sme.c 22.2 KB
Newer Older
S
Samuel Ortiz 已提交
1 2 3 4 5 6 7 8 9 10
/*
 * SME code for cfg80211's connect emulation.
 *
 * Copyright 2009	Johannes Berg <johannes@sipsolutions.net>
 * Copyright (C) 2009   Intel Corporation. All rights reserved.
 */

#include <linux/etherdevice.h>
#include <linux/if_arp.h>
#include <linux/workqueue.h>
11 12
#include <linux/wireless.h>
#include <net/iw_handler.h>
S
Samuel Ortiz 已提交
13 14 15
#include <net/cfg80211.h>
#include <net/rtnetlink.h>
#include "nl80211.h"
16
#include "reg.h"
S
Samuel Ortiz 已提交
17

18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38
struct cfg80211_conn {
	struct cfg80211_connect_params params;
	/* these are sub-states of the _CONNECTING sme_state */
	enum {
		CFG80211_CONN_IDLE,
		CFG80211_CONN_SCANNING,
		CFG80211_CONN_SCAN_AGAIN,
		CFG80211_CONN_AUTHENTICATE_NEXT,
		CFG80211_CONN_AUTHENTICATING,
		CFG80211_CONN_ASSOCIATE_NEXT,
		CFG80211_CONN_ASSOCIATING,
	} state;
	u8 bssid[ETH_ALEN];
	u8 *ie;
	size_t ie_len;
	bool auto_auth;
};


static int cfg80211_conn_scan(struct wireless_dev *wdev)
{
39
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
40 41 42 43
	struct cfg80211_scan_request *request;
	int n_channels, err;

	ASSERT_RTNL();
44
	ASSERT_RDEV_LOCK(rdev);
J
Johannes Berg 已提交
45
	ASSERT_WDEV_LOCK(wdev);
46

47
	if (rdev->scan_req)
48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91
		return -EBUSY;

	if (wdev->conn->params.channel) {
		n_channels = 1;
	} else {
		enum ieee80211_band band;
		n_channels = 0;

		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
			if (!wdev->wiphy->bands[band])
				continue;
			n_channels += wdev->wiphy->bands[band]->n_channels;
		}
	}
	request = kzalloc(sizeof(*request) + sizeof(request->ssids[0]) +
			  sizeof(request->channels[0]) * n_channels,
			  GFP_KERNEL);
	if (!request)
		return -ENOMEM;

	request->channels = (void *)((char *)request + sizeof(*request));
	if (wdev->conn->params.channel)
		request->channels[0] = wdev->conn->params.channel;
	else {
		int i = 0, j;
		enum ieee80211_band band;

		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
			if (!wdev->wiphy->bands[band])
				continue;
			for (j = 0; j < wdev->wiphy->bands[band]->n_channels;
			     i++, j++)
				request->channels[i] =
					&wdev->wiphy->bands[band]->channels[j];
		}
	}
	request->n_channels = n_channels;
	request->ssids = (void *)(request->channels + n_channels);
	request->n_ssids = 1;

	memcpy(request->ssids[0].ssid, wdev->conn->params.ssid,
		wdev->conn->params.ssid_len);
	request->ssids[0].ssid_len = wdev->conn->params.ssid_len;

92
	request->dev = wdev->netdev;
93
	request->wiphy = &rdev->wiphy;
94

95
	rdev->scan_req = request;
96

97
	err = rdev->ops->scan(wdev->wiphy, wdev->netdev, request);
98 99
	if (!err) {
		wdev->conn->state = CFG80211_CONN_SCANNING;
100
		nl80211_send_scan_start(rdev, wdev->netdev);
101
		dev_hold(wdev->netdev);
102
	} else {
103
		rdev->scan_req = NULL;
104 105 106 107 108 109 110
		kfree(request);
	}
	return err;
}

static int cfg80211_conn_do_work(struct wireless_dev *wdev)
{
111
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
J
Johannes Berg 已提交
112 113
	struct cfg80211_connect_params *params;
	int err;
114

J
Johannes Berg 已提交
115 116
	ASSERT_WDEV_LOCK(wdev);

117 118 119
	if (!wdev->conn)
		return 0;

J
Johannes Berg 已提交
120 121
	params = &wdev->conn->params;

