mesh.c 40.7 KB
Newer Older
1
/*
R
Rui Paulo 已提交
2
 * Copyright (c) 2008, 2009 open80211s Ltd.
3 4 5 6 7 8 9 10
 * Authors:    Luis Carlos Cobo <luisca@cozybit.com>
 * 	       Javier Cardona <javier@cozybit.com>
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

11
#include <linux/slab.h>
12
#include <asm/unaligned.h>
13 14
#include "ieee80211_i.h"
#include "mesh.h"
15
#include "driver-ops.h"
16

J
Johannes Berg 已提交
17
static int mesh_allocated;
18 19
static struct kmem_cache *rm_cache;

20 21 22 23 24 25
bool mesh_action_is_path_sel(struct ieee80211_mgmt *mgmt)
{
	return (mgmt->u.action.u.mesh_action.action_code ==
			WLAN_MESH_ACTION_HWMP_PATH_SELECTION);
}

26 27 28 29 30 31 32 33 34
void ieee80211s_init(void)
{
	mesh_allocated = 1;
	rm_cache = kmem_cache_create("mesh_rmc", sizeof(struct rmc_entry),
				     0, 0, NULL);
}

void ieee80211s_stop(void)
{
J
Johannes Berg 已提交
35 36
	if (!mesh_allocated)
		return;
37 38 39
	kmem_cache_destroy(rm_cache);
}

40
static void ieee80211_mesh_housekeeping_timer(struct timer_list *t)
41
{
42 43
	struct ieee80211_sub_if_data *sdata =
		from_timer(sdata, t, u.mesh.housekeeping_timer);
44 45 46
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;

47
	set_bit(MESH_WORK_HOUSEKEEPING, &ifmsh->wrkq_flags);
48

J
Johannes Berg 已提交
49
	ieee80211_queue_work(&local->hw, &sdata->work);
50 51
}

52 53 54
/**
 * mesh_matches_local - check if the config of a mesh point matches ours
 *
55
 * @sdata: local mesh subif
56
 * @ie: information elements of a management frame from the mesh peer
57 58 59 60
 *
 * This function checks if the mesh configuration of a mesh point matches the
 * local mesh configuration, i.e. if both nodes belong to the same mesh network.
 */
61 62
bool mesh_matches_local(struct ieee80211_sub_if_data *sdata,
			struct ieee802_11_elems *ie)
63
{
64
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
65
	u32 basic_rates = 0;
66
	struct cfg80211_chan_def sta_chan_def;
67
	struct ieee80211_supported_band *sband;
68 69 70 71 72 73 74 75 76 77 78

	/*
	 * As support for each feature is added, check for matching
	 * - On mesh config capabilities
	 *   - Power Save Support En
	 *   - Sync support enabled
	 *   - Sync support active
	 *   - Sync support required from peer
	 *   - MDA enabled
	 * - Power management control on fc
	 */
79 80 81 82 83 84 85
	if (!(ifmsh->mesh_id_len == ie->mesh_id_len &&
	     memcmp(ifmsh->mesh_id, ie->mesh_id, ie->mesh_id_len) == 0 &&
	     (ifmsh->mesh_pp_id == ie->mesh_config->meshconf_psel) &&
	     (ifmsh->mesh_pm_id == ie->mesh_config->meshconf_pmetric) &&
	     (ifmsh->mesh_cc_id == ie->mesh_config->meshconf_congest) &&
	     (ifmsh->mesh_sp_id == ie->mesh_config->meshconf_synch) &&
	     (ifmsh->mesh_auth_id == ie->mesh_config->meshconf_auth)))
J
Johannes Berg 已提交
86
		return false;
87

88 89 90 91 92
	sband = ieee80211_get_sband(sdata);
	if (!sband)
		return false;

	ieee80211_sta_get_rates(sdata, ie, sband->band,
93 94
				&basic_rates);

95
	if (sdata->vif.bss_conf.basic_rates != basic_rates)
J
Johannes Berg 已提交
96
		return false;
97

98 99 100 101
	cfg80211_chandef_create(&sta_chan_def, sdata->vif.bss_conf.chandef.chan,
				NL80211_CHAN_NO_HT);
	ieee80211_chandef_ht_oper(ie->ht_operation, &sta_chan_def);
	ieee80211_chandef_vht_oper(ie->vht_operation, &sta_chan_def);
102

103 104
	if (!cfg80211_chandef_compatible(&sdata->vif.bss_conf.chandef,
					 &sta_chan_def))
J
Johannes Berg 已提交
105
		return false;
106

107
	return true;
108 109 110 111 112 113 114
}

/**
 * mesh_peer_accepts_plinks - check if an mp is willing to establish peer links
 *
 * @ie: information elements of a management frame from the mesh peer
 */
115
bool mesh_peer_accepts_plinks(struct ieee802_11_elems *ie)
116
{
117
	return (ie->mesh_config->meshconf_cap &
J
Johannes Berg 已提交
118
			IEEE80211_MESHCONF_CAPAB_ACCEPT_PLINKS) != 0;
119 120 121
}

/**
122
 * mesh_accept_plinks_update - update accepting_plink in local mesh beacons
123
 *
124
 * @sdata: mesh interface in which mesh beacons are going to be updated
125 126
 *
 * Returns: beacon changed flag if the beacon content changed.
127
 */
128
u32 mesh_accept_plinks_update(struct ieee80211_sub_if_data *sdata)
129 130
{
	bool free_plinks;
131
	u32 changed = 0;
132 133 134

	/* In case mesh_plink_free_count > 0 and mesh_plinktbl_capacity == 0,
	 * the mesh interface might be able to establish plinks with peers that
135 136 137
	 * are already on the table but are not on PLINK_ESTAB state. However,
	 * in general the mesh interface is not accepting peer link requests
	 * from new peers, and that must be reflected in the beacon
138 139 140
	 */
	free_plinks = mesh_plink_availables(sdata);

141 142 143 144 145 146
	if (free_plinks != sdata->u.mesh.accepting_plinks) {
		sdata->u.mesh.accepting_plinks = free_plinks;
		changed = BSS_CHANGED_BEACON;
	}

	return changed;
147 148
}

149 150 151 152 153 154 155 156
/*
 * mesh_sta_cleanup - clean up any mesh sta state
 *
 * @sta: mesh sta to clean up.
 */
void mesh_sta_cleanup(struct sta_info *sta)
{
	struct ieee80211_sub_if_data *sdata = sta->sdata;
157
	u32 changed = mesh_plink_deactivate(sta);
158

159
	if (changed)
T
Thomas Pedersen 已提交
160
		ieee80211_mbss_info_change_notify(sdata, changed);
161 162
}

163
int mesh_rmc_init(struct ieee80211_sub_if_data *sdata)
164 165 166
{
	int i;

167 168
	sdata->u.mesh.rmc = kmalloc(sizeof(struct mesh_rmc), GFP_KERNEL);
	if (!sdata->u.mesh.rmc)
169
		return -ENOMEM;
170
	sdata->u.mesh.rmc->idx_mask = RMC_BUCKETS - 1;
171
	for (i = 0; i < RMC_BUCKETS; i++)
172
		INIT_HLIST_HEAD(&sdata->u.mesh.rmc->bucket[i]);
173 174 175
	return 0;
}

176
void mesh_rmc_free(struct ieee80211_sub_if_data *sdata)
177
{
178
	struct mesh_rmc *rmc = sdata->u.mesh.rmc;
179 180
	struct rmc_entry *p;
	struct hlist_node *n;
181 182
	int i;

183
	if (!sdata->u.mesh.rmc)
184 185
		return;

