rx.c 101.9 KB
Newer Older
1 2 3 4
/*
 * Copyright 2002-2005, Instant802 Networks, Inc.
 * Copyright 2005-2006, Devicescape Software, Inc.
 * Copyright 2006-2007	Jiri Benc <jbenc@suse.cz>
5
 * Copyright 2007-2010	Johannes Berg <johannes@sipsolutions.net>
6
 * Copyright 2013-2014  Intel Mobile Communications GmbH
7 8 9 10 11 12
 *
 * This program is free software; you can redistribute it and/or modify
 * it under the terms of the GNU General Public License version 2 as
 * published by the Free Software Foundation.
 */

13
#include <linux/jiffies.h>
14
#include <linux/slab.h>
15 16 17 18
#include <linux/kernel.h>
#include <linux/skbuff.h>
#include <linux/netdevice.h>
#include <linux/etherdevice.h>
19
#include <linux/rcupdate.h>
20
#include <linux/export.h>
21 22
#include <net/mac80211.h>
#include <net/ieee80211_radiotap.h>
23
#include <asm/unaligned.h>
24 25

#include "ieee80211_i.h"
26
#include "driver-ops.h"
J
Johannes Berg 已提交
27
#include "led.h"
28
#include "mesh.h"
29 30 31 32
#include "wep.h"
#include "wpa.h"
#include "tkip.h"
#include "wme.h"
33
#include "rate.h"
34

35 36 37 38 39 40 41 42 43 44
static inline void ieee80211_rx_stats(struct net_device *dev, u32 len)
{
	struct pcpu_sw_netstats *tstats = this_cpu_ptr(dev->tstats);

	u64_stats_update_begin(&tstats->syncp);
	tstats->rx_packets++;
	tstats->rx_bytes += len;
	u64_stats_update_end(&tstats->syncp);
}

45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89
static u8 *ieee80211_get_bssid(struct ieee80211_hdr *hdr, size_t len,
			       enum nl80211_iftype type)
{
	__le16 fc = hdr->frame_control;

	if (ieee80211_is_data(fc)) {
		if (len < 24) /* drop incorrect hdr len (data) */
			return NULL;

		if (ieee80211_has_a4(fc))
			return NULL;
		if (ieee80211_has_tods(fc))
			return hdr->addr1;
		if (ieee80211_has_fromds(fc))
			return hdr->addr2;

		return hdr->addr3;
	}

	if (ieee80211_is_mgmt(fc)) {
		if (len < 24) /* drop incorrect hdr len (mgmt) */
			return NULL;
		return hdr->addr3;
	}

	if (ieee80211_is_ctl(fc)) {
		if (ieee80211_is_pspoll(fc))
			return hdr->addr1;

		if (ieee80211_is_back_req(fc)) {
			switch (type) {
			case NL80211_IFTYPE_STATION:
				return hdr->addr2;
			case NL80211_IFTYPE_AP:
			case NL80211_IFTYPE_AP_VLAN:
				return hdr->addr1;
			default:
				break; /* fall through to the return */
			}
		}
	}

	return NULL;
}

90 91 92 93 94 95 96
/*
 * monitor mode reception
 *
 * This function cleans up the SKB, i.e. it removes all the stuff
 * only useful for monitoring.
 */
static struct sk_buff *remove_monitor_info(struct ieee80211_local *local,
97 98
					   struct sk_buff *skb,
					   unsigned int rtap_vendor_space)
99
{
100
	if (ieee80211_hw_check(&local->hw, RX_INCLUDES_FCS)) {
101
		if (likely(skb->len > FCS_LEN))
Z
Zhu Yi 已提交
102
			__pskb_trim(skb, skb->len - FCS_LEN);
103 104 105 106
		else {
			/* driver bug */
			WARN_ON(1);
			dev_kfree_skb(skb);
107
			return NULL;
108 109 110
		}
	}

111 112
	__pskb_pull(skb, rtap_vendor_space);

113 114 115
	return skb;
}

116 117
static inline bool should_drop_frame(struct sk_buff *skb, int present_fcs_len,
				     unsigned int rtap_vendor_space)
118
{
119
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
120 121 122
	struct ieee80211_hdr *hdr;

	hdr = (void *)(skb->data + rtap_vendor_space);
123

124
	if (status->flag & (RX_FLAG_FAILED_FCS_CRC |
125 126
			    RX_FLAG_FAILED_PLCP_CRC |
			    RX_FLAG_ONLY_MONITOR))
127 128
		return true;

129
	if (unlikely(skb->len < 16 + present_fcs_len + rtap_vendor_space))
130 131
		return true;

H
Harvey Harrison 已提交
132 133 134
	if (ieee80211_is_ctl(hdr->frame_control) &&
	    !ieee80211_is_pspoll(hdr->frame_control) &&
	    !ieee80211_is_back_req(hdr->frame_control))
135 136 137
		return true;

	return false;
138 139
}

140
static int
141 142 143
ieee80211_rx_radiotap_hdrlen(struct ieee80211_local *local,
			     struct ieee80211_rx_status *status,
			     struct sk_buff *skb)
144 145 146 147
{
	int len;

	/* always present fields */
148
	len = sizeof(struct ieee80211_radiotap_header) + 8;
149

150 151 152
	/* allocate extra bitmaps */
	if (status->chains)
		len += 4 * hweight8(status->chains);
153 154 155

	if (ieee80211_have_rx_timestamp(status)) {
		len = ALIGN(len, 8);
156
		len += 8;
157
	}
158
	if (ieee80211_hw_check(&local->hw, SIGNAL_DBM))
159 160
		len += 1;

161 162 163 164
	/* antenna field, if we don't have per-chain info */
	if (!status->chains)
		len += 1;

165 166
	/* padding for RX_FLAGS if necessary */
	len = ALIGN(len, 2);
167

168 169 170
	if (status->flag & RX_FLAG_HT) /* HT info */
		len += 3;

171
	if (status->flag & RX_FLAG_AMPDU_DETAILS) {
172
		len = ALIGN(len, 4);
173 174 175
		len += 8;
	}

176 177 178 179 180
	if (status->flag & RX_FLAG_VHT) {
		len = ALIGN(len, 2);
		len += 12;
	}

181 182 183 184 185
	if (status->chains) {
		/* antenna and antenna signal fields */
		len += 2 * hweight8(status->chains);
	}

186 187 188 189 190 191 192 193 194 195 196 197 198 199 200
	if (status->flag & RX_FLAG_RADIOTAP_VENDOR_DATA) {
		struct ieee80211_vendor_radiotap *rtap = (void *)skb->data;

		/* vendor presence bitmap */
		len += 4;
		/* alignment for fixed 6-byte vendor data header */
		len = ALIGN(len, 2);
		/* vendor data header */
		len += 6;
		if (WARN_ON(rtap->align == 0))
			rtap->align = 1;
		len = ALIGN(len, rtap->align);
		len += rtap->len + rtap->pad;
	}

201 202 203
	return len;
}

204
/*
205 206 207 208 209 210 211 212
 * ieee80211_add_rx_radiotap_header - add radiotap header
 *
 * add a radiotap header containing all the fields which the hardware provided.
 */
static void
ieee80211_add_rx_radiotap_header(struct ieee80211_local *local,
				 struct sk_buff *skb,
				 struct ieee80211_rate *rate,
213
				 int rtap_len, bool has_fcs)
214
{
215
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
216 217
	struct ieee80211_radiotap_header *rthdr;
	unsigned char *pos;
218 219
	__le32 *it_present;
	u32 it_present_val;
220
	u16 rx_flags = 0;
221
	u16 channel_flags = 0;
222 223
	int mpdulen, chain;
	unsigned long chains = status->chains;
224 225 226 227 228 229 230
	struct ieee80211_vendor_radiotap rtap = {};

	if (status->flag & RX_FLAG_RADIOTAP_VENDOR_DATA) {
		rtap = *(struct ieee80211_vendor_radiotap *)skb->data;
		/* rtap.len and rtap.pad are undone immediately */
		skb_pull(skb, sizeof(rtap) + rtap.len + rtap.pad);
	}
231 232

	mpdulen = skb->len;
233
	if (!(has_fcs && ieee80211_hw_check(&local->hw, RX_INCLUDES_FCS)))
234
		mpdulen += FCS_LEN;
235 236

	rthdr = (struct ieee80211_radiotap_header *)skb_push(skb, rtap_len);
237
	memset(rthdr, 0, rtap_len - rtap.len - rtap.pad);
238
	it_present = &rthdr->it_present;
239 240

	/* radiotap header, set always present flags */
241
	rthdr->it_len = cpu_to_le16(rtap_len);
242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257
	it_present_val = BIT(IEEE80211_RADIOTAP_FLAGS) |
			 BIT(IEEE80211_RADIOTAP_CHANNEL) |
			 BIT(IEEE80211_RADIOTAP_RX_FLAGS);

	if (!status->chains)
		it_present_val |= BIT(IEEE80211_RADIOTAP_ANTENNA);

	for_each_set_bit(chain, &chains, IEEE80211_MAX_CHAINS) {
		it_present_val |=
			BIT(IEEE80211_RADIOTAP_EXT) |
			BIT(IEEE80211_RADIOTAP_RADIOTAP_NAMESPACE);
		put_unaligned_le32(it_present_val, it_present);
		it_present++;
		it_present_val = BIT(IEEE80211_RADIOTAP_ANTENNA) |
				 BIT(IEEE80211_RADIOTAP_DBM_ANTSIGNAL);
	}
258

259 260 261 262 263 264 265 266
	if (status->flag & RX_FLAG_RADIOTAP_VENDOR_DATA) {
		it_present_val |= BIT(IEEE80211_RADIOTAP_VENDOR_NAMESPACE) |
				  BIT(IEEE80211_RADIOTAP_EXT);
		put_unaligned_le32(it_present_val, it_present);
		it_present++;
		it_present_val = rtap.present;
	}

267 268 269 270
	put_unaligned_le32(it_present_val, it_present);

	pos = (void *)(it_present + 1);

271 272 273
	/* the order of the following fields is important */

	/* IEEE80211_RADIOTAP_TSFT */
274
	if (ieee80211_have_rx_timestamp(status)) {
275 276 277
		/* padding */
		while ((pos - (u8 *)rthdr) & 7)
			*pos++ = 0;
278 279 280 281
		put_unaligned_le64(
			ieee80211_calculate_rx_timestamp(local, status,
							 mpdulen, 0),
			pos);
J
Johannes Berg 已提交
282
		rthdr->it_present |= cpu_to_le32(1 << IEEE80211_RADIOTAP_TSFT);
283 284 285 286
		pos += 8;
	}

	/* IEEE80211_RADIOTAP_FLAGS */
287
	if (has_fcs && ieee80211_hw_check(&local->hw, RX_INCLUDES_FCS))
288
		*pos |= IEEE80211_RADIOTAP_F_FCS;
J
Johannes Berg 已提交
289 290
	if (status->flag & (RX_FLAG_FAILED_FCS_CRC | RX_FLAG_FAILED_PLCP_CRC))
		*pos |= IEEE80211_RADIOTAP_F_BADFCS;
291 292
	if (status->flag & RX_FLAG_SHORTPRE)
		*pos |= IEEE80211_RADIOTAP_F_SHORTPRE;
293 294 295
	pos++;

	/* IEEE80211_RADIOTAP_RATE */
296
	if (!rate || status->flag & (RX_FLAG_HT | RX_FLAG_VHT)) {
297
		/*
298
		 * Without rate information don't add it. If we have,
299
		 * MCS information is a separate field in radiotap,
300 301
		 * added below. The byte here is needed as padding
		 * for the channel though, so initialise it to 0.
302 303
		 */
		*pos = 0;
304
	} else {
305
		int shift = 0;
306
		rthdr->it_present |= cpu_to_le32(1 << IEEE80211_RADIOTAP_RATE);
307 308 309 310 311
		if (status->flag & RX_FLAG_10MHZ)
			shift = 1;
		else if (status->flag & RX_FLAG_5MHZ)
			shift = 2;
		*pos = DIV_ROUND_UP(rate->bitrate, 5 * (1 << shift));
312
	}
313 314 315
	pos++;

	/* IEEE80211_RADIOTAP_CHANNEL */
316
	put_unaligned_le16(status->freq, pos);
317
	pos += 2;
318 319 320 321 322
	if (status->flag & RX_FLAG_10MHZ)
		channel_flags |= IEEE80211_CHAN_HALF;
	else if (status->flag & RX_FLAG_5MHZ)
		channel_flags |= IEEE80211_CHAN_QUARTER;

323
	if (status->band == IEEE80211_BAND_5GHZ)
324
		channel_flags |= IEEE80211_CHAN_OFDM | IEEE80211_CHAN_5GHZ;
325
	else if (status->flag & (RX_FLAG_HT | RX_FLAG_VHT))
326
		channel_flags |= IEEE80211_CHAN_DYN | IEEE80211_CHAN_2GHZ;
327
	else if (rate && rate->flags & IEEE80211_RATE_ERP_G)
328
		channel_flags |= IEEE80211_CHAN_OFDM | IEEE80211_CHAN_2GHZ;
329
	else if (rate)
330
		channel_flags |= IEEE80211_CHAN_CCK | IEEE80211_CHAN_2GHZ;
331
	else
332 333
		channel_flags |= IEEE80211_CHAN_2GHZ;
	put_unaligned_le16(channel_flags, pos);
334 335 336
	pos += 2;

	/* IEEE80211_RADIOTAP_DBM_ANTSIGNAL */
337
	if (ieee80211_hw_check(&local->hw, SIGNAL_DBM) &&
338
	    !(status->flag & RX_FLAG_NO_SIGNAL_VAL)) {
339 340 341 342 343 344 345 346
		*pos = status->signal;
		rthdr->it_present |=
			cpu_to_le32(1 << IEEE80211_RADIOTAP_DBM_ANTSIGNAL);
		pos++;
	}

	/* IEEE80211_RADIOTAP_LOCK_QUALITY is missing */

347 348 349 350 351
	if (!status->chains) {
		/* IEEE80211_RADIOTAP_ANTENNA */
		*pos = status->antenna;
		pos++;
	}
352 353 354 355 356

	/* IEEE80211_RADIOTAP_DB_ANTNOISE is not used */

	/* IEEE80211_RADIOTAP_RX_FLAGS */
	/* ensure 2 byte alignment for the 2 byte field as required */
357
	if ((pos - (u8 *)rthdr) & 1)
358
		*pos++ = 0;
J
Johannes Berg 已提交
359
	if (status->flag & RX_FLAG_FAILED_PLCP_CRC)
360 361
		rx_flags |= IEEE80211_RADIOTAP_F_RX_BADPLCP;
	put_unaligned_le16(rx_flags, pos);
362
	pos += 2;
363 364

	if (status->flag & RX_FLAG_HT) {
365 366
		unsigned int stbc;

367
		rthdr->it_present |= cpu_to_le32(1 << IEEE80211_RADIOTAP_MCS);
368
		*pos++ = local->hw.radiotap_mcs_details;
369 370 371 372 373
		*pos = 0;
		if (status->flag & RX_FLAG_SHORT_GI)
			*pos |= IEEE80211_RADIOTAP_MCS_SGI;
		if (status->flag & RX_FLAG_40MHZ)
			*pos |= IEEE80211_RADIOTAP_MCS_BW_40;
374 375
		if (status->flag & RX_FLAG_HT_GF)
			*pos |= IEEE80211_RADIOTAP_MCS_FMT_GF;
376 377
		if (status->flag & RX_FLAG_LDPC)
			*pos |= IEEE80211_RADIOTAP_MCS_FEC_LDPC;
378 379
		stbc = (status->flag & RX_FLAG_STBC_MASK) >> RX_FLAG_STBC_SHIFT;
		*pos |= stbc << IEEE80211_RADIOTAP_MCS_STBC_SHIFT;
380 381 382
		pos++;
		*pos++ = status->rate_idx;
	}
383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409

	if (status->flag & RX_FLAG_AMPDU_DETAILS) {
		u16 flags = 0;

		/* ensure 4 byte alignment */
		while ((pos - (u8 *)rthdr) & 3)
			pos++;
		rthdr->it_present |=
			cpu_to_le32(1 << IEEE80211_RADIOTAP_AMPDU_STATUS);
		put_unaligned_le32(status->ampdu_reference, pos);
		pos += 4;
		if (status->flag & RX_FLAG_AMPDU_LAST_KNOWN)
			flags |= IEEE80211_RADIOTAP_AMPDU_LAST_KNOWN;
		if (status->flag & RX_FLAG_AMPDU_IS_LAST)
			flags |= IEEE80211_RADIOTAP_AMPDU_IS_LAST;
		if (status->flag & RX_FLAG_AMPDU_DELIM_CRC_ERROR)
			flags |= IEEE80211_RADIOTAP_AMPDU_DELIM_CRC_ERR;
		if (status->flag & RX_FLAG_AMPDU_DELIM_CRC_KNOWN)
			flags |= IEEE80211_RADIOTAP_AMPDU_DELIM_CRC_KNOWN;
		put_unaligned_le16(flags, pos);
		pos += 2;
		if (status->flag & RX_FLAG_AMPDU_DELIM_CRC_KNOWN)
			*pos++ = status->ampdu_delimiter_crc;
		else
			*pos++ = 0;
		*pos++ = 0;
	}
410

411 412 413 414 415 416 417 418 419
	if (status->flag & RX_FLAG_VHT) {
		u16 known = local->hw.radiotap_vht_details;

		rthdr->it_present |= cpu_to_le32(1 << IEEE80211_RADIOTAP_VHT);
		put_unaligned_le16(known, pos);
		pos += 2;
		/* flags */
		if (status->flag & RX_FLAG_SHORT_GI)
			*pos |= IEEE80211_RADIOTAP_VHT_FLAG_SGI;
420 421 422
		/* in VHT, STBC is binary */
		if (status->flag & RX_FLAG_STBC_MASK)
			*pos |= IEEE80211_RADIOTAP_VHT_FLAG_STBC;
423 424
		if (status->vht_flag & RX_VHT_FLAG_BF)
			*pos |= IEEE80211_RADIOTAP_VHT_FLAG_BEAMFORMED;
425 426
		pos++;
		/* bandwidth */
427
		if (status->vht_flag & RX_VHT_FLAG_80MHZ)
428
			*pos++ = 4;
429
		else if (status->vht_flag & RX_VHT_FLAG_160MHZ)
430 431 432 433 434 435 436 437 438
			*pos++ = 11;
		else if (status->flag & RX_FLAG_40MHZ)
			*pos++ = 1;
		else /* 20 MHz */
			*pos++ = 0;
		/* MCS/NSS */
		*pos = (status->rate_idx << 4) | status->vht_nss;
		pos += 4;
		/* coding field */
439 440
		if (status->flag & RX_FLAG_LDPC)
			*pos |= IEEE80211_RADIOTAP_CODING_LDPC_USER0;
441 442 443 444 445 446 447
		pos++;
		/* group ID */
		pos++;
		/* partial_aid */
		pos += 2;
	}

448 449 450 451
	for_each_set_bit(chain, &chains, IEEE80211_MAX_CHAINS) {
		*pos++ = status->chain_signal[chain];
		*pos++ = chain;
	}
452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467

	if (status->flag & RX_FLAG_RADIOTAP_VENDOR_DATA) {
		/* ensure 2 byte alignment for the vendor field as required */
		if ((pos - (u8 *)rthdr) & 1)
			*pos++ = 0;
		*pos++ = rtap.oui[0];
		*pos++ = rtap.oui[1];
		*pos++ = rtap.oui[2];
		*pos++ = rtap.subns;
		put_unaligned_le16(rtap.len, pos);
		pos += 2;
		/* align the actual payload as requested */
		while ((pos - (u8 *)rthdr) & (rtap.align - 1))
			*pos++ = 0;
		/* data (and possible padding) already follows */
	}
468 469
}

470 471 472 473 474 475 476
/*
 * This function copies a received frame to all monitor interfaces and
 * returns a cleaned-up SKB that no longer includes the FCS nor the
 * radiotap header the driver might have added.
 */
static struct sk_buff *
ieee80211_rx_monitor(struct ieee80211_local *local, struct sk_buff *origskb,
477
		     struct ieee80211_rate *rate)
478
{
479
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(origskb);
480
	struct ieee80211_sub_if_data *sdata;
481
	int rt_hdrlen, needed_headroom;
482 483 484
	struct sk_buff *skb, *skb2;
	struct net_device *prev_dev = NULL;
	int present_fcs_len = 0;
485 486 487 488 489 490 491
	unsigned int rtap_vendor_space = 0;

	if (unlikely(status->flag & RX_FLAG_RADIOTAP_VENDOR_DATA)) {
		struct ieee80211_vendor_radiotap *rtap = (void *)origskb->data;

		rtap_vendor_space = sizeof(*rtap) + rtap->len + rtap->pad;
	}
492 493 494 495 496 497 498 499 500

