nl80211.c 115.9 KB
Newer Older
1 2 3
/*
 * This is the new netlink-based wireless configuration interface.
 *
4
 * Copyright 2006-2009	Johannes Berg <johannes@sipsolutions.net>
5 6 7 8 9 10 11 12 13 14 15
 */

#include <linux/if.h>
#include <linux/module.h>
#include <linux/err.h>
#include <linux/list.h>
#include <linux/if_ether.h>
#include <linux/ieee80211.h>
#include <linux/nl80211.h>
#include <linux/rtnetlink.h>
#include <linux/netlink.h>
16
#include <linux/etherdevice.h>
17
#include <net/net_namespace.h>
18 19
#include <net/genetlink.h>
#include <net/cfg80211.h>
20
#include <net/sock.h>
21 22
#include "core.h"
#include "nl80211.h"
23
#include "reg.h"
24 25 26 27 28 29 30 31

/* the netlink family */
static struct genl_family nl80211_fam = {
	.id = GENL_ID_GENERATE,	/* don't bother with a hardcoded ID */
	.name = "nl80211",	/* have users key off the name instead */
	.hdrsize = 0,		/* no private header */
	.version = 1,		/* no particular meaning now */
	.maxattr = NL80211_ATTR_MAX,
32
	.netnsok = true,
33 34
};

35
/* internal helper: get rdev and dev */
36
static int get_rdev_dev_by_info_ifindex(struct genl_info *info,
37
				       struct cfg80211_registered_device **rdev,
38 39
				       struct net_device **dev)
{
40
	struct nlattr **attrs = info->attrs;
41 42
	int ifindex;

J
Johannes Berg 已提交
43
	if (!attrs[NL80211_ATTR_IFINDEX])
44 45
		return -EINVAL;

J
Johannes Berg 已提交
46
	ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]);
47
	*dev = dev_get_by_index(genl_info_net(info), ifindex);
48 49 50
	if (!*dev)
		return -ENODEV;

51
	*rdev = cfg80211_get_dev_from_ifindex(genl_info_net(info), ifindex);
52
	if (IS_ERR(*rdev)) {
53
		dev_put(*dev);
54
		return PTR_ERR(*rdev);
55 56 57 58 59 60 61 62 63
	}

	return 0;
}

/* policy for the attributes */
static struct nla_policy nl80211_policy[NL80211_ATTR_MAX+1] __read_mostly = {
	[NL80211_ATTR_WIPHY] = { .type = NLA_U32 },
	[NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING,
64
				      .len = 20-1 },
65
	[NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED },
66
	[NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 },
S
Sujith 已提交
67
	[NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 },
68 69 70 71
	[NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 },
	[NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 },
	[NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 },
	[NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 },
72 73 74 75

	[NL80211_ATTR_IFTYPE] = { .type = NLA_U32 },
	[NL80211_ATTR_IFINDEX] = { .type = NLA_U32 },
	[NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 },
76 77

	[NL80211_ATTR_MAC] = { .type = NLA_BINARY, .len = ETH_ALEN },
78
	[NL80211_ATTR_PREV_BSSID] = { .type = NLA_BINARY, .len = ETH_ALEN },
79

80
	[NL80211_ATTR_KEY] = { .type = NLA_NESTED, },
81 82 83 84 85
	[NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY,
				    .len = WLAN_MAX_KEY_LEN },
	[NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 },
	[NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 },
	[NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG },
86
	[NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
87 88 89 90 91 92 93

	[NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 },
	[NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 },
	[NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY,
				       .len = IEEE80211_MAX_DATA_LEN },
	[NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY,
				       .len = IEEE80211_MAX_DATA_LEN },
94 95 96 97 98
	[NL80211_ATTR_STA_AID] = { .type = NLA_U16 },
	[NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED },
	[NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 },
	[NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY,
					       .len = NL80211_MAX_SUPP_RATES },
99
	[NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 },
100
	[NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 },
J
Johannes Berg 已提交
101
	[NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ },
102 103 104
	[NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY,
				.len = IEEE80211_MAX_MESH_ID_LEN },
	[NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 },
105

106 107 108
	[NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 },
	[NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED },

109 110 111
	[NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 },
	[NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 },
	[NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 },
112 113
	[NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY,
					   .len = NL80211_MAX_SUPP_RATES },
114

115 116
	[NL80211_ATTR_MESH_PARAMS] = { .type = NLA_NESTED },

117 118
	[NL80211_ATTR_HT_CAPABILITY] = { .type = NLA_BINARY,
					 .len = NL80211_HT_CAPABILITY_LEN },
119 120 121 122

	[NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 },
	[NL80211_ATTR_IE] = { .type = NLA_BINARY,
			      .len = IEEE80211_MAX_DATA_LEN },
123 124
	[NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED },
	[NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED },
125 126 127 128 129

	[NL80211_ATTR_SSID] = { .type = NLA_BINARY,
				.len = IEEE80211_MAX_SSID_LEN },
	[NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 },
	[NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 },
J
Johannes Berg 已提交
130
	[NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG },
131
	[NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG },
132
	[NL80211_ATTR_USE_MFP] = { .type = NLA_U32 },
133 134 135
	[NL80211_ATTR_STA_FLAGS2] = {
		.len = sizeof(struct nl80211_sta_flag_update),
	},
136
	[NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG },
S
Samuel Ortiz 已提交
137 138 139
	[NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG },
	[NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 },
	[NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 },
140
	[NL80211_ATTR_PID] = { .type = NLA_U32 },
141
	[NL80211_ATTR_4ADDR] = { .type = NLA_U8 },
142 143
};

144 145 146
/* policy for the attributes */
static struct nla_policy
nl80211_key_policy[NL80211_KEY_MAX + 1] __read_mostly = {
J
Johannes Berg 已提交
147
	[NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN },
148 149 150 151 152 153 154
	[NL80211_KEY_IDX] = { .type = NLA_U8 },
	[NL80211_KEY_CIPHER] = { .type = NLA_U32 },
	[NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 8 },
	[NL80211_KEY_DEFAULT] = { .type = NLA_FLAG },
	[NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG },
};

155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174
/* ifidx get helper */
static int nl80211_get_ifidx(struct netlink_callback *cb)
{
	int res;

	res = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize,
			  nl80211_fam.attrbuf, nl80211_fam.maxattr,
			  nl80211_policy);
	if (res)
		return res;

	if (!nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX])
		return -EINVAL;

	res = nla_get_u32(nl80211_fam.attrbuf[NL80211_ATTR_IFINDEX]);
	if (!res)
		return -EINVAL;
	return res;
}

175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204
/* IE validation */
static bool is_valid_ie_attr(const struct nlattr *attr)
{
	const u8 *pos;
	int len;

	if (!attr)
		return true;

	pos = nla_data(attr);
	len = nla_len(attr);

	while (len) {
		u8 elemlen;

		if (len < 2)
			return false;
		len -= 2;

		elemlen = pos[1];
		if (elemlen > len)
			return false;

		len -= elemlen;
		pos += 2 + elemlen;
	}

	return true;
}

205 206 207 208 209 210 211 212
/* message building helper */
static inline void *nl80211hdr_put(struct sk_buff *skb, u32 pid, u32 seq,
				   int flags, u8 cmd)
{
	/* since there is no private header just add the generic one */
	return genlmsg_put(skb, pid, seq, &nl80211_fam, flags, cmd);
}

213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236
static int nl80211_msg_put_channel(struct sk_buff *msg,
				   struct ieee80211_channel *chan)
{
	NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_FREQ,
		    chan->center_freq);

	if (chan->flags & IEEE80211_CHAN_DISABLED)
		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_DISABLED);
	if (chan->flags & IEEE80211_CHAN_PASSIVE_SCAN)
		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_PASSIVE_SCAN);
	if (chan->flags & IEEE80211_CHAN_NO_IBSS)
		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_NO_IBSS);
	if (chan->flags & IEEE80211_CHAN_RADAR)
		NLA_PUT_FLAG(msg, NL80211_FREQUENCY_ATTR_RADAR);

	NLA_PUT_U32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER,
		    DBM_TO_MBM(chan->max_power));

	return 0;

 nla_put_failure:
	return -ENOBUFS;
}

237 238
/* netlink command implementations */

239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332
struct key_parse {
	struct key_params p;
	int idx;
	bool def, defmgmt;
};

static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k)
{
	struct nlattr *tb[NL80211_KEY_MAX + 1];
	int err = nla_parse_nested(tb, NL80211_KEY_MAX, key,
				   nl80211_key_policy);
	if (err)
		return err;

	k->def = !!tb[NL80211_KEY_DEFAULT];
	k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT];

	if (tb[NL80211_KEY_IDX])
		k->idx = nla_get_u8(tb[NL80211_KEY_IDX]);

	if (tb[NL80211_KEY_DATA]) {
		k->p.key = nla_data(tb[NL80211_KEY_DATA]);
		k->p.key_len = nla_len(tb[NL80211_KEY_DATA]);
	}

	if (tb[NL80211_KEY_SEQ]) {
		k->p.seq = nla_data(tb[NL80211_KEY_SEQ]);
		k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]);
	}

	if (tb[NL80211_KEY_CIPHER])
		k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]);

	return 0;
}

static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k)
{
	if (info->attrs[NL80211_ATTR_KEY_DATA]) {
		k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]);
		k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]);
	}

	if (info->attrs[NL80211_ATTR_KEY_SEQ]) {
		k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]);
		k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]);
	}

	if (info->attrs[NL80211_ATTR_KEY_IDX])
		k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);

	if (info->attrs[NL80211_ATTR_KEY_CIPHER])
		k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]);

	k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT];
	k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT];

	return 0;
}

static int nl80211_parse_key(struct genl_info *info, struct key_parse *k)
{
	int err;

	memset(k, 0, sizeof(*k));
	k->idx = -1;

	if (info->attrs[NL80211_ATTR_KEY])
		err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k);
	else
		err = nl80211_parse_key_old(info, k);

	if (err)
		return err;

	if (k->def && k->defmgmt)
		return -EINVAL;

	if (k->idx != -1) {
		if (k->defmgmt) {
			if (k->idx < 4 || k->idx > 5)
				return -EINVAL;
		} else if (k->def) {
			if (k->idx < 0 || k->idx > 3)
				return -EINVAL;
		} else {
			if (k->idx < 0 || k->idx > 5)
				return -EINVAL;
		}
	}

	return 0;
}

J
Johannes Berg 已提交
333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409
static struct cfg80211_cached_keys *
nl80211_parse_connkeys(struct cfg80211_registered_device *rdev,
		       struct nlattr *keys)
{
	struct key_parse parse;
	struct nlattr *key;
	struct cfg80211_cached_keys *result;
	int rem, err, def = 0;

	result = kzalloc(sizeof(*result), GFP_KERNEL);
	if (!result)
		return ERR_PTR(-ENOMEM);

	result->def = -1;
	result->defmgmt = -1;

	nla_for_each_nested(key, keys, rem) {
		memset(&parse, 0, sizeof(parse));
		parse.idx = -1;

		err = nl80211_parse_key_new(key, &parse);
		if (err)
			goto error;
		err = -EINVAL;
		if (!parse.p.key)
			goto error;
		if (parse.idx < 0 || parse.idx > 4)
			goto error;
		if (parse.def) {
			if (def)
				goto error;
			def = 1;
			result->def = parse.idx;
		} else if (parse.defmgmt)
			goto error;
		err = cfg80211_validate_key_settings(rdev, &parse.p,
						     parse.idx, NULL);
		if (err)
			goto error;
		result->params[parse.idx].cipher = parse.p.cipher;
		result->params[parse.idx].key_len = parse.p.key_len;
		result->params[parse.idx].key = result->data[parse.idx];
		memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len);
	}

	return result;
 error:
	kfree(result);
	return ERR_PTR(err);
}

static int nl80211_key_allowed(struct wireless_dev *wdev)
{
	ASSERT_WDEV_LOCK(wdev);

	if (!netif_running(wdev->netdev))
		return -ENETDOWN;

	switch (wdev->iftype) {
	case NL80211_IFTYPE_AP:
	case NL80211_IFTYPE_AP_VLAN:
		break;
	case NL80211_IFTYPE_ADHOC:
		if (!wdev->current_bss)
			return -ENOLINK;
		break;
	case NL80211_IFTYPE_STATION:
		if (wdev->sme_state != CFG80211_SME_CONNECTED)
			return -ENOLINK;
		break;
	default:
		return -EINVAL;
	}

	return 0;
}

410 411 412 413
static int nl80211_send_wiphy(struct sk_buff *msg, u32 pid, u32 seq, int flags,
			      struct cfg80211_registered_device *dev)
{
	void *hdr;
414 415 416
	struct nlattr *nl_bands, *nl_band;
	struct nlattr *nl_freqs, *nl_freq;
	struct nlattr *nl_rates, *nl_rate;
417
	struct nlattr *nl_modes;
418
	struct nlattr *nl_cmds;
419 420 421 422
	enum ieee80211_band band;
	struct ieee80211_channel *chan;
	struct ieee80211_rate *rate;
	int i;
423
	u16 ifmodes = dev->wiphy.interface_modes;
424 425 426 427 428

	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_WIPHY);
	if (!hdr)
		return -1;

429
	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, dev->wiphy_idx);
430
	NLA_PUT_STRING(msg, NL80211_ATTR_WIPHY_NAME, wiphy_name(&dev->wiphy));
431

432 433 434
	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
		    cfg80211_rdev_list_generation);

435 436 437 438 439 440 441 442 443
	NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT,
		   dev->wiphy.retry_short);
	NLA_PUT_U8(msg, NL80211_ATTR_WIPHY_RETRY_LONG,
		   dev->wiphy.retry_long);
	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD,
		    dev->wiphy.frag_threshold);
	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD,
		    dev->wiphy.rts_threshold);

444 445
	NLA_PUT_U8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS,
		   dev->wiphy.max_scan_ssids);
446 447
	NLA_PUT_U16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN,
		    dev->wiphy.max_scan_ie_len);
448

449 450 451 452
	NLA_PUT(msg, NL80211_ATTR_CIPHER_SUITES,
		sizeof(u32) * dev->wiphy.n_cipher_suites,
		dev->wiphy.cipher_suites);

453 454 455 456 457 458 459 460 461 462 463 464 465 466
	nl_modes = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_IFTYPES);
	if (!nl_modes)
		goto nla_put_failure;

	i = 0;
	while (ifmodes) {
		if (ifmodes & 1)
			NLA_PUT_FLAG(msg, i);
		ifmodes >>= 1;
		i++;
	}

	nla_nest_end(msg, nl_modes);

467 468 469 470 471 472 473 474 475 476 477 478
	nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS);
	if (!nl_bands)
		goto nla_put_failure;

	for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
		if (!dev->wiphy.bands[band])
			continue;

		nl_band = nla_nest_start(msg, band);
		if (!nl_band)
			goto nla_put_failure;

J
Johannes Berg 已提交
479 480 481 482 483 484 485 486 487 488 489 490 491
		/* add HT info */
		if (dev->wiphy.bands[band]->ht_cap.ht_supported) {
			NLA_PUT(msg, NL80211_BAND_ATTR_HT_MCS_SET,
				sizeof(dev->wiphy.bands[band]->ht_cap.mcs),
				&dev->wiphy.bands[band]->ht_cap.mcs);
			NLA_PUT_U16(msg, NL80211_BAND_ATTR_HT_CAPA,
				dev->wiphy.bands[band]->ht_cap.cap);
			NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR,
				dev->wiphy.bands[band]->ht_cap.ampdu_factor);
			NLA_PUT_U8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY,
				dev->wiphy.bands[band]->ht_cap.ampdu_density);
		}

492 493 494 495 496 497 498 499 500 501 502
		/* add frequencies */
		nl_freqs = nla_nest_start(msg, NL80211_BAND_ATTR_FREQS);
		if (!nl_freqs)
			goto nla_put_failure;

		for (i = 0; i < dev->wiphy.bands[band]->n_channels; i++) {
			nl_freq = nla_nest_start(msg, i);
			if (!nl_freq)
				goto nla_put_failure;

			chan = &dev->wiphy.bands[band]->channels[i];
503 504 505

			if (nl80211_msg_put_channel(msg, chan))
				goto nla_put_failure;
506

507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537
			nla_nest_end(msg, nl_freq);
		}

		nla_nest_end(msg, nl_freqs);

		/* add bitrates */
		nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES);
		if (!nl_rates)
			goto nla_put_failure;

		for (i = 0; i < dev->wiphy.bands[band]->n_bitrates; i++) {
			nl_rate = nla_nest_start(msg, i);
			if (!nl_rate)
				goto nla_put_failure;

			rate = &dev->wiphy.bands[band]->bitrates[i];
			NLA_PUT_U32(msg, NL80211_BITRATE_ATTR_RATE,
				    rate->bitrate);
			if (rate->flags & IEEE80211_RATE_SHORT_PREAMBLE)
				NLA_PUT_FLAG(msg,
					NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE);

			nla_nest_end(msg, nl_rate);
		}

		nla_nest_end(msg, nl_rates);

		nla_nest_end(msg, nl_band);
	}
	nla_nest_end(msg, nl_bands);

538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558
	nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS);
	if (!nl_cmds)
		goto nla_put_failure;

	i = 0;
#define CMD(op, n)						\
	 do {							\
		if (dev->ops->op) {				\
			i++;					\
			NLA_PUT_U32(msg, i, NL80211_CMD_ ## n);	\
		}						\
	} while (0)

	CMD(add_virtual_intf, NEW_INTERFACE);
	CMD(change_virtual_intf, SET_INTERFACE);
	CMD(add_key, NEW_KEY);
	CMD(add_beacon, NEW_BEACON);
	CMD(add_station, NEW_STATION);
	CMD(add_mpath, NEW_MPATH);
	CMD(set_mesh_params, SET_MESH_PARAMS);
	CMD(change_bss, SET_BSS);
559 560 561 562
	CMD(auth, AUTHENTICATE);
	CMD(assoc, ASSOCIATE);
	CMD(deauth, DEAUTHENTICATE);
	CMD(disassoc, DISASSOCIATE);
J
Johannes Berg 已提交
563
	CMD(join_ibss, JOIN_IBSS);
J
Johannes Berg 已提交
564
	if (dev->wiphy.flags & WIPHY_FLAG_NETNS_OK) {
565 566 567
		i++;
		NLA_PUT_U32(msg, i, NL80211_CMD_SET_WIPHY_NETNS);
	}
568 569

#undef CMD
S
Samuel Ortiz 已提交
570

571
	if (dev->ops->connect || dev->ops->auth) {
S
Samuel Ortiz 已提交
572 573 574 575
		i++;
		NLA_PUT_U32(msg, i, NL80211_CMD_CONNECT);
	}

576
	if (dev->ops->disconnect || dev->ops->deauth) {
S
Samuel Ortiz 已提交
577 578 579 580
		i++;
		NLA_PUT_U32(msg, i, NL80211_CMD_DISCONNECT);
	}

581 582
	nla_nest_end(msg, nl_cmds);

583 584 585
	return genlmsg_end(msg, hdr);

 nla_put_failure:
586 587
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
588 589 590 591 592 593 594 595
}

static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb)
{
	int idx = 0;
	int start = cb->args[0];
	struct cfg80211_registered_device *dev;

596
	mutex_lock(&cfg80211_mutex);
597
	list_for_each_entry(dev, &cfg80211_rdev_list, list) {
598 599
		if (!net_eq(wiphy_net(&dev->wiphy), sock_net(skb->sk)))
			continue;
600
		if (++idx <= start)
601 602 603
			continue;
		if (nl80211_send_wiphy(skb, NETLINK_CB(cb->skb).pid,
				       cb->nlh->nlmsg_seq, NLM_F_MULTI,
604 605
				       dev) < 0) {
			idx--;
606
			break;
607
		}
608
	}
609
	mutex_unlock(&cfg80211_mutex);
610 611 612 613 614 615 616 617 618 619 620 621 622 623 624

	cb->args[0] = idx;

	return skb->len;
}

static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info)
{
	struct sk_buff *msg;
	struct cfg80211_registered_device *dev;

	dev = cfg80211_get_dev_from_info(info);
	if (IS_ERR(dev))
		return PTR_ERR(dev);