122 123 124 125
	switch (wdev->conn->state) {
	case CFG80211_CONN_SCAN_AGAIN:
		return cfg80211_conn_scan(wdev);
	case CFG80211_CONN_AUTHENTICATE_NEXT:
126
		BUG_ON(!rdev->ops->auth);
J
Johannes Berg 已提交
127
		wdev->conn->state = CFG80211_CONN_AUTHENTICATING;
128
		return __cfg80211_mlme_auth(rdev, wdev->netdev,
J
Johannes Berg 已提交
129 130 131
					    params->channel, params->auth_type,
					    params->bssid,
					    params->ssid, params->ssid_len,
J
Johannes Berg 已提交
132 133 134
					    NULL, 0,
					    params->key, params->key_len,
					    params->key_idx);
135
	case CFG80211_CONN_ASSOCIATE_NEXT:
136
		BUG_ON(!rdev->ops->assoc);
J
Johannes Berg 已提交
137
		wdev->conn->state = CFG80211_CONN_ASSOCIATING;
138 139 140 141 142 143
		/*
		 * We could, later, implement roaming here and then actually
		 * set prev_bssid to non-NULL. But then we need to be aware
		 * that some APs don't like that -- so we'd need to retry
		 * the association.
		 */
144
		err = __cfg80211_mlme_assoc(rdev, wdev->netdev,
J
Johannes Berg 已提交
145 146 147 148 149
					    params->channel, params->bssid,
					    NULL,
					    params->ssid, params->ssid_len,
					    params->ie, params->ie_len,
					    false, &params->crypto);
J
Johannes Berg 已提交
150
		if (err)
151
			__cfg80211_mlme_deauth(rdev, wdev->netdev, params->bssid,
J
Johannes Berg 已提交
152 153
					       NULL, 0,
					       WLAN_REASON_DEAUTH_LEAVING);
J
Johannes Berg 已提交
154
		return err;
155 156 157 158 159 160 161
	default:
		return 0;
	}
}

void cfg80211_conn_work(struct work_struct *work)
{
162
	struct cfg80211_registered_device *rdev =
163 164 165 166
		container_of(work, struct cfg80211_registered_device, conn_work);
	struct wireless_dev *wdev;

	rtnl_lock();
167 168
	cfg80211_lock_rdev(rdev);
	mutex_lock(&rdev->devlist_mtx);
169

170
	list_for_each_entry(wdev, &rdev->netdev_list, list) {
J
Johannes Berg 已提交
171 172 173
		wdev_lock(wdev);
		if (!netif_running(wdev->netdev)) {
			wdev_unlock(wdev);
174
			continue;
J
Johannes Berg 已提交
175 176 177
		}
		if (wdev->sme_state != CFG80211_SME_CONNECTING) {
			wdev_unlock(wdev);
178
			continue;
J
Johannes Berg 已提交
179
		}
180
		if (cfg80211_conn_do_work(wdev))
J
Johannes Berg 已提交
181 182 183 184 185
			__cfg80211_connect_result(
					wdev->netdev,
					wdev->conn->params.bssid,
					NULL, 0, NULL, 0,
					WLAN_STATUS_UNSPECIFIED_FAILURE,
186
					false, NULL);
J
Johannes Berg 已提交
187
		wdev_unlock(wdev);
188 189
	}

190 191
	mutex_unlock(&rdev->devlist_mtx);
	cfg80211_unlock_rdev(rdev);
192 193 194 195 196
	rtnl_unlock();
}

static bool cfg80211_get_conn_bss(struct wireless_dev *wdev)
{
197
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
198 199 200
	struct cfg80211_bss *bss;
	u16 capa = WLAN_CAPABILITY_ESS;

J
Johannes Berg 已提交
201 202
	ASSERT_WDEV_LOCK(wdev);

203 204 205 206 207 208 209 210 211 212 213 214 215 216 217
	if (wdev->conn->params.privacy)
		capa |= WLAN_CAPABILITY_PRIVACY;

	bss = cfg80211_get_bss(wdev->wiphy, NULL, wdev->conn->params.bssid,
			       wdev->conn->params.ssid,
			       wdev->conn->params.ssid_len,
			       WLAN_CAPABILITY_ESS | WLAN_CAPABILITY_PRIVACY,
			       capa);
	if (!bss)
		return false;

	memcpy(wdev->conn->bssid, bss->bssid, ETH_ALEN);
	wdev->conn->params.bssid = wdev->conn->bssid;
	wdev->conn->params.channel = bss->channel;
	wdev->conn->state = CFG80211_CONN_AUTHENTICATE_NEXT;
218
	schedule_work(&rdev->conn_work);
219 220 221 222 223

	cfg80211_put_bss(bss);
	return true;
}

J
Johannes Berg 已提交
224
static void __cfg80211_sme_scan_done(struct net_device *dev)
225 226
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
227
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
228

J
Johannes Berg 已提交
229 230
	ASSERT_WDEV_LOCK(wdev);

231 232 233
	if (wdev->sme_state != CFG80211_SME_CONNECTING)
		return;

