1 /* 2 * This is the new netlink-based wireless configuration interface. 3 * 4 * Copyright 2006-2010 Johannes Berg <johannes@sipsolutions.net> 5 * Copyright 2013-2014 Intel Mobile Communications GmbH 6 * Copyright 2015-2016 Intel Deutschland GmbH 7 */ 8 9 #include <linux/if.h> 10 #include <linux/module.h> 11 #include <linux/err.h> 12 #include <linux/slab.h> 13 #include <linux/list.h> 14 #include <linux/if_ether.h> 15 #include <linux/ieee80211.h> 16 #include <linux/nl80211.h> 17 #include <linux/rtnetlink.h> 18 #include <linux/netlink.h> 19 #include <linux/etherdevice.h> 20 #include <net/net_namespace.h> 21 #include <net/genetlink.h> 22 #include <net/cfg80211.h> 23 #include <net/sock.h> 24 #include <net/inet_connection_sock.h> 25 #include "core.h" 26 #include "nl80211.h" 27 #include "reg.h" 28 #include "rdev-ops.h" 29 30 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev, 31 struct genl_info *info, 32 struct cfg80211_crypto_settings *settings, 33 int cipher_limit); 34 35 /* the netlink family */ 36 static struct genl_family nl80211_fam; 37 38 /* multicast groups */ 39 enum nl80211_multicast_groups { 40 NL80211_MCGRP_CONFIG, 41 NL80211_MCGRP_SCAN, 42 NL80211_MCGRP_REGULATORY, 43 NL80211_MCGRP_MLME, 44 NL80211_MCGRP_VENDOR, 45 NL80211_MCGRP_NAN, 46 NL80211_MCGRP_TESTMODE /* keep last - ifdef! */ 47 }; 48 49 static const struct genl_multicast_group nl80211_mcgrps[] = { 50 [NL80211_MCGRP_CONFIG] = { .name = NL80211_MULTICAST_GROUP_CONFIG }, 51 [NL80211_MCGRP_SCAN] = { .name = NL80211_MULTICAST_GROUP_SCAN }, 52 [NL80211_MCGRP_REGULATORY] = { .name = NL80211_MULTICAST_GROUP_REG }, 53 [NL80211_MCGRP_MLME] = { .name = NL80211_MULTICAST_GROUP_MLME }, 54 [NL80211_MCGRP_VENDOR] = { .name = NL80211_MULTICAST_GROUP_VENDOR }, 55 [NL80211_MCGRP_NAN] = { .name = NL80211_MULTICAST_GROUP_NAN }, 56 #ifdef CONFIG_NL80211_TESTMODE 57 [NL80211_MCGRP_TESTMODE] = { .name = NL80211_MULTICAST_GROUP_TESTMODE } 58 #endif 59 }; 60 61 /* returns ERR_PTR values */ 62 static struct wireless_dev * 63 __cfg80211_wdev_from_attrs(struct net *netns, struct nlattr **attrs) 64 { 65 struct cfg80211_registered_device *rdev; 66 struct wireless_dev *result = NULL; 67 bool have_ifidx = attrs[NL80211_ATTR_IFINDEX]; 68 bool have_wdev_id = attrs[NL80211_ATTR_WDEV]; 69 u64 wdev_id; 70 int wiphy_idx = -1; 71 int ifidx = -1; 72 73 ASSERT_RTNL(); 74 75 if (!have_ifidx && !have_wdev_id) 76 return ERR_PTR(-EINVAL); 77 78 if (have_ifidx) 79 ifidx = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]); 80 if (have_wdev_id) { 81 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]); 82 wiphy_idx = wdev_id >> 32; 83 } 84 85 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 86 struct wireless_dev *wdev; 87 88 if (wiphy_net(&rdev->wiphy) != netns) 89 continue; 90 91 if (have_wdev_id && rdev->wiphy_idx != wiphy_idx) 92 continue; 93 94 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 95 if (have_ifidx && wdev->netdev && 96 wdev->netdev->ifindex == ifidx) { 97 result = wdev; 98 break; 99 } 100 if (have_wdev_id && wdev->identifier == (u32)wdev_id) { 101 result = wdev; 102 break; 103 } 104 } 105 106 if (result) 107 break; 108 } 109 110 if (result) 111 return result; 112 return ERR_PTR(-ENODEV); 113 } 114 115 static struct cfg80211_registered_device * 116 __cfg80211_rdev_from_attrs(struct net *netns, struct nlattr **attrs) 117 { 118 struct cfg80211_registered_device *rdev = NULL, *tmp; 119 struct net_device *netdev; 120 121 ASSERT_RTNL(); 122 123 if (!attrs[NL80211_ATTR_WIPHY] && 124 !attrs[NL80211_ATTR_IFINDEX] && 125 !attrs[NL80211_ATTR_WDEV]) 126 return ERR_PTR(-EINVAL); 127 128 if (attrs[NL80211_ATTR_WIPHY]) 129 rdev = cfg80211_rdev_by_wiphy_idx( 130 nla_get_u32(attrs[NL80211_ATTR_WIPHY])); 131 132 if (attrs[NL80211_ATTR_WDEV]) { 133 u64 wdev_id = nla_get_u64(attrs[NL80211_ATTR_WDEV]); 134 struct wireless_dev *wdev; 135 bool found = false; 136 137 tmp = cfg80211_rdev_by_wiphy_idx(wdev_id >> 32); 138 if (tmp) { 139 /* make sure wdev exists */ 140 list_for_each_entry(wdev, &tmp->wiphy.wdev_list, list) { 141 if (wdev->identifier != (u32)wdev_id) 142 continue; 143 found = true; 144 break; 145 } 146 147 if (!found) 148 tmp = NULL; 149 150 if (rdev && tmp != rdev) 151 return ERR_PTR(-EINVAL); 152 rdev = tmp; 153 } 154 } 155 156 if (attrs[NL80211_ATTR_IFINDEX]) { 157 int ifindex = nla_get_u32(attrs[NL80211_ATTR_IFINDEX]); 158 159 netdev = __dev_get_by_index(netns, ifindex); 160 if (netdev) { 161 if (netdev->ieee80211_ptr) 162 tmp = wiphy_to_rdev( 163 netdev->ieee80211_ptr->wiphy); 164 else 165 tmp = NULL; 166 167 /* not wireless device -- return error */ 168 if (!tmp) 169 return ERR_PTR(-EINVAL); 170 171 /* mismatch -- return error */ 172 if (rdev && tmp != rdev) 173 return ERR_PTR(-EINVAL); 174 175 rdev = tmp; 176 } 177 } 178 179 if (!rdev) 180 return ERR_PTR(-ENODEV); 181 182 if (netns != wiphy_net(&rdev->wiphy)) 183 return ERR_PTR(-ENODEV); 184 185 return rdev; 186 } 187 188 /* 189 * This function returns a pointer to the driver 190 * that the genl_info item that is passed refers to. 191 * 192 * The result of this can be a PTR_ERR and hence must 193 * be checked with IS_ERR() for errors. 194 */ 195 static struct cfg80211_registered_device * 196 cfg80211_get_dev_from_info(struct net *netns, struct genl_info *info) 197 { 198 return __cfg80211_rdev_from_attrs(netns, info->attrs); 199 } 200 201 /* policy for the attributes */ 202 static const struct nla_policy nl80211_policy[NUM_NL80211_ATTR] = { 203 [NL80211_ATTR_WIPHY] = { .type = NLA_U32 }, 204 [NL80211_ATTR_WIPHY_NAME] = { .type = NLA_NUL_STRING, 205 .len = 20-1 }, 206 [NL80211_ATTR_WIPHY_TXQ_PARAMS] = { .type = NLA_NESTED }, 207 208 [NL80211_ATTR_WIPHY_FREQ] = { .type = NLA_U32 }, 209 [NL80211_ATTR_WIPHY_CHANNEL_TYPE] = { .type = NLA_U32 }, 210 [NL80211_ATTR_CHANNEL_WIDTH] = { .type = NLA_U32 }, 211 [NL80211_ATTR_CENTER_FREQ1] = { .type = NLA_U32 }, 212 [NL80211_ATTR_CENTER_FREQ2] = { .type = NLA_U32 }, 213 214 [NL80211_ATTR_WIPHY_RETRY_SHORT] = { .type = NLA_U8 }, 215 [NL80211_ATTR_WIPHY_RETRY_LONG] = { .type = NLA_U8 }, 216 [NL80211_ATTR_WIPHY_FRAG_THRESHOLD] = { .type = NLA_U32 }, 217 [NL80211_ATTR_WIPHY_RTS_THRESHOLD] = { .type = NLA_U32 }, 218 [NL80211_ATTR_WIPHY_COVERAGE_CLASS] = { .type = NLA_U8 }, 219 [NL80211_ATTR_WIPHY_DYN_ACK] = { .type = NLA_FLAG }, 220 221 [NL80211_ATTR_IFTYPE] = { .type = NLA_U32 }, 222 [NL80211_ATTR_IFINDEX] = { .type = NLA_U32 }, 223 [NL80211_ATTR_IFNAME] = { .type = NLA_NUL_STRING, .len = IFNAMSIZ-1 }, 224 225 [NL80211_ATTR_MAC] = { .len = ETH_ALEN }, 226 [NL80211_ATTR_PREV_BSSID] = { .len = ETH_ALEN }, 227 228 [NL80211_ATTR_KEY] = { .type = NLA_NESTED, }, 229 [NL80211_ATTR_KEY_DATA] = { .type = NLA_BINARY, 230 .len = WLAN_MAX_KEY_LEN }, 231 [NL80211_ATTR_KEY_IDX] = { .type = NLA_U8 }, 232 [NL80211_ATTR_KEY_CIPHER] = { .type = NLA_U32 }, 233 [NL80211_ATTR_KEY_DEFAULT] = { .type = NLA_FLAG }, 234 [NL80211_ATTR_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 }, 235 [NL80211_ATTR_KEY_TYPE] = { .type = NLA_U32 }, 236 237 [NL80211_ATTR_BEACON_INTERVAL] = { .type = NLA_U32 }, 238 [NL80211_ATTR_DTIM_PERIOD] = { .type = NLA_U32 }, 239 [NL80211_ATTR_BEACON_HEAD] = { .type = NLA_BINARY, 240 .len = IEEE80211_MAX_DATA_LEN }, 241 [NL80211_ATTR_BEACON_TAIL] = { .type = NLA_BINARY, 242 .len = IEEE80211_MAX_DATA_LEN }, 243 [NL80211_ATTR_STA_AID] = { .type = NLA_U16 }, 244 [NL80211_ATTR_STA_FLAGS] = { .type = NLA_NESTED }, 245 [NL80211_ATTR_STA_LISTEN_INTERVAL] = { .type = NLA_U16 }, 246 [NL80211_ATTR_STA_SUPPORTED_RATES] = { .type = NLA_BINARY, 247 .len = NL80211_MAX_SUPP_RATES }, 248 [NL80211_ATTR_STA_PLINK_ACTION] = { .type = NLA_U8 }, 249 [NL80211_ATTR_STA_VLAN] = { .type = NLA_U32 }, 250 [NL80211_ATTR_MNTR_FLAGS] = { /* NLA_NESTED can't be empty */ }, 251 [NL80211_ATTR_MESH_ID] = { .type = NLA_BINARY, 252 .len = IEEE80211_MAX_MESH_ID_LEN }, 253 [NL80211_ATTR_MPATH_NEXT_HOP] = { .type = NLA_U32 }, 254 255 [NL80211_ATTR_REG_ALPHA2] = { .type = NLA_STRING, .len = 2 }, 256 [NL80211_ATTR_REG_RULES] = { .type = NLA_NESTED }, 257 258 [NL80211_ATTR_BSS_CTS_PROT] = { .type = NLA_U8 }, 259 [NL80211_ATTR_BSS_SHORT_PREAMBLE] = { .type = NLA_U8 }, 260 [NL80211_ATTR_BSS_SHORT_SLOT_TIME] = { .type = NLA_U8 }, 261 [NL80211_ATTR_BSS_BASIC_RATES] = { .type = NLA_BINARY, 262 .len = NL80211_MAX_SUPP_RATES }, 263 [NL80211_ATTR_BSS_HT_OPMODE] = { .type = NLA_U16 }, 264 265 [NL80211_ATTR_MESH_CONFIG] = { .type = NLA_NESTED }, 266 [NL80211_ATTR_SUPPORT_MESH_AUTH] = { .type = NLA_FLAG }, 267 268 [NL80211_ATTR_HT_CAPABILITY] = { .len = NL80211_HT_CAPABILITY_LEN }, 269 270 [NL80211_ATTR_MGMT_SUBTYPE] = { .type = NLA_U8 }, 271 [NL80211_ATTR_IE] = { .type = NLA_BINARY, 272 .len = IEEE80211_MAX_DATA_LEN }, 273 [NL80211_ATTR_SCAN_FREQUENCIES] = { .type = NLA_NESTED }, 274 [NL80211_ATTR_SCAN_SSIDS] = { .type = NLA_NESTED }, 275 276 [NL80211_ATTR_SSID] = { .type = NLA_BINARY, 277 .len = IEEE80211_MAX_SSID_LEN }, 278 [NL80211_ATTR_AUTH_TYPE] = { .type = NLA_U32 }, 279 [NL80211_ATTR_REASON_CODE] = { .type = NLA_U16 }, 280 [NL80211_ATTR_FREQ_FIXED] = { .type = NLA_FLAG }, 281 [NL80211_ATTR_TIMED_OUT] = { .type = NLA_FLAG }, 282 [NL80211_ATTR_USE_MFP] = { .type = NLA_U32 }, 283 [NL80211_ATTR_STA_FLAGS2] = { 284 .len = sizeof(struct nl80211_sta_flag_update), 285 }, 286 [NL80211_ATTR_CONTROL_PORT] = { .type = NLA_FLAG }, 287 [NL80211_ATTR_CONTROL_PORT_ETHERTYPE] = { .type = NLA_U16 }, 288 [NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT] = { .type = NLA_FLAG }, 289 [NL80211_ATTR_PRIVACY] = { .type = NLA_FLAG }, 290 [NL80211_ATTR_CIPHER_SUITE_GROUP] = { .type = NLA_U32 }, 291 [NL80211_ATTR_WPA_VERSIONS] = { .type = NLA_U32 }, 292 [NL80211_ATTR_PID] = { .type = NLA_U32 }, 293 [NL80211_ATTR_4ADDR] = { .type = NLA_U8 }, 294 [NL80211_ATTR_PMKID] = { .type = NLA_BINARY, 295 .len = WLAN_PMKID_LEN }, 296 [NL80211_ATTR_DURATION] = { .type = NLA_U32 }, 297 [NL80211_ATTR_COOKIE] = { .type = NLA_U64 }, 298 [NL80211_ATTR_TX_RATES] = { .type = NLA_NESTED }, 299 [NL80211_ATTR_FRAME] = { .type = NLA_BINARY, 300 .len = IEEE80211_MAX_DATA_LEN }, 301 [NL80211_ATTR_FRAME_MATCH] = { .type = NLA_BINARY, }, 302 [NL80211_ATTR_PS_STATE] = { .type = NLA_U32 }, 303 [NL80211_ATTR_CQM] = { .type = NLA_NESTED, }, 304 [NL80211_ATTR_LOCAL_STATE_CHANGE] = { .type = NLA_FLAG }, 305 [NL80211_ATTR_AP_ISOLATE] = { .type = NLA_U8 }, 306 [NL80211_ATTR_WIPHY_TX_POWER_SETTING] = { .type = NLA_U32 }, 307 [NL80211_ATTR_WIPHY_TX_POWER_LEVEL] = { .type = NLA_U32 }, 308 [NL80211_ATTR_FRAME_TYPE] = { .type = NLA_U16 }, 309 [NL80211_ATTR_WIPHY_ANTENNA_TX] = { .type = NLA_U32 }, 310 [NL80211_ATTR_WIPHY_ANTENNA_RX] = { .type = NLA_U32 }, 311 [NL80211_ATTR_MCAST_RATE] = { .type = NLA_U32 }, 312 [NL80211_ATTR_OFFCHANNEL_TX_OK] = { .type = NLA_FLAG }, 313 [NL80211_ATTR_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED }, 314 [NL80211_ATTR_WOWLAN_TRIGGERS] = { .type = NLA_NESTED }, 315 [NL80211_ATTR_STA_PLINK_STATE] = { .type = NLA_U8 }, 316 [NL80211_ATTR_SCHED_SCAN_INTERVAL] = { .type = NLA_U32 }, 317 [NL80211_ATTR_REKEY_DATA] = { .type = NLA_NESTED }, 318 [NL80211_ATTR_SCAN_SUPP_RATES] = { .type = NLA_NESTED }, 319 [NL80211_ATTR_HIDDEN_SSID] = { .type = NLA_U32 }, 320 [NL80211_ATTR_IE_PROBE_RESP] = { .type = NLA_BINARY, 321 .len = IEEE80211_MAX_DATA_LEN }, 322 [NL80211_ATTR_IE_ASSOC_RESP] = { .type = NLA_BINARY, 323 .len = IEEE80211_MAX_DATA_LEN }, 324 [NL80211_ATTR_ROAM_SUPPORT] = { .type = NLA_FLAG }, 325 [NL80211_ATTR_SCHED_SCAN_MATCH] = { .type = NLA_NESTED }, 326 [NL80211_ATTR_TX_NO_CCK_RATE] = { .type = NLA_FLAG }, 327 [NL80211_ATTR_TDLS_ACTION] = { .type = NLA_U8 }, 328 [NL80211_ATTR_TDLS_DIALOG_TOKEN] = { .type = NLA_U8 }, 329 [NL80211_ATTR_TDLS_OPERATION] = { .type = NLA_U8 }, 330 [NL80211_ATTR_TDLS_SUPPORT] = { .type = NLA_FLAG }, 331 [NL80211_ATTR_TDLS_EXTERNAL_SETUP] = { .type = NLA_FLAG }, 332 [NL80211_ATTR_TDLS_INITIATOR] = { .type = NLA_FLAG }, 333 [NL80211_ATTR_DONT_WAIT_FOR_ACK] = { .type = NLA_FLAG }, 334 [NL80211_ATTR_PROBE_RESP] = { .type = NLA_BINARY, 335 .len = IEEE80211_MAX_DATA_LEN }, 336 [NL80211_ATTR_DFS_REGION] = { .type = NLA_U8 }, 337 [NL80211_ATTR_DISABLE_HT] = { .type = NLA_FLAG }, 338 [NL80211_ATTR_HT_CAPABILITY_MASK] = { 339 .len = NL80211_HT_CAPABILITY_LEN 340 }, 341 [NL80211_ATTR_NOACK_MAP] = { .type = NLA_U16 }, 342 [NL80211_ATTR_INACTIVITY_TIMEOUT] = { .type = NLA_U16 }, 343 [NL80211_ATTR_BG_SCAN_PERIOD] = { .type = NLA_U16 }, 344 [NL80211_ATTR_WDEV] = { .type = NLA_U64 }, 345 [NL80211_ATTR_USER_REG_HINT_TYPE] = { .type = NLA_U32 }, 346 [NL80211_ATTR_AUTH_DATA] = { .type = NLA_BINARY, }, 347 [NL80211_ATTR_VHT_CAPABILITY] = { .len = NL80211_VHT_CAPABILITY_LEN }, 348 [NL80211_ATTR_SCAN_FLAGS] = { .type = NLA_U32 }, 349 [NL80211_ATTR_P2P_CTWINDOW] = { .type = NLA_U8 }, 350 [NL80211_ATTR_P2P_OPPPS] = { .type = NLA_U8 }, 351 [NL80211_ATTR_ACL_POLICY] = {. type = NLA_U32 }, 352 [NL80211_ATTR_MAC_ADDRS] = { .type = NLA_NESTED }, 353 [NL80211_ATTR_STA_CAPABILITY] = { .type = NLA_U16 }, 354 [NL80211_ATTR_STA_EXT_CAPABILITY] = { .type = NLA_BINARY, }, 355 [NL80211_ATTR_SPLIT_WIPHY_DUMP] = { .type = NLA_FLAG, }, 356 [NL80211_ATTR_DISABLE_VHT] = { .type = NLA_FLAG }, 357 [NL80211_ATTR_VHT_CAPABILITY_MASK] = { 358 .len = NL80211_VHT_CAPABILITY_LEN, 359 }, 360 [NL80211_ATTR_MDID] = { .type = NLA_U16 }, 361 [NL80211_ATTR_IE_RIC] = { .type = NLA_BINARY, 362 .len = IEEE80211_MAX_DATA_LEN }, 363 [NL80211_ATTR_PEER_AID] = { .type = NLA_U16 }, 364 [NL80211_ATTR_CH_SWITCH_COUNT] = { .type = NLA_U32 }, 365 [NL80211_ATTR_CH_SWITCH_BLOCK_TX] = { .type = NLA_FLAG }, 366 [NL80211_ATTR_CSA_IES] = { .type = NLA_NESTED }, 367 [NL80211_ATTR_CSA_C_OFF_BEACON] = { .type = NLA_BINARY }, 368 [NL80211_ATTR_CSA_C_OFF_PRESP] = { .type = NLA_BINARY }, 369 [NL80211_ATTR_STA_SUPPORTED_CHANNELS] = { .type = NLA_BINARY }, 370 [NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES] = { .type = NLA_BINARY }, 371 [NL80211_ATTR_HANDLE_DFS] = { .type = NLA_FLAG }, 372 [NL80211_ATTR_OPMODE_NOTIF] = { .type = NLA_U8 }, 373 [NL80211_ATTR_VENDOR_ID] = { .type = NLA_U32 }, 374 [NL80211_ATTR_VENDOR_SUBCMD] = { .type = NLA_U32 }, 375 [NL80211_ATTR_VENDOR_DATA] = { .type = NLA_BINARY }, 376 [NL80211_ATTR_QOS_MAP] = { .type = NLA_BINARY, 377 .len = IEEE80211_QOS_MAP_LEN_MAX }, 378 [NL80211_ATTR_MAC_HINT] = { .len = ETH_ALEN }, 379 [NL80211_ATTR_WIPHY_FREQ_HINT] = { .type = NLA_U32 }, 380 [NL80211_ATTR_TDLS_PEER_CAPABILITY] = { .type = NLA_U32 }, 381 [NL80211_ATTR_SOCKET_OWNER] = { .type = NLA_FLAG }, 382 [NL80211_ATTR_CSA_C_OFFSETS_TX] = { .type = NLA_BINARY }, 383 [NL80211_ATTR_USE_RRM] = { .type = NLA_FLAG }, 384 [NL80211_ATTR_TSID] = { .type = NLA_U8 }, 385 [NL80211_ATTR_USER_PRIO] = { .type = NLA_U8 }, 386 [NL80211_ATTR_ADMITTED_TIME] = { .type = NLA_U16 }, 387 [NL80211_ATTR_SMPS_MODE] = { .type = NLA_U8 }, 388 [NL80211_ATTR_MAC_MASK] = { .len = ETH_ALEN }, 389 [NL80211_ATTR_WIPHY_SELF_MANAGED_REG] = { .type = NLA_FLAG }, 390 [NL80211_ATTR_NETNS_FD] = { .type = NLA_U32 }, 391 [NL80211_ATTR_SCHED_SCAN_DELAY] = { .type = NLA_U32 }, 392 [NL80211_ATTR_REG_INDOOR] = { .type = NLA_FLAG }, 393 [NL80211_ATTR_PBSS] = { .type = NLA_FLAG }, 394 [NL80211_ATTR_BSS_SELECT] = { .type = NLA_NESTED }, 395 [NL80211_ATTR_STA_SUPPORT_P2P_PS] = { .type = NLA_U8 }, 396 [NL80211_ATTR_MU_MIMO_GROUP_DATA] = { 397 .len = VHT_MUMIMO_GROUPS_DATA_LEN 398 }, 399 [NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR] = { .len = ETH_ALEN }, 400 [NL80211_ATTR_NAN_MASTER_PREF] = { .type = NLA_U8 }, 401 [NL80211_ATTR_NAN_DUAL] = { .type = NLA_U8 }, 402 [NL80211_ATTR_NAN_FUNC] = { .type = NLA_NESTED }, 403 [NL80211_ATTR_FILS_KEK] = { .type = NLA_BINARY, 404 .len = FILS_MAX_KEK_LEN }, 405 [NL80211_ATTR_FILS_NONCES] = { .len = 2 * FILS_NONCE_LEN }, 406 [NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED] = { .type = NLA_FLAG, }, 407 [NL80211_ATTR_BSSID] = { .len = ETH_ALEN }, 408 }; 409 410 /* policy for the key attributes */ 411 static const struct nla_policy nl80211_key_policy[NL80211_KEY_MAX + 1] = { 412 [NL80211_KEY_DATA] = { .type = NLA_BINARY, .len = WLAN_MAX_KEY_LEN }, 413 [NL80211_KEY_IDX] = { .type = NLA_U8 }, 414 [NL80211_KEY_CIPHER] = { .type = NLA_U32 }, 415 [NL80211_KEY_SEQ] = { .type = NLA_BINARY, .len = 16 }, 416 [NL80211_KEY_DEFAULT] = { .type = NLA_FLAG }, 417 [NL80211_KEY_DEFAULT_MGMT] = { .type = NLA_FLAG }, 418 [NL80211_KEY_TYPE] = { .type = NLA_U32 }, 419 [NL80211_KEY_DEFAULT_TYPES] = { .type = NLA_NESTED }, 420 }; 421 422 /* policy for the key default flags */ 423 static const struct nla_policy 424 nl80211_key_default_policy[NUM_NL80211_KEY_DEFAULT_TYPES] = { 425 [NL80211_KEY_DEFAULT_TYPE_UNICAST] = { .type = NLA_FLAG }, 426 [NL80211_KEY_DEFAULT_TYPE_MULTICAST] = { .type = NLA_FLAG }, 427 }; 428 429 #ifdef CONFIG_PM 430 /* policy for WoWLAN attributes */ 431 static const struct nla_policy 432 nl80211_wowlan_policy[NUM_NL80211_WOWLAN_TRIG] = { 433 [NL80211_WOWLAN_TRIG_ANY] = { .type = NLA_FLAG }, 434 [NL80211_WOWLAN_TRIG_DISCONNECT] = { .type = NLA_FLAG }, 435 [NL80211_WOWLAN_TRIG_MAGIC_PKT] = { .type = NLA_FLAG }, 436 [NL80211_WOWLAN_TRIG_PKT_PATTERN] = { .type = NLA_NESTED }, 437 [NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE] = { .type = NLA_FLAG }, 438 [NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST] = { .type = NLA_FLAG }, 439 [NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE] = { .type = NLA_FLAG }, 440 [NL80211_WOWLAN_TRIG_RFKILL_RELEASE] = { .type = NLA_FLAG }, 441 [NL80211_WOWLAN_TRIG_TCP_CONNECTION] = { .type = NLA_NESTED }, 442 [NL80211_WOWLAN_TRIG_NET_DETECT] = { .type = NLA_NESTED }, 443 }; 444 445 static const struct nla_policy 446 nl80211_wowlan_tcp_policy[NUM_NL80211_WOWLAN_TCP] = { 447 [NL80211_WOWLAN_TCP_SRC_IPV4] = { .type = NLA_U32 }, 448 [NL80211_WOWLAN_TCP_DST_IPV4] = { .type = NLA_U32 }, 449 [NL80211_WOWLAN_TCP_DST_MAC] = { .len = ETH_ALEN }, 450 [NL80211_WOWLAN_TCP_SRC_PORT] = { .type = NLA_U16 }, 451 [NL80211_WOWLAN_TCP_DST_PORT] = { .type = NLA_U16 }, 452 [NL80211_WOWLAN_TCP_DATA_PAYLOAD] = { .len = 1 }, 453 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ] = { 454 .len = sizeof(struct nl80211_wowlan_tcp_data_seq) 455 }, 456 [NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN] = { 457 .len = sizeof(struct nl80211_wowlan_tcp_data_token) 458 }, 459 [NL80211_WOWLAN_TCP_DATA_INTERVAL] = { .type = NLA_U32 }, 460 [NL80211_WOWLAN_TCP_WAKE_PAYLOAD] = { .len = 1 }, 461 [NL80211_WOWLAN_TCP_WAKE_MASK] = { .len = 1 }, 462 }; 463 #endif /* CONFIG_PM */ 464 465 /* policy for coalesce rule attributes */ 466 static const struct nla_policy 467 nl80211_coalesce_policy[NUM_NL80211_ATTR_COALESCE_RULE] = { 468 [NL80211_ATTR_COALESCE_RULE_DELAY] = { .type = NLA_U32 }, 469 [NL80211_ATTR_COALESCE_RULE_CONDITION] = { .type = NLA_U32 }, 470 [NL80211_ATTR_COALESCE_RULE_PKT_PATTERN] = { .type = NLA_NESTED }, 471 }; 472 473 /* policy for GTK rekey offload attributes */ 474 static const struct nla_policy 475 nl80211_rekey_policy[NUM_NL80211_REKEY_DATA] = { 476 [NL80211_REKEY_DATA_KEK] = { .len = NL80211_KEK_LEN }, 477 [NL80211_REKEY_DATA_KCK] = { .len = NL80211_KCK_LEN }, 478 [NL80211_REKEY_DATA_REPLAY_CTR] = { .len = NL80211_REPLAY_CTR_LEN }, 479 }; 480 481 static const struct nla_policy 482 nl80211_match_policy[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1] = { 483 [NL80211_SCHED_SCAN_MATCH_ATTR_SSID] = { .type = NLA_BINARY, 484 .len = IEEE80211_MAX_SSID_LEN }, 485 [NL80211_SCHED_SCAN_MATCH_ATTR_RSSI] = { .type = NLA_U32 }, 486 }; 487 488 static const struct nla_policy 489 nl80211_plan_policy[NL80211_SCHED_SCAN_PLAN_MAX + 1] = { 490 [NL80211_SCHED_SCAN_PLAN_INTERVAL] = { .type = NLA_U32 }, 491 [NL80211_SCHED_SCAN_PLAN_ITERATIONS] = { .type = NLA_U32 }, 492 }; 493 494 static const struct nla_policy 495 nl80211_bss_select_policy[NL80211_BSS_SELECT_ATTR_MAX + 1] = { 496 [NL80211_BSS_SELECT_ATTR_RSSI] = { .type = NLA_FLAG }, 497 [NL80211_BSS_SELECT_ATTR_BAND_PREF] = { .type = NLA_U32 }, 498 [NL80211_BSS_SELECT_ATTR_RSSI_ADJUST] = { 499 .len = sizeof(struct nl80211_bss_select_rssi_adjust) 500 }, 501 }; 502 503 /* policy for NAN function attributes */ 504 static const struct nla_policy 505 nl80211_nan_func_policy[NL80211_NAN_FUNC_ATTR_MAX + 1] = { 506 [NL80211_NAN_FUNC_TYPE] = { .type = NLA_U8 }, 507 [NL80211_NAN_FUNC_SERVICE_ID] = { .type = NLA_BINARY, 508 .len = NL80211_NAN_FUNC_SERVICE_ID_LEN }, 509 [NL80211_NAN_FUNC_PUBLISH_TYPE] = { .type = NLA_U8 }, 510 [NL80211_NAN_FUNC_PUBLISH_BCAST] = { .type = NLA_FLAG }, 511 [NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE] = { .type = NLA_FLAG }, 512 [NL80211_NAN_FUNC_FOLLOW_UP_ID] = { .type = NLA_U8 }, 513 [NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID] = { .type = NLA_U8 }, 514 [NL80211_NAN_FUNC_FOLLOW_UP_DEST] = { .len = ETH_ALEN }, 515 [NL80211_NAN_FUNC_CLOSE_RANGE] = { .type = NLA_FLAG }, 516 [NL80211_NAN_FUNC_TTL] = { .type = NLA_U32 }, 517 [NL80211_NAN_FUNC_SERVICE_INFO] = { .type = NLA_BINARY, 518 .len = NL80211_NAN_FUNC_SERVICE_SPEC_INFO_MAX_LEN }, 519 [NL80211_NAN_FUNC_SRF] = { .type = NLA_NESTED }, 520 [NL80211_NAN_FUNC_RX_MATCH_FILTER] = { .type = NLA_NESTED }, 521 [NL80211_NAN_FUNC_TX_MATCH_FILTER] = { .type = NLA_NESTED }, 522 [NL80211_NAN_FUNC_INSTANCE_ID] = { .type = NLA_U8 }, 523 [NL80211_NAN_FUNC_TERM_REASON] = { .type = NLA_U8 }, 524 }; 525 526 /* policy for Service Response Filter attributes */ 527 static const struct nla_policy 528 nl80211_nan_srf_policy[NL80211_NAN_SRF_ATTR_MAX + 1] = { 529 [NL80211_NAN_SRF_INCLUDE] = { .type = NLA_FLAG }, 530 [NL80211_NAN_SRF_BF] = { .type = NLA_BINARY, 531 .len = NL80211_NAN_FUNC_SRF_MAX_LEN }, 532 [NL80211_NAN_SRF_BF_IDX] = { .type = NLA_U8 }, 533 [NL80211_NAN_SRF_MAC_ADDRS] = { .type = NLA_NESTED }, 534 }; 535 536 static int nl80211_prepare_wdev_dump(struct sk_buff *skb, 537 struct netlink_callback *cb, 538 struct cfg80211_registered_device **rdev, 539 struct wireless_dev **wdev) 540 { 541 int err; 542 543 rtnl_lock(); 544 545 if (!cb->args[0]) { 546 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 547 genl_family_attrbuf(&nl80211_fam), 548 nl80211_fam.maxattr, nl80211_policy); 549 if (err) 550 goto out_unlock; 551 552 *wdev = __cfg80211_wdev_from_attrs( 553 sock_net(skb->sk), 554 genl_family_attrbuf(&nl80211_fam)); 555 if (IS_ERR(*wdev)) { 556 err = PTR_ERR(*wdev); 557 goto out_unlock; 558 } 559 *rdev = wiphy_to_rdev((*wdev)->wiphy); 560 /* 0 is the first index - add 1 to parse only once */ 561 cb->args[0] = (*rdev)->wiphy_idx + 1; 562 cb->args[1] = (*wdev)->identifier; 563 } else { 564 /* subtract the 1 again here */ 565 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1); 566 struct wireless_dev *tmp; 567 568 if (!wiphy) { 569 err = -ENODEV; 570 goto out_unlock; 571 } 572 *rdev = wiphy_to_rdev(wiphy); 573 *wdev = NULL; 574 575 list_for_each_entry(tmp, &(*rdev)->wiphy.wdev_list, list) { 576 if (tmp->identifier == cb->args[1]) { 577 *wdev = tmp; 578 break; 579 } 580 } 581 582 if (!*wdev) { 583 err = -ENODEV; 584 goto out_unlock; 585 } 586 } 587 588 return 0; 589 out_unlock: 590 rtnl_unlock(); 591 return err; 592 } 593 594 static void nl80211_finish_wdev_dump(struct cfg80211_registered_device *rdev) 595 { 596 rtnl_unlock(); 597 } 598 599 /* IE validation */ 600 static bool is_valid_ie_attr(const struct nlattr *attr) 601 { 602 const u8 *pos; 603 int len; 604 605 if (!attr) 606 return true; 607 608 pos = nla_data(attr); 609 len = nla_len(attr); 610 611 while (len) { 612 u8 elemlen; 613 614 if (len < 2) 615 return false; 616 len -= 2; 617 618 elemlen = pos[1]; 619 if (elemlen > len) 620 return false; 621 622 len -= elemlen; 623 pos += 2 + elemlen; 624 } 625 626 return true; 627 } 628 629 /* message building helper */ 630 static inline void *nl80211hdr_put(struct sk_buff *skb, u32 portid, u32 seq, 631 int flags, u8 cmd) 632 { 633 /* since there is no private header just add the generic one */ 634 return genlmsg_put(skb, portid, seq, &nl80211_fam, flags, cmd); 635 } 636 637 static int nl80211_msg_put_channel(struct sk_buff *msg, 638 struct ieee80211_channel *chan, 639 bool large) 640 { 641 /* Some channels must be completely excluded from the 642 * list to protect old user-space tools from breaking 643 */ 644 if (!large && chan->flags & 645 (IEEE80211_CHAN_NO_10MHZ | IEEE80211_CHAN_NO_20MHZ)) 646 return 0; 647 648 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_FREQ, 649 chan->center_freq)) 650 goto nla_put_failure; 651 652 if ((chan->flags & IEEE80211_CHAN_DISABLED) && 653 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_DISABLED)) 654 goto nla_put_failure; 655 if (chan->flags & IEEE80211_CHAN_NO_IR) { 656 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_IR)) 657 goto nla_put_failure; 658 if (nla_put_flag(msg, __NL80211_FREQUENCY_ATTR_NO_IBSS)) 659 goto nla_put_failure; 660 } 661 if (chan->flags & IEEE80211_CHAN_RADAR) { 662 if (nla_put_flag(msg, NL80211_FREQUENCY_ATTR_RADAR)) 663 goto nla_put_failure; 664 if (large) { 665 u32 time; 666 667 time = elapsed_jiffies_msecs(chan->dfs_state_entered); 668 669 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_STATE, 670 chan->dfs_state)) 671 goto nla_put_failure; 672 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_DFS_TIME, 673 time)) 674 goto nla_put_failure; 675 if (nla_put_u32(msg, 676 NL80211_FREQUENCY_ATTR_DFS_CAC_TIME, 677 chan->dfs_cac_ms)) 678 goto nla_put_failure; 679 } 680 } 681 682 if (large) { 683 if ((chan->flags & IEEE80211_CHAN_NO_HT40MINUS) && 684 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_MINUS)) 685 goto nla_put_failure; 686 if ((chan->flags & IEEE80211_CHAN_NO_HT40PLUS) && 687 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_HT40_PLUS)) 688 goto nla_put_failure; 689 if ((chan->flags & IEEE80211_CHAN_NO_80MHZ) && 690 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_80MHZ)) 691 goto nla_put_failure; 692 if ((chan->flags & IEEE80211_CHAN_NO_160MHZ) && 693 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_160MHZ)) 694 goto nla_put_failure; 695 if ((chan->flags & IEEE80211_CHAN_INDOOR_ONLY) && 696 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_INDOOR_ONLY)) 697 goto nla_put_failure; 698 if ((chan->flags & IEEE80211_CHAN_IR_CONCURRENT) && 699 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_IR_CONCURRENT)) 700 goto nla_put_failure; 701 if ((chan->flags & IEEE80211_CHAN_NO_20MHZ) && 702 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_20MHZ)) 703 goto nla_put_failure; 704 if ((chan->flags & IEEE80211_CHAN_NO_10MHZ) && 705 nla_put_flag(msg, NL80211_FREQUENCY_ATTR_NO_10MHZ)) 706 goto nla_put_failure; 707 } 708 709 if (nla_put_u32(msg, NL80211_FREQUENCY_ATTR_MAX_TX_POWER, 710 DBM_TO_MBM(chan->max_power))) 711 goto nla_put_failure; 712 713 return 0; 714 715 nla_put_failure: 716 return -ENOBUFS; 717 } 718 719 /* netlink command implementations */ 720 721 struct key_parse { 722 struct key_params p; 723 int idx; 724 int type; 725 bool def, defmgmt; 726 bool def_uni, def_multi; 727 }; 728 729 static int nl80211_parse_key_new(struct nlattr *key, struct key_parse *k) 730 { 731 struct nlattr *tb[NL80211_KEY_MAX + 1]; 732 int err = nla_parse_nested(tb, NL80211_KEY_MAX, key, 733 nl80211_key_policy); 734 if (err) 735 return err; 736 737 k->def = !!tb[NL80211_KEY_DEFAULT]; 738 k->defmgmt = !!tb[NL80211_KEY_DEFAULT_MGMT]; 739 740 if (k->def) { 741 k->def_uni = true; 742 k->def_multi = true; 743 } 744 if (k->defmgmt) 745 k->def_multi = true; 746 747 if (tb[NL80211_KEY_IDX]) 748 k->idx = nla_get_u8(tb[NL80211_KEY_IDX]); 749 750 if (tb[NL80211_KEY_DATA]) { 751 k->p.key = nla_data(tb[NL80211_KEY_DATA]); 752 k->p.key_len = nla_len(tb[NL80211_KEY_DATA]); 753 } 754 755 if (tb[NL80211_KEY_SEQ]) { 756 k->p.seq = nla_data(tb[NL80211_KEY_SEQ]); 757 k->p.seq_len = nla_len(tb[NL80211_KEY_SEQ]); 758 } 759 760 if (tb[NL80211_KEY_CIPHER]) 761 k->p.cipher = nla_get_u32(tb[NL80211_KEY_CIPHER]); 762 763 if (tb[NL80211_KEY_TYPE]) { 764 k->type = nla_get_u32(tb[NL80211_KEY_TYPE]); 765 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) 766 return -EINVAL; 767 } 768 769 if (tb[NL80211_KEY_DEFAULT_TYPES]) { 770 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES]; 771 772 err = nla_parse_nested(kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1, 773 tb[NL80211_KEY_DEFAULT_TYPES], 774 nl80211_key_default_policy); 775 if (err) 776 return err; 777 778 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST]; 779 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST]; 780 } 781 782 return 0; 783 } 784 785 static int nl80211_parse_key_old(struct genl_info *info, struct key_parse *k) 786 { 787 if (info->attrs[NL80211_ATTR_KEY_DATA]) { 788 k->p.key = nla_data(info->attrs[NL80211_ATTR_KEY_DATA]); 789 k->p.key_len = nla_len(info->attrs[NL80211_ATTR_KEY_DATA]); 790 } 791 792 if (info->attrs[NL80211_ATTR_KEY_SEQ]) { 793 k->p.seq = nla_data(info->attrs[NL80211_ATTR_KEY_SEQ]); 794 k->p.seq_len = nla_len(info->attrs[NL80211_ATTR_KEY_SEQ]); 795 } 796 797 if (info->attrs[NL80211_ATTR_KEY_IDX]) 798 k->idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]); 799 800 if (info->attrs[NL80211_ATTR_KEY_CIPHER]) 801 k->p.cipher = nla_get_u32(info->attrs[NL80211_ATTR_KEY_CIPHER]); 802 803 k->def = !!info->attrs[NL80211_ATTR_KEY_DEFAULT]; 804 k->defmgmt = !!info->attrs[NL80211_ATTR_KEY_DEFAULT_MGMT]; 805 806 if (k->def) { 807 k->def_uni = true; 808 k->def_multi = true; 809 } 810 if (k->defmgmt) 811 k->def_multi = true; 812 813 if (info->attrs[NL80211_ATTR_KEY_TYPE]) { 814 k->type = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]); 815 if (k->type < 0 || k->type >= NUM_NL80211_KEYTYPES) 816 return -EINVAL; 817 } 818 819 if (info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES]) { 820 struct nlattr *kdt[NUM_NL80211_KEY_DEFAULT_TYPES]; 821 int err = nla_parse_nested( 822 kdt, NUM_NL80211_KEY_DEFAULT_TYPES - 1, 823 info->attrs[NL80211_ATTR_KEY_DEFAULT_TYPES], 824 nl80211_key_default_policy); 825 if (err) 826 return err; 827 828 k->def_uni = kdt[NL80211_KEY_DEFAULT_TYPE_UNICAST]; 829 k->def_multi = kdt[NL80211_KEY_DEFAULT_TYPE_MULTICAST]; 830 } 831 832 return 0; 833 } 834 835 static int nl80211_parse_key(struct genl_info *info, struct key_parse *k) 836 { 837 int err; 838 839 memset(k, 0, sizeof(*k)); 840 k->idx = -1; 841 k->type = -1; 842 843 if (info->attrs[NL80211_ATTR_KEY]) 844 err = nl80211_parse_key_new(info->attrs[NL80211_ATTR_KEY], k); 845 else 846 err = nl80211_parse_key_old(info, k); 847 848 if (err) 849 return err; 850 851 if (k->def && k->defmgmt) 852 return -EINVAL; 853 854 if (k->defmgmt) { 855 if (k->def_uni || !k->def_multi) 856 return -EINVAL; 857 } 858 859 if (k->idx != -1) { 860 if (k->defmgmt) { 861 if (k->idx < 4 || k->idx > 5) 862 return -EINVAL; 863 } else if (k->def) { 864 if (k->idx < 0 || k->idx > 3) 865 return -EINVAL; 866 } else { 867 if (k->idx < 0 || k->idx > 5) 868 return -EINVAL; 869 } 870 } 871 872 return 0; 873 } 874 875 static struct cfg80211_cached_keys * 876 nl80211_parse_connkeys(struct cfg80211_registered_device *rdev, 877 struct nlattr *keys, bool *no_ht) 878 { 879 struct key_parse parse; 880 struct nlattr *key; 881 struct cfg80211_cached_keys *result; 882 int rem, err, def = 0; 883 bool have_key = false; 884 885 nla_for_each_nested(key, keys, rem) { 886 have_key = true; 887 break; 888 } 889 890 if (!have_key) 891 return NULL; 892 893 result = kzalloc(sizeof(*result), GFP_KERNEL); 894 if (!result) 895 return ERR_PTR(-ENOMEM); 896 897 result->def = -1; 898 899 nla_for_each_nested(key, keys, rem) { 900 memset(&parse, 0, sizeof(parse)); 901 parse.idx = -1; 902 903 err = nl80211_parse_key_new(key, &parse); 904 if (err) 905 goto error; 906 err = -EINVAL; 907 if (!parse.p.key) 908 goto error; 909 if (parse.idx < 0 || parse.idx > 3) 910 goto error; 911 if (parse.def) { 912 if (def) 913 goto error; 914 def = 1; 915 result->def = parse.idx; 916 if (!parse.def_uni || !parse.def_multi) 917 goto error; 918 } else if (parse.defmgmt) 919 goto error; 920 err = cfg80211_validate_key_settings(rdev, &parse.p, 921 parse.idx, false, NULL); 922 if (err) 923 goto error; 924 if (parse.p.cipher != WLAN_CIPHER_SUITE_WEP40 && 925 parse.p.cipher != WLAN_CIPHER_SUITE_WEP104) { 926 err = -EINVAL; 927 goto error; 928 } 929 result->params[parse.idx].cipher = parse.p.cipher; 930 result->params[parse.idx].key_len = parse.p.key_len; 931 result->params[parse.idx].key = result->data[parse.idx]; 932 memcpy(result->data[parse.idx], parse.p.key, parse.p.key_len); 933 934 /* must be WEP key if we got here */ 935 if (no_ht) 936 *no_ht = true; 937 } 938 939 if (result->def < 0) { 940 err = -EINVAL; 941 goto error; 942 } 943 944 return result; 945 error: 946 kfree(result); 947 return ERR_PTR(err); 948 } 949 950 static int nl80211_key_allowed(struct wireless_dev *wdev) 951 { 952 ASSERT_WDEV_LOCK(wdev); 953 954 switch (wdev->iftype) { 955 case NL80211_IFTYPE_AP: 956 case NL80211_IFTYPE_AP_VLAN: 957 case NL80211_IFTYPE_P2P_GO: 958 case NL80211_IFTYPE_MESH_POINT: 959 break; 960 case NL80211_IFTYPE_ADHOC: 961 case NL80211_IFTYPE_STATION: 962 case NL80211_IFTYPE_P2P_CLIENT: 963 if (!wdev->current_bss) 964 return -ENOLINK; 965 break; 966 case NL80211_IFTYPE_UNSPECIFIED: 967 case NL80211_IFTYPE_OCB: 968 case NL80211_IFTYPE_MONITOR: 969 case NL80211_IFTYPE_NAN: 970 case NL80211_IFTYPE_P2P_DEVICE: 971 case NL80211_IFTYPE_WDS: 972 case NUM_NL80211_IFTYPES: 973 return -EINVAL; 974 } 975 976 return 0; 977 } 978 979 static struct ieee80211_channel *nl80211_get_valid_chan(struct wiphy *wiphy, 980 struct nlattr *tb) 981 { 982 struct ieee80211_channel *chan; 983 984 if (tb == NULL) 985 return NULL; 986 chan = ieee80211_get_channel(wiphy, nla_get_u32(tb)); 987 if (!chan || chan->flags & IEEE80211_CHAN_DISABLED) 988 return NULL; 989 return chan; 990 } 991 992 static int nl80211_put_iftypes(struct sk_buff *msg, u32 attr, u16 ifmodes) 993 { 994 struct nlattr *nl_modes = nla_nest_start(msg, attr); 995 int i; 996 997 if (!nl_modes) 998 goto nla_put_failure; 999 1000 i = 0; 1001 while (ifmodes) { 1002 if ((ifmodes & 1) && nla_put_flag(msg, i)) 1003 goto nla_put_failure; 1004 ifmodes >>= 1; 1005 i++; 1006 } 1007 1008 nla_nest_end(msg, nl_modes); 1009 return 0; 1010 1011 nla_put_failure: 1012 return -ENOBUFS; 1013 } 1014 1015 static int nl80211_put_iface_combinations(struct wiphy *wiphy, 1016 struct sk_buff *msg, 1017 bool large) 1018 { 1019 struct nlattr *nl_combis; 1020 int i, j; 1021 1022 nl_combis = nla_nest_start(msg, 1023 NL80211_ATTR_INTERFACE_COMBINATIONS); 1024 if (!nl_combis) 1025 goto nla_put_failure; 1026 1027 for (i = 0; i < wiphy->n_iface_combinations; i++) { 1028 const struct ieee80211_iface_combination *c; 1029 struct nlattr *nl_combi, *nl_limits; 1030 1031 c = &wiphy->iface_combinations[i]; 1032 1033 nl_combi = nla_nest_start(msg, i + 1); 1034 if (!nl_combi) 1035 goto nla_put_failure; 1036 1037 nl_limits = nla_nest_start(msg, NL80211_IFACE_COMB_LIMITS); 1038 if (!nl_limits) 1039 goto nla_put_failure; 1040 1041 for (j = 0; j < c->n_limits; j++) { 1042 struct nlattr *nl_limit; 1043 1044 nl_limit = nla_nest_start(msg, j + 1); 1045 if (!nl_limit) 1046 goto nla_put_failure; 1047 if (nla_put_u32(msg, NL80211_IFACE_LIMIT_MAX, 1048 c->limits[j].max)) 1049 goto nla_put_failure; 1050 if (nl80211_put_iftypes(msg, NL80211_IFACE_LIMIT_TYPES, 1051 c->limits[j].types)) 1052 goto nla_put_failure; 1053 nla_nest_end(msg, nl_limit); 1054 } 1055 1056 nla_nest_end(msg, nl_limits); 1057 1058 if (c->beacon_int_infra_match && 1059 nla_put_flag(msg, NL80211_IFACE_COMB_STA_AP_BI_MATCH)) 1060 goto nla_put_failure; 1061 if (nla_put_u32(msg, NL80211_IFACE_COMB_NUM_CHANNELS, 1062 c->num_different_channels) || 1063 nla_put_u32(msg, NL80211_IFACE_COMB_MAXNUM, 1064 c->max_interfaces)) 1065 goto nla_put_failure; 1066 if (large && 1067 (nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_WIDTHS, 1068 c->radar_detect_widths) || 1069 nla_put_u32(msg, NL80211_IFACE_COMB_RADAR_DETECT_REGIONS, 1070 c->radar_detect_regions))) 1071 goto nla_put_failure; 1072 if (c->beacon_int_min_gcd && 1073 nla_put_u32(msg, NL80211_IFACE_COMB_BI_MIN_GCD, 1074 c->beacon_int_min_gcd)) 1075 goto nla_put_failure; 1076 1077 nla_nest_end(msg, nl_combi); 1078 } 1079 1080 nla_nest_end(msg, nl_combis); 1081 1082 return 0; 1083 nla_put_failure: 1084 return -ENOBUFS; 1085 } 1086 1087 #ifdef CONFIG_PM 1088 static int nl80211_send_wowlan_tcp_caps(struct cfg80211_registered_device *rdev, 1089 struct sk_buff *msg) 1090 { 1091 const struct wiphy_wowlan_tcp_support *tcp = rdev->wiphy.wowlan->tcp; 1092 struct nlattr *nl_tcp; 1093 1094 if (!tcp) 1095 return 0; 1096 1097 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION); 1098 if (!nl_tcp) 1099 return -ENOBUFS; 1100 1101 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 1102 tcp->data_payload_max)) 1103 return -ENOBUFS; 1104 1105 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 1106 tcp->data_payload_max)) 1107 return -ENOBUFS; 1108 1109 if (tcp->seq && nla_put_flag(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ)) 1110 return -ENOBUFS; 1111 1112 if (tcp->tok && nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN, 1113 sizeof(*tcp->tok), tcp->tok)) 1114 return -ENOBUFS; 1115 1116 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL, 1117 tcp->data_interval_max)) 1118 return -ENOBUFS; 1119 1120 if (nla_put_u32(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD, 1121 tcp->wake_payload_max)) 1122 return -ENOBUFS; 1123 1124 nla_nest_end(msg, nl_tcp); 1125 return 0; 1126 } 1127 1128 static int nl80211_send_wowlan(struct sk_buff *msg, 1129 struct cfg80211_registered_device *rdev, 1130 bool large) 1131 { 1132 struct nlattr *nl_wowlan; 1133 1134 if (!rdev->wiphy.wowlan) 1135 return 0; 1136 1137 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS_SUPPORTED); 1138 if (!nl_wowlan) 1139 return -ENOBUFS; 1140 1141 if (((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_ANY) && 1142 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) || 1143 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_DISCONNECT) && 1144 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) || 1145 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT) && 1146 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) || 1147 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_SUPPORTS_GTK_REKEY) && 1148 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED)) || 1149 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE) && 1150 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) || 1151 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ) && 1152 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) || 1153 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE) && 1154 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) || 1155 ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE) && 1156 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) 1157 return -ENOBUFS; 1158 1159 if (rdev->wiphy.wowlan->n_patterns) { 1160 struct nl80211_pattern_support pat = { 1161 .max_patterns = rdev->wiphy.wowlan->n_patterns, 1162 .min_pattern_len = rdev->wiphy.wowlan->pattern_min_len, 1163 .max_pattern_len = rdev->wiphy.wowlan->pattern_max_len, 1164 .max_pkt_offset = rdev->wiphy.wowlan->max_pkt_offset, 1165 }; 1166 1167 if (nla_put(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN, 1168 sizeof(pat), &pat)) 1169 return -ENOBUFS; 1170 } 1171 1172 if ((rdev->wiphy.wowlan->flags & WIPHY_WOWLAN_NET_DETECT) && 1173 nla_put_u32(msg, NL80211_WOWLAN_TRIG_NET_DETECT, 1174 rdev->wiphy.wowlan->max_nd_match_sets)) 1175 return -ENOBUFS; 1176 1177 if (large && nl80211_send_wowlan_tcp_caps(rdev, msg)) 1178 return -ENOBUFS; 1179 1180 nla_nest_end(msg, nl_wowlan); 1181 1182 return 0; 1183 } 1184 #endif 1185 1186 static int nl80211_send_coalesce(struct sk_buff *msg, 1187 struct cfg80211_registered_device *rdev) 1188 { 1189 struct nl80211_coalesce_rule_support rule; 1190 1191 if (!rdev->wiphy.coalesce) 1192 return 0; 1193 1194 rule.max_rules = rdev->wiphy.coalesce->n_rules; 1195 rule.max_delay = rdev->wiphy.coalesce->max_delay; 1196 rule.pat.max_patterns = rdev->wiphy.coalesce->n_patterns; 1197 rule.pat.min_pattern_len = rdev->wiphy.coalesce->pattern_min_len; 1198 rule.pat.max_pattern_len = rdev->wiphy.coalesce->pattern_max_len; 1199 rule.pat.max_pkt_offset = rdev->wiphy.coalesce->max_pkt_offset; 1200 1201 if (nla_put(msg, NL80211_ATTR_COALESCE_RULE, sizeof(rule), &rule)) 1202 return -ENOBUFS; 1203 1204 return 0; 1205 } 1206 1207 static int nl80211_send_band_rateinfo(struct sk_buff *msg, 1208 struct ieee80211_supported_band *sband) 1209 { 1210 struct nlattr *nl_rates, *nl_rate; 1211 struct ieee80211_rate *rate; 1212 int i; 1213 1214 /* add HT info */ 1215 if (sband->ht_cap.ht_supported && 1216 (nla_put(msg, NL80211_BAND_ATTR_HT_MCS_SET, 1217 sizeof(sband->ht_cap.mcs), 1218 &sband->ht_cap.mcs) || 1219 nla_put_u16(msg, NL80211_BAND_ATTR_HT_CAPA, 1220 sband->ht_cap.cap) || 1221 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_FACTOR, 1222 sband->ht_cap.ampdu_factor) || 1223 nla_put_u8(msg, NL80211_BAND_ATTR_HT_AMPDU_DENSITY, 1224 sband->ht_cap.ampdu_density))) 1225 return -ENOBUFS; 1226 1227 /* add VHT info */ 1228 if (sband->vht_cap.vht_supported && 1229 (nla_put(msg, NL80211_BAND_ATTR_VHT_MCS_SET, 1230 sizeof(sband->vht_cap.vht_mcs), 1231 &sband->vht_cap.vht_mcs) || 1232 nla_put_u32(msg, NL80211_BAND_ATTR_VHT_CAPA, 1233 sband->vht_cap.cap))) 1234 return -ENOBUFS; 1235 1236 /* add bitrates */ 1237 nl_rates = nla_nest_start(msg, NL80211_BAND_ATTR_RATES); 1238 if (!nl_rates) 1239 return -ENOBUFS; 1240 1241 for (i = 0; i < sband->n_bitrates; i++) { 1242 nl_rate = nla_nest_start(msg, i); 1243 if (!nl_rate) 1244 return -ENOBUFS; 1245 1246 rate = &sband->bitrates[i]; 1247 if (nla_put_u32(msg, NL80211_BITRATE_ATTR_RATE, 1248 rate->bitrate)) 1249 return -ENOBUFS; 1250 if ((rate->flags & IEEE80211_RATE_SHORT_PREAMBLE) && 1251 nla_put_flag(msg, 1252 NL80211_BITRATE_ATTR_2GHZ_SHORTPREAMBLE)) 1253 return -ENOBUFS; 1254 1255 nla_nest_end(msg, nl_rate); 1256 } 1257 1258 nla_nest_end(msg, nl_rates); 1259 1260 return 0; 1261 } 1262 1263 static int 1264 nl80211_send_mgmt_stypes(struct sk_buff *msg, 1265 const struct ieee80211_txrx_stypes *mgmt_stypes) 1266 { 1267 u16 stypes; 1268 struct nlattr *nl_ftypes, *nl_ifs; 1269 enum nl80211_iftype ift; 1270 int i; 1271 1272 if (!mgmt_stypes) 1273 return 0; 1274 1275 nl_ifs = nla_nest_start(msg, NL80211_ATTR_TX_FRAME_TYPES); 1276 if (!nl_ifs) 1277 return -ENOBUFS; 1278 1279 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) { 1280 nl_ftypes = nla_nest_start(msg, ift); 1281 if (!nl_ftypes) 1282 return -ENOBUFS; 1283 i = 0; 1284 stypes = mgmt_stypes[ift].tx; 1285 while (stypes) { 1286 if ((stypes & 1) && 1287 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, 1288 (i << 4) | IEEE80211_FTYPE_MGMT)) 1289 return -ENOBUFS; 1290 stypes >>= 1; 1291 i++; 1292 } 1293 nla_nest_end(msg, nl_ftypes); 1294 } 1295 1296 nla_nest_end(msg, nl_ifs); 1297 1298 nl_ifs = nla_nest_start(msg, NL80211_ATTR_RX_FRAME_TYPES); 1299 if (!nl_ifs) 1300 return -ENOBUFS; 1301 1302 for (ift = 0; ift < NUM_NL80211_IFTYPES; ift++) { 1303 nl_ftypes = nla_nest_start(msg, ift); 1304 if (!nl_ftypes) 1305 return -ENOBUFS; 1306 i = 0; 1307 stypes = mgmt_stypes[ift].rx; 1308 while (stypes) { 1309 if ((stypes & 1) && 1310 nla_put_u16(msg, NL80211_ATTR_FRAME_TYPE, 1311 (i << 4) | IEEE80211_FTYPE_MGMT)) 1312 return -ENOBUFS; 1313 stypes >>= 1; 1314 i++; 1315 } 1316 nla_nest_end(msg, nl_ftypes); 1317 } 1318 nla_nest_end(msg, nl_ifs); 1319 1320 return 0; 1321 } 1322 1323 #define CMD(op, n) \ 1324 do { \ 1325 if (rdev->ops->op) { \ 1326 i++; \ 1327 if (nla_put_u32(msg, i, NL80211_CMD_ ## n)) \ 1328 goto nla_put_failure; \ 1329 } \ 1330 } while (0) 1331 1332 static int nl80211_add_commands_unsplit(struct cfg80211_registered_device *rdev, 1333 struct sk_buff *msg) 1334 { 1335 int i = 0; 1336 1337 /* 1338 * do *NOT* add anything into this function, new things need to be 1339 * advertised only to new versions of userspace that can deal with 1340 * the split (and they can't possibly care about new features... 1341 */ 1342 CMD(add_virtual_intf, NEW_INTERFACE); 1343 CMD(change_virtual_intf, SET_INTERFACE); 1344 CMD(add_key, NEW_KEY); 1345 CMD(start_ap, START_AP); 1346 CMD(add_station, NEW_STATION); 1347 CMD(add_mpath, NEW_MPATH); 1348 CMD(update_mesh_config, SET_MESH_CONFIG); 1349 CMD(change_bss, SET_BSS); 1350 CMD(auth, AUTHENTICATE); 1351 CMD(assoc, ASSOCIATE); 1352 CMD(deauth, DEAUTHENTICATE); 1353 CMD(disassoc, DISASSOCIATE); 1354 CMD(join_ibss, JOIN_IBSS); 1355 CMD(join_mesh, JOIN_MESH); 1356 CMD(set_pmksa, SET_PMKSA); 1357 CMD(del_pmksa, DEL_PMKSA); 1358 CMD(flush_pmksa, FLUSH_PMKSA); 1359 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) 1360 CMD(remain_on_channel, REMAIN_ON_CHANNEL); 1361 CMD(set_bitrate_mask, SET_TX_BITRATE_MASK); 1362 CMD(mgmt_tx, FRAME); 1363 CMD(mgmt_tx_cancel_wait, FRAME_WAIT_CANCEL); 1364 if (rdev->wiphy.flags & WIPHY_FLAG_NETNS_OK) { 1365 i++; 1366 if (nla_put_u32(msg, i, NL80211_CMD_SET_WIPHY_NETNS)) 1367 goto nla_put_failure; 1368 } 1369 if (rdev->ops->set_monitor_channel || rdev->ops->start_ap || 1370 rdev->ops->join_mesh) { 1371 i++; 1372 if (nla_put_u32(msg, i, NL80211_CMD_SET_CHANNEL)) 1373 goto nla_put_failure; 1374 } 1375 CMD(set_wds_peer, SET_WDS_PEER); 1376 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) { 1377 CMD(tdls_mgmt, TDLS_MGMT); 1378 CMD(tdls_oper, TDLS_OPER); 1379 } 1380 if (rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) 1381 CMD(sched_scan_start, START_SCHED_SCAN); 1382 CMD(probe_client, PROBE_CLIENT); 1383 CMD(set_noack_map, SET_NOACK_MAP); 1384 if (rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS) { 1385 i++; 1386 if (nla_put_u32(msg, i, NL80211_CMD_REGISTER_BEACONS)) 1387 goto nla_put_failure; 1388 } 1389 CMD(start_p2p_device, START_P2P_DEVICE); 1390 CMD(set_mcast_rate, SET_MCAST_RATE); 1391 #ifdef CONFIG_NL80211_TESTMODE 1392 CMD(testmode_cmd, TESTMODE); 1393 #endif 1394 1395 if (rdev->ops->connect || rdev->ops->auth) { 1396 i++; 1397 if (nla_put_u32(msg, i, NL80211_CMD_CONNECT)) 1398 goto nla_put_failure; 1399 } 1400 1401 if (rdev->ops->disconnect || rdev->ops->deauth) { 1402 i++; 1403 if (nla_put_u32(msg, i, NL80211_CMD_DISCONNECT)) 1404 goto nla_put_failure; 1405 } 1406 1407 return i; 1408 nla_put_failure: 1409 return -ENOBUFS; 1410 } 1411 1412 struct nl80211_dump_wiphy_state { 1413 s64 filter_wiphy; 1414 long start; 1415 long split_start, band_start, chan_start, capa_start; 1416 bool split; 1417 }; 1418 1419 static int nl80211_send_wiphy(struct cfg80211_registered_device *rdev, 1420 enum nl80211_commands cmd, 1421 struct sk_buff *msg, u32 portid, u32 seq, 1422 int flags, struct nl80211_dump_wiphy_state *state) 1423 { 1424 void *hdr; 1425 struct nlattr *nl_bands, *nl_band; 1426 struct nlattr *nl_freqs, *nl_freq; 1427 struct nlattr *nl_cmds; 1428 enum nl80211_band band; 1429 struct ieee80211_channel *chan; 1430 int i; 1431 const struct ieee80211_txrx_stypes *mgmt_stypes = 1432 rdev->wiphy.mgmt_stypes; 1433 u32 features; 1434 1435 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 1436 if (!hdr) 1437 return -ENOBUFS; 1438 1439 if (WARN_ON(!state)) 1440 return -EINVAL; 1441 1442 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 1443 nla_put_string(msg, NL80211_ATTR_WIPHY_NAME, 1444 wiphy_name(&rdev->wiphy)) || 1445 nla_put_u32(msg, NL80211_ATTR_GENERATION, 1446 cfg80211_rdev_list_generation)) 1447 goto nla_put_failure; 1448 1449 if (cmd != NL80211_CMD_NEW_WIPHY) 1450 goto finish; 1451 1452 switch (state->split_start) { 1453 case 0: 1454 if (nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_SHORT, 1455 rdev->wiphy.retry_short) || 1456 nla_put_u8(msg, NL80211_ATTR_WIPHY_RETRY_LONG, 1457 rdev->wiphy.retry_long) || 1458 nla_put_u32(msg, NL80211_ATTR_WIPHY_FRAG_THRESHOLD, 1459 rdev->wiphy.frag_threshold) || 1460 nla_put_u32(msg, NL80211_ATTR_WIPHY_RTS_THRESHOLD, 1461 rdev->wiphy.rts_threshold) || 1462 nla_put_u8(msg, NL80211_ATTR_WIPHY_COVERAGE_CLASS, 1463 rdev->wiphy.coverage_class) || 1464 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCAN_SSIDS, 1465 rdev->wiphy.max_scan_ssids) || 1466 nla_put_u8(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_SSIDS, 1467 rdev->wiphy.max_sched_scan_ssids) || 1468 nla_put_u16(msg, NL80211_ATTR_MAX_SCAN_IE_LEN, 1469 rdev->wiphy.max_scan_ie_len) || 1470 nla_put_u16(msg, NL80211_ATTR_MAX_SCHED_SCAN_IE_LEN, 1471 rdev->wiphy.max_sched_scan_ie_len) || 1472 nla_put_u8(msg, NL80211_ATTR_MAX_MATCH_SETS, 1473 rdev->wiphy.max_match_sets) || 1474 nla_put_u32(msg, NL80211_ATTR_MAX_NUM_SCHED_SCAN_PLANS, 1475 rdev->wiphy.max_sched_scan_plans) || 1476 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_INTERVAL, 1477 rdev->wiphy.max_sched_scan_plan_interval) || 1478 nla_put_u32(msg, NL80211_ATTR_MAX_SCAN_PLAN_ITERATIONS, 1479 rdev->wiphy.max_sched_scan_plan_iterations)) 1480 goto nla_put_failure; 1481 1482 if ((rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN) && 1483 nla_put_flag(msg, NL80211_ATTR_SUPPORT_IBSS_RSN)) 1484 goto nla_put_failure; 1485 if ((rdev->wiphy.flags & WIPHY_FLAG_MESH_AUTH) && 1486 nla_put_flag(msg, NL80211_ATTR_SUPPORT_MESH_AUTH)) 1487 goto nla_put_failure; 1488 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) && 1489 nla_put_flag(msg, NL80211_ATTR_SUPPORT_AP_UAPSD)) 1490 goto nla_put_failure; 1491 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_FW_ROAM) && 1492 nla_put_flag(msg, NL80211_ATTR_ROAM_SUPPORT)) 1493 goto nla_put_failure; 1494 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) && 1495 nla_put_flag(msg, NL80211_ATTR_TDLS_SUPPORT)) 1496 goto nla_put_failure; 1497 if ((rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP) && 1498 nla_put_flag(msg, NL80211_ATTR_TDLS_EXTERNAL_SETUP)) 1499 goto nla_put_failure; 1500 state->split_start++; 1501 if (state->split) 1502 break; 1503 case 1: 1504 if (nla_put(msg, NL80211_ATTR_CIPHER_SUITES, 1505 sizeof(u32) * rdev->wiphy.n_cipher_suites, 1506 rdev->wiphy.cipher_suites)) 1507 goto nla_put_failure; 1508 1509 if (nla_put_u8(msg, NL80211_ATTR_MAX_NUM_PMKIDS, 1510 rdev->wiphy.max_num_pmkids)) 1511 goto nla_put_failure; 1512 1513 if ((rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) && 1514 nla_put_flag(msg, NL80211_ATTR_CONTROL_PORT_ETHERTYPE)) 1515 goto nla_put_failure; 1516 1517 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_TX, 1518 rdev->wiphy.available_antennas_tx) || 1519 nla_put_u32(msg, NL80211_ATTR_WIPHY_ANTENNA_AVAIL_RX, 1520 rdev->wiphy.available_antennas_rx)) 1521 goto nla_put_failure; 1522 1523 if ((rdev->wiphy.flags & WIPHY_FLAG_AP_PROBE_RESP_OFFLOAD) && 1524 nla_put_u32(msg, NL80211_ATTR_PROBE_RESP_OFFLOAD, 1525 rdev->wiphy.probe_resp_offload)) 1526 goto nla_put_failure; 1527 1528 if ((rdev->wiphy.available_antennas_tx || 1529 rdev->wiphy.available_antennas_rx) && 1530 rdev->ops->get_antenna) { 1531 u32 tx_ant = 0, rx_ant = 0; 1532 int res; 1533 1534 res = rdev_get_antenna(rdev, &tx_ant, &rx_ant); 1535 if (!res) { 1536 if (nla_put_u32(msg, 1537 NL80211_ATTR_WIPHY_ANTENNA_TX, 1538 tx_ant) || 1539 nla_put_u32(msg, 1540 NL80211_ATTR_WIPHY_ANTENNA_RX, 1541 rx_ant)) 1542 goto nla_put_failure; 1543 } 1544 } 1545 1546 state->split_start++; 1547 if (state->split) 1548 break; 1549 case 2: 1550 if (nl80211_put_iftypes(msg, NL80211_ATTR_SUPPORTED_IFTYPES, 1551 rdev->wiphy.interface_modes)) 1552 goto nla_put_failure; 1553 state->split_start++; 1554 if (state->split) 1555 break; 1556 case 3: 1557 nl_bands = nla_nest_start(msg, NL80211_ATTR_WIPHY_BANDS); 1558 if (!nl_bands) 1559 goto nla_put_failure; 1560 1561 for (band = state->band_start; 1562 band < NUM_NL80211_BANDS; band++) { 1563 struct ieee80211_supported_band *sband; 1564 1565 sband = rdev->wiphy.bands[band]; 1566 1567 if (!sband) 1568 continue; 1569 1570 nl_band = nla_nest_start(msg, band); 1571 if (!nl_band) 1572 goto nla_put_failure; 1573 1574 switch (state->chan_start) { 1575 case 0: 1576 if (nl80211_send_band_rateinfo(msg, sband)) 1577 goto nla_put_failure; 1578 state->chan_start++; 1579 if (state->split) 1580 break; 1581 default: 1582 /* add frequencies */ 1583 nl_freqs = nla_nest_start( 1584 msg, NL80211_BAND_ATTR_FREQS); 1585 if (!nl_freqs) 1586 goto nla_put_failure; 1587 1588 for (i = state->chan_start - 1; 1589 i < sband->n_channels; 1590 i++) { 1591 nl_freq = nla_nest_start(msg, i); 1592 if (!nl_freq) 1593 goto nla_put_failure; 1594 1595 chan = &sband->channels[i]; 1596 1597 if (nl80211_msg_put_channel( 1598 msg, chan, 1599 state->split)) 1600 goto nla_put_failure; 1601 1602 nla_nest_end(msg, nl_freq); 1603 if (state->split) 1604 break; 1605 } 1606 if (i < sband->n_channels) 1607 state->chan_start = i + 2; 1608 else 1609 state->chan_start = 0; 1610 nla_nest_end(msg, nl_freqs); 1611 } 1612 1613 nla_nest_end(msg, nl_band); 1614 1615 if (state->split) { 1616 /* start again here */ 1617 if (state->chan_start) 1618 band--; 1619 break; 1620 } 1621 } 1622 nla_nest_end(msg, nl_bands); 1623 1624 if (band < NUM_NL80211_BANDS) 1625 state->band_start = band + 1; 1626 else 1627 state->band_start = 0; 1628 1629 /* if bands & channels are done, continue outside */ 1630 if (state->band_start == 0 && state->chan_start == 0) 1631 state->split_start++; 1632 if (state->split) 1633 break; 1634 case 4: 1635 nl_cmds = nla_nest_start(msg, NL80211_ATTR_SUPPORTED_COMMANDS); 1636 if (!nl_cmds) 1637 goto nla_put_failure; 1638 1639 i = nl80211_add_commands_unsplit(rdev, msg); 1640 if (i < 0) 1641 goto nla_put_failure; 1642 if (state->split) { 1643 CMD(crit_proto_start, CRIT_PROTOCOL_START); 1644 CMD(crit_proto_stop, CRIT_PROTOCOL_STOP); 1645 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH) 1646 CMD(channel_switch, CHANNEL_SWITCH); 1647 CMD(set_qos_map, SET_QOS_MAP); 1648 if (rdev->wiphy.features & 1649 NL80211_FEATURE_SUPPORTS_WMM_ADMISSION) 1650 CMD(add_tx_ts, ADD_TX_TS); 1651 CMD(set_multicast_to_unicast, SET_MULTICAST_TO_UNICAST); 1652 CMD(update_connect_params, UPDATE_CONNECT_PARAMS); 1653 } 1654 #undef CMD 1655 1656 nla_nest_end(msg, nl_cmds); 1657 state->split_start++; 1658 if (state->split) 1659 break; 1660 case 5: 1661 if (rdev->ops->remain_on_channel && 1662 (rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL) && 1663 nla_put_u32(msg, 1664 NL80211_ATTR_MAX_REMAIN_ON_CHANNEL_DURATION, 1665 rdev->wiphy.max_remain_on_channel_duration)) 1666 goto nla_put_failure; 1667 1668 if ((rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX) && 1669 nla_put_flag(msg, NL80211_ATTR_OFFCHANNEL_TX_OK)) 1670 goto nla_put_failure; 1671 1672 if (nl80211_send_mgmt_stypes(msg, mgmt_stypes)) 1673 goto nla_put_failure; 1674 state->split_start++; 1675 if (state->split) 1676 break; 1677 case 6: 1678 #ifdef CONFIG_PM 1679 if (nl80211_send_wowlan(msg, rdev, state->split)) 1680 goto nla_put_failure; 1681 state->split_start++; 1682 if (state->split) 1683 break; 1684 #else 1685 state->split_start++; 1686 #endif 1687 case 7: 1688 if (nl80211_put_iftypes(msg, NL80211_ATTR_SOFTWARE_IFTYPES, 1689 rdev->wiphy.software_iftypes)) 1690 goto nla_put_failure; 1691 1692 if (nl80211_put_iface_combinations(&rdev->wiphy, msg, 1693 state->split)) 1694 goto nla_put_failure; 1695 1696 state->split_start++; 1697 if (state->split) 1698 break; 1699 case 8: 1700 if ((rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME) && 1701 nla_put_u32(msg, NL80211_ATTR_DEVICE_AP_SME, 1702 rdev->wiphy.ap_sme_capa)) 1703 goto nla_put_failure; 1704 1705 features = rdev->wiphy.features; 1706 /* 1707 * We can only add the per-channel limit information if the 1708 * dump is split, otherwise it makes it too big. Therefore 1709 * only advertise it in that case. 1710 */ 1711 if (state->split) 1712 features |= NL80211_FEATURE_ADVERTISE_CHAN_LIMITS; 1713 if (nla_put_u32(msg, NL80211_ATTR_FEATURE_FLAGS, features)) 1714 goto nla_put_failure; 1715 1716 if (rdev->wiphy.ht_capa_mod_mask && 1717 nla_put(msg, NL80211_ATTR_HT_CAPABILITY_MASK, 1718 sizeof(*rdev->wiphy.ht_capa_mod_mask), 1719 rdev->wiphy.ht_capa_mod_mask)) 1720 goto nla_put_failure; 1721 1722 if (rdev->wiphy.flags & WIPHY_FLAG_HAVE_AP_SME && 1723 rdev->wiphy.max_acl_mac_addrs && 1724 nla_put_u32(msg, NL80211_ATTR_MAC_ACL_MAX, 1725 rdev->wiphy.max_acl_mac_addrs)) 1726 goto nla_put_failure; 1727 1728 /* 1729 * Any information below this point is only available to 1730 * applications that can deal with it being split. This 1731 * helps ensure that newly added capabilities don't break 1732 * older tools by overrunning their buffers. 