J
Johannes Berg 已提交
186
	for (i = 0; i < RMC_BUCKETS; i++) {
187 188
		hlist_for_each_entry_safe(p, n, &rmc->bucket[i], list) {
			hlist_del(&p->list);
189 190
			kmem_cache_free(rm_cache, p);
		}
J
Johannes Berg 已提交
191
	}
192 193

	kfree(rmc);
194
	sdata->u.mesh.rmc = NULL;
195 196 197 198 199
}

/**
 * mesh_rmc_check - Check frame in recent multicast cache and add if absent.
 *
J
Johannes Berg 已提交
200
 * @sdata:	interface
201 202 203 204 205 206 207 208 209
 * @sa:		source address
 * @mesh_hdr:	mesh_header
 *
 * Returns: 0 if the frame is not in the cache, nonzero otherwise.
 *
 * Checks using the source address and the mesh sequence number if we have
 * received this frame lately. If the frame is not in the cache, it is added to
 * it.
 */
J
Johannes Berg 已提交
210 211
int mesh_rmc_check(struct ieee80211_sub_if_data *sdata,
		   const u8 *sa, struct ieee80211s_hdr *mesh_hdr)
212
{
213
	struct mesh_rmc *rmc = sdata->u.mesh.rmc;
214 215 216
	u32 seqnum = 0;
	int entries = 0;
	u8 idx;
217 218
	struct rmc_entry *p;
	struct hlist_node *n;
219

220 221 222
	if (!rmc)
		return -1;

223
	/* Don't care about endianness since only match matters */
224 225
	memcpy(&seqnum, &mesh_hdr->seqnum, sizeof(mesh_hdr->seqnum));
	idx = le32_to_cpu(mesh_hdr->seqnum) & rmc->idx_mask;
226
	hlist_for_each_entry_safe(p, n, &rmc->bucket[idx], list) {
227 228
		++entries;
		if (time_after(jiffies, p->exp_time) ||
J
Johannes Berg 已提交
229
		    entries == RMC_QUEUE_MAX_LEN) {
230
			hlist_del(&p->list);
231 232
			kmem_cache_free(rm_cache, p);
			--entries;
J
Johannes Berg 已提交
233
		} else if ((seqnum == p->seqnum) && ether_addr_equal(sa, p->sa))
234 235 236 237
			return -1;
	}

	p = kmem_cache_alloc(rm_cache, GFP_ATOMIC);
238
	if (!p)
239
		return 0;
240

241 242 243
	p->seqnum = seqnum;
	p->exp_time = jiffies + RMC_TIMEOUT;
	memcpy(p->sa, sa, ETH_ALEN);
244
	hlist_add_head(&p->list, &rmc->bucket[idx]);
245 246 247
	return 0;
}

J
Johannes Berg 已提交
248 249
int mesh_add_meshconf_ie(struct ieee80211_sub_if_data *sdata,
			 struct sk_buff *skb)
250 251 252 253 254 255 256 257 258 259 260 261
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	u8 *pos, neighbors;
	u8 meshconf_len = sizeof(struct ieee80211_meshconf_ie);

	if (skb_tailroom(skb) < 2 + meshconf_len)
		return -ENOMEM;

	pos = skb_put(skb, 2 + meshconf_len);
	*pos++ = WLAN_EID_MESH_CONFIG;
	*pos++ = meshconf_len;

262 263 264
	/* save a pointer for quick updates in pre-tbtt */
	ifmsh->meshconf_offset = pos - skb->data;

265 266 267 268 269 270 271 272 273 274 275
	/* Active path selection protocol ID */
	*pos++ = ifmsh->mesh_pp_id;
	/* Active path selection metric ID   */
	*pos++ = ifmsh->mesh_pm_id;
	/* Congestion control mode identifier */
	*pos++ = ifmsh->mesh_cc_id;
	/* Synchronization protocol identifier */
	*pos++ = ifmsh->mesh_sp_id;
	/* Authentication Protocol identifier */
	*pos++ = ifmsh->mesh_auth_id;
	/* Mesh Formation Info - number of neighbors */
276
	neighbors = atomic_read(&ifmsh->estab_plinks);
277
	neighbors = min_t(int, neighbors, IEEE80211_MAX_MESH_PEERINGS);
278 279
	*pos++ = neighbors << 1;
	/* Mesh capability */
280 281 282
	*pos = 0x00;
	*pos |= ifmsh->mshcfg.dot11MeshForwarding ?
			IEEE80211_MESHCONF_CAPAB_FORWARDING : 0x00;
283
	*pos |= ifmsh->accepting_plinks ?
J
Johannes Berg 已提交
284
			IEEE80211_MESHCONF_CAPAB_ACCEPT_PLINKS : 0x00;
M
Marco Porsch 已提交
285 286
	/* Mesh PS mode. See IEEE802.11-2012 8.4.2.100.8 */
	*pos |= ifmsh->ps_peers_deep_sleep ?
J
Johannes Berg 已提交
287
			IEEE80211_MESHCONF_CAPAB_POWER_SAVE_LEVEL : 0x00;
288 289 290
	return 0;
}

J
Johannes Berg 已提交
291
int mesh_add_meshid_ie(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	u8 *pos;

	if (skb_tailroom(skb) < 2 + ifmsh->mesh_id_len)
		return -ENOMEM;

	pos = skb_put(skb, 2 + ifmsh->mesh_id_len);
	*pos++ = WLAN_EID_MESH_ID;
	*pos++ = ifmsh->mesh_id_len;
	if (ifmsh->mesh_id_len)
		memcpy(pos, ifmsh->mesh_id, ifmsh->mesh_id_len);

	return 0;
}

J
Johannes Berg 已提交
308 309
static int mesh_add_awake_window_ie(struct ieee80211_sub_if_data *sdata,
				    struct sk_buff *skb)
M
Marco Porsch 已提交
310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	u8 *pos;

	/* see IEEE802.11-2012 13.14.6 */
	if (ifmsh->ps_peers_light_sleep == 0 &&
	    ifmsh->ps_peers_deep_sleep == 0 &&
	    ifmsh->nonpeer_pm == NL80211_MESH_POWER_ACTIVE)
		return 0;

	if (skb_tailroom(skb) < 4)
		return -ENOMEM;

	pos = skb_put(skb, 2 + 2);
	*pos++ = WLAN_EID_MESH_AWAKE_WINDOW;
	*pos++ = 2;
	put_unaligned_le16(ifmsh->mshcfg.dot11MeshAwakeWindowDuration, pos);

	return 0;
}

J
Johannes Berg 已提交
331 332
int mesh_add_vendor_ies(struct ieee80211_sub_if_data *sdata,
			struct sk_buff *skb)
333 334 335 336 337 338 339 340 341 342 343
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	u8 offset, len;
	const u8 *data;

	if (!ifmsh->ie || !ifmsh->ie_len)
		return 0;

	/* fast-forward to vendor IEs */
	offset = ieee80211_ie_split_vendor(ifmsh->ie, ifmsh->ie_len, 0);

344
	if (offset < ifmsh->ie_len) {
345 346 347 348
		len = ifmsh->ie_len - offset;
		data = ifmsh->ie + offset;
		if (skb_tailroom(skb) < len)
			return -ENOMEM;
349
		skb_put_data(skb, data, len);
350 351 352 353 354
	}

	return 0;
}

J
Johannes Berg 已提交
355
int mesh_add_rsn_ie(struct ieee80211_sub_if_data *sdata, struct sk_buff *skb)
356 357 358 359 360 361 362 363 364
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	u8 len = 0;
	const u8 *data;

	if (!ifmsh->ie || !ifmsh->ie_len)
		return 0;

	/* find RSN IE */
365 366 367
	data = cfg80211_find_ie(WLAN_EID_RSN, ifmsh->ie, ifmsh->ie_len);
	if (!data)
		return 0;
368

369 370 371 372
	len = data[1] + 2;

	if (skb_tailroom(skb) < len)
		return -ENOMEM;
373
	skb_put_data(skb, data, len);
374 375 376 377

	return 0;
}

J
Johannes Berg 已提交
378 379
static int mesh_add_ds_params_ie(struct ieee80211_sub_if_data *sdata,
				 struct sk_buff *skb)
380
{
J
Johannes Berg 已提交
381 382
	struct ieee80211_chanctx_conf *chanctx_conf;
	struct ieee80211_channel *chan;
383
	u8 *pos;
384

385 386 387
	if (skb_tailroom(skb) < 3)
		return -ENOMEM;

J
Johannes Berg 已提交
388 389 390 391 392 393
	rcu_read_lock();
	chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
	if (WARN_ON(!chanctx_conf)) {
		rcu_read_unlock();
		return -EINVAL;
	}
394
	chan = chanctx_conf->def.chan;
J
Johannes Berg 已提交
395 396
	rcu_read_unlock();

397 398 399 400
	pos = skb_put(skb, 2 + 1);
	*pos++ = WLAN_EID_DS_PARAMS;
	*pos++ = 1;
	*pos++ = ieee80211_frequency_to_channel(chan->center_freq);
401

