nl80211/mac80211: define and allow configuring mesh element TTL
[linux-block.git] / net / wireless / nl80211.c
1 /*
2  * This is the new netlink-based wireless configuration interface.
3  *
4  * Copyright 2006-2010  Johannes Berg <johannes@sipsolutions.net>
5  */
6
7 #include <linux/if.h>
8 #include <linux/module.h>
9 #include <linux/err.h>
10 #include <linux/slab.h>
11 #include <linux/list.h>
12 #include <linux/if_ether.h>
13 #include <linux/ieee80211.h>
14 #include <linux/nl80211.h>
15 #include <linux/rtnetlink.h>
16 #include <linux/netlink.h>
17 #include <linux/etherdevice.h>
18 #include <net/net_namespace.h>
19 #include <net/genetlink.h>
20 #include <net/cfg80211.h>
21 #include <net/sock.h>
22 #include "core.h"
23 #include "nl80211.h"
24 #include "reg.h"
25
26 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
27                             struct genl_info *info);
28 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
29                               struct genl_info *info);
30
31 /* the netlink family */
32 static struct genl_family nl80211_fam = {
33         .id = GENL_ID_GENERATE, /* don't bother with a hardcoded ID */
34         .name = "nl80211",      /* have users key off the name instead */
35         .hdrsize = 0,           /* no private header */
36         .version = 1,           /* no particular meaning now */
37         .maxattr = NL80211_ATTR_MAX,
38         .netnsok = true,
39         .pre_doit = nl80211_pre_doit,
40         .post_doit = nl80211_post_doit,
41 };
42
43 /* internal helper: get rdev and dev */
44 static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
45                                        struct cfg80211_registered_device **rdev,
46                                        struct net_device **dev)
47 {
48         struct nlattr **attrs = info->attrs;
49         int ifindex;
50
51         if (!attrs[NL80211_ATTR_IFINDEX])
52                 return -EINVAL;
53
54         ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
55         *dev = dev_get_by_index(genl_info_net(info), ifindex);
56         if (!*dev)
57                 return -ENODEV;
58
59         *rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
60         if (IS_ERR(*rdev)) {
61                 dev_put(*dev);
62                 return PTR_ERR(*rdev);
63         }
64
65         return 0;
66 }
67
68 /* policy for the attributes */
69 static const struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] = {
70         [NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
71         [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
72                                       .len = 20-1 },
73         [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
74         [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
75         [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
76         [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
77         [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
78         [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
79         [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
80         [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 },
81
82         [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
83         [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
84         [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
85
86         [NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
87         [NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
88
89         [NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
90         [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
91                                     .len = WLAN_MAX_KEY_LEN },
92         [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
93         [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
94         [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
95         [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
96         [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 },
97
98         [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
99         [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
100         [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
101                                        .len = IEEE80211_MAX_DATA_LEN },
102         [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
103                                        .len = IEEE80211_MAX_DATA_LEN },
104         [NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
105         [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
106         [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
107         [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
108                                                .len = NL80211_MAX_SUPP_RATES },
109         [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
110         [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
111         [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
112         [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
113                                 .len = IEEE80211_MAX_MESH_ID_LEN },
114         [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
115
116         [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
117         [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },
118
119         [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
120         [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
121         [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
122         [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
123                                            .len = NL80211_MAX_SUPP_RATES },
124
125         [NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },
126
127         [NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
128                                          .len = NL80211_HT_CAPABILITY_LEN },
129
130         [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
131         [NL80211_ATTR_IE] = { .type = NLA_BINARY,
132                               .len = IEEE80211_MAX_DATA_LEN },
133         [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
134         [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
135
136         [NL80211_ATTR_SSID] = { .type = NLA_BINARY,
137                                 .len = IEEE80211_MAX_SSID_LEN },
138         [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
139         [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
140         [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
141         [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
142         [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
143         [NL80211_ATTR_STA_FLAGS2] = {
144                 .len = sizeof(struct nl80211_sta_flag_update),
145         },
146         [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
147         [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 },
148         [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG },
149         [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
150         [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
151         [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
152         [NL80211_ATTR_PID] = { .type = NLA_U32 },
153         [NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
154         [NL80211_ATTR_PMKID] = { .type = NLA_BINARY,
155                                  .len = WLAN_PMKID_LEN },
156         [NL80211_ATTR_DURATION] = { .type = NLA_U32 },
157         [NL80211_ATTR_COOKIE] = { .type = NLA_U64 },
158         [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED },
159         [NL80211_ATTR_FRAME] = { .type = NLA_BINARY,
160                                  .len = IEEE80211_MAX_DATA_LEN },
161         [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, },
162         [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 },
163         [NL80211_ATTR_CQM] = { .type = NLA_NESTED, },
164         [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG },
165         [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 },
166         [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 },
167         [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 },
168         [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 },
169         [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 },
170         [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 },
171         [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 },
172         [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG },
173 };
174
175 /* policy for the key attributes */
176 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = {
177         [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
178         [NL80211_KEY_IDX] = { .type = NLA_U8 },
179         [NL80211_KEY_CIPHER] = { .type = NLA_U32 },
180         [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
181         [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
182         [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
183         [NL80211_KEY_TYPE] = { .type = NLA_U32 },
184 };
185
186 /* ifidx get helper */
187 static int nl80211_get_ifidx(struct netlink_callback *cb)
188 {
189         int res;
190
191         res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
192                           nl80211_fam.attrbuf, nl80211_fam.maxattr,
193                           nl80211_policy);
194         if (res)
195                 return res;
196
197         if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
198                 return -EINVAL;
199
200         res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
201         if (!res)
202                 return -EINVAL;
203         return res;
204 }
205
206 static int nl80211_prepare_netdev_dump(struct sk_buff *skb,
207                                        struct netlink_callback *cb,
208                                        struct cfg80211_registered_device **rdev,
209                                        struct net_device **dev)
210 {
211         int ifidx = cb->args[0];
212         int err;
213
214         if (!ifidx)
215                 ifidx = nl80211_get_ifidx(cb);
216         if (ifidx < 0)
217                 return ifidx;
218
219         cb->args[0] = ifidx;
220
221         rtnl_lock();
222
223         *dev = __dev_get_by_index(sock_net(skb->sk), ifidx);
224         if (!*dev) {
225                 err = -ENODEV;
226                 goto out_rtnl;
227         }
228
229         *rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
230         if (IS_ERR(*rdev)) {
231                 err = PTR_ERR(*rdev);
232                 goto out_rtnl;
233         }
234
235         return 0;
236  out_rtnl:
237         rtnl_unlock();
238         return err;
239 }
240
241 static void nl80211_finish_netdev_dump(struct cfg80211_registered_device *rdev)
242 {
243         cfg80211_unlock_rdev(rdev);
244         rtnl_unlock();
245 }
246
247 /* IE validation */
248 static bool is_valid_ie_attr(const struct nlattr *attr)
249 {
250         const u8 *pos;
251         int len;
252
253         if (!attr)
254                 return true;
255
256         pos = nla_data(attr);
257         len = nla_len(attr);
258
259         while (len) {
260                 u8 elemlen;
261
262                 if (len < 2)
263                         return false;
264                 len -= 2;
265
266                 elemlen = pos[1];
267                 if (elemlen > len)
268                         return false;
269
270                 len -= elemlen;
271                 pos += 2 + elemlen;
272         }
273
274         return true;
275 }
276
277 /* message building helper */
278 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
279                                    int flags, u8 cmd)
280 {
281         /* since there is no private header just add the generic one */
282         return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
283 }
284
285 static int nl80211_msg_put_channel(struct sk_buff *msg,
286                                    struct ieee80211_channel *chan)
287 {
288         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
289                     chan->center_freq);
290
291         if (chan->flags & IEEE80211_CHAN_DISABLED)
292                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
293         if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
294                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
295         if (chan->flags & IEEE80211_CHAN_NO_IBSS)
296                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
297         if (chan->flags & IEEE80211_CHAN_RADAR)
298                 NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);
299
300         NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
301                     DBM_TO_MBM(chan->max_power));
302
303         return 0;
304
305  nla_put_failure:
306         return -ENOBUFS;
307 }
308
309 /* netlink command implementations */
310
311 struct key_parse {
312         struct key_params p;
313         int idx;
314         int type;
315         bool def, defmgmt;
316 };
317
318 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
319 {
320         struct nlattr *tb[NL80211_KEY_MAX + 1];
321         int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
322                                    nl80211_key_policy);
323         if (err)
324                 return err;
325
326         k->def = !!tb[NL80211_KEY_DEFAULT];
327         k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];
328
329         if (tb[NL80211_KEY_IDX])
330                 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);
331
332         if (tb[NL80211_KEY_DATA]) {
333                 k->p.key = nla_data(tb[NL80211_KEY_DATA]);
334                 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
335         }
336
337         if (tb[NL80211_KEY_SEQ]) {
338                 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
339                 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
340         }
341
342         if (tb[NL80211_KEY_CIPHER])
343                 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);
344
345         if (tb[NL80211_KEY_TYPE]) {
346                 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]);
347                 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
348                         return -EINVAL;
349         }
350
351         return 0;
352 }
353
354 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
355 {
356         if (info->attrs[NL80211_ATTR_KEY_DATA]) {
357                 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
358                 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
359         }
360
361         if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
362                 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
363                 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
364         }
365
366         if (info->attrs[NL80211_ATTR_KEY_IDX])
367                 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
368
369         if (info->attrs[NL80211_ATTR_KEY_CIPHER])
370                 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);
371
372         k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
373         k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];
374
375         if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
376                 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
377                 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES)
378                         return -EINVAL;
379         }
380
381         return 0;
382 }
383
384 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
385 {
386         int err;
387
388         memset(k, 0, sizeof(*k));
389         k->idx = -1;
390         k->type = -1;
391
392         if (info->attrs[NL80211_ATTR_KEY])
393                 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
394         else
395                 err = nl80211_parse_key_old(info, k);
396
397         if (err)
398                 return err;
399
400         if (k->def && k->defmgmt)
401                 return -EINVAL;
402
403         if (k->idx != -1) {
404                 if (k->defmgmt) {
405                         if (k->idx < 4 || k->idx > 5)
406                                 return -EINVAL;
407                 } else if (k->def) {
408                         if (k->idx < 0 || k->idx > 3)
409                                 return -EINVAL;
410                 } else {
411                         if (k->idx < 0 || k->idx > 5)
412                                 return -EINVAL;
413                 }
414         }
415
416         return 0;
417 }
418
419 static struct cfg80211_cached_keys *
420 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
421                        struct nlattr *keys)
422 {
423         struct key_parse parse;
424         struct nlattr *key;
425         struct cfg80211_cached_keys *result;
426         int rem, err, def = 0;
427
428         result = kzalloc(sizeof(*result), GFP_KERNEL);
429         if (!result)
430                 return ERR_PTR(-ENOMEM);
431
432         result->def = -1;
433         result->defmgmt = -1;
434
435         nla_for_each_nested(key, keys, rem) {
436                 memset(&parse, 0, sizeof(parse));
437                 parse.idx = -1;
438
439                 err = nl80211_parse_key_new(key, &parse);
440                 if (err)
441                         goto error;
442                 err = -EINVAL;
443                 if (!parse.p.key)
444                         goto error;
445                 if (parse.idx < 0 || parse.idx > 4)
446                         goto error;
447                 if (parse.def) {
448                         if (def)
449                                 goto error;
450                         def = 1;
451                         result->def = parse.idx;
452                 } else if (parse.defmgmt)
453                         goto error;
454                 err = cfg80211_validate_key_settings(rdev, &parse.p,
455                                                      parse.idx, false, NULL);
456                 if (err)
457                         goto error;
458                 result->params[parse.idx].cipher = parse.p.cipher;
459                 result->params[parse.idx].key_len = parse.p.key_len;
460                 result->params[parse.idx].key = result->data[parse.idx];
461                 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
462         }
463
464         return result;
465  error:
466         kfree(result);
467         return ERR_PTR(err);
468 }
469
470 static int nl80211_key_allowed(struct wireless_dev *wdev)
471 {
472         ASSERT_WDEV_LOCK(wdev);
473
474         switch (wdev->iftype) {
475         case NL80211_IFTYPE_AP:
476         case NL80211_IFTYPE_AP_VLAN:
477         case NL80211_IFTYPE_P2P_GO:
478                 break;
479         case NL80211_IFTYPE_ADHOC:
480                 if (!wdev->current_bss)
481                         return -ENOLINK;
482                 break;
483         case NL80211_IFTYPE_STATION:
484         case NL80211_IFTYPE_P2P_CLIENT:
485                 if (wdev->sme_state != CFG80211_SME_CONNECTED)
486                         return -ENOLINK;
487                 break;
488         default:
489                 return -EINVAL;
490         }
491
492         return 0;
493 }
494
495 static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
496                               struct cfg80211_registered_device *dev)
497 {
498         void *hdr;
499         struct nlattr *nl_bands, *nl_band;
500         struct nlattr *nl_freqs, *nl_freq;
501         struct nlattr *nl_rates, *nl_rate;
502         struct nlattr *nl_modes;
503         struct nlattr *nl_cmds;
504         enum ieee80211_band band;
505         struct ieee80211_channel *chan;
506         struct ieee80211_rate *rate;
507         int i;
508         u16 ifmodes = dev->wiphy.interface_modes;
509         const struct ieee80211_txrx_stypes *mgmt_stypes =
510                                 dev->wiphy.mgmt_stypes;
511
512         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
513         if (!hdr)
514                 return -1;
515
516         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
517         NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
518
519         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
520                     cfg80211_rdev_list_generation);
521
522         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
523                    dev->wiphy.retry_short);
524         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
525                    dev->wiphy.retry_long);
526         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
527                     dev->wiphy.frag_threshold);
528         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
529                     dev->wiphy.rts_threshold);
530         NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS,
531                     dev->wiphy.coverage_class);
532         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
533                    dev->wiphy.max_scan_ssids);
534         NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
535                     dev->wiphy.max_scan_ie_len);
536
537         if (dev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)
538                 NLA_PUT_FLAG(msg, NL80211_ATTR_SUPPORT_IBSS_RSN);
539
540         NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
541                 sizeof(u32) * dev->wiphy.n_cipher_suites,
542                 dev->wiphy.cipher_suites);
543
544         NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_PMKIDS,
545                    dev->wiphy.max_num_pmkids);
546
547         if (dev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL)
548                 NLA_PUT_FLAG(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE);
549
550         if (dev->ops->get_antenna) {
551                 u32 tx_ant = 0, rx_ant = 0;
552                 int res;
553                 res = dev->ops->get_antenna(&dev->wiphy, &tx_ant, &rx_ant);
554                 if (!res) {
555                         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_TX, tx_ant);
556                         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_ANTENNA_RX, rx_ant);
557                 }
558         }
559
560         nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
561         if (!nl_modes)
562                 goto nla_put_failure;
563
564         i = 0;
565         while (ifmodes) {
566                 if (ifmodes & 1)
567                         NLA_PUT_FLAG(msg, i);
568                 ifmodes >>= 1;
569                 i++;
570         }
571
572         nla_nest_end(msg, nl_modes);
573
574         nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
575         if (!nl_bands)
576                 goto nla_put_failure;
577
578         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
579                 if (!dev->wiphy.bands[band])
580                         continue;
581
582                 nl_band = nla_nest_start(msg, band);
583                 if (!nl_band)
584                         goto nla_put_failure;
585
586                 /* add HT info */
587                 if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
588                         NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
589                                 sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
590                                 &dev->wiphy.bands[band]->ht_cap.mcs);
591                         NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
592                                 dev->wiphy.bands[band]->ht_cap.cap);
593                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
594                                 dev->wiphy.bands[band]->ht_cap.ampdu_factor);
595                         NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
596                                 dev->wiphy.bands[band]->ht_cap.ampdu_density);
597                 }
598
599                 /* add frequencies */
600                 nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
601                 if (!nl_freqs)
602                         goto nla_put_failure;
603
604                 for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
605                         nl_freq = nla_nest_start(msg, i);
606                         if (!nl_freq)
607                                 goto nla_put_failure;
608
609                         chan = &dev->wiphy.bands[band]->channels[i];
610
611                         if (nl80211_msg_put_channel(msg, chan))
612                                 goto nla_put_failure;
613
614                         nla_nest_end(msg, nl_freq);
615                 }
616
617                 nla_nest_end(msg, nl_freqs);
618
619                 /* add bitrates */
620                 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
621                 if (!nl_rates)
622                         goto nla_put_failure;
623
624                 for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
625                         nl_rate = nla_nest_start(msg, i);
626                         if (!nl_rate)
627                                 goto nla_put_failure;
628
629                         rate = &dev->wiphy.bands[band]->bitrates[i];
630                         NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
631                                     rate->bitrate);
632                         if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
633                                 NLA_PUT_FLAG(msg,
634                                         NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);
635
636                         nla_nest_end(msg, nl_rate);
637                 }
638
639                 nla_nest_end(msg, nl_rates);
640
641                 nla_nest_end(msg, nl_band);
642         }
643         nla_nest_end(msg, nl_bands);
644
645         nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
646         if (!nl_cmds)
647                 goto nla_put_failure;
648
649         i = 0;
650 #define CMD(op, n)                                              \
651          do {                                                   \
652                 if (dev->ops->op) {                             \
653                         i++;                                    \
654                         NLA_PUT_U32(msg, i, NL80211_CMD_ ## n); \
655                 }                                               \
656         } while (0)
657
658         CMD(add_virtual_intf, NEW_INTERFACE);
659         CMD(change_virtual_intf, SET_INTERFACE);
660         CMD(add_key, NEW_KEY);
661         CMD(add_beacon, NEW_BEACON);
662         CMD(add_station, NEW_STATION);
663         CMD(add_mpath, NEW_MPATH);
664         CMD(set_mesh_params, SET_MESH_PARAMS);
665         CMD(change_bss, SET_BSS);
666         CMD(auth, AUTHENTICATE);
667         CMD(assoc, ASSOCIATE);
668         CMD(deauth, DEAUTHENTICATE);
669         CMD(disassoc, DISASSOCIATE);
670         CMD(join_ibss, JOIN_IBSS);
671         CMD(set_pmksa, SET_PMKSA);
672         CMD(del_pmksa, DEL_PMKSA);
673         CMD(flush_pmksa, FLUSH_PMKSA);
674         CMD(remain_on_channel, REMAIN_ON_CHANNEL);
675         CMD(set_bitrate_mask, SET_TX_BITRATE_MASK);
676         CMD(mgmt_tx, FRAME);
677         CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL);
678         if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
679                 i++;
680                 NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
681         }
682         CMD(set_channel, SET_CHANNEL);
683         CMD(set_wds_peer, SET_WDS_PEER);
684
685 #undef CMD
686
687         if (dev->ops->connect || dev->ops->auth) {
688                 i++;
689                 NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
690         }
691
692         if (dev->ops->disconnect || dev->ops->deauth) {
693                 i++;
694                 NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
695         }
696
697         nla_nest_end(msg, nl_cmds);
698
699         /* for now at least assume all drivers have it */
700         if (dev->ops->mgmt_tx)
701                 NLA_PUT_FLAG(msg, NL80211_ATTR_OFFCHANNEL_TX_OK);
702
703         if (mgmt_stypes) {
704                 u16 stypes;
705                 struct nlattr *nl_ftypes, *nl_ifs;
706                 enum nl80211_iftype ift;
707
708                 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES);
709                 if (!nl_ifs)
710                         goto nla_put_failure;
711
712                 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
713                         nl_ftypes = nla_nest_start(msg, ift);
714                         if (!nl_ftypes)
715                                 goto nla_put_failure;
716                         i = 0;
717                         stypes = mgmt_stypes[ift].tx;
718                         while (stypes) {
719                                 if (stypes & 1)
720                                         NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
721                                                     (i << 4) | IEEE80211_FTYPE_MGMT);
722                                 stypes >>= 1;
723                                 i++;
724                         }
725                         nla_nest_end(msg, nl_ftypes);
726                 }
727
728                 nla_nest_end(msg, nl_ifs);
729
730                 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES);
731                 if (!nl_ifs)
732                         goto nla_put_failure;
733
734                 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) {
735                         nl_ftypes = nla_nest_start(msg, ift);
736                         if (!nl_ftypes)
737                                 goto nla_put_failure;
738                         i = 0;
739                         stypes = mgmt_stypes[ift].rx;
740                         while (stypes) {
741                                 if (stypes & 1)
742                                         NLA_PUT_U16(msg, NL80211_ATTR_FRAME_TYPE,
743                                                     (i << 4) | IEEE80211_FTYPE_MGMT);
744                                 stypes >>= 1;
745                                 i++;
746                         }
747                         nla_nest_end(msg, nl_ftypes);
748                 }
749                 nla_nest_end(msg, nl_ifs);
750         }
751
752         return genlmsg_end(msg, hdr);
753
754  nla_put_failure:
755         genlmsg_cancel(msg, hdr);
756         return -EMSGSIZE;
757 }
758
759 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
760 {
761         int idx = 0;
762         int start = cb->args[0];
763         struct cfg80211_registered_device *dev;
764
765         mutex_lock(&cfg80211_mutex);
766         list_for_each_entry(dev, &cfg80211_rdev_list, list) {
767                 if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
768                         continue;
769                 if (++idx <= start)
770                         continue;
771                 if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
772                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
773                                        dev) < 0) {
774                         idx--;
775                         break;
776                 }
777         }
778         mutex_unlock(&cfg80211_mutex);
779
780         cb->args[0] = idx;
781
782         return skb->len;
783 }
784
785 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
786 {
787         struct sk_buff *msg;
788         struct cfg80211_registered_device *dev = info->user_ptr[0];
789
790         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
791         if (!msg)
792                 return -ENOMEM;
793
794         if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0) {
795                 nlmsg_free(msg);
796                 return -ENOBUFS;
797         }
798
799         return genlmsg_reply(msg, info);
800 }
801
802 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
803         [NL80211_TXQ_ATTR_QUEUE]                = { .type = NLA_U8 },
804         [NL80211_TXQ_ATTR_TXOP]                 = { .type = NLA_U16 },
805         [NL80211_TXQ_ATTR_CWMIN]                = { .type = NLA_U16 },
806         [NL80211_TXQ_ATTR_CWMAX]                = { .type = NLA_U16 },
807         [NL80211_TXQ_ATTR_AIFS]                 = { .type = NLA_U8 },
808 };
809
810 static int parse_txq_params(struct nlattr *tb[],
811                             struct ieee80211_txq_params *txq_params)
812 {
813         if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
814             !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
815             !tb[NL80211_TXQ_ATTR_AIFS])
816                 return -EINVAL;
817
818         txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
819         txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
820         txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
821         txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
822         txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);
823
824         return 0;
825 }
826
827 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev)
828 {
829         /*
830          * You can only set the channel explicitly for AP, mesh
831          * and WDS type interfaces; all others have their channel
832          * managed via their respective "establish a connection"
833          * command (connect, join, ...)