234
	if (!wdev->conn)
235 236 237 238 239 240 241 242 243
		return;

	if (wdev->conn->state != CFG80211_CONN_SCANNING &&
	    wdev->conn->state != CFG80211_CONN_SCAN_AGAIN)
		return;

	if (!cfg80211_get_conn_bss(wdev)) {
		/* not found */
		if (wdev->conn->state == CFG80211_CONN_SCAN_AGAIN)
244
			schedule_work(&rdev->conn_work);
245
		else
J
Johannes Berg 已提交
246 247 248 249 250
			__cfg80211_connect_result(
					wdev->netdev,
					wdev->conn->params.bssid,
					NULL, 0, NULL, 0,
					WLAN_STATUS_UNSPECIFIED_FAILURE,
251
					false, NULL);
252 253 254
	}
}

J
Johannes Berg 已提交
255 256 257 258 259 260 261 262 263 264 265
void cfg80211_sme_scan_done(struct net_device *dev)
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;

	wdev_lock(wdev);
	__cfg80211_sme_scan_done(dev);
	wdev_unlock(wdev);
}

void cfg80211_sme_rx_auth(struct net_device *dev,
			  const u8 *buf, size_t len)
266 267 268 269 270 271 272
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
	struct wiphy *wiphy = wdev->wiphy;
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);
	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *)buf;
	u16 status_code = le16_to_cpu(mgmt->u.auth.status_code);

J
Johannes Berg 已提交
273 274
	ASSERT_WDEV_LOCK(wdev);

275 276 277 278 279 280 281 282 283 284 285 286 287
	/* should only RX auth frames when connecting */
	if (wdev->sme_state != CFG80211_SME_CONNECTING)
		return;

	if (WARN_ON(!wdev->conn))
		return;

	if (status_code == WLAN_STATUS_NOT_SUPPORTED_AUTH_ALG &&
	    wdev->conn->auto_auth &&
	    wdev->conn->params.auth_type != NL80211_AUTHTYPE_NETWORK_EAP) {
		/* select automatically between only open, shared, leap */
		switch (wdev->conn->params.auth_type) {
		case NL80211_AUTHTYPE_OPEN_SYSTEM:
J
Johannes Berg 已提交
288 289 290 291 292 293
			if (wdev->connect_keys)
				wdev->conn->params.auth_type =
					NL80211_AUTHTYPE_SHARED_KEY;
			else
				wdev->conn->params.auth_type =
					NL80211_AUTHTYPE_NETWORK_EAP;
294 295 296 297 298 299 300 301 302 303 304 305 306
			break;
		case NL80211_AUTHTYPE_SHARED_KEY:
			wdev->conn->params.auth_type =
				NL80211_AUTHTYPE_NETWORK_EAP;
			break;
		default:
			/* huh? */
			wdev->conn->params.auth_type =
				NL80211_AUTHTYPE_OPEN_SYSTEM;
			break;
		}
		wdev->conn->state = CFG80211_CONN_AUTHENTICATE_NEXT;
		schedule_work(&rdev->conn_work);
J
Johannes Berg 已提交
307
	} else if (status_code != WLAN_STATUS_SUCCESS) {
J
Johannes Berg 已提交
308
		__cfg80211_connect_result(dev, mgmt->bssid, NULL, 0, NULL, 0,
309
					  status_code, false, NULL);
J
Johannes Berg 已提交
310
	} else if (wdev->sme_state == CFG80211_SME_CONNECTING &&
311 312 313 314 315
		 wdev->conn->state == CFG80211_CONN_AUTHENTICATING) {
		wdev->conn->state = CFG80211_CONN_ASSOCIATE_NEXT;
		schedule_work(&rdev->conn_work);
	}
}
S
Samuel Ortiz 已提交
316

J
Johannes Berg 已提交
317 318 319
void __cfg80211_connect_result(struct net_device *dev, const u8 *bssid,
			       const u8 *req_ie, size_t req_ie_len,
			       const u8 *resp_ie, size_t resp_ie_len,
320 321
			       u16 status, bool wextev,
			       struct cfg80211_bss *bss)
S
Samuel Ortiz 已提交
322 323
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
324
	u8 *country_ie;
S
Samuel Ortiz 已提交
325 326 327 328
#ifdef CONFIG_WIRELESS_EXT
	union iwreq_data wrqu;
#endif

J
Johannes Berg 已提交
329 330
	ASSERT_WDEV_LOCK(wdev);

S
Samuel Ortiz 已提交
331 332 333
	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_STATION))
		return;

334 335 336
	if (wdev->sme_state == CFG80211_SME_CONNECTED)
		nl80211_send_roamed(wiphy_to_dev(wdev->wiphy), dev,
				    bssid, req_ie, req_ie_len,
J
Johannes Berg 已提交
337
				    resp_ie, resp_ie_len, GFP_KERNEL);
338 339 340 341
	else
		nl80211_send_connect_result(wiphy_to_dev(wdev->wiphy), dev,
					    bssid, req_ie, req_ie_len,
					    resp_ie, resp_ie_len,
J
Johannes Berg 已提交
342
					    status, GFP_KERNEL);
343 344 345 346 347 348