1733 * 1734 * We still increment split_start so that in the split 1735 * case we'll continue with more data in the next round, 1736 * but break unconditionally so unsplit data stops here. 1737 */ 1738 state->split_start++; 1739 break; 1740 case 9: 1741 if (rdev->wiphy.extended_capabilities && 1742 (nla_put(msg, NL80211_ATTR_EXT_CAPA, 1743 rdev->wiphy.extended_capabilities_len, 1744 rdev->wiphy.extended_capabilities) || 1745 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK, 1746 rdev->wiphy.extended_capabilities_len, 1747 rdev->wiphy.extended_capabilities_mask))) 1748 goto nla_put_failure; 1749 1750 if (rdev->wiphy.vht_capa_mod_mask && 1751 nla_put(msg, NL80211_ATTR_VHT_CAPABILITY_MASK, 1752 sizeof(*rdev->wiphy.vht_capa_mod_mask), 1753 rdev->wiphy.vht_capa_mod_mask)) 1754 goto nla_put_failure; 1755 1756 state->split_start++; 1757 break; 1758 case 10: 1759 if (nl80211_send_coalesce(msg, rdev)) 1760 goto nla_put_failure; 1761 1762 if ((rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ) && 1763 (nla_put_flag(msg, NL80211_ATTR_SUPPORT_5_MHZ) || 1764 nla_put_flag(msg, NL80211_ATTR_SUPPORT_10_MHZ))) 1765 goto nla_put_failure; 1766 1767 if (rdev->wiphy.max_ap_assoc_sta && 1768 nla_put_u32(msg, NL80211_ATTR_MAX_AP_ASSOC_STA, 1769 rdev->wiphy.max_ap_assoc_sta)) 1770 goto nla_put_failure; 1771 1772 state->split_start++; 1773 break; 1774 case 11: 1775 if (rdev->wiphy.n_vendor_commands) { 1776 const struct nl80211_vendor_cmd_info *info; 1777 struct nlattr *nested; 1778 1779 nested = nla_nest_start(msg, NL80211_ATTR_VENDOR_DATA); 1780 if (!nested) 1781 goto nla_put_failure; 1782 1783 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) { 1784 info = &rdev->wiphy.vendor_commands[i].info; 1785 if (nla_put(msg, i + 1, sizeof(*info), info)) 1786 goto nla_put_failure; 1787 } 1788 nla_nest_end(msg, nested); 1789 } 1790 1791 if (rdev->wiphy.n_vendor_events) { 1792 const struct nl80211_vendor_cmd_info *info; 1793 struct nlattr *nested; 1794 1795 nested = nla_nest_start(msg, 1796 NL80211_ATTR_VENDOR_EVENTS); 1797 if (!nested) 1798 goto nla_put_failure; 1799 1800 for (i = 0; i < rdev->wiphy.n_vendor_events; i++) { 1801 info = &rdev->wiphy.vendor_events[i]; 1802 if (nla_put(msg, i + 1, sizeof(*info), info)) 1803 goto nla_put_failure; 1804 } 1805 nla_nest_end(msg, nested); 1806 } 1807 state->split_start++; 1808 break; 1809 case 12: 1810 if (rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH && 1811 nla_put_u8(msg, NL80211_ATTR_MAX_CSA_COUNTERS, 1812 rdev->wiphy.max_num_csa_counters)) 1813 goto nla_put_failure; 1814 1815 if (rdev->wiphy.regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 1816 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 1817 goto nla_put_failure; 1818 1819 if (nla_put(msg, NL80211_ATTR_EXT_FEATURES, 1820 sizeof(rdev->wiphy.ext_features), 1821 rdev->wiphy.ext_features)) 1822 goto nla_put_failure; 1823 1824 if (rdev->wiphy.bss_select_support) { 1825 struct nlattr *nested; 1826 u32 bss_select_support = rdev->wiphy.bss_select_support; 1827 1828 nested = nla_nest_start(msg, NL80211_ATTR_BSS_SELECT); 1829 if (!nested) 1830 goto nla_put_failure; 1831 1832 i = 0; 1833 while (bss_select_support) { 1834 if ((bss_select_support & 1) && 1835 nla_put_flag(msg, i)) 1836 goto nla_put_failure; 1837 i++; 1838 bss_select_support >>= 1; 1839 } 1840 nla_nest_end(msg, nested); 1841 } 1842 1843 state->split_start++; 1844 break; 1845 case 13: 1846 if (rdev->wiphy.num_iftype_ext_capab && 1847 rdev->wiphy.iftype_ext_capab) { 1848 struct nlattr *nested_ext_capab, *nested; 1849 1850 nested = nla_nest_start(msg, 1851 NL80211_ATTR_IFTYPE_EXT_CAPA); 1852 if (!nested) 1853 goto nla_put_failure; 1854 1855 for (i = state->capa_start; 1856 i < rdev->wiphy.num_iftype_ext_capab; i++) { 1857 const struct wiphy_iftype_ext_capab *capab; 1858 1859 capab = &rdev->wiphy.iftype_ext_capab[i]; 1860 1861 nested_ext_capab = nla_nest_start(msg, i); 1862 if (!nested_ext_capab || 1863 nla_put_u32(msg, NL80211_ATTR_IFTYPE, 1864 capab->iftype) || 1865 nla_put(msg, NL80211_ATTR_EXT_CAPA, 1866 capab->extended_capabilities_len, 1867 capab->extended_capabilities) || 1868 nla_put(msg, NL80211_ATTR_EXT_CAPA_MASK, 1869 capab->extended_capabilities_len, 1870 capab->extended_capabilities_mask)) 1871 goto nla_put_failure; 1872 1873 nla_nest_end(msg, nested_ext_capab); 1874 if (state->split) 1875 break; 1876 } 1877 nla_nest_end(msg, nested); 1878 if (i < rdev->wiphy.num_iftype_ext_capab) { 1879 state->capa_start = i + 1; 1880 break; 1881 } 1882 } 1883 1884 /* done */ 1885 state->split_start = 0; 1886 break; 1887 } 1888 finish: 1889 genlmsg_end(msg, hdr); 1890 return 0; 1891 1892 nla_put_failure: 1893 genlmsg_cancel(msg, hdr); 1894 return -EMSGSIZE; 1895 } 1896 1897 static int nl80211_dump_wiphy_parse(struct sk_buff *skb, 1898 struct netlink_callback *cb, 1899 struct nl80211_dump_wiphy_state *state) 1900 { 1901 struct nlattr **tb = genl_family_attrbuf(&nl80211_fam); 1902 int ret = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 1903 tb, nl80211_fam.maxattr, nl80211_policy); 1904 /* ignore parse errors for backward compatibility */ 1905 if (ret) 1906 return 0; 1907 1908 state->split = tb[NL80211_ATTR_SPLIT_WIPHY_DUMP]; 1909 if (tb[NL80211_ATTR_WIPHY]) 1910 state->filter_wiphy = nla_get_u32(tb[NL80211_ATTR_WIPHY]); 1911 if (tb[NL80211_ATTR_WDEV]) 1912 state->filter_wiphy = nla_get_u64(tb[NL80211_ATTR_WDEV]) >> 32; 1913 if (tb[NL80211_ATTR_IFINDEX]) { 1914 struct net_device *netdev; 1915 struct cfg80211_registered_device *rdev; 1916 int ifidx = nla_get_u32(tb[NL80211_ATTR_IFINDEX]); 1917 1918 netdev = __dev_get_by_index(sock_net(skb->sk), ifidx); 1919 if (!netdev) 1920 return -ENODEV; 1921 if (netdev->ieee80211_ptr) { 1922 rdev = wiphy_to_rdev( 1923 netdev->ieee80211_ptr->wiphy); 1924 state->filter_wiphy = rdev->wiphy_idx; 1925 } 1926 } 1927 1928 return 0; 1929 } 1930 1931 static int nl80211_dump_wiphy(struct sk_buff *skb, struct netlink_callback *cb) 1932 { 1933 int idx = 0, ret; 1934 struct nl80211_dump_wiphy_state *state = (void *)cb->args[0]; 1935 struct cfg80211_registered_device *rdev; 1936 1937 rtnl_lock(); 1938 if (!state) { 1939 state = kzalloc(sizeof(*state), GFP_KERNEL); 1940 if (!state) { 1941 rtnl_unlock(); 1942 return -ENOMEM; 1943 } 1944 state->filter_wiphy = -1; 1945 ret = nl80211_dump_wiphy_parse(skb, cb, state); 1946 if (ret) { 1947 kfree(state); 1948 rtnl_unlock(); 1949 return ret; 1950 } 1951 cb->args[0] = (long)state; 1952 } 1953 1954 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 1955 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk))) 1956 continue; 1957 if (++idx <= state->start) 1958 continue; 1959 if (state->filter_wiphy != -1 && 1960 state->filter_wiphy != rdev->wiphy_idx) 1961 continue; 1962 /* attempt to fit multiple wiphy data chunks into the skb */ 1963 do { 1964 ret = nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, 1965 skb, 1966 NETLINK_CB(cb->skb).portid, 1967 cb->nlh->nlmsg_seq, 1968 NLM_F_MULTI, state); 1969 if (ret < 0) { 1970 /* 1971 * If sending the wiphy data didn't fit (ENOBUFS 1972 * or EMSGSIZE returned), this SKB is still 1973 * empty (so it's not too big because another 1974 * wiphy dataset is already in the skb) and 1975 * we've not tried to adjust the dump allocation 1976 * yet ... then adjust the alloc size to be 1977 * bigger, and return 1 but with the empty skb. 1978 * This results in an empty message being RX'ed 1979 * in userspace, but that is ignored. 1980 * 1981 * We can then retry with the larger buffer. 1982 */ 1983 if ((ret == -ENOBUFS || ret == -EMSGSIZE) && 1984 !skb->len && !state->split && 1985 cb->min_dump_alloc < 4096) { 1986 cb->min_dump_alloc = 4096; 1987 state->split_start = 0; 1988 rtnl_unlock(); 1989 return 1; 1990 } 1991 idx--; 1992 break; 1993 } 1994 } while (state->split_start > 0); 1995 break; 1996 } 1997 rtnl_unlock(); 1998 1999 state->start = idx; 2000 2001 return skb->len; 2002 } 2003 2004 static int nl80211_dump_wiphy_done(struct netlink_callback *cb) 2005 { 2006 kfree((void *)cb->args[0]); 2007 return 0; 2008 } 2009 2010 static int nl80211_get_wiphy(struct sk_buff *skb, struct genl_info *info) 2011 { 2012 struct sk_buff *msg; 2013 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2014 struct nl80211_dump_wiphy_state state = {}; 2015 2016 msg = nlmsg_new(4096, GFP_KERNEL); 2017 if (!msg) 2018 return -ENOMEM; 2019 2020 if (nl80211_send_wiphy(rdev, NL80211_CMD_NEW_WIPHY, msg, 2021 info->snd_portid, info->snd_seq, 0, 2022 &state) < 0) { 2023 nlmsg_free(msg); 2024 return -ENOBUFS; 2025 } 2026 2027 return genlmsg_reply(msg, info); 2028 } 2029 2030 static const struct nla_policy txq_params_policy[NL80211_TXQ_ATTR_MAX + 1] = { 2031 [NL80211_TXQ_ATTR_QUEUE] = { .type = NLA_U8 }, 2032 [NL80211_TXQ_ATTR_TXOP] = { .type = NLA_U16 }, 2033 [NL80211_TXQ_ATTR_CWMIN] = { .type = NLA_U16 }, 2034 [NL80211_TXQ_ATTR_CWMAX] = { .type = NLA_U16 }, 2035 [NL80211_TXQ_ATTR_AIFS] = { .type = NLA_U8 }, 2036 }; 2037 2038 static int parse_txq_params(struct nlattr *tb[], 2039 struct ieee80211_txq_params *txq_params) 2040 { 2041 if (!tb[NL80211_TXQ_ATTR_AC] || !tb[NL80211_TXQ_ATTR_TXOP] || 2042 !tb[NL80211_TXQ_ATTR_CWMIN] || !tb[NL80211_TXQ_ATTR_CWMAX] || 2043 !tb[NL80211_TXQ_ATTR_AIFS]) 2044 return -EINVAL; 2045 2046 txq_params->ac = nla_get_u8(tb[NL80211_TXQ_ATTR_AC]); 2047 txq_params->txop = nla_get_u16(tb[NL80211_TXQ_ATTR_TXOP]); 2048 txq_params->cwmin = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMIN]); 2049 txq_params->cwmax = nla_get_u16(tb[NL80211_TXQ_ATTR_CWMAX]); 2050 txq_params->aifs = nla_get_u8(tb[NL80211_TXQ_ATTR_AIFS]); 2051 2052 if (txq_params->ac >= NL80211_NUM_ACS) 2053 return -EINVAL; 2054 2055 return 0; 2056 } 2057 2058 static bool nl80211_can_set_dev_channel(struct wireless_dev *wdev) 2059 { 2060 /* 2061 * You can only set the channel explicitly for WDS interfaces, 2062 * all others have their channel managed via their respective 2063 * "establish a connection" command (connect, join, ...) 2064 * 2065 * For AP/GO and mesh mode, the channel can be set with the 2066 * channel userspace API, but is only stored and passed to the 2067 * low-level driver when the AP starts or the mesh is joined. 2068 * This is for backward compatibility, userspace can also give 2069 * the channel in the start-ap or join-mesh commands instead. 2070 * 2071 * Monitors are special as they are normally slaved to 2072 * whatever else is going on, so they have their own special 2073 * operation to set the monitor channel if possible. 2074 */ 2075 return !wdev || 2076 wdev->iftype == NL80211_IFTYPE_AP || 2077 wdev->iftype == NL80211_IFTYPE_MESH_POINT || 2078 wdev->iftype == NL80211_IFTYPE_MONITOR || 2079 wdev->iftype == NL80211_IFTYPE_P2P_GO; 2080 } 2081 2082 static int nl80211_parse_chandef(struct cfg80211_registered_device *rdev, 2083 struct genl_info *info, 2084 struct cfg80211_chan_def *chandef) 2085 { 2086 u32 control_freq; 2087 2088 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 2089 return -EINVAL; 2090 2091 control_freq = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_FREQ]); 2092 2093 chandef->chan = ieee80211_get_channel(&rdev->wiphy, control_freq); 2094 chandef->width = NL80211_CHAN_WIDTH_20_NOHT; 2095 chandef->center_freq1 = control_freq; 2096 chandef->center_freq2 = 0; 2097 2098 /* Primary channel not allowed */ 2099 if (!chandef->chan || chandef->chan->flags & IEEE80211_CHAN_DISABLED) 2100 return -EINVAL; 2101 2102 if (info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]) { 2103 enum nl80211_channel_type chantype; 2104 2105 chantype = nla_get_u32( 2106 info->attrs[NL80211_ATTR_WIPHY_CHANNEL_TYPE]); 2107 2108 switch (chantype) { 2109 case NL80211_CHAN_NO_HT: 2110 case NL80211_CHAN_HT20: 2111 case NL80211_CHAN_HT40PLUS: 2112 case NL80211_CHAN_HT40MINUS: 2113 cfg80211_chandef_create(chandef, chandef->chan, 2114 chantype); 2115 break; 2116 default: 2117 return -EINVAL; 2118 } 2119 } else if (info->attrs[NL80211_ATTR_CHANNEL_WIDTH]) { 2120 chandef->width = 2121 nla_get_u32(info->attrs[NL80211_ATTR_CHANNEL_WIDTH]); 2122 if (info->attrs[NL80211_ATTR_CENTER_FREQ1]) 2123 chandef->center_freq1 = 2124 nla_get_u32( 2125 info->attrs[NL80211_ATTR_CENTER_FREQ1]); 2126 if (info->attrs[NL80211_ATTR_CENTER_FREQ2]) 2127 chandef->center_freq2 = 2128 nla_get_u32( 2129 info->attrs[NL80211_ATTR_CENTER_FREQ2]); 2130 } 2131 2132 if (!cfg80211_chandef_valid(chandef)) 2133 return -EINVAL; 2134 2135 if (!cfg80211_chandef_usable(&rdev->wiphy, chandef, 2136 IEEE80211_CHAN_DISABLED)) 2137 return -EINVAL; 2138 2139 if ((chandef->width == NL80211_CHAN_WIDTH_5 || 2140 chandef->width == NL80211_CHAN_WIDTH_10) && 2141 !(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_5_10_MHZ)) 2142 return -EINVAL; 2143 2144 return 0; 2145 } 2146 2147 static int __nl80211_set_channel(struct cfg80211_registered_device *rdev, 2148 struct net_device *dev, 2149 struct genl_info *info) 2150 { 2151 struct cfg80211_chan_def chandef; 2152 int result; 2153 enum nl80211_iftype iftype = NL80211_IFTYPE_MONITOR; 2154 struct wireless_dev *wdev = NULL; 2155 2156 if (dev) 2157 wdev = dev->ieee80211_ptr; 2158 if (!nl80211_can_set_dev_channel(wdev)) 2159 return -EOPNOTSUPP; 2160 if (wdev) 2161 iftype = wdev->iftype; 2162 2163 result = nl80211_parse_chandef(rdev, info, &chandef); 2164 if (result) 2165 return result; 2166 2167 switch (iftype) { 2168 case NL80211_IFTYPE_AP: 2169 case NL80211_IFTYPE_P2P_GO: 2170 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef, 2171 iftype)) { 2172 result = -EINVAL; 2173 break; 2174 } 2175 if (wdev->beacon_interval) { 2176 if (!dev || !rdev->ops->set_ap_chanwidth || 2177 !(rdev->wiphy.features & 2178 NL80211_FEATURE_AP_MODE_CHAN_WIDTH_CHANGE)) { 2179 result = -EBUSY; 2180 break; 2181 } 2182 2183 /* Only allow dynamic channel width changes */ 2184 if (chandef.chan != wdev->preset_chandef.chan) { 2185 result = -EBUSY; 2186 break; 2187 } 2188 result = rdev_set_ap_chanwidth(rdev, dev, &chandef); 2189 if (result) 2190 break; 2191 } 2192 wdev->preset_chandef = chandef; 2193 result = 0; 2194 break; 2195 case NL80211_IFTYPE_MESH_POINT: 2196 result = cfg80211_set_mesh_channel(rdev, wdev, &chandef); 2197 break; 2198 case NL80211_IFTYPE_MONITOR: 2199 result = cfg80211_set_monitor_channel(rdev, &chandef); 2200 break; 2201 default: 2202 result = -EINVAL; 2203 } 2204 2205 return result; 2206 } 2207 2208 static int nl80211_set_channel(struct sk_buff *skb, struct genl_info *info) 2209 { 2210 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2211 struct net_device *netdev = info->user_ptr[1]; 2212 2213 return __nl80211_set_channel(rdev, netdev, info); 2214 } 2215 2216 static int nl80211_set_wds_peer(struct sk_buff *skb, struct genl_info *info) 2217 { 2218 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2219 struct net_device *dev = info->user_ptr[1]; 2220 struct wireless_dev *wdev = dev->ieee80211_ptr; 2221 const u8 *bssid; 2222 2223 if (!info->attrs[NL80211_ATTR_MAC]) 2224 return -EINVAL; 2225 2226 if (netif_running(dev)) 2227 return -EBUSY; 2228 2229 if (!rdev->ops->set_wds_peer) 2230 return -EOPNOTSUPP; 2231 2232 if (wdev->iftype != NL80211_IFTYPE_WDS) 2233 return -EOPNOTSUPP; 2234 2235 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 2236 return rdev_set_wds_peer(rdev, dev, bssid); 2237 } 2238 2239 static int nl80211_set_wiphy(struct sk_buff *skb, struct genl_info *info) 2240 { 2241 struct cfg80211_registered_device *rdev; 2242 struct net_device *netdev = NULL; 2243 struct wireless_dev *wdev; 2244 int result = 0, rem_txq_params = 0; 2245 struct nlattr *nl_txq_params; 2246 u32 changed; 2247 u8 retry_short = 0, retry_long = 0; 2248 u32 frag_threshold = 0, rts_threshold = 0; 2249 u8 coverage_class = 0; 2250 2251 ASSERT_RTNL(); 2252 2253 /* 2254 * Try to find the wiphy and netdev. Normally this 2255 * function shouldn't need the netdev, but this is 2256 * done for backward compatibility -- previously 2257 * setting the channel was done per wiphy, but now 2258 * it is per netdev. Previous userland like hostapd 2259 * also passed a netdev to set_wiphy, so that it is 2260 * possible to let that go to the right netdev! 2261 */ 2262 2263 if (info->attrs[NL80211_ATTR_IFINDEX]) { 2264 int ifindex = nla_get_u32(info->attrs[NL80211_ATTR_IFINDEX]); 2265 2266 netdev = __dev_get_by_index(genl_info_net(info), ifindex); 2267 if (netdev && netdev->ieee80211_ptr) 2268 rdev = wiphy_to_rdev(netdev->ieee80211_ptr->wiphy); 2269 else 2270 netdev = NULL; 2271 } 2272 2273 if (!netdev) { 2274 rdev = __cfg80211_rdev_from_attrs(genl_info_net(info), 2275 info->attrs); 2276 if (IS_ERR(rdev)) 2277 return PTR_ERR(rdev); 2278 wdev = NULL; 2279 netdev = NULL; 2280 result = 0; 2281 } else 2282 wdev = netdev->ieee80211_ptr; 2283 2284 /* 2285 * end workaround code, by now the rdev is available 2286 * and locked, and wdev may or may not be NULL. 2287 */ 2288 2289 if (info->attrs[NL80211_ATTR_WIPHY_NAME]) 2290 result = cfg80211_dev_rename( 2291 rdev, nla_data(info->attrs[NL80211_ATTR_WIPHY_NAME])); 2292 2293 if (result) 2294 return result; 2295 2296 if (info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS]) { 2297 struct ieee80211_txq_params txq_params; 2298 struct nlattr *tb[NL80211_TXQ_ATTR_MAX + 1]; 2299 2300 if (!rdev->ops->set_txq_params) 2301 return -EOPNOTSUPP; 2302 2303 if (!netdev) 2304 return -EINVAL; 2305 2306 if (netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 2307 netdev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 2308 return -EINVAL; 2309 2310 if (!netif_running(netdev)) 2311 return -ENETDOWN; 2312 2313 nla_for_each_nested(nl_txq_params, 2314 info->attrs[NL80211_ATTR_WIPHY_TXQ_PARAMS], 2315 rem_txq_params) { 2316 result = nla_parse_nested(tb, NL80211_TXQ_ATTR_MAX, 2317 nl_txq_params, 2318 txq_params_policy); 2319 if (result) 2320 return result; 2321 result = parse_txq_params(tb, &txq_params); 2322 if (result) 2323 return result; 2324 2325 result = rdev_set_txq_params(rdev, netdev, 2326 &txq_params); 2327 if (result) 2328 return result; 2329 } 2330 } 2331 2332 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 2333 result = __nl80211_set_channel( 2334 rdev, 2335 nl80211_can_set_dev_channel(wdev) ? netdev : NULL, 2336 info); 2337 if (result) 2338 return result; 2339 } 2340 2341 if (info->attrs[NL80211_ATTR_WIPHY_TX_POWER_SETTING]) { 2342 struct wireless_dev *txp_wdev = wdev; 2343 enum nl80211_tx_power_setting type; 2344 int idx, mbm = 0; 2345 2346 if (!(rdev->wiphy.features & NL80211_FEATURE_VIF_TXPOWER)) 2347 txp_wdev = NULL; 2348 2349 if (!rdev->ops->set_tx_power) 2350 return -EOPNOTSUPP; 2351 2352 idx = NL80211_ATTR_WIPHY_TX_POWER_SETTING; 2353 type = nla_get_u32(info->attrs[idx]); 2354 2355 if (!info->attrs[NL80211_ATTR_WIPHY_TX_POWER_LEVEL] && 2356 (type != NL80211_TX_POWER_AUTOMATIC)) 2357 return -EINVAL; 2358 2359 if (type != NL80211_TX_POWER_AUTOMATIC) { 2360 idx = NL80211_ATTR_WIPHY_TX_POWER_LEVEL; 2361 mbm = nla_get_u32(info->attrs[idx]); 2362 } 2363 2364 result = rdev_set_tx_power(rdev, txp_wdev, type, mbm); 2365 if (result) 2366 return result; 2367 } 2368 2369 if (info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX] && 2370 info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]) { 2371 u32 tx_ant, rx_ant; 2372 2373 if ((!rdev->wiphy.available_antennas_tx && 2374 !rdev->wiphy.available_antennas_rx) || 2375 !rdev->ops->set_antenna) 2376 return -EOPNOTSUPP; 2377 2378 tx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_TX]); 2379 rx_ant = nla_get_u32(info->attrs[NL80211_ATTR_WIPHY_ANTENNA_RX]); 2380 2381 /* reject antenna configurations which don't match the 2382 * available antenna masks, except for the "all" mask */ 2383 if ((~tx_ant && (tx_ant & ~rdev->wiphy.available_antennas_tx)) || 2384 (~rx_ant && (rx_ant & ~rdev->wiphy.available_antennas_rx))) 2385 return -EINVAL; 2386 2387 tx_ant = tx_ant & rdev->wiphy.available_antennas_tx; 2388 rx_ant = rx_ant & rdev->wiphy.available_antennas_rx; 2389 2390 result = rdev_set_antenna(rdev, tx_ant, rx_ant); 2391 if (result) 2392 return result; 2393 } 2394 2395 changed = 0; 2396 2397 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]) { 2398 retry_short = nla_get_u8( 2399 info->attrs[NL80211_ATTR_WIPHY_RETRY_SHORT]); 2400 if (retry_short == 0) 2401 return -EINVAL; 2402 2403 changed |= WIPHY_PARAM_RETRY_SHORT; 2404 } 2405 2406 if (info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]) { 2407 retry_long = nla_get_u8( 2408 info->attrs[NL80211_ATTR_WIPHY_RETRY_LONG]); 2409 if (retry_long == 0) 2410 return -EINVAL; 2411 2412 changed |= WIPHY_PARAM_RETRY_LONG; 2413 } 2414 2415 if (info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]) { 2416 frag_threshold = nla_get_u32( 2417 info->attrs[NL80211_ATTR_WIPHY_FRAG_THRESHOLD]); 2418 if (frag_threshold < 256) 2419 return -EINVAL; 2420 2421 if (frag_threshold != (u32) -1) { 2422 /* 2423 * Fragments (apart from the last one) are required to 2424 * have even length. Make the fragmentation code 2425 * simpler by stripping LSB should someone try to use 2426 * odd threshold value. 2427 */ 2428 frag_threshold &= ~0x1; 2429 } 2430 changed |= WIPHY_PARAM_FRAG_THRESHOLD; 2431 } 2432 2433 if (info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]) { 2434 rts_threshold = nla_get_u32( 2435 info->attrs[NL80211_ATTR_WIPHY_RTS_THRESHOLD]); 2436 changed |= WIPHY_PARAM_RTS_THRESHOLD; 2437 } 2438 2439 if (info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]) { 2440 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) 2441 return -EINVAL; 2442 2443 coverage_class = nla_get_u8( 2444 info->attrs[NL80211_ATTR_WIPHY_COVERAGE_CLASS]); 2445 changed |= WIPHY_PARAM_COVERAGE_CLASS; 2446 } 2447 2448 if (info->attrs[NL80211_ATTR_WIPHY_DYN_ACK]) { 2449 if (!(rdev->wiphy.features & NL80211_FEATURE_ACKTO_ESTIMATION)) 2450 return -EOPNOTSUPP; 2451 2452 changed |= WIPHY_PARAM_DYN_ACK; 2453 } 2454 2455 if (changed) { 2456 u8 old_retry_short, old_retry_long; 2457 u32 old_frag_threshold, old_rts_threshold; 2458 u8 old_coverage_class; 2459 2460 if (!rdev->ops->set_wiphy_params) 2461 return -EOPNOTSUPP; 2462 2463 old_retry_short = rdev->wiphy.retry_short; 2464 old_retry_long = rdev->wiphy.retry_long; 2465 old_frag_threshold = rdev->wiphy.frag_threshold; 2466 old_rts_threshold = rdev->wiphy.rts_threshold; 2467 old_coverage_class = rdev->wiphy.coverage_class; 2468 2469 if (changed & WIPHY_PARAM_RETRY_SHORT) 2470 rdev->wiphy.retry_short = retry_short; 2471 if (changed & WIPHY_PARAM_RETRY_LONG) 2472 rdev->wiphy.retry_long = retry_long; 2473 if (changed & WIPHY_PARAM_FRAG_THRESHOLD) 2474 rdev->wiphy.frag_threshold = frag_threshold; 2475 if (changed & WIPHY_PARAM_RTS_THRESHOLD) 2476 rdev->wiphy.rts_threshold = rts_threshold; 2477 if (changed & WIPHY_PARAM_COVERAGE_CLASS) 2478 rdev->wiphy.coverage_class = coverage_class; 2479 2480 result = rdev_set_wiphy_params(rdev, changed); 2481 if (result) { 2482 rdev->wiphy.retry_short = old_retry_short; 2483 rdev->wiphy.retry_long = old_retry_long; 2484 rdev->wiphy.frag_threshold = old_frag_threshold; 2485 rdev->wiphy.rts_threshold = old_rts_threshold; 2486 rdev->wiphy.coverage_class = old_coverage_class; 2487 return result; 2488 } 2489 } 2490 return 0; 2491 } 2492 2493 static inline u64 wdev_id(struct wireless_dev *wdev) 2494 { 2495 return (u64)wdev->identifier | 2496 ((u64)wiphy_to_rdev(wdev->wiphy)->wiphy_idx << 32); 2497 } 2498 2499 static int nl80211_send_chandef(struct sk_buff *msg, 2500 const struct cfg80211_chan_def *chandef) 2501 { 2502 if (WARN_ON(!cfg80211_chandef_valid(chandef))) 2503 return -EINVAL; 2504 2505 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, 2506 chandef->chan->center_freq)) 2507 return -ENOBUFS; 2508 switch (chandef->width) { 2509 case NL80211_CHAN_WIDTH_20_NOHT: 2510 case NL80211_CHAN_WIDTH_20: 2511 case NL80211_CHAN_WIDTH_40: 2512 if (nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, 2513 cfg80211_get_chandef_type(chandef))) 2514 return -ENOBUFS; 2515 break; 2516 default: 2517 break; 2518 } 2519 if (nla_put_u32(msg, NL80211_ATTR_CHANNEL_WIDTH, chandef->width)) 2520 return -ENOBUFS; 2521 if (nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ1, chandef->center_freq1)) 2522 return -ENOBUFS; 2523 if (chandef->center_freq2 && 2524 nla_put_u32(msg, NL80211_ATTR_CENTER_FREQ2, chandef->center_freq2)) 2525 return -ENOBUFS; 2526 return 0; 2527 } 2528 2529 static int nl80211_send_iface(struct sk_buff *msg, u32 portid, u32 seq, int flags, 2530 struct cfg80211_registered_device *rdev, 2531 struct wireless_dev *wdev, bool removal) 2532 { 2533 struct net_device *dev = wdev->netdev; 2534 u8 cmd = NL80211_CMD_NEW_INTERFACE; 2535 void *hdr; 2536 2537 if (removal) 2538 cmd = NL80211_CMD_DEL_INTERFACE; 2539 2540 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 2541 if (!hdr) 2542 return -1; 2543 2544 if (dev && 2545 (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 2546 nla_put_string(msg, NL80211_ATTR_IFNAME, dev->name))) 2547 goto nla_put_failure; 2548 2549 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 2550 nla_put_u32(msg, NL80211_ATTR_IFTYPE, wdev->iftype) || 2551 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 2552 NL80211_ATTR_PAD) || 2553 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, wdev_address(wdev)) || 2554 nla_put_u32(msg, NL80211_ATTR_GENERATION, 2555 rdev->devlist_generation ^ 2556 (cfg80211_rdev_list_generation << 2))) 2557 goto nla_put_failure; 2558 2559 if (rdev->ops->get_channel) { 2560 int ret; 2561 struct cfg80211_chan_def chandef; 2562 2563 ret = rdev_get_channel(rdev, wdev, &chandef); 2564 if (ret == 0) { 2565 if (nl80211_send_chandef(msg, &chandef)) 2566 goto nla_put_failure; 2567 } 2568 } 2569 2570 if (rdev->ops->get_tx_power) { 2571 int dbm, ret; 2572 2573 ret = rdev_get_tx_power(rdev, wdev, &dbm); 2574 if (ret == 0 && 2575 nla_put_u32(msg, NL80211_ATTR_WIPHY_TX_POWER_LEVEL, 2576 DBM_TO_MBM(dbm))) 2577 goto nla_put_failure; 2578 } 2579 2580 if (wdev->ssid_len) { 2581 if (nla_put(msg, NL80211_ATTR_SSID, wdev->ssid_len, wdev->ssid)) 2582 goto nla_put_failure; 2583 } 2584 2585 genlmsg_end(msg, hdr); 2586 return 0; 2587 2588 nla_put_failure: 2589 genlmsg_cancel(msg, hdr); 2590 return -EMSGSIZE; 2591 } 2592 2593 static int nl80211_dump_interface(struct sk_buff *skb, struct netlink_callback *cb) 2594 { 2595 int wp_idx = 0; 2596 int if_idx = 0; 2597 int wp_start = cb->args[0]; 2598 int if_start = cb->args[1]; 2599 int filter_wiphy = -1; 2600 struct cfg80211_registered_device *rdev; 2601 struct wireless_dev *wdev; 2602 2603 rtnl_lock(); 2604 if (!cb->args[2]) { 2605 struct nl80211_dump_wiphy_state state = { 2606 .filter_wiphy = -1, 2607 }; 2608 int ret; 2609 2610 ret = nl80211_dump_wiphy_parse(skb, cb, &state); 2611 if (ret) 2612 return ret; 2613 2614 filter_wiphy = state.filter_wiphy; 2615 2616 /* 2617 * if filtering, set cb->args[2] to +1 since 0 is the default 2618 * value needed to determine that parsing is necessary. 2619 */ 2620 if (filter_wiphy >= 0) 2621 cb->args[2] = filter_wiphy + 1; 2622 else 2623 cb->args[2] = -1; 2624 } else if (cb->args[2] > 0) { 2625 filter_wiphy = cb->args[2] - 1; 2626 } 2627 2628 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 2629 if (!net_eq(wiphy_net(&rdev->wiphy), sock_net(skb->sk))) 2630 continue; 2631 if (wp_idx < wp_start) { 2632 wp_idx++; 2633 continue; 2634 } 2635 2636 if (filter_wiphy >= 0 && filter_wiphy != rdev->wiphy_idx) 2637 continue; 2638 2639 if_idx = 0; 2640 2641 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 2642 if (if_idx < if_start) { 2643 if_idx++; 2644 continue; 2645 } 2646 if (nl80211_send_iface(skb, NETLINK_CB(cb->skb).portid, 2647 cb->nlh->nlmsg_seq, NLM_F_MULTI, 2648 rdev, wdev, false) < 0) { 2649 goto out; 2650 } 2651 if_idx++; 2652 } 2653 2654 wp_idx++; 2655 } 2656 out: 2657 rtnl_unlock(); 2658 2659 cb->args[0] = wp_idx; 2660 cb->args[1] = if_idx; 2661 2662 return skb->len; 2663 } 2664 2665 static int nl80211_get_interface(struct sk_buff *skb, struct genl_info *info) 2666 { 2667 struct sk_buff *msg; 2668 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2669 struct wireless_dev *wdev = info->user_ptr[1]; 2670 2671 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 2672 if (!msg) 2673 return -ENOMEM; 2674 2675 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0, 2676 rdev, wdev, false) < 0) { 2677 nlmsg_free(msg); 2678 return -ENOBUFS; 2679 } 2680 2681 return genlmsg_reply(msg, info); 2682 } 2683 2684 static const struct nla_policy mntr_flags_policy[NL80211_MNTR_FLAG_MAX + 1] = { 2685 [NL80211_MNTR_FLAG_FCSFAIL] = { .type = NLA_FLAG }, 2686 [NL80211_MNTR_FLAG_PLCPFAIL] = { .type = NLA_FLAG }, 2687 [NL80211_MNTR_FLAG_CONTROL] = { .type = NLA_FLAG }, 2688 [NL80211_MNTR_FLAG_OTHER_BSS] = { .type = NLA_FLAG }, 2689 [NL80211_MNTR_FLAG_COOK_FRAMES] = { .type = NLA_FLAG }, 2690 [NL80211_MNTR_FLAG_ACTIVE] = { .type = NLA_FLAG }, 2691 }; 2692 2693 static int parse_monitor_flags(struct nlattr *nla, u32 *mntrflags) 2694 { 2695 struct nlattr *flags[NL80211_MNTR_FLAG_MAX + 1]; 2696 int flag; 2697 2698 *mntrflags = 0; 2699 2700 if (!nla) 2701 return -EINVAL; 2702 2703 if (nla_parse_nested(flags, NL80211_MNTR_FLAG_MAX, 2704 nla, mntr_flags_policy)) 2705 return -EINVAL; 2706 2707 for (flag = 1; flag <= NL80211_MNTR_FLAG_MAX; flag++) 2708 if (flags[flag]) 2709 *mntrflags |= (1<<flag); 2710 2711 return 0; 2712 } 2713 2714 static int nl80211_valid_4addr(struct cfg80211_registered_device *rdev, 2715 struct net_device *netdev, u8 use_4addr, 2716 enum nl80211_iftype iftype) 2717 { 2718 if (!use_4addr) { 2719 if (netdev && (netdev->priv_flags & IFF_BRIDGE_PORT)) 2720 return -EBUSY; 2721 return 0; 2722 } 2723 2724 switch (iftype) { 2725 case NL80211_IFTYPE_AP_VLAN: 2726 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_AP) 2727 return 0; 2728 break; 2729 case NL80211_IFTYPE_STATION: 2730 if (rdev->wiphy.flags & WIPHY_FLAG_4ADDR_STATION) 2731 return 0; 2732 break; 2733 default: 2734 break; 2735 } 2736 2737 return -EOPNOTSUPP; 2738 } 2739 2740 static int nl80211_set_interface(struct sk_buff *skb, struct genl_info *info) 2741 { 2742 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2743 struct vif_params params; 2744 int err; 2745 enum nl80211_iftype otype, ntype; 2746 struct net_device *dev = info->user_ptr[1]; 2747 u32 _flags, *flags = NULL; 2748 bool change = false; 2749 2750 memset(¶ms, 0, sizeof(params)); 2751 2752 otype = ntype = dev->ieee80211_ptr->iftype; 2753 2754 if (info->attrs[NL80211_ATTR_IFTYPE]) { 2755 ntype = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]); 2756 if (otype != ntype) 2757 change = true; 2758 if (ntype > NL80211_IFTYPE_MAX) 2759 return -EINVAL; 2760 } 2761 2762 if (info->attrs[NL80211_ATTR_MESH_ID]) { 2763 struct wireless_dev *wdev = dev->ieee80211_ptr; 2764 2765 if (ntype != NL80211_IFTYPE_MESH_POINT) 2766 return -EINVAL; 2767 if (netif_running(dev)) 2768 return -EBUSY; 2769 2770 wdev_lock(wdev); 2771 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN != 2772 IEEE80211_MAX_MESH_ID_LEN); 2773 wdev->mesh_id_up_len = 2774 nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 2775 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]), 2776 wdev->mesh_id_up_len); 2777 wdev_unlock(wdev); 2778 } 2779 2780 if (info->attrs[NL80211_ATTR_4ADDR]) { 2781 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]); 2782 change = true; 2783 err = nl80211_valid_4addr(rdev, dev, params.use_4addr, ntype); 2784 if (err) 2785 return err; 2786 } else { 2787 params.use_4addr = -1; 2788 } 2789 2790 if (info->attrs[NL80211_ATTR_MNTR_FLAGS]) { 2791 if (ntype != NL80211_IFTYPE_MONITOR) 2792 return -EINVAL; 2793 err = parse_monitor_flags(info->attrs[NL80211_ATTR_MNTR_FLAGS], 2794 &_flags); 2795 if (err) 2796 return err; 2797 2798 flags = &_flags; 2799 change = true; 2800 } 2801 2802 if (info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]) { 2803 const u8 *mumimo_groups; 2804 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER; 2805 2806 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag)) 2807 return -EOPNOTSUPP; 2808 2809 mumimo_groups = 2810 nla_data(info->attrs[NL80211_ATTR_MU_MIMO_GROUP_DATA]); 2811 2812 /* bits 0 and 63 are reserved and must be zero */ 2813 if ((mumimo_groups[0] & BIT(7)) || 2814 (mumimo_groups[VHT_MUMIMO_GROUPS_DATA_LEN - 1] & BIT(0))) 2815 return -EINVAL; 2816 2817 memcpy(params.vht_mumimo_groups, mumimo_groups, 2818 VHT_MUMIMO_GROUPS_DATA_LEN); 2819 change = true; 2820 } 2821 2822 if (info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR]) { 2823 u32 cap_flag = NL80211_EXT_FEATURE_MU_MIMO_AIR_SNIFFER; 2824 2825 if (!wiphy_ext_feature_isset(&rdev->wiphy, cap_flag)) 2826 return -EOPNOTSUPP; 2827 2828 nla_memcpy(params.macaddr, 2829 info->attrs[NL80211_ATTR_MU_MIMO_FOLLOW_MAC_ADDR], 2830 ETH_ALEN); 2831 change = true; 2832 } 2833 2834 if (flags && (*flags & MONITOR_FLAG_ACTIVE) && 2835 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR)) 2836 return -EOPNOTSUPP; 2837 2838 if (change) 2839 err = cfg80211_change_iface(rdev, dev, ntype, flags, ¶ms); 2840 else 2841 err = 0; 2842 2843 if (!err && params.use_4addr != -1) 2844 dev->ieee80211_ptr->use_4addr = params.use_4addr; 2845 2846 return err; 2847 } 2848 2849 static int nl80211_new_interface(struct sk_buff *skb, struct genl_info *info) 2850 { 2851 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2852 struct vif_params params; 2853 struct wireless_dev *wdev; 2854 struct sk_buff *msg; 2855 int err; 2856 enum nl80211_iftype type = NL80211_IFTYPE_UNSPECIFIED; 2857 u32 flags; 2858 2859 /* to avoid failing a new interface creation due to pending removal */ 2860 cfg80211_destroy_ifaces(rdev); 2861 2862 memset(¶ms, 0, sizeof(params)); 2863 2864 if (!info->attrs[NL80211_ATTR_IFNAME]) 2865 return -EINVAL; 2866 2867 if (info->attrs[NL80211_ATTR_IFTYPE]) { 2868 type = nla_get_u32(info->attrs[NL80211_ATTR_IFTYPE]); 2869 if (type > NL80211_IFTYPE_MAX) 2870 return -EINVAL; 2871 } 2872 2873 if (!rdev->ops->add_virtual_intf || 2874 !(rdev->wiphy.interface_modes & (1 << type))) 2875 return -EOPNOTSUPP; 2876 2877 if ((type == NL80211_IFTYPE_P2P_DEVICE || type == NL80211_IFTYPE_NAN || 2878 rdev->wiphy.features & NL80211_FEATURE_MAC_ON_CREATE) && 2879 info->attrs[NL80211_ATTR_MAC]) { 2880 nla_memcpy(params.macaddr, info->attrs[NL80211_ATTR_MAC], 2881 ETH_ALEN); 2882 if (!is_valid_ether_addr(params.macaddr)) 2883 return -EADDRNOTAVAIL; 2884 } 2885 2886 if (info->attrs[NL80211_ATTR_4ADDR]) { 2887 params.use_4addr = !!nla_get_u8(info->attrs[NL80211_ATTR_4ADDR]); 2888 err = nl80211_valid_4addr(rdev, NULL, params.use_4addr, type); 2889 if (err) 2890 return err; 2891 } 2892 2893 err = parse_monitor_flags(type == NL80211_IFTYPE_MONITOR ? 2894 info->attrs[NL80211_ATTR_MNTR_FLAGS] : NULL, 2895 &flags); 2896 2897 if (!err && (flags & MONITOR_FLAG_ACTIVE) && 2898 !(rdev->wiphy.features & NL80211_FEATURE_ACTIVE_MONITOR)) 2899 return -EOPNOTSUPP; 2900 2901 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 2902 if (!msg) 2903 return -ENOMEM; 2904 2905 wdev = rdev_add_virtual_intf(rdev, 2906 nla_data(info->attrs[NL80211_ATTR_IFNAME]), 2907 NET_NAME_USER, type, err ? NULL : &flags, 2908 ¶ms); 2909 if (WARN_ON(!wdev)) { 2910 nlmsg_free(msg); 2911 return -EPROTO; 2912 } else if (IS_ERR(wdev)) { 2913 nlmsg_free(msg); 2914 return PTR_ERR(wdev); 2915 } 2916 2917 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) 2918 wdev->owner_nlportid = info->snd_portid; 2919 2920 switch (type) { 2921 case NL80211_IFTYPE_MESH_POINT: 2922 if (!info->attrs[NL80211_ATTR_MESH_ID]) 2923 break; 2924 wdev_lock(wdev); 2925 BUILD_BUG_ON(IEEE80211_MAX_SSID_LEN != 2926 IEEE80211_MAX_MESH_ID_LEN); 2927 wdev->mesh_id_up_len = 2928 nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 2929 memcpy(wdev->ssid, nla_data(info->attrs[NL80211_ATTR_MESH_ID]), 2930 wdev->mesh_id_up_len); 2931 wdev_unlock(wdev); 2932 break; 2933 case NL80211_IFTYPE_NAN: 2934 case NL80211_IFTYPE_P2P_DEVICE: 2935 /* 2936 * P2P Device and NAN do not have a netdev, so don't go 2937 * through the netdev notifier and must be added here 2938 */ 2939 mutex_init(&wdev->mtx); 2940 INIT_LIST_HEAD(&wdev->event_list); 2941 spin_lock_init(&wdev->event_lock); 2942 INIT_LIST_HEAD(&wdev->mgmt_registrations); 2943 spin_lock_init(&wdev->mgmt_registrations_lock); 2944 2945 wdev->identifier = ++rdev->wdev_id; 2946 list_add_rcu(&wdev->list, &rdev->wiphy.wdev_list); 2947 rdev->devlist_generation++; 2948 break; 2949 default: 2950 break; 2951 } 2952 2953 if (nl80211_send_iface(msg, info->snd_portid, info->snd_seq, 0, 2954 rdev, wdev, false) < 0) { 2955 nlmsg_free(msg); 2956 return -ENOBUFS; 2957 } 2958 2959 /* 2960 * For wdevs which have no associated netdev object (e.g. of type 2961 * NL80211_IFTYPE_P2P_DEVICE), emit the NEW_INTERFACE event here. 2962 * For all other types, the event will be generated from the 2963 * netdev notifier 2964 */ 2965 if (!wdev->netdev) 2966 nl80211_notify_iface(rdev, wdev, NL80211_CMD_NEW_INTERFACE); 2967 2968 return genlmsg_reply(msg, info); 2969 } 2970 2971 static int nl80211_del_interface(struct sk_buff *skb, struct genl_info *info) 2972 { 2973 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2974 struct wireless_dev *wdev = info->user_ptr[1]; 2975 2976 if (!rdev->ops->del_virtual_intf) 2977 return -EOPNOTSUPP; 2978 2979 /* 2980 * If we remove a wireless device without a netdev then clear 2981 * user_ptr[1] so that nl80211_post_doit won't dereference it 2982 * to check if it needs to do dev_put(). Otherwise it crashes 2983 * since the wdev has been freed, unlike with a netdev where 2984 * we need the dev_put() for the netdev to really be freed. 2985 */ 2986 if (!wdev->netdev) 2987 info->user_ptr[1] = NULL; 2988 2989 return rdev_del_virtual_intf(rdev, wdev); 2990 } 2991 2992 static int nl80211_set_noack_map(struct sk_buff *skb, struct genl_info *info) 2993 { 2994 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 2995 struct net_device *dev = info->user_ptr[1]; 2996 u16 noack_map; 2997 2998 if (!info->attrs[NL80211_ATTR_NOACK_MAP]) 2999 return -EINVAL; 3000 3001 if (!rdev->ops->set_noack_map) 3002 return -EOPNOTSUPP; 3003 3004 noack_map = nla_get_u16(info->attrs[NL80211_ATTR_NOACK_MAP]); 3005 3006 return rdev_set_noack_map(rdev, dev, noack_map); 3007 } 3008 3009 struct get_key_cookie { 3010 struct sk_buff *msg; 3011 int error; 3012 int idx; 3013 }; 3014 3015 static void get_key_callback(void *c, struct key_params *params) 3016 { 3017 struct nlattr *key; 3018 struct get_key_cookie *cookie = c; 3019 3020 if ((params->key && 3021 nla_put(cookie->msg, NL80211_ATTR_KEY_DATA, 3022 params->key_len, params->key)) || 3023 (params->seq && 3024 nla_put(cookie->msg, NL80211_ATTR_KEY_SEQ, 3025 params->seq_len, params->seq)) || 3026 (params->cipher && 3027 nla_put_u32(cookie->msg, NL80211_ATTR_KEY_CIPHER, 3028 params->cipher))) 3029 goto nla_put_failure; 3030 3031 key = nla_nest_start(cookie->msg, NL80211_ATTR_KEY); 3032 if (!key) 3033 goto nla_put_failure; 3034 3035 if ((params->key && 3036 nla_put(cookie->msg, NL80211_KEY_DATA, 3037 params->key_len, params->key)) || 3038 (params->seq && 3039 nla_put(cookie->msg, NL80211_KEY_SEQ, 3040 params->seq_len, params->seq)) || 3041 (params->cipher && 3042 nla_put_u32(cookie->msg, NL80211_KEY_CIPHER, 3043 params->cipher))) 3044 goto nla_put_failure; 3045 3046 if (nla_put_u8(cookie->msg, NL80211_ATTR_KEY_IDX, cookie->idx)) 3047 goto nla_put_failure; 3048 3049 nla_nest_end(cookie->msg, key); 3050 3051 return; 3052 nla_put_failure: 3053 cookie->error = 1; 3054 } 3055 3056 static int nl80211_get_key(struct sk_buff *skb, struct genl_info *info) 3057 { 3058 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3059 int err; 3060 struct net_device *dev = info->user_ptr[1]; 3061 u8 key_idx = 0; 3062 const u8 *mac_addr = NULL; 3063 bool pairwise; 3064 struct get_key_cookie cookie = { 3065 .error = 0, 3066 }; 3067 void *hdr; 3068 struct sk_buff *msg; 3069 3070 if (info->attrs[NL80211_ATTR_KEY_IDX]) 3071 key_idx = nla_get_u8(info->attrs[NL80211_ATTR_KEY_IDX]); 3072 3073 if (key_idx > 5) 3074 return -EINVAL; 3075 3076 if (info->attrs[NL80211_ATTR_MAC]) 3077 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3078 3079 pairwise = !!mac_addr; 3080 if (info->attrs[NL80211_ATTR_KEY_TYPE]) { 3081 u32 kt = nla_get_u32(info->attrs[NL80211_ATTR_KEY_TYPE]); 3082 3083 if (kt >= NUM_NL80211_KEYTYPES) 3084 return -EINVAL; 3085 if (kt != NL80211_KEYTYPE_GROUP && 3086 kt != NL80211_KEYTYPE_PAIRWISE) 3087 return -EINVAL; 3088 pairwise = kt == NL80211_KEYTYPE_PAIRWISE; 3089 } 3090 3091 if (!rdev->ops->get_key) 3092 return -EOPNOTSUPP; 3093 3094 if (!pairwise && mac_addr && !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)) 3095 return -ENOENT; 3096 3097 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 3098 if (!msg) 3099 return -ENOMEM; 3100 3101 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 3102 NL80211_CMD_NEW_KEY); 3103 if (!hdr) 3104 goto nla_put_failure; 3105 3106 cookie.msg = msg; 3107 cookie.idx = key_idx; 3108 3109 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 3110 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_idx)) 3111 goto nla_put_failure; 3112 if (mac_addr && 3113 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr)) 3114 goto nla_put_failure; 3115 3116 err = rdev_get_key(rdev, dev, key_idx, pairwise, mac_addr, &cookie, 3117 get_key_callback); 3118 3119 if (err) 3120 goto free_msg; 3121 3122 if (cookie.error) 3123 goto nla_put_failure; 3124 3125 genlmsg_end(msg, hdr); 3126 return genlmsg_reply(msg, info); 3127 3128 nla_put_failure: 3129 err = -ENOBUFS; 3130 free_msg: 3131 nlmsg_free(msg); 3132 return err; 3133 } 3134 3135 static int nl80211_set_key(struct sk_buff *skb, struct genl_info *info) 3136 { 3137 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3138 struct key_parse key; 3139 int err; 3140 struct net_device *dev = info->user_ptr[1]; 3141 3142 err = nl80211_parse_key(info, &key); 3143 if (err) 3144 return err; 3145 3146 if (key.idx < 0) 3147 return -EINVAL; 3148 3149 /* only support setting default key */ 3150 if (!key.def && !key.defmgmt) 3151 return -EINVAL; 3152 3153 wdev_lock(dev->ieee80211_ptr); 3154 3155 if (key.def) { 3156 if (!rdev->ops->set_default_key) { 3157 err = -EOPNOTSUPP; 3158 goto out; 3159 } 3160 3161 err = nl80211_key_allowed(dev->ieee80211_ptr); 3162 if (err) 3163 goto out; 3164 3165 err = rdev_set_default_key(rdev, dev, key.idx, 3166 key.def_uni, key.def_multi); 3167 3168 if (err) 3169 goto out; 3170 3171 #ifdef CONFIG_CFG80211_WEXT 3172 dev->ieee80211_ptr->wext.default_key = key.idx; 3173 #endif 3174 } else { 3175 if (key.def_uni || !key.def_multi) { 3176 err = -EINVAL; 3177 goto out; 3178 } 3179 3180 if (!rdev->ops->set_default_mgmt_key) { 3181 err = -EOPNOTSUPP; 3182 goto out; 3183 } 3184 3185 err = nl80211_key_allowed(dev->ieee80211_ptr); 3186 if (err) 3187 goto out; 3188 3189 err = rdev_set_default_mgmt_key(rdev, dev, key.idx); 3190 if (err) 3191 goto out; 3192 3193 #ifdef CONFIG_CFG80211_WEXT 3194 dev->ieee80211_ptr->wext.default_mgmt_key = key.idx; 3195 #endif 3196 } 3197 3198 out: 3199 wdev_unlock(dev->ieee80211_ptr); 3200 3201 return err; 3202 } 3203 3204 static int nl80211_new_key(struct sk_buff *skb, struct genl_info *info) 3205 { 3206 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3207 int err; 3208 struct net_device *dev = info->user_ptr[1]; 3209 struct key_parse key; 3210 const u8 *mac_addr = NULL; 3211 3212 err = nl80211_parse_key(info, &key); 3213 if (err) 3214 return err; 3215 3216 if (!key.p.key) 3217 return -EINVAL; 3218 3219 if (info->attrs[NL80211_ATTR_MAC]) 3220 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3221 3222 if (key.type == -1) { 3223 if (mac_addr) 3224 key.type = NL80211_KEYTYPE_PAIRWISE; 3225 else 3226 key.type = NL80211_KEYTYPE_GROUP; 3227 } 3228 3229 /* for now */ 3230 if (key.type != NL80211_KEYTYPE_PAIRWISE && 3231 key.type != NL80211_KEYTYPE_GROUP) 3232 return -EINVAL; 3233 3234 if (!rdev->ops->add_key) 3235 return -EOPNOTSUPP; 3236 3237 if (cfg80211_validate_key_settings(rdev, &key.p, key.idx, 3238 key.type == NL80211_KEYTYPE_PAIRWISE, 3239 mac_addr)) 3240 return -EINVAL; 3241 3242 wdev_lock(dev->ieee80211_ptr); 3243 err = nl80211_key_allowed(dev->ieee80211_ptr); 3244 if (!err) 3245 err = rdev_add_key(rdev, dev, key.idx, 3246 key.type == NL80211_KEYTYPE_PAIRWISE, 3247 mac_addr, &key.p); 3248 wdev_unlock(dev->ieee80211_ptr); 3249 3250 return err; 3251 } 3252 3253 static int nl80211_del_key(struct sk_buff *skb, struct genl_info *info) 3254 { 3255 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3256 int err; 3257 struct net_device *dev = info->user_ptr[1]; 3258 u8 *mac_addr = NULL; 3259 struct key_parse key; 3260 3261 err = nl80211_parse_key(info, &key); 3262 if (err) 3263 return err; 3264 3265 if (info->attrs[NL80211_ATTR_MAC]) 3266 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 3267 3268 if (key.type == -1) { 3269 if (mac_addr) 3270 key.type = NL80211_KEYTYPE_PAIRWISE; 3271 else 3272 key.type = NL80211_KEYTYPE_GROUP; 3273 } 3274 3275 /* for now */ 3276 if (key.type != NL80211_KEYTYPE_PAIRWISE && 3277 key.type != NL80211_KEYTYPE_GROUP) 3278 return -EINVAL; 3279 3280 if (!rdev->ops->del_key) 3281 return -EOPNOTSUPP; 3282 3283 wdev_lock(dev->ieee80211_ptr); 3284 err = nl80211_key_allowed(dev->ieee80211_ptr); 3285 3286 if (key.type == NL80211_KEYTYPE_GROUP && mac_addr && 3287 !(rdev->wiphy.flags & WIPHY_FLAG_IBSS_RSN)) 3288 err = -ENOENT; 3289 3290 if (!err) 3291 err = rdev_del_key(rdev, dev, key.idx, 3292 key.type == NL80211_KEYTYPE_PAIRWISE, 3293 mac_addr); 3294 3295 #ifdef CONFIG_CFG80211_WEXT 3296 if (!err) { 3297 if (key.idx == dev->ieee80211_ptr->wext.default_key) 3298 dev->ieee80211_ptr->wext.default_key = -1; 3299 else if (key.idx == dev->ieee80211_ptr->wext.default_mgmt_key) 3300 dev->ieee80211_ptr->wext.default_mgmt_key = -1; 3301 } 3302 #endif 3303 wdev_unlock(dev->ieee80211_ptr); 3304 3305 return err; 3306 } 3307 3308 /* This function returns an error or the number of nested attributes */ 3309 static int validate_acl_mac_addrs(struct nlattr *nl_attr) 3310 { 3311 struct nlattr *attr; 3312 int n_entries = 0, tmp; 3313 3314 nla_for_each_nested(attr, nl_attr, tmp) { 3315 if (nla_len(attr) != ETH_ALEN) 3316 return -EINVAL; 3317 3318 n_entries++; 3319 } 3320 3321 return n_entries; 3322 } 3323 3324 /* 3325 * This function parses ACL information and allocates memory for ACL data. 3326 * On successful return, the calling function is responsible to free the 3327 * ACL buffer returned by this function. 3328 */ 3329 static struct cfg80211_acl_data *parse_acl_data(struct wiphy *wiphy, 3330 struct genl_info *info) 3331 { 3332 enum nl80211_acl_policy acl_policy; 3333 struct nlattr *attr; 3334 struct cfg80211_acl_data *acl; 3335 int i = 0, n_entries, tmp; 3336 3337 if (!wiphy->max_acl_mac_addrs) 3338 return ERR_PTR(-EOPNOTSUPP); 3339 3340 if (!info->attrs[NL80211_ATTR_ACL_POLICY]) 3341 return ERR_PTR(-EINVAL); 3342 3343 acl_policy = nla_get_u32(info->attrs[NL80211_ATTR_ACL_POLICY]); 3344 if (acl_policy != NL80211_ACL_POLICY_ACCEPT_UNLESS_LISTED && 3345 acl_policy != NL80211_ACL_POLICY_DENY_UNLESS_LISTED) 3346 return ERR_PTR(-EINVAL); 3347 3348 if (!info->attrs[NL80211_ATTR_MAC_ADDRS]) 3349 return ERR_PTR(-EINVAL); 3350 3351 n_entries = validate_acl_mac_addrs(info->attrs[NL80211_ATTR_MAC_ADDRS]); 3352 if (n_entries < 0) 3353 return ERR_PTR(n_entries); 3354 3355 if (n_entries > wiphy->max_acl_mac_addrs) 3356 return ERR_PTR(-ENOTSUPP); 3357 3358 acl = kzalloc(sizeof(*acl) + (sizeof(struct mac_address) * n_entries), 3359 GFP_KERNEL); 3360 if (!acl) 3361 return ERR_PTR(-ENOMEM); 3362 3363 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_MAC_ADDRS], tmp) { 3364 memcpy(acl->mac_addrs[i].addr, nla_data(attr), ETH_ALEN); 3365 i++; 3366 } 3367 3368 acl->n_acl_entries = n_entries; 3369 acl->acl_policy = acl_policy; 3370 3371 return acl; 3372 } 3373 3374 static int nl80211_set_mac_acl(struct sk_buff *skb, struct genl_info *info) 3375 { 3376 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3377 struct net_device *dev = info->user_ptr[1]; 3378 struct cfg80211_acl_data *acl; 3379 int err; 3380 3381 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3382 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3383 return -EOPNOTSUPP; 3384 3385 if (!dev->ieee80211_ptr->beacon_interval) 3386 return -EINVAL; 3387 3388 acl = parse_acl_data(&rdev->wiphy, info); 3389 if (IS_ERR(acl)) 3390 return PTR_ERR(acl); 3391 3392 err = rdev_set_mac_acl(rdev, dev, acl); 3393 3394 kfree(acl); 3395 3396 return err; 3397 } 3398 3399 static u32 rateset_to_mask(struct ieee80211_supported_band *sband, 3400 u8 *rates, u8 rates_len) 3401 { 3402 u8 i; 3403 u32 mask = 0; 3404 3405 for (i = 0; i < rates_len; i++) { 3406 int rate = (rates[i] & 0x7f) * 5; 3407 int ridx; 3408 3409 for (ridx = 0; ridx < sband->n_bitrates; ridx++) { 3410 struct ieee80211_rate *srate = 3411 &sband->bitrates[ridx]; 3412 if (rate == srate->bitrate) { 3413 mask |= 1 << ridx; 3414 break; 3415 } 3416 } 3417 if (ridx == sband->n_bitrates) 3418 return 0; /* rate not found */ 3419 } 3420 3421 return mask; 3422 } 3423 3424 static bool ht_rateset_to_mask(struct ieee80211_supported_band *sband, 3425 u8 *rates, u8 rates_len, 3426 u8 mcs[IEEE80211_HT_MCS_MASK_LEN]) 3427 { 3428 u8 i; 3429 3430 memset(mcs, 0, IEEE80211_HT_MCS_MASK_LEN); 3431 3432 for (i = 0; i < rates_len; i++) { 3433 int ridx, rbit; 3434 3435 ridx = rates[i] / 8; 3436 rbit = BIT(rates[i] % 8); 3437 3438 /* check validity */ 3439 if ((ridx < 0) || (ridx >= IEEE80211_HT_MCS_MASK_LEN)) 3440 return false; 3441 3442 /* check availability */ 3443 if (sband->ht_cap.mcs.rx_mask[ridx] & rbit) 3444 mcs[ridx] |= rbit; 3445 else 3446 return false; 3447 } 3448 3449 return true; 3450 } 3451 3452 static u16 vht_mcs_map_to_mcs_mask(u8 vht_mcs_map) 3453 { 3454 u16 mcs_mask = 0; 3455 3456 switch (vht_mcs_map) { 3457 case IEEE80211_VHT_MCS_NOT_SUPPORTED: 3458 break; 3459 case IEEE80211_VHT_MCS_SUPPORT_0_7: 3460 mcs_mask = 0x00FF; 3461 break; 3462 case IEEE80211_VHT_MCS_SUPPORT_0_8: 3463 mcs_mask = 0x01FF; 3464 break; 3465 case IEEE80211_VHT_MCS_SUPPORT_0_9: 3466 mcs_mask = 0x03FF; 3467 break; 3468 default: 3469 break; 3470 } 3471 3472 return mcs_mask; 3473 } 3474 3475 static void vht_build_mcs_mask(u16 vht_mcs_map, 3476 u16 vht_mcs_mask[NL80211_VHT_NSS_MAX]) 3477 { 3478 u8 nss; 3479 3480 for (nss = 0; nss < NL80211_VHT_NSS_MAX; nss++) { 3481 vht_mcs_mask[nss] = vht_mcs_map_to_mcs_mask(vht_mcs_map & 0x03); 3482 vht_mcs_map >>= 2; 3483 } 3484 } 3485 3486 static bool vht_set_mcs_mask(struct ieee80211_supported_band *sband, 3487 struct nl80211_txrate_vht *txrate, 3488 u16 mcs[NL80211_VHT_NSS_MAX]) 3489 { 3490 u16 tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map); 3491 u16 tx_mcs_mask[NL80211_VHT_NSS_MAX] = {}; 3492 u8 i; 3493 3494 if (!sband->vht_cap.vht_supported) 3495 return false; 3496 3497 memset(mcs, 0, sizeof(u16) * NL80211_VHT_NSS_MAX); 3498 3499 /* Build vht_mcs_mask from VHT capabilities */ 3500 vht_build_mcs_mask(tx_mcs_map, tx_mcs_mask); 3501 3502 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) { 3503 if ((tx_mcs_mask[i] & txrate->mcs[i]) == txrate->mcs[i]) 3504 mcs[i] = txrate->mcs[i]; 3505 else 3506 return false; 3507 } 3508 3509 return true; 3510 } 3511 3512 static const struct nla_policy nl80211_txattr_policy[NL80211_TXRATE_MAX + 1] = { 3513 [NL80211_TXRATE_LEGACY] = { .type = NLA_BINARY, 3514 .len = NL80211_MAX_SUPP_RATES }, 3515 [NL80211_TXRATE_HT] = { .type = NLA_BINARY, 3516 .len = NL80211_MAX_SUPP_HT_RATES }, 3517 [NL80211_TXRATE_VHT] = { .len = sizeof(struct nl80211_txrate_vht)}, 3518 [NL80211_TXRATE_GI] = { .type = NLA_U8 }, 3519 }; 3520 3521 static int nl80211_parse_tx_bitrate_mask(struct genl_info *info, 3522 struct cfg80211_bitrate_mask *mask) 3523 { 3524 struct nlattr *tb[NL80211_TXRATE_MAX + 1]; 3525 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3526 int rem, i; 3527 struct nlattr *tx_rates; 3528 struct ieee80211_supported_band *sband; 3529 u16 vht_tx_mcs_map; 3530 3531 memset(mask, 0, sizeof(*mask)); 3532 /* Default to all rates enabled */ 3533 for (i = 0; i < NUM_NL80211_BANDS; i++) { 3534 sband = rdev->wiphy.bands[i]; 3535 3536 if (!sband) 3537 continue; 3538 3539 mask->control[i].legacy = (1 << sband->n_bitrates) - 1; 3540 memcpy(mask->control[i].ht_mcs, 3541 sband->ht_cap.mcs.rx_mask, 3542 sizeof(mask->control[i].ht_mcs)); 3543 3544 if (!sband->vht_cap.vht_supported) 3545 continue; 3546 3547 vht_tx_mcs_map = le16_to_cpu(sband->vht_cap.vht_mcs.tx_mcs_map); 3548 vht_build_mcs_mask(vht_tx_mcs_map, mask->control[i].vht_mcs); 3549 } 3550 3551 /* if no rates are given set it back to the defaults */ 3552 if (!info->attrs[NL80211_ATTR_TX_RATES]) 3553 goto out; 3554 3555 /* The nested attribute uses enum nl80211_band as the index. This maps 3556 * directly to the enum nl80211_band values used in cfg80211. 3557 */ 3558 BUILD_BUG_ON(NL80211_MAX_SUPP_HT_RATES > IEEE80211_HT_MCS_MASK_LEN * 8); 3559 nla_for_each_nested(tx_rates, info->attrs[NL80211_ATTR_TX_RATES], rem) { 3560 enum nl80211_band band = nla_type(tx_rates); 3561 int err; 3562 3563 if (band < 0 || band >= NUM_NL80211_BANDS) 3564 return -EINVAL; 3565 sband = rdev->wiphy.bands[band]; 3566 if (sband == NULL) 3567 return -EINVAL; 3568 err = nla_parse_nested(tb, NL80211_TXRATE_MAX, tx_rates, 3569 nl80211_txattr_policy); 3570 if (err) 3571 return err; 3572 if (tb[NL80211_TXRATE_LEGACY]) { 3573 mask->control[band].legacy = rateset_to_mask( 3574 sband, 3575 nla_data(tb[NL80211_TXRATE_LEGACY]), 3576 nla_len(tb[NL80211_TXRATE_LEGACY])); 3577 if ((mask->control[band].legacy == 0) && 3578 nla_len(tb[NL80211_TXRATE_LEGACY])) 3579 return -EINVAL; 3580 } 3581 if (tb[NL80211_TXRATE_HT]) { 3582 if (!ht_rateset_to_mask( 3583 sband, 3584 nla_data(tb[NL80211_TXRATE_HT]), 3585 nla_len(tb[NL80211_TXRATE_HT]), 3586 mask->control[band].ht_mcs)) 3587 return -EINVAL; 3588 } 3589 if (tb[NL80211_TXRATE_VHT]) { 3590 if (!vht_set_mcs_mask( 3591 sband, 3592 nla_data(tb[NL80211_TXRATE_VHT]), 3593 mask->control[band].vht_mcs)) 3594 return -EINVAL; 3595 } 3596 if (tb[NL80211_TXRATE_GI]) { 3597 mask->control[band].gi = 3598 nla_get_u8(tb[NL80211_TXRATE_GI]); 3599 if (mask->control[band].gi > NL80211_TXRATE_FORCE_LGI) 3600 return -EINVAL; 3601 } 3602 3603 if (mask->control[band].legacy == 0) { 3604 /* don't allow empty legacy rates if HT or VHT 3605 * are not even supported. 3606 */ 3607 if (!