834          *
835          * Monitors are special as they are normally slaved to
836          * whatever else is going on, so they behave as though
837          * you tried setting the wiphy channel itself.
838          */
839         return !wdev ||
840                 wdev->iftype == NL80211_IFTYPE_AP ||
841                 wdev->iftype == NL80211_IFTYPE_WDS ||
842                 wdev->iftype == NL80211_IFTYPE_MESH_POINT ||
843                 wdev->iftype == NL80211_IFTYPE_MONITOR ||
844                 wdev->iftype == NL80211_IFTYPE_P2P_GO;
845 }
846
847 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev,
848                                  struct wireless_dev *wdev,
849                                  struct genl_info *info)
850 {
851         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
852         u32 freq;
853         int result;
854
855         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
856                 return -EINVAL;
857
858         if (!nl80211_can_set_dev_channel(wdev))
859                 return -EOPNOTSUPP;
860
861         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
862                 channel_type = nla_get_u32(info->attrs[
863                                    NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
864                 if (channel_type != NL80211_CHAN_NO_HT &&
865                     channel_type != NL80211_CHAN_HT20 &&
866                     channel_type != NL80211_CHAN_HT40PLUS &&
867                     channel_type != NL80211_CHAN_HT40MINUS)
868                         return -EINVAL;
869         }
870
871         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
872
873         mutex_lock(&rdev->devlist_mtx);
874         if (wdev) {
875                 wdev_lock(wdev);
876                 result = cfg80211_set_freq(rdev, wdev, freq, channel_type);
877                 wdev_unlock(wdev);
878         } else {
879                 result = cfg80211_set_freq(rdev, NULL, freq, channel_type);
880         }
881         mutex_unlock(&rdev->devlist_mtx);
882
883         return result;
884 }
885
886 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info)
887 {
888         struct cfg80211_registered_device *rdev = info->user_ptr[0];
889         struct net_device *netdev = info->user_ptr[1];
890
891         return __nl80211_set_channel(rdev, netdev->ieee80211_ptr, info);
892 }
893
894 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info)
895 {
896         struct cfg80211_registered_device *rdev = info->user_ptr[0];
897         struct net_device *dev = info->user_ptr[1];
898         struct wireless_dev *wdev = dev->ieee80211_ptr;
899         const u8 *bssid;
900
901         if (!info->attrs[NL80211_ATTR_MAC])
902                 return -EINVAL;
903
904         if (netif_running(dev))
905                 return -EBUSY;
906
907         if (!rdev->ops->set_wds_peer)
908                 return -EOPNOTSUPP;
909
910         if (wdev->iftype != NL80211_IFTYPE_WDS)
911                 return -EOPNOTSUPP;
912
913         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
914         return rdev->ops->set_wds_peer(wdev->wiphy, dev, bssid);
915 }
916
917
918 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
919 {
920         struct cfg80211_registered_device *rdev;
921         struct net_device *netdev = NULL;
922         struct wireless_dev *wdev;
923         int result = 0, rem_txq_params = 0;
924         struct nlattr *nl_txq_params;
925         u32 changed;
926         u8 retry_short = 0, retry_long = 0;
927         u32 frag_threshold = 0, rts_threshold = 0;
928         u8 coverage_class = 0;
929
930         /*
931          * Try to find the wiphy and netdev. Normally this
932          * function shouldn't need the netdev, but this is
933          * done for backward compatibility -- previously
934          * setting the channel was done per wiphy, but now
935          * it is per netdev. Previous userland like hostapd
936          * also passed a netdev to set_wiphy, so that it is
937          * possible to let that go to the right netdev!
938          */
939         mutex_lock(&cfg80211_mutex);
940
941         if (info->attrs[NL80211_ATTR_IFINDEX]) {
942                 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]);
943
944                 netdev = dev_get_by_index(genl_info_net(info), ifindex);
945                 if (netdev && netdev->ieee80211_ptr) {
946                         rdev = wiphy_to_dev(netdev->ieee80211_ptr->wiphy);
947                         mutex_lock(&rdev->mtx);
948                 } else
949                         netdev = NULL;
950         }
951
952         if (!netdev) {
953                 rdev = __cfg80211_rdev_from_info(info);
954                 if (IS_ERR(rdev)) {
955                         mutex_unlock(&cfg80211_mutex);
956                         return PTR_ERR(rdev);
957                 }
958                 wdev = NULL;
959                 netdev = NULL;
960                 result = 0;
961
962                 mutex_lock(&rdev->mtx);
963         } else if (netif_running(netdev) &&
964                    nl80211_can_set_dev_channel(netdev->ieee80211_ptr))
965                 wdev = netdev->ieee80211_ptr;
966         else
967                 wdev = NULL;
968
969         /*
970          * end workaround code, by now the rdev is available
971          * and locked, and wdev may or may not be NULL.
972          */
973
974         if (info->attrs[NL80211_ATTR_WIPHY_NAME])
975                 result = cfg80211_dev_rename(
976                         rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
977
978         mutex_unlock(&cfg80211_mutex);
979
980         if (result)
981                 goto bad_res;
982
983         if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
984                 struct ieee80211_txq_params txq_params;
985                 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];
986
987                 if (!rdev->ops->set_txq_params) {
988                         result = -EOPNOTSUPP;
989                         goto bad_res;
990                 }
991
992                 nla_for_each_nested(nl_txq_params,
993                                     info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
994                                     rem_txq_params) {
995                         nla_parse(tb, NL80211_TXQ_ATTR_MAX,
996                                   nla_data(nl_txq_params),
997                                   nla_len(nl_txq_params),
998                                   txq_params_policy);
999                         result = parse_txq_params(tb, &txq_params);
1000                         if (result)
1001                                 goto bad_res;
1002
1003                         result = rdev->ops->set_txq_params(&rdev->wiphy,
1004                                                            &txq_params);
1005                         if (result)
1006                                 goto bad_res;
1007                 }
1008         }
1009
1010         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
1011                 result = __nl80211_set_channel(rdev, wdev, info);
1012                 if (result)
1013                         goto bad_res;
1014         }
1015
1016         if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) {
1017                 enum nl80211_tx_power_setting type;
1018                 int idx, mbm = 0;
1019
1020                 if (!rdev->ops->set_tx_power) {
1021                         result = -EOPNOTSUPP;
1022                         goto bad_res;
1023                 }
1024
1025                 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING;
1026                 type = nla_get_u32(info->attrs[idx]);
1027
1028                 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] &&
1029                     (type != NL80211_TX_POWER_AUTOMATIC)) {
1030                         result = -EINVAL;
1031                         goto bad_res;
1032                 }
1033
1034                 if (type != NL80211_TX_POWER_AUTOMATIC) {
1035                         idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL;
1036                         mbm = nla_get_u32(info->attrs[idx]);
1037                 }
1038
1039                 result = rdev->ops->set_tx_power(&rdev->wiphy, type, mbm);
1040                 if (result)
1041                         goto bad_res;
1042         }
1043
1044         if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] &&
1045             info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) {
1046                 u32 tx_ant, rx_ant;
1047                 if (!rdev->ops->set_antenna) {
1048                         result = -EOPNOTSUPP;
1049                         goto bad_res;
1050                 }
1051
1052                 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]);
1053                 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]);
1054
1055                 result = rdev->ops->set_antenna(&rdev->wiphy, tx_ant, rx_ant);
1056                 if (result)
1057                         goto bad_res;
1058         }
1059
1060         changed = 0;
1061
1062         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
1063                 retry_short = nla_get_u8(
1064                         info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
1065                 if (retry_short == 0) {
1066                         result = -EINVAL;
1067                         goto bad_res;
1068                 }
1069                 changed |= WIPHY_PARAM_RETRY_SHORT;
1070         }
1071
1072         if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
1073                 retry_long = nla_get_u8(
1074                         info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
1075                 if (retry_long == 0) {
1076                         result = -EINVAL;
1077                         goto bad_res;
1078                 }
1079                 changed |= WIPHY_PARAM_RETRY_LONG;
1080         }
1081
1082         if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
1083                 frag_threshold = nla_get_u32(
1084                         info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
1085                 if (frag_threshold < 256) {
1086                         result = -EINVAL;
1087                         goto bad_res;
1088                 }
1089                 if (frag_threshold != (u32) -1) {
1090                         /*
1091                          * Fragments (apart from the last one) are required to
1092                          * have even length. Make the fragmentation code
1093                          * simpler by stripping LSB should someone try to use
1094                          * odd threshold value.
1095                          */
1096                         frag_threshold &= ~0x1;
1097                 }
1098                 changed |= WIPHY_PARAM_FRAG_THRESHOLD;
1099         }
1100
1101         if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
1102                 rts_threshold = nla_get_u32(
1103                         info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
1104                 changed |= WIPHY_PARAM_RTS_THRESHOLD;
1105         }
1106
1107         if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) {
1108                 coverage_class = nla_get_u8(
1109                         info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]);
1110                 changed |= WIPHY_PARAM_COVERAGE_CLASS;
1111         }
1112
1113         if (changed) {
1114                 u8 old_retry_short, old_retry_long;
1115                 u32 old_frag_threshold, old_rts_threshold;
1116                 u8 old_coverage_class;
1117
1118                 if (!rdev->ops->set_wiphy_params) {
1119                         result = -EOPNOTSUPP;
1120                         goto bad_res;
1121                 }
1122
1123                 old_retry_short = rdev->wiphy.retry_short;
1124                 old_retry_long = rdev->wiphy.retry_long;
1125                 old_frag_threshold = rdev->wiphy.frag_threshold;
1126                 old_rts_threshold = rdev->wiphy.rts_threshold;
1127                 old_coverage_class = rdev->wiphy.coverage_class;
1128
1129                 if (changed & WIPHY_PARAM_RETRY_SHORT)
1130                         rdev->wiphy.retry_short = retry_short;
1131                 if (changed & WIPHY_PARAM_RETRY_LONG)
1132                         rdev->wiphy.retry_long = retry_long;
1133                 if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
1134                         rdev->wiphy.frag_threshold = frag_threshold;
1135                 if (changed & WIPHY_PARAM_RTS_THRESHOLD)
1136                         rdev->wiphy.rts_threshold = rts_threshold;
1137                 if (changed & WIPHY_PARAM_COVERAGE_CLASS)
1138                         rdev->wiphy.coverage_class = coverage_class;
1139
1140                 result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
1141                 if (result) {
1142                         rdev->wiphy.retry_short = old_retry_short;
1143                         rdev->wiphy.retry_long = old_retry_long;
1144                         rdev->wiphy.frag_threshold = old_frag_threshold;
1145                         rdev->wiphy.rts_threshold = old_rts_threshold;
1146                         rdev->wiphy.coverage_class = old_coverage_class;
1147                 }
1148         }
1149
1150  bad_res:
1151         mutex_unlock(&rdev->mtx);
1152         if (netdev)
1153                 dev_put(netdev);
1154         return result;
1155 }
1156
1157
1158 static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
1159                               struct cfg80211_registered_device *rdev,
1160                               struct net_device *dev)
1161 {
1162         void *hdr;
1163
1164         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
1165         if (!hdr)
1166                 return -1;
1167
1168         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1169         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
1170         NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
1171         NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
1172
1173         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
1174                     rdev->devlist_generation ^
1175                         (cfg80211_rdev_list_generation << 2));
1176
1177         return genlmsg_end(msg, hdr);
1178
1179  nla_put_failure:
1180         genlmsg_cancel(msg, hdr);
1181         return -EMSGSIZE;
1182 }
1183
1184 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
1185 {
1186         int wp_idx = 0;
1187         int if_idx = 0;
1188         int wp_start = cb->args[0];
1189         int if_start = cb->args[1];
1190         struct cfg80211_registered_device *rdev;
1191         struct wireless_dev *wdev;
1192
1193         mutex_lock(&cfg80211_mutex);
1194         list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
1195                 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
1196                         continue;
1197                 if (wp_idx < wp_start) {
1198                         wp_idx++;
1199                         continue;
1200                 }
1201                 if_idx = 0;
1202
1203                 mutex_lock(&rdev->devlist_mtx);
1204                 list_for_each_entry(wdev, &rdev->netdev_list, list) {
1205                         if (if_idx < if_start) {
1206                                 if_idx++;
1207                                 continue;
1208                         }
1209                         if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
1210                                                cb->nlh->nlmsg_seq, NLM_F_MULTI,
1211                                                rdev, wdev->netdev) < 0) {
1212                                 mutex_unlock(&rdev->devlist_mtx);
1213                                 goto out;
1214                         }
1215                         if_idx++;
1216                 }
1217                 mutex_unlock(&rdev->devlist_mtx);
1218
1219                 wp_idx++;
1220         }
1221  out:
1222         mutex_unlock(&cfg80211_mutex);
1223
1224         cb->args[0] = wp_idx;
1225         cb->args[1] = if_idx;
1226
1227         return skb->len;
1228 }
1229
1230 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
1231 {
1232         struct sk_buff *msg;
1233         struct cfg80211_registered_device *dev = info->user_ptr[0];
1234         struct net_device *netdev = info->user_ptr[1];
1235
1236         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1237         if (!msg)
1238                 return -ENOMEM;
1239
1240         if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
1241                                dev, netdev) < 0) {
1242                 nlmsg_free(msg);
1243                 return -ENOBUFS;
1244         }
1245
1246         return genlmsg_reply(msg, info);
1247 }
1248
1249 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
1250         [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
1251         [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
1252         [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
1253         [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
1254         [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
1255 };
1256
1257 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
1258 {
1259         struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
1260         int flag;
1261
1262         *mntrflags = 0;
1263
1264         if (!nla)
1265                 return -EINVAL;
1266
1267         if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
1268                              nla, mntr_flags_policy))
1269                 return -EINVAL;
1270
1271         for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
1272                 if (flags[flag])
1273                         *mntrflags |= (1<<flag);
1274
1275         return 0;
1276 }
1277
1278 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev,
1279                                struct net_device *netdev, u8 use_4addr,
1280                                enum nl80211_iftype iftype)
1281 {
1282         if (!use_4addr) {
1283                 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT))
1284                         return -EBUSY;
1285                 return 0;
1286         }
1287
1288         switch (iftype) {
1289         case NL80211_IFTYPE_AP_VLAN:
1290                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP)
1291                         return 0;
1292                 break;
1293         case NL80211_IFTYPE_STATION:
1294                 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION)
1295                         return 0;
1296                 break;
1297         default:
1298                 break;
1299         }
1300
1301         return -EOPNOTSUPP;
1302 }
1303
1304 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
1305 {
1306         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1307         struct vif_params params;
1308         int err;
1309         enum nl80211_iftype otype, ntype;
1310         struct net_device *dev = info->user_ptr[1];
1311         u32 _flags, *flags = NULL;
1312         bool change = false;
1313
1314         memset(&params, 0, sizeof(params));
1315
1316         otype = ntype = dev->ieee80211_ptr->iftype;
1317
1318         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1319                 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1320                 if (otype != ntype)
1321                         change = true;
1322                 if (ntype > NL80211_IFTYPE_MAX)
1323                         return -EINVAL;
1324         }
1325
1326         if (info->attrs[NL80211_ATTR_MESH_ID]) {
1327                 if (ntype != NL80211_IFTYPE_MESH_POINT)
1328                         return -EINVAL;
1329                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1330                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1331                 change = true;
1332         }
1333
1334         if (info->attrs[NL80211_ATTR_4ADDR]) {
1335                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1336                 change = true;
1337                 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype);
1338                 if (err)
1339                         return err;
1340         } else {
1341                 params.use_4addr = -1;
1342         }
1343
1344         if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
1345                 if (ntype != NL80211_IFTYPE_MONITOR)
1346                         return -EINVAL;
1347                 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
1348                                           &_flags);
1349                 if (err)
1350                         return err;
1351
1352                 flags = &_flags;
1353                 change = true;
1354         }
1355
1356         if (change)
1357                 err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1358         else
1359                 err = 0;
1360
1361         if (!err && params.use_4addr != -1)
1362                 dev->ieee80211_ptr->use_4addr = params.use_4addr;
1363
1364         return err;
1365 }
1366
1367 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
1368 {
1369         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1370         struct vif_params params;
1371         int err;
1372         enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1373         u32 flags;
1374
1375         memset(&params, 0, sizeof(params));
1376
1377         if (!info->attrs[NL80211_ATTR_IFNAME])
1378                 return -EINVAL;
1379
1380         if (info->attrs[NL80211_ATTR_IFTYPE]) {
1381                 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
1382                 if (type > NL80211_IFTYPE_MAX)
1383                         return -EINVAL;
1384         }
1385
1386         if (!rdev->ops->add_virtual_intf ||
1387             !(rdev->wiphy.interface_modes & (1 << type)))
1388                 return -EOPNOTSUPP;
1389
1390         if (type == NL80211_IFTYPE_MESH_POINT &&
1391             info->attrs[NL80211_ATTR_MESH_ID]) {
1392                 params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
1393                 params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1394         }
1395
1396         if (info->attrs[NL80211_ATTR_4ADDR]) {
1397                 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
1398                 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type);
1399                 if (err)
1400                         return err;
1401         }
1402
1403         err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
1404                                   info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
1405                                   &flags);
1406         err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1407                 nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1408                 type, err ? NULL : &flags, &params);
1409
1410         return err;
1411 }
1412
1413 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
1414 {
1415         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1416         struct net_device *dev = info->user_ptr[1];
1417
1418         if (!rdev->ops->del_virtual_intf)
1419                 return -EOPNOTSUPP;
1420
1421         return rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1422 }
1423
1424 struct get_key_cookie {
1425         struct sk_buff *msg;
1426         int error;
1427         int idx;
1428 };
1429
1430 static void get_key_callback(void *c, struct key_params *params)
1431 {
1432         struct nlattr *key;
1433         struct get_key_cookie *cookie = c;
1434
1435         if (params->key)
1436                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
1437                         params->key_len, params->key);
1438
1439         if (params->seq)
1440                 NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
1441                         params->seq_len, params->seq);
1442
1443         if (params->cipher)
1444                 NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
1445                             params->cipher);
1446
1447         key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
1448         if (!key)
1449                 goto nla_put_failure;
1450
1451         if (params->key)
1452                 NLA_PUT(cookie->msg, NL80211_KEY_DATA,
1453                         params->key_len, params->key);
1454
1455         if (params->seq)
1456                 NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
1457                         params->seq_len, params->seq);
1458
1459         if (params->cipher)
1460                 NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
1461                             params->cipher);
1462
1463         NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);
1464
1465         nla_nest_end(cookie->msg, key);
1466
1467         return;
1468  nla_put_failure:
1469         cookie->error = 1;
1470 }
1471
1472 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
1473 {
1474         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1475         int err;
1476         struct net_device *dev = info->user_ptr[1];
1477         u8 key_idx = 0;
1478         const u8 *mac_addr = NULL;
1479         bool pairwise;
1480         struct get_key_cookie cookie = {
1481                 .error = 0,
1482         };
1483         void *hdr;
1484         struct sk_buff *msg;
1485
1486         if (info->attrs[NL80211_ATTR_KEY_IDX])
1487                 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);
1488
1489         if (key_idx > 5)
1490                 return -EINVAL;
1491
1492         if (info->attrs[NL80211_ATTR_MAC])
1493                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1494
1495         pairwise = !!mac_addr;
1496         if (info->attrs[NL80211_ATTR_KEY_TYPE]) {
1497                 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]);
1498                 if (kt >= NUM_NL80211_KEYTYPES)
1499                         return -EINVAL;
1500                 if (kt != NL80211_KEYTYPE_GROUP &&
1501                     kt != NL80211_KEYTYPE_PAIRWISE)
1502                         return -EINVAL;
1503                 pairwise = kt == NL80211_KEYTYPE_PAIRWISE;
1504         }
1505
1506         if (!rdev->ops->get_key)
1507                 return -EOPNOTSUPP;
1508
1509         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1510         if (!msg)
1511                 return -ENOMEM;
1512
1513         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
1514                              NL80211_CMD_NEW_KEY);
1515         if (IS_ERR(hdr))
1516                 return PTR_ERR(hdr);
1517
1518         cookie.msg = msg;
1519         cookie.idx = key_idx;
1520
