138 return PTR_ERR(params.acl);
5139 }
5140
a0de1ca3
JC
5141 params.twt_responder =
5142 nla_get_flag(info->attrs[NL80211_ATTR_TWT_RESPONDER]);
5143
796e90f4
JC
5144 if (info->attrs[NL80211_ATTR_HE_OBSS_PD]) {
5145 err = nl80211_parse_he_obss_pd(
5146 info->attrs[NL80211_ATTR_HE_OBSS_PD],
5147 &params.he_obss_pd);
bc7a39b4
LC
5148 if (err)
5149 goto out;
796e90f4
JC
5150 }
5151
5c5e52d1
JC
5152 if (info->attrs[NL80211_ATTR_HE_BSS_COLOR]) {
5153 err = nl80211_parse_he_bss_color(
5154 info->attrs[NL80211_ATTR_HE_BSS_COLOR],
5155 &params.he_bss_color);
5156 if (err)
60a0121f 5157 goto out;
5c5e52d1
JC
5158 }
5159
66cd794e
JB
5160 nl80211_calculate_ap_params(&params);
5161
fe494370
SD
5162 if (info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])
5163 params.flags |= AP_SETTINGS_EXTERNAL_AUTH_SUPPORT;
5164
c56589ed 5165 wdev_lock(wdev);
e35e4d28 5166 err = rdev_start_ap(rdev, dev, &params);
46c1dd0c 5167 if (!err) {
683b6d3b 5168 wdev->preset_chandef = params.chandef;
8860020e 5169 wdev->beacon_interval = params.beacon_interval;
9e0e2961 5170 wdev->chandef = params.chandef;
06e191e2
AQ
5171 wdev->ssid_len = params.ssid_len;
5172 memcpy(wdev->ssid, params.ssid, wdev->ssid_len);
466a3061
DK
5173
5174 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
5175 wdev->conn_owner_nlportid = info->snd_portid;
46c1dd0c 5176 }
c56589ed 5177 wdev_unlock(wdev);
77765eaf 5178
9951ebfc 5179out:
77765eaf
VT
5180 kfree(params.acl);
5181
56d1893d 5182 return err;
ed1b6cc7
JB
5183}
5184
8860020e
JB
5185static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info)
5186{
5187 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5188 struct net_device *dev = info->user_ptr[1];
5189 struct wireless_dev *wdev = dev->ieee80211_ptr;
5190 struct cfg80211_beacon_data params;
5191 int err;
5192
5193 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5194 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
5195 return -EOPNOTSUPP;
5196
5197 if (!rdev->ops->change_beacon)
5198 return -EOPNOTSUPP;
5199
5200 if (!wdev->beacon_interval)
5201 return -EINVAL;
5202
81e54d08 5203 err = nl80211_parse_beacon(rdev, info->attrs, &params);
8860020e
JB
5204 if (err)
5205 return err;
5206
c56589ed
SW
5207 wdev_lock(wdev);
5208 err = rdev_change_beacon(rdev, dev, &params);
5209 wdev_unlock(wdev);
5210
5211 return err;
8860020e
JB
5212}
5213
5214static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info)
ed1b6cc7 5215{
4c476991
JB
5216 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5217 struct net_device *dev = info->user_ptr[1];
ed1b6cc7 5218
7c8d5e03 5219 return cfg80211_stop_ap(rdev, dev, false);
ed1b6cc7
JB
5220}
5221
5727ef1b
JB
5222static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
5223 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
5224 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
5225 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
0e46724a 5226 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
b39c48fa 5227 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG },
d83023da 5228 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG },
5727ef1b
JB
5229};
5230
eccb8e8f 5231static int parse_station_flags(struct genl_info *info,
bdd3ae3d 5232 enum nl80211_iftype iftype,
eccb8e8f 5233 struct station_parameters *params)
5727ef1b
JB
5234{
5235 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
eccb8e8f 5236 struct nlattr *nla;
5727ef1b
JB
5237 int flag;
5238
eccb8e8f
JB
5239 /*
5240 * Try parsing the new attribute first so userspace
5241 * can specify both for older kernels.
5242 */
5243 nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
5244 if (nla) {
5245 struct nl80211_sta_flag_update *sta_flags;
5246
5247 sta_flags = nla_data(nla);
5248 params->sta_flags_mask = sta_flags->mask;
5249 params->sta_flags_set = sta_flags->set;
77ee7c89 5250 params->sta_flags_set &= params->sta_flags_mask;
eccb8e8f
JB
5251 if ((params->sta_flags_mask |
5252 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
5253 return -EINVAL;
5254 return 0;
5255 }
5256
5257 /* if present, parse the old attribute */
5727ef1b 5258
eccb8e8f 5259 nla = info->attrs[NL80211_ATTR_STA_FLAGS];
5727ef1b
JB
5260 if (!nla)
5261 return 0;
5262
8cb08174 5263 if (nla_parse_nested_deprecated(flags, NL80211_STA_FLAG_MAX, nla, sta_flags_policy, info->extack))
5727ef1b
JB
5264 return -EINVAL;
5265
bdd3ae3d
JB
5266 /*
5267 * Only allow certain flags for interface types so that
5268 * other attributes are silently ignored. Remember that
5269 * this is backward compatibility code with old userspace
5270 * and shouldn't be hit in other cases anyway.
5271 */
5272 switch (iftype) {
5273 case NL80211_IFTYPE_AP:
5274 case NL80211_IFTYPE_AP_VLAN:
5275 case NL80211_IFTYPE_P2P_GO:
5276 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
5277 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
5278 BIT(NL80211_STA_FLAG_WME) |
5279 BIT(NL80211_STA_FLAG_MFP);
5280 break;
5281 case NL80211_IFTYPE_P2P_CLIENT:
5282 case NL80211_IFTYPE_STATION:
5283 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) |
5284 BIT(NL80211_STA_FLAG_TDLS_PEER);
5285 break;
5286 case NL80211_IFTYPE_MESH_POINT:
5287 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5288 BIT(NL80211_STA_FLAG_MFP) |
5289 BIT(NL80211_STA_FLAG_AUTHORIZED);
5cf3006c 5290 break;
bdd3ae3d
JB
5291 default:
5292 return -EINVAL;
5293 }
5727ef1b 5294
3383b5a6
JB
5295 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) {
5296 if (flags[flag]) {
eccb8e8f 5297 params->sta_flags_set |= (1<<flag);
5727ef1b 5298
3383b5a6
JB
5299 /* no longer support new API additions in old API */
5300 if (flag > NL80211_STA_FLAG_MAX_OLD_API)
5301 return -EINVAL;
5302 }
5303 }
5304
5727ef1b
JB
5305 return 0;
5306}
5307
9bb7e0f2 5308bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, int attr)
c8dcfd8a
FF
5309{
5310 struct nlattr *rate;
8eb41c8d
VK
5311 u32 bitrate;
5312 u16 bitrate_compat;
bbf67e45 5313 enum nl80211_rate_info rate_flg;
c8dcfd8a 5314
ae0be8de 5315 rate = nla_nest_start_noflag(msg, attr);
c8dcfd8a 5316 if (!rate)
db9c64cf 5317 return false;
c8dcfd8a
FF
5318
5319 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
5320 bitrate = cfg80211_calculate_bitrate(info);
8eb41c8d
VK
5321 /* report 16-bit bitrate only if we can */
5322 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0;
db9c64cf
JB
5323 if (bitrate > 0 &&
5324 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate))
5325 return false;
5326 if (bitrate_compat > 0 &&
5327 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat))
5328 return false;
5329
b51f3bee
JB
5330 switch (info->bw) {
5331 case RATE_INFO_BW_5:
5332 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH;
5333 break;
5334 case RATE_INFO_BW_10:
5335 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH;
5336 break;
5337 default:
5338 WARN_ON(1);
7b506ff6 5339 fallthrough;
b51f3bee
JB
5340 case RATE_INFO_BW_20:
5341 rate_flg = 0;
5342 break;
5343 case RATE_INFO_BW_40:
5344 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH;
5345 break;
5346 case RATE_INFO_BW_80:
5347 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH;
5348 break;
5349 case RATE_INFO_BW_160:
5350 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH;
5351 break;
c4cbaf79
LC
5352 case RATE_INFO_BW_HE_RU:
5353 rate_flg = 0;
5354 WARN_ON(!(info->flags & RATE_INFO_FLAGS_HE_MCS));
b51f3bee
JB
5355 }
5356
5357 if (rate_flg && nla_put_flag(msg, rate_flg))
5358 return false;
5359
db9c64cf
JB
5360 if (info->flags & RATE_INFO_FLAGS_MCS) {
5361 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs))
5362 return false;
db9c64cf
JB
5363 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
5364 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
5365 return false;
5366 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) {
5367 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs))
5368 return false;
5369 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss))
5370 return false;
db9c64cf
JB
5371 if (info->flags & RATE_INFO_FLAGS_SHORT_GI &&
5372 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI))
5373 return false;
c4cbaf79
LC
5374 } else if (info->flags & RATE_INFO_FLAGS_HE_MCS) {
5375 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_MCS, info->mcs))
5376 return false;
5377 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_NSS, info->nss))
5378 return false;
5379 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_GI, info->he_gi))
5380 return false;
5381 if (nla_put_u8(msg, NL80211_RATE_INFO_HE_DCM, info->he_dcm))
5382 return false;
5383 if (info->bw == RATE_INFO_BW_HE_RU &&
5384 nla_put_u8(msg, NL80211_RATE_INFO_HE_RU_ALLOC,
5385 info->he_ru_alloc))
5386 return false;
db9c64cf 5387 }
c8dcfd8a
FF
5388
5389 nla_nest_end(msg, rate);
5390 return true;
c8dcfd8a
FF
5391}
5392
119363c7
FF
5393static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal,
5394 int id)
5395{
5396 void *attr;
5397 int i = 0;
5398
5399 if (!mask)
5400 return true;
5401
ae0be8de 5402 attr = nla_nest_start_noflag(msg, id);
119363c7
FF
5403 if (!attr)
5404 return false;
5405
5406 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) {
5407 if (!(mask & BIT(i)))
5408 continue;
5409
5410 if (nla_put_u8(msg, i, signal[i]))
5411 return false;
5412 }
5413
5414 nla_nest_end(msg, attr);
5415
5416 return true;
5417}
5418
cf5ead82
JB
5419static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid,
5420 u32 seq, int flags,
66266b3a
JL
5421 struct cfg80211_registered_device *rdev,
5422 struct net_device *dev,
98b62183 5423 const u8 *mac_addr, struct station_info *sinfo)
fd5b74dc
JB
5424{
5425 void *hdr;
f4263c98 5426 struct nlattr *sinfoattr, *bss_param;
fd5b74dc 5427
cf5ead82 5428 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
f77bf486
AS
5429 if (!hdr) {
5430 cfg80211_sinfo_release_content(sinfo);
fd5b74dc 5431 return -1;
f77bf486 5432 }
fd5b74dc 5433
9360ffd1
DM
5434 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
5435 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
5436 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation))
5437 goto nla_put_failure;
f5ea9120 5438
ae0be8de 5439 sinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_STA_INFO);
2ec600d6 5440 if (!sinfoattr)
fd5b74dc 5441 goto nla_put_failure;
319090bf
JB
5442
5443#define PUT_SINFO(attr, memb, type) do { \
d686b920 5444 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \
397c657a 5445 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_ ## attr) && \
319090bf
JB
5446 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \
5447 sinfo->memb)) \
5448 goto nla_put_failure; \
5449 } while (0)
d686b920 5450#define PUT_SINFO_U64(attr, memb) do { \
397c657a 5451 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_ ## attr) && \
d686b920
JB
5452 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \
5453 sinfo->memb, NL80211_STA_INFO_PAD)) \
5454 goto nla_put_failure; \
5455 } while (0)
319090bf
JB
5456
5457 PUT_SINFO(CONNECTED_TIME, connected_time, u32);
5458 PUT_SINFO(INACTIVE_TIME, inactive_time, u32);
6c7a0033 5459 PUT_SINFO_U64(ASSOC_AT_BOOTTIME, assoc_at);
319090bf 5460
397c657a
OE
5461 if (sinfo->filled & (BIT_ULL(NL80211_STA_INFO_RX_BYTES) |
5462 BIT_ULL(NL80211_STA_INFO_RX_BYTES64)) &&
9360ffd1 5463 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES,
42745e03 5464 (u32)sinfo->rx_bytes))
9360ffd1 5465 goto nla_put_failure;
319090bf 5466
397c657a
OE
5467 if (sinfo->filled & (BIT_ULL(NL80211_STA_INFO_TX_BYTES) |
5468 BIT_ULL(NL80211_STA_INFO_TX_BYTES64)) &&
9360ffd1 5469 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES,
42745e03
VK
5470 (u32)sinfo->tx_bytes))
5471 goto nla_put_failure;
319090bf 5472
d686b920
JB
5473 PUT_SINFO_U64(RX_BYTES64, rx_bytes);
5474 PUT_SINFO_U64(TX_BYTES64, tx_bytes);
319090bf
JB
5475 PUT_SINFO(LLID, llid, u16);
5476 PUT_SINFO(PLID, plid, u16);
5477 PUT_SINFO(PLINK_STATE, plink_state, u8);
d686b920 5478 PUT_SINFO_U64(RX_DURATION, rx_duration);
36647055
THJ
5479 PUT_SINFO_U64(TX_DURATION, tx_duration);
5480
5481 if (wiphy_ext_feature_isset(&rdev->wiphy,
5482 NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
5483 PUT_SINFO(AIRTIME_WEIGHT, airtime_weight, u16);
319090bf 5484
66266b3a
JL
5485 switch (rdev->wiphy.signal_type) {
5486 case CFG80211_SIGNAL_TYPE_MBM:
319090bf
JB
5487 PUT_SINFO(SIGNAL, signal, u8);
5488 PUT_SINFO(SIGNAL_AVG, signal_avg, u8);
66266b3a
JL
5489 break;
5490 default:
5491 break;
5492 }
397c657a 5493 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL)) {
119363c7
FF
5494 if (!nl80211_put_signal(msg, sinfo->chains,
5495 sinfo->chain_signal,
5496 NL80211_STA_INFO_CHAIN_SIGNAL))
5497 goto nla_put_failure;
5498 }
397c657a 5499 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) {
119363c7
FF
5500 if (!nl80211_put_signal(msg, sinfo->chains,
5501 sinfo->chain_signal_avg,
5502 NL80211_STA_INFO_CHAIN_SIGNAL_AVG))
5503 goto nla_put_failure;
5504 }
397c657a 5505 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_TX_BITRATE)) {
c8dcfd8a
FF
5506 if (!nl80211_put_sta_rate(msg, &sinfo->txrate,
5507 NL80211_STA_INFO_TX_BITRATE))
5508 goto nla_put_failure;
5509 }
397c657a 5510 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_RX_BITRATE)) {
c8dcfd8a
FF
5511 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate,
5512 NL80211_STA_INFO_RX_BITRATE))
420e7fab 5513 goto nla_put_failure;
420e7fab 5514 }
319090bf
JB
5515
5516 PUT_SINFO(RX_PACKETS, rx_packets, u32);
5517 PUT_SINFO(TX_PACKETS, tx_packets, u32);
5518 PUT_SINFO(TX_RETRIES, tx_retries, u32);
5519 PUT_SINFO(TX_FAILED, tx_failed, u32);
5520 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32);
ab60633c 5521 PUT_SINFO(AIRTIME_LINK_METRIC, airtime_link_metric, u32);
319090bf
JB
5522 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32);
5523 PUT_SINFO(LOCAL_PM, local_pm, u32);
5524 PUT_SINFO(PEER_PM, peer_pm, u32);
5525 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32);
dbdaee7a 5526 PUT_SINFO(CONNECTED_TO_GATE, connected_to_gate, u8);
1303a51c 5527 PUT_SINFO(CONNECTED_TO_AS, connected_to_as, u8);
319090bf 5528
397c657a 5529 if (sinfo->filled & BIT_ULL(NL80211_STA_INFO_BSS_PARAM)) {
ae0be8de
MK
5530 bss_param = nla_nest_start_noflag(msg,
5531 NL80211_STA_INFO_BSS_PARAM);
f4263c98
PS
5532 if (!bss_param)
5533 goto nla_put_failure;
5534
9360ffd1
DM
5535 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) &&
5536 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) ||
5537 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) &&
5538 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) ||
5539 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) &&
5540 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) ||
5541 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD,
5542 sinfo->bss_param.dtim_period) ||
5543 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL,
5544 sinfo->bss_param.beacon_interval))
5545 goto nla_put_failure;
f4263c98
PS
5546
5547 nla_nest_end(msg, bss_param);
5548 }
397c657a 5549 if ((sinfo->filled & BIT_ULL(NL80211_STA_INFO_STA_FLAGS)) &&
9360ffd1
DM
5550 nla_put(msg, NL80211_STA_INFO_STA_FLAGS,
5551 sizeof(struct nl80211_sta_flag_update),
5552 &sinfo->sta_flags))
5553 goto nla_put_failure;
319090bf 5554
d686b920
JB
5555 PUT_SINFO_U64(T_OFFSET, t_offset);
5556 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc);
5557 PUT_SINFO_U64(BEACON_RX, rx_beacon);
a76b1942 5558 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8);
0d4e14a3
AB
5559 PUT_SINFO(RX_MPDUS, rx_mpdu_count, u32);
5560 PUT_SINFO(FCS_ERROR_COUNT, fcs_err_count, u32);
81d5439d 5561 if (wiphy_ext_feature_isset(&rdev->wiphy,
9c06602b
BP
5562 NL80211_EXT_FEATURE_ACK_SIGNAL_SUPPORT)) {
5563 PUT_SINFO(ACK_SIGNAL, ack_signal, u8);
5564 PUT_SINFO(ACK_SIGNAL_AVG, avg_ack_signal, s8);
5565 }
319090bf
JB
5566
5567#undef PUT_SINFO
d686b920 5568#undef PUT_SINFO_U64
6de39808 5569
8689c051 5570 if (sinfo->pertid) {
6de39808
JB
5571 struct nlattr *tidsattr;
5572 int tid;
5573
ae0be8de
MK
5574 tidsattr = nla_nest_start_noflag(msg,
5575 NL80211_STA_INFO_TID_STATS);
6de39808
JB
5576 if (!tidsattr)
5577 goto nla_put_failure;
5578
5579 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) {
5580 struct cfg80211_tid_stats *tidstats;
5581 struct nlattr *tidattr;
5582
5583 tidstats = &sinfo->pertid[tid];
5584
5585 if (!tidstats->filled)
5586 continue;
5587
ae0be8de 5588 tidattr = nla_nest_start_noflag(msg, tid + 1);
6de39808
JB
5589 if (!tidattr)
5590 goto nla_put_failure;
5591
d686b920 5592#define PUT_TIDVAL_U64(attr, memb) do { \
6de39808 5593 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \
d686b920
JB
5594 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \
5595 tidstats->memb, NL80211_TID_STATS_PAD)) \
6de39808
JB
5596 goto nla_put_failure; \
5597 } while (0)
5598
d686b920
JB
5599 PUT_TIDVAL_U64(RX_MSDU, rx_msdu);
5600 PUT_TIDVAL_U64(TX_MSDU, tx_msdu);
5601 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries);
5602 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed);
6de39808 5603
d686b920 5604#undef PUT_TIDVAL_U64
52539ca8
THJ
5605 if ((tidstats->filled &
5606 BIT(NL80211_TID_STATS_TXQ_STATS)) &&
5607 !nl80211_put_txq_stats(msg, &tidstats->txq_stats,
5608 NL80211_TID_STATS_TXQ_STATS))
5609 goto nla_put_failure;
5610
6de39808
JB
5611 nla_nest_end(msg, tidattr);
5612 }
5613
5614 nla_nest_end(msg, tidsattr);
5615 }
5616
2ec600d6 5617 nla_nest_end(msg, sinfoattr);
fd5b74dc 5618
319090bf 5619 if (sinfo->assoc_req_ies_len &&
9360ffd1
DM
5620 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len,
5621 sinfo->assoc_req_ies))
5622 goto nla_put_failure;
50d3dfb7 5623
7ea3e110 5624 cfg80211_sinfo_release_content(sinfo);
053c095a
JB
5625 genlmsg_end(msg, hdr);
5626 return 0;
fd5b74dc
JB
5627
5628 nla_put_failure:
7ea3e110 5629 cfg80211_sinfo_release_content(sinfo);
bc3ed28c
TG
5630 genlmsg_cancel(msg, hdr);
5631 return -EMSGSIZE;
fd5b74dc
JB
5632}
5633
2ec600d6 5634static int nl80211_dump_station(struct sk_buff *skb,
bba95fef 5635 struct netlink_callback *cb)
2ec600d6 5636{
73887fd9 5637 struct station_info sinfo;
1b8ec87a 5638 struct cfg80211_registered_device *rdev;
97990a06 5639 struct wireless_dev *wdev;
2ec600d6 5640 u8 mac_addr[ETH_ALEN];
97990a06 5641 int sta_idx = cb->args[2];
2ec600d6 5642 int err;
2ec600d6 5643
ea90e0dc 5644 rtnl_lock();
5297c65c 5645 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
67748893 5646 if (err)
ea90e0dc 5647 goto out_err;
bba95fef 5648
97990a06
JB
5649 if (!wdev->netdev) {
5650 err = -EINVAL;
5651 goto out_err;
5652 }
5653
1b8ec87a 5654 if (!rdev->ops->dump_station) {
eec60b03 5655 err = -EOPNOTSUPP;
bba95fef
JB
5656 goto out_err;
5657 }
5658
bba95fef 5659 while (1) {
73887fd9 5660 memset(&sinfo, 0, sizeof(sinfo));
1b8ec87a 5661 err = rdev_dump_station(rdev, wdev->netdev, sta_idx,
73887fd9 5662 mac_addr, &sinfo);
bba95fef
JB
5663 if (err == -ENOENT)
5664 break;
5665 if (err)
3b85875a 5666 goto out_err;
bba95fef 5667
cf5ead82 5668 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION,
15e47304 5669 NETLINK_CB(cb->skb).portid,
bba95fef 5670 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1b8ec87a 5671 rdev, wdev->netdev, mac_addr,
73887fd9 5672 &sinfo) < 0)
bba95fef
JB
5673 goto out;
5674
5675 sta_idx++;
5676 }
5677
bba95fef 5678 out:
97990a06 5679 cb->args[2] = sta_idx;
bba95fef 5680 err = skb->len;
bba95fef 5681 out_err:
ea90e0dc 5682 rtnl_unlock();
bba95fef
JB
5683
5684 return err;
2ec600d6 5685}
fd5b74dc 5686
5727ef1b
JB
5687static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
5688{
4c476991
JB
5689 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5690 struct net_device *dev = info->user_ptr[1];
73887fd9 5691 struct station_info sinfo;
fd5b74dc
JB
5692 struct sk_buff *msg;
5693 u8 *mac_addr = NULL;
4c476991 5694 int err;
fd5b74dc 5695
73887fd9 5696 memset(&sinfo, 0, sizeof(sinfo));
fd5b74dc 5697
73887fd9
JB
5698 if (!info->attrs[NL80211_ATTR_MAC])
5699 return -EINVAL;
fd5b74dc
JB
5700
5701 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
5702
73887fd9
JB
5703 if (!rdev->ops->get_station)
5704 return -EOPNOTSUPP;
3b85875a 5705
73887fd9 5706 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
fd5b74dc 5707 if (err)
73887fd9 5708 return err;
2ec600d6 5709
fd2120ca 5710 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7ea3e110 5711 if (!msg) {
ba8f566a 5712 cfg80211_sinfo_release_content(&sinfo);
73887fd9 5713 return -ENOMEM;
7ea3e110 5714 }
fd5b74dc 5715
cf5ead82
JB
5716 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION,
5717 info->snd_portid, info->snd_seq, 0,
73887fd9 5718 rdev, dev, mac_addr, &sinfo) < 0) {
4c476991 5719 nlmsg_free(msg);
73887fd9 5720 return -ENOBUFS;
4c476991 5721 }
3b85875a 5722
73887fd9 5723 return genlmsg_reply(msg, info);
5727ef1b
JB
5724}
5725
77ee7c89
JB
5726int cfg80211_check_station_change(struct wiphy *wiphy,
5727 struct station_parameters *params,
5728 enum cfg80211_station_type statype)
5729{
e4208427
AB
5730 if (params->listen_interval != -1 &&
5731 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89 5732 return -EINVAL;
e4208427 5733
17b94247
AB
5734 if (params->support_p2p_ps != -1 &&
5735 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
5736 return -EINVAL;
5737
c72e1140 5738 if (params->aid &&
e4208427
AB
5739 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) &&
5740 statype != CFG80211_STA_AP_CLIENT_UNASSOC)
77ee7c89
JB
5741 return -EINVAL;
5742
5743 /* When you run into this, adjust the code below for the new flag */
5744 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
5745
5746 switch (statype) {
eef941e6
TP
5747 case CFG80211_STA_MESH_PEER_KERNEL:
5748 case CFG80211_STA_MESH_PEER_USER:
77ee7c89
JB
5749 /*
5750 * No ignoring the TDLS flag here -- the userspace mesh
5751 * code doesn't have the bug of including TDLS in the
5752 * mask everywhere.
5753 */
5754 if (params->sta_flags_mask &
5755 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5756 BIT(NL80211_STA_FLAG_MFP) |
5757 BIT(NL80211_STA_FLAG_AUTHORIZED)))
5758 return -EINVAL;
5759 break;
5760 case CFG80211_STA_TDLS_PEER_SETUP:
5761 case CFG80211_STA_TDLS_PEER_ACTIVE:
5762 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
5763 return -EINVAL;
5764 /* ignore since it can't change */
5765 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
5766 break;
5767 default:
5768 /* disallow mesh-specific things */
5769 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION)
5770 return -EINVAL;
5771 if (params->local_pm)
5772 return -EINVAL;
5773 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
5774 return -EINVAL;
5775 }
5776
5777 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
5778 statype != CFG80211_STA_TDLS_PEER_ACTIVE) {
5779 /* TDLS can't be set, ... */
5780 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))
5781 return -EINVAL;
5782 /*
5783 * ... but don't bother the driver with it. This works around
5784 * a hostapd/wpa_supplicant issue -- it always includes the
5785 * TLDS_PEER flag in the mask even for AP mode.
5786 */
5787 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
5788 }
5789
47edb11b
AB
5790 if (statype != CFG80211_STA_TDLS_PEER_SETUP &&
5791 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
5792 /* reject other things that can't change */
5793 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD)
5794 return -EINVAL;
5795 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY)
5796 return -EINVAL;
5797 if (params->supported_rates)
5798 return -EINVAL;
c4cbaf79
LC
5799 if (params->ext_capab || params->ht_capa || params->vht_capa ||
5800 params->he_capa)
77ee7c89
JB
5801 return -EINVAL;
5802 }
5803
47edb11b
AB
5804 if (statype != CFG80211_STA_AP_CLIENT &&
5805 statype != CFG80211_STA_AP_CLIENT_UNASSOC) {
77ee7c89
JB
5806 if (params->vlan)
5807 return -EINVAL;
5808 }
5809
5810 switch (statype) {
5811 case CFG80211_STA_AP_MLME_CLIENT:
5812 /* Use this only for authorizing/unauthorizing a station */
5813 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED)))
5814 return -EOPNOTSUPP;
5815 break;
5816 case CFG80211_STA_AP_CLIENT:
47edb11b 5817 case CFG80211_STA_AP_CLIENT_UNASSOC:
77ee7c89
JB
5818 /* accept only the listed bits */
5819 if (params->sta_flags_mask &
5820 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
5821 BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5822 BIT(NL80211_STA_FLAG_ASSOCIATED) |
5823 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) |
5824 BIT(NL80211_STA_FLAG_WME) |
5825 BIT(NL80211_STA_FLAG_MFP)))
5826 return -EINVAL;
5827
5828 /* but authenticated/associated only if driver handles it */
5829 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
5830 params->sta_flags_mask &
5831 (BIT(NL80211_STA_FLAG_AUTHENTICATED) |
5832 BIT(NL80211_STA_FLAG_ASSOCIATED)))
5833 return -EINVAL;
5834 break;
5835 case CFG80211_STA_IBSS:
5836 case CFG80211_STA_AP_STA:
5837 /* reject any changes other than AUTHORIZED */
5838 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
5839 return -EINVAL;
5840 break;
5841 case CFG80211_STA_TDLS_PEER_SETUP:
5842 /* reject any changes other than AUTHORIZED or WME */
5843 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) |
5844 BIT(NL80211_STA_FLAG_WME)))
5845 return -EINVAL;
5846 /* force (at least) rates when authorizing */
5847 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) &&
5848 !params->supported_rates)
5849 return -EINVAL;
5850 break;
5851 case CFG80211_STA_TDLS_PEER_ACTIVE:
5852 /* reject any changes */
5853 return -EINVAL;
eef941e6 5854 case CFG80211_STA_MESH_PEER_KERNEL:
77ee7c89
JB
5855 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE)
5856 return -EINVAL;
5857 break;
eef941e6 5858 case CFG80211_STA_MESH_PEER_USER:
42925040
CYY
5859 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION &&
5860 params->plink_action != NL80211_PLINK_ACTION_BLOCK)
77ee7c89
JB
5861 return -EINVAL;
5862 break;
5863 }
5864
06f7c88c
BL
5865 /*
5866 * Older kernel versions ignored this attribute entirely, so don't
5867 * reject attempts to update it but mark it as unused instead so the
5868 * driver won't look at the data.
5869 */
5870 if (statype != CFG80211_STA_AP_CLIENT_UNASSOC &&
5871 statype != CFG80211_STA_TDLS_PEER_SETUP)
5872 params->opmode_notif_used = false;
5873
77ee7c89
JB
5874 return 0;
5875}
5876EXPORT_SYMBOL(cfg80211_check_station_change);
5877
5727ef1b 5878/*
c258d2de 5879 * Get vlan interface making sure it is running and on the right wiphy.
5727ef1b 5880 */
80b99899
JB
5881static struct net_device *get_vlan(struct genl_info *info,
5882 struct cfg80211_registered_device *rdev)
5727ef1b 5883{
463d0183 5884 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
80b99899
JB
5885 struct net_device *v;
5886 int ret;
5887
5888 if (!vlanattr)
5889 return NULL;
5890
5891 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr));
5892 if (!v)
5893 return ERR_PTR(-ENODEV);
5894
5895 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) {
5896 ret = -EINVAL;
5897 goto error;
5727ef1b 5898 }
80b99899 5899
77ee7c89
JB
5900 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
5901 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
5902 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) {
5903 ret = -EINVAL;
5904 goto error;
5905 }
5906
80b99899
JB
5907 if (!netif_running(v)) {
5908 ret = -ENETDOWN;
5909 goto error;
5910 }
5911
5912 return v;
5913 error:
5914 dev_put(v);
5915 return ERR_PTR(ret);
5727ef1b
JB
5916}
5917
94e860f1
JB
5918static const struct nla_policy
5919nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = {
df881293
JM
5920 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 },
5921 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 },
5922};
5923
ff276691
JB
5924static int nl80211_parse_sta_wme(struct genl_info *info,
5925 struct station_parameters *params)
df881293 5926{
df881293
JM
5927 struct nlattr *tb[NL80211_STA_WME_MAX + 1];
5928 struct nlattr *nla;
5929 int err;
5930
df881293
JM
5931 /* parse WME attributes if present */
5932 if (!info->attrs[NL80211_ATTR_STA_WME])
5933 return 0;
5934
5935 nla = info->attrs[NL80211_ATTR_STA_WME];
8cb08174
JB
5936 err = nla_parse_nested_deprecated(tb, NL80211_STA_WME_MAX, nla,
5937 nl80211_sta_wme_policy,
5938 info->extack);
df881293
JM
5939 if (err)
5940 return err;
5941
5942 if (tb[NL80211_STA_WME_UAPSD_QUEUES])
5943 params->uapsd_queues = nla_get_u8(
5944 tb[NL80211_STA_WME_UAPSD_QUEUES]);
5945 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK)
5946 return -EINVAL;
5947
5948 if (tb[NL80211_STA_WME_MAX_SP])
5949 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]);
5950
5951 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK)
5952 return -EINVAL;
5953
5954 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD;
5955
5956 return 0;
5957}
5958
c01fc9ad
SD
5959static int nl80211_parse_sta_channel_info(struct genl_info *info,
5960 struct station_parameters *params)
5961{
5962 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) {
5963 params->supported_channels =
5964 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
5965 params->supported_channels_len =
5966 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]);
5967 /*
5968 * Need to include at least one (first channel, number of
cb9abd48
JB
5969 * channels) tuple for each subband (checked in policy),
5970 * and must have proper tuples for the rest of the data as well.
c01fc9ad 5971 */
c01fc9ad
SD
5972 if (params->supported_channels_len % 2)
5973 return -EINVAL;
5974 }
5975
5976 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) {
5977 params->supported_oper_classes =
5978 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
5979 params->supported_oper_classes_len =
5980 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]);
c01fc9ad
SD
5981 }
5982 return 0;
5983}
5984
ff276691
JB
5985static int nl80211_set_station_tdls(struct genl_info *info,
5986 struct station_parameters *params)
5987{
c01fc9ad 5988 int err;
ff276691 5989 /* Dummy STA entry gets updated once the peer capabilities are known */
5e4b6f56
JM
5990 if (info->attrs[NL80211_ATTR_PEER_AID])
5991 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
ff276691
JB
5992 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
5993 params->ht_capa =
5994 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5995 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
5996 params->vht_capa =
5997 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
c4cbaf79
LC
5998 if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
5999 params->he_capa =
6000 nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
6001 params->he_capa_len =
6002 nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
c4cbaf79 6003 }
ff276691 6004
c01fc9ad
SD
6005 err = nl80211_parse_sta_channel_info(info, params);
6006 if (err)
6007 return err;
6008
ff276691
JB
6009 return nl80211_parse_sta_wme(info, params);
6010}
6011
e96d1cd2
ARN
6012static int nl80211_parse_sta_txpower_setting(struct genl_info *info,
6013 struct station_parameters *params)
6014{
6015 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6016 int idx;
6017
6018 if (info->attrs[NL80211_ATTR_STA_TX_POWER_SETTING]) {
6019 if (!rdev->ops->set_tx_power ||
6020 !wiphy_ext_feature_isset(&rdev->wiphy,
6021 NL80211_EXT_FEATURE_STA_TX_PWR))
6022 return -EOPNOTSUPP;
6023
6024 idx = NL80211_ATTR_STA_TX_POWER_SETTING;
6025 params->txpwr.type = nla_get_u8(info->attrs[idx]);
6026
6027 if (params->txpwr.type == NL80211_TX_POWER_LIMITED) {
6028 idx = NL80211_ATTR_STA_TX_POWER;
6029
6030 if (info->attrs[idx])
6031 params->txpwr.power =
6032 nla_get_s16(info->attrs[idx]);
6033 else
6034 return -EINVAL;
6035 }
6036 params->sta_modify_mask |= STATION_PARAM_APPLY_STA_TXPOWER;
6037 }
6038
6039 return 0;
6040}
6041
5727ef1b
JB
6042static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
6043{
4c476991 6044 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 6045 struct net_device *dev = info->user_ptr[1];
5727ef1b 6046 struct station_parameters params;
77ee7c89
JB
6047 u8 *mac_addr;
6048 int err;
5727ef1b
JB
6049
6050 memset(&params, 0, sizeof(params));
6051
77ee7c89
JB
6052 if (!rdev->ops->change_station)
6053 return -EOPNOTSUPP;
6054
e4208427
AB
6055 /*
6056 * AID and listen_interval properties can be set only for unassociated
6057 * station. Include these parameters here and will check them in
6058 * cfg80211_check_station_change().
6059 */
a9bc31e4
AB
6060 if (info->attrs[NL80211_ATTR_STA_AID])
6061 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
e4208427 6062
14f34e36
GG
6063 if (info->attrs[NL80211_ATTR_VLAN_ID])
6064 params.vlan_id = nla_get_u16(info->attrs[NL80211_ATTR_VLAN_ID]);
6065
e4208427
AB
6066 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
6067 params.listen_interval =
6068 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
6069 else
6070 params.listen_interval = -1;
5727ef1b 6071
ab0d76f6
JB
6072 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS])
6073 params.support_p2p_ps =
6074 nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
6075 else
17b94247 6076 params.support_p2p_ps = -1;
17b94247 6077
5727ef1b
JB
6078 if (!info->attrs[NL80211_ATTR_MAC])
6079 return -EINVAL;
6080
6081 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6082
6083 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
6084 params.supported_rates =
6085 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
6086 params.supported_rates_len =
6087 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
6088 }
6089
9d62a986
JM
6090 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
6091 params.capability =
6092 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
6093 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
6094 }
6095
6096 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
6097 params.ext_capab =
6098 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
6099 params.ext_capab_len =
6100 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
6101 }
6102
bdd3ae3d 6103 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
6104 return -EINVAL;
6105
ab0d76f6 6106 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2ec600d6 6107 params.plink_action =
f8bacc21 6108 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2ec600d6 6109
f8bacc21 6110 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) {
9c3990aa 6111 params.plink_state =
f8bacc21 6112 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]);
ab0d76f6 6113 if (info->attrs[NL80211_ATTR_MESH_PEER_AID])
7d27a0ba
MH
6114 params.peer_aid = nla_get_u16(
6115 info->attrs[NL80211_ATTR_MESH_PEER_AID]);
f8bacc21
JB
6116 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE;
6117 }
9c3990aa 6118
ab0d76f6
JB
6119 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE])
6120 params.local_pm = nla_get_u32(
3b1c5a53
MP
6121 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]);
6122
06f7c88c
BL
6123 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
6124 params.opmode_notif_used = true;
6125 params.opmode_notif =
6126 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
6127 }
6128
43e64bf3
RM
6129 if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY])
6130 params.he_6ghz_capa =
6131 nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
6132
36647055
THJ
6133 if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT])
6134 params.airtime_weight =
6135 nla_get_u16(info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]);
6136
6137 if (params.airtime_weight &&
6138 !wiphy_ext_feature_isset(&rdev->wiphy,
6139 NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
6140 return -EOPNOTSUPP;
6141
e96d1cd2
ARN
6142 err = nl80211_parse_sta_txpower_setting(info, &params);
6143 if (err)
6144 return err;
6145
77ee7c89
JB
6146 /* Include parameters for TDLS peer (will check later) */
6147 err = nl80211_set_station_tdls(info, &params);
6148 if (err)
6149 return err;
6150
6151 params.vlan = get_vlan(info, rdev);
6152 if (IS_ERR(params.vlan))
6153 return PTR_ERR(params.vlan);
6154
a97f4424
JB
6155 switch (dev->ieee80211_ptr->iftype) {
6156 case NL80211_IFTYPE_AP:
6157 case NL80211_IFTYPE_AP_VLAN:
074ac8df 6158 case NL80211_IFTYPE_P2P_GO:
074ac8df 6159 case NL80211_IFTYPE_P2P_CLIENT:
a97f4424 6160 case NL80211_IFTYPE_STATION:
267335d6 6161 case NL80211_IFTYPE_ADHOC:
a97f4424 6162 case NL80211_IFTYPE_MESH_POINT:
a97f4424
JB
6163 break;
6164 default:
77ee7c89
JB
6165 err = -EOPNOTSUPP;
6166 goto out_put_vlan;
034d655e
JB
6167 }
6168
77ee7c89 6169 /* driver will call cfg80211_check_station_change() */
e35e4d28 6170 err = rdev_change_station(rdev, dev, mac_addr, &params);
5727ef1b 6171
77ee7c89 6172 out_put_vlan:
5727ef1b
JB
6173 if (params.vlan)
6174 dev_put(params.vlan);
3b85875a 6175
5727ef1b
JB
6176 return err;
6177}
6178
6179static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
6180{
4c476991 6181 struct cfg80211_registered_device *rdev = info->user_ptr[0];
5727ef1b 6182 int err;
4c476991 6183 struct net_device *dev = info->user_ptr[1];
5727ef1b
JB
6184 struct station_parameters params;
6185 u8 *mac_addr = NULL;
bda95eb1
JB
6186 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) |
6187 BIT(NL80211_STA_FLAG_ASSOCIATED);
5727ef1b
JB
6188
6189 memset(&params, 0, sizeof(params));
6190
984c311b
JB
6191 if (!rdev->ops->add_station)
6192 return -EOPNOTSUPP;
6193
5727ef1b
JB
6194 if (!info->attrs[NL80211_ATTR_MAC])
6195 return -EINVAL;
6196
5727ef1b
JB
6197 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
6198 return -EINVAL;
6199
6200 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
6201 return -EINVAL;
6202
5e4b6f56
JM
6203 if (!info->attrs[NL80211_ATTR_STA_AID] &&
6204 !info->attrs[NL80211_ATTR_PEER_AID])
0e956c13
TLSC
6205 return -EINVAL;
6206
5727ef1b
JB
6207 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
6208 params.supported_rates =
6209 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
6210 params.supported_rates_len =
6211 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
6212 params.listen_interval =
6213 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
51b50fbe 6214
14f34e36
GG
6215 if (info->attrs[NL80211_ATTR_VLAN_ID])
6216 params.vlan_id = nla_get_u16(info->attrs[NL80211_ATTR_VLAN_ID]);
6217
17b94247 6218 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) {
ab0d76f6
JB
6219 params.support_p2p_ps =
6220 nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]);
17b94247
AB
6221 } else {
6222 /*
6223 * if not specified, assume it's supported for P2P GO interface,
6224 * and is NOT supported for AP interface
6225 */
6226 params.support_p2p_ps =
6227 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO;
6228 }
6229
3d124ea2 6230 if (info->attrs[NL80211_ATTR_PEER_AID])
5e4b6f56 6231 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]);
3d124ea2
JM
6232 else
6233 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
51b50fbe 6234
9d62a986
JM
6235 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) {
6236 params.capability =
6237 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]);
6238 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY;
6239 }
6240
6241 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) {
6242 params.ext_capab =
6243 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
6244 params.ext_capab_len =
6245 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]);
6246 }
6247
36aedc90
JM
6248 if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
6249 params.ht_capa =
6250 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
5727ef1b 6251
f461be3e
MP
6252 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY])
6253 params.vht_capa =
6254 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]);
6255
c4cbaf79
LC
6256 if (info->attrs[NL80211_ATTR_HE_CAPABILITY]) {
6257 params.he_capa =
6258 nla_data(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
6259 params.he_capa_len =
6260 nla_len(info->attrs[NL80211_ATTR_HE_CAPABILITY]);
c4cbaf79
LC
6261 }
6262
43e64bf3
RM
6263 if (info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY])
6264 params.he_6ghz_capa =
6265 nla_data(info->attrs[NL80211_ATTR_HE_6GHZ_CAPABILITY]);
6266
60f4a7b1
MK
6267 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) {
6268 params.opmode_notif_used = true;
6269 params.opmode_notif =
6270 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]);
6271 }
6272
ab0d76f6 6273 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
96b78dff 6274 params.plink_action =
f8bacc21 6275 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
96b78dff 6276
36647055
THJ
6277 if (info->attrs[NL80211_ATTR_AIRTIME_WEIGHT])
6278 params.airtime_weight =
6279 nla_get_u16(info->attrs[NL80211_ATTR_AIRTIME_WEIGHT]);
6280
6281 if (params.airtime_weight &&
6282 !wiphy_ext_feature_isset(&rdev->wiphy,
6283 NL80211_EXT_FEATURE_AIRTIME_FAIRNESS))
6284 return -EOPNOTSUPP;
6285
e96d1cd2
ARN
6286 err = nl80211_parse_sta_txpower_setting(info, &params);
6287 if (err)
6288 return err;
6289
c01fc9ad
SD
6290 err = nl80211_parse_sta_channel_info(info, &params);
6291 if (err)
6292 return err;
6293
ff276691
JB
6294 err = nl80211_parse_sta_wme(info, &params);
6295 if (err)
6296 return err;
bdd90d5e 6297
bdd3ae3d 6298 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, &params))
5727ef1b
JB
6299 return -EINVAL;
6300
496fcc29
JB
6301 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT
6302 * as userspace might just pass through the capabilities from the IEs
6303 * directly, rather than enforcing this restriction and returning an
6304 * error in this case.
6305 */
6306 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) {
6307 params.ht_capa = NULL;
6308 params.vht_capa = NULL;
c4cbaf79
LC
6309
6310 /* HE requires WME */
43e64bf3 6311 if (params.he_capa_len || params.he_6ghz_capa)
c4cbaf79 6312 return -EINVAL;
496fcc29
JB
6313 }
6314
43e64bf3
RM
6315 /* Ensure that HT/VHT capabilities are not set for 6 GHz HE STA */
6316 if (params.he_6ghz_capa && (params.ht_capa || params.vht_capa))
6317 return -EINVAL;
6318
77ee7c89
JB
6319 /* When you run into this, adjust the code below for the new flag */
6320 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7);
6321
bdd90d5e
JB
6322 switch (dev->ieee80211_ptr->iftype) {
6323 case NL80211_IFTYPE_AP:
6324 case NL80211_IFTYPE_AP_VLAN:
6325 case NL80211_IFTYPE_P2P_GO:
984c311b
JB
6326 /* ignore WME attributes if iface/sta is not capable */
6327 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) ||
6328 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME)))
6329 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
c75786c9 6330
bdd90d5e 6331 /* TDLS peers cannot be added */
3d124ea2
JM
6332 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
6333 info->attrs[NL80211_ATTR_PEER_AID])
4319e193 6334 return -EINVAL;
bdd90d5e
JB
6335 /* but don't bother the driver with it */
6336 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER);
3b9ce80c 6337
d582cffb
JB
6338 /* allow authenticated/associated only if driver handles it */
6339 if (!(rdev->wiphy.features &
6340 NL80211_FEATURE_FULL_AP_CLIENT_STATE) &&
bda95eb1 6341 params.sta_flags_mask & auth_assoc)
d582cffb
JB
6342 return -EINVAL;
6343
bda95eb1
JB
6344 /* Older userspace, or userspace wanting to be compatible with
6345 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth
6346 * and assoc flags in the mask, but assumes the station will be
6347 * added as associated anyway since this was the required driver
6348 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was
6349 * introduced.
6350 * In order to not bother drivers with this quirk in the API
6351 * set the flags in both the mask and set for new stations in
6352 * this case.
6353 */
6354 if (!(params.sta_flags_mask & auth_assoc)) {
6355 params.sta_flags_mask |= auth_assoc;
6356 params.sta_flags_set |= auth_assoc;
6357 }
6358
bdd90d5e
JB
6359 /* must be last in here for error handling */
6360 params.vlan = get_vlan(info, rdev);
6361 if (IS_ERR(params.vlan))
6362 return PTR_ERR(params.vlan);
6363 break;
6364 case NL80211_IFTYPE_MESH_POINT:
984c311b
JB
6365 /* ignore uAPSD data */
6366 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
6367
d582cffb
JB
6368 /* associated is disallowed */
6369 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED))
6370 return -EINVAL;
bdd90d5e 6371 /* TDLS peers cannot be added */
3d124ea2
JM
6372 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) ||
6373 info->attrs[NL80211_ATTR_PEER_AID])
bdd90d5e
JB
6374 return -EINVAL;
6375 break;
6376 case NL80211_IFTYPE_STATION:
93d08f0b 6377 case NL80211_IFTYPE_P2P_CLIENT:
984c311b
JB
6378 /* ignore uAPSD data */
6379 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD;
6380
77ee7c89
JB
6381 /* these are disallowed */
6382 if (params.sta_flags_mask &
6383 (BIT(NL80211_STA_FLAG_ASSOCIATED) |
6384 BIT(NL80211_STA_FLAG_AUTHENTICATED)))
d582cffb 6385 return -EINVAL;
bdd90d5e
JB
6386 /* Only TDLS peers can be added */
6387 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)))
6388 return -EINVAL;
6389 /* Can only add if TDLS ... */
6390 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS))
6391 return -EOPNOTSUPP;
6392 /* ... with external setup is supported */
6393 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP))
6394 return -EOPNOTSUPP;
77ee7c89
JB
6395 /*
6396 * Older wpa_supplicant versions always mark the TDLS peer
6397 * as authorized, but it shouldn't yet be.
6398 */
6399 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED);
bdd90d5e
JB
6400 break;
6401 default:
6402 return -EOPNOTSUPP;
c75786c9
EP
6403 }
6404
bdd90d5e 6405 /* be aware of params.vlan when changing code here */
5727ef1b 6406
e35e4d28 6407 err = rdev_add_station(rdev, dev, mac_addr, &params);
5727ef1b 6408
5727ef1b
JB
6409 if (params.vlan)
6410 dev_put(params.vlan);
5727ef1b
JB
6411 return err;
6412}
6413
6414static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
6415{
4c476991
JB
6416 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6417 struct net_device *dev = info->user_ptr[1];
89c771e5
JM
6418 struct station_del_parameters params;
6419
6420 memset(&params, 0, sizeof(params));
5727ef1b
JB
6421
6422 if (info->attrs[NL80211_ATTR_MAC])
89c771e5 6423 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]);
5727ef1b 6424
306b79ea
JB
6425 switch (dev->ieee80211_ptr->iftype) {
6426 case NL80211_IFTYPE_AP:
6427 case NL80211_IFTYPE_AP_VLAN:
6428 case NL80211_IFTYPE_MESH_POINT:
6429 case NL80211_IFTYPE_P2P_GO:
6430 /* always accept these */
6431 break;
6432 case NL80211_IFTYPE_ADHOC:
6433 /* conditionally accept */
6434 if (wiphy_ext_feature_isset(&rdev->wiphy,
6435 NL80211_EXT_FEATURE_DEL_IBSS_STA))
6436 break;
edafcf42 6437 return -EINVAL;
306b79ea 6438 default:
4c476991 6439 return -EINVAL;
306b79ea 6440 }
5727ef1b 6441
4c476991
JB
6442 if (!rdev->ops->del_station)
6443 return -EOPNOTSUPP;
3b85875a 6444
98856866
JM
6445 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) {
6446 params.subtype =
6447 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]);
6448 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 &&
6449 params.subtype != IEEE80211_STYPE_DEAUTH >> 4)
6450 return -EINVAL;
6451 } else {
6452 /* Default to Deauthentication frame */
6453 params.subtype = IEEE80211_STYPE_DEAUTH >> 4;
6454 }
6455
6456 if (info->attrs[NL80211_ATTR_REASON_CODE]) {
6457 params.reason_code =
6458 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
6459 if (params.reason_code == 0)
6460 return -EINVAL; /* 0 is reserved */
6461 } else {
6462 /* Default to reason code 2 */
6463 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID;
6464 }
6465
89c771e5 6466 return rdev_del_station(rdev, dev, &params);
5727ef1b
JB
6467}
6468
15e47304 6469static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq,
2ec600d6
LCC
6470 int flags, struct net_device *dev,
6471 u8 *dst, u8 *next_hop,
6472 struct mpath_info *pinfo)
6473{
6474 void *hdr;
6475 struct nlattr *pinfoattr;
6476
1ef4c850 6477 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH);
2ec600d6
LCC
6478 if (!hdr)
6479 return -1;
6480
9360ffd1
DM
6481 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
6482 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) ||
6483 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) ||
6484 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation))
6485 goto nla_put_failure;
f5ea9120 6486
ae0be8de 6487 pinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_MPATH_INFO);
2ec600d6
LCC
6488 if (!pinfoattr)
6489 goto nla_put_failure;
9360ffd1
DM
6490 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) &&
6491 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
6492 pinfo->frame_qlen))
6493 goto nla_put_failure;
6494 if (((pinfo->filled & MPATH_INFO_SN) &&
6495 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) ||
6496 ((pinfo->filled & MPATH_INFO_METRIC) &&
6497 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC,
6498 pinfo->metric)) ||
6499 ((pinfo->filled & MPATH_INFO_EXPTIME) &&
6500 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME,
6501 pinfo->exptime)) ||
6502 ((pinfo->filled & MPATH_INFO_FLAGS) &&
6503 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS,
6504 pinfo->flags)) ||
6505 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) &&
6506 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
6507 pinfo->discovery_timeout)) ||
6508 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) &&
6509 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
cc241636
JH
6510 pinfo->discovery_retries)) ||
6511 ((pinfo->filled & MPATH_INFO_HOP_COUNT) &&
6512 nla_put_u8(msg, NL80211_MPATH_INFO_HOP_COUNT,
540bbcb9
JH
6513 pinfo->hop_count)) ||
6514 ((pinfo->filled & MPATH_INFO_PATH_CHANGE) &&
6515 nla_put_u32(msg, NL80211_MPATH_INFO_PATH_CHANGE,
6516 pinfo->path_change_count)))
9360ffd1 6517 goto nla_put_failure;
2ec600d6
LCC
6518
6519 nla_nest_end(msg, pinfoattr);
6520
053c095a
JB
6521 genlmsg_end(msg, hdr);
6522 return 0;
2ec600d6
LCC
6523
6524 nla_put_failure:
bc3ed28c
TG
6525 genlmsg_cancel(msg, hdr);
6526 return -EMSGSIZE;
2ec600d6
LCC
6527}
6528
6529static int nl80211_dump_mpath(struct sk_buff *skb,
bba95fef 6530 struct netlink_callback *cb)
2ec600d6 6531{
2ec600d6 6532 struct mpath_info pinfo;
1b8ec87a 6533 struct cfg80211_registered_device *rdev;
97990a06 6534 struct wireless_dev *wdev;
2ec600d6
LCC
6535 u8 dst[ETH_ALEN];
6536 u8 next_hop[ETH_ALEN];
97990a06 6537 int path_idx = cb->args[2];
2ec600d6 6538 int err;
2ec600d6 6539
ea90e0dc 6540 rtnl_lock();
5297c65c 6541 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
67748893 6542 if (err)
ea90e0dc 6543 goto out_err;
bba95fef 6544
1b8ec87a 6545 if (!rdev->ops->dump_mpath) {
eec60b03 6546 err = -EOPNOTSUPP;
bba95fef
JB
6547 goto out_err;
6548 }
6549
97990a06 6550 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
eec60b03 6551 err = -EOPNOTSUPP;
0448b5fc 6552 goto out_err;
eec60b03
JM
6553 }
6554
bba95fef 6555 while (1) {
1b8ec87a 6556 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst,
97990a06 6557 next_hop, &pinfo);
bba95fef 6558 if (err == -ENOENT)
2ec600d6 6559 break;
bba95fef 6560 if (err)
3b85875a 6561 goto out_err;
2ec600d6 6562
15e47304 6563 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
bba95fef 6564 cb->nlh->nlmsg_seq, NLM_F_MULTI,
97990a06 6565 wdev->netdev, dst, next_hop,
bba95fef
JB
6566 &pinfo) < 0)
6567 goto out;
2ec600d6 6568
bba95fef 6569 path_idx++;
2ec600d6 6570 }
2ec600d6 6571
bba95fef 6572 out:
97990a06 6573 cb->args[2] = path_idx;
bba95fef 6574 err = skb->len;
bba95fef 6575 out_err:
ea90e0dc 6576 rtnl_unlock();
bba95fef 6577 return err;
2ec600d6
LCC
6578}
6579
6580static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
6581{
4c476991 6582 struct cfg80211_registered_device *rdev = info->user_ptr[0];
2ec600d6 6583 int err;
4c476991 6584 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6585 struct mpath_info pinfo;
6586 struct sk_buff *msg;
6587 u8 *dst = NULL;
6588 u8 next_hop[ETH_ALEN];
6589
6590 memset(&pinfo, 0, sizeof(pinfo));
6591
6592 if (!info->attrs[NL80211_ATTR_MAC])
6593 return -EINVAL;
6594
6595 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6596
4c476991
JB
6597 if (!rdev->ops->get_mpath)
6598 return -EOPNOTSUPP;
2ec600d6 6599
4c476991
JB
6600 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6601 return -EOPNOTSUPP;
eec60b03 6602
e35e4d28 6603 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo);
2ec600d6 6604 if (err)
4c476991 6605 return err;
2ec600d6 6606
fd2120ca 6607 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2ec600d6 6608 if (!msg)
4c476991 6609 return -ENOMEM;
2ec600d6 6610
15e47304 6611 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
4c476991
JB
6612 dev, dst, next_hop, &pinfo) < 0) {
6613 nlmsg_free(msg);
6614 return -ENOBUFS;
6615 }
3b85875a 6616
4c476991 6617 return genlmsg_reply(msg, info);
2ec600d6
LCC
6618}
6619
6620static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
6621{
4c476991
JB
6622 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6623 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6624 u8 *dst = NULL;
6625 u8 *next_hop = NULL;
6626
6627 if (!info->attrs[NL80211_ATTR_MAC])
6628 return -EINVAL;
6629
6630 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
6631 return -EINVAL;
6632
6633 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6634 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
6635
4c476991
JB
6636 if (!rdev->ops->change_mpath)
6637 return -EOPNOTSUPP;
35a8efe1 6638
4c476991
JB
6639 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6640 return -EOPNOTSUPP;
2ec600d6 6641
e35e4d28 6642 return rdev_change_mpath(rdev, dev, dst, next_hop);
2ec600d6 6643}
4c476991 6644
2ec600d6
LCC
6645static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
6646{
4c476991
JB
6647 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6648 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6649 u8 *dst = NULL;
6650 u8 *next_hop = NULL;
6651
6652 if (!info->attrs[NL80211_ATTR_MAC])
6653 return -EINVAL;
6654
6655 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
6656 return -EINVAL;
6657
6658 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6659 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
6660
4c476991
JB
6661 if (!rdev->ops->add_mpath)
6662 return -EOPNOTSUPP;
35a8efe1 6663
4c476991
JB
6664 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6665 return -EOPNOTSUPP;
2ec600d6 6666
e35e4d28 6667 return rdev_add_mpath(rdev, dev, dst, next_hop);
2ec600d6
LCC
6668}
6669
6670static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
6671{
4c476991
JB
6672 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6673 struct net_device *dev = info->user_ptr[1];
2ec600d6
LCC
6674 u8 *dst = NULL;
6675
6676 if (info->attrs[NL80211_ATTR_MAC])
6677 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6678
4c476991
JB
6679 if (!rdev->ops->del_mpath)
6680 return -EOPNOTSUPP;
3b85875a 6681
b501426c
MP
6682 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6683 return -EOPNOTSUPP;
6684
e35e4d28 6685 return rdev_del_mpath(rdev, dev, dst);
2ec600d6
LCC
6686}
6687
66be7d2b
HR
6688static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info)
6689{
6690 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6691 int err;
6692 struct net_device *dev = info->user_ptr[1];
6693 struct mpath_info pinfo;
6694 struct sk_buff *msg;
6695 u8 *dst = NULL;
6696 u8 mpp[ETH_ALEN];
6697
6698 memset(&pinfo, 0, sizeof(pinfo));
6699
6700 if (!info->attrs[NL80211_ATTR_MAC])
6701 return -EINVAL;
6702
6703 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
6704
6705 if (!rdev->ops->get_mpp)
6706 return -EOPNOTSUPP;
6707
6708 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
6709 return -EOPNOTSUPP;
6710
6711 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo);
6712 if (err)
6713 return err;
6714
6715 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
6716 if (!msg)
6717 return -ENOMEM;
6718
6719 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0,
6720 dev, dst, mpp, &pinfo) < 0) {
6721 nlmsg_free(msg);
6722 return -ENOBUFS;
6723 }
6724
6725 return genlmsg_reply(msg, info);
6726}
6727
6728static int nl80211_dump_mpp(struct sk_buff *skb,
6729 struct netlink_callback *cb)
6730{
6731 struct mpath_info pinfo;
6732 struct cfg80211_registered_device *rdev;
6733 struct wireless_dev *wdev;
6734 u8 dst[ETH_ALEN];
6735 u8 mpp[ETH_ALEN];
6736 int path_idx = cb->args[2];
6737 int err;
6738
ea90e0dc 6739 rtnl_lock();
5297c65c 6740 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
66be7d2b 6741 if (err)
ea90e0dc 6742 goto out_err;
66be7d2b
HR
6743
6744 if (!rdev->ops->dump_mpp) {
6745 err = -EOPNOTSUPP;
6746 goto out_err;
6747 }
6748
6749 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) {
6750 err = -EOPNOTSUPP;
6751 goto out_err;
6752 }
6753
6754 while (1) {
6755 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst,
6756 mpp, &pinfo);
6757 if (err == -ENOENT)
6758 break;
6759 if (err)
6760 goto out_err;
6761
6762 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid,
6763 cb->nlh->nlmsg_seq, NLM_F_MULTI,
6764 wdev->netdev, dst, mpp,
6765 &pinfo) < 0)
6766 goto out;
6767
6768 path_idx++;
6769 }
6770
6771 out:
6772 cb->args[2] = path_idx;
6773 err = skb->len;
6774 out_err:
ea90e0dc 6775 rtnl_unlock();
66be7d2b
HR
6776 return err;
6777}
6778
9f1ba906
JM
6779static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
6780{
4c476991
JB
6781 struct cfg80211_registered_device *rdev = info->user_ptr[0];
6782 struct net_device *dev = info->user_ptr[1];
c56589ed 6783 struct wireless_dev *wdev = dev->ieee80211_ptr;
9f1ba906 6784 struct bss_parameters params;
c56589ed 6785 int err;
9f1ba906
JM
6786
6787 memset(&params, 0, sizeof(params));
6788 /* default to not changing parameters */
6789 params.use_cts_prot = -1;
6790 params.use_short_preamble = -1;
6791 params.use_short_slot_time = -1;
fd8aaaf3 6792 params.ap_isolate = -1;
50b12f59 6793 params.ht_opmode = -1;
53cabad7
JB
6794 params.p2p_ctwindow = -1;
6795 params.p2p_opp_ps = -1;
9f1ba906
JM
6796
6797 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
6798 params.use_cts_prot =
6799 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
6800 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
6801 params.use_short_preamble =
6802 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
6803 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
6804 params.use_short_slot_time =
6805 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
90c97a04
JM
6806 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
6807 params.basic_rates =
6808 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6809 params.basic_rates_len =
6810 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
6811 }
fd8aaaf3
FF
6812 if (info->attrs[NL80211_ATTR_AP_ISOLATE])
6813 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
50b12f59
HS
6814 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
6815 params.ht_opmode =
6816 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
9f1ba906 6817
53cabad7
JB
6818 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) {
6819 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6820 return -EINVAL;
6821 params.p2p_ctwindow =
ab0d76f6 6822 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]);
53cabad7
JB
6823 if (params.p2p_ctwindow != 0 &&
6824 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN))
6825 return -EINVAL;
6826 }
6827
6828 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) {
6829 u8 tmp;
6830
6831 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6832 return -EINVAL;
6833 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]);
53cabad7
JB
6834 params.p2p_opp_ps = tmp;
6835 if (params.p2p_opp_ps &&
6836 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS))
6837 return -EINVAL;
6838 }
6839
4c476991
JB
6840 if (!rdev->ops->change_bss)
6841 return -EOPNOTSUPP;
9f1ba906 6842
074ac8df 6843 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4c476991
JB
6844 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
6845 return -EOPNOTSUPP;
3b85875a 6846
c56589ed
SW
6847 wdev_lock(wdev);
6848 err = rdev_change_bss(rdev, dev, &params);
6849 wdev_unlock(wdev);
6850
6851 return err;
9f1ba906
JM
6852}
6853
b2e1b302
LR
6854static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
6855{
b2e1b302 6856 char *data = NULL;
05050753 6857 bool is_indoor;
57b5ce07 6858 enum nl80211_user_reg_hint_type user_reg_hint_type;
05050753
I
6859 u32 owner_nlportid;
6860
80778f18
LR
6861 /*
6862 * You should only get this when cfg80211 hasn't yet initialized
6863 * completely when built-in to the kernel right between the time
6864 * window between nl80211_init() and regulatory_init(), if that is
6865 * even possible.