402
	return 0;
403 404
}

J
Johannes Berg 已提交
405 406
int mesh_add_ht_cap_ie(struct ieee80211_sub_if_data *sdata,
		       struct sk_buff *skb)
407 408 409 410
{
	struct ieee80211_supported_band *sband;
	u8 *pos;

411 412 413 414
	sband = ieee80211_get_sband(sdata);
	if (!sband)
		return -EINVAL;

415
	if (!sband->ht_cap.ht_supported ||
416 417 418
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_20_NOHT ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_5 ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_10)
419 420 421 422 423 424
		return 0;

	if (skb_tailroom(skb) < 2 + sizeof(struct ieee80211_ht_cap))
		return -ENOMEM;

	pos = skb_put(skb, 2 + sizeof(struct ieee80211_ht_cap));
B
Ben Greear 已提交
425
	ieee80211_ie_build_ht_cap(pos, &sband->ht_cap, sband->ht_cap.cap);
426 427 428 429

	return 0;
}

J
Johannes Berg 已提交
430 431
int mesh_add_ht_oper_ie(struct ieee80211_sub_if_data *sdata,
			struct sk_buff *skb)
432 433
{
	struct ieee80211_local *local = sdata->local;
J
Johannes Berg 已提交
434 435 436 437
	struct ieee80211_chanctx_conf *chanctx_conf;
	struct ieee80211_channel *channel;
	struct ieee80211_supported_band *sband;
	struct ieee80211_sta_ht_cap *ht_cap;
438 439
	u8 *pos;

J
Johannes Berg 已提交
440 441 442 443 444 445
	rcu_read_lock();
	chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
	if (WARN_ON(!chanctx_conf)) {
		rcu_read_unlock();
		return -EINVAL;
	}
446
	channel = chanctx_conf->def.chan;
J
Johannes Berg 已提交
447 448 449 450 451
	rcu_read_unlock();

	sband = local->hw.wiphy->bands[channel->band];
	ht_cap = &sband->ht_cap;

452 453 454 455
	if (!ht_cap->ht_supported ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_20_NOHT ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_5 ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_10)
456 457
		return 0;

458
	if (skb_tailroom(skb) < 2 + sizeof(struct ieee80211_ht_operation))
459 460
		return -ENOMEM;

461
	pos = skb_put(skb, 2 + sizeof(struct ieee80211_ht_operation));
462
	ieee80211_ie_build_ht_oper(pos, ht_cap, &sdata->vif.bss_conf.chandef,
463 464
				   sdata->vif.bss_conf.ht_operation_mode,
				   false);
465 466 467

	return 0;
}
J
Johannes Berg 已提交
468

469 470 471 472 473 474
int mesh_add_vht_cap_ie(struct ieee80211_sub_if_data *sdata,
			struct sk_buff *skb)
{
	struct ieee80211_supported_band *sband;
	u8 *pos;

475 476 477 478
	sband = ieee80211_get_sband(sdata);
	if (!sband)
		return -EINVAL;

479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531
	if (!sband->vht_cap.vht_supported ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_20_NOHT ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_5 ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_10)
		return 0;

	if (skb_tailroom(skb) < 2 + sizeof(struct ieee80211_vht_cap))
		return -ENOMEM;

	pos = skb_put(skb, 2 + sizeof(struct ieee80211_vht_cap));
	ieee80211_ie_build_vht_cap(pos, &sband->vht_cap, sband->vht_cap.cap);

	return 0;
}

int mesh_add_vht_oper_ie(struct ieee80211_sub_if_data *sdata,
			 struct sk_buff *skb)
{
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_chanctx_conf *chanctx_conf;
	struct ieee80211_channel *channel;
	struct ieee80211_supported_band *sband;
	struct ieee80211_sta_vht_cap *vht_cap;
	u8 *pos;

	rcu_read_lock();
	chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
	if (WARN_ON(!chanctx_conf)) {
		rcu_read_unlock();
		return -EINVAL;
	}
	channel = chanctx_conf->def.chan;
	rcu_read_unlock();

	sband = local->hw.wiphy->bands[channel->band];
	vht_cap = &sband->vht_cap;

	if (!vht_cap->vht_supported ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_20_NOHT ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_5 ||
	    sdata->vif.bss_conf.chandef.width == NL80211_CHAN_WIDTH_10)
		return 0;

	if (skb_tailroom(skb) < 2 + sizeof(struct ieee80211_vht_operation))
		return -ENOMEM;

	pos = skb_put(skb, 2 + sizeof(struct ieee80211_vht_operation));
	ieee80211_ie_build_vht_oper(pos, vht_cap,
				    &sdata->vif.bss_conf.chandef);

	return 0;
}

532
static void ieee80211_mesh_path_timer(struct timer_list *t)
533 534
{
	struct ieee80211_sub_if_data *sdata =
535
		from_timer(sdata, t, u.mesh.mesh_path_timer);
536

537
	ieee80211_queue_work(&sdata->local->hw, &sdata->work);
538 539
}

540
static void ieee80211_mesh_path_root_timer(struct timer_list *t)
541 542
{
	struct ieee80211_sub_if_data *sdata =
543
		from_timer(sdata, t, u.mesh.mesh_path_root_timer);
544 545 546 547
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;

	set_bit(MESH_WORK_ROOT, &ifmsh->wrkq_flags);

548
	ieee80211_queue_work(&sdata->local->hw, &sdata->work);
549 550
}

551 552
void ieee80211_mesh_root_setup(struct ieee80211_if_mesh *ifmsh)
{
553
	if (ifmsh->mshcfg.dot11MeshHWMPRootMode > IEEE80211_ROOTMODE_ROOT)
554 555 556 557 558 559 560 561
		set_bit(MESH_WORK_ROOT, &ifmsh->wrkq_flags);
	else {
		clear_bit(MESH_WORK_ROOT, &ifmsh->wrkq_flags);
		/* stop running timer */
		del_timer_sync(&ifmsh->mesh_path_root_timer);
	}
}

562 563
/**
 * ieee80211_fill_mesh_addresses - fill addresses of a locally originated mesh frame
J
Johannes Berg 已提交
564
 * @hdr:	802.11 frame header
565 566 567 568 569 570 571
 * @fc:		frame control field
 * @meshda:	destination address in the mesh
 * @meshsa:	source address address in the mesh.  Same as TA, as frame is
 *              locally originated.
 *
 * Return the length of the 802.11 (does not include a mesh control header)
 */
572 573 574
int ieee80211_fill_mesh_addresses(struct ieee80211_hdr *hdr, __le16 *fc,
				  const u8 *meshda, const u8 *meshsa)
{
575 576 577 578 579 580 581 582
	if (is_multicast_ether_addr(meshda)) {
		*fc |= cpu_to_le16(IEEE80211_FCTL_FROMDS);
		/* DA TA SA */
		memcpy(hdr->addr1, meshda, ETH_ALEN);
		memcpy(hdr->addr2, meshsa, ETH_ALEN);
		memcpy(hdr->addr3, meshsa, ETH_ALEN);
		return 24;
	} else {
583
		*fc |= cpu_to_le16(IEEE80211_FCTL_FROMDS | IEEE80211_FCTL_TODS);
584
		/* RA TA DA SA */
585
		eth_zero_addr(hdr->addr1);   /* RA is resolved later */
586 587 588 589 590 591 592
		memcpy(hdr->addr2, meshsa, ETH_ALEN);
		memcpy(hdr->addr3, meshda, ETH_ALEN);
		memcpy(hdr->addr4, meshsa, ETH_ALEN);
		return 30;
	}
}

J
Johannes Berg 已提交
593 594 595
/**
 * ieee80211_new_mesh_header - create a new mesh header
 * @sdata:	mesh interface to be used
J
Johannes Berg 已提交
596
 * @meshhdr:    uninitialized mesh header
597 598 599 600 601
 * @addr4or5:   1st address in the ae header, which may correspond to address 4
 *              (if addr6 is NULL) or address 5 (if addr6 is present). It may
 *              be NULL.
 * @addr6:	2nd address in the ae header, which corresponds to addr6 of the
 *              mesh frame
J
Johannes Berg 已提交
602 603 604
 *
 * Return the header length.
 */
605 606 607
unsigned int ieee80211_new_mesh_header(struct ieee80211_sub_if_data *sdata,
				       struct ieee80211s_hdr *meshhdr,
				       const char *addr4or5, const char *addr6)
J
Johannes Berg 已提交
608
{
J
Johannes Berg 已提交
609 610 611
	if (WARN_ON(!addr4or5 && addr6))
		return 0;

