mac80211: Rename mesh_params to mesh_config to prepare for mesh_setup
[linux-2.6-block.git] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006-2010  Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/slab.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/net_namespace.h>
19 #include <net/genetlink.h>
20 #include <net/cfg80211.h>
21 #include <net/sock.h>
22 #include "core.h"
23 #include "nl80211.h"
24 #include "reg.h"
25
26 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27                             struct genl_info *info);
28 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29                               struct genl_info *info);
30
31 /* the netlink family */
32 static struct genl_family nl80211_fam = {
33         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34         .name = "nl80211",      /* have users key off the name instead */
35         .hdrsize = 0,           /* no private header */
36         .version = 1,           /* no particular meaning now */
37         .maxattr = NL80211_ATTR_MAX,
38         .netnsok = true,
39         .pre_doit = nl80211_pre_doit,
40         .post_doit = nl80211_post_doit,
41 };
42
43 /* internal helper: get rdev and dev */
44 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
45                                        struct cfg80211_registered_device **rdev,
46                                        struct net_device **dev)
47 {
48         struct nlattr **attrs = info->attrs;
49         int ifindex;
50
51         if (!attrs[NL80211_ATTR_IFINDEX])
52                 return -EINVAL;
53
54         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
55         *dev = dev_get_by_index(genl_info_net(info), ifindex);
56         if (!*dev)
57                 return -ENODEV;
58
59         *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
60         if (IS_ERR(*rdev)) {
61                 dev_put(*dev);
62                 return PTR_ERR(*rdev);
63         }
64
65         return 0;
66 }
67
68 /* policy for the attributes */
69 static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
70         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
72                                       .len = 20-1 },
73         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
74         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
75         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
76         [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77         [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78         [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79         [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
80         [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
81
82         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
85
86         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
87         [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
88
89         [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
90         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91                                     .len = WLAN_MAX_KEY_LEN },
92         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
95         [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
96         [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
97
98         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101                                        .len = IEEE80211_MAX_DATA_LEN },
102         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103                                        .len = IEEE80211_MAX_DATA_LEN },
104         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108                                                .len = NL80211_MAX_SUPP_RATES },
109         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
110         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
111         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
112         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113                                 .len = IEEE80211_MAX_MESH_ID_LEN },
114         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
115
116         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
119         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
122         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123                                            .len = NL80211_MAX_SUPP_RATES },
124         [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 },
125
126         [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED },
127
128         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
129                                          .len = NL80211_HT_CAPABILITY_LEN },
130
131         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
132         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
133                               .len = IEEE80211_MAX_DATA_LEN },
134         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
135         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
136
137         [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
138                                 .len = IEEE80211_MAX_SSID_LEN },
139         [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
140         [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
141         [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
142         [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
143         [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
144         [NL80211_ATTR_STA_FLAGS2] = {
145                 .len = sizeof(struct nl80211_sta_flag_update),
146         },
147         [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
148         [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
149         [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
150         [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
151         [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
152         [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
153         [NL80211_ATTR_PID] = { .type = NLA_U32 },
154         [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
155         [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
156                                  .len = WLAN_PMKID_LEN },
157         [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
158         [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
159         [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
160         [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
161                                  .len = IEEE80211_MAX_DATA_LEN },
162         [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
163         [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
164         [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
165         [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
166         [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
167         [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
168         [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
169         [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
170         [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
171         [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
172         [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
173         [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
174         [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
175 };
176
177 /* policy for the key attributes */
178 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
179         [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
180         [NL80211_KEY_IDX] = { .type = NLA_U8 },
181         [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
182         [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
183         [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
184         [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
185         [NL80211_KEY_TYPE] = { .type = NLA_U32 },
186         [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED },
187 };
188
189 /* policy for the key default flags */
190 static const struct nla_policy
191 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = {
192         [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG },
193         [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG },
194 };
195
196 /* ifidx get helper */
197 static int nl80211_get_ifidx(struct netlink_callback *cb)
198 {
199         int res;
200
201         res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
202                           nl80211_fam.attrbuf, nl80211_fam.maxattr,
203                           nl80211_policy);
204         if (res)
205                 return res;
206
207         if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
208                 return -EINVAL;
209
210         res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
211         if (!res)
212                 return -EINVAL;
213         return res;
214 }
215
216 static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
217                                        struct netlink_callback *cb,
218                                        struct cfg80211_registered_device **rdev,
219                                        struct net_device **dev)
220 {
221         int ifidx = cb->args[0];
222         int err;
223
224         if (!ifidx)
225                 ifidx = nl80211_get_ifidx(cb);
226         if (ifidx < 0)
227                 return ifidx;
228
229         cb->args[0] = ifidx;
230
231         rtnl_lock();
232
233         *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
234         if (!*dev) {
235                 err = -ENODEV;
236                 goto out_rtnl;
237         }
238
239         *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
240         if (IS_ERR(*rdev)) {
241                 err = PTR_ERR(*rdev);
242                 goto out_rtnl;
243         }
244
245         return 0;
246  out_rtnl:
247         rtnl_unlock();
248         return err;
249 }
250
251 static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
252 {
253         cfg80211_unlock_rdev(rdev);
254         rtnl_unlock();
255 }
256
257 /* IE validation */
258 static bool is_valid_ie_attr(const struct nlattr *attr)
259 {
260         const u8 *pos;
261         int len;
262
263         if (!attr)
264                 return true;
265
266         pos = nla_data(attr);
267         len = nla_len(attr);
268
269         while (len) {
270                 u8 elemlen;
271
272                 if (len < 2)
273                         return false;
274                 len -= 2;
275
276                 elemlen = pos[1];
277                 if (elemlen > len)
278                         return false;
279
280                 len -= elemlen;
281                 pos += 2 + elemlen;
282         }
283
284         return true;
285 }
286
287 /* message building helper */
288 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
289                                    int flags, u8 cmd)
290 {
291         /* since there is no private header just add the generic one */
292         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
293 }
294
295 static int nl80211_msg_put_channel(struct sk_buff *msg,
296                                    struct ieee80211_channel *chan)
297 {
298         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
299                     chan->center_freq);
300
301         if (chan->flags & IEEE80211_CHAN_DISABLED)
302                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
303         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
304                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
305         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
306                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
307         if (chan->flags & IEEE80211_CHAN_RADAR)
308                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
309
310         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
311                     DBM_TO_MBM(chan->max_power));
312
313         return 0;
314
315  nla_put_failure:
316         return -ENOBUFS;
317 }
318
319 /* netlink command implementations */
320
321 struct key_parse {
322         struct key_params p;
323         int idx;
324         int type;
325         bool def, defmgmt;
326         bool def_uni, def_multi;
327 };
328
329 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
330 {
331         struct nlattr *tb[NL80211_KEY_MAX + 1];
332         int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
333                                    nl80211_key_policy);
334         if (err)
335                 return err;
336
337         k->def = !!tb[NL80211_KEY_DEFAULT];
338         k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
339
340         if (k->def) {
341                 k->def_uni = true;
342                 k->def_multi = true;
343         }
344         if (k->defmgmt)
345                 k->def_multi = true;
346
347         if (tb[NL80211_KEY_IDX])
348                 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
349
350         if (tb[NL80211_KEY_DATA]) {
351                 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
352                 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
353         }
354
355         if (tb[NL80211_KEY_SEQ]) {
356                 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
357                 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
358         }
359
360         if (tb[NL80211_KEY_CIPHER])
361                 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
362
363         if (tb[NL80211_KEY_TYPE]) {
364                 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
365                 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
366                         return -EINVAL;
367         }
368
369         if (tb[NL80211_KEY_DEFAULT_TYPES]) {
370                 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
371                 int err = nla_parse_nested(kdt,
372                                            NUM_NL80211_KEY_DEFAULT_TYPES - 1,
373                                            tb[NL80211_KEY_DEFAULT_TYPES],
374                                            nl80211_key_default_policy);
375                 if (err)
376                         return err;
377
378                 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
379                 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
380         }
381
382         return 0;
383 }
384
385 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
386 {
387         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
388                 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
389                 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
390         }
391
392         if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
393                 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
394                 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
395         }
396
397         if (info->attrs[NL80211_ATTR_KEY_IDX])
398                 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
399
400         if (info->attrs[NL80211_ATTR_KEY_CIPHER])
401                 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
402
403         k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
404         k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
405
406         if (k->def) {
407                 k->def_uni = true;
408                 k->def_multi = true;
409         }
410         if (k->defmgmt)
411                 k->def_multi = true;
412
413         if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
414                 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
415                 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
416                         return -EINVAL;
417         }
418
419         if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) {
420                 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES];
421                 int err = nla_parse_nested(
422                                 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1,
423                                 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES],
424                                 nl80211_key_default_policy);
425                 if (err)
426                         return err;
427
428                 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST];
429                 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST];
430         }
431
432         return 0;
433 }
434
435 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
436 {
437         int err;
438
439         memset(k, 0, sizeof(*k));
440         k->idx = -1;
441         k->type = -1;
442
443         if (info->attrs[NL80211_ATTR_KEY])
444                 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
445         else
446                 err = nl80211_parse_key_old(info, k);
447
448         if (err)
449                 return err;
450
451         if (k->def && k->defmgmt)
452                 return -EINVAL;
453
454         if (k->defmgmt) {
455                 if (k->def_uni || !k->def_multi)
456                         return -EINVAL;
457         }
458
459         if (k->idx != -1) {
460                 if (k->defmgmt) {
461                         if (k->idx < 4 || k->idx > 5)
462                                 return -EINVAL;
463                 } else if (k->def) {
464                         if (k->idx < 0 || k->idx > 3)
465                                 return -EINVAL;
466                 } else {
467                         if (k->idx < 0 || k->idx > 5)
468                                 return -EINVAL;
469                 }
470         }
471
472         return 0;
473 }
474
475 static struct cfg80211_cached_keys *
476 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
477                        struct nlattr *keys)
478 {
479         struct key_parse parse;
480         struct nlattr *key;
481         struct cfg80211_cached_keys *result;
482         int rem, err, def = 0;
483
484         result = kzalloc(sizeof(*result), GFP_KERNEL);
485         if (!result)
486                 return ERR_PTR(-ENOMEM);
487
488         result->def = -1;
489         result->defmgmt = -1;
490
491         nla_for_each_nested(key, keys, rem) {
492                 memset(&parse, 0, sizeof(parse));
493                 parse.idx = -1;
494
495                 err = nl80211_parse_key_new(key, &parse);
496                 if (err)
497                         goto error;
498                 err = -EINVAL;
499                 if (!parse.p.key)
500                         goto error;
501                 if (parse.idx < 0 || parse.idx > 4)
502                         goto error;
503                 if (parse.def) {
504                         if (def)
505                                 goto error;
506                         def = 1;
507                         result->def = parse.idx;
508                         if (!parse.def_uni || !parse.def_multi)
509                                 goto error;
510                 } else if (parse.defmgmt)
511                         goto error;
512                 err = cfg80211_validate_key_settings(rdev, &parse.p,
513                                                      parse.idx, false, NULL);
514                 if (err)
515                         goto error;
516                 result->params[parse.idx].cipher = parse.p.cipher;
517                 result->params[parse.idx].key_len = parse.p.key_len;
518                 result->params[parse.idx].key = result->data[parse.idx];
519                 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
520         }
521
522         return result;
523  error:
524         kfree(result);
525         return ERR_PTR(err);
526 }
527
528 static int nl80211_key_allowed(struct wireless_dev *wdev)
529 {
530         ASSERT_WDEV_LOCK(wdev);
531
532         switch (wdev->iftype) {
533         case NL80211_IFTYPE_AP:
534         case NL80211_IFTYPE_AP_VLAN:
535         case NL80211_IFTYPE_P2P_GO:
536                 break;
537         case NL80211_IFTYPE_ADHOC:
538                 if (!wdev->current_bss)
539                         return -ENOLINK;
540                 break;
541         case NL80211_IFTYPE_STATION:
542         case NL80211_IFTYPE_P2P_CLIENT:
543                 if (wdev->sme_state != CFG80211_SME_CONNECTED)
544                         return -ENOLINK;
545                 break;
546         default:
547                 return -EINVAL;
548         }
549
550         return 0;
551 }
552
553 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
554                               struct cfg80211_registered_device *dev)
555 {
556         void *hdr;
557         struct nlattr *nl_bands, *nl_band;
558         struct nlattr *nl_freqs, *nl_freq;
559         struct nlattr *nl_rates, *nl_rate;
560         struct nlattr *nl_modes;
561         struct nlattr *nl_cmds;
562         enum ieee80211_band band;
563         struct ieee80211_channel *chan;
564         struct ieee80211_rate *rate;
565         int i;
566         u16 ifmodes = dev->wiphy.interface_modes;
567         const struct ieee80211_txrx_stypes *mgmt_stypes =
568                                 dev->wiphy.mgmt_stypes;
569
570         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
571         if (!hdr)
572                 return -1;
573
574         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
575         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
576
577         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
578                     cfg80211_rdev_list_generation);
579
580         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
581                    dev->wiphy.retry_short);
582         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
583                    dev->wiphy.retry_long);
584         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
585                     dev->wiphy.frag_threshold);
586         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
587                     dev->wiphy.rts_threshold);
588         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
589                     dev->wiphy.coverage_class);
590         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
591                    dev->wiphy.max_scan_ssids);
592         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
593                     dev->wiphy.max_scan_ie_len);
594
595         if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
596                 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
597
598         NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
599                 sizeof(u32) * dev->wiphy.n_cipher_suites,
600                 dev->wiphy.cipher_suites);
601
602         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
603                    dev->wiphy.max_num_pmkids);
604
605         if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
606                 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
607
608         if (dev->wiphy.available_antennas && dev->ops->get_antenna) {
609                 u32 tx_ant = 0, rx_ant = 0;
610                 int res;
611                 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
612                 if (!res) {
613                         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
614                         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
615                 }
616         }
617
618         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
619         if (!nl_modes)
620                 goto nla_put_failure;
621
622         i = 0;
623         while (ifmodes) {
624                 if (ifmodes & 1)
625                         NLA_PUT_FLAG(msg, i);
626                 ifmodes >>= 1;
627                 i++;
628         }
629
630         nla_nest_end(msg, nl_modes);
631
632         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
633         if (!nl_bands)
634                 goto nla_put_failure;
635
636         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
637                 if (!dev->wiphy.bands[band])
638                         continue;
639
640                 nl_band = nla_nest_start(msg, band);
641                 if (!nl_band)
642                         goto nla_put_failure;
643
644                 /* add HT info */
645                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
646                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
647                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
648                                 &dev->wiphy.bands[band]->ht_cap.mcs);
649                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
650                                 dev->wiphy.bands[band]->ht_cap.cap);
651                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
652                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
653                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
654                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
655                 }
656
657                 /* add frequencies */
658                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
659                 if (!nl_freqs)
660                         goto nla_put_failure;
661
662                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
663                         nl_freq = nla_nest_start(msg, i);
664                         if (!nl_freq)
665                                 goto nla_put_failure;
666
667                         chan = &dev->wiphy.bands[band]->channels[i];
668
669                         if (nl80211_msg_put_channel(msg, chan))
670                                 goto nla_put_failure;
671
672                         nla_nest_end(msg, nl_freq);
673                 }
674
675                 nla_nest_end(msg, nl_freqs);
676
677                 /* add bitrates */
678                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
679                 if (!nl_rates)
680                         goto nla_put_failure;
681
682                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
683                         nl_rate = nla_nest_start(msg, i);
684                         if (!nl_rate)
685                                 goto nla_put_failure;
686
687                         rate = &dev->wiphy.bands[band]->bitrates[i];
688                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
689                                     rate->bitrate);
690                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
691                                 NLA_PUT_FLAG(msg,
692                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
693
694                         nla_nest_end(msg, nl_rate);
695                 }
696
697                 nla_nest_end(msg, nl_rates);
698
699                 nla_nest_end(msg, nl_band);
700         }
701         nla_nest_end(msg, nl_bands);
702
703         nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
704         if (!nl_cmds)
705                 goto nla_put_failure;
706
707         i = 0;
708 #define CMD(op, n)                                              \
709          do {                                                   \
710                 if (dev->ops->op) {                             \
711                         i++;                                    \
712                         NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
713                 }                                               \
714         } while (0)
715
716         CMD(add_virtual_intf, NEW_INTERFACE);
717         CMD(change_virtual_intf, SET_INTERFACE);
718         CMD(add_key, NEW_KEY);
719         CMD(add_beacon, NEW_BEACON);
720         CMD(add_station, NEW_STATION);
721         CMD(add_mpath, NEW_MPATH);
722         CMD(update_mesh_config, SET_MESH_CONFIG);
723         CMD(change_bss, SET_BSS);
724         CMD(auth, AUTHENTICATE);
725         CMD(assoc, ASSOCIATE);
726         CMD(deauth, DEAUTHENTICATE);
727         CMD(disassoc, DISASSOCIATE);
728         CMD(join_ibss, JOIN_IBSS);
729         CMD(join_mesh, JOIN_MESH);
730         CMD(set_pmksa, SET_PMKSA);
731         CMD(del_pmksa, DEL_PMKSA);
732         CMD(flush_pmksa, FLUSH_PMKSA);
733         CMD(remain_on_channel, REMAIN_ON_CHANNEL);
734         CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
735         CMD(mgmt_tx, FRAME);
736         CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
737         if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
738                 i++;
739                 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
740         }
741         CMD(set_channel, SET_CHANNEL);
742         CMD(set_wds_peer, SET_WDS_PEER);
743
744 #undef CMD
745
746         if (dev->ops->connect || dev->ops->auth) {
747                 i++;
748                 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
749         }
750
751         if (dev->ops->disconnect || dev->ops->deauth) {
752                 i++;
753                 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
754         }
755
756         nla_nest_end(msg, nl_cmds);
757
758         if (dev->ops->remain_on_channel)
759                 NLA_PUT_U32(msg, NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION,
760                             dev->wiphy.max_remain_on_channel_duration);
761
762         /* for now at least assume all drivers have it */
763         if (dev->ops->mgmt_tx)
764                 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
765
766         if (mgmt_stypes) {
767                 u16 stypes;
768                 struct nlattr *nl_ftypes, *nl_ifs;
769                 enum nl80211_iftype ift;
770
771                 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
772                 if (!nl_ifs)
773                         goto nla_put_failure;
774
775                 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
776                         nl_ftypes = nla_nest_start(msg, ift);
777                         if (!nl_ftypes)
778                                 goto nla_put_failure;
779                         i = 0;
780                         stypes = mgmt_stypes[ift].tx;
781                         while (stypes) {
782                                 if (stypes & 1)
783                                         NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
784                                                     (i << 4) | IEEE80211_FTYPE_MGMT);
785                                 stypes >>= 1;
786                                 i++;
787                         }
788                         nla_nest_end(msg, nl_ftypes);
789                 }
790
791                 nla_nest_end(msg, nl_ifs);
792
793                 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
794                 if (!nl_ifs)
795                         goto nla_put_failure;
796
797                 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
798                         nl_ftypes = nla_nest_start(msg, ift);
799                         if (!nl_ftypes)
800                                 goto nla_put_failure;
801                         i = 0;
802                         stypes = mgmt_stypes[ift].rx;
803                         while (stypes) {
804                                 if (stypes & 1)
805                                         NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
806                                                     (i << 4) | IEEE80211_FTYPE_MGMT);
807                                 stypes >>= 1;
808                                 i++;
809                         }
810                         nla_nest_end(msg, nl_ftypes);
811                 }
812                 nla_nest_end(msg, nl_ifs);
813         }
814
815         return genlmsg_end(msg, hdr);
816
817  nla_put_failure:
818         genlmsg_cancel(msg, hdr);
819         return -EMSGSIZE;
820 }
821
822 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
823 {
824         int idx = 0;
825         int start = cb->args[0];
826         struct cfg80211_registered_device *dev;
827
828         mutex_lock(&cfg80211_mutex);
829         list_for_each_entry(dev, &cfg80211_rdev_list, list) {
830                 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
831                         continue;
832                 if (++idx <= start)
833                         continue;
834                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
835                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
836                                        dev) < 0) {
837                         idx--;
838                         break;
839                 }
840         }
841         mutex_unlock(&cfg80211_mutex);
842
843         cb->args[0] = idx;
844
845         return skb->len;
846 }
847
848 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
849 {
850         struct sk_buff *msg;
851         struct cfg80211_registered_device *dev = info->user_ptr[0];
852
853         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
854         if (!msg)
855                 return -ENOMEM;
856
857         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
858                 nlmsg_free(msg);
859                 return -ENOBUFS;
860         }
861
862         return genlmsg_reply(msg, info);
863 }
864
865 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
866         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
867         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
868         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
869         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
870         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
871 };
872
873 static int parse_txq_params(struct nlattr *tb[],
874                             struct ieee80211_txq_params *txq_params)
875 {
876         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
877             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
878             !tb[NL80211_TXQ_ATTR_AIFS])
879                 return -EINVAL;
880
881         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
882         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
883         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
884         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
885         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
886
887         return 0;
888 }
889
890 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
891 {
892         /*
893          * You can only set the channel explicitly for AP, mesh
894          * and WDS type interfaces; all others have their channel
895          * managed via their respective "establish a connection"
896          * command (connect, join, ...)