(rdev->wiphy.bands[band]->ht_cap.ht_supported || 3608 rdev->wiphy.bands[band]->vht_cap.vht_supported)) 3609 return -EINVAL; 3610 3611 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) 3612 if (mask->control[band].ht_mcs[i]) 3613 goto out; 3614 3615 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) 3616 if (mask->control[band].vht_mcs[i]) 3617 goto out; 3618 3619 /* legacy and mcs rates may not be both empty */ 3620 return -EINVAL; 3621 } 3622 } 3623 3624 out: 3625 return 0; 3626 } 3627 3628 static int validate_beacon_tx_rate(struct cfg80211_registered_device *rdev, 3629 enum nl80211_band band, 3630 struct cfg80211_bitrate_mask *beacon_rate) 3631 { 3632 u32 count_ht, count_vht, i; 3633 u32 rate = beacon_rate->control[band].legacy; 3634 3635 /* Allow only one rate */ 3636 if (hweight32(rate) > 1) 3637 return -EINVAL; 3638 3639 count_ht = 0; 3640 for (i = 0; i < IEEE80211_HT_MCS_MASK_LEN; i++) { 3641 if (hweight8(beacon_rate->control[band].ht_mcs[i]) > 1) { 3642 return -EINVAL; 3643 } else if (beacon_rate->control[band].ht_mcs[i]) { 3644 count_ht++; 3645 if (count_ht > 1) 3646 return -EINVAL; 3647 } 3648 if (count_ht && rate) 3649 return -EINVAL; 3650 } 3651 3652 count_vht = 0; 3653 for (i = 0; i < NL80211_VHT_NSS_MAX; i++) { 3654 if (hweight16(beacon_rate->control[band].vht_mcs[i]) > 1) { 3655 return -EINVAL; 3656 } else if (beacon_rate->control[band].vht_mcs[i]) { 3657 count_vht++; 3658 if (count_vht > 1) 3659 return -EINVAL; 3660 } 3661 if (count_vht && rate) 3662 return -EINVAL; 3663 } 3664 3665 if ((count_ht && count_vht) || (!rate && !count_ht && !count_vht)) 3666 return -EINVAL; 3667 3668 if (rate && 3669 !wiphy_ext_feature_isset(&rdev->wiphy, 3670 NL80211_EXT_FEATURE_BEACON_RATE_LEGACY)) 3671 return -EINVAL; 3672 if (count_ht && 3673 !wiphy_ext_feature_isset(&rdev->wiphy, 3674 NL80211_EXT_FEATURE_BEACON_RATE_HT)) 3675 return -EINVAL; 3676 if (count_vht && 3677 !wiphy_ext_feature_isset(&rdev->wiphy, 3678 NL80211_EXT_FEATURE_BEACON_RATE_VHT)) 3679 return -EINVAL; 3680 3681 return 0; 3682 } 3683 3684 static int nl80211_parse_beacon(struct nlattr *attrs[], 3685 struct cfg80211_beacon_data *bcn) 3686 { 3687 bool haveinfo = false; 3688 3689 if (!is_valid_ie_attr(attrs[NL80211_ATTR_BEACON_TAIL]) || 3690 !is_valid_ie_attr(attrs[NL80211_ATTR_IE]) || 3691 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_PROBE_RESP]) || 3692 !is_valid_ie_attr(attrs[NL80211_ATTR_IE_ASSOC_RESP])) 3693 return -EINVAL; 3694 3695 memset(bcn, 0, sizeof(*bcn)); 3696 3697 if (attrs[NL80211_ATTR_BEACON_HEAD]) { 3698 bcn->head = nla_data(attrs[NL80211_ATTR_BEACON_HEAD]); 3699 bcn->head_len = nla_len(attrs[NL80211_ATTR_BEACON_HEAD]); 3700 if (!bcn->head_len) 3701 return -EINVAL; 3702 haveinfo = true; 3703 } 3704 3705 if (attrs[NL80211_ATTR_BEACON_TAIL]) { 3706 bcn->tail = nla_data(attrs[NL80211_ATTR_BEACON_TAIL]); 3707 bcn->tail_len = nla_len(attrs[NL80211_ATTR_BEACON_TAIL]); 3708 haveinfo = true; 3709 } 3710 3711 if (!haveinfo) 3712 return -EINVAL; 3713 3714 if (attrs[NL80211_ATTR_IE]) { 3715 bcn->beacon_ies = nla_data(attrs[NL80211_ATTR_IE]); 3716 bcn->beacon_ies_len = nla_len(attrs[NL80211_ATTR_IE]); 3717 } 3718 3719 if (attrs[NL80211_ATTR_IE_PROBE_RESP]) { 3720 bcn->proberesp_ies = 3721 nla_data(attrs[NL80211_ATTR_IE_PROBE_RESP]); 3722 bcn->proberesp_ies_len = 3723 nla_len(attrs[NL80211_ATTR_IE_PROBE_RESP]); 3724 } 3725 3726 if (attrs[NL80211_ATTR_IE_ASSOC_RESP]) { 3727 bcn->assocresp_ies = 3728 nla_data(attrs[NL80211_ATTR_IE_ASSOC_RESP]); 3729 bcn->assocresp_ies_len = 3730 nla_len(attrs[NL80211_ATTR_IE_ASSOC_RESP]); 3731 } 3732 3733 if (attrs[NL80211_ATTR_PROBE_RESP]) { 3734 bcn->probe_resp = nla_data(attrs[NL80211_ATTR_PROBE_RESP]); 3735 bcn->probe_resp_len = nla_len(attrs[NL80211_ATTR_PROBE_RESP]); 3736 } 3737 3738 return 0; 3739 } 3740 3741 static bool nl80211_get_ap_channel(struct cfg80211_registered_device *rdev, 3742 struct cfg80211_ap_settings *params) 3743 { 3744 struct wireless_dev *wdev; 3745 bool ret = false; 3746 3747 list_for_each_entry(wdev, &rdev->wiphy.wdev_list, list) { 3748 if (wdev->iftype != NL80211_IFTYPE_AP && 3749 wdev->iftype != NL80211_IFTYPE_P2P_GO) 3750 continue; 3751 3752 if (!wdev->preset_chandef.chan) 3753 continue; 3754 3755 params->chandef = wdev->preset_chandef; 3756 ret = true; 3757 break; 3758 } 3759 3760 return ret; 3761 } 3762 3763 static bool nl80211_valid_auth_type(struct cfg80211_registered_device *rdev, 3764 enum nl80211_auth_type auth_type, 3765 enum nl80211_commands cmd) 3766 { 3767 if (auth_type > NL80211_AUTHTYPE_MAX) 3768 return false; 3769 3770 switch (cmd) { 3771 case NL80211_CMD_AUTHENTICATE: 3772 if (!(rdev->wiphy.features & NL80211_FEATURE_SAE) && 3773 auth_type == NL80211_AUTHTYPE_SAE) 3774 return false; 3775 if (!wiphy_ext_feature_isset(&rdev->wiphy, 3776 NL80211_EXT_FEATURE_FILS_STA) && 3777 (auth_type == NL80211_AUTHTYPE_FILS_SK || 3778 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 3779 auth_type == NL80211_AUTHTYPE_FILS_PK)) 3780 return false; 3781 return true; 3782 case NL80211_CMD_CONNECT: 3783 case NL80211_CMD_START_AP: 3784 /* SAE not supported yet */ 3785 if (auth_type == NL80211_AUTHTYPE_SAE) 3786 return false; 3787 /* FILS not supported yet */ 3788 if (auth_type == NL80211_AUTHTYPE_FILS_SK || 3789 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 3790 auth_type == NL80211_AUTHTYPE_FILS_PK) 3791 return false; 3792 return true; 3793 default: 3794 return false; 3795 } 3796 } 3797 3798 static int nl80211_start_ap(struct sk_buff *skb, struct genl_info *info) 3799 { 3800 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3801 struct net_device *dev = info->user_ptr[1]; 3802 struct wireless_dev *wdev = dev->ieee80211_ptr; 3803 struct cfg80211_ap_settings params; 3804 int err; 3805 3806 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3807 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3808 return -EOPNOTSUPP; 3809 3810 if (!rdev->ops->start_ap) 3811 return -EOPNOTSUPP; 3812 3813 if (wdev->beacon_interval) 3814 return -EALREADY; 3815 3816 memset(¶ms, 0, sizeof(params)); 3817 3818 /* these are required for START_AP */ 3819 if (!info->attrs[NL80211_ATTR_BEACON_INTERVAL] || 3820 !info->attrs[NL80211_ATTR_DTIM_PERIOD] || 3821 !info->attrs[NL80211_ATTR_BEACON_HEAD]) 3822 return -EINVAL; 3823 3824 err = nl80211_parse_beacon(info->attrs, ¶ms.beacon); 3825 if (err) 3826 return err; 3827 3828 params.beacon_interval = 3829 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 3830 params.dtim_period = 3831 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]); 3832 3833 err = cfg80211_validate_beacon_int(rdev, dev->ieee80211_ptr->iftype, 3834 params.beacon_interval); 3835 if (err) 3836 return err; 3837 3838 /* 3839 * In theory, some of these attributes should be required here 3840 * but since they were not used when the command was originally 3841 * added, keep them optional for old user space programs to let 3842 * them continue to work with drivers that do not need the 3843 * additional information -- drivers must check! 3844 */ 3845 if (info->attrs[NL80211_ATTR_SSID]) { 3846 params.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 3847 params.ssid_len = 3848 nla_len(info->attrs[NL80211_ATTR_SSID]); 3849 if (params.ssid_len == 0 || 3850 params.ssid_len > IEEE80211_MAX_SSID_LEN) 3851 return -EINVAL; 3852 } 3853 3854 if (info->attrs[NL80211_ATTR_HIDDEN_SSID]) { 3855 params.hidden_ssid = nla_get_u32( 3856 info->attrs[NL80211_ATTR_HIDDEN_SSID]); 3857 if (params.hidden_ssid != NL80211_HIDDEN_SSID_NOT_IN_USE && 3858 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_LEN && 3859 params.hidden_ssid != NL80211_HIDDEN_SSID_ZERO_CONTENTS) 3860 return -EINVAL; 3861 } 3862 3863 params.privacy = !!info->attrs[NL80211_ATTR_PRIVACY]; 3864 3865 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) { 3866 params.auth_type = nla_get_u32( 3867 info->attrs[NL80211_ATTR_AUTH_TYPE]); 3868 if (!nl80211_valid_auth_type(rdev, params.auth_type, 3869 NL80211_CMD_START_AP)) 3870 return -EINVAL; 3871 } else 3872 params.auth_type = NL80211_AUTHTYPE_AUTOMATIC; 3873 3874 err = nl80211_crypto_settings(rdev, info, ¶ms.crypto, 3875 NL80211_MAX_NR_CIPHER_SUITES); 3876 if (err) 3877 return err; 3878 3879 if (info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]) { 3880 if (!(rdev->wiphy.features & NL80211_FEATURE_INACTIVITY_TIMER)) 3881 return -EOPNOTSUPP; 3882 params.inactivity_timeout = nla_get_u16( 3883 info->attrs[NL80211_ATTR_INACTIVITY_TIMEOUT]); 3884 } 3885 3886 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) { 3887 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3888 return -EINVAL; 3889 params.p2p_ctwindow = 3890 nla_get_u8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]); 3891 if (params.p2p_ctwindow > 127) 3892 return -EINVAL; 3893 if (params.p2p_ctwindow != 0 && 3894 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) 3895 return -EINVAL; 3896 } 3897 3898 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) { 3899 u8 tmp; 3900 3901 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3902 return -EINVAL; 3903 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]); 3904 if (tmp > 1) 3905 return -EINVAL; 3906 params.p2p_opp_ps = tmp; 3907 if (params.p2p_opp_ps != 0 && 3908 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) 3909 return -EINVAL; 3910 } 3911 3912 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 3913 err = nl80211_parse_chandef(rdev, info, ¶ms.chandef); 3914 if (err) 3915 return err; 3916 } else if (wdev->preset_chandef.chan) { 3917 params.chandef = wdev->preset_chandef; 3918 } else if (!nl80211_get_ap_channel(rdev, ¶ms)) 3919 return -EINVAL; 3920 3921 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, ¶ms.chandef, 3922 wdev->iftype)) 3923 return -EINVAL; 3924 3925 if (info->attrs[NL80211_ATTR_TX_RATES]) { 3926 err = nl80211_parse_tx_bitrate_mask(info, ¶ms.beacon_rate); 3927 if (err) 3928 return err; 3929 3930 err = validate_beacon_tx_rate(rdev, params.chandef.chan->band, 3931 ¶ms.beacon_rate); 3932 if (err) 3933 return err; 3934 } 3935 3936 if (info->attrs[NL80211_ATTR_SMPS_MODE]) { 3937 params.smps_mode = 3938 nla_get_u8(info->attrs[NL80211_ATTR_SMPS_MODE]); 3939 switch (params.smps_mode) { 3940 case NL80211_SMPS_OFF: 3941 break; 3942 case NL80211_SMPS_STATIC: 3943 if (!(rdev->wiphy.features & 3944 NL80211_FEATURE_STATIC_SMPS)) 3945 return -EINVAL; 3946 break; 3947 case NL80211_SMPS_DYNAMIC: 3948 if (!(rdev->wiphy.features & 3949 NL80211_FEATURE_DYNAMIC_SMPS)) 3950 return -EINVAL; 3951 break; 3952 default: 3953 return -EINVAL; 3954 } 3955 } else { 3956 params.smps_mode = NL80211_SMPS_OFF; 3957 } 3958 3959 params.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]); 3960 if (params.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) 3961 return -EOPNOTSUPP; 3962 3963 if (info->attrs[NL80211_ATTR_ACL_POLICY]) { 3964 params.acl = parse_acl_data(&rdev->wiphy, info); 3965 if (IS_ERR(params.acl)) 3966 return PTR_ERR(params.acl); 3967 } 3968 3969 wdev_lock(wdev); 3970 err = rdev_start_ap(rdev, dev, ¶ms); 3971 if (!err) { 3972 wdev->preset_chandef = params.chandef; 3973 wdev->beacon_interval = params.beacon_interval; 3974 wdev->chandef = params.chandef; 3975 wdev->ssid_len = params.ssid_len; 3976 memcpy(wdev->ssid, params.ssid, wdev->ssid_len); 3977 } 3978 wdev_unlock(wdev); 3979 3980 kfree(params.acl); 3981 3982 return err; 3983 } 3984 3985 static int nl80211_set_beacon(struct sk_buff *skb, struct genl_info *info) 3986 { 3987 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 3988 struct net_device *dev = info->user_ptr[1]; 3989 struct wireless_dev *wdev = dev->ieee80211_ptr; 3990 struct cfg80211_beacon_data params; 3991 int err; 3992 3993 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 3994 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 3995 return -EOPNOTSUPP; 3996 3997 if (!rdev->ops->change_beacon) 3998 return -EOPNOTSUPP; 3999 4000 if (!wdev->beacon_interval) 4001 return -EINVAL; 4002 4003 err = nl80211_parse_beacon(info->attrs, ¶ms); 4004 if (err) 4005 return err; 4006 4007 wdev_lock(wdev); 4008 err = rdev_change_beacon(rdev, dev, ¶ms); 4009 wdev_unlock(wdev); 4010 4011 return err; 4012 } 4013 4014 static int nl80211_stop_ap(struct sk_buff *skb, struct genl_info *info) 4015 { 4016 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4017 struct net_device *dev = info->user_ptr[1]; 4018 4019 return cfg80211_stop_ap(rdev, dev, false); 4020 } 4021 4022 static const struct nla_policy sta_flags_policy[NL80211_STA_FLAG_MAX + 1] = { 4023 [NL80211_STA_FLAG_AUTHORIZED] = { .type = NLA_FLAG }, 4024 [NL80211_STA_FLAG_SHORT_PREAMBLE] = { .type = NLA_FLAG }, 4025 [NL80211_STA_FLAG_WME] = { .type = NLA_FLAG }, 4026 [NL80211_STA_FLAG_MFP] = { .type = NLA_FLAG }, 4027 [NL80211_STA_FLAG_AUTHENTICATED] = { .type = NLA_FLAG }, 4028 [NL80211_STA_FLAG_TDLS_PEER] = { .type = NLA_FLAG }, 4029 }; 4030 4031 static int parse_station_flags(struct genl_info *info, 4032 enum nl80211_iftype iftype, 4033 struct station_parameters *params) 4034 { 4035 struct nlattr *flags[NL80211_STA_FLAG_MAX + 1]; 4036 struct nlattr *nla; 4037 int flag; 4038 4039 /* 4040 * Try parsing the new attribute first so userspace 4041 * can specify both for older kernels. 4042 */ 4043 nla = info->attrs[NL80211_ATTR_STA_FLAGS2]; 4044 if (nla) { 4045 struct nl80211_sta_flag_update *sta_flags; 4046 4047 sta_flags = nla_data(nla); 4048 params->sta_flags_mask = sta_flags->mask; 4049 params->sta_flags_set = sta_flags->set; 4050 params->sta_flags_set &= params->sta_flags_mask; 4051 if ((params->sta_flags_mask | 4052 params->sta_flags_set) & BIT(__NL80211_STA_FLAG_INVALID)) 4053 return -EINVAL; 4054 return 0; 4055 } 4056 4057 /* if present, parse the old attribute */ 4058 4059 nla = info->attrs[NL80211_ATTR_STA_FLAGS]; 4060 if (!nla) 4061 return 0; 4062 4063 if (nla_parse_nested(flags, NL80211_STA_FLAG_MAX, 4064 nla, sta_flags_policy)) 4065 return -EINVAL; 4066 4067 /* 4068 * Only allow certain flags for interface types so that 4069 * other attributes are silently ignored. Remember that 4070 * this is backward compatibility code with old userspace 4071 * and shouldn't be hit in other cases anyway. 4072 */ 4073 switch (iftype) { 4074 case NL80211_IFTYPE_AP: 4075 case NL80211_IFTYPE_AP_VLAN: 4076 case NL80211_IFTYPE_P2P_GO: 4077 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) | 4078 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) | 4079 BIT(NL80211_STA_FLAG_WME) | 4080 BIT(NL80211_STA_FLAG_MFP); 4081 break; 4082 case NL80211_IFTYPE_P2P_CLIENT: 4083 case NL80211_IFTYPE_STATION: 4084 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHORIZED) | 4085 BIT(NL80211_STA_FLAG_TDLS_PEER); 4086 break; 4087 case NL80211_IFTYPE_MESH_POINT: 4088 params->sta_flags_mask = BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4089 BIT(NL80211_STA_FLAG_MFP) | 4090 BIT(NL80211_STA_FLAG_AUTHORIZED); 4091 default: 4092 return -EINVAL; 4093 } 4094 4095 for (flag = 1; flag <= NL80211_STA_FLAG_MAX; flag++) { 4096 if (flags[flag]) { 4097 params->sta_flags_set |= (1<<flag); 4098 4099 /* no longer support new API additions in old API */ 4100 if (flag > NL80211_STA_FLAG_MAX_OLD_API) 4101 return -EINVAL; 4102 } 4103 } 4104 4105 return 0; 4106 } 4107 4108 static bool nl80211_put_sta_rate(struct sk_buff *msg, struct rate_info *info, 4109 int attr) 4110 { 4111 struct nlattr *rate; 4112 u32 bitrate; 4113 u16 bitrate_compat; 4114 enum nl80211_attrs rate_flg; 4115 4116 rate = nla_nest_start(msg, attr); 4117 if (!rate) 4118 return false; 4119 4120 /* cfg80211_calculate_bitrate will return 0 for mcs >= 32 */ 4121 bitrate = cfg80211_calculate_bitrate(info); 4122 /* report 16-bit bitrate only if we can */ 4123 bitrate_compat = bitrate < (1UL << 16) ? bitrate : 0; 4124 if (bitrate > 0 && 4125 nla_put_u32(msg, NL80211_RATE_INFO_BITRATE32, bitrate)) 4126 return false; 4127 if (bitrate_compat > 0 && 4128 nla_put_u16(msg, NL80211_RATE_INFO_BITRATE, bitrate_compat)) 4129 return false; 4130 4131 switch (info->bw) { 4132 case RATE_INFO_BW_5: 4133 rate_flg = NL80211_RATE_INFO_5_MHZ_WIDTH; 4134 break; 4135 case RATE_INFO_BW_10: 4136 rate_flg = NL80211_RATE_INFO_10_MHZ_WIDTH; 4137 break; 4138 default: 4139 WARN_ON(1); 4140 /* fall through */ 4141 case RATE_INFO_BW_20: 4142 rate_flg = 0; 4143 break; 4144 case RATE_INFO_BW_40: 4145 rate_flg = NL80211_RATE_INFO_40_MHZ_WIDTH; 4146 break; 4147 case RATE_INFO_BW_80: 4148 rate_flg = NL80211_RATE_INFO_80_MHZ_WIDTH; 4149 break; 4150 case RATE_INFO_BW_160: 4151 rate_flg = NL80211_RATE_INFO_160_MHZ_WIDTH; 4152 break; 4153 } 4154 4155 if (rate_flg && nla_put_flag(msg, rate_flg)) 4156 return false; 4157 4158 if (info->flags & RATE_INFO_FLAGS_MCS) { 4159 if (nla_put_u8(msg, NL80211_RATE_INFO_MCS, info->mcs)) 4160 return false; 4161 if (info->flags & RATE_INFO_FLAGS_SHORT_GI && 4162 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)) 4163 return false; 4164 } else if (info->flags & RATE_INFO_FLAGS_VHT_MCS) { 4165 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_MCS, info->mcs)) 4166 return false; 4167 if (nla_put_u8(msg, NL80211_RATE_INFO_VHT_NSS, info->nss)) 4168 return false; 4169 if (info->flags & RATE_INFO_FLAGS_SHORT_GI && 4170 nla_put_flag(msg, NL80211_RATE_INFO_SHORT_GI)) 4171 return false; 4172 } 4173 4174 nla_nest_end(msg, rate); 4175 return true; 4176 } 4177 4178 static bool nl80211_put_signal(struct sk_buff *msg, u8 mask, s8 *signal, 4179 int id) 4180 { 4181 void *attr; 4182 int i = 0; 4183 4184 if (!mask) 4185 return true; 4186 4187 attr = nla_nest_start(msg, id); 4188 if (!attr) 4189 return false; 4190 4191 for (i = 0; i < IEEE80211_MAX_CHAINS; i++) { 4192 if (!(mask & BIT(i))) 4193 continue; 4194 4195 if (nla_put_u8(msg, i, signal[i])) 4196 return false; 4197 } 4198 4199 nla_nest_end(msg, attr); 4200 4201 return true; 4202 } 4203 4204 static int nl80211_send_station(struct sk_buff *msg, u32 cmd, u32 portid, 4205 u32 seq, int flags, 4206 struct cfg80211_registered_device *rdev, 4207 struct net_device *dev, 4208 const u8 *mac_addr, struct station_info *sinfo) 4209 { 4210 void *hdr; 4211 struct nlattr *sinfoattr, *bss_param; 4212 4213 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 4214 if (!hdr) 4215 return -1; 4216 4217 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 4218 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) || 4219 nla_put_u32(msg, NL80211_ATTR_GENERATION, sinfo->generation)) 4220 goto nla_put_failure; 4221 4222 sinfoattr = nla_nest_start(msg, NL80211_ATTR_STA_INFO); 4223 if (!sinfoattr) 4224 goto nla_put_failure; 4225 4226 #define PUT_SINFO(attr, memb, type) do { \ 4227 BUILD_BUG_ON(sizeof(type) == sizeof(u64)); \ 4228 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \ 4229 nla_put_ ## type(msg, NL80211_STA_INFO_ ## attr, \ 4230 sinfo->memb)) \ 4231 goto nla_put_failure; \ 4232 } while (0) 4233 #define PUT_SINFO_U64(attr, memb) do { \ 4234 if (sinfo->filled & (1ULL << NL80211_STA_INFO_ ## attr) && \ 4235 nla_put_u64_64bit(msg, NL80211_STA_INFO_ ## attr, \ 4236 sinfo->memb, NL80211_STA_INFO_PAD)) \ 4237 goto nla_put_failure; \ 4238 } while (0) 4239 4240 PUT_SINFO(CONNECTED_TIME, connected_time, u32); 4241 PUT_SINFO(INACTIVE_TIME, inactive_time, u32); 4242 4243 if (sinfo->filled & (BIT(NL80211_STA_INFO_RX_BYTES) | 4244 BIT(NL80211_STA_INFO_RX_BYTES64)) && 4245 nla_put_u32(msg, NL80211_STA_INFO_RX_BYTES, 4246 (u32)sinfo->rx_bytes)) 4247 goto nla_put_failure; 4248 4249 if (sinfo->filled & (BIT(NL80211_STA_INFO_TX_BYTES) | 4250 BIT(NL80211_STA_INFO_TX_BYTES64)) && 4251 nla_put_u32(msg, NL80211_STA_INFO_TX_BYTES, 4252 (u32)sinfo->tx_bytes)) 4253 goto nla_put_failure; 4254 4255 PUT_SINFO_U64(RX_BYTES64, rx_bytes); 4256 PUT_SINFO_U64(TX_BYTES64, tx_bytes); 4257 PUT_SINFO(LLID, llid, u16); 4258 PUT_SINFO(PLID, plid, u16); 4259 PUT_SINFO(PLINK_STATE, plink_state, u8); 4260 PUT_SINFO_U64(RX_DURATION, rx_duration); 4261 4262 switch (rdev->wiphy.signal_type) { 4263 case CFG80211_SIGNAL_TYPE_MBM: 4264 PUT_SINFO(SIGNAL, signal, u8); 4265 PUT_SINFO(SIGNAL_AVG, signal_avg, u8); 4266 break; 4267 default: 4268 break; 4269 } 4270 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL)) { 4271 if (!nl80211_put_signal(msg, sinfo->chains, 4272 sinfo->chain_signal, 4273 NL80211_STA_INFO_CHAIN_SIGNAL)) 4274 goto nla_put_failure; 4275 } 4276 if (sinfo->filled & BIT(NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) { 4277 if (!nl80211_put_signal(msg, sinfo->chains, 4278 sinfo->chain_signal_avg, 4279 NL80211_STA_INFO_CHAIN_SIGNAL_AVG)) 4280 goto nla_put_failure; 4281 } 4282 if (sinfo->filled & BIT(NL80211_STA_INFO_TX_BITRATE)) { 4283 if (!nl80211_put_sta_rate(msg, &sinfo->txrate, 4284 NL80211_STA_INFO_TX_BITRATE)) 4285 goto nla_put_failure; 4286 } 4287 if (sinfo->filled & BIT(NL80211_STA_INFO_RX_BITRATE)) { 4288 if (!nl80211_put_sta_rate(msg, &sinfo->rxrate, 4289 NL80211_STA_INFO_RX_BITRATE)) 4290 goto nla_put_failure; 4291 } 4292 4293 PUT_SINFO(RX_PACKETS, rx_packets, u32); 4294 PUT_SINFO(TX_PACKETS, tx_packets, u32); 4295 PUT_SINFO(TX_RETRIES, tx_retries, u32); 4296 PUT_SINFO(TX_FAILED, tx_failed, u32); 4297 PUT_SINFO(EXPECTED_THROUGHPUT, expected_throughput, u32); 4298 PUT_SINFO(BEACON_LOSS, beacon_loss_count, u32); 4299 PUT_SINFO(LOCAL_PM, local_pm, u32); 4300 PUT_SINFO(PEER_PM, peer_pm, u32); 4301 PUT_SINFO(NONPEER_PM, nonpeer_pm, u32); 4302 4303 if (sinfo->filled & BIT(NL80211_STA_INFO_BSS_PARAM)) { 4304 bss_param = nla_nest_start(msg, NL80211_STA_INFO_BSS_PARAM); 4305 if (!bss_param) 4306 goto nla_put_failure; 4307 4308 if (((sinfo->bss_param.flags & BSS_PARAM_FLAGS_CTS_PROT) && 4309 nla_put_flag(msg, NL80211_STA_BSS_PARAM_CTS_PROT)) || 4310 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_PREAMBLE) && 4311 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_PREAMBLE)) || 4312 ((sinfo->bss_param.flags & BSS_PARAM_FLAGS_SHORT_SLOT_TIME) && 4313 nla_put_flag(msg, NL80211_STA_BSS_PARAM_SHORT_SLOT_TIME)) || 4314 nla_put_u8(msg, NL80211_STA_BSS_PARAM_DTIM_PERIOD, 4315 sinfo->bss_param.dtim_period) || 4316 nla_put_u16(msg, NL80211_STA_BSS_PARAM_BEACON_INTERVAL, 4317 sinfo->bss_param.beacon_interval)) 4318 goto nla_put_failure; 4319 4320 nla_nest_end(msg, bss_param); 4321 } 4322 if ((sinfo->filled & BIT(NL80211_STA_INFO_STA_FLAGS)) && 4323 nla_put(msg, NL80211_STA_INFO_STA_FLAGS, 4324 sizeof(struct nl80211_sta_flag_update), 4325 &sinfo->sta_flags)) 4326 goto nla_put_failure; 4327 4328 PUT_SINFO_U64(T_OFFSET, t_offset); 4329 PUT_SINFO_U64(RX_DROP_MISC, rx_dropped_misc); 4330 PUT_SINFO_U64(BEACON_RX, rx_beacon); 4331 PUT_SINFO(BEACON_SIGNAL_AVG, rx_beacon_signal_avg, u8); 4332 4333 #undef PUT_SINFO 4334 #undef PUT_SINFO_U64 4335 4336 if (sinfo->filled & BIT(NL80211_STA_INFO_TID_STATS)) { 4337 struct nlattr *tidsattr; 4338 int tid; 4339 4340 tidsattr = nla_nest_start(msg, NL80211_STA_INFO_TID_STATS); 4341 if (!tidsattr) 4342 goto nla_put_failure; 4343 4344 for (tid = 0; tid < IEEE80211_NUM_TIDS + 1; tid++) { 4345 struct cfg80211_tid_stats *tidstats; 4346 struct nlattr *tidattr; 4347 4348 tidstats = &sinfo->pertid[tid]; 4349 4350 if (!tidstats->filled) 4351 continue; 4352 4353 tidattr = nla_nest_start(msg, tid + 1); 4354 if (!tidattr) 4355 goto nla_put_failure; 4356 4357 #define PUT_TIDVAL_U64(attr, memb) do { \ 4358 if (tidstats->filled & BIT(NL80211_TID_STATS_ ## attr) && \ 4359 nla_put_u64_64bit(msg, NL80211_TID_STATS_ ## attr, \ 4360 tidstats->memb, NL80211_TID_STATS_PAD)) \ 4361 goto nla_put_failure; \ 4362 } while (0) 4363 4364 PUT_TIDVAL_U64(RX_MSDU, rx_msdu); 4365 PUT_TIDVAL_U64(TX_MSDU, tx_msdu); 4366 PUT_TIDVAL_U64(TX_MSDU_RETRIES, tx_msdu_retries); 4367 PUT_TIDVAL_U64(TX_MSDU_FAILED, tx_msdu_failed); 4368 4369 #undef PUT_TIDVAL_U64 4370 nla_nest_end(msg, tidattr); 4371 } 4372 4373 nla_nest_end(msg, tidsattr); 4374 } 4375 4376 nla_nest_end(msg, sinfoattr); 4377 4378 if (sinfo->assoc_req_ies_len && 4379 nla_put(msg, NL80211_ATTR_IE, sinfo->assoc_req_ies_len, 4380 sinfo->assoc_req_ies)) 4381 goto nla_put_failure; 4382 4383 genlmsg_end(msg, hdr); 4384 return 0; 4385 4386 nla_put_failure: 4387 genlmsg_cancel(msg, hdr); 4388 return -EMSGSIZE; 4389 } 4390 4391 static int nl80211_dump_station(struct sk_buff *skb, 4392 struct netlink_callback *cb) 4393 { 4394 struct station_info sinfo; 4395 struct cfg80211_registered_device *rdev; 4396 struct wireless_dev *wdev; 4397 u8 mac_addr[ETH_ALEN]; 4398 int sta_idx = cb->args[2]; 4399 int err; 4400 4401 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 4402 if (err) 4403 return err; 4404 4405 if (!wdev->netdev) { 4406 err = -EINVAL; 4407 goto out_err; 4408 } 4409 4410 if (!rdev->ops->dump_station) { 4411 err = -EOPNOTSUPP; 4412 goto out_err; 4413 } 4414 4415 while (1) { 4416 memset(&sinfo, 0, sizeof(sinfo)); 4417 err = rdev_dump_station(rdev, wdev->netdev, sta_idx, 4418 mac_addr, &sinfo); 4419 if (err == -ENOENT) 4420 break; 4421 if (err) 4422 goto out_err; 4423 4424 if (nl80211_send_station(skb, NL80211_CMD_NEW_STATION, 4425 NETLINK_CB(cb->skb).portid, 4426 cb->nlh->nlmsg_seq, NLM_F_MULTI, 4427 rdev, wdev->netdev, mac_addr, 4428 &sinfo) < 0) 4429 goto out; 4430 4431 sta_idx++; 4432 } 4433 4434 out: 4435 cb->args[2] = sta_idx; 4436 err = skb->len; 4437 out_err: 4438 nl80211_finish_wdev_dump(rdev); 4439 4440 return err; 4441 } 4442 4443 static int nl80211_get_station(struct sk_buff *skb, struct genl_info *info) 4444 { 4445 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4446 struct net_device *dev = info->user_ptr[1]; 4447 struct station_info sinfo; 4448 struct sk_buff *msg; 4449 u8 *mac_addr = NULL; 4450 int err; 4451 4452 memset(&sinfo, 0, sizeof(sinfo)); 4453 4454 if (!info->attrs[NL80211_ATTR_MAC]) 4455 return -EINVAL; 4456 4457 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4458 4459 if (!rdev->ops->get_station) 4460 return -EOPNOTSUPP; 4461 4462 err = rdev_get_station(rdev, dev, mac_addr, &sinfo); 4463 if (err) 4464 return err; 4465 4466 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 4467 if (!msg) 4468 return -ENOMEM; 4469 4470 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 4471 info->snd_portid, info->snd_seq, 0, 4472 rdev, dev, mac_addr, &sinfo) < 0) { 4473 nlmsg_free(msg); 4474 return -ENOBUFS; 4475 } 4476 4477 return genlmsg_reply(msg, info); 4478 } 4479 4480 int cfg80211_check_station_change(struct wiphy *wiphy, 4481 struct station_parameters *params, 4482 enum cfg80211_station_type statype) 4483 { 4484 if (params->listen_interval != -1 && 4485 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4486 return -EINVAL; 4487 4488 if (params->support_p2p_ps != -1 && 4489 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4490 return -EINVAL; 4491 4492 if (params->aid && 4493 !(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) && 4494 statype != CFG80211_STA_AP_CLIENT_UNASSOC) 4495 return -EINVAL; 4496 4497 /* When you run into this, adjust the code below for the new flag */ 4498 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7); 4499 4500 switch (statype) { 4501 case CFG80211_STA_MESH_PEER_KERNEL: 4502 case CFG80211_STA_MESH_PEER_USER: 4503 /* 4504 * No ignoring the TDLS flag here -- the userspace mesh 4505 * code doesn't have the bug of including TDLS in the 4506 * mask everywhere. 4507 */ 4508 if (params->sta_flags_mask & 4509 ~(BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4510 BIT(NL80211_STA_FLAG_MFP) | 4511 BIT(NL80211_STA_FLAG_AUTHORIZED))) 4512 return -EINVAL; 4513 break; 4514 case CFG80211_STA_TDLS_PEER_SETUP: 4515 case CFG80211_STA_TDLS_PEER_ACTIVE: 4516 if (!(params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))) 4517 return -EINVAL; 4518 /* ignore since it can't change */ 4519 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 4520 break; 4521 default: 4522 /* disallow mesh-specific things */ 4523 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION) 4524 return -EINVAL; 4525 if (params->local_pm) 4526 return -EINVAL; 4527 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE) 4528 return -EINVAL; 4529 } 4530 4531 if (statype != CFG80211_STA_TDLS_PEER_SETUP && 4532 statype != CFG80211_STA_TDLS_PEER_ACTIVE) { 4533 /* TDLS can't be set, ... */ 4534 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) 4535 return -EINVAL; 4536 /* 4537 * ... but don't bother the driver with it. This works around 4538 * a hostapd/wpa_supplicant issue -- it always includes the 4539 * TLDS_PEER flag in the mask even for AP mode. 4540 */ 4541 params->sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 4542 } 4543 4544 if (statype != CFG80211_STA_TDLS_PEER_SETUP && 4545 statype != CFG80211_STA_AP_CLIENT_UNASSOC) { 4546 /* reject other things that can't change */ 4547 if (params->sta_modify_mask & STATION_PARAM_APPLY_UAPSD) 4548 return -EINVAL; 4549 if (params->sta_modify_mask & STATION_PARAM_APPLY_CAPABILITY) 4550 return -EINVAL; 4551 if (params->supported_rates) 4552 return -EINVAL; 4553 if (params->ext_capab || params->ht_capa || params->vht_capa) 4554 return -EINVAL; 4555 } 4556 4557 if (statype != CFG80211_STA_AP_CLIENT && 4558 statype != CFG80211_STA_AP_CLIENT_UNASSOC) { 4559 if (params->vlan) 4560 return -EINVAL; 4561 } 4562 4563 switch (statype) { 4564 case CFG80211_STA_AP_MLME_CLIENT: 4565 /* Use this only for authorizing/unauthorizing a station */ 4566 if (!(params->sta_flags_mask & BIT(NL80211_STA_FLAG_AUTHORIZED))) 4567 return -EOPNOTSUPP; 4568 break; 4569 case CFG80211_STA_AP_CLIENT: 4570 case CFG80211_STA_AP_CLIENT_UNASSOC: 4571 /* accept only the listed bits */ 4572 if (params->sta_flags_mask & 4573 ~(BIT(NL80211_STA_FLAG_AUTHORIZED) | 4574 BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4575 BIT(NL80211_STA_FLAG_ASSOCIATED) | 4576 BIT(NL80211_STA_FLAG_SHORT_PREAMBLE) | 4577 BIT(NL80211_STA_FLAG_WME) | 4578 BIT(NL80211_STA_FLAG_MFP))) 4579 return -EINVAL; 4580 4581 /* but authenticated/associated only if driver handles it */ 4582 if (!(wiphy->features & NL80211_FEATURE_FULL_AP_CLIENT_STATE) && 4583 params->sta_flags_mask & 4584 (BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4585 BIT(NL80211_STA_FLAG_ASSOCIATED))) 4586 return -EINVAL; 4587 break; 4588 case CFG80211_STA_IBSS: 4589 case CFG80211_STA_AP_STA: 4590 /* reject any changes other than AUTHORIZED */ 4591 if (params->sta_flags_mask & ~BIT(NL80211_STA_FLAG_AUTHORIZED)) 4592 return -EINVAL; 4593 break; 4594 case CFG80211_STA_TDLS_PEER_SETUP: 4595 /* reject any changes other than AUTHORIZED or WME */ 4596 if (params->sta_flags_mask & ~(BIT(NL80211_STA_FLAG_AUTHORIZED) | 4597 BIT(NL80211_STA_FLAG_WME))) 4598 return -EINVAL; 4599 /* force (at least) rates when authorizing */ 4600 if (params->sta_flags_set & BIT(NL80211_STA_FLAG_AUTHORIZED) && 4601 !params->supported_rates) 4602 return -EINVAL; 4603 break; 4604 case CFG80211_STA_TDLS_PEER_ACTIVE: 4605 /* reject any changes */ 4606 return -EINVAL; 4607 case CFG80211_STA_MESH_PEER_KERNEL: 4608 if (params->sta_modify_mask & STATION_PARAM_APPLY_PLINK_STATE) 4609 return -EINVAL; 4610 break; 4611 case CFG80211_STA_MESH_PEER_USER: 4612 if (params->plink_action != NL80211_PLINK_ACTION_NO_ACTION && 4613 params->plink_action != NL80211_PLINK_ACTION_BLOCK) 4614 return -EINVAL; 4615 break; 4616 } 4617 4618 /* 4619 * Older kernel versions ignored this attribute entirely, so don't 4620 * reject attempts to update it but mark it as unused instead so the 4621 * driver won't look at the data. 4622 */ 4623 if (statype != CFG80211_STA_AP_CLIENT_UNASSOC && 4624 statype != CFG80211_STA_TDLS_PEER_SETUP) 4625 params->opmode_notif_used = false; 4626 4627 return 0; 4628 } 4629 EXPORT_SYMBOL(cfg80211_check_station_change); 4630 4631 /* 4632 * Get vlan interface making sure it is running and on the right wiphy. 4633 */ 4634 static struct net_device *get_vlan(struct genl_info *info, 4635 struct cfg80211_registered_device *rdev) 4636 { 4637 struct nlattr *vlanattr = info->attrs[NL80211_ATTR_STA_VLAN]; 4638 struct net_device *v; 4639 int ret; 4640 4641 if (!vlanattr) 4642 return NULL; 4643 4644 v = dev_get_by_index(genl_info_net(info), nla_get_u32(vlanattr)); 4645 if (!v) 4646 return ERR_PTR(-ENODEV); 4647 4648 if (!v->ieee80211_ptr || v->ieee80211_ptr->wiphy != &rdev->wiphy) { 4649 ret = -EINVAL; 4650 goto error; 4651 } 4652 4653 if (v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN && 4654 v->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 4655 v->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) { 4656 ret = -EINVAL; 4657 goto error; 4658 } 4659 4660 if (!netif_running(v)) { 4661 ret = -ENETDOWN; 4662 goto error; 4663 } 4664 4665 return v; 4666 error: 4667 dev_put(v); 4668 return ERR_PTR(ret); 4669 } 4670 4671 static const struct nla_policy 4672 nl80211_sta_wme_policy[NL80211_STA_WME_MAX + 1] = { 4673 [NL80211_STA_WME_UAPSD_QUEUES] = { .type = NLA_U8 }, 4674 [NL80211_STA_WME_MAX_SP] = { .type = NLA_U8 }, 4675 }; 4676 4677 static int nl80211_parse_sta_wme(struct genl_info *info, 4678 struct station_parameters *params) 4679 { 4680 struct nlattr *tb[NL80211_STA_WME_MAX + 1]; 4681 struct nlattr *nla; 4682 int err; 4683 4684 /* parse WME attributes if present */ 4685 if (!info->attrs[NL80211_ATTR_STA_WME]) 4686 return 0; 4687 4688 nla = info->attrs[NL80211_ATTR_STA_WME]; 4689 err = nla_parse_nested(tb, NL80211_STA_WME_MAX, nla, 4690 nl80211_sta_wme_policy); 4691 if (err) 4692 return err; 4693 4694 if (tb[NL80211_STA_WME_UAPSD_QUEUES]) 4695 params->uapsd_queues = nla_get_u8( 4696 tb[NL80211_STA_WME_UAPSD_QUEUES]); 4697 if (params->uapsd_queues & ~IEEE80211_WMM_IE_STA_QOSINFO_AC_MASK) 4698 return -EINVAL; 4699 4700 if (tb[NL80211_STA_WME_MAX_SP]) 4701 params->max_sp = nla_get_u8(tb[NL80211_STA_WME_MAX_SP]); 4702 4703 if (params->max_sp & ~IEEE80211_WMM_IE_STA_QOSINFO_SP_MASK) 4704 return -EINVAL; 4705 4706 params->sta_modify_mask |= STATION_PARAM_APPLY_UAPSD; 4707 4708 return 0; 4709 } 4710 4711 static int nl80211_parse_sta_channel_info(struct genl_info *info, 4712 struct station_parameters *params) 4713 { 4714 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]) { 4715 params->supported_channels = 4716 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]); 4717 params->supported_channels_len = 4718 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_CHANNELS]); 4719 /* 4720 * Need to include at least one (first channel, number of 4721 * channels) tuple for each subband, and must have proper 4722 * tuples for the rest of the data as well. 4723 */ 4724 if (params->supported_channels_len < 2) 4725 return -EINVAL; 4726 if (params->supported_channels_len % 2) 4727 return -EINVAL; 4728 } 4729 4730 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]) { 4731 params->supported_oper_classes = 4732 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]); 4733 params->supported_oper_classes_len = 4734 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_OPER_CLASSES]); 4735 /* 4736 * The value of the Length field of the Supported Operating 4737 * Classes element is between 2 and 253. 4738 */ 4739 if (params->supported_oper_classes_len < 2 || 4740 params->supported_oper_classes_len > 253) 4741 return -EINVAL; 4742 } 4743 return 0; 4744 } 4745 4746 static int nl80211_set_station_tdls(struct genl_info *info, 4747 struct station_parameters *params) 4748 { 4749 int err; 4750 /* Dummy STA entry gets updated once the peer capabilities are known */ 4751 if (info->attrs[NL80211_ATTR_PEER_AID]) 4752 params->aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]); 4753 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) 4754 params->ht_capa = 4755 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]); 4756 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) 4757 params->vht_capa = 4758 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]); 4759 4760 err = nl80211_parse_sta_channel_info(info, params); 4761 if (err) 4762 return err; 4763 4764 return nl80211_parse_sta_wme(info, params); 4765 } 4766 4767 static int nl80211_set_station(struct sk_buff *skb, struct genl_info *info) 4768 { 4769 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4770 struct net_device *dev = info->user_ptr[1]; 4771 struct station_parameters params; 4772 u8 *mac_addr; 4773 int err; 4774 4775 memset(¶ms, 0, sizeof(params)); 4776 4777 if (!rdev->ops->change_station) 4778 return -EOPNOTSUPP; 4779 4780 /* 4781 * AID and listen_interval properties can be set only for unassociated 4782 * station. Include these parameters here and will check them in 4783 * cfg80211_check_station_change(). 4784 */ 4785 if (info->attrs[NL80211_ATTR_STA_AID]) 4786 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]); 4787 4788 if (info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]) 4789 params.listen_interval = 4790 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]); 4791 else 4792 params.listen_interval = -1; 4793 4794 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) { 4795 u8 tmp; 4796 4797 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]); 4798 if (tmp >= NUM_NL80211_P2P_PS_STATUS) 4799 return -EINVAL; 4800 4801 params.support_p2p_ps = tmp; 4802 } else { 4803 params.support_p2p_ps = -1; 4804 } 4805 4806 if (!info->attrs[NL80211_ATTR_MAC]) 4807 return -EINVAL; 4808 4809 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4810 4811 if (info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) { 4812 params.supported_rates = 4813 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4814 params.supported_rates_len = 4815 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4816 } 4817 4818 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) { 4819 params.capability = 4820 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]); 4821 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY; 4822 } 4823 4824 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) { 4825 params.ext_capab = 4826 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4827 params.ext_capab_len = 4828 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4829 } 4830 4831 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, ¶ms)) 4832 return -EINVAL; 4833 4834 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) { 4835 params.plink_action = 4836 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]); 4837 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS) 4838 return -EINVAL; 4839 } 4840 4841 if (info->attrs[NL80211_ATTR_STA_PLINK_STATE]) { 4842 params.plink_state = 4843 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_STATE]); 4844 if (params.plink_state >= NUM_NL80211_PLINK_STATES) 4845 return -EINVAL; 4846 if (info->attrs[NL80211_ATTR_MESH_PEER_AID]) { 4847 params.peer_aid = nla_get_u16( 4848 info->attrs[NL80211_ATTR_MESH_PEER_AID]); 4849 if (params.peer_aid > IEEE80211_MAX_AID) 4850 return -EINVAL; 4851 } 4852 params.sta_modify_mask |= STATION_PARAM_APPLY_PLINK_STATE; 4853 } 4854 4855 if (info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]) { 4856 enum nl80211_mesh_power_mode pm = nla_get_u32( 4857 info->attrs[NL80211_ATTR_LOCAL_MESH_POWER_MODE]); 4858 4859 if (pm <= NL80211_MESH_POWER_UNKNOWN || 4860 pm > NL80211_MESH_POWER_MAX) 4861 return -EINVAL; 4862 4863 params.local_pm = pm; 4864 } 4865 4866 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) { 4867 params.opmode_notif_used = true; 4868 params.opmode_notif = 4869 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]); 4870 } 4871 4872 /* Include parameters for TDLS peer (will check later) */ 4873 err = nl80211_set_station_tdls(info, ¶ms); 4874 if (err) 4875 return err; 4876 4877 params.vlan = get_vlan(info, rdev); 4878 if (IS_ERR(params.vlan)) 4879 return PTR_ERR(params.vlan); 4880 4881 switch (dev->ieee80211_ptr->iftype) { 4882 case NL80211_IFTYPE_AP: 4883 case NL80211_IFTYPE_AP_VLAN: 4884 case NL80211_IFTYPE_P2P_GO: 4885 case NL80211_IFTYPE_P2P_CLIENT: 4886 case NL80211_IFTYPE_STATION: 4887 case NL80211_IFTYPE_ADHOC: 4888 case NL80211_IFTYPE_MESH_POINT: 4889 break; 4890 default: 4891 err = -EOPNOTSUPP; 4892 goto out_put_vlan; 4893 } 4894 4895 /* driver will call cfg80211_check_station_change() */ 4896 err = rdev_change_station(rdev, dev, mac_addr, ¶ms); 4897 4898 out_put_vlan: 4899 if (params.vlan) 4900 dev_put(params.vlan); 4901 4902 return err; 4903 } 4904 4905 static int nl80211_new_station(struct sk_buff *skb, struct genl_info *info) 4906 { 4907 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 4908 int err; 4909 struct net_device *dev = info->user_ptr[1]; 4910 struct station_parameters params; 4911 u8 *mac_addr = NULL; 4912 u32 auth_assoc = BIT(NL80211_STA_FLAG_AUTHENTICATED) | 4913 BIT(NL80211_STA_FLAG_ASSOCIATED); 4914 4915 memset(¶ms, 0, sizeof(params)); 4916 4917 if (!rdev->ops->add_station) 4918 return -EOPNOTSUPP; 4919 4920 if (!info->attrs[NL80211_ATTR_MAC]) 4921 return -EINVAL; 4922 4923 if (!info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]) 4924 return -EINVAL; 4925 4926 if (!info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]) 4927 return -EINVAL; 4928 4929 if (!info->attrs[NL80211_ATTR_STA_AID] && 4930 !info->attrs[NL80211_ATTR_PEER_AID]) 4931 return -EINVAL; 4932 4933 mac_addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 4934 params.supported_rates = 4935 nla_data(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4936 params.supported_rates_len = 4937 nla_len(info->attrs[NL80211_ATTR_STA_SUPPORTED_RATES]); 4938 params.listen_interval = 4939 nla_get_u16(info->attrs[NL80211_ATTR_STA_LISTEN_INTERVAL]); 4940 4941 if (info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]) { 4942 u8 tmp; 4943 4944 tmp = nla_get_u8(info->attrs[NL80211_ATTR_STA_SUPPORT_P2P_PS]); 4945 if (tmp >= NUM_NL80211_P2P_PS_STATUS) 4946 return -EINVAL; 4947 4948 params.support_p2p_ps = tmp; 4949 } else { 4950 /* 4951 * if not specified, assume it's supported for P2P GO interface, 4952 * and is NOT supported for AP interface 4953 */ 4954 params.support_p2p_ps = 4955 dev->ieee80211_ptr->iftype == NL80211_IFTYPE_P2P_GO; 4956 } 4957 4958 if (info->attrs[NL80211_ATTR_PEER_AID]) 4959 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_PEER_AID]); 4960 else 4961 params.aid = nla_get_u16(info->attrs[NL80211_ATTR_STA_AID]); 4962 if (!params.aid || params.aid > IEEE80211_MAX_AID) 4963 return -EINVAL; 4964 4965 if (info->attrs[NL80211_ATTR_STA_CAPABILITY]) { 4966 params.capability = 4967 nla_get_u16(info->attrs[NL80211_ATTR_STA_CAPABILITY]); 4968 params.sta_modify_mask |= STATION_PARAM_APPLY_CAPABILITY; 4969 } 4970 4971 if (info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]) { 4972 params.ext_capab = 4973 nla_data(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4974 params.ext_capab_len = 4975 nla_len(info->attrs[NL80211_ATTR_STA_EXT_CAPABILITY]); 4976 } 4977 4978 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) 4979 params.ht_capa = 4980 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]); 4981 4982 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) 4983 params.vht_capa = 4984 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]); 4985 4986 if (info->attrs[NL80211_ATTR_OPMODE_NOTIF]) { 4987 params.opmode_notif_used = true; 4988 params.opmode_notif = 4989 nla_get_u8(info->attrs[NL80211_ATTR_OPMODE_NOTIF]); 4990 } 4991 4992 if (info->attrs[NL80211_ATTR_STA_PLINK_ACTION]) { 4993 params.plink_action = 4994 nla_get_u8(info->attrs[NL80211_ATTR_STA_PLINK_ACTION]); 4995 if (params.plink_action >= NUM_NL80211_PLINK_ACTIONS) 4996 return -EINVAL; 4997 } 4998 4999 err = nl80211_parse_sta_channel_info(info, ¶ms); 5000 if (err) 5001 return err; 5002 5003 err = nl80211_parse_sta_wme(info, ¶ms); 5004 if (err) 5005 return err; 5006 5007 if (parse_station_flags(info, dev->ieee80211_ptr->iftype, ¶ms)) 5008 return -EINVAL; 5009 5010 /* HT/VHT requires QoS, but if we don't have that just ignore HT/VHT 5011 * as userspace might just pass through the capabilities from the IEs 5012 * directly, rather than enforcing this restriction and returning an 5013 * error in this case. 5014 */ 5015 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) { 5016 params.ht_capa = NULL; 5017 params.vht_capa = NULL; 5018 } 5019 5020 /* When you run into this, adjust the code below for the new flag */ 5021 BUILD_BUG_ON(NL80211_STA_FLAG_MAX != 7); 5022 5023 switch (dev->ieee80211_ptr->iftype) { 5024 case NL80211_IFTYPE_AP: 5025 case NL80211_IFTYPE_AP_VLAN: 5026 case NL80211_IFTYPE_P2P_GO: 5027 /* ignore WME attributes if iface/sta is not capable */ 5028 if (!(rdev->wiphy.flags & WIPHY_FLAG_AP_UAPSD) || 5029 !(params.sta_flags_set & BIT(NL80211_STA_FLAG_WME))) 5030 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5031 5032 /* TDLS peers cannot be added */ 5033 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) || 5034 info->attrs[NL80211_ATTR_PEER_AID]) 5035 return -EINVAL; 5036 /* but don't bother the driver with it */ 5037 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_TDLS_PEER); 5038 5039 /* allow authenticated/associated only if driver handles it */ 5040 if (!(rdev->wiphy.features & 5041 NL80211_FEATURE_FULL_AP_CLIENT_STATE) && 5042 params.sta_flags_mask & auth_assoc) 5043 return -EINVAL; 5044 5045 /* Older userspace, or userspace wanting to be compatible with 5046 * !NL80211_FEATURE_FULL_AP_CLIENT_STATE, will not set the auth 5047 * and assoc flags in the mask, but assumes the station will be 5048 * added as associated anyway since this was the required driver 5049 * behaviour before NL80211_FEATURE_FULL_AP_CLIENT_STATE was 5050 * introduced. 5051 * In order to not bother drivers with this quirk in the API 5052 * set the flags in both the mask and set for new stations in 5053 * this case. 5054 */ 5055 if (!(params.sta_flags_mask & auth_assoc)) { 5056 params.sta_flags_mask |= auth_assoc; 5057 params.sta_flags_set |= auth_assoc; 5058 } 5059 5060 /* must be last in here for error handling */ 5061 params.vlan = get_vlan(info, rdev); 5062 if (IS_ERR(params.vlan)) 5063 return PTR_ERR(params.vlan); 5064 break; 5065 case NL80211_IFTYPE_MESH_POINT: 5066 /* ignore uAPSD data */ 5067 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5068 5069 /* associated is disallowed */ 5070 if (params.sta_flags_mask & BIT(NL80211_STA_FLAG_ASSOCIATED)) 5071 return -EINVAL; 5072 /* TDLS peers cannot be added */ 5073 if ((params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER)) || 5074 info->attrs[NL80211_ATTR_PEER_AID]) 5075 return -EINVAL; 5076 break; 5077 case NL80211_IFTYPE_STATION: 5078 case NL80211_IFTYPE_P2P_CLIENT: 5079 /* ignore uAPSD data */ 5080 params.sta_modify_mask &= ~STATION_PARAM_APPLY_UAPSD; 5081 5082 /* these are disallowed */ 5083 if (params.sta_flags_mask & 5084 (BIT(NL80211_STA_FLAG_ASSOCIATED) | 5085 BIT(NL80211_STA_FLAG_AUTHENTICATED))) 5086 return -EINVAL; 5087 /* Only TDLS peers can be added */ 5088 if (!(params.sta_flags_set & BIT(NL80211_STA_FLAG_TDLS_PEER))) 5089 return -EINVAL; 5090 /* Can only add if TDLS ... */ 5091 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS)) 5092 return -EOPNOTSUPP; 5093 /* ... with external setup is supported */ 5094 if (!(rdev->wiphy.flags & WIPHY_FLAG_TDLS_EXTERNAL_SETUP)) 5095 return -EOPNOTSUPP; 5096 /* 5097 * Older wpa_supplicant versions always mark the TDLS peer 5098 * as authorized, but it shouldn't yet be. 5099 */ 5100 params.sta_flags_mask &= ~BIT(NL80211_STA_FLAG_AUTHORIZED); 5101 break; 5102 default: 5103 return -EOPNOTSUPP; 5104 } 5105 5106 /* be aware of params.vlan when changing code here */ 5107 5108 err = rdev_add_station(rdev, dev, mac_addr, ¶ms); 5109 5110 if (params.vlan) 5111 dev_put(params.vlan); 5112 return err; 5113 } 5114 5115 static int nl80211_del_station(struct sk_buff *skb, struct genl_info *info) 5116 { 5117 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5118 struct net_device *dev = info->user_ptr[1]; 5119 struct station_del_parameters params; 5120 5121 memset(¶ms, 0, sizeof(params)); 5122 5123 if (info->attrs[NL80211_ATTR_MAC]) 5124 params.mac = nla_data(info->attrs[NL80211_ATTR_MAC]); 5125 5126 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 5127 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP_VLAN && 5128 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT && 5129 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5130 return -EINVAL; 5131 5132 if (!rdev->ops->del_station) 5133 return -EOPNOTSUPP; 5134 5135 if (info->attrs[NL80211_ATTR_MGMT_SUBTYPE]) { 5136 params.subtype = 5137 nla_get_u8(info->attrs[NL80211_ATTR_MGMT_SUBTYPE]); 5138 if (params.subtype != IEEE80211_STYPE_DISASSOC >> 4 && 5139 params.subtype != IEEE80211_STYPE_DEAUTH >> 4) 5140 return -EINVAL; 5141 } else { 5142 /* Default to Deauthentication frame */ 5143 params.subtype = IEEE80211_STYPE_DEAUTH >> 4; 5144 } 5145 5146 if (info->attrs[NL80211_ATTR_REASON_CODE]) { 5147 params.reason_code = 5148 nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 5149 if (params.reason_code == 0) 5150 return -EINVAL; /* 0 is reserved */ 5151 } else { 5152 /* Default to reason code 2 */ 5153 params.reason_code = WLAN_REASON_PREV_AUTH_NOT_VALID; 5154 } 5155 5156 return rdev_del_station(rdev, dev, ¶ms); 5157 } 5158 5159 static int nl80211_send_mpath(struct sk_buff *msg, u32 portid, u32 seq, 5160 int flags, struct net_device *dev, 5161 u8 *dst, u8 *next_hop, 5162 struct mpath_info *pinfo) 5163 { 5164 void *hdr; 5165 struct nlattr *pinfoattr; 5166 5167 hdr = nl80211hdr_put(msg, portid, seq, flags, NL80211_CMD_NEW_MPATH); 5168 if (!hdr) 5169 return -1; 5170 5171 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 5172 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, dst) || 5173 nla_put(msg, NL80211_ATTR_MPATH_NEXT_HOP, ETH_ALEN, next_hop) || 5174 nla_put_u32(msg, NL80211_ATTR_GENERATION, pinfo->generation)) 5175 goto nla_put_failure; 5176 5177 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MPATH_INFO); 5178 if (!pinfoattr) 5179 goto nla_put_failure; 5180 if ((pinfo->filled & MPATH_INFO_FRAME_QLEN) && 5181 nla_put_u32(msg, NL80211_MPATH_INFO_FRAME_QLEN, 5182 pinfo->frame_qlen)) 5183 goto nla_put_failure; 5184 if (((pinfo->filled & MPATH_INFO_SN) && 5185 nla_put_u32(msg, NL80211_MPATH_INFO_SN, pinfo->sn)) || 5186 ((pinfo->filled & MPATH_INFO_METRIC) && 5187 nla_put_u32(msg, NL80211_MPATH_INFO_METRIC, 5188 pinfo->metric)) || 5189 ((pinfo->filled & MPATH_INFO_EXPTIME) && 5190 nla_put_u32(msg, NL80211_MPATH_INFO_EXPTIME, 5191 pinfo->exptime)) || 5192 ((pinfo->filled & MPATH_INFO_FLAGS) && 5193 nla_put_u8(msg, NL80211_MPATH_INFO_FLAGS, 5194 pinfo->flags)) || 5195 ((pinfo->filled & MPATH_INFO_DISCOVERY_TIMEOUT) && 5196 nla_put_u32(msg, NL80211_MPATH_INFO_DISCOVERY_TIMEOUT, 5197 pinfo->discovery_timeout)) || 5198 ((pinfo->filled & MPATH_INFO_DISCOVERY_RETRIES) && 5199 nla_put_u8(msg, NL80211_MPATH_INFO_DISCOVERY_RETRIES, 5200 pinfo->discovery_retries))) 5201 goto nla_put_failure; 5202 5203 nla_nest_end(msg, pinfoattr); 5204 5205 genlmsg_end(msg, hdr); 5206 return 0; 5207 5208 nla_put_failure: 5209 genlmsg_cancel(msg, hdr); 5210 return -EMSGSIZE; 5211 } 5212 5213 static int nl80211_dump_mpath(struct sk_buff *skb, 5214 struct netlink_callback *cb) 5215 { 5216 struct mpath_info pinfo; 5217 struct cfg80211_registered_device *rdev; 5218 struct wireless_dev *wdev; 5219 u8 dst[ETH_ALEN]; 5220 u8 next_hop[ETH_ALEN]; 5221 int path_idx = cb->args[2]; 5222 int err; 5223 5224 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 5225 if (err) 5226 return err; 5227 5228 if (!rdev->ops->dump_mpath) { 5229 err = -EOPNOTSUPP; 5230 goto out_err; 5231 } 5232 5233 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) { 5234 err = -EOPNOTSUPP; 5235 goto out_err; 5236 } 5237 5238 while (1) { 5239 err = rdev_dump_mpath(rdev, wdev->netdev, path_idx, dst, 5240 next_hop, &pinfo); 5241 if (err == -ENOENT) 5242 break; 5243 if (err) 5244 goto out_err; 5245 5246 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid, 5247 cb->nlh->nlmsg_seq, NLM_F_MULTI, 5248 wdev->netdev, dst, next_hop, 5249 &pinfo) < 0) 5250 goto out; 5251 5252 path_idx++; 5253 } 5254 5255 out: 5256 cb->args[2] = path_idx; 5257 err = skb->len; 5258 out_err: 5259 nl80211_finish_wdev_dump(rdev); 5260 return err; 5261 } 5262 5263 static int nl80211_get_mpath(struct sk_buff *skb, struct genl_info *info) 5264 { 5265 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5266 int err; 5267 struct net_device *dev = info->user_ptr[1]; 5268 struct mpath_info pinfo; 5269 struct sk_buff *msg; 5270 u8 *dst = NULL; 5271 u8 next_hop[ETH_ALEN]; 5272 5273 memset(&pinfo, 0, sizeof(pinfo)); 5274 5275 if (!info->attrs[NL80211_ATTR_MAC]) 5276 return -EINVAL; 5277 5278 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5279 5280 if (!rdev->ops->get_mpath) 5281 return -EOPNOTSUPP; 5282 5283 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5284 return -EOPNOTSUPP; 5285 5286 err = rdev_get_mpath(rdev, dev, dst, next_hop, &pinfo); 5287 if (err) 5288 return err; 5289 5290 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5291 if (!msg) 5292 return -ENOMEM; 5293 5294 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0, 5295 dev, dst, next_hop, &pinfo) < 0) { 5296 nlmsg_free(msg); 5297 return -ENOBUFS; 5298 } 5299 5300 return genlmsg_reply(msg, info); 5301 } 5302 5303 static int nl80211_set_mpath(struct sk_buff *skb, struct genl_info *info) 5304 { 5305 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5306 struct net_device *dev = info->user_ptr[1]; 5307 u8 *dst = NULL; 5308 u8 *next_hop = NULL; 5309 5310 if (!info->attrs[NL80211_ATTR_MAC]) 5311 return -EINVAL; 5312 5313 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]) 5314 return -EINVAL; 5315 5316 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5317 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]); 5318 5319 if (!rdev->ops->change_mpath) 5320 return -EOPNOTSUPP; 5321 5322 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5323 return -EOPNOTSUPP; 5324 5325 return rdev_change_mpath(rdev, dev, dst, next_hop); 5326 } 5327 5328 static int nl80211_new_mpath(struct sk_buff *skb, struct genl_info *info) 5329 { 5330 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5331 struct net_device *dev = info->user_ptr[1]; 5332 u8 *dst = NULL; 5333 u8 *next_hop = NULL; 5334 5335 if (!info->attrs[NL80211_ATTR_MAC]) 5336 return -EINVAL; 5337 5338 if (!info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]) 5339 return -EINVAL; 5340 5341 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5342 next_hop = nla_data(info->attrs[NL80211_ATTR_MPATH_NEXT_HOP]); 5343 5344 if (!rdev->ops->add_mpath) 5345 return -EOPNOTSUPP; 5346 5347 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5348 return -EOPNOTSUPP; 5349 5350 return rdev_add_mpath(rdev, dev, dst, next_hop); 5351 } 5352 5353 static int nl80211_del_mpath(struct sk_buff *skb, struct genl_info *info) 5354 { 5355 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5356 struct net_device *dev = info->user_ptr[1]; 5357 u8 *dst = NULL; 5358 5359 if (info->attrs[NL80211_ATTR_MAC]) 5360 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5361 5362 if (!rdev->ops->del_mpath) 5363 return -EOPNOTSUPP; 5364 5365 return rdev_del_mpath(rdev, dev, dst); 5366 } 5367 5368 static int nl80211_get_mpp(struct sk_buff *skb, struct genl_info *info) 5369 { 5370 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5371 int err; 5372 struct net_device *dev = info->user_ptr[1]; 5373 struct mpath_info pinfo; 5374 struct sk_buff *msg; 5375 u8 *dst = NULL; 5376 u8 mpp[ETH_ALEN]; 5377 5378 memset(&pinfo, 0, sizeof(pinfo)); 5379 5380 if (!info->attrs[NL80211_ATTR_MAC]) 5381 return -EINVAL; 5382 5383 dst = nla_data(info->attrs[NL80211_ATTR_MAC]); 5384 5385 if (!rdev->ops->get_mpp) 5386 return -EOPNOTSUPP; 5387 5388 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT) 5389 return -EOPNOTSUPP; 5390 5391 err = rdev_get_mpp(rdev, dev, dst, mpp, &pinfo); 5392 if (err) 5393 return err; 5394 5395 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5396 if (!msg) 5397 return -ENOMEM; 5398 5399 if (nl80211_send_mpath(msg, info->snd_portid, info->snd_seq, 0, 5400 dev, dst, mpp, &pinfo) < 0) { 5401 nlmsg_free(msg); 5402 return -ENOBUFS; 5403 } 5404 5405 return genlmsg_reply(msg, info); 5406 } 5407 5408 static int nl80211_dump_mpp(struct sk_buff *skb, 5409 struct netlink_callback *cb) 5410 { 5411 struct mpath_info pinfo; 5412 struct cfg80211_registered_device *rdev; 5413 struct wireless_dev *wdev; 5414 u8 dst[ETH_ALEN]; 5415 u8 mpp[ETH_ALEN]; 5416 int path_idx = cb->args[2]; 5417 int err; 5418 5419 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 5420 if (err) 5421 return err; 5422 5423 if (!rdev->ops->dump_mpp) { 5424 err = -EOPNOTSUPP; 5425 goto out_err; 5426 } 5427 5428 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) { 5429 err = -EOPNOTSUPP; 5430 goto out_err; 5431 } 5432 5433 while (1) { 5434 err = rdev_dump_mpp(rdev, wdev->netdev, path_idx, dst, 5435 mpp, &pinfo); 5436 if (err == -ENOENT) 5437 break; 5438 if (err) 5439 goto out_err; 5440 5441 if (nl80211_send_mpath(skb, NETLINK_CB(cb->skb).portid, 5442 cb->nlh->nlmsg_seq, NLM_F_MULTI, 5443 wdev->netdev, dst, mpp, 5444 &pinfo) < 0) 5445 goto out; 5446 5447 path_idx++; 5448 } 5449 5450 out: 5451 cb->args[2] = path_idx; 5452 err = skb->len; 5453 out_err: 5454 nl80211_finish_wdev_dump(rdev); 5455 return err; 5456 } 5457 5458 static int nl80211_set_bss(struct sk_buff *skb, struct genl_info *info) 5459 { 5460 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5461 struct net_device *dev = info->user_ptr[1]; 5462 struct wireless_dev *wdev = dev->ieee80211_ptr; 5463 struct bss_parameters params; 5464 int err; 5465 5466 memset(¶ms, 0, sizeof(params)); 5467 /* default to not changing parameters */ 5468 params.use_cts_prot = -1; 5469 params.use_short_preamble = -1; 5470 params.use_short_slot_time = -1; 5471 params.ap_isolate = -1; 5472 params.ht_opmode = -1; 5473 params.p2p_ctwindow = -1; 5474 params.p2p_opp_ps = -1; 5475 5476 if (info->attrs[NL80211_ATTR_BSS_CTS_PROT]) 5477 params.use_cts_prot = 5478 nla_get_u8(info->attrs[NL80211_ATTR_BSS_CTS_PROT]); 5479 if (info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]) 5480 params.use_short_preamble = 5481 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_PREAMBLE]); 5482 if (info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]) 5483 params.use_short_slot_time = 5484 nla_get_u8(info->attrs[NL80211_ATTR_BSS_SHORT_SLOT_TIME]); 5485 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 5486 params.basic_rates = 5487 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 5488 params.basic_rates_len = 5489 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 5490 } 5491 if (info->attrs[NL80211_ATTR_AP_ISOLATE]) 5492 params.ap_isolate = !!nla_get_u8(info->attrs[NL80211_ATTR_AP_ISOLATE]); 5493 if (info->attrs[NL80211_ATTR_BSS_HT_OPMODE]) 5494 params.ht_opmode = 5495 nla_get_u16(info->attrs[NL80211_ATTR_BSS_HT_OPMODE]); 5496 5497 if (info->attrs[NL80211_ATTR_P2P_CTWINDOW]) { 5498 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5499 return -EINVAL; 5500 params.p2p_ctwindow = 5501 nla_get_s8(info->attrs[NL80211_ATTR_P2P_CTWINDOW]); 5502 if (params.p2p_ctwindow < 0) 5503 return -EINVAL; 5504 if (params.p2p_ctwindow != 0 && 5505 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_CTWIN)) 5506 return -EINVAL; 5507 } 5508 5509 if (info->attrs[NL80211_ATTR_P2P_OPPPS]) { 5510 u8 tmp; 5511 5512 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5513 return -EINVAL; 5514 tmp = nla_get_u8(info->attrs[NL80211_ATTR_P2P_OPPPS]); 5515 if (tmp > 1) 5516 return -EINVAL; 5517 params.p2p_opp_ps = tmp; 5518 if (params.p2p_opp_ps && 5519 !