#ifdef CONFIG_WIRELESS_EXT
	if (wextev) {
		if (req_ie && status == WLAN_STATUS_SUCCESS) {
			memset(&wrqu, 0, sizeof(wrqu));
			wrqu.data.length = req_ie_len;
Z
Zhu Yi 已提交
349
			wireless_send_event(dev, IWEVASSOCREQIE, &wrqu, req_ie);
350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365
		}

		if (resp_ie && status == WLAN_STATUS_SUCCESS) {
			memset(&wrqu, 0, sizeof(wrqu));
			wrqu.data.length = resp_ie_len;
			wireless_send_event(dev, IWEVASSOCRESPIE, &wrqu, resp_ie);
		}

		memset(&wrqu, 0, sizeof(wrqu));
		wrqu.ap_addr.sa_family = ARPHRD_ETHER;
		if (bssid && status == WLAN_STATUS_SUCCESS)
			memcpy(wrqu.ap_addr.sa_data, bssid, ETH_ALEN);
		wireless_send_event(dev, SIOCGIWAP, &wrqu, NULL);
	}
#endif

366 367 368 369 370 371
	if (wdev->current_bss) {
		cfg80211_unhold_bss(wdev->current_bss);
		cfg80211_put_bss(&wdev->current_bss->pub);
		wdev->current_bss = NULL;
	}

372
	if (status == WLAN_STATUS_SUCCESS &&
J
Johannes Berg 已提交
373 374
	    wdev->sme_state == CFG80211_SME_IDLE)
		goto success;
375

376
	if (wdev->sme_state != CFG80211_SME_CONNECTING)
S
Samuel Ortiz 已提交
377 378
		return;

J
Johannes Berg 已提交
379 380 381
	if (wdev->conn)
		wdev->conn->state = CFG80211_CONN_IDLE;

J
Johannes Berg 已提交
382
	if (status != WLAN_STATUS_SUCCESS) {
S
Samuel Ortiz 已提交
383
		wdev->sme_state = CFG80211_SME_IDLE;
J
Johannes Berg 已提交
384 385
		kfree(wdev->conn);
		wdev->conn = NULL;
J
Johannes Berg 已提交
386 387 388
		kfree(wdev->connect_keys);
		wdev->connect_keys = NULL;
		return;
S
Samuel Ortiz 已提交
389
	}
J
Johannes Berg 已提交
390

391 392 393 394 395 396
 success:
	if (!bss)
		bss = cfg80211_get_bss(wdev->wiphy, NULL, bssid,
				       wdev->ssid, wdev->ssid_len,
				       WLAN_CAPABILITY_ESS,
				       WLAN_CAPABILITY_ESS);
J
Johannes Berg 已提交
397 398 399 400 401 402 403 404 405

	if (WARN_ON(!bss))
		return;

	cfg80211_hold_bss(bss_from_pub(bss));
	wdev->current_bss = bss_from_pub(bss);

	wdev->sme_state = CFG80211_SME_CONNECTED;
	cfg80211_upload_connect_keys(wdev);
406 407 408 409 410 411 412 413 414 415 416 417 418 419

	country_ie = (u8 *) ieee80211_bss_get_ie(bss, WLAN_EID_COUNTRY);

	if (!country_ie)
		return;

	/*
	 * ieee80211_bss_get_ie() ensures we can access:
	 * - country_ie + 2, the start of the country ie data, and
	 * - and country_ie[1] which is the IE length
	 */
	regulatory_hint_11d(wdev->wiphy,
			    country_ie + 2,
			    country_ie[1]);
S
Samuel Ortiz 已提交
420
}
421 422 423 424 425 426

void cfg80211_connect_result(struct net_device *dev, const u8 *bssid,
			     const u8 *req_ie, size_t req_ie_len,
			     const u8 *resp_ie, size_t resp_ie_len,
			     u16 status, gfp_t gfp)
{
J
Johannes Berg 已提交
427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449
	struct wireless_dev *wdev = dev->ieee80211_ptr;
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
	struct cfg80211_event *ev;
	unsigned long flags;

	ev = kzalloc(sizeof(*ev) + req_ie_len + resp_ie_len, gfp);
	if (!ev)
		return;

	ev->type = EVENT_CONNECT_RESULT;
	memcpy(ev->cr.bssid, bssid, ETH_ALEN);
	ev->cr.req_ie = ((u8 *)ev) + sizeof(*ev);
	ev->cr.req_ie_len = req_ie_len;
	memcpy((void *)ev->cr.req_ie, req_ie, req_ie_len);
	ev->cr.resp_ie = ((u8 *)ev) + sizeof(*ev) + req_ie_len;
	ev->cr.resp_ie_len = resp_ie_len;
	memcpy((void *)ev->cr.resp_ie, resp_ie, resp_ie_len);
	ev->cr.status = status;

	spin_lock_irqsave(&wdev->event_lock, flags);
	list_add_tail(&ev->list, &wdev->event_list);
	spin_unlock_irqrestore(&wdev->event_lock, flags);
	schedule_work(&rdev->event_work);
450
}
S
Samuel Ortiz 已提交
451 452
EXPORT_SYMBOL(cfg80211_connect_result);