625
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
626 627 628 629 630 631
	if (!msg)
		goto out_err;

	if (nl80211_send_wiphy(msg, info->snd_pid, info->snd_seq, 0, dev) < 0)
		goto out_free;

632
	cfg80211_unlock_rdev(dev);
633

J
Johannes Berg 已提交
634
	return genlmsg_reply(msg, info);
635 636 637 638

 out_free:
	nlmsg_free(msg);
 out_err:
639
	cfg80211_unlock_rdev(dev);
640 641 642
	return -ENOBUFS;
}

643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667
static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = {
	[NL80211_TXQ_ATTR_QUEUE]		= { .type = NLA_U8 },
	[NL80211_TXQ_ATTR_TXOP]			= { .type = NLA_U16 },
	[NL80211_TXQ_ATTR_CWMIN]		= { .type = NLA_U16 },
	[NL80211_TXQ_ATTR_CWMAX]		= { .type = NLA_U16 },
	[NL80211_TXQ_ATTR_AIFS]			= { .type = NLA_U8 },
};

static int parse_txq_params(struct nlattr *tb[],
			    struct ieee80211_txq_params *txq_params)
{
	if (!tb[NL80211_TXQ_ATTR_QUEUE] || !tb[NL80211_TXQ_ATTR_TXOP] ||
	    !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] ||
	    !tb[NL80211_TXQ_ATTR_AIFS])
		return -EINVAL;

	txq_params->queue = nla_get_u8(tb[NL80211_TXQ_ATTR_QUEUE]);
	txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]);
	txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]);
	txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]);
	txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]);

	return 0;
}

668 669 670
static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info)
{
	struct cfg80211_registered_device *rdev;
671 672
	int result = 0, rem_txq_params = 0;
	struct nlattr *nl_txq_params;
673 674 675
	u32 changed;
	u8 retry_short = 0, retry_long = 0;
	u32 frag_threshold = 0, rts_threshold = 0;
676

677
	rtnl_lock();
678

679 680
	mutex_lock(&cfg80211_mutex);

681
	rdev = __cfg80211_rdev_from_info(info);
682
	if (IS_ERR(rdev)) {
683
		mutex_unlock(&cfg80211_mutex);
684 685 686 687 688 689 690
		result = PTR_ERR(rdev);
		goto unlock;
	}

	mutex_lock(&rdev->mtx);

	if (info->attrs[NL80211_ATTR_WIPHY_NAME])
691 692
		result = cfg80211_dev_rename(
			rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME]));
693 694 695 696 697

	mutex_unlock(&cfg80211_mutex);

	if (result)
		goto bad_res;
698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724

	if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) {
		struct ieee80211_txq_params txq_params;
		struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1];

		if (!rdev->ops->set_txq_params) {
			result = -EOPNOTSUPP;
			goto bad_res;
		}

		nla_for_each_nested(nl_txq_params,
				    info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS],
				    rem_txq_params) {
			nla_parse(tb, NL80211_TXQ_ATTR_MAX,
				  nla_data(nl_txq_params),
				  nla_len(nl_txq_params),
				  txq_params_policy);
			result = parse_txq_params(tb, &txq_params);
			if (result)
				goto bad_res;

			result = rdev->ops->set_txq_params(&rdev->wiphy,
							   &txq_params);
			if (result)
				goto bad_res;
		}
	}
725

726
	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
S
Sujith 已提交
727
		enum nl80211_channel_type channel_type = NL80211_CHAN_NO_HT;
728
		u32 freq;
729

730 731
		result = -EINVAL;

S
Sujith 已提交
732 733 734 735 736 737 738
		if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) {
			channel_type = nla_get_u32(info->attrs[
					   NL80211_ATTR_WIPHY_CHANNEL_TYPE]);
			if (channel_type != NL80211_CHAN_NO_HT &&
			    channel_type != NL80211_CHAN_HT20 &&
			    channel_type != NL80211_CHAN_HT40PLUS &&
			    channel_type != NL80211_CHAN_HT40MINUS)
739 740 741 742
				goto bad_res;
		}

		freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]);
743

744
		mutex_lock(&rdev->devlist_mtx);
745
		result = rdev_set_freq(rdev, NULL, freq, channel_type);
746
		mutex_unlock(&rdev->devlist_mtx);
747 748 749 750
		if (result)
			goto bad_res;
	}

751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828
	changed = 0;

	if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) {
		retry_short = nla_get_u8(
			info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]);
		if (retry_short == 0) {
			result = -EINVAL;
			goto bad_res;
		}
		changed |= WIPHY_PARAM_RETRY_SHORT;
	}

	if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) {
		retry_long = nla_get_u8(
			info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]);
		if (retry_long == 0) {
			result = -EINVAL;
			goto bad_res;
		}
		changed |= WIPHY_PARAM_RETRY_LONG;
	}

	if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) {
		frag_threshold = nla_get_u32(
			info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]);
		if (frag_threshold < 256) {
			result = -EINVAL;
			goto bad_res;
		}
		if (frag_threshold != (u32) -1) {
			/*
			 * Fragments (apart from the last one) are required to
			 * have even length. Make the fragmentation code
			 * simpler by stripping LSB should someone try to use
			 * odd threshold value.
			 */
			frag_threshold &= ~0x1;
		}
		changed |= WIPHY_PARAM_FRAG_THRESHOLD;
	}

	if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) {
		rts_threshold = nla_get_u32(
			info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]);
		changed |= WIPHY_PARAM_RTS_THRESHOLD;
	}

	if (changed) {
		u8 old_retry_short, old_retry_long;
		u32 old_frag_threshold, old_rts_threshold;

		if (!rdev->ops->set_wiphy_params) {
			result = -EOPNOTSUPP;
			goto bad_res;
		}

		old_retry_short = rdev->wiphy.retry_short;
		old_retry_long = rdev->wiphy.retry_long;
		old_frag_threshold = rdev->wiphy.frag_threshold;
		old_rts_threshold = rdev->wiphy.rts_threshold;

		if (changed & WIPHY_PARAM_RETRY_SHORT)
			rdev->wiphy.retry_short = retry_short;
		if (changed & WIPHY_PARAM_RETRY_LONG)
			rdev->wiphy.retry_long = retry_long;
		if (changed & WIPHY_PARAM_FRAG_THRESHOLD)
			rdev->wiphy.frag_threshold = frag_threshold;
		if (changed & WIPHY_PARAM_RTS_THRESHOLD)
			rdev->wiphy.rts_threshold = rts_threshold;

		result = rdev->ops->set_wiphy_params(&rdev->wiphy, changed);
		if (result) {
			rdev->wiphy.retry_short = old_retry_short;
			rdev->wiphy.retry_long = old_retry_long;
			rdev->wiphy.frag_threshold = old_frag_threshold;
			rdev->wiphy.rts_threshold = old_rts_threshold;
		}
	}
829

830
 bad_res:
831 832 833
	mutex_unlock(&rdev->mtx);
 unlock:
	rtnl_unlock();
834 835 836 837 838
	return result;
}


static int nl80211_send_iface(struct sk_buff *msg, u32 pid, u32 seq, int flags,
839
			      struct cfg80211_registered_device *rdev,
840 841 842 843 844 845 846 847 848
			      struct net_device *dev)
{
	void *hdr;

	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_INTERFACE);
	if (!hdr)
		return -1;

	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
849
	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
850
	NLA_PUT_STRING(msg, NL80211_ATTR_IFNAME, dev->name);
J
Johannes Berg 已提交
851
	NLA_PUT_U32(msg, NL80211_ATTR_IFTYPE, dev->ieee80211_ptr->iftype);
852 853 854 855 856

	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION,
		    rdev->devlist_generation ^
			(cfg80211_rdev_list_generation << 2));

857 858 859
	return genlmsg_end(msg, hdr);

 nla_put_failure:
860 861
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
862 863 864 865 866 867 868 869
}

static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb)
{
	int wp_idx = 0;
	int if_idx = 0;
	int wp_start = cb->args[0];
	int if_start = cb->args[1];
870
	struct cfg80211_registered_device *rdev;
871 872
	struct wireless_dev *wdev;

873
	mutex_lock(&cfg80211_mutex);
874 875
	list_for_each_entry(rdev, &cfg80211_rdev_list, list) {
		if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk)))
876
			continue;
J
Johannes Berg 已提交
877 878
		if (wp_idx < wp_start) {
			wp_idx++;
879
			continue;
J
Johannes Berg 已提交
880
		}
881 882
		if_idx = 0;

883 884
		mutex_lock(&rdev->devlist_mtx);
		list_for_each_entry(wdev, &rdev->netdev_list, list) {
J
Johannes Berg 已提交
885 886
			if (if_idx < if_start) {
				if_idx++;
887
				continue;
J
Johannes Berg 已提交
888
			}
889 890
			if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).pid,
					       cb->nlh->nlmsg_seq, NLM_F_MULTI,
891 892
					       rdev, wdev->netdev) < 0) {
				mutex_unlock(&rdev->devlist_mtx);
J
Johannes Berg 已提交
893 894 895
				goto out;
			}
			if_idx++;
896
		}
897
		mutex_unlock(&rdev->devlist_mtx);
J
Johannes Berg 已提交
898 899

		wp_idx++;
900
	}
J
Johannes Berg 已提交
901
 out:
902
	mutex_unlock(&cfg80211_mutex);
903 904 905 906 907 908 909 910 911 912 913 914 915 916

	cb->args[0] = wp_idx;
	cb->args[1] = if_idx;

	return skb->len;
}

static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info)
{
	struct sk_buff *msg;
	struct cfg80211_registered_device *dev;
	struct net_device *netdev;
	int err;

917
	err = get_rdev_dev_by_info_ifindex(info, &dev, &netdev);
918 919 920
	if (err)
		return err;

921
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
922 923 924
	if (!msg)
		goto out_err;

925 926
	if (nl80211_send_iface(msg, info->snd_pid, info->snd_seq, 0,
			       dev, netdev) < 0)
927 928 929
		goto out_free;

	dev_put(netdev);
930
	cfg80211_unlock_rdev(dev);
931

J
Johannes Berg 已提交
932
	return genlmsg_reply(msg, info);
933 934 935 936 937

 out_free:
	nlmsg_free(msg);
 out_err:
	dev_put(netdev);
938
	cfg80211_unlock_rdev(dev);
939 940 941
	return -ENOBUFS;
}

942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970
static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = {
	[NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG },
	[NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG },
	[NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG },
	[NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG },
	[NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG },
};

static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags)
{
	struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1];
	int flag;

	*mntrflags = 0;

	if (!nla)
		return -EINVAL;

	if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX,
			     nla, mntr_flags_policy))
		return -EINVAL;

	for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++)
		if (flags[flag])
			*mntrflags |= (1<<flag);

	return 0;
}

971 972
static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info)
{
973
	struct cfg80211_registered_device *rdev;
974
	struct vif_params params;
975
	int err;
J
Johannes Berg 已提交
976
	enum nl80211_iftype otype, ntype;
977
	struct net_device *dev;
978
	u32 _flags, *flags = NULL;
979
	bool change = false;
980

981 982
	memset(&params, 0, sizeof(params));

J
Johannes Berg 已提交
983 984
	rtnl_lock();

985
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
986
	if (err)
J
Johannes Berg 已提交
987 988
		goto unlock_rtnl;

J
Johannes Berg 已提交
989
	otype = ntype = dev->ieee80211_ptr->iftype;
990

991
	if (info->attrs[NL80211_ATTR_IFTYPE]) {
992
		ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
J
Johannes Berg 已提交
993
		if (otype != ntype)
994
			change = true;
J
Johannes Berg 已提交
995
		if (ntype > NL80211_IFTYPE_MAX) {
996
			err = -EINVAL;
997
			goto unlock;
998
		}
999 1000
	}

1001
	if (info->attrs[NL80211_ATTR_MESH_ID]) {
J
Johannes Berg 已提交
1002
		if (ntype != NL80211_IFTYPE_MESH_POINT) {
1003 1004 1005
			err = -EINVAL;
			goto unlock;
		}
1006 1007
		params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
		params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
1008
		change = true;
1009 1010
	}

1011 1012 1013 1014 1015 1016 1017
	if (info->attrs[NL80211_ATTR_4ADDR]) {
		params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);
		change = true;
	} else {
		params.use_4addr = -1;
	}

1018
	if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) {
J
Johannes Berg 已提交
1019
		if (ntype != NL80211_IFTYPE_MONITOR) {
1020 1021 1022 1023 1024
			err = -EINVAL;
			goto unlock;
		}
		err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS],
					  &_flags);
1025 1026 1027 1028 1029
		if (err)
			goto unlock;

		flags = &_flags;
		change = true;
1030
	}
J
Johannes Berg 已提交
1031

1032
	if (change)
1033
		err = cfg80211_change_iface(rdev, dev, ntype, flags, &params);
1034 1035
	else
		err = 0;
J
Johannes Berg 已提交
1036

1037
 unlock:
1038
	dev_put(dev);
1039
	cfg80211_unlock_rdev(rdev);
J
Johannes Berg 已提交
1040 1041
 unlock_rtnl:
	rtnl_unlock();
1042 1043 1044 1045 1046
	return err;
}

static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info)
{
1047
	struct cfg80211_registered_device *rdev;
1048
	struct vif_params params;
1049 1050
	int err;
	enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED;
1051
	u32 flags;
1052

1053 1054
	memset(&params, 0, sizeof(params));

1055 1056 1057 1058 1059 1060 1061 1062 1063
	if (!info->attrs[NL80211_ATTR_IFNAME])
		return -EINVAL;

	if (info->attrs[NL80211_ATTR_IFTYPE]) {
		type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]);
		if (type > NL80211_IFTYPE_MAX)
			return -EINVAL;
	}

J
Johannes Berg 已提交
1064 1065
	rtnl_lock();

1066 1067 1068
	rdev = cfg80211_get_dev_from_info(info);
	if (IS_ERR(rdev)) {
		err = PTR_ERR(rdev);
J
Johannes Berg 已提交
1069 1070
		goto unlock_rtnl;
	}
1071

1072 1073
	if (!rdev->ops->add_virtual_intf ||
	    !(rdev->wiphy.interface_modes & (1 << type))) {
1074 1075 1076 1077
		err = -EOPNOTSUPP;
		goto unlock;
	}

1078 1079 1080 1081 1082 1083
	if (type == NL80211_IFTYPE_MESH_POINT &&
	    info->attrs[NL80211_ATTR_MESH_ID]) {
		params.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]);
		params.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]);
	}

1084 1085 1086
	if (info->attrs[NL80211_ATTR_4ADDR])
		params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]);

1087 1088 1089
	err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ?
				  info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL,
				  &flags);
1090
	err = rdev->ops->add_virtual_intf(&rdev->wiphy,
1091
		nla_data(info->attrs[NL80211_ATTR_IFNAME]),
1092 1093
		type, err ? NULL : &flags, &params);

1094
 unlock:
1095
	cfg80211_unlock_rdev(rdev);
J
Johannes Berg 已提交
1096 1097
 unlock_rtnl:
	rtnl_unlock();
1098 1099 1100 1101 1102
	return err;
}

static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info)
{
1103
	struct cfg80211_registered_device *rdev;
1104
	int err;
1105 1106
	struct net_device *dev;

J
Johannes Berg 已提交
1107 1108
	rtnl_lock();

1109
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1110
	if (err)
J
Johannes Berg 已提交
1111
		goto unlock_rtnl;
1112

1113
	if (!rdev->ops->del_virtual_intf) {
1114 1115 1116 1117
		err = -EOPNOTSUPP;
		goto out;
	}

1118
	err = rdev->ops->del_virtual_intf(&rdev->wiphy, dev);
1119 1120

 out:
1121
	cfg80211_unlock_rdev(rdev);
1122
	dev_put(dev);
J
Johannes Berg 已提交
1123 1124
 unlock_rtnl:
	rtnl_unlock();
1125 1126 1127
	return err;
}

1128 1129 1130
struct get_key_cookie {
	struct sk_buff *msg;
	int error;
1131
	int idx;
1132 1133 1134 1135
};

static void get_key_callback(void *c, struct key_params *params)
{
1136
	struct nlattr *key;
1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150
	struct get_key_cookie *cookie = c;

	if (params->key)
		NLA_PUT(cookie->msg, NL80211_ATTR_KEY_DATA,
			params->key_len, params->key);

	if (params->seq)
		NLA_PUT(cookie->msg, NL80211_ATTR_KEY_SEQ,
			params->seq_len, params->seq);

	if (params->cipher)
		NLA_PUT_U32(cookie->msg, NL80211_ATTR_KEY_CIPHER,
			    params->cipher);

1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170
	key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY);
	if (!key)
		goto nla_put_failure;

	if (params->key)
		NLA_PUT(cookie->msg, NL80211_KEY_DATA,
			params->key_len, params->key);

	if (params->seq)
		NLA_PUT(cookie->msg, NL80211_KEY_SEQ,
			params->seq_len, params->seq);

	if (params->cipher)
		NLA_PUT_U32(cookie->msg, NL80211_KEY_CIPHER,
			    params->cipher);

	NLA_PUT_U8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx);

	nla_nest_end(cookie->msg, key);

1171 1172 1173 1174 1175 1176 1177
	return;
 nla_put_failure:
	cookie->error = 1;
}

static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info)
{
1178
	struct cfg80211_registered_device *rdev;
1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191
	int err;
	struct net_device *dev;
	u8 key_idx = 0;
	u8 *mac_addr = NULL;
	struct get_key_cookie cookie = {
		.error = 0,
	};
	void *hdr;
	struct sk_buff *msg;

	if (info->attrs[NL80211_ATTR_KEY_IDX])
		key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]);

1192
	if (key_idx > 5)
1193 1194 1195 1196 1197
		return -EINVAL;

	if (info->attrs[NL80211_ATTR_MAC])
		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
1198 1199
	rtnl_lock();

1200
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1201
	if (err)
J
Johannes Berg 已提交
1202
		goto unlock_rtnl;
1203

1204
	if (!rdev->ops->get_key) {
1205 1206 1207 1208
		err = -EOPNOTSUPP;
		goto out;
	}

1209
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1210 1211 1212 1213 1214 1215 1216 1217 1218 1219
	if (!msg) {
		err = -ENOMEM;
		goto out;
	}

	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
			     NL80211_CMD_NEW_KEY);

	if (IS_ERR(hdr)) {
		err = PTR_ERR(hdr);
N
Niko Jokinen 已提交
1220
		goto free_msg;
1221 1222 1223
	}

	cookie.msg = msg;
1224
	cookie.idx = key_idx;
1225 1226 1227 1228 1229 1230

	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
	NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_idx);
	if (mac_addr)
		NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);

1231
	err = rdev->ops->get_key(&rdev->wiphy, dev, key_idx, mac_addr,
1232 1233 1234
				&cookie, get_key_callback);

	if (err)
N
Niko Jokinen 已提交
1235
		goto free_msg;
1236 1237 1238 1239 1240

	if (cookie.error)
		goto nla_put_failure;

	genlmsg_end(msg, hdr);
J
Johannes Berg 已提交
1241
	err = genlmsg_reply(msg, info);
1242 1243 1244 1245
	goto out;

 nla_put_failure:
	err = -ENOBUFS;
N
Niko Jokinen 已提交
1246
 free_msg:
1247 1248
	nlmsg_free(msg);
 out:
1249
	cfg80211_unlock_rdev(rdev);
1250
	dev_put(dev);
J
Johannes Berg 已提交
1251 1252 1253
 unlock_rtnl:
	rtnl_unlock();

1254 1255 1256 1257 1258
	return err;
}

static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info)
{
1259
	struct cfg80211_registered_device *rdev;
1260
	struct key_parse key;
1261 1262
	int err;
	struct net_device *dev;
1263 1264
	int (*func)(struct wiphy *wiphy, struct net_device *netdev,
		    u8 key_index);
1265

1266 1267 1268
	err = nl80211_parse_key(info, &key);
	if (err)
		return err;
1269

1270
	if (key.idx < 0)
1271 1272
		return -EINVAL;

1273 1274
	/* only support setting default key */
	if (!key.def && !key.defmgmt)
1275 1276
		return -EINVAL;

J
Johannes Berg 已提交
1277 1278
	rtnl_lock();

1279
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1280
	if (err)
J
Johannes Berg 已提交
1281
		goto unlock_rtnl;
1282