612
	memset(meshhdr, 0, sizeof(*meshhdr));
J
Johannes Berg 已提交
613

614
	meshhdr->ttl = sdata->u.mesh.mshcfg.dot11MeshTTL;
J
Johannes Berg 已提交
615 616

	/* FIXME: racy -- TX on multiple queues can be concurrent */
617 618
	put_unaligned(cpu_to_le32(sdata->u.mesh.mesh_seqnum), &meshhdr->seqnum);
	sdata->u.mesh.mesh_seqnum++;
J
Johannes Berg 已提交
619

620
	if (addr4or5 && !addr6) {
621
		meshhdr->flags |= MESH_FLAGS_AE_A4;
622
		memcpy(meshhdr->eaddr1, addr4or5, ETH_ALEN);
J
Johannes Berg 已提交
623
		return 2 * ETH_ALEN;
624
	} else if (addr4or5 && addr6) {
625
		meshhdr->flags |= MESH_FLAGS_AE_A5_A6;
626 627
		memcpy(meshhdr->eaddr1, addr4or5, ETH_ALEN);
		memcpy(meshhdr->eaddr2, addr6, ETH_ALEN);
J
Johannes Berg 已提交
628
		return 3 * ETH_ALEN;
629
	}
J
Johannes Berg 已提交
630 631

	return ETH_ALEN;
J
Johannes Berg 已提交
632 633
}

J
Johannes Berg 已提交
634
static void ieee80211_mesh_housekeeping(struct ieee80211_sub_if_data *sdata)
635
{
J
Johannes Berg 已提交
636
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
637
	u32 changed;
638

639 640
	if (ifmsh->mshcfg.plink_timeout > 0)
		ieee80211_sta_expire(sdata, ifmsh->mshcfg.plink_timeout * HZ);
641 642
	mesh_path_expire(sdata);

643
	changed = mesh_accept_plinks_update(sdata);
T
Thomas Pedersen 已提交
644
	ieee80211_mbss_info_change_notify(sdata, changed);
645 646

	mod_timer(&ifmsh->housekeeping_timer,
J
Johannes Berg 已提交
647 648
		  round_jiffies(jiffies +
				IEEE80211_MESH_HOUSEKEEPING_INTERVAL));
649 650
}

651 652 653
static void ieee80211_mesh_rootpath(struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
654
	u32 interval;
655 656

	mesh_path_tx_root_frame(sdata);
657 658 659 660 661 662

	if (ifmsh->mshcfg.dot11MeshHWMPRootMode == IEEE80211_PROACTIVE_RANN)
		interval = ifmsh->mshcfg.dot11MeshHWMPRannInterval;
	else
		interval = ifmsh->mshcfg.dot11MeshHWMProotInterval;

663
	mod_timer(&ifmsh->mesh_path_root_timer,
664
		  round_jiffies(TU_TO_EXP_TIME(interval)));
665 666
}

T
Thomas Pedersen 已提交
667 668 669 670 671 672 673 674
static int
ieee80211_mesh_build_beacon(struct ieee80211_if_mesh *ifmsh)
{
	struct beacon_data *bcn;
	int head_len, tail_len;
	struct sk_buff *skb;
	struct ieee80211_mgmt *mgmt;
	struct ieee80211_chanctx_conf *chanctx_conf;
675
	struct mesh_csa_settings *csa;
676
	enum nl80211_band band;
T
Thomas Pedersen 已提交
677 678
	u8 *pos;
	struct ieee80211_sub_if_data *sdata;
J
Johannes Berg 已提交
679
	int hdr_len = offsetofend(struct ieee80211_mgmt, u.beacon);
T
Thomas Pedersen 已提交
680 681 682 683 684 685 686 687 688

	sdata = container_of(ifmsh, struct ieee80211_sub_if_data, u.mesh);
	rcu_read_lock();
	chanctx_conf = rcu_dereference(sdata->vif.chanctx_conf);
	band = chanctx_conf->def.chan->band;
	rcu_read_unlock();

	head_len = hdr_len +
		   2 + /* NULL SSID */
689 690
		   /* Channel Switch Announcement */
		   2 + sizeof(struct ieee80211_channel_sw_ie) +
691
		   /* Mesh Channel Switch Parameters */
692
		   2 + sizeof(struct ieee80211_mesh_chansw_params_ie) +
693 694 695
		   /* Channel Switch Wrapper + Wide Bandwidth CSA IE */
		   2 + 2 + sizeof(struct ieee80211_wide_bw_chansw_ie) +
		   2 + sizeof(struct ieee80211_sec_chan_offs_ie) +
T
Thomas Pedersen 已提交
696 697 698 699 700 701 702 703
		   2 + 8 + /* supported rates */
		   2 + 3; /* DS params */
	tail_len = 2 + (IEEE80211_MAX_SUPP_RATES - 8) +
		   2 + sizeof(struct ieee80211_ht_cap) +
		   2 + sizeof(struct ieee80211_ht_operation) +
		   2 + ifmsh->mesh_id_len +
		   2 + sizeof(struct ieee80211_meshconf_ie) +
		   2 + sizeof(__le16) + /* awake window */
704 705
		   2 + sizeof(struct ieee80211_vht_cap) +
		   2 + sizeof(struct ieee80211_vht_operation) +
T
Thomas Pedersen 已提交
706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721
		   ifmsh->ie_len;

	bcn = kzalloc(sizeof(*bcn) + head_len + tail_len, GFP_KERNEL);
	/* need an skb for IE builders to operate on */
	skb = dev_alloc_skb(max(head_len, tail_len));

	if (!bcn || !skb)
		goto out_free;

	/*
	 * pointers go into the block we allocated,
	 * memory is | beacon_data | head | tail |
	 */
	bcn->head = ((u8 *) bcn) + sizeof(*bcn);

	/* fill in the head */
722
	mgmt = skb_put_zero(skb, hdr_len);
T
Thomas Pedersen 已提交
723 724 725 726 727 728 729 730 731 732 733 734 735 736 737
	mgmt->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
					  IEEE80211_STYPE_BEACON);
	eth_broadcast_addr(mgmt->da);
	memcpy(mgmt->sa, sdata->vif.addr, ETH_ALEN);
	memcpy(mgmt->bssid, sdata->vif.addr, ETH_ALEN);
	ieee80211_mps_set_frame_flags(sdata, NULL, (void *) mgmt);
	mgmt->u.beacon.beacon_int =
		cpu_to_le16(sdata->vif.bss_conf.beacon_int);
	mgmt->u.beacon.capab_info |= cpu_to_le16(
		sdata->u.mesh.security ? WLAN_CAPABILITY_PRIVACY : 0);

	pos = skb_put(skb, 2);
	*pos++ = WLAN_EID_SSID;
	*pos++ = 0x0;

738 739 740
	rcu_read_lock();
	csa = rcu_dereference(ifmsh->csa);
	if (csa) {
741 742 743 744 745
		enum nl80211_channel_type ct;
		struct cfg80211_chan_def *chandef;
		int ie_len = 2 + sizeof(struct ieee80211_channel_sw_ie) +
			     2 + sizeof(struct ieee80211_mesh_chansw_params_ie);