1521         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1522         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
1523         if (mac_addr)
1524                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1525
1526         if (pairwise && mac_addr &&
1527             !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1528                 return -ENOENT;
1529
1530         err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, pairwise,
1531                                  mac_addr, &cookie, get_key_callback);
1532
1533         if (err)
1534                 goto free_msg;
1535
1536         if (cookie.error)
1537                 goto nla_put_failure;
1538
1539         genlmsg_end(msg, hdr);
1540         return genlmsg_reply(msg, info);
1541
1542  nla_put_failure:
1543         err = -ENOBUFS;
1544  free_msg:
1545         nlmsg_free(msg);
1546         return err;
1547 }
1548
1549 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
1550 {
1551         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1552         struct key_parse key;
1553         int err;
1554         struct net_device *dev = info->user_ptr[1];
1555         int (*func)(struct wiphy *wiphy, struct net_device *netdev,
1556                     u8 key_index);
1557
1558         err = nl80211_parse_key(info, &key);
1559         if (err)
1560                 return err;
1561
1562         if (key.idx < 0)
1563                 return -EINVAL;
1564
1565         /* only support setting default key */
1566         if (!key.def && !key.defmgmt)
1567                 return -EINVAL;
1568
1569         if (key.def)
1570                 func = rdev->ops->set_default_key;
1571         else
1572                 func = rdev->ops->set_default_mgmt_key;
1573
1574         if (!func)
1575                 return -EOPNOTSUPP;
1576
1577         wdev_lock(dev->ieee80211_ptr);
1578         err = nl80211_key_allowed(dev->ieee80211_ptr);
1579         if (!err)
1580                 err = func(&rdev->wiphy, dev, key.idx);
1581
1582 #ifdef CONFIG_CFG80211_WEXT
1583         if (!err) {
1584                 if (func == rdev->ops->set_default_key)
1585                         dev->ieee80211_ptr->wext.default_key = key.idx;
1586                 else
1587                         dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1588         }
1589 #endif
1590         wdev_unlock(dev->ieee80211_ptr);
1591
1592         return err;
1593 }
1594
1595 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
1596 {
1597         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1598         int err;
1599         struct net_device *dev = info->user_ptr[1];
1600         struct key_parse key;
1601         const u8 *mac_addr = NULL;
1602
1603         err = nl80211_parse_key(info, &key);
1604         if (err)
1605                 return err;
1606
1607         if (!key.p.key)
1608                 return -EINVAL;
1609
1610         if (info->attrs[NL80211_ATTR_MAC])
1611                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1612
1613         if (key.type == -1) {
1614                 if (mac_addr)
1615                         key.type = NL80211_KEYTYPE_PAIRWISE;
1616                 else
1617                         key.type = NL80211_KEYTYPE_GROUP;
1618         }
1619
1620         /* for now */
1621         if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1622             key.type != NL80211_KEYTYPE_GROUP)
1623                 return -EINVAL;
1624
1625         if (!rdev->ops->add_key)
1626                 return -EOPNOTSUPP;
1627
1628         if (cfg80211_validate_key_settings(rdev, &key.p, key.idx,
1629                                            key.type == NL80211_KEYTYPE_PAIRWISE,
1630                                            mac_addr))
1631                 return -EINVAL;
1632
1633         wdev_lock(dev->ieee80211_ptr);
1634         err = nl80211_key_allowed(dev->ieee80211_ptr);
1635         if (!err)
1636                 err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
1637                                          key.type == NL80211_KEYTYPE_PAIRWISE,
1638                                          mac_addr, &key.p);
1639         wdev_unlock(dev->ieee80211_ptr);
1640
1641         return err;
1642 }
1643
1644 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
1645 {
1646         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1647         int err;
1648         struct net_device *dev = info->user_ptr[1];
1649         u8 *mac_addr = NULL;
1650         struct key_parse key;
1651
1652         err = nl80211_parse_key(info, &key);
1653         if (err)
1654                 return err;
1655
1656         if (info->attrs[NL80211_ATTR_MAC])
1657                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1658
1659         if (key.type == -1) {
1660                 if (mac_addr)
1661                         key.type = NL80211_KEYTYPE_PAIRWISE;
1662                 else
1663                         key.type = NL80211_KEYTYPE_GROUP;
1664         }
1665
1666         /* for now */
1667         if (key.type != NL80211_KEYTYPE_PAIRWISE &&
1668             key.type != NL80211_KEYTYPE_GROUP)
1669                 return -EINVAL;
1670
1671         if (!rdev->ops->del_key)
1672                 return -EOPNOTSUPP;
1673
1674         wdev_lock(dev->ieee80211_ptr);
1675         err = nl80211_key_allowed(dev->ieee80211_ptr);
1676
1677         if (key.type == NL80211_KEYTYPE_PAIRWISE && mac_addr &&
1678             !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN))
1679                 err = -ENOENT;
1680
1681         if (!err)
1682                 err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx,
1683                                          key.type == NL80211_KEYTYPE_PAIRWISE,
1684                                          mac_addr);
1685
1686 #ifdef CONFIG_CFG80211_WEXT
1687         if (!err) {
1688                 if (key.idx == dev->ieee80211_ptr->wext.default_key)
1689                         dev->ieee80211_ptr->wext.default_key = -1;
1690                 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1691                         dev->ieee80211_ptr->wext.default_mgmt_key = -1;
1692         }
1693 #endif
1694         wdev_unlock(dev->ieee80211_ptr);
1695
1696         return err;
1697 }
1698
1699 static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
1700 {
1701         int (*call)(struct wiphy *wiphy, struct net_device *dev,
1702                     struct beacon_parameters *info);
1703         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1704         struct net_device *dev = info->user_ptr[1];
1705         struct beacon_parameters params;
1706         int haveinfo = 0;
1707
1708         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
1709                 return -EINVAL;
1710
1711         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1712             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1713                 return -EOPNOTSUPP;
1714
1715         switch (info->genlhdr->cmd) {
1716         case NL80211_CMD_NEW_BEACON:
1717                 /* these are required for NEW_BEACON */
1718                 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
1719                     !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
1720                     !info->attrs[NL80211_ATTR_BEACON_HEAD])
1721                         return -EINVAL;
1722
1723                 call = rdev->ops->add_beacon;
1724                 break;
1725         case NL80211_CMD_SET_BEACON:
1726                 call = rdev->ops->set_beacon;
1727                 break;
1728         default:
1729                 WARN_ON(1);
1730                 return -EOPNOTSUPP;
1731         }
1732
1733         if (!call)
1734                 return -EOPNOTSUPP;
1735
1736         memset(&params, 0, sizeof(params));
1737
1738         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
1739                 params.interval =
1740                     nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
1741                 haveinfo = 1;
1742         }
1743
1744         if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
1745                 params.dtim_period =
1746                     nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
1747                 haveinfo = 1;
1748         }
1749
1750         if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
1751                 params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1752                 params.head_len =
1753                     nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
1754                 haveinfo = 1;
1755         }
1756
1757         if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
1758                 params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1759                 params.tail_len =
1760                     nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
1761                 haveinfo = 1;
1762         }
1763
1764         if (!haveinfo)
1765                 return -EINVAL;
1766
1767         return call(&rdev->wiphy, dev, &params);
1768 }
1769
1770 static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
1771 {
1772         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1773         struct net_device *dev = info->user_ptr[1];
1774
1775         if (!rdev->ops->del_beacon)
1776                 return -EOPNOTSUPP;
1777
1778         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
1779             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
1780                 return -EOPNOTSUPP;
1781
1782         return rdev->ops->del_beacon(&rdev->wiphy, dev);
1783 }
1784
1785 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
1786         [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
1787         [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
1788         [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1789         [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1790 };
1791
1792 static int parse_station_flags(struct genl_info *info,
1793                                struct station_parameters *params)
1794 {
1795         struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1796         struct nlattr *nla;
1797         int flag;
1798
1799         /*
1800          * Try parsing the new attribute first so userspace
1801          * can specify both for older kernels.
1802          */
1803         nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
1804         if (nla) {
1805                 struct nl80211_sta_flag_update *sta_flags;
1806
1807                 sta_flags = nla_data(nla);
1808                 params->sta_flags_mask = sta_flags->mask;
1809                 params->sta_flags_set = sta_flags->set;
1810                 if ((params->sta_flags_mask |
1811                      params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
1812                         return -EINVAL;
1813                 return 0;
1814         }
1815
1816         /* if present, parse the old attribute */
1817
1818         nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1819         if (!nla)
1820                 return 0;
1821
1822         if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
1823                              nla, sta_flags_policy))
1824                 return -EINVAL;
1825
1826         params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
1827         params->sta_flags_mask &= ~1;
1828
1829         for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
1830                 if (flags[flag])
1831                         params->sta_flags_set |= (1<<flag);
1832
1833         return 0;
1834 }
1835
1836 static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
1837                                 int flags, struct net_device *dev,
1838                                 const u8 *mac_addr, struct station_info *sinfo)
1839 {
1840         void *hdr;
1841         struct nlattr *sinfoattr, *txrate;
1842         u16 bitrate;
1843
1844         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
1845         if (!hdr)
1846                 return -1;
1847
1848         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
1849         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);
1850
1851         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);
1852
1853         sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
1854         if (!sinfoattr)
1855                 goto nla_put_failure;
1856         if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
1857                 NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
1858                             sinfo->inactive_time);
1859         if (sinfo->filled & STATION_INFO_RX_BYTES)
1860                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
1861                             sinfo->rx_bytes);
1862         if (sinfo->filled & STATION_INFO_TX_BYTES)
1863                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
1864                             sinfo->tx_bytes);
1865         if (sinfo->filled & STATION_INFO_LLID)
1866                 NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
1867                             sinfo->llid);
1868         if (sinfo->filled & STATION_INFO_PLID)
1869                 NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
1870                             sinfo->plid);
1871         if (sinfo->filled & STATION_INFO_PLINK_STATE)
1872                 NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
1873                             sinfo->plink_state);
1874         if (sinfo->filled & STATION_INFO_SIGNAL)
1875                 NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
1876                            sinfo->signal);
1877         if (sinfo->filled & STATION_INFO_TX_BITRATE) {
1878                 txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
1879                 if (!txrate)
1880                         goto nla_put_failure;
1881
1882                 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */
1883                 bitrate = cfg80211_calculate_bitrate(&sinfo->txrate);
1884                 if (bitrate > 0)
1885                         NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1886
1887                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
1888                         NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
1889                                     sinfo->txrate.mcs);
1890                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
1891                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
1892                 if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
1893                         NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);
1894
1895                 nla_nest_end(msg, txrate);
1896         }
1897         if (sinfo->filled & STATION_INFO_RX_PACKETS)
1898                 NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
1899                             sinfo->rx_packets);
1900         if (sinfo->filled & STATION_INFO_TX_PACKETS)
1901                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
1902                             sinfo->tx_packets);
1903         if (sinfo->filled & STATION_INFO_TX_RETRIES)
1904                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_RETRIES,
1905                             sinfo->tx_retries);
1906         if (sinfo->filled & STATION_INFO_TX_FAILED)
1907                 NLA_PUT_U32(msg, NL80211_STA_INFO_TX_FAILED,
1908                             sinfo->tx_failed);
1909         nla_nest_end(msg, sinfoattr);
1910
1911         return genlmsg_end(msg, hdr);
1912
1913  nla_put_failure:
1914         genlmsg_cancel(msg, hdr);
1915         return -EMSGSIZE;
1916 }
1917
1918 static int nl80211_dump_station(struct sk_buff *skb,
1919                                 struct netlink_callback *cb)
1920 {
1921         struct station_info sinfo;
1922         struct cfg80211_registered_device *dev;
1923         struct net_device *netdev;
1924         u8 mac_addr[ETH_ALEN];
1925         int sta_idx = cb->args[1];
1926         int err;
1927
1928         err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
1929         if (err)
1930                 return err;
1931
1932         if (!dev->ops->dump_station) {
1933                 err = -EOPNOTSUPP;
1934                 goto out_err;
1935         }
1936
1937         while (1) {
1938                 err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
1939                                              mac_addr, &sinfo);
1940                 if (err == -ENOENT)
1941                         break;
1942                 if (err)
1943                         goto out_err;
1944
1945                 if (nl80211_send_station(skb,
1946                                 NETLINK_CB(cb->skb).pid,
1947                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
1948                                 netdev, mac_addr,
1949                                 &sinfo) < 0)
1950                         goto out;
1951
1952                 sta_idx++;
1953         }
1954
1955
1956  out:
1957         cb->args[1] = sta_idx;
1958         err = skb->len;
1959  out_err:
1960         nl80211_finish_netdev_dump(dev);
1961
1962         return err;
1963 }
1964
1965 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
1966 {
1967         struct cfg80211_registered_device *rdev = info->user_ptr[0];
1968         struct net_device *dev = info->user_ptr[1];
1969         struct station_info sinfo;
1970         struct sk_buff *msg;
1971         u8 *mac_addr = NULL;
1972         int err;
1973
1974         memset(&sinfo, 0, sizeof(sinfo));
1975
1976         if (!info->attrs[NL80211_ATTR_MAC])
1977                 return -EINVAL;
1978
1979         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
1980
1981         if (!rdev->ops->get_station)
1982                 return -EOPNOTSUPP;
1983
1984         err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
1985         if (err)
1986                 return err;
1987
1988         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1989         if (!msg)
1990                 return -ENOMEM;
1991
1992         if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1993                                  dev, mac_addr, &sinfo) < 0) {
1994                 nlmsg_free(msg);
1995                 return -ENOBUFS;
1996         }
1997
1998         return genlmsg_reply(msg, info);
1999 }
2000
2001 /*
2002  * Get vlan interface making sure it is running and on the right wiphy.
2003  */
2004 static int get_vlan(struct genl_info *info,
2005                     struct cfg80211_registered_device *rdev,
2006                     struct net_device **vlan)
2007 {
2008         struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
2009         *vlan = NULL;
2010
2011         if (vlanattr) {
2012                 *vlan = dev_get_by_index(genl_info_net(info),
2013                                          nla_get_u32(vlanattr));
2014                 if (!*vlan)
2015                         return -ENODEV;
2016                 if (!(*vlan)->ieee80211_ptr)
2017                         return -EINVAL;
2018                 if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
2019                         return -EINVAL;
2020                 if (!netif_running(*vlan))
2021                         return -ENETDOWN;
2022         }
2023         return 0;
2024 }
2025
2026 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
2027 {
2028         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2029         int err;
2030         struct net_device *dev = info->user_ptr[1];
2031         struct station_parameters params;
2032         u8 *mac_addr = NULL;
2033
2034         memset(&params, 0, sizeof(params));
2035
2036         params.listen_interval = -1;
2037
2038         if (info->attrs[NL80211_ATTR_STA_AID])
2039                 return -EINVAL;
2040
2041         if (!info->attrs[NL80211_ATTR_MAC])
2042                 return -EINVAL;
2043
2044         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2045
2046         if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
2047                 params.supported_rates =
2048                         nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2049                 params.supported_rates_len =
2050                         nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2051         }
2052
2053         if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2054                 params.listen_interval =
2055                     nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2056
2057         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2058                 params.ht_capa =
2059                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2060
2061         if (parse_station_flags(info, &params))
2062                 return -EINVAL;
2063
2064         if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
2065                 params.plink_action =
2066                     nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);
2067
2068         err = get_vlan(info, rdev, &params.vlan);
2069         if (err)
2070                 goto out;
2071
2072         /* validate settings */
2073         err = 0;
2074
2075         switch (dev->ieee80211_ptr->iftype) {
2076         case NL80211_IFTYPE_AP:
2077         case NL80211_IFTYPE_AP_VLAN:
2078         case NL80211_IFTYPE_P2P_GO:
2079                 /* disallow mesh-specific things */
2080                 if (params.plink_action)
2081                         err = -EINVAL;
2082                 break;
2083         case NL80211_IFTYPE_P2P_CLIENT:
2084         case NL80211_IFTYPE_STATION:
2085                 /* disallow everything but AUTHORIZED flag */
2086                 if (params.plink_action)
2087                         err = -EINVAL;
2088                 if (params.vlan)
2089                         err = -EINVAL;
2090                 if (params.supported_rates)
2091                         err = -EINVAL;
2092                 if (params.ht_capa)
2093                         err = -EINVAL;
2094                 if (params.listen_interval >= 0)
2095                         err = -EINVAL;
2096                 if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
2097                         err = -EINVAL;
2098                 break;
2099         case NL80211_IFTYPE_MESH_POINT:
2100                 /* disallow things mesh doesn't support */
2101                 if (params.vlan)
2102                         err = -EINVAL;
2103                 if (params.ht_capa)
2104                         err = -EINVAL;
2105                 if (params.listen_interval >= 0)
2106                         err = -EINVAL;
2107                 if (params.supported_rates)
2108                         err = -EINVAL;
2109                 if (params.sta_flags_mask)
2110                         err = -EINVAL;
2111                 break;
2112         default:
2113                 err = -EINVAL;
2114         }
2115
2116         if (err)
2117                 goto out;
2118
2119         if (!rdev->ops->change_station) {
2120                 err = -EOPNOTSUPP;
2121                 goto out;
2122         }
2123
2124         err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
2125
2126  out:
2127         if (params.vlan)
2128                 dev_put(params.vlan);
2129
2130         return err;
2131 }
2132
2133 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
2134 {
2135         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2136         int err;
2137         struct net_device *dev = info->user_ptr[1];
2138         struct station_parameters params;
2139         u8 *mac_addr = NULL;
2140
2141         memset(&params, 0, sizeof(params));
2142
2143         if (!info->attrs[NL80211_ATTR_MAC])
2144                 return -EINVAL;
2145
2146         if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
2147                 return -EINVAL;
2148
2149         if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
2150                 return -EINVAL;
2151
2152         if (!info->attrs[NL80211_ATTR_STA_AID])
2153                 return -EINVAL;
2154
2155         mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2156         params.supported_rates =
2157                 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2158         params.supported_rates_len =
2159                 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
2160         params.listen_interval =
2161                 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
2162
2163         params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
2164         if (!params.aid || params.aid > IEEE80211_MAX_AID)
2165                 return -EINVAL;
2166
2167         if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
2168                 params.ht_capa =
2169                         nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
2170
2171         if (parse_station_flags(info, &params))
2172                 return -EINVAL;
2173
2174         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2175             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2176             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2177                 return -EINVAL;
2178
2179         err = get_vlan(info, rdev, &params.vlan);
2180         if (err)
2181                 goto out;
2182
2183         /* validate settings */
2184         err = 0;
2185
2186         if (!rdev->ops->add_station) {
2187                 err = -EOPNOTSUPP;
2188                 goto out;
2189         }
2190
2191         err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2192
2193  out:
2194         if (params.vlan)
2195                 dev_put(params.vlan);
2196         return err;
2197 }
2198
2199 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
2200 {
2201         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2202         struct net_device *dev = info->user_ptr[1];
2203         u8 *mac_addr = NULL;
2204
2205         if (info->attrs[NL80211_ATTR_MAC])
2206                 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
2207
2208         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2209             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
2210             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT &&
2211             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2212                 return -EINVAL;
2213
2214         if (!rdev->ops->del_station)
2215                 return -EOPNOTSUPP;
2216
2217         return rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2218 }
2219
2220 static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
2221                                 int flags, struct net_device *dev,
2222                                 u8 *dst, u8 *next_hop,
2223                                 struct mpath_info *pinfo)
2224 {
2225         void *hdr;
2226         struct nlattr *pinfoattr;
2227