(rdev->wiphy.features & NL80211_FEATURE_P2P_GO_OPPPS)) 5520 return -EINVAL; 5521 } 5522 5523 if (!rdev->ops->change_bss) 5524 return -EOPNOTSUPP; 5525 5526 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_AP && 5527 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_GO) 5528 return -EOPNOTSUPP; 5529 5530 wdev_lock(wdev); 5531 err = rdev_change_bss(rdev, dev, ¶ms); 5532 wdev_unlock(wdev); 5533 5534 return err; 5535 } 5536 5537 static int nl80211_req_set_reg(struct sk_buff *skb, struct genl_info *info) 5538 { 5539 char *data = NULL; 5540 bool is_indoor; 5541 enum nl80211_user_reg_hint_type user_reg_hint_type; 5542 u32 owner_nlportid; 5543 5544 /* 5545 * You should only get this when cfg80211 hasn't yet initialized 5546 * completely when built-in to the kernel right between the time 5547 * window between nl80211_init() and regulatory_init(), if that is 5548 * even possible. 5549 */ 5550 if (unlikely(!rcu_access_pointer(cfg80211_regdomain))) 5551 return -EINPROGRESS; 5552 5553 if (info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]) 5554 user_reg_hint_type = 5555 nla_get_u32(info->attrs[NL80211_ATTR_USER_REG_HINT_TYPE]); 5556 else 5557 user_reg_hint_type = NL80211_USER_REG_HINT_USER; 5558 5559 switch (user_reg_hint_type) { 5560 case NL80211_USER_REG_HINT_USER: 5561 case NL80211_USER_REG_HINT_CELL_BASE: 5562 if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) 5563 return -EINVAL; 5564 5565 data = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]); 5566 return regulatory_hint_user(data, user_reg_hint_type); 5567 case NL80211_USER_REG_HINT_INDOOR: 5568 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) { 5569 owner_nlportid = info->snd_portid; 5570 is_indoor = !!info->attrs[NL80211_ATTR_REG_INDOOR]; 5571 } else { 5572 owner_nlportid = 0; 5573 is_indoor = true; 5574 } 5575 5576 return regulatory_hint_indoor(is_indoor, owner_nlportid); 5577 default: 5578 return -EINVAL; 5579 } 5580 } 5581 5582 static int nl80211_get_mesh_config(struct sk_buff *skb, 5583 struct genl_info *info) 5584 { 5585 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5586 struct net_device *dev = info->user_ptr[1]; 5587 struct wireless_dev *wdev = dev->ieee80211_ptr; 5588 struct mesh_config cur_params; 5589 int err = 0; 5590 void *hdr; 5591 struct nlattr *pinfoattr; 5592 struct sk_buff *msg; 5593 5594 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) 5595 return -EOPNOTSUPP; 5596 5597 if (!rdev->ops->get_mesh_config) 5598 return -EOPNOTSUPP; 5599 5600 wdev_lock(wdev); 5601 /* If not connected, get default parameters */ 5602 if (!wdev->mesh_id_len) 5603 memcpy(&cur_params, &default_mesh_config, sizeof(cur_params)); 5604 else 5605 err = rdev_get_mesh_config(rdev, dev, &cur_params); 5606 wdev_unlock(wdev); 5607 5608 if (err) 5609 return err; 5610 5611 /* Draw up a netlink message to send back */ 5612 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 5613 if (!msg) 5614 return -ENOMEM; 5615 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 5616 NL80211_CMD_GET_MESH_CONFIG); 5617 if (!hdr) 5618 goto out; 5619 pinfoattr = nla_nest_start(msg, NL80211_ATTR_MESH_CONFIG); 5620 if (!pinfoattr) 5621 goto nla_put_failure; 5622 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 5623 nla_put_u16(msg, NL80211_MESHCONF_RETRY_TIMEOUT, 5624 cur_params.dot11MeshRetryTimeout) || 5625 nla_put_u16(msg, NL80211_MESHCONF_CONFIRM_TIMEOUT, 5626 cur_params.dot11MeshConfirmTimeout) || 5627 nla_put_u16(msg, NL80211_MESHCONF_HOLDING_TIMEOUT, 5628 cur_params.dot11MeshHoldingTimeout) || 5629 nla_put_u16(msg, NL80211_MESHCONF_MAX_PEER_LINKS, 5630 cur_params.dot11MeshMaxPeerLinks) || 5631 nla_put_u8(msg, NL80211_MESHCONF_MAX_RETRIES, 5632 cur_params.dot11MeshMaxRetries) || 5633 nla_put_u8(msg, NL80211_MESHCONF_TTL, 5634 cur_params.dot11MeshTTL) || 5635 nla_put_u8(msg, NL80211_MESHCONF_ELEMENT_TTL, 5636 cur_params.element_ttl) || 5637 nla_put_u8(msg, NL80211_MESHCONF_AUTO_OPEN_PLINKS, 5638 cur_params.auto_open_plinks) || 5639 nla_put_u32(msg, NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR, 5640 cur_params.dot11MeshNbrOffsetMaxNeighbor) || 5641 nla_put_u8(msg, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES, 5642 cur_params.dot11MeshHWMPmaxPREQretries) || 5643 nla_put_u32(msg, NL80211_MESHCONF_PATH_REFRESH_TIME, 5644 cur_params.path_refresh_time) || 5645 nla_put_u16(msg, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT, 5646 cur_params.min_discovery_timeout) || 5647 nla_put_u32(msg, NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT, 5648 cur_params.dot11MeshHWMPactivePathTimeout) || 5649 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL, 5650 cur_params.dot11MeshHWMPpreqMinInterval) || 5651 nla_put_u16(msg, NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL, 5652 cur_params.dot11MeshHWMPperrMinInterval) || 5653 nla_put_u16(msg, NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME, 5654 cur_params.dot11MeshHWMPnetDiameterTraversalTime) || 5655 nla_put_u8(msg, NL80211_MESHCONF_HWMP_ROOTMODE, 5656 cur_params.dot11MeshHWMPRootMode) || 5657 nla_put_u16(msg, NL80211_MESHCONF_HWMP_RANN_INTERVAL, 5658 cur_params.dot11MeshHWMPRannInterval) || 5659 nla_put_u8(msg, NL80211_MESHCONF_GATE_ANNOUNCEMENTS, 5660 cur_params.dot11MeshGateAnnouncementProtocol) || 5661 nla_put_u8(msg, NL80211_MESHCONF_FORWARDING, 5662 cur_params.dot11MeshForwarding) || 5663 nla_put_u32(msg, NL80211_MESHCONF_RSSI_THRESHOLD, 5664 cur_params.rssi_threshold) || 5665 nla_put_u32(msg, NL80211_MESHCONF_HT_OPMODE, 5666 cur_params.ht_opmode) || 5667 nla_put_u32(msg, NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT, 5668 cur_params.dot11MeshHWMPactivePathToRootTimeout) || 5669 nla_put_u16(msg, NL80211_MESHCONF_HWMP_ROOT_INTERVAL, 5670 cur_params.dot11MeshHWMProotInterval) || 5671 nla_put_u16(msg, NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL, 5672 cur_params.dot11MeshHWMPconfirmationInterval) || 5673 nla_put_u32(msg, NL80211_MESHCONF_POWER_MODE, 5674 cur_params.power_mode) || 5675 nla_put_u16(msg, NL80211_MESHCONF_AWAKE_WINDOW, 5676 cur_params.dot11MeshAwakeWindowDuration) || 5677 nla_put_u32(msg, NL80211_MESHCONF_PLINK_TIMEOUT, 5678 cur_params.plink_timeout)) 5679 goto nla_put_failure; 5680 nla_nest_end(msg, pinfoattr); 5681 genlmsg_end(msg, hdr); 5682 return genlmsg_reply(msg, info); 5683 5684 nla_put_failure: 5685 genlmsg_cancel(msg, hdr); 5686 out: 5687 nlmsg_free(msg); 5688 return -ENOBUFS; 5689 } 5690 5691 static const struct nla_policy nl80211_meshconf_params_policy[NL80211_MESHCONF_ATTR_MAX+1] = { 5692 [NL80211_MESHCONF_RETRY_TIMEOUT] = { .type = NLA_U16 }, 5693 [NL80211_MESHCONF_CONFIRM_TIMEOUT] = { .type = NLA_U16 }, 5694 [NL80211_MESHCONF_HOLDING_TIMEOUT] = { .type = NLA_U16 }, 5695 [NL80211_MESHCONF_MAX_PEER_LINKS] = { .type = NLA_U16 }, 5696 [NL80211_MESHCONF_MAX_RETRIES] = { .type = NLA_U8 }, 5697 [NL80211_MESHCONF_TTL] = { .type = NLA_U8 }, 5698 [NL80211_MESHCONF_ELEMENT_TTL] = { .type = NLA_U8 }, 5699 [NL80211_MESHCONF_AUTO_OPEN_PLINKS] = { .type = NLA_U8 }, 5700 [NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR] = { .type = NLA_U32 }, 5701 [NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES] = { .type = NLA_U8 }, 5702 [NL80211_MESHCONF_PATH_REFRESH_TIME] = { .type = NLA_U32 }, 5703 [NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT] = { .type = NLA_U16 }, 5704 [NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT] = { .type = NLA_U32 }, 5705 [NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL] = { .type = NLA_U16 }, 5706 [NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL] = { .type = NLA_U16 }, 5707 [NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME] = { .type = NLA_U16 }, 5708 [NL80211_MESHCONF_HWMP_ROOTMODE] = { .type = NLA_U8 }, 5709 [NL80211_MESHCONF_HWMP_RANN_INTERVAL] = { .type = NLA_U16 }, 5710 [NL80211_MESHCONF_GATE_ANNOUNCEMENTS] = { .type = NLA_U8 }, 5711 [NL80211_MESHCONF_FORWARDING] = { .type = NLA_U8 }, 5712 [NL80211_MESHCONF_RSSI_THRESHOLD] = { .type = NLA_U32 }, 5713 [NL80211_MESHCONF_HT_OPMODE] = { .type = NLA_U16 }, 5714 [NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT] = { .type = NLA_U32 }, 5715 [NL80211_MESHCONF_HWMP_ROOT_INTERVAL] = { .type = NLA_U16 }, 5716 [NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL] = { .type = NLA_U16 }, 5717 [NL80211_MESHCONF_POWER_MODE] = { .type = NLA_U32 }, 5718 [NL80211_MESHCONF_AWAKE_WINDOW] = { .type = NLA_U16 }, 5719 [NL80211_MESHCONF_PLINK_TIMEOUT] = { .type = NLA_U32 }, 5720 }; 5721 5722 static const struct nla_policy 5723 nl80211_mesh_setup_params_policy[NL80211_MESH_SETUP_ATTR_MAX+1] = { 5724 [NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC] = { .type = NLA_U8 }, 5725 [NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL] = { .type = NLA_U8 }, 5726 [NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC] = { .type = NLA_U8 }, 5727 [NL80211_MESH_SETUP_USERSPACE_AUTH] = { .type = NLA_FLAG }, 5728 [NL80211_MESH_SETUP_AUTH_PROTOCOL] = { .type = NLA_U8 }, 5729 [NL80211_MESH_SETUP_USERSPACE_MPM] = { .type = NLA_FLAG }, 5730 [NL80211_MESH_SETUP_IE] = { .type = NLA_BINARY, 5731 .len = IEEE80211_MAX_DATA_LEN }, 5732 [NL80211_MESH_SETUP_USERSPACE_AMPE] = { .type = NLA_FLAG }, 5733 }; 5734 5735 static int nl80211_check_bool(const struct nlattr *nla, u8 min, u8 max, bool *out) 5736 { 5737 u8 val = nla_get_u8(nla); 5738 if (val < min || val > max) 5739 return -EINVAL; 5740 *out = val; 5741 return 0; 5742 } 5743 5744 static int nl80211_check_u8(const struct nlattr *nla, u8 min, u8 max, u8 *out) 5745 { 5746 u8 val = nla_get_u8(nla); 5747 if (val < min || val > max) 5748 return -EINVAL; 5749 *out = val; 5750 return 0; 5751 } 5752 5753 static int nl80211_check_u16(const struct nlattr *nla, u16 min, u16 max, u16 *out) 5754 { 5755 u16 val = nla_get_u16(nla); 5756 if (val < min || val > max) 5757 return -EINVAL; 5758 *out = val; 5759 return 0; 5760 } 5761 5762 static int nl80211_check_u32(const struct nlattr *nla, u32 min, u32 max, u32 *out) 5763 { 5764 u32 val = nla_get_u32(nla); 5765 if (val < min || val > max) 5766 return -EINVAL; 5767 *out = val; 5768 return 0; 5769 } 5770 5771 static int nl80211_check_s32(const struct nlattr *nla, s32 min, s32 max, s32 *out) 5772 { 5773 s32 val = nla_get_s32(nla); 5774 if (val < min || val > max) 5775 return -EINVAL; 5776 *out = val; 5777 return 0; 5778 } 5779 5780 static int nl80211_check_power_mode(const struct nlattr *nla, 5781 enum nl80211_mesh_power_mode min, 5782 enum nl80211_mesh_power_mode max, 5783 enum nl80211_mesh_power_mode *out) 5784 { 5785 u32 val = nla_get_u32(nla); 5786 if (val < min || val > max) 5787 return -EINVAL; 5788 *out = val; 5789 return 0; 5790 } 5791 5792 static int nl80211_parse_mesh_config(struct genl_info *info, 5793 struct mesh_config *cfg, 5794 u32 *mask_out) 5795 { 5796 struct nlattr *tb[NL80211_MESHCONF_ATTR_MAX + 1]; 5797 u32 mask = 0; 5798 u16 ht_opmode; 5799 5800 #define FILL_IN_MESH_PARAM_IF_SET(tb, cfg, param, min, max, mask, attr, fn) \ 5801 do { \ 5802 if (tb[attr]) { \ 5803 if (fn(tb[attr], min, max, &cfg->param)) \ 5804 return -EINVAL; \ 5805 mask |= (1 << (attr - 1)); \ 5806 } \ 5807 } while (0) 5808 5809 if (!info->attrs[NL80211_ATTR_MESH_CONFIG]) 5810 return -EINVAL; 5811 if (nla_parse_nested(tb, NL80211_MESHCONF_ATTR_MAX, 5812 info->attrs[NL80211_ATTR_MESH_CONFIG], 5813 nl80211_meshconf_params_policy)) 5814 return -EINVAL; 5815 5816 /* This makes sure that there aren't more than 32 mesh config 5817 * parameters (otherwise our bitfield scheme would not work.) */ 5818 BUILD_BUG_ON(NL80211_MESHCONF_ATTR_MAX > 32); 5819 5820 /* Fill in the params struct */ 5821 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshRetryTimeout, 1, 255, 5822 mask, NL80211_MESHCONF_RETRY_TIMEOUT, 5823 nl80211_check_u16); 5824 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshConfirmTimeout, 1, 255, 5825 mask, NL80211_MESHCONF_CONFIRM_TIMEOUT, 5826 nl80211_check_u16); 5827 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHoldingTimeout, 1, 255, 5828 mask, NL80211_MESHCONF_HOLDING_TIMEOUT, 5829 nl80211_check_u16); 5830 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxPeerLinks, 0, 255, 5831 mask, NL80211_MESHCONF_MAX_PEER_LINKS, 5832 nl80211_check_u16); 5833 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshMaxRetries, 0, 16, 5834 mask, NL80211_MESHCONF_MAX_RETRIES, 5835 nl80211_check_u8); 5836 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshTTL, 1, 255, 5837 mask, NL80211_MESHCONF_TTL, nl80211_check_u8); 5838 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, element_ttl, 1, 255, 5839 mask, NL80211_MESHCONF_ELEMENT_TTL, 5840 nl80211_check_u8); 5841 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, auto_open_plinks, 0, 1, 5842 mask, NL80211_MESHCONF_AUTO_OPEN_PLINKS, 5843 nl80211_check_bool); 5844 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshNbrOffsetMaxNeighbor, 5845 1, 255, mask, 5846 NL80211_MESHCONF_SYNC_OFFSET_MAX_NEIGHBOR, 5847 nl80211_check_u32); 5848 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPmaxPREQretries, 0, 255, 5849 mask, NL80211_MESHCONF_HWMP_MAX_PREQ_RETRIES, 5850 nl80211_check_u8); 5851 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, path_refresh_time, 1, 65535, 5852 mask, NL80211_MESHCONF_PATH_REFRESH_TIME, 5853 nl80211_check_u32); 5854 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, min_discovery_timeout, 1, 65535, 5855 mask, NL80211_MESHCONF_MIN_DISCOVERY_TIMEOUT, 5856 nl80211_check_u16); 5857 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathTimeout, 5858 1, 65535, mask, 5859 NL80211_MESHCONF_HWMP_ACTIVE_PATH_TIMEOUT, 5860 nl80211_check_u32); 5861 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPpreqMinInterval, 5862 1, 65535, mask, 5863 NL80211_MESHCONF_HWMP_PREQ_MIN_INTERVAL, 5864 nl80211_check_u16); 5865 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPperrMinInterval, 5866 1, 65535, mask, 5867 NL80211_MESHCONF_HWMP_PERR_MIN_INTERVAL, 5868 nl80211_check_u16); 5869 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5870 dot11MeshHWMPnetDiameterTraversalTime, 5871 1, 65535, mask, 5872 NL80211_MESHCONF_HWMP_NET_DIAM_TRVS_TIME, 5873 nl80211_check_u16); 5874 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRootMode, 0, 4, 5875 mask, NL80211_MESHCONF_HWMP_ROOTMODE, 5876 nl80211_check_u8); 5877 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPRannInterval, 1, 65535, 5878 mask, NL80211_MESHCONF_HWMP_RANN_INTERVAL, 5879 nl80211_check_u16); 5880 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5881 dot11MeshGateAnnouncementProtocol, 0, 1, 5882 mask, NL80211_MESHCONF_GATE_ANNOUNCEMENTS, 5883 nl80211_check_bool); 5884 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshForwarding, 0, 1, 5885 mask, NL80211_MESHCONF_FORWARDING, 5886 nl80211_check_bool); 5887 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, rssi_threshold, -255, 0, 5888 mask, NL80211_MESHCONF_RSSI_THRESHOLD, 5889 nl80211_check_s32); 5890 /* 5891 * Check HT operation mode based on 5892 * IEEE 802.11 2012 8.4.2.59 HT Operation element. 5893 */ 5894 if (tb[NL80211_MESHCONF_HT_OPMODE]) { 5895 ht_opmode = nla_get_u16(tb[NL80211_MESHCONF_HT_OPMODE]); 5896 5897 if (ht_opmode & ~(IEEE80211_HT_OP_MODE_PROTECTION | 5898 IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT | 5899 IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5900 return -EINVAL; 5901 5902 if ((ht_opmode & IEEE80211_HT_OP_MODE_NON_GF_STA_PRSNT) && 5903 (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5904 return -EINVAL; 5905 5906 switch (ht_opmode & IEEE80211_HT_OP_MODE_PROTECTION) { 5907 case IEEE80211_HT_OP_MODE_PROTECTION_NONE: 5908 case IEEE80211_HT_OP_MODE_PROTECTION_20MHZ: 5909 if (ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT) 5910 return -EINVAL; 5911 break; 5912 case IEEE80211_HT_OP_MODE_PROTECTION_NONMEMBER: 5913 case IEEE80211_HT_OP_MODE_PROTECTION_NONHT_MIXED: 5914 if (!(ht_opmode & IEEE80211_HT_OP_MODE_NON_HT_STA_PRSNT)) 5915 return -EINVAL; 5916 break; 5917 } 5918 cfg->ht_opmode = ht_opmode; 5919 mask |= (1 << (NL80211_MESHCONF_HT_OPMODE - 1)); 5920 } 5921 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMPactivePathToRootTimeout, 5922 1, 65535, mask, 5923 NL80211_MESHCONF_HWMP_PATH_TO_ROOT_TIMEOUT, 5924 nl80211_check_u32); 5925 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshHWMProotInterval, 1, 65535, 5926 mask, NL80211_MESHCONF_HWMP_ROOT_INTERVAL, 5927 nl80211_check_u16); 5928 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, 5929 dot11MeshHWMPconfirmationInterval, 5930 1, 65535, mask, 5931 NL80211_MESHCONF_HWMP_CONFIRMATION_INTERVAL, 5932 nl80211_check_u16); 5933 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, power_mode, 5934 NL80211_MESH_POWER_ACTIVE, 5935 NL80211_MESH_POWER_MAX, 5936 mask, NL80211_MESHCONF_POWER_MODE, 5937 nl80211_check_power_mode); 5938 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, dot11MeshAwakeWindowDuration, 5939 0, 65535, mask, 5940 NL80211_MESHCONF_AWAKE_WINDOW, nl80211_check_u16); 5941 FILL_IN_MESH_PARAM_IF_SET(tb, cfg, plink_timeout, 0, 0xffffffff, 5942 mask, NL80211_MESHCONF_PLINK_TIMEOUT, 5943 nl80211_check_u32); 5944 if (mask_out) 5945 *mask_out = mask; 5946 5947 return 0; 5948 5949 #undef FILL_IN_MESH_PARAM_IF_SET 5950 } 5951 5952 static int nl80211_parse_mesh_setup(struct genl_info *info, 5953 struct mesh_setup *setup) 5954 { 5955 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 5956 struct nlattr *tb[NL80211_MESH_SETUP_ATTR_MAX + 1]; 5957 5958 if (!info->attrs[NL80211_ATTR_MESH_SETUP]) 5959 return -EINVAL; 5960 if (nla_parse_nested(tb, NL80211_MESH_SETUP_ATTR_MAX, 5961 info->attrs[NL80211_ATTR_MESH_SETUP], 5962 nl80211_mesh_setup_params_policy)) 5963 return -EINVAL; 5964 5965 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC]) 5966 setup->sync_method = 5967 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_SYNC])) ? 5968 IEEE80211_SYNC_METHOD_VENDOR : 5969 IEEE80211_SYNC_METHOD_NEIGHBOR_OFFSET; 5970 5971 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL]) 5972 setup->path_sel_proto = 5973 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_PATH_SEL])) ? 5974 IEEE80211_PATH_PROTOCOL_VENDOR : 5975 IEEE80211_PATH_PROTOCOL_HWMP; 5976 5977 if (tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC]) 5978 setup->path_metric = 5979 (nla_get_u8(tb[NL80211_MESH_SETUP_ENABLE_VENDOR_METRIC])) ? 5980 IEEE80211_PATH_METRIC_VENDOR : 5981 IEEE80211_PATH_METRIC_AIRTIME; 5982 5983 if (tb[NL80211_MESH_SETUP_IE]) { 5984 struct nlattr *ieattr = 5985 tb[NL80211_MESH_SETUP_IE]; 5986 if (!is_valid_ie_attr(ieattr)) 5987 return -EINVAL; 5988 setup->ie = nla_data(ieattr); 5989 setup->ie_len = nla_len(ieattr); 5990 } 5991 if (tb[NL80211_MESH_SETUP_USERSPACE_MPM] && 5992 !(rdev->wiphy.features & NL80211_FEATURE_USERSPACE_MPM)) 5993 return -EINVAL; 5994 setup->user_mpm = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_MPM]); 5995 setup->is_authenticated = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AUTH]); 5996 setup->is_secure = nla_get_flag(tb[NL80211_MESH_SETUP_USERSPACE_AMPE]); 5997 if (setup->is_secure) 5998 setup->user_mpm = true; 5999 6000 if (tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]) { 6001 if (!setup->user_mpm) 6002 return -EINVAL; 6003 setup->auth_id = 6004 nla_get_u8(tb[NL80211_MESH_SETUP_AUTH_PROTOCOL]); 6005 } 6006 6007 return 0; 6008 } 6009 6010 static int nl80211_update_mesh_config(struct sk_buff *skb, 6011 struct genl_info *info) 6012 { 6013 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6014 struct net_device *dev = info->user_ptr[1]; 6015 struct wireless_dev *wdev = dev->ieee80211_ptr; 6016 struct mesh_config cfg; 6017 u32 mask; 6018 int err; 6019 6020 if (wdev->iftype != NL80211_IFTYPE_MESH_POINT) 6021 return -EOPNOTSUPP; 6022 6023 if (!rdev->ops->update_mesh_config) 6024 return -EOPNOTSUPP; 6025 6026 err = nl80211_parse_mesh_config(info, &cfg, &mask); 6027 if (err) 6028 return err; 6029 6030 wdev_lock(wdev); 6031 if (!wdev->mesh_id_len) 6032 err = -ENOLINK; 6033 6034 if (!err) 6035 err = rdev_update_mesh_config(rdev, dev, mask, &cfg); 6036 6037 wdev_unlock(wdev); 6038 6039 return err; 6040 } 6041 6042 static int nl80211_put_regdom(const struct ieee80211_regdomain *regdom, 6043 struct sk_buff *msg) 6044 { 6045 struct nlattr *nl_reg_rules; 6046 unsigned int i; 6047 6048 if (nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, regdom->alpha2) || 6049 (regdom->dfs_region && 6050 nla_put_u8(msg, NL80211_ATTR_DFS_REGION, regdom->dfs_region))) 6051 goto nla_put_failure; 6052 6053 nl_reg_rules = nla_nest_start(msg, NL80211_ATTR_REG_RULES); 6054 if (!nl_reg_rules) 6055 goto nla_put_failure; 6056 6057 for (i = 0; i < regdom->n_reg_rules; i++) { 6058 struct nlattr *nl_reg_rule; 6059 const struct ieee80211_reg_rule *reg_rule; 6060 const struct ieee80211_freq_range *freq_range; 6061 const struct ieee80211_power_rule *power_rule; 6062 unsigned int max_bandwidth_khz; 6063 6064 reg_rule = ®dom->reg_rules[i]; 6065 freq_range = ®_rule->freq_range; 6066 power_rule = ®_rule->power_rule; 6067 6068 nl_reg_rule = nla_nest_start(msg, i); 6069 if (!nl_reg_rule) 6070 goto nla_put_failure; 6071 6072 max_bandwidth_khz = freq_range->max_bandwidth_khz; 6073 if (!max_bandwidth_khz) 6074 max_bandwidth_khz = reg_get_max_bandwidth(regdom, 6075 reg_rule); 6076 6077 if (nla_put_u32(msg, NL80211_ATTR_REG_RULE_FLAGS, 6078 reg_rule->flags) || 6079 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_START, 6080 freq_range->start_freq_khz) || 6081 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_END, 6082 freq_range->end_freq_khz) || 6083 nla_put_u32(msg, NL80211_ATTR_FREQ_RANGE_MAX_BW, 6084 max_bandwidth_khz) || 6085 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN, 6086 power_rule->max_antenna_gain) || 6087 nla_put_u32(msg, NL80211_ATTR_POWER_RULE_MAX_EIRP, 6088 power_rule->max_eirp) || 6089 nla_put_u32(msg, NL80211_ATTR_DFS_CAC_TIME, 6090 reg_rule->dfs_cac_ms)) 6091 goto nla_put_failure; 6092 6093 nla_nest_end(msg, nl_reg_rule); 6094 } 6095 6096 nla_nest_end(msg, nl_reg_rules); 6097 return 0; 6098 6099 nla_put_failure: 6100 return -EMSGSIZE; 6101 } 6102 6103 static int nl80211_get_reg_do(struct sk_buff *skb, struct genl_info *info) 6104 { 6105 const struct ieee80211_regdomain *regdom = NULL; 6106 struct cfg80211_registered_device *rdev; 6107 struct wiphy *wiphy = NULL; 6108 struct sk_buff *msg; 6109 void *hdr; 6110 6111 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 6112 if (!msg) 6113 return -ENOBUFS; 6114 6115 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 6116 NL80211_CMD_GET_REG); 6117 if (!hdr) 6118 goto put_failure; 6119 6120 if (info->attrs[NL80211_ATTR_WIPHY]) { 6121 bool self_managed; 6122 6123 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info); 6124 if (IS_ERR(rdev)) { 6125 nlmsg_free(msg); 6126 return PTR_ERR(rdev); 6127 } 6128 6129 wiphy = &rdev->wiphy; 6130 self_managed = wiphy->regulatory_flags & 6131 REGULATORY_WIPHY_SELF_MANAGED; 6132 regdom = get_wiphy_regdom(wiphy); 6133 6134 /* a self-managed-reg device must have a private regdom */ 6135 if (WARN_ON(!regdom && self_managed)) { 6136 nlmsg_free(msg); 6137 return -EINVAL; 6138 } 6139 6140 if (regdom && 6141 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 6142 goto nla_put_failure; 6143 } 6144 6145 if (!wiphy && reg_last_request_cell_base() && 6146 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE, 6147 NL80211_USER_REG_HINT_CELL_BASE)) 6148 goto nla_put_failure; 6149 6150 rcu_read_lock(); 6151 6152 if (!regdom) 6153 regdom = rcu_dereference(cfg80211_regdomain); 6154 6155 if (nl80211_put_regdom(regdom, msg)) 6156 goto nla_put_failure_rcu; 6157 6158 rcu_read_unlock(); 6159 6160 genlmsg_end(msg, hdr); 6161 return genlmsg_reply(msg, info); 6162 6163 nla_put_failure_rcu: 6164 rcu_read_unlock(); 6165 nla_put_failure: 6166 genlmsg_cancel(msg, hdr); 6167 put_failure: 6168 nlmsg_free(msg); 6169 return -EMSGSIZE; 6170 } 6171 6172 static int nl80211_send_regdom(struct sk_buff *msg, struct netlink_callback *cb, 6173 u32 seq, int flags, struct wiphy *wiphy, 6174 const struct ieee80211_regdomain *regdom) 6175 { 6176 void *hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags, 6177 NL80211_CMD_GET_REG); 6178 6179 if (!hdr) 6180 return -1; 6181 6182 genl_dump_check_consistent(cb, hdr, &nl80211_fam); 6183 6184 if (nl80211_put_regdom(regdom, msg)) 6185 goto nla_put_failure; 6186 6187 if (!wiphy && reg_last_request_cell_base() && 6188 nla_put_u32(msg, NL80211_ATTR_USER_REG_HINT_TYPE, 6189 NL80211_USER_REG_HINT_CELL_BASE)) 6190 goto nla_put_failure; 6191 6192 if (wiphy && 6193 nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 6194 goto nla_put_failure; 6195 6196 if (wiphy && wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 6197 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 6198 goto nla_put_failure; 6199 6200 genlmsg_end(msg, hdr); 6201 return 0; 6202 6203 nla_put_failure: 6204 genlmsg_cancel(msg, hdr); 6205 return -EMSGSIZE; 6206 } 6207 6208 static int nl80211_get_reg_dump(struct sk_buff *skb, 6209 struct netlink_callback *cb) 6210 { 6211 const struct ieee80211_regdomain *regdom = NULL; 6212 struct cfg80211_registered_device *rdev; 6213 int err, reg_idx, start = cb->args[2]; 6214 6215 rtnl_lock(); 6216 6217 if (cfg80211_regdomain && start == 0) { 6218 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq, 6219 NLM_F_MULTI, NULL, 6220 rtnl_dereference(cfg80211_regdomain)); 6221 if (err < 0) 6222 goto out_err; 6223 } 6224 6225 /* the global regdom is idx 0 */ 6226 reg_idx = 1; 6227 list_for_each_entry(rdev, &cfg80211_rdev_list, list) { 6228 regdom = get_wiphy_regdom(&rdev->wiphy); 6229 if (!regdom) 6230 continue; 6231 6232 if (++reg_idx <= start) 6233 continue; 6234 6235 err = nl80211_send_regdom(skb, cb, cb->nlh->nlmsg_seq, 6236 NLM_F_MULTI, &rdev->wiphy, regdom); 6237 if (err < 0) { 6238 reg_idx--; 6239 break; 6240 } 6241 } 6242 6243 cb->args[2] = reg_idx; 6244 err = skb->len; 6245 out_err: 6246 rtnl_unlock(); 6247 return err; 6248 } 6249 6250 #ifdef CONFIG_CFG80211_CRDA_SUPPORT 6251 static const struct nla_policy reg_rule_policy[NL80211_REG_RULE_ATTR_MAX + 1] = { 6252 [NL80211_ATTR_REG_RULE_FLAGS] = { .type = NLA_U32 }, 6253 [NL80211_ATTR_FREQ_RANGE_START] = { .type = NLA_U32 }, 6254 [NL80211_ATTR_FREQ_RANGE_END] = { .type = NLA_U32 }, 6255 [NL80211_ATTR_FREQ_RANGE_MAX_BW] = { .type = NLA_U32 }, 6256 [NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN] = { .type = NLA_U32 }, 6257 [NL80211_ATTR_POWER_RULE_MAX_EIRP] = { .type = NLA_U32 }, 6258 [NL80211_ATTR_DFS_CAC_TIME] = { .type = NLA_U32 }, 6259 }; 6260 6261 static int parse_reg_rule(struct nlattr *tb[], 6262 struct ieee80211_reg_rule *reg_rule) 6263 { 6264 struct ieee80211_freq_range *freq_range = ®_rule->freq_range; 6265 struct ieee80211_power_rule *power_rule = ®_rule->power_rule; 6266 6267 if (!tb[NL80211_ATTR_REG_RULE_FLAGS]) 6268 return -EINVAL; 6269 if (!tb[NL80211_ATTR_FREQ_RANGE_START]) 6270 return -EINVAL; 6271 if (!tb[NL80211_ATTR_FREQ_RANGE_END]) 6272 return -EINVAL; 6273 if (!tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]) 6274 return -EINVAL; 6275 if (!tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]) 6276 return -EINVAL; 6277 6278 reg_rule->flags = nla_get_u32(tb[NL80211_ATTR_REG_RULE_FLAGS]); 6279 6280 freq_range->start_freq_khz = 6281 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_START]); 6282 freq_range->end_freq_khz = 6283 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_END]); 6284 freq_range->max_bandwidth_khz = 6285 nla_get_u32(tb[NL80211_ATTR_FREQ_RANGE_MAX_BW]); 6286 6287 power_rule->max_eirp = 6288 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_EIRP]); 6289 6290 if (tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]) 6291 power_rule->max_antenna_gain = 6292 nla_get_u32(tb[NL80211_ATTR_POWER_RULE_MAX_ANT_GAIN]); 6293 6294 if (tb[NL80211_ATTR_DFS_CAC_TIME]) 6295 reg_rule->dfs_cac_ms = 6296 nla_get_u32(tb[NL80211_ATTR_DFS_CAC_TIME]); 6297 6298 return 0; 6299 } 6300 6301 static int nl80211_set_reg(struct sk_buff *skb, struct genl_info *info) 6302 { 6303 struct nlattr *tb[NL80211_REG_RULE_ATTR_MAX + 1]; 6304 struct nlattr *nl_reg_rule; 6305 char *alpha2; 6306 int rem_reg_rules, r; 6307 u32 num_rules = 0, rule_idx = 0, size_of_regd; 6308 enum nl80211_dfs_regions dfs_region = NL80211_DFS_UNSET; 6309 struct ieee80211_regdomain *rd; 6310 6311 if (!info->attrs[NL80211_ATTR_REG_ALPHA2]) 6312 return -EINVAL; 6313 6314 if (!info->attrs[NL80211_ATTR_REG_RULES]) 6315 return -EINVAL; 6316 6317 alpha2 = nla_data(info->attrs[NL80211_ATTR_REG_ALPHA2]); 6318 6319 if (info->attrs[NL80211_ATTR_DFS_REGION]) 6320 dfs_region = nla_get_u8(info->attrs[NL80211_ATTR_DFS_REGION]); 6321 6322 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES], 6323 rem_reg_rules) { 6324 num_rules++; 6325 if (num_rules > NL80211_MAX_SUPP_REG_RULES) 6326 return -EINVAL; 6327 } 6328 6329 if (!reg_is_valid_request(alpha2)) 6330 return -EINVAL; 6331 6332 size_of_regd = sizeof(struct ieee80211_regdomain) + 6333 num_rules * sizeof(struct ieee80211_reg_rule); 6334 6335 rd = kzalloc(size_of_regd, GFP_KERNEL); 6336 if (!rd) 6337 return -ENOMEM; 6338 6339 rd->n_reg_rules = num_rules; 6340 rd->alpha2[0] = alpha2[0]; 6341 rd->alpha2[1] = alpha2[1]; 6342 6343 /* 6344 * Disable DFS master mode if the DFS region was 6345 * not supported or known on this kernel. 6346 */ 6347 if (reg_supported_dfs_region(dfs_region)) 6348 rd->dfs_region = dfs_region; 6349 6350 nla_for_each_nested(nl_reg_rule, info->attrs[NL80211_ATTR_REG_RULES], 6351 rem_reg_rules) { 6352 r = nla_parse_nested(tb, NL80211_REG_RULE_ATTR_MAX, 6353 nl_reg_rule, reg_rule_policy); 6354 if (r) 6355 goto bad_reg; 6356 r = parse_reg_rule(tb, &rd->reg_rules[rule_idx]); 6357 if (r) 6358 goto bad_reg; 6359 6360 rule_idx++; 6361 6362 if (rule_idx > NL80211_MAX_SUPP_REG_RULES) { 6363 r = -EINVAL; 6364 goto bad_reg; 6365 } 6366 } 6367 6368 /* set_regdom takes ownership of rd */ 6369 return set_regdom(rd, REGD_SOURCE_CRDA); 6370 bad_reg: 6371 kfree(rd); 6372 return r; 6373 } 6374 #endif /* CONFIG_CFG80211_CRDA_SUPPORT */ 6375 6376 static int validate_scan_freqs(struct nlattr *freqs) 6377 { 6378 struct nlattr *attr1, *attr2; 6379 int n_channels = 0, tmp1, tmp2; 6380 6381 nla_for_each_nested(attr1, freqs, tmp1) { 6382 n_channels++; 6383 /* 6384 * Some hardware has a limited channel list for 6385 * scanning, and it is pretty much nonsensical 6386 * to scan for a channel twice, so disallow that 6387 * and don't require drivers to check that the 6388 * channel list they get isn't longer than what 6389 * they can scan, as long as they can scan all 6390 * the channels they registered at once. 6391 */ 6392 nla_for_each_nested(attr2, freqs, tmp2) 6393 if (attr1 != attr2 && 6394 nla_get_u32(attr1) == nla_get_u32(attr2)) 6395 return 0; 6396 } 6397 6398 return n_channels; 6399 } 6400 6401 static bool is_band_valid(struct wiphy *wiphy, enum nl80211_band b) 6402 { 6403 return b < NUM_NL80211_BANDS && wiphy->bands[b]; 6404 } 6405 6406 static int parse_bss_select(struct nlattr *nla, struct wiphy *wiphy, 6407 struct cfg80211_bss_selection *bss_select) 6408 { 6409 struct nlattr *attr[NL80211_BSS_SELECT_ATTR_MAX + 1]; 6410 struct nlattr *nest; 6411 int err; 6412 bool found = false; 6413 int i; 6414 6415 /* only process one nested attribute */ 6416 nest = nla_data(nla); 6417 if (!nla_ok(nest, nla_len(nest))) 6418 return -EINVAL; 6419 6420 err = nla_parse_nested(attr, NL80211_BSS_SELECT_ATTR_MAX, nest, 6421 nl80211_bss_select_policy); 6422 if (err) 6423 return err; 6424 6425 /* only one attribute may be given */ 6426 for (i = 0; i <= NL80211_BSS_SELECT_ATTR_MAX; i++) { 6427 if (attr[i]) { 6428 if (found) 6429 return -EINVAL; 6430 found = true; 6431 } 6432 } 6433 6434 bss_select->behaviour = __NL80211_BSS_SELECT_ATTR_INVALID; 6435 6436 if (attr[NL80211_BSS_SELECT_ATTR_RSSI]) 6437 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI; 6438 6439 if (attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]) { 6440 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_BAND_PREF; 6441 bss_select->param.band_pref = 6442 nla_get_u32(attr[NL80211_BSS_SELECT_ATTR_BAND_PREF]); 6443 if (!is_band_valid(wiphy, bss_select->param.band_pref)) 6444 return -EINVAL; 6445 } 6446 6447 if (attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]) { 6448 struct nl80211_bss_select_rssi_adjust *adj_param; 6449 6450 adj_param = nla_data(attr[NL80211_BSS_SELECT_ATTR_RSSI_ADJUST]); 6451 bss_select->behaviour = NL80211_BSS_SELECT_ATTR_RSSI_ADJUST; 6452 bss_select->param.adjust.band = adj_param->band; 6453 bss_select->param.adjust.delta = adj_param->delta; 6454 if (!is_band_valid(wiphy, bss_select->param.adjust.band)) 6455 return -EINVAL; 6456 } 6457 6458 /* user-space did not provide behaviour attribute */ 6459 if (bss_select->behaviour == __NL80211_BSS_SELECT_ATTR_INVALID) 6460 return -EINVAL; 6461 6462 if (!(wiphy->bss_select_support & BIT(bss_select->behaviour))) 6463 return -EINVAL; 6464 6465 return 0; 6466 } 6467 6468 static int nl80211_parse_random_mac(struct nlattr **attrs, 6469 u8 *mac_addr, u8 *mac_addr_mask) 6470 { 6471 int i; 6472 6473 if (!attrs[NL80211_ATTR_MAC] && !attrs[NL80211_ATTR_MAC_MASK]) { 6474 eth_zero_addr(mac_addr); 6475 eth_zero_addr(mac_addr_mask); 6476 mac_addr[0] = 0x2; 6477 mac_addr_mask[0] = 0x3; 6478 6479 return 0; 6480 } 6481 6482 /* need both or none */ 6483 if (!attrs[NL80211_ATTR_MAC] || !attrs[NL80211_ATTR_MAC_MASK]) 6484 return -EINVAL; 6485 6486 memcpy(mac_addr, nla_data(attrs[NL80211_ATTR_MAC]), ETH_ALEN); 6487 memcpy(mac_addr_mask, nla_data(attrs[NL80211_ATTR_MAC_MASK]), ETH_ALEN); 6488 6489 /* don't allow or configure an mcast address */ 6490 if (!is_multicast_ether_addr(mac_addr_mask) || 6491 is_multicast_ether_addr(mac_addr)) 6492 return -EINVAL; 6493 6494 /* 6495 * allow users to pass a MAC address that has bits set outside 6496 * of the mask, but don't bother drivers with having to deal 6497 * with such bits 6498 */ 6499 for (i = 0; i < ETH_ALEN; i++) 6500 mac_addr[i] &= mac_addr_mask[i]; 6501 6502 return 0; 6503 } 6504 6505 static int nl80211_trigger_scan(struct sk_buff *skb, struct genl_info *info) 6506 { 6507 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6508 struct wireless_dev *wdev = info->user_ptr[1]; 6509 struct cfg80211_scan_request *request; 6510 struct nlattr *attr; 6511 struct wiphy *wiphy; 6512 int err, tmp, n_ssids = 0, n_channels, i; 6513 size_t ie_len; 6514 6515 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 6516 return -EINVAL; 6517 6518 wiphy = &rdev->wiphy; 6519 6520 if (wdev->iftype == NL80211_IFTYPE_NAN) 6521 return -EOPNOTSUPP; 6522 6523 if (!rdev->ops->scan) 6524 return -EOPNOTSUPP; 6525 6526 if (rdev->scan_req || rdev->scan_msg) { 6527 err = -EBUSY; 6528 goto unlock; 6529 } 6530 6531 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6532 n_channels = validate_scan_freqs( 6533 info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]); 6534 if (!n_channels) { 6535 err = -EINVAL; 6536 goto unlock; 6537 } 6538 } else { 6539 n_channels = ieee80211_get_num_supported_channels(wiphy); 6540 } 6541 6542 if (info->attrs[NL80211_ATTR_SCAN_SSIDS]) 6543 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) 6544 n_ssids++; 6545 6546 if (n_ssids > wiphy->max_scan_ssids) { 6547 err = -EINVAL; 6548 goto unlock; 6549 } 6550 6551 if (info->attrs[NL80211_ATTR_IE]) 6552 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 6553 else 6554 ie_len = 0; 6555 6556 if (ie_len > wiphy->max_scan_ie_len) { 6557 err = -EINVAL; 6558 goto unlock; 6559 } 6560 6561 request = kzalloc(sizeof(*request) 6562 + sizeof(*request->ssids) * n_ssids 6563 + sizeof(*request->channels) * n_channels 6564 + ie_len, GFP_KERNEL); 6565 if (!request) { 6566 err = -ENOMEM; 6567 goto unlock; 6568 } 6569 6570 if (n_ssids) 6571 request->ssids = (void *)&request->channels[n_channels]; 6572 request->n_ssids = n_ssids; 6573 if (ie_len) { 6574 if (n_ssids) 6575 request->ie = (void *)(request->ssids + n_ssids); 6576 else 6577 request->ie = (void *)(request->channels + n_channels); 6578 } 6579 6580 i = 0; 6581 if (info->attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6582 /* user specified, bail out if channel not found */ 6583 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_FREQUENCIES], tmp) { 6584 struct ieee80211_channel *chan; 6585 6586 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr)); 6587 6588 if (!chan) { 6589 err = -EINVAL; 6590 goto out_free; 6591 } 6592 6593 /* ignore disabled channels */ 6594 if (chan->flags & IEEE80211_CHAN_DISABLED) 6595 continue; 6596 6597 request->channels[i] = chan; 6598 i++; 6599 } 6600 } else { 6601 enum nl80211_band band; 6602 6603 /* all channels */ 6604 for (band = 0; band < NUM_NL80211_BANDS; band++) { 6605 int j; 6606 6607 if (!wiphy->bands[band]) 6608 continue; 6609 for (j = 0; j < wiphy->bands[band]->n_channels; j++) { 6610 struct ieee80211_channel *chan; 6611 6612 chan = &wiphy->bands[band]->channels[j]; 6613 6614 if (chan->flags & IEEE80211_CHAN_DISABLED) 6615 continue; 6616 6617 request->channels[i] = chan; 6618 i++; 6619 } 6620 } 6621 } 6622 6623 if (!i) { 6624 err = -EINVAL; 6625 goto out_free; 6626 } 6627 6628 request->n_channels = i; 6629 6630 i = 0; 6631 if (n_ssids) { 6632 nla_for_each_nested(attr, info->attrs[NL80211_ATTR_SCAN_SSIDS], tmp) { 6633 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) { 6634 err = -EINVAL; 6635 goto out_free; 6636 } 6637 request->ssids[i].ssid_len = nla_len(attr); 6638 memcpy(request->ssids[i].ssid, nla_data(attr), nla_len(attr)); 6639 i++; 6640 } 6641 } 6642 6643 if (info->attrs[NL80211_ATTR_IE]) { 6644 request->ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 6645 memcpy((void *)request->ie, 6646 nla_data(info->attrs[NL80211_ATTR_IE]), 6647 request->ie_len); 6648 } 6649 6650 for (i = 0; i < NUM_NL80211_BANDS; i++) 6651 if (wiphy->bands[i]) 6652 request->rates[i] = 6653 (1 << wiphy->bands[i]->n_bitrates) - 1; 6654 6655 if (info->attrs[NL80211_ATTR_SCAN_SUPP_RATES]) { 6656 nla_for_each_nested(attr, 6657 info->attrs[NL80211_ATTR_SCAN_SUPP_RATES], 6658 tmp) { 6659 enum nl80211_band band = nla_type(attr); 6660 6661 if (band < 0 || band >= NUM_NL80211_BANDS) { 6662 err = -EINVAL; 6663 goto out_free; 6664 } 6665 6666 if (!wiphy->bands[band]) 6667 continue; 6668 6669 err = ieee80211_get_ratemask(wiphy->bands[band], 6670 nla_data(attr), 6671 nla_len(attr), 6672 &request->rates[band]); 6673 if (err) 6674 goto out_free; 6675 } 6676 } 6677 6678 if (info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]) { 6679 if (!wiphy_ext_feature_isset(wiphy, 6680 NL80211_EXT_FEATURE_SET_SCAN_DWELL)) { 6681 err = -EOPNOTSUPP; 6682 goto out_free; 6683 } 6684 6685 request->duration = 6686 nla_get_u16(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION]); 6687 request->duration_mandatory = 6688 nla_get_flag(info->attrs[NL80211_ATTR_MEASUREMENT_DURATION_MANDATORY]); 6689 } 6690 6691 if (info->attrs[NL80211_ATTR_SCAN_FLAGS]) { 6692 request->flags = nla_get_u32( 6693 info->attrs[NL80211_ATTR_SCAN_FLAGS]); 6694 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) && 6695 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) { 6696 err = -EOPNOTSUPP; 6697 goto out_free; 6698 } 6699 6700 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) { 6701 if (!(wiphy->features & 6702 NL80211_FEATURE_SCAN_RANDOM_MAC_ADDR)) { 6703 err = -EOPNOTSUPP; 6704 goto out_free; 6705 } 6706 6707 if (wdev->current_bss) { 6708 err = -EOPNOTSUPP; 6709 goto out_free; 6710 } 6711 6712 err = nl80211_parse_random_mac(info->attrs, 6713 request->mac_addr, 6714 request->mac_addr_mask); 6715 if (err) 6716 goto out_free; 6717 } 6718 } 6719 6720 request->no_cck = 6721 nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]); 6722 6723 /* Initial implementation used NL80211_ATTR_MAC to set the specific 6724 * BSSID to scan for. This was problematic because that same attribute 6725 * was already used for another purpose (local random MAC address). The 6726 * NL80211_ATTR_BSSID attribute was added to fix this. For backwards 6727 * compatibility with older userspace components, also use the 6728 * NL80211_ATTR_MAC value here if it can be determined to be used for 6729 * the specific BSSID use case instead of the random MAC address 6730 * (NL80211_ATTR_SCAN_FLAGS is used to enable random MAC address use). 6731 */ 6732 if (info->attrs[NL80211_ATTR_BSSID]) 6733 memcpy(request->bssid, 6734 nla_data(info->attrs[NL80211_ATTR_BSSID]), ETH_ALEN); 6735 else if (!(request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) && 6736 info->attrs[NL80211_ATTR_MAC]) 6737 memcpy(request->bssid, nla_data(info->attrs[NL80211_ATTR_MAC]), 6738 ETH_ALEN); 6739 else 6740 eth_broadcast_addr(request->bssid); 6741 6742 request->wdev = wdev; 6743 request->wiphy = &rdev->wiphy; 6744 request->scan_start = jiffies; 6745 6746 rdev->scan_req = request; 6747 err = rdev_scan(rdev, request); 6748 6749 if (!err) { 6750 nl80211_send_scan_start(rdev, wdev); 6751 if (wdev->netdev) 6752 dev_hold(wdev->netdev); 6753 } else { 6754 out_free: 6755 rdev->scan_req = NULL; 6756 kfree(request); 6757 } 6758 6759 unlock: 6760 return err; 6761 } 6762 6763 static int nl80211_abort_scan(struct sk_buff *skb, struct genl_info *info) 6764 { 6765 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 6766 struct wireless_dev *wdev = info->user_ptr[1]; 6767 6768 if (!rdev->ops->abort_scan) 6769 return -EOPNOTSUPP; 6770 6771 if (rdev->scan_msg) 6772 return 0; 6773 6774 if (!rdev->scan_req) 6775 return -ENOENT; 6776 6777 rdev_abort_scan(rdev, wdev); 6778 return 0; 6779 } 6780 6781 static int 6782 nl80211_parse_sched_scan_plans(struct wiphy *wiphy, int n_plans, 6783 struct cfg80211_sched_scan_request *request, 6784 struct nlattr **attrs) 6785 { 6786 int tmp, err, i = 0; 6787 struct nlattr *attr; 6788 6789 if (!attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) { 6790 u32 interval; 6791 6792 /* 6793 * If scan plans are not specified, 6794 * %NL80211_ATTR_SCHED_SCAN_INTERVAL must be specified. In this 6795 * case one scan plan will be set with the specified scan 6796 * interval and infinite number of iterations. 6797 */ 6798 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6799 return -EINVAL; 6800 6801 interval = nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]); 6802 if (!interval) 6803 return -EINVAL; 6804 6805 request->scan_plans[0].interval = 6806 DIV_ROUND_UP(interval, MSEC_PER_SEC); 6807 if (!request->scan_plans[0].interval) 6808 return -EINVAL; 6809 6810 if (request->scan_plans[0].interval > 6811 wiphy->max_sched_scan_plan_interval) 6812 request->scan_plans[0].interval = 6813 wiphy->max_sched_scan_plan_interval; 6814 6815 return 0; 6816 } 6817 6818 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) { 6819 struct nlattr *plan[NL80211_SCHED_SCAN_PLAN_MAX + 1]; 6820 6821 if (WARN_ON(i >= n_plans)) 6822 return -EINVAL; 6823 6824 err = nla_parse_nested(plan, NL80211_SCHED_SCAN_PLAN_MAX, 6825 attr, nl80211_plan_policy); 6826 if (err) 6827 return err; 6828 6829 if (!plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]) 6830 return -EINVAL; 6831 6832 request->scan_plans[i].interval = 6833 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_INTERVAL]); 6834 if (!request->scan_plans[i].interval || 6835 request->scan_plans[i].interval > 6836 wiphy->max_sched_scan_plan_interval) 6837 return -EINVAL; 6838 6839 if (plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]) { 6840 request->scan_plans[i].iterations = 6841 nla_get_u32(plan[NL80211_SCHED_SCAN_PLAN_ITERATIONS]); 6842 if (!request->scan_plans[i].iterations || 6843 (request->scan_plans[i].iterations > 6844 wiphy->max_sched_scan_plan_iterations)) 6845 return -EINVAL; 6846 } else if (i < n_plans - 1) { 6847 /* 6848 * All scan plans but the last one must specify 6849 * a finite number of iterations 6850 */ 6851 return -EINVAL; 6852 } 6853 6854 i++; 6855 } 6856 6857 /* 6858 * The last scan plan must not specify the number of 6859 * iterations, it is supposed to run infinitely 6860 */ 6861 if (request->scan_plans[n_plans - 1].iterations) 6862 return -EINVAL; 6863 6864 return 0; 6865 } 6866 6867 static struct cfg80211_sched_scan_request * 6868 nl80211_parse_sched_scan(struct wiphy *wiphy, struct wireless_dev *wdev, 6869 struct nlattr **attrs) 6870 { 6871 struct cfg80211_sched_scan_request *request; 6872 struct nlattr *attr; 6873 int err, tmp, n_ssids = 0, n_match_sets = 0, n_channels, i, n_plans = 0; 6874 enum nl80211_band band; 6875 size_t ie_len; 6876 struct nlattr *tb[NL80211_SCHED_SCAN_MATCH_ATTR_MAX + 1]; 6877 s32 default_match_rssi = NL80211_SCAN_RSSI_THOLD_OFF; 6878 6879 if (!is_valid_ie_attr(attrs[NL80211_ATTR_IE])) 6880 return ERR_PTR(-EINVAL); 6881 6882 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 6883 n_channels = validate_scan_freqs( 6884 attrs[NL80211_ATTR_SCAN_FREQUENCIES]); 6885 if (!n_channels) 6886 return ERR_PTR(-EINVAL); 6887 } else { 6888 n_channels = ieee80211_get_num_supported_channels(wiphy); 6889 } 6890 6891 if (attrs[NL80211_ATTR_SCAN_SSIDS]) 6892 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS], 6893 tmp) 6894 n_ssids++; 6895 6896 if (n_ssids > wiphy->max_sched_scan_ssids) 6897 return ERR_PTR(-EINVAL); 6898 6899 /* 6900 * First, count the number of 'real' matchsets. Due to an issue with 6901 * the old implementation, matchsets containing only the RSSI attribute 6902 * (NL80211_SCHED_SCAN_MATCH_ATTR_RSSI) are considered as the 'default' 6903 * RSSI for all matchsets, rather than their own matchset for reporting 6904 * all APs with a strong RSSI. This is needed to be compatible with 6905 * older userspace that treated a matchset with only the RSSI as the 6906 * global RSSI for all other matchsets - if there are other matchsets. 6907 */ 6908 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) { 6909 nla_for_each_nested(attr, 6910 attrs[NL80211_ATTR_SCHED_SCAN_MATCH], 6911 tmp) { 6912 struct nlattr *rssi; 6913 6914 err = nla_parse_nested(tb, 6915 NL80211_SCHED_SCAN_MATCH_ATTR_MAX, 6916 attr, nl80211_match_policy); 6917 if (err) 6918 return ERR_PTR(err); 6919 /* add other standalone attributes here */ 6920 if (tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]) { 6921 n_match_sets++; 6922 continue; 6923 } 6924 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI]; 6925 if (rssi) 6926 default_match_rssi = nla_get_s32(rssi); 6927 } 6928 } 6929 6930 /* However, if there's no other matchset, add the RSSI one */ 6931 if (!n_match_sets && default_match_rssi != NL80211_SCAN_RSSI_THOLD_OFF) 6932 n_match_sets = 1; 6933 6934 if (n_match_sets > wiphy->max_match_sets) 6935 return ERR_PTR(-EINVAL); 6936 6937 if (attrs[NL80211_ATTR_IE]) 6938 ie_len = nla_len(attrs[NL80211_ATTR_IE]); 6939 else 6940 ie_len = 0; 6941 6942 if (ie_len > wiphy->max_sched_scan_ie_len) 6943 return ERR_PTR(-EINVAL); 6944 6945 if (attrs[NL80211_ATTR_SCHED_SCAN_PLANS]) { 6946 /* 6947 * NL80211_ATTR_SCHED_SCAN_INTERVAL must not be specified since 6948 * each scan plan already specifies its own interval 6949 */ 6950 if (attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6951 return ERR_PTR(-EINVAL); 6952 6953 nla_for_each_nested(attr, 6954 attrs[NL80211_ATTR_SCHED_SCAN_PLANS], tmp) 6955 n_plans++; 6956 } else { 6957 /* 6958 * The scan interval attribute is kept for backward 6959 * compatibility. If no scan plans are specified and sched scan 6960 * interval is specified, one scan plan will be set with this 6961 * scan interval and infinite number of iterations. 6962 */ 6963 if (!attrs[NL80211_ATTR_SCHED_SCAN_INTERVAL]) 6964 return ERR_PTR(-EINVAL); 6965 6966 n_plans = 1; 6967 } 6968 6969 if (!n_plans || n_plans > wiphy->max_sched_scan_plans) 6970 return ERR_PTR(-EINVAL); 6971 6972 request = kzalloc(sizeof(*request) 6973 + sizeof(*request->ssids) * n_ssids 6974 + sizeof(*request->match_sets) * n_match_sets 6975 + sizeof(*request->scan_plans) * n_plans 6976 + sizeof(*request->channels) * n_channels 6977 + ie_len, GFP_KERNEL); 6978 if (!request) 6979 return ERR_PTR(-ENOMEM); 6980 6981 if (n_ssids) 6982 request->ssids = (void *)&request->channels[n_channels]; 6983 request->n_ssids = n_ssids; 6984 if (ie_len) { 6985 if (n_ssids) 6986 request->ie = (void *)(request->ssids + n_ssids); 6987 else 6988 request->ie = (void *)(request->channels + n_channels); 6989 } 6990 6991 if (n_match_sets) { 6992 if (request->ie) 6993 request->match_sets = (void *)(request->ie + ie_len); 6994 else if (n_ssids) 6995 request->match_sets = 6996 (void *)(request->ssids + n_ssids); 6997 else 6998 request->match_sets = 6999 (void *)(request->channels + n_channels); 7000 } 7001 request->n_match_sets = n_match_sets; 7002 7003 if (n_match_sets) 7004 request->scan_plans = (void *)(request->match_sets + 7005 n_match_sets); 7006 else if (request->ie) 7007 request->scan_plans = (void *)(request->ie + ie_len); 7008 else if (n_ssids) 7009 request->scan_plans = (void *)(request->ssids + n_ssids); 7010 else 7011 request->scan_plans = (void *)(request->channels + n_channels); 7012 7013 request->n_scan_plans = n_plans; 7014 7015 i = 0; 7016 if (attrs[NL80211_ATTR_SCAN_FREQUENCIES]) { 7017 /* user specified, bail out if channel not found */ 7018 nla_for_each_nested(attr, 7019 attrs[NL80211_ATTR_SCAN_FREQUENCIES], 7020 tmp) { 7021 struct ieee80211_channel *chan; 7022 7023 chan = ieee80211_get_channel(wiphy, nla_get_u32(attr)); 7024 7025 if (!chan) { 7026 err = -EINVAL; 7027 goto out_free; 7028 } 7029 7030 /* ignore disabled channels */ 7031 if (chan->flags & IEEE80211_CHAN_DISABLED) 7032 continue; 7033 7034 request->channels[i] = chan; 7035 i++; 7036 } 7037 } else { 7038 /* all channels */ 7039 for (band = 0; band < NUM_NL80211_BANDS; band++) { 7040 int j; 7041 7042 if (!wiphy->bands[band]) 7043 continue; 7044 for (j = 0; j < wiphy->bands[band]->n_channels; j++) { 7045 struct ieee80211_channel *chan; 7046 7047 chan = &wiphy->bands[band]->channels[j]; 7048 7049 if (chan->flags & IEEE80211_CHAN_DISABLED) 7050 continue; 7051 7052 request->channels[i] = chan; 7053 i++; 7054 } 7055 } 7056 } 7057 7058 if (!i) { 7059 err = -EINVAL; 7060 goto out_free; 7061 } 7062 7063 request->n_channels = i; 7064 7065 i = 0; 7066 if (n_ssids) { 7067 nla_for_each_nested(attr, attrs[NL80211_ATTR_SCAN_SSIDS], 7068 tmp) { 7069 if (nla_len(attr) > IEEE80211_MAX_SSID_LEN) { 7070 err = -EINVAL; 7071 goto out_free; 7072 } 7073 request->ssids[i].ssid_len = nla_len(attr); 7074 memcpy(request->ssids[i].ssid, nla_data(attr), 7075 nla_len(attr)); 7076 i++; 7077 } 7078 } 7079 7080 i = 0; 7081 if (attrs[NL80211_ATTR_SCHED_SCAN_MATCH]) { 7082 nla_for_each_nested(attr, 7083 attrs[NL80211_ATTR_SCHED_SCAN_MATCH], 7084 tmp) { 7085 struct nlattr *ssid, *rssi; 7086 7087 err = nla_parse_nested(tb, 7088 NL80211_SCHED_SCAN_MATCH_ATTR_MAX, 7089 attr, nl80211_match_policy); 7090 if (err) 7091 goto out_free; 7092 ssid = tb[NL80211_SCHED_SCAN_MATCH_ATTR_SSID]; 7093 if (ssid) { 7094 if (WARN_ON(i >= n_match_sets)) { 7095 /* this indicates a programming error, 7096 * the loop above should have verified 7097 * things properly 7098 */ 7099 err = -EINVAL; 7100 goto out_free; 7101 } 7102 7103 if (nla_len(ssid) > IEEE80211_MAX_SSID_LEN) { 7104 err = -EINVAL; 7105 goto out_free; 7106 } 7107 memcpy(request->match_sets[i].ssid.ssid, 7108 nla_data(ssid), nla_len(ssid)); 7109 request->match_sets[i].ssid.ssid_len = 7110 nla_len(ssid); 7111 /* special attribute - old implementation w/a */ 7112 request->match_sets[i].rssi_thold = 7113 default_match_rssi; 7114 rssi = tb[NL80211_SCHED_SCAN_MATCH_ATTR_RSSI]; 7115 if (rssi) 7116 request->match_sets[i].rssi_thold = 7117 nla_get_s32(rssi); 7118 } 7119 i++; 7120 } 7121 7122 /* there was no other matchset, so the RSSI one is alone */ 7123 if (i == 0 && n_match_sets) 7124 request->match_sets[0].rssi_thold = default_match_rssi; 7125 7126 request->min_rssi_thold = INT_MAX; 7127 for (i = 0; i < n_match_sets; i++) 7128 request->min_rssi_thold = 7129 min(request->match_sets[i].rssi_thold, 7130 request->min_rssi_thold); 7131 } else { 7132 request->min_rssi_thold = NL80211_SCAN_RSSI_THOLD_OFF; 7133 } 7134 7135 if (ie_len) { 7136 request->ie_len = ie_len; 7137 memcpy((void *)request->ie, 7138 nla_data(attrs[NL80211_ATTR_IE]), 7139 request->ie_len); 7140 } 7141 7142 if (attrs[NL80211_ATTR_SCAN_FLAGS]) { 7143 request->flags = nla_get_u32( 7144 attrs[NL80211_ATTR_SCAN_FLAGS]); 7145 if ((request->flags & NL80211_SCAN_FLAG_LOW_PRIORITY) && 7146 !(wiphy->features & NL80211_FEATURE_LOW_PRIORITY_SCAN)) { 7147 err = -EOPNOTSUPP; 7148 goto out_free; 7149 } 7150 7151 if (request->flags & NL80211_SCAN_FLAG_RANDOM_ADDR) { 7152 u32 flg = NL80211_FEATURE_SCHED_SCAN_RANDOM_MAC_ADDR; 7153 7154 if (!wdev) /* must be net-detect */ 7155 flg = NL80211_FEATURE_ND_RANDOM_MAC_ADDR; 7156 7157 if (!