	/*
	 * First, we may need to make a copy of the skb because
	 *  (1) we need to modify it for radiotap (if not present), and
	 *  (2) the other RX handlers will modify the skb we got.
	 *
	 * We don't need to, of course, if we aren't going to return
	 * the SKB because it has a bad FCS/PLCP checksum.
	 */
J
Johannes Berg 已提交
501

502
	if (ieee80211_hw_check(&local->hw, RX_INCLUDES_FCS))
503 504
		present_fcs_len = FCS_LEN;

505 506
	/* ensure hdr->frame_control and vendor radiotap data are in skb head */
	if (!pskb_may_pull(origskb, 2 + rtap_vendor_space)) {
Z
Zhu Yi 已提交
507 508 509 510
		dev_kfree_skb(origskb);
		return NULL;
	}

511
	if (!local->monitors || (status->flag & RX_FLAG_SKIP_MONITOR)) {
512 513
		if (should_drop_frame(origskb, present_fcs_len,
				      rtap_vendor_space)) {
514 515 516 517
			dev_kfree_skb(origskb);
			return NULL;
		}

518
		return remove_monitor_info(local, origskb, rtap_vendor_space);
519 520
	}

521
	/* room for the radiotap header based on driver features */
522 523
	rt_hdrlen = ieee80211_rx_radiotap_hdrlen(local, status, origskb);
	needed_headroom = rt_hdrlen - rtap_vendor_space;
524

525
	if (should_drop_frame(origskb, present_fcs_len, rtap_vendor_space)) {
526 527 528 529 530 531 532 533 534 535 536 537
		/* only need to expand headroom if necessary */
		skb = origskb;
		origskb = NULL;

		/*
		 * This shouldn't trigger often because most devices have an
		 * RX header they pull before we get here, and that should
		 * be big enough for our radiotap information. We should
		 * probably export the length to drivers so that we can have
		 * them allocate enough headroom to start with.
		 */
		if (skb_headroom(skb) < needed_headroom &&
538
		    pskb_expand_head(skb, needed_headroom, 0, GFP_ATOMIC)) {
539 540 541 542 543 544 545 546 547 548
			dev_kfree_skb(skb);
			return NULL;
		}
	} else {
		/*
		 * Need to make a copy and possibly remove radiotap header
		 * and FCS from the original.
		 */
		skb = skb_copy_expand(origskb, needed_headroom, 0, GFP_ATOMIC);

549 550
		origskb = remove_monitor_info(local, origskb,
					      rtap_vendor_space);
551 552 553 554 555

		if (!skb)
			return origskb;
	}

J
Johannes Berg 已提交
556
	/* prepend radiotap information */
557
	ieee80211_add_rx_radiotap_header(local, skb, rate, rt_hdrlen, true);
558

559
	skb_reset_mac_header(skb);
560 561 562 563 564
	skb->ip_summed = CHECKSUM_UNNECESSARY;
	skb->pkt_type = PACKET_OTHERHOST;
	skb->protocol = htons(ETH_P_802_2);

	list_for_each_entry_rcu(sdata, &local->interfaces, list) {
565
		if (sdata->vif.type != NL80211_IFTYPE_MONITOR)
566 567
			continue;

568 569 570
		if (sdata->u.mntr_flags & MONITOR_FLAG_COOK_FRAMES)
			continue;

571
		if (!ieee80211_sdata_running(sdata))
572 573
			continue;

574 575 576 577
		if (prev_dev) {
			skb2 = skb_clone(skb, GFP_ATOMIC);
			if (skb2) {
				skb2->dev = prev_dev;
578
				netif_receive_skb(skb2);
579 580 581 582
			}
		}

		prev_dev = sdata->dev;
583
		ieee80211_rx_stats(sdata->dev, skb->len);
584 585 586 587
	}

	if (prev_dev) {
		skb->dev = prev_dev;
588
		netif_receive_skb(skb);
589 590 591 592 593 594
	} else
		dev_kfree_skb(skb);

	return origskb;
}

595
static void ieee80211_parse_qos(struct ieee80211_rx_data *rx)
596
{
597
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
598
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
599
	int tid, seqno_idx, security_idx;
600 601

	/* does the frame have a qos control field? */
602 603
	if (ieee80211_is_data_qos(hdr->frame_control)) {
		u8 *qc = ieee80211_get_qos_ctl(hdr);
604
		/* frame has qos control */
605
		tid = *qc & IEEE80211_QOS_CTL_TID_MASK;
606
		if (*qc & IEEE80211_QOS_CTL_A_MSDU_PRESENT)
607
			status->rx_flags |= IEEE80211_RX_AMSDU;
608 609 610

		seqno_idx = tid;
		security_idx = tid;
611
	} else {
612 613 614 615 616 617 618 619 620 621 622
		/*
		 * IEEE 802.11-2007, 7.1.3.4.1 ("Sequence Number field"):
		 *
		 *	Sequence numbers for management frames, QoS data
		 *	frames with a broadcast/multicast address in the
		 *	Address 1 field, and all non-QoS data frames sent
		 *	by QoS STAs are assigned using an additional single
		 *	modulo-4096 counter, [...]
		 *
		 * We also use that counter for non-QoS STAs.
		 */
623
		seqno_idx = IEEE80211_NUM_TIDS;
624 625
		security_idx = 0;
		if (ieee80211_is_mgmt(hdr->frame_control))
626
			security_idx = IEEE80211_NUM_TIDS;
627
		tid = 0;
628
	}
629

630 631
	rx->seqno_idx = seqno_idx;
	rx->security_idx = security_idx;
632 633 634
	/* Set skb->priority to 1d tag if highest order bit of TID is not set.
	 * For now, set skb->priority to 0 for other cases. */
	rx->skb->priority = (tid > 7) ? 0 : tid;
635
}
636

637 638 639 640 641 642 643 644 645 646 647
/**
 * DOC: Packet alignment
 *
 * Drivers always need to pass packets that are aligned to two-byte boundaries
 * to the stack.
 *
 * Additionally, should, if possible, align the payload data in a way that
 * guarantees that the contained IP header is aligned to a four-byte
 * boundary. In the case of regular frames, this simply means aligning the
 * payload to a four-byte boundary (because either the IP header is directly
 * contained, or IV/RFC1042 headers that have a length divisible by four are
648 649 650
 * in front of it).  If the payload data is not properly aligned and the
 * architecture doesn't support efficient unaligned operations, mac80211
 * will align the data.
651 652 653 654 655 656 657
 *
 * With A-MSDU frames, however, the payload data address must yield two modulo
 * four because there are 14-byte 802.3 headers within the A-MSDU frames that
 * push the IP header further back to a multiple of four again. Thankfully, the
 * specs were sane enough this time around to require padding each A-MSDU
 * subframe to a length that is a multiple of four.
 *
L
Lucas De Marchi 已提交
658
 * Padding like Atheros hardware adds which is between the 802.11 header and
659 660 661 662
 * the payload is not supported, the driver is required to move the 802.11
 * header to be directly in front of the payload in that case.
 */
static void ieee80211_verify_alignment(struct ieee80211_rx_data *rx)
663
{
664
#ifdef CONFIG_MAC80211_VERBOSE_DEBUG
665
	WARN_ON_ONCE((unsigned long)rx->skb->data & 1);
666
#endif
667 668
}

669

670 671
/* rx handlers */

672 673 674 675
static int ieee80211_is_unicast_robust_mgmt_frame(struct sk_buff *skb)
{
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;

676
	if (is_multicast_ether_addr(hdr->addr1))
677 678
		return 0;

679
	return ieee80211_is_robust_mgmt_frame(skb);
680 681 682 683 684 685 686
}


static int ieee80211_is_multicast_robust_mgmt_frame(struct sk_buff *skb)
{
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;

687
	if (!is_multicast_ether_addr(hdr->addr1))
688 689
		return 0;

690
	return ieee80211_is_robust_mgmt_frame(skb);
691 692 693 694 695 696 697 698
}


/* Get the BIP key index from MMIE; return -1 if this is not a BIP frame */
static int ieee80211_get_mmie_keyidx(struct sk_buff *skb)
{
	struct ieee80211_mgmt *hdr = (struct ieee80211_mgmt *) skb->data;
	struct ieee80211_mmie *mmie;
699
	struct ieee80211_mmie_16 *mmie16;
700

J
Johannes Berg 已提交
701
	if (skb->len < 24 + sizeof(*mmie) || !is_multicast_ether_addr(hdr->da))
702 703
		return -1;

704
	if (!ieee80211_is_robust_mgmt_frame(skb))
705 706 707 708
		return -1; /* not a robust management frame */

	mmie = (struct ieee80211_mmie *)
		(skb->data + skb->len - sizeof(*mmie));
709 710 711 712 713 714 715 716 717 718 719 720
	if (mmie->element_id == WLAN_EID_MMIE &&
	    mmie->length == sizeof(*mmie) - 2)
		return le16_to_cpu(mmie->key_id);

	mmie16 = (struct ieee80211_mmie_16 *)
		(skb->data + skb->len - sizeof(*mmie16));
	if (skb->len >= 24 + sizeof(*mmie16) &&
	    mmie16->element_id == WLAN_EID_MMIE &&
	    mmie16->length == sizeof(*mmie16) - 2)
		return le16_to_cpu(mmie16->key_id);

	return -1;
721 722
}

723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743
static int iwl80211_get_cs_keyid(const struct ieee80211_cipher_scheme *cs,
				 struct sk_buff *skb)
{
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
	__le16 fc;
	int hdrlen;
	u8 keyid;

	fc = hdr->frame_control;
	hdrlen = ieee80211_hdrlen(fc);

	if (skb->len < hdrlen + cs->hdr_len)
		return -EINVAL;

	skb_copy_bits(skb, hdrlen + cs->key_idx_off, &keyid, 1);
	keyid &= cs->key_idx_mask;
	keyid >>= cs->key_idx_shift;

	return keyid;
}

J
Johannes Berg 已提交
744
static ieee80211_rx_result ieee80211_rx_mesh_check(struct ieee80211_rx_data *rx)
745
{
746
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
747
	char *dev_addr = rx->sdata->vif.addr;
748

749
	if (ieee80211_is_data(hdr->frame_control)) {
750 751
		if (is_multicast_ether_addr(hdr->addr1)) {
			if (ieee80211_has_tods(hdr->frame_control) ||
J
Johannes Berg 已提交
752
			    !ieee80211_has_fromds(hdr->frame_control))
753
				return RX_DROP_MONITOR;
754
			if (ether_addr_equal(hdr->addr3, dev_addr))
755 756 757 758
				return RX_DROP_MONITOR;
		} else {
			if (!ieee80211_has_a4(hdr->frame_control))
				return RX_DROP_MONITOR;
759
			if (ether_addr_equal(hdr->addr4, dev_addr))
760 761
				return RX_DROP_MONITOR;
		}
762 763 764 765 766 767
	}

	/* If there is not an established peer link and this is not a peer link
	 * establisment frame, beacon or probe, drop the frame.
	 */

768
	if (!rx->sta || sta_plink_state(rx->sta) != NL80211_PLINK_ESTAB) {
769
		struct ieee80211_mgmt *mgmt;
770

771
		if (!ieee80211_is_mgmt(hdr->frame_control))
772 773
			return RX_DROP_MONITOR;

774
		if (ieee80211_is_action(hdr->frame_control)) {
775
			u8 category;
776 777 778 779 780

			/* make sure category field is present */
			if (rx->skb->len < IEEE80211_MIN_ACTION_SIZE)
				return RX_DROP_MONITOR;

781
			mgmt = (struct ieee80211_mgmt *)hdr;
782 783
			category = mgmt->u.action.category;
			if (category != WLAN_CATEGORY_MESH_ACTION &&
J
Johannes Berg 已提交
784
			    category != WLAN_CATEGORY_SELF_PROTECTED)
785 786 787 788
				return RX_DROP_MONITOR;
			return RX_CONTINUE;
		}

789 790
		if (ieee80211_is_probe_req(hdr->frame_control) ||
		    ieee80211_is_probe_resp(hdr->frame_control) ||
791 792
		    ieee80211_is_beacon(hdr->frame_control) ||
		    ieee80211_is_auth(hdr->frame_control))
793 794 795 796 797
			return RX_CONTINUE;

		return RX_DROP_MONITOR;
	}

J
Johannes Berg 已提交
798 799
	return RX_CONTINUE;
}
800

801
static void ieee80211_release_reorder_frame(struct ieee80211_sub_if_data *sdata,
802
					    struct tid_ampdu_rx *tid_agg_rx,
803 804
					    int index,
					    struct sk_buff_head *frames)
805
{
806 807
	struct sk_buff_head *skb_list = &tid_agg_rx->reorder_buf[index];
	struct sk_buff *skb;
808
	struct ieee80211_rx_status *status;
809

810 811
	lockdep_assert_held(&tid_agg_rx->reorder_lock);

812
	if (skb_queue_empty(skb_list))
813 814
		goto no_frame;

815 816 817 818 819 820
	if (!ieee80211_rx_reorder_ready(skb_list)) {
		__skb_queue_purge(skb_list);
		goto no_frame;
	}

	/* release frames from the reorder ring buffer */
821
	tid_agg_rx->stored_mpdu_num--;
822 823 824 825 826
	while ((skb = __skb_dequeue(skb_list))) {
		status = IEEE80211_SKB_RXCB(skb);
		status->rx_flags |= IEEE80211_RX_DEFERRED_RELEASE;
		__skb_queue_tail(frames, skb);
	}
827 828

no_frame:
829
	tid_agg_rx->head_seq_num = ieee80211_sn_inc(tid_agg_rx->head_seq_num);
830 831
}

832
static void ieee80211_release_reorder_frames(struct ieee80211_sub_if_data *sdata,
833
					     struct tid_ampdu_rx *tid_agg_rx,
834 835
					     u16 head_seq_num,
					     struct sk_buff_head *frames)
836 837 838
{
	int index;

839 840
	lockdep_assert_held(&tid_agg_rx->reorder_lock);

841
	while (ieee80211_sn_less(tid_agg_rx->head_seq_num, head_seq_num)) {
842
		index = tid_agg_rx->head_seq_num % tid_agg_rx->buf_size;
843 844
		ieee80211_release_reorder_frame(sdata, tid_agg_rx, index,
						frames);
845 846 847 848 849 850 851 852 853
	}
}

/*
 * Timeout (in jiffies) for skb's that are waiting in the RX reorder buffer. If
 * the skb was added to the buffer longer than this time ago, the earlier
 * frames that have not yet been received are assumed to be lost and the skb
 * can be released for processing. This may also release other skb's from the
 * reorder buffer if there are no additional gaps between the frames.
854 855
 *
 * Callers must hold tid_agg_rx->reorder_lock.
856 857 858
 */
#define HT_RX_REORDER_BUF_TIMEOUT (HZ / 10)

859
static void ieee80211_sta_reorder_release(struct ieee80211_sub_if_data *sdata,
860 861
					  struct tid_ampdu_rx *tid_agg_rx,
					  struct sk_buff_head *frames)
862
{
863
	int index, i, j;
864

865 866
	lockdep_assert_held(&tid_agg_rx->reorder_lock);

867
	/* release the buffer until next missing frame */
868
	index = tid_agg_rx->head_seq_num % tid_agg_rx->buf_size;
869
	if (!ieee80211_rx_reorder_ready(&tid_agg_rx->reorder_buf[index]) &&
870
	    tid_agg_rx->stored_mpdu_num) {
871 872 873 874 875 876 877
		/*
		 * No buffers ready to be released, but check whether any
		 * frames in the reorder buffer have timed out.
		 */
		int skipped = 1;
		for (j = (index + 1) % tid_agg_rx->buf_size; j != index;
		     j = (j + 1) % tid_agg_rx->buf_size) {
878 879
			if (!ieee80211_rx_reorder_ready(
					&tid_agg_rx->reorder_buf[j])) {
880 881 882
				skipped++;
				continue;
			}
883 884
			if (skipped &&
			    !time_after(jiffies, tid_agg_rx->reorder_time[j] +
885
					HT_RX_REORDER_BUF_TIMEOUT))
886
				goto set_release_timer;
887

888 889 890 891 892
			/* don't leave incomplete A-MSDUs around */
			for (i = (index + 1) % tid_agg_rx->buf_size; i != j;
			     i = (i + 1) % tid_agg_rx->buf_size)
				__skb_queue_purge(&tid_agg_rx->reorder_buf[i]);

J
Johannes Berg 已提交
893 894
			ht_dbg_ratelimited(sdata,
					   "release an RX reorder frame due to timeout on earlier frames\n");
895 896
			ieee80211_release_reorder_frame(sdata, tid_agg_rx, j,
							frames);
897 898 899 900 901

			/*
			 * Increment the head seq# also for the skipped slots.
			 */
			tid_agg_rx->head_seq_num =
902 903
				(tid_agg_rx->head_seq_num +
				 skipped) & IEEE80211_SN_MASK;
904 905
			skipped = 0;
		}
906 907
	} else while (ieee80211_rx_reorder_ready(
				&tid_agg_rx->reorder_buf[index])) {
908 909
		ieee80211_release_reorder_frame(sdata, tid_agg_rx, index,
						frames);
910
		index =	tid_agg_rx->head_seq_num % tid_agg_rx->buf_size;
911
	}
912 913

	if (tid_agg_rx->stored_mpdu_num) {
914
		j = index = tid_agg_rx->head_seq_num % tid_agg_rx->buf_size;
915 916 917

		for (; j != (index - 1) % tid_agg_rx->buf_size;
		     j = (j + 1) % tid_agg_rx->buf_size) {
918 919
			if (ieee80211_rx_reorder_ready(
					&tid_agg_rx->reorder_buf[j]))
920 921 922 923 924
				break;
		}

 set_release_timer:

925 926 927 928
		if (!tid_agg_rx->removed)
			mod_timer(&tid_agg_rx->reorder_timer,
				  tid_agg_rx->reorder_time[j] + 1 +
				  HT_RX_REORDER_BUF_TIMEOUT);
929 930 931
	} else {
		del_timer(&tid_agg_rx->reorder_timer);
	}
932 933
}

934 935 936 937 938
/*
 * As this function belongs to the RX path it must be under
 * rcu_read_lock protection. It returns false if the frame
 * can be processed immediately, true if it was consumed.
 */
939
static bool ieee80211_sta_manage_reorder_buf(struct ieee80211_sub_if_data *sdata,
940
					     struct tid_ampdu_rx *tid_agg_rx,
941 942
					     struct sk_buff *skb,
					     struct sk_buff_head *frames)
943 944
{
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
945
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
946 947 948 949
	u16 sc = le16_to_cpu(hdr->seq_ctrl);
	u16 mpdu_seq_num = (sc & IEEE80211_SCTL_SEQ) >> 4;
	u16 head_seq_num, buf_size;
	int index;
950
	bool ret = true;
951

952 953
	spin_lock(&tid_agg_rx->reorder_lock);

954 955 956 957 958 959 960 961 962 963
	/*
	 * Offloaded BA sessions have no known starting sequence number so pick
	 * one from first Rxed frame for this tid after BA was started.
	 */
	if (unlikely(tid_agg_rx->auto_seq)) {
		tid_agg_rx->auto_seq = false;
		tid_agg_rx->ssn = mpdu_seq_num;
		tid_agg_rx->head_seq_num = mpdu_seq_num;
	}

964 965 966 967
	buf_size = tid_agg_rx->buf_size;
	head_seq_num = tid_agg_rx->head_seq_num;

	/* frame with out of date sequence number */
968
	if (ieee80211_sn_less(mpdu_seq_num, head_seq_num)) {
969
		dev_kfree_skb(skb);
970
		goto out;
971 972 973 974 975 976
	}

	/*
	 * If frame the sequence number exceeds our buffering window
	 * size release some previous frames to make room for this one.
	 */
977 978 979
	if (!ieee80211_sn_less(mpdu_seq_num, head_seq_num + buf_size)) {
		head_seq_num = ieee80211_sn_inc(
				ieee80211_sn_sub(mpdu_seq_num, buf_size));
980
		/* release stored frames up to new head to stack */
981
		ieee80211_release_reorder_frames(sdata, tid_agg_rx,
982
						 head_seq_num, frames);
983 984 985 986
	}