1283
	if (key.def)
1284
		func = rdev->ops->set_default_key;
1285
	else
1286
		func = rdev->ops->set_default_mgmt_key;
1287 1288

	if (!func) {
1289 1290 1291 1292
		err = -EOPNOTSUPP;
		goto out;
	}

J
Johannes Berg 已提交
1293 1294 1295 1296 1297
	wdev_lock(dev->ieee80211_ptr);
	err = nl80211_key_allowed(dev->ieee80211_ptr);
	if (!err)
		err = func(&rdev->wiphy, dev, key.idx);

J
Johannes Berg 已提交
1298
#ifdef CONFIG_CFG80211_WEXT
1299
	if (!err) {
1300
		if (func == rdev->ops->set_default_key)
1301
			dev->ieee80211_ptr->wext.default_key = key.idx;
1302
		else
1303
			dev->ieee80211_ptr->wext.default_mgmt_key = key.idx;
1304 1305
	}
#endif
J
Johannes Berg 已提交
1306
	wdev_unlock(dev->ieee80211_ptr);
1307 1308

 out:
1309
	cfg80211_unlock_rdev(rdev);
1310
	dev_put(dev);
J
Johannes Berg 已提交
1311 1312 1313 1314

 unlock_rtnl:
	rtnl_unlock();

1315 1316 1317 1318 1319
	return err;
}

static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info)
{
1320
	struct cfg80211_registered_device *rdev;
J
Johannes Berg 已提交
1321
	int err;
1322
	struct net_device *dev;
1323
	struct key_parse key;
1324 1325
	u8 *mac_addr = NULL;

1326 1327 1328
	err = nl80211_parse_key(info, &key);
	if (err)
		return err;
1329

1330
	if (!key.p.key)
1331 1332 1333 1334 1335
		return -EINVAL;

	if (info->attrs[NL80211_ATTR_MAC])
		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
1336 1337
	rtnl_lock();

1338
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1339
	if (err)
J
Johannes Berg 已提交
1340
		goto unlock_rtnl;
1341

J
Johannes Berg 已提交
1342 1343
	if (!rdev->ops->add_key) {
		err = -EOPNOTSUPP;
1344 1345 1346
		goto out;
	}

J
Johannes Berg 已提交
1347 1348
	if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, mac_addr)) {
		err = -EINVAL;
1349 1350 1351
		goto out;
	}

J
Johannes Berg 已提交
1352 1353 1354 1355 1356 1357
	wdev_lock(dev->ieee80211_ptr);
	err = nl80211_key_allowed(dev->ieee80211_ptr);
	if (!err)
		err = rdev->ops->add_key(&rdev->wiphy, dev, key.idx,
					 mac_addr, &key.p);
	wdev_unlock(dev->ieee80211_ptr);
1358 1359

 out:
1360
	cfg80211_unlock_rdev(rdev);
1361
	dev_put(dev);
J
Johannes Berg 已提交
1362 1363 1364
 unlock_rtnl:
	rtnl_unlock();

1365 1366 1367 1368 1369
	return err;
}

static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info)
{
1370
	struct cfg80211_registered_device *rdev;
1371 1372 1373
	int err;
	struct net_device *dev;
	u8 *mac_addr = NULL;
1374
	struct key_parse key;
1375

1376 1377 1378
	err = nl80211_parse_key(info, &key);
	if (err)
		return err;
1379 1380 1381 1382

	if (info->attrs[NL80211_ATTR_MAC])
		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
1383 1384
	rtnl_lock();

1385
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1386
	if (err)
J
Johannes Berg 已提交
1387
		goto unlock_rtnl;
1388

1389
	if (!rdev->ops->del_key) {
1390 1391 1392 1393
		err = -EOPNOTSUPP;
		goto out;
	}

J
Johannes Berg 已提交
1394 1395 1396 1397
	wdev_lock(dev->ieee80211_ptr);
	err = nl80211_key_allowed(dev->ieee80211_ptr);
	if (!err)
		err = rdev->ops->del_key(&rdev->wiphy, dev, key.idx, mac_addr);
1398

J
Johannes Berg 已提交
1399
#ifdef CONFIG_CFG80211_WEXT
1400
	if (!err) {
1401
		if (key.idx == dev->ieee80211_ptr->wext.default_key)
1402
			dev->ieee80211_ptr->wext.default_key = -1;
1403
		else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key)
1404 1405 1406
			dev->ieee80211_ptr->wext.default_mgmt_key = -1;
	}
#endif
J
Johannes Berg 已提交
1407
	wdev_unlock(dev->ieee80211_ptr);
1408

1409
 out:
1410
	cfg80211_unlock_rdev(rdev);
1411
	dev_put(dev);
J
Johannes Berg 已提交
1412 1413 1414 1415

 unlock_rtnl:
	rtnl_unlock();

1416 1417 1418
	return err;
}

1419 1420 1421 1422
static int nl80211_addset_beacon(struct sk_buff *skb, struct genl_info *info)
{
        int (*call)(struct wiphy *wiphy, struct net_device *dev,
		    struct beacon_parameters *info);
1423
	struct cfg80211_registered_device *rdev;
1424 1425 1426 1427 1428
	int err;
	struct net_device *dev;
	struct beacon_parameters params;
	int haveinfo = 0;

1429 1430 1431
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_BEACON_TAIL]))
		return -EINVAL;

J
Johannes Berg 已提交
1432 1433
	rtnl_lock();

1434
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1435
	if (err)
J
Johannes Berg 已提交
1436
		goto unlock_rtnl;
1437

1438 1439 1440 1441 1442
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
		err = -EOPNOTSUPP;
		goto out;
	}

1443 1444 1445 1446 1447 1448 1449 1450 1451 1452
	switch (info->genlhdr->cmd) {
	case NL80211_CMD_NEW_BEACON:
		/* these are required for NEW_BEACON */
		if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] ||
		    !info->attrs[NL80211_ATTR_DTIM_PERIOD] ||
		    !info->attrs[NL80211_ATTR_BEACON_HEAD]) {
			err = -EINVAL;
			goto out;
		}

1453
		call = rdev->ops->add_beacon;
1454 1455
		break;
	case NL80211_CMD_SET_BEACON:
1456
		call = rdev->ops->set_beacon;
1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501
		break;
	default:
		WARN_ON(1);
		err = -EOPNOTSUPP;
		goto out;
	}

	if (!call) {
		err = -EOPNOTSUPP;
		goto out;
	}

	memset(&params, 0, sizeof(params));

	if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
		params.interval =
		    nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
		haveinfo = 1;
	}

	if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) {
		params.dtim_period =
		    nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]);
		haveinfo = 1;
	}

	if (info->attrs[NL80211_ATTR_BEACON_HEAD]) {
		params.head = nla_data(info->attrs[NL80211_ATTR_BEACON_HEAD]);
		params.head_len =
		    nla_len(info->attrs[NL80211_ATTR_BEACON_HEAD]);
		haveinfo = 1;
	}

	if (info->attrs[NL80211_ATTR_BEACON_TAIL]) {
		params.tail = nla_data(info->attrs[NL80211_ATTR_BEACON_TAIL]);
		params.tail_len =
		    nla_len(info->attrs[NL80211_ATTR_BEACON_TAIL]);
		haveinfo = 1;
	}

	if (!haveinfo) {
		err = -EINVAL;
		goto out;
	}

1502
	err = call(&rdev->wiphy, dev, &params);
1503 1504

 out:
1505
	cfg80211_unlock_rdev(rdev);
1506
	dev_put(dev);
J
Johannes Berg 已提交
1507 1508 1509
 unlock_rtnl:
	rtnl_unlock();

1510 1511 1512 1513 1514
	return err;
}

static int nl80211_del_beacon(struct sk_buff *skb, struct genl_info *info)
{
1515
	struct cfg80211_registered_device *rdev;
1516 1517 1518
	int err;
	struct net_device *dev;

J
Johannes Berg 已提交
1519 1520
	rtnl_lock();

1521
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1522
	if (err)
J
Johannes Berg 已提交
1523
		goto unlock_rtnl;
1524

1525
	if (!rdev->ops->del_beacon) {
1526 1527 1528 1529
		err = -EOPNOTSUPP;
		goto out;
	}

1530 1531 1532 1533
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
		err = -EOPNOTSUPP;
		goto out;
	}
1534
	err = rdev->ops->del_beacon(&rdev->wiphy, dev);
1535 1536

 out:
1537
	cfg80211_unlock_rdev(rdev);
1538
	dev_put(dev);
J
Johannes Berg 已提交
1539 1540 1541
 unlock_rtnl:
	rtnl_unlock();

1542 1543 1544
	return err;
}

1545 1546 1547 1548
static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = {
	[NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG },
	[NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG },
	[NL80211_STA_FLAG_WME] = { .type = NLA_FLAG },
1549
	[NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG },
1550 1551
};

1552 1553
static int parse_station_flags(struct genl_info *info,
			       struct station_parameters *params)
1554 1555
{
	struct nlattr *flags[NL80211_STA_FLAG_MAX + 1];
1556
	struct nlattr *nla;
1557 1558
	int flag;

1559 1560 1561 1562 1563 1564 1565 1566 1567 1568 1569 1570 1571 1572 1573 1574 1575 1576
	/*
	 * Try parsing the new attribute first so userspace
	 * can specify both for older kernels.
	 */
	nla = info->attrs[NL80211_ATTR_STA_FLAGS2];
	if (nla) {
		struct nl80211_sta_flag_update *sta_flags;

		sta_flags = nla_data(nla);
		params->sta_flags_mask = sta_flags->mask;
		params->sta_flags_set = sta_flags->set;
		if ((params->sta_flags_mask |
		     params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID))
			return -EINVAL;
		return 0;
	}

	/* if present, parse the old attribute */
1577

1578
	nla = info->attrs[NL80211_ATTR_STA_FLAGS];
1579 1580 1581 1582 1583 1584 1585
	if (!nla)
		return 0;

	if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX,
			     nla, sta_flags_policy))
		return -EINVAL;

1586 1587
	params->sta_flags_mask = (1 << __NL80211_STA_FLAG_AFTER_LAST) - 1;
	params->sta_flags_mask &= ~1;
1588 1589 1590

	for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++)
		if (flags[flag])
1591
			params->sta_flags_set |= (1<<flag);
1592 1593 1594 1595

	return 0;
}

1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628
static u16 nl80211_calculate_bitrate(struct rate_info *rate)
{
	int modulation, streams, bitrate;

	if (!(rate->flags & RATE_INFO_FLAGS_MCS))
		return rate->legacy;

	/* the formula below does only work for MCS values smaller than 32 */
	if (rate->mcs >= 32)
		return 0;

	modulation = rate->mcs & 7;
	streams = (rate->mcs >> 3) + 1;

	bitrate = (rate->flags & RATE_INFO_FLAGS_40_MHZ_WIDTH) ?
			13500000 : 6500000;

	if (modulation < 4)
		bitrate *= (modulation + 1);
	else if (modulation == 4)
		bitrate *= (modulation + 2);
	else
		bitrate *= (modulation + 3);

	bitrate *= streams;

	if (rate->flags & RATE_INFO_FLAGS_SHORT_GI)
		bitrate = (bitrate / 9) * 10;

	/* do NOT round down here */
	return (bitrate + 50000) / 100000;
}

1629 1630
static int nl80211_send_station(struct sk_buff *msg, u32 pid, u32 seq,
				int flags, struct net_device *dev,
1631
				u8 *mac_addr, struct station_info *sinfo)
1632 1633
{
	void *hdr;
1634 1635
	struct nlattr *sinfoattr, *txrate;
	u16 bitrate;
1636 1637 1638 1639 1640 1641 1642 1643

	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
	if (!hdr)
		return -1;

	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr);

1644 1645
	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, sinfo->generation);

1646 1647
	sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO);
	if (!sinfoattr)
1648
		goto nla_put_failure;
1649 1650 1651 1652 1653 1654 1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666
	if (sinfo->filled & STATION_INFO_INACTIVE_TIME)
		NLA_PUT_U32(msg, NL80211_STA_INFO_INACTIVE_TIME,
			    sinfo->inactive_time);
	if (sinfo->filled & STATION_INFO_RX_BYTES)
		NLA_PUT_U32(msg, NL80211_STA_INFO_RX_BYTES,
			    sinfo->rx_bytes);
	if (sinfo->filled & STATION_INFO_TX_BYTES)
		NLA_PUT_U32(msg, NL80211_STA_INFO_TX_BYTES,
			    sinfo->tx_bytes);
	if (sinfo->filled & STATION_INFO_LLID)
		NLA_PUT_U16(msg, NL80211_STA_INFO_LLID,
			    sinfo->llid);
	if (sinfo->filled & STATION_INFO_PLID)
		NLA_PUT_U16(msg, NL80211_STA_INFO_PLID,
			    sinfo->plid);
	if (sinfo->filled & STATION_INFO_PLINK_STATE)
		NLA_PUT_U8(msg, NL80211_STA_INFO_PLINK_STATE,
			    sinfo->plink_state);
1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678
	if (sinfo->filled & STATION_INFO_SIGNAL)
		NLA_PUT_U8(msg, NL80211_STA_INFO_SIGNAL,
			   sinfo->signal);
	if (sinfo->filled & STATION_INFO_TX_BITRATE) {
		txrate = nla_nest_start(msg, NL80211_STA_INFO_TX_BITRATE);
		if (!txrate)
			goto nla_put_failure;

		/* nl80211_calculate_bitrate will return 0 for mcs >= 32 */
		bitrate = nl80211_calculate_bitrate(&sinfo->txrate);
		if (bitrate > 0)
			NLA_PUT_U16(msg, NL80211_RATE_INFO_BITRATE, bitrate);
1679

1680 1681 1682 1683 1684 1685 1686 1687 1688 1689
		if (sinfo->txrate.flags & RATE_INFO_FLAGS_MCS)
			NLA_PUT_U8(msg, NL80211_RATE_INFO_MCS,
				    sinfo->txrate.mcs);
		if (sinfo->txrate.flags & RATE_INFO_FLAGS_40_MHZ_WIDTH)
			NLA_PUT_FLAG(msg, NL80211_RATE_INFO_40_MHZ_WIDTH);
		if (sinfo->txrate.flags & RATE_INFO_FLAGS_SHORT_GI)
			NLA_PUT_FLAG(msg, NL80211_RATE_INFO_SHORT_GI);

		nla_nest_end(msg, txrate);
	}
1690 1691 1692 1693 1694 1695
	if (sinfo->filled & STATION_INFO_RX_PACKETS)
		NLA_PUT_U32(msg, NL80211_STA_INFO_RX_PACKETS,
			    sinfo->rx_packets);
	if (sinfo->filled & STATION_INFO_TX_PACKETS)
		NLA_PUT_U32(msg, NL80211_STA_INFO_TX_PACKETS,
			    sinfo->tx_packets);
1696
	nla_nest_end(msg, sinfoattr);
1697 1698 1699 1700

	return genlmsg_end(msg, hdr);

 nla_put_failure:
1701 1702
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
1703 1704
}

1705
static int nl80211_dump_station(struct sk_buff *skb,
J
Johannes Berg 已提交
1706
				struct netlink_callback *cb)
1707 1708 1709
{
	struct station_info sinfo;
	struct cfg80211_registered_device *dev;
J
Johannes Berg 已提交
1710
	struct net_device *netdev;
1711
	u8 mac_addr[ETH_ALEN];
J
Johannes Berg 已提交
1712 1713
	int ifidx = cb->args[0];
	int sta_idx = cb->args[1];
1714 1715
	int err;

1716 1717 1718 1719
	if (!ifidx)
		ifidx = nl80211_get_ifidx(cb);
	if (ifidx < 0)
		return ifidx;
1720

J
Johannes Berg 已提交
1721 1722
	rtnl_lock();

1723
	netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
J
Johannes Berg 已提交
1724 1725 1726 1727
	if (!netdev) {
		err = -ENODEV;
		goto out_rtnl;
	}
1728

1729
	dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
J
Johannes Berg 已提交
1730 1731
	if (IS_ERR(dev)) {
		err = PTR_ERR(dev);
J
Johannes Berg 已提交
1732
		goto out_rtnl;
J
Johannes Berg 已提交
1733 1734 1735
	}

	if (!dev->ops->dump_station) {
1736
		err = -EOPNOTSUPP;
J
Johannes Berg 已提交
1737 1738 1739 1740 1741 1742 1743 1744 1745
		goto out_err;
	}

	while (1) {
		err = dev->ops->dump_station(&dev->wiphy, netdev, sta_idx,
					     mac_addr, &sinfo);
		if (err == -ENOENT)
			break;
		if (err)
J
Johannes Berg 已提交
1746
			goto out_err;
J
Johannes Berg 已提交
1747 1748 1749 1750 1751 1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762

		if (nl80211_send_station(skb,
				NETLINK_CB(cb->skb).pid,
				cb->nlh->nlmsg_seq, NLM_F_MULTI,
				netdev, mac_addr,
				&sinfo) < 0)
			goto out;

		sta_idx++;
	}


 out:
	cb->args[1] = sta_idx;
	err = skb->len;
 out_err:
1763
	cfg80211_unlock_rdev(dev);
J
Johannes Berg 已提交
1764 1765
 out_rtnl:
	rtnl_unlock();
J
Johannes Berg 已提交
1766 1767

	return err;
1768
}
1769

1770 1771
static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info)
{
1772
	struct cfg80211_registered_device *rdev;
1773 1774
	int err;
	struct net_device *dev;
1775
	struct station_info sinfo;
1776 1777 1778
	struct sk_buff *msg;
	u8 *mac_addr = NULL;

1779
	memset(&sinfo, 0, sizeof(sinfo));
1780 1781 1782 1783 1784 1785

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
1786 1787
	rtnl_lock();

1788
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1789
	if (err)
J
Johannes Berg 已提交
1790
		goto out_rtnl;
1791

1792
	if (!rdev->ops->get_station) {
1793 1794 1795 1796
		err = -EOPNOTSUPP;
		goto out;
	}

1797
	err = rdev->ops->get_station(&rdev->wiphy, dev, mac_addr, &sinfo);
1798 1799 1800
	if (err)
		goto out;

1801
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
1802 1803 1804 1805
	if (!msg)
		goto out;

	if (nl80211_send_station(msg, info->snd_pid, info->snd_seq, 0,
1806
				 dev, mac_addr, &sinfo) < 0)
1807 1808
		goto out_free;

J
Johannes Berg 已提交
1809
	err = genlmsg_reply(msg, info);
1810 1811 1812 1813 1814
	goto out;

 out_free:
	nlmsg_free(msg);
 out:
1815
	cfg80211_unlock_rdev(rdev);
1816
	dev_put(dev);
J
Johannes Berg 已提交
1817 1818 1819
 out_rtnl:
	rtnl_unlock();

1820
	return err;
1821 1822 1823
}

/*
1824
 * Get vlan interface making sure it is running and on the right wiphy.
1825
 */
1826
static int get_vlan(struct genl_info *info,
1827 1828 1829
		    struct cfg80211_registered_device *rdev,
		    struct net_device **vlan)
{
1830
	struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN];
1831 1832 1833
	*vlan = NULL;

	if (vlanattr) {
1834 1835
		*vlan = dev_get_by_index(genl_info_net(info),
					 nla_get_u32(vlanattr));
1836 1837 1838 1839 1840 1841
		if (!*vlan)
			return -ENODEV;
		if (!(*vlan)->ieee80211_ptr)
			return -EINVAL;
		if ((*vlan)->ieee80211_ptr->wiphy != &rdev->wiphy)
			return -EINVAL;
1842 1843
		if (!netif_running(*vlan))
			return -ENETDOWN;
1844 1845 1846 1847 1848 1849
	}
	return 0;
}

static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info)
{
1850
	struct cfg80211_registered_device *rdev;
1851 1852 1853 1854 1855 1856 1857 1858 1859 1860 1861 1862 1863 1864 1865 1866 1867 1868 1869 1870 1871 1872 1873 1874 1875 1876 1877 1878
	int err;
	struct net_device *dev;
	struct station_parameters params;
	u8 *mac_addr = NULL;

	memset(&params, 0, sizeof(params));

	params.listen_interval = -1;

	if (info->attrs[NL80211_ATTR_STA_AID])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);

	if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) {
		params.supported_rates =
			nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
		params.supported_rates_len =
			nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
	}

	if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
		params.listen_interval =
		    nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);