897          *
898          * Monitors are special as they are normally slaved to
899          * whatever else is going on, so they behave as though
900          * you tried setting the wiphy channel itself.
901          */
902         return !wdev ||
903                 wdev->iftype == NL80211_IFTYPE_AP ||
904                 wdev->iftype == NL80211_IFTYPE_WDS ||
905                 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
906                 wdev->iftype == NL80211_IFTYPE_MONITOR ||
907                 wdev->iftype == NL80211_IFTYPE_P2P_GO;
908 }
909
910 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
911                                  struct wireless_dev *wdev,
912                                  struct genl_info *info)
913 {
914         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
915         u32 freq;
916         int result;
917
918         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
919                 return -EINVAL;
920
921         if (!nl80211_can_set_dev_channel(wdev))
922                 return -EOPNOTSUPP;
923
924         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
925                 channel_type = nla_get_u32(info->attrs[
926                                    NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
927                 if (channel_type != NL80211_CHAN_NO_HT &&
928                     channel_type != NL80211_CHAN_HT20 &&
929                     channel_type != NL80211_CHAN_HT40PLUS &&
930                     channel_type != NL80211_CHAN_HT40MINUS)
931                         return -EINVAL;
932         }
933
934         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
935
936         mutex_lock(&rdev->devlist_mtx);
937         if (wdev) {
938                 wdev_lock(wdev);
939                 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
940                 wdev_unlock(wdev);
941         } else {
942                 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
943         }
944         mutex_unlock(&rdev->devlist_mtx);
945
946         return result;
947 }
948
949 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
950 {
951         struct cfg80211_registered_device *rdev = info->user_ptr[0];
952         struct net_device *netdev = info->user_ptr[1];
953
954         return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
955 }
956
957 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
958 {
959         struct cfg80211_registered_device *rdev = info->user_ptr[0];
960         struct net_device *dev = info->user_ptr[1];
961         struct wireless_dev *wdev = dev->ieee80211_ptr;
962         const u8 *bssid;
963
964         if (!info->attrs[NL80211_ATTR_MAC])
965                 return -EINVAL;
966
967         if (netif_running(dev))
968                 return -EBUSY;
969
970         if (!rdev->ops->set_wds_peer)
971                 return -EOPNOTSUPP;
972
973         if (wdev->iftype != NL80211_IFTYPE_WDS)
974                 return -EOPNOTSUPP;
975
976         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
977         return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
978 }
979
980
981 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
982 {
983         struct cfg80211_registered_device *rdev;
984         struct net_device *netdev = NULL;
985         struct wireless_dev *wdev;
986         int result = 0, rem_txq_params = 0;
987         struct nlattr *nl_txq_params;
988         u32 changed;
989         u8 retry_short = 0, retry_long = 0;
990         u32 frag_threshold = 0, rts_threshold = 0;
991         u8 coverage_class = 0;
992
993         /*
994          * Try to find the wiphy and netdev. Normally this
995          * function shouldn't need the netdev, but this is
996          * done for backward compatibility -- previously
997          * setting the channel was done per wiphy, but now
998          * it is per netdev. Previous userland like hostapd
999          * also passed a netdev to set_wiphy, so that it is
1000          * possible to let that go to the right netdev!
1001          */
1002         mutex_lock(&cfg80211_mutex);
1003
1004         if (info->attrs[NL80211_ATTR_IFINDEX]) {
1005                 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
1006
1007                 netdev = dev_get_by_index(genl_info_net(info), ifindex);
1008                 if (netdev && netdev->ieee80211_ptr) {
1009                         rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
1010                         mutex_lock(&rdev->mtx);
1011                 } else
1012                         netdev = NULL;
1013         }
1014
1015         if (!netdev) {
1016                 rdev = __cfg80211_rdev_from_info(info);
1017                 if (IS_ERR(rdev)) {
1018                         mutex_unlock(&cfg80211_mutex);
1019                         return PTR_ERR(rdev);
1020                 }
1021                 wdev = NULL;
1022                 netdev = NULL;
1023                 result = 0;
1024
1025                 mutex_lock(&rdev->mtx);
1026         } else if (netif_running(netdev) &&
1027                    nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
1028                 wdev = netdev->ieee80211_ptr;
1029         else
1030                 wdev = NULL;
1031
1032         /*
1033          * end workaround code, by now the rdev is available
1034          * and locked, and wdev may or may not be NULL.
1035          */
1036
1037         if (info->attrs[NL80211_ATTR_WIPHY_NAME])
1038                 result = cfg80211_dev_rename(
1039                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
1040
1041         mutex_unlock(&cfg80211_mutex);
1042
1043         if (result)
1044                 goto bad_res;
1045
1046         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
1047                 struct ieee80211_txq_params txq_params;
1048                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
1049
1050                 if (!rdev->ops->set_txq_params) {
1051                         result = -EOPNOTSUPP;
1052                         goto bad_res;
1053                 }
1054
1055                 nla_for_each_nested(nl_txq_params,
1056                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
1057                                     rem_txq_params) {
1058                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
1059                                   nla_data(nl_txq_params),
1060                                   nla_len(nl_txq_params),
1061                                   txq_params_policy);
1062                         result = parse_txq_params(tb, &txq_params);
1063                         if (result)
1064                                 goto bad_res;
1065
1066                         result = rdev->ops->set_txq_params(&rdev->wiphy,
1067                                                            &txq_params);
1068                         if (result)
1069                                 goto bad_res;
1070                 }
1071         }
1072
1073         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
1074                 result = __nl80211_set_channel(rdev, wdev, info);
1075                 if (result)
1076                         goto bad_res;
1077         }
1078
1079         if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1080                 enum nl80211_tx_power_setting type;
1081                 int idx, mbm = 0;
1082
1083                 if (!rdev->ops->set_tx_power) {
1084                         result = -EOPNOTSUPP;
1085                         goto bad_res;
1086                 }
1087
1088                 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1089                 type = nla_get_u32(info->attrs[idx]);
1090
1091                 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1092                     (type != NL80211_TX_POWER_AUTOMATIC)) {
1093                         result = -EINVAL;
1094                         goto bad_res;
1095                 }
1096
1097                 if (type != NL80211_TX_POWER_AUTOMATIC) {
1098                         idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1099                         mbm = nla_get_u32(info->attrs[idx]);
1100                 }
1101
1102                 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1103                 if (result)
1104                         goto bad_res;
1105         }
1106
1107         if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1108             info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1109                 u32 tx_ant, rx_ant;
1110                 if (!rdev->wiphy.available_antennas || !rdev->ops->set_antenna) {
1111                         result = -EOPNOTSUPP;
1112                         goto bad_res;
1113                 }
1114
1115                 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1116                 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1117
1118                 /* reject antenna configurations which don't match the
1119                  * available antenna mask, except for the "all" mask */
1120                 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas)) ||
1121                     (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas))) {
1122                         result = -EINVAL;
1123                         goto bad_res;
1124                 }
1125
1126                 tx_ant = tx_ant & rdev->wiphy.available_antennas;
1127                 rx_ant = rx_ant & rdev->wiphy.available_antennas;
1128
1129                 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1130                 if (result)
1131                         goto bad_res;
1132         }
1133
1134         changed = 0;
1135
1136         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1137                 retry_short = nla_get_u8(
1138                         info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1139                 if (retry_short == 0) {
1140                         result = -EINVAL;
1141                         goto bad_res;
1142                 }
1143                 changed |= WIPHY_PARAM_RETRY_SHORT;
1144         }
1145
1146         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1147                 retry_long = nla_get_u8(
1148                         info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1149                 if (retry_long == 0) {
1150                         result = -EINVAL;
1151                         goto bad_res;
1152                 }
1153                 changed |= WIPHY_PARAM_RETRY_LONG;
1154         }
1155
1156         if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1157                 frag_threshold = nla_get_u32(
1158                         info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1159                 if (frag_threshold < 256) {
1160                         result = -EINVAL;
1161                         goto bad_res;
1162                 }
1163                 if (frag_threshold != (u32) -1) {
1164                         /*
1165                          * Fragments (apart from the last one) are required to
1166                          * have even length. Make the fragmentation code
1167                          * simpler by stripping LSB should someone try to use
1168                          * odd threshold value.
1169                          */
1170                         frag_threshold &= ~0x1;
1171                 }
1172                 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1173         }
1174
1175         if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1176                 rts_threshold = nla_get_u32(
1177                         info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1178                 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1179         }
1180
1181         if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1182                 coverage_class = nla_get_u8(
1183                         info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1184                 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1185         }
1186
1187         if (changed) {
1188                 u8 old_retry_short, old_retry_long;
1189                 u32 old_frag_threshold, old_rts_threshold;
1190                 u8 old_coverage_class;
1191
1192                 if (!rdev->ops->set_wiphy_params) {
1193                         result = -EOPNOTSUPP;
1194                         goto bad_res;
1195                 }
1196
1197                 old_retry_short = rdev->wiphy.retry_short;
1198                 old_retry_long = rdev->wiphy.retry_long;
1199                 old_frag_threshold = rdev->wiphy.frag_threshold;
1200                 old_rts_threshold = rdev->wiphy.rts_threshold;
1201                 old_coverage_class = rdev->wiphy.coverage_class;
1202
1203                 if (changed & WIPHY_PARAM_RETRY_SHORT)
1204                         rdev->wiphy.retry_short = retry_short;
1205                 if (changed & WIPHY_PARAM_RETRY_LONG)
1206                         rdev->wiphy.retry_long = retry_long;
1207                 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1208                         rdev->wiphy.frag_threshold = frag_threshold;
1209                 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1210                         rdev->wiphy.rts_threshold = rts_threshold;
1211                 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1212                         rdev->wiphy.coverage_class = coverage_class;
1213
1214                 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1215                 if (result) {
1216                         rdev->wiphy.retry_short = old_retry_short;
1217                         rdev->wiphy.retry_long = old_retry_long;
1218                         rdev->wiphy.frag_threshold = old_frag_threshold;
1219                         rdev->wiphy.rts_threshold = old_rts_threshold;
1220                         rdev->wiphy.coverage_class = old_coverage_class;
1221                 }
1222         }
1223
1224  bad_res:
1225         mutex_unlock(&rdev->mtx);
1226         if (netdev)
1227                 dev_put(netdev);
1228         return result;
1229 }
1230
1231
1232 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
1233                               struct cfg80211_registered_device *rdev,
1234                               struct net_device *dev)
1235 {
1236         void *hdr;
1237
1238         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1239         if (!hdr)
1240                 return -1;
1241
1242         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1243         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
1244         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
1245         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
1246
1247         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1248                     rdev->devlist_generation ^
1249                         (cfg80211_rdev_list_generation << 2));
1250
1251         return genlmsg_end(msg, hdr);
1252
1253  nla_put_failure:
1254         genlmsg_cancel(msg, hdr);
1255         return -EMSGSIZE;
1256 }
1257
1258 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1259 {
1260         int wp_idx = 0;
1261         int if_idx = 0;
1262         int wp_start = cb->args[0];
1263         int if_start = cb->args[1];
1264         struct cfg80211_registered_device *rdev;
1265         struct wireless_dev *wdev;
1266
1267         mutex_lock(&cfg80211_mutex);
1268         list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1269                 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
1270                         continue;
1271                 if (wp_idx < wp_start) {
1272                         wp_idx++;
1273                         continue;
1274                 }
1275                 if_idx = 0;
1276
1277                 mutex_lock(&rdev->devlist_mtx);
1278                 list_for_each_entry(wdev, &rdev->netdev_list, list) {
1279                         if (if_idx < if_start) {
1280                                 if_idx++;
1281                                 continue;
1282                         }
1283                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1284                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
1285                                                rdev, wdev->netdev) < 0) {
1286                                 mutex_unlock(&rdev->devlist_mtx);
1287                                 goto out;
1288                         }
1289                         if_idx++;
1290                 }
1291                 mutex_unlock(&rdev->devlist_mtx);
1292
1293                 wp_idx++;
1294         }
1295  out:
1296         mutex_unlock(&cfg80211_mutex);
1297
1298         cb->args[0] = wp_idx;
1299         cb->args[1] = if_idx;
1300
1301         return skb->len;
1302 }
1303
1304 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1305 {
1306         struct sk_buff *msg;
1307         struct cfg80211_registered_device *dev = info->user_ptr[0];
1308         struct net_device *netdev = info->user_ptr[1];
1309
1310         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1311         if (!msg)
1312                 return -ENOMEM;
1313
1314         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1315                                dev, netdev) < 0) {
1316                 nlmsg_free(msg);
1317                 return -ENOBUFS;
1318         }
1319
1320         return genlmsg_reply(msg, info);
1321 }
1322
1323 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1324         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1325         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1326         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1327         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1328         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1329 };
1330
1331 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1332 {
1333         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1334         int flag;
1335
1336         *mntrflags = 0;
1337
1338         if (!nla)
1339                 return -EINVAL;
1340
1341         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1342                              nla, mntr_flags_policy))
1343                 return -EINVAL;
1344
1345         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1346                 if (flags[flag])
1347                         *mntrflags |= (1<<flag);
1348
1349         return 0;
1350 }
1351
1352 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
1353                                struct net_device *netdev, u8 use_4addr,
1354                                enum nl80211_iftype iftype)
1355 {
1356         if (!use_4addr) {
1357                 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
1358                         return -EBUSY;
1359                 return 0;
1360         }
1361
1362         switch (iftype) {
1363         case NL80211_IFTYPE_AP_VLAN:
1364                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1365                         return 0;
1366                 break;
1367         case NL80211_IFTYPE_STATION:
1368                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1369                         return 0;
1370                 break;
1371         default:
1372                 break;
1373         }
1374
1375         return -EOPNOTSUPP;
1376 }
1377
1378 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1379 {
1380         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1381         struct vif_params params;
1382         int err;
1383         enum nl80211_iftype otype, ntype;
1384         struct net_device *dev = info->user_ptr[1];
1385         u32 _flags, *flags = NULL;
1386         bool change = false;
1387
1388         memset(&params, 0, sizeof(params));
1389
1390         otype = ntype = dev->ieee80211_ptr->iftype;
1391
1392         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1393                 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1394                 if (otype != ntype)
1395                         change = true;
1396                 if (ntype > NL80211_IFTYPE_MAX)
1397                         return -EINVAL;
1398         }
1399
1400         if (info->attrs[NL80211_ATTR_MESH_ID]) {
1401                 struct wireless_dev *wdev = dev->ieee80211_ptr;
1402
1403                 if (ntype != NL80211_IFTYPE_MESH_POINT)
1404                         return -EINVAL;
1405                 if (netif_running(dev))
1406                         return -EBUSY;
1407
1408                 wdev_lock(wdev);
1409                 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1410                              IEEE80211_MAX_MESH_ID_LEN);
1411                 wdev->mesh_id_up_len =
1412                         nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1413                 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1414                        wdev->mesh_id_up_len);
1415                 wdev_unlock(wdev);
1416         }
1417
1418         if (info->attrs[NL80211_ATTR_4ADDR]) {
1419                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1420                 change = true;
1421                 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1422                 if (err)
1423                         return err;
1424         } else {
1425                 params.use_4addr = -1;
1426         }
1427
1428         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1429                 if (ntype != NL80211_IFTYPE_MONITOR)
1430                         return -EINVAL;
1431                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1432                                           &_flags);
1433                 if (err)
1434                         return err;
1435
1436                 flags = &_flags;
1437                 change = true;
1438         }
1439
1440         if (change)
1441                 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1442         else
1443                 err = 0;
1444
1445         if (!err && params.use_4addr != -1)
1446                 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1447
1448         return err;
1449 }
1450
1451 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1452 {
1453         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1454         struct vif_params params;
1455         struct net_device *dev;
1456         int err;
1457         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1458         u32 flags;
1459
1460         memset(&params, 0, sizeof(params));
1461
1462         if (!info->attrs[NL80211_ATTR_IFNAME])
1463                 return -EINVAL;
1464
1465         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1466                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1467                 if (type > NL80211_IFTYPE_MAX)
1468                         return -EINVAL;
1469         }
1470
1471         if (!rdev->ops->add_virtual_intf ||
1472             !(rdev->wiphy.interface_modes & (1 << type)))
1473                 return -EOPNOTSUPP;
1474
1475         if (info->attrs[NL80211_ATTR_4ADDR]) {
1476                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1477                 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1478                 if (err)
1479                         return err;
1480         }
1481
1482         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1483                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1484                                   &flags);
1485         dev = rdev->ops->add_virtual_intf(&rdev->wiphy,
1486                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1487                 type, err ? NULL : &flags, &params);
1488         if (IS_ERR(dev))
1489                 return PTR_ERR(dev);
1490
1491         if (type == NL80211_IFTYPE_MESH_POINT &&
1492             info->attrs[NL80211_ATTR_MESH_ID]) {
1493                 struct wireless_dev *wdev = dev->ieee80211_ptr;
1494
1495                 wdev_lock(wdev);
1496                 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN !=
1497                              IEEE80211_MAX_MESH_ID_LEN);
1498                 wdev->mesh_id_up_len =
1499                         nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1500                 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
1501                        wdev->mesh_id_up_len);
1502                 wdev_unlock(wdev);
1503         }
1504
1505         return 0;
1506 }
1507
1508 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1509 {
1510         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1511         struct net_device *dev = info->user_ptr[1];
1512
1513         if (!rdev->ops->del_virtual_intf)
1514                 return -EOPNOTSUPP;
1515
1516         return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1517 }
1518
1519 struct get_key_cookie {
1520         struct sk_buff *msg;
1521         int error;
1522         int idx;
1523 };
1524
1525 static void get_key_callback(void *c, struct key_params *params)
1526 {
1527         struct nlattr *key;
1528         struct get_key_cookie *cookie = c;
1529
1530         if (params->key)
1531                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1532                         params->key_len, params->key);
1533
1534         if (params->seq)
1535                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1536                         params->seq_len, params->seq);
1537
1538         if (params->cipher)
1539                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1540                             params->cipher);
1541
1542         key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1543         if (!key)
1544                 goto nla_put_failure;
1545
1546         if (params->key)
1547                 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1548                         params->key_len, params->key);
1549
1550         if (params->seq)
1551                 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1552                         params->seq_len, params->seq);
1553
1554         if (params->cipher)
1555                 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1556                             params->cipher);
1557
1558         NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1559
1560         nla_nest_end(cookie->msg, key);
1561
1562         return;
1563  nla_put_failure:
1564         cookie->error = 1;
1565 }
1566
1567 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1568 {
1569         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1570         int err;
1571         struct net_device *dev = info->user_ptr[1];
1572         u8 key_idx = 0;
1573         const u8 *mac_addr = NULL;
1574         bool pairwise;
1575         struct get_key_cookie cookie = {
1576                 .error = 0,
1577         };
1578         void *hdr;
1579         struct sk_buff *msg;
1580
1581         if (info->attrs[NL80211_ATTR_KEY_IDX])
1582                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1583
1584         if (key_idx > 5)
1585                 return -EINVAL;
1586
1587         if (info->attrs[NL80211_ATTR_MAC])
1588                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1589
1590         pairwise = !!mac_addr;
1591         if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1592                 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1593                 if (kt >= NUM_NL80211_KEYTYPES)
1594                         return -EINVAL;
1595                 if (kt != NL80211_KEYTYPE_GROUP &&
1596                     kt != NL80211_KEYTYPE_PAIRWISE)
1597                         return -EINVAL;
1598                 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1599         }
1600
1601         if (!rdev->ops->get_key)
1602                 return -EOPNOTSUPP;
1603
1604         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1605         if (!msg)
1606                 return -ENOMEM;
1607
1608         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1609                              NL80211_CMD_NEW_KEY);
1610         if (IS_ERR(hdr))
1611                 return PTR_ERR(hdr);
1612
1613         cookie.msg = msg;
1614         cookie.idx = key_idx;
1615
1616         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1617         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1618         if (mac_addr)
1619                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1620
1621         if (pairwise && mac_addr &&
1622             !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1623                 return -ENOENT;
1624
1625         err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1626                                  mac_addr, &cookie, get_key_callback);
1627
1628         if (err)
1629                 goto free_msg;
1630
1631         if (cookie.error)
1632                 goto nla_put_failure;
1633
1634         genlmsg_end(msg, hdr);
1635         return genlmsg_reply(msg, info);
1636
1637  nla_put_failure:
1638         err = -ENOBUFS;
1639  free_msg:
1640         nlmsg_free(msg);
1641         return err;
1642 }
1643
1644 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1645 {
1646         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1647         struct key_parse key;
1648         int err;
1649         struct net_device *dev = info->user_ptr[1];
1650
1651         err = nl80211_parse_key(info, &key);
1652         if (err)
1653                 return err;
1654
1655         if (key.idx < 0)
1656                 return -EINVAL;
1657
1658         /* only support setting default key */
1659         if (!key.def && !key.defmgmt)
1660                 return -EINVAL;
1661
1662         wdev_lock(dev->ieee80211_ptr);
1663
1664         if (key.def) {
1665                 if (!rdev->ops->set_default_key) {
1666                         err = -EOPNOTSUPP;
1667                         goto out;
1668                 }
1669
1670                 err = nl80211_key_allowed(dev->ieee80211_ptr);
1671                 if (err)
1672                         goto out;
1673
1674                 if (!(rdev->wiphy.flags &
1675                                 WIPHY_FLAG_SUPPORTS_SEPARATE_DEFAULT_KEYS)) {
1676                         if (!key.def_uni || !key.def_multi) {
1677                                 err = -EOPNOTSUPP;
1678                                 goto out;
1679                         }
1680                 }
1681
1682                 err = rdev->ops->set_default_key(&rdev->wiphy, dev, key.idx,
1683                                                  key.def_uni, key.def_multi);
1684
1685                 if (err)
1686                         goto out;
1687
1688 #ifdef CONFIG_CFG80211_WEXT
1689                 dev->ieee80211_ptr->wext.default_key = key.idx;
1690 #endif
1691         } else {
1692                 if (key.def_uni || !key.def_multi) {
1693                         err = -EINVAL;
1694                         goto out;
1695                 }
1696
1697                 if (!rdev->ops->set_default_mgmt_key) {
1698                         err = -EOPNOTSUPP;
1699                         goto out;
1700                 }
1701
1702                 err = nl80211_key_allowed(dev->ieee80211_ptr);
1703                 if (err)
1704                         goto out;
1705
1706                 err = rdev->ops->set_default_mgmt_key(&rdev->wiphy,
1707                                                       dev, key.idx);
1708                 if (err)
1709                         goto out;
1710
1711 #ifdef CONFIG_CFG80211_WEXT
1712                 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1713 #endif
1714         }
1715
1716  out:
1717         wdev_unlock(dev->ieee80211_ptr);
1718
1719         return err;
1720 }
1721
1722 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1723 {
1724         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1725         int err;
1726         struct net_device *dev = info->user_ptr[1];
1727         struct key_parse key;
1728         const u8 *mac_addr = NULL;
1729
1730         err = nl80211_parse_key(info, &key);
1731         if (err)
1732                 return err;
1733
1734         if (!key.p.key)
1735                 return -EINVAL;
1736
1737         if (info->attrs[NL80211_ATTR_MAC])
1738                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1739
1740         if (key.type == -1) {
1741                 if (mac_addr)
1742                         key.type = NL80211_KEYTYPE_PAIRWISE;
1743                 else
1744                         key.type = NL80211_KEYTYPE_GROUP;
1745         }
1746
1747         /* for now */
1748         if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1749             key.type != NL80211_KEYTYPE_GROUP)
1750                 return -EINVAL;
1751
1752         if (!rdev->ops->add_key)
1753                 return -EOPNOTSUPP;
1754
1755         if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1756                                            key.type == NL80211_KEYTYPE_PAIRWISE,
1757                                            mac_addr))
1758                 return -EINVAL;
1759
1760         wdev_lock(dev->ieee80211_ptr);
1761         err = nl80211_key_allowed(dev->ieee80211_ptr);
1762         if (!err)
1763                 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1764                                          key.type == NL80211_KEYTYPE_PAIRWISE,
1765                                          mac_addr, &key.p);
1766         wdev_unlock(dev->ieee80211_ptr);
1767
1768         return err;
1769 }
1770
1771 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1772 {
1773         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1774         int err;
1775         struct net_device *dev = info->user_ptr[1];
1776         u8 *mac_addr = NULL;
1777         struct key_parse key;
1778
1779         err = nl80211_parse_key(info, &key);
1780         if (err)