(wiphy->features & flg)) { 7158 err = -EOPNOTSUPP; 7159 goto out_free; 7160 } 7161 7162 if (wdev && wdev->current_bss) { 7163 err = -EOPNOTSUPP; 7164 goto out_free; 7165 } 7166 7167 err = nl80211_parse_random_mac(attrs, request->mac_addr, 7168 request->mac_addr_mask); 7169 if (err) 7170 goto out_free; 7171 } 7172 } 7173 7174 if (attrs[NL80211_ATTR_SCHED_SCAN_DELAY]) 7175 request->delay = 7176 nla_get_u32(attrs[NL80211_ATTR_SCHED_SCAN_DELAY]); 7177 7178 err = nl80211_parse_sched_scan_plans(wiphy, n_plans, request, attrs); 7179 if (err) 7180 goto out_free; 7181 7182 request->scan_start = jiffies; 7183 7184 return request; 7185 7186 out_free: 7187 kfree(request); 7188 return ERR_PTR(err); 7189 } 7190 7191 static int nl80211_start_sched_scan(struct sk_buff *skb, 7192 struct genl_info *info) 7193 { 7194 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7195 struct net_device *dev = info->user_ptr[1]; 7196 struct wireless_dev *wdev = dev->ieee80211_ptr; 7197 struct cfg80211_sched_scan_request *sched_scan_req; 7198 int err; 7199 7200 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) || 7201 !rdev->ops->sched_scan_start) 7202 return -EOPNOTSUPP; 7203 7204 if (rdev->sched_scan_req) 7205 return -EINPROGRESS; 7206 7207 sched_scan_req = nl80211_parse_sched_scan(&rdev->wiphy, wdev, 7208 info->attrs); 7209 7210 err = PTR_ERR_OR_ZERO(sched_scan_req); 7211 if (err) 7212 goto out_err; 7213 7214 err = rdev_sched_scan_start(rdev, dev, sched_scan_req); 7215 if (err) 7216 goto out_free; 7217 7218 sched_scan_req->dev = dev; 7219 sched_scan_req->wiphy = &rdev->wiphy; 7220 7221 if (info->attrs[NL80211_ATTR_SOCKET_OWNER]) 7222 sched_scan_req->owner_nlportid = info->snd_portid; 7223 7224 rcu_assign_pointer(rdev->sched_scan_req, sched_scan_req); 7225 7226 nl80211_send_sched_scan(rdev, dev, 7227 NL80211_CMD_START_SCHED_SCAN); 7228 return 0; 7229 7230 out_free: 7231 kfree(sched_scan_req); 7232 out_err: 7233 return err; 7234 } 7235 7236 static int nl80211_stop_sched_scan(struct sk_buff *skb, 7237 struct genl_info *info) 7238 { 7239 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7240 7241 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) || 7242 !rdev->ops->sched_scan_stop) 7243 return -EOPNOTSUPP; 7244 7245 return __cfg80211_stop_sched_scan(rdev, false); 7246 } 7247 7248 static int nl80211_start_radar_detection(struct sk_buff *skb, 7249 struct genl_info *info) 7250 { 7251 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7252 struct net_device *dev = info->user_ptr[1]; 7253 struct wireless_dev *wdev = dev->ieee80211_ptr; 7254 struct cfg80211_chan_def chandef; 7255 enum nl80211_dfs_regions dfs_region; 7256 unsigned int cac_time_ms; 7257 int err; 7258 7259 dfs_region = reg_get_dfs_region(wdev->wiphy); 7260 if (dfs_region == NL80211_DFS_UNSET) 7261 return -EINVAL; 7262 7263 err = nl80211_parse_chandef(rdev, info, &chandef); 7264 if (err) 7265 return err; 7266 7267 if (netif_carrier_ok(dev)) 7268 return -EBUSY; 7269 7270 if (wdev->cac_started) 7271 return -EBUSY; 7272 7273 err = cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, 7274 wdev->iftype); 7275 if (err < 0) 7276 return err; 7277 7278 if (err == 0) 7279 return -EINVAL; 7280 7281 if (!cfg80211_chandef_dfs_usable(wdev->wiphy, &chandef)) 7282 return -EINVAL; 7283 7284 if (!rdev->ops->start_radar_detection) 7285 return -EOPNOTSUPP; 7286 7287 cac_time_ms = cfg80211_chandef_dfs_cac_time(&rdev->wiphy, &chandef); 7288 if (WARN_ON(!cac_time_ms)) 7289 cac_time_ms = IEEE80211_DFS_MIN_CAC_TIME_MS; 7290 7291 err = rdev_start_radar_detection(rdev, dev, &chandef, cac_time_ms); 7292 if (!err) { 7293 wdev->chandef = chandef; 7294 wdev->cac_started = true; 7295 wdev->cac_start_time = jiffies; 7296 wdev->cac_time_ms = cac_time_ms; 7297 } 7298 return err; 7299 } 7300 7301 static int nl80211_channel_switch(struct sk_buff *skb, struct genl_info *info) 7302 { 7303 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7304 struct net_device *dev = info->user_ptr[1]; 7305 struct wireless_dev *wdev = dev->ieee80211_ptr; 7306 struct cfg80211_csa_settings params; 7307 /* csa_attrs is defined static to avoid waste of stack size - this 7308 * function is called under RTNL lock, so this should not be a problem. 7309 */ 7310 static struct nlattr *csa_attrs[NL80211_ATTR_MAX+1]; 7311 int err; 7312 bool need_new_beacon = false; 7313 int len, i; 7314 u32 cs_count; 7315 7316 if (!rdev->ops->channel_switch || 7317 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_CHANNEL_SWITCH)) 7318 return -EOPNOTSUPP; 7319 7320 switch (dev->ieee80211_ptr->iftype) { 7321 case NL80211_IFTYPE_AP: 7322 case NL80211_IFTYPE_P2P_GO: 7323 need_new_beacon = true; 7324 7325 /* useless if AP is not running */ 7326 if (!wdev->beacon_interval) 7327 return -ENOTCONN; 7328 break; 7329 case NL80211_IFTYPE_ADHOC: 7330 if (!wdev->ssid_len) 7331 return -ENOTCONN; 7332 break; 7333 case NL80211_IFTYPE_MESH_POINT: 7334 if (!wdev->mesh_id_len) 7335 return -ENOTCONN; 7336 break; 7337 default: 7338 return -EOPNOTSUPP; 7339 } 7340 7341 memset(¶ms, 0, sizeof(params)); 7342 7343 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] || 7344 !info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]) 7345 return -EINVAL; 7346 7347 /* only important for AP, IBSS and mesh create IEs internally */ 7348 if (need_new_beacon && !info->attrs[NL80211_ATTR_CSA_IES]) 7349 return -EINVAL; 7350 7351 /* Even though the attribute is u32, the specification says 7352 * u8, so let's make sure we don't overflow. 7353 */ 7354 cs_count = nla_get_u32(info->attrs[NL80211_ATTR_CH_SWITCH_COUNT]); 7355 if (cs_count > 255) 7356 return -EINVAL; 7357 7358 params.count = cs_count; 7359 7360 if (!need_new_beacon) 7361 goto skip_beacons; 7362 7363 err = nl80211_parse_beacon(info->attrs, ¶ms.beacon_after); 7364 if (err) 7365 return err; 7366 7367 err = nla_parse_nested(csa_attrs, NL80211_ATTR_MAX, 7368 info->attrs[NL80211_ATTR_CSA_IES], 7369 nl80211_policy); 7370 if (err) 7371 return err; 7372 7373 err = nl80211_parse_beacon(csa_attrs, ¶ms.beacon_csa); 7374 if (err) 7375 return err; 7376 7377 if (!csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]) 7378 return -EINVAL; 7379 7380 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]); 7381 if (!len || (len % sizeof(u16))) 7382 return -EINVAL; 7383 7384 params.n_counter_offsets_beacon = len / sizeof(u16); 7385 if (rdev->wiphy.max_num_csa_counters && 7386 (params.n_counter_offsets_beacon > 7387 rdev->wiphy.max_num_csa_counters)) 7388 return -EINVAL; 7389 7390 params.counter_offsets_beacon = 7391 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_BEACON]); 7392 7393 /* sanity checks - counters should fit and be the same */ 7394 for (i = 0; i < params.n_counter_offsets_beacon; i++) { 7395 u16 offset = params.counter_offsets_beacon[i]; 7396 7397 if (offset >= params.beacon_csa.tail_len) 7398 return -EINVAL; 7399 7400 if (params.beacon_csa.tail[offset] != params.count) 7401 return -EINVAL; 7402 } 7403 7404 if (csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]) { 7405 len = nla_len(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]); 7406 if (!len || (len % sizeof(u16))) 7407 return -EINVAL; 7408 7409 params.n_counter_offsets_presp = len / sizeof(u16); 7410 if (rdev->wiphy.max_num_csa_counters && 7411 (params.n_counter_offsets_presp > 7412 rdev->wiphy.max_num_csa_counters)) 7413 return -EINVAL; 7414 7415 params.counter_offsets_presp = 7416 nla_data(csa_attrs[NL80211_ATTR_CSA_C_OFF_PRESP]); 7417 7418 /* sanity checks - counters should fit and be the same */ 7419 for (i = 0; i < params.n_counter_offsets_presp; i++) { 7420 u16 offset = params.counter_offsets_presp[i]; 7421 7422 if (offset >= params.beacon_csa.probe_resp_len) 7423 return -EINVAL; 7424 7425 if (params.beacon_csa.probe_resp[offset] != 7426 params.count) 7427 return -EINVAL; 7428 } 7429 } 7430 7431 skip_beacons: 7432 err = nl80211_parse_chandef(rdev, info, ¶ms.chandef); 7433 if (err) 7434 return err; 7435 7436 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, ¶ms.chandef, 7437 wdev->iftype)) 7438 return -EINVAL; 7439 7440 err = cfg80211_chandef_dfs_required(wdev->wiphy, 7441 ¶ms.chandef, 7442 wdev->iftype); 7443 if (err < 0) 7444 return err; 7445 7446 if (err > 0) 7447 params.radar_required = true; 7448 7449 if (info->attrs[NL80211_ATTR_CH_SWITCH_BLOCK_TX]) 7450 params.block_tx = true; 7451 7452 wdev_lock(wdev); 7453 err = rdev_channel_switch(rdev, dev, ¶ms); 7454 wdev_unlock(wdev); 7455 7456 return err; 7457 } 7458 7459 static int nl80211_send_bss(struct sk_buff *msg, struct netlink_callback *cb, 7460 u32 seq, int flags, 7461 struct cfg80211_registered_device *rdev, 7462 struct wireless_dev *wdev, 7463 struct cfg80211_internal_bss *intbss) 7464 { 7465 struct cfg80211_bss *res = &intbss->pub; 7466 const struct cfg80211_bss_ies *ies; 7467 void *hdr; 7468 struct nlattr *bss; 7469 7470 ASSERT_WDEV_LOCK(wdev); 7471 7472 hdr = nl80211hdr_put(msg, NETLINK_CB(cb->skb).portid, seq, flags, 7473 NL80211_CMD_NEW_SCAN_RESULTS); 7474 if (!hdr) 7475 return -1; 7476 7477 genl_dump_check_consistent(cb, hdr, &nl80211_fam); 7478 7479 if (nla_put_u32(msg, NL80211_ATTR_GENERATION, rdev->bss_generation)) 7480 goto nla_put_failure; 7481 if (wdev->netdev && 7482 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex)) 7483 goto nla_put_failure; 7484 if (nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 7485 NL80211_ATTR_PAD)) 7486 goto nla_put_failure; 7487 7488 bss = nla_nest_start(msg, NL80211_ATTR_BSS); 7489 if (!bss) 7490 goto nla_put_failure; 7491 if ((!is_zero_ether_addr(res->bssid) && 7492 nla_put(msg, NL80211_BSS_BSSID, ETH_ALEN, res->bssid))) 7493 goto nla_put_failure; 7494 7495 rcu_read_lock(); 7496 /* indicate whether we have probe response data or not */ 7497 if (rcu_access_pointer(res->proberesp_ies) && 7498 nla_put_flag(msg, NL80211_BSS_PRESP_DATA)) 7499 goto fail_unlock_rcu; 7500 7501 /* this pointer prefers to be pointed to probe response data 7502 * but is always valid 7503 */ 7504 ies = rcu_dereference(res->ies); 7505 if (ies) { 7506 if (nla_put_u64_64bit(msg, NL80211_BSS_TSF, ies->tsf, 7507 NL80211_BSS_PAD)) 7508 goto fail_unlock_rcu; 7509 if (ies->len && nla_put(msg, NL80211_BSS_INFORMATION_ELEMENTS, 7510 ies->len, ies->data)) 7511 goto fail_unlock_rcu; 7512 } 7513 7514 /* and this pointer is always (unless driver didn't know) beacon data */ 7515 ies = rcu_dereference(res->beacon_ies); 7516 if (ies && ies->from_beacon) { 7517 if (nla_put_u64_64bit(msg, NL80211_BSS_BEACON_TSF, ies->tsf, 7518 NL80211_BSS_PAD)) 7519 goto fail_unlock_rcu; 7520 if (ies->len && nla_put(msg, NL80211_BSS_BEACON_IES, 7521 ies->len, ies->data)) 7522 goto fail_unlock_rcu; 7523 } 7524 rcu_read_unlock(); 7525 7526 if (res->beacon_interval && 7527 nla_put_u16(msg, NL80211_BSS_BEACON_INTERVAL, res->beacon_interval)) 7528 goto nla_put_failure; 7529 if (nla_put_u16(msg, NL80211_BSS_CAPABILITY, res->capability) || 7530 nla_put_u32(msg, NL80211_BSS_FREQUENCY, res->channel->center_freq) || 7531 nla_put_u32(msg, NL80211_BSS_CHAN_WIDTH, res->scan_width) || 7532 nla_put_u32(msg, NL80211_BSS_SEEN_MS_AGO, 7533 jiffies_to_msecs(jiffies - intbss->ts))) 7534 goto nla_put_failure; 7535 7536 if (intbss->parent_tsf && 7537 (nla_put_u64_64bit(msg, NL80211_BSS_PARENT_TSF, 7538 intbss->parent_tsf, NL80211_BSS_PAD) || 7539 nla_put(msg, NL80211_BSS_PARENT_BSSID, ETH_ALEN, 7540 intbss->parent_bssid))) 7541 goto nla_put_failure; 7542 7543 if (intbss->ts_boottime && 7544 nla_put_u64_64bit(msg, NL80211_BSS_LAST_SEEN_BOOTTIME, 7545 intbss->ts_boottime, NL80211_BSS_PAD)) 7546 goto nla_put_failure; 7547 7548 switch (rdev->wiphy.signal_type) { 7549 case CFG80211_SIGNAL_TYPE_MBM: 7550 if (nla_put_u32(msg, NL80211_BSS_SIGNAL_MBM, res->signal)) 7551 goto nla_put_failure; 7552 break; 7553 case CFG80211_SIGNAL_TYPE_UNSPEC: 7554 if (nla_put_u8(msg, NL80211_BSS_SIGNAL_UNSPEC, res->signal)) 7555 goto nla_put_failure; 7556 break; 7557 default: 7558 break; 7559 } 7560 7561 switch (wdev->iftype) { 7562 case NL80211_IFTYPE_P2P_CLIENT: 7563 case NL80211_IFTYPE_STATION: 7564 if (intbss == wdev->current_bss && 7565 nla_put_u32(msg, NL80211_BSS_STATUS, 7566 NL80211_BSS_STATUS_ASSOCIATED)) 7567 goto nla_put_failure; 7568 break; 7569 case NL80211_IFTYPE_ADHOC: 7570 if (intbss == wdev->current_bss && 7571 nla_put_u32(msg, NL80211_BSS_STATUS, 7572 NL80211_BSS_STATUS_IBSS_JOINED)) 7573 goto nla_put_failure; 7574 break; 7575 default: 7576 break; 7577 } 7578 7579 nla_nest_end(msg, bss); 7580 7581 genlmsg_end(msg, hdr); 7582 return 0; 7583 7584 fail_unlock_rcu: 7585 rcu_read_unlock(); 7586 nla_put_failure: 7587 genlmsg_cancel(msg, hdr); 7588 return -EMSGSIZE; 7589 } 7590 7591 static int nl80211_dump_scan(struct sk_buff *skb, struct netlink_callback *cb) 7592 { 7593 struct cfg80211_registered_device *rdev; 7594 struct cfg80211_internal_bss *scan; 7595 struct wireless_dev *wdev; 7596 int start = cb->args[2], idx = 0; 7597 int err; 7598 7599 err = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 7600 if (err) 7601 return err; 7602 7603 wdev_lock(wdev); 7604 spin_lock_bh(&rdev->bss_lock); 7605 cfg80211_bss_expire(rdev); 7606 7607 cb->seq = rdev->bss_generation; 7608 7609 list_for_each_entry(scan, &rdev->bss_list, list) { 7610 if (++idx <= start) 7611 continue; 7612 if (nl80211_send_bss(skb, cb, 7613 cb->nlh->nlmsg_seq, NLM_F_MULTI, 7614 rdev, wdev, scan) < 0) { 7615 idx--; 7616 break; 7617 } 7618 } 7619 7620 spin_unlock_bh(&rdev->bss_lock); 7621 wdev_unlock(wdev); 7622 7623 cb->args[2] = idx; 7624 nl80211_finish_wdev_dump(rdev); 7625 7626 return skb->len; 7627 } 7628 7629 static int nl80211_send_survey(struct sk_buff *msg, u32 portid, u32 seq, 7630 int flags, struct net_device *dev, 7631 bool allow_radio_stats, 7632 struct survey_info *survey) 7633 { 7634 void *hdr; 7635 struct nlattr *infoattr; 7636 7637 /* skip radio stats if userspace didn't request them */ 7638 if (!survey->channel && !allow_radio_stats) 7639 return 0; 7640 7641 hdr = nl80211hdr_put(msg, portid, seq, flags, 7642 NL80211_CMD_NEW_SURVEY_RESULTS); 7643 if (!hdr) 7644 return -ENOMEM; 7645 7646 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex)) 7647 goto nla_put_failure; 7648 7649 infoattr = nla_nest_start(msg, NL80211_ATTR_SURVEY_INFO); 7650 if (!infoattr) 7651 goto nla_put_failure; 7652 7653 if (survey->channel && 7654 nla_put_u32(msg, NL80211_SURVEY_INFO_FREQUENCY, 7655 survey->channel->center_freq)) 7656 goto nla_put_failure; 7657 7658 if ((survey->filled & SURVEY_INFO_NOISE_DBM) && 7659 nla_put_u8(msg, NL80211_SURVEY_INFO_NOISE, survey->noise)) 7660 goto nla_put_failure; 7661 if ((survey->filled & SURVEY_INFO_IN_USE) && 7662 nla_put_flag(msg, NL80211_SURVEY_INFO_IN_USE)) 7663 goto nla_put_failure; 7664 if ((survey->filled & SURVEY_INFO_TIME) && 7665 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME, 7666 survey->time, NL80211_SURVEY_INFO_PAD)) 7667 goto nla_put_failure; 7668 if ((survey->filled & SURVEY_INFO_TIME_BUSY) && 7669 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_BUSY, 7670 survey->time_busy, NL80211_SURVEY_INFO_PAD)) 7671 goto nla_put_failure; 7672 if ((survey->filled & SURVEY_INFO_TIME_EXT_BUSY) && 7673 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_EXT_BUSY, 7674 survey->time_ext_busy, NL80211_SURVEY_INFO_PAD)) 7675 goto nla_put_failure; 7676 if ((survey->filled & SURVEY_INFO_TIME_RX) && 7677 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_RX, 7678 survey->time_rx, NL80211_SURVEY_INFO_PAD)) 7679 goto nla_put_failure; 7680 if ((survey->filled & SURVEY_INFO_TIME_TX) && 7681 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_TX, 7682 survey->time_tx, NL80211_SURVEY_INFO_PAD)) 7683 goto nla_put_failure; 7684 if ((survey->filled & SURVEY_INFO_TIME_SCAN) && 7685 nla_put_u64_64bit(msg, NL80211_SURVEY_INFO_TIME_SCAN, 7686 survey->time_scan, NL80211_SURVEY_INFO_PAD)) 7687 goto nla_put_failure; 7688 7689 nla_nest_end(msg, infoattr); 7690 7691 genlmsg_end(msg, hdr); 7692 return 0; 7693 7694 nla_put_failure: 7695 genlmsg_cancel(msg, hdr); 7696 return -EMSGSIZE; 7697 } 7698 7699 static int nl80211_dump_survey(struct sk_buff *skb, struct netlink_callback *cb) 7700 { 7701 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 7702 struct survey_info survey; 7703 struct cfg80211_registered_device *rdev; 7704 struct wireless_dev *wdev; 7705 int survey_idx = cb->args[2]; 7706 int res; 7707 bool radio_stats; 7708 7709 res = nl80211_prepare_wdev_dump(skb, cb, &rdev, &wdev); 7710 if (res) 7711 return res; 7712 7713 /* prepare_wdev_dump parsed the attributes */ 7714 radio_stats = attrbuf[NL80211_ATTR_SURVEY_RADIO_STATS]; 7715 7716 if (!wdev->netdev) { 7717 res = -EINVAL; 7718 goto out_err; 7719 } 7720 7721 if (!rdev->ops->dump_survey) { 7722 res = -EOPNOTSUPP; 7723 goto out_err; 7724 } 7725 7726 while (1) { 7727 res = rdev_dump_survey(rdev, wdev->netdev, survey_idx, &survey); 7728 if (res == -ENOENT) 7729 break; 7730 if (res) 7731 goto out_err; 7732 7733 /* don't send disabled channels, but do send non-channel data */ 7734 if (survey.channel && 7735 survey.channel->flags & IEEE80211_CHAN_DISABLED) { 7736 survey_idx++; 7737 continue; 7738 } 7739 7740 if (nl80211_send_survey(skb, 7741 NETLINK_CB(cb->skb).portid, 7742 cb->nlh->nlmsg_seq, NLM_F_MULTI, 7743 wdev->netdev, radio_stats, &survey) < 0) 7744 goto out; 7745 survey_idx++; 7746 } 7747 7748 out: 7749 cb->args[2] = survey_idx; 7750 res = skb->len; 7751 out_err: 7752 nl80211_finish_wdev_dump(rdev); 7753 return res; 7754 } 7755 7756 static bool nl80211_valid_wpa_versions(u32 wpa_versions) 7757 { 7758 return !(wpa_versions & ~(NL80211_WPA_VERSION_1 | 7759 NL80211_WPA_VERSION_2)); 7760 } 7761 7762 static int nl80211_authenticate(struct sk_buff *skb, struct genl_info *info) 7763 { 7764 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7765 struct net_device *dev = info->user_ptr[1]; 7766 struct ieee80211_channel *chan; 7767 const u8 *bssid, *ssid, *ie = NULL, *auth_data = NULL; 7768 int err, ssid_len, ie_len = 0, auth_data_len = 0; 7769 enum nl80211_auth_type auth_type; 7770 struct key_parse key; 7771 bool local_state_change; 7772 7773 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 7774 return -EINVAL; 7775 7776 if (!info->attrs[NL80211_ATTR_MAC]) 7777 return -EINVAL; 7778 7779 if (!info->attrs[NL80211_ATTR_AUTH_TYPE]) 7780 return -EINVAL; 7781 7782 if (!info->attrs[NL80211_ATTR_SSID]) 7783 return -EINVAL; 7784 7785 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 7786 return -EINVAL; 7787 7788 err = nl80211_parse_key(info, &key); 7789 if (err) 7790 return err; 7791 7792 if (key.idx >= 0) { 7793 if (key.type != -1 && key.type != NL80211_KEYTYPE_GROUP) 7794 return -EINVAL; 7795 if (!key.p.key || !key.p.key_len) 7796 return -EINVAL; 7797 if ((key.p.cipher != WLAN_CIPHER_SUITE_WEP40 || 7798 key.p.key_len != WLAN_KEY_LEN_WEP40) && 7799 (key.p.cipher != WLAN_CIPHER_SUITE_WEP104 || 7800 key.p.key_len != WLAN_KEY_LEN_WEP104)) 7801 return -EINVAL; 7802 if (key.idx > 3) 7803 return -EINVAL; 7804 } else { 7805 key.p.key_len = 0; 7806 key.p.key = NULL; 7807 } 7808 7809 if (key.idx >= 0) { 7810 int i; 7811 bool ok = false; 7812 7813 for (i = 0; i < rdev->wiphy.n_cipher_suites; i++) { 7814 if (key.p.cipher == rdev->wiphy.cipher_suites[i]) { 7815 ok = true; 7816 break; 7817 } 7818 } 7819 if (!ok) 7820 return -EINVAL; 7821 } 7822 7823 if (!rdev->ops->auth) 7824 return -EOPNOTSUPP; 7825 7826 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 7827 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 7828 return -EOPNOTSUPP; 7829 7830 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 7831 chan = nl80211_get_valid_chan(&rdev->wiphy, 7832 info->attrs[NL80211_ATTR_WIPHY_FREQ]); 7833 if (!chan) 7834 return -EINVAL; 7835 7836 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 7837 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 7838 7839 if (info->attrs[NL80211_ATTR_IE]) { 7840 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 7841 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 7842 } 7843 7844 auth_type = nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]); 7845 if (!nl80211_valid_auth_type(rdev, auth_type, NL80211_CMD_AUTHENTICATE)) 7846 return -EINVAL; 7847 7848 if ((auth_type == NL80211_AUTHTYPE_SAE || 7849 auth_type == NL80211_AUTHTYPE_FILS_SK || 7850 auth_type == NL80211_AUTHTYPE_FILS_SK_PFS || 7851 auth_type == NL80211_AUTHTYPE_FILS_PK) && 7852 !info->attrs[NL80211_ATTR_AUTH_DATA]) 7853 return -EINVAL; 7854 7855 if (info->attrs[NL80211_ATTR_AUTH_DATA]) { 7856 if (auth_type != NL80211_AUTHTYPE_SAE && 7857 auth_type != NL80211_AUTHTYPE_FILS_SK && 7858 auth_type != NL80211_AUTHTYPE_FILS_SK_PFS && 7859 auth_type != NL80211_AUTHTYPE_FILS_PK) 7860 return -EINVAL; 7861 auth_data = nla_data(info->attrs[NL80211_ATTR_AUTH_DATA]); 7862 auth_data_len = nla_len(info->attrs[NL80211_ATTR_AUTH_DATA]); 7863 /* need to include at least Auth Transaction and Status Code */ 7864 if (auth_data_len < 4) 7865 return -EINVAL; 7866 } 7867 7868 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 7869 7870 /* 7871 * Since we no longer track auth state, ignore 7872 * requests to only change local state. 7873 */ 7874 if (local_state_change) 7875 return 0; 7876 7877 wdev_lock(dev->ieee80211_ptr); 7878 err = cfg80211_mlme_auth(rdev, dev, chan, auth_type, bssid, 7879 ssid, ssid_len, ie, ie_len, 7880 key.p.key, key.p.key_len, key.idx, 7881 auth_data, auth_data_len); 7882 wdev_unlock(dev->ieee80211_ptr); 7883 return err; 7884 } 7885 7886 static int nl80211_crypto_settings(struct cfg80211_registered_device *rdev, 7887 struct genl_info *info, 7888 struct cfg80211_crypto_settings *settings, 7889 int cipher_limit) 7890 { 7891 memset(settings, 0, sizeof(*settings)); 7892 7893 settings->control_port = info->attrs[NL80211_ATTR_CONTROL_PORT]; 7894 7895 if (info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]) { 7896 u16 proto; 7897 7898 proto = nla_get_u16( 7899 info->attrs[NL80211_ATTR_CONTROL_PORT_ETHERTYPE]); 7900 settings->control_port_ethertype = cpu_to_be16(proto); 7901 if (!(rdev->wiphy.flags & WIPHY_FLAG_CONTROL_PORT_PROTOCOL) && 7902 proto != ETH_P_PAE) 7903 return -EINVAL; 7904 if (info->attrs[NL80211_ATTR_CONTROL_PORT_NO_ENCRYPT]) 7905 settings->control_port_no_encrypt = true; 7906 } else 7907 settings->control_port_ethertype = cpu_to_be16(ETH_P_PAE); 7908 7909 if (info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]) { 7910 void *data; 7911 int len, i; 7912 7913 data = nla_data(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]); 7914 len = nla_len(info->attrs[NL80211_ATTR_CIPHER_SUITES_PAIRWISE]); 7915 settings->n_ciphers_pairwise = len / sizeof(u32); 7916 7917 if (len % sizeof(u32)) 7918 return -EINVAL; 7919 7920 if (settings->n_ciphers_pairwise > cipher_limit) 7921 return -EINVAL; 7922 7923 memcpy(settings->ciphers_pairwise, data, len); 7924 7925 for (i = 0; i < settings->n_ciphers_pairwise; i++) 7926 if (!cfg80211_supported_cipher_suite( 7927 &rdev->wiphy, 7928 settings->ciphers_pairwise[i])) 7929 return -EINVAL; 7930 } 7931 7932 if (info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]) { 7933 settings->cipher_group = 7934 nla_get_u32(info->attrs[NL80211_ATTR_CIPHER_SUITE_GROUP]); 7935 if (!cfg80211_supported_cipher_suite(&rdev->wiphy, 7936 settings->cipher_group)) 7937 return -EINVAL; 7938 } 7939 7940 if (info->attrs[NL80211_ATTR_WPA_VERSIONS]) { 7941 settings->wpa_versions = 7942 nla_get_u32(info->attrs[NL80211_ATTR_WPA_VERSIONS]); 7943 if (!nl80211_valid_wpa_versions(settings->wpa_versions)) 7944 return -EINVAL; 7945 } 7946 7947 if (info->attrs[NL80211_ATTR_AKM_SUITES]) { 7948 void *data; 7949 int len; 7950 7951 data = nla_data(info->attrs[NL80211_ATTR_AKM_SUITES]); 7952 len = nla_len(info->attrs[NL80211_ATTR_AKM_SUITES]); 7953 settings->n_akm_suites = len / sizeof(u32); 7954 7955 if (len % sizeof(u32)) 7956 return -EINVAL; 7957 7958 if (settings->n_akm_suites > NL80211_MAX_NR_AKM_SUITES) 7959 return -EINVAL; 7960 7961 memcpy(settings->akm_suites, data, len); 7962 } 7963 7964 return 0; 7965 } 7966 7967 static int nl80211_associate(struct sk_buff *skb, struct genl_info *info) 7968 { 7969 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 7970 struct net_device *dev = info->user_ptr[1]; 7971 struct ieee80211_channel *chan; 7972 struct cfg80211_assoc_request req = {}; 7973 const u8 *bssid, *ssid; 7974 int err, ssid_len = 0; 7975 7976 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 7977 return -EINVAL; 7978 7979 if (!info->attrs[NL80211_ATTR_MAC] || 7980 !info->attrs[NL80211_ATTR_SSID] || 7981 !info->attrs[NL80211_ATTR_WIPHY_FREQ]) 7982 return -EINVAL; 7983 7984 if (!rdev->ops->assoc) 7985 return -EOPNOTSUPP; 7986 7987 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 7988 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 7989 return -EOPNOTSUPP; 7990 7991 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 7992 7993 chan = nl80211_get_valid_chan(&rdev->wiphy, 7994 info->attrs[NL80211_ATTR_WIPHY_FREQ]); 7995 if (!chan) 7996 return -EINVAL; 7997 7998 ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 7999 ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8000 8001 if (info->attrs[NL80211_ATTR_IE]) { 8002 req.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8003 req.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8004 } 8005 8006 if (info->attrs[NL80211_ATTR_USE_MFP]) { 8007 enum nl80211_mfp mfp = 8008 nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]); 8009 if (mfp == NL80211_MFP_REQUIRED) 8010 req.use_mfp = true; 8011 else if (mfp != NL80211_MFP_NO) 8012 return -EINVAL; 8013 } 8014 8015 if (info->attrs[NL80211_ATTR_PREV_BSSID]) 8016 req.prev_bssid = nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]); 8017 8018 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT])) 8019 req.flags |= ASSOC_REQ_DISABLE_HT; 8020 8021 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8022 memcpy(&req.ht_capa_mask, 8023 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8024 sizeof(req.ht_capa_mask)); 8025 8026 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8027 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8028 return -EINVAL; 8029 memcpy(&req.ht_capa, 8030 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8031 sizeof(req.ht_capa)); 8032 } 8033 8034 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT])) 8035 req.flags |= ASSOC_REQ_DISABLE_VHT; 8036 8037 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8038 memcpy(&req.vht_capa_mask, 8039 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]), 8040 sizeof(req.vht_capa_mask)); 8041 8042 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) { 8043 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8044 return -EINVAL; 8045 memcpy(&req.vht_capa, 8046 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]), 8047 sizeof(req.vht_capa)); 8048 } 8049 8050 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) { 8051 if (!((rdev->wiphy.features & 8052 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) && 8053 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) && 8054 !wiphy_ext_feature_isset(&rdev->wiphy, 8055 NL80211_EXT_FEATURE_RRM)) 8056 return -EINVAL; 8057 req.flags |= ASSOC_REQ_USE_RRM; 8058 } 8059 8060 if (info->attrs[NL80211_ATTR_FILS_KEK]) { 8061 req.fils_kek = nla_data(info->attrs[NL80211_ATTR_FILS_KEK]); 8062 req.fils_kek_len = nla_len(info->attrs[NL80211_ATTR_FILS_KEK]); 8063 if (!info->attrs[NL80211_ATTR_FILS_NONCES]) 8064 return -EINVAL; 8065 req.fils_nonces = 8066 nla_data(info->attrs[NL80211_ATTR_FILS_NONCES]); 8067 } 8068 8069 err = nl80211_crypto_settings(rdev, info, &req.crypto, 1); 8070 if (!err) { 8071 wdev_lock(dev->ieee80211_ptr); 8072 err = cfg80211_mlme_assoc(rdev, dev, chan, bssid, 8073 ssid, ssid_len, &req); 8074 wdev_unlock(dev->ieee80211_ptr); 8075 } 8076 8077 return err; 8078 } 8079 8080 static int nl80211_deauthenticate(struct sk_buff *skb, struct genl_info *info) 8081 { 8082 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8083 struct net_device *dev = info->user_ptr[1]; 8084 const u8 *ie = NULL, *bssid; 8085 int ie_len = 0, err; 8086 u16 reason_code; 8087 bool local_state_change; 8088 8089 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8090 return -EINVAL; 8091 8092 if (!info->attrs[NL80211_ATTR_MAC]) 8093 return -EINVAL; 8094 8095 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8096 return -EINVAL; 8097 8098 if (!rdev->ops->deauth) 8099 return -EOPNOTSUPP; 8100 8101 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8102 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8103 return -EOPNOTSUPP; 8104 8105 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8106 8107 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8108 if (reason_code == 0) { 8109 /* Reason Code 0 is reserved */ 8110 return -EINVAL; 8111 } 8112 8113 if (info->attrs[NL80211_ATTR_IE]) { 8114 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8115 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8116 } 8117 8118 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 8119 8120 wdev_lock(dev->ieee80211_ptr); 8121 err = cfg80211_mlme_deauth(rdev, dev, bssid, ie, ie_len, reason_code, 8122 local_state_change); 8123 wdev_unlock(dev->ieee80211_ptr); 8124 return err; 8125 } 8126 8127 static int nl80211_disassociate(struct sk_buff *skb, struct genl_info *info) 8128 { 8129 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8130 struct net_device *dev = info->user_ptr[1]; 8131 const u8 *ie = NULL, *bssid; 8132 int ie_len = 0, err; 8133 u16 reason_code; 8134 bool local_state_change; 8135 8136 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8137 return -EINVAL; 8138 8139 if (!info->attrs[NL80211_ATTR_MAC]) 8140 return -EINVAL; 8141 8142 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8143 return -EINVAL; 8144 8145 if (!rdev->ops->disassoc) 8146 return -EOPNOTSUPP; 8147 8148 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8149 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8150 return -EOPNOTSUPP; 8151 8152 bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8153 8154 reason_code = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8155 if (reason_code == 0) { 8156 /* Reason Code 0 is reserved */ 8157 return -EINVAL; 8158 } 8159 8160 if (info->attrs[NL80211_ATTR_IE]) { 8161 ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8162 ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8163 } 8164 8165 local_state_change = !!info->attrs[NL80211_ATTR_LOCAL_STATE_CHANGE]; 8166 8167 wdev_lock(dev->ieee80211_ptr); 8168 err = cfg80211_mlme_disassoc(rdev, dev, bssid, ie, ie_len, reason_code, 8169 local_state_change); 8170 wdev_unlock(dev->ieee80211_ptr); 8171 return err; 8172 } 8173 8174 static bool 8175 nl80211_parse_mcast_rate(struct cfg80211_registered_device *rdev, 8176 int mcast_rate[NUM_NL80211_BANDS], 8177 int rateval) 8178 { 8179 struct wiphy *wiphy = &rdev->wiphy; 8180 bool found = false; 8181 int band, i; 8182 8183 for (band = 0; band < NUM_NL80211_BANDS; band++) { 8184 struct ieee80211_supported_band *sband; 8185 8186 sband = wiphy->bands[band]; 8187 if (!sband) 8188 continue; 8189 8190 for (i = 0; i < sband->n_bitrates; i++) { 8191 if (sband->bitrates[i].bitrate == rateval) { 8192 mcast_rate[band] = i + 1; 8193 found = true; 8194 break; 8195 } 8196 } 8197 } 8198 8199 return found; 8200 } 8201 8202 static int nl80211_join_ibss(struct sk_buff *skb, struct genl_info *info) 8203 { 8204 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8205 struct net_device *dev = info->user_ptr[1]; 8206 struct cfg80211_ibss_params ibss; 8207 struct wiphy *wiphy; 8208 struct cfg80211_cached_keys *connkeys = NULL; 8209 int err; 8210 8211 memset(&ibss, 0, sizeof(ibss)); 8212 8213 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8214 return -EINVAL; 8215 8216 if (!info->attrs[NL80211_ATTR_SSID] || 8217 !nla_len(info->attrs[NL80211_ATTR_SSID])) 8218 return -EINVAL; 8219 8220 ibss.beacon_interval = 100; 8221 8222 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) 8223 ibss.beacon_interval = 8224 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 8225 8226 err = cfg80211_validate_beacon_int(rdev, NL80211_IFTYPE_ADHOC, 8227 ibss.beacon_interval); 8228 if (err) 8229 return err; 8230 8231 if (!rdev->ops->join_ibss) 8232 return -EOPNOTSUPP; 8233 8234 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) 8235 return -EOPNOTSUPP; 8236 8237 wiphy = &rdev->wiphy; 8238 8239 if (info->attrs[NL80211_ATTR_MAC]) { 8240 ibss.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8241 8242 if (!is_valid_ether_addr(ibss.bssid)) 8243 return -EINVAL; 8244 } 8245 ibss.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8246 ibss.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8247 8248 if (info->attrs[NL80211_ATTR_IE]) { 8249 ibss.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8250 ibss.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8251 } 8252 8253 err = nl80211_parse_chandef(rdev, info, &ibss.chandef); 8254 if (err) 8255 return err; 8256 8257 if (!cfg80211_reg_can_beacon(&rdev->wiphy, &ibss.chandef, 8258 NL80211_IFTYPE_ADHOC)) 8259 return -EINVAL; 8260 8261 switch (ibss.chandef.width) { 8262 case NL80211_CHAN_WIDTH_5: 8263 case NL80211_CHAN_WIDTH_10: 8264 case NL80211_CHAN_WIDTH_20_NOHT: 8265 break; 8266 case NL80211_CHAN_WIDTH_20: 8267 case NL80211_CHAN_WIDTH_40: 8268 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)) 8269 return -EINVAL; 8270 break; 8271 case NL80211_CHAN_WIDTH_80: 8272 case NL80211_CHAN_WIDTH_80P80: 8273 case NL80211_CHAN_WIDTH_160: 8274 if (!(rdev->wiphy.features & NL80211_FEATURE_HT_IBSS)) 8275 return -EINVAL; 8276 if (!wiphy_ext_feature_isset(&rdev->wiphy, 8277 NL80211_EXT_FEATURE_VHT_IBSS)) 8278 return -EINVAL; 8279 break; 8280 default: 8281 return -EINVAL; 8282 } 8283 8284 ibss.channel_fixed = !!info->attrs[NL80211_ATTR_FREQ_FIXED]; 8285 ibss.privacy = !!info->attrs[NL80211_ATTR_PRIVACY]; 8286 8287 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 8288 u8 *rates = 8289 nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 8290 int n_rates = 8291 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 8292 struct ieee80211_supported_band *sband = 8293 wiphy->bands[ibss.chandef.chan->band]; 8294 8295 err = ieee80211_get_ratemask(sband, rates, n_rates, 8296 &ibss.basic_rates); 8297 if (err) 8298 return err; 8299 } 8300 8301 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8302 memcpy(&ibss.ht_capa_mask, 8303 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8304 sizeof(ibss.ht_capa_mask)); 8305 8306 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8307 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8308 return -EINVAL; 8309 memcpy(&ibss.ht_capa, 8310 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8311 sizeof(ibss.ht_capa)); 8312 } 8313 8314 if (info->attrs[NL80211_ATTR_MCAST_RATE] && 8315 !nl80211_parse_mcast_rate(rdev, ibss.mcast_rate, 8316 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]))) 8317 return -EINVAL; 8318 8319 if (ibss.privacy && info->attrs[NL80211_ATTR_KEYS]) { 8320 bool no_ht = false; 8321 8322 connkeys = nl80211_parse_connkeys(rdev, 8323 info->attrs[NL80211_ATTR_KEYS], 8324 &no_ht); 8325 if (IS_ERR(connkeys)) 8326 return PTR_ERR(connkeys); 8327 8328 if ((ibss.chandef.width != NL80211_CHAN_WIDTH_20_NOHT) && 8329 no_ht) { 8330 kzfree(connkeys); 8331 return -EINVAL; 8332 } 8333 } 8334 8335 ibss.control_port = 8336 nla_get_flag(info->attrs[NL80211_ATTR_CONTROL_PORT]); 8337 8338 ibss.userspace_handles_dfs = 8339 nla_get_flag(info->attrs[NL80211_ATTR_HANDLE_DFS]); 8340 8341 err = cfg80211_join_ibss(rdev, dev, &ibss, connkeys); 8342 if (err) 8343 kzfree(connkeys); 8344 return err; 8345 } 8346 8347 static int nl80211_leave_ibss(struct sk_buff *skb, struct genl_info *info) 8348 { 8349 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8350 struct net_device *dev = info->user_ptr[1]; 8351 8352 if (!rdev->ops->leave_ibss) 8353 return -EOPNOTSUPP; 8354 8355 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC) 8356 return -EOPNOTSUPP; 8357 8358 return cfg80211_leave_ibss(rdev, dev, false); 8359 } 8360 8361 static int nl80211_set_mcast_rate(struct sk_buff *skb, struct genl_info *info) 8362 { 8363 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8364 struct net_device *dev = info->user_ptr[1]; 8365 int mcast_rate[NUM_NL80211_BANDS]; 8366 u32 nla_rate; 8367 int err; 8368 8369 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_ADHOC && 8370 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_MESH_POINT && 8371 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_OCB) 8372 return -EOPNOTSUPP; 8373 8374 if (!rdev->ops->set_mcast_rate) 8375 return -EOPNOTSUPP; 8376 8377 memset(mcast_rate, 0, sizeof(mcast_rate)); 8378 8379 if (!info->attrs[NL80211_ATTR_MCAST_RATE]) 8380 return -EINVAL; 8381 8382 nla_rate = nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]); 8383 if (!nl80211_parse_mcast_rate(rdev, mcast_rate, nla_rate)) 8384 return -EINVAL; 8385 8386 err = rdev_set_mcast_rate(rdev, dev, mcast_rate); 8387 8388 return err; 8389 } 8390 8391 static struct sk_buff * 8392 __cfg80211_alloc_vendor_skb(struct cfg80211_registered_device *rdev, 8393 struct wireless_dev *wdev, int approxlen, 8394 u32 portid, u32 seq, enum nl80211_commands cmd, 8395 enum nl80211_attrs attr, 8396 const struct nl80211_vendor_cmd_info *info, 8397 gfp_t gfp) 8398 { 8399 struct sk_buff *skb; 8400 void *hdr; 8401 struct nlattr *data; 8402 8403 skb = nlmsg_new(approxlen + 100, gfp); 8404 if (!skb) 8405 return NULL; 8406 8407 hdr = nl80211hdr_put(skb, portid, seq, 0, cmd); 8408 if (!hdr) { 8409 kfree_skb(skb); 8410 return NULL; 8411 } 8412 8413 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx)) 8414 goto nla_put_failure; 8415 8416 if (info) { 8417 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_ID, 8418 info->vendor_id)) 8419 goto nla_put_failure; 8420 if (nla_put_u32(skb, NL80211_ATTR_VENDOR_SUBCMD, 8421 info->subcmd)) 8422 goto nla_put_failure; 8423 } 8424 8425 if (wdev) { 8426 if (nla_put_u64_64bit(skb, NL80211_ATTR_WDEV, 8427 wdev_id(wdev), NL80211_ATTR_PAD)) 8428 goto nla_put_failure; 8429 if (wdev->netdev && 8430 nla_put_u32(skb, NL80211_ATTR_IFINDEX, 8431 wdev->netdev->ifindex)) 8432 goto nla_put_failure; 8433 } 8434 8435 data = nla_nest_start(skb, attr); 8436 if (!data) 8437 goto nla_put_failure; 8438 8439 ((void **)skb->cb)[0] = rdev; 8440 ((void **)skb->cb)[1] = hdr; 8441 ((void **)skb->cb)[2] = data; 8442 8443 return skb; 8444 8445 nla_put_failure: 8446 kfree_skb(skb); 8447 return NULL; 8448 } 8449 8450 struct sk_buff *__cfg80211_alloc_event_skb(struct wiphy *wiphy, 8451 struct wireless_dev *wdev, 8452 enum nl80211_commands cmd, 8453 enum nl80211_attrs attr, 8454 int vendor_event_idx, 8455 int approxlen, gfp_t gfp) 8456 { 8457 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 8458 const struct nl80211_vendor_cmd_info *info; 8459 8460 switch (cmd) { 8461 case NL80211_CMD_TESTMODE: 8462 if (WARN_ON(vendor_event_idx != -1)) 8463 return NULL; 8464 info = NULL; 8465 break; 8466 case NL80211_CMD_VENDOR: 8467 if (WARN_ON(vendor_event_idx < 0 || 8468 vendor_event_idx >= wiphy->n_vendor_events)) 8469 return NULL; 8470 info = &wiphy->vendor_events[vendor_event_idx]; 8471 break; 8472 default: 8473 WARN_ON(1); 8474 return NULL; 8475 } 8476 8477 return __cfg80211_alloc_vendor_skb(rdev, wdev, approxlen, 0, 0, 8478 cmd, attr, info, gfp); 8479 } 8480 EXPORT_SYMBOL(__cfg80211_alloc_event_skb); 8481 8482 void __cfg80211_send_event_skb(struct sk_buff *skb, gfp_t gfp) 8483 { 8484 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0]; 8485 void *hdr = ((void **)skb->cb)[1]; 8486 struct nlattr *data = ((void **)skb->cb)[2]; 8487 enum nl80211_multicast_groups mcgrp = NL80211_MCGRP_TESTMODE; 8488 8489 /* clear CB data for netlink core to own from now on */ 8490 memset(skb->cb, 0, sizeof(skb->cb)); 8491 8492 nla_nest_end(skb, data); 8493 genlmsg_end(skb, hdr); 8494 8495 if (data->nla_type == NL80211_ATTR_VENDOR_DATA) 8496 mcgrp = NL80211_MCGRP_VENDOR; 8497 8498 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), skb, 0, 8499 mcgrp, gfp); 8500 } 8501 EXPORT_SYMBOL(__cfg80211_send_event_skb); 8502 8503 #ifdef CONFIG_NL80211_TESTMODE 8504 static int nl80211_testmode_do(struct sk_buff *skb, struct genl_info *info) 8505 { 8506 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8507 struct wireless_dev *wdev = 8508 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs); 8509 int err; 8510 8511 if (!rdev->ops->testmode_cmd) 8512 return -EOPNOTSUPP; 8513 8514 if (IS_ERR(wdev)) { 8515 err = PTR_ERR(wdev); 8516 if (err != -EINVAL) 8517 return err; 8518 wdev = NULL; 8519 } else if (wdev->wiphy != &rdev->wiphy) { 8520 return -EINVAL; 8521 } 8522 8523 if (!info->attrs[NL80211_ATTR_TESTDATA]) 8524 return -EINVAL; 8525 8526 rdev->cur_cmd_info = info; 8527 err = rdev_testmode_cmd(rdev, wdev, 8528 nla_data(info->attrs[NL80211_ATTR_TESTDATA]), 8529 nla_len(info->attrs[NL80211_ATTR_TESTDATA])); 8530 rdev->cur_cmd_info = NULL; 8531 8532 return err; 8533 } 8534 8535 static int nl80211_testmode_dump(struct sk_buff *skb, 8536 struct netlink_callback *cb) 8537 { 8538 struct cfg80211_registered_device *rdev; 8539 int err; 8540 long phy_idx; 8541 void *data = NULL; 8542 int data_len = 0; 8543 8544 rtnl_lock(); 8545 8546 if (cb->args[0]) { 8547 /* 8548 * 0 is a valid index, but not valid for args[0], 8549 * so we need to offset by 1. 8550 */ 8551 phy_idx = cb->args[0] - 1; 8552 } else { 8553 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 8554 8555 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 8556 attrbuf, nl80211_fam.maxattr, nl80211_policy); 8557 if (err) 8558 goto out_err; 8559 8560 rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf); 8561 if (IS_ERR(rdev)) { 8562 err = PTR_ERR(rdev); 8563 goto out_err; 8564 } 8565 phy_idx = rdev->wiphy_idx; 8566 rdev = NULL; 8567 8568 if (attrbuf[NL80211_ATTR_TESTDATA]) 8569 cb->args[1] = (long)attrbuf[NL80211_ATTR_TESTDATA]; 8570 } 8571 8572 if (cb->args[1]) { 8573 data = nla_data((void *)cb->args[1]); 8574 data_len = nla_len((void *)cb->args[1]); 8575 } 8576 8577 rdev = cfg80211_rdev_by_wiphy_idx(phy_idx); 8578 if (!rdev) { 8579 err = -ENOENT; 8580 goto out_err; 8581 } 8582 8583 if (!rdev->ops->testmode_dump) { 8584 err = -EOPNOTSUPP; 8585 goto out_err; 8586 } 8587 8588 while (1) { 8589 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid, 8590 cb->nlh->nlmsg_seq, NLM_F_MULTI, 8591 NL80211_CMD_TESTMODE); 8592 struct nlattr *tmdata; 8593 8594 if (!hdr) 8595 break; 8596 8597 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, phy_idx)) { 8598 genlmsg_cancel(skb, hdr); 8599 break; 8600 } 8601 8602 tmdata = nla_nest_start(skb, NL80211_ATTR_TESTDATA); 8603 if (!tmdata) { 8604 genlmsg_cancel(skb, hdr); 8605 break; 8606 } 8607 err = rdev_testmode_dump(rdev, skb, cb, data, data_len); 8608 nla_nest_end(skb, tmdata); 8609 8610 if (err == -ENOBUFS || err == -ENOENT) { 8611 genlmsg_cancel(skb, hdr); 8612 break; 8613 } else if (err) { 8614 genlmsg_cancel(skb, hdr); 8615 goto out_err; 8616 } 8617 8618 genlmsg_end(skb, hdr); 8619 } 8620 8621 err = skb->len; 8622 /* see above */ 8623 cb->args[0] = phy_idx + 1; 8624 out_err: 8625 rtnl_unlock(); 8626 return err; 8627 } 8628 #endif 8629 8630 static int nl80211_connect(struct sk_buff *skb, struct genl_info *info) 8631 { 8632 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8633 struct net_device *dev = info->user_ptr[1]; 8634 struct cfg80211_connect_params connect; 8635 struct wiphy *wiphy; 8636 struct cfg80211_cached_keys *connkeys = NULL; 8637 int err; 8638 8639 memset(&connect, 0, sizeof(connect)); 8640 8641 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8642 return -EINVAL; 8643 8644 if (!info->attrs[NL80211_ATTR_SSID] || 8645 !nla_len(info->attrs[NL80211_ATTR_SSID])) 8646 return -EINVAL; 8647 8648 if (info->attrs[NL80211_ATTR_AUTH_TYPE]) { 8649 connect.auth_type = 8650 nla_get_u32(info->attrs[NL80211_ATTR_AUTH_TYPE]); 8651 if (!nl80211_valid_auth_type(rdev, connect.auth_type, 8652 NL80211_CMD_CONNECT)) 8653 return -EINVAL; 8654 } else 8655 connect.auth_type = NL80211_AUTHTYPE_AUTOMATIC; 8656 8657 connect.privacy = info->attrs[NL80211_ATTR_PRIVACY]; 8658 8659 err = nl80211_crypto_settings(rdev, info, &connect.crypto, 8660 NL80211_MAX_NR_CIPHER_SUITES); 8661 if (err) 8662 return err; 8663 8664 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8665 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8666 return -EOPNOTSUPP; 8667 8668 wiphy = &rdev->wiphy; 8669 8670 connect.bg_scan_period = -1; 8671 if (info->attrs[NL80211_ATTR_BG_SCAN_PERIOD] && 8672 (wiphy->flags & WIPHY_FLAG_SUPPORTS_FW_ROAM)) { 8673 connect.bg_scan_period = 8674 nla_get_u16(info->attrs[NL80211_ATTR_BG_SCAN_PERIOD]); 8675 } 8676 8677 if (info->attrs[NL80211_ATTR_MAC]) 8678 connect.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8679 else if (info->attrs[NL80211_ATTR_MAC_HINT]) 8680 connect.bssid_hint = 8681 nla_data(info->attrs[NL80211_ATTR_MAC_HINT]); 8682 connect.ssid = nla_data(info->attrs[NL80211_ATTR_SSID]); 8683 connect.ssid_len = nla_len(info->attrs[NL80211_ATTR_SSID]); 8684 8685 if (info->attrs[NL80211_ATTR_IE]) { 8686 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8687 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8688 } 8689 8690 if (info->attrs[NL80211_ATTR_USE_MFP]) { 8691 connect.mfp = nla_get_u32(info->attrs[NL80211_ATTR_USE_MFP]); 8692 if (connect.mfp != NL80211_MFP_REQUIRED && 8693 connect.mfp != NL80211_MFP_NO) 8694 return -EINVAL; 8695 } else { 8696 connect.mfp = NL80211_MFP_NO; 8697 } 8698 8699 if (info->attrs[NL80211_ATTR_PREV_BSSID]) 8700 connect.prev_bssid = 8701 nla_data(info->attrs[NL80211_ATTR_PREV_BSSID]); 8702 8703 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 8704 connect.channel = nl80211_get_valid_chan( 8705 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ]); 8706 if (!connect.channel) 8707 return -EINVAL; 8708 } else if (info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]) { 8709 connect.channel_hint = nl80211_get_valid_chan( 8710 wiphy, info->attrs[NL80211_ATTR_WIPHY_FREQ_HINT]); 8711 if (!connect.channel_hint) 8712 return -EINVAL; 8713 } 8714 8715 if (connect.privacy && info->attrs[NL80211_ATTR_KEYS]) { 8716 connkeys = nl80211_parse_connkeys(rdev, 8717 info->attrs[NL80211_ATTR_KEYS], NULL); 8718 if (IS_ERR(connkeys)) 8719 return PTR_ERR(connkeys); 8720 } 8721 8722 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_HT])) 8723 connect.flags |= ASSOC_REQ_DISABLE_HT; 8724 8725 if (info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) 8726 memcpy(&connect.ht_capa_mask, 8727 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]), 8728 sizeof(connect.ht_capa_mask)); 8729 8730 if (info->attrs[NL80211_ATTR_HT_CAPABILITY]) { 8731 if (!info->attrs[NL80211_ATTR_HT_CAPABILITY_MASK]) { 8732 kzfree(connkeys); 8733 return -EINVAL; 8734 } 8735 memcpy(&connect.ht_capa, 8736 nla_data(info->attrs[NL80211_ATTR_HT_CAPABILITY]), 8737 sizeof(connect.ht_capa)); 8738 } 8739 8740 if (nla_get_flag(info->attrs[NL80211_ATTR_DISABLE_VHT])) 8741 connect.flags |= ASSOC_REQ_DISABLE_VHT; 8742 8743 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) 8744 memcpy(&connect.vht_capa_mask, 8745 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]), 8746 sizeof(connect.vht_capa_mask)); 8747 8748 if (info->attrs[NL80211_ATTR_VHT_CAPABILITY]) { 8749 if (!info->attrs[NL80211_ATTR_VHT_CAPABILITY_MASK]) { 8750 kzfree(connkeys); 8751 return -EINVAL; 8752 } 8753 memcpy(&connect.vht_capa, 8754 nla_data(info->attrs[NL80211_ATTR_VHT_CAPABILITY]), 8755 sizeof(connect.vht_capa)); 8756 } 8757 8758 if (nla_get_flag(info->attrs[NL80211_ATTR_USE_RRM])) { 8759 if (!((rdev->wiphy.features & 8760 NL80211_FEATURE_DS_PARAM_SET_IE_IN_PROBES) && 8761 (rdev->wiphy.features & NL80211_FEATURE_QUIET)) && 8762 !wiphy_ext_feature_isset(&rdev->wiphy, 8763 NL80211_EXT_FEATURE_RRM)) { 8764 kzfree(connkeys); 8765 return -EINVAL; 8766 } 8767 connect.flags |= ASSOC_REQ_USE_RRM; 8768 } 8769 8770 connect.pbss = nla_get_flag(info->attrs[NL80211_ATTR_PBSS]); 8771 if (connect.pbss && !rdev->wiphy.bands[NL80211_BAND_60GHZ]) { 8772 kzfree(connkeys); 8773 return -EOPNOTSUPP; 8774 } 8775 8776 if (info->attrs[NL80211_ATTR_BSS_SELECT]) { 8777 /* bss selection makes no sense if bssid is set */ 8778 if (connect.bssid) { 8779 kzfree(connkeys); 8780 return -EINVAL; 8781 } 8782 8783 err = parse_bss_select(info->attrs[NL80211_ATTR_BSS_SELECT], 8784 wiphy, &connect.bss_select); 8785 if (err) { 8786 kzfree(connkeys); 8787 return err; 8788 } 8789 } 8790 8791 wdev_lock(dev->ieee80211_ptr); 8792 err = cfg80211_connect(rdev, dev, &connect, connkeys, 8793 connect.prev_bssid); 8794 wdev_unlock(dev->ieee80211_ptr); 8795 if (err) 8796 kzfree(connkeys); 8797 return err; 8798 } 8799 8800 static int nl80211_update_connect_params(struct sk_buff *skb, 8801 struct genl_info *info) 8802 { 8803 struct cfg80211_connect_params connect = {}; 8804 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8805 struct net_device *dev = info->user_ptr[1]; 8806 struct wireless_dev *wdev = dev->ieee80211_ptr; 8807 u32 changed = 0; 8808 int ret; 8809 8810 if (!rdev->ops->update_connect_params) 8811 return -EOPNOTSUPP; 8812 8813 if (info->attrs[NL80211_ATTR_IE]) { 8814 if (!is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 8815 return -EINVAL; 8816 connect.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 8817 connect.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 8818 changed |= UPDATE_ASSOC_IES; 8819 } 8820 8821 wdev_lock(dev->ieee80211_ptr); 8822 if (!wdev->current_bss) 8823 ret = -ENOLINK; 8824 else 8825 ret = rdev_update_connect_params(rdev, dev, &connect, changed); 8826 wdev_unlock(dev->ieee80211_ptr); 8827 8828 return ret; 8829 } 8830 8831 static int nl80211_disconnect(struct sk_buff *skb, struct genl_info *info) 8832 { 8833 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8834 struct net_device *dev = info->user_ptr[1]; 8835 u16 reason; 8836 int ret; 8837 8838 if (!info->attrs[NL80211_ATTR_REASON_CODE]) 8839 reason = WLAN_REASON_DEAUTH_LEAVING; 8840 else 8841 reason = nla_get_u16(info->attrs[NL80211_ATTR_REASON_CODE]); 8842 8843 if (reason == 0) 8844 return -EINVAL; 8845 8846 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8847 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8848 return -EOPNOTSUPP; 8849 8850 wdev_lock(dev->ieee80211_ptr); 8851 ret = cfg80211_disconnect(rdev, dev, reason, true); 8852 wdev_unlock(dev->ieee80211_ptr); 8853 return ret; 8854 } 8855 8856 static int nl80211_wiphy_netns(struct sk_buff *skb, struct genl_info *info) 8857 { 8858 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8859 struct net *net; 8860 int err; 8861 8862 if (info->attrs[NL80211_ATTR_PID]) { 8863 u32 pid = nla_get_u32(info->attrs[NL80211_ATTR_PID]); 8864 8865 net = get_net_ns_by_pid(pid); 8866 } else if (info->attrs[NL80211_ATTR_NETNS_FD]) { 8867 u32 fd = nla_get_u32(info->attrs[NL80211_ATTR_NETNS_FD]); 8868 8869 net = get_net_ns_by_fd(fd); 8870 } else { 8871 return -EINVAL; 8872 } 8873 8874 if (IS_ERR(net)) 8875 return PTR_ERR(net); 8876 8877 err = 0; 8878 8879 /* check if anything to do */ 8880 if (!net_eq(wiphy_net(&rdev->wiphy), net)) 8881 err = cfg80211_switch_netns(rdev, net); 8882 8883 put_net(net); 8884 return err; 8885 } 8886 8887 static int nl80211_setdel_pmksa(struct sk_buff *skb, struct genl_info *info) 8888 { 8889 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8890 int (*rdev_ops)(struct wiphy *wiphy, struct net_device *dev, 8891 struct cfg80211_pmksa *pmksa) = NULL; 8892 struct net_device *dev = info->user_ptr[1]; 8893 struct cfg80211_pmksa pmksa; 8894 8895 memset(&pmksa, 0, sizeof(struct cfg80211_pmksa)); 8896 8897 if (!info->attrs[NL80211_ATTR_MAC]) 8898 return -EINVAL; 8899 8900 if (!info->attrs[NL80211_ATTR_PMKID]) 8901 return -EINVAL; 8902 8903 pmksa.pmkid = nla_data(info->attrs[NL80211_ATTR_PMKID]); 8904 pmksa.bssid = nla_data(info->attrs[NL80211_ATTR_MAC]); 8905 8906 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8907 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8908 return -EOPNOTSUPP; 8909 8910 switch (info->genlhdr->cmd) { 8911 case NL80211_CMD_SET_PMKSA: 8912 rdev_ops = rdev->ops->set_pmksa; 8913 break; 8914 case NL80211_CMD_DEL_PMKSA: 8915 rdev_ops = rdev->ops->del_pmksa; 8916 break; 8917 default: 8918 WARN_ON(1); 8919 break; 8920 } 8921 8922 if (!rdev_ops) 8923 return -EOPNOTSUPP; 8924 8925 return rdev_ops(&rdev->wiphy, dev, &pmksa); 8926 } 8927 8928 static int nl80211_flush_pmksa(struct sk_buff *skb, struct genl_info *info) 8929 { 8930 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8931 struct net_device *dev = info->user_ptr[1]; 8932 8933 if (dev->ieee80211_ptr->iftype != NL80211_IFTYPE_STATION && 8934 dev->ieee80211_ptr->iftype != NL80211_IFTYPE_P2P_CLIENT) 8935 return -EOPNOTSUPP; 8936 8937 if (!rdev->ops->flush_pmksa) 8938 return -EOPNOTSUPP; 8939 8940 return rdev_flush_pmksa(rdev, dev); 8941 } 8942 8943 static int nl80211_tdls_mgmt(struct sk_buff *skb, struct genl_info *info) 8944 { 8945 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8946 struct net_device *dev = info->user_ptr[1]; 8947 u8 action_code, dialog_token; 8948 u32 peer_capability = 0; 8949 u16 status_code; 8950 u8 *peer; 8951 bool initiator; 8952 8953 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) || 8954 !rdev->ops->tdls_mgmt) 8955 return -EOPNOTSUPP; 8956 8957 if (!info->attrs[NL80211_ATTR_TDLS_ACTION] || 8958 !info->attrs[NL80211_ATTR_STATUS_CODE] || 8959 !info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN] || 8960 !info->attrs[NL80211_ATTR_IE] || 8961 !info->attrs[NL80211_ATTR_MAC]) 8962 return -EINVAL; 8963 8964 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 8965 action_code = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_ACTION]); 8966 status_code = nla_get_u16(info->attrs[NL80211_ATTR_STATUS_CODE]); 8967 dialog_token = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_DIALOG_TOKEN]); 8968 initiator = nla_get_flag(info->attrs[NL80211_ATTR_TDLS_INITIATOR]); 8969 if (info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]) 8970 peer_capability = 8971 nla_get_u32(info->attrs[NL80211_ATTR_TDLS_PEER_CAPABILITY]); 8972 8973 return rdev_tdls_mgmt(rdev, dev, peer, action_code, 8974 dialog_token, status_code, peer_capability, 8975 initiator, 8976 nla_data(info->attrs[NL80211_ATTR_IE]), 8977 nla_len(info->attrs[NL80211_ATTR_IE])); 8978 } 8979 8980 static int nl80211_tdls_oper(struct sk_buff *skb, struct genl_info *info) 8981 { 8982 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 8983 struct net_device *dev = info->user_ptr[1]; 8984 enum nl80211_tdls_operation operation; 8985 u8 *peer; 8986 8987 if (!(rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_TDLS) || 8988 !rdev->ops->tdls_oper) 8989 return -EOPNOTSUPP; 8990 8991 if (!info->attrs[NL80211_ATTR_TDLS_OPERATION] || 8992 !info->attrs[NL80211_ATTR_MAC]) 8993 return -EINVAL; 8994 8995 operation = nla_get_u8(info->attrs[NL80211_ATTR_TDLS_OPERATION]); 8996 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 8997 8998 return rdev_tdls_oper(rdev, dev, peer, operation); 8999 } 9000 9001 static int nl80211_remain_on_channel(struct sk_buff *skb, 9002 struct genl_info *info) 9003 { 9004 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9005 struct wireless_dev *wdev = info->user_ptr[1]; 9006 struct cfg80211_chan_def chandef; 9007 struct sk_buff *msg; 9008 void *hdr; 9009 u64 cookie; 9010 u32 duration; 9011 int err; 9012 9013 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ] || 9014 !info->attrs[NL80211_ATTR_DURATION]) 9015 return -EINVAL; 9016 9017 duration = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]); 9018 9019 if (!rdev->ops->remain_on_channel || 9020 !(rdev->wiphy.flags & WIPHY_FLAG_HAS_REMAIN_ON_CHANNEL)) 9021 return -EOPNOTSUPP; 9022 9023 /* 9024 * We should be on that channel for at least a minimum amount of 9025 * time (10ms) but no longer than the driver supports. 