1879 1880 1881 1882
	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
		params.ht_capa =
			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);

1883
	if (parse_station_flags(info, &params))
1884 1885
		return -EINVAL;

1886 1887 1888 1889
	if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION])
		params.plink_action =
		    nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]);

J
Johannes Berg 已提交
1890 1891
	rtnl_lock();

1892
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
1893
	if (err)
J
Johannes Berg 已提交
1894
		goto out_rtnl;
1895

1896
	err = get_vlan(info, rdev, &params.vlan);
1897
	if (err)
1898
		goto out;
1899 1900 1901 1902 1903 1904 1905 1906 1907 1908 1909 1910 1911 1912 1913 1914 1915 1916 1917 1918 1919 1920 1921 1922 1923 1924 1925 1926 1927 1928 1929 1930 1931 1932 1933 1934 1935 1936 1937 1938 1939

	/* validate settings */
	err = 0;

	switch (dev->ieee80211_ptr->iftype) {
	case NL80211_IFTYPE_AP:
	case NL80211_IFTYPE_AP_VLAN:
		/* disallow mesh-specific things */
		if (params.plink_action)
			err = -EINVAL;
		break;
	case NL80211_IFTYPE_STATION:
		/* disallow everything but AUTHORIZED flag */
		if (params.plink_action)
			err = -EINVAL;
		if (params.vlan)
			err = -EINVAL;
		if (params.supported_rates)
			err = -EINVAL;
		if (params.ht_capa)
			err = -EINVAL;
		if (params.listen_interval >= 0)
			err = -EINVAL;
		if (params.sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED))
			err = -EINVAL;
		break;
	case NL80211_IFTYPE_MESH_POINT:
		/* disallow things mesh doesn't support */
		if (params.vlan)
			err = -EINVAL;
		if (params.ht_capa)
			err = -EINVAL;
		if (params.listen_interval >= 0)
			err = -EINVAL;
		if (params.supported_rates)
			err = -EINVAL;
		if (params.sta_flags_mask)
			err = -EINVAL;
		break;
	default:
		err = -EINVAL;
1940 1941
	}

1942 1943 1944
	if (err)
		goto out;

1945
	if (!rdev->ops->change_station) {
1946 1947 1948 1949
		err = -EOPNOTSUPP;
		goto out;
	}

1950
	err = rdev->ops->change_station(&rdev->wiphy, dev, mac_addr, &params);
1951 1952 1953 1954

 out:
	if (params.vlan)
		dev_put(params.vlan);
1955
	cfg80211_unlock_rdev(rdev);
1956
	dev_put(dev);
J
Johannes Berg 已提交
1957 1958 1959
 out_rtnl:
	rtnl_unlock();

1960 1961 1962 1963 1964
	return err;
}

static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info)
{
1965
	struct cfg80211_registered_device *rdev;
1966 1967 1968 1969 1970 1971 1972 1973 1974 1975 1976 1977 1978 1979 1980 1981 1982 1983 1984 1985 1986 1987 1988
	int err;
	struct net_device *dev;
	struct station_parameters params;
	u8 *mac_addr = NULL;

	memset(&params, 0, sizeof(params));

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES])
		return -EINVAL;

	mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);
	params.supported_rates =
		nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
	params.supported_rates_len =
		nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]);
	params.listen_interval =
		nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]);
1989

1990 1991 1992 1993 1994
	if (info->attrs[NL80211_ATTR_STA_AID]) {
		params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]);
		if (!params.aid || params.aid > IEEE80211_MAX_AID)
			return -EINVAL;
	}
1995

1996 1997 1998
	if (info->attrs[NL80211_ATTR_HT_CAPABILITY])
		params.ht_capa =
			nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]);
1999

2000
	if (parse_station_flags(info, &params))
2001 2002
		return -EINVAL;

J
Johannes Berg 已提交
2003 2004
	rtnl_lock();

2005
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2006
	if (err)
J
Johannes Berg 已提交
2007
		goto out_rtnl;
2008

2009
	err = get_vlan(info, rdev, &params.vlan);
2010
	if (err)
2011
		goto out;
2012 2013 2014 2015 2016 2017 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 2028 2029 2030 2031 2032 2033 2034 2035 2036 2037 2038 2039

	/* validate settings */
	err = 0;

	switch (dev->ieee80211_ptr->iftype) {
	case NL80211_IFTYPE_AP:
	case NL80211_IFTYPE_AP_VLAN:
		/* all ok but must have AID */
		if (!params.aid)
			err = -EINVAL;
		break;
	case NL80211_IFTYPE_MESH_POINT:
		/* disallow things mesh doesn't support */
		if (params.vlan)
			err = -EINVAL;
		if (params.aid)
			err = -EINVAL;
		if (params.ht_capa)
			err = -EINVAL;
		if (params.listen_interval >= 0)
			err = -EINVAL;
		if (params.supported_rates)
			err = -EINVAL;
		if (params.sta_flags_mask)
			err = -EINVAL;
		break;
	default:
		err = -EINVAL;
2040 2041
	}

2042 2043 2044
	if (err)
		goto out;

2045
	if (!rdev->ops->add_station) {
2046 2047 2048 2049
		err = -EOPNOTSUPP;
		goto out;
	}

2050 2051 2052 2053 2054
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

2055
	err = rdev->ops->add_station(&rdev->wiphy, dev, mac_addr, &params);
2056 2057 2058 2059

 out:
	if (params.vlan)
		dev_put(params.vlan);
2060
	cfg80211_unlock_rdev(rdev);
2061
	dev_put(dev);
J
Johannes Berg 已提交
2062 2063 2064
 out_rtnl:
	rtnl_unlock();

2065 2066 2067 2068 2069
	return err;
}

static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info)
{
2070
	struct cfg80211_registered_device *rdev;
2071 2072 2073 2074 2075 2076 2077
	int err;
	struct net_device *dev;
	u8 *mac_addr = NULL;

	if (info->attrs[NL80211_ATTR_MAC])
		mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
2078 2079
	rtnl_lock();

2080
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2081
	if (err)
J
Johannes Berg 已提交
2082
		goto out_rtnl;
2083

2084
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP &&
2085 2086
	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN &&
	    dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
2087 2088 2089 2090
		err = -EINVAL;
		goto out;
	}

2091
	if (!rdev->ops->del_station) {
2092 2093 2094 2095
		err = -EOPNOTSUPP;
		goto out;
	}

2096
	err = rdev->ops->del_station(&rdev->wiphy, dev, mac_addr);
2097 2098

 out:
2099
	cfg80211_unlock_rdev(rdev);
2100
	dev_put(dev);
J
Johannes Berg 已提交
2101 2102 2103
 out_rtnl:
	rtnl_unlock();

2104 2105 2106
	return err;
}

2107 2108 2109 2110 2111 2112 2113 2114 2115 2116 2117 2118 2119 2120 2121 2122
static int nl80211_send_mpath(struct sk_buff *msg, u32 pid, u32 seq,
				int flags, struct net_device *dev,
				u8 *dst, u8 *next_hop,
				struct mpath_info *pinfo)
{
	void *hdr;
	struct nlattr *pinfoattr;

	hdr = nl80211hdr_put(msg, pid, seq, flags, NL80211_CMD_NEW_STATION);
	if (!hdr)
		return -1;

	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, dst);
	NLA_PUT(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop);

2123 2124
	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, pinfo->generation);

2125 2126 2127 2128 2129 2130
	pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO);
	if (!pinfoattr)
		goto nla_put_failure;
	if (pinfo->filled & MPATH_INFO_FRAME_QLEN)
		NLA_PUT_U32(msg, NL80211_MPATH_INFO_FRAME_QLEN,
			    pinfo->frame_qlen);
2131 2132 2133
	if (pinfo->filled & MPATH_INFO_SN)
		NLA_PUT_U32(msg, NL80211_MPATH_INFO_SN,
			    pinfo->sn);
2134 2135 2136 2137 2138 2139 2140 2141 2142 2143 2144 2145 2146 2147 2148 2149 2150 2151 2152 2153 2154
	if (pinfo->filled & MPATH_INFO_METRIC)
		NLA_PUT_U32(msg, NL80211_MPATH_INFO_METRIC,
			    pinfo->metric);
	if (pinfo->filled & MPATH_INFO_EXPTIME)
		NLA_PUT_U32(msg, NL80211_MPATH_INFO_EXPTIME,
			    pinfo->exptime);
	if (pinfo->filled & MPATH_INFO_FLAGS)
		NLA_PUT_U8(msg, NL80211_MPATH_INFO_FLAGS,
			    pinfo->flags);
	if (pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT)
		NLA_PUT_U32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT,
			    pinfo->discovery_timeout);
	if (pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES)
		NLA_PUT_U8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES,
			    pinfo->discovery_retries);

	nla_nest_end(msg, pinfoattr);

	return genlmsg_end(msg, hdr);

 nla_put_failure:
2155 2156
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
2157 2158 2159
}

static int nl80211_dump_mpath(struct sk_buff *skb,
J
Johannes Berg 已提交
2160
			      struct netlink_callback *cb)
2161 2162 2163
{
	struct mpath_info pinfo;
	struct cfg80211_registered_device *dev;
J
Johannes Berg 已提交
2164
	struct net_device *netdev;
2165 2166
	u8 dst[ETH_ALEN];
	u8 next_hop[ETH_ALEN];
J
Johannes Berg 已提交
2167 2168
	int ifidx = cb->args[0];
	int path_idx = cb->args[1];
2169 2170
	int err;

2171 2172 2173 2174
	if (!ifidx)
		ifidx = nl80211_get_ifidx(cb);
	if (ifidx < 0)
		return ifidx;
J
Johannes Berg 已提交
2175

J
Johannes Berg 已提交
2176 2177
	rtnl_lock();

2178
	netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
J
Johannes Berg 已提交
2179 2180 2181 2182
	if (!netdev) {
		err = -ENODEV;
		goto out_rtnl;
	}
J
Johannes Berg 已提交
2183

2184
	dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
J
Johannes Berg 已提交
2185 2186
	if (IS_ERR(dev)) {
		err = PTR_ERR(dev);
J
Johannes Berg 已提交
2187
		goto out_rtnl;
J
Johannes Berg 已提交
2188 2189 2190
	}

	if (!dev->ops->dump_mpath) {
2191
		err = -EOPNOTSUPP;
J
Johannes Berg 已提交
2192 2193 2194
		goto out_err;
	}

2195 2196
	if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
		err = -EOPNOTSUPP;
2197
		goto out_err;
2198 2199
	}

J
Johannes Berg 已提交
2200 2201 2202 2203
	while (1) {
		err = dev->ops->dump_mpath(&dev->wiphy, netdev, path_idx,
					   dst, next_hop, &pinfo);
		if (err == -ENOENT)
2204
			break;
J
Johannes Berg 已提交
2205
		if (err)
J
Johannes Berg 已提交
2206
			goto out_err;
2207

J
Johannes Berg 已提交
2208 2209 2210 2211 2212
		if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).pid,
				       cb->nlh->nlmsg_seq, NLM_F_MULTI,
				       netdev, dst, next_hop,
				       &pinfo) < 0)
			goto out;
2213

J
Johannes Berg 已提交
2214
		path_idx++;
2215 2216 2217
	}


J
Johannes Berg 已提交
2218 2219 2220 2221
 out:
	cb->args[1] = path_idx;
	err = skb->len;
 out_err:
2222
	cfg80211_unlock_rdev(dev);
J
Johannes Berg 已提交
2223 2224
 out_rtnl:
	rtnl_unlock();
J
Johannes Berg 已提交
2225 2226

	return err;
2227 2228 2229 2230
}

static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info)
{
2231
	struct cfg80211_registered_device *rdev;
2232 2233 2234 2235 2236 2237 2238 2239 2240 2241 2242 2243 2244 2245
	int err;
	struct net_device *dev;
	struct mpath_info pinfo;
	struct sk_buff *msg;
	u8 *dst = NULL;
	u8 next_hop[ETH_ALEN];

	memset(&pinfo, 0, sizeof(pinfo));

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
2246 2247
	rtnl_lock();

2248
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2249
	if (err)
J
Johannes Berg 已提交
2250
		goto out_rtnl;
2251

2252
	if (!rdev->ops->get_mpath) {
2253 2254 2255 2256
		err = -EOPNOTSUPP;
		goto out;
	}

2257 2258 2259 2260 2261
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
		err = -EOPNOTSUPP;
		goto out;
	}

2262
	err = rdev->ops->get_mpath(&rdev->wiphy, dev, dst, next_hop, &pinfo);
2263 2264 2265
	if (err)
		goto out;

2266
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2267 2268 2269 2270 2271 2272 2273
	if (!msg)
		goto out;

	if (nl80211_send_mpath(msg, info->snd_pid, info->snd_seq, 0,
				 dev, dst, next_hop, &pinfo) < 0)
		goto out_free;

J
Johannes Berg 已提交
2274
	err = genlmsg_reply(msg, info);
2275 2276 2277 2278 2279
	goto out;

 out_free:
	nlmsg_free(msg);
 out:
2280
	cfg80211_unlock_rdev(rdev);
2281
	dev_put(dev);
J
Johannes Berg 已提交
2282 2283 2284
 out_rtnl:
	rtnl_unlock();

2285 2286 2287 2288 2289
	return err;
}

static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info)
{
2290
	struct cfg80211_registered_device *rdev;
2291 2292 2293 2294 2295 2296 2297 2298 2299 2300 2301 2302 2303 2304
	int err;
	struct net_device *dev;
	u8 *dst = NULL;
	u8 *next_hop = NULL;

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
		return -EINVAL;

	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
	next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);

J
Johannes Berg 已提交
2305 2306
	rtnl_lock();

2307
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2308
	if (err)
J
Johannes Berg 已提交
2309
		goto out_rtnl;
2310

2311
	if (!rdev->ops->change_mpath) {
2312 2313 2314 2315
		err = -EOPNOTSUPP;
		goto out;
	}

2316 2317 2318 2319 2320
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
		err = -EOPNOTSUPP;
		goto out;
	}

2321 2322 2323 2324 2325
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

2326
	err = rdev->ops->change_mpath(&rdev->wiphy, dev, dst, next_hop);
2327 2328

 out:
2329
	cfg80211_unlock_rdev(rdev);
2330
	dev_put(dev);
J
Johannes Berg 已提交
2331 2332 2333
 out_rtnl:
	rtnl_unlock();

2334 2335 2336 2337
	return err;
}
static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info)
{
2338
	struct cfg80211_registered_device *rdev;
2339 2340 2341 2342 2343 2344 2345 2346 2347 2348 2349 2350 2351 2352
	int err;
	struct net_device *dev;
	u8 *dst = NULL;
	u8 *next_hop = NULL;

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP])
		return -EINVAL;

	dst = nla_data(info->attrs[NL80211_ATTR_MAC]);
	next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]);

J
Johannes Berg 已提交
2353 2354
	rtnl_lock();

2355
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2356
	if (err)
J
Johannes Berg 已提交
2357
		goto out_rtnl;
2358

2359
	if (!rdev->ops->add_mpath) {
2360 2361 2362 2363
		err = -EOPNOTSUPP;
		goto out;
	}

2364 2365 2366 2367 2368
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) {
		err = -EOPNOTSUPP;
		goto out;
	}

2369 2370 2371 2372 2373
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

2374
	err = rdev->ops->add_mpath(&rdev->wiphy, dev, dst, next_hop);
2375 2376

 out:
2377
	cfg80211_unlock_rdev(rdev);
2378
	dev_put(dev);
J
Johannes Berg 已提交
2379 2380 2381
 out_rtnl:
	rtnl_unlock();

2382 2383 2384 2385 2386
	return err;
}

static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info)
{
2387
	struct cfg80211_registered_device *rdev;
2388 2389 2390 2391 2392 2393 2394
	int err;
	struct net_device *dev;
	u8 *dst = NULL;

	if (info->attrs[NL80211_ATTR_MAC])
		dst = nla_data(info->attrs[NL80211_ATTR_MAC]);

J
Johannes Berg 已提交
2395 2396
	rtnl_lock();

2397
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2398
	if (err)
J
Johannes Berg 已提交
2399
		goto out_rtnl;
2400

2401
	if (!rdev->ops->del_mpath) {
2402 2403 2404 2405
		err = -EOPNOTSUPP;
		goto out;
	}

2406
	err = rdev->ops->del_mpath(&rdev->wiphy, dev, dst);
2407 2408

 out:
2409
	cfg80211_unlock_rdev(rdev);
2410
	dev_put(dev);
J
Johannes Berg 已提交
2411 2412 2413
 out_rtnl:
	rtnl_unlock();

2414 2415 2416
	return err;
}

2417 2418
static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info)
{
2419
	struct cfg80211_registered_device *rdev;
2420 2421 2422 2423 2424 2425 2426 2427 2428 2429 2430 2431 2432 2433 2434 2435 2436 2437 2438
	int err;
	struct net_device *dev;
	struct bss_parameters params;

	memset(&params, 0, sizeof(params));
	/* default to not changing parameters */
	params.use_cts_prot = -1;
	params.use_short_preamble = -1;
	params.use_short_slot_time = -1;

	if (info->attrs[NL80211_ATTR_BSS_CTS_PROT])
		params.use_cts_prot =
		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]);
	if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE])
		params.use_short_preamble =
		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]);
	if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME])
		params.use_short_slot_time =
		    nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]);
2439 2440 2441 2442 2443 2444
	if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) {
		params.basic_rates =
			nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
		params.basic_rates_len =
			nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]);
	}
2445

J
Johannes Berg 已提交
2446 2447
	rtnl_lock();

2448
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2449
	if (err)
J
Johannes Berg 已提交
2450
		goto out_rtnl;
2451

2452
	if (!rdev->ops->change_bss) {
2453 2454 2455 2456
		err = -EOPNOTSUPP;
		goto out;
	}

2457 2458 2459 2460 2461
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP) {
		err = -EOPNOTSUPP;
		goto out;
	}

2462
	err = rdev->ops->change_bss(&rdev->wiphy, dev, &params);
2463 2464

 out:
2465
	cfg80211_unlock_rdev(rdev);
2466
	dev_put(dev);
J
Johannes Berg 已提交
2467 2468 2469
 out_rtnl:
	rtnl_unlock();

2470 2471 2472
	return err;
}

2473 2474 2475 2476 2477 2478 2479 2480 2481 2482 2483 2484 2485 2486 2487 2488 2489 2490 2491 2492 2493 2494 2495 2496 2497 2498 2499 2500 2501 2502 2503 2504 2505 2506 2507 2508 2509 2510 2511 2512 2513 2514 2515 2516 2517 2518 2519 2520 2521 2522 2523
static const struct nla_policy
	reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = {
	[NL80211_ATTR_REG_RULE_FLAGS]		= { .type = NLA_U32 },
	[NL80211_ATTR_FREQ_RANGE_START]		= { .type = NLA_U32 },
	[NL80211_ATTR_FREQ_RANGE_END]		= { .type = NLA_U32 },
	[NL80211_ATTR_FREQ_RANGE_MAX_BW]	= { .type = NLA_U32 },
	[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]	= { .type = NLA_U32 },
	[NL80211_ATTR_POWER_RULE_MAX_EIRP]	= { .type = NLA_U32 },
};

static int parse_reg_rule(struct nlattr *tb[],
	struct ieee80211_reg_rule *reg_rule)
{
	struct ieee80211_freq_range *freq_range = &reg_rule->freq_range;
	struct ieee80211_power_rule *power_rule = &reg_rule->power_rule;

	if (!tb[NL80211_ATTR_REG_RULE_FLAGS])
		return -EINVAL;
	if (!tb[NL80211_ATTR_FREQ_RANGE_START])
		return -EINVAL;
	if (!tb[NL80211_ATTR_FREQ_RANGE_END])
		return -EINVAL;
	if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW])
		return -EINVAL;
	if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP])
		return -EINVAL;

	reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]);

	freq_range->start_freq_khz =
		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]);
	freq_range->end_freq_khz =
		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]);
	freq_range->max_bandwidth_khz =
		nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]);

	power_rule->max_eirp =
		nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]);

	if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN])
		power_rule->max_antenna_gain =
			nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]);

	return 0;
}

static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info)
{
	int r;
	char *data = NULL;