1781                 return err;
1782
1783         if (info->attrs[NL80211_ATTR_MAC])
1784                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1785
1786         if (key.type == -1) {
1787                 if (mac_addr)
1788                         key.type = NL80211_KEYTYPE_PAIRWISE;
1789                 else
1790                         key.type = NL80211_KEYTYPE_GROUP;
1791         }
1792
1793         /* for now */
1794         if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1795             key.type != NL80211_KEYTYPE_GROUP)
1796                 return -EINVAL;
1797
1798         if (!rdev->ops->del_key)
1799                 return -EOPNOTSUPP;
1800
1801         wdev_lock(dev->ieee80211_ptr);
1802         err = nl80211_key_allowed(dev->ieee80211_ptr);
1803
1804         if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1805             !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1806                 err = -ENOENT;
1807
1808         if (!err)
1809                 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1810                                          key.type == NL80211_KEYTYPE_PAIRWISE,
1811                                          mac_addr);
1812
1813 #ifdef CONFIG_CFG80211_WEXT
1814         if (!err) {
1815                 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1816                         dev->ieee80211_ptr->wext.default_key = -1;
1817                 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1818                         dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1819         }
1820 #endif
1821         wdev_unlock(dev->ieee80211_ptr);
1822
1823         return err;
1824 }
1825
1826 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1827 {
1828         int (*call)(struct wiphy *wiphy, struct net_device *dev,
1829                     struct beacon_parameters *info);
1830         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1831         struct net_device *dev = info->user_ptr[1];
1832         struct beacon_parameters params;
1833         int haveinfo = 0;
1834
1835         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1836                 return -EINVAL;
1837
1838         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1839             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1840                 return -EOPNOTSUPP;
1841
1842         switch (info->genlhdr->cmd) {
1843         case NL80211_CMD_NEW_BEACON:
1844                 /* these are required for NEW_BEACON */
1845                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1846                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1847                     !info->attrs[NL80211_ATTR_BEACON_HEAD])
1848                         return -EINVAL;
1849
1850                 call = rdev->ops->add_beacon;
1851                 break;
1852         case NL80211_CMD_SET_BEACON:
1853                 call = rdev->ops->set_beacon;
1854                 break;
1855         default:
1856                 WARN_ON(1);
1857                 return -EOPNOTSUPP;
1858         }
1859
1860         if (!call)
1861                 return -EOPNOTSUPP;
1862
1863         memset(&params, 0, sizeof(params));
1864
1865         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1866                 params.interval =
1867                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1868                 haveinfo = 1;
1869         }
1870
1871         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1872                 params.dtim_period =
1873                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1874                 haveinfo = 1;
1875         }
1876
1877         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1878                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1879                 params.head_len =
1880                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1881                 haveinfo = 1;
1882         }
1883
1884         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1885                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1886                 params.tail_len =
1887                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1888                 haveinfo = 1;
1889         }
1890
1891         if (!haveinfo)
1892                 return -EINVAL;
1893
1894         return call(&rdev->wiphy, dev, &params);
1895 }
1896
1897 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1898 {
1899         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1900         struct net_device *dev = info->user_ptr[1];
1901
1902         if (!rdev->ops->del_beacon)
1903                 return -EOPNOTSUPP;
1904
1905         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1906             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1907                 return -EOPNOTSUPP;
1908
1909         return rdev->ops->del_beacon(&rdev->wiphy, dev);
1910 }
1911
1912 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1913         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1914         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1915         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1916         [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1917 };
1918
1919 static int parse_station_flags(struct genl_info *info,
1920                                struct station_parameters *params)
1921 {
1922         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1923         struct nlattr *nla;
1924         int flag;
1925
1926         /*
1927          * Try parsing the new attribute first so userspace
1928          * can specify both for older kernels.
1929          */
1930         nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1931         if (nla) {
1932                 struct nl80211_sta_flag_update *sta_flags;
1933
1934                 sta_flags = nla_data(nla);
1935                 params->sta_flags_mask = sta_flags->mask;
1936                 params->sta_flags_set = sta_flags->set;
1937                 if ((params->sta_flags_mask |
1938                      params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1939                         return -EINVAL;
1940                 return 0;
1941         }
1942
1943         /* if present, parse the old attribute */
1944
1945         nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1946         if (!nla)
1947                 return 0;
1948
1949         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1950                              nla, sta_flags_policy))
1951                 return -EINVAL;
1952
1953         params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1954         params->sta_flags_mask &= ~1;
1955
1956         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1957                 if (flags[flag])
1958                         params->sta_flags_set |= (1<<flag);
1959
1960         return 0;
1961 }
1962
1963 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1964                                 int flags, struct net_device *dev,
1965                                 const u8 *mac_addr, struct station_info *sinfo)
1966 {
1967         void *hdr;
1968         struct nlattr *sinfoattr, *txrate;
1969         u16 bitrate;
1970
1971         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1972         if (!hdr)
1973                 return -1;
1974
1975         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1976         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1977
1978         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1979
1980         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1981         if (!sinfoattr)
1982                 goto nla_put_failure;
1983         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1984                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1985                             sinfo->inactive_time);
1986         if (sinfo->filled & STATION_INFO_RX_BYTES)
1987                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1988                             sinfo->rx_bytes);
1989         if (sinfo->filled & STATION_INFO_TX_BYTES)
1990                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1991                             sinfo->tx_bytes);
1992         if (sinfo->filled & STATION_INFO_LLID)
1993                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1994                             sinfo->llid);
1995         if (sinfo->filled & STATION_INFO_PLID)
1996                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1997                             sinfo->plid);
1998         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1999                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
2000                             sinfo->plink_state);
2001         if (sinfo->filled & STATION_INFO_SIGNAL)
2002                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
2003                            sinfo->signal);
2004         if (sinfo->filled & STATION_INFO_SIGNAL_AVG)
2005                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL_AVG,
2006                            sinfo->signal_avg);
2007         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
2008                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
2009                 if (!txrate)
2010                         goto nla_put_failure;
2011
2012                 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
2013                 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
2014                 if (bitrate > 0)
2015                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
2016
2017                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
2018                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
2019                                     sinfo->txrate.mcs);
2020                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
2021                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
2022                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
2023                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
2024
2025                 nla_nest_end(msg, txrate);
2026         }
2027         if (sinfo->filled & STATION_INFO_RX_PACKETS)
2028                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
2029                             sinfo->rx_packets);
2030         if (sinfo->filled & STATION_INFO_TX_PACKETS)
2031                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
2032                             sinfo->tx_packets);
2033         if (sinfo->filled & STATION_INFO_TX_RETRIES)
2034                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
2035                             sinfo->tx_retries);
2036         if (sinfo->filled & STATION_INFO_TX_FAILED)
2037                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
2038                             sinfo->tx_failed);
2039         nla_nest_end(msg, sinfoattr);
2040
2041         return genlmsg_end(msg, hdr);
2042
2043  nla_put_failure:
2044         genlmsg_cancel(msg, hdr);
2045         return -EMSGSIZE;
2046 }
2047
2048 static int nl80211_dump_station(struct sk_buff *skb,
2049                                 struct netlink_callback *cb)
2050 {
2051         struct station_info sinfo;
2052         struct cfg80211_registered_device *dev;
2053         struct net_device *netdev;
2054         u8 mac_addr[ETH_ALEN];
2055         int sta_idx = cb->args[1];
2056         int err;
2057
2058         err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2059         if (err)
2060                 return err;
2061
2062         if (!dev->ops->dump_station) {
2063                 err = -EOPNOTSUPP;
2064                 goto out_err;
2065         }
2066
2067         while (1) {
2068                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
2069                                              mac_addr, &sinfo);
2070                 if (err == -ENOENT)
2071                         break;
2072                 if (err)
2073                         goto out_err;
2074
2075                 if (nl80211_send_station(skb,
2076                                 NETLINK_CB(cb->skb).pid,
2077                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
2078                                 netdev, mac_addr,
2079                                 &sinfo) < 0)
2080                         goto out;
2081
2082                 sta_idx++;
2083         }
2084
2085
2086  out:
2087         cb->args[1] = sta_idx;
2088         err = skb->len;
2089  out_err:
2090         nl80211_finish_netdev_dump(dev);
2091
2092         return err;
2093 }
2094
2095 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
2096 {
2097         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2098         struct net_device *dev = info->user_ptr[1];
2099         struct station_info sinfo;
2100         struct sk_buff *msg;
2101         u8 *mac_addr = NULL;
2102         int err;
2103
2104         memset(&sinfo, 0, sizeof(sinfo));
2105
2106         if (!info->attrs[NL80211_ATTR_MAC])
2107                 return -EINVAL;
2108
2109         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2110
2111         if (!rdev->ops->get_station)
2112                 return -EOPNOTSUPP;
2113
2114         err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
2115         if (err)
2116                 return err;
2117
2118         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2119         if (!msg)
2120                 return -ENOMEM;
2121
2122         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
2123                                  dev, mac_addr, &sinfo) < 0) {
2124                 nlmsg_free(msg);
2125                 return -ENOBUFS;
2126         }
2127
2128         return genlmsg_reply(msg, info);
2129 }
2130
2131 /*
2132  * Get vlan interface making sure it is running and on the right wiphy.
2133  */
2134 static int get_vlan(struct genl_info *info,
2135                     struct cfg80211_registered_device *rdev,
2136                     struct net_device **vlan)
2137 {
2138         struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
2139         *vlan = NULL;
2140
2141         if (vlanattr) {
2142                 *vlan = dev_get_by_index(genl_info_net(info),
2143                                          nla_get_u32(vlanattr));
2144                 if (!*vlan)
2145                         return -ENODEV;
2146                 if (!(*vlan)->ieee80211_ptr)
2147                         return -EINVAL;
2148                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2149                         return -EINVAL;
2150                 if (!netif_running(*vlan))
2151                         return -ENETDOWN;
2152         }
2153         return 0;
2154 }
2155
2156 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2157 {
2158         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2159         int err;
2160         struct net_device *dev = info->user_ptr[1];
2161         struct station_parameters params;
2162         u8 *mac_addr = NULL;
2163
2164         memset(&params, 0, sizeof(params));
2165
2166         params.listen_interval = -1;
2167
2168         if (info->attrs[NL80211_ATTR_STA_AID])
2169                 return -EINVAL;
2170
2171         if (!info->attrs[NL80211_ATTR_MAC])
2172                 return -EINVAL;
2173
2174         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2175
2176         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2177                 params.supported_rates =
2178                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2179                 params.supported_rates_len =
2180                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2181         }
2182
2183         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2184                 params.listen_interval =
2185                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2186
2187         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2188                 params.ht_capa =
2189                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2190
2191         if (parse_station_flags(info, &params))
2192                 return -EINVAL;
2193
2194         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2195                 params.plink_action =
2196                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2197
2198         err = get_vlan(info, rdev, &params.vlan);
2199         if (err)
2200                 goto out;
2201
2202         /* validate settings */
2203         err = 0;
2204
2205         switch (dev->ieee80211_ptr->iftype) {
2206         case NL80211_IFTYPE_AP:
2207         case NL80211_IFTYPE_AP_VLAN:
2208         case NL80211_IFTYPE_P2P_GO:
2209                 /* disallow mesh-specific things */
2210                 if (params.plink_action)
2211                         err = -EINVAL;
2212                 break;
2213         case NL80211_IFTYPE_P2P_CLIENT:
2214         case NL80211_IFTYPE_STATION:
2215                 /* disallow everything but AUTHORIZED flag */
2216                 if (params.plink_action)
2217                         err = -EINVAL;
2218                 if (params.vlan)
2219                         err = -EINVAL;
2220                 if (params.supported_rates)
2221                         err = -EINVAL;
2222                 if (params.ht_capa)
2223                         err = -EINVAL;
2224                 if (params.listen_interval >= 0)
2225                         err = -EINVAL;
2226                 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2227                         err = -EINVAL;
2228                 break;
2229         case NL80211_IFTYPE_MESH_POINT:
2230                 /* disallow things mesh doesn't support */
2231                 if (params.vlan)
2232                         err = -EINVAL;
2233                 if (params.ht_capa)
2234                         err = -EINVAL;
2235                 if (params.listen_interval >= 0)
2236                         err = -EINVAL;
2237                 if (params.supported_rates)
2238                         err = -EINVAL;
2239                 if (params.sta_flags_mask)
2240                         err = -EINVAL;
2241                 break;
2242         default:
2243                 err = -EINVAL;
2244         }
2245
2246         if (err)
2247                 goto out;
2248
2249         if (!rdev->ops->change_station) {
2250                 err = -EOPNOTSUPP;
2251                 goto out;
2252         }
2253
2254         err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
2255
2256  out:
2257         if (params.vlan)
2258                 dev_put(params.vlan);
2259
2260         return err;
2261 }
2262
2263 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2264 {
2265         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2266         int err;
2267         struct net_device *dev = info->user_ptr[1];
2268         struct station_parameters params;
2269         u8 *mac_addr = NULL;
2270
2271         memset(&params, 0, sizeof(params));
2272
2273         if (!info->attrs[NL80211_ATTR_MAC])
2274                 return -EINVAL;
2275
2276         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2277                 return -EINVAL;
2278
2279         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2280                 return -EINVAL;
2281
2282         if (!info->attrs[NL80211_ATTR_STA_AID])
2283                 return -EINVAL;
2284
2285         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2286         params.supported_rates =
2287                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2288         params.supported_rates_len =
2289                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2290         params.listen_interval =
2291                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2292
2293         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2294         if (!params.aid || params.aid > IEEE80211_MAX_AID)
2295                 return -EINVAL;
2296
2297         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2298                 params.ht_capa =
2299                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2300
2301         if (parse_station_flags(info, &params))
2302                 return -EINVAL;
2303
2304         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2305             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2306             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2307                 return -EINVAL;
2308
2309         err = get_vlan(info, rdev, &params.vlan);
2310         if (err)
2311                 goto out;
2312
2313         /* validate settings */
2314         err = 0;
2315
2316         if (!rdev->ops->add_station) {
2317                 err = -EOPNOTSUPP;
2318                 goto out;
2319         }
2320
2321         err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2322
2323  out:
2324         if (params.vlan)
2325                 dev_put(params.vlan);
2326         return err;
2327 }
2328
2329 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2330 {
2331         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2332         struct net_device *dev = info->user_ptr[1];
2333         u8 *mac_addr = NULL;
2334
2335         if (info->attrs[NL80211_ATTR_MAC])
2336                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2337
2338         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2339             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2340             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2341             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2342                 return -EINVAL;
2343
2344         if (!rdev->ops->del_station)
2345                 return -EOPNOTSUPP;
2346
2347         return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2348 }
2349
2350 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2351                                 int flags, struct net_device *dev,
2352                                 u8 *dst, u8 *next_hop,
2353                                 struct mpath_info *pinfo)
2354 {
2355         void *hdr;
2356         struct nlattr *pinfoattr;
2357
2358         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2359         if (!hdr)
2360                 return -1;
2361
2362         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2363         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2364         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2365
2366         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2367
2368         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2369         if (!pinfoattr)
2370                 goto nla_put_failure;
2371         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2372                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2373                             pinfo->frame_qlen);
2374         if (pinfo->filled & MPATH_INFO_SN)
2375                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2376                             pinfo->sn);
2377         if (pinfo->filled & MPATH_INFO_METRIC)
2378                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2379                             pinfo->metric);
2380         if (pinfo->filled & MPATH_INFO_EXPTIME)
2381                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2382                             pinfo->exptime);
2383         if (pinfo->filled & MPATH_INFO_FLAGS)
2384                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2385                             pinfo->flags);
2386         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2387                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2388                             pinfo->discovery_timeout);
2389         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2390                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2391                             pinfo->discovery_retries);
2392
2393         nla_nest_end(msg, pinfoattr);
2394
2395         return genlmsg_end(msg, hdr);
2396
2397  nla_put_failure:
2398         genlmsg_cancel(msg, hdr);
2399         return -EMSGSIZE;
2400 }
2401
2402 static int nl80211_dump_mpath(struct sk_buff *skb,
2403                               struct netlink_callback *cb)
2404 {
2405         struct mpath_info pinfo;
2406         struct cfg80211_registered_device *dev;
2407         struct net_device *netdev;
2408         u8 dst[ETH_ALEN];
2409         u8 next_hop[ETH_ALEN];
2410         int path_idx = cb->args[1];
2411         int err;
2412
2413         err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2414         if (err)
2415                 return err;
2416
2417         if (!dev->ops->dump_mpath) {
2418                 err = -EOPNOTSUPP;
2419                 goto out_err;
2420         }
2421
2422         if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2423                 err = -EOPNOTSUPP;
2424                 goto out_err;
2425         }
2426
2427         while (1) {
2428                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2429                                            dst, next_hop, &pinfo);
2430                 if (err == -ENOENT)
2431                         break;
2432                 if (err)
2433                         goto out_err;
2434
2435                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2436                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
2437                                        netdev, dst, next_hop,
2438                                        &pinfo) < 0)
2439                         goto out;
2440
2441                 path_idx++;
2442         }
2443
2444
2445  out:
2446         cb->args[1] = path_idx;
2447         err = skb->len;
2448  out_err:
2449         nl80211_finish_netdev_dump(dev);
2450         return err;
2451 }
2452
2453 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2454 {
2455         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2456         int err;
2457         struct net_device *dev = info->user_ptr[1];
2458         struct mpath_info pinfo;
2459         struct sk_buff *msg;
2460         u8 *dst = NULL;
2461         u8 next_hop[ETH_ALEN];
2462
2463         memset(&pinfo, 0, sizeof(pinfo));
2464
2465         if (!info->attrs[NL80211_ATTR_MAC])
2466                 return -EINVAL;
2467
2468         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2469
2470         if (!rdev->ops->get_mpath)
2471                 return -EOPNOTSUPP;
2472
2473         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2474                 return -EOPNOTSUPP;
2475
2476         err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2477         if (err)
2478                 return err;
2479
2480         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2481         if (!msg)
2482                 return -ENOMEM;
2483
2484         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2485                                  dev, dst, next_hop, &pinfo) < 0) {
2486                 nlmsg_free(msg);
2487                 return -ENOBUFS;
2488         }
2489
2490         return genlmsg_reply(msg, info);
2491 }
2492
2493 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2494 {
2495         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2496         struct net_device *dev = info->user_ptr[1];
2497         u8 *dst = NULL;
2498         u8 *next_hop = NULL;
2499
2500         if (!info->attrs[NL80211_ATTR_MAC])
2501                 return -EINVAL;
2502
2503         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2504                 return -EINVAL;
2505
2506         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2507         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2508
2509         if (!rdev->ops->change_mpath)
2510                 return -EOPNOTSUPP;
2511
2512         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2513                 return -EOPNOTSUPP;
2514
2515         return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2516 }
2517
2518 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2519 {
2520         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2521         struct net_device *dev = info->user_ptr[1];
2522         u8 *dst = NULL;
2523         u8 *next_hop = NULL;
2524
2525         if (!info->attrs[NL80211_ATTR_MAC])
2526                 return -EINVAL;
2527
2528         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2529                 return -EINVAL;
2530
2531         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2532         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2533
2534         if (!rdev->ops->add_mpath)
2535                 return -EOPNOTSUPP;
2536
2537         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2538                 return -EOPNOTSUPP;
2539
2540         return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2541 }
2542
2543 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2544 {
2545         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2546         struct net_device *dev = info->user_ptr[1];
2547         u8 *dst = NULL;
2548
2549         if (info->attrs[NL80211_ATTR_MAC])
2550                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2551
2552         if (!rdev->ops->del_mpath)
2553                 return -EOPNOTSUPP;
2554
2555         return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2556 }
2557
2558 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2559 {
2560         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2561         struct net_device *dev = info->user_ptr[1];
2562         struct bss_parameters params;
2563
2564         memset(&params, 0, sizeof(params));
2565         /* default to not changing parameters */
2566         params.use_cts_prot = -1;
2567         params.use_short_preamble = -1;
2568         params.use_short_slot_time = -1;
2569         params.ap_isolate = -1;
2570         params.ht_opmode = -1;
2571
2572         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2573                 params.use_cts_prot =
2574                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2575         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2576                 params.use_short_preamble =
2577                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2578         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2579                 params.use_short_slot_time =
2580                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2581         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2582                 params.basic_rates =
2583                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2584                 params.basic_rates_len =
2585                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2586         }
2587         if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2588                 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
2589         if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE])
2590                 params.ht_opmode =
2591                         nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]);
2592
2593         if (!rdev->ops->change_bss)
2594                 return -EOPNOTSUPP;
2595
2596         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2597             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2598                 return -EOPNOTSUPP;
2599
2600         return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2601 }
2602
2603 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2604         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
2605         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
2606         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
2607         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
2608         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
2609         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
2610 };
2611
2612 static int parse_reg_rule(struct nlattr *tb[],
2613         struct ieee80211_reg_rule *reg_rule)
2614 {
2615         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2616         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2617
2618         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2619                 return -EINVAL;
2620         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2621                 return -EINVAL;
2622         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2623                 return -EINVAL;
2624         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2625                 return -EINVAL;
2626         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2627                 return -EINVAL;
2628
2629         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2630
2631         freq_range->start_freq_khz =
2632                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2633         freq_range->end_freq_khz =
2634                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2635         freq_range->max_bandwidth_khz =
2636                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2637
2638         power_rule->max_eirp =
2639                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2640
2641         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2642                 power_rule->max_antenna_gain =
2643                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2644
2645         return 0;
2646 }
2647
2648 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2649 {
2650         int r;
2651         char *data = NULL;
2652
2653         /*
2654          * You should only get this when cfg80211 hasn't yet initialized
2655          * completely when built-in to the kernel right between the time
2656          * window between nl80211_init() and regulatory_init(), if that is
2657          * even possible.