	/* Now the new frame is always in the range of the reordering buffer */

987
	index = mpdu_seq_num % tid_agg_rx->buf_size;
988 989

	/* check if we already stored this frame */
990
	if (ieee80211_rx_reorder_ready(&tid_agg_rx->reorder_buf[index])) {
991
		dev_kfree_skb(skb);
992
		goto out;
993 994 995 996 997
	}

	/*
	 * If the current MPDU is in the right order and nothing else
	 * is stored we can process it directly, no need to buffer it.
998 999
	 * If it is first but there's something stored, we may be able
	 * to release frames after this one.
1000 1001 1002
	 */
	if (mpdu_seq_num == tid_agg_rx->head_seq_num &&
	    tid_agg_rx->stored_mpdu_num == 0) {
1003 1004 1005
		if (!(status->flag & RX_FLAG_AMSDU_MORE))
			tid_agg_rx->head_seq_num =
				ieee80211_sn_inc(tid_agg_rx->head_seq_num);
1006 1007
		ret = false;
		goto out;
1008 1009 1010
	}

	/* put the frame in the reordering buffer */
1011 1012 1013 1014 1015 1016
	__skb_queue_tail(&tid_agg_rx->reorder_buf[index], skb);
	if (!(status->flag & RX_FLAG_AMSDU_MORE)) {
		tid_agg_rx->reorder_time[index] = jiffies;
		tid_agg_rx->stored_mpdu_num++;
		ieee80211_sta_reorder_release(sdata, tid_agg_rx, frames);
	}
1017

1018 1019 1020
 out:
	spin_unlock(&tid_agg_rx->reorder_lock);
	return ret;
1021 1022 1023 1024 1025 1026
}

/*
 * Reorder MPDUs from A-MPDUs, keeping them on a buffer. Returns
 * true if the MPDU was buffered, false if it should be processed.
 */
1027 1028
static void ieee80211_rx_reorder_ampdu(struct ieee80211_rx_data *rx,
				       struct sk_buff_head *frames)
1029
{
1030 1031
	struct sk_buff *skb = rx->skb;
	struct ieee80211_local *local = rx->local;
1032
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *) skb->data;
1033
	struct sta_info *sta = rx->sta;
1034 1035
	struct tid_ampdu_rx *tid_agg_rx;
	u16 sc;
1036
	u8 tid, ack_policy;
1037

1038 1039
	if (!ieee80211_is_data_qos(hdr->frame_control) ||
	    is_multicast_ether_addr(hdr->addr1))
1040
		goto dont_reorder;
1041 1042 1043 1044 1045 1046 1047

	/*
	 * filter the QoS data rx stream according to
	 * STA/TID and check if this STA/TID is on aggregation
	 */

	if (!sta)
1048
		goto dont_reorder;
1049

1050 1051
	ack_policy = *ieee80211_get_qos_ctl(hdr) &
		     IEEE80211_QOS_CTL_ACK_POLICY_MASK;
1052 1053
	tid = *ieee80211_get_qos_ctl(hdr) & IEEE80211_QOS_CTL_TID_MASK;

1054 1055 1056
	tid_agg_rx = rcu_dereference(sta->ampdu_mlme.tid_rx[tid]);
	if (!tid_agg_rx)
		goto dont_reorder;
1057 1058 1059

	/* qos null data frames are excluded */
	if (unlikely(hdr->frame_control & cpu_to_le16(IEEE80211_STYPE_NULLFUNC)))
1060
		goto dont_reorder;
1061

1062 1063 1064 1065 1066
	/* not part of a BA session */
	if (ack_policy != IEEE80211_QOS_CTL_ACK_POLICY_BLOCKACK &&
	    ack_policy != IEEE80211_QOS_CTL_ACK_POLICY_NORMAL)
		goto dont_reorder;

1067 1068 1069 1070
	/* new, potentially un-ordered, ampdu frame - process it */

	/* reset session timer */
	if (tid_agg_rx->timeout)
1071
		tid_agg_rx->last_rx = jiffies;
1072 1073 1074 1075

	/* if this mpdu is fragmented - terminate rx aggregation session */
	sc = le16_to_cpu(hdr->seq_ctrl);
	if (sc & IEEE80211_SCTL_FRAG) {
1076
		skb->pkt_type = IEEE80211_SDATA_QUEUE_TYPE_FRAME;
1077 1078
		skb_queue_tail(&rx->sdata->skb_queue, skb);
		ieee80211_queue_work(&local->hw, &rx->sdata->work);
1079
		return;
1080 1081
	}

1082 1083 1084 1085 1086 1087 1088
	/*
	 * No locking needed -- we will only ever process one
	 * RX packet at a time, and thus own tid_agg_rx. All
	 * other code manipulating it needs to (and does) make
	 * sure that we cannot get to it any more before doing
	 * anything with it.
	 */
1089 1090
	if (ieee80211_sta_manage_reorder_buf(rx->sdata, tid_agg_rx, skb,
					     frames))
1091 1092 1093
		return;

 dont_reorder:
1094
	__skb_queue_tail(frames, skb);
1095
}
1096

1097
static ieee80211_rx_result debug_noinline
1098
ieee80211_rx_h_check_dup(struct ieee80211_rx_data *rx)
1099
{
1100
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
1101
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
1102

1103 1104 1105
	if (status->flag & RX_FLAG_DUP_VALIDATED)
		return RX_CONTINUE;

1106 1107 1108 1109
	/*
	 * Drop duplicate 802.11 retransmissions
	 * (IEEE 802.11-2012: 9.3.2.10 "Duplicate detection and recovery")
	 */
1110 1111 1112 1113 1114 1115 1116 1117 1118

	if (rx->skb->len < 24)
		return RX_CONTINUE;

	if (ieee80211_is_ctl(hdr->frame_control) ||
	    ieee80211_is_qos_nullfunc(hdr->frame_control) ||
	    is_multicast_ether_addr(hdr->addr1))
		return RX_CONTINUE;

1119 1120 1121 1122 1123 1124
	if (!rx->sta)
		return RX_CONTINUE;

	if (unlikely(ieee80211_has_retry(hdr->frame_control) &&
		     rx->sta->last_seq_ctrl[rx->seqno_idx] == hdr->seq_ctrl)) {
		I802_DEBUG_INC(rx->local->dot11FrameDuplicateCount);
1125
		rx->sta->rx_stats.num_duplicates++;
1126 1127 1128
		return RX_DROP_UNUSABLE;
	} else if (!(status->flag & RX_FLAG_AMSDU_MORE)) {
		rx->sta->last_seq_ctrl[rx->seqno_idx] = hdr->seq_ctrl;
1129 1130
	}

1131 1132 1133 1134 1135 1136 1137 1138
	return RX_CONTINUE;
}

static ieee80211_rx_result debug_noinline
ieee80211_rx_h_check(struct ieee80211_rx_data *rx)
{
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;

1139 1140 1141
	/* Drop disallowed frame classes based on STA auth/assoc state;
	 * IEEE 802.11, Chap 5.5.
	 *
J
Johannes Berg 已提交
1142 1143
	 * mac80211 filters only based on association state, i.e. it drops
	 * Class 3 frames from not associated stations. hostapd sends
1144 1145 1146
	 * deauth/disassoc frames when needed. In addition, hostapd is
	 * responsible for filtering on both auth and assoc states.
	 */
1147

J
Johannes Berg 已提交
1148
	if (ieee80211_vif_is_mesh(&rx->sdata->vif))
1149 1150
		return ieee80211_rx_mesh_check(rx);

1151 1152
	if (unlikely((ieee80211_is_data(hdr->frame_control) ||
		      ieee80211_is_pspoll(hdr->frame_control)) &&
1153
		     rx->sdata->vif.type != NL80211_IFTYPE_ADHOC &&
B
Bill Jordan 已提交
1154
		     rx->sdata->vif.type != NL80211_IFTYPE_WDS &&
1155
		     rx->sdata->vif.type != NL80211_IFTYPE_OCB &&
J
Johannes Berg 已提交
1156
		     (!rx->sta || !test_sta_flag(rx->sta, WLAN_STA_ASSOC)))) {
1157 1158 1159 1160 1161 1162
		/*
		 * accept port control frames from the AP even when it's not
		 * yet marked ASSOC to prevent a race where we don't set the
		 * assoc bit quickly enough before it sends the first frame
		 */
		if (rx->sta && rx->sdata->vif.type == NL80211_IFTYPE_STATION &&
1163
		    ieee80211_is_data_present(hdr->frame_control)) {
1164 1165 1166 1167 1168 1169 1170 1171 1172 1173
			unsigned int hdrlen;
			__be16 ethertype;

			hdrlen = ieee80211_hdrlen(hdr->frame_control);

			if (rx->skb->len < hdrlen + 8)
				return RX_DROP_MONITOR;

			skb_copy_bits(rx->skb, hdrlen + 6, &ethertype, 2);
			if (ethertype == rx->sdata->control_port_protocol)
1174 1175
				return RX_CONTINUE;
		}
1176 1177 1178 1179 1180 1181 1182

		if (rx->sdata->vif.type == NL80211_IFTYPE_AP &&
		    cfg80211_rx_spurious_frame(rx->sdata->dev,
					       hdr->addr2,
					       GFP_ATOMIC))
			return RX_DROP_UNUSABLE;

J
Johannes Berg 已提交
1183
		return RX_DROP_MONITOR;
1184
	}
1185

1186
	return RX_CONTINUE;
1187 1188 1189
}


1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222
static ieee80211_rx_result debug_noinline
ieee80211_rx_h_check_more_data(struct ieee80211_rx_data *rx)
{
	struct ieee80211_local *local;
	struct ieee80211_hdr *hdr;
	struct sk_buff *skb;

	local = rx->local;
	skb = rx->skb;
	hdr = (struct ieee80211_hdr *) skb->data;

	if (!local->pspolling)
		return RX_CONTINUE;

	if (!ieee80211_has_fromds(hdr->frame_control))
		/* this is not from AP */
		return RX_CONTINUE;

	if (!ieee80211_is_data(hdr->frame_control))
		return RX_CONTINUE;

	if (!ieee80211_has_moredata(hdr->frame_control)) {
		/* AP has no more frames buffered for us */
		local->pspolling = false;
		return RX_CONTINUE;
	}

	/* more data bit is set, let's request a new frame from the AP */
	ieee80211_send_pspoll(local, rx->sdata);

	return RX_CONTINUE;
}

1223
static void sta_ps_start(struct sta_info *sta)
1224
{
1225
	struct ieee80211_sub_if_data *sdata = sta->sdata;
1226
	struct ieee80211_local *local = sdata->local;
1227
	struct ps_data *ps;
1228
	int tid;
1229

1230 1231 1232 1233 1234 1235 1236
	if (sta->sdata->vif.type == NL80211_IFTYPE_AP ||
	    sta->sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
		ps = &sdata->bss->ps;
	else
		return;

	atomic_inc(&ps->num_sta_ps);
J
Johannes Berg 已提交
1237
	set_sta_flag(sta, WLAN_STA_PS_STA);
1238
	if (!ieee80211_hw_check(&local->hw, AP_LINK_PS))
1239
		drv_sta_notify(local, sdata, STA_NOTIFY_SLEEP, &sta->sta);
J
Johannes Berg 已提交
1240 1241
	ps_dbg(sdata, "STA %pM aid %d enters power save mode\n",
	       sta->sta.addr, sta->sta.aid);
1242

J
Johannes Berg 已提交
1243 1244
	ieee80211_clear_fast_xmit(sta);

1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255
	if (!sta->sta.txq[0])
		return;

	for (tid = 0; tid < ARRAY_SIZE(sta->sta.txq); tid++) {
		struct txq_info *txqi = to_txq_info(sta->sta.txq[tid]);

		if (!skb_queue_len(&txqi->queue))
			set_bit(tid, &sta->txq_buffered_tids);
		else
			clear_bit(tid, &sta->txq_buffered_tids);
	}
1256 1257
}

1258
static void sta_ps_end(struct sta_info *sta)
1259
{
J
Johannes Berg 已提交
1260 1261
	ps_dbg(sta->sdata, "STA %pM aid %d exits power save mode\n",
	       sta->sta.addr, sta->sta.aid);
1262

J
Johannes Berg 已提交
1263
	if (test_sta_flag(sta, WLAN_STA_PS_DRIVER)) {
1264 1265 1266 1267 1268 1269 1270
		/*
		 * Clear the flag only if the other one is still set
		 * so that the TX path won't start TX'ing new frames
		 * directly ... In the case that the driver flag isn't
		 * set ieee80211_sta_ps_deliver_wakeup() will clear it.
		 */
		clear_sta_flag(sta, WLAN_STA_PS_STA);
J
Johannes Berg 已提交
1271 1272
		ps_dbg(sta->sdata, "STA %pM aid %d driver-ps-blocked\n",
		       sta->sta.addr, sta->sta.aid);
1273 1274 1275
		return;
	}

1276 1277
	set_sta_flag(sta, WLAN_STA_PS_DELIVER);
	clear_sta_flag(sta, WLAN_STA_PS_STA);
1278
	ieee80211_sta_ps_deliver_wakeup(sta);
1279 1280
}

1281
int ieee80211_sta_ps_transition(struct ieee80211_sta *pubsta, bool start)
1282
{
1283
	struct sta_info *sta = container_of(pubsta, struct sta_info, sta);
1284 1285
	bool in_ps;

1286
	WARN_ON(!ieee80211_hw_check(&sta->local->hw, AP_LINK_PS));
1287 1288

	/* Don't let the same PS state be set twice */
1289
	in_ps = test_sta_flag(sta, WLAN_STA_PS_STA);
1290 1291 1292 1293
	if ((start && in_ps) || (!start && !in_ps))
		return -EINVAL;

	if (start)
1294
		sta_ps_start(sta);
1295
	else
1296
		sta_ps_end(sta);
1297 1298 1299 1300 1301

	return 0;
}
EXPORT_SYMBOL(ieee80211_sta_ps_transition);

J
Johannes Berg 已提交
1302 1303 1304 1305 1306 1307 1308 1309
static ieee80211_rx_result debug_noinline
ieee80211_rx_h_uapsd_and_pspoll(struct ieee80211_rx_data *rx)
{
	struct ieee80211_sub_if_data *sdata = rx->sdata;
	struct ieee80211_hdr *hdr = (void *)rx->skb->data;
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
	int tid, ac;

1310
	if (!rx->sta)
J
Johannes Berg 已提交
1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321
		return RX_CONTINUE;

	if (sdata->vif.type != NL80211_IFTYPE_AP &&
	    sdata->vif.type != NL80211_IFTYPE_AP_VLAN)
		return RX_CONTINUE;

	/*
	 * The device handles station powersave, so don't do anything about
	 * uAPSD and PS-Poll frames (the latter shouldn't even come up from
	 * it to mac80211 since they're handled.)
	 */
1322
	if (ieee80211_hw_check(&sdata->local->hw, AP_LINK_PS))
J
Johannes Berg 已提交
1323 1324 1325 1326 1327 1328 1329
		return RX_CONTINUE;

	/*
	 * Don't do anything if the station isn't already asleep. In
	 * the uAPSD case, the station will probably be marked asleep,
	 * in the PS-Poll case the station must be confused ...
	 */
J
Johannes Berg 已提交
1330
	if (!test_sta_flag(rx->sta, WLAN_STA_PS_STA))
J
Johannes Berg 已提交
1331 1332 1333
		return RX_CONTINUE;

	if (unlikely(ieee80211_is_pspoll(hdr->frame_control))) {
J
Johannes Berg 已提交
1334 1335
		if (!test_sta_flag(rx->sta, WLAN_STA_SP)) {
			if (!test_sta_flag(rx->sta, WLAN_STA_PS_DRIVER))
1336 1337
				ieee80211_sta_ps_deliver_poll_response(rx->sta);
			else
J
Johannes Berg 已提交
1338
				set_sta_flag(rx->sta, WLAN_STA_PSPOLL);
1339
		}
J
Johannes Berg 已提交
1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364

		/* Free PS Poll skb here instead of returning RX_DROP that would
		 * count as an dropped frame. */
		dev_kfree_skb(rx->skb);

		return RX_QUEUED;
	} else if (!ieee80211_has_morefrags(hdr->frame_control) &&
		   !(status->rx_flags & IEEE80211_RX_DEFERRED_RELEASE) &&
		   ieee80211_has_pm(hdr->frame_control) &&
		   (ieee80211_is_data_qos(hdr->frame_control) ||
		    ieee80211_is_qos_nullfunc(hdr->frame_control))) {
		tid = *ieee80211_get_qos_ctl(hdr) & IEEE80211_QOS_CTL_TID_MASK;
		ac = ieee802_1d_to_ac[tid & 7];

		/*
		 * If this AC is not trigger-enabled do nothing.
		 *
		 * NB: This could/should check a separate bitmap of trigger-
		 * enabled queues, but for now we only implement uAPSD w/o
		 * TSPEC changes to the ACs, so they're always the same.
		 */
		if (!(rx->sta->sta.uapsd_queues & BIT(ac)))
			return RX_CONTINUE;

		/* if we are in a service period, do nothing */
J
Johannes Berg 已提交
1365
		if (test_sta_flag(rx->sta, WLAN_STA_SP))
J
Johannes Berg 已提交
1366 1367
			return RX_CONTINUE;

J
Johannes Berg 已提交
1368
		if (!test_sta_flag(rx->sta, WLAN_STA_PS_DRIVER))
J
Johannes Berg 已提交
1369 1370
			ieee80211_sta_ps_deliver_uapsd(rx->sta);
		else
J
Johannes Berg 已提交
1371
			set_sta_flag(rx->sta, WLAN_STA_UAPSD);
J
Johannes Berg 已提交
1372 1373 1374 1375 1376
	}

	return RX_CONTINUE;
}

1377
static ieee80211_rx_result debug_noinline
1378
ieee80211_rx_h_sta_process(struct ieee80211_rx_data *rx)
1379 1380
{
	struct sta_info *sta = rx->sta;
J
Johannes Berg 已提交
1381 1382 1383
	struct sk_buff *skb = rx->skb;
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
1384
	int i;
1385 1386

	if (!sta)
1387
		return RX_CONTINUE;
1388

J
Johannes Berg 已提交
1389 1390
	/*
	 * Update last_rx only for IBSS packets which are for the current
1391 1392 1393 1394 1395
	 * BSSID and for station already AUTHORIZED to avoid keeping the
	 * current IBSS network alive in cases where other STAs start
	 * using different BSSID. This will also give the station another
	 * chance to restart the authentication/authorization in case
	 * something went wrong the first time.
J
Johannes Berg 已提交
1396
	 */
1397
	if (rx->sdata->vif.type == NL80211_IFTYPE_ADHOC) {
1398
		u8 *bssid = ieee80211_get_bssid(hdr, rx->skb->len,
1399
						NL80211_IFTYPE_ADHOC);
1400 1401
		if (ether_addr_equal(bssid, rx->sdata->u.ibss.bssid) &&
		    test_sta_flag(sta, WLAN_STA_AUTHORIZED)) {
1402
			sta->rx_stats.last_rx = jiffies;
1403 1404
			if (ieee80211_is_data(hdr->frame_control) &&
			    !is_multicast_ether_addr(hdr->addr1)) {
1405 1406 1407 1408 1409 1410 1411 1412
				sta->rx_stats.last_rate_idx =
					status->rate_idx;
				sta->rx_stats.last_rate_flag =
					status->flag;
				sta->rx_stats.last_rate_vht_flag =
					status->vht_flag;
				sta->rx_stats.last_rate_vht_nss =
					status->vht_nss;
1413 1414
			}
		}
1415
	} else if (rx->sdata->vif.type == NL80211_IFTYPE_OCB) {
1416
		sta->rx_stats.last_rx = jiffies;
J
Johannes Berg 已提交
1417 1418
	} else if (!is_multicast_ether_addr(hdr->addr1)) {
		/*
1419 1420
		 * Mesh beacons will update last_rx when if they are found to
		 * match the current local configuration when processed.
1421
		 */
1422
		sta->rx_stats.last_rx = jiffies;
1423
		if (ieee80211_is_data(hdr->frame_control)) {
1424 1425 1426 1427
			sta->rx_stats.last_rate_idx = status->rate_idx;
			sta->rx_stats.last_rate_flag = status->flag;
			sta->rx_stats.last_rate_vht_flag = status->vht_flag;
			sta->rx_stats.last_rate_vht_nss = status->vht_nss;
1428
		}
1429 1430
	}