746
		pos = skb_put_zero(skb, ie_len);
747 748 749 750 751
		*pos++ = WLAN_EID_CHANNEL_SWITCH;
		*pos++ = 3;
		*pos++ = 0x0;
		*pos++ = ieee80211_frequency_to_channel(
				csa->settings.chandef.chan->center_freq);
752
		bcn->csa_current_counter = csa->settings.count;
753
		bcn->csa_counter_offsets[0] = hdr_len + 6;
754 755 756
		*pos++ = csa->settings.count;
		*pos++ = WLAN_EID_CHAN_SWITCH_PARAM;
		*pos++ = 6;
757
		if (ifmsh->csa_role == IEEE80211_MESH_CSA_ROLE_INIT) {
758 759 760 761 762 763 764 765 766
			*pos++ = ifmsh->mshcfg.dot11MeshTTL;
			*pos |= WLAN_EID_CHAN_SWITCH_PARAM_INITIATOR;
		} else {
			*pos++ = ifmsh->chsw_ttl;
		}
		*pos++ |= csa->settings.block_tx ?
			  WLAN_EID_CHAN_SWITCH_PARAM_TX_RESTRICT : 0x00;
		put_unaligned_le16(WLAN_REASON_MESH_CHAN, pos);
		pos += 2;
767
		put_unaligned_le16(ifmsh->pre_value, pos);
768
		pos += 2;
769 770 771 772

		switch (csa->settings.chandef.width) {
		case NL80211_CHAN_WIDTH_40:
			ie_len = 2 + sizeof(struct ieee80211_sec_chan_offs_ie);
773
			pos = skb_put_zero(skb, ie_len);
774 775 776 777 778 779 780 781 782 783 784 785 786 787 788

			*pos++ = WLAN_EID_SECONDARY_CHANNEL_OFFSET; /* EID */
			*pos++ = 1;				    /* len */
			ct = cfg80211_get_chandef_type(&csa->settings.chandef);
			if (ct == NL80211_CHAN_HT40PLUS)
				*pos++ = IEEE80211_HT_PARAM_CHA_SEC_ABOVE;
			else
				*pos++ = IEEE80211_HT_PARAM_CHA_SEC_BELOW;
			break;
		case NL80211_CHAN_WIDTH_80:
		case NL80211_CHAN_WIDTH_80P80:
		case NL80211_CHAN_WIDTH_160:
			/* Channel Switch Wrapper + Wide Bandwidth CSA IE */
			ie_len = 2 + 2 +
				 sizeof(struct ieee80211_wide_bw_chansw_ie);
789
			pos = skb_put_zero(skb, ie_len);
790 791 792 793 794 795 796 797 798 799

			*pos++ = WLAN_EID_CHANNEL_SWITCH_WRAPPER; /* EID */
			*pos++ = 5;				  /* len */
			/* put sub IE */
			chandef = &csa->settings.chandef;
			ieee80211_ie_build_wide_bw_cs(pos, chandef);
			break;
		default:
			break;
		}
800 801 802
	}
	rcu_read_unlock();

T
Thomas Pedersen 已提交
803
	if (ieee80211_add_srates_ie(sdata, skb, true, band) ||
J
Johannes Berg 已提交
804
	    mesh_add_ds_params_ie(sdata, skb))
T
Thomas Pedersen 已提交
805 806 807 808 809 810 811 812 813 814
		goto out_free;

	bcn->head_len = skb->len;
	memcpy(bcn->head, skb->data, bcn->head_len);

	/* now the tail */
	skb_trim(skb, 0);
	bcn->tail = bcn->head + bcn->head_len;

	if (ieee80211_add_ext_srates_ie(sdata, skb, true, band) ||
J
Johannes Berg 已提交
815 816 817 818 819 820
	    mesh_add_rsn_ie(sdata, skb) ||
	    mesh_add_ht_cap_ie(sdata, skb) ||
	    mesh_add_ht_oper_ie(sdata, skb) ||
	    mesh_add_meshid_ie(sdata, skb) ||
	    mesh_add_meshconf_ie(sdata, skb) ||
	    mesh_add_awake_window_ie(sdata, skb) ||
821 822
	    mesh_add_vht_cap_ie(sdata, skb) ||
	    mesh_add_vht_oper_ie(sdata, skb) ||
J
Johannes Berg 已提交
823
	    mesh_add_vendor_ies(sdata, skb))
T
Thomas Pedersen 已提交
824 825 826 827
		goto out_free;

	bcn->tail_len = skb->len;
	memcpy(bcn->tail, skb->data, bcn->tail_len);
828 829
	bcn->meshconf = (struct ieee80211_meshconf_ie *)
					(bcn->tail + ifmsh->meshconf_offset);
T
Thomas Pedersen 已提交
830 831 832 833 834 835 836 837 838 839 840

	dev_kfree_skb(skb);
	rcu_assign_pointer(ifmsh->beacon, bcn);
	return 0;
out_free:
	kfree(bcn);
	dev_kfree_skb(skb);
	return -ENOMEM;
}

static int
841
ieee80211_mesh_rebuild_beacon(struct ieee80211_sub_if_data *sdata)
T
Thomas Pedersen 已提交
842 843 844 845
{
	struct beacon_data *old_bcn;
	int ret;

846 847 848
	old_bcn = rcu_dereference_protected(sdata->u.mesh.beacon,
					    lockdep_is_held(&sdata->wdev.mtx));
	ret = ieee80211_mesh_build_beacon(&sdata->u.mesh);
T
Thomas Pedersen 已提交
849 850
	if (ret)
		/* just reuse old beacon */
851
		return ret;
T
Thomas Pedersen 已提交
852 853 854

	if (old_bcn)
		kfree_rcu(old_bcn, rcu_head);
855
	return 0;
T
Thomas Pedersen 已提交
856 857 858 859 860
}

void ieee80211_mbss_info_change_notify(struct ieee80211_sub_if_data *sdata,
				       u32 changed)
{
861 862 863 864 865 866 867 868 869 870 871 872
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	unsigned long bits = changed;
	u32 bit;

	if (!bits)
		return;

	/* if we race with running work, worst case this work becomes a noop */
	for_each_set_bit(bit, &bits, sizeof(changed) * BITS_PER_BYTE)
		set_bit(bit, &ifmsh->mbss_changed);
	set_bit(MESH_WORK_MBSS_CHANGED, &ifmsh->wrkq_flags);
	ieee80211_queue_work(&sdata->local->hw, &sdata->work);
T
Thomas Pedersen 已提交
873 874 875
}

int ieee80211_start_mesh(struct ieee80211_sub_if_data *sdata)
876 877 878
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	struct ieee80211_local *local = sdata->local;
879 880 881 882 883
	u32 changed = BSS_CHANGED_BEACON |
		      BSS_CHANGED_BEACON_ENABLED |
		      BSS_CHANGED_HT |
		      BSS_CHANGED_BASIC_RATES |
		      BSS_CHANGED_BEACON_INT;
884

885 886 887 888 889
	local->fif_other_bss++;
	/* mesh ifaces must set allmulti to forward mcast traffic */
	atomic_inc(&local->iff_allmultis);
	ieee80211_configure_filter(local);

890
	ifmsh->mesh_cc_id = 0;	/* Disabled */
891 892 893
	/* register sync ops from extensible synchronization framework */
	ifmsh->sync_ops = ieee80211_mesh_sync_ops_get(ifmsh->mesh_sp_id);
	ifmsh->sync_offset_clockdrift_max = 0;
894
	set_bit(MESH_WORK_HOUSEKEEPING, &ifmsh->wrkq_flags);
895
	ieee80211_mesh_root_setup(ifmsh);
J
Johannes Berg 已提交
896
	ieee80211_queue_work(&local->hw, &sdata->work);
897 898
	sdata->vif.bss_conf.ht_operation_mode =
				ifmsh->mshcfg.ht_opmode;
899
	sdata->vif.bss_conf.enable_beacon = true;
900

901
	changed |= ieee80211_mps_local_status_update(sdata);
M
Marco Porsch 已提交
902

T
Thomas Pedersen 已提交
903 904 905 906 907
	if (ieee80211_mesh_build_beacon(ifmsh)) {
		ieee80211_stop_mesh(sdata);
		return -ENOMEM;
	}

908
	ieee80211_recalc_dtim(local, sdata);
909
	ieee80211_bss_info_change_notify(sdata, changed);
910 911

	netif_carrier_on(sdata->dev);
T
Thomas Pedersen 已提交
912
	return 0;
913 914 915 916
}

void ieee80211_stop_mesh(struct ieee80211_sub_if_data *sdata)
{
917
	struct ieee80211_local *local = sdata->local;
918
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
T
Thomas Pedersen 已提交
919
	struct beacon_data *bcn;
920

921 922
	netif_carrier_off(sdata->dev);

923 924 925 926
	/* flush STAs and mpaths on this iface */
	sta_info_flush(sdata);
	mesh_path_flush_by_iface(sdata);