J
Johannes Berg 已提交
453 454 455
void __cfg80211_roamed(struct wireless_dev *wdev, const u8 *bssid,
		       const u8 *req_ie, size_t req_ie_len,
		       const u8 *resp_ie, size_t resp_ie_len)
S
Samuel Ortiz 已提交
456 457 458 459 460 461
{
	struct cfg80211_bss *bss;
#ifdef CONFIG_WIRELESS_EXT
	union iwreq_data wrqu;
#endif

J
Johannes Berg 已提交
462 463
	ASSERT_WDEV_LOCK(wdev);

S
Samuel Ortiz 已提交
464 465 466 467 468 469 470 471 472 473 474 475
	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_STATION))
		return;

	if (WARN_ON(wdev->sme_state != CFG80211_SME_CONNECTED))
		return;

	/* internal error -- how did we get to CONNECTED w/o BSS? */
	if (WARN_ON(!wdev->current_bss)) {
		return;
	}

	cfg80211_unhold_bss(wdev->current_bss);
J
Johannes Berg 已提交
476
	cfg80211_put_bss(&wdev->current_bss->pub);
S
Samuel Ortiz 已提交
477 478 479 480 481 482 483 484 485
	wdev->current_bss = NULL;

	bss = cfg80211_get_bss(wdev->wiphy, NULL, bssid,
			       wdev->ssid, wdev->ssid_len,
			       WLAN_CAPABILITY_ESS, WLAN_CAPABILITY_ESS);

	if (WARN_ON(!bss))
		return;

J
Johannes Berg 已提交
486 487
	cfg80211_hold_bss(bss_from_pub(bss));
	wdev->current_bss = bss_from_pub(bss);
S
Samuel Ortiz 已提交
488

J
Johannes Berg 已提交
489 490 491
	nl80211_send_roamed(wiphy_to_dev(wdev->wiphy), wdev->netdev, bssid,
			    req_ie, req_ie_len, resp_ie, resp_ie_len,
			    GFP_KERNEL);
S
Samuel Ortiz 已提交
492 493 494 495 496

#ifdef CONFIG_WIRELESS_EXT
	if (req_ie) {
		memset(&wrqu, 0, sizeof(wrqu));
		wrqu.data.length = req_ie_len;
Z
Zhu Yi 已提交
497
		wireless_send_event(wdev->netdev, IWEVASSOCREQIE,
J
Johannes Berg 已提交
498
				    &wrqu, req_ie);
S
Samuel Ortiz 已提交
499 500 501 502 503
	}

	if (resp_ie) {
		memset(&wrqu, 0, sizeof(wrqu));
		wrqu.data.length = resp_ie_len;
J
Johannes Berg 已提交
504 505
		wireless_send_event(wdev->netdev, IWEVASSOCRESPIE,
				    &wrqu, resp_ie);
S
Samuel Ortiz 已提交
506 507 508 509 510
	}

	memset(&wrqu, 0, sizeof(wrqu));
	wrqu.ap_addr.sa_family = ARPHRD_ETHER;
	memcpy(wrqu.ap_addr.sa_data, bssid, ETH_ALEN);
J
Johannes Berg 已提交
511
	wireless_send_event(wdev->netdev, SIOCGIWAP, &wrqu, NULL);
S
Samuel Ortiz 已提交
512 513
#endif
}
J
Johannes Berg 已提交
514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541

void cfg80211_roamed(struct net_device *dev, const u8 *bssid,
		     const u8 *req_ie, size_t req_ie_len,
		     const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
	struct cfg80211_event *ev;
	unsigned long flags;

	ev = kzalloc(sizeof(*ev) + req_ie_len + resp_ie_len, gfp);
	if (!ev)
		return;

	ev->type = EVENT_ROAMED;
	memcpy(ev->rm.bssid, bssid, ETH_ALEN);
	ev->rm.req_ie = ((u8 *)ev) + sizeof(*ev);
	ev->rm.req_ie_len = req_ie_len;
	memcpy((void *)ev->rm.req_ie, req_ie, req_ie_len);
	ev->rm.resp_ie = ((u8 *)ev) + sizeof(*ev) + req_ie_len;
	ev->rm.resp_ie_len = resp_ie_len;
	memcpy((void *)ev->rm.resp_ie, resp_ie, resp_ie_len);

	spin_lock_irqsave(&wdev->event_lock, flags);
	list_add_tail(&ev->list, &wdev->event_list);
	spin_unlock_irqrestore(&wdev->event_lock, flags);
	schedule_work(&rdev->event_work);
}
S
Samuel Ortiz 已提交
542 543
EXPORT_SYMBOL(cfg80211_roamed);