2228         hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
2229         if (!hdr)
2230                 return -1;
2231
2232         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2233         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
2234         NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);
2235
2236         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);
2237
2238         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
2239         if (!pinfoattr)
2240                 goto nla_put_failure;
2241         if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
2242                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
2243                             pinfo->frame_qlen);
2244         if (pinfo->filled & MPATH_INFO_SN)
2245                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
2246                             pinfo->sn);
2247         if (pinfo->filled & MPATH_INFO_METRIC)
2248                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
2249                             pinfo->metric);
2250         if (pinfo->filled & MPATH_INFO_EXPTIME)
2251                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
2252                             pinfo->exptime);
2253         if (pinfo->filled & MPATH_INFO_FLAGS)
2254                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
2255                             pinfo->flags);
2256         if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
2257                 NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
2258                             pinfo->discovery_timeout);
2259         if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
2260                 NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
2261                             pinfo->discovery_retries);
2262
2263         nla_nest_end(msg, pinfoattr);
2264
2265         return genlmsg_end(msg, hdr);
2266
2267  nla_put_failure:
2268         genlmsg_cancel(msg, hdr);
2269         return -EMSGSIZE;
2270 }
2271
2272 static int nl80211_dump_mpath(struct sk_buff *skb,
2273                               struct netlink_callback *cb)
2274 {
2275         struct mpath_info pinfo;
2276         struct cfg80211_registered_device *dev;
2277         struct net_device *netdev;
2278         u8 dst[ETH_ALEN];
2279         u8 next_hop[ETH_ALEN];
2280         int path_idx = cb->args[1];
2281         int err;
2282
2283         err = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
2284         if (err)
2285                 return err;
2286
2287         if (!dev->ops->dump_mpath) {
2288                 err = -EOPNOTSUPP;
2289                 goto out_err;
2290         }
2291
2292         if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2293                 err = -EOPNOTSUPP;
2294                 goto out_err;
2295         }
2296
2297         while (1) {
2298                 err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
2299                                            dst, next_hop, &pinfo);
2300                 if (err == -ENOENT)
2301                         break;
2302                 if (err)
2303                         goto out_err;
2304
2305                 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
2306                                        cb->nlh->nlmsg_seq, NLM_F_MULTI,
2307                                        netdev, dst, next_hop,
2308                                        &pinfo) < 0)
2309                         goto out;
2310
2311                 path_idx++;
2312         }
2313
2314
2315  out:
2316         cb->args[1] = path_idx;
2317         err = skb->len;
2318  out_err:
2319         nl80211_finish_netdev_dump(dev);
2320         return err;
2321 }
2322
2323 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
2324 {
2325         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2326         int err;
2327         struct net_device *dev = info->user_ptr[1];
2328         struct mpath_info pinfo;
2329         struct sk_buff *msg;
2330         u8 *dst = NULL;
2331         u8 next_hop[ETH_ALEN];
2332
2333         memset(&pinfo, 0, sizeof(pinfo));
2334
2335         if (!info->attrs[NL80211_ATTR_MAC])
2336                 return -EINVAL;
2337
2338         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2339
2340         if (!rdev->ops->get_mpath)
2341                 return -EOPNOTSUPP;
2342
2343         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2344                 return -EOPNOTSUPP;
2345
2346         err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2347         if (err)
2348                 return err;
2349
2350         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2351         if (!msg)
2352                 return -ENOMEM;
2353
2354         if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
2355                                  dev, dst, next_hop, &pinfo) < 0) {
2356                 nlmsg_free(msg);
2357                 return -ENOBUFS;
2358         }
2359
2360         return genlmsg_reply(msg, info);
2361 }
2362
2363 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
2364 {
2365         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2366         struct net_device *dev = info->user_ptr[1];
2367         u8 *dst = NULL;
2368         u8 *next_hop = NULL;
2369
2370         if (!info->attrs[NL80211_ATTR_MAC])
2371                 return -EINVAL;
2372
2373         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2374                 return -EINVAL;
2375
2376         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2377         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2378
2379         if (!rdev->ops->change_mpath)
2380                 return -EOPNOTSUPP;
2381
2382         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2383                 return -EOPNOTSUPP;
2384
2385         return rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2386 }
2387
2388 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
2389 {
2390         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2391         struct net_device *dev = info->user_ptr[1];
2392         u8 *dst = NULL;
2393         u8 *next_hop = NULL;
2394
2395         if (!info->attrs[NL80211_ATTR_MAC])
2396                 return -EINVAL;
2397
2398         if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
2399                 return -EINVAL;
2400
2401         dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2402         next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);
2403
2404         if (!rdev->ops->add_mpath)
2405                 return -EOPNOTSUPP;
2406
2407         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT)
2408                 return -EOPNOTSUPP;
2409
2410         return rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2411 }
2412
2413 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
2414 {
2415         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2416         struct net_device *dev = info->user_ptr[1];
2417         u8 *dst = NULL;
2418
2419         if (info->attrs[NL80211_ATTR_MAC])
2420                 dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
2421
2422         if (!rdev->ops->del_mpath)
2423                 return -EOPNOTSUPP;
2424
2425         return rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2426 }
2427
2428 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
2429 {
2430         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2431         struct net_device *dev = info->user_ptr[1];
2432         struct bss_parameters params;
2433
2434         memset(&params, 0, sizeof(params));
2435         /* default to not changing parameters */
2436         params.use_cts_prot = -1;
2437         params.use_short_preamble = -1;
2438         params.use_short_slot_time = -1;
2439         params.ap_isolate = -1;
2440
2441         if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
2442                 params.use_cts_prot =
2443                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
2444         if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
2445                 params.use_short_preamble =
2446                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
2447         if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
2448                 params.use_short_slot_time =
2449                     nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2450         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
2451                 params.basic_rates =
2452                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2453                 params.basic_rates_len =
2454                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
2455         }
2456         if (info->attrs[NL80211_ATTR_AP_ISOLATE])
2457                 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]);
2458
2459         if (!rdev->ops->change_bss)
2460                 return -EOPNOTSUPP;
2461
2462         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2463             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
2464                 return -EOPNOTSUPP;
2465
2466         return rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2467 }
2468
2469 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
2470         [NL80211_ATTR_REG_RULE_FLAGS]           = { .type = NLA_U32 },
2471         [NL80211_ATTR_FREQ_RANGE_START]         = { .type = NLA_U32 },
2472         [NL80211_ATTR_FREQ_RANGE_END]           = { .type = NLA_U32 },
2473         [NL80211_ATTR_FREQ_RANGE_MAX_BW]        = { .type = NLA_U32 },
2474         [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]  = { .type = NLA_U32 },
2475         [NL80211_ATTR_POWER_RULE_MAX_EIRP]      = { .type = NLA_U32 },
2476 };
2477
2478 static int parse_reg_rule(struct nlattr *tb[],
2479         struct ieee80211_reg_rule *reg_rule)
2480 {
2481         struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
2482         struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;
2483
2484         if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
2485                 return -EINVAL;
2486         if (!tb[NL80211_ATTR_FREQ_RANGE_START])
2487                 return -EINVAL;
2488         if (!tb[NL80211_ATTR_FREQ_RANGE_END])
2489                 return -EINVAL;
2490         if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
2491                 return -EINVAL;
2492         if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
2493                 return -EINVAL;
2494
2495         reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);
2496
2497         freq_range->start_freq_khz =
2498                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
2499         freq_range->end_freq_khz =
2500                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
2501         freq_range->max_bandwidth_khz =
2502                 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);
2503
2504         power_rule->max_eirp =
2505                 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);
2506
2507         if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
2508                 power_rule->max_antenna_gain =
2509                         nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);
2510
2511         return 0;
2512 }
2513
2514 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
2515 {
2516         int r;
2517         char *data = NULL;
2518
2519         /*
2520          * You should only get this when cfg80211 hasn't yet initialized
2521          * completely when built-in to the kernel right between the time
2522          * window between nl80211_init() and regulatory_init(), if that is
2523          * even possible.
2524          */
2525         mutex_lock(&cfg80211_mutex);
2526         if (unlikely(!cfg80211_regdomain)) {
2527                 mutex_unlock(&cfg80211_mutex);
2528                 return -EINPROGRESS;
2529         }
2530         mutex_unlock(&cfg80211_mutex);
2531
2532         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2533                 return -EINVAL;
2534
2535         data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2536
2537         r = regulatory_hint_user(data);
2538
2539         return r;
2540 }
2541
2542 static int nl80211_get_mesh_params(struct sk_buff *skb,
2543         struct genl_info *info)
2544 {
2545         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2546         struct mesh_config cur_params;
2547         int err;
2548         struct net_device *dev = info->user_ptr[1];
2549         void *hdr;
2550         struct nlattr *pinfoattr;
2551         struct sk_buff *msg;
2552
2553         if (!rdev->ops->get_mesh_params)
2554                 return -EOPNOTSUPP;
2555
2556         /* Get the mesh params */
2557         err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2558         if (err)
2559                 return err;
2560
2561         /* Draw up a netlink message to send back */
2562         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2563         if (!msg)
2564                 return -ENOMEM;
2565         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2566                              NL80211_CMD_GET_MESH_PARAMS);
2567         if (!hdr)
2568                 goto nla_put_failure;
2569         pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
2570         if (!pinfoattr)
2571                 goto nla_put_failure;
2572         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
2573         NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
2574                         cur_params.dot11MeshRetryTimeout);
2575         NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
2576                         cur_params.dot11MeshConfirmTimeout);
2577         NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
2578                         cur_params.dot11MeshHoldingTimeout);
2579         NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
2580                         cur_params.dot11MeshMaxPeerLinks);
2581         NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
2582                         cur_params.dot11MeshMaxRetries);
2583         NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
2584                         cur_params.dot11MeshTTL);
2585         NLA_PUT_U8(msg, NL80211_MESHCONF_ELEMENT_TTL,
2586                         cur_params.element_ttl);
2587         NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
2588                         cur_params.auto_open_plinks);
2589         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2590                         cur_params.dot11MeshHWMPmaxPREQretries);
2591         NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
2592                         cur_params.path_refresh_time);
2593         NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2594                         cur_params.min_discovery_timeout);
2595         NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2596                         cur_params.dot11MeshHWMPactivePathTimeout);
2597         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2598                         cur_params.dot11MeshHWMPpreqMinInterval);
2599         NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2600                         cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2601         NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
2602                         cur_params.dot11MeshHWMPRootMode);
2603         nla_nest_end(msg, pinfoattr);
2604         genlmsg_end(msg, hdr);
2605         return genlmsg_reply(msg, info);
2606
2607  nla_put_failure:
2608         genlmsg_cancel(msg, hdr);
2609         nlmsg_free(msg);
2610         return -ENOBUFS;
2611 }
2612
2613 #define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
2614 do {\
2615         if (table[attr_num]) {\
2616                 cfg.param = nla_fn(table[attr_num]); \
2617                 mask |= (1 << (attr_num - 1)); \
2618         } \
2619 } while (0);\
2620
2621 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = {
2622         [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
2623         [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
2624         [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
2625         [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
2626         [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
2627         [NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
2628         [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 },
2629         [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },
2630
2631         [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
2632         [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
2633         [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
2634         [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
2635         [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
2636         [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
2637 };
2638
2639 static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
2640 {
2641         u32 mask;
2642         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2643         struct net_device *dev = info->user_ptr[1];
2644         struct mesh_config cfg;
2645         struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
2646         struct nlattr *parent_attr;
2647
2648         parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
2649         if (!parent_attr)
2650                 return -EINVAL;
2651         if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
2652                         parent_attr, nl80211_meshconf_params_policy))
2653                 return -EINVAL;
2654
2655         if (!rdev->ops->set_mesh_params)
2656                 return -EOPNOTSUPP;
2657
2658         /* This makes sure that there aren't more than 32 mesh config
2659          * parameters (otherwise our bitfield scheme would not work.) */
2660         BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);
2661
2662         /* Fill in the params struct */
2663         mask = 0;
2664         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
2665                         mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
2666         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
2667                         mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
2668         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
2669                         mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
2670         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
2671                         mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
2672         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
2673                         mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
2674         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
2675                         mask, NL80211_MESHCONF_TTL, nla_get_u8);
2676         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl,
2677                         mask, NL80211_MESHCONF_ELEMENT_TTL, nla_get_u8);
2678         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
2679                         mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
2680         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
2681                         mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
2682                         nla_get_u8);
2683         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
2684                         mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
2685         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
2686                         mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
2687                         nla_get_u16);
2688         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
2689                         mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
2690                         nla_get_u32);
2691         FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
2692                         mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
2693                         nla_get_u16);
2694         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2695                         dot11MeshHWMPnetDiameterTraversalTime,
2696                         mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
2697                         nla_get_u16);
2698         FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
2699                         dot11MeshHWMPRootMode, mask,
2700                         NL80211_MESHCONF_HWMP_ROOTMODE,
2701                         nla_get_u8);
2702
2703         /* Apply changes */
2704         return rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2705 }
2706
2707 #undef FILL_IN_MESH_PARAM_IF_SET
2708
2709 static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
2710 {
2711         struct sk_buff *msg;
2712         void *hdr = NULL;
2713         struct nlattr *nl_reg_rules;
2714         unsigned int i;
2715         int err = -EINVAL;
2716
2717         mutex_lock(&cfg80211_mutex);
2718
2719         if (!cfg80211_regdomain)
2720                 goto out;
2721
2722         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2723         if (!msg) {
2724                 err = -ENOBUFS;
2725                 goto out;
2726         }
2727
2728         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
2729                              NL80211_CMD_GET_REG);
2730         if (!hdr)
2731                 goto nla_put_failure;
2732
2733         NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
2734                 cfg80211_regdomain->alpha2);
2735
2736         nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
2737         if (!nl_reg_rules)
2738                 goto nla_put_failure;
2739
2740         for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
2741                 struct nlattr *nl_reg_rule;
2742                 const struct ieee80211_reg_rule *reg_rule;
2743                 const struct ieee80211_freq_range *freq_range;
2744                 const struct ieee80211_power_rule *power_rule;
2745
2746                 reg_rule = &cfg80211_regdomain->reg_rules[i];
2747                 freq_range = &reg_rule->freq_range;
2748                 power_rule = &reg_rule->power_rule;
2749
2750                 nl_reg_rule = nla_nest_start(msg, i);
2751                 if (!nl_reg_rule)
2752                         goto nla_put_failure;
2753
2754                 NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
2755                         reg_rule->flags);
2756                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
2757                         freq_range->start_freq_khz);
2758                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
2759                         freq_range->end_freq_khz);
2760                 NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
2761                         freq_range->max_bandwidth_khz);
2762                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
2763                         power_rule->max_antenna_gain);
2764                 NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
2765                         power_rule->max_eirp);
2766
2767                 nla_nest_end(msg, nl_reg_rule);
2768         }
2769
2770         nla_nest_end(msg, nl_reg_rules);
2771
2772         genlmsg_end(msg, hdr);
2773         err = genlmsg_reply(msg, info);
2774         goto out;
2775
2776 nla_put_failure:
2777         genlmsg_cancel(msg, hdr);
2778         nlmsg_free(msg);
2779         err = -EMSGSIZE;
2780 out:
2781         mutex_unlock(&cfg80211_mutex);
2782         return err;
2783 }
2784
2785 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
2786 {
2787         struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
2788         struct nlattr *nl_reg_rule;
2789         char *alpha2 = NULL;
2790         int rem_reg_rules = 0, r = 0;
2791         u32 num_rules = 0, rule_idx = 0, size_of_regd;
2792         struct ieee80211_regdomain *rd = NULL;
2793
2794         if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
2795                 return -EINVAL;
2796
2797         if (!info->attrs[NL80211_ATTR_REG_RULES])
2798                 return -EINVAL;
2799
2800         alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);
2801
2802         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2803                         rem_reg_rules) {
2804                 num_rules++;
2805                 if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2806                         return -EINVAL;
2807         }
2808
2809         mutex_lock(&cfg80211_mutex);
2810
2811         if (!reg_is_valid_request(alpha2)) {
2812                 r = -EINVAL;
2813                 goto bad_reg;
2814         }
2815
2816         size_of_regd = sizeof(struct ieee80211_regdomain) +
2817                 (num_rules * sizeof(struct ieee80211_reg_rule));
2818
2819         rd = kzalloc(size_of_regd, GFP_KERNEL);
2820         if (!rd) {
2821                 r = -ENOMEM;
2822                 goto bad_reg;
2823         }
2824
2825         rd->n_reg_rules = num_rules;
2826         rd->alpha2[0] = alpha2[0];
2827         rd->alpha2[1] = alpha2[1];
2828
2829         nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
2830                         rem_reg_rules) {
2831                 nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
2832                         nla_data(nl_reg_rule), nla_len(nl_reg_rule),
2833                         reg_rule_policy);
2834                 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
2835                 if (r)
2836                         goto bad_reg;
2837
2838                 rule_idx++;
2839
2840                 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
2841                         r = -EINVAL;
2842                         goto bad_reg;
2843                 }
2844         }
2845
2846         BUG_ON(rule_idx != num_rules);
2847
2848         r = set_regdom(rd);
2849
2850         mutex_unlock(&cfg80211_mutex);
2851
2852         return r;
2853
2854  bad_reg:
2855         mutex_unlock(&cfg80211_mutex);
2856         kfree(rd);
2857         return r;
2858 }
2859
2860 static int validate_scan_freqs(struct nlattr *freqs)
2861 {
2862         struct nlattr *attr1, *attr2;
2863         int n_channels = 0, tmp1, tmp2;
2864
2865         nla_for_each_nested(attr1, freqs, tmp1) {
2866                 n_channels++;
2867                 /*
2868                  * Some hardware has a limited channel list for
2869                  * scanning, and it is pretty much nonsensical
2870                  * to scan for a channel twice, so disallow that
2871                  * and don't require drivers to check that the
2872                  * channel list they get isn't longer than what
2873                  * they can scan, as long as they can scan all
2874                  * the channels they registered at once.