927
	/* stop the beacon */
928
	ifmsh->mesh_id_len = 0;
929 930
	sdata->vif.bss_conf.enable_beacon = false;
	clear_bit(SDATA_STATE_OFFCHANNEL_BEACON_STOPPED, &sdata->state);
931
	ieee80211_bss_info_change_notify(sdata, BSS_CHANGED_BEACON_ENABLED);
932 933

	/* remove beacon */
T
Thomas Pedersen 已提交
934
	bcn = rcu_dereference_protected(ifmsh->beacon,
935
					lockdep_is_held(&sdata->wdev.mtx));
M
Monam Agarwal 已提交
936
	RCU_INIT_POINTER(ifmsh->beacon, NULL);
T
Thomas Pedersen 已提交
937
	kfree_rcu(bcn, rcu_head);
938

M
Marco Porsch 已提交
939 940 941 942
	/* free all potentially still buffered group-addressed frames */
	local->total_ps_buffered -= skb_queue_len(&ifmsh->ps.bc_buf);
	skb_queue_purge(&ifmsh->ps.bc_buf);

943
	del_timer_sync(&sdata->u.mesh.housekeeping_timer);
944
	del_timer_sync(&sdata->u.mesh.mesh_path_root_timer);
J
Johannes Berg 已提交
945
	del_timer_sync(&sdata->u.mesh.mesh_path_timer);
946

947 948 949 950
	/* clear any mesh work (for next join) we may have accrued */
	ifmsh->wrkq_flags = 0;
	ifmsh->mbss_changed = 0;

951 952 953
	local->fif_other_bss--;
	atomic_dec(&local->iff_allmultis);
	ieee80211_configure_filter(local);
954 955
}

956 957 958 959 960 961 962 963 964 965 966 967 968 969 970
static void ieee80211_mesh_csa_mark_radar(struct ieee80211_sub_if_data *sdata)
{
	int err;

	/* if the current channel is a DFS channel, mark the channel as
	 * unavailable.
	 */
	err = cfg80211_chandef_dfs_required(sdata->local->hw.wiphy,
					    &sdata->vif.bss_conf.chandef,
					    NL80211_IFTYPE_MESH_POINT);
	if (err > 0)
		cfg80211_radar_event(sdata->local->hw.wiphy,
				     &sdata->vif.bss_conf.chandef, GFP_ATOMIC);
}

971 972 973 974 975 976 977
static bool
ieee80211_mesh_process_chnswitch(struct ieee80211_sub_if_data *sdata,
				 struct ieee802_11_elems *elems, bool beacon)
{
	struct cfg80211_csa_settings params;
	struct ieee80211_csa_ie csa_ie;
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
978
	struct ieee80211_supported_band *sband;
979
	int err;
980 981
	u32 sta_flags;

982 983
	sdata_assert_lock(sdata);

984 985 986 987
	sband = ieee80211_get_sband(sdata);
	if (!sband)
		return false;

988
	sta_flags = 0;
989 990 991 992 993
	switch (sdata->vif.bss_conf.chandef.width) {
	case NL80211_CHAN_WIDTH_20_NOHT:
		sta_flags |= IEEE80211_STA_DISABLE_HT;
	case NL80211_CHAN_WIDTH_20:
		sta_flags |= IEEE80211_STA_DISABLE_40MHZ;
994 995
	case NL80211_CHAN_WIDTH_40:
		sta_flags |= IEEE80211_STA_DISABLE_VHT;
996 997 998 999 1000 1001
		break;
	default:
		break;
	}

	memset(&params, 0, sizeof(params));
1002
	err = ieee80211_parse_ch_switch_ie(sdata, elems, sband->band,
1003 1004 1005 1006 1007 1008 1009
					   sta_flags, sdata->vif.addr,
					   &csa_ie);
	if (err < 0)
		return false;
	if (err)
		return false;

1010 1011 1012 1013 1014 1015
	/* Mark the channel unavailable if the reason for the switch is
	 * regulatory.
	 */
	if (csa_ie.reason_code == WLAN_REASON_MESH_CHAN_REGULATORY)
		ieee80211_mesh_csa_mark_radar(sdata);

1016 1017 1018 1019
	params.chandef = csa_ie.chandef;
	params.count = csa_ie.count;

	if (!cfg80211_chandef_usable(sdata->local->hw.wiphy, &params.chandef,
1020 1021 1022
				     IEEE80211_CHAN_DISABLED) ||
	    !cfg80211_reg_can_beacon(sdata->local->hw.wiphy, &params.chandef,
				     NL80211_IFTYPE_MESH_POINT)) {
1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033
		sdata_info(sdata,
			   "mesh STA %pM switches to unsupported channel (%d MHz, width:%d, CF1/2: %d/%d MHz), aborting\n",
			   sdata->vif.addr,
			   params.chandef.chan->center_freq,
			   params.chandef.width,
			   params.chandef.center_freq1,
			   params.chandef.center_freq2);
		return false;
	}

	err = cfg80211_chandef_dfs_required(sdata->local->hw.wiphy,
1034 1035
					    &params.chandef,
					    NL80211_IFTYPE_MESH_POINT);
1036 1037
	if (err < 0)
		return false;
1038 1039 1040 1041 1042 1043 1044 1045
	if (err > 0 && !ifmsh->userspace_handles_dfs) {
		sdata_info(sdata,
			   "mesh STA %pM switches to channel requiring DFS (%d MHz, width:%d, CF1/2: %d/%d MHz), aborting\n",
			   sdata->vif.addr,
			   params.chandef.chan->center_freq,
			   params.chandef.width,
			   params.chandef.center_freq1,
			   params.chandef.center_freq2);
1046
		return false;
1047
	}
1048 1049

	params.radar_required = err;
1050

1051 1052 1053 1054 1055 1056
	if (cfg80211_chandef_identical(&params.chandef,
				       &sdata->vif.bss_conf.chandef)) {
		mcsa_dbg(sdata,
			 "received csa with an identical chandef, ignoring\n");
		return true;
	}
1057 1058 1059 1060 1061 1062

	mcsa_dbg(sdata,
		 "received channel switch announcement to go to channel %d MHz\n",
		 params.chandef.chan->center_freq);

	params.block_tx = csa_ie.mode & WLAN_EID_CHAN_SWITCH_PARAM_TX_RESTRICT;
1063
	if (beacon) {
1064
		ifmsh->chsw_ttl = csa_ie.ttl - 1;
1065 1066 1067 1068
		if (ifmsh->pre_value >= csa_ie.pre_value)
			return false;
		ifmsh->pre_value = csa_ie.pre_value;
	}
1069

1070
	if (ifmsh->chsw_ttl >= ifmsh->mshcfg.dot11MeshTTL)
1071
		return false;
1072

1073
	ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_REPEATER;
1074

1075 1076 1077
	if (ieee80211_channel_switch(sdata->local->hw.wiphy, sdata->dev,
				     &params) < 0)
		return false;
1078 1079 1080 1081

	return true;
}

1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092
static void
ieee80211_mesh_rx_probe_req(struct ieee80211_sub_if_data *sdata,
			    struct ieee80211_mgmt *mgmt, size_t len)
{
	struct ieee80211_local *local = sdata->local;
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	struct sk_buff *presp;
	struct beacon_data *bcn;
	struct ieee80211_mgmt *hdr;
	struct ieee802_11_elems elems;
	size_t baselen;
1093
	u8 *pos;
1094 1095 1096 1097 1098 1099

	pos = mgmt->u.probe_req.variable;
	baselen = (u8 *) pos - (u8 *) mgmt;
	if (baselen > len)
		return;

1100
	ieee802_11_parse_elems(pos, len - baselen, false, &elems);
1101

1102 1103 1104
	if (!elems.mesh_id)
		return;

