1 // SPDX-License-Identifier: GPL-2.0-only 2 /* 3 * Off-channel operation helpers 4 * 5 * Copyright 2003, Jouni Malinen <jkmaline@cc.hut.fi> 6 * Copyright 2004, Instant802 Networks, Inc. 7 * Copyright 2005, Devicescape Software, Inc. 8 * Copyright 2006-2007 Jiri Benc <jbenc@suse.cz> 9 * Copyright 2007, Michael Wu <flamingice@sourmilk.net> 10 * Copyright 2009 Johannes Berg <johannes@sipsolutions.net> 11 * Copyright (C) 2019, 2022-2026 Intel Corporation 12 */ 13 #include <linux/export.h> 14 #include <net/mac80211.h> 15 #include "ieee80211_i.h" 16 #include "driver-ops.h" 17 18 /* 19 * Tell our hardware to disable PS. 20 * Optionally inform AP that we will go to sleep so that it will buffer 21 * the frames while we are doing off-channel work. This is optional 22 * because we *may* be doing work on-operating channel, and want our 23 * hardware unconditionally awake, but still let the AP send us normal frames. 24 */ 25 static void ieee80211_offchannel_ps_enable(struct ieee80211_sub_if_data *sdata) 26 { 27 struct ieee80211_local *local = sdata->local; 28 struct ieee80211_if_managed *ifmgd = &sdata->u.mgd; 29 bool offchannel_ps_enabled = false; 30 31 /* FIXME: what to do when local->pspolling is true? */ 32 33 timer_delete_sync(&local->dynamic_ps_timer); 34 timer_delete_sync(&ifmgd->bcn_mon_timer); 35 timer_delete_sync(&ifmgd->conn_mon_timer); 36 37 wiphy_work_cancel(local->hw.wiphy, &local->dynamic_ps_enable_work); 38 39 if (local->hw.conf.flags & IEEE80211_CONF_PS) { 40 offchannel_ps_enabled = true; 41 local->hw.conf.flags &= ~IEEE80211_CONF_PS; 42 ieee80211_hw_config(local, -1, IEEE80211_CONF_CHANGE_PS); 43 } 44 45 if (!offchannel_ps_enabled || 46 !ieee80211_hw_check(&local->hw, PS_NULLFUNC_STACK)) 47 /* 48 * If power save was enabled, no need to send a nullfunc 49 * frame because AP knows that we are sleeping. But if the 50 * hardware is creating the nullfunc frame for power save 51 * status (ie. IEEE80211_HW_PS_NULLFUNC_STACK is not 52 * enabled) and power save was enabled, the firmware just 53 * sent a null frame with power save disabled. So we need 54 * to send a new nullfunc frame to inform the AP that we 55 * are again sleeping. 56 */ 57 ieee80211_send_nullfunc(local, sdata, true); 58 } 59 60 /* inform AP that we are awake again */ 61 static void ieee80211_offchannel_ps_disable(struct ieee80211_sub_if_data *sdata) 62 { 63 struct ieee80211_local *local = sdata->local; 64 65 if (!local->ps_sdata) 66 ieee80211_send_nullfunc(local, sdata, false); 67 else if (local->hw.conf.dynamic_ps_timeout > 0) { 68 /* 69 * the dynamic_ps_timer had been running before leaving the 70 * operating channel, restart the timer now and send a nullfunc 71 * frame to inform the AP that we are awake so that AP sends 72 * the buffered packets (if any). 73 */ 74 ieee80211_send_nullfunc(local, sdata, false); 75 mod_timer(&local->dynamic_ps_timer, jiffies + 76 msecs_to_jiffies(local->hw.conf.dynamic_ps_timeout)); 77 } 78 79 ieee80211_sta_reset_beacon_monitor(sdata); 80 ieee80211_sta_reset_conn_monitor(sdata); 81 } 82 83 void ieee80211_offchannel_stop_vifs(struct ieee80211_local *local) 84 { 85 struct ieee80211_sub_if_data *sdata; 86 87 lockdep_assert_wiphy(local->hw.wiphy); 88 89 if (WARN_ON(!local->emulate_chanctx)) 90 return; 91 92 /* 93 * notify the AP about us leaving the channel and stop all 94 * STA interfaces. 95 */ 96 97 /* 98 * Stop queues and transmit all frames queued by the driver 99 * before sending nullfunc to enable powersave at the AP. 100 */ 101 ieee80211_stop_queues_by_reason(&local->hw, IEEE80211_MAX_QUEUE_MAP, 102 IEEE80211_QUEUE_STOP_REASON_OFFCHANNEL, 103 false); 104 ieee80211_flush_queues(local, NULL, false); 105 106 list_for_each_entry(sdata, &local->interfaces, list) { 107 if (!ieee80211_sdata_running(sdata)) 108 continue; 109 110 if (sdata->vif.type == NL80211_IFTYPE_P2P_DEVICE || 111 sdata->vif.type == NL80211_IFTYPE_NAN) 112 continue; 113 114 if (sdata->vif.type != NL80211_IFTYPE_MONITOR) 115 set_bit(SDATA_STATE_OFFCHANNEL, &sdata->state); 116 117 /* Check to see if we should disable beaconing. */ 118 if (sdata->vif.bss_conf.enable_beacon) { 119 set_bit(SDATA_STATE_OFFCHANNEL_BEACON_STOPPED, 120 &sdata->state); 121 sdata->vif.bss_conf.enable_beacon = false; 122 ieee80211_link_info_change_notify( 123 sdata, &sdata->deflink, 124 BSS_CHANGED_BEACON_ENABLED); 125 } 126 127 if (sdata->vif.type == NL80211_IFTYPE_STATION && 128 sdata->u.mgd.associated) 129 ieee80211_offchannel_ps_enable(sdata); 130 } 131 } 132 133 void ieee80211_offchannel_return(struct ieee80211_local *local) 134 { 135 struct ieee80211_sub_if_data *sdata; 136 137 lockdep_assert_wiphy(local->hw.wiphy); 138 139 if (WARN_ON(!local->emulate_chanctx)) 140 return; 141 142 list_for_each_entry(sdata, &local->interfaces, list) { 143 if (sdata->vif.type == NL80211_IFTYPE_P2P_DEVICE) 144 continue; 145 146 if (sdata->vif.type != NL80211_IFTYPE_MONITOR) 147 clear_bit(SDATA_STATE_OFFCHANNEL, &sdata->state); 148 149 if (!ieee80211_sdata_running(sdata)) 150 continue; 151 152 /* Tell AP we're back */ 153 if (sdata->vif.type == NL80211_IFTYPE_STATION && 154 sdata->u.mgd.associated) 155 ieee80211_offchannel_ps_disable(sdata); 156 157 if (test_and_clear_bit(SDATA_STATE_OFFCHANNEL_BEACON_STOPPED, 158 &sdata->state)) { 159 sdata->vif.bss_conf.enable_beacon = true; 160 ieee80211_link_info_change_notify( 161 sdata, &sdata->deflink, 162 BSS_CHANGED_BEACON_ENABLED); 163 } 164 } 165 166 ieee80211_wake_queues_by_reason(&local->hw, IEEE80211_MAX_QUEUE_MAP, 167 IEEE80211_QUEUE_STOP_REASON_OFFCHANNEL, 168 false); 169 } 170 171 static void ieee80211_roc_notify_destroy(struct ieee80211_roc_work *roc) 172 { 173 /* was never transmitted */ 174 if (roc->frame) { 175 cfg80211_mgmt_tx_status(&roc->sdata->wdev, roc->mgmt_tx_cookie, 176 roc->frame->data, roc->frame->len, 177 false, GFP_KERNEL); 178 ieee80211_free_txskb(&roc->sdata->local->hw, roc->frame); 179 } 180 181 if (!roc->mgmt_tx_cookie) 182 cfg80211_remain_on_channel_expired(&roc->sdata->wdev, 183 roc->cookie, roc->chan, 184 GFP_KERNEL); 185 else 186 cfg80211_tx_mgmt_expired(&roc->sdata->wdev, 187 roc->mgmt_tx_cookie, 188 roc->chan, GFP_KERNEL); 189 190 list_del(&roc->list); 191 kfree(roc); 192 } 193 194 static unsigned long ieee80211_end_finished_rocs(struct ieee80211_local *local, 195 unsigned long now) 196 { 197 struct ieee80211_roc_work *roc, *tmp; 198 long remaining_dur_min = LONG_MAX; 199 200 lockdep_assert_wiphy(local->hw.wiphy); 201 202 list_for_each_entry_safe(roc, tmp, &local->roc_list, list) { 203 long remaining; 204 205 if (!roc->started) 206 break; 207 208 remaining = roc->start_time + 209 msecs_to_jiffies(roc->duration) - 210 now; 211 212 /* In case of HW ROC, it is possible that the HW finished the 213 * ROC session before the actual requested time. In such a case 214 * end the ROC session (disregarding the remaining time). 215 */ 216 if (roc->abort || roc->hw_begun || remaining <= 0) 217 ieee80211_roc_notify_destroy(roc); 218 else 219 remaining_dur_min = min(remaining_dur_min, remaining); 220 } 221 222 return remaining_dur_min; 223 } 224 225 static bool ieee80211_recalc_sw_work(struct ieee80211_local *local, 226 unsigned long now) 227 { 228 long dur = ieee80211_end_finished_rocs(local, now); 229 230 if (dur == LONG_MAX) 231 return false; 232 233 wiphy_delayed_work_queue(local->hw.wiphy, &local->roc_work, dur); 234 return true; 235 } 236 237 static void ieee80211_handle_roc_started(struct ieee80211_roc_work *roc, 238 unsigned long start_time) 239 { 240 if (WARN_ON(roc->notified)) 241 return; 242 243 roc->start_time = start_time; 244 roc->started = true; 245 246 if (roc->mgmt_tx_cookie) { 247 if (!WARN_ON(!roc->frame)) { 248 ieee80211_tx_skb_tid_band(roc->sdata, roc->frame, 7, 249 roc->chan->band); 250 roc->frame = NULL; 251 } 252 } else { 253 cfg80211_ready_on_channel(&roc->sdata->wdev, roc->cookie, 254 roc->chan, roc->req_duration, 255 