6866 */
458f4f9e 6867 if (unlikely(!rcu_access_pointer(cfg80211_regdomain)))
fe33eb39 6868 return -EINPROGRESS;
80778f18 6869
57b5ce07
LR
6870 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE])
6871 user_reg_hint_type =
6872 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]);
6873 else
6874 user_reg_hint_type = NL80211_USER_REG_HINT_USER;
6875
6876 switch (user_reg_hint_type) {
6877 case NL80211_USER_REG_HINT_USER:
6878 case NL80211_USER_REG_HINT_CELL_BASE:
52616f2b
IP
6879 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
6880 return -EINVAL;
6881
6882 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
6883 return regulatory_hint_user(data, user_reg_hint_type);
6884 case NL80211_USER_REG_HINT_INDOOR:
05050753
I
6885 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
6886 owner_nlportid = info->snd_portid;
6887 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR];
6888 } else {
6889 owner_nlportid = 0;
6890 is_indoor = true;
6891 }
6892
6893 return regulatory_hint_indoor(is_indoor, owner_nlportid);
57b5ce07
LR
6894 default:
6895 return -EINVAL;
6896 }
b2e1b302
LR
6897}
6898
1ea4ff3e
JB
6899static int nl80211_reload_regdb(struct sk_buff *skb, struct genl_info *info)
6900{
6901 return reg_reload_regdb();
6902}
6903
24bdd9f4 6904static int nl80211_get_mesh_config(struct sk_buff *skb,
29cbe68c 6905 struct genl_info *info)
93da9cc1 6906{
4c476991 6907 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 6908 struct net_device *dev = info->user_ptr[1];
29cbe68c
JB
6909 struct wireless_dev *wdev = dev->ieee80211_ptr;
6910 struct mesh_config cur_params;
6911 int err = 0;
93da9cc1 6912 void *hdr;
6913 struct nlattr *pinfoattr;
6914 struct sk_buff *msg;
6915
29cbe68c
JB
6916 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
6917 return -EOPNOTSUPP;
6918
24bdd9f4 6919 if (!rdev->ops->get_mesh_config)
4c476991 6920 return -EOPNOTSUPP;
f3f92586 6921
29cbe68c
JB
6922 wdev_lock(wdev);
6923 /* If not connected, get default parameters */
6924 if (!wdev->mesh_id_len)
6925 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
6926 else
e35e4d28 6927 err = rdev_get_mesh_config(rdev, dev, &cur_params);
29cbe68c
JB
6928 wdev_unlock(wdev);
6929
93da9cc1 6930 if (err)
4c476991 6931 return err;
93da9cc1 6932
6933 /* Draw up a netlink message to send back */
fd2120ca 6934 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
6935 if (!msg)
6936 return -ENOMEM;
15e47304 6937 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
24bdd9f4 6938 NL80211_CMD_GET_MESH_CONFIG);
93da9cc1 6939 if (!hdr)
efe1cf0c 6940 goto out;
ae0be8de 6941 pinfoattr = nla_nest_start_noflag(msg, NL80211_ATTR_MESH_CONFIG);
93da9cc1 6942 if (!pinfoattr)
6943 goto nla_put_failure;
9360ffd1
DM
6944 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
6945 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
6946 cur_params.dot11MeshRetryTimeout) ||
6947 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
6948 cur_params.dot11MeshConfirmTimeout) ||
6949 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
6950 cur_params.dot11MeshHoldingTimeout) ||
6951 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
6952 cur_params.dot11MeshMaxPeerLinks) ||
6953 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES,
6954 cur_params.dot11MeshMaxRetries) ||
6955 nla_put_u8(msg, NL80211_MESHCONF_TTL,
6956 cur_params.dot11MeshTTL) ||
6957 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL,
6958 cur_params.element_ttl) ||
6959 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
6960 cur_params.auto_open_plinks) ||
7eab0f64
JL
6961 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
6962 cur_params.dot11MeshNbrOffsetMaxNeighbor) ||
9360ffd1
DM
6963 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
6964 cur_params.dot11MeshHWMPmaxPREQretries) ||
6965 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
6966 cur_params.path_refresh_time) ||
6967 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
6968 cur_params.min_discovery_timeout) ||
6969 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
6970 cur_params.dot11MeshHWMPactivePathTimeout) ||
6971 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
6972 cur_params.dot11MeshHWMPpreqMinInterval) ||
6973 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
6974 cur_params.dot11MeshHWMPperrMinInterval) ||
6975 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
6976 cur_params.dot11MeshHWMPnetDiameterTraversalTime) ||
6977 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
6978 cur_params.dot11MeshHWMPRootMode) ||
6979 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL,
6980 cur_params.dot11MeshHWMPRannInterval) ||
6981 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
6982 cur_params.dot11MeshGateAnnouncementProtocol) ||
6983 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING,
6984 cur_params.dot11MeshForwarding) ||
335d5349 6985 nla_put_s32(msg, NL80211_MESHCONF_RSSI_THRESHOLD,
70c33eaa
AN
6986 cur_params.rssi_threshold) ||
6987 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE,
ac1073a6
CYY
6988 cur_params.ht_opmode) ||
6989 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
6990 cur_params.dot11MeshHWMPactivePathToRootTimeout) ||
6991 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
728b19e5
CYY
6992 cur_params.dot11MeshHWMProotInterval) ||
6993 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
3b1c5a53
MP
6994 cur_params.dot11MeshHWMPconfirmationInterval) ||
6995 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE,
6996 cur_params.power_mode) ||
6997 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW,
8e7c0538
CT
6998 cur_params.dot11MeshAwakeWindowDuration) ||
6999 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT,
01d66fbd
BC
7000 cur_params.plink_timeout) ||
7001 nla_put_u8(msg, NL80211_MESHCONF_CONNECTED_TO_GATE,
e3718a61
LL
7002 cur_params.dot11MeshConnectedToMeshGate) ||
7003 nla_put_u8(msg, NL80211_MESHCONF_NOLEARN,
184eebe6
MT
7004 cur_params.dot11MeshNolearn) ||
7005 nla_put_u8(msg, NL80211_MESHCONF_CONNECTED_TO_AS,
7006 cur_params.dot11MeshConnectedToAuthServer))
9360ffd1 7007 goto nla_put_failure;
93da9cc1 7008 nla_nest_end(msg, pinfoattr);
7009 genlmsg_end(msg, hdr);
4c476991 7010 return genlmsg_reply(msg, info);
93da9cc1 7011
3b85875a 7012 nla_put_failure:
efe1cf0c 7013 out:
d080e275 7014 nlmsg_free(msg);
4c476991 7015 return -ENOBUFS;
93da9cc1 7016}
7017
ab0d76f6
JB
7018static const struct nla_policy
7019nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
7020 [NL80211_MESHCONF_RETRY_TIMEOUT] =
7021 NLA_POLICY_RANGE(NLA_U16, 1, 255),
7022 [NL80211_MESHCONF_CONFIRM_TIMEOUT] =
7023 NLA_POLICY_RANGE(NLA_U16, 1, 255),
7024 [NL80211_MESHCONF_HOLDING_TIMEOUT] =
7025 NLA_POLICY_RANGE(NLA_U16, 1, 255),
7026 [NL80211_MESHCONF_MAX_PEER_LINKS] =
7027 NLA_POLICY_RANGE(NLA_U16, 0, 255),
7028 [NL80211_MESHCONF_MAX_RETRIES] = NLA_POLICY_MAX(NLA_U8, 16),
7029 [NL80211_MESHCONF_TTL] = NLA_POLICY_MIN(NLA_U8, 1),
7030 [NL80211_MESHCONF_ELEMENT_TTL] = NLA_POLICY_MIN(NLA_U8, 1),
7031 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = NLA_POLICY_MAX(NLA_U8, 1),
7032 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] =
7033 NLA_POLICY_RANGE(NLA_U32, 1, 255),
93da9cc1 7034 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
7035 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
ab0d76f6 7036 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = NLA_POLICY_MIN(NLA_U16, 1),
93da9cc1 7037 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
ab0d76f6
JB
7038 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] =
7039 NLA_POLICY_MIN(NLA_U16, 1),
7040 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] =
7041 NLA_POLICY_MIN(NLA_U16, 1),
7042 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] =
7043 NLA_POLICY_MIN(NLA_U16, 1),
7044 [NL80211_MESHCONF_HWMP_ROOTMODE] = NLA_POLICY_MAX(NLA_U8, 4),
7045 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] =
7046 NLA_POLICY_MIN(NLA_U16, 1),
7047 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = NLA_POLICY_MAX(NLA_U8, 1),
7048 [NL80211_MESHCONF_FORWARDING] = NLA_POLICY_MAX(NLA_U8, 1),
7049 [NL80211_MESHCONF_RSSI_THRESHOLD] =
7050 NLA_POLICY_RANGE(NLA_S32, -255, 0),
a4f606ea 7051 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 },
ac1073a6 7052 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 },
ab0d76f6
JB
7053 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] =
7054 NLA_POLICY_MIN(NLA_U16, 1),
7055 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] =
7056 NLA_POLICY_MIN(NLA_U16, 1),
7057 [NL80211_MESHCONF_POWER_MODE] =
7058 NLA_POLICY_RANGE(NLA_U32,
7059 NL80211_MESH_POWER_ACTIVE,
7060 NL80211_MESH_POWER_MAX),
3b1c5a53 7061 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 },
8e7c0538 7062 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 },
01d66fbd 7063 [NL80211_MESHCONF_CONNECTED_TO_GATE] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
e3718a61 7064 [NL80211_MESHCONF_NOLEARN] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
184eebe6 7065 [NL80211_MESHCONF_CONNECTED_TO_AS] = NLA_POLICY_RANGE(NLA_U8, 0, 1),
93da9cc1 7066};
7067
c80d545d
JC
7068static const struct nla_policy
7069 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = {
d299a1f2 7070 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 },
c80d545d
JC
7071 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 },
7072 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 },
15d5dda6 7073 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG },
6e16d90b 7074 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 },
bb2798d4 7075 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG },
3d7af878
JB
7076 [NL80211_MESH_SETUP_IE] =
7077 NLA_POLICY_VALIDATE_FN(NLA_BINARY, validate_ie_attr,
7078 IEEE80211_MAX_DATA_LEN),
b130e5ce 7079 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG },
c80d545d
JC
7080};
7081
24bdd9f4 7082static int nl80211_parse_mesh_config(struct genl_info *info,
bd90fdcc
JB
7083 struct mesh_config *cfg,
7084 u32 *mask_out)
93da9cc1 7085{
93da9cc1 7086 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
bd90fdcc 7087 u32 mask = 0;
9757235f 7088 u16 ht_opmode;
93da9cc1 7089
ab0d76f6
JB
7090#define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, mask, attr, fn) \
7091do { \
7092 if (tb[attr]) { \
7093 cfg->param = fn(tb[attr]); \
7094 mask |= BIT((attr) - 1); \
7095 } \
ea54fba2 7096} while (0)
bd90fdcc 7097
24bdd9f4 7098 if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
93da9cc1 7099 return -EINVAL;
8cb08174 7100 if (nla_parse_nested_deprecated(tb, NL80211_MESHCONF_ATTR_MAX, info->attrs[NL80211_ATTR_MESH_CONFIG], nl80211_meshconf_params_policy, info->extack))
93da9cc1 7101 return -EINVAL;
7102
93da9cc1 7103 /* This makes sure that there aren't more than 32 mesh config
7104 * parameters (otherwise our bitfield scheme would not work.) */
7105 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
7106
7107 /* Fill in the params struct */
ab0d76f6
JB
7108 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, mask,
7109 NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
7110 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, mask,
7111 NL80211_MESHCONF_CONFIRM_TIMEOUT,
7112 nla_get_u16);
7113 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, mask,
7114 NL80211_MESHCONF_HOLDING_TIMEOUT,
7115 nla_get_u16);
7116 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, mask,
7117 NL80211_MESHCONF_MAX_PEER_LINKS,
7118 nla_get_u16);
7119 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, mask,
7120 NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
7121 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, mask,
7122 NL80211_MESHCONF_TTL, nla_get_u8);
7123 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, mask,
7124 NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
7125 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, mask,
7126 NL80211_MESHCONF_AUTO_OPEN_PLINKS,
7127 nla_get_u8);
ea54fba2 7128 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor,
ab0d76f6 7129 mask,
a4f606ea 7130 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR,
ab0d76f6
JB
7131 nla_get_u32);
7132 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, mask,
7133 NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
7134 nla_get_u8);
7135 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, mask,
7136 NL80211_MESHCONF_PATH_REFRESH_TIME,
7137 nla_get_u32);
7138 if (mask & BIT(NL80211_MESHCONF_PATH_REFRESH_TIME) &&
7139 (cfg->path_refresh_time < 1 || cfg->path_refresh_time > 65535))
7140 return -EINVAL;
7141 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, mask,
7142 NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
7143 nla_get_u16);
ea54fba2 7144 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
ab0d76f6 7145 mask,
a4f606ea 7146 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
ab0d76f6
JB
7147 nla_get_u32);
7148 if (mask & BIT(NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT) &&
7149 (cfg->dot11MeshHWMPactivePathTimeout < 1 ||
7150 cfg->dot11MeshHWMPactivePathTimeout > 65535))
7151 return -EINVAL;
7152 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval, mask,
ea54fba2 7153 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
ab0d76f6
JB
7154 nla_get_u16);
7155 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval, mask,
ea54fba2 7156 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL,
ab0d76f6 7157 nla_get_u16);
93da9cc1 7158 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ab0d76f6 7159 dot11MeshHWMPnetDiameterTraversalTime, mask,
a4f606ea 7160 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
ab0d76f6
JB
7161 nla_get_u16);
7162 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, mask,
7163 NL80211_MESHCONF_HWMP_ROOTMODE, nla_get_u8);
7164 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, mask,
7165 NL80211_MESHCONF_HWMP_RANN_INTERVAL,
7166 nla_get_u16);
7167 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshGateAnnouncementProtocol,
ea54fba2 7168 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS,
ab0d76f6
JB
7169 nla_get_u8);
7170 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, mask,
7171 NL80211_MESHCONF_FORWARDING, nla_get_u8);
7172 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, mask,
7173 NL80211_MESHCONF_RSSI_THRESHOLD,
7174 nla_get_s32);
01d66fbd
BC
7175 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConnectedToMeshGate, mask,
7176 NL80211_MESHCONF_CONNECTED_TO_GATE,
7177 nla_get_u8);
184eebe6
MT
7178 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConnectedToAuthServer, mask,
7179 NL80211_MESHCONF_CONNECTED_TO_AS,
7180 nla_get_u8);
9757235f
MH
7181 /*
7182 * Check HT operation mode based on
188f60ab 7183 * IEEE 802.11-2016 9.4.2.57 HT Operation element.
9757235f
MH
7184 */
7185 if (tb[NL80211_MESHCONF_HT_OPMODE]) {
7186 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]);
7187
7188 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION |
7189 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT |
7190 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT))
7191 return -EINVAL;
7192
188f60ab
BC
7193 /* NON_HT_STA bit is reserved, but some programs set it */
7194 ht_opmode &= ~IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT;
9757235f 7195
9757235f 7196 cfg->ht_opmode = ht_opmode;
fd551bac 7197 mask |= (1 << (NL80211_MESHCONF_HT_OPMODE - 1));
9757235f 7198 }
728b19e5 7199 FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
ab0d76f6
JB
7200 dot11MeshHWMPactivePathToRootTimeout, mask,
7201 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT,
7202 nla_get_u32);
7203 if (mask & BIT(NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT) &&
7204 (cfg->dot11MeshHWMPactivePathToRootTimeout < 1 ||
7205 cfg->dot11MeshHWMPactivePathToRootTimeout > 65535))
7206 return -EINVAL;
7207 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, mask,
7208 NL80211_MESHCONF_HWMP_ROOT_INTERVAL,
7209 nla_get_u16);
7210 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPconfirmationInterval,
7211 mask,
728b19e5 7212 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL,
ab0d76f6
JB
7213 nla_get_u16);
7214 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode, mask,
7215 NL80211_MESHCONF_POWER_MODE, nla_get_u32);
7216 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration, mask,
7217 NL80211_MESHCONF_AWAKE_WINDOW, nla_get_u16);
7218 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, mask,
7219 NL80211_MESHCONF_PLINK_TIMEOUT, nla_get_u32);
e3718a61
LL
7220 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNolearn, mask,
7221 NL80211_MESHCONF_NOLEARN, nla_get_u8);
bd90fdcc
JB
7222 if (mask_out)
7223 *mask_out = mask;
c80d545d 7224
bd90fdcc
JB
7225 return 0;
7226
7227#undef FILL_IN_MESH_PARAM_IF_SET
7228}
7229
c80d545d
JC
7230static int nl80211_parse_mesh_setup(struct genl_info *info,
7231 struct mesh_setup *setup)
7232{
bb2798d4 7233 struct cfg80211_registered_device *rdev = info->user_ptr[0];
c80d545d
JC
7234 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1];
7235
7236 if (!info->attrs[NL80211_ATTR_MESH_SETUP])
7237 return -EINVAL;
8cb08174 7238 if (nla_parse_nested_deprecated(tb, NL80211_MESH_SETUP_ATTR_MAX, info->attrs[NL80211_ATTR_MESH_SETUP], nl80211_mesh_setup_params_policy, info->extack))
c80d545d
JC
7239 return -EINVAL;
7240
d299a1f2
JC
7241 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])
7242 setup->sync_method =
7243 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ?
7244 IEEE80211_SYNC_METHOD_VENDOR :
7245 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET;
7246
c80d545d
JC
7247 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])
7248 setup->path_sel_proto =
7249 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ?
7250 IEEE80211_PATH_PROTOCOL_VENDOR :
7251 IEEE80211_PATH_PROTOCOL_HWMP;
7252
7253 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])
7254 setup->path_metric =
7255 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ?
7256 IEEE80211_PATH_METRIC_VENDOR :
7257 IEEE80211_PATH_METRIC_AIRTIME;
7258
581a8b0f 7259 if (tb[NL80211_MESH_SETUP_IE]) {
c80d545d 7260 struct nlattr *ieattr =
581a8b0f 7261 tb[NL80211_MESH_SETUP_IE];
581a8b0f
JC
7262 setup->ie = nla_data(ieattr);
7263 setup->ie_len = nla_len(ieattr);
c80d545d 7264 }
bb2798d4
TP
7265 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] &&
7266 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM))
7267 return -EINVAL;
7268 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]);
b130e5ce
JC
7269 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]);
7270 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]);
bb2798d4
TP
7271 if (setup->is_secure)
7272 setup->user_mpm = true;
c80d545d 7273
6e16d90b
CT
7274 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) {
7275 if (!setup->user_mpm)
7276 return -EINVAL;
7277 setup->auth_id =
7278 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]);
7279 }
7280
c80d545d
JC
7281 return 0;
7282}
7283
24bdd9f4 7284static int nl80211_update_mesh_config(struct sk_buff *skb,
29cbe68c 7285 struct genl_info *info)
bd90fdcc
JB
7286{
7287 struct cfg80211_registered_device *rdev = info->user_ptr[0];
7288 struct net_device *dev = info->user_ptr[1];
29cbe68c 7289 struct wireless_dev *wdev = dev->ieee80211_ptr;
bd90fdcc
JB
7290 struct mesh_config cfg;
7291 u32 mask;
7292 int err;
7293
29cbe68c
JB
7294 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
7295 return -EOPNOTSUPP;
7296
24bdd9f4 7297 if (!rdev->ops->update_mesh_config)
bd90fdcc
JB
7298 return -EOPNOTSUPP;
7299
24bdd9f4 7300 err = nl80211_parse_mesh_config(info, &cfg, &mask);
bd90fdcc
JB
7301 if (err)
7302 return err;
7303
29cbe68c
JB
7304 wdev_lock(wdev);
7305 if (!wdev->mesh_id_len)
7306 err = -ENOLINK;
7307
7308 if (!err)
e35e4d28 7309 err = rdev_update_mesh_config(rdev, dev, mask, &cfg);
29cbe68c
JB
7310
7311 wdev_unlock(wdev);
7312
7313 return err;
93da9cc1 7314}
7315
ad30ca2c
AN
7316static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom,
7317 struct sk_buff *msg)
f130347c 7318{
f130347c
LR
7319 struct nlattr *nl_reg_rules;
7320 unsigned int i;
f130347c 7321
458f4f9e
JB
7322 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) ||
7323 (regdom->dfs_region &&
7324 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region)))
ad30ca2c 7325 goto nla_put_failure;
458f4f9e 7326
ae0be8de 7327 nl_reg_rules = nla_nest_start_noflag(msg, NL80211_ATTR_REG_RULES);
f130347c 7328 if (!nl_reg_rules)
ad30ca2c 7329 goto nla_put_failure;
f130347c 7330
458f4f9e 7331 for (i = 0; i < regdom->n_reg_rules; i++) {
f130347c
LR
7332 struct nlattr *nl_reg_rule;
7333 const struct ieee80211_reg_rule *reg_rule;
7334 const struct ieee80211_freq_range *freq_range;
7335 const struct ieee80211_power_rule *power_rule;
97524820 7336 unsigned int max_bandwidth_khz;
f130347c 7337
458f4f9e 7338 reg_rule = &regdom->reg_rules[i];
f130347c
LR
7339 freq_range = &reg_rule->freq_range;
7340 power_rule = &reg_rule->power_rule;
7341
ae0be8de 7342 nl_reg_rule = nla_nest_start_noflag(msg, i);
f130347c 7343 if (!nl_reg_rule)
ad30ca2c 7344 goto nla_put_failure;
f130347c 7345
97524820
JD
7346 max_bandwidth_khz = freq_range->max_bandwidth_khz;
7347 if (!max_bandwidth_khz)
7348 max_bandwidth_khz = reg_get_max_bandwidth(regdom,
7349 reg_rule);
7350
9360ffd1
DM
7351 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS,
7352 reg_rule->flags) ||
7353 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START,
7354 freq_range->start_freq_khz) ||
7355 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END,
7356 freq_range->end_freq_khz) ||
7357 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
97524820 7358 max_bandwidth_khz) ||
9360ffd1
DM
7359 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
7360 power_rule->max_antenna_gain) ||
7361 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
089027e5
JD
7362 power_rule->max_eirp) ||
7363 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME,
7364 reg_rule->dfs_cac_ms))
ad30ca2c 7365 goto nla_put_failure;
f130347c
LR
7366
7367 nla_nest_end(msg, nl_reg_rule);
7368 }
7369
7370 nla_nest_end(msg, nl_reg_rules);
ad30ca2c
AN
7371 return 0;
7372
7373nla_put_failure:
7374 return -EMSGSIZE;
7375}
7376
7377static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info)
7378{
7379 const struct ieee80211_regdomain *regdom = NULL;
7380 struct cfg80211_registered_device *rdev;
7381 struct wiphy *wiphy = NULL;
7382 struct sk_buff *msg;
7383 void *hdr;
7384
7385 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
7386 if (!msg)
7387 return -ENOBUFS;
7388
7389 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7390 NL80211_CMD_GET_REG);
7391 if (!hdr)
7392 goto put_failure;
7393
7394 if (info->attrs[NL80211_ATTR_WIPHY]) {
1bdd716c
AN
7395 bool self_managed;
7396
ad30ca2c
AN
7397 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
7398 if (IS_ERR(rdev)) {
7399 nlmsg_free(msg);
7400 return PTR_ERR(rdev);
7401 }
7402
7403 wiphy = &rdev->wiphy;
1bdd716c
AN
7404 self_managed = wiphy->regulatory_flags &
7405 REGULATORY_WIPHY_SELF_MANAGED;
ad30ca2c
AN
7406 regdom = get_wiphy_regdom(wiphy);
7407
1bdd716c
AN
7408 /* a self-managed-reg device must have a private regdom */
7409 if (WARN_ON(!regdom && self_managed)) {
7410 nlmsg_free(msg);
7411 return -EINVAL;
7412 }
7413
ad30ca2c
AN
7414 if (regdom &&
7415 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
7416 goto nla_put_failure;
7417 }
7418
7419 if (!wiphy && reg_last_request_cell_base() &&
7420 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
7421 NL80211_USER_REG_HINT_CELL_BASE))
7422 goto nla_put_failure;
7423
7424 rcu_read_lock();
7425
7426 if (!regdom)
7427 regdom = rcu_dereference(cfg80211_regdomain);
7428
7429 if (nl80211_put_regdom(regdom, msg))
7430 goto nla_put_failure_rcu;
7431
7432 rcu_read_unlock();
f130347c
LR
7433
7434 genlmsg_end(msg, hdr);
5fe231e8 7435 return genlmsg_reply(msg, info);
f130347c 7436
458f4f9e
JB
7437nla_put_failure_rcu:
7438 rcu_read_unlock();
f130347c 7439nla_put_failure:
efe1cf0c 7440put_failure:
d080e275 7441 nlmsg_free(msg);
5fe231e8 7442 return -EMSGSIZE;
f130347c
LR
7443}
7444
ad30ca2c
AN
7445static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb,
7446 u32 seq, int flags, struct wiphy *wiphy,
7447 const struct ieee80211_regdomain *regdom)
7448{
7449 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
7450 NL80211_CMD_GET_REG);
7451
7452 if (!hdr)
7453 return -1;
7454
0a833c29 7455 genl_dump_check_consistent(cb, hdr);
ad30ca2c
AN
7456
7457 if (nl80211_put_regdom(regdom, msg))
7458 goto nla_put_failure;
7459
7460 if (!wiphy && reg_last_request_cell_base() &&
7461 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE,
7462 NL80211_USER_REG_HINT_CELL_BASE))
7463 goto nla_put_failure;
7464
7465 if (wiphy &&
7466 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
7467 goto nla_put_failure;
7468
1bdd716c
AN
7469 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
7470 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
7471 goto nla_put_failure;
7472
053c095a
JB
7473 genlmsg_end(msg, hdr);
7474 return 0;
ad30ca2c
AN
7475
7476nla_put_failure:
7477 genlmsg_cancel(msg, hdr);
7478 return -EMSGSIZE;
7479}
7480
7481static int nl80211_get_reg_dump(struct sk_buff *skb,
7482 struct netlink_callback *cb)
7483{
7484 const struct ieee80211_regdomain *regdom = NULL;
7485 struct cfg80211_registered_device *rdev;
7486 int err, reg_idx, start = cb->args[2];
7487
7488 rtnl_lock();
7489
7490 if (cfg80211_regdomain && start == 0) {
7491 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
7492 NLM_F_MULTI, NULL,
7493 rtnl_dereference(cfg80211_regdomain));
7494 if (err < 0)
7495 goto out_err;
7496 }
7497
7498 /* the global regdom is idx 0 */
7499 reg_idx = 1;
7500 list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
7501 regdom = get_wiphy_regdom(&rdev->wiphy);
7502 if (!regdom)
7503 continue;
7504
7505 if (++reg_idx <= start)
7506 continue;
7507
7508 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq,
7509 NLM_F_MULTI, &rdev->wiphy, regdom);
7510 if (err < 0) {
7511 reg_idx--;
7512 break;
7513 }
7514 }
7515
7516 cb->args[2] = reg_idx;
7517 err = skb->len;
7518out_err:
7519 rtnl_unlock();
7520 return err;
7521}
7522
b6863036
JB
7523#ifdef CONFIG_CFG80211_CRDA_SUPPORT
7524static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
7525 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 },
7526 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 },
7527 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 },
7528 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 },
7529 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 },
7530 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 },
7531 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 },
7532};
7533
7534static int parse_reg_rule(struct nlattr *tb[],
7535 struct ieee80211_reg_rule *reg_rule)
7536{
7537 struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
7538 struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
7539
7540 if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
7541 return -EINVAL;
7542 if (!tb[NL80211_ATTR_FREQ_RANGE_START])
7543 return -EINVAL;
7544 if (!tb[NL80211_ATTR_FREQ_RANGE_END])
7545 return -EINVAL;
7546 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
7547 return -EINVAL;
7548 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
7549 return -EINVAL;
7550
7551 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
7552
7553 freq_range->start_freq_khz =
7554 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
7555 freq_range->end_freq_khz =
7556 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
7557 freq_range->max_bandwidth_khz =
7558 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
7559
7560 power_rule->max_eirp =
7561 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
7562
7563 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
7564 power_rule->max_antenna_gain =
7565 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
7566
7567 if (tb[NL80211_ATTR_DFS_CAC_TIME])
7568 reg_rule->dfs_cac_ms =
7569 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]);
7570
7571 return 0;
7572}
7573
b2e1b302
LR
7574static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
7575{
7576 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
7577 struct nlattr *nl_reg_rule;
ea372c54
JB
7578 char *alpha2;
7579 int rem_reg_rules, r;
391d132c 7580 u32 num_rules = 0, rule_idx = 0;
4c7d3982 7581 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET;
ea372c54 7582 struct ieee80211_regdomain *rd;
b2e1b302
LR
7583
7584 if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
7585 return -EINVAL;
7586
7587 if (!info->attrs[NL80211_ATTR_REG_RULES])
7588 return -EINVAL;
7589
7590 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
7591
8b60b078
LR
7592 if (info->attrs[NL80211_ATTR_DFS_REGION])
7593 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]);
7594
b2e1b302 7595 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 7596 rem_reg_rules) {
b2e1b302
LR
7597 num_rules++;
7598 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
4776c6e7 7599 return -EINVAL;
b2e1b302
LR
7600 }
7601
e438768f
LR
7602 if (!reg_is_valid_request(alpha2))
7603 return -EINVAL;
7604
391d132c 7605 rd = kzalloc(struct_size(rd, reg_rules, num_rules), GFP_KERNEL);
6913b49a
JB
7606 if (!rd)
7607 return -ENOMEM;
b2e1b302
LR
7608
7609 rd->n_reg_rules = num_rules;
7610 rd->alpha2[0] = alpha2[0];
7611 rd->alpha2[1] = alpha2[1];
7612
8b60b078
LR
7613 /*
7614 * Disable DFS master mode if the DFS region was
7615 * not supported or known on this kernel.
7616 */
7617 if (reg_supported_dfs_region(dfs_region))
7618 rd->dfs_region = dfs_region;
7619
b2e1b302 7620 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
1a919318 7621 rem_reg_rules) {
8cb08174
JB
7622 r = nla_parse_nested_deprecated(tb, NL80211_REG_RULE_ATTR_MAX,
7623 nl_reg_rule, reg_rule_policy,
7624 info->extack);
ae811e21
JB
7625 if (r)
7626 goto bad_reg;
b2e1b302
LR
7627 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
7628 if (r)
7629 goto bad_reg;
7630
7631 rule_idx++;
7632
d0e18f83
LR
7633 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
7634 r = -EINVAL;
b2e1b302 7635 goto bad_reg;
d0e18f83 7636 }
b2e1b302
LR
7637 }
7638
06627990
JB
7639 /* set_regdom takes ownership of rd */
7640 return set_regdom(rd, REGD_SOURCE_CRDA);
d2372b31 7641 bad_reg:
b2e1b302 7642 kfree(rd);
d0e18f83 7643 return r;
b2e1b302 7644}
b6863036 7645#endif /* CONFIG_CFG80211_CRDA_SUPPORT */
b2e1b302 7646
83f5e2cf
JB
7647static int validate_scan_freqs(struct nlattr *freqs)
7648{
7649 struct nlattr *attr1, *attr2;
7650 int n_channels = 0, tmp1, tmp2;
7651
d7f13f74
SD
7652 nla_for_each_nested(attr1, freqs, tmp1)
7653 if (nla_len(attr1) != sizeof(u32))
7654 return 0;
7655
83f5e2cf
JB
7656 nla_for_each_nested(attr1, freqs, tmp1) {
7657 n_channels++;
7658 /*
7659 * Some hardware has a limited channel list for
7660 * scanning, and it is pretty much nonsensical
7661 * to scan for a channel twice, so disallow that
7662 * and don't require drivers to check that the
7663 * channel list they get isn't longer than what
7664 * they can scan, as long as they can scan all
7665 * the channels they registered at once.
7666 */
7667 nla_for_each_nested(attr2, freqs, tmp2)
7668 if (attr1 != attr2 &&
7669 nla_get_u32(attr1) == nla_get_u32(attr2))
7670 return 0;
7671 }
7672
7673 return n_channels;
7674}
7675
57fbcce3 7676static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b)
38de03d2 7677{
57fbcce3 7678 return b < NUM_NL80211_BANDS && wiphy->bands[b];
38de03d2
AS
7679}
7680
7681static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy,
7682 struct cfg80211_bss_selection *bss_select)
7683{
7684 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1];
7685 struct nlattr *nest;
7686 int err;
7687 bool found = false;
7688 int i;
7689
7690 /* only process one nested attribute */
7691 nest = nla_data(nla);
7692 if (!nla_ok(nest, nla_len(nest)))
7693 return -EINVAL;
7694
8cb08174
JB
7695 err = nla_parse_nested_deprecated(attr, NL80211_BSS_SELECT_ATTR_MAX,
7696 nest, nl80211_bss_select_policy,
7697 NULL);
38de03d2
AS
7698 if (err)
7699 return err;
7700
7701 /* only one attribute may be given */
7702 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) {
7703 if (attr[i]) {
7704 if (found)
7705 return -EINVAL;
7706 found = true;
7707 }
7708 }
7709
7710 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID;
7711
7712 if (attr[NL80211_BSS_SELECT_ATTR_RSSI])
7713 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI;
7714
7715 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) {
7716 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF;
7717 bss_select->param.band_pref =
7718 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]);
7719 if (!is_band_valid(wiphy, bss_select->param.band_pref))
7720 return -EINVAL;
7721 }
7722
7723 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) {
7724 struct nl80211_bss_select_rssi_adjust *adj_param;
7725
7726 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]);
7727 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST;
7728 bss_select->param.adjust.band = adj_param->band;
7729 bss_select->param.adjust.delta = adj_param->delta;
7730 if (!is_band_valid(wiphy, bss_select->param.adjust.band))
7731 return -EINVAL;
7732 }
7733
7734 /* user-space did not provide behaviour attribute */
7735 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID)
7736 return -EINVAL;
7737
7738 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour)))
7739 return -EINVAL;
7740
7741 return 0;
7742}
7743
9bb7e0f2
JB
7744int nl80211_parse_random_mac(struct nlattr **attrs,
7745 u8 *mac_addr, u8 *mac_addr_mask)
ad2b26ab
JB
7746{
7747 int i;
7748
7749 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) {
d2beae10
JP
7750 eth_zero_addr(mac_addr);
7751 eth_zero_addr(mac_addr_mask);
ad2b26ab
JB
7752 mac_addr[0] = 0x2;
7753 mac_addr_mask[0] = 0x3;
7754
7755 return 0;
7756 }
7757
7758 /* need both or none */
7759 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK])
7760 return -EINVAL;
7761
7762 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN);
7763 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN);
7764
7765 /* don't allow or configure an mcast address */
7766 if (!is_multicast_ether_addr(mac_addr_mask) ||
7767 is_multicast_ether_addr(mac_addr))
7768 return -EINVAL;
7769
7770 /*
7771 * allow users to pass a MAC address that has bits set outside
7772 * of the mask, but don't bother drivers with having to deal
7773 * with such bits
7774 */
7775 for (i = 0; i < ETH_ALEN; i++)
7776 mac_addr[i] &= mac_addr_mask[i];
7777
7778 return 0;
7779}
7780
34373d12
VT
7781static bool cfg80211_off_channel_oper_allowed(struct wireless_dev *wdev)
7782{
7783 ASSERT_WDEV_LOCK(wdev);
7784
7785 if (!cfg80211_beaconing_iface_active(wdev))
7786 return true;
7787
7788 if (!(wdev->chandef.chan->flags & IEEE80211_CHAN_RADAR))
7789 return true;
7790
7791 return regulatory_pre_cac_allowed(wdev->wiphy);
7792}
7793
db0a4ad8
JB
7794static bool nl80211_check_scan_feat(struct wiphy *wiphy, u32 flags, u32 flag,
7795 enum nl80211_ext_feature_index feat)
7796{
7797 if (!(flags & flag))
7798 return true;
7799 if (wiphy_ext_feature_isset(wiphy, feat))
7800 return true;
7801 return false;
7802}
7803
2d23d073
RZ
7804static int
7805nl80211_check_scan_flags(struct wiphy *wiphy, struct wireless_dev *wdev,
7806 void *request, struct nlattr **attrs,
7807 bool is_sched_scan)
7808{
7809 u8 *mac_addr, *mac_addr_mask;
7810 u32 *flags;
7811 enum nl80211_feature_flags randomness_flag;
7812
7813 if (!attrs[NL80211_ATTR_SCAN_FLAGS])
7814 return 0;
7815
7816 if (is_sched_scan) {
7817 struct cfg80211_sched_scan_request *req = request;
7818
7819 randomness_flag = wdev ?
7820 NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR :
7821 NL80211_FEATURE_ND_RANDOM_MAC_ADDR;
7822 flags = &req->flags;
7823 mac_addr = req->mac_addr;
7824 mac_addr_mask = req->mac_addr_mask;
7825 } else {
7826 struct cfg80211_scan_request *req = request;
7827
7828 randomness_flag = NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR;
7829 flags = &req->flags;
7830 mac_addr = req->mac_addr;
7831 mac_addr_mask = req->mac_addr_mask;
7832 }
7833
7834 *flags = nla_get_u32(attrs[NL80211_ATTR_SCAN_FLAGS]);
7835
5037a009
SD
7836 if (((*flags & NL80211_SCAN_FLAG_LOW_PRIORITY) &&
7837 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) ||
db0a4ad8
JB
7838 !nl80211_check_scan_feat(wiphy, *flags,
7839 NL80211_SCAN_FLAG_LOW_SPAN,
7840 NL80211_EXT_FEATURE_LOW_SPAN_SCAN) ||
7841 !nl80211_check_scan_feat(wiphy, *flags,
7842 NL80211_SCAN_FLAG_LOW_POWER,
7843 NL80211_EXT_FEATURE_LOW_POWER_SCAN) ||
7844 !nl80211_check_scan_feat(wiphy, *flags,
7845 NL80211_SCAN_FLAG_HIGH_ACCURACY,
7846 NL80211_EXT_FEATURE_HIGH_ACCURACY_SCAN) ||
7847 !nl80211_check_scan_feat(wiphy, *flags,
7848 NL80211_SCAN_FLAG_FILS_MAX_CHANNEL_TIME,
7849 NL80211_EXT_FEATURE_FILS_MAX_CHANNEL_TIME) ||
7850 !nl80211_check_scan_feat(wiphy, *flags,
7851 NL80211_SCAN_FLAG_ACCEPT_BCAST_PROBE_RESP,
7852 NL80211_EXT_FEATURE_ACCEPT_BCAST_PROBE_RESP) ||
7853 !nl80211_check_scan_feat(wiphy, *flags,
7854 NL80211_SCAN_FLAG_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION,
7855 NL80211_EXT_FEATURE_OCE_PROBE_REQ_DEFERRAL_SUPPRESSION) ||
7856 !nl80211_check_scan_feat(wiphy, *flags,
7857 NL80211_SCAN_FLAG_OCE_PROBE_REQ_HIGH_TX_RATE,
2e076f19
JB
7858 NL80211_EXT_FEATURE_OCE_PROBE_REQ_HIGH_TX_RATE) ||
7859 !nl80211_check_scan_feat(wiphy, *flags,
7860 NL80211_SCAN_FLAG_RANDOM_SN,
7861 NL80211_EXT_FEATURE_SCAN_RANDOM_SN) ||
7862 !nl80211_check_scan_feat(wiphy, *flags,
7863 NL80211_SCAN_FLAG_MIN_PREQ_CONTENT,
7864 NL80211_EXT_FEATURE_SCAN_MIN_PREQ_CONTENT))
2d23d073
RZ
7865 return -EOPNOTSUPP;
7866
7867 if (*flags & NL80211_SCAN_FLAG_RANDOM_ADDR) {
7868 int err;
7869
7870 if (!(wiphy->features & randomness_flag) ||
7871 (wdev && wdev->current_bss))
7872 return -EOPNOTSUPP;
7873
7874 err = nl80211_parse_random_mac(attrs, mac_addr, mac_addr_mask);
7875 if (err)
7876 return err;
7877 }
7878
2d23d073
RZ
7879 return 0;
7880}
7881
2a519311
JB
7882static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
7883{
4c476991 7884 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fd014284 7885 struct wireless_dev *wdev = info->user_ptr[1];
2a519311 7886 struct cfg80211_scan_request *request;
2032f3b2
TP
7887 struct nlattr *scan_freqs = NULL;
7888 bool scan_freqs_khz = false;
2a519311
JB
7889 struct nlattr *attr;
7890 struct wiphy *wiphy;
83f5e2cf 7891 int err, tmp, n_ssids = 0, n_channels, i;
70692ad2 7892 size_t ie_len;
2a519311 7893
79c97e97 7894 wiphy = &rdev->wiphy;
2a519311 7895
cb3b7d87
AB
7896 if (wdev->iftype == NL80211_IFTYPE_NAN)
7897 return -EOPNOTSUPP;
7898
4c476991
JB
7899 if (!rdev->ops->scan)
7900 return -EOPNOTSUPP;
2a519311 7901
83286856
CJ
7902 if (rdev->scan_req || rdev->scan_msg)
7903 return -EBUSY;
2a519311 7904
2032f3b2
TP
7905 if (info->attrs[NL80211_ATTR_SCAN_FREQ_KHZ]) {
7906 if (!wiphy_ext_feature_isset(wiphy,
7907 NL80211_EXT_FEATURE_SCAN_FREQ_KHZ))
7908 return -EOPNOTSUPP;
7909 scan_freqs = info->attrs[NL80211_ATTR_SCAN_FREQ_KHZ];
7910 scan_freqs_khz = true;
7911 } else if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES])
7912 scan_freqs = info->attrs[NL80211_ATTR_SCAN_FREQUENCIES];
7913
7914 if (scan_freqs) {
7915 n_channels = validate_scan_freqs(scan_freqs);
83286856
CJ
7916 if (!n_channels)
7917 return -EINVAL;
2a519311 7918 } else {
bdfbec2d 7919 n_channels = ieee80211_get_num_supported_channels(wiphy);
2a519311
JB
7920 }
7921
7922 if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
7923 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
7924 n_ssids++;
7925
83286856
CJ
7926 if (n_ssids > wiphy->max_scan_ssids)
7927 return -EINVAL;
2a519311 7928
70692ad2
JM
7929 if (info->attrs[NL80211_ATTR_IE])
7930 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
7931 else
7932 ie_len = 0;
7933
83286856
CJ
7934 if (ie_len > wiphy->max_scan_ie_len)
7935 return -EINVAL;
18a83659 7936
2a519311 7937 request = kzalloc(sizeof(*request)
a2cd43c5
LC
7938 + sizeof(*request->ssids) * n_ssids
7939 + sizeof(*request->channels) * n_channels
70692ad2 7940 + ie_len, GFP_KERNEL);
83286856
CJ
7941 if (!request)
7942 return -ENOMEM;
2a519311 7943
2a519311 7944 if (n_ssids)
5ba63533 7945 request->ssids = (void *)&request->channels[n_channels];
2a519311 7946 request->n_ssids = n_ssids;
70692ad2 7947 if (ie_len) {
13874e4b 7948 if (n_ssids)
70692ad2
JM
7949 request->ie = (void *)(request->ssids + n_ssids);
7950 else
7951 request->ie = (void *)(request->channels + n_channels);
7952 }
2a519311 7953
584991dc 7954 i = 0;
2032f3b2 7955 if (scan_freqs) {
2a519311 7956 /* user specified, bail out if channel not found */
2032f3b2 7957 nla_for_each_nested(attr, scan_freqs, tmp) {
584991dc 7958 struct ieee80211_channel *chan;
2032f3b2 7959 int freq = nla_get_u32(attr);
584991dc 7960
2032f3b2
TP
7961 if (!scan_freqs_khz)
7962 freq = MHZ_TO_KHZ(freq);
584991dc 7963
2032f3b2 7964 chan = ieee80211_get_channel_khz(wiphy, freq);
584991dc 7965 if (!chan) {
2a519311
JB
7966 err = -EINVAL;
7967 goto out_free;
7968 }
584991dc
JB
7969
7970 /* ignore disabled channels */
7971 if (chan->flags & IEEE80211_CHAN_DISABLED)
7972 continue;
7973
7974 request->channels[i] = chan;
2a519311
JB
7975 i++;
7976 }
7977 } else {
57fbcce3 7978 enum nl80211_band band;
34850ab2 7979
2a519311 7980 /* all channels */
57fbcce3 7981 for (band = 0; band < NUM_NL80211_BANDS; band++) {
2a519311 7982 int j;
7a087e74 7983
2a519311
JB
7984 if (!wiphy->bands[band])
7985 continue;
7986 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
584991dc
JB
7987 struct ieee80211_channel *chan;
7988
7989 chan = &wiphy->bands[band]->channels[j];
7990
7991 if (chan->flags & IEEE80211_CHAN_DISABLED)
7992 continue;
7993
7994 request->channels[i] = chan;
2a519311
JB
7995 i++;
7996 }
7997 }
7998 }
7999
584991dc
JB
8000 if (!i) {
8001 err = -EINVAL;
8002 goto out_free;
8003 }
8004
8005 request->n_channels = i;
8006
34373d12
VT
8007 wdev_lock(wdev);
8008 if (!cfg80211_off_channel_oper_allowed(wdev)) {
8009 struct ieee80211_channel *chan;
8010
8011 if (request->n_channels != 1) {
8012 wdev_unlock(wdev);
8013 err = -EBUSY;
8014 goto out_free;
8015 }
8016
8017 chan = request->channels[0];
8018 if (chan->center_freq != wdev->chandef.chan->center_freq) {
8019 wdev_unlock(wdev);
8020 err = -EBUSY;
8021 goto out_free;
8022 }
8023 }
8024 wdev_unlock(wdev);
8025
2a519311 8026 i = 0;
13874e4b 8027 if (n_ssids) {
2a519311 8028 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
57a27e1d 8029 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
2a519311
JB
8030 err = -EINVAL;
8031 goto out_free;
8032 }
57a27e1d 8033 request->ssids[i].ssid_len = nla_len(attr);
2a519311 8034 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
2a519311
JB
8035 i++;
8036 }
8037 }
8038
70692ad2
JM
8039 if (info->attrs[NL80211_ATTR_IE]) {
8040 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
de95a54b
JB
8041 memcpy((void *)request->ie,
8042 nla_data(info->attrs[NL80211_ATTR_IE]),
70692ad2
JM
8043 request->ie_len);
8044 }
8045
57fbcce3 8046 for (i = 0; i < NUM_NL80211_BANDS; i++)
a401d2bb
JB
8047 if (wiphy->bands[i])
8048 request->rates[i] =
8049 (1 << wiphy->bands[i]->n_bitrates) - 1;
34850ab2
JB
8050
8051 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) {
8052 nla_for_each_nested(attr,
8053 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES],
8054 tmp) {
57fbcce3 8055 enum nl80211_band band = nla_type(attr);
34850ab2 8056
57fbcce3 8057 if (band < 0 || band >= NUM_NL80211_BANDS) {
34850ab2
JB
8058 err = -EINVAL;
8059 goto out_free;
8060 }
1b09cd82
FF
8061
8062 if (!wiphy->bands[band])
8063 continue;
8064
34850ab2
JB
8065 err = ieee80211_get_ratemask(wiphy->bands[band],
8066 nla_data(attr),
8067 nla_len(attr),
8068 &request->rates[band]);
8069 if (err)
8070 goto out_free;
8071 }
8072 }
8073
1d76250b
AS
8074 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) {
8075 if (!wiphy_ext_feature_isset(wiphy,
8076 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) {
8077 err = -EOPNOTSUPP;
8078 goto out_free;
8079 }
8080
8081 request->duration =
8082 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]);
8083 request->duration_mandatory =
8084 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]);
8085 }
8086
2d23d073
RZ
8087 err = nl80211_check_scan_flags(wiphy, wdev, request, info->attrs,
8088 false);
8089 if (err)
8090 goto out_free;
ed473771 8091
e9f935e3
RM
8092 request->no_cck =
8093 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
8094
2fa436b3
VK
8095 /* Initial implementation used NL80211_ATTR_MAC to set the specific
8096 * BSSID to scan for. This was problematic because that same attribute
8097 * was already used for another purpose (local random MAC address). The
8098 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards
8099 * compatibility with older userspace components, also use the
8100 * NL80211_ATTR_MAC value here if it can be determined to be used for
8101 * the specific BSSID use case instead of the random MAC address
8102 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use).
8103 */
8104 if (info->attrs[NL80211_ATTR_BSSID])
8105 memcpy(request->bssid,
8106 nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN);
8107 else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) &&
8108 info->attrs[NL80211_ATTR_MAC])
818965d3
JM
8109 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]),
8110 ETH_ALEN);
8111 else
8112 eth_broadcast_addr(request->bssid);
8113
fd014284 8114 request->wdev = wdev;
79c97e97 8115 request->wiphy = &rdev->wiphy;
15d6030b 8116 request->scan_start = jiffies;
2a519311 8117
79c97e97 8118 rdev->scan_req = request;
e35e4d28 8119 err = rdev_scan(rdev, request);
2a519311 8120
504776be
CJ
8121 if (err)
8122 goto out_free;
8123
8124 nl80211_send_scan_start(rdev, wdev);
8125 if (wdev->netdev)
8126 dev_hold(wdev->netdev);
8127
8128 return 0;
8129
2a519311 8130 out_free:
504776be
CJ
8131 rdev->scan_req = NULL;
8132 kfree(request);
3b85875a 8133
2a519311
JB
8134 return err;
8135}
8136
91d3ab46
VK
8137static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info)
8138{
8139 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8140 struct wireless_dev *wdev = info->user_ptr[1];
8141
8142 if (!rdev->ops->abort_scan)
8143 return -EOPNOTSUPP;
8144
8145 if (rdev->scan_msg)
8146 return 0;
8147
8148 if (!rdev->scan_req)
8149 return -ENOENT;
8150
8151 rdev_abort_scan(rdev, wdev);
8152 return 0;
8153}
8154
3b06d277
AS
8155static int
8156nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans,
8157 struct cfg80211_sched_scan_request *request,
8158 struct nlattr **attrs)
8159{
8160 int tmp, err, i = 0;
8161 struct nlattr *attr;
8162
8163 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
8164 u32 interval;
8165
8166 /*
8167 * If scan plans are not specified,
5a88de53 8168 * %NL80211_ATTR_SCHED_SCAN_INTERVAL will be specified. In this
3b06d277
AS
8169 * case one scan plan will be set with the specified scan
8170 * interval and infinite number of iterations.