2658          */
2659         mutex_lock(&cfg80211_mutex);
2660         if (unlikely(!cfg80211_regdomain)) {
2661                 mutex_unlock(&cfg80211_mutex);
2662                 return -EINPROGRESS;
2663         }
2664         mutex_unlock(&cfg80211_mutex);
2665
2666         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2667                 return -EINVAL;
2668
2669         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2670
2671         r = regulatory_hint_user(data);
2672
2673         return r;
2674 }
2675
2676 static int nl80211_get_mesh_config(struct sk_buff *skb,
2677                                    struct genl_info *info)
2678 {
2679         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2680         struct net_device *dev = info->user_ptr[1];
2681         struct wireless_dev *wdev = dev->ieee80211_ptr;
2682         struct mesh_config cur_params;
2683         int err = 0;
2684         void *hdr;
2685         struct nlattr *pinfoattr;
2686         struct sk_buff *msg;
2687
2688         if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2689                 return -EOPNOTSUPP;
2690
2691         if (!rdev->ops->get_mesh_config)
2692                 return -EOPNOTSUPP;
2693
2694         wdev_lock(wdev);
2695         /* If not connected, get default parameters */
2696         if (!wdev->mesh_id_len)
2697                 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params));
2698         else
2699                 err = rdev->ops->get_mesh_config(&rdev->wiphy, dev,
2700                                                  &cur_params);
2701         wdev_unlock(wdev);
2702
2703         if (err)
2704                 return err;
2705
2706         /* Draw up a netlink message to send back */
2707         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2708         if (!msg)
2709                 return -ENOMEM;
2710         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2711                              NL80211_CMD_GET_MESH_CONFIG);
2712         if (!hdr)
2713                 goto nla_put_failure;
2714         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG);
2715         if (!pinfoattr)
2716                 goto nla_put_failure;
2717         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2718         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2719                         cur_params.dot11MeshRetryTimeout);
2720         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2721                         cur_params.dot11MeshConfirmTimeout);
2722         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2723                         cur_params.dot11MeshHoldingTimeout);
2724         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2725                         cur_params.dot11MeshMaxPeerLinks);
2726         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2727                         cur_params.dot11MeshMaxRetries);
2728         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2729                         cur_params.dot11MeshTTL);
2730         NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2731                         cur_params.element_ttl);
2732         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2733                         cur_params.auto_open_plinks);
2734         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2735                         cur_params.dot11MeshHWMPmaxPREQretries);
2736         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2737                         cur_params.path_refresh_time);
2738         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2739                         cur_params.min_discovery_timeout);
2740         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2741                         cur_params.dot11MeshHWMPactivePathTimeout);
2742         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2743                         cur_params.dot11MeshHWMPpreqMinInterval);
2744         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2745                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2746         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2747                         cur_params.dot11MeshHWMPRootMode);
2748         nla_nest_end(msg, pinfoattr);
2749         genlmsg_end(msg, hdr);
2750         return genlmsg_reply(msg, info);
2751
2752  nla_put_failure:
2753         genlmsg_cancel(msg, hdr);
2754         nlmsg_free(msg);
2755         return -ENOBUFS;
2756 }
2757
2758 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
2759         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2760         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2761         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2762         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2763         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2764         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2765         [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
2766         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2767
2768         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2769         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2770         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2771         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2772         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2773         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2774 };
2775
2776 static int nl80211_parse_mesh_config(struct genl_info *info,
2777                                      struct mesh_config *cfg,
2778                                      u32 *mask_out)
2779 {
2780         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2781         u32 mask = 0;
2782
2783 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2784 do {\
2785         if (table[attr_num]) {\
2786                 cfg->param = nla_fn(table[attr_num]); \
2787                 mask |= (1 << (attr_num - 1)); \
2788         } \
2789 } while (0);\
2790
2791
2792         if (!info->attrs[NL80211_ATTR_MESH_CONFIG])
2793                 return -EINVAL;
2794         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2795                              info->attrs[NL80211_ATTR_MESH_CONFIG],
2796                              nl80211_meshconf_params_policy))
2797                 return -EINVAL;
2798
2799         /* This makes sure that there aren't more than 32 mesh config
2800          * parameters (otherwise our bitfield scheme would not work.) */
2801         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2802
2803         /* Fill in the params struct */
2804         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2805                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2806         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2807                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2808         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2809                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2810         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2811                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2812         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2813                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2814         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2815                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2816         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2817                         mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
2818         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2819                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2820         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2821                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2822                         nla_get_u8);
2823         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2824                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2825         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2826                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2827                         nla_get_u16);
2828         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2829                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2830                         nla_get_u32);
2831         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2832                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2833                         nla_get_u16);
2834         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2835                         dot11MeshHWMPnetDiameterTraversalTime,
2836                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2837                         nla_get_u16);
2838         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2839                         dot11MeshHWMPRootMode, mask,
2840                         NL80211_MESHCONF_HWMP_ROOTMODE,
2841                         nla_get_u8);
2842
2843         if (mask_out)
2844                 *mask_out = mask;
2845         return 0;
2846
2847 #undef FILL_IN_MESH_PARAM_IF_SET
2848 }
2849
2850 static int nl80211_update_mesh_config(struct sk_buff *skb,
2851                                       struct genl_info *info)
2852 {
2853         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2854         struct net_device *dev = info->user_ptr[1];
2855         struct wireless_dev *wdev = dev->ieee80211_ptr;
2856         struct mesh_config cfg;
2857         u32 mask;
2858         int err;
2859
2860         if (wdev->iftype != NL80211_IFTYPE_MESH_POINT)
2861                 return -EOPNOTSUPP;
2862
2863         if (!rdev->ops->update_mesh_config)
2864                 return -EOPNOTSUPP;
2865
2866         err = nl80211_parse_mesh_config(info, &cfg, &mask);
2867         if (err)
2868                 return err;
2869
2870         wdev_lock(wdev);
2871         if (!wdev->mesh_id_len)
2872                 err = -ENOLINK;
2873
2874         if (!err)
2875                 err = rdev->ops->update_mesh_config(&rdev->wiphy, dev,
2876                                                     mask, &cfg);
2877
2878         wdev_unlock(wdev);
2879
2880         return err;
2881 }
2882
2883 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2884 {
2885         struct sk_buff *msg;
2886         void *hdr = NULL;
2887         struct nlattr *nl_reg_rules;
2888         unsigned int i;
2889         int err = -EINVAL;
2890
2891         mutex_lock(&cfg80211_mutex);
2892
2893         if (!cfg80211_regdomain)
2894                 goto out;
2895
2896         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2897         if (!msg) {
2898                 err = -ENOBUFS;
2899                 goto out;
2900         }
2901
2902         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2903                              NL80211_CMD_GET_REG);
2904         if (!hdr)
2905                 goto nla_put_failure;
2906
2907         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2908                 cfg80211_regdomain->alpha2);
2909
2910         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2911         if (!nl_reg_rules)
2912                 goto nla_put_failure;
2913
2914         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2915                 struct nlattr *nl_reg_rule;
2916                 const struct ieee80211_reg_rule *reg_rule;
2917                 const struct ieee80211_freq_range *freq_range;
2918                 const struct ieee80211_power_rule *power_rule;
2919
2920                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2921                 freq_range = &reg_rule->freq_range;
2922                 power_rule = &reg_rule->power_rule;
2923
2924                 nl_reg_rule = nla_nest_start(msg, i);
2925                 if (!nl_reg_rule)
2926                         goto nla_put_failure;
2927
2928                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2929                         reg_rule->flags);
2930                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2931                         freq_range->start_freq_khz);
2932                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2933                         freq_range->end_freq_khz);
2934                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2935                         freq_range->max_bandwidth_khz);
2936                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2937                         power_rule->max_antenna_gain);
2938                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2939                         power_rule->max_eirp);
2940
2941                 nla_nest_end(msg, nl_reg_rule);
2942         }
2943
2944         nla_nest_end(msg, nl_reg_rules);
2945
2946         genlmsg_end(msg, hdr);
2947         err = genlmsg_reply(msg, info);
2948         goto out;
2949
2950 nla_put_failure:
2951         genlmsg_cancel(msg, hdr);
2952         nlmsg_free(msg);
2953         err = -EMSGSIZE;
2954 out:
2955         mutex_unlock(&cfg80211_mutex);
2956         return err;
2957 }
2958
2959 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2960 {
2961         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2962         struct nlattr *nl_reg_rule;
2963         char *alpha2 = NULL;
2964         int rem_reg_rules = 0, r = 0;
2965         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2966         struct ieee80211_regdomain *rd = NULL;
2967
2968         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2969                 return -EINVAL;
2970
2971         if (!info->attrs[NL80211_ATTR_REG_RULES])
2972                 return -EINVAL;
2973
2974         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2975
2976         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2977                         rem_reg_rules) {
2978                 num_rules++;
2979                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2980                         return -EINVAL;
2981         }
2982
2983         mutex_lock(&cfg80211_mutex);
2984
2985         if (!reg_is_valid_request(alpha2)) {
2986                 r = -EINVAL;
2987                 goto bad_reg;
2988         }
2989
2990         size_of_regd = sizeof(struct ieee80211_regdomain) +
2991                 (num_rules * sizeof(struct ieee80211_reg_rule));
2992
2993         rd = kzalloc(size_of_regd, GFP_KERNEL);
2994         if (!rd) {
2995                 r = -ENOMEM;
2996                 goto bad_reg;
2997         }
2998
2999         rd->n_reg_rules = num_rules;
3000         rd->alpha2[0] = alpha2[0];
3001         rd->alpha2[1] = alpha2[1];
3002
3003         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
3004                         rem_reg_rules) {
3005                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
3006                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
3007                         reg_rule_policy);
3008                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
3009                 if (r)
3010                         goto bad_reg;
3011
3012                 rule_idx++;
3013
3014                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
3015                         r = -EINVAL;
3016                         goto bad_reg;
3017                 }
3018         }
3019
3020         BUG_ON(rule_idx != num_rules);
3021
3022         r = set_regdom(rd);
3023
3024         mutex_unlock(&cfg80211_mutex);
3025
3026         return r;
3027
3028  bad_reg:
3029         mutex_unlock(&cfg80211_mutex);
3030         kfree(rd);
3031         return r;
3032 }
3033
3034 static int validate_scan_freqs(struct nlattr *freqs)
3035 {
3036         struct nlattr *attr1, *attr2;
3037         int n_channels = 0, tmp1, tmp2;
3038
3039         nla_for_each_nested(attr1, freqs, tmp1) {
3040                 n_channels++;
3041                 /*
3042                  * Some hardware has a limited channel list for
3043                  * scanning, and it is pretty much nonsensical
3044                  * to scan for a channel twice, so disallow that
3045                  * and don't require drivers to check that the
3046                  * channel list they get isn't longer than what
3047                  * they can scan, as long as they can scan all
3048                  * the channels they registered at once.