1431 1432 1433
	if (rx->sdata->vif.type == NL80211_IFTYPE_STATION)
		ieee80211_sta_rx_notify(rx->sdata, hdr);

1434 1435
	sta->rx_stats.fragments++;
	sta->rx_stats.bytes += rx->skb->len;
1436
	if (!(status->flag & RX_FLAG_NO_SIGNAL_VAL)) {
1437 1438
		sta->rx_stats.last_signal = status->signal;
		ewma_signal_add(&sta->rx_stats.avg_signal, -status->signal);
1439
	}
1440

1441
	if (status->chains) {
1442
		sta->rx_stats.chains = status->chains;
1443 1444 1445 1446 1447 1448
		for (i = 0; i < ARRAY_SIZE(status->chain_signal); i++) {
			int signal = status->chain_signal[i];

			if (!(status->chains & BIT(i)))
				continue;

1449 1450 1451
			sta->rx_stats.chain_signal_last[i] = signal;
			ewma_signal_add(&sta->rx_stats.chain_signal_avg[i],
					-signal);
1452 1453 1454
		}
	}

1455 1456 1457 1458
	/*
	 * Change STA power saving mode only at the end of a frame
	 * exchange sequence.
	 */
1459
	if (!ieee80211_hw_check(&sta->local->hw, AP_LINK_PS) &&
1460
	    !ieee80211_has_morefrags(hdr->frame_control) &&
1461
	    !(status->rx_flags & IEEE80211_RX_DEFERRED_RELEASE) &&
1462
	    (rx->sdata->vif.type == NL80211_IFTYPE_AP ||
1463 1464 1465 1466 1467 1468 1469
	     rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN) &&
	    /* PM bit is only checked in frames where it isn't reserved,
	     * in AP mode it's reserved in non-bufferable management frames
	     * (cf. IEEE 802.11-2012 8.2.4.1.7 Power Management field)
	     */
	    (!ieee80211_is_mgmt(hdr->frame_control) ||
	     ieee80211_is_bufferable_mmpdu(hdr->frame_control))) {
J
Johannes Berg 已提交
1470
		if (test_sta_flag(sta, WLAN_STA_PS_STA)) {
1471
			if (!ieee80211_has_pm(hdr->frame_control))
1472
				sta_ps_end(sta);
1473 1474
		} else {
			if (ieee80211_has_pm(hdr->frame_control))
1475
				sta_ps_start(sta);
1476
		}
1477 1478
	}

M
Marco Porsch 已提交
1479 1480 1481 1482
	/* mesh power save support */
	if (ieee80211_vif_is_mesh(&rx->sdata->vif))
		ieee80211_mps_rx_h_sta_process(sta, hdr);

1483 1484 1485 1486 1487 1488
	/*
	 * Drop (qos-)data::nullfunc frames silently, since they
	 * are used only to control station power saving mode.
	 */
	if (ieee80211_is_nullfunc(hdr->frame_control) ||
	    ieee80211_is_qos_nullfunc(hdr->frame_control)) {
1489
		I802_DEBUG_INC(rx->local->rx_handlers_drop_nullfunc);
1490 1491 1492

		/*
		 * If we receive a 4-addr nullfunc frame from a STA
1493 1494 1495
		 * that was not moved to a 4-addr STA vlan yet send
		 * the event to userspace and for older hostapd drop
		 * the frame to the monitor interface.
1496 1497 1498 1499
		 */
		if (ieee80211_has_a4(hdr->frame_control) &&
		    (rx->sdata->vif.type == NL80211_IFTYPE_AP ||
		     (rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN &&
1500 1501 1502 1503 1504
		      !rx->sdata->u.vlan.sta))) {
			if (!test_and_set_sta_flag(sta, WLAN_STA_4ADDR_EVENT))
				cfg80211_rx_unexpected_4addr_frame(
					rx->sdata->dev, sta->sta.addr,
					GFP_ATOMIC);
1505
			return RX_DROP_MONITOR;
1506
		}
1507 1508 1509 1510
		/*
		 * Update counter and free packet here to avoid
		 * counting this as a dropped packed.
		 */
1511
		sta->rx_stats.packets++;
1512
		dev_kfree_skb(rx->skb);
1513
		return RX_QUEUED;
1514 1515
	}

1516
	return RX_CONTINUE;
1517 1518
} /* ieee80211_rx_h_sta_process */

1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530
static ieee80211_rx_result debug_noinline
ieee80211_rx_h_decrypt(struct ieee80211_rx_data *rx)
{
	struct sk_buff *skb = rx->skb;
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
	int keyidx;
	int hdrlen;
	ieee80211_rx_result result = RX_DROP_UNUSABLE;
	struct ieee80211_key *sta_ptk = NULL;
	int mmie_keyidx = -1;
	__le16 fc;
1531
	const struct ieee80211_cipher_scheme *cs = NULL;
1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561

	/*
	 * Key selection 101
	 *
	 * There are four types of keys:
	 *  - GTK (group keys)
	 *  - IGTK (group keys for management frames)
	 *  - PTK (pairwise keys)
	 *  - STK (station-to-station pairwise keys)
	 *
	 * When selecting a key, we have to distinguish between multicast
	 * (including broadcast) and unicast frames, the latter can only
	 * use PTKs and STKs while the former always use GTKs and IGTKs.
	 * Unless, of course, actual WEP keys ("pre-RSNA") are used, then
	 * unicast frames can also use key indices like GTKs. Hence, if we
	 * don't have a PTK/STK we check the key index for a WEP key.
	 *
	 * Note that in a regular BSS, multicast frames are sent by the
	 * AP only, associated stations unicast the frame to the AP first
	 * which then multicasts it on their behalf.
	 *
	 * There is also a slight problem in IBSS mode: GTKs are negotiated
	 * with each station, that is something we don't currently handle.
	 * The spec seems to expect that one negotiates the same key with
	 * every station but there's no such requirement; VLANs could be
	 * possible.
	 */

	/* start without a key */
	rx->key = NULL;
1562
	fc = hdr->frame_control;
1563

1564 1565
	if (rx->sta) {
		int keyid = rx->sta->ptk_idx;
1566

1567 1568 1569 1570 1571 1572 1573 1574
		if (ieee80211_has_protected(fc) && rx->sta->cipher_scheme) {
			cs = rx->sta->cipher_scheme;
			keyid = iwl80211_get_cs_keyid(cs, rx->skb);
			if (unlikely(keyid < 0))
				return RX_DROP_UNUSABLE;
		}
		sta_ptk = rcu_dereference(rx->sta->ptk[keyid]);
	}
1575 1576 1577 1578 1579 1580 1581 1582 1583 1584 1585 1586 1587 1588 1589 1590 1591 1592 1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603 1604 1605 1606 1607 1608 1609 1610 1611 1612 1613 1614 1615 1616 1617 1618 1619 1620 1621 1622 1623 1624 1625 1626 1627 1628 1629 1630 1631 1632 1633 1634 1635

	if (!ieee80211_has_protected(fc))
		mmie_keyidx = ieee80211_get_mmie_keyidx(rx->skb);

	if (!is_multicast_ether_addr(hdr->addr1) && sta_ptk) {
		rx->key = sta_ptk;
		if ((status->flag & RX_FLAG_DECRYPTED) &&
		    (status->flag & RX_FLAG_IV_STRIPPED))
			return RX_CONTINUE;
		/* Skip decryption if the frame is not protected. */
		if (!ieee80211_has_protected(fc))
			return RX_CONTINUE;
	} else if (mmie_keyidx >= 0) {
		/* Broadcast/multicast robust management frame / BIP */
		if ((status->flag & RX_FLAG_DECRYPTED) &&
		    (status->flag & RX_FLAG_IV_STRIPPED))
			return RX_CONTINUE;

		if (mmie_keyidx < NUM_DEFAULT_KEYS ||
		    mmie_keyidx >= NUM_DEFAULT_KEYS + NUM_DEFAULT_MGMT_KEYS)
			return RX_DROP_MONITOR; /* unexpected BIP keyidx */
		if (rx->sta)
			rx->key = rcu_dereference(rx->sta->gtk[mmie_keyidx]);
		if (!rx->key)
			rx->key = rcu_dereference(rx->sdata->keys[mmie_keyidx]);
	} else if (!ieee80211_has_protected(fc)) {
		/*
		 * The frame was not protected, so skip decryption. However, we
		 * need to set rx->key if there is a key that could have been
		 * used so that the frame may be dropped if encryption would
		 * have been expected.
		 */
		struct ieee80211_key *key = NULL;
		struct ieee80211_sub_if_data *sdata = rx->sdata;
		int i;

		if (ieee80211_is_mgmt(fc) &&
		    is_multicast_ether_addr(hdr->addr1) &&
		    (key = rcu_dereference(rx->sdata->default_mgmt_key)))
			rx->key = key;
		else {
			if (rx->sta) {
				for (i = 0; i < NUM_DEFAULT_KEYS; i++) {
					key = rcu_dereference(rx->sta->gtk[i]);
					if (key)
						break;
				}
			}
			if (!key) {
				for (i = 0; i < NUM_DEFAULT_KEYS; i++) {
					key = rcu_dereference(sdata->keys[i]);
					if (key)
						break;
				}
			}
			if (key)
				rx->key = key;
		}
		return RX_CONTINUE;
	} else {
		u8 keyid;
1636

1637 1638 1639 1640 1641 1642 1643 1644 1645 1646 1647 1648 1649 1650 1651
		/*
		 * The device doesn't give us the IV so we won't be
		 * able to look up the key. That's ok though, we
		 * don't need to decrypt the frame, we just won't
		 * be able to keep statistics accurate.
		 * Except for key threshold notifications, should
		 * we somehow allow the driver to tell us which key
		 * the hardware used if this flag is set?
		 */
		if ((status->flag & RX_FLAG_DECRYPTED) &&
		    (status->flag & RX_FLAG_IV_STRIPPED))
			return RX_CONTINUE;

		hdrlen = ieee80211_hdrlen(fc);

1652 1653
		if (cs) {
			keyidx = iwl80211_get_cs_keyid(cs, rx->skb);
1654

1655 1656 1657 1658 1659 1660 1661 1662 1663 1664 1665 1666
			if (unlikely(keyidx < 0))
				return RX_DROP_UNUSABLE;
		} else {
			if (rx->skb->len < 8 + hdrlen)
				return RX_DROP_UNUSABLE; /* TODO: count this? */
			/*
			 * no need to call ieee80211_wep_get_keyidx,
			 * it verifies a bunch of things we've done already
			 */
			skb_copy_bits(rx->skb, hdrlen + 3, &keyid, 1);
			keyidx = keyid >> 6;
		}
1667 1668 1669 1670 1671 1672 1673 1674 1675 1676 1677 1678 1679 1680 1681 1682 1683 1684 1685 1686 1687 1688 1689 1690 1691 1692 1693 1694 1695 1696 1697 1698 1699 1700 1701 1702 1703 1704 1705 1706

		/* check per-station GTK first, if multicast packet */
		if (is_multicast_ether_addr(hdr->addr1) && rx->sta)
			rx->key = rcu_dereference(rx->sta->gtk[keyidx]);

		/* if not found, try default key */
		if (!rx->key) {
			rx->key = rcu_dereference(rx->sdata->keys[keyidx]);

			/*
			 * RSNA-protected unicast frames should always be
			 * sent with pairwise or station-to-station keys,
			 * but for WEP we allow using a key index as well.
			 */
			if (rx->key &&
			    rx->key->conf.cipher != WLAN_CIPHER_SUITE_WEP40 &&
			    rx->key->conf.cipher != WLAN_CIPHER_SUITE_WEP104 &&
			    !is_multicast_ether_addr(hdr->addr1))
				rx->key = NULL;
		}
	}

	if (rx->key) {
		if (unlikely(rx->key->flags & KEY_FLAG_TAINTED))
			return RX_DROP_MONITOR;

		/* TODO: add threshold stuff again */
	} else {
		return RX_DROP_MONITOR;
	}

	switch (rx->key->conf.cipher) {
	case WLAN_CIPHER_SUITE_WEP40:
	case WLAN_CIPHER_SUITE_WEP104:
		result = ieee80211_crypto_wep_decrypt(rx);
		break;
	case WLAN_CIPHER_SUITE_TKIP:
		result = ieee80211_crypto_tkip_decrypt(rx);
		break;
	case WLAN_CIPHER_SUITE_CCMP:
J
Jouni Malinen 已提交
1707 1708 1709 1710 1711 1712
		result = ieee80211_crypto_ccmp_decrypt(
			rx, IEEE80211_CCMP_MIC_LEN);
		break;
	case WLAN_CIPHER_SUITE_CCMP_256:
		result = ieee80211_crypto_ccmp_decrypt(
			rx, IEEE80211_CCMP_256_MIC_LEN);
1713 1714 1715 1716
		break;
	case WLAN_CIPHER_SUITE_AES_CMAC:
		result = ieee80211_crypto_aes_cmac_decrypt(rx);
		break;
1717 1718 1719
	case WLAN_CIPHER_SUITE_BIP_CMAC_256:
		result = ieee80211_crypto_aes_cmac_256_decrypt(rx);
		break;
1720 1721 1722 1723
	case WLAN_CIPHER_SUITE_BIP_GMAC_128:
	case WLAN_CIPHER_SUITE_BIP_GMAC_256:
		result = ieee80211_crypto_aes_gmac_decrypt(rx);
		break;
1724 1725 1726 1727
	case WLAN_CIPHER_SUITE_GCMP:
	case WLAN_CIPHER_SUITE_GCMP_256:
		result = ieee80211_crypto_gcmp_decrypt(rx);
		break;
1728
	default:
1729
		result = ieee80211_crypto_hw_decrypt(rx);
1730 1731 1732 1733 1734 1735 1736 1737 1738 1739
	}

	/* the hdr variable is invalid after the decrypt handlers */

	/* either the frame has been decrypted or will be dropped */
	status->flag |= RX_FLAG_DECRYPTED;

	return result;
}

1740 1741 1742 1743 1744 1745 1746 1747 1748 1749 1750
static inline struct ieee80211_fragment_entry *
ieee80211_reassemble_add(struct ieee80211_sub_if_data *sdata,
			 unsigned int frag, unsigned int seq, int rx_queue,
			 struct sk_buff **skb)
{
	struct ieee80211_fragment_entry *entry;

	entry = &sdata->fragments[sdata->fragment_next++];
	if (sdata->fragment_next >= IEEE80211_FRAGMENT_MAX)
		sdata->fragment_next = 0;

J
Johannes Berg 已提交
1751
	if (!skb_queue_empty(&entry->skb_list))
1752 1753 1754 1755 1756 1757 1758 1759 1760 1761 1762 1763 1764 1765 1766 1767
		__skb_queue_purge(&entry->skb_list);

	__skb_queue_tail(&entry->skb_list, *skb); /* no need for locking */
	*skb = NULL;
	entry->first_frag_time = jiffies;
	entry->seq = seq;
	entry->rx_queue = rx_queue;
	entry->last_frag = frag;
	entry->ccmp = 0;
	entry->extra_len = 0;

	return entry;
}

static inline struct ieee80211_fragment_entry *
ieee80211_reassemble_find(struct ieee80211_sub_if_data *sdata,
1768
			  unsigned int frag, unsigned int seq,
1769 1770 1771 1772 1773 1774 1775 1776 1777 1778 1779 1780 1781 1782 1783 1784 1785 1786 1787
			  int rx_queue, struct ieee80211_hdr *hdr)
{
	struct ieee80211_fragment_entry *entry;
	int i, idx;

	idx = sdata->fragment_next;
	for (i = 0; i < IEEE80211_FRAGMENT_MAX; i++) {
		struct ieee80211_hdr *f_hdr;

		idx--;
		if (idx < 0)
			idx = IEEE80211_FRAGMENT_MAX - 1;

		entry = &sdata->fragments[idx];
		if (skb_queue_empty(&entry->skb_list) || entry->seq != seq ||
		    entry->rx_queue != rx_queue ||
		    entry->last_frag + 1 != frag)
			continue;

1788
		f_hdr = (struct ieee80211_hdr *)entry->skb_list.next->data;
1789

1790 1791 1792 1793 1794
		/*
		 * Check ftype and addresses are equal, else check next fragment
		 */
		if (((hdr->frame_control ^ f_hdr->frame_control) &
		     cpu_to_le16(IEEE80211_FCTL_FTYPE)) ||
1795 1796
		    !ether_addr_equal(hdr->addr1, f_hdr->addr1) ||
		    !ether_addr_equal(hdr->addr2, f_hdr->addr2))
1797 1798
			continue;

1799
		if (time_after(jiffies, entry->first_frag_time + 2 * HZ)) {
1800 1801 1802 1803 1804 1805 1806 1807 1808
			__skb_queue_purge(&entry->skb_list);
			continue;
		}
		return entry;
	}

	return NULL;
}

1809
static ieee80211_rx_result debug_noinline
1810
ieee80211_rx_h_defragment(struct ieee80211_rx_data *rx)
1811 1812 1813
{
	struct ieee80211_hdr *hdr;
	u16 sc;
1814
	__le16 fc;
1815 1816 1817
	unsigned int frag, seq;
	struct ieee80211_fragment_entry *entry;
	struct sk_buff *skb;
1818
	struct ieee80211_rx_status *status;
1819

1820
	hdr = (struct ieee80211_hdr *)rx->skb->data;
1821
	fc = hdr->frame_control;
1822 1823 1824 1825

	if (ieee80211_is_ctl(fc))
		return RX_CONTINUE;

1826 1827 1828
	sc = le16_to_cpu(hdr->seq_ctrl);
	frag = sc & IEEE80211_SCTL_FRAG;

1829
	if (is_multicast_ether_addr(hdr->addr1)) {
1830
		I802_DEBUG_INC(rx->local->dot11MulticastReceivedFrameCount);
1831
		goto out_no_led;
1832
	}
1833

1834 1835 1836
	if (likely(!ieee80211_has_morefrags(fc) && frag == 0))
		goto out;

1837 1838
	I802_DEBUG_INC(rx->local->rx_handlers_fragments);

Z
Zhu Yi 已提交
1839 1840 1841
	if (skb_linearize(rx->skb))
		return RX_DROP_UNUSABLE;

1842 1843 1844 1845 1846 1847
	/*
	 *  skb_linearize() might change the skb->data and
	 *  previously cached variables (in this case, hdr) need to
	 *  be refreshed with the new data.
	 */
	hdr = (struct ieee80211_hdr *)rx->skb->data;
1848 1849 1850 1851 1852
	seq = (sc & IEEE80211_SCTL_SEQ) >> 4;

	if (frag == 0) {
		/* This is the first fragment of a new frame. */
		entry = ieee80211_reassemble_add(rx->sdata, frag, seq,
1853
						 rx->seqno_idx, &(rx->skb));
J
Jouni Malinen 已提交
1854 1855 1856
		if (rx->key &&
		    (rx->key->conf.cipher == WLAN_CIPHER_SUITE_CCMP ||
		     rx->key->conf.cipher == WLAN_CIPHER_SUITE_CCMP_256) &&
1857
		    ieee80211_has_protected(fc)) {
1858
			int queue = rx->security_idx;
1859 1860 1861 1862
			/* Store CCMP PN so that we can verify that the next
			 * fragment has a sequential PN value. */
			entry->ccmp = 1;
			memcpy(entry->last_pn,
1863
			       rx->key->u.ccmp.rx_pn[queue],
1864
			       IEEE80211_CCMP_PN_LEN);
1865
		}
1866
		return RX_QUEUED;
1867 1868 1869 1870 1871
	}

	/* This is a fragment for a frame that should already be pending in
	 * fragment cache. Add this fragment to the end of the pending entry.
	 */
1872 1873
	entry = ieee80211_reassemble_find(rx->sdata, frag, seq,
					  rx->seqno_idx, hdr);
1874 1875
	if (!entry) {
		I802_DEBUG_INC(rx->local->rx_handlers_drop_defrag);
J
Johannes Berg 已提交
1876
		return RX_DROP_MONITOR;
1877 1878 1879 1880 1881 1882
	}