GFP_KERNEL); 256 } 257 258 roc->notified = true; 259 } 260 261 static void ieee80211_hw_roc_start(struct wiphy *wiphy, struct wiphy_work *work) 262 { 263 struct ieee80211_local *local = 264 container_of(work, struct ieee80211_local, hw_roc_start); 265 struct ieee80211_roc_work *roc; 266 267 lockdep_assert_wiphy(local->hw.wiphy); 268 269 list_for_each_entry(roc, &local->roc_list, list) { 270 if (!roc->started) 271 break; 272 273 roc->hw_begun = true; 274 ieee80211_handle_roc_started(roc, local->hw_roc_start_time); 275 } 276 } 277 278 void ieee80211_ready_on_channel(struct ieee80211_hw *hw) 279 { 280 struct ieee80211_local *local = hw_to_local(hw); 281 282 local->hw_roc_start_time = jiffies; 283 284 trace_api_ready_on_channel(local); 285 286 wiphy_work_queue(hw->wiphy, &local->hw_roc_start); 287 } 288 EXPORT_SYMBOL_GPL(ieee80211_ready_on_channel); 289 290 static void _ieee80211_start_next_roc(struct ieee80211_local *local) 291 { 292 struct ieee80211_roc_work *roc, *tmp; 293 enum ieee80211_roc_type type; 294 u32 min_dur, max_dur; 295 296 lockdep_assert_wiphy(local->hw.wiphy); 297 298 if (WARN_ON(list_empty(&local->roc_list))) 299 return; 300 301 roc = list_first_entry(&local->roc_list, struct ieee80211_roc_work, 302 list); 303 304 if (WARN_ON(roc->started)) 305 return; 306 307 min_dur = roc->duration; 308 max_dur = roc->duration; 309 type = roc->type; 310 311 list_for_each_entry(tmp, &local->roc_list, list) { 312 if (tmp == roc) 313 continue; 314 if (tmp->sdata != roc->sdata || tmp->chan != roc->chan) 315 break; 316 max_dur = max(tmp->duration, max_dur); 317 min_dur = min(tmp->duration, min_dur); 318 type = max(tmp->type, type); 319 } 320 321 if (local->ops->remain_on_channel) { 322 int ret = drv_remain_on_channel(local, roc->sdata, roc->chan, 323 max_dur, type); 324 325 if (ret) { 326 wiphy_warn(local->hw.wiphy, 327 "failed to start next HW ROC (%d)\n", ret); 328 /* 329 * queue the work struct again to avoid recursion 330 * when multiple failures occur 331 */ 332 list_for_each_entry(tmp, &local->roc_list, list) { 333 if (tmp->sdata != roc->sdata || 334 tmp->chan != roc->chan) 335 break; 336 tmp->started = true; 337 tmp->abort = true; 338 } 339 wiphy_work_queue(local->hw.wiphy, &local->hw_roc_done); 340 return; 341 } 342 343 /* we'll notify about the start once the HW calls back */ 344 list_for_each_entry(tmp, &local->roc_list, list) { 345 if (tmp->sdata != roc->sdata || tmp->chan != roc->chan) 346 break; 347 tmp->started = true; 348 } 349 } else { 350 /* If actually operating on the desired channel (with at least 351 * 20 MHz channel width) don't stop all the operations but still 352 * treat it as though the ROC operation started properly, so 353 * other ROC operations won't interfere with this one. 354 * 355 * Note: scan can't run, tmp_channel is what we use, so this 356 * must be the currently active channel. 357 */ 358 roc->on_channel = roc->chan == local->hw.conf.chandef.chan; 359 360 /* start this ROC */ 361 ieee80211_recalc_idle(local); 362 363 if (!roc->on_channel) { 364 ieee80211_offchannel_stop_vifs(local); 365 366 local->tmp_channel = roc->chan; 367 ieee80211_hw_conf_chan(local); 368 } 369 370 wiphy_delayed_work_queue(local->hw.wiphy, &local->roc_work, 371 msecs_to_jiffies(min_dur)); 372 373 /* tell userspace or send frame(s) */ 374 list_for_each_entry(tmp, &local->roc_list, list) { 375 if (tmp->sdata != roc->sdata || tmp->chan != roc->chan) 376 break; 377 378 tmp->on_channel = roc->on_channel; 379 ieee80211_handle_roc_started(tmp, jiffies); 380 } 381 } 382 } 383 384 void ieee80211_start_next_roc(struct ieee80211_local *local) 385 { 386 struct ieee80211_roc_work *roc; 387 388 lockdep_assert_wiphy(local->hw.wiphy); 389 390 if (list_empty(&local->roc_list)) { 391 ieee80211_run_deferred_scan(local); 392 return; 393 } 394 395 /* defer roc if driver is not started (i.e. during reconfig) */ 396 if (local->in_reconfig) 397 return; 398 399 roc = list_first_entry(&local->roc_list, struct