3049                  */
3050                 nla_for_each_nested(attr2, freqs, tmp2)
3051                         if (attr1 != attr2 &&
3052                             nla_get_u32(attr1) == nla_get_u32(attr2))
3053                                 return 0;
3054         }
3055
3056         return n_channels;
3057 }
3058
3059 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
3060 {
3061         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3062         struct net_device *dev = info->user_ptr[1];
3063         struct cfg80211_scan_request *request;
3064         struct cfg80211_ssid *ssid;
3065         struct ieee80211_channel *channel;
3066         struct nlattr *attr;
3067         struct wiphy *wiphy;
3068         int err, tmp, n_ssids = 0, n_channels, i;
3069         enum ieee80211_band band;
3070         size_t ie_len;
3071
3072         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3073                 return -EINVAL;
3074
3075         wiphy = &rdev->wiphy;
3076
3077         if (!rdev->ops->scan)
3078                 return -EOPNOTSUPP;
3079
3080         if (rdev->scan_req)
3081                 return -EBUSY;
3082
3083         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3084                 n_channels = validate_scan_freqs(
3085                                 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
3086                 if (!n_channels)
3087                         return -EINVAL;
3088         } else {
3089                 n_channels = 0;
3090
3091                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
3092                         if (wiphy->bands[band])
3093                                 n_channels += wiphy->bands[band]->n_channels;
3094         }
3095
3096         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
3097                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
3098                         n_ssids++;
3099
3100         if (n_ssids > wiphy->max_scan_ssids)
3101                 return -EINVAL;
3102
3103         if (info->attrs[NL80211_ATTR_IE])
3104                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3105         else
3106                 ie_len = 0;
3107
3108         if (ie_len > wiphy->max_scan_ie_len)
3109                 return -EINVAL;
3110
3111         request = kzalloc(sizeof(*request)
3112                         + sizeof(*ssid) * n_ssids
3113                         + sizeof(channel) * n_channels
3114                         + ie_len, GFP_KERNEL);
3115         if (!request)
3116                 return -ENOMEM;
3117
3118         if (n_ssids)
3119                 request->ssids = (void *)&request->channels[n_channels];
3120         request->n_ssids = n_ssids;
3121         if (ie_len) {
3122                 if (request->ssids)
3123                         request->ie = (void *)(request->ssids + n_ssids);
3124                 else
3125                         request->ie = (void *)(request->channels + n_channels);
3126         }
3127
3128         i = 0;
3129         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
3130                 /* user specified, bail out if channel not found */
3131                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
3132                         struct ieee80211_channel *chan;
3133
3134                         chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
3135
3136                         if (!chan) {
3137                                 err = -EINVAL;
3138                                 goto out_free;
3139                         }
3140
3141                         /* ignore disabled channels */
3142                         if (chan->flags & IEEE80211_CHAN_DISABLED)
3143                                 continue;
3144
3145                         request->channels[i] = chan;
3146                         i++;
3147                 }
3148         } else {
3149                 /* all channels */
3150                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3151                         int j;
3152                         if (!wiphy->bands[band])
3153                                 continue;
3154                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
3155                                 struct ieee80211_channel *chan;
3156
3157                                 chan = &wiphy->bands[band]->channels[j];
3158
3159                                 if (chan->flags & IEEE80211_CHAN_DISABLED)
3160                                         continue;
3161
3162                                 request->channels[i] = chan;
3163                                 i++;
3164                         }
3165                 }
3166         }
3167
3168         if (!i) {
3169                 err = -EINVAL;
3170                 goto out_free;
3171         }
3172
3173         request->n_channels = i;
3174
3175         i = 0;
3176         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3177                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3178                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3179                                 err = -EINVAL;
3180                                 goto out_free;
3181                         }
3182                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3183                         request->ssids[i].ssid_len = nla_len(attr);
3184                         i++;
3185                 }
3186         }
3187
3188         if (info->attrs[NL80211_ATTR_IE]) {
3189                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3190                 memcpy((void *)request->ie,
3191                        nla_data(info->attrs[NL80211_ATTR_IE]),
3192                        request->ie_len);
3193         }
3194
3195         request->dev = dev;
3196         request->wiphy = &rdev->wiphy;
3197
3198         rdev->scan_req = request;
3199         err = rdev->ops->scan(&rdev->wiphy, dev, request);
3200
3201         if (!err) {
3202                 nl80211_send_scan_start(rdev, dev);
3203                 dev_hold(dev);
3204         } else {
3205  out_free:
3206                 rdev->scan_req = NULL;
3207                 kfree(request);
3208         }
3209
3210         return err;
3211 }
3212
3213 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3214                             struct cfg80211_registered_device *rdev,
3215                             struct wireless_dev *wdev,
3216                             struct cfg80211_internal_bss *intbss)
3217 {
3218         struct cfg80211_bss *res = &intbss->pub;
3219         void *hdr;
3220         struct nlattr *bss;
3221         int i;
3222
3223         ASSERT_WDEV_LOCK(wdev);
3224
3225         hdr = nl80211hdr_put(msg, pid, seq, flags,
3226                              NL80211_CMD_NEW_SCAN_RESULTS);
3227         if (!hdr)
3228                 return -1;
3229
3230         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3231         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3232
3233         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3234         if (!bss)
3235                 goto nla_put_failure;
3236         if (!is_zero_ether_addr(res->bssid))
3237                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3238         if (res->information_elements && res->len_information_elements)
3239                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3240                         res->len_information_elements,
3241                         res->information_elements);
3242         if (res->beacon_ies && res->len_beacon_ies &&
3243             res->beacon_ies != res->information_elements)
3244                 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3245                         res->len_beacon_ies, res->beacon_ies);
3246         if (res->tsf)
3247                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3248         if (res->beacon_interval)
3249                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3250         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3251         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3252         NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3253                 jiffies_to_msecs(jiffies - intbss->ts));
3254
3255         switch (rdev->wiphy.signal_type) {
3256         case CFG80211_SIGNAL_TYPE_MBM:
3257                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3258                 break;
3259         case CFG80211_SIGNAL_TYPE_UNSPEC:
3260                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3261                 break;
3262         default:
3263                 break;
3264         }
3265
3266         switch (wdev->iftype) {
3267         case NL80211_IFTYPE_P2P_CLIENT:
3268         case NL80211_IFTYPE_STATION:
3269                 if (intbss == wdev->current_bss)
3270                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3271                                     NL80211_BSS_STATUS_ASSOCIATED);
3272                 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3273                         if (intbss != wdev->auth_bsses[i])
3274                                 continue;
3275                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3276                                     NL80211_BSS_STATUS_AUTHENTICATED);
3277                         break;
3278                 }
3279                 break;
3280         case NL80211_IFTYPE_ADHOC:
3281                 if (intbss == wdev->current_bss)
3282                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3283                                     NL80211_BSS_STATUS_IBSS_JOINED);
3284                 break;
3285         default:
3286                 break;
3287         }
3288
3289         nla_nest_end(msg, bss);
3290
3291         return genlmsg_end(msg, hdr);
3292
3293  nla_put_failure:
3294         genlmsg_cancel(msg, hdr);
3295         return -EMSGSIZE;
3296 }
3297
3298 static int nl80211_dump_scan(struct sk_buff *skb,
3299                              struct netlink_callback *cb)
3300 {
3301         struct cfg80211_registered_device *rdev;
3302         struct net_device *dev;
3303         struct cfg80211_internal_bss *scan;
3304         struct wireless_dev *wdev;
3305         int start = cb->args[1], idx = 0;
3306         int err;
3307
3308         err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3309         if (err)
3310                 return err;
3311
3312         wdev = dev->ieee80211_ptr;
3313
3314         wdev_lock(wdev);
3315         spin_lock_bh(&rdev->bss_lock);
3316         cfg80211_bss_expire(rdev);
3317
3318         list_for_each_entry(scan, &rdev->bss_list, list) {
3319                 if (++idx <= start)
3320                         continue;
3321                 if (nl80211_send_bss(skb,
3322                                 NETLINK_CB(cb->skb).pid,
3323                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3324                                 rdev, wdev, scan) < 0) {
3325                         idx--;
3326                         break;
3327                 }
3328         }
3329
3330         spin_unlock_bh(&rdev->bss_lock);
3331         wdev_unlock(wdev);
3332
3333         cb->args[1] = idx;
3334         nl80211_finish_netdev_dump(rdev);
3335
3336         return skb->len;
3337 }
3338
3339 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3340                                 int flags, struct net_device *dev,
3341                                 struct survey_info *survey)
3342 {
3343         void *hdr;
3344         struct nlattr *infoattr;
3345
3346         /* Survey without a channel doesn't make sense */
3347         if (!survey->channel)
3348                 return -EINVAL;
3349
3350         hdr = nl80211hdr_put(msg, pid, seq, flags,
3351                              NL80211_CMD_NEW_SURVEY_RESULTS);
3352         if (!hdr)
3353                 return -ENOMEM;
3354
3355         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3356
3357         infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3358         if (!infoattr)
3359                 goto nla_put_failure;
3360
3361         NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3362                     survey->channel->center_freq);
3363         if (survey->filled & SURVEY_INFO_NOISE_DBM)
3364                 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3365                             survey->noise);
3366         if (survey->filled & SURVEY_INFO_IN_USE)
3367                 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
3368         if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3369                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3370                             survey->channel_time);
3371         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3372                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3373                             survey->channel_time_busy);
3374         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3375                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3376                             survey->channel_time_ext_busy);
3377         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3378                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3379                             survey->channel_time_rx);
3380         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3381                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3382                             survey->channel_time_tx);
3383
3384         nla_nest_end(msg, infoattr);
3385
3386         return genlmsg_end(msg, hdr);
3387
3388  nla_put_failure:
3389         genlmsg_cancel(msg, hdr);
3390         return -EMSGSIZE;
3391 }
3392
3393 static int nl80211_dump_survey(struct sk_buff *skb,
3394                         struct netlink_callback *cb)
3395 {
3396         struct survey_info survey;
3397         struct cfg80211_registered_device *dev;
3398         struct net_device *netdev;
3399         int survey_idx = cb->args[1];
3400         int res;
3401
3402         res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3403         if (res)
3404                 return res;
3405
3406         if (!dev->ops->dump_survey) {
3407                 res = -EOPNOTSUPP;
3408                 goto out_err;
3409         }
3410
3411         while (1) {
3412                 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3413                                             &survey);
3414                 if (res == -ENOENT)
3415                         break;
3416                 if (res)
3417                         goto out_err;
3418
3419                 if (nl80211_send_survey(skb,
3420                                 NETLINK_CB(cb->skb).pid,
3421                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3422                                 netdev,
3423                                 &survey) < 0)
3424                         goto out;
3425                 survey_idx++;
3426         }
3427
3428  out:
3429         cb->args[1] = survey_idx;
3430         res = skb->len;
3431  out_err:
3432         nl80211_finish_netdev_dump(dev);
3433         return res;
3434 }
3435
3436 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3437 {
3438         return auth_type <= NL80211_AUTHTYPE_MAX;
3439 }
3440
3441 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3442 {
3443         return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3444                                   NL80211_WPA_VERSION_2));
3445 }
3446
3447 static bool nl80211_valid_akm_suite(u32 akm)
3448 {
3449         return akm == WLAN_AKM_SUITE_8021X ||
3450                 akm == WLAN_AKM_SUITE_PSK;
3451 }
3452
3453 static bool nl80211_valid_cipher_suite(u32 cipher)
3454 {
3455         return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3456                 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3457                 cipher == WLAN_CIPHER_SUITE_TKIP ||
3458                 cipher == WLAN_CIPHER_SUITE_CCMP ||
3459                 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3460 }
3461
3462
3463 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3464 {
3465         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3466         struct net_device *dev = info->user_ptr[1];
3467         struct ieee80211_channel *chan;
3468         const u8 *bssid, *ssid, *ie = NULL;
3469         int err, ssid_len, ie_len = 0;
3470         enum nl80211_auth_type auth_type;
3471         struct key_parse key;
3472         bool local_state_change;
3473
3474         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3475                 return -EINVAL;
3476
3477         if (!info->attrs[NL80211_ATTR_MAC])
3478                 return -EINVAL;
3479
3480         if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3481                 return -EINVAL;
3482
3483         if (!info->attrs[NL80211_ATTR_SSID])
3484                 return -EINVAL;
3485
3486         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3487                 return -EINVAL;
3488
3489         err = nl80211_parse_key(info, &key);
3490         if (err)
3491                 return err;
3492
3493         if (key.idx >= 0) {
3494                 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3495                         return -EINVAL;
3496                 if (!key.p.key || !key.p.key_len)
3497                         return -EINVAL;
3498                 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3499                      key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3500                     (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3501                      key.p.key_len != WLAN_KEY_LEN_WEP104))
3502                         return -EINVAL;
3503                 if (key.idx > 4)
3504                         return -EINVAL;
3505         } else {
3506                 key.p.key_len = 0;
3507                 key.p.key = NULL;
3508         }
3509
3510         if (key.idx >= 0) {
3511                 int i;
3512                 bool ok = false;
3513                 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3514                         if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3515                                 ok = true;
3516                                 break;
3517                         }
3518                 }
3519                 if (!ok)
3520                         return -EINVAL;
3521         }
3522
3523         if (!rdev->ops->auth)
3524                 return -EOPNOTSUPP;
3525
3526         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3527             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3528                 return -EOPNOTSUPP;
3529
3530         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3531         chan = ieee80211_get_channel(&rdev->wiphy,
3532                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3533         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3534                 return -EINVAL;
3535
3536         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3537         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3538
3539         if (info->attrs[NL80211_ATTR_IE]) {
3540                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3541                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3542         }
3543
3544         auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3545         if (!nl80211_valid_auth_type(auth_type))
3546                 return -EINVAL;
3547
3548         local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3549
3550         return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3551                                   ssid, ssid_len, ie, ie_len,
3552                                   key.p.key, key.p.key_len, key.idx,
3553                                   local_state_change);
3554 }
3555
3556 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3557                                    struct genl_info *info,
3558                                    struct cfg80211_crypto_settings *settings,
3559                                    int cipher_limit)
3560 {
3561         memset(settings, 0, sizeof(*settings));
3562
3563         settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3564
3565         if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3566                 u16 proto;
3567                 proto = nla_get_u16(
3568                         info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3569                 settings->control_port_ethertype = cpu_to_be16(proto);
3570                 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3571                     proto != ETH_P_PAE)
3572                         return -EINVAL;
3573                 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3574                         settings->control_port_no_encrypt = true;
3575         } else
3576                 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3577
3578         if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3579                 void *data;
3580                 int len, i;
3581
3582                 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3583                 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3584                 settings->n_ciphers_pairwise = len / sizeof(u32);
3585
3586                 if (len % sizeof(u32))
3587                         return -EINVAL;
3588
3589                 if (settings->n_ciphers_pairwise > cipher_limit)
3590                         return -EINVAL;
3591
3592                 memcpy(settings->ciphers_pairwise, data, len);
3593
3594                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3595                         if (!nl80211_valid_cipher_suite(
3596                                         settings->ciphers_pairwise[i]))
3597                                 return -EINVAL;
3598         }
3599
3600         if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3601                 settings->cipher_group =
3602                         nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3603                 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3604                         return -EINVAL;
3605         }
3606
3607         if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3608                 settings->wpa_versions =
3609                         nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3610                 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3611                         return -EINVAL;
3612         }
3613
3614         if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3615                 void *data;
3616                 int len, i;
3617
3618                 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3619                 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3620                 settings->n_akm_suites = len / sizeof(u32);
3621
3622                 if (len % sizeof(u32))
3623                         return -EINVAL;
3624
3625                 memcpy(settings->akm_suites, data, len);
3626
3627                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3628                         if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3629                                 return -EINVAL;
3630         }
3631
3632         return 0;
3633 }
3634
3635 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3636 {
3637         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3638         struct net_device *dev = info->user_ptr[1];
3639         struct cfg80211_crypto_settings crypto;
3640         struct ieee80211_channel *chan;
3641         const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3642         int err, ssid_len, ie_len = 0;
3643         bool use_mfp = false;
3644
3645         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3646                 return -EINVAL;
3647
3648         if (!info->attrs[NL80211_ATTR_MAC] ||
3649             !info->attrs[NL80211_ATTR_SSID] ||
3650             !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3651                 return -EINVAL;
3652
3653         if (!rdev->ops->assoc)
3654                 return -EOPNOTSUPP;
3655
3656         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3657             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3658                 return -EOPNOTSUPP;
3659
3660         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3661
3662         chan = ieee80211_get_channel(&rdev->wiphy,
3663                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3664         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3665                 return -EINVAL;
3666
3667         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3668         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3669
3670         if (info->attrs[NL80211_ATTR_IE]) {
3671                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3672                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3673         }
3674
3675         if (info->attrs[NL80211_ATTR_USE_MFP]) {
3676                 enum nl80211_mfp mfp =
3677                         nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3678                 if (mfp == NL80211_MFP_REQUIRED)
3679                         use_mfp = true;
3680                 else if (mfp != NL80211_MFP_NO)
3681                         return -EINVAL;
3682         }
3683
3684         if (info->attrs[NL80211_ATTR_PREV_BSSID])
3685                 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3686
3687         err = nl80211_crypto_settings(rdev, info, &crypto, 1);
3688         if (!err)
3689                 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3690                                           ssid, ssid_len, ie, ie_len, use_mfp,
3691                                           &crypto);
3692
3693         return err;
3694 }
3695
3696 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3697 {
3698         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3699         struct net_device *dev = info->user_ptr[1];
3700         const u8 *ie = NULL, *bssid;
3701         int ie_len = 0;
3702         u16 reason_code;
3703         bool local_state_change;
3704
3705         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3706                 return -EINVAL;
3707
3708         if (!info->attrs[NL80211_ATTR_MAC])
3709                 return -EINVAL;
3710
3711         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3712                 return -EINVAL;
3713
3714         if (!rdev->ops->deauth)
3715                 return -EOPNOTSUPP;
3716
3717         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3718             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3719                 return -EOPNOTSUPP;
3720
3721         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3722
3723         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3724         if (reason_code == 0) {
3725                 /* Reason Code 0 is reserved */
3726                 return -EINVAL;
3727         }
3728
3729         if (info->attrs[NL80211_ATTR_IE]) {
3730                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3731                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3732         }
3733
3734         local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3735
3736         return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3737                                     local_state_change);
3738 }
3739
3740 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3741 {
3742         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3743         struct net_device *dev = info->user_ptr[1];
3744         const u8 *ie = NULL, *bssid;
3745         int ie_len = 0;
3746         u16 reason_code;
3747         bool local_state_change;
3748
3749         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3750                 return -EINVAL;
3751
3752         if (!info->attrs[NL80211_ATTR_MAC])
3753                 return -EINVAL;
3754
3755         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3756                 return -EINVAL;
3757
3758         if (!rdev->ops->disassoc)
3759                 return -EOPNOTSUPP;
3760
3761         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3762             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3763                 return -EOPNOTSUPP;
3764
3765         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3766
3767         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3768         if (reason_code == 0) {
3769                 /* Reason Code 0 is reserved */
3770                 return -EINVAL;
3771         }
3772
3773         if (info->attrs[NL80211_ATTR_IE]) {
3774                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3775                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3776         }
3777
3778         local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3779
3780         return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3781                                       local_state_change);
3782 }
3783
3784 static bool
3785 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3786                          int mcast_rate[IEEE80211_NUM_BANDS],
3787                          int rateval)
3788 {
3789         struct wiphy *wiphy = &rdev->wiphy;
3790         bool found = false;
3791         int band, i;
3792
3793         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3794                 struct ieee80211_supported_band *sband;
3795
3796                 sband = wiphy->bands[band];
3797                 if (!sband)
3798                         continue;
3799
3800                 for (i = 0; i < sband->n_bitrates; i++) {
3801                         if (sband->bitrates[i].bitrate == rateval) {
3802                                 mcast_rate[band] = i + 1;
3803                                 found = true;
3804                                 break;
3805                         }
3806                 }
3807         }
3808
3809         return found;
3810 }
3811
3812 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3813 {
3814         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3815         struct net_device *dev = info->user_ptr[1];
3816         struct cfg80211_ibss_params ibss;
3817         struct wiphy *wiphy;