	/* Verify that MPDUs within one MSDU have sequential PN values.
	 * (IEEE 802.11i, 8.3.3.4.5) */
	if (entry->ccmp) {
		int i;
1883
		u8 pn[IEEE80211_CCMP_PN_LEN], *rpn;
1884
		int queue;
J
Jouni Malinen 已提交
1885 1886 1887
		if (!rx->key ||
		    (rx->key->conf.cipher != WLAN_CIPHER_SUITE_CCMP &&
		     rx->key->conf.cipher != WLAN_CIPHER_SUITE_CCMP_256))
J
Johannes Berg 已提交
1888
			return RX_DROP_UNUSABLE;
1889 1890
		memcpy(pn, entry->last_pn, IEEE80211_CCMP_PN_LEN);
		for (i = IEEE80211_CCMP_PN_LEN - 1; i >= 0; i--) {
1891 1892 1893 1894
			pn[i]++;
			if (pn[i])
				break;
		}
1895
		queue = rx->security_idx;
1896
		rpn = rx->key->u.ccmp.rx_pn[queue];
1897
		if (memcmp(pn, rpn, IEEE80211_CCMP_PN_LEN))
J
Johannes Berg 已提交
1898
			return RX_DROP_UNUSABLE;
1899
		memcpy(entry->last_pn, pn, IEEE80211_CCMP_PN_LEN);
1900 1901
	}

1902
	skb_pull(rx->skb, ieee80211_hdrlen(fc));
1903 1904 1905
	__skb_queue_tail(&entry->skb_list, rx->skb);
	entry->last_frag = frag;
	entry->extra_len += rx->skb->len;
1906
	if (ieee80211_has_morefrags(fc)) {
1907
		rx->skb = NULL;
1908
		return RX_QUEUED;
1909 1910 1911 1912
	}

	rx->skb = __skb_dequeue(&entry->skb_list);
	if (skb_tailroom(rx->skb) < entry->extra_len) {
1913
		I802_DEBUG_INC(rx->local->rx_expand_skb_head_defrag);
1914 1915 1916 1917
		if (unlikely(pskb_expand_head(rx->skb, 0, entry->extra_len,
					      GFP_ATOMIC))) {
			I802_DEBUG_INC(rx->local->rx_handlers_drop_defrag);
			__skb_queue_purge(&entry->skb_list);
J
Johannes Berg 已提交
1918
			return RX_DROP_UNUSABLE;
1919 1920 1921 1922 1923 1924 1925 1926
		}
	}
	while ((skb = __skb_dequeue(&entry->skb_list))) {
		memcpy(skb_put(rx->skb, skb->len), skb->data, skb->len);
		dev_kfree_skb(skb);
	}

	/* Complete frame has been reassembled - process it now */
1927
	status = IEEE80211_SKB_RXCB(rx->skb);
1928 1929

 out:
1930 1931
	ieee80211_led_rx(rx->local);
 out_no_led:
1932
	if (rx->sta)
1933
		rx->sta->rx_stats.packets++;
1934
	return RX_CONTINUE;
1935 1936
}

J
Johannes Berg 已提交
1937
static int ieee80211_802_1x_port_control(struct ieee80211_rx_data *rx)
1938
{
J
Johannes Berg 已提交
1939
	if (unlikely(!rx->sta || !test_sta_flag(rx->sta, WLAN_STA_AUTHORIZED)))
1940
		return -EACCES;
1941

1942
	return 0;
1943 1944
}

J
Johannes Berg 已提交
1945
static int ieee80211_drop_unencrypted(struct ieee80211_rx_data *rx, __le16 fc)
1946
{
J
Johannes Berg 已提交
1947 1948 1949
	struct sk_buff *skb = rx->skb;
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);

1950
	/*
1951 1952
	 * Pass through unencrypted frames if the hardware has
	 * decrypted them already.
1953
	 */
J
Johannes Berg 已提交
1954
	if (status->flag & RX_FLAG_DECRYPTED)
1955
		return 0;
1956 1957

	/* Drop unencrypted frames if key is set. */
1958 1959
	if (unlikely(!ieee80211_has_protected(fc) &&
		     !ieee80211_is_nullfunc(fc) &&
1960
		     ieee80211_is_data(fc) && rx->key))
1961
		return -EACCES;
1962 1963 1964 1965

	return 0;
}

J
Johannes Berg 已提交
1966
static int ieee80211_drop_unencrypted_mgmt(struct ieee80211_rx_data *rx)
1967 1968
{
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
1969
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
1970 1971
	__le16 fc = hdr->frame_control;

1972 1973 1974 1975 1976 1977
	/*
	 * Pass through unencrypted frames if the hardware has
	 * decrypted them already.
	 */
	if (status->flag & RX_FLAG_DECRYPTED)
		return 0;
1978

J
Johannes Berg 已提交
1979
	if (rx->sta && test_sta_flag(rx->sta, WLAN_STA_MFP)) {
1980 1981
		if (unlikely(!ieee80211_has_protected(fc) &&
			     ieee80211_is_unicast_robust_mgmt_frame(rx->skb) &&
1982
			     rx->key)) {
1983 1984 1985 1986 1987
			if (ieee80211_is_deauth(fc) ||
			    ieee80211_is_disassoc(fc))
				cfg80211_rx_unprot_mlme_mgmt(rx->sdata->dev,
							     rx->skb->data,
							     rx->skb->len);
1988
			return -EACCES;
1989
		}
1990
		/* BIP does not use Protected field, so need to check MMIE */
1991
		if (unlikely(ieee80211_is_multicast_robust_mgmt_frame(rx->skb) &&
1992
			     ieee80211_get_mmie_keyidx(rx->skb) < 0)) {
1993 1994 1995 1996 1997
			if (ieee80211_is_deauth(fc) ||
			    ieee80211_is_disassoc(fc))
				cfg80211_rx_unprot_mlme_mgmt(rx->sdata->dev,
							     rx->skb->data,
							     rx->skb->len);
1998
			return -EACCES;
1999
		}
2000 2001 2002 2003 2004
		/*
		 * When using MFP, Action frames are not allowed prior to
		 * having configured keys.
		 */
		if (unlikely(ieee80211_is_action(fc) && !rx->key &&
2005
			     ieee80211_is_robust_mgmt_frame(rx->skb)))
2006 2007
			return -EACCES;
	}
2008

2009
	return 0;
2010 2011
}

2012
static int
2013
__ieee80211_data_to_8023(struct ieee80211_rx_data *rx, bool *port_control)
2014
{
J
Johannes Berg 已提交
2015
	struct ieee80211_sub_if_data *sdata = rx->sdata;
2016
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
2017 2018 2019
	bool check_port_control = false;
	struct ethhdr *ehdr;
	int ret;
2020

2021
	*port_control = false;
2022 2023
	if (ieee80211_has_a4(hdr->frame_control) &&
	    sdata->vif.type == NL80211_IFTYPE_AP_VLAN && !sdata->u.vlan.sta)
2024
		return -1;
2025

2026 2027 2028 2029 2030 2031 2032 2033 2034
	if (sdata->vif.type == NL80211_IFTYPE_STATION &&
	    !!sdata->u.mgd.use_4addr != !!ieee80211_has_a4(hdr->frame_control)) {

		if (!sdata->u.mgd.use_4addr)
			return -1;
		else
			check_port_control = true;
	}

2035
	if (is_multicast_ether_addr(hdr->addr1) &&
2036
	    sdata->vif.type == NL80211_IFTYPE_AP_VLAN && sdata->u.vlan.sta)
2037
		return -1;
2038

2039
	ret = ieee80211_data_to_8023(rx->skb, sdata->vif.addr, sdata->vif.type);
2040
	if (ret < 0)
2041 2042 2043
		return ret;

	ehdr = (struct ethhdr *) rx->skb->data;
2044 2045 2046
	if (ehdr->h_proto == rx->sdata->control_port_protocol)
		*port_control = true;
	else if (check_port_control)
2047 2048 2049
		return -1;

	return 0;
2050
}
2051

2052 2053 2054
/*
 * requires that rx->skb is a frame with ethernet header
 */
2055
static bool ieee80211_frame_allowed(struct ieee80211_rx_data *rx, __le16 fc)
2056
{
2057
	static const u8 pae_group_addr[ETH_ALEN] __aligned(2)
2058 2059 2060 2061 2062 2063 2064
		= { 0x01, 0x80, 0xC2, 0x00, 0x00, 0x03 };
	struct ethhdr *ehdr = (struct ethhdr *) rx->skb->data;

	/*
	 * Allow EAPOL frames to us/the PAE group address regardless
	 * of whether the frame was encrypted or not.
	 */
2065
	if (ehdr->h_proto == rx->sdata->control_port_protocol &&
2066 2067
	    (ether_addr_equal(ehdr->h_dest, rx->sdata->vif.addr) ||
	     ether_addr_equal(ehdr->h_dest, pae_group_addr)))
2068 2069 2070
		return true;

	if (ieee80211_802_1x_port_control(rx) ||
2071
	    ieee80211_drop_unencrypted(rx, fc))
2072 2073 2074 2075 2076 2077 2078 2079
		return false;

	return true;
}

/*
 * requires that rx->skb is a frame with ethernet header
 */
2080
static void
2081
ieee80211_deliver_skb(struct ieee80211_rx_data *rx)
2082
{
J
Johannes Berg 已提交
2083 2084
	struct ieee80211_sub_if_data *sdata = rx->sdata;
	struct net_device *dev = sdata->dev;
2085
	struct sk_buff *skb, *xmit_skb;
2086 2087
	struct ethhdr *ehdr = (struct ethhdr *) rx->skb->data;
	struct sta_info *dsta;
2088

2089 2090
	skb = rx->skb;
	xmit_skb = NULL;
2091

2092 2093
	ieee80211_rx_stats(dev, skb->len);

2094 2095
	if ((sdata->vif.type == NL80211_IFTYPE_AP ||
	     sdata->vif.type == NL80211_IFTYPE_AP_VLAN) &&
2096
	    !(sdata->flags & IEEE80211_SDATA_DONT_BRIDGE_PACKETS) &&
2097
	    (sdata->vif.type != NL80211_IFTYPE_AP_VLAN || !sdata->u.vlan.sta)) {
2098 2099 2100 2101 2102
		if (is_multicast_ether_addr(ehdr->h_dest)) {
			/*
			 * send multicast frames both to higher layers in
			 * local net stack and back to the wireless medium
			 */
2103
			xmit_skb = skb_copy(skb, GFP_ATOMIC);
2104
			if (!xmit_skb)
J
Johannes Berg 已提交
2105
				net_info_ratelimited("%s: failed to clone multicast frame\n",
2106
						    dev->name);
2107
		} else {
2108 2109
			dsta = sta_info_get(sdata, skb->data);
			if (dsta) {
2110 2111 2112 2113 2114
				/*
				 * The destination station is associated to
				 * this AP (in this VLAN), so send the frame
				 * directly to it and do not pass it to local
				 * net stack.
2115
				 */
2116
				xmit_skb = skb;
2117 2118 2119 2120 2121
				skb = NULL;
			}
		}
	}

2122
#ifndef CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS
2123 2124 2125 2126 2127 2128
	if (skb) {
		/* 'align' will only take the values 0 or 2 here since all
		 * frames are required to be aligned to 2-byte boundaries
		 * when being passed to mac80211; the code here works just
		 * as well if that isn't true, but mac80211 assumes it can
		 * access fields as 2-byte aligned (e.g. for ether_addr_equal)
2129
		 */
2130 2131 2132
		int align;

		align = (unsigned long)(skb->data + sizeof(struct ethhdr)) & 3;
2133 2134 2135 2136 2137 2138
		if (align) {
			if (WARN_ON(skb_headroom(skb) < 3)) {
				dev_kfree_skb(skb);
				skb = NULL;
			} else {
				u8 *data = skb->data;
2139 2140 2141 2142
				size_t len = skb_headlen(skb);
				skb->data -= align;
				memmove(skb->data, data, len);
				skb_set_tail_pointer(skb, len);
2143 2144
			}
		}
2145
	}
2146 2147
#endif

2148 2149 2150 2151
	if (skb) {
		/* deliver to local stack */
		skb->protocol = eth_type_trans(skb, dev);
		memset(skb->cb, 0, sizeof(skb->cb));
2152 2153
		if (rx->napi)
			napi_gro_receive(rx->napi, skb);
J
Johannes Berg 已提交
2154 2155
		else
			netif_receive_skb(skb);
2156 2157
	}

2158
	if (xmit_skb) {
2159 2160 2161 2162 2163 2164
		/*
		 * Send to wireless media and increase priority by 256 to
		 * keep the received priority instead of reclassifying
		 * the frame (see cfg80211_classify8021d).
		 */
		xmit_skb->priority += 256;
2165
		xmit_skb->protocol = htons(ETH_P_802_3);
2166 2167
		skb_reset_network_header(xmit_skb);
		skb_reset_mac_header(xmit_skb);
2168
		dev_queue_xmit(xmit_skb);
2169
	}
2170 2171
}

2172
static ieee80211_rx_result debug_noinline
2173
ieee80211_rx_h_amsdu(struct ieee80211_rx_data *rx)
2174
{
J
Johannes Berg 已提交
2175
	struct net_device *dev = rx->sdata->dev;
Z
Zhu Yi 已提交
2176
	struct sk_buff *skb = rx->skb;
2177 2178
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)skb->data;
	__le16 fc = hdr->frame_control;
Z
Zhu Yi 已提交
2179
	struct sk_buff_head frame_list;
2180
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
2181

2182
	if (unlikely(!ieee80211_is_data(fc)))
2183
		return RX_CONTINUE;
2184

2185
	if (unlikely(!ieee80211_is_data_present(fc)))
J
Johannes Berg 已提交
2186
		return RX_DROP_MONITOR;
2187

2188
	if (!(status->rx_flags & IEEE80211_RX_AMSDU))
2189
		return RX_CONTINUE;
2190

Z
Zhu Yi 已提交
2191 2192 2193
	if (ieee80211_has_a4(hdr->frame_control) &&
	    rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN &&
	    !rx->sdata->u.vlan.sta)
J
Johannes Berg 已提交
2194
		return RX_DROP_UNUSABLE;
2195

Z
Zhu Yi 已提交
2196 2197 2198 2199 2200
	if (is_multicast_ether_addr(hdr->addr1) &&
	    ((rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN &&
	      rx->sdata->u.vlan.sta) ||
	     (rx->sdata->vif.type == NL80211_IFTYPE_STATION &&
	      rx->sdata->u.mgd.use_4addr)))
J
Johannes Berg 已提交
2201
		return RX_DROP_UNUSABLE;
2202

Z
Zhu Yi 已提交
2203 2204
	skb->dev = dev;
	__skb_queue_head_init(&frame_list);
2205

Z
Zhu Yi 已提交
2206 2207 2208
	if (skb_linearize(skb))
		return RX_DROP_UNUSABLE;

Z
Zhu Yi 已提交
2209 2210
	ieee80211_amsdu_to_8023s(skb, &frame_list, dev->dev_addr,
				 rx->sdata->vif.type,
2211
				 rx->local->hw.extra_tx_headroom, true);
2212

Z
Zhu Yi 已提交
2213 2214
	while (!skb_queue_empty(&frame_list)) {
		rx->skb = __skb_dequeue(&frame_list);
2215

2216
		if (!ieee80211_frame_allowed(rx, fc)) {
Z
Zhu Yi 已提交
2217
			dev_kfree_skb(rx->skb);
2218 2219
			continue;
		}
2220 2221 2222 2223

		ieee80211_deliver_skb(rx);
	}

2224
	return RX_QUEUED;
2225 2226
}

I
Ingo Molnar 已提交
2227
#ifdef CONFIG_MAC80211_MESH
2228
static ieee80211_rx_result
2229 2230
ieee80211_rx_h_mesh_fwding(struct ieee80211_rx_data *rx)
{
2231 2232
	struct ieee80211_hdr *fwd_hdr, *hdr;
	struct ieee80211_tx_info *info;
2233 2234
	struct ieee80211s_hdr *mesh_hdr;
	struct sk_buff *skb = rx->skb, *fwd_skb;
J
Johannes Berg 已提交
2235
	struct ieee80211_local *local = rx->local;
J
Johannes Berg 已提交
2236
	struct ieee80211_sub_if_data *sdata = rx->sdata;
2237
	struct ieee80211_if_mesh *ifmsh = &sdata->u.mesh;
2238
	u16 ac, q, hdrlen;
2239 2240 2241

	hdr = (struct ieee80211_hdr *) skb->data;
	hdrlen = ieee80211_hdrlen(hdr->frame_control);
2242 2243 2244 2245 2246 2247 2248 2249 2250 2251 2252 2253 2254 2255

	/* make sure fixed part of mesh header is there, also checks skb len */
	if (!pskb_may_pull(rx->skb, hdrlen + 6))
		return RX_DROP_MONITOR;

	mesh_hdr = (struct ieee80211s_hdr *) (skb->data + hdrlen);

	/* make sure full mesh header is there, also checks skb len */
	if (!pskb_may_pull(rx->skb,
			   hdrlen + ieee80211_get_mesh_hdrlen(mesh_hdr)))
		return RX_DROP_MONITOR;

	/* reload pointers */
	hdr = (struct ieee80211_hdr *) skb->data;
2256 2257
	mesh_hdr = (struct ieee80211s_hdr *) (skb->data + hdrlen);

2258 2259 2260
	if (ieee80211_drop_unencrypted(rx, hdr->frame_control))
		return RX_DROP_MONITOR;

2261 2262 2263
	/* frame is in RMC, don't forward */
	if (ieee80211_is_data(hdr->frame_control) &&
	    is_multicast_ether_addr(hdr->addr1) &&
J
Johannes Berg 已提交
2264
	    mesh_rmc_check(rx->sdata, hdr->addr3, mesh_hdr))
2265 2266
		return RX_DROP_MONITOR;

2267
	if (!ieee80211_is_data(hdr->frame_control))
2268 2269 2270 2271 2272
		return RX_CONTINUE;

	if (!mesh_hdr->ttl)
		return RX_DROP_MONITOR;

2273
	if (mesh_hdr->flags & MESH_FLAGS_AE) {
2274
		struct mesh_path *mppath;
2275 2276 2277 2278 2279 2280
		char *proxied_addr;
		char *mpp_addr;

		if (is_multicast_ether_addr(hdr->addr1)) {
			mpp_addr = hdr->addr3;
			proxied_addr = mesh_hdr->eaddr1;
2281 2282
		} else if (mesh_hdr->flags & MESH_FLAGS_AE_A5_A6) {
			/* has_a4 already checked in ieee80211_rx_mesh_check */
2283 2284
			mpp_addr = hdr->addr4;
			proxied_addr = mesh_hdr->eaddr2;
2285 2286
		} else {
			return RX_DROP_MONITOR;
2287
		}
2288 2289

		rcu_read_lock();
J
Johannes Berg 已提交
2290
		mppath = mpp_path_lookup(sdata, proxied_addr);
2291
		if (!mppath) {
J
Johannes Berg 已提交
2292
			mpp_path_add(sdata, proxied_addr, mpp_addr);
2293 2294
		} else {
			spin_lock_bh(&mppath->state_lock);
2295
			if (!ether_addr_equal(mppath->mpp, mpp_addr))
2296
				memcpy(mppath->mpp, mpp_addr, ETH_ALEN);
2297 2298 2299 2300 2301
			spin_unlock_bh(&mppath->state_lock);
		}
		rcu_read_unlock();
	}

2302 2303
	/* Frame has reached destination.  Don't forward */
	if (!is_multicast_ether_addr(hdr->addr1) &&
2304
	    ether_addr_equal(sdata->vif.addr, hdr->addr3))
2305 2306
		return RX_CONTINUE;

2307 2308
	ac = ieee80211_select_queue_80211(sdata, skb, hdr);
	q = sdata->vif.hw_queue[ac];
2309
	if (ieee80211_queue_stopped(&local->hw, q)) {
2310
		IEEE80211_IFSTA_MESH_CTR_INC(ifmsh, dropped_frames_congestion);
2311 2312 2313
		return RX_DROP_MONITOR;
	}
	skb_set_queue_mapping(skb, q);
2314

2315 2316
	if (!--mesh_hdr->ttl) {
		IEEE80211_IFSTA_MESH_CTR_INC(ifmsh, dropped_frames_ttl);
2317
		goto out;
2318 2319
	}

2320 2321 2322
	if (!ifmsh->mshcfg.dot11MeshForwarding)
		goto out;