9026 */ 9027 if (duration < NL80211_MIN_REMAIN_ON_CHANNEL_TIME || 9028 duration > rdev->wiphy.max_remain_on_channel_duration) 9029 return -EINVAL; 9030 9031 err = nl80211_parse_chandef(rdev, info, &chandef); 9032 if (err) 9033 return err; 9034 9035 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9036 if (!msg) 9037 return -ENOMEM; 9038 9039 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9040 NL80211_CMD_REMAIN_ON_CHANNEL); 9041 if (!hdr) { 9042 err = -ENOBUFS; 9043 goto free_msg; 9044 } 9045 9046 err = rdev_remain_on_channel(rdev, wdev, chandef.chan, 9047 duration, &cookie); 9048 9049 if (err) 9050 goto free_msg; 9051 9052 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 9053 NL80211_ATTR_PAD)) 9054 goto nla_put_failure; 9055 9056 genlmsg_end(msg, hdr); 9057 9058 return genlmsg_reply(msg, info); 9059 9060 nla_put_failure: 9061 err = -ENOBUFS; 9062 free_msg: 9063 nlmsg_free(msg); 9064 return err; 9065 } 9066 9067 static int nl80211_cancel_remain_on_channel(struct sk_buff *skb, 9068 struct genl_info *info) 9069 { 9070 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9071 struct wireless_dev *wdev = info->user_ptr[1]; 9072 u64 cookie; 9073 9074 if (!info->attrs[NL80211_ATTR_COOKIE]) 9075 return -EINVAL; 9076 9077 if (!rdev->ops->cancel_remain_on_channel) 9078 return -EOPNOTSUPP; 9079 9080 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 9081 9082 return rdev_cancel_remain_on_channel(rdev, wdev, cookie); 9083 } 9084 9085 static int nl80211_set_tx_bitrate_mask(struct sk_buff *skb, 9086 struct genl_info *info) 9087 { 9088 struct cfg80211_bitrate_mask mask; 9089 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9090 struct net_device *dev = info->user_ptr[1]; 9091 int err; 9092 9093 if (!rdev->ops->set_bitrate_mask) 9094 return -EOPNOTSUPP; 9095 9096 err = nl80211_parse_tx_bitrate_mask(info, &mask); 9097 if (err) 9098 return err; 9099 9100 return rdev_set_bitrate_mask(rdev, dev, NULL, &mask); 9101 } 9102 9103 static int nl80211_register_mgmt(struct sk_buff *skb, struct genl_info *info) 9104 { 9105 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9106 struct wireless_dev *wdev = info->user_ptr[1]; 9107 u16 frame_type = IEEE80211_FTYPE_MGMT | IEEE80211_STYPE_ACTION; 9108 9109 if (!info->attrs[NL80211_ATTR_FRAME_MATCH]) 9110 return -EINVAL; 9111 9112 if (info->attrs[NL80211_ATTR_FRAME_TYPE]) 9113 frame_type = nla_get_u16(info->attrs[NL80211_ATTR_FRAME_TYPE]); 9114 9115 switch (wdev->iftype) { 9116 case NL80211_IFTYPE_STATION: 9117 case NL80211_IFTYPE_ADHOC: 9118 case NL80211_IFTYPE_P2P_CLIENT: 9119 case NL80211_IFTYPE_AP: 9120 case NL80211_IFTYPE_AP_VLAN: 9121 case NL80211_IFTYPE_MESH_POINT: 9122 case NL80211_IFTYPE_P2P_GO: 9123 case NL80211_IFTYPE_P2P_DEVICE: 9124 break; 9125 case NL80211_IFTYPE_NAN: 9126 default: 9127 return -EOPNOTSUPP; 9128 } 9129 9130 /* not much point in registering if we can't reply */ 9131 if (!rdev->ops->mgmt_tx) 9132 return -EOPNOTSUPP; 9133 9134 return cfg80211_mlme_register_mgmt(wdev, info->snd_portid, frame_type, 9135 nla_data(info->attrs[NL80211_ATTR_FRAME_MATCH]), 9136 nla_len(info->attrs[NL80211_ATTR_FRAME_MATCH])); 9137 } 9138 9139 static int nl80211_tx_mgmt(struct sk_buff *skb, struct genl_info *info) 9140 { 9141 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9142 struct wireless_dev *wdev = info->user_ptr[1]; 9143 struct cfg80211_chan_def chandef; 9144 int err; 9145 void *hdr = NULL; 9146 u64 cookie; 9147 struct sk_buff *msg = NULL; 9148 struct cfg80211_mgmt_tx_params params = { 9149 .dont_wait_for_ack = 9150 info->attrs[NL80211_ATTR_DONT_WAIT_FOR_ACK], 9151 }; 9152 9153 if (!info->attrs[NL80211_ATTR_FRAME]) 9154 return -EINVAL; 9155 9156 if (!rdev->ops->mgmt_tx) 9157 return -EOPNOTSUPP; 9158 9159 switch (wdev->iftype) { 9160 case NL80211_IFTYPE_P2P_DEVICE: 9161 if (!info->attrs[NL80211_ATTR_WIPHY_FREQ]) 9162 return -EINVAL; 9163 case NL80211_IFTYPE_STATION: 9164 case NL80211_IFTYPE_ADHOC: 9165 case NL80211_IFTYPE_P2P_CLIENT: 9166 case NL80211_IFTYPE_AP: 9167 case NL80211_IFTYPE_AP_VLAN: 9168 case NL80211_IFTYPE_MESH_POINT: 9169 case NL80211_IFTYPE_P2P_GO: 9170 break; 9171 case NL80211_IFTYPE_NAN: 9172 default: 9173 return -EOPNOTSUPP; 9174 } 9175 9176 if (info->attrs[NL80211_ATTR_DURATION]) { 9177 if (!(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)) 9178 return -EINVAL; 9179 params.wait = nla_get_u32(info->attrs[NL80211_ATTR_DURATION]); 9180 9181 /* 9182 * We should wait on the channel for at least a minimum amount 9183 * of time (10ms) but no longer than the driver supports. 9184 */ 9185 if (params.wait < NL80211_MIN_REMAIN_ON_CHANNEL_TIME || 9186 params.wait > rdev->wiphy.max_remain_on_channel_duration) 9187 return -EINVAL; 9188 } 9189 9190 params.offchan = info->attrs[NL80211_ATTR_OFFCHANNEL_TX_OK]; 9191 9192 if (params.offchan && !(rdev->wiphy.flags & WIPHY_FLAG_OFFCHAN_TX)) 9193 return -EINVAL; 9194 9195 params.no_cck = nla_get_flag(info->attrs[NL80211_ATTR_TX_NO_CCK_RATE]); 9196 9197 /* get the channel if any has been specified, otherwise pass NULL to 9198 * the driver. The latter will use the current one 9199 */ 9200 chandef.chan = NULL; 9201 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 9202 err = nl80211_parse_chandef(rdev, info, &chandef); 9203 if (err) 9204 return err; 9205 } 9206 9207 if (!chandef.chan && params.offchan) 9208 return -EINVAL; 9209 9210 params.buf = nla_data(info->attrs[NL80211_ATTR_FRAME]); 9211 params.len = nla_len(info->attrs[NL80211_ATTR_FRAME]); 9212 9213 if (info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]) { 9214 int len = nla_len(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]); 9215 int i; 9216 9217 if (len % sizeof(u16)) 9218 return -EINVAL; 9219 9220 params.n_csa_offsets = len / sizeof(u16); 9221 params.csa_offsets = 9222 nla_data(info->attrs[NL80211_ATTR_CSA_C_OFFSETS_TX]); 9223 9224 /* check that all the offsets fit the frame */ 9225 for (i = 0; i < params.n_csa_offsets; i++) { 9226 if (params.csa_offsets[i] >= params.len) 9227 return -EINVAL; 9228 } 9229 } 9230 9231 if (!params.dont_wait_for_ack) { 9232 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9233 if (!msg) 9234 return -ENOMEM; 9235 9236 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9237 NL80211_CMD_FRAME); 9238 if (!hdr) { 9239 err = -ENOBUFS; 9240 goto free_msg; 9241 } 9242 } 9243 9244 params.chan = chandef.chan; 9245 err = cfg80211_mlme_mgmt_tx(rdev, wdev, ¶ms, &cookie); 9246 if (err) 9247 goto free_msg; 9248 9249 if (msg) { 9250 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 9251 NL80211_ATTR_PAD)) 9252 goto nla_put_failure; 9253 9254 genlmsg_end(msg, hdr); 9255 return genlmsg_reply(msg, info); 9256 } 9257 9258 return 0; 9259 9260 nla_put_failure: 9261 err = -ENOBUFS; 9262 free_msg: 9263 nlmsg_free(msg); 9264 return err; 9265 } 9266 9267 static int nl80211_tx_mgmt_cancel_wait(struct sk_buff *skb, struct genl_info *info) 9268 { 9269 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9270 struct wireless_dev *wdev = info->user_ptr[1]; 9271 u64 cookie; 9272 9273 if (!info->attrs[NL80211_ATTR_COOKIE]) 9274 return -EINVAL; 9275 9276 if (!rdev->ops->mgmt_tx_cancel_wait) 9277 return -EOPNOTSUPP; 9278 9279 switch (wdev->iftype) { 9280 case NL80211_IFTYPE_STATION: 9281 case NL80211_IFTYPE_ADHOC: 9282 case NL80211_IFTYPE_P2P_CLIENT: 9283 case NL80211_IFTYPE_AP: 9284 case NL80211_IFTYPE_AP_VLAN: 9285 case NL80211_IFTYPE_P2P_GO: 9286 case NL80211_IFTYPE_P2P_DEVICE: 9287 break; 9288 case NL80211_IFTYPE_NAN: 9289 default: 9290 return -EOPNOTSUPP; 9291 } 9292 9293 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 9294 9295 return rdev_mgmt_tx_cancel_wait(rdev, wdev, cookie); 9296 } 9297 9298 static int nl80211_set_power_save(struct sk_buff *skb, struct genl_info *info) 9299 { 9300 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9301 struct wireless_dev *wdev; 9302 struct net_device *dev = info->user_ptr[1]; 9303 u8 ps_state; 9304 bool state; 9305 int err; 9306 9307 if (!info->attrs[NL80211_ATTR_PS_STATE]) 9308 return -EINVAL; 9309 9310 ps_state = nla_get_u32(info->attrs[NL80211_ATTR_PS_STATE]); 9311 9312 if (ps_state != NL80211_PS_DISABLED && ps_state != NL80211_PS_ENABLED) 9313 return -EINVAL; 9314 9315 wdev = dev->ieee80211_ptr; 9316 9317 if (!rdev->ops->set_power_mgmt) 9318 return -EOPNOTSUPP; 9319 9320 state = (ps_state == NL80211_PS_ENABLED) ? true : false; 9321 9322 if (state == wdev->ps) 9323 return 0; 9324 9325 err = rdev_set_power_mgmt(rdev, dev, state, wdev->ps_timeout); 9326 if (!err) 9327 wdev->ps = state; 9328 return err; 9329 } 9330 9331 static int nl80211_get_power_save(struct sk_buff *skb, struct genl_info *info) 9332 { 9333 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9334 enum nl80211_ps_state ps_state; 9335 struct wireless_dev *wdev; 9336 struct net_device *dev = info->user_ptr[1]; 9337 struct sk_buff *msg; 9338 void *hdr; 9339 int err; 9340 9341 wdev = dev->ieee80211_ptr; 9342 9343 if (!rdev->ops->set_power_mgmt) 9344 return -EOPNOTSUPP; 9345 9346 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 9347 if (!msg) 9348 return -ENOMEM; 9349 9350 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9351 NL80211_CMD_GET_POWER_SAVE); 9352 if (!hdr) { 9353 err = -ENOBUFS; 9354 goto free_msg; 9355 } 9356 9357 if (wdev->ps) 9358 ps_state = NL80211_PS_ENABLED; 9359 else 9360 ps_state = NL80211_PS_DISABLED; 9361 9362 if (nla_put_u32(msg, NL80211_ATTR_PS_STATE, ps_state)) 9363 goto nla_put_failure; 9364 9365 genlmsg_end(msg, hdr); 9366 return genlmsg_reply(msg, info); 9367 9368 nla_put_failure: 9369 err = -ENOBUFS; 9370 free_msg: 9371 nlmsg_free(msg); 9372 return err; 9373 } 9374 9375 static const struct nla_policy 9376 nl80211_attr_cqm_policy[NL80211_ATTR_CQM_MAX + 1] = { 9377 [NL80211_ATTR_CQM_RSSI_THOLD] = { .type = NLA_U32 }, 9378 [NL80211_ATTR_CQM_RSSI_HYST] = { .type = NLA_U32 }, 9379 [NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT] = { .type = NLA_U32 }, 9380 [NL80211_ATTR_CQM_TXE_RATE] = { .type = NLA_U32 }, 9381 [NL80211_ATTR_CQM_TXE_PKTS] = { .type = NLA_U32 }, 9382 [NL80211_ATTR_CQM_TXE_INTVL] = { .type = NLA_U32 }, 9383 }; 9384 9385 static int nl80211_set_cqm_txe(struct genl_info *info, 9386 u32 rate, u32 pkts, u32 intvl) 9387 { 9388 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9389 struct net_device *dev = info->user_ptr[1]; 9390 struct wireless_dev *wdev = dev->ieee80211_ptr; 9391 9392 if (rate > 100 || intvl > NL80211_CQM_TXE_MAX_INTVL) 9393 return -EINVAL; 9394 9395 if (!rdev->ops->set_cqm_txe_config) 9396 return -EOPNOTSUPP; 9397 9398 if (wdev->iftype != NL80211_IFTYPE_STATION && 9399 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) 9400 return -EOPNOTSUPP; 9401 9402 return rdev_set_cqm_txe_config(rdev, dev, rate, pkts, intvl); 9403 } 9404 9405 static int nl80211_set_cqm_rssi(struct genl_info *info, 9406 s32 threshold, u32 hysteresis) 9407 { 9408 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9409 struct net_device *dev = info->user_ptr[1]; 9410 struct wireless_dev *wdev = dev->ieee80211_ptr; 9411 9412 if (threshold > 0) 9413 return -EINVAL; 9414 9415 /* disabling - hysteresis should also be zero then */ 9416 if (threshold == 0) 9417 hysteresis = 0; 9418 9419 if (!rdev->ops->set_cqm_rssi_config) 9420 return -EOPNOTSUPP; 9421 9422 if (wdev->iftype != NL80211_IFTYPE_STATION && 9423 wdev->iftype != NL80211_IFTYPE_P2P_CLIENT) 9424 return -EOPNOTSUPP; 9425 9426 return rdev_set_cqm_rssi_config(rdev, dev, threshold, hysteresis); 9427 } 9428 9429 static int nl80211_set_cqm(struct sk_buff *skb, struct genl_info *info) 9430 { 9431 struct nlattr *attrs[NL80211_ATTR_CQM_MAX + 1]; 9432 struct nlattr *cqm; 9433 int err; 9434 9435 cqm = info->attrs[NL80211_ATTR_CQM]; 9436 if (!cqm) 9437 return -EINVAL; 9438 9439 err = nla_parse_nested(attrs, NL80211_ATTR_CQM_MAX, cqm, 9440 nl80211_attr_cqm_policy); 9441 if (err) 9442 return err; 9443 9444 if (attrs[NL80211_ATTR_CQM_RSSI_THOLD] && 9445 attrs[NL80211_ATTR_CQM_RSSI_HYST]) { 9446 s32 threshold = nla_get_s32(attrs[NL80211_ATTR_CQM_RSSI_THOLD]); 9447 u32 hysteresis = nla_get_u32(attrs[NL80211_ATTR_CQM_RSSI_HYST]); 9448 9449 return nl80211_set_cqm_rssi(info, threshold, hysteresis); 9450 } 9451 9452 if (attrs[NL80211_ATTR_CQM_TXE_RATE] && 9453 attrs[NL80211_ATTR_CQM_TXE_PKTS] && 9454 attrs[NL80211_ATTR_CQM_TXE_INTVL]) { 9455 u32 rate = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_RATE]); 9456 u32 pkts = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_PKTS]); 9457 u32 intvl = nla_get_u32(attrs[NL80211_ATTR_CQM_TXE_INTVL]); 9458 9459 return nl80211_set_cqm_txe(info, rate, pkts, intvl); 9460 } 9461 9462 return -EINVAL; 9463 } 9464 9465 static int nl80211_join_ocb(struct sk_buff *skb, struct genl_info *info) 9466 { 9467 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9468 struct net_device *dev = info->user_ptr[1]; 9469 struct ocb_setup setup = {}; 9470 int err; 9471 9472 err = nl80211_parse_chandef(rdev, info, &setup.chandef); 9473 if (err) 9474 return err; 9475 9476 return cfg80211_join_ocb(rdev, dev, &setup); 9477 } 9478 9479 static int nl80211_leave_ocb(struct sk_buff *skb, struct genl_info *info) 9480 { 9481 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9482 struct net_device *dev = info->user_ptr[1]; 9483 9484 return cfg80211_leave_ocb(rdev, dev); 9485 } 9486 9487 static int nl80211_join_mesh(struct sk_buff *skb, struct genl_info *info) 9488 { 9489 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9490 struct net_device *dev = info->user_ptr[1]; 9491 struct mesh_config cfg; 9492 struct mesh_setup setup; 9493 int err; 9494 9495 /* start with default */ 9496 memcpy(&cfg, &default_mesh_config, sizeof(cfg)); 9497 memcpy(&setup, &default_mesh_setup, sizeof(setup)); 9498 9499 if (info->attrs[NL80211_ATTR_MESH_CONFIG]) { 9500 /* and parse parameters if given */ 9501 err = nl80211_parse_mesh_config(info, &cfg, NULL); 9502 if (err) 9503 return err; 9504 } 9505 9506 if (!info->attrs[NL80211_ATTR_MESH_ID] || 9507 !nla_len(info->attrs[NL80211_ATTR_MESH_ID])) 9508 return -EINVAL; 9509 9510 setup.mesh_id = nla_data(info->attrs[NL80211_ATTR_MESH_ID]); 9511 setup.mesh_id_len = nla_len(info->attrs[NL80211_ATTR_MESH_ID]); 9512 9513 if (info->attrs[NL80211_ATTR_MCAST_RATE] && 9514 !nl80211_parse_mcast_rate(rdev, setup.mcast_rate, 9515 nla_get_u32(info->attrs[NL80211_ATTR_MCAST_RATE]))) 9516 return -EINVAL; 9517 9518 if (info->attrs[NL80211_ATTR_BEACON_INTERVAL]) { 9519 setup.beacon_interval = 9520 nla_get_u32(info->attrs[NL80211_ATTR_BEACON_INTERVAL]); 9521 9522 err = cfg80211_validate_beacon_int(rdev, 9523 NL80211_IFTYPE_MESH_POINT, 9524 setup.beacon_interval); 9525 if (err) 9526 return err; 9527 } 9528 9529 if (info->attrs[NL80211_ATTR_DTIM_PERIOD]) { 9530 setup.dtim_period = 9531 nla_get_u32(info->attrs[NL80211_ATTR_DTIM_PERIOD]); 9532 if (setup.dtim_period < 1 || setup.dtim_period > 100) 9533 return -EINVAL; 9534 } 9535 9536 if (info->attrs[NL80211_ATTR_MESH_SETUP]) { 9537 /* parse additional setup parameters if given */ 9538 err = nl80211_parse_mesh_setup(info, &setup); 9539 if (err) 9540 return err; 9541 } 9542 9543 if (setup.user_mpm) 9544 cfg.auto_open_plinks = false; 9545 9546 if (info->attrs[NL80211_ATTR_WIPHY_FREQ]) { 9547 err = nl80211_parse_chandef(rdev, info, &setup.chandef); 9548 if (err) 9549 return err; 9550 } else { 9551 /* cfg80211_join_mesh() will sort it out */ 9552 setup.chandef.chan = NULL; 9553 } 9554 9555 if (info->attrs[NL80211_ATTR_BSS_BASIC_RATES]) { 9556 u8 *rates = nla_data(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 9557 int n_rates = 9558 nla_len(info->attrs[NL80211_ATTR_BSS_BASIC_RATES]); 9559 struct ieee80211_supported_band *sband; 9560 9561 if (!setup.chandef.chan) 9562 return -EINVAL; 9563 9564 sband = rdev->wiphy.bands[setup.chandef.chan->band]; 9565 9566 err = ieee80211_get_ratemask(sband, rates, n_rates, 9567 &setup.basic_rates); 9568 if (err) 9569 return err; 9570 } 9571 9572 if (info->attrs[NL80211_ATTR_TX_RATES]) { 9573 err = nl80211_parse_tx_bitrate_mask(info, &setup.beacon_rate); 9574 if (err) 9575 return err; 9576 9577 err = validate_beacon_tx_rate(rdev, setup.chandef.chan->band, 9578 &setup.beacon_rate); 9579 if (err) 9580 return err; 9581 } 9582 9583 return cfg80211_join_mesh(rdev, dev, &setup, &cfg); 9584 } 9585 9586 static int nl80211_leave_mesh(struct sk_buff *skb, struct genl_info *info) 9587 { 9588 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9589 struct net_device *dev = info->user_ptr[1]; 9590 9591 return cfg80211_leave_mesh(rdev, dev); 9592 } 9593 9594 #ifdef CONFIG_PM 9595 static int nl80211_send_wowlan_patterns(struct sk_buff *msg, 9596 struct cfg80211_registered_device *rdev) 9597 { 9598 struct cfg80211_wowlan *wowlan = rdev->wiphy.wowlan_config; 9599 struct nlattr *nl_pats, *nl_pat; 9600 int i, pat_len; 9601 9602 if (!wowlan->n_patterns) 9603 return 0; 9604 9605 nl_pats = nla_nest_start(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN); 9606 if (!nl_pats) 9607 return -ENOBUFS; 9608 9609 for (i = 0; i < wowlan->n_patterns; i++) { 9610 nl_pat = nla_nest_start(msg, i + 1); 9611 if (!nl_pat) 9612 return -ENOBUFS; 9613 pat_len = wowlan->patterns[i].pattern_len; 9614 if (nla_put(msg, NL80211_PKTPAT_MASK, DIV_ROUND_UP(pat_len, 8), 9615 wowlan->patterns[i].mask) || 9616 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len, 9617 wowlan->patterns[i].pattern) || 9618 nla_put_u32(msg, NL80211_PKTPAT_OFFSET, 9619 wowlan->patterns[i].pkt_offset)) 9620 return -ENOBUFS; 9621 nla_nest_end(msg, nl_pat); 9622 } 9623 nla_nest_end(msg, nl_pats); 9624 9625 return 0; 9626 } 9627 9628 static int nl80211_send_wowlan_tcp(struct sk_buff *msg, 9629 struct cfg80211_wowlan_tcp *tcp) 9630 { 9631 struct nlattr *nl_tcp; 9632 9633 if (!tcp) 9634 return 0; 9635 9636 nl_tcp = nla_nest_start(msg, NL80211_WOWLAN_TRIG_TCP_CONNECTION); 9637 if (!nl_tcp) 9638 return -ENOBUFS; 9639 9640 if (nla_put_in_addr(msg, NL80211_WOWLAN_TCP_SRC_IPV4, tcp->src) || 9641 nla_put_in_addr(msg, NL80211_WOWLAN_TCP_DST_IPV4, tcp->dst) || 9642 nla_put(msg, NL80211_WOWLAN_TCP_DST_MAC, ETH_ALEN, tcp->dst_mac) || 9643 nla_put_u16(msg, NL80211_WOWLAN_TCP_SRC_PORT, tcp->src_port) || 9644 nla_put_u16(msg, NL80211_WOWLAN_TCP_DST_PORT, tcp->dst_port) || 9645 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD, 9646 tcp->payload_len, tcp->payload) || 9647 nla_put_u32(msg, NL80211_WOWLAN_TCP_DATA_INTERVAL, 9648 tcp->data_interval) || 9649 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_PAYLOAD, 9650 tcp->wake_len, tcp->wake_data) || 9651 nla_put(msg, NL80211_WOWLAN_TCP_WAKE_MASK, 9652 DIV_ROUND_UP(tcp->wake_len, 8), tcp->wake_mask)) 9653 return -ENOBUFS; 9654 9655 if (tcp->payload_seq.len && 9656 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ, 9657 sizeof(tcp->payload_seq), &tcp->payload_seq)) 9658 return -ENOBUFS; 9659 9660 if (tcp->payload_tok.len && 9661 nla_put(msg, NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN, 9662 sizeof(tcp->payload_tok) + tcp->tokens_size, 9663 &tcp->payload_tok)) 9664 return -ENOBUFS; 9665 9666 nla_nest_end(msg, nl_tcp); 9667 9668 return 0; 9669 } 9670 9671 static int nl80211_send_wowlan_nd(struct sk_buff *msg, 9672 struct cfg80211_sched_scan_request *req) 9673 { 9674 struct nlattr *nd, *freqs, *matches, *match, *scan_plans, *scan_plan; 9675 int i; 9676 9677 if (!req) 9678 return 0; 9679 9680 nd = nla_nest_start(msg, NL80211_WOWLAN_TRIG_NET_DETECT); 9681 if (!nd) 9682 return -ENOBUFS; 9683 9684 if (req->n_scan_plans == 1 && 9685 nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_INTERVAL, 9686 req->scan_plans[0].interval * 1000)) 9687 return -ENOBUFS; 9688 9689 if (nla_put_u32(msg, NL80211_ATTR_SCHED_SCAN_DELAY, req->delay)) 9690 return -ENOBUFS; 9691 9692 freqs = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES); 9693 if (!freqs) 9694 return -ENOBUFS; 9695 9696 for (i = 0; i < req->n_channels; i++) { 9697 if (nla_put_u32(msg, i, req->channels[i]->center_freq)) 9698 return -ENOBUFS; 9699 } 9700 9701 nla_nest_end(msg, freqs); 9702 9703 if (req->n_match_sets) { 9704 matches = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_MATCH); 9705 if (!matches) 9706 return -ENOBUFS; 9707 9708 for (i = 0; i < req->n_match_sets; i++) { 9709 match = nla_nest_start(msg, i); 9710 if (!match) 9711 return -ENOBUFS; 9712 9713 if (nla_put(msg, NL80211_SCHED_SCAN_MATCH_ATTR_SSID, 9714 req->match_sets[i].ssid.ssid_len, 9715 req->match_sets[i].ssid.ssid)) 9716 return -ENOBUFS; 9717 nla_nest_end(msg, match); 9718 } 9719 nla_nest_end(msg, matches); 9720 } 9721 9722 scan_plans = nla_nest_start(msg, NL80211_ATTR_SCHED_SCAN_PLANS); 9723 if (!scan_plans) 9724 return -ENOBUFS; 9725 9726 for (i = 0; i < req->n_scan_plans; i++) { 9727 scan_plan = nla_nest_start(msg, i + 1); 9728 if (!scan_plan) 9729 return -ENOBUFS; 9730 9731 if (!scan_plan || 9732 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_INTERVAL, 9733 req->scan_plans[i].interval) || 9734 (req->scan_plans[i].iterations && 9735 nla_put_u32(msg, NL80211_SCHED_SCAN_PLAN_ITERATIONS, 9736 req->scan_plans[i].iterations))) 9737 return -ENOBUFS; 9738 nla_nest_end(msg, scan_plan); 9739 } 9740 nla_nest_end(msg, scan_plans); 9741 9742 nla_nest_end(msg, nd); 9743 9744 return 0; 9745 } 9746 9747 static int nl80211_get_wowlan(struct sk_buff *skb, struct genl_info *info) 9748 { 9749 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9750 struct sk_buff *msg; 9751 void *hdr; 9752 u32 size = NLMSG_DEFAULT_SIZE; 9753 9754 if (!rdev->wiphy.wowlan) 9755 return -EOPNOTSUPP; 9756 9757 if (rdev->wiphy.wowlan_config && rdev->wiphy.wowlan_config->tcp) { 9758 /* adjust size to have room for all the data */ 9759 size += rdev->wiphy.wowlan_config->tcp->tokens_size + 9760 rdev->wiphy.wowlan_config->tcp->payload_len + 9761 rdev->wiphy.wowlan_config->tcp->wake_len + 9762 rdev->wiphy.wowlan_config->tcp->wake_len / 8; 9763 } 9764 9765 msg = nlmsg_new(size, GFP_KERNEL); 9766 if (!msg) 9767 return -ENOMEM; 9768 9769 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 9770 NL80211_CMD_GET_WOWLAN); 9771 if (!hdr) 9772 goto nla_put_failure; 9773 9774 if (rdev->wiphy.wowlan_config) { 9775 struct nlattr *nl_wowlan; 9776 9777 nl_wowlan = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS); 9778 if (!nl_wowlan) 9779 goto nla_put_failure; 9780 9781 if ((rdev->wiphy.wowlan_config->any && 9782 nla_put_flag(msg, NL80211_WOWLAN_TRIG_ANY)) || 9783 (rdev->wiphy.wowlan_config->disconnect && 9784 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) || 9785 (rdev->wiphy.wowlan_config->magic_pkt && 9786 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) || 9787 (rdev->wiphy.wowlan_config->gtk_rekey_failure && 9788 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) || 9789 (rdev->wiphy.wowlan_config->eap_identity_req && 9790 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) || 9791 (rdev->wiphy.wowlan_config->four_way_handshake && 9792 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) || 9793 (rdev->wiphy.wowlan_config->rfkill_release && 9794 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE))) 9795 goto nla_put_failure; 9796 9797 if (nl80211_send_wowlan_patterns(msg, rdev)) 9798 goto nla_put_failure; 9799 9800 if (nl80211_send_wowlan_tcp(msg, 9801 rdev->wiphy.wowlan_config->tcp)) 9802 goto nla_put_failure; 9803 9804 if (nl80211_send_wowlan_nd( 9805 msg, 9806 rdev->wiphy.wowlan_config->nd_config)) 9807 goto nla_put_failure; 9808 9809 nla_nest_end(msg, nl_wowlan); 9810 } 9811 9812 genlmsg_end(msg, hdr); 9813 return genlmsg_reply(msg, info); 9814 9815 nla_put_failure: 9816 nlmsg_free(msg); 9817 return -ENOBUFS; 9818 } 9819 9820 static int nl80211_parse_wowlan_tcp(struct cfg80211_registered_device *rdev, 9821 struct nlattr *attr, 9822 struct cfg80211_wowlan *trig) 9823 { 9824 struct nlattr *tb[NUM_NL80211_WOWLAN_TCP]; 9825 struct cfg80211_wowlan_tcp *cfg; 9826 struct nl80211_wowlan_tcp_data_token *tok = NULL; 9827 struct nl80211_wowlan_tcp_data_seq *seq = NULL; 9828 u32 size; 9829 u32 data_size, wake_size, tokens_size = 0, wake_mask_size; 9830 int err, port; 9831 9832 if (!rdev->wiphy.wowlan->tcp) 9833 return -EINVAL; 9834 9835 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TCP, attr, 9836 nl80211_wowlan_tcp_policy); 9837 if (err) 9838 return err; 9839 9840 if (!tb[NL80211_WOWLAN_TCP_SRC_IPV4] || 9841 !tb[NL80211_WOWLAN_TCP_DST_IPV4] || 9842 !tb[NL80211_WOWLAN_TCP_DST_MAC] || 9843 !tb[NL80211_WOWLAN_TCP_DST_PORT] || 9844 !tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD] || 9845 !tb[NL80211_WOWLAN_TCP_DATA_INTERVAL] || 9846 !tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD] || 9847 !tb[NL80211_WOWLAN_TCP_WAKE_MASK]) 9848 return -EINVAL; 9849 9850 data_size = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]); 9851 if (data_size > rdev->wiphy.wowlan->tcp->data_payload_max) 9852 return -EINVAL; 9853 9854 if (nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) > 9855 rdev->wiphy.wowlan->tcp->data_interval_max || 9856 nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]) == 0) 9857 return -EINVAL; 9858 9859 wake_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]); 9860 if (wake_size > rdev->wiphy.wowlan->tcp->wake_payload_max) 9861 return -EINVAL; 9862 9863 wake_mask_size = nla_len(tb[NL80211_WOWLAN_TCP_WAKE_MASK]); 9864 if (wake_mask_size != DIV_ROUND_UP(wake_size, 8)) 9865 return -EINVAL; 9866 9867 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]) { 9868 u32 tokln = nla_len(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]); 9869 9870 tok = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_TOKEN]); 9871 tokens_size = tokln - sizeof(*tok); 9872 9873 if (!tok->len || tokens_size % tok->len) 9874 return -EINVAL; 9875 if (!rdev->wiphy.wowlan->tcp->tok) 9876 return -EINVAL; 9877 if (tok->len > rdev->wiphy.wowlan->tcp->tok->max_len) 9878 return -EINVAL; 9879 if (tok->len < rdev->wiphy.wowlan->tcp->tok->min_len) 9880 return -EINVAL; 9881 if (tokens_size > rdev->wiphy.wowlan->tcp->tok->bufsize) 9882 return -EINVAL; 9883 if (tok->offset + tok->len > data_size) 9884 return -EINVAL; 9885 } 9886 9887 if (tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]) { 9888 seq = nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD_SEQ]); 9889 if (!rdev->wiphy.wowlan->tcp->seq) 9890 return -EINVAL; 9891 if (seq->len == 0 || seq->len > 4) 9892 return -EINVAL; 9893 if (seq->len + seq->offset > data_size) 9894 return -EINVAL; 9895 } 9896 9897 size = sizeof(*cfg); 9898 size += data_size; 9899 size += wake_size + wake_mask_size; 9900 size += tokens_size; 9901 9902 cfg = kzalloc(size, GFP_KERNEL); 9903 if (!cfg) 9904 return -ENOMEM; 9905 cfg->src = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_SRC_IPV4]); 9906 cfg->dst = nla_get_in_addr(tb[NL80211_WOWLAN_TCP_DST_IPV4]); 9907 memcpy(cfg->dst_mac, nla_data(tb[NL80211_WOWLAN_TCP_DST_MAC]), 9908 ETH_ALEN); 9909 if (tb[NL80211_WOWLAN_TCP_SRC_PORT]) 9910 port = nla_get_u16(tb[NL80211_WOWLAN_TCP_SRC_PORT]); 9911 else 9912 port = 0; 9913 #ifdef CONFIG_INET 9914 /* allocate a socket and port for it and use it */ 9915 err = __sock_create(wiphy_net(&rdev->wiphy), PF_INET, SOCK_STREAM, 9916 IPPROTO_TCP, &cfg->sock, 1); 9917 if (err) { 9918 kfree(cfg); 9919 return err; 9920 } 9921 if (inet_csk_get_port(cfg->sock->sk, port)) { 9922 sock_release(cfg->sock); 9923 kfree(cfg); 9924 return -EADDRINUSE; 9925 } 9926 cfg->src_port = inet_sk(cfg->sock->sk)->inet_num; 9927 #else 9928 if (!port) { 9929 kfree(cfg); 9930 return -EINVAL; 9931 } 9932 cfg->src_port = port; 9933 #endif 9934 9935 cfg->dst_port = nla_get_u16(tb[NL80211_WOWLAN_TCP_DST_PORT]); 9936 cfg->payload_len = data_size; 9937 cfg->payload = (u8 *)cfg + sizeof(*cfg) + tokens_size; 9938 memcpy((void *)cfg->payload, 9939 nla_data(tb[NL80211_WOWLAN_TCP_DATA_PAYLOAD]), 9940 data_size); 9941 if (seq) 9942 cfg->payload_seq = *seq; 9943 cfg->data_interval = nla_get_u32(tb[NL80211_WOWLAN_TCP_DATA_INTERVAL]); 9944 cfg->wake_len = wake_size; 9945 cfg->wake_data = (u8 *)cfg + sizeof(*cfg) + tokens_size + data_size; 9946 memcpy((void *)cfg->wake_data, 9947 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_PAYLOAD]), 9948 wake_size); 9949 cfg->wake_mask = (u8 *)cfg + sizeof(*cfg) + tokens_size + 9950 data_size + wake_size; 9951 memcpy((void *)cfg->wake_mask, 9952 nla_data(tb[NL80211_WOWLAN_TCP_WAKE_MASK]), 9953 wake_mask_size); 9954 if (tok) { 9955 cfg->tokens_size = tokens_size; 9956 memcpy(&cfg->payload_tok, tok, sizeof(*tok) + tokens_size); 9957 } 9958 9959 trig->tcp = cfg; 9960 9961 return 0; 9962 } 9963 9964 static int nl80211_parse_wowlan_nd(struct cfg80211_registered_device *rdev, 9965 const struct wiphy_wowlan_support *wowlan, 9966 struct nlattr *attr, 9967 struct cfg80211_wowlan *trig) 9968 { 9969 struct nlattr **tb; 9970 int err; 9971 9972 tb = kzalloc(NUM_NL80211_ATTR * sizeof(*tb), GFP_KERNEL); 9973 if (!tb) 9974 return -ENOMEM; 9975 9976 if (!(wowlan->flags & WIPHY_WOWLAN_NET_DETECT)) { 9977 err = -EOPNOTSUPP; 9978 goto out; 9979 } 9980 9981 err = nla_parse_nested(tb, NL80211_ATTR_MAX, attr, nl80211_policy); 9982 if (err) 9983 goto out; 9984 9985 trig->nd_config = nl80211_parse_sched_scan(&rdev->wiphy, NULL, tb); 9986 err = PTR_ERR_OR_ZERO(trig->nd_config); 9987 if (err) 9988 trig->nd_config = NULL; 9989 9990 out: 9991 kfree(tb); 9992 return err; 9993 } 9994 9995 static int nl80211_set_wowlan(struct sk_buff *skb, struct genl_info *info) 9996 { 9997 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 9998 struct nlattr *tb[NUM_NL80211_WOWLAN_TRIG]; 9999 struct cfg80211_wowlan new_triggers = {}; 10000 struct cfg80211_wowlan *ntrig; 10001 const struct wiphy_wowlan_support *wowlan = rdev->wiphy.wowlan; 10002 int err, i; 10003 bool prev_enabled = rdev->wiphy.wowlan_config; 10004 bool regular = false; 10005 10006 if (!wowlan) 10007 return -EOPNOTSUPP; 10008 10009 if (!info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS]) { 10010 cfg80211_rdev_free_wowlan(rdev); 10011 rdev->wiphy.wowlan_config = NULL; 10012 goto set_wakeup; 10013 } 10014 10015 err = nla_parse_nested(tb, MAX_NL80211_WOWLAN_TRIG, 10016 info->attrs[NL80211_ATTR_WOWLAN_TRIGGERS], 10017 nl80211_wowlan_policy); 10018 if (err) 10019 return err; 10020 10021 if (tb[NL80211_WOWLAN_TRIG_ANY]) { 10022 if (!(wowlan->flags & WIPHY_WOWLAN_ANY)) 10023 return -EINVAL; 10024 new_triggers.any = true; 10025 } 10026 10027 if (tb[NL80211_WOWLAN_TRIG_DISCONNECT]) { 10028 if (!(wowlan->flags & WIPHY_WOWLAN_DISCONNECT)) 10029 return -EINVAL; 10030 new_triggers.disconnect = true; 10031 regular = true; 10032 } 10033 10034 if (tb[NL80211_WOWLAN_TRIG_MAGIC_PKT]) { 10035 if (!(wowlan->flags & WIPHY_WOWLAN_MAGIC_PKT)) 10036 return -EINVAL; 10037 new_triggers.magic_pkt = true; 10038 regular = true; 10039 } 10040 10041 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_SUPPORTED]) 10042 return -EINVAL; 10043 10044 if (tb[NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE]) { 10045 if (!(wowlan->flags & WIPHY_WOWLAN_GTK_REKEY_FAILURE)) 10046 return -EINVAL; 10047 new_triggers.gtk_rekey_failure = true; 10048 regular = true; 10049 } 10050 10051 if (tb[NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST]) { 10052 if (!(wowlan->flags & WIPHY_WOWLAN_EAP_IDENTITY_REQ)) 10053 return -EINVAL; 10054 new_triggers.eap_identity_req = true; 10055 regular = true; 10056 } 10057 10058 if (tb[NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE]) { 10059 if (!(wowlan->flags & WIPHY_WOWLAN_4WAY_HANDSHAKE)) 10060 return -EINVAL; 10061 new_triggers.four_way_handshake = true; 10062 regular = true; 10063 } 10064 10065 if (tb[NL80211_WOWLAN_TRIG_RFKILL_RELEASE]) { 10066 if (!(wowlan->flags & WIPHY_WOWLAN_RFKILL_RELEASE)) 10067 return -EINVAL; 10068 new_triggers.rfkill_release = true; 10069 regular = true; 10070 } 10071 10072 if (tb[NL80211_WOWLAN_TRIG_PKT_PATTERN]) { 10073 struct nlattr *pat; 10074 int n_patterns = 0; 10075 int rem, pat_len, mask_len, pkt_offset; 10076 struct nlattr *pat_tb[NUM_NL80211_PKTPAT]; 10077 10078 regular = true; 10079 10080 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN], 10081 rem) 10082 n_patterns++; 10083 if (n_patterns > wowlan->n_patterns) 10084 return -EINVAL; 10085 10086 new_triggers.patterns = kcalloc(n_patterns, 10087 sizeof(new_triggers.patterns[0]), 10088 GFP_KERNEL); 10089 if (!new_triggers.patterns) 10090 return -ENOMEM; 10091 10092 new_triggers.n_patterns = n_patterns; 10093 i = 0; 10094 10095 nla_for_each_nested(pat, tb[NL80211_WOWLAN_TRIG_PKT_PATTERN], 10096 rem) { 10097 u8 *mask_pat; 10098 10099 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, 10100 NULL); 10101 err = -EINVAL; 10102 if (!pat_tb[NL80211_PKTPAT_MASK] || 10103 !pat_tb[NL80211_PKTPAT_PATTERN]) 10104 goto error; 10105 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]); 10106 mask_len = DIV_ROUND_UP(pat_len, 8); 10107 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len) 10108 goto error; 10109 if (pat_len > wowlan->pattern_max_len || 10110 pat_len < wowlan->pattern_min_len) 10111 goto error; 10112 10113 if (!pat_tb[NL80211_PKTPAT_OFFSET]) 10114 pkt_offset = 0; 10115 else 10116 pkt_offset = nla_get_u32( 10117 pat_tb[NL80211_PKTPAT_OFFSET]); 10118 if (pkt_offset > wowlan->max_pkt_offset) 10119 goto error; 10120 new_triggers.patterns[i].pkt_offset = pkt_offset; 10121 10122 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL); 10123 if (!mask_pat) { 10124 err = -ENOMEM; 10125 goto error; 10126 } 10127 new_triggers.patterns[i].mask = mask_pat; 10128 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]), 10129 mask_len); 10130 mask_pat += mask_len; 10131 new_triggers.patterns[i].pattern = mask_pat; 10132 new_triggers.patterns[i].pattern_len = pat_len; 10133 memcpy(mask_pat, 10134 nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), 10135 pat_len); 10136 i++; 10137 } 10138 } 10139 10140 if (tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION]) { 10141 regular = true; 10142 err = nl80211_parse_wowlan_tcp( 10143 rdev, tb[NL80211_WOWLAN_TRIG_TCP_CONNECTION], 10144 &new_triggers); 10145 if (err) 10146 goto error; 10147 } 10148 10149 if (tb[NL80211_WOWLAN_TRIG_NET_DETECT]) { 10150 regular = true; 10151 err = nl80211_parse_wowlan_nd( 10152 rdev, wowlan, tb[NL80211_WOWLAN_TRIG_NET_DETECT], 10153 &new_triggers); 10154 if (err) 10155 goto error; 10156 } 10157 10158 /* The 'any' trigger means the device continues operating more or less 10159 * as in its normal operation mode and wakes up the host on most of the 10160 * normal interrupts (like packet RX, ...) 10161 * It therefore makes little sense to combine with the more constrained 10162 * wakeup trigger modes. 10163 */ 10164 if (new_triggers.any && regular) { 10165 err = -EINVAL; 10166 goto error; 10167 } 10168 10169 ntrig = kmemdup(&new_triggers, sizeof(new_triggers), GFP_KERNEL); 10170 if (!ntrig) { 10171 err = -ENOMEM; 10172 goto error; 10173 } 10174 cfg80211_rdev_free_wowlan(rdev); 10175 rdev->wiphy.wowlan_config = ntrig; 10176 10177 set_wakeup: 10178 if (rdev->ops->set_wakeup && 10179 prev_enabled != !!rdev->wiphy.wowlan_config) 10180 rdev_set_wakeup(rdev, rdev->wiphy.wowlan_config); 10181 10182 return 0; 10183 error: 10184 for (i = 0; i < new_triggers.n_patterns; i++) 10185 kfree(new_triggers.patterns[i].mask); 10186 kfree(new_triggers.patterns); 10187 if (new_triggers.tcp && new_triggers.tcp->sock) 10188 sock_release(new_triggers.tcp->sock); 10189 kfree(new_triggers.tcp); 10190 kfree(new_triggers.nd_config); 10191 return err; 10192 } 10193 #endif 10194 10195 static int nl80211_send_coalesce_rules(struct sk_buff *msg, 10196 struct cfg80211_registered_device *rdev) 10197 { 10198 struct nlattr *nl_pats, *nl_pat, *nl_rule, *nl_rules; 10199 int i, j, pat_len; 10200 struct cfg80211_coalesce_rules *rule; 10201 10202 if (!rdev->coalesce->n_rules) 10203 return 0; 10204 10205 nl_rules = nla_nest_start(msg, NL80211_ATTR_COALESCE_RULE); 10206 if (!nl_rules) 10207 return -ENOBUFS; 10208 10209 for (i = 0; i < rdev->coalesce->n_rules; i++) { 10210 nl_rule = nla_nest_start(msg, i + 1); 10211 if (!nl_rule) 10212 return -ENOBUFS; 10213 10214 rule = &rdev->coalesce->rules[i]; 10215 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_DELAY, 10216 rule->delay)) 10217 return -ENOBUFS; 10218 10219 if (nla_put_u32(msg, NL80211_ATTR_COALESCE_RULE_CONDITION, 10220 rule->condition)) 10221 return -ENOBUFS; 10222 10223 nl_pats = nla_nest_start(msg, 10224 NL80211_ATTR_COALESCE_RULE_PKT_PATTERN); 10225 if (!nl_pats) 10226 return -ENOBUFS; 10227 10228 for (j = 0; j < rule->n_patterns; j++) { 10229 nl_pat = nla_nest_start(msg, j + 1); 10230 if (!nl_pat) 10231 return -ENOBUFS; 10232 pat_len = rule->patterns[j].pattern_len; 10233 if (nla_put(msg, NL80211_PKTPAT_MASK, 10234 DIV_ROUND_UP(pat_len, 8), 10235 rule->patterns[j].mask) || 10236 nla_put(msg, NL80211_PKTPAT_PATTERN, pat_len, 10237 rule->patterns[j].pattern) || 10238 nla_put_u32(msg, NL80211_PKTPAT_OFFSET, 10239 rule->patterns[j].pkt_offset)) 10240 return -ENOBUFS; 10241 nla_nest_end(msg, nl_pat); 10242 } 10243 nla_nest_end(msg, nl_pats); 10244 nla_nest_end(msg, nl_rule); 10245 } 10246 nla_nest_end(msg, nl_rules); 10247 10248 return 0; 10249 } 10250 10251 static int nl80211_get_coalesce(struct sk_buff *skb, struct genl_info *info) 10252 { 10253 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10254 struct sk_buff *msg; 10255 void *hdr; 10256 10257 if (!rdev->wiphy.coalesce) 10258 return -EOPNOTSUPP; 10259 10260 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10261 if (!msg) 10262 return -ENOMEM; 10263 10264 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10265 NL80211_CMD_GET_COALESCE); 10266 if (!hdr) 10267 goto nla_put_failure; 10268 10269 if (rdev->coalesce && nl80211_send_coalesce_rules(msg, rdev)) 10270 goto nla_put_failure; 10271 10272 genlmsg_end(msg, hdr); 10273 return genlmsg_reply(msg, info); 10274 10275 nla_put_failure: 10276 nlmsg_free(msg); 10277 return -ENOBUFS; 10278 } 10279 10280 void cfg80211_rdev_free_coalesce(struct cfg80211_registered_device *rdev) 10281 { 10282 struct cfg80211_coalesce *coalesce = rdev->coalesce; 10283 int i, j; 10284 struct cfg80211_coalesce_rules *rule; 10285 10286 if (!coalesce) 10287 return; 10288 10289 for (i = 0; i < coalesce->n_rules; i++) { 10290 rule = &coalesce->rules[i]; 10291 for (j = 0; j < rule->n_patterns; j++) 10292 kfree(rule->patterns[j].mask); 10293 kfree(rule->patterns); 10294 } 10295 kfree(coalesce->rules); 10296 kfree(coalesce); 10297 rdev->coalesce = NULL; 10298 } 10299 10300 static int nl80211_parse_coalesce_rule(struct cfg80211_registered_device *rdev, 10301 struct nlattr *rule, 10302 struct cfg80211_coalesce_rules *new_rule) 10303 { 10304 int err, i; 10305 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce; 10306 struct nlattr *tb[NUM_NL80211_ATTR_COALESCE_RULE], *pat; 10307 int rem, pat_len, mask_len, pkt_offset, n_patterns = 0; 10308 struct nlattr *pat_tb[NUM_NL80211_PKTPAT]; 10309 10310 err = nla_parse_nested(tb, NL80211_ATTR_COALESCE_RULE_MAX, rule, 10311 nl80211_coalesce_policy); 10312 if (err) 10313 return err; 10314 10315 if (tb[NL80211_ATTR_COALESCE_RULE_DELAY]) 10316 new_rule->delay = 10317 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_DELAY]); 10318 if (new_rule->delay > coalesce->max_delay) 10319 return -EINVAL; 10320 10321 if (tb[NL80211_ATTR_COALESCE_RULE_CONDITION]) 10322 new_rule->condition = 10323 nla_get_u32(tb[NL80211_ATTR_COALESCE_RULE_CONDITION]); 10324 if (new_rule->condition != NL80211_COALESCE_CONDITION_MATCH && 10325 new_rule->condition != NL80211_COALESCE_CONDITION_NO_MATCH) 10326 return -EINVAL; 10327 10328 if (!tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN]) 10329 return -EINVAL; 10330 10331 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN], 10332 rem) 10333 n_patterns++; 10334 if (n_patterns > coalesce->n_patterns) 10335 return -EINVAL; 10336 10337 new_rule->patterns = kcalloc(n_patterns, sizeof(new_rule->patterns[0]), 10338 GFP_KERNEL); 10339 if (!new_rule->patterns) 10340 return -ENOMEM; 10341 10342 new_rule->n_patterns = n_patterns; 10343 i = 0; 10344 10345 nla_for_each_nested(pat, tb[NL80211_ATTR_COALESCE_RULE_PKT_PATTERN], 10346 rem) { 10347 u8 *mask_pat; 10348 10349 nla_parse_nested(pat_tb, MAX_NL80211_PKTPAT, pat, NULL); 10350 if (!pat_tb[NL80211_PKTPAT_MASK] || 10351 !pat_tb[NL80211_PKTPAT_PATTERN]) 10352 return -EINVAL; 10353 pat_len = nla_len(pat_tb[NL80211_PKTPAT_PATTERN]); 10354 mask_len = DIV_ROUND_UP(pat_len, 8); 10355 if (nla_len(pat_tb[NL80211_PKTPAT_MASK]) != mask_len) 10356 return -EINVAL; 10357 if (pat_len > coalesce->pattern_max_len || 10358 pat_len < coalesce->pattern_min_len) 10359 return -EINVAL; 10360 10361 if (!pat_tb[NL80211_PKTPAT_OFFSET]) 10362 pkt_offset = 0; 10363 else 10364 pkt_offset = nla_get_u32(pat_tb[NL80211_PKTPAT_OFFSET]); 10365 if (pkt_offset > coalesce->max_pkt_offset) 10366 return -EINVAL; 10367 new_rule->patterns[i].pkt_offset = pkt_offset; 10368 10369 mask_pat = kmalloc(mask_len + pat_len, GFP_KERNEL); 10370 if (!mask_pat) 10371 return -ENOMEM; 10372 10373 new_rule->patterns[i].mask = mask_pat; 10374 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_MASK]), 10375 mask_len); 10376 10377 mask_pat += mask_len; 10378 new_rule->patterns[i].pattern = mask_pat; 10379 new_rule->patterns[i].pattern_len = pat_len; 10380 memcpy(mask_pat, nla_data(pat_tb[NL80211_PKTPAT_PATTERN]), 10381 pat_len); 10382 i++; 10383 } 10384 10385 return 0; 10386 } 10387 10388 static int nl80211_set_coalesce(struct sk_buff *skb, struct genl_info *info) 10389 { 10390 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10391 const struct wiphy_coalesce_support *coalesce = rdev->wiphy.coalesce; 10392 struct cfg80211_coalesce new_coalesce = {}; 10393 struct cfg80211_coalesce *n_coalesce; 10394 int err, rem_rule, n_rules = 0, i, j; 10395 struct nlattr *rule; 10396 struct cfg80211_coalesce_rules *tmp_rule; 10397 10398 if (!rdev->wiphy.coalesce || !rdev->ops->set_coalesce) 10399 return -EOPNOTSUPP; 10400 10401 if (!info->attrs[NL80211_ATTR_COALESCE_RULE]) { 10402 cfg80211_rdev_free_coalesce(rdev); 10403 rdev_set_coalesce(rdev, NULL); 10404 return 0; 10405 } 10406 10407 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE], 10408 rem_rule) 10409 n_rules++; 10410 if (n_rules > coalesce->n_rules) 10411 return -EINVAL; 10412 10413 new_coalesce.rules = kcalloc(n_rules, sizeof(new_coalesce.rules[0]), 10414 GFP_KERNEL); 10415 if (!new_coalesce.rules) 10416 return -ENOMEM; 10417 10418 new_coalesce.n_rules = n_rules; 10419 i = 0; 10420 10421 nla_for_each_nested(rule, info->attrs[NL80211_ATTR_COALESCE_RULE], 10422 rem_rule) { 10423 err = nl80211_parse_coalesce_rule(rdev, rule, 10424 &new_coalesce.rules[i]); 10425 if (err) 10426 goto error; 10427 10428 i++; 10429 } 10430 10431 err = rdev_set_coalesce(rdev, &new_coalesce); 10432 if (err) 10433 goto error; 10434 10435 n_coalesce = kmemdup(&new_coalesce, sizeof(new_coalesce), GFP_KERNEL); 10436 if (!n_coalesce) { 10437 err = -ENOMEM; 10438 goto error; 10439 } 10440 cfg80211_rdev_free_coalesce(rdev); 10441 rdev->coalesce = n_coalesce; 10442 10443 return 0; 10444 error: 10445 for (i = 0; i < new_coalesce.n_rules; i++) { 10446 tmp_rule = &new_coalesce.rules[i]; 10447 for (j = 0; j < tmp_rule->n_patterns; j++) 10448 kfree(tmp_rule->patterns[j].mask); 10449 kfree(tmp_rule->patterns); 10450 } 10451 kfree(new_coalesce.rules); 10452 10453 return err; 10454 } 10455 10456 static int nl80211_set_rekey_data(struct sk_buff *skb, struct genl_info *info) 10457 { 10458 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10459 struct net_device *dev = info->user_ptr[1]; 10460 struct wireless_dev *wdev = dev->ieee80211_ptr; 10461 struct nlattr *tb[NUM_NL80211_REKEY_DATA]; 10462 struct cfg80211_gtk_rekey_data rekey_data; 10463 int err; 10464 10465 if (!info->attrs[NL80211_ATTR_REKEY_DATA]) 10466 return -EINVAL; 10467 10468 err = nla_parse_nested(tb, MAX_NL80211_REKEY_DATA, 10469 info->attrs[NL80211_ATTR_REKEY_DATA], 10470 nl80211_rekey_policy); 10471 if (err) 10472 return err; 10473 10474 if (nla_len(tb[NL80211_REKEY_DATA_REPLAY_CTR]) != NL80211_REPLAY_CTR_LEN) 10475 return -ERANGE; 10476 if (nla_len(tb[NL80211_REKEY_DATA_KEK]) != NL80211_KEK_LEN) 10477 return -ERANGE; 10478 if (nla_len(tb[NL80211_REKEY_DATA_KCK]) != NL80211_KCK_LEN) 10479 return -ERANGE; 10480 10481 rekey_data.kek = nla_data(tb[NL80211_REKEY_DATA_KEK]); 10482 rekey_data.kck = nla_data(tb[NL80211_REKEY_DATA_KCK]); 10483 rekey_data.replay_ctr = nla_data(tb[NL80211_REKEY_DATA_REPLAY_CTR]); 10484 10485 wdev_lock(wdev); 10486 if (!wdev->current_bss) { 10487 err = -ENOTCONN; 10488 goto out; 10489 } 10490 10491 if (!rdev->ops->set_rekey_data) { 10492 err = -EOPNOTSUPP; 10493 goto out; 10494 } 10495 10496 err = rdev_set_rekey_data(rdev, dev, &rekey_data); 10497 out: 10498 wdev_unlock(wdev); 10499 return err; 10500 } 10501 10502 static int nl80211_register_unexpected_frame(struct sk_buff *skb, 10503 struct genl_info *info) 10504 { 10505 struct net_device *dev = info->user_ptr[1]; 10506 struct wireless_dev *wdev = dev->ieee80211_ptr; 10507 10508 if (wdev->iftype != NL80211_IFTYPE_AP && 10509 wdev->iftype != NL80211_IFTYPE_P2P_GO) 10510 return -EINVAL; 10511 10512 if (wdev->ap_unexpected_nlportid) 10513 return -EBUSY; 10514 10515 wdev->ap_unexpected_nlportid = info->snd_portid; 10516 return 0; 10517 } 10518 10519 static int nl80211_probe_client(struct sk_buff *skb, 10520 struct genl_info *info) 10521 { 10522 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10523 struct net_device *dev = info->user_ptr[1]; 10524 struct wireless_dev *wdev = dev->ieee80211_ptr; 10525 struct sk_buff *msg; 10526 void *hdr; 10527 const u8 *addr; 10528 u64 cookie; 10529 int err; 10530 10531 if (wdev->iftype != NL80211_IFTYPE_AP && 10532 wdev->iftype != NL80211_IFTYPE_P2P_GO) 10533 return -EOPNOTSUPP; 10534 10535 if (!info->attrs[NL80211_ATTR_MAC]) 10536 return -EINVAL; 10537 10538 if (!rdev->ops->probe_client) 10539 return -EOPNOTSUPP; 10540 10541 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10542 if (!msg) 10543 return -ENOMEM; 10544 10545 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10546 NL80211_CMD_PROBE_CLIENT); 10547 if (!hdr) { 10548 err = -ENOBUFS; 10549 goto free_msg; 10550 } 10551 10552 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 10553 10554 err = rdev_probe_client(rdev, dev, addr, &cookie); 10555 if (err) 10556 goto free_msg; 10557 10558 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 10559 NL80211_ATTR_PAD)) 10560 goto nla_put_failure; 10561 10562 genlmsg_end(msg, hdr); 10563 10564 return genlmsg_reply(msg, info); 10565 10566 nla_put_failure: 10567 err = -ENOBUFS; 10568 free_msg: 10569 nlmsg_free(msg); 10570 return err; 10571 } 10572 10573 static int nl80211_register_beacons(struct sk_buff *skb, struct genl_info *info) 10574 { 10575 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10576 struct cfg80211_beacon_registration *reg, *nreg; 10577 int rv; 10578 10579 if (!(rdev->wiphy.flags & WIPHY_FLAG_REPORTS_OBSS)) 10580 return -EOPNOTSUPP; 10581 10582 nreg = kzalloc(sizeof(*nreg), GFP_KERNEL); 10583 if (!nreg) 10584 return -ENOMEM; 10585 10586 /* First, check if already registered. */ 10587 spin_lock_bh(&rdev->beacon_registrations_lock); 10588 list_for_each_entry(reg, &rdev->beacon_registrations, list) { 10589 if (reg->nlportid == info->snd_portid) { 10590 rv = -EALREADY; 10591 goto out_err; 10592 } 10593 } 10594 /* Add it to the list */ 10595 nreg->nlportid = info->snd_portid; 10596 list_add(&nreg->list, &rdev->beacon_registrations); 10597 10598 spin_unlock_bh(&rdev->beacon_registrations_lock); 10599 10600 return 0; 10601 out_err: 10602 spin_unlock_bh(&rdev->beacon_registrations_lock); 10603 kfree(nreg); 10604 return rv; 10605 } 10606 10607 static int nl80211_start_p2p_device(struct sk_buff *skb, struct genl_info *info) 10608 { 10609 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10610 struct wireless_dev *wdev = info->user_ptr[1]; 10611 int err; 10612 10613 if (!rdev->ops->start_p2p_device) 10614 return -EOPNOTSUPP; 10615 10616 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE) 10617 return -EOPNOTSUPP; 10618 10619 if (wdev_running(wdev)) 10620 return 0; 10621 10622 if (rfkill_blocked(rdev->rfkill)) 10623 return -ERFKILL; 10624 10625 err = rdev_start_p2p_device(rdev, wdev); 10626 if (err) 10627 return err; 10628 10629 wdev->is_running = true; 10630 rdev->opencount++; 10631 10632 return 0; 10633 } 10634 10635 static int nl80211_stop_p2p_device(struct sk_buff *skb, struct genl_info *info) 10636 { 10637 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10638 struct wireless_dev *wdev = info->user_ptr[1]; 10639 10640 if (wdev->iftype != NL80211_IFTYPE_P2P_DEVICE) 10641 return -EOPNOTSUPP; 10642 10643 if (!rdev->ops->stop_p2p_device) 10644 return -EOPNOTSUPP; 10645 10646 cfg80211_stop_p2p_device(rdev, wdev); 10647 10648 return 0; 10649 } 10650 10651 static int nl80211_start_nan(struct sk_buff *skb, struct genl_info *info) 10652 { 10653 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10654 struct wireless_dev *wdev = info->user_ptr[1]; 10655 struct cfg80211_nan_conf conf = {}; 10656 int err; 10657 10658 if (wdev->iftype != NL80211_IFTYPE_NAN) 10659 return -EOPNOTSUPP; 10660 10661 if (wdev_running(wdev)) 10662 return -EEXIST; 10663 10664 if (rfkill_blocked(rdev->rfkill)) 10665 return -ERFKILL; 10666 10667 if (!info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) 10668 return -EINVAL; 10669 10670 if (!info->attrs[NL80211_ATTR_NAN_DUAL]) 10671 return -EINVAL; 10672 10673 conf.master_pref = 10674 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]); 10675 if (!conf.master_pref) 10676 return -EINVAL; 10677 10678 conf.dual = nla_get_u8(info->attrs[NL80211_ATTR_NAN_DUAL]); 10679 10680 err = rdev_start_nan(rdev, wdev, &conf); 10681 if (err) 10682 return err; 10683 10684 wdev->is_running = true; 10685 rdev->opencount++; 10686 10687 return 0; 10688 } 10689 10690 static int nl80211_stop_nan(struct sk_buff *skb, struct genl_info *info) 10691 { 10692 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10693 struct wireless_dev *wdev = info->user_ptr[1]; 10694 10695 if (wdev->iftype != NL80211_IFTYPE_NAN) 10696 return -EOPNOTSUPP; 10697 10698 cfg80211_stop_nan(rdev, wdev); 10699 10700 return 0; 10701 } 10702 10703 static int validate_nan_filter(struct nlattr *filter_attr) 10704 { 10705 struct nlattr *attr; 10706 int len = 0, n_entries = 0, rem; 10707 10708 nla_for_each_nested(attr, filter_attr, rem) { 10709 len += nla_len(attr); 10710 n_entries++; 10711 } 10712 10713 if (len >= U8_MAX) 10714 return -EINVAL; 10715 10716 return n_entries; 10717 } 10718 10719 static int handle_nan_filter(struct nlattr *attr_filter, 10720 struct cfg80211_nan_func *func, 10721 bool tx) 10722 { 10723 struct nlattr *attr; 10724 int n_entries, rem, i; 10725 struct cfg80211_nan_func_filter *filter; 10726 10727 n_entries = validate_nan_filter(attr_filter); 10728 if (n_entries < 0) 10729 return n_entries; 10730 10731 BUILD_BUG_ON(sizeof(*func->rx_filters) != sizeof(*func->tx_filters)); 10732 10733 filter = kcalloc(n_entries, sizeof(*func->rx_filters), GFP_KERNEL); 10734 if (!filter) 10735 return -ENOMEM; 10736 10737 i = 0; 10738 nla_for_each_nested(attr, attr_filter, rem) { 10739 filter[i].filter = nla_memdup(attr, GFP_KERNEL); 10740 filter[i].len = nla_len(attr); 10741 i++; 10742 } 10743 if (tx) { 10744 func->num_tx_filters = n_entries; 10745 func->tx_filters = filter; 10746 } else { 10747 func->num_rx_filters = n_entries; 10748 func->rx_filters = filter; 10749 } 10750 10751 return 0; 10752 } 10753 10754 static int nl80211_nan_add_func(struct sk_buff *skb, 10755 struct genl_info *info) 10756 { 10757 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10758 struct wireless_dev *wdev = info->user_ptr[1]; 10759 struct nlattr *tb[NUM_NL80211_NAN_FUNC_ATTR], *func_attr; 10760 struct cfg80211_nan_func *func; 10761 struct sk_buff *msg = NULL; 10762 void *hdr = NULL; 10763 int err = 0; 10764 10765 if (wdev->iftype != NL80211_IFTYPE_NAN) 10766 return -EOPNOTSUPP; 10767 10768 if (!wdev_running(wdev)) 10769 return -ENOTCONN; 10770 10771 if (!info->attrs[NL80211_ATTR_NAN_FUNC]) 10772 return -EINVAL; 10773 10774 if (wdev->owner_nlportid && 10775 wdev->owner_nlportid != info->snd_portid) 10776 return -ENOTCONN; 10777 10778 err = nla_parse_nested(tb, NL80211_NAN_FUNC_ATTR_MAX, 10779 info->attrs[NL80211_ATTR_NAN_FUNC], 10780 nl80211_nan_func_policy); 10781 if (err) 10782 return err; 10783 10784 func = kzalloc(sizeof(*func), GFP_KERNEL); 10785 if (!func) 10786 return -ENOMEM; 10787 10788 func->cookie = wdev->wiphy->cookie_counter++; 10789 10790 if (!tb[NL80211_NAN_FUNC_TYPE] || 10791 nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]) > NL80211_NAN_FUNC_MAX_TYPE) { 10792 err = -EINVAL; 10793 goto out; 10794 } 10795 10796 10797 func->type = nla_get_u8(tb[NL80211_NAN_FUNC_TYPE]); 10798 10799 if (!tb[NL80211_NAN_FUNC_SERVICE_ID]) { 10800 err = -EINVAL; 10801 goto out; 10802 } 10803 10804 memcpy(func->service_id, nla_data(tb[NL80211_NAN_FUNC_SERVICE_ID]), 10805 sizeof(func->service_id)); 10806 10807 func->close_range = 10808 nla_get_flag(tb[NL80211_NAN_FUNC_CLOSE_RANGE]); 10809 10810 if (tb[NL80211_NAN_FUNC_SERVICE_INFO]) { 10811 func->serv_spec_info_len = 10812 nla_len(tb[NL80211_NAN_FUNC_SERVICE_INFO]); 10813 func->serv_spec_info = 10814 kmemdup(nla_data(tb[NL80211_NAN_FUNC_SERVICE_INFO]), 10815 func->serv_spec_info_len, 10816 GFP_KERNEL); 10817 if (!func->serv_spec_info) { 10818 err = -ENOMEM; 10819 goto out; 10820 } 10821 } 10822 10823 if (tb[NL80211_NAN_FUNC_TTL]) 10824 func->ttl = nla_get_u32(tb[NL80211_NAN_FUNC_TTL]); 10825 10826 switch (func->type) { 10827 case NL80211_NAN_FUNC_PUBLISH: 10828 if (!tb[NL80211_NAN_FUNC_PUBLISH_TYPE]) { 10829 err = -EINVAL; 10830 goto out; 10831 } 10832 10833 func->publish_type = 10834 nla_get_u8(tb[NL80211_NAN_FUNC_PUBLISH_TYPE]); 10835 func->publish_bcast = 10836 nla_get_flag(tb[NL80211_NAN_FUNC_PUBLISH_BCAST]); 10837 10838 if ((!