2875                  */
2876                 nla_for_each_nested(attr2, freqs, tmp2)
2877                         if (attr1 != attr2 &&
2878                             nla_get_u32(attr1) == nla_get_u32(attr2))
2879                                 return 0;
2880         }
2881
2882         return n_channels;
2883 }
2884
2885 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
2886 {
2887         struct cfg80211_registered_device *rdev = info->user_ptr[0];
2888         struct net_device *dev = info->user_ptr[1];
2889         struct cfg80211_scan_request *request;
2890         struct cfg80211_ssid *ssid;
2891         struct ieee80211_channel *channel;
2892         struct nlattr *attr;
2893         struct wiphy *wiphy;
2894         int err, tmp, n_ssids = 0, n_channels, i;
2895         enum ieee80211_band band;
2896         size_t ie_len;
2897
2898         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
2899                 return -EINVAL;
2900
2901         wiphy = &rdev->wiphy;
2902
2903         if (!rdev->ops->scan)
2904                 return -EOPNOTSUPP;
2905
2906         if (rdev->scan_req)
2907                 return -EBUSY;
2908
2909         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2910                 n_channels = validate_scan_freqs(
2911                                 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2912                 if (!n_channels)
2913                         return -EINVAL;
2914         } else {
2915                 n_channels = 0;
2916
2917                 for (band = 0; band < IEEE80211_NUM_BANDS; band++)
2918                         if (wiphy->bands[band])
2919                                 n_channels += wiphy->bands[band]->n_channels;
2920         }
2921
2922         if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
2923                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
2924                         n_ssids++;
2925
2926         if (n_ssids > wiphy->max_scan_ssids)
2927                 return -EINVAL;
2928
2929         if (info->attrs[NL80211_ATTR_IE])
2930                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
2931         else
2932                 ie_len = 0;
2933
2934         if (ie_len > wiphy->max_scan_ie_len)
2935                 return -EINVAL;
2936
2937         request = kzalloc(sizeof(*request)
2938                         + sizeof(*ssid) * n_ssids
2939                         + sizeof(channel) * n_channels
2940                         + ie_len, GFP_KERNEL);
2941         if (!request)
2942                 return -ENOMEM;
2943
2944         if (n_ssids)
2945                 request->ssids = (void *)&request->channels[n_channels];
2946         request->n_ssids = n_ssids;
2947         if (ie_len) {
2948                 if (request->ssids)
2949                         request->ie = (void *)(request->ssids + n_ssids);
2950                 else
2951                         request->ie = (void *)(request->channels + n_channels);
2952         }
2953
2954         i = 0;
2955         if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2956                 /* user specified, bail out if channel not found */
2957                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
2958                         struct ieee80211_channel *chan;
2959
2960                         chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));
2961
2962                         if (!chan) {
2963                                 err = -EINVAL;
2964                                 goto out_free;
2965                         }
2966
2967                         /* ignore disabled channels */
2968                         if (chan->flags & IEEE80211_CHAN_DISABLED)
2969                                 continue;
2970
2971                         request->channels[i] = chan;
2972                         i++;
2973                 }
2974         } else {
2975                 /* all channels */
2976                 for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
2977                         int j;
2978                         if (!wiphy->bands[band])
2979                                 continue;
2980                         for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
2981                                 struct ieee80211_channel *chan;
2982
2983                                 chan = &wiphy->bands[band]->channels[j];
2984
2985                                 if (chan->flags & IEEE80211_CHAN_DISABLED)
2986                                         continue;
2987
2988                                 request->channels[i] = chan;
2989                                 i++;
2990                         }
2991                 }
2992         }
2993
2994         if (!i) {
2995                 err = -EINVAL;
2996                 goto out_free;
2997         }
2998
2999         request->n_channels = i;
3000
3001         i = 0;
3002         if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
3003                 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
3004                         if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
3005                                 err = -EINVAL;
3006                                 goto out_free;
3007                         }
3008                         memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
3009                         request->ssids[i].ssid_len = nla_len(attr);
3010                         i++;
3011                 }
3012         }
3013
3014         if (info->attrs[NL80211_ATTR_IE]) {
3015                 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3016                 memcpy((void *)request->ie,
3017                        nla_data(info->attrs[NL80211_ATTR_IE]),
3018                        request->ie_len);
3019         }
3020
3021         request->dev = dev;
3022         request->wiphy = &rdev->wiphy;
3023
3024         rdev->scan_req = request;
3025         err = rdev->ops->scan(&rdev->wiphy, dev, request);
3026
3027         if (!err) {
3028                 nl80211_send_scan_start(rdev, dev);
3029                 dev_hold(dev);
3030         } else {
3031  out_free:
3032                 rdev->scan_req = NULL;
3033                 kfree(request);
3034         }
3035
3036         return err;
3037 }
3038
3039 static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
3040                             struct cfg80211_registered_device *rdev,
3041                             struct wireless_dev *wdev,
3042                             struct cfg80211_internal_bss *intbss)
3043 {
3044         struct cfg80211_bss *res = &intbss->pub;
3045         void *hdr;
3046         struct nlattr *bss;
3047         int i;
3048
3049         ASSERT_WDEV_LOCK(wdev);
3050
3051         hdr = nl80211hdr_put(msg, pid, seq, flags,
3052                              NL80211_CMD_NEW_SCAN_RESULTS);
3053         if (!hdr)
3054                 return -1;
3055
3056         NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
3057         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3058
3059         bss = nla_nest_start(msg, NL80211_ATTR_BSS);
3060         if (!bss)
3061                 goto nla_put_failure;
3062         if (!is_zero_ether_addr(res->bssid))
3063                 NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
3064         if (res->information_elements && res->len_information_elements)
3065                 NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
3066                         res->len_information_elements,
3067                         res->information_elements);
3068         if (res->beacon_ies && res->len_beacon_ies &&
3069             res->beacon_ies != res->information_elements)
3070                 NLA_PUT(msg, NL80211_BSS_BEACON_IES,
3071                         res->len_beacon_ies, res->beacon_ies);
3072         if (res->tsf)
3073                 NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
3074         if (res->beacon_interval)
3075                 NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
3076         NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
3077         NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3078         NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
3079                 jiffies_to_msecs(jiffies - intbss->ts));
3080
3081         switch (rdev->wiphy.signal_type) {
3082         case CFG80211_SIGNAL_TYPE_MBM:
3083                 NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
3084                 break;
3085         case CFG80211_SIGNAL_TYPE_UNSPEC:
3086                 NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
3087                 break;
3088         default:
3089                 break;
3090         }
3091
3092         switch (wdev->iftype) {
3093         case NL80211_IFTYPE_P2P_CLIENT:
3094         case NL80211_IFTYPE_STATION:
3095                 if (intbss == wdev->current_bss)
3096                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3097                                     NL80211_BSS_STATUS_ASSOCIATED);
3098                 else for (i = 0; i < MAX_AUTH_BSSES; i++) {
3099                         if (intbss != wdev->auth_bsses[i])
3100                                 continue;
3101                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3102                                     NL80211_BSS_STATUS_AUTHENTICATED);
3103                         break;
3104                 }
3105                 break;
3106         case NL80211_IFTYPE_ADHOC:
3107                 if (intbss == wdev->current_bss)
3108                         NLA_PUT_U32(msg, NL80211_BSS_STATUS,
3109                                     NL80211_BSS_STATUS_IBSS_JOINED);
3110                 break;
3111         default:
3112                 break;
3113         }
3114
3115         nla_nest_end(msg, bss);
3116
3117         return genlmsg_end(msg, hdr);
3118
3119  nla_put_failure:
3120         genlmsg_cancel(msg, hdr);
3121         return -EMSGSIZE;
3122 }
3123
3124 static int nl80211_dump_scan(struct sk_buff *skb,
3125                              struct netlink_callback *cb)
3126 {
3127         struct cfg80211_registered_device *rdev;
3128         struct net_device *dev;
3129         struct cfg80211_internal_bss *scan;
3130         struct wireless_dev *wdev;
3131         int start = cb->args[1], idx = 0;
3132         int err;
3133
3134         err = nl80211_prepare_netdev_dump(skb, cb, &rdev, &dev);
3135         if (err)
3136                 return err;
3137
3138         wdev = dev->ieee80211_ptr;
3139
3140         wdev_lock(wdev);
3141         spin_lock_bh(&rdev->bss_lock);
3142         cfg80211_bss_expire(rdev);
3143
3144         list_for_each_entry(scan, &rdev->bss_list, list) {
3145                 if (++idx <= start)
3146                         continue;
3147                 if (nl80211_send_bss(skb,
3148                                 NETLINK_CB(cb->skb).pid,
3149                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3150                                 rdev, wdev, scan) < 0) {
3151                         idx--;
3152                         break;
3153                 }
3154         }
3155
3156         spin_unlock_bh(&rdev->bss_lock);
3157         wdev_unlock(wdev);
3158
3159         cb->args[1] = idx;
3160         nl80211_finish_netdev_dump(rdev);
3161
3162         return skb->len;
3163 }
3164
3165 static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
3166                                 int flags, struct net_device *dev,
3167                                 struct survey_info *survey)
3168 {
3169         void *hdr;
3170         struct nlattr *infoattr;
3171
3172         /* Survey without a channel doesn't make sense */
3173         if (!survey->channel)
3174                 return -EINVAL;
3175
3176         hdr = nl80211hdr_put(msg, pid, seq, flags,
3177                              NL80211_CMD_NEW_SURVEY_RESULTS);
3178         if (!hdr)
3179                 return -ENOMEM;
3180
3181         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
3182
3183         infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
3184         if (!infoattr)
3185                 goto nla_put_failure;
3186
3187         NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
3188                     survey->channel->center_freq);
3189         if (survey->filled & SURVEY_INFO_NOISE_DBM)
3190                 NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
3191                             survey->noise);
3192         if (survey->filled & SURVEY_INFO_IN_USE)
3193                 NLA_PUT_FLAG(msg, NL80211_SURVEY_INFO_IN_USE);
3194         if (survey->filled & SURVEY_INFO_CHANNEL_TIME)
3195                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME,
3196                             survey->channel_time);
3197         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_BUSY)
3198                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_BUSY,
3199                             survey->channel_time_busy);
3200         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_EXT_BUSY)
3201                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_EXT_BUSY,
3202                             survey->channel_time_ext_busy);
3203         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_RX)
3204                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_RX,
3205                             survey->channel_time_rx);
3206         if (survey->filled & SURVEY_INFO_CHANNEL_TIME_TX)
3207                 NLA_PUT_U64(msg, NL80211_SURVEY_INFO_CHANNEL_TIME_TX,
3208                             survey->channel_time_tx);
3209
3210         nla_nest_end(msg, infoattr);
3211
3212         return genlmsg_end(msg, hdr);
3213
3214  nla_put_failure:
3215         genlmsg_cancel(msg, hdr);
3216         return -EMSGSIZE;
3217 }
3218
3219 static int nl80211_dump_survey(struct sk_buff *skb,
3220                         struct netlink_callback *cb)
3221 {
3222         struct survey_info survey;
3223         struct cfg80211_registered_device *dev;
3224         struct net_device *netdev;
3225         int survey_idx = cb->args[1];
3226         int res;
3227
3228         res = nl80211_prepare_netdev_dump(skb, cb, &dev, &netdev);
3229         if (res)
3230                 return res;
3231
3232         if (!dev->ops->dump_survey) {
3233                 res = -EOPNOTSUPP;
3234                 goto out_err;
3235         }
3236
3237         while (1) {
3238                 res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
3239                                             &survey);
3240                 if (res == -ENOENT)
3241                         break;
3242                 if (res)
3243                         goto out_err;
3244
3245                 if (nl80211_send_survey(skb,
3246                                 NETLINK_CB(cb->skb).pid,
3247                                 cb->nlh->nlmsg_seq, NLM_F_MULTI,
3248                                 netdev,
3249                                 &survey) < 0)
3250                         goto out;
3251                 survey_idx++;
3252         }
3253
3254  out:
3255         cb->args[1] = survey_idx;
3256         res = skb->len;
3257  out_err:
3258         nl80211_finish_netdev_dump(dev);
3259         return res;
3260 }
3261
3262 static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
3263 {
3264         return auth_type <= NL80211_AUTHTYPE_MAX;
3265 }
3266
3267 static bool nl80211_valid_wpa_versions(u32 wpa_versions)
3268 {
3269         return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
3270                                   NL80211_WPA_VERSION_2));
3271 }
3272
3273 static bool nl80211_valid_akm_suite(u32 akm)
3274 {
3275         return akm == WLAN_AKM_SUITE_8021X ||
3276                 akm == WLAN_AKM_SUITE_PSK;
3277 }
3278
3279 static bool nl80211_valid_cipher_suite(u32 cipher)
3280 {
3281         return cipher == WLAN_CIPHER_SUITE_WEP40 ||
3282                 cipher == WLAN_CIPHER_SUITE_WEP104 ||
3283                 cipher == WLAN_CIPHER_SUITE_TKIP ||
3284                 cipher == WLAN_CIPHER_SUITE_CCMP ||
3285                 cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3286 }
3287
3288
3289 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
3290 {
3291         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3292         struct net_device *dev = info->user_ptr[1];
3293         struct ieee80211_channel *chan;
3294         const u8 *bssid, *ssid, *ie = NULL;
3295         int err, ssid_len, ie_len = 0;
3296         enum nl80211_auth_type auth_type;
3297         struct key_parse key;
3298         bool local_state_change;
3299
3300         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3301                 return -EINVAL;
3302
3303         if (!info->attrs[NL80211_ATTR_MAC])
3304                 return -EINVAL;
3305
3306         if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
3307                 return -EINVAL;
3308
3309         if (!info->attrs[NL80211_ATTR_SSID])
3310                 return -EINVAL;
3311
3312         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
3313                 return -EINVAL;
3314
3315         err = nl80211_parse_key(info, &key);
3316         if (err)
3317                 return err;
3318
3319         if (key.idx >= 0) {
3320                 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP)
3321                         return -EINVAL;
3322                 if (!key.p.key || !key.p.key_len)
3323                         return -EINVAL;
3324                 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
3325                      key.p.key_len != WLAN_KEY_LEN_WEP40) &&
3326                     (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
3327                      key.p.key_len != WLAN_KEY_LEN_WEP104))
3328                         return -EINVAL;
3329                 if (key.idx > 4)
3330                         return -EINVAL;
3331         } else {
3332                 key.p.key_len = 0;
3333                 key.p.key = NULL;
3334         }
3335
3336         if (key.idx >= 0) {
3337                 int i;
3338                 bool ok = false;
3339                 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) {
3340                         if (key.p.cipher == rdev->wiphy.cipher_suites[i]) {
3341                                 ok = true;
3342                                 break;
3343                         }
3344                 }
3345                 if (!ok)
3346                         return -EINVAL;
3347         }
3348
3349         if (!rdev->ops->auth)
3350                 return -EOPNOTSUPP;
3351
3352         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3353             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3354                 return -EOPNOTSUPP;
3355
3356         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3357         chan = ieee80211_get_channel(&rdev->wiphy,
3358                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3359         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3360                 return -EINVAL;
3361
3362         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3363         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3364
3365         if (info->attrs[NL80211_ATTR_IE]) {
3366                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3367                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3368         }
3369
3370         auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3371         if (!nl80211_valid_auth_type(auth_type))
3372                 return -EINVAL;
3373
3374         local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3375
3376         return cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
3377                                   ssid, ssid_len, ie, ie_len,
3378                                   key.p.key, key.p.key_len, key.idx,
3379                                   local_state_change);
3380 }
3381
3382 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev,
3383                                    struct genl_info *info,
3384                                    struct cfg80211_crypto_settings *settings,
3385                                    int cipher_limit)
3386 {
3387         memset(settings, 0, sizeof(*settings));
3388
3389         settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];
3390
3391         if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) {
3392                 u16 proto;
3393                 proto = nla_get_u16(
3394                         info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]);
3395                 settings->control_port_ethertype = cpu_to_be16(proto);
3396                 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) &&
3397                     proto != ETH_P_PAE)
3398                         return -EINVAL;
3399                 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT])
3400                         settings->control_port_no_encrypt = true;
3401         } else
3402                 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE);
3403
3404         if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
3405                 void *data;
3406                 int len, i;
3407
3408                 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3409                 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
3410                 settings->n_ciphers_pairwise = len / sizeof(u32);
3411
3412                 if (len % sizeof(u32))
3413                         return -EINVAL;
3414
3415                 if (settings->n_ciphers_pairwise > cipher_limit)
3416                         return -EINVAL;
3417
3418                 memcpy(settings->ciphers_pairwise, data, len);
3419
3420                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3421                         if (!nl80211_valid_cipher_suite(
3422                                         settings->ciphers_pairwise[i]))
3423                                 return -EINVAL;
3424         }
3425
3426         if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
3427                 settings->cipher_group =
3428                         nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
3429                 if (!nl80211_valid_cipher_suite(settings->cipher_group))
3430                         return -EINVAL;
3431         }
3432
3433         if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
3434                 settings->wpa_versions =
3435                         nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
3436                 if (!nl80211_valid_wpa_versions(settings->wpa_versions))
3437                         return -EINVAL;
3438         }
3439
3440         if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
3441                 void *data;
3442                 int len, i;
3443
3444                 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
3445                 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
3446                 settings->n_akm_suites = len / sizeof(u32);
3447
3448                 if (len % sizeof(u32))
3449                         return -EINVAL;
3450
3451                 memcpy(settings->akm_suites, data, len);
3452
3453                 for (i = 0; i < settings->n_ciphers_pairwise; i++)
3454                         if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
3455                                 return -EINVAL;
3456         }
3457
3458         return 0;
3459 }
3460
3461 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
3462 {
3463         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3464         struct net_device *dev = info->user_ptr[1];
3465         struct cfg80211_crypto_settings crypto;
3466         struct ieee80211_channel *chan;
3467         const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
3468         int err, ssid_len, ie_len = 0;
3469         bool use_mfp = false;
3470
3471         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3472                 return -EINVAL;
3473
3474         if (!info->attrs[NL80211_ATTR_MAC] ||
3475             !info->attrs[NL80211_ATTR_SSID] ||
3476             !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3477                 return -EINVAL;
3478
3479         if (!rdev->ops->assoc)
3480                 return -EOPNOTSUPP;
3481
3482         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3483             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3484                 return -EOPNOTSUPP;
3485
3486         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3487
3488         chan = ieee80211_get_channel(&rdev->wiphy,
3489                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3490         if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED))
3491                 return -EINVAL;
3492
3493         ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3494         ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3495
3496         if (info->attrs[NL80211_ATTR_IE]) {
3497                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3498                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3499         }
3500
3501         if (info->attrs[NL80211_ATTR_USE_MFP]) {
3502                 enum nl80211_mfp mfp =
3503                         nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3504                 if (mfp == NL80211_MFP_REQUIRED)
3505                         use_mfp = true;
3506                 else if (mfp != NL80211_MFP_NO)
3507                         return -EINVAL;
3508         }
3509
3510         if (info->attrs[NL80211_ATTR_PREV_BSSID])
3511                 prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);
3512
3513         err = nl80211_crypto_settings(rdev, info, &crypto, 1);
3514         if (!err)
3515                 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
3516                                           ssid, ssid_len, ie, ie_len, use_mfp,
3517                                           &crypto);
3518
3519         return err;
3520 }
3521
3522 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
3523 {
3524         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3525         struct net_device *dev = info->user_ptr[1];
3526         const u8 *ie = NULL, *bssid;
3527         int ie_len = 0;
3528         u16 reason_code;
3529         bool local_state_change;
3530
3531         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3532                 return -EINVAL;
3533
3534         if (!info->attrs[NL80211_ATTR_MAC])
3535                 return -EINVAL;
3536
3537         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3538                 return -EINVAL;
3539
3540         if (!rdev->ops->deauth)
3541                 return -EOPNOTSUPP;
3542
3543         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3544             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3545                 return -EOPNOTSUPP;
3546
3547         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3548
3549         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3550         if (reason_code == 0) {
3551                 /* Reason Code 0 is reserved */
3552                 return -EINVAL;
3553         }
3554
3555         if (info->attrs[NL80211_ATTR_IE]) {
3556                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3557                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3558         }
3559
3560         local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3561
3562         return cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code,
3563                                     local_state_change);
3564 }
3565
3566 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
3567 {
3568         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3569         struct net_device *dev = info->user_ptr[1];
3570         const u8 *ie = NULL, *bssid;
3571         int ie_len = 0;
3572         u16 reason_code;
3573         bool local_state_change;
3574
3575         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3576                 return -EINVAL;
3577
3578         if (!info->attrs[NL80211_ATTR_MAC])
3579                 return -EINVAL;
3580
3581         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3582                 return -EINVAL;
3583
3584         if (!rdev->ops->disassoc)
3585                 return -EOPNOTSUPP;
3586
3587         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3588             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3589                 return -EOPNOTSUPP;
3590
3591         bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3592
3593         reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3594         if (reason_code == 0) {
3595                 /* Reason Code 0 is reserved */
3596                 return -EINVAL;
3597         }
3598
3599         if (info->attrs[NL80211_ATTR_IE]) {
3600                 ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3601                 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3602         }
3603
3604         local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE];
3605
3606         return cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code,
3607                                       local_state_change);
3608 }
3609
3610 static bool
3611 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev,
3612                          int mcast_rate[IEEE80211_NUM_BANDS],
3613                          int rateval)
3614 {
3615         struct wiphy *wiphy = &rdev->wiphy;
3616         bool found = false;
3617         int band, i;
3618
3619         for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
3620                 struct ieee80211_supported_band *sband;
3621
3622                 sband = wiphy->bands[band];
3623                 if (!sband)
3624                         continue;