8171 */
3b06d277
AS
8172 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]);
8173 if (!interval)
8174 return -EINVAL;
8175
8176 request->scan_plans[0].interval =
8177 DIV_ROUND_UP(interval, MSEC_PER_SEC);
8178 if (!request->scan_plans[0].interval)
8179 return -EINVAL;
8180
8181 if (request->scan_plans[0].interval >
8182 wiphy->max_sched_scan_plan_interval)
8183 request->scan_plans[0].interval =
8184 wiphy->max_sched_scan_plan_interval;
8185
8186 return 0;
8187 }
8188
8189 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) {
8190 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1];
8191
8192 if (WARN_ON(i >= n_plans))
8193 return -EINVAL;
8194
8cb08174
JB
8195 err = nla_parse_nested_deprecated(plan,
8196 NL80211_SCHED_SCAN_PLAN_MAX,
8197 attr, nl80211_plan_policy,
8198 NULL);
3b06d277
AS
8199 if (err)
8200 return err;
8201
8202 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL])
8203 return -EINVAL;
8204
8205 request->scan_plans[i].interval =
8206 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]);
8207 if (!request->scan_plans[i].interval ||
8208 request->scan_plans[i].interval >
8209 wiphy->max_sched_scan_plan_interval)
8210 return -EINVAL;
8211
8212 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) {
8213 request->scan_plans[i].iterations =
8214 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]);
8215 if (!request->scan_plans[i].iterations ||
8216 (request->scan_plans[i].iterations >
8217 wiphy->max_sched_scan_plan_iterations))
8218 return -EINVAL;
8219 } else if (i < n_plans - 1) {
8220 /*
8221 * All scan plans but the last one must specify
8222 * a finite number of iterations
8223 */
8224 return -EINVAL;
8225 }
8226
8227 i++;
8228 }
8229
8230 /*
8231 * The last scan plan must not specify the number of
8232 * iterations, it is supposed to run infinitely
8233 */
8234 if (request->scan_plans[n_plans - 1].iterations)
8235 return -EINVAL;
8236
8237 return 0;
8238}
8239
1e1b11b6 8240static int
8241nl80211_parse_sched_scan_per_band_rssi(struct wiphy *wiphy,
8242 struct cfg80211_match_set *match_sets,
8243 struct nlattr *tb_band_rssi,
8244 s32 rssi_thold)
8245{
8246 struct nlattr *attr;
8247 int i, tmp, ret = 0;
8248
8249 if (!wiphy_ext_feature_isset(wiphy,
8250 NL80211_EXT_FEATURE_SCHED_SCAN_BAND_SPECIFIC_RSSI_THOLD)) {
8251 if (tb_band_rssi)
8252 ret = -EOPNOTSUPP;
8253 else
8254 for (i = 0; i < NUM_NL80211_BANDS; i++)
8255 match_sets->per_band_rssi_thold[i] =
8256 NL80211_SCAN_RSSI_THOLD_OFF;
8257 return ret;
8258 }
8259
8260 for (i = 0; i < NUM_NL80211_BANDS; i++)
8261 match_sets->per_band_rssi_thold[i] = rssi_thold;
8262
8263 nla_for_each_nested(attr, tb_band_rssi, tmp) {
8264 enum nl80211_band band = nla_type(attr);
8265
8266 if (band < 0 || band >= NUM_NL80211_BANDS)
8267 return -EINVAL;
8268
8269 match_sets->per_band_rssi_thold[band] = nla_get_s32(attr);
8270 }
8271
8272 return 0;
8273}
8274
256da02d 8275static struct cfg80211_sched_scan_request *
ad2b26ab 8276nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev,
aad1e812 8277 struct nlattr **attrs, int max_match_sets)
807f8a8c
LC
8278{
8279 struct cfg80211_sched_scan_request *request;
807f8a8c 8280 struct nlattr *attr;
3b06d277 8281 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0;
57fbcce3 8282 enum nl80211_band band;
807f8a8c 8283 size_t ie_len;
a1f1c21c 8284 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1];
ea73cbce 8285 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF;
807f8a8c 8286
256da02d 8287 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c 8288 n_channels = validate_scan_freqs(
256da02d 8289 attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
807f8a8c 8290 if (!n_channels)
256da02d 8291 return ERR_PTR(-EINVAL);
807f8a8c 8292 } else {
bdfbec2d 8293 n_channels = ieee80211_get_num_supported_channels(wiphy);
807f8a8c
LC
8294 }
8295
256da02d
LC
8296 if (attrs[NL80211_ATTR_SCAN_SSIDS])
8297 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c
LC
8298 tmp)
8299 n_ssids++;
8300
93b6aa69 8301 if (n_ssids > wiphy->max_sched_scan_ssids)
256da02d 8302 return ERR_PTR(-EINVAL);
807f8a8c 8303
ea73cbce
JB
8304 /*
8305 * First, count the number of 'real' matchsets. Due to an issue with
8306 * the old implementation, matchsets containing only the RSSI attribute
8307 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default'
8308 * RSSI for all matchsets, rather than their own matchset for reporting
8309 * all APs with a strong RSSI. This is needed to be compatible with
8310 * older userspace that treated a matchset with only the RSSI as the
8311 * global RSSI for all other matchsets - if there are other matchsets.
8312 */
256da02d 8313 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 8314 nla_for_each_nested(attr,
256da02d 8315 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
ea73cbce
JB
8316 tmp) {
8317 struct nlattr *rssi;
8318
8cb08174
JB
8319 err = nla_parse_nested_deprecated(tb,
8320 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
8321 attr,
8322 nl80211_match_policy,
8323 NULL);
ea73cbce 8324 if (err)
256da02d 8325 return ERR_PTR(err);
3007e352
AVS
8326
8327 /* SSID and BSSID are mutually exclusive */
8328 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] &&
8329 tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID])
8330 return ERR_PTR(-EINVAL);
8331
ea73cbce 8332 /* add other standalone attributes here */
3007e352
AVS
8333 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID] ||
8334 tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID]) {
ea73cbce
JB
8335 n_match_sets++;
8336 continue;
8337 }
8338 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
8339 if (rssi)
8340 default_match_rssi = nla_get_s32(rssi);
8341 }
8342 }
8343
8344 /* However, if there's no other matchset, add the RSSI one */
8345 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF)
8346 n_match_sets = 1;
a1f1c21c 8347
aad1e812 8348 if (n_match_sets > max_match_sets)
256da02d 8349 return ERR_PTR(-EINVAL);
a1f1c21c 8350
256da02d
LC
8351 if (attrs[NL80211_ATTR_IE])
8352 ie_len = nla_len(attrs[NL80211_ATTR_IE]);
807f8a8c
LC
8353 else
8354 ie_len = 0;
8355
5a865bad 8356 if (ie_len > wiphy->max_sched_scan_ie_len)
256da02d 8357 return ERR_PTR(-EINVAL);
c10841ca 8358
3b06d277
AS
8359 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) {
8360 /*
8361 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since
8362 * each scan plan already specifies its own interval
8363 */
8364 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
8365 return ERR_PTR(-EINVAL);
8366
8367 nla_for_each_nested(attr,
8368 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp)
8369 n_plans++;
8370 } else {
8371 /*
8372 * The scan interval attribute is kept for backward
8373 * compatibility. If no scan plans are specified and sched scan
8374 * interval is specified, one scan plan will be set with this
8375 * scan interval and infinite number of iterations.
8376 */
8377 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL])
8378 return ERR_PTR(-EINVAL);
8379
8380 n_plans = 1;
8381 }
8382
8383 if (!n_plans || n_plans > wiphy->max_sched_scan_plans)
8384 return ERR_PTR(-EINVAL);
8385
bf95ecdb 8386 if (!wiphy_ext_feature_isset(
8387 wiphy, NL80211_EXT_FEATURE_SCHED_SCAN_RELATIVE_RSSI) &&
8388 (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI] ||
8389 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]))
8390 return ERR_PTR(-EINVAL);
8391
807f8a8c 8392 request = kzalloc(sizeof(*request)
a2cd43c5 8393 + sizeof(*request->ssids) * n_ssids
a1f1c21c 8394 + sizeof(*request->match_sets) * n_match_sets
3b06d277 8395 + sizeof(*request->scan_plans) * n_plans
a2cd43c5 8396 + sizeof(*request->channels) * n_channels
807f8a8c 8397 + ie_len, GFP_KERNEL);
256da02d
LC
8398 if (!request)
8399 return ERR_PTR(-ENOMEM);
807f8a8c
LC
8400
8401 if (n_ssids)
8402 request->ssids = (void *)&request->channels[n_channels];
8403 request->n_ssids = n_ssids;
8404 if (ie_len) {
13874e4b 8405 if (n_ssids)
807f8a8c
LC
8406 request->ie = (void *)(request->ssids + n_ssids);
8407 else
8408 request->ie = (void *)(request->channels + n_channels);
8409 }
8410
a1f1c21c
LC
8411 if (n_match_sets) {
8412 if (request->ie)
8413 request->match_sets = (void *)(request->ie + ie_len);
13874e4b 8414 else if (n_ssids)
a1f1c21c
LC
8415 request->match_sets =
8416 (void *)(request->ssids + n_ssids);
8417 else
8418 request->match_sets =
8419 (void *)(request->channels + n_channels);
8420 }
8421 request->n_match_sets = n_match_sets;
8422
3b06d277
AS
8423 if (n_match_sets)
8424 request->scan_plans = (void *)(request->match_sets +
8425 n_match_sets);
8426 else if (request->ie)
8427 request->scan_plans = (void *)(request->ie + ie_len);
8428 else if (n_ssids)
8429 request->scan_plans = (void *)(request->ssids + n_ssids);
8430 else
8431 request->scan_plans = (void *)(request->channels + n_channels);
8432
8433 request->n_scan_plans = n_plans;
8434
807f8a8c 8435 i = 0;
256da02d 8436 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
807f8a8c
LC
8437 /* user specified, bail out if channel not found */
8438 nla_for_each_nested(attr,
256da02d 8439 attrs[NL80211_ATTR_SCAN_FREQUENCIES],
807f8a8c
LC
8440 tmp) {
8441 struct ieee80211_channel *chan;
8442
8443 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
8444
8445 if (!chan) {
8446 err = -EINVAL;
8447 goto out_free;
8448 }
8449
8450 /* ignore disabled channels */
8451 if (chan->flags & IEEE80211_CHAN_DISABLED)
8452 continue;
8453
8454 request->channels[i] = chan;
8455 i++;
8456 }
8457 } else {
8458 /* all channels */
57fbcce3 8459 for (band = 0; band < NUM_NL80211_BANDS; band++) {
807f8a8c 8460 int j;
7a087e74 8461
807f8a8c
LC
8462 if (!wiphy->bands[band])
8463 continue;
8464 for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
8465 struct ieee80211_channel *chan;
8466
8467 chan = &wiphy->bands[band]->channels[j];
8468
8469 if (chan->flags & IEEE80211_CHAN_DISABLED)
8470 continue;
8471
8472 request->channels[i] = chan;
8473 i++;
8474 }
8475 }
8476 }
8477
8478 if (!i) {
8479 err = -EINVAL;
8480 goto out_free;
8481 }
8482
8483 request->n_channels = i;
8484
8485 i = 0;
13874e4b 8486 if (n_ssids) {
256da02d 8487 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS],
807f8a8c 8488 tmp) {
57a27e1d 8489 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) {
807f8a8c
LC
8490 err = -EINVAL;
8491 goto out_free;
8492 }
57a27e1d 8493 request->ssids[i].ssid_len = nla_len(attr);
807f8a8c
LC
8494 memcpy(request->ssids[i].ssid, nla_data(attr),
8495 nla_len(attr));
807f8a8c
LC
8496 i++;
8497 }
8498 }
8499
a1f1c21c 8500 i = 0;
256da02d 8501 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) {
a1f1c21c 8502 nla_for_each_nested(attr,
256da02d 8503 attrs[NL80211_ATTR_SCHED_SCAN_MATCH],
a1f1c21c 8504 tmp) {
3007e352 8505 struct nlattr *ssid, *bssid, *rssi;
a1f1c21c 8506
8cb08174
JB
8507 err = nla_parse_nested_deprecated(tb,
8508 NL80211_SCHED_SCAN_MATCH_ATTR_MAX,
8509 attr,
8510 nl80211_match_policy,
8511 NULL);
ae811e21
JB
8512 if (err)
8513 goto out_free;
4a4ab0d7 8514 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID];
3007e352 8515 bssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_BSSID];
d39f3b4f
JB
8516
8517 if (!ssid && !bssid) {
8518 i++;
8519 continue;
8520 }
8521
8522 if (WARN_ON(i >= n_match_sets)) {
8523 /* this indicates a programming error,
8524 * the loop above should have verified
8525 * things properly
8526 */
8527 err = -EINVAL;
8528 goto out_free;
8529 }
8530
8531 if (ssid) {
d39f3b4f
JB
8532 memcpy(request->match_sets[i].ssid.ssid,
8533 nla_data(ssid), nla_len(ssid));
8534 request->match_sets[i].ssid.ssid_len =
8535 nla_len(ssid);
8536 }
cb9abd48 8537 if (bssid)
d39f3b4f
JB
8538 memcpy(request->match_sets[i].bssid,
8539 nla_data(bssid), ETH_ALEN);
3007e352 8540
d39f3b4f
JB
8541 /* special attribute - old implementation w/a */
8542 request->match_sets[i].rssi_thold = default_match_rssi;
8543 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI];
8544 if (rssi)
ea73cbce 8545 request->match_sets[i].rssi_thold =
d39f3b4f 8546 nla_get_s32(rssi);
1e1b11b6 8547
8548 /* Parse per band RSSI attribute */
8549 err = nl80211_parse_sched_scan_per_band_rssi(wiphy,
8550 &request->match_sets[i],
8551 tb[NL80211_SCHED_SCAN_MATCH_PER_BAND_RSSI],
8552 request->match_sets[i].rssi_thold);
8553 if (err)
8554 goto out_free;
8555
a1f1c21c
LC
8556 i++;
8557 }
ea73cbce
JB
8558
8559 /* there was no other matchset, so the RSSI one is alone */
f89f46cf 8560 if (i == 0 && n_match_sets)
ea73cbce
JB
8561 request->match_sets[0].rssi_thold = default_match_rssi;
8562
8563 request->min_rssi_thold = INT_MAX;
8564 for (i = 0; i < n_match_sets; i++)
8565 request->min_rssi_thold =
8566 min(request->match_sets[i].rssi_thold,
8567 request->min_rssi_thold);
8568 } else {
8569 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF;
a1f1c21c
LC
8570 }
8571
9900e484
JB
8572 if (ie_len) {
8573 request->ie_len = ie_len;
807f8a8c 8574 memcpy((void *)request->ie,
256da02d 8575 nla_data(attrs[NL80211_ATTR_IE]),
807f8a8c
LC
8576 request->ie_len);
8577 }
8578
2d23d073
RZ
8579 err = nl80211_check_scan_flags(wiphy, wdev, request, attrs, true);
8580 if (err)
8581 goto out_free;
ed473771 8582
9c748934
LC
8583 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY])
8584 request->delay =
8585 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]);
8586
bf95ecdb 8587 if (attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]) {
8588 request->relative_rssi = nla_get_s8(
8589 attrs[NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI]);
8590 request->relative_rssi_set = true;
8591 }
8592
8593 if (request->relative_rssi_set &&
8594 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]) {
8595 struct nl80211_bss_select_rssi_adjust *rssi_adjust;
8596
8597 rssi_adjust = nla_data(
8598 attrs[NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST]);
8599 request->rssi_adjust.band = rssi_adjust->band;
8600 request->rssi_adjust.delta = rssi_adjust->delta;
8601 if (!is_band_valid(wiphy, request->rssi_adjust.band)) {
8602 err = -EINVAL;
8603 goto out_free;
8604 }
8605 }
8606
3b06d277
AS
8607 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs);
8608 if (err)
8609 goto out_free;
8610
15d6030b 8611 request->scan_start = jiffies;
807f8a8c 8612
256da02d 8613 return request;
807f8a8c
LC
8614
8615out_free:
8616 kfree(request);
256da02d
LC
8617 return ERR_PTR(err);
8618}
8619
8620static int nl80211_start_sched_scan(struct sk_buff *skb,
8621 struct genl_info *info)
8622{
8623 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8624 struct net_device *dev = info->user_ptr[1];
ad2b26ab 8625 struct wireless_dev *wdev = dev->ieee80211_ptr;
31a60ed1 8626 struct cfg80211_sched_scan_request *sched_scan_req;
ca986ad9 8627 bool want_multi;
256da02d
LC
8628 int err;
8629
ca986ad9 8630 if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_start)
256da02d
LC
8631 return -EOPNOTSUPP;
8632
ca986ad9
AVS
8633 want_multi = info->attrs[NL80211_ATTR_SCHED_SCAN_MULTI];
8634 err = cfg80211_sched_scan_req_possible(rdev, want_multi);
8635 if (err)
8636 return err;
256da02d 8637
31a60ed1 8638 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev,
aad1e812
AVS
8639 info->attrs,
8640 rdev->wiphy.max_match_sets);
31a60ed1
JR
8641
8642 err = PTR_ERR_OR_ZERO(sched_scan_req);
256da02d
LC
8643 if (err)
8644 goto out_err;
8645
ca986ad9
AVS
8646 /* leave request id zero for legacy request
8647 * or if driver does not support multi-scheduled scan
8648 */
2fd351a8
DK
8649 if (want_multi && rdev->wiphy.max_sched_scan_reqs > 1)
8650 sched_scan_req->reqid = cfg80211_assign_cookie(rdev);
ca986ad9 8651
31a60ed1 8652 err = rdev_sched_scan_start(rdev, dev, sched_scan_req);
256da02d
LC
8653 if (err)
8654 goto out_free;
8655
31a60ed1
JR
8656 sched_scan_req->dev = dev;
8657 sched_scan_req->wiphy = &rdev->wiphy;
8658
93a1e86c
JR
8659 if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
8660 sched_scan_req->owner_nlportid = info->snd_portid;
8661
ca986ad9 8662 cfg80211_add_sched_scan_req(rdev, sched_scan_req);
256da02d 8663
96b08fd6 8664 nl80211_send_sched_scan(sched_scan_req, NL80211_CMD_START_SCHED_SCAN);
256da02d
LC
8665 return 0;
8666
8667out_free:
31a60ed1 8668 kfree(sched_scan_req);
256da02d 8669out_err:
807f8a8c
LC
8670 return err;
8671}
8672
8673static int nl80211_stop_sched_scan(struct sk_buff *skb,
8674 struct genl_info *info)
8675{
ca986ad9 8676 struct cfg80211_sched_scan_request *req;
807f8a8c 8677 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ca986ad9 8678 u64 cookie;
807f8a8c 8679
ca986ad9 8680 if (!rdev->wiphy.max_sched_scan_reqs || !rdev->ops->sched_scan_stop)
807f8a8c
LC
8681 return -EOPNOTSUPP;
8682
ca986ad9
AVS
8683 if (info->attrs[NL80211_ATTR_COOKIE]) {
8684 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
8685 return __cfg80211_stop_sched_scan(rdev, cookie, false);
8686 }
8687
8688 req = list_first_or_null_rcu(&rdev->sched_scan_req_list,
8689 struct cfg80211_sched_scan_request,
8690 list);
8691 if (!req || req->reqid ||
8692 (req->owner_nlportid &&
8693 req->owner_nlportid != info->snd_portid))
8694 return -ENOENT;
8695
8696 return cfg80211_stop_sched_scan_req(rdev, req, false);
807f8a8c
LC
8697}
8698
04f39047
SW
8699static int nl80211_start_radar_detection(struct sk_buff *skb,
8700 struct genl_info *info)
8701{
8702 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8703 struct net_device *dev = info->user_ptr[1];
8704 struct wireless_dev *wdev = dev->ieee80211_ptr;
13cf6dec 8705 struct wiphy *wiphy = wdev->wiphy;
04f39047 8706 struct cfg80211_chan_def chandef;
55f7435c 8707 enum nl80211_dfs_regions dfs_region;
31559f35 8708 unsigned int cac_time_ms;
04f39047
SW
8709 int err;
8710
13cf6dec 8711 dfs_region = reg_get_dfs_region(wiphy);
55f7435c
LR
8712 if (dfs_region == NL80211_DFS_UNSET)
8713 return -EINVAL;
8714
04f39047
SW
8715 err = nl80211_parse_chandef(rdev, info, &chandef);
8716 if (err)
8717 return err;
8718
ff311bc1
SW
8719 if (netif_carrier_ok(dev))
8720 return -EBUSY;
8721
04f39047
SW
8722 if (wdev->cac_started)
8723 return -EBUSY;
8724
13cf6dec 8725 err = cfg80211_chandef_dfs_required(wiphy, &chandef, wdev->iftype);
04f39047
SW
8726 if (err < 0)
8727 return err;
8728
8729 if (err == 0)
8730 return -EINVAL;
8731
13cf6dec 8732 if (!cfg80211_chandef_dfs_usable(wiphy, &chandef))
04f39047
SW
8733 return -EINVAL;
8734
13cf6dec
DL
8735 /* CAC start is offloaded to HW and can't be started manually */
8736 if (wiphy_ext_feature_isset(wiphy, NL80211_EXT_FEATURE_DFS_OFFLOAD))
8737 return -EOPNOTSUPP;
8738
04f39047
SW
8739 if (!rdev->ops->start_radar_detection)
8740 return -EOPNOTSUPP;
8741
31559f35
JD
8742 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef);
8743 if (WARN_ON(!cac_time_ms))
8744 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS;
8745
a1056b1b 8746 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms);
04f39047 8747 if (!err) {
9e0e2961 8748 wdev->chandef = chandef;
04f39047
SW
8749 wdev->cac_started = true;
8750 wdev->cac_start_time = jiffies;
31559f35 8751 wdev->cac_time_ms = cac_time_ms;
04f39047 8752 }
04f39047
SW
8753 return err;
8754}
8755
30c63115
S
8756static int nl80211_notify_radar_detection(struct sk_buff *skb,
8757 struct genl_info *info)
8758{
8759 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8760 struct net_device *dev = info->user_ptr[1];
8761 struct wireless_dev *wdev = dev->ieee80211_ptr;
8762 struct wiphy *wiphy = wdev->wiphy;
8763 struct cfg80211_chan_def chandef;
8764 enum nl80211_dfs_regions dfs_region;
8765 int err;
8766
8767 dfs_region = reg_get_dfs_region(wiphy);
8768 if (dfs_region == NL80211_DFS_UNSET) {
8769 GENL_SET_ERR_MSG(info,
8770 "DFS Region is not set. Unexpected Radar indication");
8771 return -EINVAL;
8772 }
8773
8774 err = nl80211_parse_chandef(rdev, info, &chandef);
8775 if (err) {
8776 GENL_SET_ERR_MSG(info, "Unable to extract chandef info");
8777 return err;
8778 }
8779
8780 err = cfg80211_chandef_dfs_required(wiphy, &chandef, wdev->iftype);
8781 if (err < 0) {
8782 GENL_SET_ERR_MSG(info, "chandef is invalid");
8783 return err;
8784 }
8785
8786 if (err == 0) {
8787 GENL_SET_ERR_MSG(info,
8788 "Unexpected Radar indication for chandef/iftype");
8789 return -EINVAL;
8790 }
8791
8792 /* Do not process this notification if radar is already detected
8793 * by kernel on this channel, and return success.
8794 */
8795 if (chandef.chan->dfs_state == NL80211_DFS_UNAVAILABLE)
8796 return 0;
8797
8798 cfg80211_set_dfs_state(wiphy, &chandef, NL80211_DFS_UNAVAILABLE);
8799
8800 cfg80211_sched_dfs_chan_update(rdev);
8801
a680fe46 8802 rdev->radar_chandef = chandef;
30c63115
S
8803
8804 /* Propagate this notification to other radios as well */
8805 queue_work(cfg80211_wq, &rdev->propagate_radar_detect_wk);
8806
8807 return 0;
8808}
8809
16ef1fe2
SW
8810static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info)
8811{
8812 struct cfg80211_registered_device *rdev = info->user_ptr[0];
8813 struct net_device *dev = info->user_ptr[1];
8814 struct wireless_dev *wdev = dev->ieee80211_ptr;
8815 struct cfg80211_csa_settings params;
8816 /* csa_attrs is defined static to avoid waste of stack size - this
8817 * function is called under RTNL lock, so this should not be a problem.
8818 */
8819 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1];
16ef1fe2 8820 int err;
ee4bc9e7 8821 bool need_new_beacon = false;
8d9de16f 8822 bool need_handle_dfs_flag = true;
9a774c78 8823 int len, i;
252e07ca 8824 u32 cs_count;
16ef1fe2
SW
8825
8826 if (!rdev->ops->channel_switch ||
8827 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH))
8828 return -EOPNOTSUPP;
8829
ee4bc9e7
SW
8830 switch (dev->ieee80211_ptr->iftype) {
8831 case NL80211_IFTYPE_AP:
8832 case NL80211_IFTYPE_P2P_GO:
8833 need_new_beacon = true;
8d9de16f
BB
8834 /* For all modes except AP the handle_dfs flag needs to be
8835 * supplied to tell the kernel that userspace will handle radar
8836 * events when they happen. Otherwise a switch to a channel
8837 * requiring DFS will be rejected.
8838 */
8839 need_handle_dfs_flag = false;
ee4bc9e7
SW
8840
8841 /* useless if AP is not running */
8842 if (!wdev->beacon_interval)
1ff79dfa 8843 return -ENOTCONN;
ee4bc9e7
SW
8844 break;
8845 case NL80211_IFTYPE_ADHOC:
1ff79dfa
JB
8846 if (!wdev->ssid_len)
8847 return -ENOTCONN;
8848 break;
c6da674a 8849 case NL80211_IFTYPE_MESH_POINT:
1ff79dfa
JB
8850 if (!wdev->mesh_id_len)
8851 return -ENOTCONN;
ee4bc9e7
SW
8852 break;
8853 default:
16ef1fe2 8854 return -EOPNOTSUPP;
ee4bc9e7 8855 }
16ef1fe2
SW
8856
8857 memset(&params, 0, sizeof(params));
c177db2d 8858 params.beacon_csa.ftm_responder = -1;
16ef1fe2
SW
8859
8860 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
8861 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT])
8862 return -EINVAL;
8863
8864 /* only important for AP, IBSS and mesh create IEs internally */
d0a361a5 8865 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES])
16ef1fe2
SW
8866 return -EINVAL;
8867
252e07ca
LC
8868 /* Even though the attribute is u32, the specification says
8869 * u8, so let's make sure we don't overflow.
8870 */
8871 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]);
8872 if (cs_count > 255)
8873 return -EINVAL;
8874
8875 params.count = cs_count;
16ef1fe2 8876
ee4bc9e7
SW
8877 if (!need_new_beacon)
8878 goto skip_beacons;
8879
81e54d08 8880 err = nl80211_parse_beacon(rdev, info->attrs, &params.beacon_after);
16ef1fe2
SW
8881 if (err)
8882 return err;
8883
8cb08174
JB
8884 err = nla_parse_nested_deprecated(csa_attrs, NL80211_ATTR_MAX,
8885 info->attrs[NL80211_ATTR_CSA_IES],
8886 nl80211_policy, info->extack);
16ef1fe2
SW
8887 if (err)
8888 return err;
8889
81e54d08 8890 err = nl80211_parse_beacon(rdev, csa_attrs, &params.beacon_csa);
16ef1fe2
SW
8891 if (err)
8892 return err;
8893
8894 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON])
8895 return -EINVAL;
8896
9a774c78
AO
8897 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
8898 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
8899 return -EINVAL;
8900
9a774c78
AO
8901 params.n_counter_offsets_beacon = len / sizeof(u16);
8902 if (rdev->wiphy.max_num_csa_counters &&
8903 (params.n_counter_offsets_beacon >
8904 rdev->wiphy.max_num_csa_counters))
16ef1fe2
SW
8905 return -EINVAL;
8906
9a774c78
AO
8907 params.counter_offsets_beacon =
8908 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]);
8909
8910 /* sanity checks - counters should fit and be the same */
8911 for (i = 0; i < params.n_counter_offsets_beacon; i++) {
8912 u16 offset = params.counter_offsets_beacon[i];
8913
8914 if (offset >= params.beacon_csa.tail_len)
8915 return -EINVAL;
8916
8917 if (params.beacon_csa.tail[offset] != params.count)
8918 return -EINVAL;
8919 }
8920
16ef1fe2 8921 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) {
9a774c78
AO
8922 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
8923 if (!len || (len % sizeof(u16)))
16ef1fe2
SW
8924 return -EINVAL;
8925
9a774c78
AO
8926 params.n_counter_offsets_presp = len / sizeof(u16);
8927 if (rdev->wiphy.max_num_csa_counters &&
ad5987b4 8928 (params.n_counter_offsets_presp >
9a774c78 8929 rdev->wiphy.max_num_csa_counters))
16ef1fe2 8930 return -EINVAL;
9a774c78
AO
8931
8932 params.counter_offsets_presp =
8933 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]);
8934
8935 /* sanity checks - counters should fit and be the same */
8936 for (i = 0; i < params.n_counter_offsets_presp; i++) {
8937 u16 offset = params.counter_offsets_presp[i];
8938
8939 if (offset >= params.beacon_csa.probe_resp_len)
8940 return -EINVAL;
8941
8942 if (params.beacon_csa.probe_resp[offset] !=
8943 params.count)
8944 return -EINVAL;
8945 }
16ef1fe2
SW
8946 }
8947
ee4bc9e7 8948skip_beacons:
16ef1fe2
SW
8949 err = nl80211_parse_chandef(rdev, info, &params.chandef);
8950 if (err)
8951 return err;
8952
923b352f
AN
8953 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &params.chandef,
8954 wdev->iftype))
16ef1fe2
SW
8955 return -EINVAL;
8956
2beb6dab
LC
8957 err = cfg80211_chandef_dfs_required(wdev->wiphy,
8958 &params.chandef,
8959 wdev->iftype);
8960 if (err < 0)
8961 return err;
8962
8d9de16f 8963 if (err > 0) {
2beb6dab 8964 params.radar_required = true;
8d9de16f
BB
8965 if (need_handle_dfs_flag &&
8966 !nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS])) {
8967 return -EINVAL;
8968 }
8969 }
16ef1fe2 8970
16ef1fe2
SW
8971 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX])
8972 params.block_tx = true;
8973
c56589ed
SW
8974 wdev_lock(wdev);
8975 err = rdev_channel_switch(rdev, dev, &params);
8976 wdev_unlock(wdev);
8977
8978 return err;
16ef1fe2
SW
8979}
8980
9720bb3a
JB
8981static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb,
8982 u32 seq, int flags,
2a519311 8983 struct cfg80211_registered_device *rdev,
48ab905d
JB
8984 struct wireless_dev *wdev,
8985 struct cfg80211_internal_bss *intbss)
2a519311 8986{
48ab905d 8987 struct cfg80211_bss *res = &intbss->pub;
9caf0364 8988 const struct cfg80211_bss_ies *ies;
2a519311
JB
8989 void *hdr;
8990 struct nlattr *bss;
48ab905d
JB
8991
8992 ASSERT_WDEV_LOCK(wdev);
2a519311 8993
15e47304 8994 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags,
2a519311
JB
8995 NL80211_CMD_NEW_SCAN_RESULTS);
8996 if (!hdr)
8997 return -1;
8998
0a833c29 8999 genl_dump_check_consistent(cb, hdr);
9720bb3a 9000
97990a06
JB
9001 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation))
9002 goto nla_put_failure;
9003 if (wdev->netdev &&
9360ffd1
DM
9004 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex))
9005 goto nla_put_failure;
2dad624e
ND
9006 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
9007 NL80211_ATTR_PAD))
97990a06 9008 goto nla_put_failure;
2a519311 9009
ae0be8de 9010 bss = nla_nest_start_noflag(msg, NL80211_ATTR_BSS);
2a519311
JB
9011 if (!bss)
9012 goto nla_put_failure;
9360ffd1 9013 if ((!is_zero_ether_addr(res->bssid) &&
9caf0364 9014 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid)))
9360ffd1 9015 goto nla_put_failure;
9caf0364
JB
9016
9017 rcu_read_lock();
0e227084
JB
9018 /* indicate whether we have probe response data or not */
9019 if (rcu_access_pointer(res->proberesp_ies) &&
9020 nla_put_flag(msg, NL80211_BSS_PRESP_DATA))
9021 goto fail_unlock_rcu;
9022
9023 /* this pointer prefers to be pointed to probe response data
9024 * but is always valid
9025 */
9caf0364 9026 ies = rcu_dereference(res->ies);
8cef2c9d 9027 if (ies) {
2dad624e
ND
9028 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf,
9029 NL80211_BSS_PAD))
8cef2c9d 9030 goto fail_unlock_rcu;
8cef2c9d
JB
9031 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS,
9032 ies->len, ies->data))
9033 goto fail_unlock_rcu;
9caf0364 9034 }
0e227084
JB
9035
9036 /* and this pointer is always (unless driver didn't know) beacon data */
9caf0364 9037 ies = rcu_dereference(res->beacon_ies);
0e227084 9038 if (ies && ies->from_beacon) {
2dad624e
ND
9039 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf,
9040 NL80211_BSS_PAD))
8cef2c9d
JB
9041 goto fail_unlock_rcu;
9042 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES,
9043 ies->len, ies->data))
9044 goto fail_unlock_rcu;
9caf0364
JB
9045 }
9046 rcu_read_unlock();
9047
9360ffd1
DM
9048 if (res->beacon_interval &&
9049 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval))
9050 goto nla_put_failure;
9051 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) ||
9052 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) ||
942ba88b
TP
9053 nla_put_u32(msg, NL80211_BSS_FREQUENCY_OFFSET,
9054 res->channel->freq_offset) ||
dcd6eac1 9055 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) ||
9360ffd1
DM
9056 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO,
9057 jiffies_to_msecs(jiffies - intbss->ts)))
9058 goto nla_put_failure;
2a519311 9059
1d76250b
AS
9060 if (intbss->parent_tsf &&
9061 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF,
9062 intbss->parent_tsf, NL80211_BSS_PAD) ||
9063 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN,
9064 intbss->parent_bssid)))
9065 goto nla_put_failure;
9066
6e19bc4b 9067 if (intbss->ts_boottime &&
2dad624e
ND
9068 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME,
9069 intbss->ts_boottime, NL80211_BSS_PAD))
6e19bc4b
DS
9070 goto nla_put_failure;
9071
983dafaa
SD
9072 if (!nl80211_put_signal(msg, intbss->pub.chains,
9073 intbss->pub.chain_signal,
9074 NL80211_BSS_CHAIN_SIGNAL))
9075 goto nla_put_failure;
9076
77965c97 9077 switch (rdev->wiphy.signal_type) {
2a519311 9078 case CFG80211_SIGNAL_TYPE_MBM:
9360ffd1
DM
9079 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal))
9080 goto nla_put_failure;
2a519311
JB
9081 break;
9082 case CFG80211_SIGNAL_TYPE_UNSPEC:
9360ffd1
DM
9083 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal))
9084 goto nla_put_failure;
2a519311
JB
9085 break;
9086 default:
9087 break;
9088 }
9089
48ab905d 9090 switch (wdev->iftype) {
074ac8df 9091 case NL80211_IFTYPE_P2P_CLIENT:
48ab905d 9092 case NL80211_IFTYPE_STATION:
9360ffd1
DM
9093 if (intbss == wdev->current_bss &&
9094 nla_put_u32(msg, NL80211_BSS_STATUS,
9095 NL80211_BSS_STATUS_ASSOCIATED))
9096 goto nla_put_failure;
48ab905d
JB
9097 break;
9098 case NL80211_IFTYPE_ADHOC:
9360ffd1
DM
9099 if (intbss == wdev->current_bss &&
9100 nla_put_u32(msg, NL80211_BSS_STATUS,
9101 NL80211_BSS_STATUS_IBSS_JOINED))
9102 goto nla_put_failure;
48ab905d
JB
9103 break;
9104 default:
9105 break;
9106 }
9107
2a519311
JB
9108 nla_nest_end(msg, bss);
9109
053c095a
JB
9110 genlmsg_end(msg, hdr);
9111 return 0;
2a519311 9112
8cef2c9d
JB
9113 fail_unlock_rcu:
9114 rcu_read_unlock();
2a519311
JB
9115 nla_put_failure:
9116 genlmsg_cancel(msg, hdr);
9117 return -EMSGSIZE;
9118}
9119
97990a06 9120static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb)
2a519311 9121{
48ab905d 9122 struct cfg80211_registered_device *rdev;
2a519311 9123 struct cfg80211_internal_bss *scan;
48ab905d 9124 struct wireless_dev *wdev;
97990a06 9125 int start = cb->args[2], idx = 0;
2a519311
JB
9126 int err;
9127
ea90e0dc 9128 rtnl_lock();
5297c65c 9129 err = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
ea90e0dc
JB
9130 if (err) {
9131 rtnl_unlock();
67748893 9132 return err;
ea90e0dc 9133 }
2a519311 9134
48ab905d
JB
9135 wdev_lock(wdev);
9136 spin_lock_bh(&rdev->bss_lock);
d1e23c94
DK
9137
9138 /*
9139 * dump_scan will be called multiple times to break up the scan results
9140 * into multiple messages. It is unlikely that any more bss-es will be
9141 * expired after the first call, so only call only call this on the
9142 * first dump_scan invocation.
9143 */
9144 if (start == 0)
9145 cfg80211_bss_expire(rdev);
48ab905d 9146
9720bb3a
JB
9147 cb->seq = rdev->bss_generation;
9148
48ab905d 9149 list_for_each_entry(scan, &rdev->bss_list, list) {
2a519311
JB
9150 if (++idx <= start)
9151 continue;
9720bb3a 9152 if (nl80211_send_bss(skb, cb,
2a519311 9153 cb->nlh->nlmsg_seq, NLM_F_MULTI,
48ab905d 9154 rdev, wdev, scan) < 0) {
2a519311 9155 idx--;
67748893 9156 break;
2a519311
JB
9157 }
9158 }
9159
48ab905d
JB
9160 spin_unlock_bh(&rdev->bss_lock);
9161 wdev_unlock(wdev);
2a519311 9162
97990a06 9163 cb->args[2] = idx;
ea90e0dc 9164 rtnl_unlock();
2a519311 9165
67748893 9166 return skb->len;
2a519311
JB
9167}
9168
15e47304 9169static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq,
11f78ac3
JB
9170 int flags, struct net_device *dev,
9171 bool allow_radio_stats,
9172 struct survey_info *survey)
61fa713c
HS
9173{
9174 void *hdr;
9175 struct nlattr *infoattr;
9176
11f78ac3
JB
9177 /* skip radio stats if userspace didn't request them */
9178 if (!survey->channel && !allow_radio_stats)
9179 return 0;
9180
15e47304 9181 hdr = nl80211hdr_put(msg, portid, seq, flags,
61fa713c
HS
9182 NL80211_CMD_NEW_SURVEY_RESULTS);
9183 if (!hdr)
9184 return -ENOMEM;
9185
9360ffd1
DM
9186 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9187 goto nla_put_failure;
61fa713c 9188
ae0be8de 9189 infoattr = nla_nest_start_noflag(msg, NL80211_ATTR_SURVEY_INFO);
61fa713c
HS
9190 if (!infoattr)
9191 goto nla_put_failure;
9192
11f78ac3
JB
9193 if (survey->channel &&
9194 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY,
9360ffd1
DM
9195 survey->channel->center_freq))
9196 goto nla_put_failure;
9197
9198 if ((survey->filled & SURVEY_INFO_NOISE_DBM) &&
9199 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise))
9200 goto nla_put_failure;
9201 if ((survey->filled & SURVEY_INFO_IN_USE) &&
9202 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE))
9203 goto nla_put_failure;
4ed20beb 9204 if ((survey->filled & SURVEY_INFO_TIME) &&
2dad624e
ND
9205 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME,
9206 survey->time, NL80211_SURVEY_INFO_PAD))
9360ffd1 9207 goto nla_put_failure;
4ed20beb 9208 if ((survey->filled & SURVEY_INFO_TIME_BUSY) &&
2dad624e
ND
9209 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY,
9210 survey->time_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 9211 goto nla_put_failure;
4ed20beb 9212 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) &&
2dad624e
ND
9213 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY,
9214 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD))
9360ffd1 9215 goto nla_put_failure;
4ed20beb 9216 if ((survey->filled & SURVEY_INFO_TIME_RX) &&
2dad624e
ND
9217 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX,
9218 survey->time_rx, NL80211_SURVEY_INFO_PAD))
9360ffd1 9219 goto nla_put_failure;
4ed20beb 9220 if ((survey->filled & SURVEY_INFO_TIME_TX) &&
2dad624e
ND
9221 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX,
9222 survey->time_tx, NL80211_SURVEY_INFO_PAD))
9360ffd1 9223 goto nla_put_failure;
052536ab 9224 if ((survey->filled & SURVEY_INFO_TIME_SCAN) &&
2dad624e
ND
9225 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN,
9226 survey->time_scan, NL80211_SURVEY_INFO_PAD))
052536ab 9227 goto nla_put_failure;
c8cd6e7f
FF
9228 if ((survey->filled & SURVEY_INFO_TIME_BSS_RX) &&
9229 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BSS_RX,
9230 survey->time_bss_rx, NL80211_SURVEY_INFO_PAD))
9231 goto nla_put_failure;
61fa713c
HS
9232
9233 nla_nest_end(msg, infoattr);
9234
053c095a
JB
9235 genlmsg_end(msg, hdr);
9236 return 0;
61fa713c
HS
9237
9238 nla_put_failure:
9239 genlmsg_cancel(msg, hdr);
9240 return -EMSGSIZE;
9241}
9242
11f78ac3 9243static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb)
61fa713c 9244{
50508d94 9245 struct nlattr **attrbuf;
61fa713c 9246 struct survey_info survey;
1b8ec87a 9247 struct cfg80211_registered_device *rdev;
97990a06
JB
9248 struct wireless_dev *wdev;
9249 int survey_idx = cb->args[2];
61fa713c 9250 int res;
11f78ac3 9251 bool radio_stats;
61fa713c 9252
50508d94
JB
9253 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf), GFP_KERNEL);
9254 if (!attrbuf)
9255 return -ENOMEM;
9256
ea90e0dc 9257 rtnl_lock();
5297c65c 9258 res = nl80211_prepare_wdev_dump(cb, &rdev, &wdev);
67748893 9259 if (res)
ea90e0dc 9260 goto out_err;
61fa713c 9261
11f78ac3 9262 /* prepare_wdev_dump parsed the attributes */
c90c39da 9263 radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS];
11f78ac3 9264
97990a06
JB
9265 if (!wdev->netdev) {
9266 res = -EINVAL;
9267 goto out_err;
9268 }
9269
1b8ec87a 9270 if (!rdev->ops->dump_survey) {
61fa713c
HS
9271 res = -EOPNOTSUPP;
9272 goto out_err;
9273 }
9274
9275 while (1) {
1b8ec87a 9276 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey);
61fa713c
HS
9277 if (res == -ENOENT)
9278 break;
9279 if (res)
9280 goto out_err;
9281
11f78ac3
JB
9282 /* don't send disabled channels, but do send non-channel data */
9283 if (survey.channel &&
9284 survey.channel->flags & IEEE80211_CHAN_DISABLED) {
180cdc79
LR
9285 survey_idx++;
9286 continue;
9287 }
9288
61fa713c 9289 if (nl80211_send_survey(skb,
15e47304 9290 NETLINK_CB(cb->skb).portid,
61fa713c 9291 cb->nlh->nlmsg_seq, NLM_F_MULTI,
11f78ac3 9292 wdev->netdev, radio_stats, &survey) < 0)
61fa713c
HS
9293 goto out;
9294 survey_idx++;
9295 }
9296
9297 out:
97990a06 9298 cb->args[2] = survey_idx;
61fa713c
HS
9299 res = skb->len;
9300 out_err:
50508d94 9301 kfree(attrbuf);
ea90e0dc 9302 rtnl_unlock();
61fa713c
HS
9303 return res;
9304}
9305
b23aa676
SO
9306static bool nl80211_valid_wpa_versions(u32 wpa_versions)
9307{
9308 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
cc3e14c2
CHH
9309 NL80211_WPA_VERSION_2 |
9310 NL80211_WPA_VERSION_3));
b23aa676
SO
9311}
9312
636a5d36
JM
9313static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
9314{
4c476991
JB
9315 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9316 struct net_device *dev = info->user_ptr[1];
19957bb3 9317 struct ieee80211_channel *chan;
11b6b5a4
JM
9318 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL;
9319 int err, ssid_len, ie_len = 0, auth_data_len = 0;
19957bb3 9320 enum nl80211_auth_type auth_type;
fffd0934 9321 struct key_parse key;
d5cdfacb 9322 bool local_state_change;
942ba88b 9323 u32 freq;
636a5d36 9324
f4a11bb0
JB
9325 if (!info->attrs[NL80211_ATTR_MAC])
9326 return -EINVAL;
9327
1778092e
JM
9328 if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
9329 return -EINVAL;
9330
19957bb3
JB
9331 if (!info->attrs[NL80211_ATTR_SSID])
9332 return -EINVAL;
9333
9334 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
9335 return -EINVAL;
9336
fffd0934
JB
9337 err = nl80211_parse_key(info, &key);
9338 if (err)
9339 return err;
9340
9341 if (key.idx >= 0) {
e31b8213
JB
9342 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
9343 return -EINVAL;
fffd0934
JB
9344 if (!key.p.key || !key.p.key_len)
9345 return -EINVAL;
9346 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
9347 key.p.key_len != WLAN_KEY_LEN_WEP40) &&
9348 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
9349 key.p.key_len != WLAN_KEY_LEN_WEP104))
9350 return -EINVAL;
b6b5555b 9351 if (key.idx > 3)
fffd0934
JB
9352 return -EINVAL;
9353 } else {
9354 key.p.key_len = 0;
9355 key.p.key = NULL;
9356 }
9357
afea0b7a
JB
9358 if (key.idx >= 0) {
9359 int i;
9360 bool ok = false;
7a087e74 9361
afea0b7a
JB
9362 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
9363 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
9364 ok = true;
9365 break;
9366 }
9367 }
4c476991
JB
9368 if (!ok)
9369 return -EINVAL;
afea0b7a
JB
9370 }
9371
4c476991
JB
9372 if (!rdev->ops->auth)
9373 return -EOPNOTSUPP;
636a5d36 9374
074ac8df 9375 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9376 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9377 return -EOPNOTSUPP;
eec60b03 9378
19957bb3 9379 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
942ba88b
TP
9380 freq = MHZ_TO_KHZ(nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
9381 if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
9382 freq +=
9383 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
9384
9385 chan = nl80211_get_valid_chan(&rdev->wiphy, freq);
664834de 9386 if (!chan)
4c476991 9387 return -EINVAL;
636a5d36 9388
19957bb3
JB
9389 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9390 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
9391
9392 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
9393 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9394 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9395 }
9396
19957bb3 9397 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e 9398 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE))
4c476991 9399 return -EINVAL;
636a5d36 9400
63181060
JM
9401 if ((auth_type == NL80211_AUTHTYPE_SAE ||
9402 auth_type == NL80211_AUTHTYPE_FILS_SK ||
9403 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS ||
9404 auth_type == NL80211_AUTHTYPE_FILS_PK) &&
11b6b5a4 9405 !info->attrs[NL80211_ATTR_AUTH_DATA])
e39e5b5e
JM
9406 return -EINVAL;
9407
11b6b5a4 9408 if (info->attrs[NL80211_ATTR_AUTH_DATA]) {
63181060
JM
9409 if (auth_type != NL80211_AUTHTYPE_SAE &&
9410 auth_type != NL80211_AUTHTYPE_FILS_SK &&
9411 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS &&
9412 auth_type != NL80211_AUTHTYPE_FILS_PK)
e39e5b5e 9413 return -EINVAL;
11b6b5a4
JM
9414 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]);
9415 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]);
e39e5b5e
JM
9416 }
9417
d5cdfacb
JM
9418 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
9419
95de817b
JB
9420 /*
9421 * Since we no longer track auth state, ignore
9422 * requests to only change local state.