2524 2525 2526 2527 2528 2529 2530 2531
	/*
	 * You should only get this when cfg80211 hasn't yet initialized
	 * completely when built-in to the kernel right between the time
	 * window between nl80211_init() and regulatory_init(), if that is
	 * even possible.
	 */
	mutex_lock(&cfg80211_mutex);
	if (unlikely(!cfg80211_regdomain)) {
2532 2533
		mutex_unlock(&cfg80211_mutex);
		return -EINPROGRESS;
2534
	}
2535
	mutex_unlock(&cfg80211_mutex);
2536

2537 2538
	if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
		return -EINVAL;
2539 2540 2541 2542 2543

	data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);

#ifdef CONFIG_WIRELESS_OLD_REGULATORY
	/* We ignore world regdom requests with the old regdom setup */
2544 2545
	if (is_world_regdom(data))
		return -EINVAL;
2546
#endif
2547 2548 2549

	r = regulatory_hint_user(data);

2550 2551 2552
	return r;
}

2553 2554 2555
static int nl80211_get_mesh_params(struct sk_buff *skb,
	struct genl_info *info)
{
2556
	struct cfg80211_registered_device *rdev;
2557 2558 2559 2560 2561 2562 2563
	struct mesh_config cur_params;
	int err;
	struct net_device *dev;
	void *hdr;
	struct nlattr *pinfoattr;
	struct sk_buff *msg;

J
Johannes Berg 已提交
2564 2565
	rtnl_lock();

2566
	/* Look up our device */
2567
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2568
	if (err)
J
Johannes Berg 已提交
2569
		goto out_rtnl;
2570

2571
	if (!rdev->ops->get_mesh_params) {
2572 2573 2574 2575
		err = -EOPNOTSUPP;
		goto out;
	}

2576
	/* Get the mesh params */
2577
	err = rdev->ops->get_mesh_params(&rdev->wiphy, dev, &cur_params);
2578 2579 2580 2581
	if (err)
		goto out;

	/* Draw up a netlink message to send back */
2582
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2583 2584 2585 2586 2587 2588 2589 2590 2591 2592 2593 2594 2595 2596 2597 2598 2599 2600 2601 2602 2603 2604 2605 2606 2607 2608 2609 2610 2611 2612 2613 2614 2615 2616 2617 2618 2619 2620
	if (!msg) {
		err = -ENOBUFS;
		goto out;
	}
	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
			     NL80211_CMD_GET_MESH_PARAMS);
	if (!hdr)
		goto nla_put_failure;
	pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_PARAMS);
	if (!pinfoattr)
		goto nla_put_failure;
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);
	NLA_PUT_U16(msg, NL80211_MESHCONF_RETRY_TIMEOUT,
			cur_params.dot11MeshRetryTimeout);
	NLA_PUT_U16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT,
			cur_params.dot11MeshConfirmTimeout);
	NLA_PUT_U16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT,
			cur_params.dot11MeshHoldingTimeout);
	NLA_PUT_U16(msg, NL80211_MESHCONF_MAX_PEER_LINKS,
			cur_params.dot11MeshMaxPeerLinks);
	NLA_PUT_U8(msg, NL80211_MESHCONF_MAX_RETRIES,
			cur_params.dot11MeshMaxRetries);
	NLA_PUT_U8(msg, NL80211_MESHCONF_TTL,
			cur_params.dot11MeshTTL);
	NLA_PUT_U8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS,
			cur_params.auto_open_plinks);
	NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
			cur_params.dot11MeshHWMPmaxPREQretries);
	NLA_PUT_U32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME,
			cur_params.path_refresh_time);
	NLA_PUT_U16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
			cur_params.min_discovery_timeout);
	NLA_PUT_U32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
			cur_params.dot11MeshHWMPactivePathTimeout);
	NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
			cur_params.dot11MeshHWMPpreqMinInterval);
	NLA_PUT_U16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
			cur_params.dot11MeshHWMPnetDiameterTraversalTime);
2621 2622
	NLA_PUT_U8(msg, NL80211_MESHCONF_HWMP_ROOTMODE,
			cur_params.dot11MeshHWMPRootMode);
2623 2624
	nla_nest_end(msg, pinfoattr);
	genlmsg_end(msg, hdr);
J
Johannes Berg 已提交
2625
	err = genlmsg_reply(msg, info);
2626 2627
	goto out;

J
Johannes Berg 已提交
2628
 nla_put_failure:
2629 2630
	genlmsg_cancel(msg, hdr);
	err = -EMSGSIZE;
J
Johannes Berg 已提交
2631
 out:
2632
	/* Cleanup */
2633
	cfg80211_unlock_rdev(rdev);
2634
	dev_put(dev);
J
Johannes Berg 已提交
2635 2636 2637
 out_rtnl:
	rtnl_unlock();

2638 2639 2640 2641 2642 2643 2644 2645 2646 2647 2648 2649 2650 2651 2652 2653 2654 2655 2656 2657 2658 2659 2660 2661 2662 2663 2664 2665 2666 2667 2668 2669 2670
	return err;
}

#define FILL_IN_MESH_PARAM_IF_SET(table, cfg, param, mask, attr_num, nla_fn) \
do {\
	if (table[attr_num]) {\
		cfg.param = nla_fn(table[attr_num]); \
		mask |= (1 << (attr_num - 1)); \
	} \
} while (0);\

static struct nla_policy
nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] __read_mostly = {
	[NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 },
	[NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 },
	[NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 },
	[NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 },
	[NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 },
	[NL80211_MESHCONF_TTL] = { .type = NLA_U8 },
	[NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 },

	[NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 },
	[NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 },
	[NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 },
	[NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 },
	[NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 },
	[NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 },
};

static int nl80211_set_mesh_params(struct sk_buff *skb, struct genl_info *info)
{
	int err;
	u32 mask;
2671
	struct cfg80211_registered_device *rdev;
2672 2673 2674 2675 2676 2677 2678 2679 2680 2681 2682 2683
	struct net_device *dev;
	struct mesh_config cfg;
	struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1];
	struct nlattr *parent_attr;

	parent_attr = info->attrs[NL80211_ATTR_MESH_PARAMS];
	if (!parent_attr)
		return -EINVAL;
	if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX,
			parent_attr, nl80211_meshconf_params_policy))
		return -EINVAL;

J
Johannes Berg 已提交
2684 2685
	rtnl_lock();

2686
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2687
	if (err)
J
Johannes Berg 已提交
2688
		goto out_rtnl;
2689

2690
	if (!rdev->ops->set_mesh_params) {
2691 2692 2693 2694
		err = -EOPNOTSUPP;
		goto out;
	}

2695 2696 2697 2698 2699 2700 2701 2702 2703 2704 2705 2706 2707 2708 2709 2710 2711 2712 2713 2714 2715 2716 2717 2718 2719 2720 2721 2722 2723 2724 2725 2726 2727 2728 2729 2730 2731 2732
	/* This makes sure that there aren't more than 32 mesh config
	 * parameters (otherwise our bitfield scheme would not work.) */
	BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32);

	/* Fill in the params struct */
	mask = 0;
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout,
			mask, NL80211_MESHCONF_RETRY_TIMEOUT, nla_get_u16);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout,
			mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, nla_get_u16);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout,
			mask, NL80211_MESHCONF_HOLDING_TIMEOUT, nla_get_u16);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks,
			mask, NL80211_MESHCONF_MAX_PEER_LINKS, nla_get_u16);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries,
			mask, NL80211_MESHCONF_MAX_RETRIES, nla_get_u8);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL,
			mask, NL80211_MESHCONF_TTL, nla_get_u8);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks,
			mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, nla_get_u8);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries,
			mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES,
			nla_get_u8);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time,
			mask, NL80211_MESHCONF_PATH_REFRESH_TIME, nla_get_u32);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout,
			mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT,
			nla_get_u16);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout,
			mask, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT,
			nla_get_u32);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval,
			mask, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL,
			nla_get_u16);
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
			dot11MeshHWMPnetDiameterTraversalTime,
			mask, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME,
			nla_get_u16);
2733 2734 2735 2736
	FILL_IN_MESH_PARAM_IF_SET(tb, cfg,
			dot11MeshHWMPRootMode, mask,
			NL80211_MESHCONF_HWMP_ROOTMODE,
			nla_get_u8);
2737 2738

	/* Apply changes */
2739
	err = rdev->ops->set_mesh_params(&rdev->wiphy, dev, &cfg, mask);
2740

2741
 out:
2742
	/* cleanup */
2743
	cfg80211_unlock_rdev(rdev);
2744
	dev_put(dev);
J
Johannes Berg 已提交
2745 2746 2747
 out_rtnl:
	rtnl_unlock();

2748 2749 2750 2751 2752
	return err;
}

#undef FILL_IN_MESH_PARAM_IF_SET

2753 2754 2755 2756 2757 2758 2759 2760
static int nl80211_get_reg(struct sk_buff *skb, struct genl_info *info)
{
	struct sk_buff *msg;
	void *hdr = NULL;
	struct nlattr *nl_reg_rules;
	unsigned int i;
	int err = -EINVAL;

2761
	mutex_lock(&cfg80211_mutex);
2762 2763 2764 2765

	if (!cfg80211_regdomain)
		goto out;

2766
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
2767 2768 2769 2770 2771 2772 2773 2774 2775 2776 2777 2778 2779 2780 2781 2782 2783 2784 2785 2786 2787 2788 2789 2790 2791 2792 2793 2794 2795 2796 2797 2798 2799 2800 2801 2802 2803 2804 2805 2806 2807 2808 2809 2810 2811 2812 2813 2814 2815 2816
	if (!msg) {
		err = -ENOBUFS;
		goto out;
	}

	hdr = nl80211hdr_put(msg, info->snd_pid, info->snd_seq, 0,
			     NL80211_CMD_GET_REG);
	if (!hdr)
		goto nla_put_failure;

	NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2,
		cfg80211_regdomain->alpha2);

	nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES);
	if (!nl_reg_rules)
		goto nla_put_failure;

	for (i = 0; i < cfg80211_regdomain->n_reg_rules; i++) {
		struct nlattr *nl_reg_rule;
		const struct ieee80211_reg_rule *reg_rule;
		const struct ieee80211_freq_range *freq_range;
		const struct ieee80211_power_rule *power_rule;

		reg_rule = &cfg80211_regdomain->reg_rules[i];
		freq_range = &reg_rule->freq_range;
		power_rule = &reg_rule->power_rule;

		nl_reg_rule = nla_nest_start(msg, i);
		if (!nl_reg_rule)
			goto nla_put_failure;

		NLA_PUT_U32(msg, NL80211_ATTR_REG_RULE_FLAGS,
			reg_rule->flags);
		NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_START,
			freq_range->start_freq_khz);
		NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_END,
			freq_range->end_freq_khz);
		NLA_PUT_U32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW,
			freq_range->max_bandwidth_khz);
		NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN,
			power_rule->max_antenna_gain);
		NLA_PUT_U32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP,
			power_rule->max_eirp);

		nla_nest_end(msg, nl_reg_rule);
	}

	nla_nest_end(msg, nl_reg_rules);

	genlmsg_end(msg, hdr);
J
Johannes Berg 已提交
2817
	err = genlmsg_reply(msg, info);
2818 2819 2820 2821 2822 2823
	goto out;

nla_put_failure:
	genlmsg_cancel(msg, hdr);
	err = -EMSGSIZE;
out:
2824
	mutex_unlock(&cfg80211_mutex);
2825 2826 2827
	return err;
}

2828 2829 2830 2831 2832 2833 2834 2835 2836 2837 2838 2839 2840 2841 2842 2843 2844 2845 2846 2847 2848
static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info)
{
	struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1];
	struct nlattr *nl_reg_rule;
	char *alpha2 = NULL;
	int rem_reg_rules = 0, r = 0;
	u32 num_rules = 0, rule_idx = 0, size_of_regd;
	struct ieee80211_regdomain *rd = NULL;

	if (!info->attrs[NL80211_ATTR_REG_ALPHA2])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_REG_RULES])
		return -EINVAL;

	alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]);

	nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
			rem_reg_rules) {
		num_rules++;
		if (num_rules > NL80211_MAX_SUPP_REG_RULES)
2849
			return -EINVAL;
2850 2851
	}

2852 2853
	mutex_lock(&cfg80211_mutex);

2854 2855 2856 2857
	if (!reg_is_valid_request(alpha2)) {
		r = -EINVAL;
		goto bad_reg;
	}
2858 2859 2860 2861 2862

	size_of_regd = sizeof(struct ieee80211_regdomain) +
		(num_rules * sizeof(struct ieee80211_reg_rule));

	rd = kzalloc(size_of_regd, GFP_KERNEL);
2863 2864 2865 2866
	if (!rd) {
		r = -ENOMEM;
		goto bad_reg;
	}
2867 2868 2869 2870 2871 2872 2873 2874 2875 2876 2877 2878 2879 2880 2881 2882

	rd->n_reg_rules = num_rules;
	rd->alpha2[0] = alpha2[0];
	rd->alpha2[1] = alpha2[1];

	nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES],
			rem_reg_rules) {
		nla_parse(tb, NL80211_REG_RULE_ATTR_MAX,
			nla_data(nl_reg_rule), nla_len(nl_reg_rule),
			reg_rule_policy);
		r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]);
		if (r)
			goto bad_reg;

		rule_idx++;

2883 2884
		if (rule_idx > NL80211_MAX_SUPP_REG_RULES) {
			r = -EINVAL;
2885
			goto bad_reg;
2886
		}
2887 2888 2889 2890 2891
	}

	BUG_ON(rule_idx != num_rules);

	r = set_regdom(rd);
2892

2893
	mutex_unlock(&cfg80211_mutex);
2894

2895 2896
	return r;

2897
 bad_reg:
2898
	mutex_unlock(&cfg80211_mutex);
2899
	kfree(rd);
2900
	return r;
2901 2902
}

2903 2904 2905 2906 2907 2908 2909 2910 2911 2912 2913 2914 2915 2916 2917 2918 2919 2920 2921 2922 2923 2924 2925 2926 2927
static int validate_scan_freqs(struct nlattr *freqs)
{
	struct nlattr *attr1, *attr2;
	int n_channels = 0, tmp1, tmp2;

	nla_for_each_nested(attr1, freqs, tmp1) {
		n_channels++;
		/*
		 * Some hardware has a limited channel list for
		 * scanning, and it is pretty much nonsensical
		 * to scan for a channel twice, so disallow that
		 * and don't require drivers to check that the
		 * channel list they get isn't longer than what
		 * they can scan, as long as they can scan all
		 * the channels they registered at once.
		 */
		nla_for_each_nested(attr2, freqs, tmp2)
			if (attr1 != attr2 &&
			    nla_get_u32(attr1) == nla_get_u32(attr2))
				return 0;
	}

	return n_channels;
}

2928 2929
static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info)
{
2930
	struct cfg80211_registered_device *rdev;
2931 2932 2933 2934 2935 2936
	struct net_device *dev;
	struct cfg80211_scan_request *request;
	struct cfg80211_ssid *ssid;
	struct ieee80211_channel *channel;
	struct nlattr *attr;
	struct wiphy *wiphy;
2937
	int err, tmp, n_ssids = 0, n_channels, i;
2938
	enum ieee80211_band band;
2939
	size_t ie_len;
2940

2941 2942 2943
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

J
Johannes Berg 已提交
2944 2945
	rtnl_lock();

2946
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
2947
	if (err)
J
Johannes Berg 已提交
2948
		goto out_rtnl;
2949

2950
	wiphy = &rdev->wiphy;
2951

2952
	if (!rdev->ops->scan) {
2953 2954 2955 2956
		err = -EOPNOTSUPP;
		goto out;
	}

2957 2958 2959 2960 2961
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

2962
	if (rdev->scan_req) {
2963
		err = -EBUSY;
J
Johannes Berg 已提交
2964
		goto out;
2965 2966 2967
	}

	if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
2968 2969
		n_channels = validate_scan_freqs(
				info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]);
2970 2971
		if (!n_channels) {
			err = -EINVAL;
J
Johannes Berg 已提交
2972
			goto out;
2973 2974
		}
	} else {
2975 2976
		n_channels = 0;

2977 2978 2979 2980 2981 2982 2983 2984 2985 2986 2987
		for (band = 0; band < IEEE80211_NUM_BANDS; band++)
			if (wiphy->bands[band])
				n_channels += wiphy->bands[band]->n_channels;
	}

	if (info->attrs[NL80211_ATTR_SCAN_SSIDS])
		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp)
			n_ssids++;

	if (n_ssids > wiphy->max_scan_ssids) {
		err = -EINVAL;
J
Johannes Berg 已提交
2988
		goto out;
2989 2990
	}

2991 2992 2993 2994 2995
	if (info->attrs[NL80211_ATTR_IE])
		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
	else
		ie_len = 0;

2996 2997 2998 2999 3000
	if (ie_len > wiphy->max_scan_ie_len) {
		err = -EINVAL;
		goto out;
	}

3001 3002
	request = kzalloc(sizeof(*request)
			+ sizeof(*ssid) * n_ssids
3003 3004
			+ sizeof(channel) * n_channels
			+ ie_len, GFP_KERNEL);
3005 3006
	if (!request) {
		err = -ENOMEM;
J
Johannes Berg 已提交
3007
		goto out;
3008 3009 3010
	}

	if (n_ssids)
3011
		request->ssids = (void *)&request->channels[n_channels];
3012
	request->n_ssids = n_ssids;
3013 3014 3015 3016 3017 3018
	if (ie_len) {
		if (request->ssids)
			request->ie = (void *)(request->ssids + n_ssids);
		else
			request->ie = (void *)(request->channels + n_channels);
	}
3019

J
Johannes Berg 已提交
3020
	i = 0;
3021 3022 3023
	if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) {
		/* user specified, bail out if channel not found */
		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) {
J
Johannes Berg 已提交
3024 3025 3026 3027 3028
			struct ieee80211_channel *chan;

			chan = ieee80211_get_channel(wiphy, nla_get_u32(attr));

			if (!chan) {
3029 3030 3031
				err = -EINVAL;
				goto out_free;
			}
J
Johannes Berg 已提交
3032 3033 3034 3035 3036 3037

			/* ignore disabled channels */
			if (chan->flags & IEEE80211_CHAN_DISABLED)
				continue;

			request->channels[i] = chan;
3038 3039 3040 3041 3042 3043 3044 3045 3046
			i++;
		}
	} else {
		/* all channels */
		for (band = 0; band < IEEE80211_NUM_BANDS; band++) {
			int j;
			if (!wiphy->bands[band])
				continue;
			for (j = 0; j < wiphy->bands[band]->n_channels; j++) {
J
Johannes Berg 已提交
3047 3048 3049 3050 3051 3052 3053 3054
				struct ieee80211_channel *chan;

				chan = &wiphy->bands[band]->channels[j];

				if (chan->flags & IEEE80211_CHAN_DISABLED)
					continue;

				request->channels[i] = chan;
3055 3056 3057 3058 3059
				i++;
			}
		}
	}

J
Johannes Berg 已提交
3060 3061 3062 3063 3064 3065 3066
	if (!i) {
		err = -EINVAL;
		goto out_free;
	}

	request->n_channels = i;

3067 3068 3069 3070 3071 3072 3073 3074 3075 3076 3077 3078 3079
	i = 0;
	if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) {
		nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) {
			if (request->ssids[i].ssid_len > IEEE80211_MAX_SSID_LEN) {
				err = -EINVAL;
				goto out_free;
			}
			memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr));
			request->ssids[i].ssid_len = nla_len(attr);
			i++;
		}
	}

3080 3081
	if (info->attrs[NL80211_ATTR_IE]) {
		request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3082 3083
		memcpy((void *)request->ie,
		       nla_data(info->attrs[NL80211_ATTR_IE]),
3084 3085 3086
		       request->ie_len);
	}

3087
	request->dev = dev;
3088
	request->wiphy = &rdev->wiphy;
3089

3090 3091
	rdev->scan_req = request;
	err = rdev->ops->scan(&rdev->wiphy, dev, request);
3092

3093
	if (!err) {
3094
		nl80211_send_scan_start(rdev, dev);
3095 3096
		dev_hold(dev);
	}
3097