3818         struct cfg80211_cached_keys *connkeys = NULL;
3819         int err;
3820
3821         memset(&ibss, 0, sizeof(ibss));
3822
3823         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3824                 return -EINVAL;
3825
3826         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3827             !info->attrs[NL80211_ATTR_SSID] ||
3828             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3829                 return -EINVAL;
3830
3831         ibss.beacon_interval = 100;
3832
3833         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3834                 ibss.beacon_interval =
3835                         nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3836                 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3837                         return -EINVAL;
3838         }
3839
3840         if (!rdev->ops->join_ibss)
3841                 return -EOPNOTSUPP;
3842
3843         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3844                 return -EOPNOTSUPP;
3845
3846         wiphy = &rdev->wiphy;
3847
3848         if (info->attrs[NL80211_ATTR_MAC])
3849                 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3850         ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3851         ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3852
3853         if (info->attrs[NL80211_ATTR_IE]) {
3854                 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3855                 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3856         }
3857
3858         ibss.channel = ieee80211_get_channel(wiphy,
3859                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3860         if (!ibss.channel ||
3861             ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3862             ibss.channel->flags & IEEE80211_CHAN_DISABLED)
3863                 return -EINVAL;
3864
3865         ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3866         ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3867
3868         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3869                 u8 *rates =
3870                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3871                 int n_rates =
3872                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3873                 struct ieee80211_supported_band *sband =
3874                         wiphy->bands[ibss.channel->band];
3875                 int i, j;
3876
3877                 if (n_rates == 0)
3878                         return -EINVAL;
3879
3880                 for (i = 0; i < n_rates; i++) {
3881                         int rate = (rates[i] & 0x7f) * 5;
3882                         bool found = false;
3883
3884                         for (j = 0; j < sband->n_bitrates; j++) {
3885                                 if (sband->bitrates[j].bitrate == rate) {
3886                                         found = true;
3887                                         ibss.basic_rates |= BIT(j);
3888                                         break;
3889                                 }
3890                         }
3891                         if (!found)
3892                                 return -EINVAL;
3893                 }
3894         }
3895
3896         if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
3897             !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
3898                         nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
3899                 return -EINVAL;
3900
3901         if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3902                 connkeys = nl80211_parse_connkeys(rdev,
3903                                         info->attrs[NL80211_ATTR_KEYS]);
3904                 if (IS_ERR(connkeys))
3905                         return PTR_ERR(connkeys);
3906         }
3907
3908         err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
3909         if (err)
3910                 kfree(connkeys);
3911         return err;
3912 }
3913
3914 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3915 {
3916         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3917         struct net_device *dev = info->user_ptr[1];
3918
3919         if (!rdev->ops->leave_ibss)
3920                 return -EOPNOTSUPP;
3921
3922         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3923                 return -EOPNOTSUPP;
3924
3925         return cfg80211_leave_ibss(rdev, dev, false);
3926 }
3927
3928 #ifdef CONFIG_NL80211_TESTMODE
3929 static struct genl_multicast_group nl80211_testmode_mcgrp = {
3930         .name = "testmode",
3931 };
3932
3933 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3934 {
3935         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3936         int err;
3937
3938         if (!info->attrs[NL80211_ATTR_TESTDATA])
3939                 return -EINVAL;
3940
3941         err = -EOPNOTSUPP;
3942         if (rdev->ops->testmode_cmd) {
3943                 rdev->testmode_info = info;
3944                 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3945                                 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3946                                 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3947                 rdev->testmode_info = NULL;
3948         }
3949
3950         return err;
3951 }
3952
3953 static struct sk_buff *
3954 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3955                               int approxlen, u32 pid, u32 seq, gfp_t gfp)
3956 {
3957         struct sk_buff *skb;
3958         void *hdr;
3959         struct nlattr *data;
3960
3961         skb = nlmsg_new(approxlen + 100, gfp);
3962         if (!skb)
3963                 return NULL;
3964
3965         hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3966         if (!hdr) {
3967                 kfree_skb(skb);
3968                 return NULL;
3969         }
3970
3971         NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3972         data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3973
3974         ((void **)skb->cb)[0] = rdev;
3975         ((void **)skb->cb)[1] = hdr;
3976         ((void **)skb->cb)[2] = data;
3977
3978         return skb;
3979
3980  nla_put_failure:
3981         kfree_skb(skb);
3982         return NULL;
3983 }
3984
3985 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3986                                                   int approxlen)
3987 {
3988         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3989
3990         if (WARN_ON(!rdev->testmode_info))
3991                 return NULL;
3992
3993         return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3994                                 rdev->testmode_info->snd_pid,
3995                                 rdev->testmode_info->snd_seq,
3996                                 GFP_KERNEL);
3997 }
3998 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3999
4000 int cfg80211_testmode_reply(struct sk_buff *skb)
4001 {
4002         struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
4003         void *hdr = ((void **)skb->cb)[1];
4004         struct nlattr *data = ((void **)skb->cb)[2];
4005
4006         if (WARN_ON(!rdev->testmode_info)) {
4007                 kfree_skb(skb);
4008                 return -EINVAL;
4009         }
4010
4011         nla_nest_end(skb, data);
4012         genlmsg_end(skb, hdr);
4013         return genlmsg_reply(skb, rdev->testmode_info);
4014 }
4015 EXPORT_SYMBOL(cfg80211_testmode_reply);
4016
4017 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
4018                                                   int approxlen, gfp_t gfp)
4019 {
4020         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
4021
4022         return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
4023 }
4024 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
4025
4026 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
4027 {
4028         void *hdr = ((void **)skb->cb)[1];
4029         struct nlattr *data = ((void **)skb->cb)[2];
4030
4031         nla_nest_end(skb, data);
4032         genlmsg_end(skb, hdr);
4033         genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
4034 }
4035 EXPORT_SYMBOL(cfg80211_testmode_event);
4036 #endif
4037
4038 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
4039 {
4040         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4041         struct net_device *dev = info->user_ptr[1];
4042         struct cfg80211_connect_params connect;
4043         struct wiphy *wiphy;
4044         struct cfg80211_cached_keys *connkeys = NULL;
4045         int err;
4046
4047         memset(&connect, 0, sizeof(connect));
4048
4049         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
4050                 return -EINVAL;
4051
4052         if (!info->attrs[NL80211_ATTR_SSID] ||
4053             !nla_len(info->attrs[NL80211_ATTR_SSID]))
4054                 return -EINVAL;
4055
4056         if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
4057                 connect.auth_type =
4058                         nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
4059                 if (!nl80211_valid_auth_type(connect.auth_type))
4060                         return -EINVAL;
4061         } else
4062                 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
4063
4064         connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
4065
4066         err = nl80211_crypto_settings(rdev, info, &connect.crypto,
4067                                       NL80211_MAX_NR_CIPHER_SUITES);
4068         if (err)
4069                 return err;
4070
4071         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4072             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4073                 return -EOPNOTSUPP;
4074
4075         wiphy = &rdev->wiphy;
4076
4077         if (info->attrs[NL80211_ATTR_MAC])
4078                 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4079         connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
4080         connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
4081
4082         if (info->attrs[NL80211_ATTR_IE]) {
4083                 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
4084                 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
4085         }
4086
4087         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
4088                 connect.channel =
4089                         ieee80211_get_channel(wiphy,
4090                             nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
4091                 if (!connect.channel ||
4092                     connect.channel->flags & IEEE80211_CHAN_DISABLED)
4093                         return -EINVAL;
4094         }
4095
4096         if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
4097                 connkeys = nl80211_parse_connkeys(rdev,
4098                                         info->attrs[NL80211_ATTR_KEYS]);
4099                 if (IS_ERR(connkeys))
4100                         return PTR_ERR(connkeys);
4101         }
4102
4103         err = cfg80211_connect(rdev, dev, &connect, connkeys);
4104         if (err)
4105                 kfree(connkeys);
4106         return err;
4107 }
4108
4109 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
4110 {
4111         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4112         struct net_device *dev = info->user_ptr[1];
4113         u16 reason;
4114
4115         if (!info->attrs[NL80211_ATTR_REASON_CODE])
4116                 reason = WLAN_REASON_DEAUTH_LEAVING;
4117         else
4118                 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
4119
4120         if (reason == 0)
4121                 return -EINVAL;
4122
4123         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4124             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4125                 return -EOPNOTSUPP;
4126
4127         return cfg80211_disconnect(rdev, dev, reason, true);
4128 }
4129
4130 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
4131 {
4132         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4133         struct net *net;
4134         int err;
4135         u32 pid;
4136
4137         if (!info->attrs[NL80211_ATTR_PID])
4138                 return -EINVAL;
4139
4140         pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
4141
4142         net = get_net_ns_by_pid(pid);
4143         if (IS_ERR(net))
4144                 return PTR_ERR(net);
4145
4146         err = 0;
4147
4148         /* check if anything to do */
4149         if (!net_eq(wiphy_net(&rdev->wiphy), net))
4150                 err = cfg80211_switch_netns(rdev, net);
4151
4152         put_net(net);
4153         return err;
4154 }
4155
4156 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
4157 {
4158         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4159         int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
4160                         struct cfg80211_pmksa *pmksa) = NULL;
4161         struct net_device *dev = info->user_ptr[1];
4162         struct cfg80211_pmksa pmksa;
4163
4164         memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
4165
4166         if (!info->attrs[NL80211_ATTR_MAC])
4167                 return -EINVAL;
4168
4169         if (!info->attrs[NL80211_ATTR_PMKID])
4170                 return -EINVAL;
4171
4172         pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
4173         pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4174
4175         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4176             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4177                 return -EOPNOTSUPP;
4178
4179         switch (info->genlhdr->cmd) {
4180         case NL80211_CMD_SET_PMKSA:
4181                 rdev_ops = rdev->ops->set_pmksa;
4182                 break;
4183         case NL80211_CMD_DEL_PMKSA:
4184                 rdev_ops = rdev->ops->del_pmksa;
4185                 break;
4186         default:
4187                 WARN_ON(1);
4188                 break;
4189         }
4190
4191         if (!rdev_ops)
4192                 return -EOPNOTSUPP;
4193
4194         return rdev_ops(&rdev->wiphy, dev, &pmksa);
4195 }
4196
4197 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4198 {
4199         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4200         struct net_device *dev = info->user_ptr[1];
4201
4202         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4203             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4204                 return -EOPNOTSUPP;
4205
4206         if (!rdev->ops->flush_pmksa)
4207                 return -EOPNOTSUPP;
4208
4209         return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4210 }
4211
4212 static int nl80211_remain_on_channel(struct sk_buff *skb,
4213                                      struct genl_info *info)
4214 {
4215         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4216         struct net_device *dev = info->user_ptr[1];
4217         struct ieee80211_channel *chan;
4218         struct sk_buff *msg;
4219         void *hdr;
4220         u64 cookie;
4221         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4222         u32 freq, duration;
4223         int err;
4224
4225         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4226             !info->attrs[NL80211_ATTR_DURATION])
4227                 return -EINVAL;
4228
4229         duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4230
4231         /*
4232          * We should be on that channel for at least one jiffie,
4233          * and more than 5 seconds seems excessive.
4234          */
4235         if (!duration || !msecs_to_jiffies(duration) ||
4236             duration > rdev->wiphy.max_remain_on_channel_duration)
4237                 return -EINVAL;
4238
4239         if (!rdev->ops->remain_on_channel)
4240                 return -EOPNOTSUPP;
4241
4242         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4243                 channel_type = nla_get_u32(
4244                         info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4245                 if (channel_type != NL80211_CHAN_NO_HT &&
4246                     channel_type != NL80211_CHAN_HT20 &&
4247                     channel_type != NL80211_CHAN_HT40PLUS &&
4248                     channel_type != NL80211_CHAN_HT40MINUS)
4249                         return -EINVAL;
4250         }
4251
4252         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4253         chan = rdev_freq_to_chan(rdev, freq, channel_type);
4254         if (chan == NULL)
4255                 return -EINVAL;
4256
4257         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4258         if (!msg)
4259                 return -ENOMEM;
4260
4261         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4262                              NL80211_CMD_REMAIN_ON_CHANNEL);
4263
4264         if (IS_ERR(hdr)) {
4265                 err = PTR_ERR(hdr);
4266                 goto free_msg;
4267         }
4268
4269         err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4270                                            channel_type, duration, &cookie);
4271
4272         if (err)
4273                 goto free_msg;
4274
4275         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4276
4277         genlmsg_end(msg, hdr);
4278
4279         return genlmsg_reply(msg, info);
4280
4281  nla_put_failure:
4282         err = -ENOBUFS;
4283  free_msg:
4284         nlmsg_free(msg);
4285         return err;
4286 }
4287
4288 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4289                                             struct genl_info *info)
4290 {
4291         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4292         struct net_device *dev = info->user_ptr[1];
4293         u64 cookie;
4294
4295         if (!info->attrs[NL80211_ATTR_COOKIE])
4296                 return -EINVAL;
4297
4298         if (!rdev->ops->cancel_remain_on_channel)
4299                 return -EOPNOTSUPP;
4300
4301         cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4302
4303         return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4304 }
4305
4306 static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4307                            u8 *rates, u8 rates_len)
4308 {
4309         u8 i;
4310         u32 mask = 0;
4311
4312         for (i = 0; i < rates_len; i++) {
4313                 int rate = (rates[i] & 0x7f) * 5;
4314                 int ridx;
4315                 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4316                         struct ieee80211_rate *srate =
4317                                 &sband->bitrates[ridx];
4318                         if (rate == srate->bitrate) {
4319                                 mask |= 1 << ridx;
4320                                 break;
4321                         }
4322                 }
4323                 if (ridx == sband->n_bitrates)
4324                         return 0; /* rate not found */
4325         }
4326
4327         return mask;
4328 }
4329
4330 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
4331         [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4332                                     .len = NL80211_MAX_SUPP_RATES },
4333 };
4334
4335 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4336                                        struct genl_info *info)
4337 {
4338         struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4339         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4340         struct cfg80211_bitrate_mask mask;
4341         int rem, i;
4342         struct net_device *dev = info->user_ptr[1];
4343         struct nlattr *tx_rates;
4344         struct ieee80211_supported_band *sband;
4345
4346         if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4347                 return -EINVAL;
4348
4349         if (!rdev->ops->set_bitrate_mask)
4350                 return -EOPNOTSUPP;
4351
4352         memset(&mask, 0, sizeof(mask));
4353         /* Default to all rates enabled */
4354         for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4355                 sband = rdev->wiphy.bands[i];
4356                 mask.control[i].legacy =
4357                         sband ? (1 << sband->n_bitrates) - 1 : 0;
4358         }
4359
4360         /*
4361          * The nested attribute uses enum nl80211_band as the index. This maps
4362          * directly to the enum ieee80211_band values used in cfg80211.
4363          */
4364         nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4365         {
4366                 enum ieee80211_band band = nla_type(tx_rates);
4367                 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4368                         return -EINVAL;
4369                 sband = rdev->wiphy.bands[band];
4370                 if (sband == NULL)
4371                         return -EINVAL;
4372                 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4373                           nla_len(tx_rates), nl80211_txattr_policy);
4374                 if (tb[NL80211_TXRATE_LEGACY]) {
4375                         mask.control[band].legacy = rateset_to_mask(
4376                                 sband,
4377                                 nla_data(tb[NL80211_TXRATE_LEGACY]),
4378                                 nla_len(tb[NL80211_TXRATE_LEGACY]));
4379                         if (mask.control[band].legacy == 0)
4380                                 return -EINVAL;
4381                 }
4382         }
4383
4384         return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4385 }
4386
4387 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
4388 {
4389         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4390         struct net_device *dev = info->user_ptr[1];
4391         u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
4392
4393         if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4394                 return -EINVAL;
4395
4396         if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4397                 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
4398
4399         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4400             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4401             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4402             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4403             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4404             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4405                 return -EOPNOTSUPP;
4406
4407         /* not much point in registering if we can't reply */
4408         if (!rdev->ops->mgmt_tx)
4409                 return -EOPNOTSUPP;
4410
4411         return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
4412                         frame_type,
4413                         nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4414                         nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4415 }
4416
4417 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
4418 {
4419         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4420         struct net_device *dev = info->user_ptr[1];
4421         struct ieee80211_channel *chan;
4422         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4423         bool channel_type_valid = false;
4424         u32 freq;
4425         int err;
4426         void *hdr;
4427         u64 cookie;
4428         struct sk_buff *msg;
4429         unsigned int wait = 0;
4430         bool offchan;
4431
4432         if (!info->attrs[NL80211_ATTR_FRAME] ||
4433             !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4434                 return -EINVAL;
4435
4436         if (!rdev->ops->mgmt_tx)
4437                 return -EOPNOTSUPP;
4438
4439         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4440             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4441             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4442             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4443             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4444             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4445                 return -EOPNOTSUPP;
4446
4447         if (info->attrs[NL80211_ATTR_DURATION]) {
4448                 if (!rdev->ops->mgmt_tx_cancel_wait)
4449                         return -EINVAL;
4450                 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4451         }
4452
4453         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4454                 channel_type = nla_get_u32(
4455                         info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4456                 if (channel_type != NL80211_CHAN_NO_HT &&
4457                     channel_type != NL80211_CHAN_HT20 &&
4458                     channel_type != NL80211_CHAN_HT40PLUS &&
4459                     channel_type != NL80211_CHAN_HT40MINUS)
4460                         return -EINVAL;
4461                 channel_type_valid = true;
4462         }
4463
4464         offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4465
4466         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4467         chan = rdev_freq_to_chan(rdev, freq, channel_type);
4468         if (chan == NULL)
4469                 return -EINVAL;
4470
4471         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4472         if (!msg)
4473                 return -ENOMEM;
4474
4475         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4476                              NL80211_CMD_FRAME);
4477
4478         if (IS_ERR(hdr)) {
4479                 err = PTR_ERR(hdr);
4480                 goto free_msg;
4481         }
4482         err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4483                                     channel_type_valid, wait,
4484                                     nla_data(info->attrs[NL80211_ATTR_FRAME]),
4485                                     nla_len(info->attrs[NL80211_ATTR_FRAME]),
4486                                     &cookie);
4487         if (err)
4488                 goto free_msg;
4489
4490         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4491
4492         genlmsg_end(msg, hdr);
4493         return genlmsg_reply(msg, info);
4494
4495  nla_put_failure:
4496         err = -ENOBUFS;
4497  free_msg:
4498         nlmsg_free(msg);
4499         return err;
4500 }
4501
4502 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4503 {
4504         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4505         struct net_device *dev = info->user_ptr[1];
4506         u64 cookie;
4507
4508         if (!info->attrs[NL80211_ATTR_COOKIE])
4509                 return -EINVAL;
4510
4511         if (!rdev->ops->mgmt_tx_cancel_wait)
4512                 return -EOPNOTSUPP;
4513
4514         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4515             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4516             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4517             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4518             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4519             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4520                 return -EOPNOTSUPP;
4521
4522         cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4523
4524         return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4525 }
4526
4527 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4528 {
4529         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4530         struct wireless_dev *wdev;
4531         struct net_device *dev = info->user_ptr[1];
4532         u8 ps_state;
4533         bool state;
4534         int err;
4535
4536         if (!info->attrs[NL80211_ATTR_PS_STATE])
4537                 return -EINVAL;
4538
4539         ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4540
4541         if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4542                 return -EINVAL;
4543
4544         wdev = dev->ieee80211_ptr;
4545
4546         if (!rdev->ops->set_power_mgmt)
4547                 return -EOPNOTSUPP;
4548
4549         state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4550
4551         if (state == wdev->ps)
4552                 return 0;
4553
4554         err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4555                                         wdev->ps_timeout);
4556         if (!err)
4557                 wdev->ps = state;
4558         return err;
4559 }
4560
4561 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4562 {
4563         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4564         enum nl80211_ps_state ps_state;
4565         struct wireless_dev *wdev;
4566         struct net_device *dev = info->user_ptr[1];
4567         struct sk_buff *msg;
4568         void *hdr;
4569         int err;
4570
4571         wdev = dev->ieee80211_ptr;
4572
4573         if (!rdev->ops->set_power_mgmt)
4574                 return -EOPNOTSUPP;
4575
4576         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4577         if (!msg)
4578                 return -ENOMEM;
4579
4580         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4581                              NL80211_CMD_GET_POWER_SAVE);
4582         if (!hdr) {
4583                 err = -ENOBUFS;
4584                 goto free_msg;
4585         }
4586
4587         if (wdev->ps)
4588                 ps_state = NL80211_PS_ENABLED;
4589         else
4590                 ps_state = NL80211_PS_DISABLED;
4591
4592         NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4593
4594         genlmsg_end(msg, hdr);
4595         return genlmsg_reply(msg, info);
4596
4597  nla_put_failure:
4598         err = -ENOBUFS;
4599  free_msg:
4600         nlmsg_free(msg);
4601         return err;
4602 }
4603
4604 static struct nla_policy
4605 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4606         [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4607         [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4608         [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4609 };
4610
4611 static int nl80211_set_cqm_rssi(struct genl_info *info,
4612                                 s32 threshold, u32 hysteresis)
4613 {