9423 */
9424 if (local_state_change)
9425 return 0;
9426
91bf9b26
JB
9427 wdev_lock(dev->ieee80211_ptr);
9428 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
9429 ssid, ssid_len, ie, ie_len,
9430 key.p.key, key.p.key_len, key.idx,
11b6b5a4 9431 auth_data, auth_data_len);
91bf9b26
JB
9432 wdev_unlock(dev->ieee80211_ptr);
9433 return err;
636a5d36
JM
9434}
9435
64bf3d4b
DK
9436static int validate_pae_over_nl80211(struct cfg80211_registered_device *rdev,
9437 struct genl_info *info)
9438{
9439 if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
9440 GENL_SET_ERR_MSG(info, "SOCKET_OWNER not set");
9441 return -EINVAL;
9442 }
9443
9444 if (!rdev->ops->tx_control_port ||
9445 !wiphy_ext_feature_isset(&rdev->wiphy,
9446 NL80211_EXT_FEATURE_CONTROL_PORT_OVER_NL80211))
9447 return -EOPNOTSUPP;
9448
9449 return 0;
9450}
9451
c0692b8f
JB
9452static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
9453 struct genl_info *info,
3dc27d25
JB
9454 struct cfg80211_crypto_settings *settings,
9455 int cipher_limit)
b23aa676 9456{
c0b2bbd8
JB
9457 memset(settings, 0, sizeof(*settings));
9458
b23aa676
SO
9459 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
9460
c0692b8f
JB
9461 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
9462 u16 proto;
7a087e74 9463
c0692b8f
JB
9464 proto = nla_get_u16(
9465 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
9466 settings->control_port_ethertype = cpu_to_be16(proto);
9467 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
9468 proto != ETH_P_PAE)
9469 return -EINVAL;
9470 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
9471 settings->control_port_no_encrypt = true;
9472 } else
9473 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
9474
64bf3d4b
DK
9475 if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
9476 int r = validate_pae_over_nl80211(rdev, info);
9477
9478 if (r < 0)
9479 return r;
9480
9481 settings->control_port_over_nl80211 = true;
7f3f96ce
MT
9482
9483 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_PREAUTH])
9484 settings->control_port_no_preauth = true;
64bf3d4b
DK
9485 }
9486
b23aa676
SO
9487 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
9488 void *data;
9489 int len, i;
9490
9491 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
9492 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
9493 settings->n_ciphers_pairwise = len / sizeof(u32);
9494
9495 if (len % sizeof(u32))
9496 return -EINVAL;
9497
3dc27d25 9498 if (settings->n_ciphers_pairwise > cipher_limit)
b23aa676
SO
9499 return -EINVAL;
9500
9501 memcpy(settings->ciphers_pairwise, data, len);
9502
9503 for (i = 0; i < settings->n_ciphers_pairwise; i++)
38ba3c57
JM
9504 if (!cfg80211_supported_cipher_suite(
9505 &rdev->wiphy,
b23aa676
SO
9506 settings->ciphers_pairwise[i]))
9507 return -EINVAL;
9508 }
9509
9510 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
9511 settings->cipher_group =
9512 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
38ba3c57
JM
9513 if (!cfg80211_supported_cipher_suite(&rdev->wiphy,
9514 settings->cipher_group))
b23aa676
SO
9515 return -EINVAL;
9516 }
9517
9518 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
9519 settings->wpa_versions =
9520 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
9521 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
9522 return -EINVAL;
9523 }
9524
9525 if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
9526 void *data;
6d30240e 9527 int len;
b23aa676
SO
9528
9529 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
9530 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
9531 settings->n_akm_suites = len / sizeof(u32);
9532
9533 if (len % sizeof(u32))
9534 return -EINVAL;
9535
1b9ca027
JM
9536 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES)
9537 return -EINVAL;
9538
b23aa676 9539 memcpy(settings->akm_suites, data, len);
b23aa676
SO
9540 }
9541
91b5ab62
EP
9542 if (info->attrs[NL80211_ATTR_PMK]) {
9543 if (nla_len(info->attrs[NL80211_ATTR_PMK]) != WLAN_PMK_LEN)
9544 return -EINVAL;
9545 if (!wiphy_ext_feature_isset(&rdev->wiphy,
f9662274
CHH
9546 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_PSK) &&
9547 !wiphy_ext_feature_isset(&rdev->wiphy,
9548 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_AP_PSK))
91b5ab62
EP
9549 return -EINVAL;
9550 settings->psk = nla_data(info->attrs[NL80211_ATTR_PMK]);
9551 }
9552
26f7044e
CHH
9553 if (info->attrs[NL80211_ATTR_SAE_PASSWORD]) {
9554 if (!wiphy_ext_feature_isset(&rdev->wiphy,
9555 NL80211_EXT_FEATURE_SAE_OFFLOAD))
9556 return -EINVAL;
9557 settings->sae_pwd =
9558 nla_data(info->attrs[NL80211_ATTR_SAE_PASSWORD]);
9559 settings->sae_pwd_len =
9560 nla_len(info->attrs[NL80211_ATTR_SAE_PASSWORD]);
9561 }
9562
b23aa676
SO
9563 return 0;
9564}
9565
636a5d36
JM
9566static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
9567{
4c476991
JB
9568 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9569 struct net_device *dev = info->user_ptr[1];
f444de05 9570 struct ieee80211_channel *chan;
f62fab73
JB
9571 struct cfg80211_assoc_request req = {};
9572 const u8 *bssid, *ssid;
9573 int err, ssid_len = 0;
942ba88b 9574 u32 freq;
636a5d36 9575
bad29297
AZ
9576 if (dev->ieee80211_ptr->conn_owner_nlportid &&
9577 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
9578 return -EPERM;
9579
f4a11bb0 9580 if (!info->attrs[NL80211_ATTR_MAC] ||
19957bb3
JB
9581 !info->attrs[NL80211_ATTR_SSID] ||
9582 !info->attrs[NL80211_ATTR_WIPHY_FREQ])
f4a11bb0
JB
9583 return -EINVAL;
9584
4c476991
JB
9585 if (!rdev->ops->assoc)
9586 return -EOPNOTSUPP;
636a5d36 9587
074ac8df 9588 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9589 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9590 return -EOPNOTSUPP;
eec60b03 9591
19957bb3 9592 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 9593
942ba88b
TP
9594 freq = MHZ_TO_KHZ(nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
9595 if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
9596 freq +=
9597 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
9598 chan = nl80211_get_valid_chan(&rdev->wiphy, freq);
664834de 9599 if (!chan)
4c476991 9600 return -EINVAL;
636a5d36 9601
19957bb3
JB
9602 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9603 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
636a5d36
JM
9604
9605 if (info->attrs[NL80211_ATTR_IE]) {
f62fab73
JB
9606 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9607 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9608 }
9609
dc6382ce 9610 if (info->attrs[NL80211_ATTR_USE_MFP]) {
4f5dadce 9611 enum nl80211_mfp mfp =
dc6382ce 9612 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
4f5dadce 9613 if (mfp == NL80211_MFP_REQUIRED)
f62fab73 9614 req.use_mfp = true;
4c476991
JB
9615 else if (mfp != NL80211_MFP_NO)
9616 return -EINVAL;
dc6382ce
JM
9617 }
9618
3e5d7649 9619 if (info->attrs[NL80211_ATTR_PREV_BSSID])
f62fab73 9620 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3e5d7649 9621
7e7c8926 9622 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
f62fab73 9623 req.flags |= ASSOC_REQ_DISABLE_HT;
7e7c8926
BG
9624
9625 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
f62fab73
JB
9626 memcpy(&req.ht_capa_mask,
9627 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
9628 sizeof(req.ht_capa_mask));
7e7c8926
BG
9629
9630 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
f62fab73 9631 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
7e7c8926 9632 return -EINVAL;
f62fab73
JB
9633 memcpy(&req.ht_capa,
9634 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
9635 sizeof(req.ht_capa));
7e7c8926
BG
9636 }
9637
ee2aca34 9638 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
f62fab73 9639 req.flags |= ASSOC_REQ_DISABLE_VHT;
ee2aca34
JB
9640
9641 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
f62fab73
JB
9642 memcpy(&req.vht_capa_mask,
9643 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
9644 sizeof(req.vht_capa_mask));
ee2aca34
JB
9645
9646 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
f62fab73 9647 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
ee2aca34 9648 return -EINVAL;
f62fab73
JB
9649 memcpy(&req.vht_capa,
9650 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
9651 sizeof(req.vht_capa));
ee2aca34
JB
9652 }
9653
bab5ab7d 9654 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
9655 if (!((rdev->wiphy.features &
9656 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
9657 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
9658 !wiphy_ext_feature_isset(&rdev->wiphy,
9659 NL80211_EXT_FEATURE_RRM))
bab5ab7d
AK
9660 return -EINVAL;
9661 req.flags |= ASSOC_REQ_USE_RRM;
9662 }
9663
348bd456
JM
9664 if (info->attrs[NL80211_ATTR_FILS_KEK]) {
9665 req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]);
9666 req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]);
9667 if (!info->attrs[NL80211_ATTR_FILS_NONCES])
9668 return -EINVAL;
9669 req.fils_nonces =
9670 nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]);
9671 }
9672
f62fab73 9673 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1);
91bf9b26
JB
9674 if (!err) {
9675 wdev_lock(dev->ieee80211_ptr);
bd2522b1 9676
f62fab73
JB
9677 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid,
9678 ssid, ssid_len, &req);
bd2522b1
AZ
9679
9680 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
9681 dev->ieee80211_ptr->conn_owner_nlportid =
9682 info->snd_portid;
9683 memcpy(dev->ieee80211_ptr->disconnect_bssid,
9684 bssid, ETH_ALEN);
9685 }
9686
91bf9b26
JB
9687 wdev_unlock(dev->ieee80211_ptr);
9688 }
636a5d36 9689
636a5d36
JM
9690 return err;
9691}
9692
9693static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
9694{
4c476991
JB
9695 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9696 struct net_device *dev = info->user_ptr[1];
19957bb3 9697 const u8 *ie = NULL, *bssid;
91bf9b26 9698 int ie_len = 0, err;
19957bb3 9699 u16 reason_code;
d5cdfacb 9700 bool local_state_change;
636a5d36 9701
bad29297
AZ
9702 if (dev->ieee80211_ptr->conn_owner_nlportid &&
9703 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
9704 return -EPERM;
9705
f4a11bb0
JB
9706 if (!info->attrs[NL80211_ATTR_MAC])
9707 return -EINVAL;
9708
9709 if (!info->attrs[NL80211_ATTR_REASON_CODE])
9710 return -EINVAL;
9711
4c476991
JB
9712 if (!rdev->ops->deauth)
9713 return -EOPNOTSUPP;
636a5d36 9714
074ac8df 9715 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9716 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9717 return -EOPNOTSUPP;
eec60b03 9718
19957bb3 9719 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 9720
19957bb3
JB
9721 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
9722 if (reason_code == 0) {
f4a11bb0 9723 /* Reason Code 0 is reserved */
4c476991 9724 return -EINVAL;
255e737e 9725 }
636a5d36
JM
9726
9727 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
9728 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9729 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9730 }
9731
d5cdfacb
JM
9732 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
9733
91bf9b26
JB
9734 wdev_lock(dev->ieee80211_ptr);
9735 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
9736 local_state_change);
9737 wdev_unlock(dev->ieee80211_ptr);
9738 return err;
636a5d36
JM
9739}
9740
9741static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
9742{
4c476991
JB
9743 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9744 struct net_device *dev = info->user_ptr[1];
19957bb3 9745 const u8 *ie = NULL, *bssid;
91bf9b26 9746 int ie_len = 0, err;
19957bb3 9747 u16 reason_code;
d5cdfacb 9748 bool local_state_change;
636a5d36 9749
bad29297
AZ
9750 if (dev->ieee80211_ptr->conn_owner_nlportid &&
9751 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
9752 return -EPERM;
9753
f4a11bb0
JB
9754 if (!info->attrs[NL80211_ATTR_MAC])
9755 return -EINVAL;
9756
9757 if (!info->attrs[NL80211_ATTR_REASON_CODE])
9758 return -EINVAL;
9759
4c476991
JB
9760 if (!rdev->ops->disassoc)
9761 return -EOPNOTSUPP;
636a5d36 9762
074ac8df 9763 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
9764 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
9765 return -EOPNOTSUPP;
eec60b03 9766
19957bb3 9767 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
636a5d36 9768
19957bb3
JB
9769 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
9770 if (reason_code == 0) {
f4a11bb0 9771 /* Reason Code 0 is reserved */
4c476991 9772 return -EINVAL;
255e737e 9773 }
636a5d36
JM
9774
9775 if (info->attrs[NL80211_ATTR_IE]) {
19957bb3
JB
9776 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9777 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
636a5d36
JM
9778 }
9779
d5cdfacb
JM
9780 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
9781
91bf9b26
JB
9782 wdev_lock(dev->ieee80211_ptr);
9783 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
9784 local_state_change);
9785 wdev_unlock(dev->ieee80211_ptr);
9786 return err;
636a5d36
JM
9787}
9788
dd5b4cc7
FF
9789static bool
9790nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
57fbcce3 9791 int mcast_rate[NUM_NL80211_BANDS],
dd5b4cc7
FF
9792 int rateval)
9793{
9794 struct wiphy *wiphy = &rdev->wiphy;
9795 bool found = false;
9796 int band, i;
9797
57fbcce3 9798 for (band = 0; band < NUM_NL80211_BANDS; band++) {
dd5b4cc7
FF
9799 struct ieee80211_supported_band *sband;
9800
9801 sband = wiphy->bands[band];
9802 if (!sband)
9803 continue;
9804
9805 for (i = 0; i < sband->n_bitrates; i++) {
9806 if (sband->bitrates[i].bitrate == rateval) {
9807 mcast_rate[band] = i + 1;
9808 found = true;
9809 break;
9810 }
9811 }
9812 }
9813
9814 return found;
9815}
9816
04a773ad
JB
9817static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
9818{
4c476991
JB
9819 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9820 struct net_device *dev = info->user_ptr[1];
04a773ad
JB
9821 struct cfg80211_ibss_params ibss;
9822 struct wiphy *wiphy;
fffd0934 9823 struct cfg80211_cached_keys *connkeys = NULL;
04a773ad
JB
9824 int err;
9825
8e30bc55
JB
9826 memset(&ibss, 0, sizeof(ibss));
9827
683b6d3b 9828 if (!info->attrs[NL80211_ATTR_SSID] ||
04a773ad
JB
9829 !nla_len(info->attrs[NL80211_ATTR_SSID]))
9830 return -EINVAL;
9831
8e30bc55
JB
9832 ibss.beacon_interval = 100;
9833
12d20fc9 9834 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL])
8e30bc55
JB
9835 ibss.beacon_interval =
9836 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 9837
0c317a02
PK
9838 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC,
9839 ibss.beacon_interval);
12d20fc9
PK
9840 if (err)
9841 return err;
8e30bc55 9842
4c476991
JB
9843 if (!rdev->ops->join_ibss)
9844 return -EOPNOTSUPP;
04a773ad 9845
4c476991
JB
9846 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
9847 return -EOPNOTSUPP;
04a773ad 9848
79c97e97 9849 wiphy = &rdev->wiphy;
04a773ad 9850
39193498 9851 if (info->attrs[NL80211_ATTR_MAC]) {
04a773ad 9852 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
39193498
JB
9853
9854 if (!is_valid_ether_addr(ibss.bssid))
9855 return -EINVAL;
9856 }
04a773ad
JB
9857 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
9858 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
9859
9860 if (info->attrs[NL80211_ATTR_IE]) {
9861 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
9862 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
9863 }
9864
683b6d3b
JB
9865 err = nl80211_parse_chandef(rdev, info, &ibss.chandef);
9866 if (err)
9867 return err;
04a773ad 9868
174e0cd2
IP
9869 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef,
9870 NL80211_IFTYPE_ADHOC))
54858ee5
AS
9871 return -EINVAL;
9872
2f301ab2 9873 switch (ibss.chandef.width) {
bf372645
SW
9874 case NL80211_CHAN_WIDTH_5:
9875 case NL80211_CHAN_WIDTH_10:
2f301ab2
SW
9876 case NL80211_CHAN_WIDTH_20_NOHT:
9877 break;
9878 case NL80211_CHAN_WIDTH_20:
9879 case NL80211_CHAN_WIDTH_40:
ffc11991
JD
9880 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
9881 return -EINVAL;
9882 break;
9883 case NL80211_CHAN_WIDTH_80:
9884 case NL80211_CHAN_WIDTH_80P80:
9885 case NL80211_CHAN_WIDTH_160:
9886 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS))
9887 return -EINVAL;
9888 if (!wiphy_ext_feature_isset(&rdev->wiphy,
9889 NL80211_EXT_FEATURE_VHT_IBSS))
9890 return -EINVAL;
9891 break;
2f301ab2 9892 default:
c04d6150 9893 return -EINVAL;
2f301ab2 9894 }
db9c64cf 9895
04a773ad 9896 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
fffd0934
JB
9897 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
9898
fbd2c8dc
TP
9899 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
9900 u8 *rates =
9901 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
9902 int n_rates =
9903 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
9904 struct ieee80211_supported_band *sband =
683b6d3b 9905 wiphy->bands[ibss.chandef.chan->band];
fbd2c8dc 9906
34850ab2
JB
9907 err = ieee80211_get_ratemask(sband, rates, n_rates,
9908 &ibss.basic_rates);
9909 if (err)
9910 return err;
fbd2c8dc 9911 }
dd5b4cc7 9912
803768f5
SW
9913 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
9914 memcpy(&ibss.ht_capa_mask,
9915 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
9916 sizeof(ibss.ht_capa_mask));
9917
9918 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
9919 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
9920 return -EINVAL;
9921 memcpy(&ibss.ht_capa,
9922 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
9923 sizeof(ibss.ht_capa));
9924 }
9925
dd5b4cc7
FF
9926 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
9927 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
9928 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
9929 return -EINVAL;
fbd2c8dc 9930
4c476991 9931 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
de7044ee
SM
9932 bool no_ht = false;
9933
768075eb 9934 connkeys = nl80211_parse_connkeys(rdev, info, &no_ht);
4c476991
JB
9935 if (IS_ERR(connkeys))
9936 return PTR_ERR(connkeys);
de7044ee 9937
3d9d1d66
JB
9938 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) &&
9939 no_ht) {
453431a5 9940 kfree_sensitive(connkeys);
de7044ee
SM
9941 return -EINVAL;
9942 }
4c476991 9943 }
04a773ad 9944
267335d6
AQ
9945 ibss.control_port =
9946 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]);
9947
c3bfe1f6
DK
9948 if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
9949 int r = validate_pae_over_nl80211(rdev, info);
9950
d350a0f4 9951 if (r < 0) {
453431a5 9952 kfree_sensitive(connkeys);
c3bfe1f6 9953 return r;
d350a0f4 9954 }
c3bfe1f6
DK
9955
9956 ibss.control_port_over_nl80211 = true;
9957 }
9958
5336fa88
SW
9959 ibss.userspace_handles_dfs =
9960 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
9961
f8d16d3e
DK
9962 wdev_lock(dev->ieee80211_ptr);
9963 err = __cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
fffd0934 9964 if (err)
453431a5 9965 kfree_sensitive(connkeys);
f8d16d3e
DK
9966 else if (info->attrs[NL80211_ATTR_SOCKET_OWNER])
9967 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
9968 wdev_unlock(dev->ieee80211_ptr);
9969
04a773ad
JB
9970 return err;
9971}
9972
9973static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
9974{
4c476991
JB
9975 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9976 struct net_device *dev = info->user_ptr[1];
04a773ad 9977
4c476991
JB
9978 if (!rdev->ops->leave_ibss)
9979 return -EOPNOTSUPP;
04a773ad 9980
4c476991
JB
9981 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
9982 return -EOPNOTSUPP;
04a773ad 9983
4c476991 9984 return cfg80211_leave_ibss(rdev, dev, false);
04a773ad
JB
9985}
9986
f4e583c8
AQ
9987static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info)
9988{
9989 struct cfg80211_registered_device *rdev = info->user_ptr[0];
9990 struct net_device *dev = info->user_ptr[1];
57fbcce3 9991 int mcast_rate[NUM_NL80211_BANDS];
f4e583c8
AQ
9992 u32 nla_rate;
9993 int err;
9994
9995 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
876dc930
BVB
9996 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
9997 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB)
f4e583c8
AQ
9998 return -EOPNOTSUPP;
9999
10000 if (!rdev->ops->set_mcast_rate)
10001 return -EOPNOTSUPP;
10002
10003 memset(mcast_rate, 0, sizeof(mcast_rate));
10004
10005 if (!info->attrs[NL80211_ATTR_MCAST_RATE])
10006 return -EINVAL;
10007
10008 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]);
10009 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate))
10010 return -EINVAL;
10011
a1056b1b 10012 err = rdev_set_mcast_rate(rdev, dev, mcast_rate);
f4e583c8
AQ
10013
10014 return err;
10015}
10016
ad7e718c
JB
10017static struct sk_buff *
10018__cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev,
6c09e791
AK
10019 struct wireless_dev *wdev, int approxlen,
10020 u32 portid, u32 seq, enum nl80211_commands cmd,
567ffc35
JB
10021 enum nl80211_attrs attr,
10022 const struct nl80211_vendor_cmd_info *info,
10023 gfp_t gfp)
ad7e718c
JB
10024{
10025 struct sk_buff *skb;
10026 void *hdr;
10027 struct nlattr *data;
10028
10029 skb = nlmsg_new(approxlen + 100, gfp);
10030 if (!skb)
10031 return NULL;
10032
10033 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd);
10034 if (!hdr) {
10035 kfree_skb(skb);
10036 return NULL;
10037 }
10038
10039 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
10040 goto nla_put_failure;
567ffc35
JB
10041
10042 if (info) {
10043 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID,
10044 info->vendor_id))
10045 goto nla_put_failure;
10046 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD,
10047 info->subcmd))
10048 goto nla_put_failure;
10049 }
10050
6c09e791 10051 if (wdev) {
2dad624e
ND
10052 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
10053 wdev_id(wdev), NL80211_ATTR_PAD))
6c09e791
AK
10054 goto nla_put_failure;
10055 if (wdev->netdev &&
10056 nla_put_u32(skb, NL80211_ATTR_IFINDEX,
10057 wdev->netdev->ifindex))
10058 goto nla_put_failure;
10059 }
10060
ae0be8de 10061 data = nla_nest_start_noflag(skb, attr);
76e1fb4b
JB
10062 if (!data)
10063 goto nla_put_failure;
ad7e718c
JB
10064
10065 ((void **)skb->cb)[0] = rdev;
10066 ((void **)skb->cb)[1] = hdr;
10067 ((void **)skb->cb)[2] = data;
10068
10069 return skb;
10070
10071 nla_put_failure:
10072 kfree_skb(skb);
10073 return NULL;
10074}
f4e583c8 10075
e03ad6ea 10076struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy,
6c09e791 10077 struct wireless_dev *wdev,
e03ad6ea
JB
10078 enum nl80211_commands cmd,
10079 enum nl80211_attrs attr,
55c1fdf0 10080 unsigned int portid,
e03ad6ea
JB
10081 int vendor_event_idx,
10082 int approxlen, gfp_t gfp)
10083{
f26cbf40 10084 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
e03ad6ea
JB
10085 const struct nl80211_vendor_cmd_info *info;
10086
10087 switch (cmd) {
10088 case NL80211_CMD_TESTMODE:
10089 if (WARN_ON(vendor_event_idx != -1))
10090 return NULL;
10091 info = NULL;
10092 break;
10093 case NL80211_CMD_VENDOR:
10094 if (WARN_ON(vendor_event_idx < 0 ||
10095 vendor_event_idx >= wiphy->n_vendor_events))
10096 return NULL;
10097 info = &wiphy->vendor_events[vendor_event_idx];
10098 break;
10099 default:
10100 WARN_ON(1);
10101 return NULL;
10102 }
10103
55c1fdf0 10104 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, portid, 0,
e03ad6ea
JB
10105 cmd, attr, info, gfp);
10106}
10107EXPORT_SYMBOL(__cfg80211_alloc_event_skb);
10108
10109void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp)
10110{
10111 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
10112 void *hdr = ((void **)skb->cb)[1];
55c1fdf0 10113 struct nlmsghdr *nlhdr = nlmsg_hdr(skb);
e03ad6ea
JB
10114 struct nlattr *data = ((void **)skb->cb)[2];
10115 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE;
10116
bd8c78e7
JB
10117 /* clear CB data for netlink core to own from now on */
10118 memset(skb->cb, 0, sizeof(skb->cb));
10119
e03ad6ea
JB
10120 nla_nest_end(skb, data);
10121 genlmsg_end(skb, hdr);
10122
55c1fdf0
JB
10123 if (nlhdr->nlmsg_pid) {
10124 genlmsg_unicast(wiphy_net(&rdev->wiphy), skb,
10125 nlhdr->nlmsg_pid);
10126 } else {
10127 if (data->nla_type == NL80211_ATTR_VENDOR_DATA)
10128 mcgrp = NL80211_MCGRP_VENDOR;
e03ad6ea 10129
55c1fdf0
JB
10130 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
10131 skb, 0, mcgrp, gfp);
10132 }
e03ad6ea
JB
10133}
10134EXPORT_SYMBOL(__cfg80211_send_event_skb);
10135
aff89a9b 10136#ifdef CONFIG_NL80211_TESTMODE
aff89a9b
JB
10137static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
10138{
4c476991 10139 struct cfg80211_registered_device *rdev = info->user_ptr[0];
fc73f11f
DS
10140 struct wireless_dev *wdev =
10141 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
aff89a9b
JB
10142 int err;
10143
fc73f11f
DS
10144 if (!rdev->ops->testmode_cmd)
10145 return -EOPNOTSUPP;
10146
10147 if (IS_ERR(wdev)) {
10148 err = PTR_ERR(wdev);
10149 if (err != -EINVAL)
10150 return err;
10151 wdev = NULL;
10152 } else if (wdev->wiphy != &rdev->wiphy) {
10153 return -EINVAL;
10154 }
10155
aff89a9b
JB
10156 if (!info->attrs[NL80211_ATTR_TESTDATA])
10157 return -EINVAL;
10158
ad7e718c 10159 rdev->cur_cmd_info = info;
fc73f11f 10160 err = rdev_testmode_cmd(rdev, wdev,
aff89a9b
JB
10161 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
10162 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
ad7e718c 10163 rdev->cur_cmd_info = NULL;
aff89a9b 10164
aff89a9b
JB
10165 return err;
10166}
10167
71063f0e
WYG
10168static int nl80211_testmode_dump(struct sk_buff *skb,
10169 struct netlink_callback *cb)
10170{
00918d33 10171 struct cfg80211_registered_device *rdev;
50508d94 10172 struct nlattr **attrbuf = NULL;
71063f0e
WYG
10173 int err;
10174 long phy_idx;
10175 void *data = NULL;
10176 int data_len = 0;
10177
5fe231e8
JB
10178 rtnl_lock();
10179
71063f0e
WYG
10180 if (cb->args[0]) {
10181 /*
10182 * 0 is a valid index, but not valid for args[0],
10183 * so we need to offset by 1.
10184 */
10185 phy_idx = cb->args[0] - 1;
a4956dca
LC
10186
10187 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx);
10188 if (!rdev) {
10189 err = -ENOENT;
10190 goto out_err;
10191 }
71063f0e 10192 } else {
50508d94
JB
10193 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf),
10194 GFP_KERNEL);
10195 if (!attrbuf) {
10196 err = -ENOMEM;
10197 goto out_err;
10198 }
c90c39da 10199
8cb08174
JB
10200 err = nlmsg_parse_deprecated(cb->nlh,
10201 GENL_HDRLEN + nl80211_fam.hdrsize,
10202 attrbuf, nl80211_fam.maxattr,
10203 nl80211_policy, NULL);
71063f0e 10204 if (err)
5fe231e8 10205 goto out_err;
00918d33 10206
c90c39da 10207 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
2bd7e35d 10208 if (IS_ERR(rdev)) {
5fe231e8
JB
10209 err = PTR_ERR(rdev);
10210 goto out_err;
00918d33 10211 }
2bd7e35d 10212 phy_idx = rdev->wiphy_idx;
2bd7e35d 10213
c90c39da
JB
10214 if (attrbuf[NL80211_ATTR_TESTDATA])
10215 cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA];
71063f0e
WYG
10216 }
10217
10218 if (cb->args[1]) {
10219 data = nla_data((void *)cb->args[1]);
10220 data_len = nla_len((void *)cb->args[1]);
10221 }
10222
00918d33 10223 if (!rdev->ops->testmode_dump) {
71063f0e
WYG
10224 err = -EOPNOTSUPP;
10225 goto out_err;
10226 }
10227
10228 while (1) {
15e47304 10229 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
71063f0e
WYG
10230 cb->nlh->nlmsg_seq, NLM_F_MULTI,
10231 NL80211_CMD_TESTMODE);
10232 struct nlattr *tmdata;
10233
cb35fba3
DC
10234 if (!hdr)
10235 break;
10236
9360ffd1 10237 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) {
71063f0e
WYG
10238 genlmsg_cancel(skb, hdr);
10239 break;
10240 }
10241
ae0be8de 10242 tmdata = nla_nest_start_noflag(skb, NL80211_ATTR_TESTDATA);
71063f0e
WYG
10243 if (!tmdata) {
10244 genlmsg_cancel(skb, hdr);
10245 break;
10246 }
e35e4d28 10247 err = rdev_testmode_dump(rdev, skb, cb, data, data_len);
71063f0e
WYG
10248 nla_nest_end(skb, tmdata);
10249
10250 if (err == -ENOBUFS || err == -ENOENT) {
10251 genlmsg_cancel(skb, hdr);
10252 break;
10253 } else if (err) {
10254 genlmsg_cancel(skb, hdr);
10255 goto out_err;
10256 }
10257
10258 genlmsg_end(skb, hdr);
10259 }
10260
10261 err = skb->len;
10262 /* see above */
10263 cb->args[0] = phy_idx + 1;
10264 out_err:
50508d94 10265 kfree(attrbuf);
5fe231e8 10266 rtnl_unlock();
71063f0e
WYG
10267 return err;
10268}
aff89a9b
JB
10269#endif
10270
b23aa676
SO
10271static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
10272{
4c476991
JB
10273 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10274 struct net_device *dev = info->user_ptr[1];
b23aa676
SO
10275 struct cfg80211_connect_params connect;
10276 struct wiphy *wiphy;
fffd0934 10277 struct cfg80211_cached_keys *connkeys = NULL;
942ba88b 10278 u32 freq = 0;
b23aa676
SO
10279 int err;
10280
10281 memset(&connect, 0, sizeof(connect));
10282
b23aa676
SO
10283 if (!info->attrs[NL80211_ATTR_SSID] ||
10284 !nla_len(info->attrs[NL80211_ATTR_SSID]))
10285 return -EINVAL;
10286
10287 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
10288 connect.auth_type =
10289 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
e39e5b5e
JM
10290 if (!nl80211_valid_auth_type(rdev, connect.auth_type,
10291 NL80211_CMD_CONNECT))
b23aa676
SO
10292 return -EINVAL;
10293 } else
10294 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
10295
10296 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
10297
3a00df57
AS
10298 if (info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS] &&
10299 !wiphy_ext_feature_isset(&rdev->wiphy,
10300 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
10301 return -EINVAL;
10302 connect.want_1x = info->attrs[NL80211_ATTR_WANT_1X_4WAY_HS];
10303
c0692b8f 10304 err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3dc27d25 10305 NL80211_MAX_NR_CIPHER_SUITES);
b23aa676
SO
10306 if (err)
10307 return err;
b23aa676 10308
074ac8df 10309 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
10310 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
10311 return -EOPNOTSUPP;
b23aa676 10312
79c97e97 10313 wiphy = &rdev->wiphy;
b23aa676 10314
4486ea98
BS
10315 connect.bg_scan_period = -1;
10316 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] &&
10317 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) {
10318 connect.bg_scan_period =
10319 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]);
10320 }
10321
b23aa676
SO
10322 if (info->attrs[NL80211_ATTR_MAC])
10323 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
1df4a510
JM
10324 else if (info->attrs[NL80211_ATTR_MAC_HINT])
10325 connect.bssid_hint =
10326 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]);
b23aa676
SO
10327 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
10328 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
10329
10330 if (info->attrs[NL80211_ATTR_IE]) {
10331 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
10332 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
10333 }
10334
cee00a95
JM
10335 if (info->attrs[NL80211_ATTR_USE_MFP]) {
10336 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
65026002
EG
10337 if (connect.mfp == NL80211_MFP_OPTIONAL &&
10338 !wiphy_ext_feature_isset(&rdev->wiphy,
10339 NL80211_EXT_FEATURE_MFP_OPTIONAL))
10340 return -EOPNOTSUPP;
cee00a95
JM
10341 } else {
10342 connect.mfp = NL80211_MFP_NO;
10343 }
10344
ba6fbacf
JM
10345 if (info->attrs[NL80211_ATTR_PREV_BSSID])
10346 connect.prev_bssid =
10347 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
10348
942ba88b
TP
10349 if (info->attrs[NL80211_ATTR_WIPHY_FREQ])
10350 freq = MHZ_TO_KHZ(nla_get_u32(
10351 info->attrs[NL80211_ATTR_WIPHY_FREQ]));
10352 if (info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET])
10353 freq +=
10354 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_OFFSET]);
10355
10356 if (freq) {
10357 connect.channel = nl80211_get_valid_chan(wiphy, freq);
664834de 10358 if (!connect.channel)
1df4a510
JM
10359 return -EINVAL;
10360 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) {
942ba88b
TP
10361 freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]);
10362 freq = MHZ_TO_KHZ(freq);
10363 connect.channel_hint = nl80211_get_valid_chan(wiphy, freq);
664834de 10364 if (!connect.channel_hint)
4c476991 10365 return -EINVAL;
b23aa676
SO
10366 }
10367
2a38075c
AAL
10368 if (info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]) {
10369 connect.edmg.channels =
10370 nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_CHANNELS]);
10371
10372 if (info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG])
10373 connect.edmg.bw_config =
10374 nla_get_u8(info->attrs[NL80211_ATTR_WIPHY_EDMG_BW_CONFIG]);
10375 }
10376
fffd0934 10377 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
768075eb 10378 connkeys = nl80211_parse_connkeys(rdev, info, NULL);
4c476991
JB
10379 if (IS_ERR(connkeys))
10380 return PTR_ERR(connkeys);
fffd0934
JB
10381 }
10382
7e7c8926
BG
10383 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT]))
10384 connect.flags |= ASSOC_REQ_DISABLE_HT;
10385
10386 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK])
10387 memcpy(&connect.ht_capa_mask,
10388 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]),
10389 sizeof(connect.ht_capa_mask));
10390
10391 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) {
b4e4f47e 10392 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) {
453431a5 10393 kfree_sensitive(connkeys);
7e7c8926 10394 return -EINVAL;
b4e4f47e 10395 }
7e7c8926
BG
10396 memcpy(&connect.ht_capa,
10397 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]),
10398 sizeof(connect.ht_capa));
10399 }
10400
ee2aca34
JB
10401 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT]))
10402 connect.flags |= ASSOC_REQ_DISABLE_VHT;
10403
10404 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK])
10405 memcpy(&connect.vht_capa_mask,
10406 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]),
10407 sizeof(connect.vht_capa_mask));
10408
10409 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) {
10410 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) {
453431a5 10411 kfree_sensitive(connkeys);
ee2aca34
JB
10412 return -EINVAL;
10413 }
10414 memcpy(&connect.vht_capa,
10415 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]),
10416 sizeof(connect.vht_capa));
10417 }
10418
bab5ab7d 10419 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) {
0c9ca11b
BL
10420 if (!((rdev->wiphy.features &
10421 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) &&
10422 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) &&
10423 !wiphy_ext_feature_isset(&rdev->wiphy,
10424 NL80211_EXT_FEATURE_RRM)) {
453431a5 10425 kfree_sensitive(connkeys);
bab5ab7d 10426 return -EINVAL;
707554b4 10427 }
bab5ab7d
AK
10428 connect.flags |= ASSOC_REQ_USE_RRM;
10429 }
10430
34d50519 10431 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]);
57fbcce3 10432 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) {
453431a5 10433 kfree_sensitive(connkeys);
34d50519
LD
10434 return -EOPNOTSUPP;
10435 }
10436
38de03d2
AS
10437 if (info->attrs[NL80211_ATTR_BSS_SELECT]) {
10438 /* bss selection makes no sense if bssid is set */
10439 if (connect.bssid) {
453431a5 10440 kfree_sensitive(connkeys);
38de03d2
AS
10441 return -EINVAL;
10442 }
10443
10444 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT],
10445 wiphy, &connect.bss_select);
10446 if (err) {
453431a5 10447 kfree_sensitive(connkeys);
38de03d2
AS
10448 return err;
10449 }
10450 }
10451
a3caf744
VK
10452 if (wiphy_ext_feature_isset(&rdev->wiphy,
10453 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD) &&
10454 info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
10455 info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
10456 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
10457 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
10458 connect.fils_erp_username =
10459 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
10460 connect.fils_erp_username_len =
10461 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
10462 connect.fils_erp_realm =
10463 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
10464 connect.fils_erp_realm_len =
10465 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
10466 connect.fils_erp_next_seq_num =
10467 nla_get_u16(
10468 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
10469 connect.fils_erp_rrk =
10470 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
10471 connect.fils_erp_rrk_len =
10472 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
10473 } else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
10474 info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
10475 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
10476 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
453431a5 10477 kfree_sensitive(connkeys);
a3caf744
VK
10478 return -EINVAL;
10479 }
10480
40cbfa90
SD
10481 if (nla_get_flag(info->attrs[NL80211_ATTR_EXTERNAL_AUTH_SUPPORT])) {
10482 if (!info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
453431a5 10483 kfree_sensitive(connkeys);
40cbfa90
SD
10484 GENL_SET_ERR_MSG(info,
10485 "external auth requires connection ownership");
10486 return -EINVAL;
10487 }
10488 connect.flags |= CONNECT_REQ_EXTERNAL_AUTH_SUPPORT;
10489 }
10490
83739b03 10491 wdev_lock(dev->ieee80211_ptr);
bd2522b1 10492
4ce2bd9c
JM
10493 err = cfg80211_connect(rdev, dev, &connect, connkeys,
10494 connect.prev_bssid);
fffd0934 10495 if (err)
453431a5 10496 kfree_sensitive(connkeys);
bd2522b1
AZ
10497
10498 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER]) {
10499 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
10500 if (connect.bssid)
10501 memcpy(dev->ieee80211_ptr->disconnect_bssid,
10502 connect.bssid, ETH_ALEN);
10503 else
3b1648f1 10504 eth_zero_addr(dev->ieee80211_ptr->disconnect_bssid);
bd2522b1
AZ
10505 }
10506
10507 wdev_unlock(dev->ieee80211_ptr);
10508
b23aa676
SO
10509 return err;
10510}
10511
088e8df8 10512static int nl80211_update_connect_params(struct sk_buff *skb,
10513 struct genl_info *info)
10514{
10515 struct cfg80211_connect_params connect = {};
10516 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10517 struct net_device *dev = info->user_ptr[1];
10518 struct wireless_dev *wdev = dev->ieee80211_ptr;
7f9a3e15
VK
10519 bool fils_sk_offload;
10520 u32 auth_type;
088e8df8 10521 u32 changed = 0;
10522 int ret;
10523
10524 if (!rdev->ops->update_connect_params)
10525 return -EOPNOTSUPP;
10526
10527 if (info->attrs[NL80211_ATTR_IE]) {
088e8df8 10528 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
10529 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
10530 changed |= UPDATE_ASSOC_IES;
10531 }
10532
7f9a3e15
VK
10533 fils_sk_offload = wiphy_ext_feature_isset(&rdev->wiphy,
10534 NL80211_EXT_FEATURE_FILS_SK_OFFLOAD);
10535
10536 /*
10537 * when driver supports fils-sk offload all attributes must be
10538 * provided. So the else covers "fils-sk-not-all" and
10539 * "no-fils-sk-any".
10540 */
10541 if (fils_sk_offload &&
10542 info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] &&
10543 info->attrs[NL80211_ATTR_FILS_ERP_REALM] &&
10544 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] &&
10545 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
10546 connect.fils_erp_username =
10547 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
10548 connect.fils_erp_username_len =
10549 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_USERNAME]);
10550 connect.fils_erp_realm =
10551 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
10552 connect.fils_erp_realm_len =
10553 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_REALM]);
10554 connect.fils_erp_next_seq_num =
10555 nla_get_u16(
10556 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM]);
10557 connect.fils_erp_rrk =
10558 nla_data(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
10559 connect.fils_erp_rrk_len =
10560 nla_len(info->attrs[NL80211_ATTR_FILS_ERP_RRK]);
10561 changed |= UPDATE_FILS_ERP_INFO;
10562 } else if (info->attrs[NL80211_ATTR_FILS_ERP_USERNAME] ||
10563 info->attrs[NL80211_ATTR_FILS_ERP_REALM] ||
10564 info->attrs[NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM] ||
10565 info->attrs[NL80211_ATTR_FILS_ERP_RRK]) {
10566 return -EINVAL;
10567 }
10568
10569 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
10570 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
10571 if (!nl80211_valid_auth_type(rdev, auth_type,
10572 NL80211_CMD_CONNECT))
10573 return -EINVAL;
10574
10575 if (auth_type == NL80211_AUTHTYPE_FILS_SK &&
10576 fils_sk_offload && !(changed & UPDATE_FILS_ERP_INFO))
10577 return -EINVAL;
10578
10579 connect.auth_type = auth_type;
10580 changed |= UPDATE_AUTH_TYPE;
10581 }
10582
088e8df8 10583 wdev_lock(dev->ieee80211_ptr);
10584 if (!wdev->current_bss)
10585 ret = -ENOLINK;
10586 else
10587 ret = rdev_update_connect_params(rdev, dev, &connect, changed);
10588 wdev_unlock(dev->ieee80211_ptr);
10589
10590 return ret;
10591}
10592
b23aa676
SO
10593static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
10594{
4c476991
JB
10595 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10596 struct net_device *dev = info->user_ptr[1];
b23aa676 10597 u16 reason;
83739b03 10598 int ret;
b23aa676 10599
bad29297
AZ
10600 if (dev->ieee80211_ptr->conn_owner_nlportid &&
10601 dev->ieee80211_ptr->conn_owner_nlportid != info->snd_portid)
10602 return -EPERM;
10603
b23aa676
SO
10604 if (!info->attrs[NL80211_ATTR_REASON_CODE])
10605 reason = WLAN_REASON_DEAUTH_LEAVING;
10606 else
10607 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
10608
10609 if (reason == 0)
10610 return -EINVAL;
10611
074ac8df 10612 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
10613 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
10614 return -EOPNOTSUPP;
b23aa676 10615
83739b03
JB
10616 wdev_lock(dev->ieee80211_ptr);
10617 ret = cfg80211_disconnect(rdev, dev, reason, true);
10618 wdev_unlock(dev->ieee80211_ptr);
10619 return ret;
b23aa676
SO
10620}
10621
463d0183
JB
10622static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
10623{
4c476991 10624 struct cfg80211_registered_device *rdev = info->user_ptr[0];
463d0183
JB
10625 struct net *net;
10626 int err;
463d0183 10627
4b681c82
VK
10628 if (info->attrs[NL80211_ATTR_PID]) {
10629 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
10630
10631 net = get_net_ns_by_pid(pid);
10632 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) {
10633 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]);
463d0183 10634
4b681c82
VK
10635 net = get_net_ns_by_fd(fd);
10636 } else {
10637 return -EINVAL;
10638 }
463d0183 10639
4c476991
JB
10640 if (IS_ERR(net))
10641 return PTR_ERR(net);
463d0183
JB
10642
10643 err = 0;
10644
10645 /* check if anything to do */
4c476991
JB
10646 if (!net_eq(wiphy_net(&rdev->wiphy), net))
10647 err = cfg80211_switch_netns(rdev, net);
463d0183 10648
463d0183 10649 put_net(net);
463d0183
JB
10650 return err;
10651}
10652
67fbb16b
SO
10653static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
10654{
4c476991 10655 struct cfg80211_registered_device *rdev = info->user_ptr[0];
67fbb16b
SO
10656 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
10657 struct cfg80211_pmksa *pmksa) = NULL;
4c476991 10658 struct net_device *dev = info->user_ptr[1];
67fbb16b
SO
10659 struct cfg80211_pmksa pmksa;
10660
10661 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
10662
67fbb16b
SO
10663 if (!info->attrs[NL80211_ATTR_PMKID])
10664 return -EINVAL;
10665
67fbb16b 10666 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
a3caf744
VK
10667
10668 if (info->attrs[NL80211_ATTR_MAC]) {
10669 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
10670 } else if (info->attrs[NL80211_ATTR_SSID] &&
10671 info->attrs[NL80211_ATTR_FILS_CACHE_ID] &&
10672 (info->genlhdr->cmd == NL80211_CMD_DEL_PMKSA ||
10673 info->attrs[NL80211_ATTR_PMK])) {
10674 pmksa.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
10675 pmksa.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
10676 pmksa.cache_id =
10677 nla_data(info->attrs[NL80211_ATTR_FILS_CACHE_ID]);
10678 } else {
10679 return -EINVAL;
10680 }
10681 if (info->attrs[NL80211_ATTR_PMK]) {
10682 pmksa.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
10683 pmksa.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
10684 }
67fbb16b 10685
7fc82af8
VJ
10686 if (info->attrs[NL80211_ATTR_PMK_LIFETIME])
10687 pmksa.pmk_lifetime =
10688 nla_get_u32(info->attrs[NL80211_ATTR_PMK_LIFETIME]);
10689
10690 if (info->attrs[NL80211_ATTR_PMK_REAUTH_THRESHOLD])
10691 pmksa.pmk_reauth_threshold =
10692 nla_get_u8(
10693 info->attrs[NL80211_ATTR_PMK_REAUTH_THRESHOLD]);
10694
074ac8df 10695 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
6c900360
LD
10696 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
10697 !(dev->ieee80211_ptr->iftype == NL80211_IFTYPE_AP &&
10698 wiphy_ext_feature_isset(&rdev->wiphy,
10699 NL80211_EXT_FEATURE_AP_PMKSA_CACHING)))
4c476991 10700 return -EOPNOTSUPP;
67fbb16b
SO
10701
10702 switch (info->genlhdr->cmd) {
10703 case NL80211_CMD_SET_PMKSA:
10704 rdev_ops = rdev->ops->set_pmksa;
10705 break;
10706 case NL80211_CMD_DEL_PMKSA:
10707 rdev_ops = rdev->ops->del_pmksa;
10708 break;
10709 default:
10710 WARN_ON(1);
10711 break;
10712 }
10713
4c476991
JB
10714 if (!rdev_ops)
10715 return -EOPNOTSUPP;
67fbb16b 10716
4c476991 10717 return rdev_ops(&rdev->wiphy, dev, &pmksa);
67fbb16b
SO
10718}
10719
10720static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
10721{
4c476991
JB
10722 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10723 struct net_device *dev = info->user_ptr[1];
67fbb16b 10724
074ac8df 10725 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
10726 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
10727 return -EOPNOTSUPP;
67fbb16b 10728
4c476991
JB
10729 if (!rdev->ops->flush_pmksa)
10730 return -EOPNOTSUPP;
67fbb16b 10731
e35e4d28 10732 return rdev_flush_pmksa(rdev, dev);
67fbb16b
SO
10733}
10734
109086ce
AN
10735static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info)
10736{
10737 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10738 struct net_device *dev = info->user_ptr[1];
10739 u8 action_code, dialog_token;
df942e7b 10740 u32 peer_capability = 0;
109086ce
AN
10741 u16 status_code;
10742 u8 *peer;
31fa97c5 10743 bool initiator;
109086ce
AN
10744
10745 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
10746 !rdev->ops->tdls_mgmt)
10747 return -EOPNOTSUPP;
10748
10749 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] ||
10750 !info->attrs[NL80211_ATTR_STATUS_CODE] ||
10751 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] ||
10752 !info->attrs[NL80211_ATTR_IE] ||
10753 !info->attrs[NL80211_ATTR_MAC])
10754 return -EINVAL;
10755
10756 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
10757 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]);
10758 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
10759 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]);
31fa97c5 10760 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]);
df942e7b
SDU
10761 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY])
10762 peer_capability =
10763 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]);
109086ce 10764
e35e4d28 10765 return rdev_tdls_mgmt(rdev, dev, peer, action_code,
df942e7b 10766 dialog_token, status_code, peer_capability,
31fa97c5 10767 initiator,
e35e4d28
HG
10768 nla_data(info->attrs[NL80211_ATTR_IE]),
10769 nla_len(info->attrs[NL80211_ATTR_IE]));
109086ce
AN
10770}
10771
10772static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info)
10773{
10774 struct cfg80211_registered_device *rdev = info->user_ptr[0];
10775 struct net_device *dev = info->user_ptr[1];
10776 enum nl80211_tdls_operation operation;
10777 u8 *peer;
10778
10779 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) ||
10780 !rdev->ops->tdls_oper)
10781 return -EOPNOTSUPP;
10782
10783 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] ||
10784 !info->attrs[NL80211_ATTR_MAC])
10785 return -EINVAL;
10786
10787 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]);
10788 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
10789
e35e4d28 10790 return rdev_tdls_oper(rdev, dev, peer, operation);
109086ce
AN
10791}
10792
9588bbd5
JM
10793static int nl80211_remain_on_channel(struct sk_buff *skb,
10794 struct genl_info *info)
10795{
4c476991 10796 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10797 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 10798 struct cfg80211_chan_def chandef;
34373d12 10799 const struct cfg80211_chan_def *compat_chandef;
9588bbd5
JM
10800 struct sk_buff *msg;
10801 void *hdr;
10802 u64 cookie;
683b6d3b 10803 u32 duration;
9588bbd5
JM
10804 int err;
10805
10806 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
10807 !info->attrs[NL80211_ATTR_DURATION])
10808 return -EINVAL;
10809
10810 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
10811
ebf348fc
JB
10812 if (!rdev->ops->remain_on_channel ||
10813 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL))
10814 return -EOPNOTSUPP;
10815
9588bbd5 10816 /*
ebf348fc
JB
10817 * We should be on that channel for at least a minimum amount of
10818 * time (10ms) but no longer than the driver supports.
9588bbd5 10819 */
ebf348fc 10820 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
a293911d 10821 duration > rdev->wiphy.max_remain_on_channel_duration)
9588bbd5
JM
10822 return -EINVAL;
10823
683b6d3b
JB
10824 err = nl80211_parse_chandef(rdev, info, &chandef);
10825 if (err)
10826 return err;
9588bbd5 10827
34373d12
VT
10828 wdev_lock(wdev);
10829 if (!cfg80211_off_channel_oper_allowed(wdev) &&
10830 !cfg80211_chandef_identical(&wdev->chandef, &chandef)) {
10831 compat_chandef = cfg80211_chandef_compatible(&wdev->chandef,
10832 &chandef);
10833 if (compat_chandef != &chandef) {
10834 wdev_unlock(wdev);
10835 return -EBUSY;
10836 }
10837 }
10838 wdev_unlock(wdev);
10839
9588bbd5 10840 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
10841 if (!msg)
10842 return -ENOMEM;
9588bbd5 10843
15e47304 10844 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
9588bbd5 10845 NL80211_CMD_REMAIN_ON_CHANNEL);
cb35fba3
DC
10846 if (!hdr) {
10847 err = -ENOBUFS;
9588bbd5
JM
10848 goto free_msg;
10849 }
10850
683b6d3b
JB
10851 err = rdev_remain_on_channel(rdev, wdev, chandef.chan,
10852 duration, &cookie);
9588bbd5
JM
10853
10854 if (err)
10855 goto free_msg;
10856
2dad624e
ND
10857 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
10858 NL80211_ATTR_PAD))
9360ffd1 10859 goto nla_put_failure;
9588bbd5
JM
10860
10861 genlmsg_end(msg, hdr);
4c476991
JB
10862
10863 return genlmsg_reply(msg, info);
9588bbd5
JM
10864
10865 nla_put_failure:
10866 err = -ENOBUFS;
10867 free_msg:
10868 nlmsg_free(msg);
9588bbd5
JM
10869 return err;
10870}
10871
10872static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
10873 struct genl_info *info)
10874{
4c476991 10875 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10876 struct wireless_dev *wdev = info->user_ptr[1];
9588bbd5 10877 u64 cookie;
9588bbd5
JM
10878
10879 if (!info->attrs[NL80211_ATTR_COOKIE])
10880 return -EINVAL;
10881
4c476991
JB
10882 if (!rdev->ops->cancel_remain_on_channel)
10883 return -EOPNOTSUPP;
9588bbd5 10884
9588bbd5
JM
10885 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
10886
e35e4d28 10887 return rdev_cancel_remain_on_channel(rdev, wdev, cookie);
9588bbd5
JM
10888}
10889
13ae75b1
JM
10890static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
10891 struct genl_info *info)
10892{
13ae75b1 10893 struct cfg80211_bitrate_mask mask;
a7c7fbff 10894 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 10895 struct net_device *dev = info->user_ptr[1];
a7c7fbff 10896 int err;
13ae75b1 10897
4c476991
JB
10898 if (!rdev->ops->set_bitrate_mask)
10899 return -EOPNOTSUPP;
13ae75b1 10900
9a5f6488 10901 err = nl80211_parse_tx_bitrate_mask(info, info->attrs,
eb89a6a6
MH
10902 NL80211_ATTR_TX_RATES, &mask,
10903 dev);
a7c7fbff
PK
10904 if (err)
10905 return err;
13ae75b1 10906
e35e4d28 10907 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask);
13ae75b1
JM
10908}
10909
2e161f78 10910static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 10911{
4c476991 10912 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10913 struct wireless_dev *wdev = info->user_ptr[1];
2e161f78 10914 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
026331c4
JM
10915
10916 if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
10917 return -EINVAL;
10918
2e161f78
JB
10919 if (info->attrs[NL80211_ATTR_FRAME_TYPE])
10920 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
026331c4 10921
71bbc994
JB
10922 switch (wdev->iftype) {
10923 case NL80211_IFTYPE_STATION:
10924 case NL80211_IFTYPE_ADHOC:
10925 case NL80211_IFTYPE_P2P_CLIENT:
10926 case NL80211_IFTYPE_AP:
10927 case NL80211_IFTYPE_AP_VLAN:
10928 case NL80211_IFTYPE_MESH_POINT:
10929 case NL80211_IFTYPE_P2P_GO:
98104fde 10930 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 10931 break;
cb3b7d87 10932 case NL80211_IFTYPE_NAN:
71bbc994 10933 default:
4c476991 10934 return -EOPNOTSUPP;
71bbc994 10935 }
026331c4
JM
10936
10937 /* not much point in registering if we can't reply */
4c476991
JB
10938 if (!rdev->ops->mgmt_tx)
10939 return -EOPNOTSUPP;
026331c4 10940
9dba48a6
JB
10941 if (info->attrs[NL80211_ATTR_RECEIVE_MULTICAST] &&
10942 !wiphy_ext_feature_isset(&rdev->wiphy,
10943 NL80211_EXT_FEATURE_MULTICAST_REGISTRATIONS)) {
10944 GENL_SET_ERR_MSG(info,
10945 "multicast RX registrations are not supported");
10946 return -EOPNOTSUPP;
10947 }
10948
15e47304 10949 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type,
ff74c51e
IP
10950 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
10951 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]),
9dba48a6 10952 info->attrs[NL80211_ATTR_RECEIVE_MULTICAST],
ff74c51e 10953 info->extack);
026331c4
JM
10954}
10955
2e161f78 10956static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
026331c4 10957{
4c476991 10958 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 10959 struct wireless_dev *wdev = info->user_ptr[1];
683b6d3b 10960 struct cfg80211_chan_def chandef;
026331c4 10961 int err;
d64d373f 10962 void *hdr = NULL;
026331c4 10963 u64 cookie;
e247bd90 10964 struct sk_buff *msg = NULL;
b176e629
AO
10965 struct cfg80211_mgmt_tx_params params = {
10966 .dont_wait_for_ack =
10967 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK],
10968 };
026331c4 10969
683b6d3b 10970 if (!info->attrs[NL80211_ATTR_FRAME])
026331c4
JM
10971 return -EINVAL;
10972
4c476991
JB
10973 if (!rdev->ops->mgmt_tx)
10974 return -EOPNOTSUPP;
026331c4 10975
71bbc994 10976 switch (wdev->iftype) {
ea141b75
AQ
10977 case NL80211_IFTYPE_P2P_DEVICE:
10978 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
10979 return -EINVAL;
71bbc994
JB
10980 case NL80211_IFTYPE_STATION:
10981 case NL80211_IFTYPE_ADHOC:
10982 case NL80211_IFTYPE_P2P_CLIENT:
10983 case NL80211_IFTYPE_AP:
10984 case NL80211_IFTYPE_AP_VLAN:
10985 case NL80211_IFTYPE_MESH_POINT:
10986 case NL80211_IFTYPE_P2P_GO:
10987 break;
cb3b7d87 10988 case NL80211_IFTYPE_NAN:
71bbc994 10989 default:
4c476991 10990 return -EOPNOTSUPP;
71bbc994 10991 }
026331c4 10992
f7ca38df 10993 if (info->attrs[NL80211_ATTR_DURATION]) {
7c4ef712 10994 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
f7ca38df 10995 return -EINVAL;
b176e629 10996 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
ebf348fc
JB
10997
10998 /*
10999 * We should wait on the channel for at least a minimum amount
11000 * of time (10ms) but no longer than the driver supports.
11001 */
b176e629
AO
11002 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME ||
11003 params.wait > rdev->wiphy.max_remain_on_channel_duration)
ebf348fc 11004 return -EINVAL;
f7ca38df
JB
11005 }
11006
b176e629 11007 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
f7ca38df 11008
b176e629 11009 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX))
7c4ef712
JB
11010 return -EINVAL;
11011
b176e629 11012 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]);
e9f935e3 11013
ea141b75
AQ
11014 /* get the channel if any has been specified, otherwise pass NULL to
11015 * the driver. The latter will use the current one
11016 */
11017 chandef.chan = NULL;
11018 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
11019 err = nl80211_parse_chandef(rdev, info, &chandef);
11020 if (err)
11021 return err;
11022 }
11023
b176e629 11024 if (!chandef.chan && params.offchan)
ea141b75 11025 return -EINVAL;
026331c4 11026
34373d12
VT
11027 wdev_lock(wdev);
11028 if (params.offchan && !cfg80211_off_channel_oper_allowed(wdev)) {
11029 wdev_unlock(wdev);
11030 return -EBUSY;
11031 }
11032 wdev_unlock(wdev);
11033
34d22ce2
AO
11034 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
11035 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
11036
11037 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) {
11038 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
11039 int i;
11040
11041 if (len % sizeof(u16))
11042 return -EINVAL;
11043
11044 params.n_csa_offsets = len / sizeof(u16);
11045 params.csa_offsets =
11046 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]);
11047
11048 /* check that all the offsets fit the frame */
11049 for (i = 0; i < params.n_csa_offsets; i++) {
11050 if (params.csa_offsets[i] >= params.len)
11051 return -EINVAL;
11052 }
11053 }
11054
b176e629 11055 if (!params.dont_wait_for_ack) {
e247bd90
JB
11056 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
11057 if (!msg)
11058 return -ENOMEM;
026331c4 11059
15e47304 11060 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
e247bd90 11061 NL80211_CMD_FRAME);
cb35fba3
DC
11062 if (!hdr) {
11063 err = -ENOBUFS;
e247bd90
JB
11064 goto free_msg;
11065 }
026331c4 11066 }
e247bd90 11067
b176e629
AO
11068 params.chan = chandef.chan;
11069 err = cfg80211_mlme_mgmt_tx(rdev, wdev, &params, &cookie);
026331c4
JM
11070 if (err)
11071 goto free_msg;
11072
e247bd90 11073 if (msg) {
2dad624e
ND
11074 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
11075 NL80211_ATTR_PAD))
9360ffd1 11076 goto nla_put_failure;
026331c4 11077
e247bd90
JB
11078 genlmsg_end(msg, hdr);
11079 return genlmsg_reply(msg, info);
11080 }
11081
11082 return 0;
026331c4
JM
11083
11084 nla_put_failure:
11085 err = -ENOBUFS;
11086 free_msg:
11087 nlmsg_free(msg);
026331c4
JM
11088 return err;
11089}
11090
f7ca38df
JB
11091static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
11092{
11093 struct cfg80211_registered_device *rdev = info->user_ptr[0];
71bbc994 11094 struct wireless_dev *wdev = info->user_ptr[1];
f7ca38df
JB
11095 u64 cookie;
11096
11097 if (!info->attrs[NL80211_ATTR_COOKIE])
11098 return -EINVAL;
11099
11100 if (!rdev->ops->mgmt_tx_cancel_wait)
11101 return -EOPNOTSUPP;
11102
71bbc994
JB
11103 switch (wdev->iftype) {
11104 case NL80211_IFTYPE_STATION:
11105 case NL80211_IFTYPE_ADHOC:
11106 case NL80211_IFTYPE_P2P_CLIENT:
11107 case NL80211_IFTYPE_AP:
11108 case NL80211_IFTYPE_AP_VLAN:
11109 case NL80211_IFTYPE_P2P_GO:
98104fde 11110 case NL80211_IFTYPE_P2P_DEVICE:
71bbc994 11111 break;
cb3b7d87 11112 case NL80211_IFTYPE_NAN:
71bbc994 11113 default:
f7ca38df 11114 return -EOPNOTSUPP;
71bbc994 11115 }
f7ca38df
JB
11116
11117 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
11118
e35e4d28 11119 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie);
f7ca38df
JB
11120}
11121
ffb9eb3d
KV
11122static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
11123{
4c476991 11124 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d 11125 struct wireless_dev *wdev;
4c476991 11126 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
11127 u8 ps_state;
11128 bool state;
11129 int err;
11130
4c476991
JB
11131 if (!info->attrs[NL80211_ATTR_PS_STATE])
11132 return -EINVAL;
ffb9eb3d
KV
11133
11134 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
11135
ffb9eb3d
KV
11136 wdev = dev->ieee80211_ptr;
11137
4c476991
JB
11138 if (!rdev->ops->set_power_mgmt)
11139 return -EOPNOTSUPP;
ffb9eb3d
KV
11140
11141 state = (ps_state == NL80211_PS_ENABLED) ? true : false;
11142
11143 if (state == wdev->ps)
4c476991 11144 return 0;
ffb9eb3d 11145
e35e4d28 11146 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout);
4c476991
JB
11147 if (!err)
11148 wdev->ps = state;
ffb9eb3d
KV
11149 return err;
11150}
11151
11152static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
11153{
4c476991 11154 struct cfg80211_registered_device *rdev = info->user_ptr[0];
ffb9eb3d
KV
11155 enum nl80211_ps_state ps_state;
11156 struct wireless_dev *wdev;
4c476991 11157 struct net_device *dev = info->user_ptr[1];
ffb9eb3d
KV
11158 struct sk_buff *msg;
11159 void *hdr;
11160 int err;
11161
ffb9eb3d
KV
11162 wdev = dev->ieee80211_ptr;
11163
4c476991
JB
11164 if (!rdev->ops->set_power_mgmt)
11165 return -EOPNOTSUPP;
ffb9eb3d
KV
11166
11167 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4c476991
JB
11168 if (!msg)
11169 return -ENOMEM;
ffb9eb3d 11170
15e47304 11171 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ffb9eb3d
KV
11172 NL80211_CMD_GET_POWER_SAVE);
11173 if (!hdr) {
4c476991 11174 err = -ENOBUFS;
ffb9eb3d
KV
11175 goto free_msg;
11176 }
11177
11178 if (wdev->ps)
11179 ps_state = NL80211_PS_ENABLED;
11180 else
11181 ps_state = NL80211_PS_DISABLED;
11182
9360ffd1
DM
11183 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state))
11184 goto nla_put_failure;
ffb9eb3d
KV
11185
11186 genlmsg_end(msg, hdr);
4c476991 11187 return genlmsg_reply(msg, info);
ffb9eb3d 11188
4c476991 11189 nla_put_failure:
ffb9eb3d 11190 err = -ENOBUFS;
4c476991 11191 free_msg:
ffb9eb3d 11192 nlmsg_free(msg);
ffb9eb3d
KV
11193 return err;
11194}
11195
94e860f1
JB
11196static const struct nla_policy
11197nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = {
4a4b8169 11198 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_BINARY },
d6dc1a38
JO
11199 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
11200 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
84f10708
TP
11201 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 },
11202 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 },
11203 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 },
bee427b8 11204 [NL80211_ATTR_CQM_RSSI_LEVEL] = { .type = NLA_S32 },
d6dc1a38
JO
11205};
11206
84f10708 11207static int nl80211_set_cqm_txe(struct genl_info *info,
d9d8b019 11208 u32 rate, u32 pkts, u32 intvl)
84f10708
TP
11209{
11210 struct cfg80211_registered_device *rdev = info->user_ptr[0];
84f10708 11211 struct net_device *dev = info->user_ptr[1];
1da5fcc8 11212 struct wireless_dev *wdev = dev->ieee80211_ptr;
84f10708 11213
d9d8b019 11214 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL)
84f10708
TP
11215 return -EINVAL;
11216
84f10708
TP
11217 if (!rdev->ops->set_cqm_txe_config)
11218 return -EOPNOTSUPP;
11219
11220 if (wdev->iftype != NL80211_IFTYPE_STATION &&
11221 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
11222 return -EOPNOTSUPP;
11223
e35e4d28 11224 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl);
84f10708
TP
11225}
11226
4a4b8169
AZ
11227static int cfg80211_cqm_rssi_update(struct cfg80211_registered_device *rdev,
11228 struct net_device *dev)
11229{
11230 struct wireless_dev *wdev = dev->ieee80211_ptr;
11231 s32 last, low, high;
11232 u32 hyst;
1222a160 11233 int i, n, low_index;
4a4b8169
AZ
11234 int err;
11235
11236 /* RSSI reporting disabled? */
11237 if (!wdev->cqm_config)
11238 return rdev_set_cqm_rssi_range_config(rdev, dev, 0, 0);
11239
11240 /*
11241 * Obtain current RSSI value if possible, if not and no RSSI threshold
11242 * event has been received yet, we should receive an event after a
11243 * connection is established and enough beacons received to calculate
11244 * the average.