3098 3099
 out_free:
	if (err) {
3100
		rdev->scan_req = NULL;
3101 3102 3103
		kfree(request);
	}
 out:
3104
	cfg80211_unlock_rdev(rdev);
3105
	dev_put(dev);
J
Johannes Berg 已提交
3106 3107 3108
 out_rtnl:
	rtnl_unlock();

3109 3110 3111 3112 3113
	return err;
}

static int nl80211_send_bss(struct sk_buff *msg, u32 pid, u32 seq, int flags,
			    struct cfg80211_registered_device *rdev,
J
Johannes Berg 已提交
3114 3115
			    struct wireless_dev *wdev,
			    struct cfg80211_internal_bss *intbss)
3116
{
J
Johannes Berg 已提交
3117
	struct cfg80211_bss *res = &intbss->pub;
3118 3119
	void *hdr;
	struct nlattr *bss;
J
Johannes Berg 已提交
3120 3121 3122
	int i;

	ASSERT_WDEV_LOCK(wdev);
3123 3124 3125 3126 3127 3128

	hdr = nl80211hdr_put(msg, pid, seq, flags,
			     NL80211_CMD_NEW_SCAN_RESULTS);
	if (!hdr)
		return -1;

3129
	NLA_PUT_U32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation);
J
Johannes Berg 已提交
3130
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex);
3131 3132 3133 3134 3135 3136 3137 3138 3139 3140 3141 3142 3143 3144 3145 3146

	bss = nla_nest_start(msg, NL80211_ATTR_BSS);
	if (!bss)
		goto nla_put_failure;
	if (!is_zero_ether_addr(res->bssid))
		NLA_PUT(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid);
	if (res->information_elements && res->len_information_elements)
		NLA_PUT(msg, NL80211_BSS_INFORMATION_ELEMENTS,
			res->len_information_elements,
			res->information_elements);
	if (res->tsf)
		NLA_PUT_U64(msg, NL80211_BSS_TSF, res->tsf);
	if (res->beacon_interval)
		NLA_PUT_U16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval);
	NLA_PUT_U16(msg, NL80211_BSS_CAPABILITY, res->capability);
	NLA_PUT_U32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq);
3147 3148
	NLA_PUT_U32(msg, NL80211_BSS_SEEN_MS_AGO,
		jiffies_to_msecs(jiffies - intbss->ts));
3149

J
Johannes Berg 已提交
3150
	switch (rdev->wiphy.signal_type) {
3151 3152 3153 3154 3155 3156 3157 3158 3159 3160
	case CFG80211_SIGNAL_TYPE_MBM:
		NLA_PUT_U32(msg, NL80211_BSS_SIGNAL_MBM, res->signal);
		break;
	case CFG80211_SIGNAL_TYPE_UNSPEC:
		NLA_PUT_U8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal);
		break;
	default:
		break;
	}

J
Johannes Berg 已提交
3161 3162 3163 3164 3165 3166 3167 3168 3169 3170 3171 3172 3173 3174 3175 3176 3177 3178 3179 3180 3181 3182
	switch (wdev->iftype) {
	case NL80211_IFTYPE_STATION:
		if (intbss == wdev->current_bss)
			NLA_PUT_U32(msg, NL80211_BSS_STATUS,
				    NL80211_BSS_STATUS_ASSOCIATED);
		else for (i = 0; i < MAX_AUTH_BSSES; i++) {
			if (intbss != wdev->auth_bsses[i])
				continue;
			NLA_PUT_U32(msg, NL80211_BSS_STATUS,
				    NL80211_BSS_STATUS_AUTHENTICATED);
			break;
		}
		break;
	case NL80211_IFTYPE_ADHOC:
		if (intbss == wdev->current_bss)
			NLA_PUT_U32(msg, NL80211_BSS_STATUS,
				    NL80211_BSS_STATUS_IBSS_JOINED);
		break;
	default:
		break;
	}

3183 3184 3185 3186 3187 3188 3189 3190 3191 3192 3193 3194
	nla_nest_end(msg, bss);

	return genlmsg_end(msg, hdr);

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
}

static int nl80211_dump_scan(struct sk_buff *skb,
			     struct netlink_callback *cb)
{
J
Johannes Berg 已提交
3195 3196
	struct cfg80211_registered_device *rdev;
	struct net_device *dev;
3197
	struct cfg80211_internal_bss *scan;
J
Johannes Berg 已提交
3198
	struct wireless_dev *wdev;
3199 3200 3201 3202
	int ifidx = cb->args[0];
	int start = cb->args[1], idx = 0;
	int err;

3203 3204 3205 3206 3207
	if (!ifidx)
		ifidx = nl80211_get_ifidx(cb);
	if (ifidx < 0)
		return ifidx;
	cb->args[0] = ifidx;
3208

3209
	dev = dev_get_by_index(sock_net(skb->sk), ifidx);
J
Johannes Berg 已提交
3210
	if (!dev)
3211 3212
		return -ENODEV;

3213
	rdev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
J
Johannes Berg 已提交
3214 3215
	if (IS_ERR(rdev)) {
		err = PTR_ERR(rdev);
3216 3217 3218
		goto out_put_netdev;
	}

J
Johannes Berg 已提交
3219
	wdev = dev->ieee80211_ptr;
3220

J
Johannes Berg 已提交
3221 3222 3223 3224 3225
	wdev_lock(wdev);
	spin_lock_bh(&rdev->bss_lock);
	cfg80211_bss_expire(rdev);

	list_for_each_entry(scan, &rdev->bss_list, list) {
3226 3227 3228 3229 3230
		if (++idx <= start)
			continue;
		if (nl80211_send_bss(skb,
				NETLINK_CB(cb->skb).pid,
				cb->nlh->nlmsg_seq, NLM_F_MULTI,
J
Johannes Berg 已提交
3231
				rdev, wdev, scan) < 0) {
3232 3233 3234 3235 3236 3237
			idx--;
			goto out;
		}
	}

 out:
J
Johannes Berg 已提交
3238 3239
	spin_unlock_bh(&rdev->bss_lock);
	wdev_unlock(wdev);
3240 3241 3242

	cb->args[1] = idx;
	err = skb->len;
J
Johannes Berg 已提交
3243
	cfg80211_unlock_rdev(rdev);
3244
 out_put_netdev:
J
Johannes Berg 已提交
3245
	dev_put(dev);
3246 3247 3248 3249

	return err;
}

3250 3251 3252 3253 3254 3255 3256 3257 3258 3259 3260 3261 3262 3263 3264 3265 3266 3267 3268 3269 3270 3271 3272 3273 3274 3275 3276 3277 3278 3279 3280 3281 3282 3283 3284 3285 3286 3287 3288 3289 3290 3291 3292 3293 3294 3295 3296 3297 3298 3299 3300 3301 3302 3303 3304 3305 3306 3307 3308 3309 3310 3311 3312 3313 3314 3315 3316 3317 3318 3319 3320 3321 3322 3323 3324 3325 3326 3327 3328 3329 3330 3331 3332 3333 3334 3335 3336 3337 3338 3339 3340 3341 3342 3343 3344 3345 3346 3347 3348 3349
static int nl80211_send_survey(struct sk_buff *msg, u32 pid, u32 seq,
				int flags, struct net_device *dev,
				struct survey_info *survey)
{
	void *hdr;
	struct nlattr *infoattr;

	/* Survey without a channel doesn't make sense */
	if (!survey->channel)
		return -EINVAL;

	hdr = nl80211hdr_put(msg, pid, seq, flags,
			     NL80211_CMD_NEW_SURVEY_RESULTS);
	if (!hdr)
		return -ENOMEM;

	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, dev->ifindex);

	infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO);
	if (!infoattr)
		goto nla_put_failure;

	NLA_PUT_U32(msg, NL80211_SURVEY_INFO_FREQUENCY,
		    survey->channel->center_freq);
	if (survey->filled & SURVEY_INFO_NOISE_DBM)
		NLA_PUT_U8(msg, NL80211_SURVEY_INFO_NOISE,
			    survey->noise);

	nla_nest_end(msg, infoattr);

	return genlmsg_end(msg, hdr);

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
}

static int nl80211_dump_survey(struct sk_buff *skb,
			struct netlink_callback *cb)
{
	struct survey_info survey;
	struct cfg80211_registered_device *dev;
	struct net_device *netdev;
	int ifidx = cb->args[0];
	int survey_idx = cb->args[1];
	int res;

	if (!ifidx)
		ifidx = nl80211_get_ifidx(cb);
	if (ifidx < 0)
		return ifidx;
	cb->args[0] = ifidx;

	rtnl_lock();

	netdev = __dev_get_by_index(sock_net(skb->sk), ifidx);
	if (!netdev) {
		res = -ENODEV;
		goto out_rtnl;
	}

	dev = cfg80211_get_dev_from_ifindex(sock_net(skb->sk), ifidx);
	if (IS_ERR(dev)) {
		res = PTR_ERR(dev);
		goto out_rtnl;
	}

	if (!dev->ops->dump_survey) {
		res = -EOPNOTSUPP;
		goto out_err;
	}

	while (1) {
		res = dev->ops->dump_survey(&dev->wiphy, netdev, survey_idx,
					    &survey);
		if (res == -ENOENT)
			break;
		if (res)
			goto out_err;

		if (nl80211_send_survey(skb,
				NETLINK_CB(cb->skb).pid,
				cb->nlh->nlmsg_seq, NLM_F_MULTI,
				netdev,
				&survey) < 0)
			goto out;
		survey_idx++;
	}

 out:
	cb->args[1] = survey_idx;
	res = skb->len;
 out_err:
	cfg80211_unlock_rdev(dev);
 out_rtnl:
	rtnl_unlock();

	return res;
}

3350 3351
static bool nl80211_valid_auth_type(enum nl80211_auth_type auth_type)
{
S
Samuel Ortiz 已提交
3352 3353 3354 3355 3356 3357 3358 3359 3360 3361 3362 3363 3364 3365 3366 3367 3368 3369 3370 3371 3372 3373
	return auth_type <= NL80211_AUTHTYPE_MAX;
}

static bool nl80211_valid_wpa_versions(u32 wpa_versions)
{
	return !(wpa_versions & ~(NL80211_WPA_VERSION_1 |
				  NL80211_WPA_VERSION_2));
}

static bool nl80211_valid_akm_suite(u32 akm)
{
	return akm == WLAN_AKM_SUITE_8021X ||
		akm == WLAN_AKM_SUITE_PSK;
}

static bool nl80211_valid_cipher_suite(u32 cipher)
{
	return cipher == WLAN_CIPHER_SUITE_WEP40 ||
		cipher == WLAN_CIPHER_SUITE_WEP104 ||
		cipher == WLAN_CIPHER_SUITE_TKIP ||
		cipher == WLAN_CIPHER_SUITE_CCMP ||
		cipher == WLAN_CIPHER_SUITE_AES_CMAC;
3374 3375
}

S
Samuel Ortiz 已提交
3376

3377 3378
static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info)
{
3379
	struct cfg80211_registered_device *rdev;
3380
	struct net_device *dev;
J
Johannes Berg 已提交
3381 3382 3383 3384
	struct ieee80211_channel *chan;
	const u8 *bssid, *ssid, *ie = NULL;
	int err, ssid_len, ie_len = 0;
	enum nl80211_auth_type auth_type;
J
Johannes Berg 已提交
3385
	struct key_parse key;
3386

3387 3388 3389 3390 3391 3392
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

3393 3394 3395
	if (!info->attrs[NL80211_ATTR_AUTH_TYPE])
		return -EINVAL;

J
Johannes Berg 已提交
3396 3397 3398 3399 3400 3401
	if (!info->attrs[NL80211_ATTR_SSID])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ])
		return -EINVAL;

J
Johannes Berg 已提交
3402 3403 3404 3405 3406 3407 3408 3409 3410 3411 3412 3413 3414 3415 3416 3417 3418 3419 3420
	err = nl80211_parse_key(info, &key);
	if (err)
		return err;

	if (key.idx >= 0) {
		if (!key.p.key || !key.p.key_len)
			return -EINVAL;
		if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 ||
		     key.p.key_len != WLAN_KEY_LEN_WEP40) &&
		    (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 ||
		     key.p.key_len != WLAN_KEY_LEN_WEP104))
			return -EINVAL;
		if (key.idx > 4)
			return -EINVAL;
	} else {
		key.p.key_len = 0;
		key.p.key = NULL;
	}

3421 3422
	rtnl_lock();

3423
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3424 3425 3426
	if (err)
		goto unlock_rtnl;

3427
	if (!rdev->ops->auth) {
3428 3429 3430 3431
		err = -EOPNOTSUPP;
		goto out;
	}

3432 3433 3434 3435 3436
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
		err = -EOPNOTSUPP;
		goto out;
	}

3437 3438 3439 3440 3441
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

J
Johannes Berg 已提交
3442
	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3443
	chan = ieee80211_get_channel(&rdev->wiphy,
J
Johannes Berg 已提交
3444 3445 3446 3447
		nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
	if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
		err = -EINVAL;
		goto out;
3448 3449
	}

J
Johannes Berg 已提交
3450 3451
	ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
	ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3452 3453

	if (info->attrs[NL80211_ATTR_IE]) {
J
Johannes Berg 已提交
3454 3455
		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3456 3457
	}

J
Johannes Berg 已提交
3458 3459
	auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
	if (!nl80211_valid_auth_type(auth_type)) {
3460 3461
		err = -EINVAL;
		goto out;
3462 3463
	}

3464
	err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid,
J
Johannes Berg 已提交
3465 3466
				 ssid, ssid_len, ie, ie_len,
				 key.p.key, key.p.key_len, key.idx);
3467 3468

out:
3469
	cfg80211_unlock_rdev(rdev);
3470 3471 3472 3473 3474 3475
	dev_put(dev);
unlock_rtnl:
	rtnl_unlock();
	return err;
}

S
Samuel Ortiz 已提交
3476
static int nl80211_crypto_settings(struct genl_info *info,
3477 3478
				   struct cfg80211_crypto_settings *settings,
				   int cipher_limit)
S
Samuel Ortiz 已提交
3479
{
3480 3481
	memset(settings, 0, sizeof(*settings));

S
Samuel Ortiz 已提交
3482 3483 3484 3485 3486 3487 3488 3489 3490 3491 3492 3493 3494
	settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT];

	if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) {
		void *data;
		int len, i;

		data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
		len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]);
		settings->n_ciphers_pairwise = len / sizeof(u32);

		if (len % sizeof(u32))
			return -EINVAL;

3495
		if (settings->n_ciphers_pairwise > cipher_limit)
S
Samuel Ortiz 已提交
3496 3497 3498 3499 3500 3501 3502 3503 3504 3505 3506 3507 3508 3509 3510 3511 3512 3513 3514 3515 3516 3517 3518 3519 3520 3521 3522 3523 3524 3525 3526 3527 3528 3529 3530 3531 3532 3533 3534 3535 3536 3537 3538 3539 3540
			return -EINVAL;

		memcpy(settings->ciphers_pairwise, data, len);

		for (i = 0; i < settings->n_ciphers_pairwise; i++)
			if (!nl80211_valid_cipher_suite(
					settings->ciphers_pairwise[i]))
				return -EINVAL;
	}

	if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) {
		settings->cipher_group =
			nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]);
		if (!nl80211_valid_cipher_suite(settings->cipher_group))
			return -EINVAL;
	}

	if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) {
		settings->wpa_versions =
			nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]);
		if (!nl80211_valid_wpa_versions(settings->wpa_versions))
			return -EINVAL;
	}

	if (info->attrs[NL80211_ATTR_AKM_SUITES]) {
		void *data;
		int len, i;

		data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]);
		len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]);
		settings->n_akm_suites = len / sizeof(u32);

		if (len % sizeof(u32))
			return -EINVAL;

		memcpy(settings->akm_suites, data, len);

		for (i = 0; i < settings->n_ciphers_pairwise; i++)
			if (!nl80211_valid_akm_suite(settings->akm_suites[i]))
				return -EINVAL;
	}

	return 0;
}

3541 3542
static int nl80211_associate(struct sk_buff *skb, struct genl_info *info)
{
J
Johannes Berg 已提交
3543
	struct cfg80211_registered_device *rdev;
3544
	struct net_device *dev;
J
Johannes Berg 已提交
3545
	struct cfg80211_crypto_settings crypto;
3546
	struct ieee80211_channel *chan, *fixedchan;
3547
	const u8 *bssid, *ssid, *ie = NULL, *prev_bssid = NULL;
J
Johannes Berg 已提交
3548 3549
	int err, ssid_len, ie_len = 0;
	bool use_mfp = false;
3550

3551 3552 3553 3554
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MAC] ||
J
Johannes Berg 已提交
3555 3556
	    !info->attrs[NL80211_ATTR_SSID] ||
	    !info->attrs[NL80211_ATTR_WIPHY_FREQ])
3557 3558
		return -EINVAL;

3559 3560
	rtnl_lock();

3561
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3562 3563 3564
	if (err)
		goto unlock_rtnl;

J
Johannes Berg 已提交
3565
	if (!rdev->ops->assoc) {
3566 3567 3568 3569
		err = -EOPNOTSUPP;
		goto out;
	}

3570 3571 3572 3573 3574
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
		err = -EOPNOTSUPP;
		goto out;
	}

3575 3576 3577 3578 3579
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

J
Johannes Berg 已提交
3580
	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3581

J
Johannes Berg 已提交
3582 3583 3584 3585 3586
	chan = ieee80211_get_channel(&rdev->wiphy,
		nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
	if (!chan || (chan->flags & IEEE80211_CHAN_DISABLED)) {
		err = -EINVAL;
		goto out;
3587 3588
	}

3589 3590 3591 3592 3593 3594 3595 3596 3597
	mutex_lock(&rdev->devlist_mtx);
	fixedchan = rdev_fixed_channel(rdev, NULL);
	if (fixedchan && chan != fixedchan) {
		err = -EBUSY;
		mutex_unlock(&rdev->devlist_mtx);
		goto out;
	}
	mutex_unlock(&rdev->devlist_mtx);

J
Johannes Berg 已提交
3598 3599
	ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
	ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);
3600 3601

	if (info->attrs[NL80211_ATTR_IE]) {
J
Johannes Berg 已提交
3602 3603
		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3604 3605
	}

3606
	if (info->attrs[NL80211_ATTR_USE_MFP]) {
3607
		enum nl80211_mfp mfp =
3608
			nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]);
3609
		if (mfp == NL80211_MFP_REQUIRED)
J
Johannes Berg 已提交
3610
			use_mfp = true;
3611
		else if (mfp != NL80211_MFP_NO) {
3612 3613 3614 3615 3616
			err = -EINVAL;
			goto out;
		}
	}

3617 3618 3619
	if (info->attrs[NL80211_ATTR_PREV_BSSID])
		prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]);

3620
	err = nl80211_crypto_settings(info, &crypto, 1);
S
Samuel Ortiz 已提交
3621
	if (!err)
3622 3623
		err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, prev_bssid,
					  ssid, ssid_len, ie, ie_len, use_mfp,
J
Johannes Berg 已提交
3624
					  &crypto);
3625 3626

out:
3627
	cfg80211_unlock_rdev(rdev);
3628 3629 3630 3631 3632 3633 3634 3635
	dev_put(dev);
unlock_rtnl:
	rtnl_unlock();
	return err;
}

static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info)
{
3636
	struct cfg80211_registered_device *rdev;
3637
	struct net_device *dev;
J
Johannes Berg 已提交
3638 3639 3640
	const u8 *ie = NULL, *bssid;
	int err, ie_len = 0;
	u16 reason_code;
3641

3642 3643 3644 3645 3646 3647 3648 3649 3650
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_REASON_CODE])
		return -EINVAL;

3651 3652
	rtnl_lock();

3653
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3654 3655 3656
	if (err)
		goto unlock_rtnl;

3657
	if (!rdev->ops->deauth) {
3658 3659 3660 3661
		err = -EOPNOTSUPP;
		goto out;
	}

3662 3663 3664 3665 3666
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
		err = -EOPNOTSUPP;
		goto out;
	}

3667 3668 3669 3670 3671
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

J
Johannes Berg 已提交
3672
	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3673