2323 2324
	fwd_skb = skb_copy(skb, GFP_ATOMIC);
	if (!fwd_skb) {
J
Johannes Berg 已提交
2325
		net_info_ratelimited("%s: failed to clone mesh frame\n",
2326
				    sdata->name);
2327 2328 2329 2330
		goto out;
	}

	fwd_hdr =  (struct ieee80211_hdr *) fwd_skb->data;
2331
	fwd_hdr->frame_control &= ~cpu_to_le16(IEEE80211_FCTL_RETRY);
2332 2333 2334 2335 2336 2337 2338 2339
	info = IEEE80211_SKB_CB(fwd_skb);
	memset(info, 0, sizeof(*info));
	info->flags |= IEEE80211_TX_INTFL_NEED_TXPROCESSING;
	info->control.vif = &rx->sdata->vif;
	info->control.jiffies = jiffies;
	if (is_multicast_ether_addr(fwd_hdr->addr1)) {
		IEEE80211_IFSTA_MESH_CTR_INC(ifmsh, fwded_mcast);
		memcpy(fwd_hdr->addr2, sdata->vif.addr, ETH_ALEN);
M
Marco Porsch 已提交
2340 2341
		/* update power mode indication when forwarding */
		ieee80211_mps_set_frame_flags(sdata, NULL, fwd_hdr);
J
Johannes Berg 已提交
2342
	} else if (!mesh_nexthop_lookup(sdata, fwd_skb)) {
M
Marco Porsch 已提交
2343
		/* mesh power mode flags updated in mesh_nexthop_lookup */
2344 2345 2346
		IEEE80211_IFSTA_MESH_CTR_INC(ifmsh, fwded_unicast);
	} else {
		/* unable to resolve next hop */
J
Johannes Berg 已提交
2347
		mesh_path_error_tx(sdata, ifmsh->mshcfg.element_ttl,
2348 2349 2350
				   fwd_hdr->addr3, 0,
				   WLAN_REASON_MESH_PATH_NOFORWARD,
				   fwd_hdr->addr2);
2351
		IEEE80211_IFSTA_MESH_CTR_INC(ifmsh, dropped_frames_no_route);
2352
		kfree_skb(fwd_skb);
2353
		return RX_DROP_MONITOR;
2354 2355
	}

2356 2357
	IEEE80211_IFSTA_MESH_CTR_INC(ifmsh, fwded_frames);
	ieee80211_add_pending_skb(local, fwd_skb);
J
Johannes Berg 已提交
2358
 out:
2359
	if (is_multicast_ether_addr(hdr->addr1))
2360
		return RX_CONTINUE;
2361
	return RX_DROP_MONITOR;
2362
}
I
Ingo Molnar 已提交
2363
#endif
2364

2365
static ieee80211_rx_result debug_noinline
2366
ieee80211_rx_h_data(struct ieee80211_rx_data *rx)
2367
{
J
Johannes Berg 已提交
2368
	struct ieee80211_sub_if_data *sdata = rx->sdata;
2369
	struct ieee80211_local *local = rx->local;
J
Johannes Berg 已提交
2370
	struct net_device *dev = sdata->dev;
2371 2372
	struct ieee80211_hdr *hdr = (struct ieee80211_hdr *)rx->skb->data;
	__le16 fc = hdr->frame_control;
2373
	bool port_control;
2374
	int err;
2375

2376
	if (unlikely(!ieee80211_is_data(hdr->frame_control)))
2377
		return RX_CONTINUE;
2378

2379
	if (unlikely(!ieee80211_is_data_present(hdr->frame_control)))
J
Johannes Berg 已提交
2380
		return RX_DROP_MONITOR;
2381

2382
	if (rx->sta) {
2383
		/* The seqno index has the same property as needed
2384 2385 2386 2387
		 * for the rx_msdu field, i.e. it is IEEE80211_NUM_TIDS
		 * for non-QoS-data frames. Here we know it's a data
		 * frame, so count MSDUs.
		 */
2388
		rx->sta->rx_stats.msdu[rx->seqno_idx]++;
2389 2390
	}

2391
	/*
2392 2393
	 * Send unexpected-4addr-frame event to hostapd. For older versions,
	 * also drop the frame to cooked monitor interfaces.
2394 2395
	 */
	if (ieee80211_has_a4(hdr->frame_control) &&
2396 2397 2398 2399 2400
	    sdata->vif.type == NL80211_IFTYPE_AP) {
		if (rx->sta &&
		    !test_and_set_sta_flag(rx->sta, WLAN_STA_4ADDR_EVENT))
			cfg80211_rx_unexpected_4addr_frame(
				rx->sdata->dev, rx->sta->sta.addr, GFP_ATOMIC);
2401
		return RX_DROP_MONITOR;
2402
	}
2403

2404
	err = __ieee80211_data_to_8023(rx, &port_control);
2405
	if (unlikely(err))
J
Johannes Berg 已提交
2406
		return RX_DROP_UNUSABLE;
2407

2408
	if (!ieee80211_frame_allowed(rx, fc))
J
Johannes Berg 已提交
2409
		return RX_DROP_MONITOR;
2410

2411 2412 2413 2414 2415 2416 2417 2418 2419 2420 2421
	/* directly handle TDLS channel switch requests/responses */
	if (unlikely(((struct ethhdr *)rx->skb->data)->h_proto ==
						cpu_to_be16(ETH_P_TDLS))) {
		struct ieee80211_tdls_data *tf = (void *)rx->skb->data;

		if (pskb_may_pull(rx->skb,
				  offsetof(struct ieee80211_tdls_data, u)) &&
		    tf->payload_type == WLAN_TDLS_SNAP_RFTYPE &&
		    tf->category == WLAN_CATEGORY_TDLS &&
		    (tf->action_code == WLAN_TDLS_CHANNEL_SWITCH_REQUEST ||
		     tf->action_code == WLAN_TDLS_CHANNEL_SWITCH_RESPONSE)) {
2422 2423
			skb_queue_tail(&local->skb_queue_tdls_chsw, rx->skb);
			schedule_work(&local->tdls_chsw_work);
2424
			if (rx->sta)
2425
				rx->sta->rx_stats.packets++;
2426 2427 2428 2429 2430

			return RX_QUEUED;
		}
	}

2431 2432 2433 2434 2435 2436 2437 2438
	if (rx->sdata->vif.type == NL80211_IFTYPE_AP_VLAN &&
	    unlikely(port_control) && sdata->bss) {
		sdata = container_of(sdata->bss, struct ieee80211_sub_if_data,
				     u.ap);
		dev = sdata->dev;
		rx->sdata = sdata;
	}

2439 2440
	rx->skb->dev = dev;

2441
	if (local->ps_sdata && local->hw.conf.dynamic_ps_timeout > 0 &&
2442 2443 2444 2445
	    !is_multicast_ether_addr(
		    ((struct ethhdr *)rx->skb->data)->h_dest) &&
	    (!local->scanning &&
	     !test_bit(SDATA_STATE_OFFCHANNEL, &sdata->state))) {
2446 2447 2448 2449
			mod_timer(&local->dynamic_ps_timer, jiffies +
			 msecs_to_jiffies(local->hw.conf.dynamic_ps_timeout));
	}

2450
	ieee80211_deliver_skb(rx);
2451

2452
	return RX_QUEUED;
2453 2454
}

2455
static ieee80211_rx_result debug_noinline
2456
ieee80211_rx_h_ctrl(struct ieee80211_rx_data *rx, struct sk_buff_head *frames)
2457 2458
{
	struct sk_buff *skb = rx->skb;
2459
	struct ieee80211_bar *bar = (struct ieee80211_bar *)skb->data;
2460 2461 2462 2463
	struct tid_ampdu_rx *tid_agg_rx;
	u16 start_seq_num;
	u16 tid;

2464
	if (likely(!ieee80211_is_ctl(bar->frame_control)))
2465
		return RX_CONTINUE;
2466

2467
	if (ieee80211_is_back_req(bar->frame_control)) {
2468 2469 2470
		struct {
			__le16 control, start_seq_num;
		} __packed bar_data;
2471 2472 2473
		struct ieee80211_event event = {
			.type = BAR_RX_EVENT,
		};
2474

2475
		if (!rx->sta)
2476
			return RX_DROP_MONITOR;
2477 2478 2479 2480 2481 2482

		if (skb_copy_bits(skb, offsetof(struct ieee80211_bar, control),
				  &bar_data, sizeof(bar_data)))
			return RX_DROP_MONITOR;

		tid = le16_to_cpu(bar_data.control) >> 12;
2483 2484 2485

		tid_agg_rx = rcu_dereference(rx->sta->ampdu_mlme.tid_rx[tid]);
		if (!tid_agg_rx)
2486
			return RX_DROP_MONITOR;
2487

2488
		start_seq_num = le16_to_cpu(bar_data.start_seq_num) >> 4;
2489 2490 2491
		event.u.ba.tid = tid;
		event.u.ba.ssn = start_seq_num;
		event.u.ba.sta = &rx->sta->sta;
2492 2493

		/* reset session timer */
2494 2495 2496
		if (tid_agg_rx->timeout)
			mod_timer(&tid_agg_rx->session_timer,
				  TU_TO_EXP_TIME(tid_agg_rx->timeout));
2497

2498
		spin_lock(&tid_agg_rx->reorder_lock);
2499
		/* release stored frames up to start of BAR */
2500
		ieee80211_release_reorder_frames(rx->sdata, tid_agg_rx,
2501
						 start_seq_num, frames);
2502 2503
		spin_unlock(&tid_agg_rx->reorder_lock);

2504 2505
		drv_event_callback(rx->local, rx->sdata, &event);

2506 2507
		kfree_skb(skb);
		return RX_QUEUED;
2508 2509
	}

2510 2511 2512 2513 2514 2515
	/*
	 * After this point, we only want management frames,
	 * so we can drop all remaining control frames to
	 * cooked monitor interfaces.
	 */
	return RX_DROP_MONITOR;
2516 2517
}

2518 2519 2520
static void ieee80211_process_sa_query_req(struct ieee80211_sub_if_data *sdata,
					   struct ieee80211_mgmt *mgmt,
					   size_t len)
2521 2522 2523 2524 2525
{
	struct ieee80211_local *local = sdata->local;
	struct sk_buff *skb;
	struct ieee80211_mgmt *resp;

2526
	if (!ether_addr_equal(mgmt->da, sdata->vif.addr)) {
2527 2528 2529 2530
		/* Not to own unicast address */
		return;
	}

2531 2532
	if (!ether_addr_equal(mgmt->sa, sdata->u.mgd.bssid) ||
	    !ether_addr_equal(mgmt->bssid, sdata->u.mgd.bssid)) {
2533
		/* Not from the current AP or not associated yet. */
2534 2535 2536 2537 2538 2539 2540 2541 2542 2543 2544 2545 2546 2547 2548 2549
		return;
	}

	if (len < 24 + 1 + sizeof(resp->u.action.u.sa_query)) {
		/* Too short SA Query request frame */
		return;
	}

	skb = dev_alloc_skb(sizeof(*resp) + local->hw.extra_tx_headroom);
	if (skb == NULL)
		return;

	skb_reserve(skb, local->hw.extra_tx_headroom);
	resp = (struct ieee80211_mgmt *) skb_put(skb, 24);
	memset(resp, 0, 24);
	memcpy(resp->da, mgmt->sa, ETH_ALEN);
2550
	memcpy(resp->sa, sdata->vif.addr, ETH_ALEN);
2551
	memcpy(resp->bssid, sdata->u.mgd.bssid, ETH_ALEN);
2552 2553 2554 2555 2556 2557 2558 2559 2560
	resp->frame_control = cpu_to_le16(IEEE80211_FTYPE_MGMT |
					  IEEE80211_STYPE_ACTION);
	skb_put(skb, 1 + sizeof(resp->u.action.u.sa_query));
	resp->u.action.category = WLAN_CATEGORY_SA_QUERY;
	resp->u.action.u.sa_query.action = WLAN_ACTION_SA_QUERY_RESPONSE;
	memcpy(resp->u.action.u.sa_query.trans_id,
	       mgmt->u.action.u.sa_query.trans_id,
	       WLAN_SA_QUERY_TR_ID_LEN);

2561
	ieee80211_tx_skb(sdata, skb);
2562 2563
}

2564 2565 2566 2567
static ieee80211_rx_result debug_noinline
ieee80211_rx_h_mgmt_check(struct ieee80211_rx_data *rx)
{
	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *) rx->skb->data;
2568
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
2569 2570 2571 2572 2573 2574 2575 2576 2577 2578 2579 2580

	/*
	 * From here on, look only at management frames.
	 * Data and control frames are already handled,
	 * and unknown (reserved) frames are useless.
	 */
	if (rx->skb->len < 24)
		return RX_DROP_MONITOR;

	if (!ieee80211_is_mgmt(mgmt->frame_control))
		return RX_DROP_MONITOR;

J
Johannes Berg 已提交
2581 2582 2583
	if (rx->sdata->vif.type == NL80211_IFTYPE_AP &&
	    ieee80211_is_beacon(mgmt->frame_control) &&
	    !(rx->flags & IEEE80211_RX_BEACON_REPORTED)) {
2584 2585
		int sig = 0;

2586
		if (ieee80211_hw_check(&rx->local->hw, SIGNAL_DBM))
2587 2588
			sig = status->signal;

J
Johannes Berg 已提交
2589 2590
		cfg80211_report_obss_beacon(rx->local->hw.wiphy,
					    rx->skb->data, rx->skb->len,
2591
					    status->freq, sig);
J
Johannes Berg 已提交
2592 2593 2594
		rx->flags |= IEEE80211_RX_BEACON_REPORTED;
	}

2595 2596 2597 2598 2599 2600
	if (ieee80211_drop_unencrypted_mgmt(rx))
		return RX_DROP_UNUSABLE;

	return RX_CONTINUE;
}

2601 2602 2603 2604
static ieee80211_rx_result debug_noinline
ieee80211_rx_h_action(struct ieee80211_rx_data *rx)
{
	struct ieee80211_local *local = rx->local;
J
Johannes Berg 已提交
2605
	struct ieee80211_sub_if_data *sdata = rx->sdata;
2606
	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *) rx->skb->data;
2607
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
2608 2609 2610 2611 2612
	int len = rx->skb->len;

	if (!ieee80211_is_action(mgmt->frame_control))
		return RX_CONTINUE;

2613 2614
	/* drop too small frames */
	if (len < IEEE80211_MIN_ACTION_SIZE)
2615
		return RX_DROP_UNUSABLE;
2616

2617
	if (!rx->sta && mgmt->u.action.category != WLAN_CATEGORY_PUBLIC &&
2618 2619
	    mgmt->u.action.category != WLAN_CATEGORY_SELF_PROTECTED &&
	    mgmt->u.action.category != WLAN_CATEGORY_SPECTRUM_MGMT)
2620
		return RX_DROP_UNUSABLE;
2621 2622

	switch (mgmt->u.action.category) {
2623 2624 2625 2626 2627 2628 2629 2630 2631 2632 2633 2634
	case WLAN_CATEGORY_HT:
		/* reject HT action frames from stations not supporting HT */
		if (!rx->sta->sta.ht_cap.ht_supported)
			goto invalid;

		if (sdata->vif.type != NL80211_IFTYPE_STATION &&
		    sdata->vif.type != NL80211_IFTYPE_MESH_POINT &&
		    sdata->vif.type != NL80211_IFTYPE_AP_VLAN &&
		    sdata->vif.type != NL80211_IFTYPE_AP &&
		    sdata->vif.type != NL80211_IFTYPE_ADHOC)
			break;

2635
		/* verify action & smps_control/chanwidth are present */
2636 2637 2638 2639 2640 2641
		if (len < IEEE80211_MIN_ACTION_SIZE + 2)
			goto invalid;

		switch (mgmt->u.action.u.ht_smps.action) {
		case WLAN_HT_ACTION_SMPS: {
			struct ieee80211_supported_band *sband;
2642
			enum ieee80211_smps_mode smps_mode;
2643 2644 2645 2646

			/* convert to HT capability */
			switch (mgmt->u.action.u.ht_smps.smps_control) {
			case WLAN_HT_SMPS_CONTROL_DISABLED:
2647
				smps_mode = IEEE80211_SMPS_OFF;
2648 2649
				break;
			case WLAN_HT_SMPS_CONTROL_STATIC:
2650
				smps_mode = IEEE80211_SMPS_STATIC;
2651 2652
				break;
			case WLAN_HT_SMPS_CONTROL_DYNAMIC:
2653
				smps_mode = IEEE80211_SMPS_DYNAMIC;
2654 2655 2656 2657 2658 2659
				break;
			default:
				goto invalid;
			}

			/* if no change do nothing */
2660
			if (rx->sta->sta.smps_mode == smps_mode)
2661
				goto handled;
2662
			rx->sta->sta.smps_mode = smps_mode;
2663 2664 2665

			sband = rx->local->hw.wiphy->bands[status->band];

2666 2667
			rate_control_rate_update(local, sband, rx->sta,
						 IEEE80211_RC_SMPS_CHANGED);
2668 2669
			goto handled;
		}
2670 2671 2672
		case WLAN_HT_ACTION_NOTIFY_CHANWIDTH: {
			struct ieee80211_supported_band *sband;
			u8 chanwidth = mgmt->u.action.u.ht_notify_cw.chanwidth;
2673
			enum ieee80211_sta_rx_bandwidth max_bw, new_bw;
2674 2675

			/* If it doesn't support 40 MHz it can't change ... */
2676 2677
			if (!(rx->sta->sta.ht_cap.cap &
					IEEE80211_HT_CAP_SUP_WIDTH_20_40))
2678 2679
				goto handled;

2680
			if (chanwidth == IEEE80211_HT_CHANWIDTH_20MHZ)
2681
				max_bw = IEEE80211_STA_RX_BW_20;
2682
			else
2683 2684 2685 2686 2687
				max_bw = ieee80211_sta_cap_rx_bw(rx->sta);

			/* set cur_max_bandwidth and recalc sta bw */
			rx->sta->cur_max_bandwidth = max_bw;
			new_bw = ieee80211_sta_cur_vht_bw(rx->sta);
2688

2689
			if (rx->sta->sta.bandwidth == new_bw)
2690 2691
				goto handled;

2692
			rx->sta->sta.bandwidth = new_bw;
2693 2694 2695 2696 2697 2698
			sband = rx->local->hw.wiphy->bands[status->band];

			rate_control_rate_update(local, sband, rx->sta,
						 IEEE80211_RC_BW_CHANGED);
			goto handled;
		}
2699 2700 2701 2702
		default:
			goto invalid;
		}

2703
		break;
2704 2705 2706 2707 2708 2709 2710 2711 2712 2713 2714 2715 2716 2717 2718 2719
	case WLAN_CATEGORY_PUBLIC:
		if (len < IEEE80211_MIN_ACTION_SIZE + 1)
			goto invalid;
		if (sdata->vif.type != NL80211_IFTYPE_STATION)
			break;
		if (!rx->sta)
			break;
		if (!ether_addr_equal(mgmt->bssid, sdata->u.mgd.bssid))
			break;
		if (mgmt->u.action.u.ext_chan_switch.action_code !=
				WLAN_PUB_ACTION_EXT_CHANSW_ANN)
			break;
		if (len < offsetof(struct ieee80211_mgmt,
				   u.action.u.ext_chan_switch.variable))
			goto invalid;
		goto queue;
2720 2721 2722 2723 2724 2725 2726 2727 2728 2729 2730 2731 2732 2733 2734 2735 2736 2737 2738 2739 2740 2741 2742
	case WLAN_CATEGORY_VHT:
		if (sdata->vif.type != NL80211_IFTYPE_STATION &&
		    sdata->vif.type != NL80211_IFTYPE_MESH_POINT &&
		    sdata->vif.type != NL80211_IFTYPE_AP_VLAN &&
		    sdata->vif.type != NL80211_IFTYPE_AP &&
		    sdata->vif.type != NL80211_IFTYPE_ADHOC)
			break;

		/* verify action code is present */
		if (len < IEEE80211_MIN_ACTION_SIZE + 1)
			goto invalid;

		switch (mgmt->u.action.u.vht_opmode_notif.action_code) {
		case WLAN_VHT_ACTION_OPMODE_NOTIF: {
			u8 opmode;