11245 */
11246 if (!wdev->cqm_config->last_rssi_event_value && wdev->current_bss &&
11247 rdev->ops->get_station) {
73887fd9 11248 struct station_info sinfo = {};
4a4b8169
AZ
11249 u8 *mac_addr;
11250
11251 mac_addr = wdev->current_bss->pub.bssid;
11252
73887fd9
JB
11253 err = rdev_get_station(rdev, dev, mac_addr, &sinfo);
11254 if (err)
4a4b8169
AZ
11255 return err;
11256
df16737d 11257 cfg80211_sinfo_release_content(&sinfo);
397c657a 11258 if (sinfo.filled & BIT_ULL(NL80211_STA_INFO_BEACON_SIGNAL_AVG))
4a4b8169 11259 wdev->cqm_config->last_rssi_event_value =
73887fd9 11260 (s8) sinfo.rx_beacon_signal_avg;
4a4b8169
AZ
11261 }
11262
11263 last = wdev->cqm_config->last_rssi_event_value;
11264 hyst = wdev->cqm_config->rssi_hyst;
11265 n = wdev->cqm_config->n_rssi_thresholds;
11266
4b2c5a14
MH
11267 for (i = 0; i < n; i++) {
11268 i = array_index_nospec(i, n);
4a4b8169
AZ
11269 if (last < wdev->cqm_config->rssi_thresholds[i])
11270 break;
4b2c5a14 11271 }
4a4b8169 11272
1222a160
MH
11273 low_index = i - 1;
11274 if (low_index >= 0) {
11275 low_index = array_index_nospec(low_index, n);
11276 low = wdev->cqm_config->rssi_thresholds[low_index] - hyst;
11277 } else {
11278 low = S32_MIN;
11279 }
11280 if (i < n) {
11281 i = array_index_nospec(i, n);
11282 high = wdev->cqm_config->rssi_thresholds[i] + hyst - 1;
11283 } else {
11284 high = S32_MAX;
11285 }
4a4b8169
AZ
11286
11287 return rdev_set_cqm_rssi_range_config(rdev, dev, low, high);
11288}
11289
d6dc1a38 11290static int nl80211_set_cqm_rssi(struct genl_info *info,
4a4b8169
AZ
11291 const s32 *thresholds, int n_thresholds,
11292 u32 hysteresis)
d6dc1a38 11293{
4c476991 11294 struct cfg80211_registered_device *rdev = info->user_ptr[0];
4c476991 11295 struct net_device *dev = info->user_ptr[1];
1da5fcc8 11296 struct wireless_dev *wdev = dev->ieee80211_ptr;
4a4b8169
AZ
11297 int i, err;
11298 s32 prev = S32_MIN;
d6dc1a38 11299
4a4b8169
AZ
11300 /* Check all values negative and sorted */
11301 for (i = 0; i < n_thresholds; i++) {
11302 if (thresholds[i] > 0 || thresholds[i] <= prev)
11303 return -EINVAL;
d6dc1a38 11304
4a4b8169
AZ
11305 prev = thresholds[i];
11306 }
d6dc1a38 11307
074ac8df 11308 if (wdev->iftype != NL80211_IFTYPE_STATION &&
4c476991
JB
11309 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
11310 return -EOPNOTSUPP;
d6dc1a38 11311
4a4b8169
AZ
11312 wdev_lock(wdev);
11313 cfg80211_cqm_config_free(wdev);
11314 wdev_unlock(wdev);
11315
11316 if (n_thresholds <= 1 && rdev->ops->set_cqm_rssi_config) {
11317 if (n_thresholds == 0 || thresholds[0] == 0) /* Disabling */
11318 return rdev_set_cqm_rssi_config(rdev, dev, 0, 0);
11319
11320 return rdev_set_cqm_rssi_config(rdev, dev,
11321 thresholds[0], hysteresis);
11322 }
11323
11324 if (!wiphy_ext_feature_isset(&rdev->wiphy,
11325 NL80211_EXT_FEATURE_CQM_RSSI_LIST))
11326 return -EOPNOTSUPP;
11327
11328 if (n_thresholds == 1 && thresholds[0] == 0) /* Disabling */
11329 n_thresholds = 0;
11330
11331 wdev_lock(wdev);
11332 if (n_thresholds) {
11333 struct cfg80211_cqm_config *cqm_config;
11334
11335 cqm_config = kzalloc(sizeof(struct cfg80211_cqm_config) +
11336 n_thresholds * sizeof(s32), GFP_KERNEL);
11337 if (!cqm_config) {
11338 err = -ENOMEM;
11339 goto unlock;
11340 }
11341
11342 cqm_config->rssi_hyst = hysteresis;
11343 cqm_config->n_rssi_thresholds = n_thresholds;
11344 memcpy(cqm_config->rssi_thresholds, thresholds,
11345 n_thresholds * sizeof(s32));
11346
11347 wdev->cqm_config = cqm_config;
11348 }
11349
11350 err = cfg80211_cqm_rssi_update(rdev, dev);
11351
11352unlock:
11353 wdev_unlock(wdev);
11354
11355 return err;
d6dc1a38
JO
11356}
11357
11358static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
11359{
11360 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
11361 struct nlattr *cqm;
11362 int err;
11363
11364 cqm = info->attrs[NL80211_ATTR_CQM];
1da5fcc8
JB
11365 if (!cqm)
11366 return -EINVAL;
d6dc1a38 11367
8cb08174
JB
11368 err = nla_parse_nested_deprecated(attrs, NL80211_ATTR_CQM_MAX, cqm,
11369 nl80211_attr_cqm_policy,
11370 info->extack);
d6dc1a38 11371 if (err)
1da5fcc8 11372 return err;
d6dc1a38
JO
11373
11374 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
11375 attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4a4b8169
AZ
11376 const s32 *thresholds =
11377 nla_data(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
11378 int len = nla_len(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
1da5fcc8 11379 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
d6dc1a38 11380
4a4b8169
AZ
11381 if (len % 4)
11382 return -EINVAL;
11383
11384 return nl80211_set_cqm_rssi(info, thresholds, len / 4,
11385 hysteresis);
1da5fcc8
JB
11386 }
11387
11388 if (attrs[NL80211_ATTR_CQM_TXE_RATE] &&
11389 attrs[NL80211_ATTR_CQM_TXE_PKTS] &&
11390 attrs[NL80211_ATTR_CQM_TXE_INTVL]) {
11391 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]);
11392 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]);
11393 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]);
11394
11395 return nl80211_set_cqm_txe(info, rate, pkts, intvl);
11396 }
11397
11398 return -EINVAL;
d6dc1a38
JO
11399}
11400
6e0bd6c3
RL
11401static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info)
11402{
11403 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11404 struct net_device *dev = info->user_ptr[1];
11405 struct ocb_setup setup = {};
11406 int err;
11407
11408 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
11409 if (err)
11410 return err;
11411
11412 return cfg80211_join_ocb(rdev, dev, &setup);
11413}
11414
11415static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info)
11416{
11417 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11418 struct net_device *dev = info->user_ptr[1];
11419
11420 return cfg80211_leave_ocb(rdev, dev);
11421}
11422
29cbe68c
JB
11423static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
11424{
11425 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11426 struct net_device *dev = info->user_ptr[1];
11427 struct mesh_config cfg;
c80d545d 11428 struct mesh_setup setup;
29cbe68c
JB
11429 int err;
11430
11431 /* start with default */
11432 memcpy(&cfg, &default_mesh_config, sizeof(cfg));
c80d545d 11433 memcpy(&setup, &default_mesh_setup, sizeof(setup));
29cbe68c 11434
24bdd9f4 11435 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
29cbe68c 11436 /* and parse parameters if given */
24bdd9f4 11437 err = nl80211_parse_mesh_config(info, &cfg, NULL);
29cbe68c
JB
11438 if (err)
11439 return err;
11440 }
11441
11442 if (!info->attrs[NL80211_ATTR_MESH_ID] ||
11443 !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
11444 return -EINVAL;
11445
c80d545d
JC
11446 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
11447 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
11448
4bb62344
CYY
11449 if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
11450 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate,
11451 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
11452 return -EINVAL;
11453
9bdbf04d
MP
11454 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
11455 setup.beacon_interval =
11456 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
12d20fc9 11457
0c317a02
PK
11458 err = cfg80211_validate_beacon_int(rdev,
11459 NL80211_IFTYPE_MESH_POINT,
11460 setup.beacon_interval);
12d20fc9
PK
11461 if (err)
11462 return err;
9bdbf04d
MP
11463 }
11464
11465 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
11466 setup.dtim_period =
11467 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
11468 if (setup.dtim_period < 1 || setup.dtim_period > 100)
11469 return -EINVAL;
11470 }
11471
c80d545d
JC
11472 if (info->attrs[NL80211_ATTR_MESH_SETUP]) {
11473 /* parse additional setup parameters if given */
11474 err = nl80211_parse_mesh_setup(info, &setup);
11475 if (err)
11476 return err;
11477 }
11478
d37bb18a
TP
11479 if (setup.user_mpm)
11480 cfg.auto_open_plinks = false;
11481
cc1d2806 11482 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
683b6d3b
JB
11483 err = nl80211_parse_chandef(rdev, info, &setup.chandef);
11484 if (err)
11485 return err;
cc1d2806 11486 } else {
188c1b3c 11487 /* __cfg80211_join_mesh() will sort it out */
683b6d3b 11488 setup.chandef.chan = NULL;
cc1d2806
JB
11489 }
11490
ffb3cf30
AN
11491 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
11492 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
11493 int n_rates =
11494 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
11495 struct ieee80211_supported_band *sband;
11496
11497 if (!setup.chandef.chan)
11498 return -EINVAL;
11499
11500 sband = rdev->wiphy.bands[setup.chandef.chan->band];
11501
11502 err = ieee80211_get_ratemask(sband, rates, n_rates,
11503 &setup.basic_rates);
11504 if (err)
11505 return err;
11506 }
11507
8564e382 11508 if (info->attrs[NL80211_ATTR_TX_RATES]) {
9a5f6488
TC
11509 err = nl80211_parse_tx_bitrate_mask(info, info->attrs,
11510 NL80211_ATTR_TX_RATES,
eb89a6a6
MH
11511 &setup.beacon_rate,
11512 dev);
8564e382
JB
11513 if (err)
11514 return err;
11515
265698d7
JB
11516 if (!setup.chandef.chan)
11517 return -EINVAL;
11518
8564e382
JB
11519 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band,
11520 &setup.beacon_rate);
11521 if (err)
11522 return err;
11523 }
11524
d37d49c2
BB
11525 setup.userspace_handles_dfs =
11526 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]);
11527
1224f583
DK
11528 if (info->attrs[NL80211_ATTR_CONTROL_PORT_OVER_NL80211]) {
11529 int r = validate_pae_over_nl80211(rdev, info);
11530
11531 if (r < 0)
11532 return r;
11533
11534 setup.control_port_over_nl80211 = true;
11535 }
11536
188c1b3c
DK
11537 wdev_lock(dev->ieee80211_ptr);
11538 err = __cfg80211_join_mesh(rdev, dev, &setup, &cfg);
11539 if (!err && info->attrs[NL80211_ATTR_SOCKET_OWNER])
11540 dev->ieee80211_ptr->conn_owner_nlportid = info->snd_portid;
11541 wdev_unlock(dev->ieee80211_ptr);
11542
11543 return err;
29cbe68c
JB
11544}
11545
11546static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
11547{
11548 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11549 struct net_device *dev = info->user_ptr[1];
11550
11551 return cfg80211_leave_mesh(rdev, dev);
11552}
11553
dfb89c56 11554#ifdef CONFIG_PM
bb92d199
AK
11555static int nl80211_send_wowlan_patterns(struct sk_buff *msg,
11556 struct cfg80211_registered_device *rdev)
11557{
6abb9cb9 11558 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config;
bb92d199
AK
11559 struct nlattr *nl_pats, *nl_pat;
11560 int i, pat_len;
11561
6abb9cb9 11562 if (!wowlan->n_patterns)
bb92d199
AK
11563 return 0;
11564
ae0be8de 11565 nl_pats = nla_nest_start_noflag(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN);
bb92d199
AK
11566 if (!nl_pats)
11567 return -ENOBUFS;
11568
6abb9cb9 11569 for (i = 0; i < wowlan->n_patterns; i++) {
ae0be8de 11570 nl_pat = nla_nest_start_noflag(msg, i + 1);
bb92d199
AK
11571 if (!nl_pat)
11572 return -ENOBUFS;
6abb9cb9 11573 pat_len = wowlan->patterns[i].pattern_len;
50ac6607 11574 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8),
6abb9cb9 11575 wowlan->patterns[i].mask) ||
50ac6607
AK
11576 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
11577 wowlan->patterns[i].pattern) ||
11578 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
6abb9cb9 11579 wowlan->patterns[i].pkt_offset))
bb92d199
AK
11580 return -ENOBUFS;
11581 nla_nest_end(msg, nl_pat);
11582 }
11583 nla_nest_end(msg, nl_pats);
11584
11585 return 0;
11586}
11587
2a0e047e
JB
11588static int nl80211_send_wowlan_tcp(struct sk_buff *msg,
11589 struct cfg80211_wowlan_tcp *tcp)
11590{
11591 struct nlattr *nl_tcp;
11592
11593 if (!tcp)
11594 return 0;
11595
ae0be8de
MK
11596 nl_tcp = nla_nest_start_noflag(msg,
11597 NL80211_WOWLAN_TRIG_TCP_CONNECTION);
2a0e047e
JB
11598 if (!nl_tcp)
11599 return -ENOBUFS;
11600
930345ea
JB
11601 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) ||
11602 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) ||
2a0e047e
JB
11603 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) ||
11604 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) ||
11605 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) ||
11606 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD,
11607 tcp->payload_len, tcp->payload) ||
11608 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL,
11609 tcp->data_interval) ||
11610 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD,
11611 tcp->wake_len, tcp->wake_data) ||
11612 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK,
11613 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask))
11614 return -ENOBUFS;
11615
11616 if (tcp->payload_seq.len &&
11617 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ,
11618 sizeof(tcp->payload_seq), &tcp->payload_seq))
11619 return -ENOBUFS;
11620
11621 if (tcp->payload_tok.len &&
11622 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN,
11623 sizeof(tcp->payload_tok) + tcp->tokens_size,
11624 &tcp->payload_tok))
11625 return -ENOBUFS;
11626
e248ad30
JB
11627 nla_nest_end(msg, nl_tcp);
11628
2a0e047e
JB
11629 return 0;
11630}
11631
75453ccb
LC
11632static int nl80211_send_wowlan_nd(struct sk_buff *msg,
11633 struct cfg80211_sched_scan_request *req)
11634{
3b06d277 11635 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan;
75453ccb
LC
11636 int i;
11637
11638 if (!req)
11639 return 0;
11640
ae0be8de 11641 nd = nla_nest_start_noflag(msg, NL80211_WOWLAN_TRIG_NET_DETECT);
75453ccb
LC
11642 if (!nd)
11643 return -ENOBUFS;
11644
3b06d277
AS
11645 if (req->n_scan_plans == 1 &&
11646 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL,
11647 req->scan_plans[0].interval * 1000))
75453ccb
LC
11648 return -ENOBUFS;
11649
21fea567
LC
11650 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay))
11651 return -ENOBUFS;
11652
bf95ecdb 11653 if (req->relative_rssi_set) {
11654 struct nl80211_bss_select_rssi_adjust rssi_adjust;
11655
11656 if (nla_put_s8(msg, NL80211_ATTR_SCHED_SCAN_RELATIVE_RSSI,
11657 req->relative_rssi))
11658 return -ENOBUFS;
11659
11660 rssi_adjust.band = req->rssi_adjust.band;
11661 rssi_adjust.delta = req->rssi_adjust.delta;
11662 if (nla_put(msg, NL80211_ATTR_SCHED_SCAN_RSSI_ADJUST,
11663 sizeof(rssi_adjust), &rssi_adjust))
11664 return -ENOBUFS;
11665 }
11666
ae0be8de 11667 freqs = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_FREQUENCIES);
75453ccb
LC
11668 if (!freqs)
11669 return -ENOBUFS;
11670
53b18980
JB
11671 for (i = 0; i < req->n_channels; i++) {
11672 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
11673 return -ENOBUFS;
11674 }
75453ccb
LC
11675
11676 nla_nest_end(msg, freqs);
11677
11678 if (req->n_match_sets) {
ae0be8de
MK
11679 matches = nla_nest_start_noflag(msg,
11680 NL80211_ATTR_SCHED_SCAN_MATCH);
76e1fb4b
JB
11681 if (!matches)
11682 return -ENOBUFS;
11683
75453ccb 11684 for (i = 0; i < req->n_match_sets; i++) {
ae0be8de 11685 match = nla_nest_start_noflag(msg, i);
76e1fb4b
JB
11686 if (!match)
11687 return -ENOBUFS;
11688
53b18980
JB
11689 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID,
11690 req->match_sets[i].ssid.ssid_len,
11691 req->match_sets[i].ssid.ssid))
11692 return -ENOBUFS;
75453ccb
LC
11693 nla_nest_end(msg, match);
11694 }
11695 nla_nest_end(msg, matches);
11696 }
11697
ae0be8de 11698 scan_plans = nla_nest_start_noflag(msg, NL80211_ATTR_SCHED_SCAN_PLANS);
3b06d277
AS
11699 if (!scan_plans)
11700 return -ENOBUFS;
11701
11702 for (i = 0; i < req->n_scan_plans; i++) {
ae0be8de 11703 scan_plan = nla_nest_start_noflag(msg, i + 1);
76e1fb4b
JB
11704 if (!scan_plan)
11705 return -ENOBUFS;
11706
67626964 11707 if (nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL,
3b06d277
AS
11708 req->scan_plans[i].interval) ||
11709 (req->scan_plans[i].iterations &&
11710 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS,
11711 req->scan_plans[i].iterations)))
11712 return -ENOBUFS;
11713 nla_nest_end(msg, scan_plan);
11714 }
11715 nla_nest_end(msg, scan_plans);
11716
75453ccb
LC
11717 nla_nest_end(msg, nd);
11718
11719 return 0;
11720}
11721
ff1b6e69
JB
11722static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info)
11723{
11724 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11725 struct sk_buff *msg;
11726 void *hdr;
2a0e047e 11727 u32 size = NLMSG_DEFAULT_SIZE;
ff1b6e69 11728
964dc9e2 11729 if (!rdev->wiphy.wowlan)
ff1b6e69
JB
11730 return -EOPNOTSUPP;
11731
6abb9cb9 11732 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) {
2a0e047e 11733 /* adjust size to have room for all the data */
6abb9cb9
JB
11734 size += rdev->wiphy.wowlan_config->tcp->tokens_size +
11735 rdev->wiphy.wowlan_config->tcp->payload_len +
11736 rdev->wiphy.wowlan_config->tcp->wake_len +
11737 rdev->wiphy.wowlan_config->tcp->wake_len / 8;
2a0e047e
JB
11738 }
11739
11740 msg = nlmsg_new(size, GFP_KERNEL);
ff1b6e69
JB
11741 if (!msg)
11742 return -ENOMEM;
11743
15e47304 11744 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
ff1b6e69
JB
11745 NL80211_CMD_GET_WOWLAN);
11746 if (!hdr)
11747 goto nla_put_failure;
11748
6abb9cb9 11749 if (rdev->wiphy.wowlan_config) {
ff1b6e69
JB
11750 struct nlattr *nl_wowlan;
11751
ae0be8de
MK
11752 nl_wowlan = nla_nest_start_noflag(msg,
11753 NL80211_ATTR_WOWLAN_TRIGGERS);
ff1b6e69
JB
11754 if (!nl_wowlan)
11755 goto nla_put_failure;
11756
6abb9cb9 11757 if ((rdev->wiphy.wowlan_config->any &&
9360ffd1 11758 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) ||
6abb9cb9 11759 (rdev->wiphy.wowlan_config->disconnect &&
9360ffd1 11760 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) ||
6abb9cb9 11761 (rdev->wiphy.wowlan_config->magic_pkt &&
9360ffd1 11762 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) ||
6abb9cb9 11763 (rdev->wiphy.wowlan_config->gtk_rekey_failure &&
9360ffd1 11764 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) ||
6abb9cb9 11765 (rdev->wiphy.wowlan_config->eap_identity_req &&
9360ffd1 11766 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) ||
6abb9cb9 11767 (rdev->wiphy.wowlan_config->four_way_handshake &&
9360ffd1 11768 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) ||
6abb9cb9 11769 (rdev->wiphy.wowlan_config->rfkill_release &&
9360ffd1
DM
11770 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)))
11771 goto nla_put_failure;
2a0e047e 11772
bb92d199
AK
11773 if (nl80211_send_wowlan_patterns(msg, rdev))
11774 goto nla_put_failure;
2a0e047e 11775
6abb9cb9
JB
11776 if (nl80211_send_wowlan_tcp(msg,
11777 rdev->wiphy.wowlan_config->tcp))
2a0e047e 11778 goto nla_put_failure;
75453ccb
LC
11779
11780 if (nl80211_send_wowlan_nd(
11781 msg,
11782 rdev->wiphy.wowlan_config->nd_config))
11783 goto nla_put_failure;
2a0e047e 11784
ff1b6e69
JB
11785 nla_nest_end(msg, nl_wowlan);
11786 }
11787
11788 genlmsg_end(msg, hdr);
11789 return genlmsg_reply(msg, info);
11790
11791nla_put_failure:
11792 nlmsg_free(msg);
11793 return -ENOBUFS;
11794}
11795
2a0e047e
JB
11796static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev,
11797 struct nlattr *attr,
11798 struct cfg80211_wowlan *trig)
11799{
11800 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP];
11801 struct cfg80211_wowlan_tcp *cfg;
11802 struct nl80211_wowlan_tcp_data_token *tok = NULL;
11803 struct nl80211_wowlan_tcp_data_seq *seq = NULL;
11804 u32 size;
11805 u32 data_size, wake_size, tokens_size = 0, wake_mask_size;
11806 int err, port;
11807
964dc9e2 11808 if (!rdev->wiphy.wowlan->tcp)
2a0e047e
JB
11809 return -EINVAL;
11810
8cb08174
JB
11811 err = nla_parse_nested_deprecated(tb, MAX_NL80211_WOWLAN_TCP, attr,
11812 nl80211_wowlan_tcp_policy, NULL);
2a0e047e
JB
11813 if (err)
11814 return err;
11815
11816 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] ||
11817 !tb[NL80211_WOWLAN_TCP_DST_IPV4] ||
11818 !tb[NL80211_WOWLAN_TCP_DST_MAC] ||
11819 !tb[NL80211_WOWLAN_TCP_DST_PORT] ||
11820 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] ||
11821 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] ||
11822 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] ||
11823 !tb[NL80211_WOWLAN_TCP_WAKE_MASK])
11824 return -EINVAL;
11825
11826 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]);
964dc9e2 11827 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max)
2a0e047e
JB
11828 return -EINVAL;
11829
11830 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) >
964dc9e2 11831 rdev->wiphy.wowlan->tcp->data_interval_max ||
723d568a 11832 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0)
2a0e047e
JB
11833 return -EINVAL;
11834
11835 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]);
964dc9e2 11836 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max)
2a0e047e
JB
11837 return -EINVAL;
11838
11839 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]);
11840 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8))
11841 return -EINVAL;
11842
11843 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) {
11844 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
11845
11846 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]);
11847 tokens_size = tokln - sizeof(*tok);
11848
11849 if (!tok->len || tokens_size % tok->len)
11850 return -EINVAL;
964dc9e2 11851 if (!rdev->wiphy.wowlan->tcp->tok)
2a0e047e 11852 return -EINVAL;
964dc9e2 11853 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len)
2a0e047e 11854 return -EINVAL;
964dc9e2 11855 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len)
2a0e047e 11856 return -EINVAL;
964dc9e2 11857 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize)
2a0e047e
JB
11858 return -EINVAL;
11859 if (tok->offset + tok->len > data_size)
11860 return -EINVAL;
11861 }
11862
11863 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) {
11864 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]);
964dc9e2 11865 if (!rdev->wiphy.wowlan->tcp->seq)
2a0e047e
JB
11866 return -EINVAL;
11867 if (seq->len == 0 || seq->len > 4)
11868 return -EINVAL;
11869 if (seq->len + seq->offset > data_size)
11870 return -EINVAL;
11871 }
11872
11873 size = sizeof(*cfg);
11874 size += data_size;
11875 size += wake_size + wake_mask_size;
11876 size += tokens_size;
11877
11878 cfg = kzalloc(size, GFP_KERNEL);
11879 if (!cfg)
11880 return -ENOMEM;
67b61f6c
JB
11881 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]);
11882 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]);
2a0e047e
JB
11883 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]),
11884 ETH_ALEN);
11885 if (tb[NL80211_WOWLAN_TCP_SRC_PORT])
11886 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]);
11887 else
11888 port = 0;
11889#ifdef CONFIG_INET
11890 /* allocate a socket and port for it and use it */
11891 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM,
11892 IPPROTO_TCP, &cfg->sock, 1);
11893 if (err) {
11894 kfree(cfg);
11895 return err;
11896 }
11897 if (inet_csk_get_port(cfg->sock->sk, port)) {
11898 sock_release(cfg->sock);
11899 kfree(cfg);
11900 return -EADDRINUSE;
11901 }
11902 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num;
11903#else
11904 if (!port) {
11905 kfree(cfg);
11906 return -EINVAL;
11907 }
11908 cfg->src_port = port;
11909#endif
11910
11911 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]);
11912 cfg->payload_len = data_size;
11913 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size;
11914 memcpy((void *)cfg->payload,
11915 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]),
11916 data_size);
11917 if (seq)
11918 cfg->payload_seq = *seq;
11919 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]);
11920 cfg->wake_len = wake_size;
11921 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size;
11922 memcpy((void *)cfg->wake_data,
11923 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]),
11924 wake_size);
11925 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size +
11926 data_size + wake_size;
11927 memcpy((void *)cfg->wake_mask,
11928 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]),
11929 wake_mask_size);
11930 if (tok) {
11931 cfg->tokens_size = tokens_size;
11932 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size);
11933 }
11934
11935 trig->tcp = cfg;
11936
11937 return 0;
11938}
11939
8cd4d456
LC
11940static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev,
11941 const struct wiphy_wowlan_support *wowlan,
11942 struct nlattr *attr,
11943 struct cfg80211_wowlan *trig)
11944{
11945 struct nlattr **tb;
11946 int err;
11947
6396bb22 11948 tb = kcalloc(NUM_NL80211_ATTR, sizeof(*tb), GFP_KERNEL);
8cd4d456
LC
11949 if (!tb)
11950 return -ENOMEM;
11951
11952 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) {
11953 err = -EOPNOTSUPP;
11954 goto out;
11955 }
11956
8cb08174
JB
11957 err = nla_parse_nested_deprecated(tb, NL80211_ATTR_MAX, attr,
11958 nl80211_policy, NULL);
8cd4d456
LC
11959 if (err)
11960 goto out;
11961
aad1e812
AVS
11962 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb,
11963 wowlan->max_nd_match_sets);
8cd4d456
LC
11964 err = PTR_ERR_OR_ZERO(trig->nd_config);
11965 if (err)
11966 trig->nd_config = NULL;
11967
11968out:
11969 kfree(tb);
11970 return err;
11971}
11972
ff1b6e69
JB
11973static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info)
11974{
11975 struct cfg80211_registered_device *rdev = info->user_ptr[0];
11976 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG];
ff1b6e69 11977 struct cfg80211_wowlan new_triggers = {};
ae33bd81 11978 struct cfg80211_wowlan *ntrig;
964dc9e2 11979 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan;
ff1b6e69 11980 int err, i;
6abb9cb9 11981 bool prev_enabled = rdev->wiphy.wowlan_config;
98fc4386 11982 bool regular = false;
ff1b6e69 11983
964dc9e2 11984 if (!wowlan)
ff1b6e69
JB
11985 return -EOPNOTSUPP;
11986
ae33bd81
JB
11987 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) {
11988 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 11989 rdev->wiphy.wowlan_config = NULL;
ae33bd81
JB
11990 goto set_wakeup;
11991 }
ff1b6e69 11992
8cb08174
JB
11993 err = nla_parse_nested_deprecated(tb, MAX_NL80211_WOWLAN_TRIG,
11994 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS],
11995 nl80211_wowlan_policy, info->extack);
ff1b6e69
JB
11996 if (err)
11997 return err;
11998
11999 if (tb[NL80211_WOWLAN_TRIG_ANY]) {
12000 if (!(wowlan->flags & WIPHY_WOWLAN_ANY))
12001 return -EINVAL;
12002 new_triggers.any = true;
12003 }
12004
12005 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) {
12006 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT))
12007 return -EINVAL;
12008 new_triggers.disconnect = true;
98fc4386 12009 regular = true;
ff1b6e69
JB
12010 }
12011
12012 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) {
12013 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT))
12014 return -EINVAL;
12015 new_triggers.magic_pkt = true;
98fc4386 12016 regular = true;
ff1b6e69
JB
12017 }
12018
77dbbb13
JB
12019 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED])
12020 return -EINVAL;
12021
12022 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) {
12023 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE))
12024 return -EINVAL;
12025 new_triggers.gtk_rekey_failure = true;
98fc4386 12026 regular = true;
77dbbb13
JB
12027 }
12028
12029 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) {
12030 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ))
12031 return -EINVAL;
12032 new_triggers.eap_identity_req = true;
98fc4386 12033 regular = true;
77dbbb13
JB
12034 }
12035
12036 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) {
12037 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE))
12038 return -EINVAL;
12039 new_triggers.four_way_handshake = true;
98fc4386 12040 regular = true;
77dbbb13
JB
12041 }
12042
12043 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) {
12044 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE))
12045 return -EINVAL;
12046 new_triggers.rfkill_release = true;
98fc4386 12047 regular = true;
77dbbb13
JB
12048 }
12049
ff1b6e69
JB
12050 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) {
12051 struct nlattr *pat;
12052 int n_patterns = 0;
bb92d199 12053 int rem, pat_len, mask_len, pkt_offset;
50ac6607 12054 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
ff1b6e69 12055
98fc4386
JB
12056 regular = true;
12057
ff1b6e69
JB
12058 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
12059 rem)
12060 n_patterns++;
12061 if (n_patterns > wowlan->n_patterns)
12062 return -EINVAL;
12063
12064 new_triggers.patterns = kcalloc(n_patterns,
12065 sizeof(new_triggers.patterns[0]),
12066 GFP_KERNEL);
12067 if (!new_triggers.patterns)
12068 return -ENOMEM;
12069
12070 new_triggers.n_patterns = n_patterns;
12071 i = 0;
12072
12073 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN],
12074 rem) {
922bd80f
JB
12075 u8 *mask_pat;
12076
8cb08174
JB
12077 err = nla_parse_nested_deprecated(pat_tb,
12078 MAX_NL80211_PKTPAT,
12079 pat,
12080 nl80211_packet_pattern_policy,
12081 info->extack);
95bca62f
JB
12082 if (err)
12083 goto error;
12084
ff1b6e69 12085 err = -EINVAL;
50ac6607
AK
12086 if (!pat_tb[NL80211_PKTPAT_MASK] ||
12087 !pat_tb[NL80211_PKTPAT_PATTERN])
ff1b6e69 12088 goto error;
50ac6607 12089 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
ff1b6e69 12090 mask_len = DIV_ROUND_UP(pat_len, 8);
50ac6607 12091 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
ff1b6e69
JB
12092 goto error;
12093 if (pat_len > wowlan->pattern_max_len ||
12094 pat_len < wowlan->pattern_min_len)
12095 goto error;
12096
50ac6607 12097 if (!pat_tb[NL80211_PKTPAT_OFFSET])
bb92d199
AK
12098 pkt_offset = 0;
12099 else
12100 pkt_offset = nla_get_u32(
50ac6607 12101 pat_tb[NL80211_PKTPAT_OFFSET]);
bb92d199
AK
12102 if (pkt_offset > wowlan->max_pkt_offset)
12103 goto error;
12104 new_triggers.patterns[i].pkt_offset = pkt_offset;
12105
922bd80f
JB
12106 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
12107 if (!mask_pat) {
ff1b6e69
JB
12108 err = -ENOMEM;
12109 goto error;
12110 }
922bd80f
JB
12111 new_triggers.patterns[i].mask = mask_pat;
12112 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
ff1b6e69 12113 mask_len);
922bd80f
JB
12114 mask_pat += mask_len;
12115 new_triggers.patterns[i].pattern = mask_pat;
ff1b6e69 12116 new_triggers.patterns[i].pattern_len = pat_len;
922bd80f 12117 memcpy(mask_pat,
50ac6607 12118 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
ff1b6e69
JB
12119 pat_len);
12120 i++;
12121 }
12122 }
12123
2a0e047e 12124 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) {
98fc4386 12125 regular = true;
2a0e047e
JB
12126 err = nl80211_parse_wowlan_tcp(
12127 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION],
12128 &new_triggers);
12129 if (err)
12130 goto error;
12131 }
12132
8cd4d456 12133 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) {
98fc4386 12134 regular = true;
8cd4d456
LC
12135 err = nl80211_parse_wowlan_nd(
12136 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT],
12137 &new_triggers);
12138 if (err)
12139 goto error;
12140 }
12141
98fc4386
JB
12142 /* The 'any' trigger means the device continues operating more or less
12143 * as in its normal operation mode and wakes up the host on most of the
12144 * normal interrupts (like packet RX, ...)
12145 * It therefore makes little sense to combine with the more constrained
12146 * wakeup trigger modes.
12147 */
12148 if (new_triggers.any && regular) {
12149 err = -EINVAL;
12150 goto error;
12151 }
12152
ae33bd81
JB
12153 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL);
12154 if (!ntrig) {
12155 err = -ENOMEM;
12156 goto error;
ff1b6e69 12157 }
ae33bd81 12158 cfg80211_rdev_free_wowlan(rdev);
6abb9cb9 12159 rdev->wiphy.wowlan_config = ntrig;
ff1b6e69 12160
ae33bd81 12161 set_wakeup:
6abb9cb9
JB
12162 if (rdev->ops->set_wakeup &&
12163 prev_enabled != !!rdev->wiphy.wowlan_config)
12164 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config);
6d52563f 12165
ff1b6e69
JB
12166 return 0;
12167 error:
12168 for (i = 0; i < new_triggers.n_patterns; i++)
12169 kfree(new_triggers.patterns[i].mask);
12170 kfree(new_triggers.patterns);
2a0e047e
JB
12171 if (new_triggers.tcp && new_triggers.tcp->sock)
12172 sock_release(new_triggers.tcp->sock);
12173 kfree(new_triggers.tcp);
e5dbe070 12174 kfree(new_triggers.nd_config);
ff1b6e69
JB
12175 return err;
12176}
dfb89c56 12177#endif
ff1b6e69 12178
be29b99a
AK
12179static int nl80211_send_coalesce_rules(struct sk_buff *msg,
12180 struct cfg80211_registered_device *rdev)
12181{
12182 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules;
12183 int i, j, pat_len;
12184 struct cfg80211_coalesce_rules *rule;
12185
12186 if (!rdev->coalesce->n_rules)
12187 return 0;
12188
ae0be8de 12189 nl_rules = nla_nest_start_noflag(msg, NL80211_ATTR_COALESCE_RULE);
be29b99a
AK
12190 if (!nl_rules)
12191 return -ENOBUFS;
12192
12193 for (i = 0; i < rdev->coalesce->n_rules; i++) {
ae0be8de 12194 nl_rule = nla_nest_start_noflag(msg, i + 1);
be29b99a
AK
12195 if (!nl_rule)
12196 return -ENOBUFS;
12197
12198 rule = &rdev->coalesce->rules[i];
12199 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY,
12200 rule->delay))
12201 return -ENOBUFS;
12202
12203 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION,
12204 rule->condition))
12205 return -ENOBUFS;
12206
ae0be8de
MK
12207 nl_pats = nla_nest_start_noflag(msg,
12208 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN);
be29b99a
AK
12209 if (!nl_pats)
12210 return -ENOBUFS;
12211
12212 for (j = 0; j < rule->n_patterns; j++) {
ae0be8de 12213 nl_pat = nla_nest_start_noflag(msg, j + 1);
be29b99a
AK
12214 if (!nl_pat)
12215 return -ENOBUFS;
12216 pat_len = rule->patterns[j].pattern_len;
12217 if (nla_put(msg, NL80211_PKTPAT_MASK,
12218 DIV_ROUND_UP(pat_len, 8),
12219 rule->patterns[j].mask) ||
12220 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len,
12221 rule->patterns[j].pattern) ||
12222 nla_put_u32(msg, NL80211_PKTPAT_OFFSET,
12223 rule->patterns[j].pkt_offset))
12224 return -ENOBUFS;
12225 nla_nest_end(msg, nl_pat);
12226 }
12227 nla_nest_end(msg, nl_pats);
12228 nla_nest_end(msg, nl_rule);
12229 }
12230 nla_nest_end(msg, nl_rules);
12231
12232 return 0;
12233}
12234
12235static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info)
12236{
12237 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12238 struct sk_buff *msg;
12239 void *hdr;
12240
12241 if (!rdev->wiphy.coalesce)
12242 return -EOPNOTSUPP;
12243
12244 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12245 if (!msg)
12246 return -ENOMEM;
12247
12248 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12249 NL80211_CMD_GET_COALESCE);
12250 if (!hdr)
12251 goto nla_put_failure;
12252
12253 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev))
12254 goto nla_put_failure;
12255
12256 genlmsg_end(msg, hdr);
12257 return genlmsg_reply(msg, info);
12258
12259nla_put_failure:
12260 nlmsg_free(msg);
12261 return -ENOBUFS;
12262}
12263
12264void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev)
12265{
12266 struct cfg80211_coalesce *coalesce = rdev->coalesce;
12267 int i, j;
12268 struct cfg80211_coalesce_rules *rule;
12269
12270 if (!coalesce)
12271 return;
12272
12273 for (i = 0; i < coalesce->n_rules; i++) {
12274 rule = &coalesce->rules[i];
12275 for (j = 0; j < rule->n_patterns; j++)
12276 kfree(rule->patterns[j].mask);
12277 kfree(rule->patterns);
12278 }
12279 kfree(coalesce->rules);
12280 kfree(coalesce);
12281 rdev->coalesce = NULL;
12282}
12283
12284static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev,
12285 struct nlattr *rule,
12286 struct cfg80211_coalesce_rules *new_rule)
12287{
12288 int err, i;
12289 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
12290 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat;
12291 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0;
12292 struct nlattr *pat_tb[NUM_NL80211_PKTPAT];
12293
8cb08174
JB
12294 err = nla_parse_nested_deprecated(tb, NL80211_ATTR_COALESCE_RULE_MAX,
12295 rule, nl80211_coalesce_policy, NULL);
be29b99a
AK
12296 if (err)
12297 return err;
12298
12299 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY])
12300 new_rule->delay =
12301 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]);
12302 if (new_rule->delay > coalesce->max_delay)
12303 return -EINVAL;
12304
12305 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION])
12306 new_rule->condition =
12307 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]);
be29b99a
AK
12308
12309 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN])
12310 return -EINVAL;
12311
12312 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
12313 rem)
12314 n_patterns++;
12315 if (n_patterns > coalesce->n_patterns)
12316 return -EINVAL;
12317
12318 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]),
12319 GFP_KERNEL);
12320 if (!new_rule->patterns)
12321 return -ENOMEM;
12322
12323 new_rule->n_patterns = n_patterns;
12324 i = 0;
12325
12326 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN],
12327 rem) {
922bd80f
JB
12328 u8 *mask_pat;
12329
8cb08174
JB
12330 err = nla_parse_nested_deprecated(pat_tb, MAX_NL80211_PKTPAT,
12331 pat,
12332 nl80211_packet_pattern_policy,
12333 NULL);
95bca62f
JB
12334 if (err)
12335 return err;
12336
be29b99a
AK
12337 if (!pat_tb[NL80211_PKTPAT_MASK] ||
12338 !pat_tb[NL80211_PKTPAT_PATTERN])
12339 return -EINVAL;
12340 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]);
12341 mask_len = DIV_ROUND_UP(pat_len, 8);
12342 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len)
12343 return -EINVAL;
12344 if (pat_len > coalesce->pattern_max_len ||
12345 pat_len < coalesce->pattern_min_len)
12346 return -EINVAL;
12347
12348 if (!pat_tb[NL80211_PKTPAT_OFFSET])
12349 pkt_offset = 0;
12350 else
12351 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]);
12352 if (pkt_offset > coalesce->max_pkt_offset)
12353 return -EINVAL;
12354 new_rule->patterns[i].pkt_offset = pkt_offset;
12355
922bd80f
JB
12356 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL);
12357 if (!mask_pat)
be29b99a 12358 return -ENOMEM;
922bd80f
JB
12359
12360 new_rule->patterns[i].mask = mask_pat;
12361 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]),
12362 mask_len);
12363
12364 mask_pat += mask_len;
12365 new_rule->patterns[i].pattern = mask_pat;
be29b99a 12366 new_rule->patterns[i].pattern_len = pat_len;
922bd80f
JB
12367 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]),
12368 pat_len);
be29b99a
AK
12369 i++;
12370 }
12371
12372 return 0;
12373}
12374
12375static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info)
12376{
12377 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12378 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce;
12379 struct cfg80211_coalesce new_coalesce = {};
12380 struct cfg80211_coalesce *n_coalesce;
12381 int err, rem_rule, n_rules = 0, i, j;
12382 struct nlattr *rule;
12383 struct cfg80211_coalesce_rules *tmp_rule;
12384
12385 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce)
12386 return -EOPNOTSUPP;
12387
12388 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) {
12389 cfg80211_rdev_free_coalesce(rdev);
a1056b1b 12390 rdev_set_coalesce(rdev, NULL);
be29b99a
AK
12391 return 0;
12392 }
12393
12394 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
12395 rem_rule)
12396 n_rules++;
12397 if (n_rules > coalesce->n_rules)
12398 return -EINVAL;
12399
12400 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]),
12401 GFP_KERNEL);
12402 if (!new_coalesce.rules)
12403 return -ENOMEM;
12404
12405 new_coalesce.n_rules = n_rules;
12406 i = 0;
12407
12408 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE],
12409 rem_rule) {
12410 err = nl80211_parse_coalesce_rule(rdev, rule,
12411 &new_coalesce.rules[i]);
12412 if (err)
12413 goto error;
12414
12415 i++;
12416 }
12417
a1056b1b 12418 err = rdev_set_coalesce(rdev, &new_coalesce);
be29b99a
AK
12419 if (err)
12420 goto error;
12421
12422 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL);
12423 if (!n_coalesce) {
12424 err = -ENOMEM;
12425 goto error;
12426 }
12427 cfg80211_rdev_free_coalesce(rdev);
12428 rdev->coalesce = n_coalesce;
12429
12430 return 0;
12431error:
12432 for (i = 0; i < new_coalesce.n_rules; i++) {
12433 tmp_rule = &new_coalesce.rules[i];
12434 for (j = 0; j < tmp_rule->n_patterns; j++)
12435 kfree(tmp_rule->patterns[j].mask);
12436 kfree(tmp_rule->patterns);
12437 }
12438 kfree(new_coalesce.rules);
12439
12440 return err;
12441}
12442
e5497d76
JB
12443static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info)
12444{
12445 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12446 struct net_device *dev = info->user_ptr[1];
12447 struct wireless_dev *wdev = dev->ieee80211_ptr;
12448 struct nlattr *tb[NUM_NL80211_REKEY_DATA];
12449 struct cfg80211_gtk_rekey_data rekey_data;
12450 int err;
12451
12452 if (!info->attrs[NL80211_ATTR_REKEY_DATA])
12453 return -EINVAL;
12454
8cb08174
JB
12455 err = nla_parse_nested_deprecated(tb, MAX_NL80211_REKEY_DATA,
12456 info->attrs[NL80211_ATTR_REKEY_DATA],
12457 nl80211_rekey_policy, info->extack);
e5497d76
JB
12458 if (err)
12459 return err;
12460
e785fa0a
VD
12461 if (!tb[NL80211_REKEY_DATA_REPLAY_CTR] || !tb[NL80211_REKEY_DATA_KEK] ||
12462 !tb[NL80211_REKEY_DATA_KCK])
12463 return -EINVAL;
093a48d2
NE
12464 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN &&
12465 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_EXT_KEK_KCK &&
12466 nla_len(tb[NL80211_REKEY_DATA_KEK]) == NL80211_KEK_EXT_LEN))
e5497d76 12467 return -ERANGE;
093a48d2
NE
12468 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN &&
12469 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_EXT_KEK_KCK &&
12470 nla_len(tb[NL80211_REKEY_DATA_KEK]) == NL80211_KCK_EXT_LEN))
e5497d76
JB
12471 return -ERANGE;
12472
78f686ca
JB
12473 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]);
12474 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]);
12475 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]);
093a48d2
NE
12476 rekey_data.kek_len = nla_len(tb[NL80211_REKEY_DATA_KEK]);
12477 rekey_data.kck_len = nla_len(tb[NL80211_REKEY_DATA_KCK]);
12478 if (tb[NL80211_REKEY_DATA_AKM])
12479 rekey_data.akm = nla_get_u32(tb[NL80211_REKEY_DATA_AKM]);
e5497d76
JB
12480
12481 wdev_lock(wdev);
12482 if (!wdev->current_bss) {
12483 err = -ENOTCONN;
12484 goto out;
12485 }
12486
12487 if (!rdev->ops->set_rekey_data) {
12488 err = -EOPNOTSUPP;
12489 goto out;
12490 }
12491
e35e4d28 12492 err = rdev_set_rekey_data(rdev, dev, &rekey_data);
e5497d76
JB
12493 out:
12494 wdev_unlock(wdev);
12495 return err;
12496}
12497
28946da7
JB
12498static int nl80211_register_unexpected_frame(struct sk_buff *skb,
12499 struct genl_info *info)
12500{
12501 struct net_device *dev = info->user_ptr[1];
12502 struct wireless_dev *wdev = dev->ieee80211_ptr;
12503
12504 if (wdev->iftype != NL80211_IFTYPE_AP &&
12505 wdev->iftype != NL80211_IFTYPE_P2P_GO)
12506 return -EINVAL;
12507
15e47304 12508 if (wdev->ap_unexpected_nlportid)
28946da7
JB
12509 return -EBUSY;
12510
15e47304 12511 wdev->ap_unexpected_nlportid = info->snd_portid;
28946da7
JB
12512 return 0;
12513}
12514
7f6cf311
JB
12515static int nl80211_probe_client(struct sk_buff *skb,
12516 struct genl_info *info)
12517{
12518 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12519 struct net_device *dev = info->user_ptr[1];
12520 struct wireless_dev *wdev = dev->ieee80211_ptr;
12521 struct sk_buff *msg;
12522 void *hdr;
12523 const u8 *addr;
12524 u64 cookie;
12525 int err;
12526
12527 if (wdev->iftype != NL80211_IFTYPE_AP &&
12528 wdev->iftype != NL80211_IFTYPE_P2P_GO)
12529 return -EOPNOTSUPP;
12530
12531 if (!info->attrs[NL80211_ATTR_MAC])
12532 return -EINVAL;
12533
12534 if (!rdev->ops->probe_client)
12535 return -EOPNOTSUPP;
12536
12537 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12538 if (!msg)
12539 return -ENOMEM;
12540
15e47304 12541 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
7f6cf311 12542 NL80211_CMD_PROBE_CLIENT);
cb35fba3
DC
12543 if (!hdr) {
12544 err = -ENOBUFS;
7f6cf311
JB
12545 goto free_msg;
12546 }
12547
12548 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
12549
e35e4d28 12550 err = rdev_probe_client(rdev, dev, addr, &cookie);
7f6cf311
JB
12551 if (err)
12552 goto free_msg;
12553
2dad624e
ND
12554 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
12555 NL80211_ATTR_PAD))
9360ffd1 12556 goto nla_put_failure;
7f6cf311
JB
12557
12558 genlmsg_end(msg, hdr);
12559
12560 return genlmsg_reply(msg, info);
12561
12562 nla_put_failure:
12563 err = -ENOBUFS;
12564 free_msg:
12565 nlmsg_free(msg);
12566 return err;
12567}
12568
5e760230
JB
12569static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info)
12570{
12571 struct cfg80211_registered_device *rdev = info->user_ptr[0];
37c73b5f
BG
12572 struct cfg80211_beacon_registration *reg, *nreg;
12573 int rv;
5e760230
JB
12574
12575 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS))
12576 return -EOPNOTSUPP;
12577
37c73b5f
BG
12578 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL);
12579 if (!nreg)
12580 return -ENOMEM;
12581
12582 /* First, check if already registered. */
12583 spin_lock_bh(&rdev->beacon_registrations_lock);
12584 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
12585 if (reg->nlportid == info->snd_portid) {
12586 rv = -EALREADY;
12587 goto out_err;
12588 }
12589 }
12590 /* Add it to the list */
12591 nreg->nlportid = info->snd_portid;
12592 list_add(&nreg->list, &rdev->beacon_registrations);
5e760230 12593
37c73b5f 12594 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
12595
12596 return 0;
37c73b5f
BG
12597out_err:
12598 spin_unlock_bh(&rdev->beacon_registrations_lock);
12599 kfree(nreg);
12600 return rv;
5e760230
JB
12601}
12602
98104fde
JB
12603static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info)
12604{
12605 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12606 struct wireless_dev *wdev = info->user_ptr[1];
12607 int err;
12608
12609 if (!rdev->ops->start_p2p_device)
12610 return -EOPNOTSUPP;
12611
12612 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
12613 return -EOPNOTSUPP;
12614
73c7da3d 12615 if (wdev_running(wdev))
98104fde
JB
12616 return 0;
12617
b6a55015
LC
12618 if (rfkill_blocked(rdev->rfkill))
12619 return -ERFKILL;
98104fde 12620
eeb126e9 12621 err = rdev_start_p2p_device(rdev, wdev);
98104fde
JB
12622 if (err)
12623 return err;
12624
73c7da3d 12625 wdev->is_running = true;
98104fde 12626 rdev->opencount++;
98104fde
JB
12627
12628 return 0;
12629}
12630
12631static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info)
12632{
12633 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12634 struct wireless_dev *wdev = info->user_ptr[1];
12635
12636 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE)
12637 return -EOPNOTSUPP;
12638
12639 if (!rdev->ops->stop_p2p_device)
12640 return -EOPNOTSUPP;
12641
f9f47529 12642 cfg80211_stop_p2p_device(rdev, wdev);
98104fde
JB
12643
12644 return 0;
12645}
12646
cb3b7d87
AB
12647static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info)
12648{
12649 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12650 struct wireless_dev *wdev = info->user_ptr[1];
12651 struct cfg80211_nan_conf conf = {};
12652 int err;
12653
12654 if (wdev->iftype != NL80211_IFTYPE_NAN)
12655 return -EOPNOTSUPP;
12656
eeb04a96 12657 if (wdev_running(wdev))
cb3b7d87
AB
12658 return -EEXIST;
12659
12660 if (rfkill_blocked(rdev->rfkill))
12661 return -ERFKILL;
12662
12663 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF])
12664 return -EINVAL;
12665
cb3b7d87
AB
12666 conf.master_pref =
12667 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
cb3b7d87 12668
8585989d
LC
12669 if (info->attrs[NL80211_ATTR_BANDS]) {
12670 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
12671
12672 if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
12673 return -EOPNOTSUPP;
12674
12675 if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
12676 return -EINVAL;
12677
12678 conf.bands = bands;
12679 }
cb3b7d87
AB
12680
12681 err = rdev_start_nan(rdev, wdev, &conf);
12682 if (err)
12683 return err;
12684
73c7da3d 12685 wdev->is_running = true;
cb3b7d87
AB
12686 rdev->opencount++;
12687
12688 return 0;
12689}
12690
12691static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info)
12692{
12693 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12694 struct wireless_dev *wdev = info->user_ptr[1];
12695
12696 if (wdev->iftype != NL80211_IFTYPE_NAN)
12697 return -EOPNOTSUPP;
12698
12699 cfg80211_stop_nan(rdev, wdev);
12700
12701 return 0;
12702}
12703
a442b761
AB
12704static int validate_nan_filter(struct nlattr *filter_attr)
12705{
12706 struct nlattr *attr;
12707 int len = 0, n_entries = 0, rem;
12708
12709 nla_for_each_nested(attr, filter_attr, rem) {
12710 len += nla_len(attr);
12711 n_entries++;
12712 }
12713
12714 if (len >= U8_MAX)
12715 return -EINVAL;
12716
12717 return n_entries;
12718}
12719
12720static int handle_nan_filter(struct nlattr *attr_filter,
12721 struct cfg80211_nan_func *func,
12722 bool tx)
12723{
12724 struct nlattr *attr;
12725 int n_entries, rem, i;
12726 struct cfg80211_nan_func_filter *filter;
12727
12728 n_entries = validate_nan_filter(attr_filter);
12729 if (n_entries < 0)
12730 return n_entries;
12731
12732 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters));
12733
12734 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL);
12735 if (!filter)
12736 return -ENOMEM;
12737
12738 i = 0;
12739 nla_for_each_nested(attr, attr_filter, rem) {
b15ca182 12740 filter[i].filter = nla_memdup(attr, GFP_KERNEL);
a442b761
AB
12741 filter[i].len = nla_len(attr);
12742 i++;
12743 }
12744 if (tx) {
12745 func->num_tx_filters = n_entries;
12746 func->tx_filters = filter;
12747 } else {
12748 func->num_rx_filters = n_entries;
12749 func->rx_filters = filter;
12750 }
12751
12752 return 0;
12753}
12754
12755static int nl80211_nan_add_func(struct sk_buff *skb,
12756 struct genl_info *info)
12757{
12758 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12759 struct wireless_dev *wdev = info->user_ptr[1];
12760 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr;
12761 struct cfg80211_nan_func *func;
12762 struct sk_buff *msg = NULL;
12763 void *hdr = NULL;
12764 int err = 0;
12765
12766 if (wdev->iftype != NL80211_IFTYPE_NAN)
12767 return -EOPNOTSUPP;
12768
73c7da3d 12769 if (!wdev_running(wdev))
a442b761
AB
12770 return -ENOTCONN;
12771
12772 if (!info->attrs[NL80211_ATTR_NAN_FUNC])
12773 return -EINVAL;
12774
8cb08174
JB
12775 err = nla_parse_nested_deprecated(tb, NL80211_NAN_FUNC_ATTR_MAX,
12776 info->attrs[NL80211_ATTR_NAN_FUNC],
12777 nl80211_nan_func_policy,
12778 info->extack);
a442b761
AB
12779 if (err)
12780 return err;
12781
12782 func = kzalloc(sizeof(*func), GFP_KERNEL);
12783 if (!func)
12784 return -ENOMEM;
12785
b60ad348 12786 func->cookie = cfg80211_assign_cookie(rdev);
a442b761 12787
cb9abd48 12788 if (!tb[NL80211_NAN_FUNC_TYPE]) {
a442b761
AB
12789 err = -EINVAL;
12790 goto out;
12791 }
12792
12793
12794 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]);
12795
12796 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) {
12797 err = -EINVAL;
12798 goto out;
12799 }
12800
12801 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]),
12802 sizeof(func->service_id));
12803
12804 func->close_range =
12805 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]);
12806
12807 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) {
12808 func->serv_spec_info_len =
12809 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]);
12810 func->serv_spec_info =
12811 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]),
12812 func->serv_spec_info_len,
12813 GFP_KERNEL);