ieee80211_roc_work, 400 list); 401 402 if (WARN_ON_ONCE(roc->started)) 403 return; 404 405 if (local->ops->remain_on_channel) { 406 _ieee80211_start_next_roc(local); 407 } else { 408 /* delay it a bit */ 409 wiphy_delayed_work_queue(local->hw.wiphy, &local->roc_work, 410 round_jiffies_relative(HZ / 2)); 411 } 412 } 413 414 void ieee80211_reconfig_roc(struct ieee80211_local *local) 415 { 416 struct ieee80211_roc_work *roc, *tmp; 417 418 /* 419 * In the software implementation can just continue with the 420 * interruption due to reconfig, roc_work is still queued if 421 * needed. 422 */ 423 if (!local->ops->remain_on_channel) 424 return; 425 426 /* flush work so nothing from the driver is still pending */ 427 wiphy_work_flush(local->hw.wiphy, &local->hw_roc_start); 428 wiphy_work_flush(local->hw.wiphy, &local->hw_roc_done); 429 430 list_for_each_entry_safe(roc, tmp, &local->roc_list, list) { 431 if (!roc->started) 432 break; 433 434 if (!roc->hw_begun) { 435 /* it didn't start in HW yet, so we can restart it */ 436 roc->started = false; 437 continue; 438 } 439 440 /* otherwise destroy it and tell userspace */ 441 ieee80211_roc_notify_destroy(roc); 442 } 443 444 ieee80211_start_next_roc(local); 445 } 446 447 static void __ieee80211_roc_work(struct ieee80211_local *local) 448 { 449 struct ieee80211_roc_work *roc; 450 bool on_channel; 451 452 lockdep_assert_wiphy(local->hw.wiphy); 453 454 if (WARN_ON(local->ops->remain_on_channel)) 455 return; 456 457 roc = list_first_entry_or_null(&local->roc_list, 458 struct ieee80211_roc_work, list); 459 if (!roc) 460 return; 461 462 if (!roc->started) { 463 /* 464 * The work can be started by a previous ROC work, but a scan 465 * can get between things; scan finish will retrigger us. 466 */ 467 if (local->scanning) 468 return; 469 470 WARN_ON(!local->emulate_chanctx); 471 _ieee80211_start_next_roc(local); 472 } else { 473 on_channel = roc->on_channel; 474 if (ieee80211_recalc_sw_work(local, jiffies)) 475 return; 476 477 /* careful - roc pointer became invalid during recalc */ 478 479 if (!on_channel) { 480 ieee80211_flush_queues(local, NULL, false); 481 482 local->tmp_channel = NULL; 483 ieee80211_hw_conf_chan(local); 484 485 ieee80211_offchannel_return(local); 486 } 487 488 ieee80211_recalc_idle(local); 489 ieee80211_start_next_roc(local); 490 } 491 } 492 493 static void ieee80211_roc_work(struct wiphy *wiphy, struct wiphy_work *work) 494 { 495 struct ieee80211_local *local = 496 container_of(work, struct ieee80211_local, roc_work.work); 497 498 lockdep_assert_wiphy(local->hw.wiphy); 499 500 __ieee80211_roc_work(local); 501 } 502 503 static void ieee80211_hw_roc_done(struct wiphy *wiphy, struct wiphy_work *work) 504 { 505 struct ieee80211_local *local = 506 container_of(work, struct ieee80211_local, hw_roc_done); 507 508 lockdep_assert_wiphy(local->hw.wiphy); 509 510 ieee80211_end_finished_rocs(local, jiffies); 511 512 /* if there's another roc, start it now */ 513 ieee80211_start_next_roc(local); 514 } 515 516 void ieee80211_remain_on_channel_expired(struct ieee80211_hw *hw) 517 { 518 struct ieee80211_local *local = hw_to_local(hw); 519 520 trace_api_remain_on_channel_expired(local); 521 522 wiphy_work_queue(hw->wiphy, &local->hw_roc_done); 523 } 524 EXPORT_SYMBOL_GPL(ieee80211_remain_on_channel_expired); 525 526 static bool 527 ieee80211_coalesce_hw_started_roc(struct ieee80211_local *local, 528 struct ieee80211_roc_work *new_roc, 529 struct ieee80211_roc_work *cur_roc) 530 { 531 unsigned long now = jiffies; 532 unsigned long remaining; 533 534 if (WARN_ON(!cur_roc->started)) 535 return false; 536 537 /* if it was scheduled in the hardware, but not started yet, 538 * we can only combine if the older one had a longer duration 539 */ 540 if (!cur_roc->hw_begun && new_roc->duration > cur_roc->duration) 541 return false; 542 543 remaining = cur_roc->start_time + 544 msecs_to_jiffies(cur_roc->duration) - 545 now; 546 