			/* verify opmode is present */
			if (len < IEEE80211_MIN_ACTION_SIZE + 2)
				goto invalid;

			opmode = mgmt->u.action.u.vht_opmode_notif.operating_mode;

			ieee80211_vht_handle_opmode(rx->sdata, rx->sta,
2743
						    opmode, status->band);
2744 2745
			goto handled;
		}
2746 2747 2748 2749 2750
		case WLAN_VHT_ACTION_GROUPID_MGMT: {
			if (len < IEEE80211_MIN_ACTION_SIZE + 25)
				goto invalid;
			goto queue;
		}
2751 2752 2753
		default:
			break;
		}
2754
		break;
2755
	case WLAN_CATEGORY_BACK:
2756
		if (sdata->vif.type != NL80211_IFTYPE_STATION &&
2757
		    sdata->vif.type != NL80211_IFTYPE_MESH_POINT &&
2758
		    sdata->vif.type != NL80211_IFTYPE_AP_VLAN &&
2759 2760
		    sdata->vif.type != NL80211_IFTYPE_AP &&
		    sdata->vif.type != NL80211_IFTYPE_ADHOC)
2761
			break;
2762

2763 2764 2765 2766
		/* verify action_code is present */
		if (len < IEEE80211_MIN_ACTION_SIZE + 1)
			break;

2767 2768 2769 2770
		switch (mgmt->u.action.u.addba_req.action_code) {
		case WLAN_ACTION_ADDBA_REQ:
			if (len < (IEEE80211_MIN_ACTION_SIZE +
				   sizeof(mgmt->u.action.u.addba_req)))
2771 2772
				goto invalid;
			break;
2773 2774 2775
		case WLAN_ACTION_ADDBA_RESP:
			if (len < (IEEE80211_MIN_ACTION_SIZE +
				   sizeof(mgmt->u.action.u.addba_resp)))
2776 2777
				goto invalid;
			break;
2778 2779 2780
		case WLAN_ACTION_DELBA:
			if (len < (IEEE80211_MIN_ACTION_SIZE +
				   sizeof(mgmt->u.action.u.delba)))
2781 2782 2783 2784
				goto invalid;
			break;
		default:
			goto invalid;
2785
		}
2786

2787
		goto queue;
2788
	case WLAN_CATEGORY_SPECTRUM_MGMT:
2789 2790 2791 2792
		/* verify action_code is present */
		if (len < IEEE80211_MIN_ACTION_SIZE + 1)
			break;

2793 2794
		switch (mgmt->u.action.u.measurement.action_code) {
		case WLAN_ACTION_SPCT_MSR_REQ:
2795 2796 2797
			if (status->band != IEEE80211_BAND_5GHZ)
				break;

2798 2799
			if (len < (IEEE80211_MIN_ACTION_SIZE +
				   sizeof(mgmt->u.action.u.measurement)))
2800
				break;
2801 2802 2803 2804

			if (sdata->vif.type != NL80211_IFTYPE_STATION)
				break;

2805
			ieee80211_process_measurement_req(sdata, mgmt, len);
2806
			goto handled;
2807 2808 2809 2810
		case WLAN_ACTION_SPCT_CHL_SWITCH: {
			u8 *bssid;
			if (len < (IEEE80211_MIN_ACTION_SIZE +
				   sizeof(mgmt->u.action.u.chan_switch)))
2811
				break;
2812

2813
			if (sdata->vif.type != NL80211_IFTYPE_STATION &&
2814 2815
			    sdata->vif.type != NL80211_IFTYPE_ADHOC &&
			    sdata->vif.type != NL80211_IFTYPE_MESH_POINT)
2816 2817 2818 2819 2820 2821
				break;

			if (sdata->vif.type == NL80211_IFTYPE_STATION)
				bssid = sdata->u.mgd.bssid;
			else if (sdata->vif.type == NL80211_IFTYPE_ADHOC)
				bssid = sdata->u.ibss.bssid;
2822 2823
			else if (sdata->vif.type == NL80211_IFTYPE_MESH_POINT)
				bssid = mgmt->sa;
2824 2825 2826 2827
			else
				break;

			if (!ether_addr_equal(mgmt->bssid, bssid))
2828
				break;
S
Sujith 已提交
2829

2830
			goto queue;
2831
			}
2832 2833
		}
		break;
2834 2835 2836
	case WLAN_CATEGORY_SA_QUERY:
		if (len < (IEEE80211_MIN_ACTION_SIZE +
			   sizeof(mgmt->u.action.u.sa_query)))
2837 2838
			break;

2839 2840 2841
		switch (mgmt->u.action.u.sa_query.action) {
		case WLAN_ACTION_SA_QUERY_REQUEST:
			if (sdata->vif.type != NL80211_IFTYPE_STATION)
2842
				break;
2843
			ieee80211_process_sa_query_req(sdata, mgmt, len);
2844
			goto handled;
2845 2846
		}
		break;
2847
	case WLAN_CATEGORY_SELF_PROTECTED:
2848 2849 2850 2851
		if (len < (IEEE80211_MIN_ACTION_SIZE +
			   sizeof(mgmt->u.action.u.self_prot.action_code)))
			break;

2852 2853 2854 2855 2856 2857
		switch (mgmt->u.action.u.self_prot.action_code) {
		case WLAN_SP_MESH_PEERING_OPEN:
		case WLAN_SP_MESH_PEERING_CLOSE:
		case WLAN_SP_MESH_PEERING_CONFIRM:
			if (!ieee80211_vif_is_mesh(&sdata->vif))
				goto invalid;
2858
			if (sdata->u.mesh.user_mpm)
2859 2860 2861 2862 2863 2864 2865 2866 2867 2868
				/* userspace handles this frame */
				break;
			goto queue;
		case WLAN_SP_MGK_INFORM:
		case WLAN_SP_MGK_ACK:
			if (!ieee80211_vif_is_mesh(&sdata->vif))
				goto invalid;
			break;
		}
		break;
2869
	case WLAN_CATEGORY_MESH_ACTION:
2870 2871 2872 2873
		if (len < (IEEE80211_MIN_ACTION_SIZE +
			   sizeof(mgmt->u.action.u.mesh_action.action_code)))
			break;

2874 2875
		if (!ieee80211_vif_is_mesh(&sdata->vif))
			break;
2876
		if (mesh_action_is_path_sel(mgmt) &&
J
Johannes Berg 已提交
2877
		    !mesh_path_sel_is_hwmp(sdata))
2878 2879
			break;
		goto queue;
2880
	}
2881

2882 2883
	return RX_CONTINUE;

2884
 invalid:
2885
	status->rx_flags |= IEEE80211_RX_MALFORMED_ACTION_FRM;
2886 2887 2888 2889 2890
	/* will return in the next handlers */
	return RX_CONTINUE;

 handled:
	if (rx->sta)
2891
		rx->sta->rx_stats.packets++;
2892 2893 2894 2895 2896 2897 2898 2899
	dev_kfree_skb(rx->skb);
	return RX_QUEUED;

 queue:
	rx->skb->pkt_type = IEEE80211_SDATA_QUEUE_TYPE_FRAME;
	skb_queue_tail(&sdata->skb_queue, rx->skb);
	ieee80211_queue_work(&local->hw, &sdata->work);
	if (rx->sta)
2900
		rx->sta->rx_stats.packets++;
2901 2902 2903 2904 2905 2906
	return RX_QUEUED;
}

static ieee80211_rx_result debug_noinline
ieee80211_rx_h_userspace_mgmt(struct ieee80211_rx_data *rx)
{
2907
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
2908
	int sig = 0;
2909 2910

	/* skip known-bad action frames and return them in the next handler */
2911
	if (status->rx_flags & IEEE80211_RX_MALFORMED_ACTION_FRM)
2912
		return RX_CONTINUE;
2913

2914 2915 2916 2917 2918 2919 2920
	/*
	 * Getting here means the kernel doesn't know how to handle
	 * it, but maybe userspace does ... include returned frames
	 * so userspace can register for those to know whether ones
	 * it transmitted were processed or returned.
	 */

2921
	if (ieee80211_hw_check(&rx->local->hw, SIGNAL_DBM))
2922 2923
		sig = status->signal;

2924
	if (cfg80211_rx_mgmt(&rx->sdata->wdev, status->freq, sig,
2925
			     rx->skb->data, rx->skb->len, 0)) {
2926
		if (rx->sta)
2927
			rx->sta->rx_stats.packets++;
2928 2929 2930 2931 2932 2933 2934 2935 2936 2937 2938 2939 2940 2941
		dev_kfree_skb(rx->skb);
		return RX_QUEUED;
	}

	return RX_CONTINUE;
}

static ieee80211_rx_result debug_noinline
ieee80211_rx_h_action_return(struct ieee80211_rx_data *rx)
{
	struct ieee80211_local *local = rx->local;
	struct ieee80211_mgmt *mgmt = (struct ieee80211_mgmt *) rx->skb->data;
	struct sk_buff *nskb;
	struct ieee80211_sub_if_data *sdata = rx->sdata;
2942
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(rx->skb);
2943 2944 2945 2946 2947 2948 2949 2950 2951

	if (!ieee80211_is_action(mgmt->frame_control))
		return RX_CONTINUE;

	/*
	 * For AP mode, hostapd is responsible for handling any action
	 * frames that we didn't handle, including returning unknown
	 * ones. For all other modes we will return them to the sender,
	 * setting the 0x80 bit in the action category, as required by
2952
	 * 802.11-2012 9.24.4.
2953 2954 2955 2956
	 * Newer versions of hostapd shall also use the management frame
	 * registration mechanisms, but older ones still use cooked
	 * monitor interfaces so push all frames there.
	 */
2957
	if (!(status->rx_flags & IEEE80211_RX_MALFORMED_ACTION_FRM) &&
2958 2959 2960
	    (sdata->vif.type == NL80211_IFTYPE_AP ||
	     sdata->vif.type == NL80211_IFTYPE_AP_VLAN))
		return RX_DROP_MONITOR;
2961

2962 2963 2964
	if (is_multicast_ether_addr(mgmt->da))
		return RX_DROP_MONITOR;

2965 2966 2967 2968 2969 2970 2971
	/* do not return rejected action frames */
	if (mgmt->u.action.category & 0x80)
		return RX_DROP_UNUSABLE;

	nskb = skb_copy_expand(rx->skb, local->hw.extra_tx_headroom, 0,
			       GFP_ATOMIC);
	if (nskb) {
2972
		struct ieee80211_mgmt *nmgmt = (void *)nskb->data;
2973

2974 2975 2976
		nmgmt->u.action.category |= 0x80;
		memcpy(nmgmt->da, nmgmt->sa, ETH_ALEN);
		memcpy(nmgmt->sa, rx->sdata->vif.addr, ETH_ALEN);
2977 2978 2979

		memset(nskb->cb, 0, sizeof(nskb->cb));

2980 2981 2982 2983 2984 2985
		if (rx->sdata->vif.type == NL80211_IFTYPE_P2P_DEVICE) {
			struct ieee80211_tx_info *info = IEEE80211_SKB_CB(nskb);

			info->flags = IEEE80211_TX_CTL_TX_OFFCHAN |
				      IEEE80211_TX_INTFL_OFFCHAN_TX_OK |
				      IEEE80211_TX_CTL_NO_CCK_RATE;
2986
			if (ieee80211_hw_check(&local->hw, QUEUE_CONTROL))
2987 2988 2989 2990 2991 2992
				info->hw_queue =
					local->hw.offchannel_tx_hw_queue;
		}

		__ieee80211_tx_skb_tid_band(rx->sdata, nskb, 7,
					    status->band);
2993
	}
2994 2995
	dev_kfree_skb(rx->skb);
	return RX_QUEUED;
2996 2997
}

2998
static ieee80211_rx_result debug_noinline
2999
ieee80211_rx_h_mgmt(struct ieee80211_rx_data *rx)
3000
{
J
Johannes Berg 已提交
3001
	struct ieee80211_sub_if_data *sdata = rx->sdata;
3002 3003
	struct ieee80211_mgmt *mgmt = (void *)rx->skb->data;
	__le16 stype;
3004

3005
	stype = mgmt->frame_control & cpu_to_le16(IEEE80211_FCTL_STYPE);
3006

3007 3008
	if (!ieee80211_vif_is_mesh(&sdata->vif) &&
	    sdata->vif.type != NL80211_IFTYPE_ADHOC &&
3009
	    sdata->vif.type != NL80211_IFTYPE_OCB &&
3010 3011
	    sdata->vif.type != NL80211_IFTYPE_STATION)
		return RX_DROP_MONITOR;
3012

3013
	switch (stype) {
J
Johannes Berg 已提交
3014
	case cpu_to_le16(IEEE80211_STYPE_AUTH):
3015 3016 3017 3018
	case cpu_to_le16(IEEE80211_STYPE_BEACON):
	case cpu_to_le16(IEEE80211_STYPE_PROBE_RESP):
		/* process for all: mesh, mlme, ibss */
		break;
J
Johannes Berg 已提交
3019 3020
	case cpu_to_le16(IEEE80211_STYPE_ASSOC_RESP):
	case cpu_to_le16(IEEE80211_STYPE_REASSOC_RESP):
3021 3022
	case cpu_to_le16(IEEE80211_STYPE_DEAUTH):
	case cpu_to_le16(IEEE80211_STYPE_DISASSOC):
3023 3024 3025 3026
		if (is_multicast_ether_addr(mgmt->da) &&
		    !is_broadcast_ether_addr(mgmt->da))
			return RX_DROP_MONITOR;

3027 3028 3029 3030 3031
		/* process only for station */
		if (sdata->vif.type != NL80211_IFTYPE_STATION)
			return RX_DROP_MONITOR;
		break;
	case cpu_to_le16(IEEE80211_STYPE_PROBE_REQ):
3032 3033 3034
		/* process only for ibss and mesh */
		if (sdata->vif.type != NL80211_IFTYPE_ADHOC &&
		    sdata->vif.type != NL80211_IFTYPE_MESH_POINT)
3035 3036 3037 3038 3039
			return RX_DROP_MONITOR;
		break;
	default:
		return RX_DROP_MONITOR;
	}
3040

3041
	/* queue up frame and kick off work to process it */
3042
	rx->skb->pkt_type = IEEE80211_SDATA_QUEUE_TYPE_FRAME;
3043 3044
	skb_queue_tail(&sdata->skb_queue, rx->skb);
	ieee80211_queue_work(&rx->local->hw, &sdata->work);
3045
	if (rx->sta)
3046
		rx->sta->rx_stats.packets++;
3047

3048
	return RX_QUEUED;
3049 3050
}

J
Johannes Berg 已提交
3051 3052
static void ieee80211_rx_cooked_monitor(struct ieee80211_rx_data *rx,
					struct ieee80211_rate *rate)
3053 3054 3055 3056 3057
{
	struct ieee80211_sub_if_data *sdata;
	struct ieee80211_local *local = rx->local;
	struct sk_buff *skb = rx->skb, *skb2;
	struct net_device *prev_dev = NULL;
J
Johannes Berg 已提交
3058
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
3059
	int needed_headroom;
3060

3061 3062 3063 3064 3065
	/*
	 * If cooked monitor has been processed already, then
	 * don't do it again. If not, set the flag.
	 */
	if (rx->flags & IEEE80211_RX_CMNTR)
3066
		goto out_free_skb;
3067
	rx->flags |= IEEE80211_RX_CMNTR;
3068

3069 3070 3071 3072
	/* If there are no cooked monitor interfaces, just free the SKB */
	if (!local->cooked_mntrs)
		goto out_free_skb;

3073 3074
	/* vendor data is long removed here */
	status->flag &= ~RX_FLAG_RADIOTAP_VENDOR_DATA;
3075
	/* room for the radiotap header based on driver features */
3076
	needed_headroom = ieee80211_rx_radiotap_hdrlen(local, status, skb);
3077

3078 3079 3080
	if (skb_headroom(skb) < needed_headroom &&
	    pskb_expand_head(skb, needed_headroom, 0, GFP_ATOMIC))
		goto out_free_skb;
3081

3082
	/* prepend radiotap information */
3083 3084
	ieee80211_add_rx_radiotap_header(local, skb, rate, needed_headroom,
					 false);
3085 3086 3087 3088 3089 3090 3091

	skb_set_mac_header(skb, 0);
	skb->ip_summed = CHECKSUM_UNNECESSARY;
	skb->pkt_type = PACKET_OTHERHOST;
	skb->protocol = htons(ETH_P_802_2);

	list_for_each_entry_rcu(sdata, &local->interfaces, list) {
3092
		if (!ieee80211_sdata_running(sdata))
3093 3094
			continue;

3095
		if (sdata->vif.type != NL80211_IFTYPE_MONITOR ||
3096 3097 3098 3099 3100 3101 3102
		    !(sdata->u.mntr_flags & MONITOR_FLAG_COOK_FRAMES))
			continue;

		if (prev_dev) {
			skb2 = skb_clone(skb, GFP_ATOMIC);
			if (skb2) {
				skb2->dev = prev_dev;
3103
				netif_receive_skb(skb2);
3104 3105 3106 3107
			}
		}

		prev_dev = sdata->dev;
3108
		ieee80211_rx_stats(sdata->dev, skb->len);
3109 3110 3111 3112
	}

	if (prev_dev) {
		skb->dev = prev_dev;
3113
		netif_receive_skb(skb);
3114 3115
		return;
	}
3116 3117 3118 3119 3120

 out_free_skb:
	dev_kfree_skb(skb);
}

3121 3122 3123 3124 3125 3126 3127
static void ieee80211_rx_handlers_result(struct ieee80211_rx_data *rx,
					 ieee80211_rx_result res)
{
	switch (res) {
	case RX_DROP_MONITOR:
		I802_DEBUG_INC(rx->sdata->local->rx_handlers_drop);
		if (rx->sta)
3128
			rx->sta->rx_stats.dropped++;
3129 3130 3131 3132 3133 3134 3135 3136 3137
		/* fall through */
	case RX_CONTINUE: {
		struct ieee80211_rate *rate = NULL;
		struct ieee80211_supported_band *sband;
		struct ieee80211_rx_status *status;

		status = IEEE80211_SKB_RXCB((rx->skb));

		sband = rx->local->hw.wiphy->bands[status->band];
3138 3139
		if (!(status->flag & RX_FLAG_HT) &&
		    !(status->flag & RX_FLAG_VHT))
3140 3141 3142 3143 3144 3145 3146 3147
			rate = &sband->bitrates[status->rate_idx];

		ieee80211_rx_cooked_monitor(rx, rate);
		break;
		}
	case RX_DROP_UNUSABLE:
		I802_DEBUG_INC(rx->sdata->local->rx_handlers_drop);
		if (rx->sta)
3148
			rx->sta->rx_stats.dropped++;
3149 3150 3151 3152 3153 3154 3155
		dev_kfree_skb(rx->skb);
		break;
	case RX_QUEUED:
		I802_DEBUG_INC(rx->sdata->local->rx_handlers_queued);
		break;
	}
}
3156

3157 3158
static void ieee80211_rx_handlers(struct ieee80211_rx_data *rx,
				  struct sk_buff_head *frames)
3159 3160
{
	ieee80211_rx_result res = RX_DROP_MONITOR;
3161
	struct sk_buff *skb;
3162

3163 3164 3165 3166
#define CALL_RXH(rxh)			\
	do {				\
		res = rxh(rx);		\
		if (res != RX_CONTINUE)	\
3167
			goto rxh_next;  \
3168
	} while (0);
3169

3170 3171 3172 3173 3174 3175
	/* Lock here to avoid hitting all of the data used in the RX
	 * path (e.g. key data, station data, ...) concurrently when
	 * a frame is released from the reorder buffer due to timeout
	 * from the timer, potentially concurrently with RX from the
	 * driver.
	 */
3176
	spin_lock_bh(&rx->local->rx_path_lock);
3177

3178
	while ((skb = __skb_dequeue(frames))) {
3179 3180 3181 3182 3183 3184 3185 3186
		/*
		 * all the other fields are valid across frames
		 * that belong to an aMPDU since they are on the
		 * same TID from the same station
		 */
		rx->skb = skb;

		CALL_RXH(ieee80211_rx_h_check_more_data)
J
Johannes Berg 已提交
3187
		CALL_RXH(ieee80211_rx_h_uapsd_and_pspoll)
3188
		CALL_RXH(ieee80211_rx_h_sta_process)
3189
		CALL_RXH(ieee80211_rx_h_decrypt)
3190 3191 3192
		CALL_RXH(ieee80211_rx_h_defragment)
		CALL_RXH(ieee80211_rx_h_michael_mic_verify)
		/* must be after MMIC verify so header is counted in MPDU mic */
I
Ingo Molnar 已提交
3193
#ifdef CONFIG_MAC80211_MESH
3194
		if (ieee80211_vif_is_mesh(&rx->sdata->vif))
3195
			CALL_RXH(ieee80211_rx_h_mesh_fwding);
I
Ingo Molnar 已提交
3196
#endif
3197
		CALL_RXH(ieee80211_rx_h_amsdu)
3198
		CALL_RXH(ieee80211_rx_h_data)
3199 3200 3201 3202 3203 3204