3625
3626                 for (i = 0; i < sband->n_bitrates; i++) {
3627                         if (sband->bitrates[i].bitrate == rateval) {
3628                                 mcast_rate[band] = i + 1;
3629                                 found = true;
3630                                 break;
3631                         }
3632                 }
3633         }
3634
3635         return found;
3636 }
3637
3638 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
3639 {
3640         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3641         struct net_device *dev = info->user_ptr[1];
3642         struct cfg80211_ibss_params ibss;
3643         struct wiphy *wiphy;
3644         struct cfg80211_cached_keys *connkeys = NULL;
3645         int err;
3646
3647         memset(&ibss, 0, sizeof(ibss));
3648
3649         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3650                 return -EINVAL;
3651
3652         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
3653             !info->attrs[NL80211_ATTR_SSID] ||
3654             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3655                 return -EINVAL;
3656
3657         ibss.beacon_interval = 100;
3658
3659         if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
3660                 ibss.beacon_interval =
3661                         nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
3662                 if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
3663                         return -EINVAL;
3664         }
3665
3666         if (!rdev->ops->join_ibss)
3667                 return -EOPNOTSUPP;
3668
3669         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3670                 return -EOPNOTSUPP;
3671
3672         wiphy = &rdev->wiphy;
3673
3674         if (info->attrs[NL80211_ATTR_MAC])
3675                 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3676         ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3677         ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3678
3679         if (info->attrs[NL80211_ATTR_IE]) {
3680                 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3681                 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3682         }
3683
3684         ibss.channel = ieee80211_get_channel(wiphy,
3685                 nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3686         if (!ibss.channel ||
3687             ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
3688             ibss.channel->flags & IEEE80211_CHAN_DISABLED)
3689                 return -EINVAL;
3690
3691         ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
3692         ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];
3693
3694         if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
3695                 u8 *rates =
3696                         nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3697                 int n_rates =
3698                         nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
3699                 struct ieee80211_supported_band *sband =
3700                         wiphy->bands[ibss.channel->band];
3701                 int i, j;
3702
3703                 if (n_rates == 0)
3704                         return -EINVAL;
3705
3706                 for (i = 0; i < n_rates; i++) {
3707                         int rate = (rates[i] & 0x7f) * 5;
3708                         bool found = false;
3709
3710                         for (j = 0; j < sband->n_bitrates; j++) {
3711                                 if (sband->bitrates[j].bitrate == rate) {
3712                                         found = true;
3713                                         ibss.basic_rates |= BIT(j);
3714                                         break;
3715                                 }
3716                         }
3717                         if (!found)
3718                                 return -EINVAL;
3719                 }
3720         }
3721
3722         if (info->attrs[NL80211_ATTR_MCAST_RATE] &&
3723             !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate,
3724                         nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE])))
3725                 return -EINVAL;
3726
3727         if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3728                 connkeys = nl80211_parse_connkeys(rdev,
3729                                         info->attrs[NL80211_ATTR_KEYS]);
3730                 if (IS_ERR(connkeys))
3731                         return PTR_ERR(connkeys);
3732         }
3733
3734         err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
3735         if (err)
3736                 kfree(connkeys);
3737         return err;
3738 }
3739
3740 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
3741 {
3742         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3743         struct net_device *dev = info->user_ptr[1];
3744
3745         if (!rdev->ops->leave_ibss)
3746                 return -EOPNOTSUPP;
3747
3748         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC)
3749                 return -EOPNOTSUPP;
3750
3751         return cfg80211_leave_ibss(rdev, dev, false);
3752 }
3753
3754 #ifdef CONFIG_NL80211_TESTMODE
3755 static struct genl_multicast_group nl80211_testmode_mcgrp = {
3756         .name = "testmode",
3757 };
3758
3759 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
3760 {
3761         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3762         int err;
3763
3764         if (!info->attrs[NL80211_ATTR_TESTDATA])
3765                 return -EINVAL;
3766
3767         err = -EOPNOTSUPP;
3768         if (rdev->ops->testmode_cmd) {
3769                 rdev->testmode_info = info;
3770                 err = rdev->ops->testmode_cmd(&rdev->wiphy,
3771                                 nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
3772                                 nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
3773                 rdev->testmode_info = NULL;
3774         }
3775
3776         return err;
3777 }
3778
3779 static struct sk_buff *
3780 __cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
3781                               int approxlen, u32 pid, u32 seq, gfp_t gfp)
3782 {
3783         struct sk_buff *skb;
3784         void *hdr;
3785         struct nlattr *data;
3786
3787         skb = nlmsg_new(approxlen + 100, gfp);
3788         if (!skb)
3789                 return NULL;
3790
3791         hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
3792         if (!hdr) {
3793                 kfree_skb(skb);
3794                 return NULL;
3795         }
3796
3797         NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
3798         data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);
3799
3800         ((void **)skb->cb)[0] = rdev;
3801         ((void **)skb->cb)[1] = hdr;
3802         ((void **)skb->cb)[2] = data;
3803
3804         return skb;
3805
3806  nla_put_failure:
3807         kfree_skb(skb);
3808         return NULL;
3809 }
3810
3811 struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
3812                                                   int approxlen)
3813 {
3814         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3815
3816         if (WARN_ON(!rdev->testmode_info))
3817                 return NULL;
3818
3819         return __cfg80211_testmode_alloc_skb(rdev, approxlen,
3820                                 rdev->testmode_info->snd_pid,
3821                                 rdev->testmode_info->snd_seq,
3822                                 GFP_KERNEL);
3823 }
3824 EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);
3825
3826 int cfg80211_testmode_reply(struct sk_buff *skb)
3827 {
3828         struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
3829         void *hdr = ((void **)skb->cb)[1];
3830         struct nlattr *data = ((void **)skb->cb)[2];
3831
3832         if (WARN_ON(!rdev->testmode_info)) {
3833                 kfree_skb(skb);
3834                 return -EINVAL;
3835         }
3836
3837         nla_nest_end(skb, data);
3838         genlmsg_end(skb, hdr);
3839         return genlmsg_reply(skb, rdev->testmode_info);
3840 }
3841 EXPORT_SYMBOL(cfg80211_testmode_reply);
3842
3843 struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
3844                                                   int approxlen, gfp_t gfp)
3845 {
3846         struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
3847
3848         return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
3849 }
3850 EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);
3851
3852 void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
3853 {
3854         void *hdr = ((void **)skb->cb)[1];
3855         struct nlattr *data = ((void **)skb->cb)[2];
3856
3857         nla_nest_end(skb, data);
3858         genlmsg_end(skb, hdr);
3859         genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
3860 }
3861 EXPORT_SYMBOL(cfg80211_testmode_event);
3862 #endif
3863
3864 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
3865 {
3866         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3867         struct net_device *dev = info->user_ptr[1];
3868         struct cfg80211_connect_params connect;
3869         struct wiphy *wiphy;
3870         struct cfg80211_cached_keys *connkeys = NULL;
3871         int err;
3872
3873         memset(&connect, 0, sizeof(connect));
3874
3875         if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
3876                 return -EINVAL;
3877
3878         if (!info->attrs[NL80211_ATTR_SSID] ||
3879             !nla_len(info->attrs[NL80211_ATTR_SSID]))
3880                 return -EINVAL;
3881
3882         if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
3883                 connect.auth_type =
3884                         nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
3885                 if (!nl80211_valid_auth_type(connect.auth_type))
3886                         return -EINVAL;
3887         } else
3888                 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;
3889
3890         connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];
3891
3892         err = nl80211_crypto_settings(rdev, info, &connect.crypto,
3893                                       NL80211_MAX_NR_CIPHER_SUITES);
3894         if (err)
3895                 return err;
3896
3897         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3898             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3899                 return -EOPNOTSUPP;
3900
3901         wiphy = &rdev->wiphy;
3902
3903         if (info->attrs[NL80211_ATTR_MAC])
3904                 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3905         connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
3906         connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3907
3908         if (info->attrs[NL80211_ATTR_IE]) {
3909                 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
3910                 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3911         }
3912
3913         if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
3914                 connect.channel =
3915                         ieee80211_get_channel(wiphy,
3916                             nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
3917                 if (!connect.channel ||
3918                     connect.channel->flags & IEEE80211_CHAN_DISABLED)
3919                         return -EINVAL;
3920         }
3921
3922         if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
3923                 connkeys = nl80211_parse_connkeys(rdev,
3924                                         info->attrs[NL80211_ATTR_KEYS]);
3925                 if (IS_ERR(connkeys))
3926                         return PTR_ERR(connkeys);
3927         }
3928
3929         err = cfg80211_connect(rdev, dev, &connect, connkeys);
3930         if (err)
3931                 kfree(connkeys);
3932         return err;
3933 }
3934
3935 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
3936 {
3937         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3938         struct net_device *dev = info->user_ptr[1];
3939         u16 reason;
3940
3941         if (!info->attrs[NL80211_ATTR_REASON_CODE])
3942                 reason = WLAN_REASON_DEAUTH_LEAVING;
3943         else
3944                 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
3945
3946         if (reason == 0)
3947                 return -EINVAL;
3948
3949         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
3950             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
3951                 return -EOPNOTSUPP;
3952
3953         return cfg80211_disconnect(rdev, dev, reason, true);
3954 }
3955
3956 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
3957 {
3958         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3959         struct net *net;
3960         int err;
3961         u32 pid;
3962
3963         if (!info->attrs[NL80211_ATTR_PID])
3964                 return -EINVAL;
3965
3966         pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);
3967
3968         net = get_net_ns_by_pid(pid);
3969         if (IS_ERR(net))
3970                 return PTR_ERR(net);
3971
3972         err = 0;
3973
3974         /* check if anything to do */
3975         if (!net_eq(wiphy_net(&rdev->wiphy), net))
3976                 err = cfg80211_switch_netns(rdev, net);
3977
3978         put_net(net);
3979         return err;
3980 }
3981
3982 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info)
3983 {
3984         struct cfg80211_registered_device *rdev = info->user_ptr[0];
3985         int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev,
3986                         struct cfg80211_pmksa *pmksa) = NULL;
3987         struct net_device *dev = info->user_ptr[1];
3988         struct cfg80211_pmksa pmksa;
3989
3990         memset(&pmksa, 0, sizeof(struct cfg80211_pmksa));
3991
3992         if (!info->attrs[NL80211_ATTR_MAC])
3993                 return -EINVAL;
3994
3995         if (!info->attrs[NL80211_ATTR_PMKID])
3996                 return -EINVAL;
3997
3998         pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]);
3999         pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
4000
4001         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4002             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4003                 return -EOPNOTSUPP;
4004
4005         switch (info->genlhdr->cmd) {
4006         case NL80211_CMD_SET_PMKSA:
4007                 rdev_ops = rdev->ops->set_pmksa;
4008                 break;
4009         case NL80211_CMD_DEL_PMKSA:
4010                 rdev_ops = rdev->ops->del_pmksa;
4011                 break;
4012         default:
4013                 WARN_ON(1);
4014                 break;
4015         }
4016
4017         if (!rdev_ops)
4018                 return -EOPNOTSUPP;
4019
4020         return rdev_ops(&rdev->wiphy, dev, &pmksa);
4021 }
4022
4023 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info)
4024 {
4025         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4026         struct net_device *dev = info->user_ptr[1];
4027
4028         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4029             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT)
4030                 return -EOPNOTSUPP;
4031
4032         if (!rdev->ops->flush_pmksa)
4033                 return -EOPNOTSUPP;
4034
4035         return rdev->ops->flush_pmksa(&rdev->wiphy, dev);
4036 }
4037
4038 static int nl80211_remain_on_channel(struct sk_buff *skb,
4039                                      struct genl_info *info)
4040 {
4041         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4042         struct net_device *dev = info->user_ptr[1];
4043         struct ieee80211_channel *chan;
4044         struct sk_buff *msg;
4045         void *hdr;
4046         u64 cookie;
4047         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4048         u32 freq, duration;
4049         int err;
4050
4051         if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
4052             !info->attrs[NL80211_ATTR_DURATION])
4053                 return -EINVAL;
4054
4055         duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4056
4057         /*
4058          * We should be on that channel for at least one jiffie,
4059          * and more than 5 seconds seems excessive.
4060          */
4061         if (!duration || !msecs_to_jiffies(duration) || duration > 5000)
4062                 return -EINVAL;
4063
4064         if (!rdev->ops->remain_on_channel)
4065                 return -EOPNOTSUPP;
4066
4067         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4068                 channel_type = nla_get_u32(
4069                         info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4070                 if (channel_type != NL80211_CHAN_NO_HT &&
4071                     channel_type != NL80211_CHAN_HT20 &&
4072                     channel_type != NL80211_CHAN_HT40PLUS &&
4073                     channel_type != NL80211_CHAN_HT40MINUS)
4074                         return -EINVAL;
4075         }
4076
4077         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4078         chan = rdev_freq_to_chan(rdev, freq, channel_type);
4079         if (chan == NULL)
4080                 return -EINVAL;
4081
4082         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4083         if (!msg)
4084                 return -ENOMEM;
4085
4086         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4087                              NL80211_CMD_REMAIN_ON_CHANNEL);
4088
4089         if (IS_ERR(hdr)) {
4090                 err = PTR_ERR(hdr);
4091                 goto free_msg;
4092         }
4093
4094         err = rdev->ops->remain_on_channel(&rdev->wiphy, dev, chan,
4095                                            channel_type, duration, &cookie);
4096
4097         if (err)
4098                 goto free_msg;
4099
4100         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4101
4102         genlmsg_end(msg, hdr);
4103
4104         return genlmsg_reply(msg, info);
4105
4106  nla_put_failure:
4107         err = -ENOBUFS;
4108  free_msg:
4109         nlmsg_free(msg);
4110         return err;
4111 }
4112
4113 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb,
4114                                             struct genl_info *info)
4115 {
4116         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4117         struct net_device *dev = info->user_ptr[1];
4118         u64 cookie;
4119
4120         if (!info->attrs[NL80211_ATTR_COOKIE])
4121                 return -EINVAL;
4122
4123         if (!rdev->ops->cancel_remain_on_channel)
4124                 return -EOPNOTSUPP;
4125
4126         cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4127
4128         return rdev->ops->cancel_remain_on_channel(&rdev->wiphy, dev, cookie);
4129 }
4130
4131 static u32 rateset_to_mask(struct ieee80211_supported_band *sband,
4132                            u8 *rates, u8 rates_len)
4133 {
4134         u8 i;
4135         u32 mask = 0;
4136
4137         for (i = 0; i < rates_len; i++) {
4138                 int rate = (rates[i] & 0x7f) * 5;
4139                 int ridx;
4140                 for (ridx = 0; ridx < sband->n_bitrates; ridx++) {
4141                         struct ieee80211_rate *srate =
4142                                 &sband->bitrates[ridx];
4143                         if (rate == srate->bitrate) {
4144                                 mask |= 1 << ridx;
4145                                 break;
4146                         }
4147                 }
4148                 if (ridx == sband->n_bitrates)
4149                         return 0; /* rate not found */
4150         }
4151
4152         return mask;
4153 }
4154
4155 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = {
4156         [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY,
4157                                     .len = NL80211_MAX_SUPP_RATES },
4158 };
4159
4160 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb,
4161                                        struct genl_info *info)
4162 {
4163         struct nlattr *tb[NL80211_TXRATE_MAX + 1];
4164         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4165         struct cfg80211_bitrate_mask mask;
4166         int rem, i;
4167         struct net_device *dev = info->user_ptr[1];
4168         struct nlattr *tx_rates;
4169         struct ieee80211_supported_band *sband;
4170
4171         if (info->attrs[NL80211_ATTR_TX_RATES] == NULL)
4172                 return -EINVAL;
4173
4174         if (!rdev->ops->set_bitrate_mask)
4175                 return -EOPNOTSUPP;
4176
4177         memset(&mask, 0, sizeof(mask));
4178         /* Default to all rates enabled */
4179         for (i = 0; i < IEEE80211_NUM_BANDS; i++) {
4180                 sband = rdev->wiphy.bands[i];
4181                 mask.control[i].legacy =
4182                         sband ? (1 << sband->n_bitrates) - 1 : 0;
4183         }
4184
4185         /*
4186          * The nested attribute uses enum nl80211_band as the index. This maps
4187          * directly to the enum ieee80211_band values used in cfg80211.
4188          */
4189         nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem)
4190         {
4191                 enum ieee80211_band band = nla_type(tx_rates);
4192                 if (band < 0 || band >= IEEE80211_NUM_BANDS)
4193                         return -EINVAL;
4194                 sband = rdev->wiphy.bands[band];
4195                 if (sband == NULL)
4196                         return -EINVAL;
4197                 nla_parse(tb, NL80211_TXRATE_MAX, nla_data(tx_rates),
4198                           nla_len(tx_rates), nl80211_txattr_policy);
4199                 if (tb[NL80211_TXRATE_LEGACY]) {
4200                         mask.control[band].legacy = rateset_to_mask(
4201                                 sband,
4202                                 nla_data(tb[NL80211_TXRATE_LEGACY]),
4203                                 nla_len(tb[NL80211_TXRATE_LEGACY]));
4204                         if (mask.control[band].legacy == 0)
4205                                 return -EINVAL;
4206                 }
4207         }
4208
4209         return rdev->ops->set_bitrate_mask(&rdev->wiphy, dev, NULL, &mask);
4210 }
4211
4212 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info)
4213 {
4214         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4215         struct net_device *dev = info->user_ptr[1];
4216         u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION;
4217
4218         if (!info->attrs[NL80211_ATTR_FRAME_MATCH])
4219                 return -EINVAL;
4220
4221         if (info->attrs[NL80211_ATTR_FRAME_TYPE])
4222                 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]);
4223
4224         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4225             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4226             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4227             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4228             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4229             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4230                 return -EOPNOTSUPP;
4231
4232         /* not much point in registering if we can't reply */
4233         if (!rdev->ops->mgmt_tx)
4234                 return -EOPNOTSUPP;
4235
4236         return cfg80211_mlme_register_mgmt(dev->ieee80211_ptr, info->snd_pid,
4237                         frame_type,
4238                         nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]),
4239                         nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH]));
4240 }
4241
4242 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info)
4243 {
4244         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4245         struct net_device *dev = info->user_ptr[1];
4246         struct ieee80211_channel *chan;
4247         enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
4248         bool channel_type_valid = false;
4249         u32 freq;
4250         int err;
4251         void *hdr;
4252         u64 cookie;
4253         struct sk_buff *msg;
4254         unsigned int wait = 0;
4255         bool offchan;
4256
4257         if (!info->attrs[NL80211_ATTR_FRAME] ||
4258             !info->attrs[NL80211_ATTR_WIPHY_FREQ])
4259                 return -EINVAL;
4260
4261         if (!rdev->ops->mgmt_tx)
4262                 return -EOPNOTSUPP;
4263
4264         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4265             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4266             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4267             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4268             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4269             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4270                 return -EOPNOTSUPP;
4271
4272         if (info->attrs[NL80211_ATTR_DURATION]) {
4273                 if (!rdev->ops->mgmt_tx_cancel_wait)
4274                         return -EINVAL;
4275                 wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]);
4276         }
4277
4278         if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
4279                 channel_type = nla_get_u32(
4280                         info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
4281                 if (channel_type != NL80211_CHAN_NO_HT &&
4282                     channel_type != NL80211_CHAN_HT20 &&
4283                     channel_type != NL80211_CHAN_HT40PLUS &&
4284                     channel_type != NL80211_CHAN_HT40MINUS)
4285                         return -EINVAL;
4286                 channel_type_valid = true;
4287         }
4288
4289         offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK];
4290
4291         freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
4292         chan = rdev_freq_to_chan(rdev, freq, channel_type);
4293         if (chan == NULL)
4294                 return -EINVAL;
4295
4296         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4297         if (!msg)
4298                 return -ENOMEM;
4299
4300         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4301                              NL80211_CMD_FRAME);
4302
4303         if (IS_ERR(hdr)) {
4304                 err = PTR_ERR(hdr);
4305                 goto free_msg;
4306         }
4307         err = cfg80211_mlme_mgmt_tx(rdev, dev, chan, offchan, channel_type,
4308                                     channel_type_valid, wait,
4309                                     nla_data(info->attrs[NL80211_ATTR_FRAME]),
4310                                     nla_len(info->attrs[NL80211_ATTR_FRAME]),
4311                                     &cookie);
4312         if (err)
4313                 goto free_msg;
4314
4315         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
4316
4317         genlmsg_end(msg, hdr);
4318         return genlmsg_reply(msg, info);
4319
4320  nla_put_failure:
4321         err = -ENOBUFS;
4322  free_msg:
4323         nlmsg_free(msg);
4324         return err;
4325 }
4326
4327 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info)
4328 {
4329         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4330         struct net_device *dev = info->user_ptr[1];
4331         u64 cookie;
4332
4333         if (!info->attrs[NL80211_ATTR_COOKIE])
4334                 return -EINVAL;
4335
4336         if (!rdev->ops->mgmt_tx_cancel_wait)
4337                 return -EOPNOTSUPP;
4338
4339         if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION &&
4340             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC &&
4341             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT &&
4342             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
4343             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
4344             dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO)
4345                 return -EOPNOTSUPP;
4346
4347         cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]);
4348
4349         return rdev->ops->mgmt_tx_cancel_wait(&rdev->wiphy, dev, cookie);
4350 }
4351
4352 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info)
4353 {
4354         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4355         struct wireless_dev *wdev;
4356         struct net_device *dev = info->user_ptr[1];
4357         u8 ps_state;
4358         bool state;
4359         int err;
4360
4361         if (!info->attrs[NL80211_ATTR_PS_STATE])
4362                 return -EINVAL;
4363
4364         ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]);
4365
4366         if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED)
4367                 return -EINVAL;
4368
4369         wdev = dev->ieee80211_ptr;
4370
4371         if (!rdev->ops->set_power_mgmt)
4372                 return -EOPNOTSUPP;
4373
4374         state = (ps_state == NL80211_PS_ENABLED) ? true : false;
4375
4376         if (state == wdev->ps)
4377                 return 0;
4378
4379         err = rdev->ops->set_power_mgmt(wdev->wiphy, dev, state,
4380                                         wdev->ps_timeout);
4381         if (!err)
4382                 wdev->ps = state;
4383         return err;
4384 }
4385
4386 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info)
4387 {
4388         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4389         enum nl80211_ps_state ps_state;
4390         struct wireless_dev *wdev;
4391         struct net_device *dev = info->user_ptr[1];
4392         struct sk_buff *msg;
4393         void *hdr;
4394         int err;
4395
4396         wdev = dev->ieee80211_ptr;
4397