12814 if (!func->serv_spec_info) {
12815 err = -ENOMEM;
12816 goto out;
12817 }
12818 }
12819
12820 if (tb[NL80211_NAN_FUNC_TTL])
12821 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]);
12822
12823 switch (func->type) {
12824 case NL80211_NAN_FUNC_PUBLISH:
12825 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) {
12826 err = -EINVAL;
12827 goto out;
12828 }
12829
12830 func->publish_type =
12831 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]);
12832 func->publish_bcast =
12833 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]);
12834
12835 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) &&
12836 func->publish_bcast) {
12837 err = -EINVAL;
12838 goto out;
12839 }
12840 break;
12841 case NL80211_NAN_FUNC_SUBSCRIBE:
12842 func->subscribe_active =
12843 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]);
12844 break;
12845 case NL80211_NAN_FUNC_FOLLOW_UP:
12846 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] ||
3ea15452
HC
12847 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] ||
12848 !tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]) {
a442b761
AB
12849 err = -EINVAL;
12850 goto out;
12851 }
12852
12853 func->followup_id =
12854 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]);
12855 func->followup_reqid =
12856 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]);
12857 memcpy(func->followup_dest.addr,
12858 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]),
12859 sizeof(func->followup_dest.addr));
12860 if (func->ttl) {
12861 err = -EINVAL;
12862 goto out;
12863 }
12864 break;
12865 default:
12866 err = -EINVAL;
12867 goto out;
12868 }
12869
12870 if (tb[NL80211_NAN_FUNC_SRF]) {
12871 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR];
12872
8cb08174
JB
12873 err = nla_parse_nested_deprecated(srf_tb,
12874 NL80211_NAN_SRF_ATTR_MAX,
12875 tb[NL80211_NAN_FUNC_SRF],
12876 nl80211_nan_srf_policy,
12877 info->extack);
a442b761
AB
12878 if (err)
12879 goto out;
12880
12881 func->srf_include =
12882 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]);
12883
12884 if (srf_tb[NL80211_NAN_SRF_BF]) {
12885 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] ||
12886 !srf_tb[NL80211_NAN_SRF_BF_IDX]) {
12887 err = -EINVAL;
12888 goto out;
12889 }
12890
12891 func->srf_bf_len =
12892 nla_len(srf_tb[NL80211_NAN_SRF_BF]);
12893 func->srf_bf =
12894 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]),
12895 func->srf_bf_len, GFP_KERNEL);
12896 if (!func->srf_bf) {
12897 err = -ENOMEM;
12898 goto out;
12899 }
12900
12901 func->srf_bf_idx =
12902 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]);
12903 } else {
12904 struct nlattr *attr, *mac_attr =
12905 srf_tb[NL80211_NAN_SRF_MAC_ADDRS];
12906 int n_entries, rem, i = 0;
12907
12908 if (!mac_attr) {
12909 err = -EINVAL;
12910 goto out;
12911 }
12912
12913 n_entries = validate_acl_mac_addrs(mac_attr);
12914 if (n_entries <= 0) {
12915 err = -EINVAL;
12916 goto out;
12917 }
12918
12919 func->srf_num_macs = n_entries;
12920 func->srf_macs =
6396bb22 12921 kcalloc(n_entries, sizeof(*func->srf_macs),
a442b761
AB
12922 GFP_KERNEL);
12923 if (!func->srf_macs) {
12924 err = -ENOMEM;
12925 goto out;
12926 }
12927
12928 nla_for_each_nested(attr, mac_attr, rem)
12929 memcpy(func->srf_macs[i++].addr, nla_data(attr),
12930 sizeof(*func->srf_macs));
12931 }
12932 }
12933
12934 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) {
12935 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER],
12936 func, true);
12937 if (err)
12938 goto out;
12939 }
12940
12941 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) {
12942 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER],
12943 func, false);
12944 if (err)
12945 goto out;
12946 }
12947
12948 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
12949 if (!msg) {
12950 err = -ENOMEM;
12951 goto out;
12952 }
12953
12954 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
12955 NL80211_CMD_ADD_NAN_FUNCTION);
12956 /* This can't really happen - we just allocated 4KB */
12957 if (WARN_ON(!hdr)) {
12958 err = -ENOMEM;
12959 goto out;
12960 }
12961
12962 err = rdev_add_nan_func(rdev, wdev, func);
12963out:
12964 if (err < 0) {
12965 cfg80211_free_nan_func(func);
12966 nlmsg_free(msg);
12967 return err;
12968 }
12969
12970 /* propagate the instance id and cookie to userspace */
12971 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie,
12972 NL80211_ATTR_PAD))
12973 goto nla_put_failure;
12974
ae0be8de 12975 func_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_FUNC);
a442b761
AB
12976 if (!func_attr)
12977 goto nla_put_failure;
12978
12979 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID,
12980 func->instance_id))
12981 goto nla_put_failure;
12982
12983 nla_nest_end(msg, func_attr);
12984
12985 genlmsg_end(msg, hdr);
12986 return genlmsg_reply(msg, info);
12987
12988nla_put_failure:
12989 nlmsg_free(msg);
12990 return -ENOBUFS;
12991}
12992
12993static int nl80211_nan_del_func(struct sk_buff *skb,
12994 struct genl_info *info)
12995{
12996 struct cfg80211_registered_device *rdev = info->user_ptr[0];
12997 struct wireless_dev *wdev = info->user_ptr[1];
12998 u64 cookie;
12999
13000 if (wdev->iftype != NL80211_IFTYPE_NAN)
13001 return -EOPNOTSUPP;
13002
73c7da3d 13003 if (!wdev_running(wdev))
a442b761
AB
13004 return -ENOTCONN;
13005
13006 if (!info->attrs[NL80211_ATTR_COOKIE])
13007 return -EINVAL;
13008
a442b761
AB
13009 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
13010
13011 rdev_del_nan_func(rdev, wdev, cookie);
13012
13013 return 0;
13014}
13015
a5a9dcf2
AB
13016static int nl80211_nan_change_config(struct sk_buff *skb,
13017 struct genl_info *info)
13018{
13019 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13020 struct wireless_dev *wdev = info->user_ptr[1];
13021 struct cfg80211_nan_conf conf = {};
13022 u32 changed = 0;
13023
13024 if (wdev->iftype != NL80211_IFTYPE_NAN)
13025 return -EOPNOTSUPP;
13026
73c7da3d 13027 if (!wdev_running(wdev))
a5a9dcf2
AB
13028 return -ENOTCONN;
13029
13030 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) {
13031 conf.master_pref =
13032 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]);
13033 if (conf.master_pref <= 1 || conf.master_pref == 255)
13034 return -EINVAL;
13035
13036 changed |= CFG80211_NAN_CONF_CHANGED_PREF;
13037 }
13038
8585989d
LC
13039 if (info->attrs[NL80211_ATTR_BANDS]) {
13040 u32 bands = nla_get_u32(info->attrs[NL80211_ATTR_BANDS]);
13041
13042 if (bands & ~(u32)wdev->wiphy->nan_supported_bands)
13043 return -EOPNOTSUPP;
13044
13045 if (bands && !(bands & BIT(NL80211_BAND_2GHZ)))
13046 return -EINVAL;
13047
13048 conf.bands = bands;
13049 changed |= CFG80211_NAN_CONF_CHANGED_BANDS;
a5a9dcf2
AB
13050 }
13051
13052 if (!changed)
13053 return -EINVAL;
13054
13055 return rdev_nan_change_conf(rdev, wdev, &conf, changed);
13056}
13057
50bcd31d
AB
13058void cfg80211_nan_match(struct wireless_dev *wdev,
13059 struct cfg80211_nan_match_params *match, gfp_t gfp)
13060{
13061 struct wiphy *wiphy = wdev->wiphy;
13062 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
13063 struct nlattr *match_attr, *local_func_attr, *peer_func_attr;
13064 struct sk_buff *msg;
13065 void *hdr;
13066
13067 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr))
13068 return;
13069
13070 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13071 if (!msg)
13072 return;
13073
13074 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH);
13075 if (!hdr) {
13076 nlmsg_free(msg);
13077 return;
13078 }
13079
13080 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13081 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
13082 wdev->netdev->ifindex)) ||
13083 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
13084 NL80211_ATTR_PAD))
13085 goto nla_put_failure;
13086
13087 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie,
13088 NL80211_ATTR_PAD) ||
13089 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr))
13090 goto nla_put_failure;
13091
ae0be8de 13092 match_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_MATCH);
50bcd31d
AB
13093 if (!match_attr)
13094 goto nla_put_failure;
13095
ae0be8de
MK
13096 local_func_attr = nla_nest_start_noflag(msg,
13097 NL80211_NAN_MATCH_FUNC_LOCAL);
50bcd31d
AB
13098 if (!local_func_attr)
13099 goto nla_put_failure;
13100
13101 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id))
13102 goto nla_put_failure;
13103
13104 nla_nest_end(msg, local_func_attr);
13105
ae0be8de
MK
13106 peer_func_attr = nla_nest_start_noflag(msg,
13107 NL80211_NAN_MATCH_FUNC_PEER);
50bcd31d
AB
13108 if (!peer_func_attr)
13109 goto nla_put_failure;
13110
13111 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) ||
13112 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id))
13113 goto nla_put_failure;
13114
13115 if (match->info && match->info_len &&
13116 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len,
13117 match->info))
13118 goto nla_put_failure;
13119
13120 nla_nest_end(msg, peer_func_attr);
13121 nla_nest_end(msg, match_attr);
13122 genlmsg_end(msg, hdr);
13123
13124 if (!wdev->owner_nlportid)
13125 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
13126 msg, 0, NL80211_MCGRP_NAN, gfp);
13127 else
13128 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
13129 wdev->owner_nlportid);
13130
13131 return;
13132
13133nla_put_failure:
13134 nlmsg_free(msg);
13135}
13136EXPORT_SYMBOL(cfg80211_nan_match);
13137
368e5a7b
AB
13138void cfg80211_nan_func_terminated(struct wireless_dev *wdev,
13139 u8 inst_id,
13140 enum nl80211_nan_func_term_reason reason,
13141 u64 cookie, gfp_t gfp)
13142{
13143 struct wiphy *wiphy = wdev->wiphy;
13144 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
13145 struct sk_buff *msg;
13146 struct nlattr *func_attr;
13147 void *hdr;
13148
13149 if (WARN_ON(!inst_id))
13150 return;
13151
13152 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
13153 if (!msg)
13154 return;
13155
13156 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION);
13157 if (!hdr) {
13158 nlmsg_free(msg);
13159 return;
13160 }
13161
13162 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
13163 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
13164 wdev->netdev->ifindex)) ||
13165 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
13166 NL80211_ATTR_PAD))
13167 goto nla_put_failure;
13168
13169 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
13170 NL80211_ATTR_PAD))
13171 goto nla_put_failure;
13172
ae0be8de 13173 func_attr = nla_nest_start_noflag(msg, NL80211_ATTR_NAN_FUNC);
368e5a7b
AB
13174 if (!func_attr)
13175 goto nla_put_failure;
13176
13177 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) ||
13178 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason))
13179 goto nla_put_failure;
13180
13181 nla_nest_end(msg, func_attr);
13182 genlmsg_end(msg, hdr);
13183
13184 if (!wdev->owner_nlportid)
13185 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy),
13186 msg, 0, NL80211_MCGRP_NAN, gfp);
13187 else
13188 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
13189 wdev->owner_nlportid);
13190
13191 return;
13192
13193nla_put_failure:
13194 nlmsg_free(msg);
13195}
13196EXPORT_SYMBOL(cfg80211_nan_func_terminated);
13197
3713b4e3
JB
13198static int nl80211_get_protocol_features(struct sk_buff *skb,
13199 struct genl_info *info)
13200{
13201 void *hdr;
13202 struct sk_buff *msg;
13203
13204 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
13205 if (!msg)
13206 return -ENOMEM;
13207
13208 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
13209 NL80211_CMD_GET_PROTOCOL_FEATURES);
13210 if (!hdr)
13211 goto nla_put_failure;
13212
13213 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES,
13214 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP))
13215 goto nla_put_failure;
13216
13217 genlmsg_end(msg, hdr);
13218 return genlmsg_reply(msg, info);
13219
13220 nla_put_failure:
13221 kfree_skb(msg);
13222 return -ENOBUFS;
13223}
13224
355199e0
JM
13225static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info)
13226{
13227 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13228 struct cfg80211_update_ft_ies_params ft_params;
13229 struct net_device *dev = info->user_ptr[1];
13230
13231 if (!rdev->ops->update_ft_ies)
13232 return -EOPNOTSUPP;
13233
13234 if (!info->attrs[NL80211_ATTR_MDID] ||
3d7af878 13235 !info->attrs[NL80211_ATTR_IE])
355199e0
JM
13236 return -EINVAL;
13237
13238 memset(&ft_params, 0, sizeof(ft_params));
13239 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]);
13240 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
13241 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
13242
13243 return rdev_update_ft_ies(rdev, dev, &ft_params);
13244}
13245
5de17984
AS
13246static int nl80211_crit_protocol_start(struct sk_buff *skb,
13247 struct genl_info *info)
13248{
13249 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13250 struct wireless_dev *wdev = info->user_ptr[1];
13251 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC;
13252 u16 duration;
13253 int ret;
13254
13255 if (!rdev->ops->crit_proto_start)
13256 return -EOPNOTSUPP;
13257
13258 if (WARN_ON(!rdev->ops->crit_proto_stop))
13259 return -EINVAL;
13260
13261 if (rdev->crit_proto_nlportid)
13262 return -EBUSY;
13263
13264 /* determine protocol if provided */
13265 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID])
13266 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]);
13267
13268 if (proto >= NUM_NL80211_CRIT_PROTO)
13269 return -EINVAL;
13270
13271 /* timeout must be provided */
13272 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION])
13273 return -EINVAL;
13274
13275 duration =
13276 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]);
13277
5de17984
AS
13278 ret = rdev_crit_proto_start(rdev, wdev, proto, duration);
13279 if (!ret)
13280 rdev->crit_proto_nlportid = info->snd_portid;
13281
13282 return ret;
13283}
13284
13285static int nl80211_crit_protocol_stop(struct sk_buff *skb,
13286 struct genl_info *info)
13287{
13288 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13289 struct wireless_dev *wdev = info->user_ptr[1];
13290
13291 if (!rdev->ops->crit_proto_stop)
13292 return -EOPNOTSUPP;
13293
13294 if (rdev->crit_proto_nlportid) {
13295 rdev->crit_proto_nlportid = 0;
13296 rdev_crit_proto_stop(rdev, wdev);
13297 }
13298 return 0;
13299}
13300
901bb989
JB
13301static int nl80211_vendor_check_policy(const struct wiphy_vendor_command *vcmd,
13302 struct nlattr *attr,
13303 struct netlink_ext_ack *extack)
13304{
13305 if (vcmd->policy == VENDOR_CMD_RAW_DATA) {
13306 if (attr->nla_type & NLA_F_NESTED) {
13307 NL_SET_ERR_MSG_ATTR(extack, attr,
13308 "unexpected nested data");
13309 return -EINVAL;
13310 }
13311
13312 return 0;
13313 }
13314
13315 if (!(attr->nla_type & NLA_F_NESTED)) {
13316 NL_SET_ERR_MSG_ATTR(extack, attr, "expected nested data");
13317 return -EINVAL;
13318 }
13319
32d5109a 13320 return nla_validate_nested(attr, vcmd->maxattr, vcmd->policy, extack);
901bb989
JB
13321}
13322
ad7e718c
JB
13323static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info)
13324{
13325 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13326 struct wireless_dev *wdev =
13327 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs);
13328 int i, err;
13329 u32 vid, subcmd;
13330
13331 if (!rdev->wiphy.vendor_commands)
13332 return -EOPNOTSUPP;
13333
13334 if (IS_ERR(wdev)) {
13335 err = PTR_ERR(wdev);
13336 if (err != -EINVAL)
13337 return err;
13338 wdev = NULL;
13339 } else if (wdev->wiphy != &rdev->wiphy) {
13340 return -EINVAL;
13341 }
13342
13343 if (!info->attrs[NL80211_ATTR_VENDOR_ID] ||
13344 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD])
13345 return -EINVAL;
13346
13347 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]);
13348 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]);
13349 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) {
13350 const struct wiphy_vendor_command *vcmd;
13351 void *data = NULL;
13352 int len = 0;
13353
13354 vcmd = &rdev->wiphy.vendor_commands[i];
13355
13356 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
13357 continue;
13358
13359 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
13360 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
13361 if (!wdev)
13362 return -EINVAL;
13363 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
13364 !wdev->netdev)
13365 return -EINVAL;
13366
13367 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
73c7da3d 13368 if (!wdev_running(wdev))
ad7e718c
JB
13369 return -ENETDOWN;
13370 }
13371 } else {
13372 wdev = NULL;
13373 }
13374
4052d3d2
JS
13375 if (!vcmd->doit)
13376 return -EOPNOTSUPP;
13377
ad7e718c
JB
13378 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) {
13379 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]);
13380 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]);
901bb989
JB
13381
13382 err = nl80211_vendor_check_policy(vcmd,
13383 info->attrs[NL80211_ATTR_VENDOR_DATA],
13384 info->extack);
13385 if (err)
13386 return err;
ad7e718c
JB
13387 }
13388
13389 rdev->cur_cmd_info = info;
901bb989 13390 err = vcmd->doit(&rdev->wiphy, wdev, data, len);
ad7e718c
JB
13391 rdev->cur_cmd_info = NULL;
13392 return err;
13393 }
13394
13395 return -EOPNOTSUPP;
13396}
13397
7bdbe400
JB
13398static int nl80211_prepare_vendor_dump(struct sk_buff *skb,
13399 struct netlink_callback *cb,
13400 struct cfg80211_registered_device **rdev,
13401 struct wireless_dev **wdev)
13402{
50508d94 13403 struct nlattr **attrbuf;
7bdbe400
JB
13404 u32 vid, subcmd;
13405 unsigned int i;
13406 int vcmd_idx = -1;
13407 int err;
13408 void *data = NULL;
13409 unsigned int data_len = 0;
13410
7bdbe400
JB
13411 if (cb->args[0]) {
13412 /* subtract the 1 again here */
13413 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1);
13414 struct wireless_dev *tmp;
13415
ea90e0dc
JB
13416 if (!wiphy)
13417 return -ENODEV;
7bdbe400
JB
13418 *rdev = wiphy_to_rdev(wiphy);
13419 *wdev = NULL;
13420
13421 if (cb->args[1]) {
53873f13 13422 list_for_each_entry(tmp, &wiphy->wdev_list, list) {
7bdbe400
JB
13423 if (tmp->identifier == cb->args[1] - 1) {
13424 *wdev = tmp;
13425 break;
13426 }
13427 }
13428 }
13429
13430 /* keep rtnl locked in successful case */
13431 return 0;
13432 }
13433
50508d94
JB
13434 attrbuf = kcalloc(NUM_NL80211_ATTR, sizeof(*attrbuf), GFP_KERNEL);
13435 if (!attrbuf)
13436 return -ENOMEM;
13437
8cb08174
JB
13438 err = nlmsg_parse_deprecated(cb->nlh,
13439 GENL_HDRLEN + nl80211_fam.hdrsize,
13440 attrbuf, nl80211_fam.maxattr,
13441 nl80211_policy, NULL);
7bdbe400 13442 if (err)
50508d94 13443 goto out;
7bdbe400 13444
c90c39da 13445 if (!attrbuf[NL80211_ATTR_VENDOR_ID] ||
50508d94
JB
13446 !attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) {
13447 err = -EINVAL;
13448 goto out;
13449 }
7bdbe400 13450
c90c39da 13451 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk), attrbuf);
7bdbe400
JB
13452 if (IS_ERR(*wdev))
13453 *wdev = NULL;
13454
c90c39da 13455 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf);
50508d94
JB
13456 if (IS_ERR(*rdev)) {
13457 err = PTR_ERR(*rdev);
13458 goto out;
13459 }
7bdbe400 13460
c90c39da
JB
13461 vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]);
13462 subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]);
7bdbe400
JB
13463
13464 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) {
13465 const struct wiphy_vendor_command *vcmd;
13466
13467 vcmd = &(*rdev)->wiphy.vendor_commands[i];
13468
13469 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd)
13470 continue;
13471
50508d94
JB
13472 if (!vcmd->dumpit) {
13473 err = -EOPNOTSUPP;
13474 goto out;
13475 }
7bdbe400
JB
13476
13477 vcmd_idx = i;
13478 break;
13479 }
13480
50508d94
JB
13481 if (vcmd_idx < 0) {
13482 err = -EOPNOTSUPP;
13483 goto out;
13484 }
7bdbe400 13485
c90c39da
JB
13486 if (attrbuf[NL80211_ATTR_VENDOR_DATA]) {
13487 data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]);
13488 data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]);
901bb989
JB
13489
13490 err = nl80211_vendor_check_policy(
13491 &(*rdev)->wiphy.vendor_commands[vcmd_idx],
13492 attrbuf[NL80211_ATTR_VENDOR_DATA],
13493 cb->extack);
13494 if (err)
50508d94 13495 goto out;
7bdbe400
JB
13496 }
13497
13498 /* 0 is the first index - add 1 to parse only once */
13499 cb->args[0] = (*rdev)->wiphy_idx + 1;
13500 /* add 1 to know if it was NULL */
13501 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0;
13502 cb->args[2] = vcmd_idx;
13503 cb->args[3] = (unsigned long)data;
13504 cb->args[4] = data_len;
13505
13506 /* keep rtnl locked in successful case */
50508d94
JB
13507 err = 0;
13508out:
13509 kfree(attrbuf);
13510 return err;
7bdbe400
JB
13511}
13512
13513static int nl80211_vendor_cmd_dump(struct sk_buff *skb,
13514 struct netlink_callback *cb)
13515{
13516 struct cfg80211_registered_device *rdev;
13517 struct wireless_dev *wdev;
13518 unsigned int vcmd_idx;
13519 const struct wiphy_vendor_command *vcmd;
13520 void *data;
13521 int data_len;
13522 int err;
13523 struct nlattr *vendor_data;
13524
ea90e0dc 13525 rtnl_lock();
7bdbe400
JB
13526 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev);
13527 if (err)
ea90e0dc 13528 goto out;
7bdbe400
JB
13529
13530 vcmd_idx = cb->args[2];
13531 data = (void *)cb->args[3];
13532 data_len = cb->args[4];
13533 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx];
13534
13535 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV |
13536 WIPHY_VENDOR_CMD_NEED_NETDEV)) {
ea90e0dc
JB
13537 if (!wdev) {
13538 err = -EINVAL;
13539 goto out;
13540 }
7bdbe400 13541 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV &&
ea90e0dc
JB
13542 !wdev->netdev) {
13543 err = -EINVAL;
13544 goto out;
13545 }
7bdbe400
JB
13546
13547 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) {
ea90e0dc
JB
13548 if (!wdev_running(wdev)) {
13549 err = -ENETDOWN;
13550 goto out;
13551 }
7bdbe400
JB
13552 }
13553 }
13554
13555 while (1) {
13556 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid,
13557 cb->nlh->nlmsg_seq, NLM_F_MULTI,
13558 NL80211_CMD_VENDOR);
13559 if (!hdr)
13560 break;
13561
13562 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
13563 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV,
13564 wdev_id(wdev),
13565 NL80211_ATTR_PAD))) {
7bdbe400
JB
13566 genlmsg_cancel(skb, hdr);
13567 break;
13568 }
13569
ae0be8de
MK
13570 vendor_data = nla_nest_start_noflag(skb,
13571 NL80211_ATTR_VENDOR_DATA);
7bdbe400
JB
13572 if (!vendor_data) {
13573 genlmsg_cancel(skb, hdr);
13574 break;
13575 }
13576
13577 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len,
13578 (unsigned long *)&cb->args[5]);
13579 nla_nest_end(skb, vendor_data);
13580
13581 if (err == -ENOBUFS || err == -ENOENT) {
13582 genlmsg_cancel(skb, hdr);
13583 break;
9c167b2d 13584 } else if (err <= 0) {
7bdbe400
JB
13585 genlmsg_cancel(skb, hdr);
13586 goto out;
13587 }
13588
13589 genlmsg_end(skb, hdr);
13590 }
13591
13592 err = skb->len;
13593 out:
13594 rtnl_unlock();
13595 return err;
13596}
13597
ad7e718c
JB
13598struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy,
13599 enum nl80211_commands cmd,
13600 enum nl80211_attrs attr,
13601 int approxlen)
13602{
f26cbf40 13603 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ad7e718c
JB
13604
13605 if (WARN_ON(!rdev->cur_cmd_info))
13606 return NULL;
13607
6c09e791 13608 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen,
ad7e718c
JB
13609 rdev->cur_cmd_info->snd_portid,
13610 rdev->cur_cmd_info->snd_seq,
567ffc35 13611 cmd, attr, NULL, GFP_KERNEL);
ad7e718c
JB
13612}
13613EXPORT_SYMBOL(__cfg80211_alloc_reply_skb);
13614
13615int cfg80211_vendor_cmd_reply(struct sk_buff *skb)
13616{
13617 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
13618 void *hdr = ((void **)skb->cb)[1];
13619 struct nlattr *data = ((void **)skb->cb)[2];
13620
bd8c78e7
JB
13621 /* clear CB data for netlink core to own from now on */
13622 memset(skb->cb, 0, sizeof(skb->cb));
13623
ad7e718c
JB
13624 if (WARN_ON(!rdev->cur_cmd_info)) {
13625 kfree_skb(skb);
13626 return -EINVAL;
13627 }
13628
13629 nla_nest_end(skb, data);
13630 genlmsg_end(skb, hdr);
13631 return genlmsg_reply(skb, rdev->cur_cmd_info);
13632}
13633EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply);
13634
55c1fdf0
JB
13635unsigned int cfg80211_vendor_cmd_get_sender(struct wiphy *wiphy)
13636{
13637 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
13638
13639 if (WARN_ON(!rdev->cur_cmd_info))
13640 return 0;
13641
13642 return rdev->cur_cmd_info->snd_portid;
13643}
13644EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_get_sender);
13645
fa9ffc74
KP
13646static int nl80211_set_qos_map(struct sk_buff *skb,
13647 struct genl_info *info)
13648{
13649 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13650 struct cfg80211_qos_map *qos_map = NULL;
13651 struct net_device *dev = info->user_ptr[1];
13652 u8 *pos, len, num_des, des_len, des;
13653 int ret;
13654
13655 if (!rdev->ops->set_qos_map)
13656 return -EOPNOTSUPP;
13657
13658 if (info->attrs[NL80211_ATTR_QOS_MAP]) {
13659 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]);
13660 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]);
13661
c8b82802 13662 if (len % 2)
fa9ffc74
KP
13663 return -EINVAL;
13664
13665 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL);
13666 if (!qos_map)
13667 return -ENOMEM;
13668
13669 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1;
13670 if (num_des) {
13671 des_len = num_des *
13672 sizeof(struct cfg80211_dscp_exception);
13673 memcpy(qos_map->dscp_exception, pos, des_len);
13674 qos_map->num_des = num_des;
13675 for (des = 0; des < num_des; des++) {
13676 if (qos_map->dscp_exception[des].up > 7) {
13677 kfree(qos_map);
13678 return -EINVAL;
13679 }
13680 }
13681 pos += des_len;
13682 }
13683 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN);
13684 }
13685
13686 wdev_lock(dev->ieee80211_ptr);
13687 ret = nl80211_key_allowed(dev->ieee80211_ptr);
13688 if (!ret)
13689 ret = rdev_set_qos_map(rdev, dev, qos_map);
13690 wdev_unlock(dev->ieee80211_ptr);
13691
13692 kfree(qos_map);
13693 return ret;
13694}
13695
960d01ac
JB
13696static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info)
13697{
13698 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13699 struct net_device *dev = info->user_ptr[1];
13700 struct wireless_dev *wdev = dev->ieee80211_ptr;
13701 const u8 *peer;
13702 u8 tsid, up;
13703 u16 admitted_time = 0;
13704 int err;
13705
723e73ac 13706 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION))
960d01ac
JB
13707 return -EOPNOTSUPP;
13708
13709 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] ||
13710 !info->attrs[NL80211_ATTR_USER_PRIO])
13711 return -EINVAL;
13712
13713 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
960d01ac 13714 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]);
960d01ac
JB
13715
13716 /* WMM uses TIDs 0-7 even for TSPEC */
723e73ac 13717 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) {
960d01ac 13718 /* TODO: handle 802.11 TSPEC/admission control
723e73ac
JB
13719 * need more attributes for that (e.g. BA session requirement);
13720 * change the WMM adminssion test above to allow both then
960d01ac
JB
13721 */
13722 return -EINVAL;
13723 }
13724
13725 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
13726
13727 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) {
13728 admitted_time =
13729 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]);
13730 if (!admitted_time)
13731 return -EINVAL;
13732 }
13733
13734 wdev_lock(wdev);
13735 switch (wdev->iftype) {
13736 case NL80211_IFTYPE_STATION:
13737 case NL80211_IFTYPE_P2P_CLIENT:
13738 if (wdev->current_bss)
13739 break;
13740 err = -ENOTCONN;
13741 goto out;
13742 default:
13743 err = -EOPNOTSUPP;
13744 goto out;
13745 }
13746
13747 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time);
13748
13749 out:
13750 wdev_unlock(wdev);
13751 return err;
13752}
13753
13754static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info)
13755{
13756 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13757 struct net_device *dev = info->user_ptr[1];
13758 struct wireless_dev *wdev = dev->ieee80211_ptr;
13759 const u8 *peer;
13760 u8 tsid;
13761 int err;
13762
13763 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC])
13764 return -EINVAL;
13765
13766 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]);
13767 peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
13768
13769 wdev_lock(wdev);
13770 err = rdev_del_tx_ts(rdev, dev, tsid, peer);
13771 wdev_unlock(wdev);
13772
13773 return err;
13774}
13775
1057d35e
AN
13776static int nl80211_tdls_channel_switch(struct sk_buff *skb,
13777 struct genl_info *info)
13778{
13779 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13780 struct net_device *dev = info->user_ptr[1];
13781 struct wireless_dev *wdev = dev->ieee80211_ptr;
13782 struct cfg80211_chan_def chandef = {};
13783 const u8 *addr;
13784 u8 oper_class;
13785 int err;
13786
13787 if (!rdev->ops->tdls_channel_switch ||
13788 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
13789 return -EOPNOTSUPP;
13790
13791 switch (dev->ieee80211_ptr->iftype) {
13792 case NL80211_IFTYPE_STATION:
13793 case NL80211_IFTYPE_P2P_CLIENT:
13794 break;
13795 default:
13796 return -EOPNOTSUPP;
13797 }
13798
13799 if (!info->attrs[NL80211_ATTR_MAC] ||
13800 !info->attrs[NL80211_ATTR_OPER_CLASS])
13801 return -EINVAL;
13802
13803 err = nl80211_parse_chandef(rdev, info, &chandef);
13804 if (err)
13805 return err;
13806
13807 /*
13808 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012
13809 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the
13810 * specification is not defined for them.
13811 */
57fbcce3 13812 if (chandef.chan->band == NL80211_BAND_2GHZ &&
1057d35e
AN
13813 chandef.width != NL80211_CHAN_WIDTH_20_NOHT &&
13814 chandef.width != NL80211_CHAN_WIDTH_20)
13815 return -EINVAL;
13816
13817 /* we will be active on the TDLS link */
923b352f
AN
13818 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef,
13819 wdev->iftype))
1057d35e
AN
13820 return -EINVAL;
13821
13822 /* don't allow switching to DFS channels */
13823 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype))
13824 return -EINVAL;
13825
13826 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
13827 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]);
13828
13829 wdev_lock(wdev);
13830 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef);
13831 wdev_unlock(wdev);
13832
13833 return err;
13834}
13835
13836static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb,
13837 struct genl_info *info)
13838{
13839 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13840 struct net_device *dev = info->user_ptr[1];
13841 struct wireless_dev *wdev = dev->ieee80211_ptr;
13842 const u8 *addr;
13843
13844 if (!rdev->ops->tdls_channel_switch ||
13845 !rdev->ops->tdls_cancel_channel_switch ||
13846 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH))
13847 return -EOPNOTSUPP;
13848
13849 switch (dev->ieee80211_ptr->iftype) {
13850 case NL80211_IFTYPE_STATION:
13851 case NL80211_IFTYPE_P2P_CLIENT:
13852 break;
13853 default:
13854 return -EOPNOTSUPP;
13855 }
13856
13857 if (!info->attrs[NL80211_ATTR_MAC])
13858 return -EINVAL;
13859
13860 addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
13861
13862 wdev_lock(wdev);
13863 rdev_tdls_cancel_channel_switch(rdev, dev, addr);
13864 wdev_unlock(wdev);
13865
13866 return 0;
13867}
13868
ce0ce13a
MB
13869static int nl80211_set_multicast_to_unicast(struct sk_buff *skb,
13870 struct genl_info *info)
13871{
13872 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13873 struct net_device *dev = info->user_ptr[1];
13874 struct wireless_dev *wdev = dev->ieee80211_ptr;
13875 const struct nlattr *nla;
13876 bool enabled;
13877
ce0ce13a
MB
13878 if (!rdev->ops->set_multicast_to_unicast)
13879 return -EOPNOTSUPP;
13880
13881 if (wdev->iftype != NL80211_IFTYPE_AP &&
13882 wdev->iftype != NL80211_IFTYPE_P2P_GO)
13883 return -EOPNOTSUPP;
13884
13885 nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED];
13886 enabled = nla_get_flag(nla);
13887
13888 return rdev_set_multicast_to_unicast(rdev, dev, enabled);
13889}
13890
3a00df57
AS
13891static int nl80211_set_pmk(struct sk_buff *skb, struct genl_info *info)
13892{
13893 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13894 struct net_device *dev = info->user_ptr[1];
13895 struct wireless_dev *wdev = dev->ieee80211_ptr;
13896 struct cfg80211_pmk_conf pmk_conf = {};
13897 int ret;
13898
13899 if (wdev->iftype != NL80211_IFTYPE_STATION &&
13900 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
13901 return -EOPNOTSUPP;
13902
13903 if (!wiphy_ext_feature_isset(&rdev->wiphy,
13904 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
13905 return -EOPNOTSUPP;
13906
13907 if (!info->attrs[NL80211_ATTR_MAC] || !info->attrs[NL80211_ATTR_PMK])
13908 return -EINVAL;
13909
13910 wdev_lock(wdev);
13911 if (!wdev->current_bss) {
13912 ret = -ENOTCONN;
13913 goto out;
13914 }
13915
13916 pmk_conf.aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
13917 if (memcmp(pmk_conf.aa, wdev->current_bss->pub.bssid, ETH_ALEN)) {
13918 ret = -EINVAL;
13919 goto out;
13920 }
13921
13922 pmk_conf.pmk = nla_data(info->attrs[NL80211_ATTR_PMK]);
13923 pmk_conf.pmk_len = nla_len(info->attrs[NL80211_ATTR_PMK]);
13924 if (pmk_conf.pmk_len != WLAN_PMK_LEN &&
13925 pmk_conf.pmk_len != WLAN_PMK_LEN_SUITE_B_192) {
13926 ret = -EINVAL;
13927 goto out;
13928 }
13929
cb9abd48 13930 if (info->attrs[NL80211_ATTR_PMKR0_NAME])
3a00df57
AS
13931 pmk_conf.pmk_r0_name =
13932 nla_data(info->attrs[NL80211_ATTR_PMKR0_NAME]);
3a00df57
AS
13933
13934 ret = rdev_set_pmk(rdev, dev, &pmk_conf);
13935out:
13936 wdev_unlock(wdev);
13937 return ret;
13938}
13939
13940static int nl80211_del_pmk(struct sk_buff *skb, struct genl_info *info)
13941{
13942 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13943 struct net_device *dev = info->user_ptr[1];
13944 struct wireless_dev *wdev = dev->ieee80211_ptr;
13945 const u8 *aa;
13946 int ret;
13947
13948 if (wdev->iftype != NL80211_IFTYPE_STATION &&
13949 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
13950 return -EOPNOTSUPP;
13951
13952 if (!wiphy_ext_feature_isset(&rdev->wiphy,
13953 NL80211_EXT_FEATURE_4WAY_HANDSHAKE_STA_1X))
13954 return -EOPNOTSUPP;
13955
13956 if (!info->attrs[NL80211_ATTR_MAC])
13957 return -EINVAL;
13958
13959 wdev_lock(wdev);
13960 aa = nla_data(info->attrs[NL80211_ATTR_MAC]);
13961 ret = rdev_del_pmk(rdev, dev, aa);
13962 wdev_unlock(wdev);
13963
13964 return ret;
13965}
13966
40cbfa90
SD
13967static int nl80211_external_auth(struct sk_buff *skb, struct genl_info *info)
13968{
13969 struct cfg80211_registered_device *rdev = info->user_ptr[0];
13970 struct net_device *dev = info->user_ptr[1];
13971 struct cfg80211_external_auth_params params;
13972
db8d93a7 13973 if (!rdev->ops->external_auth)
40cbfa90
SD
13974 return -EOPNOTSUPP;
13975
fe494370
SD
13976 if (!info->attrs[NL80211_ATTR_SSID] &&
13977 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
13978 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
40cbfa90
SD
13979 return -EINVAL;
13980
13981 if (!info->attrs[NL80211_ATTR_BSSID])
13982 return -EINVAL;
13983
13984 if (!info->attrs[NL80211_ATTR_STATUS_CODE])
13985 return -EINVAL;
13986
13987 memset(&params, 0, sizeof(params));
13988
fe494370
SD
13989 if (info->attrs[NL80211_ATTR_SSID]) {
13990 params.ssid.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
cb9abd48 13991 if (params.ssid.ssid_len == 0)
fe494370
SD
13992 return -EINVAL;
13993 memcpy(params.ssid.ssid,
13994 nla_data(info->attrs[NL80211_ATTR_SSID]),
13995 params.ssid.ssid_len);
13996 }
40cbfa90
SD
13997
13998 memcpy(params.bssid, nla_data(info->attrs[NL80211_ATTR_BSSID]),
13999 ETH_ALEN);
14000
14001 params.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
14002
fe494370
SD
14003 if (info->attrs[NL80211_ATTR_PMKID])
14004 params.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
14005
40cbfa90
SD
14006 return rdev_external_auth(rdev, dev, &params);
14007}
14008
2576a9ac
DK
14009static int nl80211_tx_control_port(struct sk_buff *skb, struct genl_info *info)
14010{
dca9ca2d 14011 bool dont_wait_for_ack = info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK];
2576a9ac
DK
14012 struct cfg80211_registered_device *rdev = info->user_ptr[0];
14013 struct net_device *dev = info->user_ptr[1];
14014 struct wireless_dev *wdev = dev->ieee80211_ptr;
14015 const u8 *buf;
14016 size_t len;
14017 u8 *dest;
14018 u16 proto;
14019 bool noencrypt;
dca9ca2d 14020 u64 cookie = 0;
2576a9ac
DK
14021 int err;
14022
14023 if (!wiphy_ext_feature_isset(&rdev->wiphy,
14024 NL80211_EXT_FEATURE_CONTROL_PORT_OVER_NL80211))
14025 return -EOPNOTSUPP;
14026
14027 if (!rdev->ops->tx_control_port)
14028 return -EOPNOTSUPP;
14029
14030 if (!info->attrs[NL80211_ATTR_FRAME] ||
14031 !info->attrs[NL80211_ATTR_MAC] ||
14032 !info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
14033 GENL_SET_ERR_MSG(info, "Frame, MAC or ethertype missing");
14034 return -EINVAL;
14035 }
14036
14037 wdev_lock(wdev);
14038
14039 switch (wdev->iftype) {
14040 case NL80211_IFTYPE_AP:
14041 case NL80211_IFTYPE_P2P_GO:
14042 case NL80211_IFTYPE_MESH_POINT:
14043 break;
14044 case NL80211_IFTYPE_ADHOC:
14045 case NL80211_IFTYPE_STATION:
14046 case NL80211_IFTYPE_P2P_CLIENT:
14047 if (wdev->current_bss)
14048 break;
14049 err = -ENOTCONN;
14050 goto out;
14051 default:
14052 err = -EOPNOTSUPP;
14053 goto out;
14054 }
14055
14056 wdev_unlock(wdev);
14057
14058 buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
14059 len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
14060 dest = nla_data(info->attrs[NL80211_ATTR_MAC]);
14061 proto = nla_get_u16(info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
14062 noencrypt =
14063 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT]);
14064
dca9ca2d
MT
14065 err = rdev_tx_control_port(rdev, dev, buf, len,
14066 dest, cpu_to_be16(proto), noencrypt,
14067 dont_wait_for_ack ? NULL : &cookie);
14068 if (!err && !dont_wait_for_ack)
14069 nl_set_extack_cookie_u64(info->extack, cookie);
14070 return err;
2576a9ac
DK
14071 out:
14072 wdev_unlock(wdev);
14073 return err;
14074}
14075
81e54d08
PKC
14076static int nl80211_get_ftm_responder_stats(struct sk_buff *skb,
14077 struct genl_info *info)
14078{
14079 struct cfg80211_registered_device *rdev = info->user_ptr[0];
14080 struct net_device *dev = info->user_ptr[1];
14081 struct wireless_dev *wdev = dev->ieee80211_ptr;
14082 struct cfg80211_ftm_responder_stats ftm_stats = {};
14083 struct sk_buff *msg;
14084 void *hdr;
14085 struct nlattr *ftm_stats_attr;
14086 int err;
14087
14088 if (wdev->iftype != NL80211_IFTYPE_AP || !wdev->beacon_interval)
14089 return -EOPNOTSUPP;
14090
14091 err = rdev_get_ftm_responder_stats(rdev, dev, &ftm_stats);
14092 if (err)
14093 return err;
14094
14095 if (!ftm_stats.filled)
14096 return -ENODATA;
14097
14098 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
14099 if (!msg)
14100 return -ENOMEM;
14101
14102 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0,
14103 NL80211_CMD_GET_FTM_RESPONDER_STATS);
14104 if (!hdr)
1399c59f 14105 goto nla_put_failure;
81e54d08
PKC
14106
14107 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
14108 goto nla_put_failure;
14109
ae0be8de
MK
14110 ftm_stats_attr = nla_nest_start_noflag(msg,
14111 NL80211_ATTR_FTM_RESPONDER_STATS);
81e54d08
PKC
14112 if (!ftm_stats_attr)
14113 goto nla_put_failure;
14114
14115#define SET_FTM(field, name, type) \
14116 do { if ((ftm_stats.filled & BIT(NL80211_FTM_STATS_ ## name)) && \
14117 nla_put_ ## type(msg, NL80211_FTM_STATS_ ## name, \
14118 ftm_stats.field)) \
14119 goto nla_put_failure; } while (0)
14120#define SET_FTM_U64(field, name) \
14121 do { if ((ftm_stats.filled & BIT(NL80211_FTM_STATS_ ## name)) && \
14122 nla_put_u64_64bit(msg, NL80211_FTM_STATS_ ## name, \
14123 ftm_stats.field, NL80211_FTM_STATS_PAD)) \
14124 goto nla_put_failure; } while (0)
14125
14126 SET_FTM(success_num, SUCCESS_NUM, u32);
14127 SET_FTM(partial_num, PARTIAL_NUM, u32);
14128 SET_FTM(failed_num, FAILED_NUM, u32);
14129 SET_FTM(asap_num, ASAP_NUM, u32);
14130 SET_FTM(non_asap_num, NON_ASAP_NUM, u32);
14131 SET_FTM_U64(total_duration_ms, TOTAL_DURATION_MSEC);
14132 SET_FTM(unknown_triggers_num, UNKNOWN_TRIGGERS_NUM, u32);
14133 SET_FTM(reschedule_requests_num, RESCHEDULE_REQUESTS_NUM, u32);
14134 SET_FTM(out_of_window_triggers_num, OUT_OF_WINDOW_TRIGGERS_NUM, u32);
14135#undef SET_FTM
14136
14137 nla_nest_end(msg, ftm_stats_attr);
14138
14139 genlmsg_end(msg, hdr);
14140 return genlmsg_reply(msg, info);
14141
14142nla_put_failure:
14143 nlmsg_free(msg);
14144 return -ENOBUFS;
14145}
14146
cb74e977
SD
14147static int nl80211_update_owe_info(struct sk_buff *skb, struct genl_info *info)
14148{
14149 struct cfg80211_registered_device *rdev = info->user_ptr[0];
14150 struct cfg80211_update_owe_info owe_info;
14151 struct net_device *dev = info->user_ptr[1];
14152
14153 if (!rdev->ops->update_owe_info)
14154 return -EOPNOTSUPP;
14155
14156 if (!info->attrs[NL80211_ATTR_STATUS_CODE] ||
14157 !info->attrs[NL80211_ATTR_MAC])
14158 return -EINVAL;
14159
14160 memset(&owe_info, 0, sizeof(owe_info));
14161 owe_info.status = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]);
14162 nla_memcpy(owe_info.peer, info->attrs[NL80211_ATTR_MAC], ETH_ALEN);
14163
14164 if (info->attrs[NL80211_ATTR_IE]) {
14165 owe_info.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
14166 owe_info.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
14167 }
14168
14169 return rdev_update_owe_info(rdev, dev, &owe_info);
14170}
14171
5ab92e7f
RM
14172static int nl80211_probe_mesh_link(struct sk_buff *skb, struct genl_info *info)
14173{
14174 struct cfg80211_registered_device *rdev = info->user_ptr[0];
14175 struct net_device *dev = info->user_ptr[1];
14176 struct wireless_dev *wdev = dev->ieee80211_ptr;
14177 struct station_info sinfo = {};
14178 const u8 *buf;
14179 size_t len;
14180 u8 *dest;
14181 int err;
14182
14183 if (!rdev->ops->probe_mesh_link || !rdev->ops->get_station)
14184 return -EOPNOTSUPP;
14185
14186 if (!info->attrs[NL80211_ATTR_MAC] ||
14187 !info->attrs[NL80211_ATTR_FRAME]) {
14188 GENL_SET_ERR_MSG(info, "Frame or MAC missing");
14189 return -EINVAL;
14190 }
14191
14192 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
14193 return -EOPNOTSUPP;
14194
14195 dest = nla_data(info->attrs[NL80211_ATTR_MAC]);
14196 buf = nla_data(info->attrs[NL80211_ATTR_FRAME]);
14197 len = nla_len(info->attrs[NL80211_ATTR_FRAME]);
14198
14199 if (len < sizeof(struct ethhdr))
14200 return -EINVAL;
14201
14202 if (!ether_addr_equal(buf, dest) || is_multicast_ether_addr(buf) ||
14203 !ether_addr_equal(buf + ETH_ALEN, dev->dev_addr))
14204 return -EINVAL;
14205
14206 err = rdev_get_station(rdev, dev, dest, &sinfo);
14207 if (err)
14208 return err;
14209
2a279b34
FF
14210 cfg80211_sinfo_release_content(&sinfo);
14211
5ab92e7f
RM
14212 return rdev_probe_mesh_link(rdev, dev, dest, buf, len);
14213}
14214
77f576de
T
14215static int parse_tid_conf(struct cfg80211_registered_device *rdev,
14216 struct nlattr *attrs[], struct net_device *dev,
3710a8a6 14217 struct cfg80211_tid_cfg *tid_conf,
77f576de
T
14218 struct genl_info *info, const u8 *peer)
14219{
14220 struct netlink_ext_ack *extack = info->extack;
3710a8a6 14221 u64 mask;
77f576de
T
14222 int err;
14223
14224 if (!attrs[NL80211_TID_CONFIG_ATTR_TIDS])
14225 return -EINVAL;
14226
14227 tid_conf->config_override =
14228 nla_get_flag(attrs[NL80211_TID_CONFIG_ATTR_OVERRIDE]);
3710a8a6 14229 tid_conf->tids = nla_get_u16(attrs[NL80211_TID_CONFIG_ATTR_TIDS]);
77f576de
T
14230
14231 if (tid_conf->config_override) {
14232 if (rdev->ops->reset_tid_config) {
14233 err = rdev_reset_tid_config(rdev, dev, peer,
3710a8a6 14234 tid_conf->tids);
c0336955 14235 if (err)
77f576de
T
14236 return err;
14237 } else {
14238 return -EINVAL;
14239 }
14240 }
14241
14242 if (attrs[NL80211_TID_CONFIG_ATTR_NOACK]) {
3710a8a6 14243 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_NOACK);
77f576de
T
14244 tid_conf->noack =
14245 nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_NOACK]);
14246 }
14247
6a21d16c
T
14248 if (attrs[NL80211_TID_CONFIG_ATTR_RETRY_SHORT]) {
14249 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_RETRY_SHORT);
14250 tid_conf->retry_short =
14251 nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_RETRY_SHORT]);
14252
14253 if (tid_conf->retry_short > rdev->wiphy.max_data_retry_count)
14254 return -EINVAL;
14255 }
14256
14257 if (attrs[NL80211_TID_CONFIG_ATTR_RETRY_LONG]) {
14258 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_RETRY_LONG);
14259 tid_conf->retry_long =
14260 nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_RETRY_LONG]);
14261
14262 if (tid_conf->retry_long > rdev->wiphy.max_data_retry_count)
14263 return -EINVAL;
14264 }
14265
ade274b2
T
14266 if (attrs[NL80211_TID_CONFIG_ATTR_AMPDU_CTRL]) {
14267 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_AMPDU_CTRL);
14268 tid_conf->ampdu =
14269 nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_AMPDU_CTRL]);
14270 }
14271
04f7d142
T
14272 if (attrs[NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL]) {
14273 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL);
14274 tid_conf->rtscts =
14275 nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_RTSCTS_CTRL]);
14276 }
14277
33462e68
SM
14278 if (attrs[NL80211_TID_CONFIG_ATTR_AMSDU_CTRL]) {
14279 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_AMSDU_CTRL);
14280 tid_conf->amsdu =
14281 nla_get_u8(attrs[NL80211_TID_CONFIG_ATTR_AMSDU_CTRL]);
14282 }
14283
9a5f6488
TC
14284 if (attrs[NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE]) {
14285 u32 idx = NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE, attr;
14286
14287 tid_conf->txrate_type = nla_get_u8(attrs[idx]);
14288
14289 if (tid_conf->txrate_type != NL80211_TX_RATE_AUTOMATIC) {
14290 attr = NL80211_TID_CONFIG_ATTR_TX_RATE;
14291 err = nl80211_parse_tx_bitrate_mask(info, attrs, attr,
eb89a6a6 14292 &tid_conf->txrate_mask, dev);
9a5f6488
TC
14293 if (err)
14294 return err;
14295
14296 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_TX_RATE);
14297 }
14298 tid_conf->mask |= BIT(NL80211_TID_CONFIG_ATTR_TX_RATE_TYPE);
14299 }
14300
3710a8a6
JB
14301 if (peer)
14302 mask = rdev->wiphy.tid_config_support.peer;
14303 else
14304 mask = rdev->wiphy.tid_config_support.vif;
14305
14306 if (tid_conf->mask & ~mask) {
14307 NL_SET_ERR_MSG(extack, "unsupported TID configuration");
14308 return -ENOTSUPP;
14309 }
14310
77f576de
T
14311 return 0;
14312}
14313
14314static int nl80211_set_tid_config(struct sk_buff *skb,
14315 struct genl_info *info)
14316{
14317 struct cfg80211_registered_device *rdev = info->user_ptr[0];
14318 struct nlattr *attrs[NL80211_TID_CONFIG_ATTR_MAX + 1];
14319 struct net_device *dev = info->user_ptr[1];
3710a8a6 14320 struct cfg80211_tid_config *tid_config;
77f576de
T
14321 struct nlattr *tid;
14322 int conf_idx = 0, rem_conf;
14323 int ret = -EINVAL;
14324 u32 num_conf = 0;
14325
14326 if (!info->attrs[NL80211_ATTR_TID_CONFIG])
14327 return -EINVAL;
14328
14329 if (!rdev->ops->set_tid_config)
14330 return -EOPNOTSUPP;
14331
14332 nla_for_each_nested(tid, info->attrs[NL80211_ATTR_TID_CONFIG],
14333 rem_conf)
14334 num_conf++;
14335
14336 tid_config = kzalloc(struct_size(tid_config, tid_conf, num_conf),
14337 GFP_KERNEL);
14338 if (!tid_config)
14339 return -ENOMEM;
14340
14341 tid_config->n_tid_conf = num_conf;
14342
14343 if (info->attrs[NL80211_ATTR_MAC])
14344 tid_config->peer = nla_data(info->attrs[NL80211_ATTR_MAC]);
14345
14346 nla_for_each_nested(tid, info->attrs[NL80211_ATTR_TID_CONFIG],
14347 rem_conf) {
14348 ret = nla_parse_nested(attrs, NL80211_TID_CONFIG_ATTR_MAX,
14349 tid, NULL, NULL);
14350
14351 if (ret)
14352 goto bad_tid_conf;
14353
14354 ret = parse_tid_conf(rdev, attrs, dev,
14355 &tid_config->tid_conf[conf_idx],
14356 info, tid_config->peer);
14357 if (ret)
14358 goto bad_tid_conf;
14359
14360 conf_idx++;
14361 }
14362
14363 ret = rdev_set_tid_config(rdev, dev, tid_config);
14364
14365bad_tid_conf:
14366 kfree(tid_config);
14367 return ret;
14368}
14369
4c476991
JB
14370#define NL80211_FLAG_NEED_WIPHY 0x01
14371#define NL80211_FLAG_NEED_NETDEV 0x02
14372#define NL80211_FLAG_NEED_RTNL 0x04
41265714
JB
14373#define NL80211_FLAG_CHECK_NETDEV_UP 0x08
14374#define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\
14375 NL80211_FLAG_CHECK_NETDEV_UP)
1bf614ef 14376#define NL80211_FLAG_NEED_WDEV 0x10
98104fde 14377/* If a netdev is associated, it must be UP, P2P must be started */
1bf614ef
JB
14378#define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\
14379 NL80211_FLAG_CHECK_NETDEV_UP)
5393b917 14380#define NL80211_FLAG_CLEAR_SKB 0x20
4c476991 14381
f84f771d 14382static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
14383 struct genl_info *info)
14384{
14385 struct cfg80211_registered_device *rdev;
89a54e48 14386 struct wireless_dev *wdev;
4c476991 14387 struct net_device *dev;
4c476991
JB
14388 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
14389
14390 if (rtnl)
14391 rtnl_lock();
14392
14393 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4f7eff10 14394 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info);
4c476991
JB
14395 if (IS_ERR(rdev)) {
14396 if (rtnl)
14397 rtnl_unlock();
14398 return PTR_ERR(rdev);
14399 }
14400 info->user_ptr[0] = rdev;
1bf614ef
JB
14401 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV ||
14402 ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
5fe231e8
JB
14403 ASSERT_RTNL();
14404
89a54e48
JB
14405 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info),
14406 info->attrs);
14407 if (IS_ERR(wdev)) {
4c476991
JB
14408 if (rtnl)
14409 rtnl_unlock();
89a54e48 14410 return PTR_ERR(wdev);
4c476991 14411 }
89a54e48 14412
89a54e48 14413 dev = wdev->netdev;
f26cbf40 14414 rdev = wiphy_to_rdev(wdev->wiphy);
89a54e48 14415
1bf614ef
JB
14416 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
14417 if (!dev) {
1bf614ef
JB
14418 if (rtnl)
14419 rtnl_unlock();
14420 return -EINVAL;
14421 }
14422
14423 info->user_ptr[1] = dev;
14424 } else {
14425 info->user_ptr[1] = wdev;
41265714 14426 }
1bf614ef 14427
73c7da3d
AVS
14428 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
14429 !wdev_running(wdev)) {
14430 if (rtnl)
14431 rtnl_unlock();
14432 return -ENETDOWN;
14433 }
1bf614ef 14434
73c7da3d 14435 if (dev)
1bf614ef 14436 dev_hold(dev);
89a54e48 14437
4c476991 14438 info->user_ptr[0] = rdev;
4c476991
JB
14439 }
14440
14441 return 0;
14442}
14443
f84f771d 14444static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb,
4c476991
JB
14445 struct genl_info *info)
14446{
1bf614ef
JB
14447 if (info->user_ptr[1]) {
14448 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) {
14449 struct wireless_dev *wdev = info->user_ptr[1];
14450
14451 if (wdev->netdev)
14452 dev_put(wdev->netdev);
14453 } else {
14454 dev_put(info->user_ptr[1]);
14455 }
14456 }
5393b917 14457
4c476991
JB
14458 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
14459 rtnl_unlock();
5393b917
JB
14460
14461 /* If needed, clear the netlink message payload from the SKB
14462 * as it might contain key data that shouldn't stick around on
14463 * the heap after the SKB is freed. The netlink message header
14464 * is still needed for further processing, so leave it intact.