J
Johannes Berg 已提交
3674 3675
	reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
	if (reason_code == 0) {
3676 3677 3678
		/* Reason Code 0 is reserved */
		err = -EINVAL;
		goto out;
3679
	}
3680 3681

	if (info->attrs[NL80211_ATTR_IE]) {
J
Johannes Berg 已提交
3682 3683
		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3684 3685
	}

3686
	err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code);
3687 3688

out:
3689
	cfg80211_unlock_rdev(rdev);
3690 3691 3692 3693 3694 3695 3696 3697
	dev_put(dev);
unlock_rtnl:
	rtnl_unlock();
	return err;
}

static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info)
{
3698
	struct cfg80211_registered_device *rdev;
3699
	struct net_device *dev;
J
Johannes Berg 已提交
3700 3701 3702
	const u8 *ie = NULL, *bssid;
	int err, ie_len = 0;
	u16 reason_code;
3703

3704 3705 3706 3707 3708 3709 3710 3711 3712
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_MAC])
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_REASON_CODE])
		return -EINVAL;

3713 3714
	rtnl_lock();

3715
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
3716 3717 3718
	if (err)
		goto unlock_rtnl;

3719
	if (!rdev->ops->disassoc) {
3720 3721 3722 3723
		err = -EOPNOTSUPP;
		goto out;
	}

3724 3725 3726 3727 3728
	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
		err = -EOPNOTSUPP;
		goto out;
	}

3729 3730 3731 3732 3733
	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

J
Johannes Berg 已提交
3734
	bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
3735

J
Johannes Berg 已提交
3736 3737
	reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);
	if (reason_code == 0) {
3738 3739 3740
		/* Reason Code 0 is reserved */
		err = -EINVAL;
		goto out;
3741
	}
3742 3743

	if (info->attrs[NL80211_ATTR_IE]) {
J
Johannes Berg 已提交
3744 3745
		ie = nla_data(info->attrs[NL80211_ATTR_IE]);
		ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
3746 3747
	}

3748
	err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code);
3749 3750

out:
3751
	cfg80211_unlock_rdev(rdev);
3752 3753 3754 3755 3756 3757
	dev_put(dev);
unlock_rtnl:
	rtnl_unlock();
	return err;
}

J
Johannes Berg 已提交
3758 3759
static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info)
{
3760
	struct cfg80211_registered_device *rdev;
J
Johannes Berg 已提交
3761 3762 3763
	struct net_device *dev;
	struct cfg80211_ibss_params ibss;
	struct wiphy *wiphy;
J
Johannes Berg 已提交
3764
	struct cfg80211_cached_keys *connkeys = NULL;
J
Johannes Berg 已提交
3765 3766
	int err;

3767 3768
	memset(&ibss, 0, sizeof(ibss));

J
Johannes Berg 已提交
3769 3770 3771 3772 3773 3774 3775 3776
	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] ||
	    !info->attrs[NL80211_ATTR_SSID] ||
	    !nla_len(info->attrs[NL80211_ATTR_SSID]))
		return -EINVAL;

3777 3778 3779 3780 3781 3782 3783 3784 3785
	ibss.beacon_interval = 100;

	if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) {
		ibss.beacon_interval =
			nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]);
		if (ibss.beacon_interval < 1 || ibss.beacon_interval > 10000)
			return -EINVAL;
	}

J
Johannes Berg 已提交
3786 3787
	rtnl_lock();

3788
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
J
Johannes Berg 已提交
3789 3790 3791
	if (err)
		goto unlock_rtnl;

3792
	if (!rdev->ops->join_ibss) {
J
Johannes Berg 已提交
3793 3794 3795 3796 3797 3798 3799 3800 3801 3802 3803 3804 3805 3806
		err = -EOPNOTSUPP;
		goto out;
	}

	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
		err = -EOPNOTSUPP;
		goto out;
	}

	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

3807
	wiphy = &rdev->wiphy;
J
Johannes Berg 已提交
3808 3809 3810 3811 3812 3813 3814 3815 3816 3817 3818 3819 3820 3821 3822 3823 3824 3825 3826 3827 3828

	if (info->attrs[NL80211_ATTR_MAC])
		ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
	ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
	ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);

	if (info->attrs[NL80211_ATTR_IE]) {
		ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
		ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
	}

	ibss.channel = ieee80211_get_channel(wiphy,
		nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
	if (!ibss.channel ||
	    ibss.channel->flags & IEEE80211_CHAN_NO_IBSS ||
	    ibss.channel->flags & IEEE80211_CHAN_DISABLED) {
		err = -EINVAL;
		goto out;
	}

	ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED];
J
Johannes Berg 已提交
3829 3830 3831 3832 3833 3834 3835 3836 3837 3838 3839
	ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY];

	if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) {
		connkeys = nl80211_parse_connkeys(rdev,
					info->attrs[NL80211_ATTR_KEYS]);
		if (IS_ERR(connkeys)) {
			err = PTR_ERR(connkeys);
			connkeys = NULL;
			goto out;
		}
	}
J
Johannes Berg 已提交
3840

J
Johannes Berg 已提交
3841
	err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys);
J
Johannes Berg 已提交
3842 3843

out:
3844
	cfg80211_unlock_rdev(rdev);
J
Johannes Berg 已提交
3845 3846
	dev_put(dev);
unlock_rtnl:
J
Johannes Berg 已提交
3847 3848
	if (err)
		kfree(connkeys);
J
Johannes Berg 已提交
3849 3850 3851 3852 3853 3854
	rtnl_unlock();
	return err;
}

static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info)
{
3855
	struct cfg80211_registered_device *rdev;
J
Johannes Berg 已提交
3856 3857 3858 3859 3860
	struct net_device *dev;
	int err;

	rtnl_lock();

3861
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
J
Johannes Berg 已提交
3862 3863 3864
	if (err)
		goto unlock_rtnl;

3865
	if (!rdev->ops->leave_ibss) {
J
Johannes Berg 已提交
3866 3867 3868 3869 3870 3871 3872 3873 3874 3875 3876 3877 3878 3879
		err = -EOPNOTSUPP;
		goto out;
	}

	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) {
		err = -EOPNOTSUPP;
		goto out;
	}

	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

3880
	err = cfg80211_leave_ibss(rdev, dev, false);
J
Johannes Berg 已提交
3881 3882

out:
3883
	cfg80211_unlock_rdev(rdev);
J
Johannes Berg 已提交
3884 3885 3886 3887 3888 3889
	dev_put(dev);
unlock_rtnl:
	rtnl_unlock();
	return err;
}

3890 3891 3892 3893 3894 3895 3896 3897 3898 3899 3900 3901 3902 3903 3904 3905 3906 3907 3908 3909 3910 3911 3912 3913 3914 3915 3916 3917 3918 3919
#ifdef CONFIG_NL80211_TESTMODE
static struct genl_multicast_group nl80211_testmode_mcgrp = {
	.name = "testmode",
};

static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info)
{
	struct cfg80211_registered_device *rdev;
	int err;

	if (!info->attrs[NL80211_ATTR_TESTDATA])
		return -EINVAL;

	rtnl_lock();

	rdev = cfg80211_get_dev_from_info(info);
	if (IS_ERR(rdev)) {
		err = PTR_ERR(rdev);
		goto unlock_rtnl;
	}

	err = -EOPNOTSUPP;
	if (rdev->ops->testmode_cmd) {
		rdev->testmode_info = info;
		err = rdev->ops->testmode_cmd(&rdev->wiphy,
				nla_data(info->attrs[NL80211_ATTR_TESTDATA]),
				nla_len(info->attrs[NL80211_ATTR_TESTDATA]));
		rdev->testmode_info = NULL;
	}

3920
	cfg80211_unlock_rdev(rdev);
3921 3922 3923 3924 3925 3926 3927 3928 3929 3930 3931 3932 3933 3934 3935 3936 3937 3938 3939 3940 3941 3942 3943 3944 3945 3946 3947 3948 3949 3950 3951 3952 3953 3954 3955 3956 3957 3958 3959 3960 3961 3962 3963 3964 3965 3966 3967 3968 3969 3970 3971 3972 3973 3974 3975 3976 3977 3978 3979 3980 3981 3982 3983 3984 3985 3986 3987 3988 3989 3990 3991 3992 3993 3994 3995 3996 3997 3998 3999 4000 4001 4002 4003 4004 4005 4006 4007 4008 4009 4010 4011

 unlock_rtnl:
	rtnl_unlock();
	return err;
}

static struct sk_buff *
__cfg80211_testmode_alloc_skb(struct cfg80211_registered_device *rdev,
			      int approxlen, u32 pid, u32 seq, gfp_t gfp)
{
	struct sk_buff *skb;
	void *hdr;
	struct nlattr *data;

	skb = nlmsg_new(approxlen + 100, gfp);
	if (!skb)
		return NULL;

	hdr = nl80211hdr_put(skb, pid, seq, 0, NL80211_CMD_TESTMODE);
	if (!hdr) {
		kfree_skb(skb);
		return NULL;
	}

	NLA_PUT_U32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	data = nla_nest_start(skb, NL80211_ATTR_TESTDATA);

	((void **)skb->cb)[0] = rdev;
	((void **)skb->cb)[1] = hdr;
	((void **)skb->cb)[2] = data;

	return skb;

 nla_put_failure:
	kfree_skb(skb);
	return NULL;
}

struct sk_buff *cfg80211_testmode_alloc_reply_skb(struct wiphy *wiphy,
						  int approxlen)
{
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);

	if (WARN_ON(!rdev->testmode_info))
		return NULL;

	return __cfg80211_testmode_alloc_skb(rdev, approxlen,
				rdev->testmode_info->snd_pid,
				rdev->testmode_info->snd_seq,
				GFP_KERNEL);
}
EXPORT_SYMBOL(cfg80211_testmode_alloc_reply_skb);

int cfg80211_testmode_reply(struct sk_buff *skb)
{
	struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0];
	void *hdr = ((void **)skb->cb)[1];
	struct nlattr *data = ((void **)skb->cb)[2];

	if (WARN_ON(!rdev->testmode_info)) {
		kfree_skb(skb);
		return -EINVAL;
	}

	nla_nest_end(skb, data);
	genlmsg_end(skb, hdr);
	return genlmsg_reply(skb, rdev->testmode_info);
}
EXPORT_SYMBOL(cfg80211_testmode_reply);

struct sk_buff *cfg80211_testmode_alloc_event_skb(struct wiphy *wiphy,
						  int approxlen, gfp_t gfp)
{
	struct cfg80211_registered_device *rdev = wiphy_to_dev(wiphy);

	return __cfg80211_testmode_alloc_skb(rdev, approxlen, 0, 0, gfp);
}
EXPORT_SYMBOL(cfg80211_testmode_alloc_event_skb);

void cfg80211_testmode_event(struct sk_buff *skb, gfp_t gfp)
{
	void *hdr = ((void **)skb->cb)[1];
	struct nlattr *data = ((void **)skb->cb)[2];

	nla_nest_end(skb, data);
	genlmsg_end(skb, hdr);
	genlmsg_multicast(skb, 0, nl80211_testmode_mcgrp.id, gfp);
}
EXPORT_SYMBOL(cfg80211_testmode_event);
#endif

S
Samuel Ortiz 已提交
4012 4013
static int nl80211_connect(struct sk_buff *skb, struct genl_info *info)
{
4014
	struct cfg80211_registered_device *rdev;
S
Samuel Ortiz 已提交
4015 4016 4017
	struct net_device *dev;
	struct cfg80211_connect_params connect;
	struct wiphy *wiphy;
J
Johannes Berg 已提交
4018
	struct cfg80211_cached_keys *connkeys = NULL;
S
Samuel Ortiz 已提交
4019 4020 4021 4022 4023 4024 4025 4026 4027 4028 4029 4030 4031 4032 4033 4034 4035 4036 4037 4038 4039
	int err;

	memset(&connect, 0, sizeof(connect));

	if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE]))
		return -EINVAL;

	if (!info->attrs[NL80211_ATTR_SSID] ||
	    !nla_len(info->attrs[NL80211_ATTR_SSID]))
		return -EINVAL;

	if (info->attrs[NL80211_ATTR_AUTH_TYPE]) {
		connect.auth_type =
			nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]);
		if (!nl80211_valid_auth_type(connect.auth_type))
			return -EINVAL;
	} else
		connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC;

	connect.privacy = info->attrs[NL80211_ATTR_PRIVACY];

4040 4041
	err = nl80211_crypto_settings(info, &connect.crypto,
				      NL80211_MAX_NR_CIPHER_SUITES);
S
Samuel Ortiz 已提交
4042 4043 4044 4045
	if (err)
		return err;
	rtnl_lock();

4046
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
S
Samuel Ortiz 已提交
4047 4048 4049 4050 4051 4052 4053 4054 4055 4056 4057 4058 4059
	if (err)
		goto unlock_rtnl;

	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
		err = -EOPNOTSUPP;
		goto out;
	}

	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

4060
	wiphy = &rdev->wiphy;
S
Samuel Ortiz 已提交
4061 4062 4063 4064 4065 4066 4067 4068 4069 4070 4071 4072 4073 4074 4075 4076 4077 4078 4079 4080 4081 4082

	if (info->attrs[NL80211_ATTR_MAC])
		connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]);
	connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]);
	connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]);

	if (info->attrs[NL80211_ATTR_IE]) {
		connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]);
		connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]);
	}

	if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) {
		connect.channel =
			ieee80211_get_channel(wiphy,
			    nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]));
		if (!connect.channel ||
		    connect.channel->flags & IEEE80211_CHAN_DISABLED) {
			err = -EINVAL;
			goto out;
		}
	}

J
Johannes Berg 已提交
4083 4084 4085 4086 4087 4088 4089 4090 4091 4092 4093
	if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) {
		connkeys = nl80211_parse_connkeys(rdev,
					info->attrs[NL80211_ATTR_KEYS]);
		if (IS_ERR(connkeys)) {
			err = PTR_ERR(connkeys);
			connkeys = NULL;
			goto out;
		}
	}

	err = cfg80211_connect(rdev, dev, &connect, connkeys);
S
Samuel Ortiz 已提交
4094 4095

out:
4096
	cfg80211_unlock_rdev(rdev);
S
Samuel Ortiz 已提交
4097 4098
	dev_put(dev);
unlock_rtnl:
J
Johannes Berg 已提交
4099 4100
	if (err)
		kfree(connkeys);
S
Samuel Ortiz 已提交
4101 4102 4103 4104 4105 4106
	rtnl_unlock();
	return err;
}

static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info)
{
4107
	struct cfg80211_registered_device *rdev;
S
Samuel Ortiz 已提交
4108 4109 4110 4111 4112 4113 4114 4115 4116 4117 4118 4119 4120 4121
	struct net_device *dev;
	int err;
	u16 reason;

	if (!info->attrs[NL80211_ATTR_REASON_CODE])
		reason = WLAN_REASON_DEAUTH_LEAVING;
	else
		reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]);

	if (reason == 0)
		return -EINVAL;

	rtnl_lock();

4122
	err = get_rdev_dev_by_info_ifindex(info, &rdev, &dev);
S
Samuel Ortiz 已提交
4123 4124 4125 4126 4127 4128 4129 4130 4131 4132 4133 4134 4135
	if (err)
		goto unlock_rtnl;

	if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION) {
		err = -EOPNOTSUPP;
		goto out;
	}

	if (!netif_running(dev)) {
		err = -ENETDOWN;
		goto out;
	}

4136
	err = cfg80211_disconnect(rdev, dev, reason, true);
S
Samuel Ortiz 已提交
4137 4138

out:
4139
	cfg80211_unlock_rdev(rdev);
S
Samuel Ortiz 已提交
4140 4141 4142 4143 4144 4145
	dev_put(dev);
unlock_rtnl:
	rtnl_unlock();
	return err;
}

4146 4147 4148 4149 4150 4151 4152 4153 4154 4155 4156 4157 4158 4159 4160 4161 4162
static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info)
{
	struct cfg80211_registered_device *rdev;
	struct net *net;
	int err;
	u32 pid;

	if (!info->attrs[NL80211_ATTR_PID])
		return -EINVAL;

	pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]);

	rtnl_lock();

	rdev = cfg80211_get_dev_from_info(info);
	if (IS_ERR(rdev)) {
		err = PTR_ERR(rdev);
4163
		goto out_rtnl;
4164 4165 4166 4167 4168 4169 4170 4171 4172 4173 4174 4175 4176 4177 4178 4179 4180 4181 4182
	}

	net = get_net_ns_by_pid(pid);
	if (IS_ERR(net)) {
		err = PTR_ERR(net);
		goto out;
	}

	err = 0;

	/* check if anything to do */
	if (net_eq(wiphy_net(&rdev->wiphy), net))
		goto out_put_net;

	err = cfg80211_switch_netns(rdev, net);
 out_put_net:
	put_net(net);
 out:
	cfg80211_unlock_rdev(rdev);
4183
 out_rtnl:
4184 4185 4186 4187
	rtnl_unlock();
	return err;
}

4188 4189 4190 4191 4192 4193 4194 4195 4196 4197 4198 4199 4200 4201 4202 4203 4204 4205 4206 4207 4208 4209 4210 4211 4212 4213 4214 4215 4216 4217 4218 4219 4220 4221 4222 4223 4224
static struct genl_ops nl80211_ops[] = {
	{
		.cmd = NL80211_CMD_GET_WIPHY,
		.doit = nl80211_get_wiphy,
		.dumpit = nl80211_dump_wiphy,
		.policy = nl80211_policy,
		/* can be retrieved by unprivileged users */
	},
	{
		.cmd = NL80211_CMD_SET_WIPHY,
		.doit = nl80211_set_wiphy,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_GET_INTERFACE,
		.doit = nl80211_get_interface,
		.dumpit = nl80211_dump_interface,
		.policy = nl80211_policy,
		/* can be retrieved by unprivileged users */
	},
	{
		.cmd = NL80211_CMD_SET_INTERFACE,
		.doit = nl80211_set_interface,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_NEW_INTERFACE,
		.doit = nl80211_new_interface,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DEL_INTERFACE,
		.doit = nl80211_del_interface,
		.policy = nl80211_policy,
4225 4226 4227 4228 4229 4230 4231 4232 4233 4234 4235 4236 4237 4238 4239 4240 4241 4242 4243 4244 4245 4246 4247 4248
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_GET_KEY,
		.doit = nl80211_get_key,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_SET_KEY,
		.doit = nl80211_set_key,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_NEW_KEY,
		.doit = nl80211_new_key,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DEL_KEY,
		.doit = nl80211_del_key,
		.policy = nl80211_policy,
4249 4250
		.flags = GENL_ADMIN_PERM,
	},
4251 4252 4253 4254 4255 4256 4257 4258 4259 4260 4261 4262 4263 4264 4265 4266 4267 4268
	{
		.cmd = NL80211_CMD_SET_BEACON,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
		.doit = nl80211_addset_beacon,
	},
	{
		.cmd = NL80211_CMD_NEW_BEACON,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
		.doit = nl80211_addset_beacon,
	},
	{
		.cmd = NL80211_CMD_DEL_BEACON,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
		.doit = nl80211_del_beacon,
	},
4269 4270 4271
	{
		.cmd = NL80211_CMD_GET_STATION,
		.doit = nl80211_get_station,
4272
		.dumpit = nl80211_dump_station,
4273 4274 4275 4276 4277 4278 4279 4280 4281 4282 4283 4284 4285 4286 4287 4288 4289 4290
		.policy = nl80211_policy,
	},
	{
		.cmd = NL80211_CMD_SET_STATION,
		.doit = nl80211_set_station,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_NEW_STATION,
		.doit = nl80211_new_station,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DEL_STATION,
		.doit = nl80211_del_station,
		.policy = nl80211_policy,
4291 4292 4293 4294 4295 4296 4297 4298 4299 4300 4301 4302 4303 4304 4305 4306 4307 4308 4309 4310 4311 4312 4313 4314 4315
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_GET_MPATH,
		.doit = nl80211_get_mpath,
		.dumpit = nl80211_dump_mpath,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_SET_MPATH,
		.doit = nl80211_set_mpath,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_NEW_MPATH,
		.doit = nl80211_new_mpath,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DEL_MPATH,
		.doit = nl80211_del_mpath,
		.policy = nl80211_policy,
4316 4317 4318 4319 4320 4321
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_SET_BSS,
		.doit = nl80211_set_bss,
		.policy = nl80211_policy,
4322 4323
		.flags = GENL_ADMIN_PERM,
	},
4324 4325 4326 4327 4328 4329
	{
		.cmd = NL80211_CMD_GET_REG,
		.doit = nl80211_get_reg,
		.policy = nl80211_policy,
		/* can be retrieved by unprivileged users */
	},
4330 4331 4332 4333 4334 4335 4336 4337 4338 4339
	{
		.cmd = NL80211_CMD_SET_REG,
		.doit = nl80211_set_reg,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_REQ_SET_REG,
		.doit = nl80211_req_set_reg,
		.policy = nl80211_policy,
4340 4341 4342 4343 4344 4345 4346 4347 4348 4349 4350 4351
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_GET_MESH_PARAMS,
		.doit = nl80211_get_mesh_params,
		.policy = nl80211_policy,
		/* can be retrieved by unprivileged users */
	},
	{
		.cmd = NL80211_CMD_SET_MESH_PARAMS,
		.doit = nl80211_set_mesh_params,
		.policy = nl80211_policy,
4352 4353
		.flags = GENL_ADMIN_PERM,
	},
4354 4355 4356 4357 4358 4359 4360 4361 4362 4363 4364
	{
		.cmd = NL80211_CMD_TRIGGER_SCAN,
		.doit = nl80211_trigger_scan,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_GET_SCAN,
		.policy = nl80211_policy,
		.dumpit = nl80211_dump_scan,
	},
4365 4366 4367 4368 4369 4370 4371 4372 4373 4374 4375 4376 4377 4378 4379 4380 4381 4382 4383 4384 4385 4386 4387 4388
	{
		.cmd = NL80211_CMD_AUTHENTICATE,
		.doit = nl80211_authenticate,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_ASSOCIATE,
		.doit = nl80211_associate,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DEAUTHENTICATE,
		.doit = nl80211_deauthenticate,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DISASSOCIATE,
		.doit = nl80211_disassociate,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
J
Johannes Berg 已提交
4389 4390 4391 4392 4393 4394 4395 4396 4397 4398 4399 4400
	{
		.cmd = NL80211_CMD_JOIN_IBSS,
		.doit = nl80211_join_ibss,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_LEAVE_IBSS,
		.doit = nl80211_leave_ibss,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
4401 4402 4403 4404 4405 4406 4407 4408
#ifdef CONFIG_NL80211_TESTMODE
	{
		.cmd = NL80211_CMD_TESTMODE,
		.doit = nl80211_testmode_do,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
#endif
S
Samuel Ortiz 已提交
4409 4410 4411 4412 4413 4414 4415 4416 4417 4418 4419 4420
	{
		.cmd = NL80211_CMD_CONNECT,
		.doit = nl80211_connect,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
	{
		.cmd = NL80211_CMD_DISCONNECT,
		.doit = nl80211_disconnect,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
4421 4422 4423 4424 4425 4426
	{
		.cmd = NL80211_CMD_SET_WIPHY_NETNS,
		.doit = nl80211_wiphy_netns,
		.policy = nl80211_policy,
		.flags = GENL_ADMIN_PERM,
	},
4427 4428 4429 4430 4431
	{
		.cmd = NL80211_CMD_GET_SURVEY,
		.policy = nl80211_policy,
		.dumpit = nl80211_dump_survey,
	},
4432
};
4433 4434 4435
static struct genl_multicast_group nl80211_mlme_mcgrp = {
	.name = "mlme",
};
4436 4437 4438 4439 4440