4398         if (!rdev->ops->set_power_mgmt)
4399                 return -EOPNOTSUPP;
4400
4401         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4402         if (!msg)
4403                 return -ENOMEM;
4404
4405         hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
4406                              NL80211_CMD_GET_POWER_SAVE);
4407         if (!hdr) {
4408                 err = -ENOBUFS;
4409                 goto free_msg;
4410         }
4411
4412         if (wdev->ps)
4413                 ps_state = NL80211_PS_ENABLED;
4414         else
4415                 ps_state = NL80211_PS_DISABLED;
4416
4417         NLA_PUT_U32(msg, NL80211_ATTR_PS_STATE, ps_state);
4418
4419         genlmsg_end(msg, hdr);
4420         return genlmsg_reply(msg, info);
4421
4422  nla_put_failure:
4423         err = -ENOBUFS;
4424  free_msg:
4425         nlmsg_free(msg);
4426         return err;
4427 }
4428
4429 static struct nla_policy
4430 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] __read_mostly = {
4431         [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 },
4432         [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 },
4433         [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 },
4434 };
4435
4436 static int nl80211_set_cqm_rssi(struct genl_info *info,
4437                                 s32 threshold, u32 hysteresis)
4438 {
4439         struct cfg80211_registered_device *rdev = info->user_ptr[0];
4440         struct wireless_dev *wdev;
4441         struct net_device *dev = info->user_ptr[1];
4442
4443         if (threshold > 0)
4444                 return -EINVAL;
4445
4446         wdev = dev->ieee80211_ptr;
4447
4448         if (!rdev->ops->set_cqm_rssi_config)
4449                 return -EOPNOTSUPP;
4450
4451         if (wdev->iftype != NL80211_IFTYPE_STATION &&
4452             wdev->iftype != NL80211_IFTYPE_P2P_CLIENT)
4453                 return -EOPNOTSUPP;
4454
4455         return rdev->ops->set_cqm_rssi_config(wdev->wiphy, dev,
4456                                               threshold, hysteresis);
4457 }
4458
4459 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info)
4460 {
4461         struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1];
4462         struct nlattr *cqm;
4463         int err;
4464
4465         cqm = info->attrs[NL80211_ATTR_CQM];
4466         if (!cqm) {
4467                 err = -EINVAL;
4468                 goto out;
4469         }
4470
4471         err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm,
4472                                nl80211_attr_cqm_policy);
4473         if (err)
4474                 goto out;
4475
4476         if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] &&
4477             attrs[NL80211_ATTR_CQM_RSSI_HYST]) {
4478                 s32 threshold;
4479                 u32 hysteresis;
4480                 threshold = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]);
4481                 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]);
4482                 err = nl80211_set_cqm_rssi(info, threshold, hysteresis);
4483         } else
4484                 err = -EINVAL;
4485
4486 out:
4487         return err;
4488 }
4489
4490 #define NL80211_FLAG_NEED_WIPHY         0x01
4491 #define NL80211_FLAG_NEED_NETDEV        0x02
4492 #define NL80211_FLAG_NEED_RTNL          0x04
4493 #define NL80211_FLAG_CHECK_NETDEV_UP    0x08
4494 #define NL80211_FLAG_NEED_NETDEV_UP     (NL80211_FLAG_NEED_NETDEV |\
4495                                          NL80211_FLAG_CHECK_NETDEV_UP)
4496
4497 static int nl80211_pre_doit(struct genl_ops *ops, struct sk_buff *skb,
4498                             struct genl_info *info)
4499 {
4500         struct cfg80211_registered_device *rdev;
4501         struct net_device *dev;
4502         int err;
4503         bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL;
4504
4505         if (rtnl)
4506                 rtnl_lock();
4507
4508         if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) {
4509                 rdev = cfg80211_get_dev_from_info(info);
4510                 if (IS_ERR(rdev)) {
4511                         if (rtnl)
4512                                 rtnl_unlock();
4513                         return PTR_ERR(rdev);
4514                 }
4515                 info->user_ptr[0] = rdev;
4516         } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) {
4517                 err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
4518                 if (err) {
4519                         if (rtnl)
4520                                 rtnl_unlock();
4521                         return err;
4522                 }
4523                 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP &&
4524                     !netif_running(dev)) {
4525                         cfg80211_unlock_rdev(rdev);
4526                         dev_put(dev);
4527                         if (rtnl)
4528                                 rtnl_unlock();
4529                         return -ENETDOWN;
4530                 }
4531                 info->user_ptr[0] = rdev;
4532                 info->user_ptr[1] = dev;
4533         }
4534
4535         return 0;
4536 }
4537
4538 static void nl80211_post_doit(struct genl_ops *ops, struct sk_buff *skb,
4539                               struct genl_info *info)
4540 {
4541         if (info->user_ptr[0])
4542                 cfg80211_unlock_rdev(info->user_ptr[0]);
4543         if (info->user_ptr[1])
4544                 dev_put(info->user_ptr[1]);
4545         if (ops->internal_flags & NL80211_FLAG_NEED_RTNL)
4546                 rtnl_unlock();
4547 }
4548
4549 static struct genl_ops nl80211_ops[] = {
4550         {
4551                 .cmd = NL80211_CMD_GET_WIPHY,
4552                 .doit = nl80211_get_wiphy,
4553                 .dumpit = nl80211_dump_wiphy,
4554                 .policy = nl80211_policy,
4555                 /* can be retrieved by unprivileged users */
4556                 .internal_flags = NL80211_FLAG_NEED_WIPHY,
4557         },
4558         {
4559                 .cmd = NL80211_CMD_SET_WIPHY,
4560                 .doit = nl80211_set_wiphy,
4561                 .policy = nl80211_policy,
4562                 .flags = GENL_ADMIN_PERM,
4563                 .internal_flags = NL80211_FLAG_NEED_RTNL,
4564         },
4565         {
4566                 .cmd = NL80211_CMD_GET_INTERFACE,
4567                 .doit = nl80211_get_interface,
4568                 .dumpit = nl80211_dump_interface,
4569                 .policy = nl80211_policy,
4570                 /* can be retrieved by unprivileged users */
4571                 .internal_flags = NL80211_FLAG_NEED_NETDEV,
4572         },
4573         {
4574                 .cmd = NL80211_CMD_SET_INTERFACE,
4575                 .doit = nl80211_set_interface,
4576                 .policy = nl80211_policy,
4577                 .flags = GENL_ADMIN_PERM,
4578                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4579                                   NL80211_FLAG_NEED_RTNL,
4580         },
4581         {
4582                 .cmd = NL80211_CMD_NEW_INTERFACE,
4583                 .doit = nl80211_new_interface,
4584                 .policy = nl80211_policy,
4585                 .flags = GENL_ADMIN_PERM,
4586                 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4587                                   NL80211_FLAG_NEED_RTNL,
4588         },
4589         {
4590                 .cmd = NL80211_CMD_DEL_INTERFACE,
4591                 .doit = nl80211_del_interface,
4592                 .policy = nl80211_policy,
4593                 .flags = GENL_ADMIN_PERM,
4594                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4595                                   NL80211_FLAG_NEED_RTNL,
4596         },
4597         {
4598                 .cmd = NL80211_CMD_GET_KEY,
4599                 .doit = nl80211_get_key,
4600                 .policy = nl80211_policy,
4601                 .flags = GENL_ADMIN_PERM,
4602                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4603                                   NL80211_FLAG_NEED_RTNL,
4604         },
4605         {
4606                 .cmd = NL80211_CMD_SET_KEY,
4607                 .doit = nl80211_set_key,
4608                 .policy = nl80211_policy,
4609                 .flags = GENL_ADMIN_PERM,
4610                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4611                                   NL80211_FLAG_NEED_RTNL,
4612         },
4613         {
4614                 .cmd = NL80211_CMD_NEW_KEY,
4615                 .doit = nl80211_new_key,
4616                 .policy = nl80211_policy,
4617                 .flags = GENL_ADMIN_PERM,
4618                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4619                                   NL80211_FLAG_NEED_RTNL,
4620         },
4621         {
4622                 .cmd = NL80211_CMD_DEL_KEY,
4623                 .doit = nl80211_del_key,
4624                 .policy = nl80211_policy,
4625                 .flags = GENL_ADMIN_PERM,
4626                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4627                                   NL80211_FLAG_NEED_RTNL,
4628         },
4629         {
4630                 .cmd = NL80211_CMD_SET_BEACON,
4631                 .policy = nl80211_policy,
4632                 .flags = GENL_ADMIN_PERM,
4633                 .doit = nl80211_addset_beacon,
4634                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4635                                   NL80211_FLAG_NEED_RTNL,
4636         },
4637         {
4638                 .cmd = NL80211_CMD_NEW_BEACON,
4639                 .policy = nl80211_policy,
4640                 .flags = GENL_ADMIN_PERM,
4641                 .doit = nl80211_addset_beacon,
4642                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4643                                   NL80211_FLAG_NEED_RTNL,
4644         },
4645         {
4646                 .cmd = NL80211_CMD_DEL_BEACON,
4647                 .policy = nl80211_policy,
4648                 .flags = GENL_ADMIN_PERM,
4649                 .doit = nl80211_del_beacon,
4650                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4651                                   NL80211_FLAG_NEED_RTNL,
4652         },
4653         {
4654                 .cmd = NL80211_CMD_GET_STATION,
4655                 .doit = nl80211_get_station,
4656                 .dumpit = nl80211_dump_station,
4657                 .policy = nl80211_policy,
4658                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4659                                   NL80211_FLAG_NEED_RTNL,
4660         },
4661         {
4662                 .cmd = NL80211_CMD_SET_STATION,
4663                 .doit = nl80211_set_station,
4664                 .policy = nl80211_policy,
4665                 .flags = GENL_ADMIN_PERM,
4666                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4667                                   NL80211_FLAG_NEED_RTNL,
4668         },
4669         {
4670                 .cmd = NL80211_CMD_NEW_STATION,
4671                 .doit = nl80211_new_station,
4672                 .policy = nl80211_policy,
4673                 .flags = GENL_ADMIN_PERM,
4674                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4675                                   NL80211_FLAG_NEED_RTNL,
4676         },
4677         {
4678                 .cmd = NL80211_CMD_DEL_STATION,
4679                 .doit = nl80211_del_station,
4680                 .policy = nl80211_policy,
4681                 .flags = GENL_ADMIN_PERM,
4682                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4683                                   NL80211_FLAG_NEED_RTNL,
4684         },
4685         {
4686                 .cmd = NL80211_CMD_GET_MPATH,
4687                 .doit = nl80211_get_mpath,
4688                 .dumpit = nl80211_dump_mpath,
4689                 .policy = nl80211_policy,
4690                 .flags = GENL_ADMIN_PERM,
4691                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4692                                   NL80211_FLAG_NEED_RTNL,
4693         },
4694         {
4695                 .cmd = NL80211_CMD_SET_MPATH,
4696                 .doit = nl80211_set_mpath,
4697                 .policy = nl80211_policy,
4698                 .flags = GENL_ADMIN_PERM,
4699                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4700                                   NL80211_FLAG_NEED_RTNL,
4701         },
4702         {
4703                 .cmd = NL80211_CMD_NEW_MPATH,
4704                 .doit = nl80211_new_mpath,
4705                 .policy = nl80211_policy,
4706                 .flags = GENL_ADMIN_PERM,
4707                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4708                                   NL80211_FLAG_NEED_RTNL,
4709         },
4710         {
4711                 .cmd = NL80211_CMD_DEL_MPATH,
4712                 .doit = nl80211_del_mpath,
4713                 .policy = nl80211_policy,
4714                 .flags = GENL_ADMIN_PERM,
4715                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4716                                   NL80211_FLAG_NEED_RTNL,
4717         },
4718         {
4719                 .cmd = NL80211_CMD_SET_BSS,
4720                 .doit = nl80211_set_bss,
4721                 .policy = nl80211_policy,
4722                 .flags = GENL_ADMIN_PERM,
4723                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4724                                   NL80211_FLAG_NEED_RTNL,
4725         },
4726         {
4727                 .cmd = NL80211_CMD_GET_REG,
4728                 .doit = nl80211_get_reg,
4729                 .policy = nl80211_policy,
4730                 /* can be retrieved by unprivileged users */
4731         },
4732         {
4733                 .cmd = NL80211_CMD_SET_REG,
4734                 .doit = nl80211_set_reg,
4735                 .policy = nl80211_policy,
4736                 .flags = GENL_ADMIN_PERM,
4737         },
4738         {
4739                 .cmd = NL80211_CMD_REQ_SET_REG,
4740                 .doit = nl80211_req_set_reg,
4741                 .policy = nl80211_policy,
4742                 .flags = GENL_ADMIN_PERM,
4743         },
4744         {
4745                 .cmd = NL80211_CMD_GET_MESH_PARAMS,
4746                 .doit = nl80211_get_mesh_params,
4747                 .policy = nl80211_policy,
4748                 /* can be retrieved by unprivileged users */
4749                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4750                                   NL80211_FLAG_NEED_RTNL,
4751         },
4752         {
4753                 .cmd = NL80211_CMD_SET_MESH_PARAMS,
4754                 .doit = nl80211_set_mesh_params,
4755                 .policy = nl80211_policy,
4756                 .flags = GENL_ADMIN_PERM,
4757                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4758                                   NL80211_FLAG_NEED_RTNL,
4759         },
4760         {
4761                 .cmd = NL80211_CMD_TRIGGER_SCAN,
4762                 .doit = nl80211_trigger_scan,
4763                 .policy = nl80211_policy,
4764                 .flags = GENL_ADMIN_PERM,
4765                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4766                                   NL80211_FLAG_NEED_RTNL,
4767         },
4768         {
4769                 .cmd = NL80211_CMD_GET_SCAN,
4770                 .policy = nl80211_policy,
4771                 .dumpit = nl80211_dump_scan,
4772         },
4773         {
4774                 .cmd = NL80211_CMD_AUTHENTICATE,
4775                 .doit = nl80211_authenticate,
4776                 .policy = nl80211_policy,
4777                 .flags = GENL_ADMIN_PERM,
4778                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4779                                   NL80211_FLAG_NEED_RTNL,
4780         },
4781         {
4782                 .cmd = NL80211_CMD_ASSOCIATE,
4783                 .doit = nl80211_associate,
4784                 .policy = nl80211_policy,
4785                 .flags = GENL_ADMIN_PERM,
4786                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4787                                   NL80211_FLAG_NEED_RTNL,
4788         },
4789         {
4790                 .cmd = NL80211_CMD_DEAUTHENTICATE,
4791                 .doit = nl80211_deauthenticate,
4792                 .policy = nl80211_policy,
4793                 .flags = GENL_ADMIN_PERM,
4794                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4795                                   NL80211_FLAG_NEED_RTNL,
4796         },
4797         {
4798                 .cmd = NL80211_CMD_DISASSOCIATE,
4799                 .doit = nl80211_disassociate,
4800                 .policy = nl80211_policy,
4801                 .flags = GENL_ADMIN_PERM,
4802                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4803                                   NL80211_FLAG_NEED_RTNL,
4804         },
4805         {
4806                 .cmd = NL80211_CMD_JOIN_IBSS,
4807                 .doit = nl80211_join_ibss,
4808                 .policy = nl80211_policy,
4809                 .flags = GENL_ADMIN_PERM,
4810                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4811                                   NL80211_FLAG_NEED_RTNL,
4812         },
4813         {
4814                 .cmd = NL80211_CMD_LEAVE_IBSS,
4815                 .doit = nl80211_leave_ibss,
4816                 .policy = nl80211_policy,
4817                 .flags = GENL_ADMIN_PERM,
4818                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4819                                   NL80211_FLAG_NEED_RTNL,
4820         },
4821 #ifdef CONFIG_NL80211_TESTMODE
4822         {
4823                 .cmd = NL80211_CMD_TESTMODE,
4824                 .doit = nl80211_testmode_do,
4825                 .policy = nl80211_policy,
4826                 .flags = GENL_ADMIN_PERM,
4827                 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4828                                   NL80211_FLAG_NEED_RTNL,
4829         },
4830 #endif
4831         {
4832                 .cmd = NL80211_CMD_CONNECT,
4833                 .doit = nl80211_connect,
4834                 .policy = nl80211_policy,
4835                 .flags = GENL_ADMIN_PERM,
4836                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4837                                   NL80211_FLAG_NEED_RTNL,
4838         },
4839         {
4840                 .cmd = NL80211_CMD_DISCONNECT,
4841                 .doit = nl80211_disconnect,
4842                 .policy = nl80211_policy,
4843                 .flags = GENL_ADMIN_PERM,
4844                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4845                                   NL80211_FLAG_NEED_RTNL,
4846         },
4847         {
4848                 .cmd = NL80211_CMD_SET_WIPHY_NETNS,
4849                 .doit = nl80211_wiphy_netns,
4850                 .policy = nl80211_policy,
4851                 .flags = GENL_ADMIN_PERM,
4852                 .internal_flags = NL80211_FLAG_NEED_WIPHY |
4853                                   NL80211_FLAG_NEED_RTNL,
4854         },
4855         {
4856                 .cmd = NL80211_CMD_GET_SURVEY,
4857                 .policy = nl80211_policy,
4858                 .dumpit = nl80211_dump_survey,
4859         },
4860         {
4861                 .cmd = NL80211_CMD_SET_PMKSA,
4862                 .doit = nl80211_setdel_pmksa,
4863                 .policy = nl80211_policy,
4864                 .flags = GENL_ADMIN_PERM,
4865                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4866                                   NL80211_FLAG_NEED_RTNL,
4867         },
4868         {
4869                 .cmd = NL80211_CMD_DEL_PMKSA,
4870                 .doit = nl80211_setdel_pmksa,
4871                 .policy = nl80211_policy,
4872                 .flags = GENL_ADMIN_PERM,
4873                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4874                                   NL80211_FLAG_NEED_RTNL,
4875         },
4876         {
4877                 .cmd = NL80211_CMD_FLUSH_PMKSA,
4878                 .doit = nl80211_flush_pmksa,
4879                 .policy = nl80211_policy,
4880                 .flags = GENL_ADMIN_PERM,
4881                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4882                                   NL80211_FLAG_NEED_RTNL,
4883         },
4884         {
4885                 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL,
4886                 .doit = nl80211_remain_on_channel,
4887                 .policy = nl80211_policy,
4888                 .flags = GENL_ADMIN_PERM,
4889                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4890                                   NL80211_FLAG_NEED_RTNL,
4891         },
4892         {
4893                 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
4894                 .doit = nl80211_cancel_remain_on_channel,
4895                 .policy = nl80211_policy,
4896                 .flags = GENL_ADMIN_PERM,
4897                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4898                                   NL80211_FLAG_NEED_RTNL,
4899         },
4900         {
4901                 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK,
4902                 .doit = nl80211_set_tx_bitrate_mask,
4903                 .policy = nl80211_policy,
4904                 .flags = GENL_ADMIN_PERM,
4905                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4906                                   NL80211_FLAG_NEED_RTNL,
4907         },
4908         {
4909                 .cmd = NL80211_CMD_REGISTER_FRAME,
4910                 .doit = nl80211_register_mgmt,
4911                 .policy = nl80211_policy,
4912                 .flags = GENL_ADMIN_PERM,
4913                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4914                                   NL80211_FLAG_NEED_RTNL,
4915         },
4916         {
4917                 .cmd = NL80211_CMD_FRAME,
4918                 .doit = nl80211_tx_mgmt,
4919                 .policy = nl80211_policy,
4920                 .flags = GENL_ADMIN_PERM,
4921                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4922                                   NL80211_FLAG_NEED_RTNL,
4923         },
4924         {
4925                 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL,
4926                 .doit = nl80211_tx_mgmt_cancel_wait,
4927                 .policy = nl80211_policy,
4928                 .flags = GENL_ADMIN_PERM,
4929                 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP |
4930                                   NL80211_FLAG_NEED_RTNL,
4931         },
4932         {
4933                 .cmd = NL80211_CMD_SET_POWER_SAVE,
4934                 .doit = nl80211_set_power_save,
4935                 .policy = nl80211_policy,
4936                 .flags = GENL_ADMIN_PERM,
4937                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4938                                   NL80211_FLAG_NEED_RTNL,
4939         },
4940         {
4941                 .cmd = NL80211_CMD_GET_POWER_SAVE,
4942                 .doit = nl80211_get_power_save,
4943                 .policy = nl80211_policy,
4944                 /* can be retrieved by unprivileged users */
4945                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4946                                   NL80211_FLAG_NEED_RTNL,
4947         },
4948         {
4949                 .cmd = NL80211_CMD_SET_CQM,
4950                 .doit = nl80211_set_cqm,
4951                 .policy = nl80211_policy,
4952                 .flags = GENL_ADMIN_PERM,
4953                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4954                                   NL80211_FLAG_NEED_RTNL,
4955         },
4956         {
4957                 .cmd = NL80211_CMD_SET_CHANNEL,
4958                 .doit = nl80211_set_channel,
4959                 .policy = nl80211_policy,
4960                 .flags = GENL_ADMIN_PERM,
4961                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4962                                   NL80211_FLAG_NEED_RTNL,
4963         },
4964         {
4965                 .cmd = NL80211_CMD_SET_WDS_PEER,
4966                 .doit = nl80211_set_wds_peer,
4967                 .policy = nl80211_policy,
4968                 .flags = GENL_ADMIN_PERM,
4969                 .internal_flags = NL80211_FLAG_NEED_NETDEV |
4970                                   NL80211_FLAG_NEED_RTNL,
4971         },
4972 };
4973
4974 static struct genl_multicast_group nl80211_mlme_mcgrp = {
4975         .name = "mlme",
4976 };
4977
4978 /* multicast groups */
4979 static struct genl_multicast_group nl80211_config_mcgrp = {
4980         .name = "config",
4981 };
4982 static struct genl_multicast_group nl80211_scan_mcgrp = {
4983         .name = "scan",
4984 };
4985 static struct genl_multicast_group nl80211_regulatory_mcgrp = {
4986         .name = "regulatory",
4987 };
4988
4989 /* notification functions */
4990
4991 void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
4992 {
4993         struct sk_buff *msg;
4994
4995         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4996         if (!msg)
4997                 return;
4998
4999         if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
5000                 nlmsg_free(msg);
5001                 return;
5002         }
5003
5004         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5005                                 nl80211_config_mcgrp.id, GFP_KERNEL);
5006 }
5007
5008 static int nl80211_add_scan_req(struct sk_buff *msg,
5009                                 struct cfg80211_registered_device *rdev)
5010 {
5011         struct cfg80211_scan_request *req = rdev->scan_req;
5012         struct nlattr *nest;
5013         int i;
5014
5015         ASSERT_RDEV_LOCK(rdev);
5016
5017         if (WARN_ON(!req))
5018                 return 0;
5019
5020         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
5021         if (!nest)
5022                 goto nla_put_failure;
5023         for (i = 0; i < req->n_ssids; i++)
5024                 NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
5025         nla_nest_end(msg, nest);
5026
5027         nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
5028         if (!nest)
5029                 goto nla_put_failure;
5030         for (i = 0; i < req->n_channels; i++)
5031                 NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
5032         nla_nest_end(msg, nest);
5033
5034         if (req->ie)
5035                 NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);
5036
5037         return 0;
5038  nla_put_failure:
5039         return -ENOBUFS;
5040 }
5041
5042 static int nl80211_send_scan_msg(struct sk_buff *msg,
5043                                  struct cfg80211_registered_device *rdev,
5044                                  struct net_device *netdev,
5045                                  u32 pid, u32 seq, int flags,
5046                                  u32 cmd)
5047 {
5048         void *hdr;
5049
5050         hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
5051         if (!hdr)
5052                 return -1;
5053
5054         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5055         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5056
5057         /* ignore errors and send incomplete event anyway */
5058         nl80211_add_scan_req(msg, rdev);
5059
5060         return genlmsg_end(msg, hdr);
5061
5062  nla_put_failure:
5063         genlmsg_cancel(msg, hdr);
5064         return -EMSGSIZE;
5065 }
5066
5067 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
5068                              struct net_device *netdev)
5069 {
5070         struct sk_buff *msg;
5071
5072         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5073         if (!msg)
5074                 return;
5075
5076         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5077                                   NL80211_CMD_TRIGGER_SCAN) < 0) {
5078                 nlmsg_free(msg);
5079                 return;
5080         }
5081
5082         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5083                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
5084 }
5085
5086 void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
5087                             struct net_device *netdev)
5088 {
5089         struct sk_buff *msg;
5090
5091         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5092         if (!msg)
5093                 return;
5094
5095         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5096                                   NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
5097                 nlmsg_free(msg);
5098                 return;
5099         }
5100
5101         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5102                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
5103 }
5104
5105 void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
5106                                struct net_device *netdev)
5107 {
5108         struct sk_buff *msg;
5109
5110         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5111         if (!msg)
5112                 return;
5113
5114         if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
5115                                   NL80211_CMD_SCAN_ABORTED) < 0) {
5116                 nlmsg_free(msg);
5117                 return;
5118         }
5119
5120         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5121                                 nl80211_scan_mcgrp.id, GFP_KERNEL);
5122 }
5123
5124 /*
5125  * This can happen on global regulatory changes or device specific settings
5126  * based on custom world regulatory domains.