J
Johannes Berg 已提交
544
void __cfg80211_disconnected(struct net_device *dev, const u8 *ie,
545
			     size_t ie_len, u16 reason, bool from_ap)
S
Samuel Ortiz 已提交
546 547
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
J
Johannes Berg 已提交
548 549
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
	int i;
S
Samuel Ortiz 已提交
550 551 552 553
#ifdef CONFIG_WIRELESS_EXT
	union iwreq_data wrqu;
#endif

J
Johannes Berg 已提交
554 555
	ASSERT_WDEV_LOCK(wdev);

S
Samuel Ortiz 已提交
556 557 558 559 560 561 562 563
	if (WARN_ON(wdev->iftype != NL80211_IFTYPE_STATION))
		return;

	if (WARN_ON(wdev->sme_state != CFG80211_SME_CONNECTED))
		return;

	if (wdev->current_bss) {
		cfg80211_unhold_bss(wdev->current_bss);
J
Johannes Berg 已提交
564
		cfg80211_put_bss(&wdev->current_bss->pub);
S
Samuel Ortiz 已提交
565 566 567 568 569
	}

	wdev->current_bss = NULL;
	wdev->sme_state = CFG80211_SME_IDLE;

570 571 572
	if (wdev->conn) {
		kfree(wdev->conn->ie);
		wdev->conn->ie = NULL;
J
Johannes Berg 已提交
573 574
		kfree(wdev->conn);
		wdev->conn = NULL;
575 576
	}

J
Johannes Berg 已提交
577 578 579 580 581 582 583 584 585
	nl80211_send_disconnected(rdev, dev, reason, ie, ie_len, from_ap);

	/*
	 * Delete all the keys ... pairwise keys can't really
	 * exist any more anyway, but default keys might.
	 */
	if (rdev->ops->del_key)
		for (i = 0; i < 6; i++)
			rdev->ops->del_key(wdev->wiphy, dev, i, NULL);
S
Samuel Ortiz 已提交
586 587 588 589 590 591 592 593 594 595 596

#ifdef CONFIG_WIRELESS_EXT
	memset(&wrqu, 0, sizeof(wrqu));
	wrqu.ap_addr.sa_family = ARPHRD_ETHER;
	wireless_send_event(dev, SIOCGIWAP, &wrqu, NULL);
#endif
}

void cfg80211_disconnected(struct net_device *dev, u16 reason,
			   u8 *ie, size_t ie_len, gfp_t gfp)
{
J
Johannes Berg 已提交
597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615
	struct wireless_dev *wdev = dev->ieee80211_ptr;
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
	struct cfg80211_event *ev;
	unsigned long flags;

	ev = kzalloc(sizeof(*ev) + ie_len, gfp);
	if (!ev)
		return;

	ev->type = EVENT_DISCONNECTED;
	ev->dc.ie = ((u8 *)ev) + sizeof(*ev);
	ev->dc.ie_len = ie_len;
	memcpy((void *)ev->dc.ie, ie, ie_len);
	ev->dc.reason = reason;

	spin_lock_irqsave(&wdev->event_lock, flags);
	list_add_tail(&ev->list, &wdev->event_list);
	spin_unlock_irqrestore(&wdev->event_lock, flags);
	schedule_work(&rdev->event_work);
S
Samuel Ortiz 已提交
616 617 618
}
EXPORT_SYMBOL(cfg80211_disconnected);

J
Johannes Berg 已提交
619 620
int __cfg80211_connect(struct cfg80211_registered_device *rdev,
		       struct net_device *dev,
J
Johannes Berg 已提交
621 622
		       struct cfg80211_connect_params *connect,
		       struct cfg80211_cached_keys *connkeys)
S
Samuel Ortiz 已提交
623 624
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
J
Johannes Berg 已提交
625 626 627
	int err;

	ASSERT_WDEV_LOCK(wdev);
S
Samuel Ortiz 已提交
628 629 630 631

	if (wdev->sme_state != CFG80211_SME_IDLE)
		return -EALREADY;

J
Johannes Berg 已提交
632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649
	if (WARN_ON(wdev->connect_keys)) {
		kfree(wdev->connect_keys);
		wdev->connect_keys = NULL;
	}

	if (connkeys && connkeys->def >= 0) {
		int idx;

		idx = connkeys->def;
		/* If given a WEP key we may need it for shared key auth */
		if (connkeys->params[idx].cipher == WLAN_CIPHER_SUITE_WEP40 ||
		    connkeys->params[idx].cipher == WLAN_CIPHER_SUITE_WEP104) {
			connect->key_idx = idx;
			connect->key = connkeys->params[idx].key;
			connect->key_len = connkeys->params[idx].key_len;
		}
	}