(func->publish_type & NL80211_NAN_SOLICITED_PUBLISH)) && 10839 func->publish_bcast) { 10840 err = -EINVAL; 10841 goto out; 10842 } 10843 break; 10844 case NL80211_NAN_FUNC_SUBSCRIBE: 10845 func->subscribe_active = 10846 nla_get_flag(tb[NL80211_NAN_FUNC_SUBSCRIBE_ACTIVE]); 10847 break; 10848 case NL80211_NAN_FUNC_FOLLOW_UP: 10849 if (!tb[NL80211_NAN_FUNC_FOLLOW_UP_ID] || 10850 !tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]) { 10851 err = -EINVAL; 10852 goto out; 10853 } 10854 10855 func->followup_id = 10856 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_ID]); 10857 func->followup_reqid = 10858 nla_get_u8(tb[NL80211_NAN_FUNC_FOLLOW_UP_REQ_ID]); 10859 memcpy(func->followup_dest.addr, 10860 nla_data(tb[NL80211_NAN_FUNC_FOLLOW_UP_DEST]), 10861 sizeof(func->followup_dest.addr)); 10862 if (func->ttl) { 10863 err = -EINVAL; 10864 goto out; 10865 } 10866 break; 10867 default: 10868 err = -EINVAL; 10869 goto out; 10870 } 10871 10872 if (tb[NL80211_NAN_FUNC_SRF]) { 10873 struct nlattr *srf_tb[NUM_NL80211_NAN_SRF_ATTR]; 10874 10875 err = nla_parse_nested(srf_tb, NL80211_NAN_SRF_ATTR_MAX, 10876 tb[NL80211_NAN_FUNC_SRF], 10877 nl80211_nan_srf_policy); 10878 if (err) 10879 goto out; 10880 10881 func->srf_include = 10882 nla_get_flag(srf_tb[NL80211_NAN_SRF_INCLUDE]); 10883 10884 if (srf_tb[NL80211_NAN_SRF_BF]) { 10885 if (srf_tb[NL80211_NAN_SRF_MAC_ADDRS] || 10886 !srf_tb[NL80211_NAN_SRF_BF_IDX]) { 10887 err = -EINVAL; 10888 goto out; 10889 } 10890 10891 func->srf_bf_len = 10892 nla_len(srf_tb[NL80211_NAN_SRF_BF]); 10893 func->srf_bf = 10894 kmemdup(nla_data(srf_tb[NL80211_NAN_SRF_BF]), 10895 func->srf_bf_len, GFP_KERNEL); 10896 if (!func->srf_bf) { 10897 err = -ENOMEM; 10898 goto out; 10899 } 10900 10901 func->srf_bf_idx = 10902 nla_get_u8(srf_tb[NL80211_NAN_SRF_BF_IDX]); 10903 } else { 10904 struct nlattr *attr, *mac_attr = 10905 srf_tb[NL80211_NAN_SRF_MAC_ADDRS]; 10906 int n_entries, rem, i = 0; 10907 10908 if (!mac_attr) { 10909 err = -EINVAL; 10910 goto out; 10911 } 10912 10913 n_entries = validate_acl_mac_addrs(mac_attr); 10914 if (n_entries <= 0) { 10915 err = -EINVAL; 10916 goto out; 10917 } 10918 10919 func->srf_num_macs = n_entries; 10920 func->srf_macs = 10921 kzalloc(sizeof(*func->srf_macs) * n_entries, 10922 GFP_KERNEL); 10923 if (!func->srf_macs) { 10924 err = -ENOMEM; 10925 goto out; 10926 } 10927 10928 nla_for_each_nested(attr, mac_attr, rem) 10929 memcpy(func->srf_macs[i++].addr, nla_data(attr), 10930 sizeof(*func->srf_macs)); 10931 } 10932 } 10933 10934 if (tb[NL80211_NAN_FUNC_TX_MATCH_FILTER]) { 10935 err = handle_nan_filter(tb[NL80211_NAN_FUNC_TX_MATCH_FILTER], 10936 func, true); 10937 if (err) 10938 goto out; 10939 } 10940 10941 if (tb[NL80211_NAN_FUNC_RX_MATCH_FILTER]) { 10942 err = handle_nan_filter(tb[NL80211_NAN_FUNC_RX_MATCH_FILTER], 10943 func, false); 10944 if (err) 10945 goto out; 10946 } 10947 10948 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 10949 if (!msg) { 10950 err = -ENOMEM; 10951 goto out; 10952 } 10953 10954 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 10955 NL80211_CMD_ADD_NAN_FUNCTION); 10956 /* This can't really happen - we just allocated 4KB */ 10957 if (WARN_ON(!hdr)) { 10958 err = -ENOMEM; 10959 goto out; 10960 } 10961 10962 err = rdev_add_nan_func(rdev, wdev, func); 10963 out: 10964 if (err < 0) { 10965 cfg80211_free_nan_func(func); 10966 nlmsg_free(msg); 10967 return err; 10968 } 10969 10970 /* propagate the instance id and cookie to userspace */ 10971 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, func->cookie, 10972 NL80211_ATTR_PAD)) 10973 goto nla_put_failure; 10974 10975 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC); 10976 if (!func_attr) 10977 goto nla_put_failure; 10978 10979 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, 10980 func->instance_id)) 10981 goto nla_put_failure; 10982 10983 nla_nest_end(msg, func_attr); 10984 10985 genlmsg_end(msg, hdr); 10986 return genlmsg_reply(msg, info); 10987 10988 nla_put_failure: 10989 nlmsg_free(msg); 10990 return -ENOBUFS; 10991 } 10992 10993 static int nl80211_nan_del_func(struct sk_buff *skb, 10994 struct genl_info *info) 10995 { 10996 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 10997 struct wireless_dev *wdev = info->user_ptr[1]; 10998 u64 cookie; 10999 11000 if (wdev->iftype != NL80211_IFTYPE_NAN) 11001 return -EOPNOTSUPP; 11002 11003 if (!wdev_running(wdev)) 11004 return -ENOTCONN; 11005 11006 if (!info->attrs[NL80211_ATTR_COOKIE]) 11007 return -EINVAL; 11008 11009 if (wdev->owner_nlportid && 11010 wdev->owner_nlportid != info->snd_portid) 11011 return -ENOTCONN; 11012 11013 cookie = nla_get_u64(info->attrs[NL80211_ATTR_COOKIE]); 11014 11015 rdev_del_nan_func(rdev, wdev, cookie); 11016 11017 return 0; 11018 } 11019 11020 static int nl80211_nan_change_config(struct sk_buff *skb, 11021 struct genl_info *info) 11022 { 11023 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11024 struct wireless_dev *wdev = info->user_ptr[1]; 11025 struct cfg80211_nan_conf conf = {}; 11026 u32 changed = 0; 11027 11028 if (wdev->iftype != NL80211_IFTYPE_NAN) 11029 return -EOPNOTSUPP; 11030 11031 if (!wdev_running(wdev)) 11032 return -ENOTCONN; 11033 11034 if (info->attrs[NL80211_ATTR_NAN_MASTER_PREF]) { 11035 conf.master_pref = 11036 nla_get_u8(info->attrs[NL80211_ATTR_NAN_MASTER_PREF]); 11037 if (conf.master_pref <= 1 || conf.master_pref == 255) 11038 return -EINVAL; 11039 11040 changed |= CFG80211_NAN_CONF_CHANGED_PREF; 11041 } 11042 11043 if (info->attrs[NL80211_ATTR_NAN_DUAL]) { 11044 conf.dual = nla_get_u8(info->attrs[NL80211_ATTR_NAN_DUAL]); 11045 changed |= CFG80211_NAN_CONF_CHANGED_DUAL; 11046 } 11047 11048 if (!changed) 11049 return -EINVAL; 11050 11051 return rdev_nan_change_conf(rdev, wdev, &conf, changed); 11052 } 11053 11054 void cfg80211_nan_match(struct wireless_dev *wdev, 11055 struct cfg80211_nan_match_params *match, gfp_t gfp) 11056 { 11057 struct wiphy *wiphy = wdev->wiphy; 11058 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11059 struct nlattr *match_attr, *local_func_attr, *peer_func_attr; 11060 struct sk_buff *msg; 11061 void *hdr; 11062 11063 if (WARN_ON(!match->inst_id || !match->peer_inst_id || !match->addr)) 11064 return; 11065 11066 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 11067 if (!msg) 11068 return; 11069 11070 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NAN_MATCH); 11071 if (!hdr) { 11072 nlmsg_free(msg); 11073 return; 11074 } 11075 11076 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11077 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 11078 wdev->netdev->ifindex)) || 11079 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 11080 NL80211_ATTR_PAD)) 11081 goto nla_put_failure; 11082 11083 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, match->cookie, 11084 NL80211_ATTR_PAD) || 11085 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, match->addr)) 11086 goto nla_put_failure; 11087 11088 match_attr = nla_nest_start(msg, NL80211_ATTR_NAN_MATCH); 11089 if (!match_attr) 11090 goto nla_put_failure; 11091 11092 local_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_LOCAL); 11093 if (!local_func_attr) 11094 goto nla_put_failure; 11095 11096 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->inst_id)) 11097 goto nla_put_failure; 11098 11099 nla_nest_end(msg, local_func_attr); 11100 11101 peer_func_attr = nla_nest_start(msg, NL80211_NAN_MATCH_FUNC_PEER); 11102 if (!peer_func_attr) 11103 goto nla_put_failure; 11104 11105 if (nla_put_u8(msg, NL80211_NAN_FUNC_TYPE, match->type) || 11106 nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, match->peer_inst_id)) 11107 goto nla_put_failure; 11108 11109 if (match->info && match->info_len && 11110 nla_put(msg, NL80211_NAN_FUNC_SERVICE_INFO, match->info_len, 11111 match->info)) 11112 goto nla_put_failure; 11113 11114 nla_nest_end(msg, peer_func_attr); 11115 nla_nest_end(msg, match_attr); 11116 genlmsg_end(msg, hdr); 11117 11118 if (!wdev->owner_nlportid) 11119 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), 11120 msg, 0, NL80211_MCGRP_NAN, gfp); 11121 else 11122 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, 11123 wdev->owner_nlportid); 11124 11125 return; 11126 11127 nla_put_failure: 11128 nlmsg_free(msg); 11129 } 11130 EXPORT_SYMBOL(cfg80211_nan_match); 11131 11132 void cfg80211_nan_func_terminated(struct wireless_dev *wdev, 11133 u8 inst_id, 11134 enum nl80211_nan_func_term_reason reason, 11135 u64 cookie, gfp_t gfp) 11136 { 11137 struct wiphy *wiphy = wdev->wiphy; 11138 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11139 struct sk_buff *msg; 11140 struct nlattr *func_attr; 11141 void *hdr; 11142 11143 if (WARN_ON(!inst_id)) 11144 return; 11145 11146 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 11147 if (!msg) 11148 return; 11149 11150 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DEL_NAN_FUNCTION); 11151 if (!hdr) { 11152 nlmsg_free(msg); 11153 return; 11154 } 11155 11156 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11157 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 11158 wdev->netdev->ifindex)) || 11159 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 11160 NL80211_ATTR_PAD)) 11161 goto nla_put_failure; 11162 11163 if (nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 11164 NL80211_ATTR_PAD)) 11165 goto nla_put_failure; 11166 11167 func_attr = nla_nest_start(msg, NL80211_ATTR_NAN_FUNC); 11168 if (!func_attr) 11169 goto nla_put_failure; 11170 11171 if (nla_put_u8(msg, NL80211_NAN_FUNC_INSTANCE_ID, inst_id) || 11172 nla_put_u8(msg, NL80211_NAN_FUNC_TERM_REASON, reason)) 11173 goto nla_put_failure; 11174 11175 nla_nest_end(msg, func_attr); 11176 genlmsg_end(msg, hdr); 11177 11178 if (!wdev->owner_nlportid) 11179 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), 11180 msg, 0, NL80211_MCGRP_NAN, gfp); 11181 else 11182 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, 11183 wdev->owner_nlportid); 11184 11185 return; 11186 11187 nla_put_failure: 11188 nlmsg_free(msg); 11189 } 11190 EXPORT_SYMBOL(cfg80211_nan_func_terminated); 11191 11192 static int nl80211_get_protocol_features(struct sk_buff *skb, 11193 struct genl_info *info) 11194 { 11195 void *hdr; 11196 struct sk_buff *msg; 11197 11198 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 11199 if (!msg) 11200 return -ENOMEM; 11201 11202 hdr = nl80211hdr_put(msg, info->snd_portid, info->snd_seq, 0, 11203 NL80211_CMD_GET_PROTOCOL_FEATURES); 11204 if (!hdr) 11205 goto nla_put_failure; 11206 11207 if (nla_put_u32(msg, NL80211_ATTR_PROTOCOL_FEATURES, 11208 NL80211_PROTOCOL_FEATURE_SPLIT_WIPHY_DUMP)) 11209 goto nla_put_failure; 11210 11211 genlmsg_end(msg, hdr); 11212 return genlmsg_reply(msg, info); 11213 11214 nla_put_failure: 11215 kfree_skb(msg); 11216 return -ENOBUFS; 11217 } 11218 11219 static int nl80211_update_ft_ies(struct sk_buff *skb, struct genl_info *info) 11220 { 11221 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11222 struct cfg80211_update_ft_ies_params ft_params; 11223 struct net_device *dev = info->user_ptr[1]; 11224 11225 if (!rdev->ops->update_ft_ies) 11226 return -EOPNOTSUPP; 11227 11228 if (!info->attrs[NL80211_ATTR_MDID] || 11229 !is_valid_ie_attr(info->attrs[NL80211_ATTR_IE])) 11230 return -EINVAL; 11231 11232 memset(&ft_params, 0, sizeof(ft_params)); 11233 ft_params.md = nla_get_u16(info->attrs[NL80211_ATTR_MDID]); 11234 ft_params.ie = nla_data(info->attrs[NL80211_ATTR_IE]); 11235 ft_params.ie_len = nla_len(info->attrs[NL80211_ATTR_IE]); 11236 11237 return rdev_update_ft_ies(rdev, dev, &ft_params); 11238 } 11239 11240 static int nl80211_crit_protocol_start(struct sk_buff *skb, 11241 struct genl_info *info) 11242 { 11243 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11244 struct wireless_dev *wdev = info->user_ptr[1]; 11245 enum nl80211_crit_proto_id proto = NL80211_CRIT_PROTO_UNSPEC; 11246 u16 duration; 11247 int ret; 11248 11249 if (!rdev->ops->crit_proto_start) 11250 return -EOPNOTSUPP; 11251 11252 if (WARN_ON(!rdev->ops->crit_proto_stop)) 11253 return -EINVAL; 11254 11255 if (rdev->crit_proto_nlportid) 11256 return -EBUSY; 11257 11258 /* determine protocol if provided */ 11259 if (info->attrs[NL80211_ATTR_CRIT_PROT_ID]) 11260 proto = nla_get_u16(info->attrs[NL80211_ATTR_CRIT_PROT_ID]); 11261 11262 if (proto >= NUM_NL80211_CRIT_PROTO) 11263 return -EINVAL; 11264 11265 /* timeout must be provided */ 11266 if (!info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]) 11267 return -EINVAL; 11268 11269 duration = 11270 nla_get_u16(info->attrs[NL80211_ATTR_MAX_CRIT_PROT_DURATION]); 11271 11272 if (duration > NL80211_CRIT_PROTO_MAX_DURATION) 11273 return -ERANGE; 11274 11275 ret = rdev_crit_proto_start(rdev, wdev, proto, duration); 11276 if (!ret) 11277 rdev->crit_proto_nlportid = info->snd_portid; 11278 11279 return ret; 11280 } 11281 11282 static int nl80211_crit_protocol_stop(struct sk_buff *skb, 11283 struct genl_info *info) 11284 { 11285 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11286 struct wireless_dev *wdev = info->user_ptr[1]; 11287 11288 if (!rdev->ops->crit_proto_stop) 11289 return -EOPNOTSUPP; 11290 11291 if (rdev->crit_proto_nlportid) { 11292 rdev->crit_proto_nlportid = 0; 11293 rdev_crit_proto_stop(rdev, wdev); 11294 } 11295 return 0; 11296 } 11297 11298 static int nl80211_vendor_cmd(struct sk_buff *skb, struct genl_info *info) 11299 { 11300 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11301 struct wireless_dev *wdev = 11302 __cfg80211_wdev_from_attrs(genl_info_net(info), info->attrs); 11303 int i, err; 11304 u32 vid, subcmd; 11305 11306 if (!rdev->wiphy.vendor_commands) 11307 return -EOPNOTSUPP; 11308 11309 if (IS_ERR(wdev)) { 11310 err = PTR_ERR(wdev); 11311 if (err != -EINVAL) 11312 return err; 11313 wdev = NULL; 11314 } else if (wdev->wiphy != &rdev->wiphy) { 11315 return -EINVAL; 11316 } 11317 11318 if (!info->attrs[NL80211_ATTR_VENDOR_ID] || 11319 !info->attrs[NL80211_ATTR_VENDOR_SUBCMD]) 11320 return -EINVAL; 11321 11322 vid = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_ID]); 11323 subcmd = nla_get_u32(info->attrs[NL80211_ATTR_VENDOR_SUBCMD]); 11324 for (i = 0; i < rdev->wiphy.n_vendor_commands; i++) { 11325 const struct wiphy_vendor_command *vcmd; 11326 void *data = NULL; 11327 int len = 0; 11328 11329 vcmd = &rdev->wiphy.vendor_commands[i]; 11330 11331 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd) 11332 continue; 11333 11334 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV | 11335 WIPHY_VENDOR_CMD_NEED_NETDEV)) { 11336 if (!wdev) 11337 return -EINVAL; 11338 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV && 11339 !wdev->netdev) 11340 return -EINVAL; 11341 11342 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) { 11343 if (!wdev_running(wdev)) 11344 return -ENETDOWN; 11345 } 11346 11347 if (!vcmd->doit) 11348 return -EOPNOTSUPP; 11349 } else { 11350 wdev = NULL; 11351 } 11352 11353 if (info->attrs[NL80211_ATTR_VENDOR_DATA]) { 11354 data = nla_data(info->attrs[NL80211_ATTR_VENDOR_DATA]); 11355 len = nla_len(info->attrs[NL80211_ATTR_VENDOR_DATA]); 11356 } 11357 11358 rdev->cur_cmd_info = info; 11359 err = rdev->wiphy.vendor_commands[i].doit(&rdev->wiphy, wdev, 11360 data, len); 11361 rdev->cur_cmd_info = NULL; 11362 return err; 11363 } 11364 11365 return -EOPNOTSUPP; 11366 } 11367 11368 static int nl80211_prepare_vendor_dump(struct sk_buff *skb, 11369 struct netlink_callback *cb, 11370 struct cfg80211_registered_device **rdev, 11371 struct wireless_dev **wdev) 11372 { 11373 struct nlattr **attrbuf = genl_family_attrbuf(&nl80211_fam); 11374 u32 vid, subcmd; 11375 unsigned int i; 11376 int vcmd_idx = -1; 11377 int err; 11378 void *data = NULL; 11379 unsigned int data_len = 0; 11380 11381 rtnl_lock(); 11382 11383 if (cb->args[0]) { 11384 /* subtract the 1 again here */ 11385 struct wiphy *wiphy = wiphy_idx_to_wiphy(cb->args[0] - 1); 11386 struct wireless_dev *tmp; 11387 11388 if (!wiphy) { 11389 err = -ENODEV; 11390 goto out_unlock; 11391 } 11392 *rdev = wiphy_to_rdev(wiphy); 11393 *wdev = NULL; 11394 11395 if (cb->args[1]) { 11396 list_for_each_entry(tmp, &wiphy->wdev_list, list) { 11397 if (tmp->identifier == cb->args[1] - 1) { 11398 *wdev = tmp; 11399 break; 11400 } 11401 } 11402 } 11403 11404 /* keep rtnl locked in successful case */ 11405 return 0; 11406 } 11407 11408 err = nlmsg_parse(cb->nlh, GENL_HDRLEN + nl80211_fam.hdrsize, 11409 attrbuf, nl80211_fam.maxattr, nl80211_policy); 11410 if (err) 11411 goto out_unlock; 11412 11413 if (!attrbuf[NL80211_ATTR_VENDOR_ID] || 11414 !attrbuf[NL80211_ATTR_VENDOR_SUBCMD]) { 11415 err = -EINVAL; 11416 goto out_unlock; 11417 } 11418 11419 *wdev = __cfg80211_wdev_from_attrs(sock_net(skb->sk), attrbuf); 11420 if (IS_ERR(*wdev)) 11421 *wdev = NULL; 11422 11423 *rdev = __cfg80211_rdev_from_attrs(sock_net(skb->sk), attrbuf); 11424 if (IS_ERR(*rdev)) { 11425 err = PTR_ERR(*rdev); 11426 goto out_unlock; 11427 } 11428 11429 vid = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_ID]); 11430 subcmd = nla_get_u32(attrbuf[NL80211_ATTR_VENDOR_SUBCMD]); 11431 11432 for (i = 0; i < (*rdev)->wiphy.n_vendor_commands; i++) { 11433 const struct wiphy_vendor_command *vcmd; 11434 11435 vcmd = &(*rdev)->wiphy.vendor_commands[i]; 11436 11437 if (vcmd->info.vendor_id != vid || vcmd->info.subcmd != subcmd) 11438 continue; 11439 11440 if (!vcmd->dumpit) { 11441 err = -EOPNOTSUPP; 11442 goto out_unlock; 11443 } 11444 11445 vcmd_idx = i; 11446 break; 11447 } 11448 11449 if (vcmd_idx < 0) { 11450 err = -EOPNOTSUPP; 11451 goto out_unlock; 11452 } 11453 11454 if (attrbuf[NL80211_ATTR_VENDOR_DATA]) { 11455 data = nla_data(attrbuf[NL80211_ATTR_VENDOR_DATA]); 11456 data_len = nla_len(attrbuf[NL80211_ATTR_VENDOR_DATA]); 11457 } 11458 11459 /* 0 is the first index - add 1 to parse only once */ 11460 cb->args[0] = (*rdev)->wiphy_idx + 1; 11461 /* add 1 to know if it was NULL */ 11462 cb->args[1] = *wdev ? (*wdev)->identifier + 1 : 0; 11463 cb->args[2] = vcmd_idx; 11464 cb->args[3] = (unsigned long)data; 11465 cb->args[4] = data_len; 11466 11467 /* keep rtnl locked in successful case */ 11468 return 0; 11469 out_unlock: 11470 rtnl_unlock(); 11471 return err; 11472 } 11473 11474 static int nl80211_vendor_cmd_dump(struct sk_buff *skb, 11475 struct netlink_callback *cb) 11476 { 11477 struct cfg80211_registered_device *rdev; 11478 struct wireless_dev *wdev; 11479 unsigned int vcmd_idx; 11480 const struct wiphy_vendor_command *vcmd; 11481 void *data; 11482 int data_len; 11483 int err; 11484 struct nlattr *vendor_data; 11485 11486 err = nl80211_prepare_vendor_dump(skb, cb, &rdev, &wdev); 11487 if (err) 11488 return err; 11489 11490 vcmd_idx = cb->args[2]; 11491 data = (void *)cb->args[3]; 11492 data_len = cb->args[4]; 11493 vcmd = &rdev->wiphy.vendor_commands[vcmd_idx]; 11494 11495 if (vcmd->flags & (WIPHY_VENDOR_CMD_NEED_WDEV | 11496 WIPHY_VENDOR_CMD_NEED_NETDEV)) { 11497 if (!wdev) 11498 return -EINVAL; 11499 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_NETDEV && 11500 !wdev->netdev) 11501 return -EINVAL; 11502 11503 if (vcmd->flags & WIPHY_VENDOR_CMD_NEED_RUNNING) { 11504 if (!wdev_running(wdev)) 11505 return -ENETDOWN; 11506 } 11507 } 11508 11509 while (1) { 11510 void *hdr = nl80211hdr_put(skb, NETLINK_CB(cb->skb).portid, 11511 cb->nlh->nlmsg_seq, NLM_F_MULTI, 11512 NL80211_CMD_VENDOR); 11513 if (!hdr) 11514 break; 11515 11516 if (nla_put_u32(skb, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 11517 (wdev && nla_put_u64_64bit(skb, NL80211_ATTR_WDEV, 11518 wdev_id(wdev), 11519 NL80211_ATTR_PAD))) { 11520 genlmsg_cancel(skb, hdr); 11521 break; 11522 } 11523 11524 vendor_data = nla_nest_start(skb, NL80211_ATTR_VENDOR_DATA); 11525 if (!vendor_data) { 11526 genlmsg_cancel(skb, hdr); 11527 break; 11528 } 11529 11530 err = vcmd->dumpit(&rdev->wiphy, wdev, skb, data, data_len, 11531 (unsigned long *)&cb->args[5]); 11532 nla_nest_end(skb, vendor_data); 11533 11534 if (err == -ENOBUFS || err == -ENOENT) { 11535 genlmsg_cancel(skb, hdr); 11536 break; 11537 } else if (err) { 11538 genlmsg_cancel(skb, hdr); 11539 goto out; 11540 } 11541 11542 genlmsg_end(skb, hdr); 11543 } 11544 11545 err = skb->len; 11546 out: 11547 rtnl_unlock(); 11548 return err; 11549 } 11550 11551 struct sk_buff *__cfg80211_alloc_reply_skb(struct wiphy *wiphy, 11552 enum nl80211_commands cmd, 11553 enum nl80211_attrs attr, 11554 int approxlen) 11555 { 11556 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 11557 11558 if (WARN_ON(!rdev->cur_cmd_info)) 11559 return NULL; 11560 11561 return __cfg80211_alloc_vendor_skb(rdev, NULL, approxlen, 11562 rdev->cur_cmd_info->snd_portid, 11563 rdev->cur_cmd_info->snd_seq, 11564 cmd, attr, NULL, GFP_KERNEL); 11565 } 11566 EXPORT_SYMBOL(__cfg80211_alloc_reply_skb); 11567 11568 int cfg80211_vendor_cmd_reply(struct sk_buff *skb) 11569 { 11570 struct cfg80211_registered_device *rdev = ((void **)skb->cb)[0]; 11571 void *hdr = ((void **)skb->cb)[1]; 11572 struct nlattr *data = ((void **)skb->cb)[2]; 11573 11574 /* clear CB data for netlink core to own from now on */ 11575 memset(skb->cb, 0, sizeof(skb->cb)); 11576 11577 if (WARN_ON(!rdev->cur_cmd_info)) { 11578 kfree_skb(skb); 11579 return -EINVAL; 11580 } 11581 11582 nla_nest_end(skb, data); 11583 genlmsg_end(skb, hdr); 11584 return genlmsg_reply(skb, rdev->cur_cmd_info); 11585 } 11586 EXPORT_SYMBOL_GPL(cfg80211_vendor_cmd_reply); 11587 11588 static int nl80211_set_qos_map(struct sk_buff *skb, 11589 struct genl_info *info) 11590 { 11591 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11592 struct cfg80211_qos_map *qos_map = NULL; 11593 struct net_device *dev = info->user_ptr[1]; 11594 u8 *pos, len, num_des, des_len, des; 11595 int ret; 11596 11597 if (!rdev->ops->set_qos_map) 11598 return -EOPNOTSUPP; 11599 11600 if (info->attrs[NL80211_ATTR_QOS_MAP]) { 11601 pos = nla_data(info->attrs[NL80211_ATTR_QOS_MAP]); 11602 len = nla_len(info->attrs[NL80211_ATTR_QOS_MAP]); 11603 11604 if (len % 2 || len < IEEE80211_QOS_MAP_LEN_MIN || 11605 len > IEEE80211_QOS_MAP_LEN_MAX) 11606 return -EINVAL; 11607 11608 qos_map = kzalloc(sizeof(struct cfg80211_qos_map), GFP_KERNEL); 11609 if (!qos_map) 11610 return -ENOMEM; 11611 11612 num_des = (len - IEEE80211_QOS_MAP_LEN_MIN) >> 1; 11613 if (num_des) { 11614 des_len = num_des * 11615 sizeof(struct cfg80211_dscp_exception); 11616 memcpy(qos_map->dscp_exception, pos, des_len); 11617 qos_map->num_des = num_des; 11618 for (des = 0; des < num_des; des++) { 11619 if (qos_map->dscp_exception[des].up > 7) { 11620 kfree(qos_map); 11621 return -EINVAL; 11622 } 11623 } 11624 pos += des_len; 11625 } 11626 memcpy(qos_map->up, pos, IEEE80211_QOS_MAP_LEN_MIN); 11627 } 11628 11629 wdev_lock(dev->ieee80211_ptr); 11630 ret = nl80211_key_allowed(dev->ieee80211_ptr); 11631 if (!ret) 11632 ret = rdev_set_qos_map(rdev, dev, qos_map); 11633 wdev_unlock(dev->ieee80211_ptr); 11634 11635 kfree(qos_map); 11636 return ret; 11637 } 11638 11639 static int nl80211_add_tx_ts(struct sk_buff *skb, struct genl_info *info) 11640 { 11641 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11642 struct net_device *dev = info->user_ptr[1]; 11643 struct wireless_dev *wdev = dev->ieee80211_ptr; 11644 const u8 *peer; 11645 u8 tsid, up; 11646 u16 admitted_time = 0; 11647 int err; 11648 11649 if (!(rdev->wiphy.features & NL80211_FEATURE_SUPPORTS_WMM_ADMISSION)) 11650 return -EOPNOTSUPP; 11651 11652 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC] || 11653 !info->attrs[NL80211_ATTR_USER_PRIO]) 11654 return -EINVAL; 11655 11656 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]); 11657 if (tsid >= IEEE80211_NUM_TIDS) 11658 return -EINVAL; 11659 11660 up = nla_get_u8(info->attrs[NL80211_ATTR_USER_PRIO]); 11661 if (up >= IEEE80211_NUM_UPS) 11662 return -EINVAL; 11663 11664 /* WMM uses TIDs 0-7 even for TSPEC */ 11665 if (tsid >= IEEE80211_FIRST_TSPEC_TSID) { 11666 /* TODO: handle 802.11 TSPEC/admission control 11667 * need more attributes for that (e.g. BA session requirement); 11668 * change the WMM adminssion test above to allow both then 11669 */ 11670 return -EINVAL; 11671 } 11672 11673 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 11674 11675 if (info->attrs[NL80211_ATTR_ADMITTED_TIME]) { 11676 admitted_time = 11677 nla_get_u16(info->attrs[NL80211_ATTR_ADMITTED_TIME]); 11678 if (!admitted_time) 11679 return -EINVAL; 11680 } 11681 11682 wdev_lock(wdev); 11683 switch (wdev->iftype) { 11684 case NL80211_IFTYPE_STATION: 11685 case NL80211_IFTYPE_P2P_CLIENT: 11686 if (wdev->current_bss) 11687 break; 11688 err = -ENOTCONN; 11689 goto out; 11690 default: 11691 err = -EOPNOTSUPP; 11692 goto out; 11693 } 11694 11695 err = rdev_add_tx_ts(rdev, dev, tsid, peer, up, admitted_time); 11696 11697 out: 11698 wdev_unlock(wdev); 11699 return err; 11700 } 11701 11702 static int nl80211_del_tx_ts(struct sk_buff *skb, struct genl_info *info) 11703 { 11704 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11705 struct net_device *dev = info->user_ptr[1]; 11706 struct wireless_dev *wdev = dev->ieee80211_ptr; 11707 const u8 *peer; 11708 u8 tsid; 11709 int err; 11710 11711 if (!info->attrs[NL80211_ATTR_TSID] || !info->attrs[NL80211_ATTR_MAC]) 11712 return -EINVAL; 11713 11714 tsid = nla_get_u8(info->attrs[NL80211_ATTR_TSID]); 11715 peer = nla_data(info->attrs[NL80211_ATTR_MAC]); 11716 11717 wdev_lock(wdev); 11718 err = rdev_del_tx_ts(rdev, dev, tsid, peer); 11719 wdev_unlock(wdev); 11720 11721 return err; 11722 } 11723 11724 static int nl80211_tdls_channel_switch(struct sk_buff *skb, 11725 struct genl_info *info) 11726 { 11727 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11728 struct net_device *dev = info->user_ptr[1]; 11729 struct wireless_dev *wdev = dev->ieee80211_ptr; 11730 struct cfg80211_chan_def chandef = {}; 11731 const u8 *addr; 11732 u8 oper_class; 11733 int err; 11734 11735 if (!rdev->ops->tdls_channel_switch || 11736 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH)) 11737 return -EOPNOTSUPP; 11738 11739 switch (dev->ieee80211_ptr->iftype) { 11740 case NL80211_IFTYPE_STATION: 11741 case NL80211_IFTYPE_P2P_CLIENT: 11742 break; 11743 default: 11744 return -EOPNOTSUPP; 11745 } 11746 11747 if (!info->attrs[NL80211_ATTR_MAC] || 11748 !info->attrs[NL80211_ATTR_OPER_CLASS]) 11749 return -EINVAL; 11750 11751 err = nl80211_parse_chandef(rdev, info, &chandef); 11752 if (err) 11753 return err; 11754 11755 /* 11756 * Don't allow wide channels on the 2.4Ghz band, as per IEEE802.11-2012 11757 * section 10.22.6.2.1. Disallow 5/10Mhz channels as well for now, the 11758 * specification is not defined for them. 11759 */ 11760 if (chandef.chan->band == NL80211_BAND_2GHZ && 11761 chandef.width != NL80211_CHAN_WIDTH_20_NOHT && 11762 chandef.width != NL80211_CHAN_WIDTH_20) 11763 return -EINVAL; 11764 11765 /* we will be active on the TDLS link */ 11766 if (!cfg80211_reg_can_beacon_relax(&rdev->wiphy, &chandef, 11767 wdev->iftype)) 11768 return -EINVAL; 11769 11770 /* don't allow switching to DFS channels */ 11771 if (cfg80211_chandef_dfs_required(wdev->wiphy, &chandef, wdev->iftype)) 11772 return -EINVAL; 11773 11774 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 11775 oper_class = nla_get_u8(info->attrs[NL80211_ATTR_OPER_CLASS]); 11776 11777 wdev_lock(wdev); 11778 err = rdev_tdls_channel_switch(rdev, dev, addr, oper_class, &chandef); 11779 wdev_unlock(wdev); 11780 11781 return err; 11782 } 11783 11784 static int nl80211_tdls_cancel_channel_switch(struct sk_buff *skb, 11785 struct genl_info *info) 11786 { 11787 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11788 struct net_device *dev = info->user_ptr[1]; 11789 struct wireless_dev *wdev = dev->ieee80211_ptr; 11790 const u8 *addr; 11791 11792 if (!rdev->ops->tdls_channel_switch || 11793 !rdev->ops->tdls_cancel_channel_switch || 11794 !(rdev->wiphy.features & NL80211_FEATURE_TDLS_CHANNEL_SWITCH)) 11795 return -EOPNOTSUPP; 11796 11797 switch (dev->ieee80211_ptr->iftype) { 11798 case NL80211_IFTYPE_STATION: 11799 case NL80211_IFTYPE_P2P_CLIENT: 11800 break; 11801 default: 11802 return -EOPNOTSUPP; 11803 } 11804 11805 if (!info->attrs[NL80211_ATTR_MAC]) 11806 return -EINVAL; 11807 11808 addr = nla_data(info->attrs[NL80211_ATTR_MAC]); 11809 11810 wdev_lock(wdev); 11811 rdev_tdls_cancel_channel_switch(rdev, dev, addr); 11812 wdev_unlock(wdev); 11813 11814 return 0; 11815 } 11816 11817 static int nl80211_set_multicast_to_unicast(struct sk_buff *skb, 11818 struct genl_info *info) 11819 { 11820 struct cfg80211_registered_device *rdev = info->user_ptr[0]; 11821 struct net_device *dev = info->user_ptr[1]; 11822 struct wireless_dev *wdev = dev->ieee80211_ptr; 11823 const struct nlattr *nla; 11824 bool enabled; 11825 11826 if (netif_running(dev)) 11827 return -EBUSY; 11828 11829 if (!rdev->ops->set_multicast_to_unicast) 11830 return -EOPNOTSUPP; 11831 11832 if (wdev->iftype != NL80211_IFTYPE_AP && 11833 wdev->iftype != NL80211_IFTYPE_P2P_GO) 11834 return -EOPNOTSUPP; 11835 11836 nla = info->attrs[NL80211_ATTR_MULTICAST_TO_UNICAST_ENABLED]; 11837 enabled = nla_get_flag(nla); 11838 11839 return rdev_set_multicast_to_unicast(rdev, dev, enabled); 11840 } 11841 11842 #define NL80211_FLAG_NEED_WIPHY 0x01 11843 #define NL80211_FLAG_NEED_NETDEV 0x02 11844 #define NL80211_FLAG_NEED_RTNL 0x04 11845 #define NL80211_FLAG_CHECK_NETDEV_UP 0x08 11846 #define NL80211_FLAG_NEED_NETDEV_UP (NL80211_FLAG_NEED_NETDEV |\ 11847 NL80211_FLAG_CHECK_NETDEV_UP) 11848 #define NL80211_FLAG_NEED_WDEV 0x10 11849 /* If a netdev is associated, it must be UP, P2P must be started */ 11850 #define NL80211_FLAG_NEED_WDEV_UP (NL80211_FLAG_NEED_WDEV |\ 11851 NL80211_FLAG_CHECK_NETDEV_UP) 11852 #define NL80211_FLAG_CLEAR_SKB 0x20 11853 11854 static int nl80211_pre_doit(const struct genl_ops *ops, struct sk_buff *skb, 11855 struct genl_info *info) 11856 { 11857 struct cfg80211_registered_device *rdev; 11858 struct wireless_dev *wdev; 11859 struct net_device *dev; 11860 bool rtnl = ops->internal_flags & NL80211_FLAG_NEED_RTNL; 11861 11862 if (rtnl) 11863 rtnl_lock(); 11864 11865 if (ops->internal_flags & NL80211_FLAG_NEED_WIPHY) { 11866 rdev = cfg80211_get_dev_from_info(genl_info_net(info), info); 11867 if (IS_ERR(rdev)) { 11868 if (rtnl) 11869 rtnl_unlock(); 11870 return PTR_ERR(rdev); 11871 } 11872 info->user_ptr[0] = rdev; 11873 } else if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV || 11874 ops->internal_flags & NL80211_FLAG_NEED_WDEV) { 11875 ASSERT_RTNL(); 11876 11877 wdev = __cfg80211_wdev_from_attrs(genl_info_net(info), 11878 info->attrs); 11879 if (IS_ERR(wdev)) { 11880 if (rtnl) 11881 rtnl_unlock(); 11882 return PTR_ERR(wdev); 11883 } 11884 11885 dev = wdev->netdev; 11886 rdev = wiphy_to_rdev(wdev->wiphy); 11887 11888 if (ops->internal_flags & NL80211_FLAG_NEED_NETDEV) { 11889 if (!dev) { 11890 if (rtnl) 11891 rtnl_unlock(); 11892 return -EINVAL; 11893 } 11894 11895 info->user_ptr[1] = dev; 11896 } else { 11897 info->user_ptr[1] = wdev; 11898 } 11899 11900 if (ops->internal_flags & NL80211_FLAG_CHECK_NETDEV_UP && 11901 !wdev_running(wdev)) { 11902 if (rtnl) 11903 rtnl_unlock(); 11904 return -ENETDOWN; 11905 } 11906 11907 if (dev) 11908 dev_hold(dev); 11909 11910 info->user_ptr[0] = rdev; 11911 } 11912 11913 return 0; 11914 } 11915 11916 static void nl80211_post_doit(const struct genl_ops *ops, struct sk_buff *skb, 11917 struct genl_info *info) 11918 { 11919 if (info->user_ptr[1]) { 11920 if (ops->internal_flags & NL80211_FLAG_NEED_WDEV) { 11921 struct wireless_dev *wdev = info->user_ptr[1]; 11922 11923 if (wdev->netdev) 11924 dev_put(wdev->netdev); 11925 } else { 11926 dev_put(info->user_ptr[1]); 11927 } 11928 } 11929 11930 if (ops->internal_flags & NL80211_FLAG_NEED_RTNL) 11931 rtnl_unlock(); 11932 11933 /* If needed, clear the netlink message payload from the SKB 11934 * as it might contain key data that shouldn't stick around on 11935 * the heap after the SKB is freed. The netlink message header 11936 * is still needed for further processing, so leave it intact. 11937 */ 11938 if (ops->internal_flags & NL80211_FLAG_CLEAR_SKB) { 11939 struct nlmsghdr *nlh = nlmsg_hdr(skb); 11940 11941 memset(nlmsg_data(nlh), 0, nlmsg_len(nlh)); 11942 } 11943 } 11944 11945 static const struct genl_ops nl80211_ops[] = { 11946 { 11947 .cmd = NL80211_CMD_GET_WIPHY, 11948 .doit = nl80211_get_wiphy, 11949 .dumpit = nl80211_dump_wiphy, 11950 .done = nl80211_dump_wiphy_done, 11951 .policy = nl80211_policy, 11952 /* can be retrieved by unprivileged users */ 11953 .internal_flags = NL80211_FLAG_NEED_WIPHY | 11954 NL80211_FLAG_NEED_RTNL, 11955 }, 11956 { 11957 .cmd = NL80211_CMD_SET_WIPHY, 11958 .doit = nl80211_set_wiphy, 11959 .policy = nl80211_policy, 11960 .flags = GENL_UNS_ADMIN_PERM, 11961 .internal_flags = NL80211_FLAG_NEED_RTNL, 11962 }, 11963 { 11964 .cmd = NL80211_CMD_GET_INTERFACE, 11965 .doit = nl80211_get_interface, 11966 .dumpit = nl80211_dump_interface, 11967 .policy = nl80211_policy, 11968 /* can be retrieved by unprivileged users */ 11969 .internal_flags = NL80211_FLAG_NEED_WDEV | 11970 NL80211_FLAG_NEED_RTNL, 11971 }, 11972 { 11973 .cmd = NL80211_CMD_SET_INTERFACE, 11974 .doit = nl80211_set_interface, 11975 .policy = nl80211_policy, 11976 .flags = GENL_UNS_ADMIN_PERM, 11977 .internal_flags = NL80211_FLAG_NEED_NETDEV | 11978 NL80211_FLAG_NEED_RTNL, 11979 }, 11980 { 11981 .cmd = NL80211_CMD_NEW_INTERFACE, 11982 .doit = nl80211_new_interface, 11983 .policy = nl80211_policy, 11984 .flags = GENL_UNS_ADMIN_PERM, 11985 .internal_flags = NL80211_FLAG_NEED_WIPHY | 11986 NL80211_FLAG_NEED_RTNL, 11987 }, 11988 { 11989 .cmd = NL80211_CMD_DEL_INTERFACE, 11990 .doit = nl80211_del_interface, 11991 .policy = nl80211_policy, 11992 .flags = GENL_UNS_ADMIN_PERM, 11993 .internal_flags = NL80211_FLAG_NEED_WDEV | 11994 NL80211_FLAG_NEED_RTNL, 11995 }, 11996 { 11997 .cmd = NL80211_CMD_GET_KEY, 11998 .doit = nl80211_get_key, 11999 .policy = nl80211_policy, 12000 .flags = GENL_UNS_ADMIN_PERM, 12001 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12002 NL80211_FLAG_NEED_RTNL, 12003 }, 12004 { 12005 .cmd = NL80211_CMD_SET_KEY, 12006 .doit = nl80211_set_key, 12007 .policy = nl80211_policy, 12008 .flags = GENL_UNS_ADMIN_PERM, 12009 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12010 NL80211_FLAG_NEED_RTNL | 12011 NL80211_FLAG_CLEAR_SKB, 12012 }, 12013 { 12014 .cmd = NL80211_CMD_NEW_KEY, 12015 .doit = nl80211_new_key, 12016 .policy = nl80211_policy, 12017 .flags = GENL_UNS_ADMIN_PERM, 12018 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12019 NL80211_FLAG_NEED_RTNL | 12020 NL80211_FLAG_CLEAR_SKB, 12021 }, 12022 { 12023 .cmd = NL80211_CMD_DEL_KEY, 12024 .doit = nl80211_del_key, 12025 .policy = nl80211_policy, 12026 .flags = GENL_UNS_ADMIN_PERM, 12027 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12028 NL80211_FLAG_NEED_RTNL, 12029 }, 12030 { 12031 .cmd = NL80211_CMD_SET_BEACON, 12032 .policy = nl80211_policy, 12033 .flags = GENL_UNS_ADMIN_PERM, 12034 .doit = nl80211_set_beacon, 12035 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12036 NL80211_FLAG_NEED_RTNL, 12037 }, 12038 { 12039 .cmd = NL80211_CMD_START_AP, 12040 .policy = nl80211_policy, 12041 .flags = GENL_UNS_ADMIN_PERM, 12042 .doit = nl80211_start_ap, 12043 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12044 NL80211_FLAG_NEED_RTNL, 12045 }, 12046 { 12047 .cmd = NL80211_CMD_STOP_AP, 12048 .policy = nl80211_policy, 12049 .flags = GENL_UNS_ADMIN_PERM, 12050 .doit = nl80211_stop_ap, 12051 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12052 NL80211_FLAG_NEED_RTNL, 12053 }, 12054 { 12055 .cmd = NL80211_CMD_GET_STATION, 12056 .doit = nl80211_get_station, 12057 .dumpit = nl80211_dump_station, 12058 .policy = nl80211_policy, 12059 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12060 NL80211_FLAG_NEED_RTNL, 12061 }, 12062 { 12063 .cmd = NL80211_CMD_SET_STATION, 12064 .doit = nl80211_set_station, 12065 .policy = nl80211_policy, 12066 .flags = GENL_UNS_ADMIN_PERM, 12067 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12068 NL80211_FLAG_NEED_RTNL, 12069 }, 12070 { 12071 .cmd = NL80211_CMD_NEW_STATION, 12072 .doit = nl80211_new_station, 12073 .policy = nl80211_policy, 12074 .flags = GENL_UNS_ADMIN_PERM, 12075 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12076 NL80211_FLAG_NEED_RTNL, 12077 }, 12078 { 12079 .cmd = NL80211_CMD_DEL_STATION, 12080 .doit = nl80211_del_station, 12081 .policy = nl80211_policy, 12082 .flags = GENL_UNS_ADMIN_PERM, 12083 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12084 NL80211_FLAG_NEED_RTNL, 12085 }, 12086 { 12087 .cmd = NL80211_CMD_GET_MPATH, 12088 .doit = nl80211_get_mpath, 12089 .dumpit = nl80211_dump_mpath, 12090 .policy = nl80211_policy, 12091 .flags = GENL_UNS_ADMIN_PERM, 12092 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12093 NL80211_FLAG_NEED_RTNL, 12094 }, 12095 { 12096 .cmd = NL80211_CMD_GET_MPP, 12097 .doit = nl80211_get_mpp, 12098 .dumpit = nl80211_dump_mpp, 12099 .policy = nl80211_policy, 12100 .flags = GENL_UNS_ADMIN_PERM, 12101 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12102 NL80211_FLAG_NEED_RTNL, 12103 }, 12104 { 12105 .cmd = NL80211_CMD_SET_MPATH, 12106 .doit = nl80211_set_mpath, 12107 .policy = nl80211_policy, 12108 .flags = GENL_UNS_ADMIN_PERM, 12109 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12110 NL80211_FLAG_NEED_RTNL, 12111 }, 12112 { 12113 .cmd = NL80211_CMD_NEW_MPATH, 12114 .doit = nl80211_new_mpath, 12115 .policy = nl80211_policy, 12116 .flags = GENL_UNS_ADMIN_PERM, 12117 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12118 NL80211_FLAG_NEED_RTNL, 12119 }, 12120 { 12121 .cmd = NL80211_CMD_DEL_MPATH, 12122 .doit = nl80211_del_mpath, 12123 .policy = nl80211_policy, 12124 .flags = GENL_UNS_ADMIN_PERM, 12125 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12126 NL80211_FLAG_NEED_RTNL, 12127 }, 12128 { 12129 .cmd = NL80211_CMD_SET_BSS, 12130 .doit = nl80211_set_bss, 12131 .policy = nl80211_policy, 12132 .flags = GENL_UNS_ADMIN_PERM, 12133 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12134 NL80211_FLAG_NEED_RTNL, 12135 }, 12136 { 12137 .cmd = NL80211_CMD_GET_REG, 12138 .doit = nl80211_get_reg_do, 12139 .dumpit = nl80211_get_reg_dump, 12140 .policy = nl80211_policy, 12141 .internal_flags = NL80211_FLAG_NEED_RTNL, 12142 /* can be retrieved by unprivileged users */ 12143 }, 12144 #ifdef CONFIG_CFG80211_CRDA_SUPPORT 12145 { 12146 .cmd = NL80211_CMD_SET_REG, 12147 .doit = nl80211_set_reg, 12148 .policy = nl80211_policy, 12149 .flags = GENL_ADMIN_PERM, 12150 .internal_flags = NL80211_FLAG_NEED_RTNL, 12151 }, 12152 #endif 12153 { 12154 .cmd = NL80211_CMD_REQ_SET_REG, 12155 .doit = nl80211_req_set_reg, 12156 .policy = nl80211_policy, 12157 .flags = GENL_ADMIN_PERM, 12158 }, 12159 { 12160 .cmd = NL80211_CMD_GET_MESH_CONFIG, 12161 .doit = nl80211_get_mesh_config, 12162 .policy = nl80211_policy, 12163 /* can be retrieved by unprivileged users */ 12164 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12165 NL80211_FLAG_NEED_RTNL, 12166 }, 12167 { 12168 .cmd = NL80211_CMD_SET_MESH_CONFIG, 12169 .doit = nl80211_update_mesh_config, 12170 .policy = nl80211_policy, 12171 .flags = GENL_UNS_ADMIN_PERM, 12172 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12173 NL80211_FLAG_NEED_RTNL, 12174 }, 12175 { 12176 .cmd = NL80211_CMD_TRIGGER_SCAN, 12177 .doit = nl80211_trigger_scan, 12178 .policy = nl80211_policy, 12179 .flags = GENL_UNS_ADMIN_PERM, 12180 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12181 NL80211_FLAG_NEED_RTNL, 12182 }, 12183 { 12184 .cmd = NL80211_CMD_ABORT_SCAN, 12185 .doit = nl80211_abort_scan, 12186 .policy = nl80211_policy, 12187 .flags = GENL_UNS_ADMIN_PERM, 12188 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12189 NL80211_FLAG_NEED_RTNL, 12190 }, 12191 { 12192 .cmd = NL80211_CMD_GET_SCAN, 12193 .policy = nl80211_policy, 12194 .dumpit = nl80211_dump_scan, 12195 }, 12196 { 12197 .cmd = NL80211_CMD_START_SCHED_SCAN, 12198 .doit = nl80211_start_sched_scan, 12199 .policy = nl80211_policy, 12200 .flags = GENL_UNS_ADMIN_PERM, 12201 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12202 NL80211_FLAG_NEED_RTNL, 12203 }, 12204 { 12205 .cmd = NL80211_CMD_STOP_SCHED_SCAN, 12206 .doit = nl80211_stop_sched_scan, 12207 .policy = nl80211_policy, 12208 .flags = GENL_UNS_ADMIN_PERM, 12209 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12210 NL80211_FLAG_NEED_RTNL, 12211 }, 12212 { 12213 .cmd = NL80211_CMD_AUTHENTICATE, 12214 .doit = nl80211_authenticate, 12215 .policy = nl80211_policy, 12216 .flags = GENL_UNS_ADMIN_PERM, 12217 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12218 NL80211_FLAG_NEED_RTNL | 12219 NL80211_FLAG_CLEAR_SKB, 12220 }, 12221 { 12222 .cmd = NL80211_CMD_ASSOCIATE, 12223 .doit = nl80211_associate, 12224 .policy = nl80211_policy, 12225 .flags = GENL_UNS_ADMIN_PERM, 12226 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12227 NL80211_FLAG_NEED_RTNL, 12228 }, 12229 { 12230 .cmd = NL80211_CMD_DEAUTHENTICATE, 12231 .doit = nl80211_deauthenticate, 12232 .policy = nl80211_policy, 12233 .flags = GENL_UNS_ADMIN_PERM, 12234 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12235 NL80211_FLAG_NEED_RTNL, 12236 }, 12237 { 12238 .cmd = NL80211_CMD_DISASSOCIATE, 12239 .doit = nl80211_disassociate, 12240 .policy = nl80211_policy, 12241 .flags = GENL_UNS_ADMIN_PERM, 12242 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12243 NL80211_FLAG_NEED_RTNL, 12244 }, 12245 { 12246 .cmd = NL80211_CMD_JOIN_IBSS, 12247 .doit = nl80211_join_ibss, 12248 .policy = nl80211_policy, 12249 .flags = GENL_UNS_ADMIN_PERM, 12250 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12251 NL80211_FLAG_NEED_RTNL, 12252 }, 12253 { 12254 .cmd = NL80211_CMD_LEAVE_IBSS, 12255 .doit = nl80211_leave_ibss, 12256 .policy = nl80211_policy, 12257 .flags = GENL_UNS_ADMIN_PERM, 12258 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12259 NL80211_FLAG_NEED_RTNL, 12260 }, 12261 #ifdef CONFIG_NL80211_TESTMODE 12262 { 12263 .cmd = NL80211_CMD_TESTMODE, 12264 .doit = nl80211_testmode_do, 12265 .dumpit = nl80211_testmode_dump, 12266 .policy = nl80211_policy, 12267 .flags = GENL_UNS_ADMIN_PERM, 12268 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12269 NL80211_FLAG_NEED_RTNL, 12270 }, 12271 #endif 12272 { 12273 .cmd = NL80211_CMD_CONNECT, 12274 .doit = nl80211_connect, 12275 .policy = nl80211_policy, 12276 .flags = GENL_UNS_ADMIN_PERM, 12277 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12278 NL80211_FLAG_NEED_RTNL, 12279 }, 12280 { 12281 .cmd = NL80211_CMD_UPDATE_CONNECT_PARAMS, 12282 .doit = nl80211_update_connect_params, 12283 .policy = nl80211_policy, 12284 .flags = GENL_ADMIN_PERM, 12285 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12286 NL80211_FLAG_NEED_RTNL, 12287 }, 12288 { 12289 .cmd = NL80211_CMD_DISCONNECT, 12290 .doit = nl80211_disconnect, 12291 .policy = nl80211_policy, 12292 .flags = GENL_UNS_ADMIN_PERM, 12293 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12294 NL80211_FLAG_NEED_RTNL, 12295 }, 12296 { 12297 .cmd = NL80211_CMD_SET_WIPHY_NETNS, 12298 .doit = nl80211_wiphy_netns, 12299 .policy = nl80211_policy, 12300 .flags = GENL_UNS_ADMIN_PERM, 12301 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12302 NL80211_FLAG_NEED_RTNL, 12303 }, 12304 { 12305 .cmd = NL80211_CMD_GET_SURVEY, 12306 .policy = nl80211_policy, 12307 .dumpit = nl80211_dump_survey, 12308 }, 12309 { 12310 .cmd = NL80211_CMD_SET_PMKSA, 12311 .doit = nl80211_setdel_pmksa, 12312 .policy = nl80211_policy, 12313 .flags = GENL_UNS_ADMIN_PERM, 12314 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12315 NL80211_FLAG_NEED_RTNL, 12316 }, 12317 { 12318 .cmd = NL80211_CMD_DEL_PMKSA, 12319 .doit = nl80211_setdel_pmksa, 12320 .policy = nl80211_policy, 12321 .flags = GENL_UNS_ADMIN_PERM, 12322 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12323 NL80211_FLAG_NEED_RTNL, 12324 }, 12325 { 12326 .cmd = NL80211_CMD_FLUSH_PMKSA, 12327 .doit = nl80211_flush_pmksa, 12328 .policy = nl80211_policy, 12329 .flags = GENL_UNS_ADMIN_PERM, 12330 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12331 NL80211_FLAG_NEED_RTNL, 12332 }, 12333 { 12334 .cmd = NL80211_CMD_REMAIN_ON_CHANNEL, 12335 .doit = nl80211_remain_on_channel, 12336 .policy = nl80211_policy, 12337 .flags = GENL_UNS_ADMIN_PERM, 12338 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12339 NL80211_FLAG_NEED_RTNL, 12340 }, 12341 { 12342 .cmd = NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 12343 .doit = nl80211_cancel_remain_on_channel, 12344 .policy = nl80211_policy, 12345 .flags = GENL_UNS_ADMIN_PERM, 12346 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12347 NL80211_FLAG_NEED_RTNL, 12348 }, 12349 { 12350 .cmd = NL80211_CMD_SET_TX_BITRATE_MASK, 12351 .doit = nl80211_set_tx_bitrate_mask, 12352 .policy = nl80211_policy, 12353 .flags = GENL_UNS_ADMIN_PERM, 12354 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12355 NL80211_FLAG_NEED_RTNL, 12356 }, 12357 { 12358 .cmd = NL80211_CMD_REGISTER_FRAME, 12359 .doit = nl80211_register_mgmt, 12360 .policy = nl80211_policy, 12361 .flags = GENL_UNS_ADMIN_PERM, 12362 .internal_flags = NL80211_FLAG_NEED_WDEV | 12363 NL80211_FLAG_NEED_RTNL, 12364 }, 12365 { 12366 .cmd = NL80211_CMD_FRAME, 12367 .doit = nl80211_tx_mgmt, 12368 .policy = nl80211_policy, 12369 .flags = GENL_UNS_ADMIN_PERM, 12370 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12371 NL80211_FLAG_NEED_RTNL, 12372 }, 12373 { 12374 .cmd = NL80211_CMD_FRAME_WAIT_CANCEL, 12375 .doit = nl80211_tx_mgmt_cancel_wait, 12376 .policy = nl80211_policy, 12377 .flags = GENL_UNS_ADMIN_PERM, 12378 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12379 NL80211_FLAG_NEED_RTNL, 12380 }, 12381 { 12382 .cmd = NL80211_CMD_SET_POWER_SAVE, 12383 .doit = nl80211_set_power_save, 12384 .policy = nl80211_policy, 12385 .flags = GENL_UNS_ADMIN_PERM, 12386 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12387 NL80211_FLAG_NEED_RTNL, 12388 }, 12389 { 12390 .cmd = NL80211_CMD_GET_POWER_SAVE, 12391 .doit = nl80211_get_power_save, 12392 .policy = nl80211_policy, 12393 /* can be retrieved by unprivileged users */ 12394 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12395 NL80211_FLAG_NEED_RTNL, 12396 }, 12397 { 12398 .cmd = NL80211_CMD_SET_CQM, 12399 .doit = nl80211_set_cqm, 12400 .policy = nl80211_policy, 12401 .flags = GENL_UNS_ADMIN_PERM, 12402 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12403 NL80211_FLAG_NEED_RTNL, 12404 }, 12405 { 12406 .cmd = NL80211_CMD_SET_CHANNEL, 12407 .doit = nl80211_set_channel, 12408 .policy = nl80211_policy, 12409 .flags = GENL_UNS_ADMIN_PERM, 12410 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12411 NL80211_FLAG_NEED_RTNL, 12412 }, 12413 { 12414 .cmd = NL80211_CMD_SET_WDS_PEER, 12415 .doit = nl80211_set_wds_peer, 12416 .policy = nl80211_policy, 12417 .flags = GENL_UNS_ADMIN_PERM, 12418 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12419 NL80211_FLAG_NEED_RTNL, 12420 }, 12421 { 12422 .cmd = NL80211_CMD_JOIN_MESH, 12423 .doit = nl80211_join_mesh, 12424 .policy = nl80211_policy, 12425 .flags = GENL_UNS_ADMIN_PERM, 12426 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12427 NL80211_FLAG_NEED_RTNL, 12428 }, 12429 { 12430 .cmd = NL80211_CMD_LEAVE_MESH, 12431 .doit = nl80211_leave_mesh, 12432 .policy = nl80211_policy, 12433 .flags = GENL_UNS_ADMIN_PERM, 12434 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12435 NL80211_FLAG_NEED_RTNL, 12436 }, 12437 { 12438 .cmd = NL80211_CMD_JOIN_OCB, 12439 .doit = nl80211_join_ocb, 12440 .policy = nl80211_policy, 12441 .flags = GENL_UNS_ADMIN_PERM, 12442 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12443 NL80211_FLAG_NEED_RTNL, 12444 }, 12445 { 12446 .cmd = NL80211_CMD_LEAVE_OCB, 12447 .doit = nl80211_leave_ocb, 12448 .policy = nl80211_policy, 12449 .flags = GENL_UNS_ADMIN_PERM, 12450 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12451 NL80211_FLAG_NEED_RTNL, 12452 }, 12453 #ifdef CONFIG_PM 12454 { 12455 .cmd = NL80211_CMD_GET_WOWLAN, 12456 .doit = nl80211_get_wowlan, 12457 .policy = nl80211_policy, 12458 /* can be retrieved by unprivileged users */ 12459 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12460 NL80211_FLAG_NEED_RTNL, 12461 }, 12462 { 12463 .cmd = NL80211_CMD_SET_WOWLAN, 12464 .doit = nl80211_set_wowlan, 12465 .policy = nl80211_policy, 12466 .flags = GENL_UNS_ADMIN_PERM, 12467 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12468 NL80211_FLAG_NEED_RTNL, 12469 }, 12470 #endif 12471 { 12472 .cmd = NL80211_CMD_SET_REKEY_OFFLOAD, 12473 .doit = nl80211_set_rekey_data, 12474 .policy = nl80211_policy, 12475 .flags = GENL_UNS_ADMIN_PERM, 12476 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12477 NL80211_FLAG_NEED_RTNL | 12478 NL80211_FLAG_CLEAR_SKB, 12479 }, 12480 { 12481 .cmd = NL80211_CMD_TDLS_MGMT, 12482 .doit = nl80211_tdls_mgmt, 12483 .policy = nl80211_policy, 12484 .flags = GENL_UNS_ADMIN_PERM, 12485 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12486 NL80211_FLAG_NEED_RTNL, 12487 }, 12488 { 12489 .cmd = NL80211_CMD_TDLS_OPER, 12490 .doit = nl80211_tdls_oper, 12491 .policy = nl80211_policy, 12492 .flags = GENL_UNS_ADMIN_PERM, 12493 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12494 NL80211_FLAG_NEED_RTNL, 12495 }, 12496 { 12497 .cmd = NL80211_CMD_UNEXPECTED_FRAME, 12498 .doit = nl80211_register_unexpected_frame, 12499 .policy = nl80211_policy, 12500 .flags = GENL_UNS_ADMIN_PERM, 12501 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12502 NL80211_FLAG_NEED_RTNL, 12503 }, 12504 { 12505 .cmd = NL80211_CMD_PROBE_CLIENT, 12506 .doit = nl80211_probe_client, 12507 .policy = nl80211_policy, 12508 .flags = GENL_UNS_ADMIN_PERM, 12509 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12510 NL80211_FLAG_NEED_RTNL, 12511 }, 12512 { 12513 .cmd = NL80211_CMD_REGISTER_BEACONS, 12514 .doit = nl80211_register_beacons, 12515 .policy = nl80211_policy, 12516 .flags = GENL_UNS_ADMIN_PERM, 12517 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12518 NL80211_FLAG_NEED_RTNL, 12519 }, 12520 { 12521 .cmd = NL80211_CMD_SET_NOACK_MAP, 12522 .doit = nl80211_set_noack_map, 12523 .policy = nl80211_policy, 12524 .flags = GENL_UNS_ADMIN_PERM, 12525 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12526 NL80211_FLAG_NEED_RTNL, 12527 }, 12528 { 12529 .cmd = NL80211_CMD_START_P2P_DEVICE, 12530 .doit = nl80211_start_p2p_device, 12531 .policy = nl80211_policy, 12532 .flags = GENL_UNS_ADMIN_PERM, 12533 .internal_flags = NL80211_FLAG_NEED_WDEV | 12534 NL80211_FLAG_NEED_RTNL, 12535 }, 12536 { 12537 .cmd = NL80211_CMD_STOP_P2P_DEVICE, 12538 .doit = nl80211_stop_p2p_device, 12539 .policy = nl80211_policy, 12540 .flags = GENL_UNS_ADMIN_PERM, 12541 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12542 NL80211_FLAG_NEED_RTNL, 12543 }, 12544 { 12545 .cmd = NL80211_CMD_START_NAN, 12546 .doit = nl80211_start_nan, 12547 .policy = nl80211_policy, 12548 .flags = GENL_ADMIN_PERM, 12549 .internal_flags = NL80211_FLAG_NEED_WDEV | 12550 NL80211_FLAG_NEED_RTNL, 12551 }, 12552 { 12553 .cmd = NL80211_CMD_STOP_NAN, 12554 .doit = nl80211_stop_nan, 12555 .policy = nl80211_policy, 12556 .flags = GENL_ADMIN_PERM, 12557 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12558 NL80211_FLAG_NEED_RTNL, 12559 }, 12560 { 12561 .cmd = NL80211_CMD_ADD_NAN_FUNCTION, 12562 .doit = nl80211_nan_add_func, 12563 .policy = nl80211_policy, 12564 .flags = GENL_ADMIN_PERM, 12565 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12566 NL80211_FLAG_NEED_RTNL, 12567 }, 12568 { 12569 .cmd = NL80211_CMD_DEL_NAN_FUNCTION, 12570 .doit = nl80211_nan_del_func, 12571 .policy = nl80211_policy, 12572 .flags = GENL_ADMIN_PERM, 12573 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12574 NL80211_FLAG_NEED_RTNL, 12575 }, 12576 { 12577 .cmd = NL80211_CMD_CHANGE_NAN_CONFIG, 12578 .doit = nl80211_nan_change_config, 12579 .policy = nl80211_policy, 12580 .flags = GENL_ADMIN_PERM, 12581 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12582 NL80211_FLAG_NEED_RTNL, 12583 }, 12584 { 12585 .cmd = NL80211_CMD_SET_MCAST_RATE, 12586 .doit = nl80211_set_mcast_rate, 12587 .policy = nl80211_policy, 12588 .flags = GENL_UNS_ADMIN_PERM, 12589 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12590 NL80211_FLAG_NEED_RTNL, 12591 }, 12592 { 12593 .cmd = NL80211_CMD_SET_MAC_ACL, 12594 .doit = nl80211_set_mac_acl, 12595 .policy = nl80211_policy, 12596 .flags = GENL_UNS_ADMIN_PERM, 12597 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12598 NL80211_FLAG_NEED_RTNL, 12599 }, 12600 { 12601 .cmd = NL80211_CMD_RADAR_DETECT, 12602 .doit = nl80211_start_radar_detection, 12603 .policy = nl80211_policy, 12604 .flags = GENL_UNS_ADMIN_PERM, 12605 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12606 NL80211_FLAG_NEED_RTNL, 12607 }, 12608 { 12609 .cmd = NL80211_CMD_GET_PROTOCOL_FEATURES, 12610 .doit = nl80211_get_protocol_features, 12611 .policy = nl80211_policy, 12612 }, 12613 { 12614 .cmd = NL80211_CMD_UPDATE_FT_IES, 12615 .doit = nl80211_update_ft_ies, 12616 .policy = nl80211_policy, 12617 .flags = GENL_UNS_ADMIN_PERM, 12618 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12619 NL80211_FLAG_NEED_RTNL, 12620 }, 12621 { 12622 .cmd = NL80211_CMD_CRIT_PROTOCOL_START, 12623 .doit = nl80211_crit_protocol_start, 12624 .policy = nl80211_policy, 12625 .flags = GENL_UNS_ADMIN_PERM, 12626 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12627 NL80211_FLAG_NEED_RTNL, 12628 }, 12629 { 12630 .cmd = NL80211_CMD_CRIT_PROTOCOL_STOP, 12631 .doit = nl80211_crit_protocol_stop, 12632 .policy = nl80211_policy, 12633 .flags = GENL_UNS_ADMIN_PERM, 12634 .internal_flags = NL80211_FLAG_NEED_WDEV_UP | 12635 NL80211_FLAG_NEED_RTNL, 12636 }, 12637 { 12638 .cmd = NL80211_CMD_GET_COALESCE, 12639 .doit = nl80211_get_coalesce, 12640 .policy = nl80211_policy, 12641 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12642 NL80211_FLAG_NEED_RTNL, 12643 }, 12644 { 12645 .cmd = NL80211_CMD_SET_COALESCE, 12646 .doit = nl80211_set_coalesce, 12647 .policy = nl80211_policy, 12648 .flags = GENL_UNS_ADMIN_PERM, 12649 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12650 NL80211_FLAG_NEED_RTNL, 12651 }, 12652 { 12653 .cmd = NL80211_CMD_CHANNEL_SWITCH, 12654 .doit = nl80211_channel_switch, 12655 .policy = nl80211_policy, 12656 .flags = GENL_UNS_ADMIN_PERM, 12657 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12658 NL80211_FLAG_NEED_RTNL, 12659 }, 12660 { 12661 .cmd = NL80211_CMD_VENDOR, 12662 .doit = nl80211_vendor_cmd, 12663 .dumpit = nl80211_vendor_cmd_dump, 12664 .policy = nl80211_policy, 12665 .flags = GENL_UNS_ADMIN_PERM, 12666 .internal_flags = NL80211_FLAG_NEED_WIPHY | 12667 NL80211_FLAG_NEED_RTNL, 12668 }, 12669 { 12670 .cmd = NL80211_CMD_SET_QOS_MAP, 12671 .doit = nl80211_set_qos_map, 12672 .policy = nl80211_policy, 12673 .flags = GENL_UNS_ADMIN_PERM, 12674 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12675 NL80211_FLAG_NEED_RTNL, 12676 }, 12677 { 12678 .cmd = NL80211_CMD_ADD_TX_TS, 12679 .doit = nl80211_add_tx_ts, 12680 .policy = nl80211_policy, 12681 .flags = GENL_UNS_ADMIN_PERM, 12682 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12683 NL80211_FLAG_NEED_RTNL, 12684 }, 12685 { 12686 .cmd = NL80211_CMD_DEL_TX_TS, 12687 .doit = nl80211_del_tx_ts, 12688 .policy = nl80211_policy, 12689 .flags = GENL_UNS_ADMIN_PERM, 12690 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12691 NL80211_FLAG_NEED_RTNL, 12692 }, 12693 { 12694 .cmd = NL80211_CMD_TDLS_CHANNEL_SWITCH, 12695 .doit = nl80211_tdls_channel_switch, 12696 .policy = nl80211_policy, 12697 .flags = GENL_UNS_ADMIN_PERM, 12698 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12699 NL80211_FLAG_NEED_RTNL, 12700 }, 12701 { 12702 .cmd = NL80211_CMD_TDLS_CANCEL_CHANNEL_SWITCH, 12703 .doit = nl80211_tdls_cancel_channel_switch, 12704 .policy = nl80211_policy, 12705 .flags = GENL_UNS_ADMIN_PERM, 12706 .internal_flags = NL80211_FLAG_NEED_NETDEV_UP | 12707 NL80211_FLAG_NEED_RTNL, 12708 }, 12709 { 12710 .cmd = NL80211_CMD_SET_MULTICAST_TO_UNICAST, 12711 .doit = nl80211_set_multicast_to_unicast, 12712 .policy = nl80211_policy, 12713 .flags = GENL_UNS_ADMIN_PERM, 12714 .internal_flags = NL80211_FLAG_NEED_NETDEV | 12715 NL80211_FLAG_NEED_RTNL, 12716 }, 12717 }; 12718 12719 static struct genl_family nl80211_fam __ro_after_init = { 12720 .name = NL80211_GENL_NAME, /* have users key off the name instead */ 12721 .hdrsize = 0, /* no private header */ 12722 .version = 1, /* no particular meaning now */ 12723 .maxattr = NL80211_ATTR_MAX, 12724 .netnsok = true, 12725 .pre_doit = nl80211_pre_doit, 12726 .post_doit = nl80211_post_doit, 12727 .module = THIS_MODULE, 12728 .ops = nl80211_ops, 12729 .n_ops = ARRAY_SIZE(nl80211_ops), 12730 .mcgrps = nl80211_mcgrps, 12731 .n_mcgrps = ARRAY_SIZE(nl80211_mcgrps), 12732 }; 12733 12734 /* notification functions */ 12735 12736 void nl80211_notify_wiphy(struct cfg80211_registered_device *rdev, 12737 enum nl80211_commands cmd) 12738 { 12739 struct sk_buff *msg; 12740 struct nl80211_dump_wiphy_state state = {}; 12741 12742 WARN_ON(cmd != NL80211_CMD_NEW_WIPHY && 12743 cmd != NL80211_CMD_DEL_WIPHY); 12744 12745 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12746 if (!msg) 12747 return; 12748 12749 if (nl80211_send_wiphy(rdev, cmd, msg, 0, 0, 0, &state) < 0) { 12750 nlmsg_free(msg); 12751 return; 12752 } 12753 12754 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12755 NL80211_MCGRP_CONFIG, GFP_KERNEL); 12756 } 12757 12758 void nl80211_notify_iface(struct cfg80211_registered_device *rdev, 12759 struct wireless_dev *wdev, 12760 enum nl80211_commands cmd) 12761 { 12762 struct sk_buff *msg; 12763 12764 WARN_ON(cmd != NL80211_CMD_NEW_INTERFACE && 12765 cmd != NL80211_CMD_DEL_INTERFACE); 12766 12767 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12768 if (!msg) 12769 return; 12770 12771 if (nl80211_send_iface(msg, 0, 0, 0, rdev, wdev, 12772 cmd == NL80211_CMD_DEL_INTERFACE) < 0) { 12773 nlmsg_free(msg); 12774 return; 12775 } 12776 12777 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12778 NL80211_MCGRP_CONFIG, GFP_KERNEL); 12779 } 12780 12781 static int nl80211_add_scan_req(struct sk_buff *msg, 12782 struct cfg80211_registered_device *rdev) 12783 { 12784 struct cfg80211_scan_request *req = rdev->scan_req; 12785 struct nlattr *nest; 12786 int i; 12787 12788 if (WARN_ON(!req)) 12789 return 0; 12790 12791 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_SSIDS); 12792 if (!nest) 12793 goto nla_put_failure; 12794 for (i = 0; i < req->n_ssids; i++) { 12795 if (nla_put(msg, i, req->ssids[i].ssid_len, req->ssids[i].ssid)) 12796 goto nla_put_failure; 12797 } 12798 nla_nest_end(msg, nest); 12799 12800 nest = nla_nest_start(msg, NL80211_ATTR_SCAN_FREQUENCIES); 12801 if (!nest) 12802 goto nla_put_failure; 12803 for (i = 0; i < req->n_channels; i++) { 12804 if (nla_put_u32(msg, i, req->channels[i]->center_freq)) 12805 goto nla_put_failure; 12806 } 12807 nla_nest_end(msg, nest); 12808 12809 if (req->ie && 12810 nla_put(msg, NL80211_ATTR_IE, req->ie_len, req->ie)) 12811 goto nla_put_failure; 12812 12813 if (req->flags && 12814 nla_put_u32(msg, NL80211_ATTR_SCAN_FLAGS, req->flags)) 12815 goto nla_put_failure; 12816 12817 if (req->info.scan_start_tsf && 12818 (nla_put_u64_64bit(msg, NL80211_ATTR_SCAN_START_TIME_TSF, 12819 req->info.scan_start_tsf, NL80211_BSS_PAD) || 12820 nla_put(msg, NL80211_ATTR_SCAN_START_TIME_TSF_BSSID, ETH_ALEN, 12821 req->info.tsf_bssid))) 12822 goto nla_put_failure; 12823 12824 return 0; 12825 nla_put_failure: 12826 return -ENOBUFS; 12827 } 12828 12829 static int nl80211_send_scan_msg(struct sk_buff *msg, 12830 struct cfg80211_registered_device *rdev, 12831 struct wireless_dev *wdev, 12832 u32 portid, u32 seq, int flags, 12833 u32 cmd) 12834 { 12835 void *hdr; 12836 12837 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 12838 if (!hdr) 12839 return -1; 12840 12841 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 12842 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 12843 wdev->netdev->ifindex)) || 12844 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 12845 NL80211_ATTR_PAD)) 12846 goto nla_put_failure; 12847 12848 /* ignore errors and send incomplete event anyway */ 12849 nl80211_add_scan_req(msg, rdev); 12850 12851 genlmsg_end(msg, hdr); 12852 return 0; 12853 12854 nla_put_failure: 12855 genlmsg_cancel(msg, hdr); 12856 return -EMSGSIZE; 12857 } 12858 12859 static int 12860 nl80211_send_sched_scan_msg(struct sk_buff *msg, 12861 struct cfg80211_registered_device *rdev, 12862 struct net_device *netdev, 12863 u32 portid, u32 seq, int flags, u32 cmd) 12864 { 12865 void *hdr; 12866 12867 hdr = nl80211hdr_put(msg, portid, seq, flags, cmd); 12868 if (!hdr) 12869 return -1; 12870 12871 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 12872 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 12873 goto nla_put_failure; 12874 12875 genlmsg_end(msg, hdr); 12876 return 0; 12877 12878 nla_put_failure: 12879 genlmsg_cancel(msg, hdr); 12880 return -EMSGSIZE; 12881 } 12882 12883 void nl80211_send_scan_start(struct cfg80211_registered_device *rdev, 12884 struct wireless_dev *wdev) 12885 { 12886 struct sk_buff *msg; 12887 12888 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12889 if (!msg) 12890 return; 12891 12892 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0, 12893 NL80211_CMD_TRIGGER_SCAN) < 0) { 12894 nlmsg_free(msg); 12895 return; 12896 } 12897 12898 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12899 NL80211_MCGRP_SCAN, GFP_KERNEL); 12900 } 12901 12902 struct sk_buff *nl80211_build_scan_msg(struct cfg80211_registered_device *rdev, 12903 struct wireless_dev *wdev, bool aborted) 12904 { 12905 struct sk_buff *msg; 12906 12907 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12908 if (!msg) 12909 return NULL; 12910 12911 if (nl80211_send_scan_msg(msg, rdev, wdev, 0, 0, 0, 12912 aborted ? NL80211_CMD_SCAN_ABORTED : 12913 NL80211_CMD_NEW_SCAN_RESULTS) < 0) { 12914 nlmsg_free(msg); 12915 return NULL; 12916 } 12917 12918 return msg; 12919 } 12920 12921 void nl80211_send_scan_result(struct cfg80211_registered_device *rdev, 12922 struct sk_buff *msg) 12923 { 12924 if (!msg) 12925 return; 12926 12927 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12928 NL80211_MCGRP_SCAN, GFP_KERNEL); 12929 } 12930 12931 void nl80211_send_sched_scan_results(struct cfg80211_registered_device *rdev, 12932 struct net_device *netdev) 12933 { 12934 struct sk_buff *msg; 12935 12936 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12937 if (!msg) 12938 return; 12939 12940 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, 12941 NL80211_CMD_SCHED_SCAN_RESULTS) < 0) { 12942 nlmsg_free(msg); 12943 return; 12944 } 12945 12946 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12947 NL80211_MCGRP_SCAN, GFP_KERNEL); 12948 } 12949 12950 void nl80211_send_sched_scan(struct cfg80211_registered_device *rdev, 12951 struct net_device *netdev, u32 cmd) 12952 { 12953 struct sk_buff *msg; 12954 12955 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 12956 if (!msg) 12957 return; 12958 12959 if (nl80211_send_sched_scan_msg(msg, rdev, netdev, 0, 0, 0, cmd) < 0) { 12960 nlmsg_free(msg); 12961 return; 12962 } 12963 12964 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 12965 NL80211_MCGRP_SCAN, GFP_KERNEL); 12966 } 12967 12968 static bool nl80211_reg_change_event_fill(struct sk_buff *msg, 12969 struct regulatory_request *request) 12970 { 12971 /* Userspace can always count this one always being set */ 12972 if (nla_put_u8(msg, NL80211_ATTR_REG_INITIATOR, request->initiator)) 12973 goto nla_put_failure; 12974 12975 if (request->alpha2[0] == '0' && request->alpha2[1] == '0') { 12976 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12977 NL80211_REGDOM_TYPE_WORLD)) 12978 goto nla_put_failure; 12979 } else if (request->alpha2[0] == '9' && request->alpha2[1] == '9') { 12980 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12981 NL80211_REGDOM_TYPE_CUSTOM_WORLD)) 12982 goto nla_put_failure; 12983 } else if ((request->alpha2[0] == '9' && request->alpha2[1] == '8') || 12984 request->intersect) { 12985 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12986 NL80211_REGDOM_TYPE_INTERSECTION)) 12987 goto nla_put_failure; 12988 } else { 12989 if (nla_put_u8(msg, NL80211_ATTR_REG_TYPE, 12990 NL80211_REGDOM_TYPE_COUNTRY) || 12991 nla_put_string(msg, NL80211_ATTR_REG_ALPHA2, 12992 request->alpha2)) 12993 goto nla_put_failure; 12994 } 12995 12996 if (request->wiphy_idx != WIPHY_IDX_INVALID) { 12997 struct wiphy *wiphy = wiphy_idx_to_wiphy(request->wiphy_idx); 12998 12999 if (wiphy && 13000 nla_put_u32(msg, NL80211_ATTR_WIPHY, request->wiphy_idx)) 13001 goto nla_put_failure; 13002 13003 if (wiphy && 13004 wiphy->regulatory_flags & REGULATORY_WIPHY_SELF_MANAGED && 13005 nla_put_flag(msg, NL80211_ATTR_WIPHY_SELF_MANAGED_REG)) 13006 goto nla_put_failure; 13007 } 13008 13009 return true; 13010 13011 nla_put_failure: 13012 return false; 13013 } 13014 13015 /* 13016 * This can happen on global regulatory changes or device specific settings 13017 * based on custom regulatory domains. 