14465 */
14466 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) {
14467 struct nlmsghdr *nlh = nlmsg_hdr(skb);
14468
14469 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh));
14470 }
4c476991
JB
14471}
14472
4534de83 14473static const struct genl_ops nl80211_ops[] = {
55682965
JB
14474 {
14475 .cmd = NL80211_CMD_GET_WIPHY,
ef6243ac 14476 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965
JB
14477 .doit = nl80211_get_wiphy,
14478 .dumpit = nl80211_dump_wiphy,
86e8cf98 14479 .done = nl80211_dump_wiphy_done,
55682965 14480 /* can be retrieved by unprivileged users */
5fe231e8
JB
14481 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14482 NL80211_FLAG_NEED_RTNL,
55682965
JB
14483 },
14484 {
14485 .cmd = NL80211_CMD_SET_WIPHY,
ef6243ac 14486 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 14487 .doit = nl80211_set_wiphy,
5617c6cd 14488 .flags = GENL_UNS_ADMIN_PERM,
4c476991 14489 .internal_flags = NL80211_FLAG_NEED_RTNL,
55682965
JB
14490 },
14491 {
14492 .cmd = NL80211_CMD_GET_INTERFACE,
ef6243ac 14493 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965
JB
14494 .doit = nl80211_get_interface,
14495 .dumpit = nl80211_dump_interface,
55682965 14496 /* can be retrieved by unprivileged users */
5fe231e8
JB
14497 .internal_flags = NL80211_FLAG_NEED_WDEV |
14498 NL80211_FLAG_NEED_RTNL,
55682965
JB
14499 },
14500 {
14501 .cmd = NL80211_CMD_SET_INTERFACE,
ef6243ac 14502 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 14503 .doit = nl80211_set_interface,
5617c6cd 14504 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14505 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14506 NL80211_FLAG_NEED_RTNL,
55682965
JB
14507 },
14508 {
14509 .cmd = NL80211_CMD_NEW_INTERFACE,
ef6243ac 14510 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 14511 .doit = nl80211_new_interface,
5617c6cd 14512 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14513 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14514 NL80211_FLAG_NEED_RTNL,
55682965
JB
14515 },
14516 {
14517 .cmd = NL80211_CMD_DEL_INTERFACE,
ef6243ac 14518 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
55682965 14519 .doit = nl80211_del_interface,
5617c6cd 14520 .flags = GENL_UNS_ADMIN_PERM,
84efbb84 14521 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 14522 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
14523 },
14524 {
14525 .cmd = NL80211_CMD_GET_KEY,
ef6243ac 14526 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 14527 .doit = nl80211_get_key,
5617c6cd 14528 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14529 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14530 NL80211_FLAG_NEED_RTNL,
41ade00f
JB
14531 },
14532 {
14533 .cmd = NL80211_CMD_SET_KEY,
ef6243ac 14534 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 14535 .doit = nl80211_set_key,
5617c6cd 14536 .flags = GENL_UNS_ADMIN_PERM,
41265714 14537 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
14538 NL80211_FLAG_NEED_RTNL |
14539 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
14540 },
14541 {
14542 .cmd = NL80211_CMD_NEW_KEY,
ef6243ac 14543 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 14544 .doit = nl80211_new_key,
5617c6cd 14545 .flags = GENL_UNS_ADMIN_PERM,
41265714 14546 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
14547 NL80211_FLAG_NEED_RTNL |
14548 NL80211_FLAG_CLEAR_SKB,
41ade00f
JB
14549 },
14550 {
14551 .cmd = NL80211_CMD_DEL_KEY,
ef6243ac 14552 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
41ade00f 14553 .doit = nl80211_del_key,
5617c6cd 14554 .flags = GENL_UNS_ADMIN_PERM,
41265714 14555 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14556 NL80211_FLAG_NEED_RTNL,
55682965 14557 },
ed1b6cc7
JB
14558 {
14559 .cmd = NL80211_CMD_SET_BEACON,
ef6243ac 14560 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5617c6cd 14561 .flags = GENL_UNS_ADMIN_PERM,
8860020e 14562 .doit = nl80211_set_beacon,
2b5f8b0b 14563 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14564 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
14565 },
14566 {
8860020e 14567 .cmd = NL80211_CMD_START_AP,
ef6243ac 14568 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5617c6cd 14569 .flags = GENL_UNS_ADMIN_PERM,
8860020e 14570 .doit = nl80211_start_ap,
2b5f8b0b 14571 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14572 NL80211_FLAG_NEED_RTNL,
ed1b6cc7
JB
14573 },
14574 {
8860020e 14575 .cmd = NL80211_CMD_STOP_AP,
ef6243ac 14576 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5617c6cd 14577 .flags = GENL_UNS_ADMIN_PERM,
8860020e 14578 .doit = nl80211_stop_ap,
2b5f8b0b 14579 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14580 NL80211_FLAG_NEED_RTNL,
ed1b6cc7 14581 },
5727ef1b
JB
14582 {
14583 .cmd = NL80211_CMD_GET_STATION,
ef6243ac 14584 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 14585 .doit = nl80211_get_station,
2ec600d6 14586 .dumpit = nl80211_dump_station,
4c476991
JB
14587 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14588 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
14589 },
14590 {
14591 .cmd = NL80211_CMD_SET_STATION,
ef6243ac 14592 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 14593 .doit = nl80211_set_station,
5617c6cd 14594 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14595 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14596 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
14597 },
14598 {
14599 .cmd = NL80211_CMD_NEW_STATION,
ef6243ac 14600 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 14601 .doit = nl80211_new_station,
5617c6cd 14602 .flags = GENL_UNS_ADMIN_PERM,
41265714 14603 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14604 NL80211_FLAG_NEED_RTNL,
5727ef1b
JB
14605 },
14606 {
14607 .cmd = NL80211_CMD_DEL_STATION,
ef6243ac 14608 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5727ef1b 14609 .doit = nl80211_del_station,
5617c6cd 14610 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14611 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14612 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
14613 },
14614 {
14615 .cmd = NL80211_CMD_GET_MPATH,
ef6243ac 14616 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6
LCC
14617 .doit = nl80211_get_mpath,
14618 .dumpit = nl80211_dump_mpath,
5617c6cd 14619 .flags = GENL_UNS_ADMIN_PERM,
41265714 14620 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14621 NL80211_FLAG_NEED_RTNL,
2ec600d6 14622 },
66be7d2b
HR
14623 {
14624 .cmd = NL80211_CMD_GET_MPP,
ef6243ac 14625 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
66be7d2b
HR
14626 .doit = nl80211_get_mpp,
14627 .dumpit = nl80211_dump_mpp,
5617c6cd 14628 .flags = GENL_UNS_ADMIN_PERM,
66be7d2b
HR
14629 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14630 NL80211_FLAG_NEED_RTNL,
14631 },
2ec600d6
LCC
14632 {
14633 .cmd = NL80211_CMD_SET_MPATH,
ef6243ac 14634 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6 14635 .doit = nl80211_set_mpath,
5617c6cd 14636 .flags = GENL_UNS_ADMIN_PERM,
41265714 14637 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14638 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
14639 },
14640 {
14641 .cmd = NL80211_CMD_NEW_MPATH,
ef6243ac 14642 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6 14643 .doit = nl80211_new_mpath,
5617c6cd 14644 .flags = GENL_UNS_ADMIN_PERM,
41265714 14645 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14646 NL80211_FLAG_NEED_RTNL,
2ec600d6
LCC
14647 },
14648 {
14649 .cmd = NL80211_CMD_DEL_MPATH,
ef6243ac 14650 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2ec600d6 14651 .doit = nl80211_del_mpath,
5617c6cd 14652 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14653 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14654 NL80211_FLAG_NEED_RTNL,
9f1ba906
JM
14655 },
14656 {
14657 .cmd = NL80211_CMD_SET_BSS,
ef6243ac 14658 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9f1ba906 14659 .doit = nl80211_set_bss,
5617c6cd 14660 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14661 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14662 NL80211_FLAG_NEED_RTNL,
b2e1b302 14663 },
f130347c
LR
14664 {
14665 .cmd = NL80211_CMD_GET_REG,
ef6243ac 14666 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ad30ca2c
AN
14667 .doit = nl80211_get_reg_do,
14668 .dumpit = nl80211_get_reg_dump,
5fe231e8 14669 .internal_flags = NL80211_FLAG_NEED_RTNL,
f130347c
LR
14670 /* can be retrieved by unprivileged users */
14671 },
b6863036 14672#ifdef CONFIG_CFG80211_CRDA_SUPPORT
b2e1b302
LR
14673 {
14674 .cmd = NL80211_CMD_SET_REG,
ef6243ac 14675 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b2e1b302 14676 .doit = nl80211_set_reg,
b2e1b302 14677 .flags = GENL_ADMIN_PERM,
5fe231e8 14678 .internal_flags = NL80211_FLAG_NEED_RTNL,
b2e1b302 14679 },
b6863036 14680#endif
b2e1b302
LR
14681 {
14682 .cmd = NL80211_CMD_REQ_SET_REG,
ef6243ac 14683 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b2e1b302 14684 .doit = nl80211_req_set_reg,
93da9cc1 14685 .flags = GENL_ADMIN_PERM,
14686 },
1ea4ff3e
JB
14687 {
14688 .cmd = NL80211_CMD_RELOAD_REGDB,
ef6243ac 14689 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1ea4ff3e 14690 .doit = nl80211_reload_regdb,
1ea4ff3e
JB
14691 .flags = GENL_ADMIN_PERM,
14692 },
93da9cc1 14693 {
24bdd9f4 14694 .cmd = NL80211_CMD_GET_MESH_CONFIG,
ef6243ac 14695 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
24bdd9f4 14696 .doit = nl80211_get_mesh_config,
93da9cc1 14697 /* can be retrieved by unprivileged users */
2b5f8b0b 14698 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14699 NL80211_FLAG_NEED_RTNL,
93da9cc1 14700 },
14701 {
24bdd9f4 14702 .cmd = NL80211_CMD_SET_MESH_CONFIG,
ef6243ac 14703 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
24bdd9f4 14704 .doit = nl80211_update_mesh_config,
5617c6cd 14705 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c 14706 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14707 NL80211_FLAG_NEED_RTNL,
9aed3cc1 14708 },
2a519311
JB
14709 {
14710 .cmd = NL80211_CMD_TRIGGER_SCAN,
ef6243ac 14711 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2a519311 14712 .doit = nl80211_trigger_scan,
5617c6cd 14713 .flags = GENL_UNS_ADMIN_PERM,
fd014284 14714 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14715 NL80211_FLAG_NEED_RTNL,
2a519311 14716 },
91d3ab46
VK
14717 {
14718 .cmd = NL80211_CMD_ABORT_SCAN,
ef6243ac 14719 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
91d3ab46 14720 .doit = nl80211_abort_scan,
5617c6cd 14721 .flags = GENL_UNS_ADMIN_PERM,
91d3ab46
VK
14722 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
14723 NL80211_FLAG_NEED_RTNL,
14724 },
2a519311
JB
14725 {
14726 .cmd = NL80211_CMD_GET_SCAN,
ef6243ac 14727 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2a519311
JB
14728 .dumpit = nl80211_dump_scan,
14729 },
807f8a8c
LC
14730 {
14731 .cmd = NL80211_CMD_START_SCHED_SCAN,
ef6243ac 14732 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
807f8a8c 14733 .doit = nl80211_start_sched_scan,
5617c6cd 14734 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
14735 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14736 NL80211_FLAG_NEED_RTNL,
14737 },
14738 {
14739 .cmd = NL80211_CMD_STOP_SCHED_SCAN,
ef6243ac 14740 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
807f8a8c 14741 .doit = nl80211_stop_sched_scan,
5617c6cd 14742 .flags = GENL_UNS_ADMIN_PERM,
807f8a8c
LC
14743 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14744 NL80211_FLAG_NEED_RTNL,
14745 },
636a5d36
JM
14746 {
14747 .cmd = NL80211_CMD_AUTHENTICATE,
ef6243ac 14748 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14749 .doit = nl80211_authenticate,
5617c6cd 14750 .flags = GENL_UNS_ADMIN_PERM,
41265714 14751 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
14752 NL80211_FLAG_NEED_RTNL |
14753 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
14754 },
14755 {
14756 .cmd = NL80211_CMD_ASSOCIATE,
ef6243ac 14757 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14758 .doit = nl80211_associate,
5617c6cd 14759 .flags = GENL_UNS_ADMIN_PERM,
41265714 14760 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14761 NL80211_FLAG_NEED_RTNL |
14762 NL80211_FLAG_CLEAR_SKB,
636a5d36
JM
14763 },
14764 {
14765 .cmd = NL80211_CMD_DEAUTHENTICATE,
ef6243ac 14766 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14767 .doit = nl80211_deauthenticate,
5617c6cd 14768 .flags = GENL_UNS_ADMIN_PERM,
41265714 14769 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14770 NL80211_FLAG_NEED_RTNL,
636a5d36
JM
14771 },
14772 {
14773 .cmd = NL80211_CMD_DISASSOCIATE,
ef6243ac 14774 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
636a5d36 14775 .doit = nl80211_disassociate,
5617c6cd 14776 .flags = GENL_UNS_ADMIN_PERM,
41265714 14777 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14778 NL80211_FLAG_NEED_RTNL,
636a5d36 14779 },
04a773ad
JB
14780 {
14781 .cmd = NL80211_CMD_JOIN_IBSS,
ef6243ac 14782 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
04a773ad 14783 .doit = nl80211_join_ibss,
5617c6cd 14784 .flags = GENL_UNS_ADMIN_PERM,
41265714 14785 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14786 NL80211_FLAG_NEED_RTNL,
04a773ad
JB
14787 },
14788 {
14789 .cmd = NL80211_CMD_LEAVE_IBSS,
ef6243ac 14790 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
04a773ad 14791 .doit = nl80211_leave_ibss,
5617c6cd 14792 .flags = GENL_UNS_ADMIN_PERM,
41265714 14793 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14794 NL80211_FLAG_NEED_RTNL,
04a773ad 14795 },
aff89a9b
JB
14796#ifdef CONFIG_NL80211_TESTMODE
14797 {
14798 .cmd = NL80211_CMD_TESTMODE,
ef6243ac 14799 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
aff89a9b 14800 .doit = nl80211_testmode_do,
71063f0e 14801 .dumpit = nl80211_testmode_dump,
5617c6cd 14802 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14803 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14804 NL80211_FLAG_NEED_RTNL,
aff89a9b
JB
14805 },
14806#endif
b23aa676
SO
14807 {
14808 .cmd = NL80211_CMD_CONNECT,
ef6243ac 14809 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b23aa676 14810 .doit = nl80211_connect,
5617c6cd 14811 .flags = GENL_UNS_ADMIN_PERM,
41265714 14812 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14813 NL80211_FLAG_NEED_RTNL |
14814 NL80211_FLAG_CLEAR_SKB,
b23aa676 14815 },
088e8df8 14816 {
14817 .cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS,
ef6243ac 14818 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
088e8df8 14819 .doit = nl80211_update_connect_params,
088e8df8 14820 .flags = GENL_ADMIN_PERM,
14821 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14822 NL80211_FLAG_NEED_RTNL |
14823 NL80211_FLAG_CLEAR_SKB,
088e8df8 14824 },
b23aa676
SO
14825 {
14826 .cmd = NL80211_CMD_DISCONNECT,
ef6243ac 14827 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
b23aa676 14828 .doit = nl80211_disconnect,
5617c6cd 14829 .flags = GENL_UNS_ADMIN_PERM,
41265714 14830 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14831 NL80211_FLAG_NEED_RTNL,
b23aa676 14832 },
463d0183
JB
14833 {
14834 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
ef6243ac 14835 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
463d0183 14836 .doit = nl80211_wiphy_netns,
5617c6cd 14837 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14838 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14839 NL80211_FLAG_NEED_RTNL,
463d0183 14840 },
61fa713c
HS
14841 {
14842 .cmd = NL80211_CMD_GET_SURVEY,
ef6243ac 14843 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
61fa713c
HS
14844 .dumpit = nl80211_dump_survey,
14845 },
67fbb16b
SO
14846 {
14847 .cmd = NL80211_CMD_SET_PMKSA,
ef6243ac 14848 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
67fbb16b 14849 .doit = nl80211_setdel_pmksa,
5617c6cd 14850 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14851 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
14852 NL80211_FLAG_NEED_RTNL |
14853 NL80211_FLAG_CLEAR_SKB,
67fbb16b
SO
14854 },
14855 {
14856 .cmd = NL80211_CMD_DEL_PMKSA,
ef6243ac 14857 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
67fbb16b 14858 .doit = nl80211_setdel_pmksa,
5617c6cd 14859 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14860 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14861 NL80211_FLAG_NEED_RTNL,
67fbb16b
SO
14862 },
14863 {
14864 .cmd = NL80211_CMD_FLUSH_PMKSA,
ef6243ac 14865 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
67fbb16b 14866 .doit = nl80211_flush_pmksa,
5617c6cd 14867 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 14868 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4c476991 14869 NL80211_FLAG_NEED_RTNL,
67fbb16b 14870 },
9588bbd5
JM
14871 {
14872 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
ef6243ac 14873 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9588bbd5 14874 .doit = nl80211_remain_on_channel,
5617c6cd 14875 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14876 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14877 NL80211_FLAG_NEED_RTNL,
9588bbd5
JM
14878 },
14879 {
14880 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
ef6243ac 14881 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9588bbd5 14882 .doit = nl80211_cancel_remain_on_channel,
5617c6cd 14883 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14884 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14885 NL80211_FLAG_NEED_RTNL,
9588bbd5 14886 },
13ae75b1
JM
14887 {
14888 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
ef6243ac 14889 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
13ae75b1 14890 .doit = nl80211_set_tx_bitrate_mask,
5617c6cd 14891 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14892 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14893 NL80211_FLAG_NEED_RTNL,
13ae75b1 14894 },
026331c4 14895 {
2e161f78 14896 .cmd = NL80211_CMD_REGISTER_FRAME,
ef6243ac 14897 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2e161f78 14898 .doit = nl80211_register_mgmt,
5617c6cd 14899 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14900 .internal_flags = NL80211_FLAG_NEED_WDEV |
4c476991 14901 NL80211_FLAG_NEED_RTNL,
026331c4
JM
14902 },
14903 {
2e161f78 14904 .cmd = NL80211_CMD_FRAME,
ef6243ac 14905 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2e161f78 14906 .doit = nl80211_tx_mgmt,
5617c6cd 14907 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14908 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
f7ca38df
JB
14909 NL80211_FLAG_NEED_RTNL,
14910 },
14911 {
14912 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
ef6243ac 14913 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
f7ca38df 14914 .doit = nl80211_tx_mgmt_cancel_wait,
5617c6cd 14915 .flags = GENL_UNS_ADMIN_PERM,
71bbc994 14916 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
4c476991 14917 NL80211_FLAG_NEED_RTNL,
026331c4 14918 },
ffb9eb3d
KV
14919 {
14920 .cmd = NL80211_CMD_SET_POWER_SAVE,
ef6243ac 14921 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ffb9eb3d 14922 .doit = nl80211_set_power_save,
5617c6cd 14923 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14924 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14925 NL80211_FLAG_NEED_RTNL,
ffb9eb3d
KV
14926 },
14927 {
14928 .cmd = NL80211_CMD_GET_POWER_SAVE,
ef6243ac 14929 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ffb9eb3d 14930 .doit = nl80211_get_power_save,
ffb9eb3d 14931 /* can be retrieved by unprivileged users */
4c476991
JB
14932 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14933 NL80211_FLAG_NEED_RTNL,
ffb9eb3d 14934 },
d6dc1a38
JO
14935 {
14936 .cmd = NL80211_CMD_SET_CQM,
ef6243ac 14937 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
d6dc1a38 14938 .doit = nl80211_set_cqm,
5617c6cd 14939 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14940 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14941 NL80211_FLAG_NEED_RTNL,
d6dc1a38 14942 },
f444de05
JB
14943 {
14944 .cmd = NL80211_CMD_SET_CHANNEL,
ef6243ac 14945 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
f444de05 14946 .doit = nl80211_set_channel,
5617c6cd 14947 .flags = GENL_UNS_ADMIN_PERM,
4c476991
JB
14948 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14949 NL80211_FLAG_NEED_RTNL,
f444de05 14950 },
e8347eba
BJ
14951 {
14952 .cmd = NL80211_CMD_SET_WDS_PEER,
ef6243ac 14953 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
e8347eba 14954 .doit = nl80211_set_wds_peer,
5617c6cd 14955 .flags = GENL_UNS_ADMIN_PERM,
43b19952
JB
14956 .internal_flags = NL80211_FLAG_NEED_NETDEV |
14957 NL80211_FLAG_NEED_RTNL,
e8347eba 14958 },
29cbe68c
JB
14959 {
14960 .cmd = NL80211_CMD_JOIN_MESH,
ef6243ac 14961 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
29cbe68c 14962 .doit = nl80211_join_mesh,
5617c6cd 14963 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
14964 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14965 NL80211_FLAG_NEED_RTNL,
14966 },
14967 {
14968 .cmd = NL80211_CMD_LEAVE_MESH,
ef6243ac 14969 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
29cbe68c 14970 .doit = nl80211_leave_mesh,
5617c6cd 14971 .flags = GENL_UNS_ADMIN_PERM,
29cbe68c
JB
14972 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14973 NL80211_FLAG_NEED_RTNL,
14974 },
6e0bd6c3
RL
14975 {
14976 .cmd = NL80211_CMD_JOIN_OCB,
ef6243ac 14977 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
6e0bd6c3 14978 .doit = nl80211_join_ocb,
5617c6cd 14979 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
14980 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14981 NL80211_FLAG_NEED_RTNL,
14982 },
14983 {
14984 .cmd = NL80211_CMD_LEAVE_OCB,
ef6243ac 14985 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
6e0bd6c3 14986 .doit = nl80211_leave_ocb,
5617c6cd 14987 .flags = GENL_UNS_ADMIN_PERM,
6e0bd6c3
RL
14988 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
14989 NL80211_FLAG_NEED_RTNL,
14990 },
dfb89c56 14991#ifdef CONFIG_PM
ff1b6e69
JB
14992 {
14993 .cmd = NL80211_CMD_GET_WOWLAN,
ef6243ac 14994 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ff1b6e69 14995 .doit = nl80211_get_wowlan,
ff1b6e69
JB
14996 /* can be retrieved by unprivileged users */
14997 .internal_flags = NL80211_FLAG_NEED_WIPHY |
14998 NL80211_FLAG_NEED_RTNL,
14999 },
15000 {
15001 .cmd = NL80211_CMD_SET_WOWLAN,
ef6243ac 15002 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ff1b6e69 15003 .doit = nl80211_set_wowlan,
5617c6cd 15004 .flags = GENL_UNS_ADMIN_PERM,
ff1b6e69
JB
15005 .internal_flags = NL80211_FLAG_NEED_WIPHY |
15006 NL80211_FLAG_NEED_RTNL,
15007 },
dfb89c56 15008#endif
e5497d76
JB
15009 {
15010 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD,
ef6243ac 15011 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
e5497d76 15012 .doit = nl80211_set_rekey_data,
5617c6cd 15013 .flags = GENL_UNS_ADMIN_PERM,
e5497d76 15014 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5393b917
JB
15015 NL80211_FLAG_NEED_RTNL |
15016 NL80211_FLAG_CLEAR_SKB,
e5497d76 15017 },
109086ce
AN
15018 {
15019 .cmd = NL80211_CMD_TDLS_MGMT,
ef6243ac 15020 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
109086ce 15021 .doit = nl80211_tdls_mgmt,
5617c6cd 15022 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
15023 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15024 NL80211_FLAG_NEED_RTNL,
15025 },
15026 {
15027 .cmd = NL80211_CMD_TDLS_OPER,
ef6243ac 15028 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
109086ce 15029 .doit = nl80211_tdls_oper,
5617c6cd 15030 .flags = GENL_UNS_ADMIN_PERM,
109086ce
AN
15031 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15032 NL80211_FLAG_NEED_RTNL,
15033 },
28946da7
JB
15034 {
15035 .cmd = NL80211_CMD_UNEXPECTED_FRAME,
ef6243ac 15036 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
28946da7 15037 .doit = nl80211_register_unexpected_frame,
5617c6cd 15038 .flags = GENL_UNS_ADMIN_PERM,
28946da7
JB
15039 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15040 NL80211_FLAG_NEED_RTNL,
15041 },
7f6cf311
JB
15042 {
15043 .cmd = NL80211_CMD_PROBE_CLIENT,
ef6243ac 15044 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
7f6cf311 15045 .doit = nl80211_probe_client,
5617c6cd 15046 .flags = GENL_UNS_ADMIN_PERM,
2b5f8b0b 15047 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
7f6cf311
JB
15048 NL80211_FLAG_NEED_RTNL,
15049 },
5e760230
JB
15050 {
15051 .cmd = NL80211_CMD_REGISTER_BEACONS,
ef6243ac 15052 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5e760230 15053 .doit = nl80211_register_beacons,
5617c6cd 15054 .flags = GENL_UNS_ADMIN_PERM,
5e760230
JB
15055 .internal_flags = NL80211_FLAG_NEED_WIPHY |
15056 NL80211_FLAG_NEED_RTNL,
15057 },
1d9d9213
SW
15058 {
15059 .cmd = NL80211_CMD_SET_NOACK_MAP,
ef6243ac 15060 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1d9d9213 15061 .doit = nl80211_set_noack_map,
5617c6cd 15062 .flags = GENL_UNS_ADMIN_PERM,
1d9d9213
SW
15063 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15064 NL80211_FLAG_NEED_RTNL,
15065 },
98104fde
JB
15066 {
15067 .cmd = NL80211_CMD_START_P2P_DEVICE,
ef6243ac 15068 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
98104fde 15069 .doit = nl80211_start_p2p_device,
5617c6cd 15070 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
15071 .internal_flags = NL80211_FLAG_NEED_WDEV |
15072 NL80211_FLAG_NEED_RTNL,
15073 },
15074 {
15075 .cmd = NL80211_CMD_STOP_P2P_DEVICE,
ef6243ac 15076 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
98104fde 15077 .doit = nl80211_stop_p2p_device,
5617c6cd 15078 .flags = GENL_UNS_ADMIN_PERM,
98104fde
JB
15079 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15080 NL80211_FLAG_NEED_RTNL,
cb3b7d87
AB
15081 },
15082 {
15083 .cmd = NL80211_CMD_START_NAN,
ef6243ac 15084 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
cb3b7d87 15085 .doit = nl80211_start_nan,
cb3b7d87
AB
15086 .flags = GENL_ADMIN_PERM,
15087 .internal_flags = NL80211_FLAG_NEED_WDEV |
15088 NL80211_FLAG_NEED_RTNL,
15089 },
15090 {
15091 .cmd = NL80211_CMD_STOP_NAN,
ef6243ac 15092 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
cb3b7d87 15093 .doit = nl80211_stop_nan,
cb3b7d87
AB
15094 .flags = GENL_ADMIN_PERM,
15095 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15096 NL80211_FLAG_NEED_RTNL,
a442b761
AB
15097 },
15098 {
15099 .cmd = NL80211_CMD_ADD_NAN_FUNCTION,
ef6243ac 15100 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
a442b761 15101 .doit = nl80211_nan_add_func,
a442b761
AB
15102 .flags = GENL_ADMIN_PERM,
15103 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15104 NL80211_FLAG_NEED_RTNL,
15105 },
15106 {
15107 .cmd = NL80211_CMD_DEL_NAN_FUNCTION,
ef6243ac 15108 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
a442b761 15109 .doit = nl80211_nan_del_func,
a442b761
AB
15110 .flags = GENL_ADMIN_PERM,
15111 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15112 NL80211_FLAG_NEED_RTNL,
a5a9dcf2
AB
15113 },
15114 {
15115 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG,
ef6243ac 15116 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
a5a9dcf2 15117 .doit = nl80211_nan_change_config,
a5a9dcf2
AB
15118 .flags = GENL_ADMIN_PERM,
15119 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15120 NL80211_FLAG_NEED_RTNL,
98104fde 15121 },
f4e583c8
AQ
15122 {
15123 .cmd = NL80211_CMD_SET_MCAST_RATE,
ef6243ac 15124 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
f4e583c8 15125 .doit = nl80211_set_mcast_rate,
5617c6cd 15126 .flags = GENL_UNS_ADMIN_PERM,
77765eaf
VT
15127 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15128 NL80211_FLAG_NEED_RTNL,
15129 },
15130 {
15131 .cmd = NL80211_CMD_SET_MAC_ACL,
ef6243ac 15132 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
77765eaf 15133 .doit = nl80211_set_mac_acl,
5617c6cd 15134 .flags = GENL_UNS_ADMIN_PERM,
f4e583c8
AQ
15135 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15136 NL80211_FLAG_NEED_RTNL,
15137 },
04f39047
SW
15138 {
15139 .cmd = NL80211_CMD_RADAR_DETECT,
ef6243ac 15140 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
04f39047 15141 .doit = nl80211_start_radar_detection,
5617c6cd 15142 .flags = GENL_UNS_ADMIN_PERM,
04f39047
SW
15143 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15144 NL80211_FLAG_NEED_RTNL,
15145 },
3713b4e3
JB
15146 {
15147 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES,
ef6243ac 15148 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
3713b4e3 15149 .doit = nl80211_get_protocol_features,
3713b4e3 15150 },
355199e0
JM
15151 {
15152 .cmd = NL80211_CMD_UPDATE_FT_IES,
ef6243ac 15153 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
355199e0 15154 .doit = nl80211_update_ft_ies,
5617c6cd 15155 .flags = GENL_UNS_ADMIN_PERM,
355199e0
JM
15156 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15157 NL80211_FLAG_NEED_RTNL,
15158 },
5de17984
AS
15159 {
15160 .cmd = NL80211_CMD_CRIT_PROTOCOL_START,
ef6243ac 15161 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5de17984 15162 .doit = nl80211_crit_protocol_start,
5617c6cd 15163 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
15164 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15165 NL80211_FLAG_NEED_RTNL,
15166 },
15167 {
15168 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP,
ef6243ac 15169 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
5de17984 15170 .doit = nl80211_crit_protocol_stop,
5617c6cd 15171 .flags = GENL_UNS_ADMIN_PERM,
5de17984
AS
15172 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15173 NL80211_FLAG_NEED_RTNL,
be29b99a
AK
15174 },
15175 {
15176 .cmd = NL80211_CMD_GET_COALESCE,
ef6243ac 15177 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
be29b99a 15178 .doit = nl80211_get_coalesce,
be29b99a
AK
15179 .internal_flags = NL80211_FLAG_NEED_WIPHY |
15180 NL80211_FLAG_NEED_RTNL,
15181 },
15182 {
15183 .cmd = NL80211_CMD_SET_COALESCE,
ef6243ac 15184 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
be29b99a 15185 .doit = nl80211_set_coalesce,
5617c6cd 15186 .flags = GENL_UNS_ADMIN_PERM,
be29b99a
AK
15187 .internal_flags = NL80211_FLAG_NEED_WIPHY |
15188 NL80211_FLAG_NEED_RTNL,
16ef1fe2
SW
15189 },
15190 {
15191 .cmd = NL80211_CMD_CHANNEL_SWITCH,
ef6243ac 15192 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
16ef1fe2 15193 .doit = nl80211_channel_switch,
5617c6cd 15194 .flags = GENL_UNS_ADMIN_PERM,
16ef1fe2
SW
15195 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15196 NL80211_FLAG_NEED_RTNL,
15197 },
ad7e718c
JB
15198 {
15199 .cmd = NL80211_CMD_VENDOR,
ef6243ac 15200 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ad7e718c 15201 .doit = nl80211_vendor_cmd,
7bdbe400 15202 .dumpit = nl80211_vendor_cmd_dump,
5617c6cd 15203 .flags = GENL_UNS_ADMIN_PERM,
ad7e718c 15204 .internal_flags = NL80211_FLAG_NEED_WIPHY |
d6db02a8
SD
15205 NL80211_FLAG_NEED_RTNL |
15206 NL80211_FLAG_CLEAR_SKB,
ad7e718c 15207 },
fa9ffc74
KP
15208 {
15209 .cmd = NL80211_CMD_SET_QOS_MAP,
ef6243ac 15210 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
fa9ffc74 15211 .doit = nl80211_set_qos_map,
5617c6cd 15212 .flags = GENL_UNS_ADMIN_PERM,
fa9ffc74
KP
15213 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15214 NL80211_FLAG_NEED_RTNL,
15215 },
960d01ac
JB
15216 {
15217 .cmd = NL80211_CMD_ADD_TX_TS,
ef6243ac 15218 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
960d01ac 15219 .doit = nl80211_add_tx_ts,
5617c6cd 15220 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
15221 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15222 NL80211_FLAG_NEED_RTNL,
15223 },
15224 {
15225 .cmd = NL80211_CMD_DEL_TX_TS,
ef6243ac 15226 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
960d01ac 15227 .doit = nl80211_del_tx_ts,
5617c6cd 15228 .flags = GENL_UNS_ADMIN_PERM,
960d01ac
JB
15229 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15230 NL80211_FLAG_NEED_RTNL,
15231 },
1057d35e
AN
15232 {
15233 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH,
ef6243ac 15234 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1057d35e 15235 .doit = nl80211_tdls_channel_switch,
5617c6cd 15236 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
15237 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15238 NL80211_FLAG_NEED_RTNL,
15239 },
15240 {
15241 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH,
ef6243ac 15242 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
1057d35e 15243 .doit = nl80211_tdls_cancel_channel_switch,
5617c6cd 15244 .flags = GENL_UNS_ADMIN_PERM,
1057d35e
AN
15245 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15246 NL80211_FLAG_NEED_RTNL,
15247 },
ce0ce13a
MB
15248 {
15249 .cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST,
ef6243ac 15250 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
ce0ce13a 15251 .doit = nl80211_set_multicast_to_unicast,
ce0ce13a
MB
15252 .flags = GENL_UNS_ADMIN_PERM,
15253 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15254 NL80211_FLAG_NEED_RTNL,
15255 },
3a00df57
AS
15256 {
15257 .cmd = NL80211_CMD_SET_PMK,
ef6243ac 15258 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
3a00df57 15259 .doit = nl80211_set_pmk,
3a00df57 15260 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
d6db02a8
SD
15261 NL80211_FLAG_NEED_RTNL |
15262 NL80211_FLAG_CLEAR_SKB,
3a00df57
AS
15263 },
15264 {
15265 .cmd = NL80211_CMD_DEL_PMK,
ef6243ac 15266 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
3a00df57 15267 .doit = nl80211_del_pmk,
3a00df57
AS
15268 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15269 NL80211_FLAG_NEED_RTNL,
15270 },
40cbfa90
SD
15271 {
15272 .cmd = NL80211_CMD_EXTERNAL_AUTH,
ef6243ac 15273 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
40cbfa90 15274 .doit = nl80211_external_auth,
40cbfa90
SD
15275 .flags = GENL_ADMIN_PERM,
15276 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15277 NL80211_FLAG_NEED_RTNL,
15278 },
2576a9ac
DK
15279 {
15280 .cmd = NL80211_CMD_CONTROL_PORT_FRAME,
ef6243ac 15281 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
2576a9ac 15282 .doit = nl80211_tx_control_port,
2576a9ac
DK
15283 .flags = GENL_UNS_ADMIN_PERM,
15284 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15285 NL80211_FLAG_NEED_RTNL,
15286 },
81e54d08
PKC
15287 {
15288 .cmd = NL80211_CMD_GET_FTM_RESPONDER_STATS,
ef6243ac 15289 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
81e54d08 15290 .doit = nl80211_get_ftm_responder_stats,
81e54d08
PKC
15291 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15292 NL80211_FLAG_NEED_RTNL,
15293 },
9bb7e0f2
JB
15294 {
15295 .cmd = NL80211_CMD_PEER_MEASUREMENT_START,
ef6243ac 15296 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
9bb7e0f2 15297 .doit = nl80211_pmsr_start,
9bb7e0f2
JB
15298 .flags = GENL_UNS_ADMIN_PERM,
15299 .internal_flags = NL80211_FLAG_NEED_WDEV_UP |
15300 NL80211_FLAG_NEED_RTNL,
15301 },
30c63115
S
15302 {
15303 .cmd = NL80211_CMD_NOTIFY_RADAR,
ef6243ac 15304 .validate = GENL_DONT_VALIDATE_STRICT | GENL_DONT_VALIDATE_DUMP,
30c63115 15305 .doit = nl80211_notify_radar_detection,
30c63115
S
15306 .flags = GENL_UNS_ADMIN_PERM,
15307 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15308 NL80211_FLAG_NEED_RTNL,
15309 },
cb74e977
SD
15310 {
15311 .cmd = NL80211_CMD_UPDATE_OWE_INFO,
15312 .doit = nl80211_update_owe_info,
15313 .flags = GENL_ADMIN_PERM,
5ab92e7f
RM
15314 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15315 NL80211_FLAG_NEED_RTNL,
15316 },
15317 {
15318 .cmd = NL80211_CMD_PROBE_MESH_LINK,
15319 .doit = nl80211_probe_mesh_link,
15320 .flags = GENL_UNS_ADMIN_PERM,
cb74e977
SD
15321 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
15322 NL80211_FLAG_NEED_RTNL,
15323 },
77f576de
T
15324 {
15325 .cmd = NL80211_CMD_SET_TID_CONFIG,
15326 .doit = nl80211_set_tid_config,
15327 .flags = GENL_UNS_ADMIN_PERM,
15328 .internal_flags = NL80211_FLAG_NEED_NETDEV |
15329 NL80211_FLAG_NEED_RTNL,
15330 },
55682965 15331};
9588bbd5 15332
56989f6d 15333static struct genl_family nl80211_fam __ro_after_init = {
489111e5
JB
15334 .name = NL80211_GENL_NAME, /* have users key off the name instead */
15335 .hdrsize = 0, /* no private header */
15336 .version = 1, /* no particular meaning now */
15337 .maxattr = NL80211_ATTR_MAX,
3b0f31f2 15338 .policy = nl80211_policy,
489111e5
JB
15339 .netnsok = true,
15340 .pre_doit = nl80211_pre_doit,
15341 .post_doit = nl80211_post_doit,
15342 .module = THIS_MODULE,
15343 .ops = nl80211_ops,
15344 .n_ops = ARRAY_SIZE(nl80211_ops),
15345 .mcgrps = nl80211_mcgrps,
15346 .n_mcgrps = ARRAY_SIZE(nl80211_mcgrps),
50508d94 15347 .parallel_ops = true,
489111e5
JB
15348};
15349
55682965
JB
15350/* notification functions */
15351
3bb20556
JB
15352void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev,
15353 enum nl80211_commands cmd)
55682965
JB
15354{
15355 struct sk_buff *msg;
86e8cf98 15356 struct nl80211_dump_wiphy_state state = {};
55682965 15357
3bb20556
JB
15358 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY &&
15359 cmd != NL80211_CMD_DEL_WIPHY);
15360
fd2120ca 15361 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
55682965
JB
15362 if (!msg)
15363 return;
15364
3bb20556 15365 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) {
55682965
JB
15366 nlmsg_free(msg);
15367 return;
15368 }
15369
68eb5503 15370 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15371 NL80211_MCGRP_CONFIG, GFP_KERNEL);
55682965
JB
15372}
15373
896ff063
DK
15374void nl80211_notify_iface(struct cfg80211_registered_device *rdev,
15375 struct wireless_dev *wdev,
15376 enum nl80211_commands cmd)
15377{
15378 struct sk_buff *msg;
15379
896ff063
DK
15380 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
15381 if (!msg)
15382 return;
15383
3d1a5bbf 15384 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, cmd) < 0) {
896ff063
DK
15385 nlmsg_free(msg);
15386 return;
15387 }
15388
15389 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
15390 NL80211_MCGRP_CONFIG, GFP_KERNEL);
15391}
15392
362a415d
JB
15393static int nl80211_add_scan_req(struct sk_buff *msg,
15394 struct cfg80211_registered_device *rdev)
15395{
15396 struct cfg80211_scan_request *req = rdev->scan_req;
15397 struct nlattr *nest;
15398 int i;
15399
15400 if (WARN_ON(!req))
15401 return 0;
15402
ae0be8de 15403 nest = nla_nest_start_noflag(msg, NL80211_ATTR_SCAN_SSIDS);
362a415d
JB
15404 if (!nest)
15405 goto nla_put_failure;
9360ffd1
DM
15406 for (i = 0; i < req->n_ssids; i++) {
15407 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid))
15408 goto nla_put_failure;
15409 }
362a415d
JB
15410 nla_nest_end(msg, nest);
15411
2032f3b2
TP
15412 if (req->flags & NL80211_SCAN_FLAG_FREQ_KHZ) {
15413 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQ_KHZ);
15414 if (!nest)
15415 goto nla_put_failure;
15416 for (i = 0; i < req->n_channels; i++) {
15417 if (nla_put_u32(msg, i,
15418 ieee80211_channel_to_khz(req->channels[i])))
15419 goto nla_put_failure;
15420 }
15421 nla_nest_end(msg, nest);
15422 } else {
15423 nest = nla_nest_start_noflag(msg,
15424 NL80211_ATTR_SCAN_FREQUENCIES);
15425 if (!nest)
9360ffd1 15426 goto nla_put_failure;
2032f3b2
TP
15427 for (i = 0; i < req->n_channels; i++) {
15428 if (nla_put_u32(msg, i, req->channels[i]->center_freq))
15429 goto nla_put_failure;
15430 }
15431 nla_nest_end(msg, nest);
9360ffd1 15432 }
362a415d 15433
9360ffd1
DM
15434 if (req->ie &&
15435 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie))
15436 goto nla_put_failure;
362a415d 15437
ae917c9f
JB
15438 if (req->flags &&
15439 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags))
15440 goto nla_put_failure;
ed473771 15441
1d76250b
AS
15442 if (req->info.scan_start_tsf &&
15443 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF,
15444 req->info.scan_start_tsf, NL80211_BSS_PAD) ||
15445 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN,
15446 req->info.tsf_bssid)))
15447 goto nla_put_failure;
15448
362a415d
JB
15449 return 0;
15450 nla_put_failure:
15451 return -ENOBUFS;
15452}
15453
505a2e88 15454static int nl80211_prep_scan_msg(struct sk_buff *msg,
a538e2d5 15455 struct cfg80211_registered_device *rdev,
fd014284 15456 struct wireless_dev *wdev,
15e47304 15457 u32 portid, u32 seq, int flags,
a538e2d5 15458 u32 cmd)
2a519311
JB
15459{
15460 void *hdr;
15461
15e47304 15462 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd);
2a519311
JB
15463 if (!hdr)
15464 return -1;
15465
9360ffd1 15466 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
fd014284
JB
15467 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
15468 wdev->netdev->ifindex)) ||
2dad624e
ND
15469 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
15470 NL80211_ATTR_PAD))
9360ffd1 15471 goto nla_put_failure;
2a519311 15472
362a415d
JB
15473 /* ignore errors and send incomplete event anyway */
15474 nl80211_add_scan_req(msg, rdev);
2a519311 15475
053c095a
JB
15476 genlmsg_end(msg, hdr);
15477 return 0;
2a519311
JB
15478
15479 nla_put_failure:
15480 genlmsg_cancel(msg, hdr);
15481 return -EMSGSIZE;
15482}
15483
807f8a8c 15484static int
505a2e88 15485nl80211_prep_sched_scan_msg(struct sk_buff *msg,
96b08fd6 15486 struct cfg80211_sched_scan_request *req, u32 cmd)
807f8a8c
LC
15487{
15488 void *hdr;
15489
96b08fd6 15490 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
807f8a8c
LC
15491 if (!hdr)
15492 return -1;
15493
96b08fd6
AVS
15494 if (nla_put_u32(msg, NL80211_ATTR_WIPHY,
15495 wiphy_to_rdev(req->wiphy)->wiphy_idx) ||
15496 nla_put_u32(msg, NL80211_ATTR_IFINDEX, req->dev->ifindex) ||
15497 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, req->reqid,
15498 NL80211_ATTR_PAD))
9360ffd1 15499 goto nla_put_failure;
807f8a8c 15500
053c095a
JB
15501 genlmsg_end(msg, hdr);
15502 return 0;
807f8a8c
LC
15503
15504 nla_put_failure:
15505 genlmsg_cancel(msg, hdr);
15506 return -EMSGSIZE;
15507}
15508
a538e2d5 15509void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
fd014284 15510 struct wireless_dev *wdev)
a538e2d5
JB
15511{
15512 struct sk_buff *msg;
15513
58050fce 15514 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
a538e2d5
JB
15515 if (!msg)
15516 return;
15517
505a2e88 15518 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
a538e2d5
JB
15519 NL80211_CMD_TRIGGER_SCAN) < 0) {
15520 nlmsg_free(msg);
15521 return;
15522 }
15523
68eb5503 15524 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15525 NL80211_MCGRP_SCAN, GFP_KERNEL);
a538e2d5
JB
15526}
15527
f9d15d16
JB
15528struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev,
15529 struct wireless_dev *wdev, bool aborted)
2a519311
JB
15530{
15531 struct sk_buff *msg;
15532
fd2120ca 15533 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2a519311 15534 if (!msg)
f9d15d16 15535 return NULL;
2a519311 15536
505a2e88 15537 if (nl80211_prep_scan_msg(msg, rdev, wdev, 0, 0, 0,
f9d15d16
JB
15538 aborted ? NL80211_CMD_SCAN_ABORTED :
15539 NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
2a519311 15540 nlmsg_free(msg);
f9d15d16 15541 return NULL;
2a519311
JB
15542 }
15543
f9d15d16 15544 return msg;
2a519311
JB
15545}
15546
505a2e88
AVS
15547/* send message created by nl80211_build_scan_msg() */
15548void nl80211_send_scan_msg(struct cfg80211_registered_device *rdev,
15549 struct sk_buff *msg)
807f8a8c 15550{
807f8a8c
LC
15551 if (!msg)
15552 return;
15553
68eb5503 15554 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15555 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
15556}
15557
96b08fd6 15558void nl80211_send_sched_scan(struct cfg80211_sched_scan_request *req, u32 cmd)
807f8a8c
LC
15559{
15560 struct sk_buff *msg;
15561
58050fce 15562 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
807f8a8c
LC
15563 if (!msg)
15564 return;
15565
96b08fd6 15566 if (nl80211_prep_sched_scan_msg(msg, req, cmd) < 0) {
807f8a8c
LC
15567 nlmsg_free(msg);
15568 return;
15569 }
15570
96b08fd6 15571 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(req->wiphy), msg, 0,
2a94fe48 15572 NL80211_MCGRP_SCAN, GFP_KERNEL);
807f8a8c
LC
15573}
15574
b0d7aa59
JD
15575static bool nl80211_reg_change_event_fill(struct sk_buff *msg,
15576 struct regulatory_request *request)
73d54c9e 15577{
73d54c9e 15578 /* Userspace can always count this one always being set */
9360ffd1
DM
15579 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator))
15580 goto nla_put_failure;
15581
15582 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') {
15583 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
15584 NL80211_REGDOM_TYPE_WORLD))
15585 goto nla_put_failure;
15586 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') {
15587 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
15588 NL80211_REGDOM_TYPE_CUSTOM_WORLD))
15589 goto nla_put_failure;
15590 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
15591 request->intersect) {
15592 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
15593 NL80211_REGDOM_TYPE_INTERSECTION))
15594 goto nla_put_failure;
15595 } else {
15596 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE,
15597 NL80211_REGDOM_TYPE_COUNTRY) ||
15598 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2,
15599 request->alpha2))
15600 goto nla_put_failure;
15601 }
15602
ad30ca2c
AN
15603 if (request->wiphy_idx != WIPHY_IDX_INVALID) {
15604 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx);
15605
15606 if (wiphy &&
15607 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx))
15608 goto nla_put_failure;
1bdd716c
AN
15609
15610 if (wiphy &&
15611 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED &&
15612 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG))
15613 goto nla_put_failure;
ad30ca2c 15614 }
73d54c9e 15615
b0d7aa59
JD
15616 return true;
15617
15618nla_put_failure:
15619 return false;
15620}
15621
15622/*
15623 * This can happen on global regulatory changes or device specific settings
15624 * based on custom regulatory domains.