S
Samuel Ortiz 已提交
650
	if (!rdev->ops->connect) {
651 652 653
		if (!rdev->ops->auth || !rdev->ops->assoc)
			return -EOPNOTSUPP;

J
Johannes Berg 已提交
654 655 656 657 658 659
		if (WARN_ON(wdev->conn))
			return -EINPROGRESS;

		wdev->conn = kzalloc(sizeof(*wdev->conn), GFP_KERNEL);
		if (!wdev->conn)
			return -ENOMEM;
660 661 662 663 664 665 666 667 668 669 670 671 672 673

		/*
		 * Copy all parameters, and treat explicitly IEs, BSSID, SSID.
		 */
		memcpy(&wdev->conn->params, connect, sizeof(*connect));
		if (connect->bssid) {
			wdev->conn->params.bssid = wdev->conn->bssid;
			memcpy(wdev->conn->bssid, connect->bssid, ETH_ALEN);
		}

		if (connect->ie) {
			wdev->conn->ie = kmemdup(connect->ie, connect->ie_len,
						GFP_KERNEL);
			wdev->conn->params.ie = wdev->conn->ie;
J
Johannes Berg 已提交
674 675 676
			if (!wdev->conn->ie) {
				kfree(wdev->conn);
				wdev->conn = NULL;
677
				return -ENOMEM;
J
Johannes Berg 已提交
678
			}
679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699
		}

		if (connect->auth_type == NL80211_AUTHTYPE_AUTOMATIC) {
			wdev->conn->auto_auth = true;
			/* start with open system ... should mostly work */
			wdev->conn->params.auth_type =
				NL80211_AUTHTYPE_OPEN_SYSTEM;
		} else {
			wdev->conn->auto_auth = false;
		}

		memcpy(wdev->ssid, connect->ssid, connect->ssid_len);
		wdev->ssid_len = connect->ssid_len;
		wdev->conn->params.ssid = wdev->ssid;
		wdev->conn->params.ssid_len = connect->ssid_len;

		/* don't care about result -- but fill bssid & channel */
		if (!wdev->conn->params.bssid || !wdev->conn->params.channel)
			cfg80211_get_conn_bss(wdev);

		wdev->sme_state = CFG80211_SME_CONNECTING;
J
Johannes Berg 已提交
700
		wdev->connect_keys = connkeys;
701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718

		/* we're good if we have both BSSID and channel */
		if (wdev->conn->params.bssid && wdev->conn->params.channel) {
			wdev->conn->state = CFG80211_CONN_AUTHENTICATE_NEXT;
			err = cfg80211_conn_do_work(wdev);
		} else {
			/* otherwise we'll need to scan for the AP first */
			err = cfg80211_conn_scan(wdev);
			/*
			 * If we can't scan right now, then we need to scan again
			 * after the current scan finished, since the parameters
			 * changed (unless we find a good AP anyway).
			 */
			if (err == -EBUSY) {
				err = 0;
				wdev->conn->state = CFG80211_CONN_SCAN_AGAIN;
			}
		}
J
Johannes Berg 已提交
719 720 721
		if (err) {
			kfree(wdev->conn);
			wdev->conn = NULL;
722
			wdev->sme_state = CFG80211_SME_IDLE;
J
Johannes Berg 已提交
723
			wdev->connect_keys = NULL;
J
Johannes Berg 已提交
724
		}
725 726

		return err;
S
Samuel Ortiz 已提交
727 728
	} else {
		wdev->sme_state = CFG80211_SME_CONNECTING;
J
Johannes Berg 已提交
729
		wdev->connect_keys = connkeys;
S
Samuel Ortiz 已提交
730 731
		err = rdev->ops->connect(&rdev->wiphy, dev, connect);
		if (err) {
J
Johannes Berg 已提交
732
			wdev->connect_keys = NULL;
S
Samuel Ortiz 已提交
733 734 735 736
			wdev->sme_state = CFG80211_SME_IDLE;
			return err;
		}

737 738
		memcpy(wdev->ssid, connect->ssid, connect->ssid_len);
		wdev->ssid_len = connect->ssid_len;
S
Samuel Ortiz 已提交
739