547 /* if it doesn't fit entirely, schedule a new one */ 548 if (new_roc->duration > jiffies_to_msecs(remaining)) 549 return false; 550 551 /* add just after the current one so we combine their finish later */ 552 list_add(&new_roc->list, &cur_roc->list); 553 554 /* if the existing one has already begun then let this one also 555 * begin, otherwise they'll both be marked properly by the work 556 * struct that runs once the driver notifies us of the beginning 557 */ 558 if (cur_roc->hw_begun) { 559 new_roc->hw_begun = true; 560 ieee80211_handle_roc_started(new_roc, now); 561 } 562 563 return true; 564 } 565 566 static int ieee80211_start_roc_work(struct ieee80211_local *local, 567 struct ieee80211_sub_if_data *sdata, 568 struct ieee80211_channel *channel, 569 unsigned int duration, u64 *cookie, 570 struct sk_buff *txskb, 571 enum ieee80211_roc_type type) 572 { 573 struct ieee80211_roc_work *roc, *tmp; 574 bool queued = false, combine_started = true; 575 struct cfg80211_scan_request *req; 576 int ret; 577 578 lockdep_assert_wiphy(local->hw.wiphy); 579 580 if (channel->freq_offset) 581 /* this may work, but is untested */ 582 return -EOPNOTSUPP; 583 584 if (!local->emulate_chanctx && !local->ops->remain_on_channel) 585 return -EOPNOTSUPP; 586 587 roc = kzalloc_obj(*roc); 588 if (!roc) 589 return -ENOMEM; 590 591 /* 592 * If the duration is zero, then the driver 593 * wouldn't actually do anything. Set it to 594 * 10 for now. 595 * 596 * TODO: cancel the off-channel operation 597 * when we get the SKB's TX status and 598 * the wait time was zero before. 599 */ 600 if (!duration) 601 duration = 10; 602 603 roc->chan = channel; 604 roc->duration = duration; 605 roc->req_duration = duration; 606 roc->frame = txskb; 607 roc->type = type; 608 roc->sdata = sdata; 609 610 /* 611 * cookie is either the roc cookie (for normal roc) 612 * or the mgmt_tx cookie; both are pre-assigned by cfg80211 613 */ 614 if (!txskb) 615 roc->cookie = *cookie; 616 else 617 roc->mgmt_tx_cookie = *cookie; 618 619 req = wiphy_dereference(local->hw.wiphy, local->scan_req); 620 621 /* if there's no need to queue, handle it immediately */ 622 if (list_empty(&local->roc_list) && 623 !local->scanning && !ieee80211_is_radar_required(local, req)) { 624 /* if not HW assist, just queue & schedule work */ 625 if (!local->ops->remain_on_channel) { 626 list_add_tail(&roc->list, &local->roc_list); 627 wiphy_delayed_work_queue(local->hw.wiphy, 628 &local->roc_work, 0); 629 } else { 630 /* otherwise actually kick it off here 631 * (for error handling) 632 */ 633 ret = drv_remain_on_channel(local, sdata, channel, 634 duration, type); 635 if (ret) { 636 kfree(roc); 637 return ret; 638 } 639 roc->started = true; 640 list_add_tail(&roc->list, &local->roc_list); 641 } 642 643 return 0; 644 } 645 646 /* otherwise handle queueing */ 647 648 list_for_each_entry(tmp, &local->roc_list, list) { 649 if (tmp->chan != channel || tmp->sdata != sdata) 650 continue; 651 652 /* 653 * Extend this ROC if possible: If it hasn't started, add 654 * just after the new one to combine. 655 */ 656 if (!tmp->started) { 657 list_add(&roc->list, &tmp->list); 658 queued = true; 659 break; 660 } 661 662 if (!combine_started) 663 continue; 664 665 if (!local->ops->remain_on_channel) { 666 /* If there's no hardware remain-on-channel, and 667 * doing so won't push us over the maximum r-o-c 668 * we allow, then we can just add the new one to 669 * the list and mark it as having started now. 670 * If it would push over the limit, don't try to 671 * combine with other started ones (that haven't 672 * been running as long) but potentially sort it 673 * with others that had the same fate. 674 */ 675 unsigned long now = jiffies; 676 u32 elapsed = jiffies_to_msecs(now - tmp->start_time); 677 struct wiphy *wiphy = local->hw.wiphy; 678 u32 max_roc = wiphy->max_remain_on_channel_duration; 679 680 if (elapsed + roc->duration > max_roc) { 681 combine_started = false; 682 continue; 683 } 684 685 list_add(&roc->list, &tmp->list); 686 queued = true; 687 roc->on_channel = tmp->on_channel; 688 ieee80211_handle_roc_started(roc, now); 689 ieee80211_recalc_sw_work(local, now); 690 break; 691 } 692 693 queued = ieee80211_coalesce_hw_started_roc(local, roc, tmp); 694 if (queued) 695 break; 696 /* if it wasn't queued, perhaps it can be combined with 697 * another that also couldn't get combined previously, 698 * but no need to check for already started ones, since 699 * that can't work. 700 */ 701 combine_started = false; 702 } 703 704 if (!queued) 705 list_add_tail(&roc->list, &local->roc_list); 706 707 return 0; 708 } 709 710 int ieee80211_remain_on_channel(struct wiphy *wiphy, struct wireless_dev *wdev, 711 struct ieee80211_channel *chan, 712 unsigned int duration, u64 cookie, 713 const u8 *rx_addr) 714 { 715 struct ieee80211_sub_if_data *sdata = IEEE80211_WDEV_TO_SUB_IF(wdev); 716 struct ieee80211_local *local = sdata->local; 717 718 lockdep_assert_wiphy(local->hw.wiphy); 719 720 return ieee80211_start_roc_work(local, sdata, chan, 721 duration, &cookie, NULL, 722 IEEE80211_ROC_TYPE_NORMAL); 723 } 724 725 static int ieee80211_cancel_roc(struct ieee80211_local *local, 726 u64 cookie, bool mgmt_tx) 727 { 728 struct ieee80211_roc_work *roc, *tmp, *found = NULL; 729 int ret; 730 731 lockdep_assert_wiphy(local->hw.wiphy); 732 733 if (!cookie) 734 return -ENOENT; 735 736 wiphy_work_flush(local->hw.wiphy, &local->hw_roc_start); 737 738 list_for_each_entry_safe(roc, tmp, &local->roc_list, list) { 739 if (!mgmt_tx && roc->cookie != cookie) 740 continue; 741 else if (mgmt_tx && roc->mgmt_tx_cookie != cookie) 742 continue; 743 744 found = roc; 745 break; 746 } 747 748 if (!found) { 749 return -ENOENT; 750 } 751 752 if (!found->started) { 753 ieee80211_roc_notify_destroy(found); 754 goto out_unlock; 755 } 756 757 if (local->ops->remain_on_channel) { 758 ret = drv_cancel_remain_on_channel(local, roc->sdata); 759 if (WARN_ON_ONCE(ret)) { 760 return ret; 761 } 762 763 /* 764 * We could be racing against the notification from the driver: 765 * + driver is handling the notification on CPU0 766 * + user space is cancelling the remain on channel and 767 * schedules the hw_roc_done worker. 768 * 769 * Now hw_roc_done might start to run after the next roc will 770 * start and mac80211 will think that this second roc has 771 * ended prematurely. 772 * Cancel the work to make sure that all the pending workers 773 * have completed execution. 774 * Note that this assumes that by the time the driver returns 775 * from drv_cancel_remain_on_channel, it has completed all 776 * the processing of related notifications. 777 */ 778 wiphy_work_cancel(local->hw.wiphy, &local->hw_roc_done); 779 780 /* TODO: 781 * if multiple items were combined here then we really shouldn't 782 * cancel them all - we should wait for as much time as needed 783 * for the longest remaining one, and only then cancel ... 784 */ 785 list_for_each_entry_safe(roc, tmp, &local->roc_list, list) { 786 if (!roc->started) 787 break; 788 if (roc == found) 789 found = NULL; 790 ieee80211_roc_notify_destroy(roc); 791 } 792 793 /* that really must not happen - it was started */ 794 WARN_ON(found); 795 796 ieee80211_start_next_roc(local); 797 } else { 798 /* go through work struct to return to the operating channel */ 799 found->abort = true; 800 wiphy_delayed_work_queue(local->hw.wiphy, &local->roc_work, 0); 801 } 802 803 out_unlock: 804 805 return 0; 806 } 807 808 int ieee80211_cancel_remain_on_channel(struct wiphy *wiphy, 809 struct wireless_dev *wdev, u64 cookie) 810 { 811 struct ieee80211_sub_if_data *sdata = IEEE80211_WDEV_TO_SUB_IF(wdev); 812 struct ieee80211_local *local = sdata->local; 813 814 return ieee80211_cancel_roc(local, cookie, false); 815 } 816 817 int ieee80211_mgmt_tx(struct wiphy *wiphy, struct wireless_dev *wdev, 818 struct cfg80211_mgmt_tx_params *params, u64 cookie) 819 { 820 