15625 */
15626void nl80211_common_reg_change_event(enum nl80211_commands cmd_id,
15627 struct regulatory_request *request)
15628{
15629 struct sk_buff *msg;
15630 void *hdr;
15631
15632 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
15633 if (!msg)
15634 return;
15635
15636 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id);
24f6d765 15637 if (!hdr)
15638 goto nla_put_failure;
b0d7aa59 15639
24f6d765 15640 if (!nl80211_reg_change_event_fill(msg, request))
b0d7aa59
JD
15641 goto nla_put_failure;
15642
3b7b72ee 15643 genlmsg_end(msg, hdr);
73d54c9e 15644
bc43b28c 15645 rcu_read_lock();
68eb5503 15646 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 15647 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
bc43b28c 15648 rcu_read_unlock();
73d54c9e
LR
15649
15650 return;
15651
15652nla_put_failure:
73d54c9e
LR
15653 nlmsg_free(msg);
15654}
15655
6039f6d2
JM
15656static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
15657 struct net_device *netdev,
15658 const u8 *buf, size_t len,
b0b6aa2c 15659 enum nl80211_commands cmd, gfp_t gfp,
4d9ec73d
JM
15660 int uapsd_queues, const u8 *req_ies,
15661 size_t req_ies_len)
6039f6d2
JM
15662{
15663 struct sk_buff *msg;
15664 void *hdr;
15665
4d9ec73d 15666 msg = nlmsg_new(100 + len + req_ies_len, gfp);
6039f6d2
JM
15667 if (!msg)
15668 return;
15669
15670 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
15671 if (!hdr) {
15672 nlmsg_free(msg);
15673 return;
15674 }
15675
9360ffd1
DM
15676 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15677 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
4d9ec73d
JM
15678 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
15679 (req_ies &&
15680 nla_put(msg, NL80211_ATTR_REQ_IE, req_ies_len, req_ies)))
9360ffd1 15681 goto nla_put_failure;
6039f6d2 15682
b0b6aa2c
EP
15683 if (uapsd_queues >= 0) {
15684 struct nlattr *nla_wmm =
ae0be8de 15685 nla_nest_start_noflag(msg, NL80211_ATTR_STA_WME);
b0b6aa2c
EP
15686 if (!nla_wmm)
15687 goto nla_put_failure;
15688
15689 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES,
15690 uapsd_queues))
15691 goto nla_put_failure;
15692
15693 nla_nest_end(msg, nla_wmm);
15694 }
15695
3b7b72ee 15696 genlmsg_end(msg, hdr);
6039f6d2 15697
68eb5503 15698 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15699 NL80211_MCGRP_MLME, gfp);
6039f6d2
JM
15700 return;
15701
15702 nla_put_failure:
6039f6d2
JM
15703 nlmsg_free(msg);
15704}
15705
15706void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15707 struct net_device *netdev, const u8 *buf,
15708 size_t len, gfp_t gfp)
6039f6d2
JM
15709{
15710 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d 15711 NL80211_CMD_AUTHENTICATE, gfp, -1, NULL, 0);
6039f6d2
JM
15712}
15713
15714void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
15715 struct net_device *netdev, const u8 *buf,
4d9ec73d
JM
15716 size_t len, gfp_t gfp, int uapsd_queues,
15717 const u8 *req_ies, size_t req_ies_len)
6039f6d2 15718{
e6d6e342 15719 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d
JM
15720 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues,
15721 req_ies, req_ies_len);
6039f6d2
JM
15722}
15723
53b46b84 15724void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15725 struct net_device *netdev, const u8 *buf,
15726 size_t len, gfp_t gfp)
6039f6d2
JM
15727{
15728 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d 15729 NL80211_CMD_DEAUTHENTICATE, gfp, -1, NULL, 0);
6039f6d2
JM
15730}
15731
53b46b84
JM
15732void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
15733 struct net_device *netdev, const u8 *buf,
e6d6e342 15734 size_t len, gfp_t gfp)
6039f6d2
JM
15735{
15736 nl80211_send_mlme_event(rdev, netdev, buf, len,
4d9ec73d 15737 NL80211_CMD_DISASSOCIATE, gfp, -1, NULL, 0);
6039f6d2
JM
15738}
15739
6ff57cf8
JB
15740void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf,
15741 size_t len)
cf4e594e 15742{
947add36
JB
15743 struct wireless_dev *wdev = dev->ieee80211_ptr;
15744 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 15745 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
6ff57cf8
JB
15746 const struct ieee80211_mgmt *mgmt = (void *)buf;
15747 u32 cmd;
947add36 15748
6ff57cf8
JB
15749 if (WARN_ON(len < 2))
15750 return;
cf4e594e 15751
4d797fce 15752 if (ieee80211_is_deauth(mgmt->frame_control)) {
6ff57cf8 15753 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE;
4d797fce 15754 } else if (ieee80211_is_disassoc(mgmt->frame_control)) {
6ff57cf8 15755 cmd = NL80211_CMD_UNPROT_DISASSOCIATE;
4d797fce
JM
15756 } else if (ieee80211_is_beacon(mgmt->frame_control)) {
15757 if (wdev->unprot_beacon_reported &&
15758 elapsed_jiffies_msecs(wdev->unprot_beacon_reported) < 10000)
15759 return;
15760 cmd = NL80211_CMD_UNPROT_BEACON;
15761 wdev->unprot_beacon_reported = jiffies;
15762 } else {
15763 return;
15764 }
947add36 15765
6ff57cf8 15766 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len);
4d9ec73d
JM
15767 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1,
15768 NULL, 0);
cf4e594e 15769}
6ff57cf8 15770EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt);
cf4e594e 15771
1b06bb40
LR
15772static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
15773 struct net_device *netdev, int cmd,
e6d6e342 15774 const u8 *addr, gfp_t gfp)
1965c853
JM
15775{
15776 struct sk_buff *msg;
15777 void *hdr;
15778
e6d6e342 15779 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
1965c853
JM
15780 if (!msg)
15781 return;
15782
15783 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
15784 if (!hdr) {
15785 nlmsg_free(msg);
15786 return;
15787 }
15788
9360ffd1
DM
15789 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15790 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15791 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
15792 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
15793 goto nla_put_failure;
1965c853 15794
3b7b72ee 15795 genlmsg_end(msg, hdr);
1965c853 15796
68eb5503 15797 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15798 NL80211_MCGRP_MLME, gfp);
1965c853
JM
15799 return;
15800
15801 nla_put_failure:
1965c853
JM
15802 nlmsg_free(msg);
15803}
15804
15805void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15806 struct net_device *netdev, const u8 *addr,
15807 gfp_t gfp)
1965c853
JM
15808{
15809 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
e6d6e342 15810 addr, gfp);
1965c853
JM
15811}
15812
15813void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
e6d6e342
JB
15814 struct net_device *netdev, const u8 *addr,
15815 gfp_t gfp)
1965c853 15816{
e6d6e342
JB
15817 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
15818 addr, gfp);
1965c853
JM
15819}
15820
b23aa676 15821void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5349a0f7
VK
15822 struct net_device *netdev,
15823 struct cfg80211_connect_resp_params *cr,
3093ebbe 15824 gfp_t gfp)
b23aa676
SO
15825{
15826 struct sk_buff *msg;
15827 void *hdr;
15828
a3caf744 15829 msg = nlmsg_new(100 + cr->req_ie_len + cr->resp_ie_len +
76804d28
AVS
15830 cr->fils.kek_len + cr->fils.pmk_len +
15831 (cr->fils.pmkid ? WLAN_PMKID_LEN : 0), gfp);
b23aa676
SO
15832 if (!msg)
15833 return;
15834
15835 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
15836 if (!hdr) {
15837 nlmsg_free(msg);
15838 return;
15839 }
15840
9360ffd1
DM
15841 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15842 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
5349a0f7
VK
15843 (cr->bssid &&
15844 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, cr->bssid)) ||
bf1ecd21 15845 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE,
5349a0f7
VK
15846 cr->status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE :
15847 cr->status) ||
15848 (cr->status < 0 &&
3093ebbe 15849 (nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) ||
5349a0f7
VK
15850 nla_put_u32(msg, NL80211_ATTR_TIMEOUT_REASON,
15851 cr->timeout_reason))) ||
15852 (cr->req_ie &&
15853 nla_put(msg, NL80211_ATTR_REQ_IE, cr->req_ie_len, cr->req_ie)) ||
15854 (cr->resp_ie &&
15855 nla_put(msg, NL80211_ATTR_RESP_IE, cr->resp_ie_len,
a3caf744 15856 cr->resp_ie)) ||
76804d28 15857 (cr->fils.update_erp_next_seq_num &&
a3caf744 15858 nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
76804d28 15859 cr->fils.erp_next_seq_num)) ||
a3caf744 15860 (cr->status == WLAN_STATUS_SUCCESS &&
76804d28
AVS
15861 ((cr->fils.kek &&
15862 nla_put(msg, NL80211_ATTR_FILS_KEK, cr->fils.kek_len,
15863 cr->fils.kek)) ||
15864 (cr->fils.pmk &&
15865 nla_put(msg, NL80211_ATTR_PMK, cr->fils.pmk_len, cr->fils.pmk)) ||
15866 (cr->fils.pmkid &&
15867 nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, cr->fils.pmkid)))))
9360ffd1 15868 goto nla_put_failure;
b23aa676 15869
3b7b72ee 15870 genlmsg_end(msg, hdr);
b23aa676 15871
68eb5503 15872 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15873 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
15874 return;
15875
15876 nla_put_failure:
b23aa676 15877 nlmsg_free(msg);
b23aa676
SO
15878}
15879
15880void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
29ce6ecb
AS
15881 struct net_device *netdev,
15882 struct cfg80211_roam_info *info, gfp_t gfp)
b23aa676
SO
15883{
15884 struct sk_buff *msg;
15885 void *hdr;
29ce6ecb 15886 const u8 *bssid = info->bss ? info->bss->bssid : info->bssid;
b23aa676 15887
e841b7b1
AVS
15888 msg = nlmsg_new(100 + info->req_ie_len + info->resp_ie_len +
15889 info->fils.kek_len + info->fils.pmk_len +
15890 (info->fils.pmkid ? WLAN_PMKID_LEN : 0), gfp);
b23aa676
SO
15891 if (!msg)
15892 return;
15893
15894 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
15895 if (!hdr) {
15896 nlmsg_free(msg);
15897 return;
15898 }
15899
9360ffd1
DM
15900 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15901 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15902 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) ||
29ce6ecb
AS
15903 (info->req_ie &&
15904 nla_put(msg, NL80211_ATTR_REQ_IE, info->req_ie_len,
15905 info->req_ie)) ||
15906 (info->resp_ie &&
15907 nla_put(msg, NL80211_ATTR_RESP_IE, info->resp_ie_len,
e841b7b1
AVS
15908 info->resp_ie)) ||
15909 (info->fils.update_erp_next_seq_num &&
15910 nla_put_u16(msg, NL80211_ATTR_FILS_ERP_NEXT_SEQ_NUM,
15911 info->fils.erp_next_seq_num)) ||
15912 (info->fils.kek &&
15913 nla_put(msg, NL80211_ATTR_FILS_KEK, info->fils.kek_len,
15914 info->fils.kek)) ||
15915 (info->fils.pmk &&
15916 nla_put(msg, NL80211_ATTR_PMK, info->fils.pmk_len, info->fils.pmk)) ||
15917 (info->fils.pmkid &&
15918 nla_put(msg, NL80211_ATTR_PMKID, WLAN_PMKID_LEN, info->fils.pmkid)))
9360ffd1 15919 goto nla_put_failure;
b23aa676 15920
3b7b72ee 15921 genlmsg_end(msg, hdr);
b23aa676 15922
68eb5503 15923 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15924 NL80211_MCGRP_MLME, gfp);
b23aa676
SO
15925 return;
15926
503c1fb9 15927 nla_put_failure:
503c1fb9
AS
15928 nlmsg_free(msg);
15929}
15930
15931void nl80211_send_port_authorized(struct cfg80211_registered_device *rdev,
15932 struct net_device *netdev, const u8 *bssid)
15933{
15934 struct sk_buff *msg;
15935 void *hdr;
15936
15937 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
15938 if (!msg)
15939 return;
15940
15941 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PORT_AUTHORIZED);
15942 if (!hdr) {
15943 nlmsg_free(msg);
15944 return;
15945 }
15946
f4d75993
CHH
15947 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15948 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
15949 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
503c1fb9
AS
15950 goto nla_put_failure;
15951
15952 genlmsg_end(msg, hdr);
15953
15954 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
15955 NL80211_MCGRP_MLME, GFP_KERNEL);
15956 return;
15957
b23aa676 15958 nla_put_failure:
b23aa676 15959 nlmsg_free(msg);
b23aa676
SO
15960}
15961
15962void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
15963 struct net_device *netdev, u16 reason,
667503dd 15964 const u8 *ie, size_t ie_len, bool from_ap)
b23aa676
SO
15965{
15966 struct sk_buff *msg;
15967 void *hdr;
15968
4ef8c1c9 15969 msg = nlmsg_new(100 + ie_len, GFP_KERNEL);
b23aa676
SO
15970 if (!msg)
15971 return;
15972
15973 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
15974 if (!hdr) {
15975 nlmsg_free(msg);
15976 return;
15977 }
15978
9360ffd1
DM
15979 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
15980 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
86b6c465 15981 (reason &&
9360ffd1
DM
15982 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) ||
15983 (from_ap &&
15984 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) ||
15985 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie)))
15986 goto nla_put_failure;
b23aa676 15987
3b7b72ee 15988 genlmsg_end(msg, hdr);
b23aa676 15989
68eb5503 15990 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 15991 NL80211_MCGRP_MLME, GFP_KERNEL);
b23aa676
SO
15992 return;
15993
15994 nla_put_failure:
b23aa676 15995 nlmsg_free(msg);
b23aa676
SO
15996}
15997
04a773ad
JB
15998void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
15999 struct net_device *netdev, const u8 *bssid,
16000 gfp_t gfp)
16001{
16002 struct sk_buff *msg;
16003 void *hdr;
16004
fd2120ca 16005 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
04a773ad
JB
16006 if (!msg)
16007 return;
16008
16009 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
16010 if (!hdr) {
16011 nlmsg_free(msg);
16012 return;
16013 }
16014
9360ffd1
DM
16015 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16016 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
16017 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
16018 goto nla_put_failure;
04a773ad 16019
3b7b72ee 16020 genlmsg_end(msg, hdr);
04a773ad 16021
68eb5503 16022 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16023 NL80211_MCGRP_MLME, gfp);
04a773ad
JB
16024 return;
16025
16026 nla_put_failure:
04a773ad
JB
16027 nlmsg_free(msg);
16028}
16029
947add36 16030void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr,
ecbc12ad
BC
16031 const u8 *ie, u8 ie_len,
16032 int sig_dbm, gfp_t gfp)
c93b5e71 16033{
947add36 16034 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 16035 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
c93b5e71
JC
16036 struct sk_buff *msg;
16037 void *hdr;
16038
947add36
JB
16039 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT))
16040 return;
16041
16042 trace_cfg80211_notify_new_peer_candidate(dev, addr);
16043
4ef8c1c9 16044 msg = nlmsg_new(100 + ie_len, gfp);
c93b5e71
JC
16045 if (!msg)
16046 return;
16047
16048 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE);
16049 if (!hdr) {
16050 nlmsg_free(msg);
16051 return;
16052 }
16053
9360ffd1 16054 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36
JB
16055 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16056 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
9360ffd1 16057 (ie_len && ie &&
ecbc12ad
BC
16058 nla_put(msg, NL80211_ATTR_IE, ie_len, ie)) ||
16059 (sig_dbm &&
16060 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)))
9360ffd1 16061 goto nla_put_failure;
c93b5e71 16062
3b7b72ee 16063 genlmsg_end(msg, hdr);
c93b5e71 16064
68eb5503 16065 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16066 NL80211_MCGRP_MLME, gfp);
c93b5e71
JC
16067 return;
16068
16069 nla_put_failure:
c93b5e71
JC
16070 nlmsg_free(msg);
16071}
947add36 16072EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate);
c93b5e71 16073
a3b8b056
JM
16074void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
16075 struct net_device *netdev, const u8 *addr,
16076 enum nl80211_key_type key_type, int key_id,
e6d6e342 16077 const u8 *tsc, gfp_t gfp)
a3b8b056
JM
16078{
16079 struct sk_buff *msg;
16080 void *hdr;
16081
e6d6e342 16082 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
a3b8b056
JM
16083 if (!msg)
16084 return;
16085
16086 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
16087 if (!hdr) {
16088 nlmsg_free(msg);
16089 return;
16090 }
16091
9360ffd1
DM
16092 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16093 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
16094 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) ||
16095 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) ||
16096 (key_id != -1 &&
16097 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) ||
16098 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc)))
16099 goto nla_put_failure;
a3b8b056 16100
3b7b72ee 16101 genlmsg_end(msg, hdr);
a3b8b056 16102
68eb5503 16103 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16104 NL80211_MCGRP_MLME, gfp);
a3b8b056
JM
16105 return;
16106
16107 nla_put_failure:
a3b8b056
JM
16108 nlmsg_free(msg);
16109}
16110
6bad8766
LR
16111void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
16112 struct ieee80211_channel *channel_before,
16113 struct ieee80211_channel *channel_after)
16114{
16115 struct sk_buff *msg;
16116 void *hdr;
16117 struct nlattr *nl_freq;
16118
fd2120ca 16119 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
6bad8766
LR
16120 if (!msg)
16121 return;
16122
16123 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
16124 if (!hdr) {
16125 nlmsg_free(msg);
16126 return;
16127 }
16128
16129 /*
16130 * Since we are applying the beacon hint to a wiphy we know its
16131 * wiphy_idx is valid
16132 */
9360ffd1
DM
16133 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy)))
16134 goto nla_put_failure;
6bad8766
LR
16135
16136 /* Before */
ae0be8de 16137 nl_freq = nla_nest_start_noflag(msg, NL80211_ATTR_FREQ_BEFORE);
6bad8766
LR
16138 if (!nl_freq)
16139 goto nla_put_failure;
50f32718
HD
16140
16141 if (nl80211_msg_put_channel(msg, wiphy, channel_before, false))
6bad8766
LR
16142 goto nla_put_failure;
16143 nla_nest_end(msg, nl_freq);
16144
16145 /* After */
ae0be8de 16146 nl_freq = nla_nest_start_noflag(msg, NL80211_ATTR_FREQ_AFTER);
6bad8766
LR
16147 if (!nl_freq)
16148 goto nla_put_failure;
50f32718
HD
16149
16150 if (nl80211_msg_put_channel(msg, wiphy, channel_after, false))
6bad8766
LR
16151 goto nla_put_failure;
16152 nla_nest_end(msg, nl_freq);
16153
3b7b72ee 16154 genlmsg_end(msg, hdr);
6bad8766 16155
463d0183 16156 rcu_read_lock();
68eb5503 16157 genlmsg_multicast_allns(&nl80211_fam, msg, 0,
2a94fe48 16158 NL80211_MCGRP_REGULATORY, GFP_ATOMIC);
463d0183 16159 rcu_read_unlock();
6bad8766
LR
16160
16161 return;
16162
16163nla_put_failure:
6bad8766
LR
16164 nlmsg_free(msg);
16165}
16166
9588bbd5
JM
16167static void nl80211_send_remain_on_chan_event(
16168 int cmd, struct cfg80211_registered_device *rdev,
71bbc994 16169 struct wireless_dev *wdev, u64 cookie,
9588bbd5 16170 struct ieee80211_channel *chan,
9588bbd5
JM
16171 unsigned int duration, gfp_t gfp)
16172{
16173 struct sk_buff *msg;
16174 void *hdr;
16175
16176 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16177 if (!msg)
16178 return;
16179
16180 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
16181 if (!hdr) {
16182 nlmsg_free(msg);
16183 return;
16184 }
16185
9360ffd1 16186 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
16187 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
16188 wdev->netdev->ifindex)) ||
2dad624e
ND
16189 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16190 NL80211_ATTR_PAD) ||
9360ffd1 16191 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) ||
42d97a59
JB
16192 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE,
16193 NL80211_CHAN_NO_HT) ||
2dad624e
ND
16194 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
16195 NL80211_ATTR_PAD))
9360ffd1 16196 goto nla_put_failure;
9588bbd5 16197
9360ffd1
DM
16198 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL &&
16199 nla_put_u32(msg, NL80211_ATTR_DURATION, duration))
16200 goto nla_put_failure;
9588bbd5 16201
3b7b72ee 16202 genlmsg_end(msg, hdr);
9588bbd5 16203
68eb5503 16204 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16205 NL80211_MCGRP_MLME, gfp);
9588bbd5
JM
16206 return;
16207
16208 nla_put_failure:
9588bbd5
JM
16209 nlmsg_free(msg);
16210}
16211
947add36
JB
16212void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie,
16213 struct ieee80211_channel *chan,
16214 unsigned int duration, gfp_t gfp)
9588bbd5 16215{
947add36 16216 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16217 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
16218
16219 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration);
9588bbd5 16220 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
71bbc994 16221 rdev, wdev, cookie, chan,
42d97a59 16222 duration, gfp);
9588bbd5 16223}
947add36 16224EXPORT_SYMBOL(cfg80211_ready_on_channel);
9588bbd5 16225
947add36
JB
16226void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie,
16227 struct ieee80211_channel *chan,
16228 gfp_t gfp)
9588bbd5 16229{
947add36 16230 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16231 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
16232
16233 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan);
9588bbd5 16234 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
42d97a59 16235 rdev, wdev, cookie, chan, 0, gfp);
9588bbd5 16236}
947add36 16237EXPORT_SYMBOL(cfg80211_remain_on_channel_expired);
9588bbd5 16238
1c38c7f2
JP
16239void cfg80211_tx_mgmt_expired(struct wireless_dev *wdev, u64 cookie,
16240 struct ieee80211_channel *chan,
16241 gfp_t gfp)
16242{
16243 struct wiphy *wiphy = wdev->wiphy;
16244 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
16245
16246 trace_cfg80211_tx_mgmt_expired(wdev, cookie, chan);
16247 nl80211_send_remain_on_chan_event(NL80211_CMD_FRAME_WAIT_CANCEL,
16248 rdev, wdev, cookie, chan, 0, gfp);
16249}
16250EXPORT_SYMBOL(cfg80211_tx_mgmt_expired);
16251
947add36
JB
16252void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr,
16253 struct station_info *sinfo, gfp_t gfp)
98b62183 16254{
947add36 16255 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 16256 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
98b62183
JB
16257 struct sk_buff *msg;
16258
947add36
JB
16259 trace_cfg80211_new_sta(dev, mac_addr, sinfo);
16260
58050fce 16261 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
98b62183
JB
16262 if (!msg)
16263 return;
16264
cf5ead82 16265 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0,
66266b3a 16266 rdev, dev, mac_addr, sinfo) < 0) {
98b62183
JB
16267 nlmsg_free(msg);
16268 return;
16269 }
16270
68eb5503 16271 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16272 NL80211_MCGRP_MLME, gfp);
98b62183 16273}
947add36 16274EXPORT_SYMBOL(cfg80211_new_sta);
98b62183 16275
cf5ead82
JB
16276void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr,
16277 struct station_info *sinfo, gfp_t gfp)
ec15e68b 16278{
947add36 16279 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 16280 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ec15e68b 16281 struct sk_buff *msg;
73887fd9 16282 struct station_info empty_sinfo = {};
cf5ead82 16283
73887fd9
JB
16284 if (!sinfo)
16285 sinfo = &empty_sinfo;
ec15e68b 16286
947add36
JB
16287 trace_cfg80211_del_sta(dev, mac_addr);
16288
58050fce 16289 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
7ea3e110
JB
16290 if (!msg) {
16291 cfg80211_sinfo_release_content(sinfo);
73887fd9 16292 return;
7ea3e110 16293 }
ec15e68b 16294
cf5ead82 16295 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0,
57007121 16296 rdev, dev, mac_addr, sinfo) < 0) {
ec15e68b 16297 nlmsg_free(msg);
73887fd9 16298 return;
ec15e68b
JM
16299 }
16300
68eb5503 16301 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16302 NL80211_MCGRP_MLME, gfp);
ec15e68b 16303}
cf5ead82 16304EXPORT_SYMBOL(cfg80211_del_sta_sinfo);
ec15e68b 16305
947add36
JB
16306void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr,
16307 enum nl80211_connect_failed_reason reason,
16308 gfp_t gfp)
ed44a951 16309{
947add36 16310 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy;
f26cbf40 16311 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
ed44a951
PP
16312 struct sk_buff *msg;
16313 void *hdr;
16314
16315 msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
16316 if (!msg)
16317 return;
16318
16319 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED);
16320 if (!hdr) {
16321 nlmsg_free(msg);
16322 return;
16323 }
16324
16325 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16326 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) ||
16327 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason))
16328 goto nla_put_failure;
16329
16330 genlmsg_end(msg, hdr);
16331
68eb5503 16332 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16333 NL80211_MCGRP_MLME, gfp);
ed44a951
PP
16334 return;
16335
16336 nla_put_failure:
ed44a951
PP
16337 nlmsg_free(msg);
16338}
947add36 16339EXPORT_SYMBOL(cfg80211_conn_failed);
ed44a951 16340
b92ab5d8
JB
16341static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd,
16342 const u8 *addr, gfp_t gfp)
28946da7
JB
16343{
16344 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 16345 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
28946da7
JB
16346 struct sk_buff *msg;
16347 void *hdr;
6aa7de05 16348 u32 nlportid = READ_ONCE(wdev->ap_unexpected_nlportid);
28946da7 16349
15e47304 16350 if (!nlportid)
28946da7
JB
16351 return false;
16352
16353 msg = nlmsg_new(100, gfp);
16354 if (!msg)
16355 return true;
16356
b92ab5d8 16357 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
28946da7
JB
16358 if (!hdr) {
16359 nlmsg_free(msg);
16360 return true;
16361 }
16362
9360ffd1
DM
16363 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16364 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16365 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr))
16366 goto nla_put_failure;
28946da7 16367
9c90a9f6 16368 genlmsg_end(msg, hdr);
15e47304 16369 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
28946da7
JB
16370 return true;
16371
16372 nla_put_failure:
28946da7
JB
16373 nlmsg_free(msg);
16374 return true;
16375}
16376
947add36
JB
16377bool cfg80211_rx_spurious_frame(struct net_device *dev,
16378 const u8 *addr, gfp_t gfp)
b92ab5d8 16379{
947add36
JB
16380 struct wireless_dev *wdev = dev->ieee80211_ptr;
16381 bool ret;
16382
16383 trace_cfg80211_rx_spurious_frame(dev, addr);
16384
16385 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
16386 wdev->iftype != NL80211_IFTYPE_P2P_GO)) {
16387 trace_cfg80211_return_bool(false);
16388 return false;
16389 }
16390 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME,
16391 addr, gfp);
16392 trace_cfg80211_return_bool(ret);
16393 return ret;
b92ab5d8 16394}
947add36 16395EXPORT_SYMBOL(cfg80211_rx_spurious_frame);
b92ab5d8 16396
947add36
JB
16397bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev,
16398 const u8 *addr, gfp_t gfp)
b92ab5d8 16399{
947add36
JB
16400 struct wireless_dev *wdev = dev->ieee80211_ptr;
16401 bool ret;
16402
16403 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr);
16404
16405 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP &&
16406 wdev->iftype != NL80211_IFTYPE_P2P_GO &&
16407 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) {
16408 trace_cfg80211_return_bool(false);
16409 return false;
16410 }
16411 ret = __nl80211_unexpected_frame(dev,
16412 NL80211_CMD_UNEXPECTED_4ADDR_FRAME,
16413 addr, gfp);
16414 trace_cfg80211_return_bool(ret);
16415 return ret;
b92ab5d8 16416}
947add36 16417EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame);
b92ab5d8 16418
2e161f78 16419int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
15e47304 16420 struct wireless_dev *wdev, u32 nlportid,
804483e9 16421 int freq, int sig_dbm,
19504cf5 16422 const u8 *buf, size_t len, u32 flags, gfp_t gfp)
026331c4 16423{
71bbc994 16424 struct net_device *netdev = wdev->netdev;
026331c4
JM
16425 struct sk_buff *msg;
16426 void *hdr;
026331c4 16427
4ef8c1c9 16428 msg = nlmsg_new(100 + len, gfp);
026331c4
JM
16429 if (!msg)
16430 return -ENOMEM;
16431
2e161f78 16432 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
026331c4
JM
16433 if (!hdr) {
16434 nlmsg_free(msg);
16435 return -ENOMEM;
16436 }
16437
9360ffd1 16438 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
16439 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
16440 netdev->ifindex)) ||
2dad624e
ND
16441 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16442 NL80211_ATTR_PAD) ||
e76fede8 16443 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, KHZ_TO_MHZ(freq)) ||
942ba88b 16444 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_OFFSET, freq % 1000) ||
9360ffd1
DM
16445 (sig_dbm &&
16446 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
19504cf5
VK
16447 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
16448 (flags &&
16449 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags)))
9360ffd1 16450 goto nla_put_failure;
026331c4 16451
3b7b72ee 16452 genlmsg_end(msg, hdr);
026331c4 16453
15e47304 16454 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
026331c4
JM
16455
16456 nla_put_failure:
026331c4
JM
16457 nlmsg_free(msg);
16458 return -ENOBUFS;
16459}
16460
dca9ca2d
MT
16461static void nl80211_frame_tx_status(struct wireless_dev *wdev, u64 cookie,
16462 const u8 *buf, size_t len, bool ack,
16463 gfp_t gfp, enum nl80211_commands command)
026331c4 16464{
947add36 16465 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16466 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
71bbc994 16467 struct net_device *netdev = wdev->netdev;
026331c4
JM
16468 struct sk_buff *msg;
16469 void *hdr;
16470
dca9ca2d
MT
16471 if (command == NL80211_CMD_FRAME_TX_STATUS)
16472 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack);
16473 else
16474 trace_cfg80211_control_port_tx_status(wdev, cookie, ack);
947add36 16475
4ef8c1c9 16476 msg = nlmsg_new(100 + len, gfp);
026331c4
JM
16477 if (!msg)
16478 return;
16479
dca9ca2d 16480 hdr = nl80211hdr_put(msg, 0, 0, 0, command);
026331c4
JM
16481 if (!hdr) {
16482 nlmsg_free(msg);
16483 return;
16484 }
16485
9360ffd1 16486 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
71bbc994
JB
16487 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
16488 netdev->ifindex)) ||
2dad624e
ND
16489 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16490 NL80211_ATTR_PAD) ||
9360ffd1 16491 nla_put(msg, NL80211_ATTR_FRAME, len, buf) ||
2dad624e
ND
16492 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
16493 NL80211_ATTR_PAD) ||
9360ffd1
DM
16494 (ack && nla_put_flag(msg, NL80211_ATTR_ACK)))
16495 goto nla_put_failure;
026331c4 16496
3b7b72ee 16497 genlmsg_end(msg, hdr);
026331c4 16498
68eb5503 16499 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16500 NL80211_MCGRP_MLME, gfp);
026331c4
JM
16501 return;
16502
dca9ca2d 16503nla_put_failure:
026331c4
JM
16504 nlmsg_free(msg);
16505}
dca9ca2d
MT
16506
16507void cfg80211_control_port_tx_status(struct wireless_dev *wdev, u64 cookie,
16508 const u8 *buf, size_t len, bool ack,
16509 gfp_t gfp)
16510{
16511 nl80211_frame_tx_status(wdev, cookie, buf, len, ack, gfp,
16512 NL80211_CMD_CONTROL_PORT_FRAME_TX_STATUS);
16513}
16514EXPORT_SYMBOL(cfg80211_control_port_tx_status);
16515
16516void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie,
16517 const u8 *buf, size_t len, bool ack, gfp_t gfp)
16518{
16519 nl80211_frame_tx_status(wdev, cookie, buf, len, ack, gfp,
16520 NL80211_CMD_FRAME_TX_STATUS);
16521}
947add36 16522EXPORT_SYMBOL(cfg80211_mgmt_tx_status);
026331c4 16523
6a671a50 16524static int __nl80211_rx_control_port(struct net_device *dev,
a948f713 16525 struct sk_buff *skb,
6a671a50
DK
16526 bool unencrypted, gfp_t gfp)
16527{
16528 struct wireless_dev *wdev = dev->ieee80211_ptr;
16529 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
a948f713 16530 struct ethhdr *ehdr = eth_hdr(skb);
8d74a623 16531 const u8 *addr = ehdr->h_source;
a948f713 16532 u16 proto = be16_to_cpu(skb->protocol);
6a671a50
DK
16533 struct sk_buff *msg;
16534 void *hdr;
a948f713
DK
16535 struct nlattr *frame;
16536
6a671a50
DK
16537 u32 nlportid = READ_ONCE(wdev->conn_owner_nlportid);
16538
16539 if (!nlportid)
16540 return -ENOENT;
16541
a948f713 16542 msg = nlmsg_new(100 + skb->len, gfp);
6a671a50
DK
16543 if (!msg)
16544 return -ENOMEM;
16545
16546 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONTROL_PORT_FRAME);
16547 if (!hdr) {
16548 nlmsg_free(msg);
16549 return -ENOBUFS;
16550 }
16551
16552 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16553 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
16554 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16555 NL80211_ATTR_PAD) ||
8d74a623 16556 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
6a671a50
DK
16557 nla_put_u16(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE, proto) ||
16558 (unencrypted && nla_put_flag(msg,
16559 NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT)))
16560 goto nla_put_failure;
16561
a948f713
DK
16562 frame = nla_reserve(msg, NL80211_ATTR_FRAME, skb->len);
16563 if (!frame)
16564 goto nla_put_failure;
16565
16566 skb_copy_bits(skb, 0, nla_data(frame), skb->len);
6a671a50
DK
16567 genlmsg_end(msg, hdr);
16568
16569 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
16570
16571 nla_put_failure:
16572 nlmsg_free(msg);
16573 return -ENOBUFS;
16574}
16575
16576bool cfg80211_rx_control_port(struct net_device *dev,
a948f713 16577 struct sk_buff *skb, bool unencrypted)
6a671a50
DK
16578{
16579 int ret;
16580
a948f713
DK
16581 trace_cfg80211_rx_control_port(dev, skb, unencrypted);
16582 ret = __nl80211_rx_control_port(dev, skb, unencrypted, GFP_ATOMIC);
6a671a50
DK
16583 trace_cfg80211_return_bool(ret == 0);
16584 return ret == 0;
16585}
16586EXPORT_SYMBOL(cfg80211_rx_control_port);
16587
5b97f49d
JB
16588static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev,
16589 const char *mac, gfp_t gfp)
d6dc1a38 16590{
947add36 16591 struct wireless_dev *wdev = dev->ieee80211_ptr;
5b97f49d
JB
16592 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
16593 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16594 void **cb;
947add36 16595
d6dc1a38 16596 if (!msg)
5b97f49d 16597 return NULL;
d6dc1a38 16598
5b97f49d
JB
16599 cb = (void **)msg->cb;
16600
16601 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
16602 if (!cb[0]) {
d6dc1a38 16603 nlmsg_free(msg);
5b97f49d 16604 return NULL;
d6dc1a38
JO
16605 }
16606
9360ffd1 16607 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
947add36 16608 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
9360ffd1 16609 goto nla_put_failure;
d6dc1a38 16610
5b97f49d 16611 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
d6dc1a38
JO
16612 goto nla_put_failure;
16613
ae0be8de 16614 cb[1] = nla_nest_start_noflag(msg, NL80211_ATTR_CQM);
5b97f49d 16615 if (!cb[1])
9360ffd1 16616 goto nla_put_failure;
d6dc1a38 16617
5b97f49d 16618 cb[2] = rdev;
d6dc1a38 16619
5b97f49d
JB
16620 return msg;
16621 nla_put_failure:
16622 nlmsg_free(msg);
16623 return NULL;
16624}
16625
16626static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp)
16627{
16628 void **cb = (void **)msg->cb;
16629 struct cfg80211_registered_device *rdev = cb[2];
16630
16631 nla_nest_end(msg, cb[1]);
16632 genlmsg_end(msg, cb[0]);
16633
16634 memset(msg->cb, 0, sizeof(msg->cb));
d6dc1a38 16635
68eb5503 16636 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16637 NL80211_MCGRP_MLME, gfp);
5b97f49d
JB
16638}
16639
16640void cfg80211_cqm_rssi_notify(struct net_device *dev,
16641 enum nl80211_cqm_rssi_threshold_event rssi_event,
bee427b8 16642 s32 rssi_level, gfp_t gfp)
5b97f49d
JB
16643{
16644 struct sk_buff *msg;
4a4b8169
AZ
16645 struct wireless_dev *wdev = dev->ieee80211_ptr;
16646 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
5b97f49d 16647
bee427b8 16648 trace_cfg80211_cqm_rssi_notify(dev, rssi_event, rssi_level);
5b97f49d 16649
98f03342
JB
16650 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW &&
16651 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH))
16652 return;
16653
4a4b8169
AZ
16654 if (wdev->cqm_config) {
16655 wdev->cqm_config->last_rssi_event_value = rssi_level;
16656
16657 cfg80211_cqm_rssi_update(rdev, dev);
16658
16659 if (rssi_level == 0)
16660 rssi_level = wdev->cqm_config->last_rssi_event_value;
16661 }
16662
5b97f49d
JB
16663 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
16664 if (!msg)
16665 return;
16666
16667 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
16668 rssi_event))
16669 goto nla_put_failure;
16670
bee427b8
AZ
16671 if (rssi_level && nla_put_s32(msg, NL80211_ATTR_CQM_RSSI_LEVEL,
16672 rssi_level))
16673 goto nla_put_failure;
16674
5b97f49d
JB
16675 cfg80211_send_cqm(msg, gfp);
16676
d6dc1a38
JO
16677 return;
16678
16679 nla_put_failure:
d6dc1a38
JO
16680 nlmsg_free(msg);
16681}
947add36 16682EXPORT_SYMBOL(cfg80211_cqm_rssi_notify);
d6dc1a38 16683
5b97f49d
JB
16684void cfg80211_cqm_txe_notify(struct net_device *dev,
16685 const u8 *peer, u32 num_packets,
16686 u32 rate, u32 intvl, gfp_t gfp)
16687{
16688 struct sk_buff *msg;
16689
16690 msg = cfg80211_prepare_cqm(dev, peer, gfp);
16691 if (!msg)
16692 return;
16693
16694 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets))
16695 goto nla_put_failure;
16696
16697 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate))
16698 goto nla_put_failure;
16699
16700 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl))
16701 goto nla_put_failure;
16702
16703 cfg80211_send_cqm(msg, gfp);
16704 return;
16705
16706 nla_put_failure:
16707 nlmsg_free(msg);
16708}
16709EXPORT_SYMBOL(cfg80211_cqm_txe_notify);
16710
16711void cfg80211_cqm_pktloss_notify(struct net_device *dev,
16712 const u8 *peer, u32 num_packets, gfp_t gfp)
16713{
16714 struct sk_buff *msg;
16715
16716 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets);
16717
16718 msg = cfg80211_prepare_cqm(dev, peer, gfp);
16719 if (!msg)
16720 return;
16721
16722 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets))
16723 goto nla_put_failure;
16724
16725 cfg80211_send_cqm(msg, gfp);
16726 return;
16727
16728 nla_put_failure:
16729 nlmsg_free(msg);
16730}
16731EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify);
16732
98f03342
JB
16733void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp)
16734{
16735 struct sk_buff *msg;
16736
16737 msg = cfg80211_prepare_cqm(dev, NULL, gfp);
16738 if (!msg)
16739 return;
16740
16741 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT))
16742 goto nla_put_failure;
16743
16744 cfg80211_send_cqm(msg, gfp);
16745 return;
16746
16747 nla_put_failure:
16748 nlmsg_free(msg);
16749}
16750EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify);
16751
947add36
JB
16752static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev,
16753 struct net_device *netdev, const u8 *bssid,
16754 const u8 *replay_ctr, gfp_t gfp)
e5497d76
JB
16755{
16756 struct sk_buff *msg;
16757 struct nlattr *rekey_attr;
16758 void *hdr;
16759
58050fce 16760 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
e5497d76
JB
16761 if (!msg)
16762 return;
16763
16764 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD);
16765 if (!hdr) {
16766 nlmsg_free(msg);
16767 return;
16768 }
16769
9360ffd1
DM
16770 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16771 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
16772 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid))
16773 goto nla_put_failure;
e5497d76 16774
ae0be8de 16775 rekey_attr = nla_nest_start_noflag(msg, NL80211_ATTR_REKEY_DATA);
e5497d76
JB
16776 if (!rekey_attr)
16777 goto nla_put_failure;
16778
9360ffd1
DM
16779 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR,
16780 NL80211_REPLAY_CTR_LEN, replay_ctr))
16781 goto nla_put_failure;
e5497d76
JB
16782
16783 nla_nest_end(msg, rekey_attr);
16784
3b7b72ee 16785 genlmsg_end(msg, hdr);
e5497d76 16786
68eb5503 16787 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16788 NL80211_MCGRP_MLME, gfp);
e5497d76
JB
16789 return;
16790
16791 nla_put_failure:
e5497d76
JB
16792 nlmsg_free(msg);
16793}
16794
947add36
JB
16795void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid,
16796 const u8 *replay_ctr, gfp_t gfp)
16797{
16798 struct wireless_dev *wdev = dev->ieee80211_ptr;
16799 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16800 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
16801
16802 trace_cfg80211_gtk_rekey_notify(dev, bssid);
16803 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp);
16804}
16805EXPORT_SYMBOL(cfg80211_gtk_rekey_notify);
16806
16807static void
16808nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev,
16809 struct net_device *netdev, int index,
16810 const u8 *bssid, bool preauth, gfp_t gfp)
c9df56b4
JM
16811{
16812 struct sk_buff *msg;
16813 struct nlattr *attr;
16814 void *hdr;
16815
58050fce 16816 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
c9df56b4
JM
16817 if (!msg)
16818 return;
16819
16820 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE);
16821 if (!hdr) {
16822 nlmsg_free(msg);
16823 return;
16824 }
16825
9360ffd1
DM
16826 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
16827 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
16828 goto nla_put_failure;
c9df56b4 16829
ae0be8de 16830 attr = nla_nest_start_noflag(msg, NL80211_ATTR_PMKSA_CANDIDATE);
c9df56b4
JM
16831 if (!attr)
16832 goto nla_put_failure;
16833
9360ffd1
DM
16834 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) ||
16835 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) ||
16836 (preauth &&
16837 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH)))
16838 goto nla_put_failure;
c9df56b4
JM
16839
16840 nla_nest_end(msg, attr);
16841
3b7b72ee 16842 genlmsg_end(msg, hdr);
c9df56b4 16843
68eb5503 16844 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16845 NL80211_MCGRP_MLME, gfp);
c9df56b4
JM
16846 return;
16847
16848 nla_put_failure:
c9df56b4
JM
16849 nlmsg_free(msg);
16850}
16851
947add36
JB
16852void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index,
16853 const u8 *bssid, bool preauth, gfp_t gfp)
16854{
16855 struct wireless_dev *wdev = dev->ieee80211_ptr;
16856 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16857 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36
JB
16858
16859 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth);
16860 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp);
16861}
16862EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify);
16863
16864static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev,
16865 struct net_device *netdev,
16866 struct cfg80211_chan_def *chandef,
f8d7552e
LC
16867 gfp_t gfp,
16868 enum nl80211_commands notif,
16869 u8 count)
5314526b
TP
16870{
16871 struct sk_buff *msg;
16872 void *hdr;
16873
58050fce 16874 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5314526b
TP
16875 if (!msg)
16876 return;
16877
f8d7552e 16878 hdr = nl80211hdr_put(msg, 0, 0, 0, notif);
5314526b
TP
16879 if (!hdr) {
16880 nlmsg_free(msg);
16881 return;
16882 }
16883
683b6d3b
JB
16884 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex))
16885 goto nla_put_failure;
16886
16887 if (nl80211_send_chandef(msg, chandef))
7eab0f64 16888 goto nla_put_failure;
5314526b 16889
f8d7552e
LC
16890 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) &&
16891 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count)))
16892 goto nla_put_failure;
16893
5314526b
TP
16894 genlmsg_end(msg, hdr);
16895
68eb5503 16896 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16897 NL80211_MCGRP_MLME, gfp);
5314526b
TP
16898 return;
16899
16900 nla_put_failure:
5314526b
TP
16901 nlmsg_free(msg);
16902}
16903
947add36
JB
16904void cfg80211_ch_switch_notify(struct net_device *dev,
16905 struct cfg80211_chan_def *chandef)
84f10708 16906{
947add36
JB
16907 struct wireless_dev *wdev = dev->ieee80211_ptr;
16908 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 16909 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
947add36 16910
e487eaeb 16911 ASSERT_WDEV_LOCK(wdev);
947add36 16912
e487eaeb 16913 trace_cfg80211_ch_switch_notify(dev, chandef);
947add36 16914
9e0e2961 16915 wdev->chandef = *chandef;
96f55f12 16916 wdev->preset_chandef = *chandef;
5dc8cdce
SM
16917
16918 if (wdev->iftype == NL80211_IFTYPE_STATION &&
16919 !WARN_ON(!wdev->current_bss))
0afd425b 16920 cfg80211_update_assoc_bss_entry(wdev, chandef->chan);
5dc8cdce 16921
d34990bb
MV
16922 cfg80211_sched_dfs_chan_update(rdev);
16923
f8d7552e
LC
16924 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
16925 NL80211_CMD_CH_SWITCH_NOTIFY, 0);
947add36
JB
16926}
16927EXPORT_SYMBOL(cfg80211_ch_switch_notify);
16928
f8d7552e
LC
16929void cfg80211_ch_switch_started_notify(struct net_device *dev,
16930 struct cfg80211_chan_def *chandef,
16931 u8 count)
16932{
16933 struct wireless_dev *wdev = dev->ieee80211_ptr;
16934 struct wiphy *wiphy = wdev->wiphy;
16935 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
16936
16937 trace_cfg80211_ch_switch_started_notify(dev, chandef);
16938
16939 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL,
16940 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count);
16941}
16942EXPORT_SYMBOL(cfg80211_ch_switch_started_notify);
16943
04f39047
SW
16944void
16945nl80211_radar_notify(struct cfg80211_registered_device *rdev,
d2859df5 16946 const struct cfg80211_chan_def *chandef,
04f39047
SW
16947 enum nl80211_radar_event event,
16948 struct net_device *netdev, gfp_t gfp)
16949{
16950 struct sk_buff *msg;
16951 void *hdr;
16952
16953 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
16954 if (!msg)
16955 return;
16956
16957 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT);
16958 if (!hdr) {
16959 nlmsg_free(msg);
16960 return;
16961 }
16962
16963 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
16964 goto nla_put_failure;
16965
16966 /* NOP and radar events don't need a netdev parameter */
16967 if (netdev) {
16968 struct wireless_dev *wdev = netdev->ieee80211_ptr;
16969
16970 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
2dad624e
ND
16971 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
16972 NL80211_ATTR_PAD))
04f39047
SW
16973 goto nla_put_failure;
16974 }
16975
16976 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event))
16977 goto nla_put_failure;
16978
16979 if (nl80211_send_chandef(msg, chandef))
16980 goto nla_put_failure;
16981
9c90a9f6 16982 genlmsg_end(msg, hdr);
04f39047 16983
68eb5503 16984 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 16985 NL80211_MCGRP_MLME, gfp);
04f39047
SW
16986 return;
16987
16988 nla_put_failure:
04f39047
SW
16989 nlmsg_free(msg);
16990}
16991
466b9936 16992void cfg80211_sta_opmode_change_notify(struct net_device *dev, const u8 *mac,
16993 struct sta_opmode_info *sta_opmode,
16994 gfp_t gfp)
16995{
16996 struct sk_buff *msg;
16997 struct wireless_dev *wdev = dev->ieee80211_ptr;
16998 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
16999 void *hdr;
17000
17001 if (WARN_ON(!mac))
17002 return;
17003
17004 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
17005 if (!msg)
17006 return;
17007
17008 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STA_OPMODE_CHANGED);
17009 if (!hdr) {
17010 nlmsg_free(msg);
17011 return;
17012 }
17013
17014 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx))
17015 goto nla_put_failure;
17016
17017 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex))
17018 goto nla_put_failure;
17019
17020 if (nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac))
17021 goto nla_put_failure;
17022
17023 if ((sta_opmode->changed & STA_OPMODE_SMPS_MODE_CHANGED) &&
17024 nla_put_u8(msg, NL80211_ATTR_SMPS_MODE, sta_opmode->smps_mode))
17025 goto nla_put_failure;
17026
17027 if ((sta_opmode->changed & STA_OPMODE_MAX_BW_CHANGED) &&
0016d320 17028 nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, sta_opmode->bw))
466b9936 17029 goto nla_put_failure;
17030
17031 if ((sta_opmode->changed & STA_OPMODE_N_SS_CHANGED) &&
17032 nla_put_u8(msg, NL80211_ATTR_NSS, sta_opmode->rx_nss))
17033 goto nla_put_failure;
17034
17035 genlmsg_end(msg, hdr);
17036
17037 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17038 NL80211_MCGRP_MLME, gfp);
17039
17040 return;
17041
17042nla_put_failure:
17043 nlmsg_free(msg);
17044}
17045EXPORT_SYMBOL(cfg80211_sta_opmode_change_notify);
17046
7f6cf311 17047void cfg80211_probe_status(struct net_device *dev, const u8 *addr,
c4b50cd3
VN
17048 u64 cookie, bool acked, s32 ack_signal,
17049 bool is_valid_ack_signal, gfp_t gfp)
7f6cf311
JB
17050{
17051 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 17052 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
7f6cf311
JB
17053 struct sk_buff *msg;
17054 void *hdr;
7f6cf311 17055
4ee3e063
BL
17056 trace_cfg80211_probe_status(dev, addr, cookie, acked);
17057
58050fce 17058 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4ee3e063 17059
7f6cf311
JB
17060 if (!msg)
17061 return;
17062
17063 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT);
17064 if (!hdr) {
17065 nlmsg_free(msg);
17066 return;
17067 }
17068
9360ffd1
DM
17069 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17070 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
17071 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) ||
2dad624e
ND
17072 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie,
17073 NL80211_ATTR_PAD) ||
c4b50cd3
VN
17074 (acked && nla_put_flag(msg, NL80211_ATTR_ACK)) ||
17075 (is_valid_ack_signal && nla_put_s32(msg, NL80211_ATTR_ACK_SIGNAL,
17076 ack_signal)))
9360ffd1 17077 goto nla_put_failure;
7f6cf311 17078
9c90a9f6 17079 genlmsg_end(msg, hdr);
7f6cf311 17080
68eb5503 17081 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 17082 NL80211_MCGRP_MLME, gfp);
7f6cf311
JB
17083 return;
17084
17085 nla_put_failure:
7f6cf311
JB
17086 nlmsg_free(msg);
17087}
17088EXPORT_SYMBOL(cfg80211_probe_status);
17089
e76fede8
TP
17090void cfg80211_report_obss_beacon_khz(struct wiphy *wiphy, const u8 *frame,
17091 size_t len, int freq, int sig_dbm)
5e760230 17092{
f26cbf40 17093 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
5e760230
JB
17094 struct sk_buff *msg;
17095 void *hdr;
37c73b5f 17096 struct cfg80211_beacon_registration *reg;
5e760230 17097
4ee3e063
BL
17098 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm);
17099
37c73b5f
BG
17100 spin_lock_bh(&rdev->beacon_registrations_lock);
17101 list_for_each_entry(reg, &rdev->beacon_registrations, list) {
17102 msg = nlmsg_new(len + 100, GFP_ATOMIC);
17103 if (!msg) {
17104 spin_unlock_bh(&rdev->beacon_registrations_lock);
17105 return;
17106 }
5e760230 17107
37c73b5f
BG
17108 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
17109 if (!hdr)
17110 goto nla_put_failure;
5e760230 17111
37c73b5f
BG
17112 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17113 (freq &&
942ba88b
TP
17114 (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ,
17115 KHZ_TO_MHZ(freq)) ||
17116 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ_OFFSET,
17117 freq % 1000))) ||
37c73b5f
BG
17118 (sig_dbm &&
17119 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) ||
17120 nla_put(msg, NL80211_ATTR_FRAME, len, frame))
17121 goto nla_put_failure;
5e760230 17122
37c73b5f 17123 genlmsg_end(msg, hdr);
5e760230 17124
37c73b5f
BG
17125 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid);
17126 }
17127 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
17128 return;
17129
17130 nla_put_failure:
37c73b5f 17131 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230
JB
17132 nlmsg_free(msg);
17133}
e76fede8 17134EXPORT_SYMBOL(cfg80211_report_obss_beacon_khz);
5e760230 17135
cd8f7cb4 17136#ifdef CONFIG_PM
8cd4d456
LC
17137static int cfg80211_net_detect_results(struct sk_buff *msg,
17138 struct cfg80211_wowlan_wakeup *wakeup)
17139{
17140 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect;
17141 struct nlattr *nl_results, *nl_match, *nl_freqs;
17142 int i, j;
17143
ae0be8de
MK
17144 nl_results = nla_nest_start_noflag(msg,
17145 NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS);
8cd4d456
LC
17146 if (!nl_results)
17147 return -EMSGSIZE;
17148
17149 for (i = 0; i < nd->n_matches; i++) {
17150 struct cfg80211_wowlan_nd_match *match = nd->matches[i];
17151
ae0be8de 17152 nl_match = nla_nest_start_noflag(msg, i);
8cd4d456
LC
17153 if (!nl_match)
17154 break;
17155
17156 /* The SSID attribute is optional in nl80211, but for
17157 * simplicity reasons it's always present in the
17158 * cfg80211 structure. If a driver can't pass the
17159 * SSID, that needs to be changed. A zero length SSID
17160 * is still a valid SSID (wildcard), so it cannot be
17161 * used for this purpose.
17162 */
17163 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len,
17164 match->ssid.ssid)) {
17165 nla_nest_cancel(msg, nl_match);
17166 goto out;
17167 }
17168
17169 if (match->n_channels) {
ae0be8de
MK
17170 nl_freqs = nla_nest_start_noflag(msg,
17171 NL80211_ATTR_SCAN_FREQUENCIES);
8cd4d456
LC
17172 if (!nl_freqs) {
17173 nla_nest_cancel(msg, nl_match);
17174 goto out;
17175 }
17176
17177 for (j = 0; j < match->n_channels; j++) {
5528fae8 17178 if (nla_put_u32(msg, j, match->channels[j])) {
8cd4d456
LC
17179 nla_nest_cancel(msg, nl_freqs);
17180 nla_nest_cancel(msg, nl_match);
17181 goto out;
17182 }
17183 }
17184
17185 nla_nest_end(msg, nl_freqs);
17186 }
17187
17188 nla_nest_end(msg, nl_match);
17189 }
17190
17191out:
17192 nla_nest_end(msg, nl_results);
17193 return 0;
17194}
17195
cd8f7cb4
JB
17196void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev,
17197 struct cfg80211_wowlan_wakeup *wakeup,
17198 gfp_t gfp)
17199{
f26cbf40 17200 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
cd8f7cb4
JB
17201 struct sk_buff *msg;
17202 void *hdr;
9c90a9f6 17203 int size = 200;
cd8f7cb4
JB
17204
17205 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup);
17206
17207 if (wakeup)
17208 size += wakeup->packet_present_len;
17209
17210 msg = nlmsg_new(size, gfp);
17211 if (!msg)
17212 return;
17213
17214 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN);
17215 if (!hdr)
17216 goto free_msg;
17217
17218 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
17219 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
17220 NL80211_ATTR_PAD))
cd8f7cb4
JB
17221 goto free_msg;
17222
17223 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX,
17224 wdev->netdev->ifindex))
17225 goto free_msg;
17226
17227 if (wakeup) {
17228 struct nlattr *reasons;
17229
ae0be8de
MK
17230 reasons = nla_nest_start_noflag(msg,
17231 NL80211_ATTR_WOWLAN_TRIGGERS);
7fa322c8
JB
17232 if (!reasons)
17233 goto free_msg;
cd8f7cb4
JB
17234
17235 if (wakeup->disconnect &&
17236 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT))
17237 goto free_msg;
17238 if (wakeup->magic_pkt &&
17239 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT))
17240 goto free_msg;
17241 if (wakeup->gtk_rekey_failure &&
17242 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE))
17243 goto free_msg;
17244 if (wakeup->eap_identity_req &&
17245 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST))
17246 goto free_msg;
17247 if (wakeup->four_way_handshake &&
17248 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE))
17249 goto free_msg;
17250 if (wakeup->rfkill_release &&
17251 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))
17252 goto free_msg;
17253
17254 if (wakeup->pattern_idx >= 0 &&
17255 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN,
17256 wakeup->pattern_idx))
17257 goto free_msg;
17258
ae917c9f
JB
17259 if (wakeup->tcp_match &&
17260 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH))
17261 goto free_msg;
2a0e047e 17262
ae917c9f
JB
17263 if (wakeup->tcp_connlost &&
17264 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST))
17265 goto free_msg;
2a0e047e 17266
ae917c9f
JB
17267 if (wakeup->tcp_nomoretokens &&
17268 nla_put_flag(msg,
17269 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS))
17270 goto free_msg;
2a0e047e 17271
cd8f7cb4
JB
17272 if (wakeup->packet) {
17273 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211;
17274 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN;
17275
17276 if (!wakeup->packet_80211) {
17277 pkt_attr =
17278 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023;
17279 len_attr =
17280 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN;
17281 }
17282
17283 if (wakeup->packet_len &&
17284 nla_put_u32(msg, len_attr, wakeup->packet_len))
17285 goto free_msg;
17286
17287 if (nla_put(msg, pkt_attr, wakeup->packet_present_len,
17288 wakeup->packet))
17289 goto free_msg;
17290 }
17291
8cd4d456
LC
17292 if (wakeup->net_detect &&
17293 cfg80211_net_detect_results(msg, wakeup))
17294 goto free_msg;
17295
cd8f7cb4
JB
17296 nla_nest_end(msg, reasons);
17297 }
17298
9c90a9f6 17299 genlmsg_end(msg, hdr);
cd8f7cb4 17300
68eb5503 17301 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 17302 NL80211_MCGRP_MLME, gfp);
cd8f7cb4
JB
17303 return;
17304
17305 free_msg:
17306 nlmsg_free(msg);
17307}
17308EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup);
17309#endif
17310
3475b094
JM
17311void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer,
17312 enum nl80211_tdls_operation oper,
17313 u16 reason_code, gfp_t gfp)
17314{
17315 struct wireless_dev *wdev = dev->ieee80211_ptr;
f26cbf40 17316 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
3475b094
JM
17317 struct sk_buff *msg;
17318 void *hdr;
3475b094
JM
17319
17320 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper,
17321 reason_code);
17322
17323 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
17324 if (!msg)
17325 return;
17326
17327 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER);
17328 if (!hdr) {
17329 nlmsg_free(msg);
17330 return;
17331 }
17332
17333 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17334 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
17335 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) ||
17336 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) ||
17337 (reason_code > 0 &&
17338 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code)))
17339 goto nla_put_failure;
17340
9c90a9f6 17341 genlmsg_end(msg, hdr);
3475b094 17342
68eb5503 17343 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 17344 NL80211_MCGRP_MLME, gfp);
3475b094
JM
17345 return;
17346
17347 nla_put_failure:
3475b094
JM
17348 nlmsg_free(msg);
17349}
17350EXPORT_SYMBOL(cfg80211_tdls_oper_request);
17351
026331c4
JM
17352static int nl80211_netlink_notify(struct notifier_block * nb,
17353 unsigned long state,
17354 void *_notify)
17355{
17356 struct netlink_notify *notify = _notify;
17357 struct cfg80211_registered_device *rdev;
17358 struct wireless_dev *wdev;
37c73b5f 17359 struct cfg80211_beacon_registration *reg, *tmp;
026331c4 17360
8f815cdd 17361 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC)
026331c4
JM
17362 return NOTIFY_DONE;
17363
17364 rcu_read_lock();
17365
5e760230 17366 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) {
ca986ad9 17367 struct cfg80211_sched_scan_request *sched_scan_req;
753aacfd 17368
ca986ad9
AVS
17369 list_for_each_entry_rcu(sched_scan_req,
17370 &rdev->sched_scan_req_list,
17371 list) {
17372 if (sched_scan_req->owner_nlportid == notify->portid) {
17373 sched_scan_req->nl_owner_dead = true;
753aacfd 17374 schedule_work(&rdev->sched_scan_stop_wk);
ca986ad9 17375 }
753aacfd 17376 }
78f22b6a 17377
53873f13 17378 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) {
15e47304 17379 cfg80211_mlme_unregister_socket(wdev, notify->portid);
37c73b5f 17380
ab81007a
JB
17381 if (wdev->owner_nlportid == notify->portid) {
17382 wdev->nl_owner_dead = true;
17383 schedule_work(&rdev->destroy_work);
17384 } else if (wdev->conn_owner_nlportid == notify->portid) {
bd2522b1 17385 schedule_work(&wdev->disconnect_wk);
ab81007a 17386 }
9bb7e0f2
JB
17387
17388 cfg80211_release_pmsr(wdev, notify->portid);
78f22b6a
JB
17389 }
17390
37c73b5f
BG
17391 spin_lock_bh(&rdev->beacon_registrations_lock);
17392 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations,
17393 list) {
17394 if (reg->nlportid == notify->portid) {
17395 list_del(&reg->list);
17396 kfree(reg);
17397 break;
17398 }
17399 }
17400 spin_unlock_bh(&rdev->beacon_registrations_lock);
5e760230 17401 }
026331c4
JM
17402
17403 rcu_read_unlock();
17404
05050753
I
17405 /*
17406 * It is possible that the user space process that is controlling the
17407 * indoor setting disappeared, so notify the regulatory core.
17408 */
17409 regulatory_netlink_notify(notify->portid);
6784c7db 17410 return NOTIFY_OK;
026331c4
JM
17411}
17412
17413static struct notifier_block nl80211_netlink_notifier = {
17414 .notifier_call = nl80211_netlink_notify,
17415};
17416
355199e0
JM
17417void cfg80211_ft_event(struct net_device *netdev,
17418 struct cfg80211_ft_event_params *ft_event)
17419{
17420 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
f26cbf40 17421 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
355199e0
JM
17422 struct sk_buff *msg;
17423 void *hdr;
355199e0
JM
17424
17425 trace_cfg80211_ft_event(wiphy, netdev, ft_event);
17426
17427 if (!ft_event->target_ap)
17428 return;
17429
1039d081
DL
17430 msg = nlmsg_new(100 + ft_event->ies_len + ft_event->ric_ies_len,
17431 GFP_KERNEL);
355199e0
JM
17432 if (!msg)
17433 return;
17434
17435 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT);
ae917c9f
JB
17436 if (!hdr)
17437 goto out;
355199e0 17438
ae917c9f
JB
17439 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17440 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
17441 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap))
17442 goto out;
355199e0 17443
ae917c9f
JB
17444 if (ft_event->ies &&
17445 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies))
17446 goto out;
17447 if (ft_event->ric_ies &&
17448 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len,
17449 ft_event->ric_ies))
17450 goto out;
355199e0 17451
9c90a9f6 17452 genlmsg_end(msg, hdr);
355199e0 17453
68eb5503 17454 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
2a94fe48 17455 NL80211_MCGRP_MLME, GFP_KERNEL);
ae917c9f
JB
17456 return;
17457 out:
17458 nlmsg_free(msg);
355199e0
JM
17459}
17460EXPORT_SYMBOL(cfg80211_ft_event);
17461
5de17984
AS
17462void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp)
17463{
17464 struct cfg80211_registered_device *rdev;
17465 struct sk_buff *msg;
17466 void *hdr;
17467 u32 nlportid;
17468
f26cbf40 17469 rdev = wiphy_to_rdev(wdev->wiphy);
5de17984
AS
17470 if (!rdev->crit_proto_nlportid)
17471 return;
17472
17473 nlportid = rdev->crit_proto_nlportid;
17474 rdev->crit_proto_nlportid = 0;
17475
17476 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
17477 if (!msg)
17478 return;
17479
17480 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP);
17481 if (!hdr)
17482 goto nla_put_failure;
17483
17484 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
2dad624e
ND
17485 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
17486 NL80211_ATTR_PAD))
5de17984
AS
17487 goto nla_put_failure;
17488
17489 genlmsg_end(msg, hdr);
17490
17491 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid);
17492 return;
17493
17494 nla_put_failure:
5de17984 17495 nlmsg_free(msg);
5de17984
AS
17496}
17497EXPORT_SYMBOL(cfg80211_crit_proto_stopped);
17498
348baf0e
JB
17499void nl80211_send_ap_stopped(struct wireless_dev *wdev)
17500{
17501 struct wiphy *wiphy = wdev->wiphy;
f26cbf40 17502 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
348baf0e
JB
17503 struct sk_buff *msg;
17504 void *hdr;
17505
17506 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
17507 if (!msg)
17508 return;
17509
17510 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP);
17511 if (!hdr)
17512 goto out;
17513
17514 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17515 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) ||
2dad624e
ND
17516 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev),
17517 NL80211_ATTR_PAD))
348baf0e
JB
17518 goto out;
17519
17520 genlmsg_end(msg, hdr);
17521
17522 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0,
17523 NL80211_MCGRP_MLME, GFP_KERNEL);
17524 return;
17525 out:
17526 nlmsg_free(msg);
17527}
17528
40cbfa90
SD
17529int cfg80211_external_auth_request(struct net_device *dev,
17530 struct cfg80211_external_auth_params *params,
17531 gfp_t gfp)
17532{
17533 struct wireless_dev *wdev = dev->ieee80211_ptr;
17534 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy);
17535 struct sk_buff *msg;
17536 void *hdr;
17537
17538 if (!wdev->conn_owner_nlportid)
17539 return -EINVAL;
17540
17541 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
17542 if (!msg)
17543 return -ENOMEM;
17544
17545 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_EXTERNAL_AUTH);
17546 if (!hdr)
17547 goto nla_put_failure;
17548
17549 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17550 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) ||
17551 nla_put_u32(msg, NL80211_ATTR_AKM_SUITES, params->key_mgmt_suite) ||
17552 nla_put_u32(msg, NL80211_ATTR_EXTERNAL_AUTH_ACTION,
17553 params->action) ||
17554 nla_put(msg, NL80211_ATTR_BSSID, ETH_ALEN, params->bssid) ||
17555 nla_put(msg, NL80211_ATTR_SSID, params->ssid.ssid_len,
17556 params->ssid.ssid))
17557 goto nla_put_failure;
17558
17559 genlmsg_end(msg, hdr);
17560 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg,
17561 wdev->conn_owner_nlportid);
17562 return 0;
17563
17564 nla_put_failure:
17565 nlmsg_free(msg);
17566 return -ENOBUFS;
17567}
17568EXPORT_SYMBOL(cfg80211_external_auth_request);
17569
cb74e977
SD
17570void cfg80211_update_owe_info_event(struct net_device *netdev,
17571 struct cfg80211_update_owe_info *owe_info,
17572 gfp_t gfp)
17573{
17574 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy;
17575 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy);
17576 struct sk_buff *msg;
17577 void *hdr;
17578
17579 trace_cfg80211_update_owe_info_event(wiphy, netdev, owe_info);
17580
17581 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
17582 if (!msg)
17583 return;
17584
17585 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_UPDATE_OWE_INFO);
17586 if (!hdr)
17587 goto nla_put_failure;
17588
17589 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) ||
17590 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) ||
17591 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, owe_info->peer))
17592 goto nla_put_failure;
17593
17594 if (!owe_info->ie_len ||
17595 nla_put(msg, NL80211_ATTR_IE, owe_info->ie_len, owe_info->ie))
17596 goto nla_put_failure;
17597
17598 genlmsg_end(msg, hdr);
17599
17600 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0,
17601 NL80211_MCGRP_MLME, gfp);
17602 return;
17603
17604nla_put_failure:
17605 genlmsg_cancel(msg, hdr);
17606 nlmsg_free(msg);
17607}
17608EXPORT_SYMBOL(cfg80211_update_owe_info_event);
17609
55682965
JB
17610/* initialisation/exit functions */
17611
56989f6d 17612int __init nl80211_init(void)
55682965 17613{
0d63cbb5 17614 int err;
55682965 17615
489111e5 17616 err = genl_register_family(&nl80211_fam);
55682965
JB
17617 if (err)
17618 return err;
17619
026331c4
JM
17620 err = netlink_register_notifier(&nl80211_netlink_notifier);
17621 if (err)
17622 goto err_out;
17623
55682965
JB
17624 return 0;
17625 err_out:
17626 genl_unregister_family(&nl80211_fam);
17627 return err;
17628}
17629
17630void nl80211_exit(void)
17631{
026331c4 17632 netlink_unregister_notifier(&nl80211_netlink_notifier);
55682965
JB
17633 genl_unregister_family(&nl80211_fam);
17634}