1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127
	/* 802.11-2012 10.1.4.3.2 */
	if ((!ether_addr_equal(mgmt->da, sdata->vif.addr) &&
	     !is_broadcast_ether_addr(mgmt->da)) ||
	    elems.ssid_len != 0)
		return;

	if (elems.mesh_id_len != 0 &&
	    (elems.mesh_id_len != ifmsh->mesh_id_len ||
	     memcmp(elems.mesh_id, ifmsh->mesh_id, ifmsh->mesh_id_len)))
		return;

	rcu_read_lock();
	bcn = rcu_dereference(ifmsh->beacon);

	if (!bcn)
		goto out;

	presp = dev_alloc_skb(local->tx_headroom +
			      bcn->head_len + bcn->tail_len);
	if (!presp)
		goto out;

	skb_reserve(presp, local->tx_headroom);
1128 1129
	skb_put_data(presp, bcn->head, bcn->head_len);
	skb_put_data(presp, bcn->tail, bcn->tail_len);
1130 1131 1132 1133 1134 1135 1136 1137 1138 1139
	hdr = (struct ieee80211_mgmt *) presp->data;
	hdr->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
					 IEEE80211_STYPE_PROBE_RESP);
	memcpy(hdr->da, mgmt->sa, ETH_ALEN);
	IEEE80211_SKB_CB(presp)->flags |= IEEE80211_TX_INTFL_DONT_ENCRYPT;
	ieee80211_tx_skb(sdata, presp);
out:
	rcu_read_unlock();
}

1140 1141 1142 1143 1144 1145
static void ieee80211_mesh_rx_bcn_presp(struct ieee80211_sub_if_data *sdata,
					u16 stype,
					struct ieee80211_mgmt *mgmt,
					size_t len,
					struct ieee80211_rx_status *rx_status)
{
J
Johannes Berg 已提交
1146
	struct ieee80211_local *local = sdata->local;
1147
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
1148 1149 1150 1151
	struct ieee802_11_elems elems;
	struct ieee80211_channel *channel;
	size_t baselen;
	int freq;
1152
	enum nl80211_band band = rx_status->band;
1153 1154 1155

	/* ignore ProbeResp to foreign address */
	if (stype == IEEE80211_STYPE_PROBE_RESP &&
1156
	    !ether_addr_equal(mgmt->da, sdata->vif.addr))
1157 1158 1159 1160 1161 1162 1163
		return;

	baselen = (u8 *) mgmt->u.probe_resp.variable - (u8 *) mgmt;
	if (baselen > len)
		return;

	ieee802_11_parse_elems(mgmt->u.probe_resp.variable, len - baselen,
1164
			       false, &elems);
1165

1166 1167 1168 1169
	/* ignore non-mesh or secure / unsecure mismatch */
	if ((!elems.mesh_id || !elems.mesh_config) ||
	    (elems.rsn && sdata->u.mesh.security == IEEE80211_MESH_SEC_NONE) ||
	    (!elems.rsn && sdata->u.mesh.security != IEEE80211_MESH_SEC_NONE))
1170 1171
		return;

1172
	if (elems.ds_params)
1173
		freq = ieee80211_channel_to_frequency(elems.ds_params[0], band);
1174 1175 1176 1177 1178 1179 1180 1181
	else
		freq = rx_status->freq;

	channel = ieee80211_get_channel(local->hw.wiphy, freq);

	if (!channel || channel->flags & IEEE80211_CHAN_DISABLED)
		return;

1182 1183 1184 1185 1186 1187 1188 1189
	if (mesh_matches_local(sdata, &elems)) {
		mpl_dbg(sdata, "rssi_threshold=%d,rx_status->signal=%d\n",
			sdata->u.mesh.mshcfg.rssi_threshold, rx_status->signal);
		if (!sdata->u.mesh.user_mpm ||
		    sdata->u.mesh.mshcfg.rssi_threshold == 0 ||
		    sdata->u.mesh.mshcfg.rssi_threshold < rx_status->signal)
			mesh_neighbour_update(sdata, mgmt->sa, &elems);
	}
1190 1191 1192 1193

	if (ifmsh->sync_ops)
		ifmsh->sync_ops->rx_bcn_presp(sdata,
			stype, mgmt, &elems, rx_status);
1194

1195 1196
	if (ifmsh->csa_role != IEEE80211_MESH_CSA_ROLE_INIT &&
	    !sdata->vif.csa_active)
1197
		ieee80211_mesh_process_chnswitch(sdata, &elems, true);
1198 1199
}

1200 1201 1202 1203 1204
int ieee80211_mesh_finish_csa(struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	struct mesh_csa_settings *tmp_csa_settings;
	int ret = 0;
1205
	int changed = 0;
1206 1207

	/* Reset the TTL value and Initiator flag */
1208
	ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
1209 1210 1211 1212
	ifmsh->chsw_ttl = 0;

	/* Remove the CSA and MCSP elements from the beacon */
	tmp_csa_settings = rcu_dereference(ifmsh->csa);
M
Monam Agarwal 已提交
1213
	RCU_INIT_POINTER(ifmsh->csa, NULL);
1214 1215
	if (tmp_csa_settings)
		kfree_rcu(tmp_csa_settings, rcu_head);
1216 1217 1218 1219
	ret = ieee80211_mesh_rebuild_beacon(sdata);
	if (ret)
		return -EINVAL;

1220
	changed |= BSS_CHANGED_BEACON;
1221 1222 1223

	mcsa_dbg(sdata, "complete switching to center freq %d MHz",
		 sdata->vif.bss_conf.chandef.chan->center_freq);
1224
	return changed;
1225 1226 1227
}

int ieee80211_mesh_csa_beacon(struct ieee80211_sub_if_data *sdata,
1228
			      struct cfg80211_csa_settings *csa_settings)
1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	struct mesh_csa_settings *tmp_csa_settings;
	int ret = 0;

	tmp_csa_settings = kmalloc(sizeof(*tmp_csa_settings),
				   GFP_ATOMIC);
	if (!tmp_csa_settings)
		return -ENOMEM;

	memcpy(&tmp_csa_settings->settings, csa_settings,
	       sizeof(struct cfg80211_csa_settings));

	rcu_assign_pointer(ifmsh->csa, tmp_csa_settings);

	ret = ieee80211_mesh_rebuild_beacon(sdata);
	if (ret) {
		tmp_csa_settings = rcu_dereference(ifmsh->csa);
M
Monam Agarwal 已提交
1247
		RCU_INIT_POINTER(ifmsh->csa, NULL);
1248 1249 1250 1251
		kfree_rcu(tmp_csa_settings, rcu_head);
		return ret;
	}

1252
	return BSS_CHANGED_BEACON;
1253 1254
}

1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267
static int mesh_fwd_csa_frame(struct ieee80211_sub_if_data *sdata,
			       struct ieee80211_mgmt *mgmt, size_t len)
{
	struct ieee80211_mgmt *mgmt_fwd;
	struct sk_buff *skb;
	struct ieee80211_local *local = sdata->local;
	u8 *pos = mgmt->u.action.u.chan_switch.variable;
	size_t offset_ttl;

	skb = dev_alloc_skb(local->tx_headroom + len);
	if (!skb)
		return -ENOMEM;
	skb_reserve(skb, local->tx_headroom);
1268
	mgmt_fwd = skb_put(skb, len);
1269 1270

	/* offset_ttl is based on whether the secondary channel
1271
	 * offset is available or not. Subtract 1 from the mesh TTL
1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292
	 * and disable the initiator flag before forwarding.
	 */
	offset_ttl = (len < 42) ? 7 : 10;
	*(pos + offset_ttl) -= 1;
	*(pos + offset_ttl + 1) &= ~WLAN_EID_CHAN_SWITCH_PARAM_INITIATOR;

	memcpy(mgmt_fwd, mgmt, len);
	eth_broadcast_addr(mgmt_fwd->da);
	memcpy(mgmt_fwd->sa, sdata->vif.addr, ETH_ALEN);
	memcpy(mgmt_fwd->bssid, sdata->vif.addr, ETH_ALEN);

	ieee80211_tx_skb(sdata, skb);
	return 0;
}

static void mesh_rx_csa_frame(struct ieee80211_sub_if_data *sdata,
			      struct ieee80211_mgmt *mgmt, size_t len)
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	struct ieee802_11_elems elems;
	u16 pre_value;
1293
	bool fwd_csa = true;
1294
	size_t baselen;
1295
	u8 *pos;
1296 1297 1298 1299 1300 1301 1302 1303

	if (mgmt->u.action.u.measurement.action_code !=
	    WLAN_ACTION_SPCT_CHL_SWITCH)
		return;

	pos = mgmt->u.action.u.chan_switch.variable;
	baselen = offsetof(struct ieee80211_mgmt,
			   u.action.u.chan_switch.variable);
1304
	ieee802_11_parse_elems(pos, len - baselen, true, &elems);
1305