4614         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4615         struct wireless_dev *wdev;
4616         struct net_device *dev = info->user_ptr[1];
4617
4618         if (threshold > 0)
4619                 return -EINVAL;
4620
4621         wdev = dev->ieee80211_ptr;
4622
4623         if (!rdev->ops->set_cqm_rssi_config)
4624                 return -EOPNOTSUPP;
4625
4626         if (wdev->iftype != NL80211_IFTYPE_STATION &&
4627             wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4628                 return -EOPNOTSUPP;
4629
4630         return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4631                                               threshold, hysteresis);
4632 }
4633
4634 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4635 {
4636         struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4637         struct nlattr *cqm;
4638         int err;
4639
4640         cqm = info->attrs[NL80211_ATTR_CQM];
4641         if (!cqm) {
4642                 err = -EINVAL;
4643                 goto out;
4644         }
4645
4646         err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4647                                nl80211_attr_cqm_policy);
4648         if (err)
4649                 goto out;
4650
4651         if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4652             attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4653                 s32 threshold;
4654                 u32 hysteresis;
4655                 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4656                 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4657                 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4658         } else
4659                 err = -EINVAL;
4660
4661 out:
4662         return err;
4663 }
4664
4665 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info)
4666 {
4667         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4668         struct net_device *dev = info->user_ptr[1];
4669         struct mesh_config cfg;
4670         int err;
4671
4672         /* start with default */
4673         memcpy(&cfg, &default_mesh_config, sizeof(cfg));
4674
4675         if (info->attrs[NL80211_ATTR_MESH_CONFIG]) {
4676                 /* and parse parameters if given */
4677                 err = nl80211_parse_mesh_config(info, &cfg, NULL);
4678                 if (err)
4679                         return err;
4680         }
4681
4682         if (!info->attrs[NL80211_ATTR_MESH_ID] ||
4683             !nla_len(info->attrs[NL80211_ATTR_MESH_ID]))
4684                 return -EINVAL;
4685
4686         return cfg80211_join_mesh(rdev, dev,
4687                                   nla_data(info->attrs[NL80211_ATTR_MESH_ID]),
4688                                   nla_len(info->attrs[NL80211_ATTR_MESH_ID]),
4689                                   &cfg);
4690 }
4691
4692 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info)
4693 {
4694         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4695         struct net_device *dev = info->user_ptr[1];
4696
4697         return cfg80211_leave_mesh(rdev, dev);
4698 }
4699
4700 #define NL80211_FLAG_NEED_WIPHY         0x01
4701 #define NL80211_FLAG_NEED_NETDEV        0x02
4702 #define NL80211_FLAG_NEED_RTNL          0x04
4703 #define NL80211_FLAG_CHECK_NETDEV_UP    0x08
4704 #define NL80211_FLAG_NEED_NETDEV_UP     (NL80211_FLAG_NEED_NETDEV |\
4705                                          NL80211_FLAG_CHECK_NETDEV_UP)
4706
4707 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
4708                             struct genl_info *info)
4709 {
4710         struct cfg80211_registered_device *rdev;
4711         struct net_device *dev;
4712         int err;
4713         bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
4714
4715         if (rtnl)
4716                 rtnl_lock();
4717
4718         if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4719                 rdev = cfg80211_get_dev_from_info(info);
4720                 if (IS_ERR(rdev)) {
4721                         if (rtnl)
4722                                 rtnl_unlock();
4723                         return PTR_ERR(rdev);
4724                 }
4725                 info->user_ptr[0] = rdev;
4726         } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
4727                 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4728                 if (err) {
4729                         if (rtnl)
4730                                 rtnl_unlock();
4731                         return err;
4732                 }
4733                 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
4734                     !netif_running(dev)) {
4735                         cfg80211_unlock_rdev(rdev);
4736                         dev_put(dev);
4737                         if (rtnl)
4738                                 rtnl_unlock();
4739                         return -ENETDOWN;
4740                 }
4741                 info->user_ptr[0] = rdev;
4742                 info->user_ptr[1] = dev;
4743         }
4744
4745         return 0;
4746 }
4747
4748 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
4749                               struct genl_info *info)
4750 {
4751         if (info->user_ptr[0])
4752                 cfg80211_unlock_rdev(info->user_ptr[0]);
4753         if (info->user_ptr[1])
4754                 dev_put(info->user_ptr[1]);
4755         if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
4756                 rtnl_unlock();
4757 }
4758
4759 static struct genl_ops nl80211_ops[] = {
4760         {
4761                 .cmd = NL80211_CMD_GET_WIPHY,
4762                 .doit = nl80211_get_wiphy,
4763                 .dumpit = nl80211_dump_wiphy,
4764                 .policy = nl80211_policy,
4765                 /* can be retrieved by unprivileged users */
4766                 .internal_flags = NL80211_FLAG_NEED_WIPHY,
4767         },
4768         {
4769                 .cmd = NL80211_CMD_SET_WIPHY,
4770                 .doit = nl80211_set_wiphy,
4771                 .policy = nl80211_policy,
4772                 .flags = GENL_ADMIN_PERM,
4773                 .internal_flags = NL80211_FLAG_NEED_RTNL,
4774         },
4775         {
4776                 .cmd = NL80211_CMD_GET_INTERFACE,
4777                 .doit = nl80211_get_interface,
4778                 .dumpit = nl80211_dump_interface,
4779                 .policy = nl80211_policy,
4780                 /* can be retrieved by unprivileged users */
4781                 .internal_flags = NL80211_FLAG_NEED_NETDEV,
4782         },
4783         {
4784                 .cmd = NL80211_CMD_SET_INTERFACE,
4785                 .doit = nl80211_set_interface,
4786                 .policy = nl80211_policy,
4787                 .flags = GENL_ADMIN_PERM,
4788                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4789                                   NL80211_FLAG_NEED_RTNL,
4790         },
4791         {
4792                 .cmd = NL80211_CMD_NEW_INTERFACE,
4793                 .doit = nl80211_new_interface,
4794                 .policy = nl80211_policy,
4795                 .flags = GENL_ADMIN_PERM,
4796                 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4797                                   NL80211_FLAG_NEED_RTNL,
4798         },
4799         {
4800                 .cmd = NL80211_CMD_DEL_INTERFACE,
4801                 .doit = nl80211_del_interface,
4802                 .policy = nl80211_policy,
4803                 .flags = GENL_ADMIN_PERM,
4804                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4805                                   NL80211_FLAG_NEED_RTNL,
4806         },
4807         {
4808                 .cmd = NL80211_CMD_GET_KEY,
4809                 .doit = nl80211_get_key,
4810                 .policy = nl80211_policy,
4811                 .flags = GENL_ADMIN_PERM,
4812                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4813                                   NL80211_FLAG_NEED_RTNL,
4814         },
4815         {
4816                 .cmd = NL80211_CMD_SET_KEY,
4817                 .doit = nl80211_set_key,
4818                 .policy = nl80211_policy,
4819                 .flags = GENL_ADMIN_PERM,
4820                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4821                                   NL80211_FLAG_NEED_RTNL,
4822         },
4823         {
4824                 .cmd = NL80211_CMD_NEW_KEY,
4825                 .doit = nl80211_new_key,
4826                 .policy = nl80211_policy,
4827                 .flags = GENL_ADMIN_PERM,
4828                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4829                                   NL80211_FLAG_NEED_RTNL,
4830         },
4831         {
4832                 .cmd = NL80211_CMD_DEL_KEY,
4833                 .doit = nl80211_del_key,
4834                 .policy = nl80211_policy,
4835                 .flags = GENL_ADMIN_PERM,
4836                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4837                                   NL80211_FLAG_NEED_RTNL,
4838         },
4839         {
4840                 .cmd = NL80211_CMD_SET_BEACON,
4841                 .policy = nl80211_policy,
4842                 .flags = GENL_ADMIN_PERM,
4843                 .doit = nl80211_addset_beacon,
4844                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4845                                   NL80211_FLAG_NEED_RTNL,
4846         },
4847         {
4848                 .cmd = NL80211_CMD_NEW_BEACON,
4849                 .policy = nl80211_policy,
4850                 .flags = GENL_ADMIN_PERM,
4851                 .doit = nl80211_addset_beacon,
4852                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4853                                   NL80211_FLAG_NEED_RTNL,
4854         },
4855         {
4856                 .cmd = NL80211_CMD_DEL_BEACON,
4857                 .policy = nl80211_policy,
4858                 .flags = GENL_ADMIN_PERM,
4859                 .doit = nl80211_del_beacon,
4860                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4861                                   NL80211_FLAG_NEED_RTNL,
4862         },
4863         {
4864                 .cmd = NL80211_CMD_GET_STATION,
4865                 .doit = nl80211_get_station,
4866                 .dumpit = nl80211_dump_station,
4867                 .policy = nl80211_policy,
4868                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4869                                   NL80211_FLAG_NEED_RTNL,
4870         },
4871         {
4872                 .cmd = NL80211_CMD_SET_STATION,
4873                 .doit = nl80211_set_station,
4874                 .policy = nl80211_policy,
4875                 .flags = GENL_ADMIN_PERM,
4876                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4877                                   NL80211_FLAG_NEED_RTNL,
4878         },
4879         {
4880                 .cmd = NL80211_CMD_NEW_STATION,
4881                 .doit = nl80211_new_station,
4882                 .policy = nl80211_policy,
4883                 .flags = GENL_ADMIN_PERM,
4884                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4885                                   NL80211_FLAG_NEED_RTNL,
4886         },
4887         {
4888                 .cmd = NL80211_CMD_DEL_STATION,
4889                 .doit = nl80211_del_station,
4890                 .policy = nl80211_policy,
4891                 .flags = GENL_ADMIN_PERM,
4892                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4893                                   NL80211_FLAG_NEED_RTNL,
4894         },
4895         {
4896                 .cmd = NL80211_CMD_GET_MPATH,
4897                 .doit = nl80211_get_mpath,
4898                 .dumpit = nl80211_dump_mpath,
4899                 .policy = nl80211_policy,
4900                 .flags = GENL_ADMIN_PERM,
4901                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4902                                   NL80211_FLAG_NEED_RTNL,
4903         },
4904         {
4905                 .cmd = NL80211_CMD_SET_MPATH,
4906                 .doit = nl80211_set_mpath,
4907                 .policy = nl80211_policy,
4908                 .flags = GENL_ADMIN_PERM,
4909                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4910                                   NL80211_FLAG_NEED_RTNL,
4911         },
4912         {
4913                 .cmd = NL80211_CMD_NEW_MPATH,
4914                 .doit = nl80211_new_mpath,
4915                 .policy = nl80211_policy,
4916                 .flags = GENL_ADMIN_PERM,
4917                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4918                                   NL80211_FLAG_NEED_RTNL,
4919         },
4920         {
4921                 .cmd = NL80211_CMD_DEL_MPATH,
4922                 .doit = nl80211_del_mpath,
4923                 .policy = nl80211_policy,
4924                 .flags = GENL_ADMIN_PERM,
4925                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4926                                   NL80211_FLAG_NEED_RTNL,
4927         },
4928         {
4929                 .cmd = NL80211_CMD_SET_BSS,
4930                 .doit = nl80211_set_bss,
4931                 .policy = nl80211_policy,
4932                 .flags = GENL_ADMIN_PERM,
4933                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4934                                   NL80211_FLAG_NEED_RTNL,
4935         },
4936         {
4937                 .cmd = NL80211_CMD_GET_REG,
4938                 .doit = nl80211_get_reg,
4939                 .policy = nl80211_policy,
4940                 /* can be retrieved by unprivileged users */
4941         },
4942         {
4943                 .cmd = NL80211_CMD_SET_REG,
4944                 .doit = nl80211_set_reg,
4945                 .policy = nl80211_policy,
4946                 .flags = GENL_ADMIN_PERM,
4947         },
4948         {
4949                 .cmd = NL80211_CMD_REQ_SET_REG,
4950                 .doit = nl80211_req_set_reg,
4951                 .policy = nl80211_policy,
4952                 .flags = GENL_ADMIN_PERM,
4953         },
4954         {
4955                 .cmd = NL80211_CMD_GET_MESH_CONFIG,
4956                 .doit = nl80211_get_mesh_config,
4957                 .policy = nl80211_policy,
4958                 /* can be retrieved by unprivileged users */
4959                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4960                                   NL80211_FLAG_NEED_RTNL,
4961         },
4962         {
4963                 .cmd = NL80211_CMD_SET_MESH_CONFIG,
4964                 .doit = nl80211_update_mesh_config,
4965                 .policy = nl80211_policy,
4966                 .flags = GENL_ADMIN_PERM,
4967                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4968                                   NL80211_FLAG_NEED_RTNL,
4969         },
4970         {
4971                 .cmd = NL80211_CMD_TRIGGER_SCAN,
4972                 .doit = nl80211_trigger_scan,
4973                 .policy = nl80211_policy,
4974                 .flags = GENL_ADMIN_PERM,
4975                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4976                                   NL80211_FLAG_NEED_RTNL,
4977         },
4978         {
4979                 .cmd = NL80211_CMD_GET_SCAN,
4980                 .policy = nl80211_policy,
4981                 .dumpit = nl80211_dump_scan,
4982         },
4983         {
4984                 .cmd = NL80211_CMD_AUTHENTICATE,
4985                 .doit = nl80211_authenticate,
4986                 .policy = nl80211_policy,
4987                 .flags = GENL_ADMIN_PERM,
4988                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4989                                   NL80211_FLAG_NEED_RTNL,
4990         },
4991         {
4992                 .cmd = NL80211_CMD_ASSOCIATE,
4993                 .doit = nl80211_associate,
4994                 .policy = nl80211_policy,
4995                 .flags = GENL_ADMIN_PERM,
4996                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4997                                   NL80211_FLAG_NEED_RTNL,
4998         },
4999         {
5000                 .cmd = NL80211_CMD_DEAUTHENTICATE,
5001                 .doit = nl80211_deauthenticate,
5002                 .policy = nl80211_policy,
5003                 .flags = GENL_ADMIN_PERM,
5004                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5005                                   NL80211_FLAG_NEED_RTNL,
5006         },
5007         {
5008                 .cmd = NL80211_CMD_DISASSOCIATE,
5009                 .doit = nl80211_disassociate,
5010                 .policy = nl80211_policy,
5011                 .flags = GENL_ADMIN_PERM,
5012                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5013                                   NL80211_FLAG_NEED_RTNL,
5014         },
5015         {
5016                 .cmd = NL80211_CMD_JOIN_IBSS,
5017                 .doit = nl80211_join_ibss,
5018                 .policy = nl80211_policy,
5019                 .flags = GENL_ADMIN_PERM,
5020                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5021                                   NL80211_FLAG_NEED_RTNL,
5022         },
5023         {
5024                 .cmd = NL80211_CMD_LEAVE_IBSS,
5025                 .doit = nl80211_leave_ibss,
5026                 .policy = nl80211_policy,
5027                 .flags = GENL_ADMIN_PERM,
5028                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5029                                   NL80211_FLAG_NEED_RTNL,
5030         },
5031 #ifdef CONFIG_NL80211_TESTMODE
5032         {
5033                 .cmd = NL80211_CMD_TESTMODE,
5034                 .doit = nl80211_testmode_do,
5035                 .policy = nl80211_policy,
5036                 .flags = GENL_ADMIN_PERM,
5037                 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5038                                   NL80211_FLAG_NEED_RTNL,
5039         },
5040 #endif
5041         {
5042                 .cmd = NL80211_CMD_CONNECT,
5043                 .doit = nl80211_connect,
5044                 .policy = nl80211_policy,
5045                 .flags = GENL_ADMIN_PERM,
5046                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5047                                   NL80211_FLAG_NEED_RTNL,
5048         },
5049         {
5050                 .cmd = NL80211_CMD_DISCONNECT,
5051                 .doit = nl80211_disconnect,
5052                 .policy = nl80211_policy,
5053                 .flags = GENL_ADMIN_PERM,
5054                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5055                                   NL80211_FLAG_NEED_RTNL,
5056         },
5057         {
5058                 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
5059                 .doit = nl80211_wiphy_netns,
5060                 .policy = nl80211_policy,
5061                 .flags = GENL_ADMIN_PERM,
5062                 .internal_flags = NL80211_FLAG_NEED_WIPHY |
5063                                   NL80211_FLAG_NEED_RTNL,
5064         },
5065         {
5066                 .cmd = NL80211_CMD_GET_SURVEY,
5067                 .policy = nl80211_policy,
5068                 .dumpit = nl80211_dump_survey,
5069         },
5070         {
5071                 .cmd = NL80211_CMD_SET_PMKSA,
5072                 .doit = nl80211_setdel_pmksa,
5073                 .policy = nl80211_policy,
5074                 .flags = GENL_ADMIN_PERM,
5075                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5076                                   NL80211_FLAG_NEED_RTNL,
5077         },
5078         {
5079                 .cmd = NL80211_CMD_DEL_PMKSA,
5080                 .doit = nl80211_setdel_pmksa,
5081                 .policy = nl80211_policy,
5082                 .flags = GENL_ADMIN_PERM,
5083                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5084                                   NL80211_FLAG_NEED_RTNL,
5085         },
5086         {
5087                 .cmd = NL80211_CMD_FLUSH_PMKSA,
5088                 .doit = nl80211_flush_pmksa,
5089                 .policy = nl80211_policy,
5090                 .flags = GENL_ADMIN_PERM,
5091                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5092                                   NL80211_FLAG_NEED_RTNL,
5093         },
5094         {
5095                 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
5096                 .doit = nl80211_remain_on_channel,
5097                 .policy = nl80211_policy,
5098                 .flags = GENL_ADMIN_PERM,
5099                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5100                                   NL80211_FLAG_NEED_RTNL,
5101         },
5102         {
5103                 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5104                 .doit = nl80211_cancel_remain_on_channel,
5105                 .policy = nl80211_policy,
5106                 .flags = GENL_ADMIN_PERM,
5107                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5108                                   NL80211_FLAG_NEED_RTNL,
5109         },
5110         {
5111                 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
5112                 .doit = nl80211_set_tx_bitrate_mask,
5113                 .policy = nl80211_policy,
5114                 .flags = GENL_ADMIN_PERM,
5115                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5116                                   NL80211_FLAG_NEED_RTNL,
5117         },
5118         {
5119                 .cmd = NL80211_CMD_REGISTER_FRAME,
5120                 .doit = nl80211_register_mgmt,
5121                 .policy = nl80211_policy,
5122                 .flags = GENL_ADMIN_PERM,
5123                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5124                                   NL80211_FLAG_NEED_RTNL,
5125         },
5126         {
5127                 .cmd = NL80211_CMD_FRAME,
5128                 .doit = nl80211_tx_mgmt,
5129                 .policy = nl80211_policy,
5130                 .flags = GENL_ADMIN_PERM,
5131                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5132                                   NL80211_FLAG_NEED_RTNL,
5133         },
5134         {
5135                 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
5136                 .doit = nl80211_tx_mgmt_cancel_wait,
5137                 .policy = nl80211_policy,
5138                 .flags = GENL_ADMIN_PERM,
5139                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5140                                   NL80211_FLAG_NEED_RTNL,
5141         },
5142         {
5143                 .cmd = NL80211_CMD_SET_POWER_SAVE,
5144                 .doit = nl80211_set_power_save,
5145                 .policy = nl80211_policy,
5146                 .flags = GENL_ADMIN_PERM,
5147                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5148                                   NL80211_FLAG_NEED_RTNL,
5149         },
5150         {
5151                 .cmd = NL80211_CMD_GET_POWER_SAVE,
5152                 .doit = nl80211_get_power_save,
5153                 .policy = nl80211_policy,
5154                 /* can be retrieved by unprivileged users */
5155                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5156                                   NL80211_FLAG_NEED_RTNL,
5157         },
5158         {
5159                 .cmd = NL80211_CMD_SET_CQM,
5160                 .doit = nl80211_set_cqm,
5161                 .policy = nl80211_policy,
5162                 .flags = GENL_ADMIN_PERM,
5163                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5164                                   NL80211_FLAG_NEED_RTNL,
5165         },
5166         {
5167                 .cmd = NL80211_CMD_SET_CHANNEL,
5168                 .doit = nl80211_set_channel,
5169                 .policy = nl80211_policy,
5170                 .flags = GENL_ADMIN_PERM,
5171                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5172                                   NL80211_FLAG_NEED_RTNL,
5173         },
5174         {
5175                 .cmd = NL80211_CMD_SET_WDS_PEER,
5176                 .doit = nl80211_set_wds_peer,
5177                 .policy = nl80211_policy,
5178                 .flags = GENL_ADMIN_PERM,
5179                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
5180                                   NL80211_FLAG_NEED_RTNL,
5181         },
5182         {
5183                 .cmd = NL80211_CMD_JOIN_MESH,
5184                 .doit = nl80211_join_mesh,
5185                 .policy = nl80211_policy,
5186                 .flags = GENL_ADMIN_PERM,
5187                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5188                                   NL80211_FLAG_NEED_RTNL,
5189         },
5190         {
5191                 .cmd = NL80211_CMD_LEAVE_MESH,
5192                 .doit = nl80211_leave_mesh,
5193                 .policy = nl80211_policy,
5194                 .flags = GENL_ADMIN_PERM,
5195                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
5196                                   NL80211_FLAG_NEED_RTNL,
5197         },
5198 };
5199
5200 static struct genl_multicast_group nl80211_mlme_mcgrp = {
5201         .name = "mlme",
5202 };
5203
5204 /* multicast groups */
5205 static struct genl_multicast_group nl80211_config_mcgrp = {
5206         .name = "config",
5207 };
5208 static struct genl_multicast_group nl80211_scan_mcgrp = {
5209         .name = "scan",
5210 };
5211 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
5212         .name = "regulatory",
5213 };
5214
5215 /* notification functions */
5216
5217 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
5218 {
5219         struct sk_buff *msg;
5220
5221         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5222         if (!msg)
5223                 return;
5224
5225         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5226                 nlmsg_free(msg);
5227                 return;
5228         }
5229
5230         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5231                                 nl80211_config_mcgrp.id, GFP_KERNEL);
5232 }
5233
5234 static int nl80211_add_scan_req(struct sk_buff *msg,
5235                                 struct cfg80211_registered_device *rdev)
5236 {
5237         struct cfg80211_scan_request *req = rdev->scan_req;
5238         struct nlattr *nest;
5239         int i;
5240
5241         ASSERT_RDEV_LOCK(rdev);
5242
5243         if (WARN_ON(!req))
5244                 return 0;
5245
5246         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5247         if (!nest)
5248                 goto nla_put_failure;
5249         for (i = 0; i < req->n_ssids; i++)
5250                 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5251         nla_nest_end(msg, nest);
5252
5253         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5254         if (!nest)
5255                 goto nla_put_failure;
5256         for (i = 0; i < req->n_channels; i++)
5257                 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5258         nla_nest_end(msg, nest);
5259
5260         if (req->ie)
5261                 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5262
5263         return 0;
5264  nla_put_failure:
5265         return -ENOBUFS;
5266 }
5267
5268 static int nl80211_send_scan_msg(struct sk_buff *msg,
5269                                  struct cfg80211_registered_device *rdev,
5270                                  struct net_device *netdev,
5271                                  u32 pid, u32 seq, int flags,
5272                                  u32 cmd)
5273 {
5274         void *hdr;
5275
5276         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5277         if (!hdr)
5278                 return -1;
5279
5280         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5281         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5282
5283         /* ignore errors and send incomplete event anyway */
5284         nl80211_add_scan_req(msg, rdev);
5285
5286         return genlmsg_end(msg, hdr);
5287
5288  nla_put_failure:
5289         genlmsg_cancel(msg, hdr);
5290         return -EMSGSIZE;
5291 }
5292
5293 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5294                              struct net_device *netdev)
5295 {
5296         struct sk_buff *msg;
5297
5298         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5299         if (!msg)
5300                 return;
5301
5302         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5303                                   NL80211_CMD_TRIGGER_SCAN) < 0) {
5304                 nlmsg_free(msg);
5305                 return;
5306         }
5307
5308         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5309                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
5310 }
5311
5312 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5313                             struct net_device *netdev)
5314 {
5315         struct sk_buff *msg;
5316
5317         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5318         if (!msg)
5319                 return;
5320
5321         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5322                                   NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
5323                 nlmsg_free(msg);
5324                 return;
5325         }
5326
5327         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5328                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
5329 }
5330
5331 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5332                                struct net_device *netdev)
5333 {
5334         struct sk_buff *msg;
5335
5336         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5337         if (!msg)
5338                 return;
5339
5340         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5341                                   NL80211_CMD_SCAN_ABORTED) < 0) {
5342                 nlmsg_free(msg);
5343                 return;
5344         }
5345
5346         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5347                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
5348 }
5349
5350 /*
5351  * This can happen on global regulatory changes or device specific settings
5352  * based on custom world regulatory domains.