13018 */ 13019 void nl80211_common_reg_change_event(enum nl80211_commands cmd_id, 13020 struct regulatory_request *request) 13021 { 13022 struct sk_buff *msg; 13023 void *hdr; 13024 13025 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13026 if (!msg) 13027 return; 13028 13029 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd_id); 13030 if (!hdr) { 13031 nlmsg_free(msg); 13032 return; 13033 } 13034 13035 if (nl80211_reg_change_event_fill(msg, request) == false) 13036 goto nla_put_failure; 13037 13038 genlmsg_end(msg, hdr); 13039 13040 rcu_read_lock(); 13041 genlmsg_multicast_allns(&nl80211_fam, msg, 0, 13042 NL80211_MCGRP_REGULATORY, GFP_ATOMIC); 13043 rcu_read_unlock(); 13044 13045 return; 13046 13047 nla_put_failure: 13048 genlmsg_cancel(msg, hdr); 13049 nlmsg_free(msg); 13050 } 13051 13052 static void nl80211_send_mlme_event(struct cfg80211_registered_device *rdev, 13053 struct net_device *netdev, 13054 const u8 *buf, size_t len, 13055 enum nl80211_commands cmd, gfp_t gfp, 13056 int uapsd_queues) 13057 { 13058 struct sk_buff *msg; 13059 void *hdr; 13060 13061 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13062 if (!msg) 13063 return; 13064 13065 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13066 if (!hdr) { 13067 nlmsg_free(msg); 13068 return; 13069 } 13070 13071 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13072 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13073 nla_put(msg, NL80211_ATTR_FRAME, len, buf)) 13074 goto nla_put_failure; 13075 13076 if (uapsd_queues >= 0) { 13077 struct nlattr *nla_wmm = 13078 nla_nest_start(msg, NL80211_ATTR_STA_WME); 13079 if (!nla_wmm) 13080 goto nla_put_failure; 13081 13082 if (nla_put_u8(msg, NL80211_STA_WME_UAPSD_QUEUES, 13083 uapsd_queues)) 13084 goto nla_put_failure; 13085 13086 nla_nest_end(msg, nla_wmm); 13087 } 13088 13089 genlmsg_end(msg, hdr); 13090 13091 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13092 NL80211_MCGRP_MLME, gfp); 13093 return; 13094 13095 nla_put_failure: 13096 genlmsg_cancel(msg, hdr); 13097 nlmsg_free(msg); 13098 } 13099 13100 void nl80211_send_rx_auth(struct cfg80211_registered_device *rdev, 13101 struct net_device *netdev, const u8 *buf, 13102 size_t len, gfp_t gfp) 13103 { 13104 nl80211_send_mlme_event(rdev, netdev, buf, len, 13105 NL80211_CMD_AUTHENTICATE, gfp, -1); 13106 } 13107 13108 void nl80211_send_rx_assoc(struct cfg80211_registered_device *rdev, 13109 struct net_device *netdev, const u8 *buf, 13110 size_t len, gfp_t gfp, int uapsd_queues) 13111 { 13112 nl80211_send_mlme_event(rdev, netdev, buf, len, 13113 NL80211_CMD_ASSOCIATE, gfp, uapsd_queues); 13114 } 13115 13116 void nl80211_send_deauth(struct cfg80211_registered_device *rdev, 13117 struct net_device *netdev, const u8 *buf, 13118 size_t len, gfp_t gfp) 13119 { 13120 nl80211_send_mlme_event(rdev, netdev, buf, len, 13121 NL80211_CMD_DEAUTHENTICATE, gfp, -1); 13122 } 13123 13124 void nl80211_send_disassoc(struct cfg80211_registered_device *rdev, 13125 struct net_device *netdev, const u8 *buf, 13126 size_t len, gfp_t gfp) 13127 { 13128 nl80211_send_mlme_event(rdev, netdev, buf, len, 13129 NL80211_CMD_DISASSOCIATE, gfp, -1); 13130 } 13131 13132 void cfg80211_rx_unprot_mlme_mgmt(struct net_device *dev, const u8 *buf, 13133 size_t len) 13134 { 13135 struct wireless_dev *wdev = dev->ieee80211_ptr; 13136 struct wiphy *wiphy = wdev->wiphy; 13137 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13138 const struct ieee80211_mgmt *mgmt = (void *)buf; 13139 u32 cmd; 13140 13141 if (WARN_ON(len < 2)) 13142 return; 13143 13144 if (ieee80211_is_deauth(mgmt->frame_control)) 13145 cmd = NL80211_CMD_UNPROT_DEAUTHENTICATE; 13146 else 13147 cmd = NL80211_CMD_UNPROT_DISASSOCIATE; 13148 13149 trace_cfg80211_rx_unprot_mlme_mgmt(dev, buf, len); 13150 nl80211_send_mlme_event(rdev, dev, buf, len, cmd, GFP_ATOMIC, -1); 13151 } 13152 EXPORT_SYMBOL(cfg80211_rx_unprot_mlme_mgmt); 13153 13154 static void nl80211_send_mlme_timeout(struct cfg80211_registered_device *rdev, 13155 struct net_device *netdev, int cmd, 13156 const u8 *addr, gfp_t gfp) 13157 { 13158 struct sk_buff *msg; 13159 void *hdr; 13160 13161 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13162 if (!msg) 13163 return; 13164 13165 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13166 if (!hdr) { 13167 nlmsg_free(msg); 13168 return; 13169 } 13170 13171 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13172 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13173 nla_put_flag(msg, NL80211_ATTR_TIMED_OUT) || 13174 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) 13175 goto nla_put_failure; 13176 13177 genlmsg_end(msg, hdr); 13178 13179 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13180 NL80211_MCGRP_MLME, gfp); 13181 return; 13182 13183 nla_put_failure: 13184 genlmsg_cancel(msg, hdr); 13185 nlmsg_free(msg); 13186 } 13187 13188 void nl80211_send_auth_timeout(struct cfg80211_registered_device *rdev, 13189 struct net_device *netdev, const u8 *addr, 13190 gfp_t gfp) 13191 { 13192 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_AUTHENTICATE, 13193 addr, gfp); 13194 } 13195 13196 void nl80211_send_assoc_timeout(struct cfg80211_registered_device *rdev, 13197 struct net_device *netdev, const u8 *addr, 13198 gfp_t gfp) 13199 { 13200 nl80211_send_mlme_timeout(rdev, netdev, NL80211_CMD_ASSOCIATE, 13201 addr, gfp); 13202 } 13203 13204 void nl80211_send_connect_result(struct cfg80211_registered_device *rdev, 13205 struct net_device *netdev, const u8 *bssid, 13206 const u8 *req_ie, size_t req_ie_len, 13207 const u8 *resp_ie, size_t resp_ie_len, 13208 int status, gfp_t gfp) 13209 { 13210 struct sk_buff *msg; 13211 void *hdr; 13212 13213 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13214 if (!msg) 13215 return; 13216 13217 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONNECT); 13218 if (!hdr) { 13219 nlmsg_free(msg); 13220 return; 13221 } 13222 13223 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13224 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13225 (bssid && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) || 13226 nla_put_u16(msg, NL80211_ATTR_STATUS_CODE, 13227 status < 0 ? WLAN_STATUS_UNSPECIFIED_FAILURE : 13228 status) || 13229 (status < 0 && nla_put_flag(msg, NL80211_ATTR_TIMED_OUT)) || 13230 (req_ie && 13231 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) || 13232 (resp_ie && 13233 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie))) 13234 goto nla_put_failure; 13235 13236 genlmsg_end(msg, hdr); 13237 13238 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13239 NL80211_MCGRP_MLME, gfp); 13240 return; 13241 13242 nla_put_failure: 13243 genlmsg_cancel(msg, hdr); 13244 nlmsg_free(msg); 13245 } 13246 13247 void nl80211_send_roamed(struct cfg80211_registered_device *rdev, 13248 struct net_device *netdev, const u8 *bssid, 13249 const u8 *req_ie, size_t req_ie_len, 13250 const u8 *resp_ie, size_t resp_ie_len, gfp_t gfp) 13251 { 13252 struct sk_buff *msg; 13253 void *hdr; 13254 13255 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13256 if (!msg) 13257 return; 13258 13259 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_ROAM); 13260 if (!hdr) { 13261 nlmsg_free(msg); 13262 return; 13263 } 13264 13265 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13266 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13267 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid) || 13268 (req_ie && 13269 nla_put(msg, NL80211_ATTR_REQ_IE, req_ie_len, req_ie)) || 13270 (resp_ie && 13271 nla_put(msg, NL80211_ATTR_RESP_IE, resp_ie_len, resp_ie))) 13272 goto nla_put_failure; 13273 13274 genlmsg_end(msg, hdr); 13275 13276 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13277 NL80211_MCGRP_MLME, gfp); 13278 return; 13279 13280 nla_put_failure: 13281 genlmsg_cancel(msg, hdr); 13282 nlmsg_free(msg); 13283 } 13284 13285 void nl80211_send_disconnected(struct cfg80211_registered_device *rdev, 13286 struct net_device *netdev, u16 reason, 13287 const u8 *ie, size_t ie_len, bool from_ap) 13288 { 13289 struct sk_buff *msg; 13290 void *hdr; 13291 13292 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 13293 if (!msg) 13294 return; 13295 13296 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_DISCONNECT); 13297 if (!hdr) { 13298 nlmsg_free(msg); 13299 return; 13300 } 13301 13302 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13303 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13304 (from_ap && reason && 13305 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason)) || 13306 (from_ap && 13307 nla_put_flag(msg, NL80211_ATTR_DISCONNECTED_BY_AP)) || 13308 (ie && nla_put(msg, NL80211_ATTR_IE, ie_len, ie))) 13309 goto nla_put_failure; 13310 13311 genlmsg_end(msg, hdr); 13312 13313 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13314 NL80211_MCGRP_MLME, GFP_KERNEL); 13315 return; 13316 13317 nla_put_failure: 13318 genlmsg_cancel(msg, hdr); 13319 nlmsg_free(msg); 13320 } 13321 13322 void nl80211_send_ibss_bssid(struct cfg80211_registered_device *rdev, 13323 struct net_device *netdev, const u8 *bssid, 13324 gfp_t gfp) 13325 { 13326 struct sk_buff *msg; 13327 void *hdr; 13328 13329 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13330 if (!msg) 13331 return; 13332 13333 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_JOIN_IBSS); 13334 if (!hdr) { 13335 nlmsg_free(msg); 13336 return; 13337 } 13338 13339 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13340 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13341 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) 13342 goto nla_put_failure; 13343 13344 genlmsg_end(msg, hdr); 13345 13346 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13347 NL80211_MCGRP_MLME, gfp); 13348 return; 13349 13350 nla_put_failure: 13351 genlmsg_cancel(msg, hdr); 13352 nlmsg_free(msg); 13353 } 13354 13355 void cfg80211_notify_new_peer_candidate(struct net_device *dev, const u8 *addr, 13356 const u8* ie, u8 ie_len, gfp_t gfp) 13357 { 13358 struct wireless_dev *wdev = dev->ieee80211_ptr; 13359 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13360 struct sk_buff *msg; 13361 void *hdr; 13362 13363 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_MESH_POINT)) 13364 return; 13365 13366 trace_cfg80211_notify_new_peer_candidate(dev, addr); 13367 13368 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13369 if (!msg) 13370 return; 13371 13372 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NEW_PEER_CANDIDATE); 13373 if (!hdr) { 13374 nlmsg_free(msg); 13375 return; 13376 } 13377 13378 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13379 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13380 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) || 13381 (ie_len && ie && 13382 nla_put(msg, NL80211_ATTR_IE, ie_len , ie))) 13383 goto nla_put_failure; 13384 13385 genlmsg_end(msg, hdr); 13386 13387 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13388 NL80211_MCGRP_MLME, gfp); 13389 return; 13390 13391 nla_put_failure: 13392 genlmsg_cancel(msg, hdr); 13393 nlmsg_free(msg); 13394 } 13395 EXPORT_SYMBOL(cfg80211_notify_new_peer_candidate); 13396 13397 void nl80211_michael_mic_failure(struct cfg80211_registered_device *rdev, 13398 struct net_device *netdev, const u8 *addr, 13399 enum nl80211_key_type key_type, int key_id, 13400 const u8 *tsc, gfp_t gfp) 13401 { 13402 struct sk_buff *msg; 13403 void *hdr; 13404 13405 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13406 if (!msg) 13407 return; 13408 13409 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_MICHAEL_MIC_FAILURE); 13410 if (!hdr) { 13411 nlmsg_free(msg); 13412 return; 13413 } 13414 13415 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13416 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13417 (addr && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) || 13418 nla_put_u32(msg, NL80211_ATTR_KEY_TYPE, key_type) || 13419 (key_id != -1 && 13420 nla_put_u8(msg, NL80211_ATTR_KEY_IDX, key_id)) || 13421 (tsc && nla_put(msg, NL80211_ATTR_KEY_SEQ, 6, tsc))) 13422 goto nla_put_failure; 13423 13424 genlmsg_end(msg, hdr); 13425 13426 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13427 NL80211_MCGRP_MLME, gfp); 13428 return; 13429 13430 nla_put_failure: 13431 genlmsg_cancel(msg, hdr); 13432 nlmsg_free(msg); 13433 } 13434 13435 void nl80211_send_beacon_hint_event(struct wiphy *wiphy, 13436 struct ieee80211_channel *channel_before, 13437 struct ieee80211_channel *channel_after) 13438 { 13439 struct sk_buff *msg; 13440 void *hdr; 13441 struct nlattr *nl_freq; 13442 13443 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_ATOMIC); 13444 if (!msg) 13445 return; 13446 13447 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_REG_BEACON_HINT); 13448 if (!hdr) { 13449 nlmsg_free(msg); 13450 return; 13451 } 13452 13453 /* 13454 * Since we are applying the beacon hint to a wiphy we know its 13455 * wiphy_idx is valid 13456 */ 13457 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, get_wiphy_idx(wiphy))) 13458 goto nla_put_failure; 13459 13460 /* Before */ 13461 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_BEFORE); 13462 if (!nl_freq) 13463 goto nla_put_failure; 13464 if (nl80211_msg_put_channel(msg, channel_before, false)) 13465 goto nla_put_failure; 13466 nla_nest_end(msg, nl_freq); 13467 13468 /* After */ 13469 nl_freq = nla_nest_start(msg, NL80211_ATTR_FREQ_AFTER); 13470 if (!nl_freq) 13471 goto nla_put_failure; 13472 if (nl80211_msg_put_channel(msg, channel_after, false)) 13473 goto nla_put_failure; 13474 nla_nest_end(msg, nl_freq); 13475 13476 genlmsg_end(msg, hdr); 13477 13478 rcu_read_lock(); 13479 genlmsg_multicast_allns(&nl80211_fam, msg, 0, 13480 NL80211_MCGRP_REGULATORY, GFP_ATOMIC); 13481 rcu_read_unlock(); 13482 13483 return; 13484 13485 nla_put_failure: 13486 genlmsg_cancel(msg, hdr); 13487 nlmsg_free(msg); 13488 } 13489 13490 static void nl80211_send_remain_on_chan_event( 13491 int cmd, struct cfg80211_registered_device *rdev, 13492 struct wireless_dev *wdev, u64 cookie, 13493 struct ieee80211_channel *chan, 13494 unsigned int duration, gfp_t gfp) 13495 { 13496 struct sk_buff *msg; 13497 void *hdr; 13498 13499 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13500 if (!msg) 13501 return; 13502 13503 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13504 if (!hdr) { 13505 nlmsg_free(msg); 13506 return; 13507 } 13508 13509 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13510 (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13511 wdev->netdev->ifindex)) || 13512 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13513 NL80211_ATTR_PAD) || 13514 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, chan->center_freq) || 13515 nla_put_u32(msg, NL80211_ATTR_WIPHY_CHANNEL_TYPE, 13516 NL80211_CHAN_NO_HT) || 13517 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 13518 NL80211_ATTR_PAD)) 13519 goto nla_put_failure; 13520 13521 if (cmd == NL80211_CMD_REMAIN_ON_CHANNEL && 13522 nla_put_u32(msg, NL80211_ATTR_DURATION, duration)) 13523 goto nla_put_failure; 13524 13525 genlmsg_end(msg, hdr); 13526 13527 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13528 NL80211_MCGRP_MLME, gfp); 13529 return; 13530 13531 nla_put_failure: 13532 genlmsg_cancel(msg, hdr); 13533 nlmsg_free(msg); 13534 } 13535 13536 void cfg80211_ready_on_channel(struct wireless_dev *wdev, u64 cookie, 13537 struct ieee80211_channel *chan, 13538 unsigned int duration, gfp_t gfp) 13539 { 13540 struct wiphy *wiphy = wdev->wiphy; 13541 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13542 13543 trace_cfg80211_ready_on_channel(wdev, cookie, chan, duration); 13544 nl80211_send_remain_on_chan_event(NL80211_CMD_REMAIN_ON_CHANNEL, 13545 rdev, wdev, cookie, chan, 13546 duration, gfp); 13547 } 13548 EXPORT_SYMBOL(cfg80211_ready_on_channel); 13549 13550 void cfg80211_remain_on_channel_expired(struct wireless_dev *wdev, u64 cookie, 13551 struct ieee80211_channel *chan, 13552 gfp_t gfp) 13553 { 13554 struct wiphy *wiphy = wdev->wiphy; 13555 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13556 13557 trace_cfg80211_ready_on_channel_expired(wdev, cookie, chan); 13558 nl80211_send_remain_on_chan_event(NL80211_CMD_CANCEL_REMAIN_ON_CHANNEL, 13559 rdev, wdev, cookie, chan, 0, gfp); 13560 } 13561 EXPORT_SYMBOL(cfg80211_remain_on_channel_expired); 13562 13563 void cfg80211_new_sta(struct net_device *dev, const u8 *mac_addr, 13564 struct station_info *sinfo, gfp_t gfp) 13565 { 13566 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13567 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13568 struct sk_buff *msg; 13569 13570 trace_cfg80211_new_sta(dev, mac_addr, sinfo); 13571 13572 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13573 if (!msg) 13574 return; 13575 13576 if (nl80211_send_station(msg, NL80211_CMD_NEW_STATION, 0, 0, 0, 13577 rdev, dev, mac_addr, sinfo) < 0) { 13578 nlmsg_free(msg); 13579 return; 13580 } 13581 13582 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13583 NL80211_MCGRP_MLME, gfp); 13584 } 13585 EXPORT_SYMBOL(cfg80211_new_sta); 13586 13587 void cfg80211_del_sta_sinfo(struct net_device *dev, const u8 *mac_addr, 13588 struct station_info *sinfo, gfp_t gfp) 13589 { 13590 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13591 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13592 struct sk_buff *msg; 13593 struct station_info empty_sinfo = {}; 13594 13595 if (!sinfo) 13596 sinfo = &empty_sinfo; 13597 13598 trace_cfg80211_del_sta(dev, mac_addr); 13599 13600 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13601 if (!msg) 13602 return; 13603 13604 if (nl80211_send_station(msg, NL80211_CMD_DEL_STATION, 0, 0, 0, 13605 rdev, dev, mac_addr, sinfo) < 0) { 13606 nlmsg_free(msg); 13607 return; 13608 } 13609 13610 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13611 NL80211_MCGRP_MLME, gfp); 13612 } 13613 EXPORT_SYMBOL(cfg80211_del_sta_sinfo); 13614 13615 void cfg80211_conn_failed(struct net_device *dev, const u8 *mac_addr, 13616 enum nl80211_connect_failed_reason reason, 13617 gfp_t gfp) 13618 { 13619 struct wiphy *wiphy = dev->ieee80211_ptr->wiphy; 13620 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13621 struct sk_buff *msg; 13622 void *hdr; 13623 13624 msg = nlmsg_new(NLMSG_GOODSIZE, gfp); 13625 if (!msg) 13626 return; 13627 13628 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CONN_FAILED); 13629 if (!hdr) { 13630 nlmsg_free(msg); 13631 return; 13632 } 13633 13634 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13635 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac_addr) || 13636 nla_put_u32(msg, NL80211_ATTR_CONN_FAILED_REASON, reason)) 13637 goto nla_put_failure; 13638 13639 genlmsg_end(msg, hdr); 13640 13641 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13642 NL80211_MCGRP_MLME, gfp); 13643 return; 13644 13645 nla_put_failure: 13646 genlmsg_cancel(msg, hdr); 13647 nlmsg_free(msg); 13648 } 13649 EXPORT_SYMBOL(cfg80211_conn_failed); 13650 13651 static bool __nl80211_unexpected_frame(struct net_device *dev, u8 cmd, 13652 const u8 *addr, gfp_t gfp) 13653 { 13654 struct wireless_dev *wdev = dev->ieee80211_ptr; 13655 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13656 struct sk_buff *msg; 13657 void *hdr; 13658 u32 nlportid = ACCESS_ONCE(wdev->ap_unexpected_nlportid); 13659 13660 if (!nlportid) 13661 return false; 13662 13663 msg = nlmsg_new(100, gfp); 13664 if (!msg) 13665 return true; 13666 13667 hdr = nl80211hdr_put(msg, 0, 0, 0, cmd); 13668 if (!hdr) { 13669 nlmsg_free(msg); 13670 return true; 13671 } 13672 13673 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13674 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 13675 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr)) 13676 goto nla_put_failure; 13677 13678 genlmsg_end(msg, hdr); 13679 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 13680 return true; 13681 13682 nla_put_failure: 13683 genlmsg_cancel(msg, hdr); 13684 nlmsg_free(msg); 13685 return true; 13686 } 13687 13688 bool cfg80211_rx_spurious_frame(struct net_device *dev, 13689 const u8 *addr, gfp_t gfp) 13690 { 13691 struct wireless_dev *wdev = dev->ieee80211_ptr; 13692 bool ret; 13693 13694 trace_cfg80211_rx_spurious_frame(dev, addr); 13695 13696 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP && 13697 wdev->iftype != NL80211_IFTYPE_P2P_GO)) { 13698 trace_cfg80211_return_bool(false); 13699 return false; 13700 } 13701 ret = __nl80211_unexpected_frame(dev, NL80211_CMD_UNEXPECTED_FRAME, 13702 addr, gfp); 13703 trace_cfg80211_return_bool(ret); 13704 return ret; 13705 } 13706 EXPORT_SYMBOL(cfg80211_rx_spurious_frame); 13707 13708 bool cfg80211_rx_unexpected_4addr_frame(struct net_device *dev, 13709 const u8 *addr, gfp_t gfp) 13710 { 13711 struct wireless_dev *wdev = dev->ieee80211_ptr; 13712 bool ret; 13713 13714 trace_cfg80211_rx_unexpected_4addr_frame(dev, addr); 13715 13716 if (WARN_ON(wdev->iftype != NL80211_IFTYPE_AP && 13717 wdev->iftype != NL80211_IFTYPE_P2P_GO && 13718 wdev->iftype != NL80211_IFTYPE_AP_VLAN)) { 13719 trace_cfg80211_return_bool(false); 13720 return false; 13721 } 13722 ret = __nl80211_unexpected_frame(dev, 13723 NL80211_CMD_UNEXPECTED_4ADDR_FRAME, 13724 addr, gfp); 13725 trace_cfg80211_return_bool(ret); 13726 return ret; 13727 } 13728 EXPORT_SYMBOL(cfg80211_rx_unexpected_4addr_frame); 13729 13730 int nl80211_send_mgmt(struct cfg80211_registered_device *rdev, 13731 struct wireless_dev *wdev, u32 nlportid, 13732 int freq, int sig_dbm, 13733 const u8 *buf, size_t len, u32 flags, gfp_t gfp) 13734 { 13735 struct net_device *netdev = wdev->netdev; 13736 struct sk_buff *msg; 13737 void *hdr; 13738 13739 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13740 if (!msg) 13741 return -ENOMEM; 13742 13743 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME); 13744 if (!hdr) { 13745 nlmsg_free(msg); 13746 return -ENOMEM; 13747 } 13748 13749 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13750 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13751 netdev->ifindex)) || 13752 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13753 NL80211_ATTR_PAD) || 13754 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq) || 13755 (sig_dbm && 13756 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) || 13757 nla_put(msg, NL80211_ATTR_FRAME, len, buf) || 13758 (flags && 13759 nla_put_u32(msg, NL80211_ATTR_RXMGMT_FLAGS, flags))) 13760 goto nla_put_failure; 13761 13762 genlmsg_end(msg, hdr); 13763 13764 return genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 13765 13766 nla_put_failure: 13767 genlmsg_cancel(msg, hdr); 13768 nlmsg_free(msg); 13769 return -ENOBUFS; 13770 } 13771 13772 void cfg80211_mgmt_tx_status(struct wireless_dev *wdev, u64 cookie, 13773 const u8 *buf, size_t len, bool ack, gfp_t gfp) 13774 { 13775 struct wiphy *wiphy = wdev->wiphy; 13776 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 13777 struct net_device *netdev = wdev->netdev; 13778 struct sk_buff *msg; 13779 void *hdr; 13780 13781 trace_cfg80211_mgmt_tx_status(wdev, cookie, ack); 13782 13783 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13784 if (!msg) 13785 return; 13786 13787 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME_TX_STATUS); 13788 if (!hdr) { 13789 nlmsg_free(msg); 13790 return; 13791 } 13792 13793 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13794 (netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 13795 netdev->ifindex)) || 13796 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 13797 NL80211_ATTR_PAD) || 13798 nla_put(msg, NL80211_ATTR_FRAME, len, buf) || 13799 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 13800 NL80211_ATTR_PAD) || 13801 (ack && nla_put_flag(msg, NL80211_ATTR_ACK))) 13802 goto nla_put_failure; 13803 13804 genlmsg_end(msg, hdr); 13805 13806 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13807 NL80211_MCGRP_MLME, gfp); 13808 return; 13809 13810 nla_put_failure: 13811 genlmsg_cancel(msg, hdr); 13812 nlmsg_free(msg); 13813 } 13814 EXPORT_SYMBOL(cfg80211_mgmt_tx_status); 13815 13816 static struct sk_buff *cfg80211_prepare_cqm(struct net_device *dev, 13817 const char *mac, gfp_t gfp) 13818 { 13819 struct wireless_dev *wdev = dev->ieee80211_ptr; 13820 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 13821 struct sk_buff *msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13822 void **cb; 13823 13824 if (!msg) 13825 return NULL; 13826 13827 cb = (void **)msg->cb; 13828 13829 cb[0] = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_NOTIFY_CQM); 13830 if (!cb[0]) { 13831 nlmsg_free(msg); 13832 return NULL; 13833 } 13834 13835 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13836 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex)) 13837 goto nla_put_failure; 13838 13839 if (mac && nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, mac)) 13840 goto nla_put_failure; 13841 13842 cb[1] = nla_nest_start(msg, NL80211_ATTR_CQM); 13843 if (!cb[1]) 13844 goto nla_put_failure; 13845 13846 cb[2] = rdev; 13847 13848 return msg; 13849 nla_put_failure: 13850 nlmsg_free(msg); 13851 return NULL; 13852 } 13853 13854 static void cfg80211_send_cqm(struct sk_buff *msg, gfp_t gfp) 13855 { 13856 void **cb = (void **)msg->cb; 13857 struct cfg80211_registered_device *rdev = cb[2]; 13858 13859 nla_nest_end(msg, cb[1]); 13860 genlmsg_end(msg, cb[0]); 13861 13862 memset(msg->cb, 0, sizeof(msg->cb)); 13863 13864 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 13865 NL80211_MCGRP_MLME, gfp); 13866 } 13867 13868 void cfg80211_cqm_rssi_notify(struct net_device *dev, 13869 enum nl80211_cqm_rssi_threshold_event rssi_event, 13870 gfp_t gfp) 13871 { 13872 struct sk_buff *msg; 13873 13874 trace_cfg80211_cqm_rssi_notify(dev, rssi_event); 13875 13876 if (WARN_ON(rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_LOW && 13877 rssi_event != NL80211_CQM_RSSI_THRESHOLD_EVENT_HIGH)) 13878 return; 13879 13880 msg = cfg80211_prepare_cqm(dev, NULL, gfp); 13881 if (!msg) 13882 return; 13883 13884 if (nla_put_u32(msg, NL80211_ATTR_CQM_RSSI_THRESHOLD_EVENT, 13885 rssi_event)) 13886 goto nla_put_failure; 13887 13888 cfg80211_send_cqm(msg, gfp); 13889 13890 return; 13891 13892 nla_put_failure: 13893 nlmsg_free(msg); 13894 } 13895 EXPORT_SYMBOL(cfg80211_cqm_rssi_notify); 13896 13897 void cfg80211_cqm_txe_notify(struct net_device *dev, 13898 const u8 *peer, u32 num_packets, 13899 u32 rate, u32 intvl, gfp_t gfp) 13900 { 13901 struct sk_buff *msg; 13902 13903 msg = cfg80211_prepare_cqm(dev, peer, gfp); 13904 if (!msg) 13905 return; 13906 13907 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_PKTS, num_packets)) 13908 goto nla_put_failure; 13909 13910 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_RATE, rate)) 13911 goto nla_put_failure; 13912 13913 if (nla_put_u32(msg, NL80211_ATTR_CQM_TXE_INTVL, intvl)) 13914 goto nla_put_failure; 13915 13916 cfg80211_send_cqm(msg, gfp); 13917 return; 13918 13919 nla_put_failure: 13920 nlmsg_free(msg); 13921 } 13922 EXPORT_SYMBOL(cfg80211_cqm_txe_notify); 13923 13924 void cfg80211_cqm_pktloss_notify(struct net_device *dev, 13925 const u8 *peer, u32 num_packets, gfp_t gfp) 13926 { 13927 struct sk_buff *msg; 13928 13929 trace_cfg80211_cqm_pktloss_notify(dev, peer, num_packets); 13930 13931 msg = cfg80211_prepare_cqm(dev, peer, gfp); 13932 if (!msg) 13933 return; 13934 13935 if (nla_put_u32(msg, NL80211_ATTR_CQM_PKT_LOSS_EVENT, num_packets)) 13936 goto nla_put_failure; 13937 13938 cfg80211_send_cqm(msg, gfp); 13939 return; 13940 13941 nla_put_failure: 13942 nlmsg_free(msg); 13943 } 13944 EXPORT_SYMBOL(cfg80211_cqm_pktloss_notify); 13945 13946 void cfg80211_cqm_beacon_loss_notify(struct net_device *dev, gfp_t gfp) 13947 { 13948 struct sk_buff *msg; 13949 13950 msg = cfg80211_prepare_cqm(dev, NULL, gfp); 13951 if (!msg) 13952 return; 13953 13954 if (nla_put_flag(msg, NL80211_ATTR_CQM_BEACON_LOSS_EVENT)) 13955 goto nla_put_failure; 13956 13957 cfg80211_send_cqm(msg, gfp); 13958 return; 13959 13960 nla_put_failure: 13961 nlmsg_free(msg); 13962 } 13963 EXPORT_SYMBOL(cfg80211_cqm_beacon_loss_notify); 13964 13965 static void nl80211_gtk_rekey_notify(struct cfg80211_registered_device *rdev, 13966 struct net_device *netdev, const u8 *bssid, 13967 const u8 *replay_ctr, gfp_t gfp) 13968 { 13969 struct sk_buff *msg; 13970 struct nlattr *rekey_attr; 13971 void *hdr; 13972 13973 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 13974 if (!msg) 13975 return; 13976 13977 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_REKEY_OFFLOAD); 13978 if (!hdr) { 13979 nlmsg_free(msg); 13980 return; 13981 } 13982 13983 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 13984 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 13985 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, bssid)) 13986 goto nla_put_failure; 13987 13988 rekey_attr = nla_nest_start(msg, NL80211_ATTR_REKEY_DATA); 13989 if (!rekey_attr) 13990 goto nla_put_failure; 13991 13992 if (nla_put(msg, NL80211_REKEY_DATA_REPLAY_CTR, 13993 NL80211_REPLAY_CTR_LEN, replay_ctr)) 13994 goto nla_put_failure; 13995 13996 nla_nest_end(msg, rekey_attr); 13997 13998 genlmsg_end(msg, hdr); 13999 14000 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14001 NL80211_MCGRP_MLME, gfp); 14002 return; 14003 14004 nla_put_failure: 14005 genlmsg_cancel(msg, hdr); 14006 nlmsg_free(msg); 14007 } 14008 14009 void cfg80211_gtk_rekey_notify(struct net_device *dev, const u8 *bssid, 14010 const u8 *replay_ctr, gfp_t gfp) 14011 { 14012 struct wireless_dev *wdev = dev->ieee80211_ptr; 14013 struct wiphy *wiphy = wdev->wiphy; 14014 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14015 14016 trace_cfg80211_gtk_rekey_notify(dev, bssid); 14017 nl80211_gtk_rekey_notify(rdev, dev, bssid, replay_ctr, gfp); 14018 } 14019 EXPORT_SYMBOL(cfg80211_gtk_rekey_notify); 14020 14021 static void 14022 nl80211_pmksa_candidate_notify(struct cfg80211_registered_device *rdev, 14023 struct net_device *netdev, int index, 14024 const u8 *bssid, bool preauth, gfp_t gfp) 14025 { 14026 struct sk_buff *msg; 14027 struct nlattr *attr; 14028 void *hdr; 14029 14030 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14031 if (!msg) 14032 return; 14033 14034 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PMKSA_CANDIDATE); 14035 if (!hdr) { 14036 nlmsg_free(msg); 14037 return; 14038 } 14039 14040 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14041 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 14042 goto nla_put_failure; 14043 14044 attr = nla_nest_start(msg, NL80211_ATTR_PMKSA_CANDIDATE); 14045 if (!attr) 14046 goto nla_put_failure; 14047 14048 if (nla_put_u32(msg, NL80211_PMKSA_CANDIDATE_INDEX, index) || 14049 nla_put(msg, NL80211_PMKSA_CANDIDATE_BSSID, ETH_ALEN, bssid) || 14050 (preauth && 14051 nla_put_flag(msg, NL80211_PMKSA_CANDIDATE_PREAUTH))) 14052 goto nla_put_failure; 14053 14054 nla_nest_end(msg, attr); 14055 14056 genlmsg_end(msg, hdr); 14057 14058 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14059 NL80211_MCGRP_MLME, gfp); 14060 return; 14061 14062 nla_put_failure: 14063 genlmsg_cancel(msg, hdr); 14064 nlmsg_free(msg); 14065 } 14066 14067 void cfg80211_pmksa_candidate_notify(struct net_device *dev, int index, 14068 const u8 *bssid, bool preauth, gfp_t gfp) 14069 { 14070 struct wireless_dev *wdev = dev->ieee80211_ptr; 14071 struct wiphy *wiphy = wdev->wiphy; 14072 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14073 14074 trace_cfg80211_pmksa_candidate_notify(dev, index, bssid, preauth); 14075 nl80211_pmksa_candidate_notify(rdev, dev, index, bssid, preauth, gfp); 14076 } 14077 EXPORT_SYMBOL(cfg80211_pmksa_candidate_notify); 14078 14079 static void nl80211_ch_switch_notify(struct cfg80211_registered_device *rdev, 14080 struct net_device *netdev, 14081 struct cfg80211_chan_def *chandef, 14082 gfp_t gfp, 14083 enum nl80211_commands notif, 14084 u8 count) 14085 { 14086 struct sk_buff *msg; 14087 void *hdr; 14088 14089 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14090 if (!msg) 14091 return; 14092 14093 hdr = nl80211hdr_put(msg, 0, 0, 0, notif); 14094 if (!hdr) { 14095 nlmsg_free(msg); 14096 return; 14097 } 14098 14099 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex)) 14100 goto nla_put_failure; 14101 14102 if (nl80211_send_chandef(msg, chandef)) 14103 goto nla_put_failure; 14104 14105 if ((notif == NL80211_CMD_CH_SWITCH_STARTED_NOTIFY) && 14106 (nla_put_u32(msg, NL80211_ATTR_CH_SWITCH_COUNT, count))) 14107 goto nla_put_failure; 14108 14109 genlmsg_end(msg, hdr); 14110 14111 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14112 NL80211_MCGRP_MLME, gfp); 14113 return; 14114 14115 nla_put_failure: 14116 genlmsg_cancel(msg, hdr); 14117 nlmsg_free(msg); 14118 } 14119 14120 void cfg80211_ch_switch_notify(struct net_device *dev, 14121 struct cfg80211_chan_def *chandef) 14122 { 14123 struct wireless_dev *wdev = dev->ieee80211_ptr; 14124 struct wiphy *wiphy = wdev->wiphy; 14125 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14126 14127 ASSERT_WDEV_LOCK(wdev); 14128 14129 trace_cfg80211_ch_switch_notify(dev, chandef); 14130 14131 wdev->chandef = *chandef; 14132 wdev->preset_chandef = *chandef; 14133 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL, 14134 NL80211_CMD_CH_SWITCH_NOTIFY, 0); 14135 } 14136 EXPORT_SYMBOL(cfg80211_ch_switch_notify); 14137 14138 void cfg80211_ch_switch_started_notify(struct net_device *dev, 14139 struct cfg80211_chan_def *chandef, 14140 u8 count) 14141 { 14142 struct wireless_dev *wdev = dev->ieee80211_ptr; 14143 struct wiphy *wiphy = wdev->wiphy; 14144 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14145 14146 trace_cfg80211_ch_switch_started_notify(dev, chandef); 14147 14148 nl80211_ch_switch_notify(rdev, dev, chandef, GFP_KERNEL, 14149 NL80211_CMD_CH_SWITCH_STARTED_NOTIFY, count); 14150 } 14151 EXPORT_SYMBOL(cfg80211_ch_switch_started_notify); 14152 14153 void 14154 nl80211_radar_notify(struct cfg80211_registered_device *rdev, 14155 const struct cfg80211_chan_def *chandef, 14156 enum nl80211_radar_event event, 14157 struct net_device *netdev, gfp_t gfp) 14158 { 14159 struct sk_buff *msg; 14160 void *hdr; 14161 14162 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14163 if (!msg) 14164 return; 14165 14166 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_RADAR_DETECT); 14167 if (!hdr) { 14168 nlmsg_free(msg); 14169 return; 14170 } 14171 14172 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx)) 14173 goto nla_put_failure; 14174 14175 /* NOP and radar events don't need a netdev parameter */ 14176 if (netdev) { 14177 struct wireless_dev *wdev = netdev->ieee80211_ptr; 14178 14179 if (nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14180 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14181 NL80211_ATTR_PAD)) 14182 goto nla_put_failure; 14183 } 14184 14185 if (nla_put_u32(msg, NL80211_ATTR_RADAR_EVENT, event)) 14186 goto nla_put_failure; 14187 14188 if (nl80211_send_chandef(msg, chandef)) 14189 goto nla_put_failure; 14190 14191 genlmsg_end(msg, hdr); 14192 14193 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14194 NL80211_MCGRP_MLME, gfp); 14195 return; 14196 14197 nla_put_failure: 14198 genlmsg_cancel(msg, hdr); 14199 nlmsg_free(msg); 14200 } 14201 14202 void cfg80211_probe_status(struct net_device *dev, const u8 *addr, 14203 u64 cookie, bool acked, gfp_t gfp) 14204 { 14205 struct wireless_dev *wdev = dev->ieee80211_ptr; 14206 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14207 struct sk_buff *msg; 14208 void *hdr; 14209 14210 trace_cfg80211_probe_status(dev, addr, cookie, acked); 14211 14212 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14213 14214 if (!msg) 14215 return; 14216 14217 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_PROBE_CLIENT); 14218 if (!hdr) { 14219 nlmsg_free(msg); 14220 return; 14221 } 14222 14223 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14224 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 14225 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, addr) || 14226 nla_put_u64_64bit(msg, NL80211_ATTR_COOKIE, cookie, 14227 NL80211_ATTR_PAD) || 14228 (acked && nla_put_flag(msg, NL80211_ATTR_ACK))) 14229 goto nla_put_failure; 14230 14231 genlmsg_end(msg, hdr); 14232 14233 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14234 NL80211_MCGRP_MLME, gfp); 14235 return; 14236 14237 nla_put_failure: 14238 genlmsg_cancel(msg, hdr); 14239 nlmsg_free(msg); 14240 } 14241 EXPORT_SYMBOL(cfg80211_probe_status); 14242 14243 void cfg80211_report_obss_beacon(struct wiphy *wiphy, 14244 const u8 *frame, size_t len, 14245 int freq, int sig_dbm) 14246 { 14247 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14248 struct sk_buff *msg; 14249 void *hdr; 14250 struct cfg80211_beacon_registration *reg; 14251 14252 trace_cfg80211_report_obss_beacon(wiphy, frame, len, freq, sig_dbm); 14253 14254 spin_lock_bh(&rdev->beacon_registrations_lock); 14255 list_for_each_entry(reg, &rdev->beacon_registrations, list) { 14256 msg = nlmsg_new(len + 100, GFP_ATOMIC); 14257 if (!msg) { 14258 spin_unlock_bh(&rdev->beacon_registrations_lock); 14259 return; 14260 } 14261 14262 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FRAME); 14263 if (!hdr) 14264 goto nla_put_failure; 14265 14266 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14267 (freq && 14268 nla_put_u32(msg, NL80211_ATTR_WIPHY_FREQ, freq)) || 14269 (sig_dbm && 14270 nla_put_u32(msg, NL80211_ATTR_RX_SIGNAL_DBM, sig_dbm)) || 14271 nla_put(msg, NL80211_ATTR_FRAME, len, frame)) 14272 goto nla_put_failure; 14273 14274 genlmsg_end(msg, hdr); 14275 14276 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, reg->nlportid); 14277 } 14278 spin_unlock_bh(&rdev->beacon_registrations_lock); 14279 return; 14280 14281 nla_put_failure: 14282 spin_unlock_bh(&rdev->beacon_registrations_lock); 14283 if (hdr) 14284 genlmsg_cancel(msg, hdr); 14285 nlmsg_free(msg); 14286 } 14287 EXPORT_SYMBOL(cfg80211_report_obss_beacon); 14288 14289 #ifdef CONFIG_PM 14290 static int cfg80211_net_detect_results(struct sk_buff *msg, 14291 struct cfg80211_wowlan_wakeup *wakeup) 14292 { 14293 struct cfg80211_wowlan_nd_info *nd = wakeup->net_detect; 14294 struct nlattr *nl_results, *nl_match, *nl_freqs; 14295 int i, j; 14296 14297 nl_results = nla_nest_start( 14298 msg, NL80211_WOWLAN_TRIG_NET_DETECT_RESULTS); 14299 if (!nl_results) 14300 return -EMSGSIZE; 14301 14302 for (i = 0; i < nd->n_matches; i++) { 14303 struct cfg80211_wowlan_nd_match *match = nd->matches[i]; 14304 14305 nl_match = nla_nest_start(msg, i); 14306 if (!nl_match) 14307 break; 14308 14309 /* The SSID attribute is optional in nl80211, but for 14310 * simplicity reasons it's always present in the 14311 * cfg80211 structure. If a driver can't pass the 14312 * SSID, that needs to be changed. A zero length SSID 14313 * is still a valid SSID (wildcard), so it cannot be 14314 * used for this purpose. 14315 */ 14316 if (nla_put(msg, NL80211_ATTR_SSID, match->ssid.ssid_len, 14317 match->ssid.ssid)) { 14318 nla_nest_cancel(msg, nl_match); 14319 goto out; 14320 } 14321 14322 if (match->n_channels) { 14323 nl_freqs = nla_nest_start( 14324 msg, NL80211_ATTR_SCAN_FREQUENCIES); 14325 if (!nl_freqs) { 14326 nla_nest_cancel(msg, nl_match); 14327 goto out; 14328 } 14329 14330 for (j = 0; j < match->n_channels; j++) { 14331 if (nla_put_u32(msg, j, match->channels[j])) { 14332 nla_nest_cancel(msg, nl_freqs); 14333 nla_nest_cancel(msg, nl_match); 14334 goto out; 14335 } 14336 } 14337 14338 nla_nest_end(msg, nl_freqs); 14339 } 14340 14341 nla_nest_end(msg, nl_match); 14342 } 14343 14344 out: 14345 nla_nest_end(msg, nl_results); 14346 return 0; 14347 } 14348 14349 void cfg80211_report_wowlan_wakeup(struct wireless_dev *wdev, 14350 struct cfg80211_wowlan_wakeup *wakeup, 14351 gfp_t gfp) 14352 { 14353 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14354 struct sk_buff *msg; 14355 void *hdr; 14356 int size = 200; 14357 14358 trace_cfg80211_report_wowlan_wakeup(wdev->wiphy, wdev, wakeup); 14359 14360 if (wakeup) 14361 size += wakeup->packet_present_len; 14362 14363 msg = nlmsg_new(size, gfp); 14364 if (!msg) 14365 return; 14366 14367 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_SET_WOWLAN); 14368 if (!hdr) 14369 goto free_msg; 14370 14371 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14372 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14373 NL80211_ATTR_PAD)) 14374 goto free_msg; 14375 14376 if (wdev->netdev && nla_put_u32(msg, NL80211_ATTR_IFINDEX, 14377 wdev->netdev->ifindex)) 14378 goto free_msg; 14379 14380 if (wakeup) { 14381 struct nlattr *reasons; 14382 14383 reasons = nla_nest_start(msg, NL80211_ATTR_WOWLAN_TRIGGERS); 14384 if (!reasons) 14385 goto free_msg; 14386 14387 if (wakeup->disconnect && 14388 nla_put_flag(msg, NL80211_WOWLAN_TRIG_DISCONNECT)) 14389 goto free_msg; 14390 if (wakeup->magic_pkt && 14391 nla_put_flag(msg, NL80211_WOWLAN_TRIG_MAGIC_PKT)) 14392 goto free_msg; 14393 if (wakeup->gtk_rekey_failure && 14394 nla_put_flag(msg, NL80211_WOWLAN_TRIG_GTK_REKEY_FAILURE)) 14395 goto free_msg; 14396 if (wakeup->eap_identity_req && 14397 nla_put_flag(msg, NL80211_WOWLAN_TRIG_EAP_IDENT_REQUEST)) 14398 goto free_msg; 14399 if (wakeup->four_way_handshake && 14400 nla_put_flag(msg, NL80211_WOWLAN_TRIG_4WAY_HANDSHAKE)) 14401 goto free_msg; 14402 if (wakeup->rfkill_release && 14403 nla_put_flag(msg, NL80211_WOWLAN_TRIG_RFKILL_RELEASE)) 14404 goto free_msg; 14405 14406 if (wakeup->pattern_idx >= 0 && 14407 nla_put_u32(msg, NL80211_WOWLAN_TRIG_PKT_PATTERN, 14408 wakeup->pattern_idx)) 14409 goto free_msg; 14410 14411 if (wakeup->tcp_match && 14412 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_MATCH)) 14413 goto free_msg; 14414 14415 if (wakeup->tcp_connlost && 14416 nla_put_flag(msg, NL80211_WOWLAN_TRIG_WAKEUP_TCP_CONNLOST)) 14417 goto free_msg; 14418 14419 if (wakeup->tcp_nomoretokens && 14420 nla_put_flag(msg, 14421 NL80211_WOWLAN_TRIG_WAKEUP_TCP_NOMORETOKENS)) 14422 goto free_msg; 14423 14424 if (wakeup->packet) { 14425 u32 pkt_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211; 14426 u32 len_attr = NL80211_WOWLAN_TRIG_WAKEUP_PKT_80211_LEN; 14427 14428 if (!wakeup->packet_80211) { 14429 pkt_attr = 14430 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023; 14431 len_attr = 14432 NL80211_WOWLAN_TRIG_WAKEUP_PKT_8023_LEN; 14433 } 14434 14435 if (wakeup->packet_len && 14436 nla_put_u32(msg, len_attr, wakeup->packet_len)) 14437 goto free_msg; 14438 14439 if (nla_put(msg, pkt_attr, wakeup->packet_present_len, 14440 wakeup->packet)) 14441 goto free_msg; 14442 } 14443 14444 if (wakeup->net_detect && 14445 cfg80211_net_detect_results(msg, wakeup)) 14446 goto free_msg; 14447 14448 nla_nest_end(msg, reasons); 14449 } 14450 14451 genlmsg_end(msg, hdr); 14452 14453 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14454 NL80211_MCGRP_MLME, gfp); 14455 return; 14456 14457 free_msg: 14458 nlmsg_free(msg); 14459 } 14460 EXPORT_SYMBOL(cfg80211_report_wowlan_wakeup); 14461 #endif 14462 14463 void cfg80211_tdls_oper_request(struct net_device *dev, const u8 *peer, 14464 enum nl80211_tdls_operation oper, 14465 u16 reason_code, gfp_t gfp) 14466 { 14467 struct wireless_dev *wdev = dev->ieee80211_ptr; 14468 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wdev->wiphy); 14469 struct sk_buff *msg; 14470 void *hdr; 14471 14472 trace_cfg80211_tdls_oper_request(wdev->wiphy, dev, peer, oper, 14473 reason_code); 14474 14475 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14476 if (!msg) 14477 return; 14478 14479 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_TDLS_OPER); 14480 if (!hdr) { 14481 nlmsg_free(msg); 14482 return; 14483 } 14484 14485 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14486 nla_put_u32(msg, NL80211_ATTR_IFINDEX, dev->ifindex) || 14487 nla_put_u8(msg, NL80211_ATTR_TDLS_OPERATION, oper) || 14488 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, peer) || 14489 (reason_code > 0 && 14490 nla_put_u16(msg, NL80211_ATTR_REASON_CODE, reason_code))) 14491 goto nla_put_failure; 14492 14493 genlmsg_end(msg, hdr); 14494 14495 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14496 NL80211_MCGRP_MLME, gfp); 14497 return; 14498 14499 nla_put_failure: 14500 genlmsg_cancel(msg, hdr); 14501 nlmsg_free(msg); 14502 } 14503 EXPORT_SYMBOL(cfg80211_tdls_oper_request); 14504 14505 static int nl80211_netlink_notify(struct notifier_block * nb, 14506 unsigned long state, 14507 void *_notify) 14508 { 14509 struct netlink_notify *notify = _notify; 14510 struct cfg80211_registered_device *rdev; 14511 struct wireless_dev *wdev; 14512 struct cfg80211_beacon_registration *reg, *tmp; 14513 14514 if (state != NETLINK_URELEASE || notify->protocol != NETLINK_GENERIC) 14515 return NOTIFY_DONE; 14516 14517 rcu_read_lock(); 14518 14519 list_for_each_entry_rcu(rdev, &cfg80211_rdev_list, list) { 14520 bool schedule_destroy_work = false; 14521 struct cfg80211_sched_scan_request *sched_scan_req = 14522 rcu_dereference(rdev->sched_scan_req); 14523 14524 if (sched_scan_req && notify->portid && 14525 sched_scan_req->owner_nlportid == notify->portid) { 14526 sched_scan_req->owner_nlportid = 0; 14527 14528 if (rdev->ops->sched_scan_stop && 14529 rdev->wiphy.flags & WIPHY_FLAG_SUPPORTS_SCHED_SCAN) 14530 schedule_work(&rdev->sched_scan_stop_wk); 14531 } 14532 14533 list_for_each_entry_rcu(wdev, &rdev->wiphy.wdev_list, list) { 14534 cfg80211_mlme_unregister_socket(wdev, notify->portid); 14535 14536 if (wdev->owner_nlportid == notify->portid) 14537 schedule_destroy_work = true; 14538 } 14539 14540 spin_lock_bh(&rdev->beacon_registrations_lock); 14541 list_for_each_entry_safe(reg, tmp, &rdev->beacon_registrations, 14542 list) { 14543 if (reg->nlportid == notify->portid) { 14544 list_del(®->list); 14545 kfree(reg); 14546 break; 14547 } 14548 } 14549 spin_unlock_bh(&rdev->beacon_registrations_lock); 14550 14551 if (schedule_destroy_work) { 14552 struct cfg80211_iface_destroy *destroy; 14553 14554 destroy = kzalloc(sizeof(*destroy), GFP_ATOMIC); 14555 if (destroy) { 14556 destroy->nlportid = notify->portid; 14557 spin_lock(&rdev->destroy_list_lock); 14558 list_add(&destroy->list, &rdev->destroy_list); 14559 spin_unlock(&rdev->destroy_list_lock); 14560 schedule_work(&rdev->destroy_work); 14561 } 14562 } 14563 } 14564 14565 rcu_read_unlock(); 14566 14567 /* 14568 * It is possible that the user space process that is controlling the 14569 * indoor setting disappeared, so notify the regulatory core. 14570 */ 14571 regulatory_netlink_notify(notify->portid); 14572 return NOTIFY_OK; 14573 } 14574 14575 static struct notifier_block nl80211_netlink_notifier = { 14576 .notifier_call = nl80211_netlink_notify, 14577 }; 14578 14579 void cfg80211_ft_event(struct net_device *netdev, 14580 struct cfg80211_ft_event_params *ft_event) 14581 { 14582 struct wiphy *wiphy = netdev->ieee80211_ptr->wiphy; 14583 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14584 struct sk_buff *msg; 14585 void *hdr; 14586 14587 trace_cfg80211_ft_event(wiphy, netdev, ft_event); 14588 14589 if (!ft_event->target_ap) 14590 return; 14591 14592 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 14593 if (!msg) 14594 return; 14595 14596 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_FT_EVENT); 14597 if (!hdr) 14598 goto out; 14599 14600 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14601 nla_put_u32(msg, NL80211_ATTR_IFINDEX, netdev->ifindex) || 14602 nla_put(msg, NL80211_ATTR_MAC, ETH_ALEN, ft_event->target_ap)) 14603 goto out; 14604 14605 if (ft_event->ies && 14606 nla_put(msg, NL80211_ATTR_IE, ft_event->ies_len, ft_event->ies)) 14607 goto out; 14608 if (ft_event->ric_ies && 14609 nla_put(msg, NL80211_ATTR_IE_RIC, ft_event->ric_ies_len, 14610 ft_event->ric_ies)) 14611 goto out; 14612 14613 genlmsg_end(msg, hdr); 14614 14615 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(&rdev->wiphy), msg, 0, 14616 NL80211_MCGRP_MLME, GFP_KERNEL); 14617 return; 14618 out: 14619 nlmsg_free(msg); 14620 } 14621 EXPORT_SYMBOL(cfg80211_ft_event); 14622 14623 void cfg80211_crit_proto_stopped(struct wireless_dev *wdev, gfp_t gfp) 14624 { 14625 struct cfg80211_registered_device *rdev; 14626 struct sk_buff *msg; 14627 void *hdr; 14628 u32 nlportid; 14629 14630 rdev = wiphy_to_rdev(wdev->wiphy); 14631 if (!rdev->crit_proto_nlportid) 14632 return; 14633 14634 nlportid = rdev->crit_proto_nlportid; 14635 rdev->crit_proto_nlportid = 0; 14636 14637 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, gfp); 14638 if (!msg) 14639 return; 14640 14641 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_CRIT_PROTOCOL_STOP); 14642 if (!hdr) 14643 goto nla_put_failure; 14644 14645 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14646 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14647 NL80211_ATTR_PAD)) 14648 goto nla_put_failure; 14649 14650 genlmsg_end(msg, hdr); 14651 14652 genlmsg_unicast(wiphy_net(&rdev->wiphy), msg, nlportid); 14653 return; 14654 14655 nla_put_failure: 14656 if (hdr) 14657 genlmsg_cancel(msg, hdr); 14658 nlmsg_free(msg); 14659 } 14660 EXPORT_SYMBOL(cfg80211_crit_proto_stopped); 14661 14662 void nl80211_send_ap_stopped(struct wireless_dev *wdev) 14663 { 14664 struct wiphy *wiphy = wdev->wiphy; 14665 struct cfg80211_registered_device *rdev = wiphy_to_rdev(wiphy); 14666 struct sk_buff *msg; 14667 void *hdr; 14668 14669 msg = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL); 14670 if (!msg) 14671 return; 14672 14673 hdr = nl80211hdr_put(msg, 0, 0, 0, NL80211_CMD_STOP_AP); 14674 if (!hdr) 14675 goto out; 14676 14677 if (nla_put_u32(msg, NL80211_ATTR_WIPHY, rdev->wiphy_idx) || 14678 nla_put_u32(msg, NL80211_ATTR_IFINDEX, wdev->netdev->ifindex) || 14679 nla_put_u64_64bit(msg, NL80211_ATTR_WDEV, wdev_id(wdev), 14680 NL80211_ATTR_PAD)) 14681 goto out; 14682 14683 genlmsg_end(msg, hdr); 14684 14685 genlmsg_multicast_netns(&nl80211_fam, wiphy_net(wiphy), msg, 0, 14686 NL80211_MCGRP_MLME, GFP_KERNEL); 14687 return; 14688 out: 14689 nlmsg_free(msg); 14690 } 14691 14692 /* initialisation/exit functions */ 14693 14694 int __init nl80211_init(void) 14695 { 14696 int err; 14697 14698 err = genl_register_family(&nl80211_fam); 14699 if (err) 14700 return err; 14701 14702 err = netlink_register_notifier(&nl80211_netlink_notifier); 14703 if (err) 14704 goto err_out; 14705 14706 return 0; 14707 err_out: 14708 genl_unregister_family(&nl80211_fam); 14709 return err; 14710 } 14711 14712 void nl80211_exit(void) 14713 { 14714 netlink_unregister_notifier(&nl80211_netlink_notifier); 14715 genl_unregister_family(&nl80211_fam); 14716 } 14717