5127  */
5128 void nl80211_send_reg_change_event(struct regulatory_request *request)
5129 {
5130         struct sk_buff *msg;
5131         void *hdr;
5132
5133         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
5134         if (!msg)
5135                 return;
5136
5137         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
5138         if (!hdr) {
5139                 nlmsg_free(msg);
5140                 return;
5141         }
5142
5143         /* Userspace can always count this one always being set */
5144         NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);
5145
5146         if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
5147                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5148                            NL80211_REGDOM_TYPE_WORLD);
5149         else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
5150                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5151                            NL80211_REGDOM_TYPE_CUSTOM_WORLD);
5152         else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
5153                  request->intersect)
5154                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5155                            NL80211_REGDOM_TYPE_INTERSECTION);
5156         else {
5157                 NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
5158                            NL80211_REGDOM_TYPE_COUNTRY);
5159                 NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
5160         }
5161
5162         if (wiphy_idx_valid(request->wiphy_idx))
5163                 NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);
5164
5165         if (genlmsg_end(msg, hdr) < 0) {
5166                 nlmsg_free(msg);
5167                 return;
5168         }
5169
5170         rcu_read_lock();
5171         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5172                                 GFP_ATOMIC);
5173         rcu_read_unlock();
5174
5175         return;
5176
5177 nla_put_failure:
5178         genlmsg_cancel(msg, hdr);
5179         nlmsg_free(msg);
5180 }
5181
5182 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
5183                                     struct net_device *netdev,
5184                                     const u8 *buf, size_t len,
5185                                     enum nl80211_commands cmd, gfp_t gfp)
5186 {
5187         struct sk_buff *msg;
5188         void *hdr;
5189
5190         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5191         if (!msg)
5192                 return;
5193
5194         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5195         if (!hdr) {
5196                 nlmsg_free(msg);
5197                 return;
5198         }
5199
5200         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5201         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5202         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5203
5204         if (genlmsg_end(msg, hdr) < 0) {
5205                 nlmsg_free(msg);
5206                 return;
5207         }
5208
5209         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5210                                 nl80211_mlme_mcgrp.id, gfp);
5211         return;
5212
5213  nla_put_failure:
5214         genlmsg_cancel(msg, hdr);
5215         nlmsg_free(msg);
5216 }
5217
5218 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
5219                           struct net_device *netdev, const u8 *buf,
5220                           size_t len, gfp_t gfp)
5221 {
5222         nl80211_send_mlme_event(rdev, netdev, buf, len,
5223                                 NL80211_CMD_AUTHENTICATE, gfp);
5224 }
5225
5226 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
5227                            struct net_device *netdev, const u8 *buf,
5228                            size_t len, gfp_t gfp)
5229 {
5230         nl80211_send_mlme_event(rdev, netdev, buf, len,
5231                                 NL80211_CMD_ASSOCIATE, gfp);
5232 }
5233
5234 void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
5235                          struct net_device *netdev, const u8 *buf,
5236                          size_t len, gfp_t gfp)
5237 {
5238         nl80211_send_mlme_event(rdev, netdev, buf, len,
5239                                 NL80211_CMD_DEAUTHENTICATE, gfp);
5240 }
5241
5242 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
5243                            struct net_device *netdev, const u8 *buf,
5244                            size_t len, gfp_t gfp)
5245 {
5246         nl80211_send_mlme_event(rdev, netdev, buf, len,
5247                                 NL80211_CMD_DISASSOCIATE, gfp);
5248 }
5249
5250 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
5251                                       struct net_device *netdev, int cmd,
5252                                       const u8 *addr, gfp_t gfp)
5253 {
5254         struct sk_buff *msg;
5255         void *hdr;
5256
5257         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5258         if (!msg)
5259                 return;
5260
5261         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5262         if (!hdr) {
5263                 nlmsg_free(msg);
5264                 return;
5265         }
5266
5267         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5268         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5269         NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
5270         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5271
5272         if (genlmsg_end(msg, hdr) < 0) {
5273                 nlmsg_free(msg);
5274                 return;
5275         }
5276
5277         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5278                                 nl80211_mlme_mcgrp.id, gfp);
5279         return;
5280
5281  nla_put_failure:
5282         genlmsg_cancel(msg, hdr);
5283         nlmsg_free(msg);
5284 }
5285
5286 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
5287                                struct net_device *netdev, const u8 *addr,
5288                                gfp_t gfp)
5289 {
5290         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
5291                                   addr, gfp);
5292 }
5293
5294 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
5295                                 struct net_device *netdev, const u8 *addr,
5296                                 gfp_t gfp)
5297 {
5298         nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
5299                                   addr, gfp);
5300 }
5301
5302 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
5303                                  struct net_device *netdev, const u8 *bssid,
5304                                  const u8 *req_ie, size_t req_ie_len,
5305                                  const u8 *resp_ie, size_t resp_ie_len,
5306                                  u16 status, gfp_t gfp)
5307 {
5308         struct sk_buff *msg;
5309         void *hdr;
5310
5311         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5312         if (!msg)
5313                 return;
5314
5315         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
5316         if (!hdr) {
5317                 nlmsg_free(msg);
5318                 return;
5319         }
5320
5321         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5322         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5323         if (bssid)
5324                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5325         NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
5326         if (req_ie)
5327                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5328         if (resp_ie)
5329                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5330
5331         if (genlmsg_end(msg, hdr) < 0) {
5332                 nlmsg_free(msg);
5333                 return;
5334         }
5335
5336         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5337                                 nl80211_mlme_mcgrp.id, gfp);
5338         return;
5339
5340  nla_put_failure:
5341         genlmsg_cancel(msg, hdr);
5342         nlmsg_free(msg);
5343
5344 }
5345
5346 void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
5347                          struct net_device *netdev, const u8 *bssid,
5348                          const u8 *req_ie, size_t req_ie_len,
5349                          const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
5350 {
5351         struct sk_buff *msg;
5352         void *hdr;
5353
5354         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5355         if (!msg)
5356                 return;
5357
5358         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
5359         if (!hdr) {
5360                 nlmsg_free(msg);
5361                 return;
5362         }
5363
5364         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5365         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5366         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5367         if (req_ie)
5368                 NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
5369         if (resp_ie)
5370                 NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);
5371
5372         if (genlmsg_end(msg, hdr) < 0) {
5373                 nlmsg_free(msg);
5374                 return;
5375         }
5376
5377         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5378                                 nl80211_mlme_mcgrp.id, gfp);
5379         return;
5380
5381  nla_put_failure:
5382         genlmsg_cancel(msg, hdr);
5383         nlmsg_free(msg);
5384
5385 }
5386
5387 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
5388                                struct net_device *netdev, u16 reason,
5389                                const u8 *ie, size_t ie_len, bool from_ap)
5390 {
5391         struct sk_buff *msg;
5392         void *hdr;
5393
5394         msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
5395         if (!msg)
5396                 return;
5397
5398         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
5399         if (!hdr) {
5400                 nlmsg_free(msg);
5401                 return;
5402         }
5403
5404         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5405         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5406         if (from_ap && reason)
5407                 NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
5408         if (from_ap)
5409                 NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
5410         if (ie)
5411                 NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);
5412
5413         if (genlmsg_end(msg, hdr) < 0) {
5414                 nlmsg_free(msg);
5415                 return;
5416         }
5417
5418         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5419                                 nl80211_mlme_mcgrp.id, GFP_KERNEL);
5420         return;
5421
5422  nla_put_failure:
5423         genlmsg_cancel(msg, hdr);
5424         nlmsg_free(msg);
5425
5426 }
5427
5428 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
5429                              struct net_device *netdev, const u8 *bssid,
5430                              gfp_t gfp)
5431 {
5432         struct sk_buff *msg;
5433         void *hdr;
5434
5435         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5436         if (!msg)
5437                 return;
5438
5439         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
5440         if (!hdr) {
5441                 nlmsg_free(msg);
5442                 return;
5443         }
5444
5445         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5446         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5447         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
5448
5449         if (genlmsg_end(msg, hdr) < 0) {
5450                 nlmsg_free(msg);
5451                 return;
5452         }
5453
5454         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5455                                 nl80211_mlme_mcgrp.id, gfp);
5456         return;
5457
5458  nla_put_failure:
5459         genlmsg_cancel(msg, hdr);
5460         nlmsg_free(msg);
5461 }
5462
5463 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
5464                                  struct net_device *netdev, const u8 *addr,
5465                                  enum nl80211_key_type key_type, int key_id,
5466                                  const u8 *tsc, gfp_t gfp)
5467 {
5468         struct sk_buff *msg;
5469         void *hdr;
5470
5471         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5472         if (!msg)
5473                 return;
5474
5475         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
5476         if (!hdr) {
5477                 nlmsg_free(msg);
5478                 return;
5479         }
5480
5481         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5482         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5483         if (addr)
5484                 NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
5485         NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
5486         NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
5487         if (tsc)
5488                 NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);
5489
5490         if (genlmsg_end(msg, hdr) < 0) {
5491                 nlmsg_free(msg);
5492                 return;
5493         }
5494
5495         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5496                                 nl80211_mlme_mcgrp.id, gfp);
5497         return;
5498
5499  nla_put_failure:
5500         genlmsg_cancel(msg, hdr);
5501         nlmsg_free(msg);
5502 }
5503
5504 void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
5505                                     struct ieee80211_channel *channel_before,
5506                                     struct ieee80211_channel *channel_after)
5507 {
5508         struct sk_buff *msg;
5509         void *hdr;
5510         struct nlattr *nl_freq;
5511
5512         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
5513         if (!msg)
5514                 return;
5515
5516         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
5517         if (!hdr) {
5518                 nlmsg_free(msg);
5519                 return;
5520         }
5521
5522         /*
5523          * Since we are applying the beacon hint to a wiphy we know its
5524          * wiphy_idx is valid
5525          */
5526         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));
5527
5528         /* Before */
5529         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
5530         if (!nl_freq)
5531                 goto nla_put_failure;
5532         if (nl80211_msg_put_channel(msg, channel_before))
5533                 goto nla_put_failure;
5534         nla_nest_end(msg, nl_freq);
5535
5536         /* After */
5537         nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
5538         if (!nl_freq)
5539                 goto nla_put_failure;
5540         if (nl80211_msg_put_channel(msg, channel_after))
5541                 goto nla_put_failure;
5542         nla_nest_end(msg, nl_freq);
5543
5544         if (genlmsg_end(msg, hdr) < 0) {
5545                 nlmsg_free(msg);
5546                 return;
5547         }
5548
5549         rcu_read_lock();
5550         genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
5551                                 GFP_ATOMIC);
5552         rcu_read_unlock();
5553
5554         return;
5555
5556 nla_put_failure:
5557         genlmsg_cancel(msg, hdr);
5558         nlmsg_free(msg);
5559 }
5560
5561 static void nl80211_send_remain_on_chan_event(
5562         int cmd, struct cfg80211_registered_device *rdev,
5563         struct net_device *netdev, u64 cookie,
5564         struct ieee80211_channel *chan,
5565         enum nl80211_channel_type channel_type,
5566         unsigned int duration, gfp_t gfp)
5567 {
5568         struct sk_buff *msg;
5569         void *hdr;
5570
5571         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5572         if (!msg)
5573                 return;
5574
5575         hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
5576         if (!hdr) {
5577                 nlmsg_free(msg);
5578                 return;
5579         }
5580
5581         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5582         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5583         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq);
5584         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, channel_type);
5585         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5586
5587         if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL)
5588                 NLA_PUT_U32(msg, NL80211_ATTR_DURATION, duration);
5589
5590         if (genlmsg_end(msg, hdr) < 0) {
5591                 nlmsg_free(msg);
5592                 return;
5593         }
5594
5595         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5596                                 nl80211_mlme_mcgrp.id, gfp);
5597         return;
5598
5599  nla_put_failure:
5600         genlmsg_cancel(msg, hdr);
5601         nlmsg_free(msg);
5602 }
5603
5604 void nl80211_send_remain_on_channel(struct cfg80211_registered_device *rdev,
5605                                     struct net_device *netdev, u64 cookie,
5606                                     struct ieee80211_channel *chan,
5607                                     enum nl80211_channel_type channel_type,
5608                                     unsigned int duration, gfp_t gfp)
5609 {
5610         nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL,
5611                                           rdev, netdev, cookie, chan,
5612                                           channel_type, duration, gfp);
5613 }
5614
5615 void nl80211_send_remain_on_channel_cancel(
5616         struct cfg80211_registered_device *rdev, struct net_device *netdev,
5617         u64 cookie, struct ieee80211_channel *chan,
5618         enum nl80211_channel_type channel_type, gfp_t gfp)
5619 {
5620         nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL,
5621                                           rdev, netdev, cookie, chan,
5622                                           channel_type, 0, gfp);
5623 }
5624
5625 void nl80211_send_sta_event(struct cfg80211_registered_device *rdev,
5626                             struct net_device *dev, const u8 *mac_addr,
5627                             struct station_info *sinfo, gfp_t gfp)
5628 {
5629         struct sk_buff *msg;
5630
5631         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5632         if (!msg)
5633                 return;
5634
5635         if (nl80211_send_station(msg, 0, 0, 0, dev, mac_addr, sinfo) < 0) {
5636                 nlmsg_free(msg);
5637                 return;
5638         }
5639
5640         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5641                                 nl80211_mlme_mcgrp.id, gfp);
5642 }
5643
5644 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev,
5645                       struct net_device *netdev, u32 nlpid,
5646                       int freq, const u8 *buf, size_t len, gfp_t gfp)
5647 {
5648         struct sk_buff *msg;
5649         void *hdr;
5650         int err;
5651
5652         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5653         if (!msg)
5654                 return -ENOMEM;
5655
5656         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME);
5657         if (!hdr) {
5658                 nlmsg_free(msg);
5659                 return -ENOMEM;
5660         }
5661
5662         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5663         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5664         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FREQ, freq);
5665         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5666
5667         err = genlmsg_end(msg, hdr);
5668         if (err < 0) {
5669                 nlmsg_free(msg);
5670                 return err;
5671         }
5672
5673         err = genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlpid);
5674         if (err < 0)
5675                 return err;
5676         return 0;
5677
5678  nla_put_failure:
5679         genlmsg_cancel(msg, hdr);
5680         nlmsg_free(msg);
5681         return -ENOBUFS;
5682 }
5683
5684 void nl80211_send_mgmt_tx_status(struct cfg80211_registered_device *rdev,
5685                                  struct net_device *netdev, u64 cookie,
5686                                  const u8 *buf, size_t len, bool ack,
5687                                  gfp_t gfp)
5688 {
5689         struct sk_buff *msg;
5690         void *hdr;
5691
5692         msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
5693         if (!msg)
5694                 return;
5695
5696         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS);
5697         if (!hdr) {
5698                 nlmsg_free(msg);
5699                 return;
5700         }
5701
5702         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5703         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5704         NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);
5705         NLA_PUT_U64(msg, NL80211_ATTR_COOKIE, cookie);
5706         if (ack)
5707                 NLA_PUT_FLAG(msg, NL80211_ATTR_ACK);
5708
5709         if (genlmsg_end(msg, hdr) < 0) {
5710                 nlmsg_free(msg);
5711                 return;
5712         }
5713
5714         genlmsg_multicast(msg, 0, nl80211_mlme_mcgrp.id, gfp);
5715         return;
5716
5717  nla_put_failure:
5718         genlmsg_cancel(msg, hdr);
5719         nlmsg_free(msg);
5720 }
5721
5722 void
5723 nl80211_send_cqm_rssi_notify(struct cfg80211_registered_device *rdev,
5724                              struct net_device *netdev,
5725                              enum nl80211_cqm_rssi_threshold_event rssi_event,
5726                              gfp_t gfp)
5727 {
5728         struct sk_buff *msg;
5729         struct nlattr *pinfoattr;
5730         void *hdr;
5731
5732         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5733         if (!msg)
5734                 return;
5735
5736         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
5737         if (!hdr) {
5738                 nlmsg_free(msg);
5739                 return;
5740         }
5741
5742         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5743         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5744
5745         pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
5746         if (!pinfoattr)
5747                 goto nla_put_failure;
5748
5749         NLA_PUT_U32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT,
5750                     rssi_event);
5751
5752         nla_nest_end(msg, pinfoattr);
5753
5754         if (genlmsg_end(msg, hdr) < 0) {
5755                 nlmsg_free(msg);
5756                 return;
5757         }
5758
5759         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5760                                 nl80211_mlme_mcgrp.id, gfp);
5761         return;
5762
5763  nla_put_failure:
5764         genlmsg_cancel(msg, hdr);
5765         nlmsg_free(msg);
5766 }
5767
5768 void
5769 nl80211_send_cqm_pktloss_notify(struct cfg80211_registered_device *rdev,
5770                                 struct net_device *netdev, const u8 *peer,
5771                                 u32 num_packets, gfp_t gfp)
5772 {
5773         struct sk_buff *msg;
5774         struct nlattr *pinfoattr;
5775         void *hdr;
5776
5777         msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
5778         if (!msg)
5779                 return;
5780
5781         hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM);
5782         if (!hdr) {
5783                 nlmsg_free(msg);
5784                 return;
5785         }
5786
5787         NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
5788         NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
5789         NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, peer);
5790
5791         pinfoattr = nla_nest_start(msg, NL80211_ATTR_CQM);
5792         if (!pinfoattr)
5793                 goto nla_put_failure;
5794
5795         NLA_PUT_U32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets);
5796
5797         nla_nest_end(msg, pinfoattr);
5798
5799         if (genlmsg_end(msg, hdr) < 0) {
5800                 nlmsg_free(msg);
5801                 return;
5802         }
5803
5804         genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
5805                                 nl80211_mlme_mcgrp.id, gfp);
5806         return;
5807
5808  nla_put_failure:
5809         genlmsg_cancel(msg, hdr);
5810         nlmsg_free(msg);
5811 }
5812
5813 static int nl80211_netlink_notify(struct notifier_block * nb,
5814                                   unsigned long state,
5815                                   void *_notify)
5816 {
5817         struct netlink_notify *notify = _notify;
5818         struct cfg80211_registered_device *rdev;
5819         struct wireless_dev *wdev;
5820
5821         if (state != NETLINK_URELEASE)
5822                 return NOTIFY_DONE;
5823
5824         rcu_read_lock();
5825
5826         list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list)
5827                 list_for_each_entry_rcu(wdev, &rdev->netdev_list, list)
5828                         cfg80211_mlme_unregister_socket(wdev, notify->pid);
5829
5830         rcu_read_unlock();
5831
5832         return NOTIFY_DONE;
5833 }
5834
5835 static struct notifier_block nl80211_netlink_notifier = {
5836         .notifier_call = nl80211_netlink_notify,
5837 };
5838
5839 /* initialisation/exit functions */
5840
5841 int nl80211_init(void)
5842 {
5843         int err;
5844
5845         err = genl_register_family_with_ops(&nl80211_fam,
5846                 nl80211_ops, ARRAY_SIZE(nl80211_ops));
5847         if (err)
5848                 return err;
5849
5850         err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
5851         if (err)
5852                 goto err_out;
5853
5854         err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
5855         if (err)
5856                 goto err_out;
5857
5858         err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
5859         if (err)
5860                 goto err_out;
5861
5862         err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
5863         if (err)
5864                 goto err_out;
5865
5866 #ifdef CONFIG_NL80211_TESTMODE
5867         err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
5868         if (err)
5869                 goto err_out;
5870 #endif
5871
5872         err = netlink_register_notifier(&nl80211_netlink_notifier);
5873         if (err)
5874                 goto err_out;
5875
5876         return 0;
5877  err_out:
5878         genl_unregister_family(&nl80211_fam);
5879         return err;
5880 }
5881
5882 void nl80211_exit(void)
5883 {
5884         netlink_unregister_notifier(&nl80211_netlink_notifier);
5885         genl_unregister_family(&nl80211_fam);
5886 }