1306 1307
	ifmsh->chsw_ttl = elems.mesh_chansw_params_ie->mesh_ttl;
	if (!--ifmsh->chsw_ttl)
1308 1309 1310 1311 1312 1313 1314 1315
		fwd_csa = false;

	pre_value = le16_to_cpu(elems.mesh_chansw_params_ie->mesh_pre_value);
	if (ifmsh->pre_value >= pre_value)
		return;

	ifmsh->pre_value = pre_value;

1316 1317
	if (!sdata->vif.csa_active &&
	    !ieee80211_mesh_process_chnswitch(sdata, &elems, false)) {
1318 1319 1320 1321
		mcsa_dbg(sdata, "Failed to process CSA action frame");
		return;
	}

1322 1323 1324 1325 1326 1327 1328
	/* forward or re-broadcast the CSA frame */
	if (fwd_csa) {
		if (mesh_fwd_csa_frame(sdata, mgmt, len) < 0)
			mcsa_dbg(sdata, "Failed to forward the CSA frame");
	}
}

1329 1330 1331 1332 1333 1334
static void ieee80211_mesh_rx_mgmt_action(struct ieee80211_sub_if_data *sdata,
					  struct ieee80211_mgmt *mgmt,
					  size_t len,
					  struct ieee80211_rx_status *rx_status)
{
	switch (mgmt->u.action.category) {
1335 1336 1337 1338 1339 1340 1341 1342
	case WLAN_CATEGORY_SELF_PROTECTED:
		switch (mgmt->u.action.u.self_prot.action_code) {
		case WLAN_SP_MESH_PEERING_OPEN:
		case WLAN_SP_MESH_PEERING_CLOSE:
		case WLAN_SP_MESH_PEERING_CONFIRM:
			mesh_rx_plink_frame(sdata, mgmt, len, rx_status);
			break;
		}
1343
		break;
1344 1345 1346
	case WLAN_CATEGORY_MESH_ACTION:
		if (mesh_action_is_path_sel(mgmt))
			mesh_rx_path_sel_frame(sdata, mgmt, len);
1347
		break;
1348 1349 1350
	case WLAN_CATEGORY_SPECTRUM_MGMT:
		mesh_rx_csa_frame(sdata, mgmt, len);
		break;
1351 1352 1353
	}
}

1354 1355
void ieee80211_mesh_rx_queued_mgmt(struct ieee80211_sub_if_data *sdata,
				   struct sk_buff *skb)
1356 1357 1358 1359 1360
{
	struct ieee80211_rx_status *rx_status;
	struct ieee80211_mgmt *mgmt;
	u16 stype;

T
Thomas Pedersen 已提交
1361 1362 1363
	sdata_lock(sdata);

	/* mesh already went down */
1364
	if (!sdata->u.mesh.mesh_id_len)
T
Thomas Pedersen 已提交
1365 1366
		goto out;

1367
	rx_status = IEEE80211_SKB_RXCB(skb);
1368 1369 1370 1371 1372 1373 1374 1375 1376
	mgmt = (struct ieee80211_mgmt *) skb->data;
	stype = le16_to_cpu(mgmt->frame_control) & IEEE80211_FCTL_STYPE;

	switch (stype) {
	case IEEE80211_STYPE_PROBE_RESP:
	case IEEE80211_STYPE_BEACON:
		ieee80211_mesh_rx_bcn_presp(sdata, stype, mgmt, skb->len,
					    rx_status);
		break;
1377 1378 1379
	case IEEE80211_STYPE_PROBE_REQ:
		ieee80211_mesh_rx_probe_req(sdata, mgmt, skb->len);
		break;
1380 1381 1382 1383
	case IEEE80211_STYPE_ACTION:
		ieee80211_mesh_rx_mgmt_action(sdata, mgmt, skb->len, rx_status);
		break;
	}
T
Thomas Pedersen 已提交
1384 1385
out:
	sdata_unlock(sdata);
1386 1387
}

1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409
static void mesh_bss_info_changed(struct ieee80211_sub_if_data *sdata)
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
	u32 bit, changed = 0;

	for_each_set_bit(bit, &ifmsh->mbss_changed,
			 sizeof(changed) * BITS_PER_BYTE) {
		clear_bit(bit, &ifmsh->mbss_changed);
		changed |= BIT(bit);
	}

	if (sdata->vif.bss_conf.enable_beacon &&
	    (changed & (BSS_CHANGED_BEACON |
			BSS_CHANGED_HT |
			BSS_CHANGED_BASIC_RATES |
			BSS_CHANGED_BEACON_INT)))
		if (ieee80211_mesh_rebuild_beacon(sdata))
			return;

	ieee80211_bss_info_change_notify(sdata, changed);
}

1410
void ieee80211_mesh_work(struct ieee80211_sub_if_data *sdata)
1411 1412 1413
{
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;

T
Thomas Pedersen 已提交
1414 1415 1416
	sdata_lock(sdata);

	/* mesh already went down */
1417
	if (!sdata->u.mesh.mesh_id_len)
T
Thomas Pedersen 已提交
1418 1419
		goto out;

1420 1421 1422 1423 1424
	if (ifmsh->preq_queue_len &&
	    time_after(jiffies,
		       ifmsh->last_preq + msecs_to_jiffies(ifmsh->mshcfg.dot11MeshHWMPpreqMinInterval)))
		mesh_path_start_discovery(sdata);

1425
	if (test_and_clear_bit(MESH_WORK_HOUSEKEEPING, &ifmsh->wrkq_flags))
J
Johannes Berg 已提交
1426
		ieee80211_mesh_housekeeping(sdata);
1427 1428 1429

	if (test_and_clear_bit(MESH_WORK_ROOT, &ifmsh->wrkq_flags))
		ieee80211_mesh_rootpath(sdata);
1430 1431

	if (test_and_clear_bit(MESH_WORK_DRIFT_ADJUST, &ifmsh->wrkq_flags))
1432
		mesh_sync_adjust_tsf(sdata);
T
Thomas Pedersen 已提交
1433

1434 1435
	if (test_and_clear_bit(MESH_WORK_MBSS_CHANGED, &ifmsh->wrkq_flags))
		mesh_bss_info_changed(sdata);
T
Thomas Pedersen 已提交
1436 1437
out:
	sdata_unlock(sdata);
1438 1439 1440
}


J
Johannes Berg 已提交
1441 1442
void ieee80211_mesh_init_sdata(struct ieee80211_sub_if_data *sdata)
{
1443
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
1444
	static u8 zero_addr[ETH_ALEN] = {};
1445

1446 1447
	timer_setup(&ifmsh->housekeeping_timer,
		    ieee80211_mesh_housekeeping_timer, 0);
1448 1449 1450

	ifmsh->accepting_plinks = true;
	atomic_set(&ifmsh->mpaths, 0);
1451
	mesh_rmc_init(sdata);
1452
	ifmsh->last_preq = jiffies;
1453
	ifmsh->next_perr = jiffies;
1454
	ifmsh->csa_role = IEEE80211_MESH_CSA_ROLE_NONE;
J
Johannes Berg 已提交
1455 1456 1457
	/* Allocate all mesh structures when creating the first mesh interface. */
	if (!mesh_allocated)
		ieee80211s_init();
1458 1459 1460

	mesh_pathtbl_init(sdata);

1461 1462 1463
	timer_setup(&ifmsh->mesh_path_timer, ieee80211_mesh_path_timer, 0);
	timer_setup(&ifmsh->mesh_path_root_timer,
		    ieee80211_mesh_path_root_timer, 0);
1464
	INIT_LIST_HEAD(&ifmsh->preq_queue.list);
M
Marco Porsch 已提交
1465
	skb_queue_head_init(&ifmsh->ps.bc_buf);
1466
	spin_lock_init(&ifmsh->mesh_preq_queue_lock);
1467
	spin_lock_init(&ifmsh->sync_offset_lock);
T
Thomas Pedersen 已提交
1468
	RCU_INIT_POINTER(ifmsh->beacon, NULL);
1469 1470

	sdata->vif.bss_conf.bssid = zero_addr;
1471
}
1472 1473 1474 1475 1476 1477

void ieee80211_mesh_teardown_sdata(struct ieee80211_sub_if_data *sdata)
{
	mesh_rmc_free(sdata);
	mesh_pathtbl_unregister(sdata);
}