/* multicast groups */
static struct genl_multicast_group nl80211_config_mcgrp = {
	.name = "config",
};
4441 4442 4443
static struct genl_multicast_group nl80211_scan_mcgrp = {
	.name = "scan",
};
4444 4445 4446
static struct genl_multicast_group nl80211_regulatory_mcgrp = {
	.name = "regulatory",
};
4447 4448 4449 4450 4451 4452 4453

/* notification functions */

void nl80211_notify_dev_rename(struct cfg80211_registered_device *rdev)
{
	struct sk_buff *msg;

4454
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4455 4456 4457 4458 4459 4460 4461 4462
	if (!msg)
		return;

	if (nl80211_send_wiphy(msg, 0, 0, 0, rdev) < 0) {
		nlmsg_free(msg);
		return;
	}

4463 4464
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_config_mcgrp.id, GFP_KERNEL);
4465 4466
}

4467 4468 4469 4470 4471 4472 4473
static int nl80211_add_scan_req(struct sk_buff *msg,
				struct cfg80211_registered_device *rdev)
{
	struct cfg80211_scan_request *req = rdev->scan_req;
	struct nlattr *nest;
	int i;

J
Johannes Berg 已提交
4474 4475
	ASSERT_RDEV_LOCK(rdev);

4476 4477 4478 4479 4480 4481 4482 4483 4484 4485 4486 4487 4488 4489 4490 4491 4492 4493 4494 4495 4496 4497 4498 4499 4500
	if (WARN_ON(!req))
		return 0;

	nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS);
	if (!nest)
		goto nla_put_failure;
	for (i = 0; i < req->n_ssids; i++)
		NLA_PUT(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid);
	nla_nest_end(msg, nest);

	nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES);
	if (!nest)
		goto nla_put_failure;
	for (i = 0; i < req->n_channels; i++)
		NLA_PUT_U32(msg, i, req->channels[i]->center_freq);
	nla_nest_end(msg, nest);

	if (req->ie)
		NLA_PUT(msg, NL80211_ATTR_IE, req->ie_len, req->ie);

	return 0;
 nla_put_failure:
	return -ENOBUFS;
}

4501 4502 4503 4504 4505
static int nl80211_send_scan_msg(struct sk_buff *msg,
				 struct cfg80211_registered_device *rdev,
				 struct net_device *netdev,
				 u32 pid, u32 seq, int flags,
				 u32 cmd)
4506 4507 4508 4509 4510 4511 4512
{
	void *hdr;

	hdr = nl80211hdr_put(msg, pid, seq, flags, cmd);
	if (!hdr)
		return -1;

4513
	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
4514 4515
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);

4516 4517
	/* ignore errors and send incomplete event anyway */
	nl80211_add_scan_req(msg, rdev);
4518 4519 4520 4521 4522 4523 4524 4525

	return genlmsg_end(msg, hdr);

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	return -EMSGSIZE;
}

4526 4527 4528 4529 4530 4531 4532 4533 4534 4535 4536 4537 4538 4539 4540
void nl80211_send_scan_start(struct cfg80211_registered_device *rdev,
			     struct net_device *netdev)
{
	struct sk_buff *msg;

	msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
	if (!msg)
		return;

	if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
				  NL80211_CMD_TRIGGER_SCAN) < 0) {
		nlmsg_free(msg);
		return;
	}

4541 4542
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_scan_mcgrp.id, GFP_KERNEL);
4543 4544
}

4545 4546 4547 4548 4549
void nl80211_send_scan_done(struct cfg80211_registered_device *rdev,
			    struct net_device *netdev)
{
	struct sk_buff *msg;

4550
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4551 4552 4553
	if (!msg)
		return;

4554 4555
	if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
				  NL80211_CMD_NEW_SCAN_RESULTS) < 0) {
4556 4557 4558 4559
		nlmsg_free(msg);
		return;
	}

4560 4561
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_scan_mcgrp.id, GFP_KERNEL);
4562 4563 4564 4565 4566 4567 4568
}

void nl80211_send_scan_aborted(struct cfg80211_registered_device *rdev,
			       struct net_device *netdev)
{
	struct sk_buff *msg;

4569
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4570 4571 4572
	if (!msg)
		return;

4573 4574
	if (nl80211_send_scan_msg(msg, rdev, netdev, 0, 0, 0,
				  NL80211_CMD_SCAN_ABORTED) < 0) {
4575 4576 4577 4578
		nlmsg_free(msg);
		return;
	}

4579 4580
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_scan_mcgrp.id, GFP_KERNEL);
4581 4582
}

4583 4584 4585 4586 4587 4588 4589 4590 4591
/*
 * This can happen on global regulatory changes or device specific settings
 * based on custom world regulatory domains.
 */
void nl80211_send_reg_change_event(struct regulatory_request *request)
{
	struct sk_buff *msg;
	void *hdr;

4592
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
4593 4594 4595 4596 4597 4598 4599 4600 4601 4602 4603 4604 4605 4606 4607 4608 4609 4610 4611 4612 4613 4614 4615 4616 4617 4618 4619 4620 4621 4622 4623 4624 4625 4626 4627 4628
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_CHANGE);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	/* Userspace can always count this one always being set */
	NLA_PUT_U8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator);

	if (request->alpha2[0] == '0' && request->alpha2[1] == '0')
		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
			   NL80211_REGDOM_TYPE_WORLD);
	else if (request->alpha2[0] == '9' && request->alpha2[1] == '9')
		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
			   NL80211_REGDOM_TYPE_CUSTOM_WORLD);
	else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') ||
		 request->intersect)
		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
			   NL80211_REGDOM_TYPE_INTERSECTION);
	else {
		NLA_PUT_U8(msg, NL80211_ATTR_REG_TYPE,
			   NL80211_REGDOM_TYPE_COUNTRY);
		NLA_PUT_STRING(msg, NL80211_ATTR_REG_ALPHA2, request->alpha2);
	}

	if (wiphy_idx_valid(request->wiphy_idx))
		NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4629
	rcu_read_lock();
4630
	genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
4631 4632
				GFP_ATOMIC);
	rcu_read_unlock();
4633 4634 4635 4636 4637 4638 4639 4640

	return;

nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);
}

4641 4642 4643
static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev,
				    struct net_device *netdev,
				    const u8 *buf, size_t len,
4644
				    enum nl80211_commands cmd, gfp_t gfp)
4645 4646 4647 4648
{
	struct sk_buff *msg;
	void *hdr;

4649
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4650 4651 4652 4653 4654 4655 4656 4657 4658 4659 4660 4661 4662 4663 4664 4665 4666 4667
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	NLA_PUT(msg, NL80211_ATTR_FRAME, len, buf);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4668 4669
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, gfp);
4670 4671 4672 4673 4674 4675 4676 4677
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);
}

void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev,
4678 4679
			  struct net_device *netdev, const u8 *buf,
			  size_t len, gfp_t gfp)
4680 4681
{
	nl80211_send_mlme_event(rdev, netdev, buf, len,
4682
				NL80211_CMD_AUTHENTICATE, gfp);
4683 4684 4685 4686
}

void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev,
			   struct net_device *netdev, const u8 *buf,
4687
			   size_t len, gfp_t gfp)
4688
{
4689 4690
	nl80211_send_mlme_event(rdev, netdev, buf, len,
				NL80211_CMD_ASSOCIATE, gfp);
4691 4692
}

4693
void nl80211_send_deauth(struct cfg80211_registered_device *rdev,
4694 4695
			 struct net_device *netdev, const u8 *buf,
			 size_t len, gfp_t gfp)
4696 4697
{
	nl80211_send_mlme_event(rdev, netdev, buf, len,
4698
				NL80211_CMD_DEAUTHENTICATE, gfp);
4699 4700
}

4701 4702
void nl80211_send_disassoc(struct cfg80211_registered_device *rdev,
			   struct net_device *netdev, const u8 *buf,
4703
			   size_t len, gfp_t gfp)
4704 4705
{
	nl80211_send_mlme_event(rdev, netdev, buf, len,
4706
				NL80211_CMD_DISASSOCIATE, gfp);
4707 4708
}

4709 4710
static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev,
				      struct net_device *netdev, int cmd,
4711
				      const u8 *addr, gfp_t gfp)
4712 4713 4714 4715
{
	struct sk_buff *msg;
	void *hdr;

4716
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4717 4718 4719 4720 4721 4722 4723 4724 4725 4726 4727 4728 4729 4730 4731 4732 4733 4734 4735
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, cmd);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	NLA_PUT_FLAG(msg, NL80211_ATTR_TIMED_OUT);
	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4736 4737
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, gfp);
4738 4739 4740 4741 4742 4743 4744 4745
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);
}

void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev,
4746 4747
			       struct net_device *netdev, const u8 *addr,
			       gfp_t gfp)
4748 4749
{
	nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE,
4750
				  addr, gfp);
4751 4752 4753
}

void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev,
4754 4755
				struct net_device *netdev, const u8 *addr,
				gfp_t gfp)
4756
{
4757 4758
	nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE,
				  addr, gfp);
4759 4760
}

S
Samuel Ortiz 已提交
4761 4762 4763 4764 4765 4766 4767 4768 4769 4770 4771 4772 4773 4774 4775 4776 4777 4778 4779 4780 4781 4782 4783 4784 4785 4786 4787 4788 4789 4790 4791 4792 4793 4794
void nl80211_send_connect_result(struct cfg80211_registered_device *rdev,
				 struct net_device *netdev, const u8 *bssid,
				 const u8 *req_ie, size_t req_ie_len,
				 const u8 *resp_ie, size_t resp_ie_len,
				 u16 status, gfp_t gfp)
{
	struct sk_buff *msg;
	void *hdr;

	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	if (bssid)
		NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
	NLA_PUT_U16(msg, NL80211_ATTR_STATUS_CODE, status);
	if (req_ie)
		NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
	if (resp_ie)
		NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4795 4796
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, gfp);
S
Samuel Ortiz 已提交
4797 4798 4799 4800 4801 4802 4803 4804 4805 4806 4807 4808 4809 4810 4811 4812 4813 4814 4815 4816 4817 4818 4819 4820 4821 4822 4823 4824 4825 4826 4827 4828 4829 4830 4831 4832 4833 4834 4835
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);

}

void nl80211_send_roamed(struct cfg80211_registered_device *rdev,
			 struct net_device *netdev, const u8 *bssid,
			 const u8 *req_ie, size_t req_ie_len,
			 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp)
{
	struct sk_buff *msg;
	void *hdr;

	msg = nlmsg_new(NLMSG_GOODSIZE, gfp);
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);
	if (req_ie)
		NLA_PUT(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie);
	if (resp_ie)
		NLA_PUT(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4836 4837
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, gfp);
S
Samuel Ortiz 已提交
4838 4839 4840 4841 4842 4843 4844 4845 4846 4847
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);

}

void nl80211_send_disconnected(struct cfg80211_registered_device *rdev,
			       struct net_device *netdev, u16 reason,
J
Johannes Berg 已提交
4848
			       const u8 *ie, size_t ie_len, bool from_ap)
S
Samuel Ortiz 已提交
4849 4850 4851 4852
{
	struct sk_buff *msg;
	void *hdr;

J
Johannes Berg 已提交
4853
	msg = nlmsg_new(NLMSG_GOODSIZE, GFP_KERNEL);
S
Samuel Ortiz 已提交
4854 4855 4856 4857 4858 4859 4860 4861 4862 4863 4864 4865 4866 4867 4868 4869 4870 4871 4872 4873 4874 4875 4876
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	if (from_ap && reason)
		NLA_PUT_U16(msg, NL80211_ATTR_REASON_CODE, reason);
	if (from_ap)
		NLA_PUT_FLAG(msg, NL80211_ATTR_DISCONNECTED_BY_AP);
	if (ie)
		NLA_PUT(msg, NL80211_ATTR_IE, ie_len, ie);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4877 4878
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, GFP_KERNEL);
S
Samuel Ortiz 已提交
4879 4880 4881 4882 4883 4884 4885 4886
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);

}

J
Johannes Berg 已提交
4887 4888 4889 4890 4891 4892 4893
void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev,
			     struct net_device *netdev, const u8 *bssid,
			     gfp_t gfp)
{
	struct sk_buff *msg;
	void *hdr;

4894
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
J
Johannes Berg 已提交
4895 4896 4897 4898 4899 4900 4901 4902 4903 4904 4905 4906 4907 4908 4909 4910 4911 4912
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4913 4914
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, gfp);
J
Johannes Berg 已提交
4915 4916 4917 4918 4919 4920 4921
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);
}

4922 4923 4924
void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev,
				 struct net_device *netdev, const u8 *addr,
				 enum nl80211_key_type key_type, int key_id,
4925
				 const u8 *tsc, gfp_t gfp)
4926 4927 4928 4929
{
	struct sk_buff *msg;
	void *hdr;

4930
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp);
4931 4932 4933 4934 4935 4936 4937 4938 4939 4940 4941 4942 4943 4944 4945 4946 4947 4948 4949 4950 4951 4952 4953
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx);
	NLA_PUT_U32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex);
	if (addr)
		NLA_PUT(msg, NL80211_ATTR_MAC, ETH_ALEN, addr);
	NLA_PUT_U32(msg, NL80211_ATTR_KEY_TYPE, key_type);
	NLA_PUT_U8(msg, NL80211_ATTR_KEY_IDX, key_id);
	if (tsc)
		NLA_PUT(msg, NL80211_ATTR_KEY_SEQ, 6, tsc);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

4954 4955
	genlmsg_multicast_netns(wiphy_net(&rdev->wiphy), msg, 0,
				nl80211_mlme_mcgrp.id, gfp);
4956 4957 4958 4959 4960 4961 4962
	return;

 nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);
}

4963 4964 4965 4966 4967 4968 4969 4970
void nl80211_send_beacon_hint_event(struct wiphy *wiphy,
				    struct ieee80211_channel *channel_before,
				    struct ieee80211_channel *channel_after)
{
	struct sk_buff *msg;
	void *hdr;
	struct nlattr *nl_freq;

4971
	msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC);
4972 4973 4974 4975 4976 4977 4978 4979 4980 4981 4982 4983 4984 4985 4986 4987 4988 4989 4990 4991 4992 4993 4994 4995 4996 4997 4998 4999 5000 5001 5002 5003 5004 5005 5006 5007
	if (!msg)
		return;

	hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT);
	if (!hdr) {
		nlmsg_free(msg);
		return;
	}

	/*
	 * Since we are applying the beacon hint to a wiphy we know its
	 * wiphy_idx is valid
	 */
	NLA_PUT_U32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy));

	/* Before */
	nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE);
	if (!nl_freq)
		goto nla_put_failure;
	if (nl80211_msg_put_channel(msg, channel_before))
		goto nla_put_failure;
	nla_nest_end(msg, nl_freq);

	/* After */
	nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER);
	if (!nl_freq)
		goto nla_put_failure;
	if (nl80211_msg_put_channel(msg, channel_after))
		goto nla_put_failure;
	nla_nest_end(msg, nl_freq);

	if (genlmsg_end(msg, hdr) < 0) {
		nlmsg_free(msg);
		return;
	}

5008 5009 5010 5011
	rcu_read_lock();
	genlmsg_multicast_allns(msg, 0, nl80211_regulatory_mcgrp.id,
				GFP_ATOMIC);
	rcu_read_unlock();
5012 5013 5014 5015 5016 5017 5018 5019

	return;

nla_put_failure:
	genlmsg_cancel(msg, hdr);
	nlmsg_free(msg);
}

5020 5021 5022 5023
/* initialisation/exit functions */

int nl80211_init(void)
{
5024
	int err;
5025

5026 5027
	err = genl_register_family_with_ops(&nl80211_fam,
		nl80211_ops, ARRAY_SIZE(nl80211_ops));
5028 5029 5030 5031 5032 5033 5034
	if (err)
		return err;

	err = genl_register_mc_group(&nl80211_fam, &nl80211_config_mcgrp);
	if (err)
		goto err_out;

5035 5036 5037 5038
	err = genl_register_mc_group(&nl80211_fam, &nl80211_scan_mcgrp);
	if (err)
		goto err_out;

5039 5040 5041 5042
	err = genl_register_mc_group(&nl80211_fam, &nl80211_regulatory_mcgrp);
	if (err)
		goto err_out;

5043 5044 5045 5046
	err = genl_register_mc_group(&nl80211_fam, &nl80211_mlme_mcgrp);
	if (err)
		goto err_out;

5047 5048 5049 5050 5051 5052
#ifdef CONFIG_NL80211_TESTMODE
	err = genl_register_mc_group(&nl80211_fam, &nl80211_testmode_mcgrp);
	if (err)
		goto err_out;
#endif

5053 5054 5055 5056 5057 5058 5059 5060 5061 5062
	return 0;
 err_out:
	genl_unregister_family(&nl80211_fam);
	return err;
}

void nl80211_exit(void)
{
	genl_unregister_family(&nl80211_fam);
}