5353  */
5354 void nl80211_send_reg_change_event(struct regulatory_request *request)
5355 {
5356         struct sk_buff *msg;
5357         void *hdr;
5358
5359         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5360         if (!msg)
5361                 return;
5362
5363         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5364         if (!hdr) {
5365                 nlmsg_free(msg);
5366                 return;
5367         }
5368
5369         /* Userspace can always count this one always being set */
5370         NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5371
5372         if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5373                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5374                            NL80211_REGDOM_TYPE_WORLD);
5375         else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5376                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5377                            NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5378         else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5379                  request->intersect)
5380                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5381                            NL80211_REGDOM_TYPE_INTERSECTION);
5382         else {
5383                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5384                            NL80211_REGDOM_TYPE_COUNTRY);
5385                 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5386         }
5387
5388         if (wiphy_idx_valid(request->wiphy_idx))
5389                 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5390
5391         if (genlmsg_end(msg, hdr) < 0) {
5392                 nlmsg_free(msg);
5393                 return;
5394         }
5395
5396         rcu_read_lock();
5397         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5398                                 GFP_ATOMIC);
5399         rcu_read_unlock();
5400
5401         return;
5402
5403 nla_put_failure:
5404         genlmsg_cancel(msg, hdr);
5405         nlmsg_free(msg);
5406 }
5407
5408 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5409                                     struct net_device *netdev,
5410                                     const u8 *buf, size_t len,
5411                                     enum nl80211_commands cmd, gfp_t gfp)
5412 {
5413         struct sk_buff *msg;
5414         void *hdr;
5415
5416         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5417         if (!msg)
5418                 return;
5419
5420         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5421         if (!hdr) {
5422                 nlmsg_free(msg);
5423                 return;
5424         }
5425
5426         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5427         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5428         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5429
5430         if (genlmsg_end(msg, hdr) < 0) {
5431                 nlmsg_free(msg);
5432                 return;
5433         }
5434
5435         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5436                                 nl80211_mlme_mcgrp.id, gfp);
5437         return;
5438
5439  nla_put_failure:
5440         genlmsg_cancel(msg, hdr);
5441         nlmsg_free(msg);
5442 }
5443
5444 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
5445                           struct net_device *netdev, const u8 *buf,
5446                           size_t len, gfp_t gfp)
5447 {
5448         nl80211_send_mlme_event(rdev, netdev, buf, len,
5449                                 NL80211_CMD_AUTHENTICATE, gfp);
5450 }
5451
5452 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5453                            struct net_device *netdev, const u8 *buf,
5454                            size_t len, gfp_t gfp)
5455 {
5456         nl80211_send_mlme_event(rdev, netdev, buf, len,
5457                                 NL80211_CMD_ASSOCIATE, gfp);
5458 }
5459
5460 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
5461                          struct net_device *netdev, const u8 *buf,
5462                          size_t len, gfp_t gfp)
5463 {
5464         nl80211_send_mlme_event(rdev, netdev, buf, len,
5465                                 NL80211_CMD_DEAUTHENTICATE, gfp);
5466 }
5467
5468 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5469                            struct net_device *netdev, const u8 *buf,
5470                            size_t len, gfp_t gfp)
5471 {
5472         nl80211_send_mlme_event(rdev, netdev, buf, len,
5473                                 NL80211_CMD_DISASSOCIATE, gfp);
5474 }
5475
5476 void nl80211_send_unprot_deauth(struct cfg80211_registered_device *rdev,
5477                                 struct net_device *netdev, const u8 *buf,
5478                                 size_t len, gfp_t gfp)
5479 {
5480         nl80211_send_mlme_event(rdev, netdev, buf, len,
5481                                 NL80211_CMD_UNPROT_DEAUTHENTICATE, gfp);
5482 }
5483
5484 void nl80211_send_unprot_disassoc(struct cfg80211_registered_device *rdev,
5485                                   struct net_device *netdev, const u8 *buf,
5486                                   size_t len, gfp_t gfp)
5487 {
5488         nl80211_send_mlme_event(rdev, netdev, buf, len,
5489                                 NL80211_CMD_UNPROT_DISASSOCIATE, gfp);
5490 }
5491
5492 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5493                                       struct net_device *netdev, int cmd,
5494                                       const u8 *addr, gfp_t gfp)
5495 {
5496         struct sk_buff *msg;
5497         void *hdr;
5498
5499         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5500         if (!msg)
5501                 return;
5502
5503         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5504         if (!hdr) {
5505                 nlmsg_free(msg);
5506                 return;
5507         }
5508
5509         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5510         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5511         NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5512         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5513
5514         if (genlmsg_end(msg, hdr) < 0) {
5515                 nlmsg_free(msg);
5516                 return;
5517         }
5518
5519         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5520                                 nl80211_mlme_mcgrp.id, gfp);
5521         return;
5522
5523  nla_put_failure:
5524         genlmsg_cancel(msg, hdr);
5525         nlmsg_free(msg);
5526 }
5527
5528 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
5529                                struct net_device *netdev, const u8 *addr,
5530                                gfp_t gfp)
5531 {
5532         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
5533                                   addr, gfp);
5534 }
5535
5536 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
5537                                 struct net_device *netdev, const u8 *addr,
5538                                 gfp_t gfp)
5539 {
5540         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5541                                   addr, gfp);
5542 }
5543
5544 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5545                                  struct net_device *netdev, const u8 *bssid,
5546                                  const u8 *req_ie, size_t req_ie_len,
5547                                  const u8 *resp_ie, size_t resp_ie_len,
5548                                  u16 status, gfp_t gfp)
5549 {
5550         struct sk_buff *msg;
5551         void *hdr;
5552
5553         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5554         if (!msg)
5555                 return;
5556
5557         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5558         if (!hdr) {
5559                 nlmsg_free(msg);
5560                 return;
5561         }
5562
5563         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5564         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5565         if (bssid)
5566                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5567         NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5568         if (req_ie)
5569                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5570         if (resp_ie)
5571                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5572
5573         if (genlmsg_end(msg, hdr) < 0) {
5574                 nlmsg_free(msg);
5575                 return;
5576         }
5577
5578         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5579                                 nl80211_mlme_mcgrp.id, gfp);
5580         return;
5581
5582  nla_put_failure:
5583         genlmsg_cancel(msg, hdr);
5584         nlmsg_free(msg);
5585
5586 }
5587
5588 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5589                          struct net_device *netdev, const u8 *bssid,
5590                          const u8 *req_ie, size_t req_ie_len,
5591                          const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5592 {
5593         struct sk_buff *msg;
5594         void *hdr;
5595
5596         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5597         if (!msg)
5598                 return;
5599
5600         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5601         if (!hdr) {
5602                 nlmsg_free(msg);
5603                 return;
5604         }
5605
5606         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5607         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5608         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5609         if (req_ie)
5610                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5611         if (resp_ie)
5612                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5613
5614         if (genlmsg_end(msg, hdr) < 0) {
5615                 nlmsg_free(msg);
5616                 return;
5617         }
5618
5619         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5620                                 nl80211_mlme_mcgrp.id, gfp);
5621         return;
5622
5623  nla_put_failure:
5624         genlmsg_cancel(msg, hdr);
5625         nlmsg_free(msg);
5626
5627 }
5628
5629 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5630                                struct net_device *netdev, u16 reason,
5631                                const u8 *ie, size_t ie_len, bool from_ap)
5632 {
5633         struct sk_buff *msg;
5634         void *hdr;
5635
5636         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5637         if (!msg)
5638                 return;
5639
5640         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5641         if (!hdr) {
5642                 nlmsg_free(msg);
5643                 return;
5644         }
5645
5646         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5647         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5648         if (from_ap && reason)
5649                 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5650         if (from_ap)
5651                 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5652         if (ie)
5653                 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5654
5655         if (genlmsg_end(msg, hdr) < 0) {
5656                 nlmsg_free(msg);
5657                 return;
5658         }
5659
5660         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5661                                 nl80211_mlme_mcgrp.id, GFP_KERNEL);
5662         return;
5663
5664  nla_put_failure:
5665         genlmsg_cancel(msg, hdr);
5666         nlmsg_free(msg);
5667
5668 }
5669
5670 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5671                              struct net_device *netdev, const u8 *bssid,
5672                              gfp_t gfp)
5673 {
5674         struct sk_buff *msg;
5675         void *hdr;
5676
5677         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5678         if (!msg)
5679                 return;
5680
5681         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5682         if (!hdr) {
5683                 nlmsg_free(msg);
5684                 return;
5685         }
5686
5687         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5688         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5689         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5690
5691         if (genlmsg_end(msg, hdr) < 0) {
5692                 nlmsg_free(msg);
5693                 return;
5694         }
5695
5696         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5697                                 nl80211_mlme_mcgrp.id, gfp);
5698         return;
5699
5700  nla_put_failure:
5701         genlmsg_cancel(msg, hdr);
5702         nlmsg_free(msg);
5703 }
5704
5705 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5706                                  struct net_device *netdev, const u8 *addr,
5707                                  enum nl80211_key_type key_type, int key_id,
5708                                  const u8 *tsc, gfp_t gfp)
5709 {
5710         struct sk_buff *msg;
5711         void *hdr;
5712
5713         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5714         if (!msg)
5715                 return;
5716
5717         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5718         if (!hdr) {
5719                 nlmsg_free(msg);
5720                 return;
5721         }
5722
5723         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5724         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5725         if (addr)
5726                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5727         NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5728         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5729         if (tsc)
5730                 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5731
5732         if (genlmsg_end(msg, hdr) < 0) {
5733                 nlmsg_free(msg);
5734                 return;
5735         }
5736
5737         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5738                                 nl80211_mlme_mcgrp.id, gfp);
5739         return;
5740
5741  nla_put_failure:
5742         genlmsg_cancel(msg, hdr);
5743         nlmsg_free(msg);
5744 }
5745
5746 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5747                                     struct ieee80211_channel *channel_before,
5748                                     struct ieee80211_channel *channel_after)
5749 {
5750         struct sk_buff *msg;
5751         void *hdr;
5752         struct nlattr *nl_freq;
5753
5754         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
5755         if (!msg)
5756                 return;
5757
5758         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5759         if (!hdr) {
5760                 nlmsg_free(msg);
5761                 return;
5762         }
5763
5764         /*
5765          * Since we are applying the beacon hint to a wiphy we know its
5766          * wiphy_idx is valid
5767          */
5768         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5769
5770         /* Before */
5771         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5772         if (!nl_freq)
5773                 goto nla_put_failure;
5774         if (nl80211_msg_put_channel(msg, channel_before))
5775                 goto nla_put_failure;
5776         nla_nest_end(msg, nl_freq);
5777
5778         /* After */
5779         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5780         if (!nl_freq)
5781                 goto nla_put_failure;
5782         if (nl80211_msg_put_channel(msg, channel_after))
5783                 goto nla_put_failure;
5784         nla_nest_end(msg, nl_freq);
5785
5786         if (genlmsg_end(msg, hdr) < 0) {
5787                 nlmsg_free(msg);
5788                 return;
5789         }
5790
5791         rcu_read_lock();
5792         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5793                                 GFP_ATOMIC);
5794         rcu_read_unlock();
5795
5796         return;
5797
5798 nla_put_failure:
5799         genlmsg_cancel(msg, hdr);
5800         nlmsg_free(msg);
5801 }
5802
5803 static void nl80211_send_remain_on_chan_event(
5804         int cmd, struct cfg80211_registered_device *rdev,
5805         struct net_device *netdev, u64 cookie,
5806         struct ieee80211_channel *chan,
5807         enum nl80211_channel_type channel_type,
5808         unsigned int duration, gfp_t gfp)
5809 {
5810         struct sk_buff *msg;
5811         void *hdr;
5812
5813         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5814         if (!msg)
5815                 return;
5816
5817         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5818         if (!hdr) {
5819                 nlmsg_free(msg);
5820                 return;
5821         }
5822
5823         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5824         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5825         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5826         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5827         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5828
5829         if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5830                 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5831
5832         if (genlmsg_end(msg, hdr) < 0) {
5833                 nlmsg_free(msg);
5834                 return;
5835         }
5836
5837         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5838                                 nl80211_mlme_mcgrp.id, gfp);
5839         return;
5840
5841  nla_put_failure:
5842         genlmsg_cancel(msg, hdr);
5843         nlmsg_free(msg);
5844 }
5845
5846 void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5847                                     struct net_device *netdev, u64 cookie,
5848                                     struct ieee80211_channel *chan,
5849                                     enum nl80211_channel_type channel_type,
5850                                     unsigned int duration, gfp_t gfp)
5851 {
5852         nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5853                                           rdev, netdev, cookie, chan,
5854                                           channel_type, duration, gfp);
5855 }
5856
5857 void nl80211_send_remain_on_channel_cancel(
5858         struct cfg80211_registered_device *rdev, struct net_device *netdev,
5859         u64 cookie, struct ieee80211_channel *chan,
5860         enum nl80211_channel_type channel_type, gfp_t gfp)
5861 {
5862         nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5863                                           rdev, netdev, cookie, chan,
5864                                           channel_type, 0, gfp);
5865 }
5866
5867 void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5868                             struct net_device *dev, const u8 *mac_addr,
5869                             struct station_info *sinfo, gfp_t gfp)
5870 {
5871         struct sk_buff *msg;
5872
5873         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5874         if (!msg)
5875                 return;
5876
5877         if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5878                 nlmsg_free(msg);
5879                 return;
5880         }
5881
5882         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5883                                 nl80211_mlme_mcgrp.id, gfp);
5884 }
5885
5886 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
5887                       struct net_device *netdev, u32 nlpid,
5888                       int freq, const u8 *buf, size_t len, gfp_t gfp)
5889 {
5890         struct sk_buff *msg;
5891         void *hdr;
5892         int err;
5893
5894         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5895         if (!msg)
5896                 return -ENOMEM;
5897
5898         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
5899         if (!hdr) {
5900                 nlmsg_free(msg);
5901                 return -ENOMEM;
5902         }
5903
5904         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5905         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5906         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
5907         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5908
5909         err = genlmsg_end(msg, hdr);
5910         if (err < 0) {
5911                 nlmsg_free(msg);
5912                 return err;
5913         }
5914
5915         err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
5916         if (err < 0)
5917                 return err;
5918         return 0;
5919
5920  nla_put_failure:
5921         genlmsg_cancel(msg, hdr);
5922         nlmsg_free(msg);
5923         return -ENOBUFS;
5924 }
5925
5926 void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
5927                                  struct net_device *netdev, u64 cookie,
5928                                  const u8 *buf, size_t len, bool ack,
5929                                  gfp_t gfp)
5930 {
5931         struct sk_buff *msg;
5932         void *hdr;
5933
5934         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5935         if (!msg)
5936                 return;
5937
5938         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
5939         if (!hdr) {
5940                 nlmsg_free(msg);
5941                 return;
5942         }
5943
5944         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5945         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5946         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5947         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5948         if (ack)
5949                 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
5950
5951         if (genlmsg_end(msg, hdr) < 0) {
5952                 nlmsg_free(msg);
5953                 return;
5954         }
5955
5956         genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
5957         return;
5958
5959  nla_put_failure:
5960         genlmsg_cancel(msg, hdr);
5961         nlmsg_free(msg);
5962 }
5963
5964 void
5965 nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
5966                              struct net_device *netdev,
5967                              enum nl80211_cqm_rssi_threshold_event rssi_event,
5968                              gfp_t gfp)
5969 {
5970         struct sk_buff *msg;
5971         struct nlattr *pinfoattr;
5972         void *hdr;
5973
5974         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5975         if (!msg)
5976                 return;
5977
5978         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
5979         if (!hdr) {
5980                 nlmsg_free(msg);
5981                 return;
5982         }
5983
5984         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5985         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5986
5987         pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
5988         if (!pinfoattr)
5989                 goto nla_put_failure;
5990
5991         NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
5992                     rssi_event);
5993
5994         nla_nest_end(msg, pinfoattr);
5995
5996         if (genlmsg_end(msg, hdr) < 0) {
5997                 nlmsg_free(msg);
5998                 return;
5999         }
6000
6001         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6002                                 nl80211_mlme_mcgrp.id, gfp);
6003         return;
6004
6005  nla_put_failure:
6006         genlmsg_cancel(msg, hdr);
6007         nlmsg_free(msg);
6008 }
6009
6010 void
6011 nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
6012                                 struct net_device *netdev, const u8 *peer,
6013                                 u32 num_packets, gfp_t gfp)
6014 {
6015         struct sk_buff *msg;
6016         struct nlattr *pinfoattr;
6017         void *hdr;
6018
6019         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
6020         if (!msg)
6021                 return;
6022
6023         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
6024         if (!hdr) {
6025                 nlmsg_free(msg);
6026                 return;
6027         }
6028
6029         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
6030         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
6031         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
6032
6033         pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
6034         if (!pinfoattr)
6035                 goto nla_put_failure;
6036
6037         NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
6038
6039         nla_nest_end(msg, pinfoattr);
6040
6041         if (genlmsg_end(msg, hdr) < 0) {
6042                 nlmsg_free(msg);
6043                 return;
6044         }
6045
6046         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
6047                                 nl80211_mlme_mcgrp.id, gfp);
6048         return;
6049
6050  nla_put_failure:
6051         genlmsg_cancel(msg, hdr);
6052         nlmsg_free(msg);
6053 }
6054
6055 static int nl80211_netlink_notify(struct notifier_block * nb,
6056                                   unsigned long state,
6057                                   void *_notify)
6058 {
6059         struct netlink_notify *notify = _notify;
6060         struct cfg80211_registered_device *rdev;
6061         struct wireless_dev *wdev;
6062
6063         if (state != NETLINK_URELEASE)
6064                 return NOTIFY_DONE;
6065
6066         rcu_read_lock();
6067
6068         list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
6069                 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
6070                         cfg80211_mlme_unregister_socket(wdev, notify->pid);
6071
6072         rcu_read_unlock();
6073
6074         return NOTIFY_DONE;
6075 }
6076
6077 static struct notifier_block nl80211_netlink_notifier = {
6078         .notifier_call = nl80211_netlink_notify,
6079 };
6080
6081 /* initialisation/exit functions */
6082
6083 int nl80211_init(void)
6084 {
6085         int err;
6086
6087         err = genl_register_family_with_ops(&nl80211_fam,
6088                 nl80211_ops, ARRAY_SIZE(nl80211_ops));
6089         if (err)
6090                 return err;
6091
6092         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
6093         if (err)
6094                 goto err_out;
6095
6096         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
6097         if (err)
6098                 goto err_out;
6099
6100         err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
6101         if (err)
6102                 goto err_out;
6103
6104         err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
6105         if (err)
6106                 goto err_out;
6107
6108 #ifdef CONFIG_NL80211_TESTMODE
6109         err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
6110         if (err)
6111                 goto err_out;
6112 #endif
6113
6114         err = netlink_register_notifier(&nl80211_netlink_notifier);
6115         if (err)
6116                 goto err_out;
6117
6118         return 0;
6119  err_out:
6120         genl_unregister_family(&nl80211_fam);
6121         return err;
6122 }
6123
6124 void nl80211_exit(void)
6125 {
6126         netlink_unregister_notifier(&nl80211_netlink_notifier);
6127         genl_unregister_family(&nl80211_fam);
6128 }