		/* special treatment -- needs the queue */
		res = ieee80211_rx_h_ctrl(rx, frames);
		if (res != RX_CONTINUE)
			goto rxh_next;

3205
		CALL_RXH(ieee80211_rx_h_mgmt_check)
3206
		CALL_RXH(ieee80211_rx_h_action)
3207 3208
		CALL_RXH(ieee80211_rx_h_userspace_mgmt)
		CALL_RXH(ieee80211_rx_h_action_return)
3209
		CALL_RXH(ieee80211_rx_h_mgmt)
3210

3211 3212
 rxh_next:
		ieee80211_rx_handlers_result(rx, res);
3213

3214
#undef CALL_RXH
3215
	}
3216

3217
	spin_unlock_bh(&rx->local->rx_path_lock);
3218 3219
}

3220
static void ieee80211_invoke_rx_handlers(struct ieee80211_rx_data *rx)
3221
{
3222
	struct sk_buff_head reorder_release;
3223 3224
	ieee80211_rx_result res = RX_DROP_MONITOR;

3225 3226
	__skb_queue_head_init(&reorder_release);

3227 3228 3229 3230 3231 3232 3233
#define CALL_RXH(rxh)			\
	do {				\
		res = rxh(rx);		\
		if (res != RX_CONTINUE)	\
			goto rxh_next;  \
	} while (0);

3234
	CALL_RXH(ieee80211_rx_h_check_dup)
3235 3236
	CALL_RXH(ieee80211_rx_h_check)

3237
	ieee80211_rx_reorder_ampdu(rx, &reorder_release);
3238

3239
	ieee80211_rx_handlers(rx, &reorder_release);
3240
	return;
3241

3242
 rxh_next:
3243 3244 3245
	ieee80211_rx_handlers_result(rx, res);

#undef CALL_RXH
3246 3247
}

3248
/*
3249 3250
 * This function makes calls into the RX path, therefore
 * it has to be invoked under RCU read lock.
3251 3252 3253
 */
void ieee80211_release_reorder_timeout(struct sta_info *sta, int tid)
{
3254
	struct sk_buff_head frames;
3255 3256 3257 3258
	struct ieee80211_rx_data rx = {
		.sta = sta,
		.sdata = sta->sdata,
		.local = sta->local,
3259 3260 3261
		/* This is OK -- must be QoS data frame */
		.security_idx = tid,
		.seqno_idx = tid,
3262
		.napi = NULL, /* must be NULL to not have races */
3263
	};
3264 3265 3266 3267 3268
	struct tid_ampdu_rx *tid_agg_rx;

	tid_agg_rx = rcu_dereference(sta->ampdu_mlme.tid_rx[tid]);
	if (!tid_agg_rx)
		return;
3269

3270 3271
	__skb_queue_head_init(&frames);

3272
	spin_lock(&tid_agg_rx->reorder_lock);
3273
	ieee80211_sta_reorder_release(sta->sdata, tid_agg_rx, &frames);
3274
	spin_unlock(&tid_agg_rx->reorder_lock);
3275

3276 3277 3278 3279 3280 3281 3282 3283 3284
	if (!skb_queue_empty(&frames)) {
		struct ieee80211_event event = {
			.type = BA_FRAME_TIMEOUT,
			.u.ba.tid = tid,
			.u.ba.sta = &sta->sta,
		};
		drv_event_callback(rx.local, rx.sdata, &event);
	}

3285
	ieee80211_rx_handlers(&rx, &frames);
3286 3287
}

3288 3289
/* main receive path */

3290
static bool ieee80211_accept_frame(struct ieee80211_rx_data *rx)
3291
{
3292
	struct ieee80211_sub_if_data *sdata = rx->sdata;
J
Johannes Berg 已提交
3293
	struct sk_buff *skb = rx->skb;
3294
	struct ieee80211_hdr *hdr = (void *)skb->data;
J
Johannes Berg 已提交
3295 3296
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
	u8 *bssid = ieee80211_get_bssid(hdr, skb->len, sdata->vif.type);
3297 3298
	int multicast = is_multicast_ether_addr(hdr->addr1);

3299
	switch (sdata->vif.type) {
3300
	case NL80211_IFTYPE_STATION:
3301
		if (!bssid && !sdata->u.mgd.use_4addr)
3302
			return false;
3303 3304 3305
		if (multicast)
			return true;
		return ether_addr_equal(sdata->vif.addr, hdr->addr1);
3306
	case NL80211_IFTYPE_ADHOC:
3307
		if (!bssid)
3308
			return false;
3309 3310
		if (ether_addr_equal(sdata->vif.addr, hdr->addr2) ||
		    ether_addr_equal(sdata->u.ibss.bssid, hdr->addr2))
3311
			return false;
3312
		if (ieee80211_is_beacon(hdr->frame_control))
3313
			return true;
3314
		if (!ieee80211_bssid_match(bssid, sdata->u.ibss.bssid))
3315
			return false;
3316 3317
		if (!multicast &&
		    !ether_addr_equal(sdata->vif.addr, hdr->addr1))
3318
			return false;
3319
		if (!rx->sta) {
3320
			int rate_idx;
3321 3322
			if (status->flag & (RX_FLAG_HT | RX_FLAG_VHT))
				rate_idx = 0; /* TODO: HT/VHT rates */
3323
			else
J
Johannes Berg 已提交
3324
				rate_idx = status->rate_idx;
3325 3326
			ieee80211_ibss_rx_no_sta(sdata, bssid, hdr->addr2,
						 BIT(rate_idx));
3327
		}
3328
		return true;
3329 3330 3331
	case NL80211_IFTYPE_OCB:
		if (!bssid)
			return false;
3332
		if (!ieee80211_is_data_present(hdr->frame_control))
3333
			return false;
3334
		if (!is_broadcast_ether_addr(bssid))
3335
			return false;
3336 3337
		if (!multicast &&
		    !ether_addr_equal(sdata->dev->dev_addr, hdr->addr1))
3338
			return false;
3339
		if (!rx->sta) {
3340 3341 3342 3343 3344 3345 3346 3347
			int rate_idx;
			if (status->flag & RX_FLAG_HT)
				rate_idx = 0; /* TODO: HT rates */
			else
				rate_idx = status->rate_idx;
			ieee80211_ocb_rx_no_sta(sdata, bssid, hdr->addr2,
						BIT(rate_idx));
		}
3348
		return true;
3349
	case NL80211_IFTYPE_MESH_POINT:
3350 3351 3352
		if (multicast)
			return true;
		return ether_addr_equal(sdata->vif.addr, hdr->addr1);
3353 3354
	case NL80211_IFTYPE_AP_VLAN:
	case NL80211_IFTYPE_AP:
3355 3356 3357 3358
		if (!bssid)
			return ether_addr_equal(sdata->vif.addr, hdr->addr1);

		if (!ieee80211_bssid_match(bssid, sdata->vif.addr)) {
3359 3360 3361 3362 3363 3364
			/*
			 * Accept public action frames even when the
			 * BSSID doesn't match, this is used for P2P
			 * and location updates. Note that mac80211
			 * itself never looks at these frames.
			 */
3365 3366
			if (!multicast &&
			    !ether_addr_equal(sdata->vif.addr, hdr->addr1))
3367
				return false;
J
Johannes Berg 已提交
3368
			if (ieee80211_is_public_action(hdr, skb->len))
3369
				return true;
3370
			return ieee80211_is_beacon(hdr->frame_control);
3371 3372 3373
		}

		if (!ieee80211_has_tods(hdr->frame_control)) {
3374 3375 3376 3377 3378 3379 3380
			/* ignore data frames to TDLS-peers */
			if (ieee80211_is_data(hdr->frame_control))
				return false;
			/* ignore action frames to TDLS-peers */
			if (ieee80211_is_action(hdr->frame_control) &&
			    !ether_addr_equal(bssid, hdr->addr1))
				return false;
3381
		}
3382
		return true;
3383
	case NL80211_IFTYPE_WDS:
3384
		if (bssid || !ieee80211_is_data(hdr->frame_control))
3385
			return false;
3386
		return ether_addr_equal(sdata->u.wds.remote_addr, hdr->addr2);
3387
	case NL80211_IFTYPE_P2P_DEVICE:
3388 3389 3390 3391
		return ieee80211_is_public_action(hdr, skb->len) ||
		       ieee80211_is_probe_req(hdr->frame_control) ||
		       ieee80211_is_probe_resp(hdr->frame_control) ||
		       ieee80211_is_beacon(hdr->frame_control);
3392
	default:
J
Johannes Berg 已提交
3393
		break;
3394 3395
	}

3396 3397
	WARN_ON_ONCE(1);
	return false;
3398 3399
}

3400 3401 3402 3403 3404 3405 3406 3407 3408 3409 3410 3411 3412 3413
/*
 * This function returns whether or not the SKB
 * was destined for RX processing or not, which,
 * if consume is true, is equivalent to whether
 * or not the skb was consumed.
 */
static bool ieee80211_prepare_and_rx_handle(struct ieee80211_rx_data *rx,
					    struct sk_buff *skb, bool consume)
{
	struct ieee80211_local *local = rx->local;
	struct ieee80211_sub_if_data *sdata = rx->sdata;

	rx->skb = skb;

3414
	if (!ieee80211_accept_frame(rx))
3415 3416 3417 3418 3419 3420 3421
		return false;

	if (!consume) {
		skb = skb_copy(skb, GFP_ATOMIC);
		if (!skb) {
			if (net_ratelimit())
				wiphy_debug(local->hw.wiphy,
3422
					"failed to copy skb for %s\n",
3423 3424 3425 3426 3427 3428 3429 3430 3431 3432 3433
					sdata->name);
			return true;
		}

		rx->skb = skb;
	}

	ieee80211_invoke_rx_handlers(rx);
	return true;
}

3434
/*
3435
 * This is the actual Rx frames handler. as it belongs to Rx path it must
3436
 * be called with rcu_read_lock protection.
3437
 */
3438
static void __ieee80211_rx_handle_packet(struct ieee80211_hw *hw,
3439 3440
					 struct sk_buff *skb,
					 struct napi_struct *napi)
3441 3442 3443 3444
{
	struct ieee80211_local *local = hw_to_local(hw);
	struct ieee80211_sub_if_data *sdata;
	struct ieee80211_hdr *hdr;
Z
Zhu Yi 已提交
3445
	__le16 fc;
3446
	struct ieee80211_rx_data rx;
3447
	struct ieee80211_sub_if_data *prev;
3448 3449
	struct sta_info *sta, *prev_sta;
	struct rhash_head *tmp;
Z
Zhu Yi 已提交
3450
	int err = 0;
3451

Z
Zhu Yi 已提交
3452
	fc = ((struct ieee80211_hdr *)skb->data)->frame_control;
3453 3454 3455
	memset(&rx, 0, sizeof(rx));
	rx.skb = skb;
	rx.local = local;
3456
	rx.napi = napi;
3457

Z
Zhu Yi 已提交
3458
	if (ieee80211_is_data(fc) || ieee80211_is_mgmt(fc))
3459
		I802_DEBUG_INC(local->dot11ReceivedFragmentCount);
3460

3461 3462 3463 3464 3465 3466 3467
	if (ieee80211_is_mgmt(fc)) {
		/* drop frame if too short for header */
		if (skb->len < ieee80211_hdrlen(fc))
			err = -ENOBUFS;
		else
			err = skb_linearize(skb);
	} else {
Z
Zhu Yi 已提交
3468
		err = !pskb_may_pull(skb, ieee80211_hdrlen(fc));
3469
	}
Z
Zhu Yi 已提交
3470 3471 3472 3473 3474 3475 3476

	if (err) {
		dev_kfree_skb(skb);
		return;
	}

	hdr = (struct ieee80211_hdr *)skb->data;
3477
	ieee80211_parse_qos(&rx);
3478
	ieee80211_verify_alignment(&rx);
3479

J
Johannes Berg 已提交
3480 3481 3482 3483
	if (unlikely(ieee80211_is_probe_resp(hdr->frame_control) ||
		     ieee80211_is_beacon(hdr->frame_control)))
		ieee80211_scan_rx(local, skb);

Z
Zhu Yi 已提交
3484
	if (ieee80211_is_data(fc)) {
3485 3486
		const struct bucket_table *tbl;

3487
		prev_sta = NULL;
3488

3489 3490 3491
		tbl = rht_dereference_rcu(local->sta_hash.tbl, &local->sta_hash);

		for_each_sta_info(local, tbl, hdr->addr2, sta, tmp) {
3492 3493 3494 3495 3496 3497 3498
			if (!prev_sta) {
				prev_sta = sta;
				continue;
			}

			rx.sta = prev_sta;
			rx.sdata = prev_sta->sdata;
3499
			ieee80211_prepare_and_rx_handle(&rx, skb, false);
3500

3501
			prev_sta = sta;
3502
		}
3503 3504 3505 3506 3507

		if (prev_sta) {
			rx.sta = prev_sta;
			rx.sdata = prev_sta->sdata;

3508
			if (ieee80211_prepare_and_rx_handle(&rx, skb, true))
3509
				return;
3510
			goto out;
3511
		}
3512 3513
	}

3514
	prev = NULL;
3515

3516 3517 3518
	list_for_each_entry_rcu(sdata, &local->interfaces, list) {
		if (!ieee80211_sdata_running(sdata))
			continue;
J
Johannes Berg 已提交
3519

3520 3521 3522
		if (sdata->vif.type == NL80211_IFTYPE_MONITOR ||
		    sdata->vif.type == NL80211_IFTYPE_AP_VLAN)
			continue;
J
Johannes Berg 已提交
3523

3524 3525 3526 3527 3528
		/*
		 * frame is destined for this interface, but if it's
		 * not also for the previous one we handle that after
		 * the loop to avoid copying the SKB once too much
		 */
3529

3530
		if (!prev) {
3531
			prev = sdata;
3532
			continue;
J
Johannes Berg 已提交
3533
		}
3534

3535
		rx.sta = sta_info_get_bss(prev, hdr->addr2);
3536 3537
		rx.sdata = prev;
		ieee80211_prepare_and_rx_handle(&rx, skb, false);
3538

3539 3540 3541 3542
		prev = sdata;
	}

	if (prev) {
3543
		rx.sta = sta_info_get_bss(prev, hdr->addr2);
3544
		rx.sdata = prev;
3545

3546 3547
		if (ieee80211_prepare_and_rx_handle(&rx, skb, true))
			return;
3548
	}
3549

3550
 out:
3551
	dev_kfree_skb(skb);
3552
}
3553 3554 3555 3556 3557

/*
 * This is the receive path handler. It is called by a low level driver when an
 * 802.11 MPDU is received from the hardware.
 */
3558 3559
void ieee80211_rx_napi(struct ieee80211_hw *hw, struct sk_buff *skb,
		       struct napi_struct *napi)
3560 3561
{
	struct ieee80211_local *local = hw_to_local(hw);
3562 3563
	struct ieee80211_rate *rate = NULL;
	struct ieee80211_supported_band *sband;
3564
	struct ieee80211_rx_status *status = IEEE80211_SKB_RXCB(skb);
3565

3566 3567
	WARN_ON_ONCE(softirq_count() == 0);

J
Johannes Berg 已提交
3568
	if (WARN_ON(status->band >= IEEE80211_NUM_BANDS))
J
Johannes Berg 已提交
3569
		goto drop;
3570 3571

	sband = local->hw.wiphy->bands[status->band];
J
Johannes Berg 已提交
3572 3573
	if (WARN_ON(!sband))
		goto drop;
3574

J
Johannes Berg 已提交
3575 3576 3577 3578 3579 3580 3581
	/*
	 * If we're suspending, it is possible although not too likely
	 * that we'd be receiving frames after having already partially
	 * quiesced the stack. We can't process such frames then since
	 * that might, for example, cause stations to be added or other
	 * driver callbacks be invoked.
	 */
J
Johannes Berg 已提交
3582 3583
	if (unlikely(local->quiescing || local->suspended))
		goto drop;
J
Johannes Berg 已提交
3584

3585 3586 3587 3588
	/* We might be during a HW reconfig, prevent Rx for the same reason */
	if (unlikely(local->in_reconfig))
		goto drop;

3589 3590 3591 3592
	/*
	 * The same happens when we're not even started,
	 * but that's worth a warning.
	 */
J
Johannes Berg 已提交
3593 3594
	if (WARN_ON(!local->started))
		goto drop;
3595

3596
	if (likely(!(status->flag & RX_FLAG_FAILED_PLCP_CRC))) {
3597
		/*
3598 3599
		 * Validate the rate, unless a PLCP error means that
		 * we probably can't have a valid rate here anyway.
3600
		 */
3601 3602 3603 3604 3605 3606 3607 3608 3609 3610 3611 3612

		if (status->flag & RX_FLAG_HT) {
			/*
			 * rate_idx is MCS index, which can be [0-76]
			 * as documented on:
			 *
			 * http://wireless.kernel.org/en/developers/Documentation/ieee80211/802.11n
			 *
			 * Anything else would be some sort of driver or
			 * hardware error. The driver should catch hardware
			 * errors.
			 */
J
Johannes Berg 已提交
3613
			if (WARN(status->rate_idx > 76,
3614 3615 3616 3617 3618 3619
				 "Rate marked as an HT rate but passed "
				 "status->rate_idx is not "
				 "an MCS index [0-76]: %d (0x%02x)\n",
				 status->rate_idx,
				 status->rate_idx))
				goto drop;
3620 3621 3622 3623 3624 3625 3626
		} else if (status->flag & RX_FLAG_VHT) {
			if (WARN_ONCE(status->rate_idx > 9 ||
				      !status->vht_nss ||
				      status->vht_nss > 8,
				      "Rate marked as a VHT rate but data is invalid: MCS: %d, NSS: %d\n",
				      status->rate_idx, status->vht_nss))
				goto drop;
3627
		} else {
J
Johannes Berg 已提交
3628
			if (WARN_ON(status->rate_idx >= sband->n_bitrates))
3629 3630 3631
				goto drop;
			rate = &sband->bitrates[status->rate_idx];
		}
3632
	}
3633

3634 3635
	status->rx_flags = 0;

3636 3637 3638 3639 3640 3641 3642 3643 3644 3645 3646 3647 3648
	/*
	 * key references and virtual interfaces are protected using RCU
	 * and this requires that we are in a read-side RCU section during
	 * receive processing
	 */
	rcu_read_lock();

	/*
	 * Frames with failed FCS/PLCP checksum are not returned,
	 * all other frames are returned without radiotap header
	 * if it was previously present.
	 * Also, frames with less than 16 bytes are dropped.
	 */
3649
	skb = ieee80211_rx_monitor(local, skb, rate);
3650 3651 3652 3653 3654
	if (!skb) {
		rcu_read_unlock();
		return;
	}

3655 3656 3657
	ieee80211_tpt_led_trig_rx(local,
			((struct ieee80211_hdr *)skb->data)->frame_control,
			skb->len);
3658
	__ieee80211_rx_handle_packet(hw, skb, napi);
3659 3660

	rcu_read_unlock();
J
Johannes Berg 已提交
3661 3662 3663 3664

	return;
 drop:
	kfree_skb(skb);
3665
}
3666
EXPORT_SYMBOL(ieee80211_rx_napi);
3667 3668 3669

/* This is a version of the rx handler that can be called from hard irq
 * context. Post the skb on the queue and schedule the tasklet */
3670
void ieee80211_rx_irqsafe(struct ieee80211_hw *hw, struct sk_buff *skb)
3671 3672 3673 3674 3675 3676 3677 3678 3679 3680
{
	struct ieee80211_local *local = hw_to_local(hw);

	BUILD_BUG_ON(sizeof(struct ieee80211_rx_status) > sizeof(skb->cb));

	skb->pkt_type = IEEE80211_RX_MSG;
	skb_queue_tail(&local->skb_queue, skb);
	tasklet_schedule(&local->tasklet);
}
EXPORT_SYMBOL(ieee80211_rx_irqsafe);