struct ieee80211_sub_if_data *sdata = IEEE80211_WDEV_TO_SUB_IF(wdev); 821 struct ieee80211_local *local = sdata->local; 822 struct sk_buff *skb; 823 struct sta_info *sta = NULL; 824 const struct ieee80211_mgmt *mgmt = (void *)params->buf; 825 bool need_offchan = false; 826 bool mlo_sta = false; 827 int link_id = -1; 828 u32 flags; 829 int ret; 830 u8 *data; 831 832 lockdep_assert_wiphy(local->hw.wiphy); 833 834 if (params->dont_wait_for_ack) 835 flags = IEEE80211_TX_CTL_NO_ACK; 836 else 837 flags = IEEE80211_TX_INTFL_NL80211_FRAME_TX | 838 IEEE80211_TX_CTL_REQ_TX_STATUS; 839 840 if (params->no_cck) 841 flags |= IEEE80211_TX_CTL_NO_CCK_RATE; 842 843 switch (sdata->vif.type) { 844 case NL80211_IFTYPE_ADHOC: 845 if (!sdata->vif.cfg.ibss_joined) 846 need_offchan = true; 847 #ifdef CONFIG_MAC80211_MESH 848 fallthrough; 849 case NL80211_IFTYPE_MESH_POINT: 850 if (ieee80211_vif_is_mesh(&sdata->vif) && 851 !sdata->u.mesh.mesh_id_len) 852 need_offchan = true; 853 #endif 854 fallthrough; 855 case NL80211_IFTYPE_AP: 856 case NL80211_IFTYPE_AP_VLAN: 857 case NL80211_IFTYPE_P2P_GO: 858 if (sdata->vif.type != NL80211_IFTYPE_ADHOC && 859 !ieee80211_vif_is_mesh(&sdata->vif) && 860 !sdata->bss->active) 861 need_offchan = true; 862 863 rcu_read_lock(); 864 sta = sta_info_get_bss(sdata, mgmt->da); 865 mlo_sta = sta && sta->sta.mlo; 866 867 if (!ieee80211_is_action(mgmt->frame_control) || 868 mgmt->u.action.category == WLAN_CATEGORY_PUBLIC || 869 mgmt->u.action.category == WLAN_CATEGORY_SELF_PROTECTED || 870 mgmt->u.action.category == WLAN_CATEGORY_SPECTRUM_MGMT) { 871 rcu_read_unlock(); 872 break; 873 } 874 875 if (!sta) { 876 rcu_read_unlock(); 877 return -ENOLINK; 878 } 879 if (params->link_id >= 0 && 880 !(sta->sta.valid_links & BIT(params->link_id))) { 881 rcu_read_unlock(); 882 return -ENOLINK; 883 } 884 link_id = params->link_id; 885 rcu_read_unlock(); 886 break; 887 case NL80211_IFTYPE_STATION: 888 case NL80211_IFTYPE_P2P_CLIENT: 889 if (!sdata->u.mgd.associated || 890 (params->offchan && params->wait && 891 local->ops->remain_on_channel && 892 memcmp(sdata->vif.cfg.ap_addr, mgmt->bssid, ETH_ALEN))) { 893 need_offchan = true; 894 } else if (sdata->u.mgd.associated && 895 ether_addr_equal(sdata->vif.cfg.ap_addr, mgmt->da)) { 896 sta = sta_info_get_bss(sdata, mgmt->da); 897 mlo_sta = sta && sta->sta.mlo; 898 } 899 break; 900 case NL80211_IFTYPE_P2P_DEVICE: 901 case NL80211_IFTYPE_PD: 902 need_offchan = true; 903 break; 904 case NL80211_IFTYPE_NAN: 905 break; 906 case NL80211_IFTYPE_NAN_DATA: 907 if (is_multicast_ether_addr(mgmt->da)) 908 return -EOPNOTSUPP; 909 break; 910 default: 911 return -EOPNOTSUPP; 912 } 913 914 /* configurations requiring offchan cannot work if no channel has been 915 * specified 916 */ 917 if (need_offchan && !params->chan) 918 return -EINVAL; 919 920 /* Check if the operating channel is the requested channel */ 921 if (!params->chan && mlo_sta) { 922 need_offchan = false; 923 } else if (sdata->vif.type == NL80211_IFTYPE_NAN || 924 sdata->vif.type == NL80211_IFTYPE_NAN_DATA) { 925 /* Frames can be sent during NAN schedule */ 926 } else if (!need_offchan) { 927 struct ieee80211_chanctx_conf *chanctx_conf = NULL; 928 int i; 929 930 rcu_read_lock(); 931 /* Check all the links first */ 932 for (i = 0; i < ARRAY_SIZE(sdata->vif.link_conf); i++) { 933 struct ieee80211_bss_conf *conf; 934 935 conf = rcu_dereference(sdata->vif.link_conf[i]); 936 if (!conf) 937 continue; 938 939 chanctx_conf = rcu_dereference(conf->chanctx_conf); 940 if (!chanctx_conf) 941 continue; 942 943 if (mlo_sta && params->chan == chanctx_conf->def.chan && 944 ether_addr_equal(sdata->vif.addr, mgmt->sa)) { 945 link_id = i; 946 break; 947 } 948 949 if (ether_addr_equal(conf->addr, mgmt->sa)) { 950 /* If userspace requested Tx on a specific link 951 * use the same link id if the link bss is matching 952 * the requested chan. 953 */ 954 if (sdata->vif.valid_links && 955 params->link_id >= 0 && params->link_id == i && 956 params->chan == chanctx_conf->def.chan) 957 link_id = i; 958 959 break; 960 } 961 962 chanctx_conf = NULL; 963 } 964 965 if (chanctx_conf) { 966 need_offchan = params->chan && 967 (params->chan != 968 chanctx_conf->def.chan); 969 } else { 970 need_offchan = true; 971 } 972 rcu_read_unlock(); 973 } 974 975 if (need_offchan && !params->offchan) { 976 ret = -EBUSY; 977 goto out_unlock; 978 } 979 980 skb = dev_alloc_skb(local->hw.extra_tx_headroom + params->len); 981 if (!skb) { 982 ret = -ENOMEM; 983 goto out_unlock; 984 } 985 skb_reserve(skb, local->hw.extra_tx_headroom); 986 987 data = skb_put_data(skb, params->buf, params->len); 988 989 /* Update CSA counters */ 990 if (sdata->vif.bss_conf.csa_active && 991 (sdata->vif.type == NL80211_IFTYPE_AP || 992 sdata->vif.type == NL80211_IFTYPE_MESH_POINT || 993 sdata->vif.type == NL80211_IFTYPE_ADHOC) && 994 params->n_csa_offsets) { 995 int i; 996 struct beacon_data *beacon = NULL; 997 998 rcu_read_lock(); 999 1000 if (sdata->vif.type == NL80211_IFTYPE_AP) 1001 beacon = rcu_dereference(sdata->deflink.u.ap.beacon); 1002 else if (sdata->vif.type == NL80211_IFTYPE_ADHOC) 1003 beacon = rcu_dereference(sdata->u.ibss.presp); 1004 else if (ieee80211_vif_is_mesh(&sdata->vif)) 1005 beacon = rcu_dereference(sdata->u.mesh.beacon); 1006 1007 if (beacon) 1008 for (i = 0; i < params->n_csa_offsets; i++) 1009 data[params->csa_offsets[i]] = 1010 beacon->cntdwn_current_counter; 1011 1012 rcu_read_unlock(); 1013 } 1014 1015 IEEE80211_SKB_CB(skb)->flags = flags; 1016 IEEE80211_SKB_CB(skb)->control.flags |= IEEE80211_TX_CTRL_DONT_USE_RATE_MASK; 1017 1018 skb->dev = sdata->dev; 1019 1020 if (!params->dont_wait_for_ack) { 1021 /* make a copy to preserve the frame contents 1022 * in case of encryption. 1023 */ 1024 ret = ieee80211_attach_ack_skb(local, skb, &cookie, GFP_KERNEL); 1025 if (ret) { 1026 kfree_skb(skb); 1027 goto out_unlock; 1028 } 1029 } 1030 1031 if (!need_offchan) { 1032 ieee80211_tx_skb_tid(sdata, skb, 7, link_id); 1033 ret = 0; 1034 goto out_unlock; 1035 } 1036 1037 IEEE80211_SKB_CB(skb)->flags |= IEEE80211_TX_CTL_TX_OFFCHAN | 1038 IEEE80211_TX_INTFL_OFFCHAN_TX_OK; 1039 if (ieee80211_hw_check(&local->hw, QUEUE_CONTROL)) 1040 IEEE80211_SKB_CB(skb)->hw_queue = 1041 local->hw.offchannel_tx_hw_queue; 1042 1043 /* This will handle all kinds of coalescing and immediate TX */ 1044 ret = ieee80211_start_roc_work(local, sdata, params->chan, 1045 params->wait, &cookie, skb, 1046 IEEE80211_ROC_TYPE_MGMT_TX); 1047 if (ret) 1048 ieee80211_free_txskb(&local->hw, skb); 1049 out_unlock: 1050 return ret; 1051 } 1052 1053 int ieee80211_mgmt_tx_cancel_wait(struct wiphy *wiphy, 1054 struct wireless_dev *wdev, u64 cookie) 1055 { 1056 struct ieee80211_local *local = wiphy_priv(wiphy); 1057 1058 return ieee80211_cancel_roc(local, cookie, true); 1059 } 1060 1061 void ieee80211_roc_setup(struct ieee80211_local *local) 1062 { 1063 wiphy_work_init(&local->hw_roc_start, ieee80211_hw_roc_start); 1064 wiphy_work_init(&local->hw_roc_done, ieee80211_hw_roc_done); 1065 wiphy_delayed_work_init(&local->roc_work, ieee80211_roc_work); 1066 INIT_LIST_HEAD(&local->roc_list); 1067 } 1068 1069 void ieee80211_roc_purge(struct ieee80211_local *local, 1070 struct ieee80211_sub_if_data *sdata) 1071 { 1072 struct ieee80211_roc_work *roc, *tmp; 1073 bool work_to_do = false; 1074 1075 lockdep_assert_wiphy(local->hw.wiphy); 1076 1077 list_for_each_entry_safe(roc, tmp, &local->roc_list, list) { 1078 if (sdata && roc->sdata != sdata) 1079 continue; 1080 1081 if (roc->started) { 1082 if (local->ops->remain_on_channel) { 1083 /* can race, so ignore return value */ 1084 drv_cancel_remain_on_channel(local, roc->sdata); 1085 ieee80211_roc_notify_destroy(roc); 1086 } else { 1087 roc->abort = true; 1088 work_to_do = true; 1089 } 1090 } else { 1091 ieee80211_roc_notify_destroy(roc); 1092 } 1093 } 1094 if (work_to_do) 1095 __ieee80211_roc_work(local); 1096 } 1097