740 741
		return 0;
	}
S
Samuel Ortiz 已提交
742 743
}

J
Johannes Berg 已提交
744 745
int cfg80211_connect(struct cfg80211_registered_device *rdev,
		     struct net_device *dev,
J
Johannes Berg 已提交
746 747
		     struct cfg80211_connect_params *connect,
		     struct cfg80211_cached_keys *connkeys)
J
Johannes Berg 已提交
748 749 750 751
{
	int err;

	wdev_lock(dev->ieee80211_ptr);
J
Johannes Berg 已提交
752
	err = __cfg80211_connect(rdev, dev, connect, connkeys);
J
Johannes Berg 已提交
753 754 755 756 757 758 759
	wdev_unlock(dev->ieee80211_ptr);

	return err;
}

int __cfg80211_disconnect(struct cfg80211_registered_device *rdev,
			  struct net_device *dev, u16 reason, bool wextev)
S
Samuel Ortiz 已提交
760
{
761
	struct wireless_dev *wdev = dev->ieee80211_ptr;
S
Samuel Ortiz 已提交
762 763
	int err;

J
Johannes Berg 已提交
764 765
	ASSERT_WDEV_LOCK(wdev);

766 767 768
	if (wdev->sme_state == CFG80211_SME_IDLE)
		return -EINVAL;

J
Johannes Berg 已提交
769 770 771
	kfree(wdev->connect_keys);
	wdev->connect_keys = NULL;

S
Samuel Ortiz 已提交
772
	if (!rdev->ops->disconnect) {
J
Johannes Berg 已提交
773 774
		if (!rdev->ops->deauth)
			return -EOPNOTSUPP;
775

J
Johannes Berg 已提交
776 777 778 779 780
		/* was it connected by userspace SME? */
		if (!wdev->conn) {
			cfg80211_mlme_down(rdev, dev);
			return 0;
		}
781 782 783 784 785

		if (wdev->sme_state == CFG80211_SME_CONNECTING &&
		    (wdev->conn->state == CFG80211_CONN_SCANNING ||
		     wdev->conn->state == CFG80211_CONN_SCAN_AGAIN)) {
			wdev->sme_state = CFG80211_SME_IDLE;
J
Johannes Berg 已提交
786 787
			kfree(wdev->conn);
			wdev->conn = NULL;
788 789 790 791
			return 0;
		}

		/* wdev->conn->params.bssid must be set if > SCANNING */
J
Johannes Berg 已提交
792 793 794
		err = __cfg80211_mlme_deauth(rdev, dev,
					     wdev->conn->params.bssid,
					     NULL, 0, reason);
795 796
		if (err)
			return err;
S
Samuel Ortiz 已提交
797 798 799 800 801 802
	} else {
		err = rdev->ops->disconnect(&rdev->wiphy, dev, reason);
		if (err)
			return err;
	}

803
	if (wdev->sme_state == CFG80211_SME_CONNECTED)
J
Johannes Berg 已提交
804
		__cfg80211_disconnected(dev, NULL, 0, 0, false);
805
	else if (wdev->sme_state == CFG80211_SME_CONNECTING)
806 807
		__cfg80211_connect_result(dev, NULL, NULL, 0, NULL, 0,
					  WLAN_STATUS_UNSPECIFIED_FAILURE,
808
					  wextev, NULL);
S
Samuel Ortiz 已提交
809 810 811

	return 0;
}
J
Johannes Berg 已提交
812

J
Johannes Berg 已提交
813 814 815 816 817 818 819 820 821 822 823 824 825
int cfg80211_disconnect(struct cfg80211_registered_device *rdev,
			struct net_device *dev,
			u16 reason, bool wextev)
{
	int err;

	wdev_lock(dev->ieee80211_ptr);
	err = __cfg80211_disconnect(rdev, dev, reason, wextev);
	wdev_unlock(dev->ieee80211_ptr);

	return err;
}

J
Johannes Berg 已提交
826 827 828 829 830 831
void cfg80211_sme_disassoc(struct net_device *dev, int idx)
{
	struct wireless_dev *wdev = dev->ieee80211_ptr;
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wdev->wiphy);
	u8 bssid[ETH_ALEN];

J
Johannes Berg 已提交
832 833
	ASSERT_WDEV_LOCK(wdev);

J
Johannes Berg 已提交
834 835 836 837 838 839 840 841 842 843 844 845 846 847 848
	if (!wdev->conn)
		return;

	if (wdev->conn->state == CFG80211_CONN_IDLE)
		return;

	/*
	 * Ok, so the association was made by this SME -- we don't
	 * want it any more so deauthenticate too.
	 */

	if (!wdev->auth_bsses[idx])
		return;

	memcpy(bssid, wdev->auth_bsses[idx]->pub.bssid, ETH_ALEN);
J
Johannes Berg 已提交
849 850
	if (__cfg80211_mlme_deauth(rdev, dev, bssid,
				   NULL, 0, WLAN_REASON_DEAUTH_LEAVING)) {
J
Johannes Berg 已提交
851 852 853 854 855 856
		/* whatever -- assume gone anyway */
		cfg80211_unhold_bss(wdev->auth_bsses[idx]);
		cfg80211_put_bss(&wdev->auth_bsses[idx]->pub);
		wdev->auth_bsses[idx] = NULL;
	}
}